Commit graph

1549 commits

Author SHA1 Message Date
Lucas Wei
6ef92ee0d1 Merge "votable: Update don't audit file entry" 2023-02-16 06:00:51 +00:00
Lucas Wei
5a70bbb335 votable: Update don't audit file entry
Test: No votable avc errors in dmesg
Bug: 247905787
Change-Id: I95ab4dd7750e9b0f26d41fece50dc6d0aa73dd41
Signed-off-by: Lucas Wei <lucaswei@google.com>
2023-02-15 02:49:08 +00:00
Treehugger Robot
580fb1061d Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f am: 60fc07a2f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I269fe35ddd8dc13df7b275a84f86955e2853563a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 20:44:30 +00:00
Treehugger Robot
60fc07a2f5 Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I624db1bdd6fbe5de7d774954f5390fb0af884b77
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 19:41:20 +00:00
Treehugger Robot
114e2a377f Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: Ib469bb013d0c7335e2da4f429cde4c5df9395ed5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 18:56:35 +00:00
Ray Chi
beacc5b05f [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
(cherry picked from commit 9828cc747a)
Merged-In: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-14 18:13:34 +00:00
Treehugger Robot
b72bb4c53f Merge "Map AIDL Gatekeeper to same policy as HIDL version" 2023-02-14 17:48:17 +00:00
Adam Shih
9a7bb8df86 Move memory dump to gs-common
Bug: 240530709
Test: adb bugreport
Change-Id: I78433d8d170af54a4daee6c9a9218ce35e78e730
2023-02-13 14:56:30 +08:00
Subrahmanyaman
b4ec2efe4b Map AIDL Gatekeeper to same policy as HIDL version
Bug: 268342724
Test: VtsHalGatekeeperTargetTest
Change-Id: I050860bfeb0e87830e554ed19bc1efe54e7db0a5
2023-02-08 18:37:15 +00:00
Ken Yang
8e9fa12996 Merge "WLC: Add required sysfs_wlc sepolicies" 2023-02-05 02:30:37 +00:00
Ray Chi
4003532648 [ DO NOT MERGE ] usb: Add sepolicy for extcon access am: 9828cc747a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: I2c4f5571065ac696d32f5050d6b94f7957ddce3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 04:37:04 +00:00
Nicolas Geoffray
f485d48f43 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108 am: fa4c9c92e0
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Ia166fb782bc79702f9f064cf326af5872bfc1fb4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:54:42 +00:00
Nicolas Geoffray
fa4c9c92e0 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Iab23f2032100e1105e1f1edaee8a4dd90f7ec2d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:25:08 +00:00
Nicolas Geoffray
0090218108 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: I510f6f8cc0dc2c609ec46a901738374bfd9d3217
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 15:34:58 +00:00
TreeHugger Robot
5dbdb799e8 Merge "[ DO NOT MERGE ] usb: Add sepolicy for extcon access" into tm-qpr-dev 2023-02-03 14:47:47 +00:00
Taylor Nelms
c2769f1ede Modify permissions to allow dumpstate process to access decon_counters node am: ae39e117c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21041858

Change-Id: I469375e8d9bf2fed575bbb9f972f4eeaa45fbb15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 13:47:31 +00:00
Nicolas Geoffray
514eb95f8e Allow ssr_detector_app directory creation in system_app_data_file.
Bug: 260557058
Test: m
Change-Id: Iad7bb0609d7ca3ae89d6583ba3638e36300538a1
2023-02-03 13:06:50 +00:00
Ray Chi
9828cc747a [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-02 15:22:33 +08:00
Ken Yang
fcb9c033a1 WLC: Add required sysfs_wlc sepolicies
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.

Bug: 267171670
Change-Id: Ic4dca7a34e8ed9b096a650b1df4bb58290425117
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-31 15:02:51 +00:00
Taylor Nelms
ae39e117c1 Modify permissions to allow dumpstate process to access decon_counters node
Bug: 240346564
Test: Build for Oriole device with "user" build,
check bugreport for decon_counters content
Merged-In: I71883632857e76cfead39b16560b3695e13a6746
Change-Id: I010a9e8809192a5a1ee5842d5ac973d874836cea
Signed-off-by: Taylor Nelms <tknelms@google.com>
2023-01-19 14:14:25 +00:00
Victor Barr
5eea830c6e Move Support for DBA HAL in common edgetpu packages
Previously supported in some cases. Now extend it to all common cases.

Bug: 263394888
Test: Built and ran DBA HAL on Android Device
Change-Id: I70db1fae6b9f5787c635bb2fcbabc7ee0e064a9f
2023-01-17 18:42:26 +00:00
Ken Yang
fc2efe09bd Merge "WLC: Cleanup the sysfs_wlc policies" 2023-01-13 14:41:30 +00:00
Kyle Zhang
bfbf488408 Merge "Add hal_drm_widevine for Widevine exec sepolicy" 2023-01-11 05:37:46 +00:00
Ken Yang
a49c3a5479 WLC: Cleanup the sysfs_wlc policies
The sepolicy must be self-contained without including wirelss_charger to
avoid build break in AOSP

Bug: 263830018
Change-Id: I4eee380ae61f83c5563ee8842a94fd1fb9e520ef
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-10 16:02:31 +00:00
Kyle Zhang
902db3961f Add hal_drm_widevine for Widevine exec sepolicy
Bug: 243699259
Test: atp v2/widevine-eng/drm_compliance
Change-Id: Ifede19e690cb7b7333016df08fb146a0ec8f7409
2023-01-06 03:14:20 +00:00
Chungkai Mei
f5ee8054e0 sepolicy: fix avc denial
fix avc denial when applying aosp/2333702

