Presubmit Automerger Backend
205a9c66bf
[automerge] Allow Sensor HAL access to display sysfs panel_name file. 2p: 28ddd3bf9f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17308483
Bug: 208926536
Change-Id: I4980d9c85cc71e5b373c76ed43ed03191d92b0c1
2022-03-25 01:03:03 +00:00
Chris Kuiper
28ddd3bf9f
Allow Sensor HAL access to display sysfs panel_name file.
...
Bug: 208926536
Test: Accessed the display sysfs from sensor HAL correctly.
Change-Id: Ide86813de20a1240f8ac55322b017329f30b296e
2022-03-24 17:55:43 -07:00
Stephane Lee
693413dc29
Fix off-mode (charger) sepolicy for the health interface am: 84a06151a3
am: c35357078d
am: 620e6038e2
am: 282c77a88f
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039624
Change-Id: I87fd048c19ca3c30cb6a3bbc0b6e366221bf9aad
2022-03-24 05:31:14 +00:00
Jack Wu
c842deb7b2
[automerger skipped] sepolicy: gs101: fix charger_vendor permission denied am: b67138e8ae
am: 28efee70de
am: d43cfef11c
-s ours am: 6abc9f674c
-s ours
...
am skip reason: Merged-In I091dbbca35fb833e59fdbc234d74b90bfe74014c with SHA-1 dcb05d1377
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039623
Change-Id: Ia87df8c47b934dd1aebb551ed7da27dd0c896d54
2022-03-24 05:31:12 +00:00
Stephane Lee
282c77a88f
Fix off-mode (charger) sepolicy for the health interface am: 84a06151a3
am: c35357078d
am: 620e6038e2
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039624
Change-Id: I1da177501cfa887962e7a8133e4b568db9624025
2022-03-24 05:14:06 +00:00
Jack Wu
6abc9f674c
[automerger skipped] sepolicy: gs101: fix charger_vendor permission denied am: b67138e8ae
am: 28efee70de
am: d43cfef11c
-s ours
...
am skip reason: Merged-In I091dbbca35fb833e59fdbc234d74b90bfe74014c with SHA-1 dcb05d1377
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039623
Change-Id: I01702f92f112bd722cfe3852af74aa79bfaaecef
2022-03-24 05:14:05 +00:00
Stephane Lee
620e6038e2
Fix off-mode (charger) sepolicy for the health interface am: 84a06151a3
am: c35357078d
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039624
Change-Id: Ia59f2cdb6b014a802edad3b76f135a69c21002e9
2022-03-24 04:37:58 +00:00
Jack Wu
d43cfef11c
sepolicy: gs101: fix charger_vendor permission denied am: b67138e8ae
am: 28efee70de
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039623
Change-Id: I1802a01e50797f41a63ba0073f5f032a8d49939b
2022-03-24 04:37:57 +00:00
Stephane Lee
c35357078d
Fix off-mode (charger) sepolicy for the health interface am: 84a06151a3
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039624
Change-Id: Ia2c26cc56c09a535aae2d7b4e8e46ff77b79616e
2022-03-24 04:06:54 +00:00
Jack Wu
28efee70de
sepolicy: gs101: fix charger_vendor permission denied am: b67138e8ae
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2039623
Change-Id: I70510310fad5fb164c3a420685fbad7c1e1e1e71
2022-03-24 04:06:53 +00:00
Stephane Lee
84a06151a3
Fix off-mode (charger) sepolicy for the health interface
...
Bug: 223537397
Test: Ensure that there are no selinux errors for sysfs_batteryinfo in
off-mode charging
Change-Id: I46fa1b7552eb0655d0545538142131465a337f23
Merged-In: I46fa1b7552eb0655d0545538142131465a337f23
2022-03-23 11:30:31 -07:00
Jack Wu
b67138e8ae
sepolicy: gs101: fix charger_vendor permission denied
...
