Commit graph

1025 commits

Author SHA1 Message Date
Aaron Ding
5825ee37e3 Revert "pixel-selinux: add SJTAG policies" am: b078284e5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14528664

Change-Id: I05c1e374972a89fe6d5dcd75f4c8fe41b383f3ff
2021-05-31 18:46:59 +00:00
Aaron Ding
2d35ae6cb8 Revert "pixel-selinux: add SJTAG policies" am: b078284e5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14528664

Change-Id: I819e31237595331138b5230a77d5f85dbd368bc0
2021-05-31 18:43:52 +00:00
Aaron Ding
b078284e5d Revert "pixel-selinux: add SJTAG policies"
This reverts commit bc525e1a49.

Bug: 186500818
Change-Id: I0bab67d42530270a819598ac320a5946e5d7aa6d
Signed-off-by: Aaron Ding <aaronding@google.com>
2021-06-01 01:21:14 +08:00
Vova Sharaienko
a4660c88a9 Merge "hal_health_default: updated sepolicy" into sc-dev am: ce4002966a am: 977bc88d0b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14738712

Change-Id: I75846a70a82ecd1762fb9dbd20117d8627d8998e
2021-05-28 18:29:50 +00:00
Vova Sharaienko
d0fa6b0ab5 Merge "hal_health_default: updated sepolicy" into sc-dev am: ce4002966a am: e133184c45
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14738712

Change-Id: I9358a2cc6de91a13c46e868d8b80ae4cedc00758
2021-05-28 18:19:43 +00:00
Vova Sharaienko
977bc88d0b Merge "hal_health_default: updated sepolicy" into sc-dev am: ce4002966a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14738712

Change-Id: I4ea468c2ebfdec8a35bfb02897f411bb8c814f22
2021-05-28 18:06:52 +00:00
Vova Sharaienko
e133184c45 Merge "hal_health_default: updated sepolicy" into sc-dev am: ce4002966a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14738712

Change-Id: I19ce2ef9b6f771d35036dcd5fd8217bc8eb8219a
2021-05-28 17:59:27 +00:00
Vova Sharaienko
ce4002966a Merge "hal_health_default: updated sepolicy" into sc-dev 2021-05-28 17:42:45 +00:00
Rick Yiu
25f9147d6e Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev am: 6c5779d0af am: 8b7354ea6c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14692150

Change-Id: I3a8ec644efa86e0e059ff043edfcce44e7e871d1
2021-05-28 02:09:45 +00:00
Rick Yiu
94af2e728b Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev am: 6c5779d0af am: 32838e85d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14692150

Change-Id: I4723916265a0301e4cb5b0bfac9e71e5c86acbc2
2021-05-28 02:06:23 +00:00
Rick Yiu
32838e85d8 Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev am: 6c5779d0af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14692150

Change-Id: I1b2c4fb8582bf71543ea0c115f369dbb6f8abe9b
2021-05-28 01:44:23 +00:00
Rick Yiu
8b7354ea6c Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev am: 6c5779d0af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14692150

Change-Id: I5cdb6420dd45a50867d20a3b1ec97b1989af7a53
2021-05-28 01:40:56 +00:00
Rick Yiu
6c5779d0af Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev 2021-05-28 01:16:34 +00:00
Vova Sharaienko
144b6b06b3 hal_health_default: updated sepolicy
This allows the android.hardware.health service to access
AIDL Stats service

Bug: 186578402
Test: Build, flash, boot & and logcat | grep "avc"
Change-Id: I1bfd8dbca4a8a87387c5fc0cc47b9f09a6d07ea4
2021-05-27 01:51:21 +00:00
Harpreet Eli Sangha
e952c414ec Add CccDkTimeSyncService
Bug: 183676280
Test: Build and run example client.
Signed-off-by: Harpreet Eli Sangha <eliptus@google.com>
Change-Id: I862d5f3e8be3cf7d23489be374fabf26e29e0ca5
2021-05-26 16:59:51 +00:00
TreeHugger Robot
61d2448998 Merge "Add sepolicy for Trusty keymint" into sc-dev am: 9e9c6a75da am: 51a593d480
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14414676

