Stephen Crane
8a0cbfea6d
[automerger skipped] [automerged blank] Allow TEE storageproxyd permissions needed for DSU handling 2p: b9beafc9fa
am: e48d11c26c
-s ours
...
am skip reason: Merged-In I86055dd5601f8c2899d28f29bdfcb4dcb9b90d1b with SHA-1 b69ac35ff0
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16727208
Change-Id: I4e9ded6165f8e1db1aed145f8156347de70d5e73
2022-03-18 04:31:40 +00:00
Armelle Laine
92707e72ab
Merge changes from topic "trusty-dsu_fix-sc-qpr3" into sc-v2-dev-plus-aosp
...
* changes:
[automerged blank] Allow TEE storageproxyd permissions needed for DSU handling 2p: b9beafc9fa
Allow TEE storageproxyd permissions needed for DSU handling
2022-03-18 04:14:36 +00:00
Darren Hsu
61e944b081
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
am: 83e88065fc
am: 186f2306d7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: Ieebbc5aafe7ddabe3560310dd599573d0ced3caf
2022-03-17 04:54:29 +00:00
Darren Hsu
186f2306d7
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
am: 83e88065fc
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: I732b1d982c15846e2b9ae1365894b4d0ea0f424f
2022-03-17 03:55:26 +00:00
Darren Hsu
83e88065fc
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: Ic1a74c930cc6ade12dc6ea7a42f9ed347a491c95
2022-03-17 02:49:16 +00:00
samou
753edef5f6
Move ODPM file rule to pixel sepolicy
...
Bug: 213257759
Change-Id: Ic9a89950a609efe5434dfedc0aa023312c4192d9
2022-03-16 06:05:52 +00:00
Darren Hsu
2018f942a7
sepolicy: reorder genfs labels for system suspend
...
Bug: 223683748
Test: check bugreport without relevant avc denials
Change-Id: I66ede69d94bb3cb1a446e1cd5f3250b6f9b7f7e9
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-15 11:48:39 +08:00
TreeHugger Robot
e4dfe23d99
Merge "sepolicy: reorder genfs labels for system suspend" into tm-dev
2022-03-15 02:52:34 +00:00
TreeHugger Robot
85f293ab62
Merge "gs-sepolicy(uwb): Changes for new UCI stack" into tm-dev
2022-03-14 16:09:09 +00:00
TeYuan Wang
6052118e99
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
am: fe826745b3
am: faec59da79
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: I44c643184de6294c407c9fc1670b0631faac3e45
2022-03-14 06:22:59 +00:00
TeYuan Wang
faec59da79
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
am: fe826745b3
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: I919c688388bcd8cc320068f6139432b58b3f0ea4
2022-03-14 06:02:51 +00:00
TeYuan Wang
fe826745b3
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: Ie191a767c8b3450df75a37e36deebf5f20242575
2022-03-14 05:40:21 +00:00
eddielan
17f6a0a1ba
sepolicy: Add policy for persist.vendor.udfps
...
Bug: 222175797
Test: Build Pass
Change-Id: I978325adb5cf25a590b307a38ce2deac4034e656
2022-03-14 10:57:53 +08:00
TeYuan Wang
f7aba10674
Move libperfmgr thermal rules to pixel-sepolicy
...
Bug: 213257759
Bug: 188579571
Test: build
Change-Id: I9893d53055594bfb4e4dba3d68b53f0fe132617d
2022-03-10 21:28:33 +08:00
Kris Chen
9b54bf3665
Allow hal_fingerprint_default to access fwk_sensor_hwservice
...
Fix the following avc denial:
avc: denied { find } for interface=android.frameworks.sensorservice::ISensorManager sid=u:r:hal_fingerprint_default:s0 pid=1258 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:fwk_sensor_hwservice:s0 tclass=hwservice_manager permissive=0
Bug: 197789721
Test: build and test fingerprint on device.
Change-Id: I7494f28e69e5a1b660dc7fbaa528b1088048723b
2022-03-10 16:53:22 +08:00
TreeHugger Robot
a1f73d0faa
Merge "Update avc error on ROM 8276520" into tm-dev
2022-03-10 02:40:10 +00:00
Darren Hsu
44fcba7efd
sepolicy: reorder genfs labels for system suspend
...
