Wenhao Wang
f5277482c1
Fix selinux for RPMB daemon
...
Secure persistent storage has been moved to persist root.
The corresponding pathes on SELinux policy has to be updated.
Bug: 173971240
Bug: 173032298
Test: Trusty storage tests
Change-Id: I0e7756f3b4d5c6be705a87e1d7d80247df1ec4bb
2021-04-20 13:01:23 +08:00
Wei Wang
0d9dfcc1f6
Merge "Grant Fabric node access for memory min frequency setting" into sc-dev am: 0ae24df58d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14242545
Change-Id: I5c962987a7801d10506f35488672fb48ac3833a3
2021-04-20 02:54:36 +00:00
Wei Wang
2eecd29f2f
Merge "Grant Fabric node access for memory min frequency setting" into sc-dev am: 0ae24df58d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14242545
Change-Id: I47da08d8684a588094705204ac56c56334751e62
2021-04-20 02:53:43 +00:00
Wei Wang
0ae24df58d
Merge "Grant Fabric node access for memory min frequency setting" into sc-dev
2021-04-20 02:14:18 +00:00
Taeju Park
3e824702f2
Grant Fabric node access for memory min frequency setting
...
Bug: 170510392
Signed-off-by: Taeju Park <taeju@google.com>
Change-Id: Ia96c8d9e890251a4f82bf8c8bb042ae6ce57182b
2021-04-20 00:46:32 +00:00
Salmax Chang
f9718d7bab
Merge "dumpstate/incident: Fix avc errors" into sc-dev am: 854e4dfd60
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207379
Change-Id: I1e4499000e0a3a3589bf61333038e8391ca9cf79
2021-04-19 10:32:04 +00:00
Salmax Chang
4769345944
Merge "dumpstate/incident: Fix avc errors" into sc-dev am: 854e4dfd60
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207379
Change-Id: I7b6bbf41ea0df757b32e74d47e96efc80831dce4
2021-04-19 10:20:31 +00:00
Salmax Chang
854e4dfd60
Merge "dumpstate/incident: Fix avc errors" into sc-dev
2021-04-19 10:00:10 +00:00
SalmaxChang
1b17b0fbaa
dumpstate/incident: Fix avc errors
...
avc: denied { append } for path="/storage/emulated/0/Android/data/com.android.pixellogger/files/bugreport-oriole-MASTER-2021-04-19-14-57-22.zip" dev="dm-7" ino=35424 scontext=u:r:dumpstate:s0 tcontext=u:object_r:media_rw_data_file:s0:c28,c257,c512,c768 tclass=file
avc: denied { use } for path="/storage/emulated/0/Android/data/com.android.pixellogger/files/bugreport-oriole-MASTER-2021-04-19-14-57-22.zip" dev="dm-7" ino=35424 scontext=u:r:incident:s0 tcontext=u:r:logger_app:s0:c28,c257,c512,c768 tclass=fd
avc: denied { append } for path="/storage/emulated/0/Android/data/com.android.pixellogger/files/bugreport-oriole-MASTER-2021-04-19-16-30-05.zip" dev="dm-7" ino=12639 scontext=u:r:incident:s0 tcontext=u:object_r:media_rw_data_file:s0:c30,c257,c512,c768 tclass=file
Bug: 178744858
Change-Id: I07eb1f4abf6cb9b399c773854ca6f47fcd5e2f37
2021-04-19 08:34:57 +00:00
Hongbo Zeng
8b9e2b3834
allow RilConfigService to call oemrilhook api
...
