Commit graph

1434 commits

Author SHA1 Message Date
Taylor Nelms
c2769f1ede Modify permissions to allow dumpstate process to access decon_counters node am: ae39e117c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21041858

Change-Id: I469375e8d9bf2fed575bbb9f972f4eeaa45fbb15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 13:47:31 +00:00
Nicolas Geoffray
514eb95f8e Allow ssr_detector_app directory creation in system_app_data_file.
Bug: 260557058
Test: m
Change-Id: Iad7bb0609d7ca3ae89d6583ba3638e36300538a1
2023-02-03 13:06:50 +00:00
Ray Chi
9828cc747a [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-02 15:22:33 +08:00
Ken Yang
fcb9c033a1 WLC: Add required sysfs_wlc sepolicies
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.

Bug: 267171670
Change-Id: Ic4dca7a34e8ed9b096a650b1df4bb58290425117
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-31 15:02:51 +00:00
Taylor Nelms
ae39e117c1 Modify permissions to allow dumpstate process to access decon_counters node
Bug: 240346564
Test: Build for Oriole device with "user" build,
check bugreport for decon_counters content
Merged-In: I71883632857e76cfead39b16560b3695e13a6746
Change-Id: I010a9e8809192a5a1ee5842d5ac973d874836cea
Signed-off-by: Taylor Nelms <tknelms@google.com>
2023-01-19 14:14:25 +00:00
Victor Barr
5eea830c6e Move Support for DBA HAL in common edgetpu packages
Previously supported in some cases. Now extend it to all common cases.

Bug: 263394888
Test: Built and ran DBA HAL on Android Device
Change-Id: I70db1fae6b9f5787c635bb2fcbabc7ee0e064a9f
2023-01-17 18:42:26 +00:00
Ken Yang
fc2efe09bd Merge "WLC: Cleanup the sysfs_wlc policies" 2023-01-13 14:41:30 +00:00
Kyle Zhang
bfbf488408 Merge "Add hal_drm_widevine for Widevine exec sepolicy" 2023-01-11 05:37:46 +00:00
Ken Yang
a49c3a5479 WLC: Cleanup the sysfs_wlc policies
The sepolicy must be self-contained without including wirelss_charger to
avoid build break in AOSP

Bug: 263830018
Change-Id: I4eee380ae61f83c5563ee8842a94fd1fb9e520ef
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-10 16:02:31 +00:00
Kyle Zhang
902db3961f Add hal_drm_widevine for Widevine exec sepolicy
Bug: 243699259
Test: atp v2/widevine-eng/drm_compliance
Change-Id: Ifede19e690cb7b7333016df08fb146a0ec8f7409
2023-01-06 03:14:20 +00:00
Chungkai Mei
f5ee8054e0 sepolicy: fix avc denial
fix avc denial when applying aosp/2333702

Bug: 261678056
Test: boot without avc denial
Change-Id: I4674a5cb13f2f06f011c380699353b1a561ad290
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-01-05 09:40:42 +00:00
Ken Yang
8c2188f24e Merge "WLC: Add gs101 specific sepolicy for wireless_charger" 2022-12-21 08:36:14 +00:00
Taylor Nelms
66bf88de5d Merge "Modify permissions to allow dumpstate process to access decon_counters node" 2022-12-21 01:41:40 +00:00
Ken Yang
33f94a5428 WLC: Add gs101 specific sepolicy for wireless_charger
Bug: 237600973
Change-Id: If25a921ba9f0261c7f71cb88425526f307df9064
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-21 00:49:26 +00:00
Devin Moore
d1ba957ec2 Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f am: ae8eb694fa
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I16211b9a52338bbf7569508877305dbc66d5228b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 21:46:17 +00:00
Devin Moore
ae8eb694fa Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I74400a040ba88d35a9eda207eb6eabf712627799
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 20:57:13 +00:00
Devin Moore
aede443b86 Allow pixelstats hal to talk to the new AIDL sensorservice
This is being used in libsensorndkbridge now, so permissions are
required.

