Commit graph

1042 commits

Author SHA1 Message Date
Miller Liang
a21c6081c9 Merge "Fix AAudio avc denied" into sc-dev 2021-07-05 02:32:11 +00:00
millerliang
1e748ab270 Fix AAudio avc denied
E SELinux : avc:  denied  { find } for pid=765 uid=1041 name=audio
scontext=u:r:audioserver:s0 tcontext=u:object_r:audio_service:s0
tclass=service_manager permissive=0

Bug: 191103346
Test: build and run CtsNativeMediaAAudioTestCases
Change-Id: I8e9a41360a382ba5f461818b9f8d6658dd53c62a
2021-07-03 05:40:22 +00:00
sukiliu
334126304a Update avc error on ROM 7515047 am: 755c601dd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15175228

Change-Id: I19115f16b02be297118ff2055db15eb8f3fc172d
2021-07-02 12:03:28 +00:00
sukiliu
755c601dd8 Update avc error on ROM 7515047
Bug: 192617242
Bug: 192617244
Test: PtsSELinuxTestCases
Change-Id: I94f7fa36632147676adc46f520e9a2a4f9b413cd
2021-07-02 10:34:49 +08:00
YongWook Shin
eee09878b6 Allowed HWC HAL access TUI status node
Bug: 157272869
Signed-off-by: YongWook Shin <yongwook.shin@samsung.com>
Change-Id: Id4abb0277bda9c9ff13f753e6f74438ce55be0ab
2021-07-01 12:08:34 -07:00
TreeHugger Robot
c077524883 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev am: 846cba7286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15164003

Change-Id: Iec3adee2e2fbf126790a00719da38cef9f499e30
2021-07-01 08:24:42 +00:00
TreeHugger Robot
846cba7286 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev 2021-07-01 08:07:05 +00:00
Michael Ayoubi
56beb62f69 Fix hal_uwb_default dumpstate SELinux errors
Fixes: b/192026913
Test: Run dumpstate and confirm no avc denials

Signed-off-by: Michael Ayoubi <mayoubi@google.com>
Change-Id: I3d818fb066a834663dc63b8757bd16c08a1a0e9e
2021-07-01 06:55:42 +00:00
TreeHugger Robot
e86ced7327 Merge "remove obsolete errors" into sc-dev am: 5b4e06670f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15143009

Change-Id: Ic6d0bf859005720f75cc9e7d61595a7110a32bfe
2021-07-01 04:11:55 +00:00
TreeHugger Robot
5b4e06670f Merge "remove obsolete errors" into sc-dev 2021-07-01 04:01:19 +00:00
TreeHugger Robot
3de85f4a86 Merge "Remove dontaudit form tracking_denials for maxfg and regmap" into sc-dev am: 2ee38e55f1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15143006

Change-Id: I7b0c3e0787280be673678827aec4d29d18456a47
2021-07-01 03:36:32 +00:00
TreeHugger Robot
2ee38e55f1 Merge "Remove dontaudit form tracking_denials for maxfg and regmap" into sc-dev 2021-07-01 03:18:01 +00:00
Adam Shih
1a2d199a28 remove obsolete errors
Bug: 183338543
Bug: 187015705
Bug: 191133059
Bug: 180963348
Bug: 187016930
Bug: 190563838
Test: boot with no relevant error
Change-Id: I8d194415dc823da9dec5c315a6068d0d2c2d4a6c
2021-07-01 10:49:59 +08:00
Krzysztof Kosiński
54a9267749 Allow Power Stats HAL to access EdgeTPU sysfs files. am: 6d6a7c96ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15162531

Change-Id: I3f590b13d415682fe01024812084308de9be404a
2021-06-30 23:57:10 +00:00
Krzysztof Kosiński
6d6a7c96ab Allow Power Stats HAL to access EdgeTPU sysfs files.
Should fix intermittent failures of SELinuxUncheckedDenialBootTest.

Bug: 192485697
Test: build, checked for denials in logcat
Change-Id: I3b9cafd99f9ff343e5ab5c67f5f268e5eb4382d6
2021-06-30 14:02:27 -07:00
Michael Ayoubi
0536297aed Merge "allow recovery and fastboot to access secure elment" into sc-dev am: 075ba05575
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15152134

Change-Id: I46ad2d1546b4145d8408aee5677b4395c4d8e1d6
2021-06-30 17:56:53 +00:00
Michael Ayoubi
075ba05575 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-30 17:39:40 +00:00
Jeffrey Carlyle
14fcd5ffaf allow recovery and fastboot to access secure elment
This is to enable clearing of secure element during a master reset.

