Commit graph

1549 commits

Author SHA1 Message Date
Tri Vo
78011e9f3a storageproxyd: Remove setuid/setgid SELinux permissions
Bug: 205904330
Test: boot
Change-Id: Iefecc29752781151679e9f798330a36d14447df9
2022-07-15 11:07:47 -07:00
SalmaxChang
2455329536 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-44" ino=341 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 235963885
Change-Id: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
Merged-In: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
2022-07-08 03:24:01 +00:00
Adam Shih
bc85d46045 ignore shell access on wlc
Bug: 238038592
Test: boot
Change-Id: I09b67ca07d7f9573d77f64686fb818d4dc1753cc
2022-07-06 14:44:41 +08:00
TreeHugger Robot
ae60f4bc6d Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev am: 59d6e09682 am: df9d1731af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18871451

Change-Id: I354e568b012ef36d65a843185c2e4d1b7509c522
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 03:12:56 +00:00
TreeHugger Robot
df9d1731af Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev am: 59d6e09682
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18871451

Change-Id: I931993bfd0b94da00fed9e4ff6c25f95fdb9509a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:20 +00:00
TreeHugger Robot
59d6e09682 Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." into tm-qpr-dev 2022-07-01 02:15:21 +00:00
Xin Li
351260db12 Merge tm-dev-plus-aosp-without-vendor@8763363
Bug: 236760014
Merged-In: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
Change-Id: I0f66cef4179df45ee56af588df1fe1b82b0f642a
2022-06-27 23:37:34 +00:00
sashwinbalaji
7600ddd96b thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e am: cbbe4561a3 am: fcf9cbcb83
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I7468f221840e910a05136009d0639b5f96eef636
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 10:11:47 +00:00
sashwinbalaji
fcf9cbcb83 thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e am: cbbe4561a3
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I97cdd61e0634bce617d72d4543d856c709b3bddf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:54:20 +00:00
sashwinbalaji
cbbe4561a3 thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a am: 7bb947b88e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I4e27c835adfe73ef473b2afd2b303a36307e6ee9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:32:01 +00:00
sashwinbalaji
7bb947b88e thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I71bd9b49f2dc76e1e50f0b35bd404f7c8660d5d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:07:19 +00:00
sashwinbalaji
1a4cd82bc8 thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg files
Change-Id: Ia2a274ec3424bfeec25ae24e762f8ad41cb7ae86
2022-06-24 13:54:24 +08:00
SalmaxChang
a9157994c3 modem_svc: Fix avc error
avc: denied { write } for comm="modem_svc_sit" name="modem_stat" dev="dm-42" ino=331 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 234844823
Change-Id: I51db41d73be317cc7fc84981ac5f04e254a360d0
Merged-In: I51db41d73be317cc7fc84981ac5f04e254a360d0
2022-06-22 04:21:37 +00:00
SalmaxChang
0cef5e66fe hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d am: ba3c6036fc am: 8bbd5d3430 am: d3dba796f9
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: Ia6b24e15d0118326f253d0327d4a8e0cf874d879
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 03:26:10 +00:00
SalmaxChang
d3dba796f9 hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d am: ba3c6036fc am: 8bbd5d3430
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: Iecec85303b3b51cbd69f1ea8ca28448f0b0d80d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 03:07:39 +00:00
SalmaxChang
8bbd5d3430 hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d am: ba3c6036fc
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: I1fafe1f2fe007191a32368f82b06985038ea029c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 02:41:35 +00:00
SalmaxChang
ba3c6036fc hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: I9167e7032d77a57f41f2592378b551b60f09a375
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 02:24:59 +00:00
SalmaxChang
de88097de5 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-44" ino=341 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 235963885
Change-Id: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
2022-06-20 15:55:16 +08:00
Xin Li
cd158e3668 Merge "Merge Android 12 QPR 3" 2022-06-16 18:51:58 +00:00
TreeHugger Robot
5944f43530 Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad am: 2948419ca7 am: 263a6b0f8a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Ib00d0945b6ad99f81d54888c9cf54788c8f51241
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 13:00:38 +00:00
TreeHugger Robot
e8bc84e9cd Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad am: f3cb1d1dbd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Iff89da5b97cdb5c0d84042e4fbacae3fbeb9ae32
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:36:42 +00:00
TreeHugger Robot
263a6b0f8a Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad am: 2948419ca7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Ia303c50a81833a4abe489682f9ce4755f5660a88
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:36:40 +00:00
TreeHugger Robot
906d963a47 Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad am: 59ae6f320e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: I8a6b5bd58c6001584d5e41f4d9d81fc524e3d430
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:36:03 +00:00
TreeHugger Robot
2948419ca7 Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Ibe17ec9f6c2a396dc5f7b6e35e1b07b3b6b3356a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:19:33 +00:00
TreeHugger Robot
f3cb1d1dbd Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Ibd20fe601db9a6c55bf665cd61c4f93866987a7b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:18:03 +00:00
TreeHugger Robot
b20c0652ad Merge "allow rlsservice read vendor camera property" into tm-dev 2022-06-16 12:02:28 +00:00
Jidong Sun
81d0d5f20f Merge "gs101: Allow BootControl to access sysfs blow_ar" 2022-06-15 20:53:26 +00:00
matthuang
bf1333f881 Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: If9add3528bde47a618bd884ce28121b6fa32754c
2022-06-14 10:00:35 +00:00
Adam Shih
d472e161ae mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5 am: c68fe289e3 am: 5bf5ffc8d3 am: d8d5fd4374
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I75a4589877c5803c6facbb189bd36662c66d2274
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 06:29:36 +00:00
Adam Shih
d8d5fd4374 mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5 am: c68fe289e3 am: 5bf5ffc8d3
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I782454658aaca803869555cfc1179c2901ff3dc8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 06:10:27 +00:00
Adam Shih
5bf5ffc8d3 mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5 am: c68fe289e3
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I2afec41baa838d8db9ab23d9d01def68249d99c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 05:44:54 +00:00
Adam Shih
c68fe289e3 mute update_engine probing mnt_vendor_file am: 5889704eff am: 203f473af5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I15a18379ff4969dcb043e2fae94cf6c9f13ac834
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 05:18:34 +00:00
Adam Shih
203f473af5 mute update_engine probing mnt_vendor_file am: 5889704eff
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2124912