Test: m
Bug: 205764765
Change-Id: I65945c8b259538d274da23d8ecc6cf4d2362dcbd
2022-12-19 23:42:23 +00:00
TreeHugger Robot
5aa010e054 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev am: ca047e8607 am: ad5f8a13d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20502509

Change-Id: I79eaaa294adfa16f32362e2c5134f783c8aaa352
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-19 14:23:42 +00:00
TreeHugger Robot
ad5f8a13d3 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev am: ca047e8607
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20502509

Change-Id: Iadf35d359d83215d410f1aa7f1e135d56af9acb0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-19 13:43:37 +00:00
TreeHugger Robot
ca047e8607 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev 2022-12-19 12:53:32 +00:00
Taylor Nelms
807f7b2efa Modify permissions to allow dumpstate process to access decon_counters node
Bug: 240346564
Test: Build for Oriole device with "user" build, check bugreport for decon_counters content
Change-Id: I71883632857e76cfead39b16560b3695e13a6746
Signed-off-by: Taylor Nelms <tknelms@google.com>
2022-12-16 16:51:12 +00:00
Adam Shih
1d6ed7613e ignore shell access on wlc am: 1d7352fb4d am: c4c7dd1c1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20677863

Change-Id: Ia2fb569bf4a8cae8a8cc51231af9dd055b3e3b1c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 07:55:37 +00:00
Adam Shih
c4c7dd1c1a ignore shell access on wlc am: 1d7352fb4d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20677863

Change-Id: Ie42a4a9910f006c85ab945ec22486fdbaeb12e6f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 06:50:26 +00:00
Adam Shih
a1c4ddc9d1 ignore shell access on wlc am: 85bd1b8441 am: 6aa1118205
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2342468

Change-Id: I3161158edbda30465251134c06ae025184cd95c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 04:19:18 +00:00
Adam Shih
85bd1b8441 ignore shell access on wlc
Bug: 261804136
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-12-11 21:22:10 +08:00
Nicolas Geoffray
677dcd1685 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755 am: 5db7a3cc58 am: ed07258d24
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: I1a44378cddf8b63c5a67e34786cfc76c75492f73
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 21:07:53 +00:00
Nicolas Geoffray
ed07258d24 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755 am: 5db7a3cc58
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: Ic617201bc7a2ad7cbbda299f8867a7caff023aed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 20:18:06 +00:00
Nicolas Geoffray
5db7a3cc58 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: I123395fa5a397e17aeaf7cec155cf00be7af8682
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 19:31:29 +00:00
Nicolas Geoffray
356b4a4755 Also put .ShannonImsService in the vendor_ims_app domain.
For consistency when running com.shannon.imsservice code.

Test: m
Bug: 260557058
Change-Id: I5242479d32eb9362326544516c06e6a52cd30a6e
2022-12-08 14:39:19 +00:00
Adam Shih
1d7352fb4d ignore shell access on wlc
Bug: 261804136
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-12-08 17:59:16 +08:00
Adam Shih
58c0e3bb7c Merge "remove sysfs_touch setting" 2022-12-06 02:59:39 +00:00
Nicolas Geoffray
2c4c8f80d3 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664 am: a18011cd14 am: 74042321e2
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: Ic3e7cd5192a3b7bbe37aab6c53e51d011b5c1228
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 18:12:32 +00:00
Nicolas Geoffray
74042321e2 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664 am: a18011cd14
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: Ie3562efa20cadd63f2bfbaa5949f28c78d49ded5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:31:48 +00:00
Nicolas Geoffray
a18011cd14 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: I9e14e98f8c66f18e7256dffeaa7eebe5a4f54567
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:01:25 +00:00
Nicolas Geoffray
594052a664 Allow ssr_detector_app to create files of type system_app_data_file.
Bug: 260557058
Test: m
Change-Id: I8545deddd64d7eec61c5065f364a87b8726b1472
2022-12-05 13:56:52 +00:00
Adam Shih
5a7fd4f558 remove sysfs_touch setting
spi6.0 was other devices' touch setting
Bug: 256521567
Test: build pass
Change-Id: I96120b4e4930b16dcf5cbc9eba68c6a150ff0306
2022-12-05 03:14:06 +00:00
Ziyi Cui
a484ab0c49 Merge changes from topic "temp_residency_metrics" into tm-qpr-dev am: 7b5ec97f7d am: b3b59f8f88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20590705

