Commit graph

3872 commits

Author SHA1 Message Date
Adam Shih
eb9b56a10d Move cma dump to itself am: e7ea94d8e1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22241488

Change-Id: I20ef8777e4da8756fd97180307b40883e60c5916
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 01:52:42 +00:00
TreeHugger Robot
feef477d2f Merge "Remove tracking_denials/hal_fingerprint_default.te" into udc-dev 2023-03-27 01:37:37 +00:00
chenkris
2bd6ae14f3 Remove tracking_denials/hal_fingerprint_default.te
Bug: 187015705
Bug: 183338543
Test: build and test fingerprint on device.
Test: no fingerprint avc denials in logcat.
Change-Id: I1dde2c0d8c8ab2610c2b8147c15ac5c9f813345a
2023-03-24 07:40:05 +00:00
Adam Shih
e7ea94d8e1 Move cma dump to itself
Bug: 273380985
Test: adb bugreport
Change-Id: I40ecb631c7fbbea216f5c56857b92152c997e466
2023-03-24 13:56:31 +08:00
KRIS CHEN
1501f5458b Merge "Allow fingerprint hal to read sysfs_leds" into udc-dev am: 2f8f23232a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22178646

Change-Id: Ifde56bf07622f05ecc86caece163d72b2f1dde0f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 02:41:26 +00:00
KRIS CHEN
2f8f23232a Merge "Allow fingerprint hal to read sysfs_leds" into udc-dev 2023-03-24 02:06:37 +00:00
Jörg Wagner
cefbf93aaf Update Mali DDK to r40 : Additional SELinux settings am: cb6bad65e7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22170060

Change-Id: I883c67b413abdd2d5a638f62784099de9afe37d2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-21 15:15:21 +00:00
Kris Chen
d678ee3226 Allow fingerprint hal to read sysfs_leds
Fix the following avc denials:
avc: denied { search } for name="backlight" dev="sysfs" ino=79316
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=dir permissive=1

avc: denied { read } for name="state" dev="sysfs" ino=79365
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=file permissive=1

Bug: 271072126
Test: Authenticate fingerprint.
Change-Id: I67f5502bc7b4b1d6e14cf493f1bc6575980bcd0d
2023-03-21 12:19:07 +00:00
Jörg Wagner
cb6bad65e7 Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 74d31a1568)
Merged-In: I5c69a8bafe3a4c738c124facb1f437ec721cc3ea
Change-Id: I7e6734cb79b38898eb65a0194b37381a1367fc36
2023-03-21 10:31:51 +00:00
Adam Shih
1b0cecc49f use devfreq dump from gs-common am: 4d9aa0b28f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22175766

Change-Id: Ib07707b9eadf2caa57daadce6a9ee548001329d4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-21 08:29:53 +00:00
Adam Shih
4d9aa0b28f use devfreq dump from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: I0ea6767fd7640c2ee1be66f659f94c15cb4766cd
2023-03-21 12:41:23 +08:00
Enzo Liao
1eb912223d SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel. am: 893d8ddff7 am: 2bc1af0adf am: 2110a1db8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21937144

Change-Id: Icaa70fa36b8e959c91954b5641e6e7fe0aec3e2b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 05:53:07 +00:00
Enzo Liao
2110a1db8c SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel. am: 893d8ddff7 am: 2bc1af0adf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21937144

Change-Id: Ic08044ef00fef5fab0a52fe8375f3a7aa1a51924
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 05:14:54 +00:00
Enzo Liao
2bc1af0adf SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel. am: 893d8ddff7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21937144

Change-Id: Ibd95511a2d3a6e1cdebac8a20238c2ecfa876e27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 04:38:41 +00:00
Enzo Liao
893d8ddff7 SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel.
It needs to access a file pushed by hosts of test suites (details: http://go/pd-client-for-lab#heading=h.wtp07hbqvwgx)

Bug: 234359369
Design: http://go/pd-client-for-lab
Test: manual (http://b/271555983#comment3)
Change-Id: I1c9544ca2ebe1857c439f00c4589f739aca8e157
2023-03-15 03:52:17 +00:00
Xin Li
10b03660f2 [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours am: af9a0596e4 -s ours am: f782184f62 -s ours am: 0ff740c68d -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: Ie9a9afc06082ffd1f145d91547fabbcb8df98b83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 01:10:51 +00:00
Xin Li
0ff740c68d [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours am: af9a0596e4 -s ours am: f782184f62 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: Ie37f36262dee71729e90a28da38d1ebf8439713e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 00:06:22 +00:00
Xin Li
f782184f62 [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours am: af9a0596e4 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: I3eb89a6c5cdb182b2e340d61458fcbe804d156d0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 23:06:15 +00:00
Xin Li
af9a0596e4 [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: I8e0f4144027a594f78e29bde8407d130509ac6e5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 22:32:23 +00:00
Xin Li
f703b89586 Merge Android 13 QPR2
Bug: 273316506
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Change-Id: I4dfcfac354c52a6bf2828558dd44e1acca0b550a
2023-03-13 23:09:33 -07:00
Jasmine Cha
5b90d7c3a3 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 3b3aa9e921
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21913160

Change-Id: Ifdcd71f609cdcce59e5139e01f50ae77949d7f52
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:19:45 +00:00
Jasmine Cha
3b3aa9e921 Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Adam Shih
80de558c18 Move display dump to gs-common am: 7d3f25d95b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21806784

