Commit graph

1434 commits

Author SHA1 Message Date
millerliang
1e748ab270 Fix AAudio avc denied
E SELinux : avc:  denied  { find } for pid=765 uid=1041 name=audio
scontext=u:r:audioserver:s0 tcontext=u:object_r:audio_service:s0
tclass=service_manager permissive=0

Bug: 191103346
Test: build and run CtsNativeMediaAAudioTestCases
Change-Id: I8e9a41360a382ba5f461818b9f8d6658dd53c62a
2021-07-03 05:40:22 +00:00
TreeHugger Robot
6e8e0a52a0 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev am: 846cba7286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15164003

Change-Id: I69d7c6077426c73f871a3c0710f57d1c043d18c5
2021-07-01 08:25:49 +00:00
TreeHugger Robot
846cba7286 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev 2021-07-01 08:07:05 +00:00
Michael Ayoubi
56beb62f69 Fix hal_uwb_default dumpstate SELinux errors
Fixes: b/192026913
Test: Run dumpstate and confirm no avc denials

Signed-off-by: Michael Ayoubi <mayoubi@google.com>
Change-Id: I3d818fb066a834663dc63b8757bd16c08a1a0e9e
2021-07-01 06:55:42 +00:00
Krzysztof Kosiński
fdfbdf2bd6 Allow Power Stats HAL to access EdgeTPU sysfs files. am: 6d6a7c96ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15162531

Change-Id: I19b0b15c286cab140ed77b7eb2c3a741641da6de
2021-06-30 23:58:01 +00:00
Krzysztof Kosiński
6d6a7c96ab Allow Power Stats HAL to access EdgeTPU sysfs files.
Should fix intermittent failures of SELinuxUncheckedDenialBootTest.

Bug: 192485697
Test: build, checked for denials in logcat
Change-Id: I3b9cafd99f9ff343e5ab5c67f5f268e5eb4382d6
2021-06-30 14:02:27 -07:00
Michael Ayoubi
0ed8e6763c Merge "allow recovery and fastboot to access secure elment" into sc-dev am: 075ba05575
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15152134

Change-Id: If808d197690820295f130d394c91a824a25ee834
2021-06-30 17:57:47 +00:00
Michael Ayoubi
075ba05575 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-30 17:39:40 +00:00
Jeffrey Carlyle
14fcd5ffaf allow recovery and fastboot to access secure elment
This is to enable clearing of secure element during a master reset.

Bug: 182508814
Test: master reset on device with keys; verified no keys after reset
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I9bb569e09f8cd6f5640757bd0d10a14ef32946ff
2021-06-30 15:19:22 +09:00
Gazi Yamin Iqbal
737622596d Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev am: 2e1cafdfd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15100489

Change-Id: I537e8c41624e8d8d85590d550691f6cda7266853
2021-06-30 05:58:42 +00:00
Gazi Yamin Iqbal
2e1cafdfd8 Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev 2021-06-30 05:41:19 +00:00
George Lee
4aa936d63b pixelstats: add bcl directory permission
Bug: 186806028
Test: Local test
$>cmd stats print-logs
$>logcat | grep <atom id>

Signed-off-by: George Lee <geolee@google.com>
Change-Id: I7288a9ab44e2387d37c5442297cf80f5b5428c8f
2021-06-29 16:08:38 -07:00
Kevin Han
fcd18a6e4d Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev am: 1d54c8dd21
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145159

Change-Id: Ie5ffd99597f2b00758126fabf8032c94a8208a16
2021-06-29 19:51:41 +00:00
Kevin Han
1d54c8dd21 Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev 2021-06-29 19:33:01 +00:00
Kevin Han
fd47b11162 Revert "allow recovery and fastboot to access secure elment"
Revert "add gs101-specific recovery library"

Revert "recovery: enable support for device-specific WipeSe impl..."

Revert "clear secure element of Digital Car Keys during factory ..."

Revert submission 14983788-clear_keys

Reason for revert: b/192373955
Reverted Changes:
Ia8fc29e6c:add gs101-specific recovery library
Icc1eabfd4:clear secure element of Digital Car Keys during fa...
I943d97b26:recovery: enable support for device-specific WipeS...
I15c7fbd7f:allow recovery and fastboot to access secure elmen...

