Commit graph

1549 commits

Author SHA1 Message Date
SalmaxChang
70f66a06d4 modem_svc: Fix avc error am: 1be95c2e33 am: cc38423bee am: b518f1e783 am: 1973c230c4
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2116498

Change-Id: If2b5397b8379c08620b2a9b4b79c9381f8e94a14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-07 08:40:21 +00:00
SalmaxChang
b518f1e783 modem_svc: Fix avc error am: 1be95c2e33 am: cc38423bee
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2116498

Change-Id: Ib768682c1848e24f7e78ecd20ce4041f368d8f2b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-07 07:48:21 +00:00
SalmaxChang
cc38423bee modem_svc: Fix avc error am: 1be95c2e33
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2116498

Change-Id: I2099f2e0371d6bfa2eb0e0784c9b6f38055ac09f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-07 07:29:39 +00:00
SalmaxChang
1be95c2e33 modem_svc: Fix avc error
avc: denied { write } for comm="modem_svc_sit" name="modem_stat" dev="dm-42" ino=331 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 234844823
Change-Id: I51db41d73be317cc7fc84981ac5f04e254a360d0
2022-06-06 20:36:44 +08:00
Jidong Sun
f276625942 gs101: Allow BootControl to access sysfs blow_ar
Bug: 232277507
Signed-off-by: Jidong Sun <jidong@google.com>
Change-Id: I120672722a5ab8b5cadf0dce6d872e00c9fae642
2022-06-04 01:23:40 +00:00
George Chang
3b0a628ef4 Update nfc from hidl to aidl service
Bug: 216290344
Test: atest NfcNciInstrumentationTests
Test: atest VtsAidlHalNfcTargetTest
Merged-In: I288474f691670655516728fe0e164a3e5689875c
Change-Id: I288474f691670655516728fe0e164a3e5689875c
2022-06-01 16:00:07 +00:00
George Chang
16cc944791 Merge "Update nfc from hidl to aidl service" into tm-qpr-dev 2022-06-01 06:19:39 +00:00
Jaegeuk Kim
3531538a25 Allow sysfs_devices_block to f2fs-tools
The fsck.f2fs checks the sysfs entries of block devices to get disk
information. Note that, the block device entries are device-specific.

1. fsck.f2fs
avc: denied { search } for comm="fsck.f2fs" name="0:0:0:0" dev="sysfs" ino=59803 scontext=u:r:fsck:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0
avc: denied { getattr } for comm="fsck.f2fs" path="/sys/devices/platform/14700000.ufs/host0/target0:0:0/0:0:0:0/block/sda/sda7/partition" dev="sysfs" ino=60672 scontext=u:r:fsck:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

2. mkfs.f2fs
avc: denied { search } for comm="make_f2fs" name="0:0:0:0" dev="sysfs" ino=59803 scontext=u:r:e2fs:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0
avc: denied { getattr } for comm="make_f2fs" path="/sys/devices/platform/14700000.ufs/host0/target0:0:0/0:0:0:0/block/sda/sda8/partition" dev="sysfs" ino=61046 scontext=u:r:e2fs:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

Bug: 172377740
Signed-off-by: Jaegeuk Kim <jaegeuk@google.com>
Change-Id: I409feec84565f965baa96b06a5b08bcfc1a8db02
2022-05-24 14:08:14 -07:00
Kyle Tso
5cd6559689 Add logbuffer_pogo_transfer file_contexts am: 7347d18b73 am: caa8dc57b3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18400416

Change-Id: I181abe83407195830c74490f4f5ca9790f1925c3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-24 01:25:51 +00:00
Kyle Tso
7347d18b73 Add logbuffer_pogo_transfer file_contexts
Bug: 232556226
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: I1037d39f4187807e6aa9753339fae29e3bc89359
Merged-In: I1037d39f4187807e6aa9753339fae29e3bc89359
2022-05-21 15:25:58 +00:00
George Chang
b75f28c76d Merge "Revert "Update nfc from hidl to aidl service"" am: 610af798f5 am: bd74710d56
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098183