Bug: 223683748
Test: check bugreport without relevant avc denials
Change-Id: I66ede69d94bb3cb1a446e1cd5f3250b6f9b7f7e9
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-10 09:19:31 +08:00
Michael Eastwood
ecb7a69d78
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
am: a45d075fd0
am: ada03db5e0
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: Ic6e51b5ea87b5d682f406a9711d39d80c4b29a9c
2022-03-09 18:55:19 +00:00
Michael Eastwood
ada03db5e0
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
am: a45d075fd0
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: I2b73c3f4576a4f42f76afbf7b8e75fd3be838107
2022-03-09 18:32:59 +00:00
Michael Eastwood
a45d075fd0
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: I55cfbec1df5a5b3952e02875860d25db44b64b98
2022-03-09 18:00:28 +00:00
Michael Eastwood
82a110ba3b
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets"
2022-03-09 17:31:28 +00:00
Xin Li
6bc47cde6f
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours am: 594011b90b
-s ours am: 0e86159889
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: I53a128252845f7a2403302749aae2e6e43bce8bd
2022-03-09 10:02:38 +00:00
sukiliu
037f9cda4e
Update avc error on ROM 8276520
...
Bug: 223502652
Bug: 223330933
Test: PtsSELinuxTestCases
Change-Id: Ib8c14c4928410ee5ed4626e95e2882b89341ee9a
2022-03-09 14:16:33 +08:00
Michael Eastwood
f648f3c989
Update SELinux policy to allow camera HAL to send Perfetto trace packets
...
Example denials:
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:31): avc: denied { use } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:r:tr
aced:s0 tclass=fd permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:32): avc: denied { read write } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext
=u:object_r:traced_tmpfs:s0 tclass=file permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:33): avc: denied { getattr } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:
object_r:traced_tmpfs:s0 tclass=file permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:34): avc: denied { map } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:traced_tmpfs:s0 tclass=file permissive=1
Bug: 222684359
Test: Build and push new SELinux policy. Verify that trace packets are received by Perfetto.
Change-Id: I0180c6bccf8cb65f444b8fb687ab48422c211bac
2022-03-08 13:54:34 -08:00
Darren Hsu
c3d3c574f4
sepolicy: fix VTS failure for SuspendSepolicyTests
...
Label the common parent wakeup path instead of each
individual wakeup source to avoid bloating the genfs
contexts.
Bug: 221174227
Test: run vts -m SuspendSepolicyTests
Change-Id: I83a074840198aba323805fd455ee78a0e57174ac
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-08 20:57:42 +08:00
Xin Li
0e86159889
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours am: 594011b90b
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: If0e4880aa30ddfcc89e252de3f041da19401d4bc
2022-03-08 11:04:07 +00:00
Xin Li
594011b90b
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: Ic29497624866c936ddf7a7f34f9539de55d73eb9
2022-03-08 10:19:17 +00:00
Xin Li
22c3ab8b6b
Merge Android 12L
...
Bug: 222710654
Merged-In: I7b9186af0cb135241e23504fa9d6f7c3d6718c7c
Change-Id: I60cda8853fd8575beb8617025479d08ccf816fbb
2022-03-08 00:15:28 +00:00
Roshan Pius
34c5b9b239
gs-sepolicy(uwb): Changes for new UCI stack
...
1. Rename uwb vendor app.
2. Rename uwb vendor HAL binary name & service name.
3. Allow vendor HAL to host the AOSP UWB HAL service.
4. Allow NFC HAL to access uwb calibration files.
Bug: 186585880
Test: Manual Tests
Change-Id: I2c7c2466f42317d643634e24b1efb1855e673d09
2022-03-06 18:15:16 -08:00
Tri Vo
56b17a34c8
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
am: a5ccc7efa8
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I58998bc0820db2eeb6f2362a604aaff81159594e
2022-03-04 18:50:56 +00:00
Tri Vo
a5ccc7efa8
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: Ie2af054a900f32cbde1352ba9f708e163f76d86c
2022-03-04 18:29:27 +00:00
Tri Vo
22f2ffcbee
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I7b9186af0cb135241e23504fa9d6f7c3d6718c7c
2022-03-04 18:06:53 +00:00
Tri Vo
fbf92e2ada
Merge "Don't audit storageproxyd unlabeled access"
2022-03-04 17:45:37 +00:00
Midas Chien
5e5133e7f6
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours am: 9285045f0b
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: I29262cf0b26426b83493008aa2e569548e2fa436
2022-03-04 13:10:39 +00:00
Midas Chien
9285045f0b
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: Iaf03b02cd8feadc0da6b1f7cb4d0d25f47907f39
2022-03-04 12:50:47 +00:00
Midas Chien
b637545191
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: I5771c4702d7e76db359bba65f059f913d69d774f
2022-03-04 12:29:41 +00:00
Midas Chien
0e1e0e2830
[Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node
...
