Commit graph

1434 commits

Author SHA1 Message Date
Treehugger Robot
4c9a910a60 Merge "Add security context for com.google.usf.non_wake_up/wakeup." am: d6ff29d1ca am: a4d246abac am: 6481874c77
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183507

Change-Id: Ica06811653100886c99ea2d01ab09edfdd83585f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 07:46:49 +00:00
Treehugger Robot
d6ff29d1ca Merge "Add security context for com.google.usf.non_wake_up/wakeup." 2022-08-22 06:38:52 +00:00
Treehugger Robot
b551e0475f Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." am: 3cb1ea79c9 am: c56dc643a4 am: b2e001581b
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183506

Change-Id: I46122f6a44cb7bc4ea9fb1f63c4e57e8f92709f3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 05:12:24 +00:00
Treehugger Robot
3cb1ea79c9 Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." 2022-08-22 04:10:13 +00:00
Wiwit Rifa'i
443da0523a Add SE policies for HWC logs
Bug: 230361290
Test: adb bugreport
Test: adb shell vndservice call Exynos.HWCService 11 i32 0 i32 308 i32 1
Change-Id: I20ec7ee1856a45d271e0e6ebfd7eb74525b96f77
2022-08-16 13:22:33 +08:00
matthuang
62ba653669 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I8600283d9ff2ebcb45df95e5259484a60921fb1a
Merged-In: I8600283d9ff2ebcb45df95e5259484a60921fb1a
2022-08-15 18:52:58 +08:00
matthuang
7e89415aaf Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: If9add3528bde47a618bd884ce28121b6fa32754c
Merged-In: If9add3528bde47a618bd884ce28121b6fa32754c
2022-08-15 18:46:52 +08:00
yixuanjiang
0bbfb98cac aoc: add audio property for pixellogger update control
Bug: 241059471
Test: local verify
Signed-off-by: yixuanjiang <yixuanjiang@google.com>
Change-Id: I13df2ea88b884756d3a872da545e877ed6b1e033
2022-08-08 03:48:21 +00:00
TreeHugger Robot
a3fc2a745c Merge "HwInfo: Move hardware info sepolicy to pixel common" 2022-08-03 02:57:30 +00:00
Bruce Po
60920d10a6 Allow aocd to access acd-offload nodes am: 1673f21545 am: 62c16fd040
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19472656

Change-Id: Ic19b92da27365a03cc5f99523fd84a08fa0aa473
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-02 19:33:02 +00:00
Bruce Po
62c16fd040 Allow aocd to access acd-offload nodes am: 1673f21545
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19472656

Change-Id: I524c210830ba139cb36ee5c8a664d87cc5c497ec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-02 19:05:57 +00:00
Denny cy Lee
ea1580002f HwInfo: Move hardware info sepolicy to pixel common
Bug: 215271971
Test: no sepolicy for hardware info

Signed-off-by: Denny cy Lee <dennycylee@google.com>
Change-Id: Ia7bfd171fe724848e9a6f0c1adab59402d2788a9
2022-08-02 07:43:56 +00:00
Bruce Po
1673f21545 Allow aocd to access acd-offload nodes
For 3-ch hotword feature, aocd daemon will access two new file nodes
(b/235648212), which will be used for transmitting audio to/from AOC.

BUG: 240744178
Change-Id: Ie0a9403d0dca06befdb807067adb9babc4f28bfc
2022-08-02 06:29:42 +00:00
Lei Ju
1c69e17927 Merge "Allow chre to use WakeLock on whitechapel." 2022-08-01 18:49:57 +00:00
Steven Moreland
b577060b2d Restore HAL type names.
Sed'd. TH not configured on AOSP. This is the change that is applied already internally.

Change-Id: I03be37c9e50280d6fa2cfdd69dca83c0535b2e35
2022-08-01 18:41:26 +00:00
Steven Moreland
c6545d33ff Merge "Remove vendor_service." 2022-08-01 17:07:40 +00:00
Steven Moreland
b20e917ebf Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
Merged-In: I4766227e2261d0d57be090933926ff3b439694f6
(cherry picked from commit 81ccf8d719)
2022-07-29 18:34:05 +00:00
Roger Liao
75ba5fc5cc Fix build break if BOARD_WITHOUT_RADIO am: 5ea60d6348 am: 68ddcb629a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19447103

Change-Id: Idbe29367df44ffa49c6de9125f07f5837e0a2cae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-29 07:22:32 +00:00
Roger Liao
68ddcb629a Fix build break if BOARD_WITHOUT_RADIO am: 5ea60d6348
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19447103

Change-Id: I5659941108a8504cd4ea13e22f075a8cdcf60749
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-29 06:57:24 +00:00
Roger Liao
5ea60d6348 Fix build break if BOARD_WITHOUT_RADIO
Fix ERROR 'unknown type radio_vendor_data_file'

Bug: 235907512
Change-Id: I55e88c9364b42db262c057a2aa85816944c1c761
2022-07-28 17:59:28 +08:00
Steven Moreland
5e9bc45aee Merge "Remove vendor_service." into tm-dev-plus-aosp am: be1bd1eebb am: 6a8d151ba8 am: 829119e383
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19441276

Change-Id: Ideecc231104d31b1cd69714fb0ddb71992645dad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 02:26:31 +00:00
Steven Moreland
829119e383 Merge "Remove vendor_service." into tm-dev-plus-aosp am: be1bd1eebb am: 6a8d151ba8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19441276

Change-Id: Ibef456a15a20694227afe25289387c1caa2bcd0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 01:57:45 +00:00
Steven Moreland
6a8d151ba8 Merge "Remove vendor_service." into tm-dev-plus-aosp am: be1bd1eebb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19441276