Change-Id: Ic576b40641171298ad840bedbd4a9f7b67052d95
2021-06-29 19:19:24 +00:00
TreeHugger Robot
7432c08ac9 Merge "allow recovery and fastboot to access secure elment" into sc-dev am: be3d2bf325
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14681841

Change-Id: I642763bd029fdaa6fe11b440af187a37feeb7966
2021-06-29 18:03:40 +00:00
TreeHugger Robot
be3d2bf325 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-29 17:50:35 +00:00
TreeHugger Robot
3de1991b67 Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev am: 432ed9b527
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15135682

Change-Id: I84c80310cbd1897fe7ef1bac5d9b6c8bc024412e
2021-06-29 17:24:18 +00:00
TreeHugger Robot
432ed9b527 Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev 2021-06-29 17:04:07 +00:00
David Anderson
2354e3a924 Fix denial when flashing vendor_boot in fastbootd.
This mirrors the same sepolicy line in previous Pixel devices.

Bug: 189493387
Test: fastboot flash vendor_boot on r4
Change-Id: Ie15c8e6e5c01b249e1e5e244666c461253279f0b
2021-06-28 21:06:05 -07:00
Neo Yu
0dd75c76a6 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev am: 9c27ce91c8 am: 145c181a70 am: 6b8b748b87
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126897

Change-Id: Ie1ac5d1ec702b19fb97167767100d85b0f35aa5f
2021-06-29 03:51:17 +00:00
Neo Yu
145c181a70 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev am: 9c27ce91c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126897

Change-Id: Icefd3f8fb6cd01b2596e1ec41720bdbdd39b8a5c
2021-06-29 03:22:07 +00:00
Neo Yu
9c27ce91c8 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev 2021-06-29 03:05:02 +00:00
TreeHugger Robot
ba8db505db Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev am: 22f27cb215 am: 03488b260f am: 90d03e4684
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456728

Change-Id: I7c8b3c67931a73550040b20e2e2e14e59343649d
2021-06-29 02:00:41 +00:00
TreeHugger Robot
03488b260f Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev am: 22f27cb215
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456728

Change-Id: If3f1fa43325948305419f2b1e5995855bde42a4c
2021-06-29 01:31:17 +00:00
neoyu
93944a8b1c Fix avc denied for getprop "vendor.radio.call_end_reason"
06-10 11:13:02.867 10224  2377  2377 W libc    : Access denied finding property "vendor.radio.call_end_reason"

Bug: 191204793
Test: error is gone with this fix
Change-Id: I50c1d21ba4e2343aa2cee0c533b8c3dbe535e4b5
2021-06-29 01:18:12 +00:00
TreeHugger Robot
22f27cb215 Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev 2021-06-29 01:16:35 +00:00
David Lin
4b6bc8cb32 ssr_detector_app: Add additional vendor dir and crgroup allow for debug
Bug: 192126013

Signed-off-by: David Lin <dtwlin@google.com>
Change-Id: Idadf81cf92099804f300f87fb1bedf9bed7decbd
2021-06-28 21:52:51 +00:00
TreeHugger Robot
21bc76645d Merge "Hardwareinfo: battery info porting" into sc-dev am: a63fbd68d4 am: 8d6a3d96a2 am: f82eb61a93
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608134

Change-Id: I6465a0df92f93a1ee0533ff95eac5fc87fd45302
2021-06-28 16:56:31 +00:00
TreeHugger Robot
f82eb61a93 Merge "Hardwareinfo: battery info porting" into sc-dev am: a63fbd68d4 am: 8d6a3d96a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608134

Change-Id: Ic169a8455fef3e8d9b9b9bf21e08e9f8660ceb07
2021-06-28 16:47:13 +00:00
TreeHugger Robot
4a6403f455 Merge "Hardwareinfo: battery info porting" into sc-dev am: a63fbd68d4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608134

Change-Id: I90ebe00451a871473545576b52fdcbbfff008793
2021-06-28 16:34:14 +00:00
TreeHugger Robot
a63fbd68d4 Merge "Hardwareinfo: battery info porting" into sc-dev 2021-06-28 16:20:12 +00:00
Gazi Yamin Iqbal
4ea317bb6a gs101-sepolicy: allow rlsservice to read display status files
major changes:
        1. This change is to allow rlsservice to read the status of
        display status file. Similar method was employed in previous
        pixels.
Bug: 191122203
Test: p21 camera test checklist

Change-Id: I09483881294fd6dde46d4d0b7283311a2d20c404
2021-06-28 22:15:08 +08:00
TreeHugger Robot
8a3ed5c061 Merge "gs101-sepolicy: add oemrilservice_app.te" into sc-dev am: 407d0cf58d am: 3863954bf4 am: 8d82d42f94
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072301