Change-Id: I5af930d88179425306018d542b2aab4bf7d4b36c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 07:28:32 +00:00
Ziyi Cui
8e5cf6ccf1 [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics am: 1a39bb777e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20591018

Change-Id: I833905b09a613e3ae13cc06e943b39bc202b1d98
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 07:03:10 +00:00
Ziyi Cui
b3b59f8f88 Merge changes from topic "temp_residency_metrics" into tm-qpr-dev am: 7b5ec97f7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20590705

Change-Id: Ief5cae20292865a5a9e44089f406e8157dd7bb87
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 06:59:43 +00:00
Ziyi Cui
bb69de3087 [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics am: 86d7d36fcf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20527590

Change-Id: I8a812f509a63c4e5a7877195b78058b1a100eef1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 06:59:36 +00:00
Ziyi Cui
4df65fdfaf Merge "[ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics" into tm-qpr-dev 2022-12-01 06:31:37 +00:00
Ziyi Cui
7b5ec97f7d Merge changes from topic "temp_residency_metrics" into tm-qpr-dev
* changes:
  gs101-sepolicy:dumpstate: allow dumpstate access sysfs_vendor_metrics
  [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics
2022-12-01 06:27:28 +00:00
Treehugger Robot
217490dd40 Merge "Allow Trusty storageproxy property" am: 76089fcd5f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2310384

Change-Id: Icaeb14ac6313cd34257a704eadea4baa5d5f4a2d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-30 21:35:14 +00:00
Treehugger Robot
76089fcd5f Merge "Allow Trusty storageproxy property" 2022-11-30 21:06:13 +00:00
Stephen Crane
427fabf934 Allow Trusty storageproxy property am: 502c76f22b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20546072

Change-Id: I76fb4e52ef76a6d268043243f57f688eadcd4e00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-30 01:15:17 +00:00
Ziyi Cui
1a39bb777e [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics
enable pixelstats access to sysfs path, define sysfs_perfmetrics

Bug: 227809911
Bug: 232541623
Test: Verified the existence of atom and correctness of resume latency, irq stats
Change-Id: Ia0da1afb96b7f364d018d48d5cc8768c7b67f067
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:39:51 +00:00
Ziyi Cui
713d3ebf05 gs101-sepolicy:dumpstate: allow dumpstate access sysfs_vendor_metrics
Test: "adb bugreport" includes metrics capture.

Bug: 246799997
Test: "adb bugreport" includes metrics capture.
Change-Id: I48247f8378e52d15b264c37342dee5a938ba90a1
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:19:34 +00:00
Ziyi Cui
86d7d36fcf [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics
enable pixelstats access to sysfs path
Bug: 246799997
Test: Verified the existence of atom and correctness of atom stats
Change-Id: If329f2a65ed4cf347bd57150c637d38312f3dcb1
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:16:05 +00:00
Nicolas Geoffray
696c944e51 Allow ssr_detector_app writes to system_app_data_file. am: 1af71fc9ff am: 244284a31b
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2320310

Change-Id: Ia87808477911b933667159fa295aaa770bcb59e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-29 17:39:31 +00:00
Nicolas Geoffray
244284a31b Allow ssr_detector_app writes to system_app_data_file. am: 1af71fc9ff
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2320310

Change-Id: Ia7709417ea78e4b351eef8a67c7ab731dd050c83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-29 16:39:39 +00:00