Change-Id: I74bd030d4720f08730ea6fe8bffbf3c314a07b5b
2021-05-26 14:09:52 +00:00
TreeHugger Robot
2acb9f0f89 Merge "Add sepolicy for Trusty keymint" into sc-dev am: 9e9c6a75da am: 607ba868d5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14414676

Change-Id: I1a2b71b4577ffe4e3cafc69e64b9adc356fe9140
2021-05-26 14:08:54 +00:00
TreeHugger Robot
607ba868d5 Merge "Add sepolicy for Trusty keymint" into sc-dev am: 9e9c6a75da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14414676

Change-Id: I770a835945c9c73226bcbeaf06120cadb6af5cd0
2021-05-26 13:46:37 +00:00
TreeHugger Robot
51a593d480 Merge "Add sepolicy for Trusty keymint" into sc-dev am: 9e9c6a75da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14414676

Change-Id: I5e2c27949cd69819a9aa12da921494adefa16606
2021-05-26 13:44:53 +00:00
TreeHugger Robot
9e9c6a75da Merge "Add sepolicy for Trusty keymint" into sc-dev 2021-05-26 13:23:20 +00:00
sukiliu
498d13f245 Update avc error on ROM 7395282 am: 073a0f5ed1 am: 826d258fcf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14717075

Change-Id: I96c0146d4c54620b6967f5494cac1d46450de195
2021-05-26 05:14:25 +00:00
sukiliu
af73c8c528 Update avc error on ROM 7395282 am: 073a0f5ed1 am: 248d61e87a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14717075

Change-Id: I38be92b164e8d52e1413f31466c07e9999f02609
2021-05-26 05:12:26 +00:00
sukiliu
248d61e87a Update avc error on ROM 7395282 am: 073a0f5ed1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14717075

Change-Id: I40f8e723d005fad45b4ba480fbc456cb34360910
2021-05-26 04:56:37 +00:00
sukiliu
826d258fcf Update avc error on ROM 7395282 am: 073a0f5ed1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14717075

Change-Id: Ifa05ac25bfcf263c9cac8584420b17bb84fce60c
2021-05-26 04:54:42 +00:00
sukiliu
073a0f5ed1 Update avc error on ROM 7395282
avc: denied { dac_override } for comm="rebalance_inter" capability=1 scontext=u:r:rebalance_interrupts_vendor:s0 tcontext=u:r:rebalance_interrupts_vendor:s0 tclass=capability permissive=0

Bug: 189275648
Test: PtsSELinuxTestCases
Change-Id: I637f1fcd901b8bf59096ba83c927b4d353f0405b
2021-05-26 11:11:03 +08:00
Shawn Willden
c5fdb59287 Add sepolicy for Trusty keymint
Bug: 177729159
Test: VtsAidlKeyMintTargetTest on P21
Change-Id: I993faa2a829d3ad4f1b920ff59ba4fd5ef8e7db7
2021-05-25 16:37:29 -06:00
TreeHugger Robot
0578de6766 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032 am: a85442bd10
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012

Change-Id: Id12fcf0e304c0bf06261ec1032a7b12577e6b4b8
2021-05-25 19:30:55 +00:00
TreeHugger Robot
efe8194fe0 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032 am: 1e8934b03c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012

Change-Id: I728c697e49d26bc6d69d207d65599ca3e9a058c9
2021-05-25 19:29:59 +00:00
TreeHugger Robot
1e8934b03c Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012

Change-Id: Id748c228fb796c76ccc01d3b19f829928c185adf
2021-05-25 19:07:26 +00:00
TreeHugger Robot
a85442bd10 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012