Change-Id: I09eccef75ecab74c01b78c3b43cea8f0daa562ca
2021-06-27 02:24:06 +00:00
TreeHugger Robot
3863954bf4 Merge "gs101-sepolicy: add oemrilservice_app.te" into sc-dev am: 407d0cf58d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072301

Change-Id: Icf8b698caf10af881a2a90a745f3e77d80666e94
2021-06-27 01:57:50 +00:00
TreeHugger Robot
407d0cf58d Merge "gs101-sepolicy: add oemrilservice_app.te" into sc-dev 2021-06-27 01:47:21 +00:00
Jeffrey Carlyle
9ac870aa22 allow recovery and fastboot to access secure elment
This is to enable clearing of secure element during a master reset.

Bug: 182508814
Test: master reset on device with keys; verified no keys after reset
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I15c7fbd7f2c4fb34dcad0ae4f5cee3238f526fa5
2021-06-25 17:54:29 -07:00
Ilya Matyukhin
00b7e7d8b9 Merge "raviole: transition SystemUI to use HWC for LHBM" into sc-dev am: f9828a9944 am: 09792c098f am: 4c3bbb63d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15085906

Change-Id: I9989b8fcec6b6c3d064e630a68121975a917ee56
2021-06-25 02:21:56 +00:00
Adam Shih
d8f6d7acef Merge "modularize dmd" into sc-dev am: 99bfde4f38 am: c418ff2db2 am: 8463b00d4b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072291

Change-Id: I481a22c4d9712fbb2b6446f216732e225355de7f
2021-06-25 02:21:44 +00:00
Ilya Matyukhin
09792c098f Merge "raviole: transition SystemUI to use HWC for LHBM" into sc-dev am: f9828a9944
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15085906

Change-Id: If83496c47ac3e6450756a5dfc2342884a17e378d
2021-06-25 01:27:58 +00:00
Adam Shih
c418ff2db2 Merge "modularize dmd" into sc-dev am: 99bfde4f38
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072291

Change-Id: Idcd79ae7e96c304194279145cff7af20877cc30a
2021-06-25 01:27:41 +00:00
Ilya Matyukhin
f9828a9944 Merge "raviole: transition SystemUI to use HWC for LHBM" into sc-dev 2021-06-25 01:12:52 +00:00
Adam Shih
99bfde4f38 Merge "modularize dmd" into sc-dev 2021-06-25 01:12:50 +00:00
TreeHugger Robot
3d20aa5c46 Merge "vendor_init/dumpstate: Grant to access logger prop" into sc-dev am: 655f5cfd8f am: 1edfd8cfe6 am: 738837c130
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072290

Change-Id: I4cdf3d1543586a4488228461b6195c2e6796c26e
2021-06-24 10:57:24 +00:00
TreeHugger Robot
1edfd8cfe6 Merge "vendor_init/dumpstate: Grant to access logger prop" into sc-dev am: 655f5cfd8f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072290

Change-Id: Icea3ba9901b7a05239a34a64852e0196c31003b8
2021-06-24 10:20:51 +00:00
TreeHugger Robot
655f5cfd8f Merge "vendor_init/dumpstate: Grant to access logger prop" into sc-dev 2021-06-24 10:02:11 +00:00
Adam Shih
39c6f1987c Merge "modularize pktrouter" into sc-dev am: 9b0b96b907 am: 1f58e76864 am: 85bdce6ef7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15048206

Change-Id: I20ec2da8e14c933dd69ca1d0dafe592b34b3c3d4
2021-06-24 08:12:05 +00:00
Adam Shih
1f58e76864 Merge "modularize pktrouter" into sc-dev am: 9b0b96b907
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15048206

Change-Id: Ibd259d8b20c59e5e950125fbbae3bb14853d4348
2021-06-24 07:41:01 +00:00
Adam Shih
9b0b96b907 Merge "modularize pktrouter" into sc-dev 2021-06-24 07:24:45 +00:00
Ilya Matyukhin
2460cdcc9f raviole: transition SystemUI to use HWC for LHBM
This change removes direct access to the LHBM sysfs node from SystemUI,
but allows SystemUI to make binder calls to the hardware composer (HWC),
which can be used to enable or disable LHBM.

Bug: 191132545
Bug: 190563896
Bug: 184768835
Test: no avc denials
Change-Id: I5417377ff096e869ad772e4fd2fb23f8c1fd4f1e
2021-06-23 23:38:27 -07:00