Commit graph

229 commits

Author SHA1 Message Date
Wilson Sung
12abc8ef4a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 287169829
Change-Id: I0a245d81ae243a0461c19583e19912566062bb71
2023-06-14 15:30:31 +08:00
Wilson Sung
20364fe3b3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281814691
Change-Id: I2f73f5b75aec1145dee615499a7442400defbf8a
2023-05-11 06:43:02 +00:00
Bruno BELANYI
88f5acac54 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev
* changes:
  Remove 'hal_neuralnetworks_armnn' '/data' access exception
  Remove 'hal_neuralnetworks_armnn' sysprop exceptions
  Add ArmNN config sysprops SELinux rules
2023-04-27 08:06:48 +00:00
Bruno BELANYI
9702cb57f2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:347dfbe925e2218189d82d37697540af25401a22)
Merged-In: Ic8bf0d51414461689ee5768821a2a1acda923c41
Change-Id: Ic8bf0d51414461689ee5768821a2a1acda923c41
2023-04-26 17:21:18 +00:00
Bruno BELANYI
b4001ec206 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:e4254a16aa516f5960f48732b078aad4ed63df6f)
Merged-In: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
Change-Id: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
2023-04-26 17:20:54 +00:00
Adam Shih
843b0ad6b4 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
Merged-In: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-24 09:58:14 +08:00
Wilson Sung
c41cb55d4f Update SELinux error
Test: scanBugreport
Bug: 277528855
Change-Id: Ia59cd4045433f2e82a602672fe533e27e87b0275
2023-04-10 11:02:52 +08:00
Wilson Sung
816622f352 Update error on ROM 9891405
Bug: 277155042
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Ic2129188db52ec85a8afaf92c507a42695e82804
2023-04-07 14:56:21 +08:00
Wilson Sung
083b5fe640 Merge "Update SELinux error" into udc-dev 2023-03-31 10:18:47 +00:00
Wilson Sung
accb299d5d Update SELinux error
Test: scanBugreport
Bug: 276385941
Change-Id: I54627db892f95ac7ee6e9b08762b7a72793d4a00
2023-03-31 10:55:58 +08:00
Wilson Sung
28afe7393f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275002227
Change-Id: If2133d83efbfa00ee9643a25047f465c60d2d3c4
2023-03-29 06:34:07 +00:00
chenkris
2bd6ae14f3 Remove tracking_denials/hal_fingerprint_default.te
Bug: 187015705
Bug: 183338543
Test: build and test fingerprint on device.
Test: no fingerprint avc denials in logcat.
Change-Id: I1dde2c0d8c8ab2610c2b8147c15ac5c9f813345a
2023-03-24 07:40:05 +00:00
leochuang
4fe64170d3 Update SELinux error
Test: scanBugreport
Bug: 270247432
Change-Id: Ia5e76ee1c027ac2b1cbbbc6a20a20f3ea609a1b7
2023-02-22 10:30:02 +08:00
Lucas Wei
6ef92ee0d1 Merge "votable: Update don't audit file entry" 2023-02-16 06:00:51 +00:00
TreeHugger Robot
afafde41a1 Merge "Update SELinux error" 2023-02-15 03:53:59 +00:00
Treehugger Robot
6c53f05cae Merge "Remove bug_map entry for incident" am: bc70a9f3df am: dfd9324aca am: 05d473ec62
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: Ic2399bc1d08f5b79ac19e083595a0f0e3ba9233e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 03:27:43 +00:00
Lucas Wei
5a70bbb335 votable: Update don't audit file entry
Test: No votable avc errors in dmesg
Bug: 247905787
Change-Id: I95ab4dd7750e9b0f26d41fece50dc6d0aa73dd41
Signed-off-by: Lucas Wei <lucaswei@google.com>
2023-02-15 02:49:08 +00:00
leochuang
e5b2d04476 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269370106
Bug: 269045042
Change-Id: Ief58a1f19580251476c71602951550388015df01
2023-02-15 10:25:40 +08:00
Treehugger Robot
dfd9324aca Merge "Remove bug_map entry for incident" am: bc70a9f3df
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: I435bdfe151ffbb88e2b3e2f8360acfaf42093ee4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 01:36:50 +00:00
Thiébaud Weksteen
10d08a16e1 Remove bug_map entry for incident
Bug: 238570971
Bug: 238571324
Bug: 238571420
Test: presubmit
Change-Id: Ib24d85aaed87e6e5dc0b0281d65407e8c45e017c
2023-02-15 10:19:58 +11:00
leochuang
14c66190df Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269218638
Change-Id: If7d4633aa4f4f10cf3b56640ae6661a2a9b20b91
2023-02-14 15:46:17 +08:00
sukiliu
d48a10f9b0 Update SELinux error
Test: scanBugreport
Bug: 269045042
Change-Id: I6291a7d3fd3b75d68548bd2fb7287b8ff754684a
2023-02-13 10:41:23 +08:00
sukiliu
8835275413 Update SELinux error
Test: scanBugreport
Bug: 268411073
Bug: 268147283
Bug: 268146971
Change-Id: I60fdc8e3d44da7632522f57adc01c0e6879be83c
2023-02-10 10:20:35 +08:00
Kyle Zhang
bfbf488408 Merge "Add hal_drm_widevine for Widevine exec sepolicy" 2023-01-11 05:37:46 +00:00
Adam Shih
d246880b0d update error on ROM am: 776148c936 am: 6dcabc08bf
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2376986