Change-Id: Ib1fe025493a3021d69bf7f79c8809098933ba1b8
2021-05-25 19:05:23 +00:00
TreeHugger Robot
477e19f032 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev 2021-05-25 18:45:37 +00:00
TreeHugger Robot
be0ea48cef Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: cb80570b92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: Ifa1536ee09f4cd8b3c048001798d5a2b6368bd70
2021-05-25 11:58:29 +00:00
TreeHugger Robot
667ba8cb19 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: eeb41949c2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I87d15c071e3de40b367badbe185db35cc14bb332
2021-05-25 11:51:11 +00:00
TreeHugger Robot
cb80570b92 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I594759be23e922d975f395da8a1d363925dc30ca
2021-05-25 11:50:55 +00:00
TreeHugger Robot
eeb41949c2 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I7a32e0b2bcef407665e75e58d0af2db52c08323b
2021-05-25 11:49:35 +00:00
TreeHugger Robot
57eefb5b13 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev 2021-05-25 10:12:38 +00:00
Ocean Chen
b8aebc85e1 storage: update sepolicy for hardwareinfoservice
avc: denied { search } for name="0:0:0:0" dev="sysfs" ino=57525 scontext=u:r:hardware_info_app:s0:c512,c768 avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo

avc: denied { read } for name="vpd_pg80" dev="sysfs" ino=57559 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="model" dev="sysfs" ino=57534 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vendor" dev="sysfs" ino=57533 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="rev" dev="sysfs" ino=57535 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="eol_info" dev="sysfs" ino=57020 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="life_time_estimation_a" dev="sysfs" ino=57021 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo

Bug: 188755652
Test: reboot then check hardwareinfo and avc denined log
Change-Id: Ia03ebdd6b0b46b4c9ace5fbf1fc47a455a55abcb
2021-05-25 16:57:20 +08:00
Roger Fang
594eecad3e Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 21d7509c17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I1d70340b2152d73bec3d51651bb10f68e91952ae
2021-05-25 01:49:44 +00:00
Roger Fang
8522122b5f Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 292faf8ed3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I9278fff7d05c8e65bd8a9e4d39cc4a1a380ca10f
2021-05-25 01:47:48 +00:00
Roger Fang
292faf8ed3 Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I929b5c4b1f37c2e0d8bee655fc0141a5a0bbbd4e
2021-05-25 01:24:04 +00:00
Roger Fang
21d7509c17 Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: If394b6c1a719b26a295b97980b94fb217442ef76
2021-05-25 01:22:03 +00:00
Roger Fang
56cbfd5a0a Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev 2021-05-25 01:02:39 +00:00
Ines Ayara
b311856023 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 304a92ea86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I1c76cbd2013a9a3b4c8ca34184796a5a2719fdba
2021-05-25 00:41:40 +00:00
Ines Ayara
23ccf9362e Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 1a7f873b06
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I330983da9a9c6d35f341c15cb5c367e3be7a6ce7
2021-05-25 00:39:48 +00:00
Ines Ayara
1a7f873b06 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I46ee22509e42f4baf7df226b2e2eedcf3ecfaa6c
2021-05-25 00:18:54 +00:00
Ines Ayara
304a92ea86 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: Ie52a7d786c4344a7ba0e8bf6bbba87ae7f9d0999
2021-05-25 00:16:44 +00:00
Vinay Kalia
68849437bd Allow mediacodec to access the vframe-secure DMA-BUF heap
This patch fixes the following denial:

HwBinder:751_2: type=1400 audit(0.0:9): avc: denied { open } for
path="/dev/dma_heap/vframe-secure" dev="tmpfs" ino=734
scontext=u:r:mediacodec:s0 tcontext=u:object_r:vframe_heap_device:s0
tclass=chr_file permissive=0

Bug: 188121584
Test: AV1 secure video playback

Signed-off-by: Vinay Kalia <vinaykalia@google.com>
Change-Id: I455b39914dd4316a427f5f756b4fb94a2c4db204
2021-05-24 23:57:28 +00:00
Ines Ayara
dfb3783187 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev 2021-05-24 23:55:32 +00:00
Roger Fang
a97bfcc1e1 sepolicy: gs101: add permission for the hardware info dsp part number
Bug: 188757638
Test: Manually test passed

Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: Id0c3226411b058b613b92e67174f14e64c6c3a2b
2021-05-24 08:16:34 +00:00
Chase Wu
373fed0402 Merge "genfs_contexts: fix path for cs40l25a i2c devices" into sc-v2-dev am: 80ab102382
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14675588

Change-Id: Id5204cd25e6fa512e485fc771cd1982b0e8f55dd
2021-05-24 01:20:31 +00:00