Change-Id: I289ba5aa69251d8575f4bd65fbeb7a38c3e03886
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-14 04:58:45 +00:00
Adam Shih
5889704eff mute update_engine probing mnt_vendor_file
Bug: 187016910
Test: boot to home
Change-Id: I5f7141f817b543a1499ef5826177f3ac4945e857
2022-06-14 02:58:58 +00:00
JimiChen
143668225a allow rlsservice read vendor camera property
Bug: 233020488
Test: no avc denied
Change-Id: I96dee4482d4c0ff5b7852db635dc100a7ea4874c
2022-06-11 15:39:19 +08:00
Krzysztof Kosiński
17b9e03aa4 gs101: Add dontaudit statements to camera HAL policy. am: fbcf66a04a am: fd0bf19589
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18817845

Change-Id: Ib9af5b903bd9a70cd27448af38a167659c6bc867
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 21:38:34 +00:00
Krzysztof Kosiński
bdd4ecc51c gs101: Add dontaudit statements to camera HAL policy. am: fbcf66a04a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18817845

Change-Id: I6138022efbcdc8ce149123399d3a8277e69c64b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 21:04:38 +00:00
Krzysztof Kosiński
fd0bf19589 gs101: Add dontaudit statements to camera HAL policy. am: fbcf66a04a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18817845

Change-Id: Ib4b8f284129e9c32dc5c4d4a145634f46ea346eb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 21:04:37 +00:00
Adam Shih
a4fbd61988 suppress warning on writing key am: d34b17e30e am: b982767162 am: f6c8f2e547 am: 2227e772cd am: a7f0c51176
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2122355

Change-Id: I6e5d3b9cbe22976677739bcaeed54ee2f179a65d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 09:31:44 +00:00
Adam Shih
a7f0c51176 suppress warning on writing key am: d34b17e30e am: b982767162 am: f6c8f2e547 am: 2227e772cd
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2122355

Change-Id: If4d03859fea11711c90b20ee2b52bc2e3fe26b14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 09:05:17 +00:00
Adam Shih
f6c8f2e547 suppress warning on writing key am: d34b17e30e am: b982767162
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2122355

Change-Id: I4fcb994efe51982b529dcc608fd9d30cd6b16291
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 08:25:25 +00:00
Adam Shih
b982767162 suppress warning on writing key am: d34b17e30e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2122355

Change-Id: Ic03d08a0f370647ccb0e4e06643b430b3337af69
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 08:05:26 +00:00
Adam Shih
d34b17e30e suppress warning on writing key
Bug: 235553565
Test: boot to home with no relevant error
Change-Id: I43bd360eabb55f504b48bb940d951d197256c593
2022-06-10 06:29:39 +00:00
Jidong Sun
61b72806e8 gs101: Allow BootControl to access sysfs blow_ar
Bug: 232277507
Signed-off-by: Jidong Sun <jidong@google.com>
Merged-In: I120672722a5ab8b5cadf0dce6d872e00c9fae642
Change-Id: I120672722a5ab8b5cadf0dce6d872e00c9fae642
2022-06-10 06:02:53 +00:00
Krzysztof Kosiński
fbcf66a04a gs101: Add dontaudit statements to camera HAL policy.
The autogenerated dontaudit statements in tracking_denials are
actually the correct policy. Move them to the correct file and
add comments.

Fix: 178980085
Fix: 180567725
Fix: 218585004
Test: build & camera check on raven
Change-Id: I3f3a1f64d403182d4f592f1cacc6ef8d1418062d
(cherry picked from commit b71d24d62c)
2022-06-09 20:53:05 +00:00
Jidong Sun
921ddd49e4 gs101: Allow BootControl to access sysfs blow_ar am: f276625942 am: 1745c41b8a am: 4f67f60276
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18740593

Change-Id: If2428dba144e5bff4eeb305318083e40cd82997f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-08 21:47:43 +00:00
Jidong Sun
804b82350b gs101: Allow BootControl to access sysfs blow_ar am: f276625942 am: cb8342916d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18740593

Change-Id: I2c6c3670ba5045c508efdd93756c80aed45ddf9b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-08 21:27:28 +00:00
Jidong Sun
4f67f60276 gs101: Allow BootControl to access sysfs blow_ar am: f276625942 am: 1745c41b8a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18740593

Change-Id: I8629636e059bf5c2a58c1c91dd10c9a1da7b2109
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-08 21:23:49 +00:00
Jidong Sun
1ca6610378 gs101: Allow BootControl to access sysfs blow_ar am: f276625942
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18740593

Change-Id: Ie359bb975e3e5315e910f33f3c69e16a9a0b2e32
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-08 20:30:32 +00:00
SalmaxChang
33cd2234df modem_svc: Fix avc error am: 1be95c2e33 am: cc38423bee am: b518f1e783 am: 1973c230c4 am: 70f66a06d4
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2116498

Change-Id: I5573e961fba98a34ffd4a4465ba980294b1514cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-07 09:05:15 +00:00