[ 27.025458][ T443] type=1400 audit(1644391560.640:11): avc: denied { search } for comm="android.hardwar" name="vendor" dev="tmpfs" ino=2 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:mnt_vendor_file:s0 tclass=dir permissive=0
[ 26.563658][ T447] type=1400 audit(1644397622.588:5): avc: denied { search } for comm="android.hardwar" name="/" dev="sda1" ino=2 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:persist_file:s0 tclass=dir permissive=0
[ 27.198144][ T442] type=1400 audit(1644398156.152:5): avc: denied { search } for comm="android.hardwar" name="battery" dev="sda1" ino=12 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:persist_battery_file:s0 tclass=dir permissive=0
[ 27.327035][ T443] type=1400 audit(1644398785.276:5): avc: denied { read } for comm="android.hardwar" name="defender_active_time" dev="sda1" ino=17 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:persist_battery_file:s0 tclass=file permissive=0
[ 27.355009][ T443] type=1400 audit(1644398785.276:6): avc: denied { write } for comm="android.hardwar" name="defender_charger_time" dev="sda1" ino=16 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:persist_battery_file:s0 tclass=file permissive=0
[ 26.771705][ T444] type=1400 audit(1644379988.804:4): avc: denied { read } for comm="android.hardwar" name="specification_version" dev="sysfs" ino=56257 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0
[ 27.898684][ T445] type=1400 audit(1644392754.928:8): avc: denied { read } for comm="android.hardwar" name="thermal_zone6" dev="sysfs" ino=15901 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=lnk_file permissive=0
[ 29.180076][ T447] type=1400 audit(1644397625.200:9): avc: denied { write } for comm="android.hardwar" name="mode" dev="sysfs" ino=15915 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=0
[ 27.043845][ T444] type=1400 audit(1644379988.808:9): avc: denied { search } for comm="android.hardwar" name="thermal" dev="tmpfs" ino=899 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=0
[ 27.064916][ T444] type=1400 audit(1644379988.808:10): avc: denied { read } for comm="android.hardwar" name="u:object_r:vendor_battery_defender_prop:s0" dev="tmpfs" ino=306 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=file permissive=0
[ 27.356266][ T444] type=1107 audit(1644404450.376:4): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=vendor.battery.defender.state pid=457 uid=1000 gid=1000 scontext=u:r:charger_vendor:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=property_service permissive=0'
Bug: 218485039
Test: manually test, no avc: denied
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: I091dbbca35fb833e59fdbc234d74b90bfe74014c
Merged-In: I091dbbca35fb833e59fdbc234d74b90bfe74014c
2022-03-23 11:27:45 -07:00
Roshan Pius
45e114114e
gs-policy: Remove obsolete uwb vendor service rules am: 3ffd8035a2
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17293462
Change-Id: I0bc3127f0b0e8acd79a4ab244a585e1459dbf88c
2022-03-22 03:30:22 +00:00
Roshan Pius
3ffd8035a2
gs-policy: Remove obsolete uwb vendor service rules
...
This service no longer exists in the UCI stack.
Bug: 186585880
Test: Manual UWB tests
Change-Id: I198a20f85cb24f9e38035fa037609d6541640d9e
2022-03-21 09:19:16 -07:00
Armelle Laine
516314f812
[automerger skipped] Merge changes from topic "trusty-dsu_fix-sc-qpr3" into sc-v2-dev-plus-aosp am: 92707e72ab
-s ours am: fcc7d1dbae
-s ours
...
am skip reason: Merged-In I86055dd5601f8c2899d28f29bdfcb4dcb9b90d1b with SHA-1 b69ac35ff0
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16727208
Change-Id: If1138137f6e515d104c53d43b482044f402bcd72
2022-03-18 04:53:44 +00:00
Stephen Crane
8b66c6449d
[automerger skipped] [automerged blank] Allow TEE storageproxyd permissions needed for DSU handling 2p: b9beafc9fa
am: e48d11c26c
-s ours am: 8a0cbfea6d
-s ours
...
am skip reason: Merged-In I86055dd5601f8c2899d28f29bdfcb4dcb9b90d1b with SHA-1 b69ac35ff0
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16727208
Change-Id: I3b0cb7e1e6081ed09bda6f16e92807d5bf4d261a
2022-03-18 04:53:43 +00:00
Armelle Laine
fcc7d1dbae
[automerger skipped] Merge changes from topic "trusty-dsu_fix-sc-qpr3" into sc-v2-dev-plus-aosp am: 92707e72ab
-s ours
...
am skip reason: Merged-In I86055dd5601f8c2899d28f29bdfcb4dcb9b90d1b with SHA-1 b69ac35ff0
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16727208
Change-Id: I485b582f2dd3df1d6c9f25e3df31094e82e8bfc0
2022-03-18 04:31:42 +00:00
Stephen Crane
8a0cbfea6d
[automerger skipped] [automerged blank] Allow TEE storageproxyd permissions needed for DSU handling 2p: b9beafc9fa
am: e48d11c26c
-s ours
...
am skip reason: Merged-In I86055dd5601f8c2899d28f29bdfcb4dcb9b90d1b with SHA-1 b69ac35ff0
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16727208
Change-Id: I4e9ded6165f8e1db1aed145f8156347de70d5e73
2022-03-18 04:31:40 +00:00
Armelle Laine
92707e72ab
Merge changes from topic "trusty-dsu_fix-sc-qpr3" into sc-v2-dev-plus-aosp
...