Change-Id: Ie1a549f1f550e8263f2b3c01433097e0e06c3192
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 05:29:16 +00:00
Jasmine Cha
b263562360 audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: Ie1499be82e405c2ddf4cd1a62ee7ff2823befd8e
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:10:18 +08:00
Adam Shih
7d3f25d95b Move display dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: Id40661687bbd04d7eba4790dc5fe17ca5c79e47d
2023-03-07 13:01:05 +08:00
leochuang
4fe64170d3 Update SELinux error
Test: scanBugreport
Bug: 270247432
Change-Id: Ia5e76ee1c027ac2b1cbbbc6a20a20f3ea609a1b7
2023-02-22 10:30:02 +08:00
Ken Tsou
cd826e0365 [automerger skipped] [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.* am: 3194ab09f9 am: c02d353334 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21457164

Change-Id: I313ea2cb154644b1a61f40e08e0cd6f41868b5ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 15:53:31 +00:00
Ken Tsou
c02d353334 [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.* am: 3194ab09f9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21457164

Change-Id: Iad95f30732e0342f673d36999028722775706bb5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:52:58 +00:00
Ken Tsou
3194ab09f9 [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 10:28:27 +00:00
Ken Tsou
6964113b1c hal_health_default: allow to access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 07:02:01 +00:00
Lucas Wei
6ef92ee0d1 Merge "votable: Update don't audit file entry" 2023-02-16 06:00:51 +00:00
TreeHugger Robot
afafde41a1 Merge "Update SELinux error" 2023-02-15 03:53:59 +00:00
Treehugger Robot
6c53f05cae Merge "Remove bug_map entry for incident" am: bc70a9f3df am: dfd9324aca am: 05d473ec62
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: Ic2399bc1d08f5b79ac19e083595a0f0e3ba9233e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 03:27:43 +00:00
Lucas Wei
5a70bbb335 votable: Update don't audit file entry
Test: No votable avc errors in dmesg
Bug: 247905787
Change-Id: I95ab4dd7750e9b0f26d41fece50dc6d0aa73dd41
Signed-off-by: Lucas Wei <lucaswei@google.com>
2023-02-15 02:49:08 +00:00
leochuang
e5b2d04476 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269370106
Bug: 269045042
Change-Id: Ief58a1f19580251476c71602951550388015df01
2023-02-15 10:25:40 +08:00
Treehugger Robot
05d473ec62 Merge "Remove bug_map entry for incident" am: bc70a9f3df am: dfd9324aca
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: I0c0386e02131db6c353f059ad1320f51027d9e6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 02:23:51 +00:00
Treehugger Robot
dfd9324aca Merge "Remove bug_map entry for incident" am: bc70a9f3df
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: I435bdfe151ffbb88e2b3e2f8360acfaf42093ee4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 01:36:50 +00:00
Treehugger Robot
bc70a9f3df Merge "Remove bug_map entry for incident" 2023-02-15 00:31:13 +00:00
Thiébaud Weksteen
10d08a16e1 Remove bug_map entry for incident
Bug: 238570971
Bug: 238571324
Bug: 238571420
Test: presubmit
Change-Id: Ib24d85aaed87e6e5dc0b0281d65407e8c45e017c
2023-02-15 10:19:58 +11:00
TreeHugger Robot
a6f9e17cd4 Merge "Update SELinux error" 2023-02-14 22:56:03 +00:00
Treehugger Robot
580fb1061d Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f am: 60fc07a2f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I269fe35ddd8dc13df7b275a84f86955e2853563a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 20:44:30 +00:00
Treehugger Robot
60fc07a2f5 Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I624db1bdd6fbe5de7d774954f5390fb0af884b77
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 19:41:20 +00:00
Treehugger Robot
114e2a377f Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: Ib469bb013d0c7335e2da4f429cde4c5df9395ed5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 18:56:35 +00:00
Android Build Coastguard Worker
50b0c84d12 Merge cherrypicks of ['googleplex-android-review.googlesource.com/21219300'] into tm-qpr2-release.
Change-Id: Iba513e117f9749ea342aa573120c758f4a14ba68
2023-02-14 18:20:12 +00:00
Ray Chi
beacc5b05f [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
(cherry picked from commit 9828cc747a)
Merged-In: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-14 18:13:34 +00:00
Treehugger Robot
b72bb4c53f Merge "Map AIDL Gatekeeper to same policy as HIDL version" 2023-02-14 17:48:17 +00:00
leochuang
14c66190df Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269218638
Change-Id: If7d4633aa4f4f10cf3b56640ae6661a2a9b20b91
2023-02-14 15:46:17 +08:00
Adam Shih
bd3291b1c0 Merge "Move memory dump to gs-common" 2023-02-14 07:22:12 +00:00
Adam Shih
9a7bb8df86 Move memory dump to gs-common
Bug: 240530709
Test: adb bugreport
Change-Id: I78433d8d170af54a4daee6c9a9218ce35e78e730
2023-02-13 14:56:30 +08:00
sukiliu
d48a10f9b0 Update SELinux error
Test: scanBugreport
Bug: 269045042
Change-Id: I6291a7d3fd3b75d68548bd2fb7287b8ff754684a
2023-02-13 10:41:23 +08:00