Change-Id: Ia9526d71defecd28580dfd6f4619a88dc87ea58f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 01:08:22 +00:00
Steven Moreland
be1bd1eebb Merge "Remove vendor_service." into tm-dev-plus-aosp 2022-07-28 00:46:47 +00:00
Tri Vo
5d0e11a0aa storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a am: a68844f3e1 am: e4f4a40a0c am: 121cb7702d am: cd428bcab4
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: Ic063de9feb084f0a5985093e27142b098612a34b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 21:53:47 +00:00
Tri Vo
cd428bcab4 storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a am: a68844f3e1 am: e4f4a40a0c am: 121cb7702d
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: I7bba70c4cc7cbd1d6298310b60659c6272b5ff3a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 21:27:22 +00:00
Tri Vo
121cb7702d storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a am: a68844f3e1 am: e4f4a40a0c
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: Id91151413c15852b94afcda312c7890fb78c096c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 20:33:41 +00:00
Tri Vo
a68844f3e1 storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: I611a9f1ecd6157c3d1f65c250c698a9ee00a0915
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 19:43:32 +00:00
Steven Moreland
81ccf8d719 Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
2022-07-27 16:50:03 +00:00
Lei Ju
d1ddd0917e Allow chre to use WakeLock on whitechapel.
Test: Manual test to confirm wakelock is acquired.
Bug: 202447392
Change-Id: I40b83fc22fea79613c060d03beb60857b1b6e0de
2022-07-26 20:06:05 -07:00
Steven Moreland
2808c8b289 Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Merged-In: I4766227e2261d0d57be090933926ff3b439694f6
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
2022-07-27 00:28:49 +00:00
matthuang
bb144cecd2 Add security context for com.google.usf.non_wake_up/wakeup. am: c96220c282 am: c061348b1c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19291365

Change-Id: I71e0c93734dc4c49ab13f24bb18bbf6f02afa8a4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 02:12:26 +00:00
matthuang
c061348b1c Add security context for com.google.usf.non_wake_up/wakeup. am: c96220c282
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19291365

Change-Id: Idd09818dc82348398e780db3ee81948d75ffda4b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 01:47:05 +00:00
matthuang
c96220c282 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I8600283d9ff2ebcb45df95e5259484a60921fb1a
2022-07-18 15:12:45 +08:00
timmyli
0f73892408 Change SElinux so Aswang can be accessed
Need to add aswang here so that it can be accessed.

Bug: 234259081
Test: CTS
Change-Id: I3e701df76af8e803017bdfd04ce67093bf21a658
2022-07-16 06:26:56 +00:00
Tri Vo
78011e9f3a storageproxyd: Remove setuid/setgid SELinux permissions
Bug: 205904330
Test: boot
Change-Id: Iefecc29752781151679e9f798330a36d14447df9
2022-07-15 11:07:47 -07:00
SalmaxChang
2455329536 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-44" ino=341 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 235963885
Change-Id: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
Merged-In: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
2022-07-08 03:24:01 +00:00
Adam Shih
bc85d46045 ignore shell access on wlc
Bug: 238038592
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-07-06 14:44:41 +08:00
TreeHugger Robot
ae60f4bc6d Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev am: 59d6e09682 am: df9d1731af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18871451

Change-Id: I354e568b012ef36d65a843185c2e4d1b7509c522
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 03:12:56 +00:00
TreeHugger Robot
df9d1731af Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev am: 59d6e09682
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18871451

Change-Id: I931993bfd0b94da00fed9e4ff6c25f95fdb9509a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:20 +00:00
TreeHugger Robot
59d6e09682 Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev 2022-07-01 02:15:21 +00:00
Xin Li
351260db12 Merge tm-dev-plus-aosp-without-vendor@8763363
Bug: 236760014
Merged-In: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
Change-Id: I0f66cef4179df45ee56af588df1fe1b82b0f642a
2022-06-27 23:37:34 +00:00
sashwinbalaji
7600ddd96b thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e am: cbbe4561a3 am: fcf9cbcb83
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I7468f221840e910a05136009d0639b5f96eef636
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 10:11:47 +00:00
sashwinbalaji
fcf9cbcb83 thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e am: cbbe4561a3
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I97cdd61e0634bce617d72d4543d856c709b3bddf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:54:20 +00:00
sashwinbalaji
cbbe4561a3 thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I4e27c835adfe73ef473b2afd2b303a36307e6ee9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:32:01 +00:00
sashwinbalaji
7bb947b88e thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I71bd9b49f2dc76e1e50f0b35bd404f7c8660d5d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:07:19 +00:00
sashwinbalaji
1a4cd82bc8 thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg files
Change-Id: Ia2a274ec3424bfeec25ae24e762f8ad41cb7ae86
2022-06-24 13:54:24 +08:00
SalmaxChang
a9157994c3 modem_svc: Fix avc error
avc: denied { write } for comm="modem_svc_sit" name="modem_stat" dev="dm-42" ino=331 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 234844823
Change-Id: I51db41d73be317cc7fc84981ac5f04e254a360d0
Merged-In: I51db41d73be317cc7fc84981ac5f04e254a360d0
2022-06-22 04:21:37 +00:00
SalmaxChang
0cef5e66fe hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d am: ba3c6036fc am: 8bbd5d3430 am: d3dba796f9
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: Ia6b24e15d0118326f253d0327d4a8e0cf874d879
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 03:26:10 +00:00
SalmaxChang
d3dba796f9 hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d am: ba3c6036fc am: 8bbd5d3430
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: Iecec85303b3b51cbd69f1ea8ca28448f0b0d80d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 03:07:39 +00:00