* changes:
[automerged blank] Allow TEE storageproxyd permissions needed for DSU handling 2p: b9beafc9fa
Allow TEE storageproxyd permissions needed for DSU handling
2022-03-18 04:14:36 +00:00
Darren Hsu
f714240360
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
am: 83e88065fc
am: 186f2306d7
am: 61e944b081
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: I1a0978f7f2b47135559e961e3f3a80d6c46c9d7b
2022-03-17 05:27:32 +00:00
Darren Hsu
61e944b081
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
am: 83e88065fc
am: 186f2306d7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: Ieebbc5aafe7ddabe3560310dd599573d0ced3caf
2022-03-17 04:54:29 +00:00
Darren Hsu
186f2306d7
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
am: 83e88065fc
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: I732b1d982c15846e2b9ae1365894b4d0ea0f424f
2022-03-17 03:55:26 +00:00
Darren Hsu
83e88065fc
sepolicy: reorder genfs labels for system suspend am: 2018f942a7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2026063
Change-Id: Ic1a74c930cc6ade12dc6ea7a42f9ed347a491c95
2022-03-17 02:49:16 +00:00
Darren Hsu
2018f942a7
sepolicy: reorder genfs labels for system suspend
...
Bug: 223683748
Test: check bugreport without relevant avc denials
Change-Id: I66ede69d94bb3cb1a446e1cd5f3250b6f9b7f7e9
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-15 11:48:39 +08:00
TreeHugger Robot
05e3349229
Merge "sepolicy: reorder genfs labels for system suspend" into tm-dev am: e4dfe23d99
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17146134
Change-Id: I0db3bd3fa8aab0b09a58c0e33d2e0e37961e7fe9
2022-03-15 03:16:17 +00:00
TreeHugger Robot
e4dfe23d99
Merge "sepolicy: reorder genfs labels for system suspend" into tm-dev
2022-03-15 02:52:34 +00:00
TreeHugger Robot
8c1cd23ce7
Merge "gs-sepolicy(uwb): Changes for new UCI stack" into tm-dev am: 85f293ab62
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16945227
Change-Id: Icbefda5f6814c27ede2d7da8e761b52dc5d43db9
2022-03-14 16:40:38 +00:00
TreeHugger Robot
85f293ab62
Merge "gs-sepolicy(uwb): Changes for new UCI stack" into tm-dev
2022-03-14 16:09:09 +00:00
TeYuan Wang
812fd9c717
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
am: fe826745b3
am: faec59da79
am: 6052118e99
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: Ia3e15c8a4af73167f65c5933b14fdecf06b64b45
2022-03-14 06:44:14 +00:00
TeYuan Wang
6052118e99
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
am: fe826745b3
am: faec59da79
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: I44c643184de6294c407c9fc1670b0631faac3e45
2022-03-14 06:22:59 +00:00
TeYuan Wang
faec59da79
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
am: fe826745b3
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: I919c688388bcd8cc320068f6139432b58b3f0ea4
2022-03-14 06:02:51 +00:00
TeYuan Wang
fe826745b3
Move libperfmgr thermal rules to pixel-sepolicy am: f7aba10674
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2020535
Change-Id: Ie191a767c8b3450df75a37e36deebf5f20242575
2022-03-14 05:40:21 +00:00
Kris Chen
41ecb11342
Allow hal_fingerprint_default to access fwk_sensor_hwservice am: 9b54bf3665
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17149561
Change-Id: I61c3a00cd9e0ce8b8a6adfbf0310459afe9112df
2022-03-14 02:59:35 +00:00
TeYuan Wang
f7aba10674
Move libperfmgr thermal rules to pixel-sepolicy
...
Bug: 213257759
Bug: 188579571
Test: build
Change-Id: I9893d53055594bfb4e4dba3d68b53f0fe132617d
2022-03-10 21:28:33 +08:00
Kris Chen
9b54bf3665
Allow hal_fingerprint_default to access fwk_sensor_hwservice
...
Fix the following avc denial:
avc: denied { find } for interface=android.frameworks.sensorservice::ISensorManager sid=u:r:hal_fingerprint_default:s0 pid=1258 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:fwk_sensor_hwservice:s0 tclass=hwservice_manager permissive=0
Bug: 197789721
Test: build and test fingerprint on device.