Bug: 182508814
Test: master reset on device with keys; verified no keys after reset
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I9bb569e09f8cd6f5640757bd0d10a14ef32946ff
2021-06-30 15:19:22 +09:00
Gazi Yamin Iqbal
7edd8a7f81 Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev am: 2e1cafdfd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15100489

Change-Id: Idc69fa1c2e71dfa8ec660a52d4157a68afc1e27f
2021-06-30 05:57:03 +00:00
Gazi Yamin Iqbal
2e1cafdfd8 Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev 2021-06-30 05:41:19 +00:00
Ted Lin
cb3ca1e87b Remove dontaudit form tracking_denials for maxfg and regmap
Bug:190337297
Test: Check the bugreport
Change-Id: I0887e6256b4f158bd525ed66475cd1ef5672c9df
Signed-off-by: Ted Lin <tedlin@google.com>
2021-06-30 11:11:22 +08:00
Adam Shih
90ec2412b3 Merge "Avoid VTS testDataTypeViolators failure" into sc-dev am: 3ded724256
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126901

Change-Id: I3e3e0e580afbe6ccc971de2e81329495424c3b49
2021-06-30 02:04:32 +00:00
Adam Shih
3ded724256 Merge "Avoid VTS testDataTypeViolators failure" into sc-dev 2021-06-30 01:45:29 +00:00
George Lee
4aa936d63b pixelstats: add bcl directory permission
Bug: 186806028
Test: Local test
$>cmd stats print-logs
$>logcat | grep <atom id>

Signed-off-by: George Lee <geolee@google.com>
Change-Id: I7288a9ab44e2387d37c5442297cf80f5b5428c8f
2021-06-29 16:08:38 -07:00
Kevin Han
fc0c3c4939 Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev am: 1d54c8dd21
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145159

Change-Id: I70e74a9964444a39f9d0eeaca82394a8c6bbdc71
2021-06-29 19:50:38 +00:00
Kevin Han
1d54c8dd21 Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev 2021-06-29 19:33:01 +00:00
Kevin Han
fd47b11162 Revert "allow recovery and fastboot to access secure elment"
Revert "add gs101-specific recovery library"

Revert "recovery: enable support for device-specific WipeSe impl..."

Revert "clear secure element of Digital Car Keys during factory ..."

Revert submission 14983788-clear_keys

Reason for revert: b/192373955
Reverted Changes:
Ia8fc29e6c:add gs101-specific recovery library
Icc1eabfd4:clear secure element of Digital Car Keys during fa...
I943d97b26:recovery: enable support for device-specific WipeS...
I15c7fbd7f:allow recovery and fastboot to access secure elmen...

Change-Id: Ic576b40641171298ad840bedbd4a9f7b67052d95
2021-06-29 19:19:24 +00:00
TreeHugger Robot
f65af527f1 Merge "allow recovery and fastboot to access secure elment" into sc-dev am: be3d2bf325
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14681841

Change-Id: I77eaf28b2117143037257359078954d8c0e27dd1
2021-06-29 18:03:22 +00:00
TreeHugger Robot
be3d2bf325 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-29 17:50:35 +00:00
TreeHugger Robot
b9ab0e9c9d Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev am: 432ed9b527
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15135682

Change-Id: Ie2926714d97074c33ad052ff6ec87545451db8fb
2021-06-29 17:22:35 +00:00
TreeHugger Robot
432ed9b527 Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev 2021-06-29 17:04:07 +00:00
David Anderson
2354e3a924 Fix denial when flashing vendor_boot in fastbootd.
This mirrors the same sepolicy line in previous Pixel devices.