Bug: 261678056
Test: boot without avc denial
Change-Id: I4674a5cb13f2f06f011c380699353b1a561ad290
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-01-05 09:40:42 +00:00
Ken Yang
8c2188f24e Merge "WLC: Add gs101 specific sepolicy for wireless_charger" 2022-12-21 08:36:14 +00:00
Taylor Nelms
66bf88de5d Merge "Modify permissions to allow dumpstate process to access decon_counters node" 2022-12-21 01:41:40 +00:00
Ken Yang
33f94a5428 WLC: Add gs101 specific sepolicy for wireless_charger
Bug: 237600973
Change-Id: If25a921ba9f0261c7f71cb88425526f307df9064
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-21 00:49:26 +00:00
Devin Moore
d1ba957ec2 Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f am: ae8eb694fa
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I16211b9a52338bbf7569508877305dbc66d5228b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 21:46:17 +00:00
Devin Moore
ae8eb694fa Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I74400a040ba88d35a9eda207eb6eabf712627799
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 20:57:13 +00:00
Devin Moore
aede443b86 Allow pixelstats hal to talk to the new AIDL sensorservice
This is being used in libsensorndkbridge now, so permissions are
required.

Test: m
Bug: 205764765
Change-Id: I65945c8b259538d274da23d8ecc6cf4d2362dcbd
2022-12-19 23:42:23 +00:00
TreeHugger Robot
5aa010e054 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev am: ca047e8607 am: ad5f8a13d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20502509

Change-Id: I79eaaa294adfa16f32362e2c5134f783c8aaa352
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-19 14:23:42 +00:00
TreeHugger Robot
ad5f8a13d3 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev am: ca047e8607
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20502509

Change-Id: Iadf35d359d83215d410f1aa7f1e135d56af9acb0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-19 13:43:37 +00:00
TreeHugger Robot
ca047e8607 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev 2022-12-19 12:53:32 +00:00
Taylor Nelms
807f7b2efa Modify permissions to allow dumpstate process to access decon_counters node
Bug: 240346564
Test: Build for Oriole device with "user" build, check bugreport for decon_counters content
Change-Id: I71883632857e76cfead39b16560b3695e13a6746
Signed-off-by: Taylor Nelms <tknelms@google.com>
2022-12-16 16:51:12 +00:00
Adam Shih
1d6ed7613e ignore shell access on wlc am: 1d7352fb4d am: c4c7dd1c1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20677863

Change-Id: Ia2fb569bf4a8cae8a8cc51231af9dd055b3e3b1c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 07:55:37 +00:00
Adam Shih
c4c7dd1c1a ignore shell access on wlc am: 1d7352fb4d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20677863

Change-Id: Ie42a4a9910f006c85ab945ec22486fdbaeb12e6f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 06:50:26 +00:00
Adam Shih
a1c4ddc9d1 ignore shell access on wlc am: 85bd1b8441 am: 6aa1118205
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2342468

Change-Id: I3161158edbda30465251134c06ae025184cd95c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-12 04:19:18 +00:00
Adam Shih
85bd1b8441 ignore shell access on wlc
Bug: 261804136
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-12-11 21:22:10 +08:00
Nicolas Geoffray
677dcd1685 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755 am: 5db7a3cc58 am: ed07258d24
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: I1a44378cddf8b63c5a67e34786cfc76c75492f73
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 21:07:53 +00:00
Nicolas Geoffray
ed07258d24 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755 am: 5db7a3cc58
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: Ic617201bc7a2ad7cbbda299f8867a7caff023aed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 20:18:06 +00:00
Nicolas Geoffray
5db7a3cc58 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: I123395fa5a397e17aeaf7cec155cf00be7af8682
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 19:31:29 +00:00
Nicolas Geoffray
356b4a4755 Also put .ShannonImsService in the vendor_ims_app domain.
For consistency when running com.shannon.imsservice code.

Test: m
Bug: 260557058
Change-Id: I5242479d32eb9362326544516c06e6a52cd30a6e
2022-12-08 14:39:19 +00:00
Adam Shih
1d7352fb4d ignore shell access on wlc
Bug: 261804136
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
Merged-In: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-12-08 17:59:16 +08:00
Adam Shih
58c0e3bb7c Merge "remove sysfs_touch setting" 2022-12-06 02:59:39 +00:00
Nicolas Geoffray
2c4c8f80d3 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664 am: a18011cd14 am: 74042321e2
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: Ic3e7cd5192a3b7bbe37aab6c53e51d011b5c1228
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 18:12:32 +00:00
Nicolas Geoffray
74042321e2 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664 am: a18011cd14
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: Ie3562efa20cadd63f2bfbaa5949f28c78d49ded5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:31:48 +00:00
Nicolas Geoffray
a18011cd14 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: I9e14e98f8c66f18e7256dffeaa7eebe5a4f54567
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:01:25 +00:00
Nicolas Geoffray
594052a664 Allow ssr_detector_app to create files of type system_app_data_file.
Bug: 260557058
Test: m
Change-Id: I8545deddd64d7eec61c5065f364a87b8726b1472
2022-12-05 13:56:52 +00:00