Change-Id: I7494f28e69e5a1b660dc7fbaa528b1088048723b
2022-03-10 16:53:22 +08:00
TreeHugger Robot
e2d47ba125
Merge "Update avc error on ROM 8276520" into tm-dev am: a1f73d0faa
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17131103
Change-Id: Ie0ebdab2e78f4dfd8612b2c5a346fbc2328a22ae
2022-03-10 03:00:35 +00:00
TreeHugger Robot
a1f73d0faa
Merge "Update avc error on ROM 8276520" into tm-dev
2022-03-10 02:40:10 +00:00
Darren Hsu
44fcba7efd
sepolicy: reorder genfs labels for system suspend
...
Bug: 223683748
Test: check bugreport without relevant avc denials
Change-Id: I66ede69d94bb3cb1a446e1cd5f3250b6f9b7f7e9
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-10 09:19:31 +08:00
Michael Eastwood
bcf33b6879
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
am: a45d075fd0
am: ada03db5e0
am: ecb7a69d78
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: I278288a3290cb78ffcfefaf2fd7eb6a5d67a1a13
2022-03-09 19:31:05 +00:00
Michael Eastwood
ecb7a69d78
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
am: a45d075fd0
am: ada03db5e0
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: Ic6e51b5ea87b5d682f406a9711d39d80c4b29a9c
2022-03-09 18:55:19 +00:00
Michael Eastwood
ada03db5e0
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
am: a45d075fd0
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: I2b73c3f4576a4f42f76afbf7b8e75fd3be838107
2022-03-09 18:32:59 +00:00
Michael Eastwood
a45d075fd0
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets" am: 82a110ba3b
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2016899
Change-Id: I55cfbec1df5a5b3952e02875860d25db44b64b98
2022-03-09 18:00:28 +00:00
Michael Eastwood
82a110ba3b
Merge "Update SELinux policy to allow camera HAL to send Perfetto trace packets"
2022-03-09 17:31:28 +00:00
Xin Li
a78738e763
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours am: 594011b90b
-s ours am: 0e86159889
-s ours am: 6bc47cde6f
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: I11d278c39c1961aeb00f2f6d67c60bcf6a627e6b
2022-03-09 11:36:34 +00:00
Xin Li
6bc47cde6f
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours am: 594011b90b
-s ours am: 0e86159889
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: I53a128252845f7a2403302749aae2e6e43bce8bd
2022-03-09 10:02:38 +00:00
sukiliu
037f9cda4e
Update avc error on ROM 8276520
...
Bug: 223502652
Bug: 223330933
Test: PtsSELinuxTestCases
Change-Id: Ib8c14c4928410ee5ed4626e95e2882b89341ee9a
2022-03-09 14:16:33 +08:00
Darren Hsu
f0805e42df
sepolicy: fix VTS failure for SuspendSepolicyTests am: c3d3c574f4
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17118111
Change-Id: I405782f527555e9a965f858048dc44517fb14007
2022-03-09 03:52:38 +00:00
Michael Eastwood
f648f3c989
Update SELinux policy to allow camera HAL to send Perfetto trace packets
...
Example denials:
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:31): avc: denied { use } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:r:tr
aced:s0 tclass=fd permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:32): avc: denied { read write } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext
=u:object_r:traced_tmpfs:s0 tclass=file permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:33): avc: denied { getattr } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:
object_r:traced_tmpfs:s0 tclass=file permissive=1
03-04 04:25:37.524 823 823 I TracingMuxer: type=1400 audit(0.0:34): avc: denied { map } for path=2F6D656D66643A706572666574746F5F73686D656D202864656C6574656429 dev="tmpfs" ino=20229 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:traced_tmpfs:s0 tclass=file permissive=1
Bug: 222684359
Test: Build and push new SELinux policy. Verify that trace packets are received by Perfetto.
Change-Id: I0180c6bccf8cb65f444b8fb687ab48422c211bac
2022-03-08 13:54:34 -08:00
Darren Hsu
c3d3c574f4
sepolicy: fix VTS failure for SuspendSepolicyTests
...
Label the common parent wakeup path instead of each
individual wakeup source to avoid bloating the genfs
contexts.
Bug: 221174227
Test: run vts -m SuspendSepolicyTests
Change-Id: I83a074840198aba323805fd455ee78a0e57174ac
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-08 20:57:42 +08:00
Xin Li
0e86159889
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours am: 594011b90b
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: If0e4880aa30ddfcc89e252de3f041da19401d4bc
2022-03-08 11:04:07 +00:00