Change panel_idle_exit_handle selinux type to sysfs_display to allow
composer to access it.
Bug: 202182467
Test: ls -Z to check selinux type
Test: composer can access it in enforce mode
Merged-In: I5ca811f9500dc452fe6832dd772376da51f675a8
Change-Id: I5ca811f9500dc452fe6832dd772376da51f675a8
2022-03-04 10:48:08 +00:00
Midas Chien
08c3646fc1
Merge "Allow composer to read panel_idle_handle_exit sysfs node" into tm-dev
2022-03-04 06:55:05 +00:00
Tri Vo
03fef48542
Don't audit storageproxyd unlabeled access
...
Test: m sepolicy
Bug: 197502330
Change-Id: I794dac85e475434aaf024027c43c98dde60bee27
2022-03-03 13:12:17 -08:00
TreeHugger Robot
c865c80379
Merge "Add sepolicy rules for fingerprint hal" into tm-dev
2022-03-02 02:40:58 +00:00
Robert Lee
e5cf8beff3
Fix selinux error for aocd
...
allow write permission to fix following error
auditd : type=1400 audit(0.0:4): avc: denied { write } for comm="aocd" name="aoc" dev="tmpfs" ino=497 scontext=u:r:aocd:s0 tcontext=u:object_r:aoc_device:s0 tclass=chr_file permissive=0
Bug: 198490099
Test: no avc deny when enable no_ap_restart
Change-Id: Ia72ee36137d78f969c28bf22647443cef45d186a
Signed-off-by: Robert Lee <lerobert@google.com>
2022-03-01 09:13:46 +00:00
Kris Chen
e0c6120237
Add sepolicy rules for fingerprint hal
...
Fix the following avc denial:
avc: denied { set } for property=vendor.gf.cali.state pid=1152 uid=1000 gid=1000 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'
Bug: 219372997
Bug: 220263520
Test: No above avc denial in logcat.
Change-Id: I93ace30c67e04bc836bfba050028a1f25af641d5
2022-03-01 15:05:42 +08:00
Midas Chien
acd4220ac9
Allow composer to read panel_idle_handle_exit sysfs node
...
Change panel_idle_exit_handle selinux type to sysfs_display to allow
composer to access it.
Bug: 202182467
Test: ls -Z to check selinux type
Test: composer can access it in enforce mode
Change-Id: I5ca811f9500dc452fe6832dd772376da51f675a8
2022-02-25 23:07:09 +08:00
Jason Macnak
28a21a48e0
Remove sysfs_gpu type definition
...
... as it has moved to system/sepolicy.
Bug: b/161819018
Test: presubmit
Change-Id: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
Merged-In: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
2022-02-24 22:23:41 +00:00
Edwin Wong
6b7fff8497
Merge "whitechapel: sepolicy for Widevine AIDL HAL" into tm-dev
2022-02-23 01:08:19 +00:00
Aaron Tsai
e704af0ed7
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
am: 84bacff9ab
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: I6e91791926ff7d840c7317fbf5d9656338960132
2022-02-22 02:29:22 +00:00
Aaron Tsai
84bacff9ab
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: Ibdbeeee937e4c856adfebad71a956a343b820dfa
2022-02-22 01:56:28 +00:00
Aaron Tsai
d2d83c8e2d
Fix selinux error for system_app am: 05565c1f14
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: Ia3c6c0aae82c19a5d1c019cce2700c5e64c8bb11
2022-02-22 01:35:41 +00:00
Shubham Dubey
5e2e261148
Temporarily don't audit hal_fingerprint to fix avc denial
...
Fix: 220263520
Change-Id: Ic06981fdc071c5027e6ccd137c1a2d19b9366c98
2022-02-21 13:07:23 +00:00
Aaron Tsai
05565c1f14
Fix selinux error for system_app
...
01-26 05:04:53.364 440 440 I auditd : avc: denied { find } for interface=vendor.samsung_slsi.telephony.hardware.radioExternal::IOemSlsiRadioExternal sid=u:r:system_app:s0 pid=3063 scontext=u:r:system_app:s0 tcontext=u:object_r:hal_exynos_rild_hwservice:s0 tclass=hwservice_manager permissive=0
Bug: 216531913
Test: verified with the forrest ROM and error log gone
Change-Id: I73d45f3cf1fe0bd918bb4856ce554e81702e4ff9
Merged-In: I73d45f3cf1fe0bd918bb4856ce554e81702e4ff9
2022-02-21 12:16:45 +08:00