Commit graph

3861 commits

Author SHA1 Message Date
KRIS CHEN
2f8f23232a Merge "Allow fingerprint hal to read sysfs_leds" into udc-dev 2023-03-24 02:06:37 +00:00
Kris Chen
d678ee3226 Allow fingerprint hal to read sysfs_leds
Fix the following avc denials:
avc: denied { search } for name="backlight" dev="sysfs" ino=79316
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=dir permissive=1

avc: denied { read } for name="state" dev="sysfs" ino=79365
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=file permissive=1

Bug: 271072126
Test: Authenticate fingerprint.
Change-Id: I67f5502bc7b4b1d6e14cf493f1bc6575980bcd0d
2023-03-21 12:19:07 +00:00
Jörg Wagner
cb6bad65e7 Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 74d31a1568)
Merged-In: I5c69a8bafe3a4c738c124facb1f437ec721cc3ea
Change-Id: I7e6734cb79b38898eb65a0194b37381a1367fc36
2023-03-21 10:31:51 +00:00
Adam Shih
4d9aa0b28f use devfreq dump from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: I0ea6767fd7640c2ee1be66f659f94c15cb4766cd
2023-03-21 12:41:23 +08:00
Enzo Liao
2110a1db8c SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel. am: 893d8ddff7 am: 2bc1af0adf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21937144

Change-Id: Ic08044ef00fef5fab0a52fe8375f3a7aa1a51924
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 05:14:54 +00:00
Enzo Liao
2bc1af0adf SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel. am: 893d8ddff7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21937144

Change-Id: Ibd95511a2d3a6e1cdebac8a20238c2ecfa876e27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 04:38:41 +00:00
Enzo Liao
893d8ddff7 SSRestarDetector: modify the SELinux policy to allow access files owned by system for Whitechapel.
It needs to access a file pushed by hosts of test suites (details: http://go/pd-client-for-lab#heading=h.wtp07hbqvwgx)

Bug: 234359369
Design: http://go/pd-client-for-lab
Test: manual (http://b/271555983#comment3)
Change-Id: I1c9544ca2ebe1857c439f00c4589f739aca8e157
2023-03-15 03:52:17 +00:00
Xin Li
0ff740c68d [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours am: af9a0596e4 -s ours am: f782184f62 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: Ie37f36262dee71729e90a28da38d1ebf8439713e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 00:06:22 +00:00
Xin Li
f782184f62 [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours am: af9a0596e4 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: I3eb89a6c5cdb182b2e340d61458fcbe804d156d0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 23:06:15 +00:00
Xin Li
af9a0596e4 [automerger skipped] Merge Android 13 QPR2 am: f703b89586 -s ours
am skip reason: Merged-In I09b67ca07d7f9573d77f64686fb818d4dc1753cc with SHA-1 85bd1b8441 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2486782

Change-Id: I8e0f4144027a594f78e29bde8407d130509ac6e5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 22:32:23 +00:00
Xin Li
f703b89586 Merge Android 13 QPR2
Bug: 273316506
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Change-Id: I4dfcfac354c52a6bf2828558dd44e1acca0b550a
2023-03-13 23:09:33 -07:00
Jasmine Cha
3b3aa9e921 Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Jasmine Cha
b263562360 audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: Ie1499be82e405c2ddf4cd1a62ee7ff2823befd8e
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:10:18 +08:00
Adam Shih
7d3f25d95b Move display dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: Id40661687bbd04d7eba4790dc5fe17ca5c79e47d
2023-03-07 13:01:05 +08:00
leochuang
4fe64170d3 Update SELinux error
Test: scanBugreport
Bug: 270247432
Change-Id: Ia5e76ee1c027ac2b1cbbbc6a20a20f3ea609a1b7
2023-02-22 10:30:02 +08:00
Ken Tsou
cd826e0365 [automerger skipped] [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.* am: 3194ab09f9 am: c02d353334 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21457164

Change-Id: I313ea2cb154644b1a61f40e08e0cd6f41868b5ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 15:53:31 +00:00
Ken Tsou
c02d353334 [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.* am: 3194ab09f9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21457164

Change-Id: Iad95f30732e0342f673d36999028722775706bb5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:52:58 +00:00
Ken Tsou
3194ab09f9 [DO NOT MERGE] hal_health_default: access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 10:28:27 +00:00
Ken Tsou
6964113b1c hal_health_default: allow to access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 07:02:01 +00:00
Lucas Wei
6ef92ee0d1 Merge "votable: Update don't audit file entry" 2023-02-16 06:00:51 +00:00
TreeHugger Robot
afafde41a1 Merge "Update SELinux error" 2023-02-15 03:53:59 +00:00
Treehugger Robot
6c53f05cae Merge "Remove bug_map entry for incident" am: bc70a9f3df am: dfd9324aca am: 05d473ec62
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: Ic2399bc1d08f5b79ac19e083595a0f0e3ba9233e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 03:27:43 +00:00
Lucas Wei
5a70bbb335 votable: Update don't audit file entry
Test: No votable avc errors in dmesg
Bug: 247905787
Change-Id: I95ab4dd7750e9b0f26d41fece50dc6d0aa73dd41
Signed-off-by: Lucas Wei <lucaswei@google.com>
2023-02-15 02:49:08 +00:00
leochuang
e5b2d04476 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269370106
Bug: 269045042
Change-Id: Ief58a1f19580251476c71602951550388015df01
2023-02-15 10:25:40 +08:00
Treehugger Robot
05d473ec62 Merge "Remove bug_map entry for incident" am: bc70a9f3df am: dfd9324aca
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: I0c0386e02131db6c353f059ad1320f51027d9e6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 02:23:51 +00:00
Treehugger Robot
dfd9324aca Merge "Remove bug_map entry for incident" am: bc70a9f3df
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2436853