Change-Id: I8a52af1a6344042571a4804c16c681d7981f38a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 16:34:07 +00:00
George Chang
bd74710d56 Merge "Revert "Update nfc from hidl to aidl service"" am: 610af798f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098183

Change-Id: I6db59e3a762df7b4906b0c14a7324b5955951c3d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 16:05:46 +00:00
George Chang
610af798f5 Merge "Revert "Update nfc from hidl to aidl service"" 2022-05-19 15:38:39 +00:00
George Chang
71db4c206b Revert "Update nfc from hidl to aidl service"
Revert submission 2098739-nfc_aidl_switch_gs101

Reason for revert: broken tests
Reverted Changes:
Ifde6ab418:Switch NFC from HIDL to AIDL
I288474f69:Update nfc from hidl to aidl service
Bug: 233194621
Change-Id: I1dad9c64073c8baffdf5f491c38bf1e568c9af29
2022-05-19 13:45:18 +00:00
Kyle Tso
a69cc7ca48 Merge "Add logbuffer_pogo_transfer file_contexts" am: 418d114796 am: 46b42ac02b am: 50797d0f2f am: d5e2b40846 am: 1f4c55de34
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098016

Change-Id: If2c8497fa93a0eff0edd91b3d8cc33151b9fc81b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 09:43:54 +00:00
Kyle Tso
50797d0f2f Merge "Add logbuffer_pogo_transfer file_contexts" am: 418d114796 am: 46b42ac02b
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098016

Change-Id: I41ef4daefa6a78ca4e3f7fa9a6464d43feda07ca
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 08:35:59 +00:00
George Chang
4b9fecbe3a Update nfc from hidl to aidl service am: d6a8c63837 am: 8985f2ae28
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098014

Change-Id: I8e04549075ae47a89994e2eed9b5e7f8eac170e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 08:35:44 +00:00
Kyle Tso
46b42ac02b Merge "Add logbuffer_pogo_transfer file_contexts" am: 418d114796
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098016

Change-Id: Ide608651968b6eb137aa55791074d66e3e27f947
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 07:56:40 +00:00
George Chang
8985f2ae28 Update nfc from hidl to aidl service am: d6a8c63837
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2098014

Change-Id: If2212cb63fdf409ee7f5fbf78994c58c09caa8ec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-19 07:55:22 +00:00
Kyle Tso
418d114796 Merge "Add logbuffer_pogo_transfer file_contexts" 2022-05-19 02:22:56 +00:00
Kyle Tso
94e2cdeb6e Add logbuffer_pogo_transfer file_contexts
Bug: 232556226
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: I1037d39f4187807e6aa9753339fae29e3bc89359
2022-05-17 16:01:46 +08:00
George Chang
d6a8c63837 Update nfc from hidl to aidl service
Bug: 216290344
Test: atest NfcNciInstrumentationTests
Test: atest VtsAidlHalNfcTargetTest
Merged-In: I288474f691670655516728fe0e164a3e5689875c
Change-Id: I288474f691670655516728fe0e164a3e5689875c
2022-05-17 12:16:39 +08:00
George Chang
d479f730b0 Update nfc from hidl to aidl service
Bug: 216290344
Test: atest NfcNciInstrumentationTests
Test: atest VtsAidlHalNfcTargetTest
Merged-In: I288474f691670655516728fe0e164a3e5689875c
Change-Id: I288474f691670655516728fe0e164a3e5689875c
2022-05-17 04:14:57 +00:00
TreeHugger Robot
99369be2b0 Merge "Allow mediacodec to access vendor_data_file" into tm-dev am: c0d38cbc9f am: 9ceae2ff96
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18186340