04-15 21:19:42.312 373 373 E SELinux : avc: denied { find } for pid=10245 uid=1001 name=telephony.oem.oemrilhook scontext=u:r:ril_config_service_app:s0 tcontext=u:object_r:radio_service:s0 tclass=service_manager permissive=0
Bug: 185747692
Test: after apply the rule, the denial log is gone
Change-Id: I447c9c695f48ee3b528190ff33261ca3e9cd69df
2021-04-19 16:26:59 +08:00
TreeHugger Robot
c049172863
Merge "Add sepolicy rules when PowerAnomalyDataDetection service enabled" into sc-dev am: 8c30e63758
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207376
Change-Id: I623850de79cd6d44921f5ea79c8ab8d3ea56016f
2021-04-19 06:20:23 +00:00
TreeHugger Robot
8a2e0ac237
Merge "remove obsolete domains" into sc-dev am: 07121f1245
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14230396
Change-Id: I1b821e90e2dfe6ad07440a14d15d41d4291d6143
2021-04-19 06:20:01 +00:00
TreeHugger Robot
c7657f946d
Merge "Add sepolicy rules when PowerAnomalyDataDetection service enabled" into sc-dev am: 8c30e63758
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207376
Change-Id: Id20a8bf887bea871ea558e91f6c4f9f2fa2a2aa6
2021-04-19 06:18:21 +00:00
TreeHugger Robot
ad00a4479c
Merge "remove obsolete domains" into sc-dev am: 07121f1245
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14230396
Change-Id: I5649646be20304eb0c2f4d2289c8d42cdacf3af0
2021-04-19 06:17:34 +00:00
TreeHugger Robot
8c30e63758
Merge "Add sepolicy rules when PowerAnomalyDataDetection service enabled" into sc-dev
2021-04-19 06:03:11 +00:00
TreeHugger Robot
07121f1245
Merge "remove obsolete domains" into sc-dev
2021-04-19 05:56:38 +00:00
Rios Kao
546bc74b3e
Merge "Allow ssr_detector to read aoc version property" into sc-dev am: 1b25799252
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14185472
Change-Id: I670b3c3cae62c0b7f0cd5acf26ab4c769f0905e5
2021-04-19 04:35:23 +00:00
Rios Kao
3b36f9f4e9
Merge "Allow ssr_detector to read aoc version property" into sc-dev am: 1b25799252
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14185472
Change-Id: I6f06b0d6e7e1aaf1371491d14eaa374b2a78eef1
2021-04-19 04:33:27 +00:00
Rios Kao
1b25799252
Merge "Allow ssr_detector to read aoc version property" into sc-dev
2021-04-19 04:19:34 +00:00
Adam Shih
487b7ef4ef
update error on ROM 7293525 am: 59a1c3f04a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14230390
Change-Id: I4df5074d99314748940179af7678e61c5e03a33c
2021-04-19 03:45:17 +00:00
Adam Shih
597926934c
update error on ROM 7293525 am: 59a1c3f04a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14230390
Change-Id: Ie51d0e43b7c8b0c85102ab22bd3e8a835cbc1ee6
2021-04-19 03:42:21 +00:00
Adam Shih
99988c4c5f
remove obsolete domains
...
Bug: 168013500
Test: Check that abox and rpmbd are not in ROM anywhere in oriole, raven user,
userdebug and factory ROM
Change-Id: Ie091a1036ba6c25a3c7f0ef0b8f69cc9fc4e306a
2021-04-19 11:14:54 +08:00
Adam Shih
59a1c3f04a
update error on ROM 7293525
...
Bug: 185723618
Bug: 185723492
Bug: 185723694
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I5cc12384aca5dcc2658b914e5c7783f2e1e70b5d
2021-04-19 09:52:55 +08:00
TreeHugger Robot
3e60566e85
Merge "sepolicy: fix fingerprint sepolicy" into sc-dev am: 96ed3bb51c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207375
Change-Id: Iaae8bfba152a1411ab33e66128fde5e2a8d26f5b
2021-04-16 09:57:44 +00:00
TreeHugger Robot
24cbff3fd4
Merge "sepolicy: fix fingerprint sepolicy" into sc-dev am: 96ed3bb51c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207375
Change-Id: Id443be6287e001621a2d801aebbc75bf3122c7b4
2021-04-16 09:55:29 +00:00
TreeHugger Robot
96ed3bb51c
Merge "sepolicy: fix fingerprint sepolicy" into sc-dev
2021-04-16 09:25:33 +00:00
eddielan
75a9ea1ee4
sepolicy: fix fingerprint sepolicy
...