Change-Id: I435bdfe151ffbb88e2b3e2f8360acfaf42093ee4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 01:36:50 +00:00
Treehugger Robot
bc70a9f3df Merge "Remove bug_map entry for incident" 2023-02-15 00:31:13 +00:00
Thiébaud Weksteen
10d08a16e1 Remove bug_map entry for incident
Bug: 238570971
Bug: 238571324
Bug: 238571420
Test: presubmit
Change-Id: Ib24d85aaed87e6e5dc0b0281d65407e8c45e017c
2023-02-15 10:19:58 +11:00
TreeHugger Robot
a6f9e17cd4 Merge "Update SELinux error" 2023-02-14 22:56:03 +00:00
Treehugger Robot
580fb1061d Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f am: 60fc07a2f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I269fe35ddd8dc13df7b275a84f86955e2853563a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 20:44:30 +00:00
Treehugger Robot
60fc07a2f5 Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I624db1bdd6fbe5de7d774954f5390fb0af884b77
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 19:41:20 +00:00
Treehugger Robot
114e2a377f Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: Ib469bb013d0c7335e2da4f429cde4c5df9395ed5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 18:56:35 +00:00
Android Build Coastguard Worker
50b0c84d12 Merge cherrypicks of ['googleplex-android-review.googlesource.com/21219300'] into tm-qpr2-release.
Change-Id: Iba513e117f9749ea342aa573120c758f4a14ba68
2023-02-14 18:20:12 +00:00
Ray Chi
beacc5b05f [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
(cherry picked from commit 9828cc747a)
Merged-In: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-14 18:13:34 +00:00
Treehugger Robot
b72bb4c53f Merge "Map AIDL Gatekeeper to same policy as HIDL version" 2023-02-14 17:48:17 +00:00
leochuang
14c66190df Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269218654
Test: scanBugreport
Bug: 269218638
Change-Id: If7d4633aa4f4f10cf3b56640ae6661a2a9b20b91
2023-02-14 15:46:17 +08:00
Adam Shih
bd3291b1c0 Merge "Move memory dump to gs-common" 2023-02-14 07:22:12 +00:00
Adam Shih
9a7bb8df86 Move memory dump to gs-common
Bug: 240530709
Test: adb bugreport
Change-Id: I78433d8d170af54a4daee6c9a9218ce35e78e730
2023-02-13 14:56:30 +08:00
sukiliu
d48a10f9b0 Update SELinux error
Test: scanBugreport
Bug: 269045042
Change-Id: I6291a7d3fd3b75d68548bd2fb7287b8ff754684a
2023-02-13 10:41:23 +08:00
sukiliu
8835275413 Update SELinux error
Test: scanBugreport
Bug: 268411073
Bug: 268147283
Bug: 268146971
Change-Id: I60fdc8e3d44da7632522f57adc01c0e6879be83c
2023-02-10 10:20:35 +08:00
Subrahmanyaman
b4ec2efe4b Map AIDL Gatekeeper to same policy as HIDL version
Bug: 268342724
Test: VtsHalGatekeeperTargetTest
Change-Id: I050860bfeb0e87830e554ed19bc1efe54e7db0a5
2023-02-08 18:37:15 +00:00
Ken Yang
8e9fa12996 Merge "WLC: Add required sysfs_wlc sepolicies" 2023-02-05 02:30:37 +00:00
TreeHugger Robot
0e10d6a3d4 [automerger skipped] Merge "[ DO NOT MERGE ] usb: Add sepolicy for extcon access" into tm-qpr-dev am: 5dbdb799e8 am: 51d695553c -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: I0205dc11ca3217914f9a13e38e7f4a05ccb4a128
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 05:07:14 +00:00
Ray Chi
809cff1a98 [automerger skipped] [ DO NOT MERGE ] usb: Add sepolicy for extcon access am: 9828cc747a am: 4003532648 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: I68ba4f60cc25597b16c41da55c1bde935284fa07
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 05:06:51 +00:00
TreeHugger Robot
51d695553c Merge "[ DO NOT MERGE ] usb: Add sepolicy for extcon access" into tm-qpr-dev am: 5dbdb799e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: Ia05aa347d9c71ab2cdf0b511c7d77ba5ab5b83e7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 04:37:07 +00:00
Ray Chi
4003532648 [ DO NOT MERGE ] usb: Add sepolicy for extcon access am: 9828cc747a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: I2c4f5571065ac696d32f5050d6b94f7957ddce3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 04:37:04 +00:00
Nicolas Geoffray
f485d48f43 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108 am: fa4c9c92e0
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Ia166fb782bc79702f9f064cf326af5872bfc1fb4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:54:42 +00:00
Nicolas Geoffray
fa4c9c92e0 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Iab23f2032100e1105e1f1edaee8a4dd90f7ec2d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:25:08 +00:00
Nicolas Geoffray
0090218108 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: I510f6f8cc0dc2c609ec46a901738374bfd9d3217
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 15:34:58 +00:00
TreeHugger Robot
5dbdb799e8 Merge "[ DO NOT MERGE ] usb: Add sepolicy for extcon access" into tm-qpr-dev 2023-02-03 14:47:47 +00:00