Bug: 189493387
Test: fastboot flash vendor_boot on r4
Change-Id: Ie15c8e6e5c01b249e1e5e244666c461253279f0b
2021-06-28 21:06:05 -07:00
Neo Yu
590f6c96f8 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev am: 9c27ce91c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126897

Change-Id: I585e6631ce4c913405d3b5fe2296391d30fe6c52
2021-06-29 03:20:31 +00:00
Neo Yu
9c27ce91c8 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev 2021-06-29 03:05:02 +00:00
TreeHugger Robot
64bc4eef75 Merge "Sepolicy: Remove permission for fuel gauge" into sc-dev am: 15f7a61603
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14782008

Change-Id: I4e3ad8b720a7b0436eca036ff61da27f0f559de8
2021-06-29 02:00:54 +00:00
TreeHugger Robot
15f7a61603 Merge "Sepolicy: Remove permission for fuel gauge" into sc-dev 2021-06-29 01:48:34 +00:00
TreeHugger Robot
960aaab672 Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev am: 22f27cb215
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456728

Change-Id: I747f7ab531ed52ce6f8312ed5360a9cd79d3ed29
2021-06-29 01:30:30 +00:00
neoyu
93944a8b1c Fix avc denied for getprop "vendor.radio.call_end_reason"
06-10 11:13:02.867 10224  2377  2377 W libc    : Access denied finding property "vendor.radio.call_end_reason"

Bug: 191204793
Test: error is gone with this fix
Change-Id: I50c1d21ba4e2343aa2cee0c533b8c3dbe535e4b5
2021-06-29 01:18:12 +00:00
TreeHugger Robot
22f27cb215 Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev 2021-06-29 01:16:35 +00:00
Adam Shih
f9501fc87c Avoid VTS testDataTypeViolators failure
Bug: 192209720
Test: run -m CtsSecurityHostTestCases -t android.security.cts.SELinuxHostTest
Change-Id: I9043c5adfb544179bceb0f6e5cf73c2b2ddd3d02
2021-06-29 07:58:57 +08:00
David Lin
4b6bc8cb32 ssr_detector_app: Add additional vendor dir and crgroup allow for debug
Bug: 192126013

Signed-off-by: David Lin <dtwlin@google.com>
Change-Id: Idadf81cf92099804f300f87fb1bedf9bed7decbd
2021-06-28 21:52:51 +00:00
TreeHugger Robot
8d6a3d96a2 Merge "Hardwareinfo: battery info porting" into sc-dev am: a63fbd68d4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608134

Change-Id: I9c8d1f7b0b57fa279557525d15cb307442390232
2021-06-28 16:33:20 +00:00
TreeHugger Robot
a63fbd68d4 Merge "Hardwareinfo: battery info porting" into sc-dev 2021-06-28 16:20:12 +00:00
Gazi Yamin Iqbal
4ea317bb6a gs101-sepolicy: allow rlsservice to read display status files
major changes:
        1. This change is to allow rlsservice to read the status of
        display status file. Similar method was employed in previous
        pixels.
Bug: 191122203
Test: p21 camera test checklist

Change-Id: I09483881294fd6dde46d4d0b7283311a2d20c404
2021-06-28 22:15:08 +08:00
TreeHugger Robot
25fa293ed4 Merge "gs101-sepolicy: add oemrilservice_app.te" into sc-dev am: 407d0cf58d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15072301

Change-Id: Id862fe0bb0c01337a933653f6885bde170cd0324
2021-06-27 01:56:09 +00:00
TreeHugger Robot
407d0cf58d Merge "gs101-sepolicy: add oemrilservice_app.te" into sc-dev 2021-06-27 01:47:21 +00:00
Jeffrey Carlyle
9ac870aa22 allow recovery and fastboot to access secure elment
This is to enable clearing of secure element during a master reset.

Bug: 182508814
Test: master reset on device with keys; verified no keys after reset
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I15c7fbd7f2c4fb34dcad0ae4f5cee3238f526fa5
2021-06-25 17:54:29 -07:00
sukiliu
6a881fe7d8 Update avc error on ROM 7492139 am: 7ea816284d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15100479

Change-Id: I8c91559f00aca5f79f366cc99d23290f04a9e159
2021-06-25 08:11:34 +00:00
sukiliu
7ea816284d Update avc error on ROM 7492139
avc: denied { call } for comm="servicemanager" scontext=u:r:servicemanager:s0 tcontext=u:r:hal_fingerprint_default:s0 tclass=binder permissive=0

Bug: 192040144
Test: PtsSELinuxTestCases
Change-Id: I2de11d2706222a88c4234d99399b7b2437f36e31
2021-06-25 14:40:17 +08:00
sukiliu
48a2a83361 Update avc error on ROM 7490489 am: e31c8840de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15100471

Change-Id: Ia5c201aeb91106643b2825bf3c530444af8ce7ec
2021-06-25 03:10:23 +00:00