04-16 01:56:07.948 1039 1039 W fingerprint@2.1: type=1400 audit(0.0:110):
avc: denied { write } for name="wakeup_enable" dev="sysfs" ino=69197
scontext=u:r:hal_fingerprint_default:s0
tcontext=u:object_r:sysfs:s0
tclass=file permissive=0
Bug: 185538163
Test: Build Pass
Change-Id: I8f75daf22577e6a68f3b2a0250eebebd1873ea28
2021-04-16 15:17:20 +08:00
SalmaxChang
c73d07ada1
Create vendor_logger_prop am: 3c692b942a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207372
Change-Id: I32ef66fbc32e1ca1a1c5cf4765ce0ff586c23b26
2021-04-16 06:33:03 +00:00
SalmaxChang
5b14e5db89
Create vendor_logger_prop am: 3c692b942a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14207372
Change-Id: I5c767d97a1e4ddd55a2ba22c58a24fc3be4c10f4
2021-04-16 06:30:53 +00:00
SalmaxChang
3c692b942a
Create vendor_logger_prop
...
Bug: 178744858
Change-Id: I4abb6f73b068c5ed265979c3190bcc2feac76f94
2021-04-16 06:06:36 +00:00
Hsiaoan Hsu
0790114826
Add sepolicy rules when PowerAnomalyDataDetection service enabled
...
- Fix avc denied when Power anomaly data detection enable.
Bug: 185544799
Test: Verified Pass
Change-Id: I7b81e09842acb71767f60df18fd0ca4a95e0ff09
2021-04-16 13:37:04 +08:00
TreeHugger Robot
e13ba8bc04
Merge "Update sepolicy for the egetpu_logging service to access the sysfs." into sc-dev am: ca24e70422
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14194013
Change-Id: I38b0a7ebaed84c336440558b030329fdcdd06e10
2021-04-16 02:38:54 +00:00
TreeHugger Robot
f6fff87e28
Merge "Update sepolicy for the egetpu_logging service to access the sysfs." into sc-dev am: ca24e70422
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14194013
Change-Id: Icfcdfb4d7fc0b437d3bd0d60bc10239bcdbd514e
2021-04-16 02:36:18 +00:00
TreeHugger Robot
ca24e70422
Merge "Update sepolicy for the egetpu_logging service to access the sysfs." into sc-dev
2021-04-16 02:15:58 +00:00
Max Shi
bf808b39f5
Add sepolicy for sensor HAL accessing AOC reset sysfs node. am: 55bd05960f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14167428
Change-Id: Ibcd80f9711e1d9976dfcf9a745c7bdd600479235
2021-04-16 00:04:38 +00:00
Ahmed ElArabawy
d191543cb2
Merge "ssr_detector: provide wlan firmware version" into sc-dev am: 4a5d646504
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14197331
Change-Id: I1a439519d7d2150983b17e606126a95cfb2d3181
2021-04-16 00:04:32 +00:00
Max Shi
0fd9e3970a
Add sepolicy for sensor HAL accessing AOC reset sysfs node. am: 55bd05960f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14167428
Change-Id: I63c1b97911f6e853dcc41f3ab1ebde385235d3a5
2021-04-16 00:02:00 +00:00
Ahmed ElArabawy
8e2e50c07a
Merge "ssr_detector: provide wlan firmware version" into sc-dev am: 4a5d646504
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14197331
Change-Id: Ice4ffb15a7f0f042b9a57bfad404a204fcf94bd8
2021-04-16 00:00:49 +00:00
qinyiyan
4585613637
Update sepolicy for the egetpu_logging service to access the sysfs.
...
Test: make selinux_policy -j128 and pushed sepolicy modules to the
device. The avc denials are gone.