Change-Id: I44544211e779a729bec0686eb0ff1f8f4cb33c91
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:46:31 +00:00
TreeHugger Robot
a48761315f Merge "Allow mediacodec to access vendor_data_file" into tm-dev am: c0d38cbc9f am: ed1ec96363
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18186340

Change-Id: I294f324c4c26521cb7d8553e6127281826c30a1d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:44 +00:00
TreeHugger Robot
e9a23e8017 Merge "Allow mediacodec to access vendor_data_file" into tm-dev am: c0d38cbc9f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18186340

Change-Id: I6aa2cd70650dcebab561faf257d22d526a352052
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:48:07 +00:00
TreeHugger Robot
c0d38cbc9f Merge "Allow mediacodec to access vendor_data_file" into tm-dev 2022-05-13 09:24:01 +00:00
Lily Lin
ca85474dbe Merge "Add selinux permissions to r/w sysfs st33spi_state" into tm-dev am: e910a12468 am: 5389123249
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17988448

Change-Id: I619b1afeebbe51d58ba0b60fbe3dc2ac3733bc23
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 02:25:08 +00:00
Will McVicker
3dbfde7852 genfs_contexts: fix more i2c raw paths am: 9cbc9eceec am: 6c256f9fee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18192191

Change-Id: I4e9c3bf9cbe7e3d5d34fa0bda3d4260cc40cc479
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 02:25:02 +00:00
Lily Lin
0edffa70de Merge "Add selinux permissions to r/w sysfs st33spi_state" into tm-dev am: e910a12468 am: 4c32542348
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17988448

Change-Id: I2882c67018bcb6e25c0a962cd447a7ca41ecc760
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 02:24:22 +00:00
Will McVicker
e08258e33e genfs_contexts: fix more i2c raw paths am: 9cbc9eceec am: deccc1a295
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18192191

Change-Id: I8f5a74070ad7d04da2b1d44b1f53fd5cdfe88e9b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 02:24:01 +00:00
Lily Lin
d5f5a51c51 Merge "Add selinux permissions to r/w sysfs st33spi_state" into tm-dev am: e910a12468
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17988448

Change-Id: Ib7ad61c19257b34ca9028d2b0f3fd4ee76e37c89
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 01:56:03 +00:00
Lily Lin
e910a12468 Merge "Add selinux permissions to r/w sysfs st33spi_state" into tm-dev 2022-05-11 01:22:36 +00:00
Will McVicker
f78f5ab19a genfs_contexts: fix more i2c raw paths am: 9cbc9eceec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18192191

Change-Id: If52caa5df6e4008c9c038fe128f7e4f1e1f56c30
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-10 22:55:56 +00:00
Jerry Huang
a5e9b426eb Allow mediacodec to access vendor_data_file
For dumping output buffer of HDR to SDR fliter.

This patch fixes the following denial:

05-06 15:26:54.248  1046   856   856 W HwBinder:856_4: type=1400 audit(0.0:174404): avc: denied { getattr } for name="/" dev="dmabuf" ino=1 scontext=u:r:mediacodec:s0 tcontext=u:object_r:unlabeled:s0 tclass=filesystem permissive=0

Bug: 229360116
Change-Id: I41acb29407a7ddb27279a834e27c5ee515efe666
2022-05-10 09:22:12 +00:00
Lily Lin
59f29edf92 Add selinux permissions to r/w sysfs st33spi_state
Bug: 228655141
Test: Confirm can read/write st33spi_state
Change-Id: I65299414d6268580dc532170759459147378418b
2022-05-10 16:32:45 +08:00
Krzysztof Kosiński
b71d24d62c gs101: Add dontaudit statements to camera HAL policy.
The autogenerated dontaudit statements in tracking_denials are
actually the correct policy. Move them to the correct file and
add comments.