Change-Id: I546135adca5de40c7792405ba32d4f4cc8328424
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-06 05:05:08 +00:00
Kyle Zhang
902db3961f Add hal_drm_widevine for Widevine exec sepolicy
Bug: 243699259
Test: atp v2/widevine-eng/drm_compliance
Change-Id: Ifede19e690cb7b7333016df08fb146a0ec8f7409
2023-01-06 03:14:20 +00:00
Adam Shih
776148c936 update error on ROM
Bug: 242203678
Test: pass boot test
Change-Id: Ib50c5aed2787d068e589491373a75de47cbe48ee
Merged-In: Ifa7de8df3b09eabee7df8008dbb381854e18f48f
2023-01-06 02:42:14 +00:00
Adam Shih
afe63f78cc Update SELinux error
Test: scanBugreport
Bug: 264483673
Test: scanAvcDeniedLogRightAfterReboot
Change-Id: I954f764f035fcffa06c1c940bece36f0d7e42711
2023-01-05 13:38:16 +08:00
Adam Shih
46285b5dd5 Update SELinux error
Test: scanBugreport
Bug: 264483156
Change-Id: Ifa7de8df3b09eabee7df8008dbb381854e18f48f
2023-01-05 11:04:58 +08:00
Lucas Wei
8a9fd1b4aa votable: update SEpolicy error am: 5851e17605
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20265110

Change-Id: I3d444fed3a236050d00988b59a4237df3815f2e4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-24 03:28:26 +00:00
Lucas Wei
5851e17605 votable: update SEpolicy error
Bug: 247905787
Signed-off-by: Lucas Wei <lucaswei@google.com>
Change-Id: Ia6dfb7796ab46b0ac339b98465ccd91624b655ed
2022-10-23 23:23:41 +08:00
Thiébaud Weksteen
7d6c449261 Revert "Update SELinux error"
This reverts commit 286d40c81b.

Test: TH
Bug: 241172186
Bug: 241172220
Bug: 241172337
Bug: 241172391
Bug: 241172490
Change-Id: Id3453e85aee3ee8e0255d3e53f37ca4488d7c9f9
2022-08-15 13:47:56 +10:00
Adam Shih
286d40c81b Update SELinux error
Test: checkSensors
Bug: 241172337
Test: scanBugreport
Bug: 241172490
Test: testAtomicWrite
Bug: 241172490
Test: testConfigMaxSectorsKB
Bug: 241172490
Test: testDirectWriteNormalReadInEncryptedDir
Bug: 241172391
Test: testInvalidWrite
Bug: 241172490
Test: testLoopMaxPartDefined
Bug: 241172391
Test: testNormalWriteDirectReadInEncryptedDir
Bug: 241172490
Test: testPinFile
Bug: 241172490
Test: testSmallFileInEncryptedDir
Bug: 241172490
Change-Id: Iee5a8e6fff46b62ec0a448b05db64a788b7d08fb
2022-08-03 01:09:57 +00:00
Adam Shih
479986a020 Update SELinux error
Test: checkSensors
Bug: 240632824
Test: checkLockScreen
Bug: 240632824
Test: scanBugreport
Bug: 240632824
Change-Id: I4fee87636dc65765e4ab3e10e0b7080d7b4d44b2
2022-07-29 10:18:10 +08:00
Kyle Lin
3014f97824 Merge "Remove dontaudit since read early_wakeup completed" 2022-07-28 02:51:37 +00:00
Stephane Lee
faec9385c4 Bug fixed in ag/19153533
Bug: 238143381
Test: N/A
Change-Id: If527ea681abaa221e55533a3dab1371ecac7a3b2
2022-07-22 16:55:24 -07:00
Jimmy Shiu
55d41f1a3e Remove dontaudit since read early_wakeup completed
The display file node, early_wakeup, just for trigger the worker for
display and it doesn't have meaningful read function. But PowerHAL read
all nodes and try to dump their valuesi while triggering bugreport. As
the read operation has been completed, so we can remove the clause.