Bug:185448476
Change-Id: Ibff482b64a6cdbc5a7967bb8cc4281c8bd0b5b98
2021-04-15 23:57:32 +00:00
Max Shi
55bd05960f
Add sepolicy for sensor HAL accessing AOC reset sysfs node.
...
Bug: 184858369
Test: Verify sensor HAL process can write to the sysfs node.
Change-Id: I9700323bafa413b88f25e4117499bcc936bce9c6
2021-04-15 23:37:15 +00:00
Ahmed ElArabawy
4a5d646504
Merge "ssr_detector: provide wlan firmware version" into sc-dev
2021-04-15 23:32:26 +00:00
rioskao
a0a4a7f2a2
Allow ssr_detector to read aoc version property
...
sst_detector would need firmware version in order to
parse dump information with corresponding symbol of the version
04-15 13:05:39.196 28845 28864 W libc : Access denied finding property "vendor.aoc.firmware.version"
Bug: 185473950
Test: validate by force ramdump of aoc.
Change-Id: Iebf62b97897ccc2a84a174dafca90f446b771915
2021-04-15 22:53:18 +08:00
Jenny Ho
c15e4b72f2
Merge "Allow to dump pps-dc" into sc-dev am: 9ec58d031a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14140257
Change-Id: Iacaa2d56fc4ace8a91cc2e341f4f1f20dff5a6af
2021-04-15 11:21:24 +00:00
Jenny Ho
2dd8bf92c6
Merge "Allow to dump pps-dc" into sc-dev am: 9ec58d031a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14140257
Change-Id: I36e4f653f1bfcab9b5c884e452ec053894177d99
2021-04-15 11:16:01 +00:00
Jenny Ho
9ec58d031a
Merge "Allow to dump pps-dc" into sc-dev
2021-04-15 10:26:57 +00:00
Roger Wang
da8122c867
ssr_detector: provide wlan firmware version
...
In this commit, we allow ssr_detector to collect
wlan firmware version from property. This information
is useful for doing SSR statistic.
avc log:
avc: denied { read } for comm="FileObserver" name="u:object_r:vendor_wifi_version:s0" dev="tmpfs" ino=324 scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:object_r:vendor_wifi_version:s0 tclass=file permissive=0
Bug: 185457155
Test: check firmware version can be collected.
ssrInfo SSRInfo{mSubsystem='wlan', mCrashReason='Dongle_Trap_traptest+0x8_pcidev_handle_user_disconnect+0xbb', mRamdumpFile='coredump_wlan_2021-04-15_18-01-54.bin', mTimeStamp='2021-04-15_18-01-54', mBuildVersion='20.25.423.4', mUID='05a6029c-4f74-3172-9a3f-7fa8e8bcc6c4', mExtraBuildVersion=''}, uid 05a6029c-4f74-3172-9a3f-7fa8e8bcc6c4
Change-Id: Ibf2ce8f0c7a7dd752963c738bf28da14034cc209
2021-04-15 18:08:52 +08:00
Charlie Chen
bbe9ffe0e8
Merge changes from topic "remove_video_system_heap" into sc-dev am: 742daf873c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14187064
Change-Id: If5d1cecad9d65888364eb43f4ba2d5b296452058
2021-04-15 09:11:41 +00:00
Charlie Chen
89e6693435
Merge changes from topic "remove_video_system_heap" into sc-dev am: 742daf873c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14187064
Change-Id: I98048923a0865e28d6b67c5efffce8b8295371c5
2021-04-15 08:59:10 +00:00
Charlie Chen
742daf873c
Merge changes from topic "remove_video_system_heap" into sc-dev
...
* changes:
Formatting file_contexts
remove video_system_heap
2021-04-15 07:56:19 +00:00
TreeHugger Robot
6b2103ed0c
Merge "Allow power stats HAL read uwb power_stats sysfs node" into sc-dev am: a4d458026a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14189309
Change-Id: I67474bd39ad5bb247df79ad27d88cb14b7bc8955
2021-04-15 06:57:10 +00:00