Fix: 178980085
Fix: 180567725
Test: build & camera check on raven
Change-Id: I3f3a1f64d403182d4f592f1cacc6ef8d1418062d
2022-05-10 05:34:51 +00:00
George Chang
650076c577 Merge "Update nfc from hidl to aidl service" 2022-05-06 07:07:19 +00:00
Will McVicker
9cbc9eceec genfs_contexts: fix more i2c raw paths
These were added in commit 8a19d8be9c ("genfs_contexts: fix path for
i2c peripheral devices") to address missing i2c paths when kernel
modules are loaded in parallel. The raw i2c paths were not added in that
commit. So add them here in order to fix a vibrator crash for
P21-mainline due to not having the named i2c paths.

Bug: 231637004
Fixes: 8a19d8be9c ("genfs_contexts: fix path for i2c peripheral devices")
Change-Id: I02dfff504704f761c99c328b39595789c2cbeef5
2022-05-05 16:04:31 -07:00
TreeHugger Robot
bbe95c3a79 Merge changes from topic "gs101-move-dwc3-irq" into tm-dev am: 36f7fe941d am: 82a83b366a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18164764

Change-Id: Ia31705514741c26b3ab34ecc21edb45e57ef89c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 08:46:04 +00:00
Ray Chi
d924169220 Allow hal_usb_gadget_impl to access proc_irq am: 7ac349e932 am: b5c3f6e0ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17313628

Change-Id: I96ba2776bb32556b1a3f01cf83cc3d0da63ea7fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 08:46:02 +00:00
Ray Chi
b5c3f6e0ba Allow hal_usb_gadget_impl to access proc_irq am: 7ac349e932
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17313628

Change-Id: I12709e8375ab34a1ed08ae48ce2db522d98f188c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 07:27:12 +00:00
TreeHugger Robot
36f7fe941d Merge changes from topic "gs101-move-dwc3-irq" into tm-dev
* changes:
  Revert "add sepolicy for set_usb_irq.sh"
  Allow hal_usb_gadget_impl to access proc_irq
2022-05-05 07:08:20 +00:00
Yichi Chen
e2a93ee001 Merge "Allow hal_fingerprint_default to access hal_pixel_display_service" into tm-dev am: 650209645c am: b2c0884cd9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17823364

Change-Id: I5ff9750abee568345789c6a2f9ad9d6df3eff8e3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:44:18 +00:00
Yichi Chen
43d6af291c Merge "Allow hal_fingerprint_default to access hal_pixel_display_service" into tm-dev am: 650209645c am: b2c0884cd9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17823364

Change-Id: I0c12bd8decf007033f42c492d149d6afb0a1244f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:44:17 +00:00
Yichi Chen
b83ddf305d Merge "Allow hal_fingerprint_default to access hal_pixel_display_service" into tm-dev am: 650209645c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17823364

Change-Id: I7fcfd0a6cfc006f2f68a5aa1d1e97f88ca321f38
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:17:59 +00:00
Yichi Chen
650209645c Merge "Allow hal_fingerprint_default to access hal_pixel_display_service" into tm-dev 2022-05-05 02:03:49 +00:00
George Chang
130f2b784e Update nfc from hidl to aidl service
Bug: 216290344
Test: atest NfcNciInstrumentationTests
Test: atest VtsAidlHalNfcTargetTest
Change-Id: I288474f691670655516728fe0e164a3e5689875c
2022-05-05 01:13:59 +08:00
William McVicker
d5094282b6 Merge "genfs_contexts: add raw i2c-s2mpg10mfd and i2c-s2mpg11mfd nodes" into tm-dev am: e6250cd86e am: 18cb713b62
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18123741

Change-Id: Ie615dcd13480e7cc91195c8726ebbc13e2225342
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-04 17:12:51 +00:00
William McVicker
cd65dd36d5 Merge "genfs_contexts: add raw i2c-s2mpg10mfd and i2c-s2mpg11mfd nodes" into tm-dev am: e6250cd86e am: 18cb713b62
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18123741

Change-Id: Idef6f9e9c77289b596a2346817e37e3f555d4361
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-04 17:10:26 +00:00