07-02 00:53:56.888   522   522 W android.hardwar: type=1400 audit(0.0:8): avc: denied { dac_read_search } for capability=2 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0
07-02 00:53:56.888   522   522 W android.hardwar: type=1400 audit(0.0:9): avc: denied { dac_override } for capability=1 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0

Bug: 221384860
Bug: 192617242
Bug: 171760921
Test: adb shell dumpsys android.hardware.power.IPower/default
Change-Id: If0018499cc19f79819ef69794d7672d5a53de74e
2022-07-18 11:08:58 +08:00
Minchan Kim
86ef69850b Remove vendor_init.te from tracking_denials
Since last error fixed, remove the vendor_init.te from tracking_denials.

Bug: 190337297
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I5178c864a70748c1dddf8c08baa8d653cd0225d9
2022-07-15 05:10:55 +00:00
Adam Shih
32d987cd24 Update SELinux error
Bug: 234547283
Change-Id: I50bd66a22755eefe7aa24ec1042e3b6cb627ad3d
2022-07-15 00:30:47 +00:00
Adam Shih
74d2d8963f Update error on ROM 8820442
Bug: 238825802
Test: testSysfsHealth
Change-Id: I607f78de19b18b258309f89669ded393dd74a2a7
2022-07-13 11:01:28 +08:00
Adam Shih
c6186c2960 Update SELinux error
Test: checkSensors
Bug: 238571420
Test: checkLockScreen
Bug: 238570971
Test: scanBugreport
Bug: 238571324
Change-Id: Ia6f2db6374d7ebe1a9c3f5b0bd8d152ed9d4a9a0
2022-07-11 10:24:12 +08:00
Adam Shih
347e482d19 Update SELinux error
Test: checkLockScreen
Bug: 238263438
Bug: 238263568
Change-Id: I694924ceb031abb749e4b92a715d3b7dc87088be
2022-07-07 11:29:44 +08:00
Adam Shih
bc85d46045 ignore shell access on wlc
Bug: 238038592
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-07-06 14:44:41 +08:00
Adam Shih
a8aeb4a6c9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238143262
Bug: 238143381
Change-Id: Ibe3ce917418d71b61aa6d085041a51dda5998c74
2022-07-06 02:58:51 +00:00
Adam Shih
7835523aea Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238038592
Change-Id: Id248ba82c49fa09be28f7a0219eb42b0ecc9e358
2022-07-05 11:17:25 +08:00
Adam Shih
d472e161ae mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5 am: c68fe289e3 am: 5bf5ffc8d3 am: d8d5fd4374
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I75a4589877c5803c6facbb189bd36662c66d2274
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 06:29:36 +00:00
Adam Shih
5bf5ffc8d3 mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5 am: c68fe289e3
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I2afec41baa838d8db9ab23d9d01def68249d99c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 05:44:54 +00:00
Adam Shih
c68fe289e3 mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I15a18379ff4969dcb043e2fae94cf6c9f13ac834
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 05:18:34 +00:00
Adam Shih
5889704eff mute update_engine probing mnt_vendor_file
Bug: 187016910
Test: boot to home
Change-Id: I5f7141f817b543a1499ef5826177f3ac4945e857
2022-06-14 02:58:58 +00:00
Krzysztof Kosiński
bdd4ecc51c gs101: Add dontaudit statements to camera HAL policy. am: fbcf66a04a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18817845

Change-Id: I6138022efbcdc8ce149123399d3a8277e69c64b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 21:04:38 +00:00