Commit graph

1066 commits

Author SHA1 Message Date
Franklin He
c53c03b843 Add new sepolicy to allow Power Hint
SELinux policy changes to work with https://googleplex-android-review.git.corp.google.com/c/device/google/gs101/+/14997393
This allows the NNAPI HAL to make IPC calls to the Power HAL in order to request power hints

Bug: 191241561
Test: Pushed new SEPolicy to device, verified no AVC problems when making IPC calls
Change-Id: I8209b3677bedf908901389c07304f4478d0431b0
2021-06-17 07:59:11 +00:00
Yuriy Romanenko
14786d9b40 Allow rlsservice/camera HAL to read /apex/apex-info-list.xml
To detect apex updates

Bug: 188246923
Test: See topic
Change-Id: I28a27741c1c285f8b49a2aa50bc0665143c1b7cb
2021-06-16 20:55:38 -07:00
TreeHugger Robot
9f15636f26 Merge "vendor_telephony_app.te: add selinuxfs:file" into sc-dev am: 502b653380 am: a62f3266fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963703

Change-Id: Idd8908e2cc25bcdafcc932e09335ccc6bf037dc7
2021-06-17 02:05:07 +00:00
TreeHugger Robot
00d192d4d7 Merge "vendor_telephony_app.te: add selinuxfs:file" into sc-dev am: 502b653380 am: c3d33dfd8f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963703

Change-Id: I197b8a0d86df33a98610bbcbf6b7567a23319862
2021-06-17 02:04:42 +00:00
TreeHugger Robot
c3d33dfd8f Merge "vendor_telephony_app.te: add selinuxfs:file" into sc-dev am: 502b653380
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963703

Change-Id: Id126e3c4849db6a693458c67215c81e08c33c1a2
2021-06-17 01:44:20 +00:00
TreeHugger Robot
a62f3266fc Merge "vendor_telephony_app.te: add selinuxfs:file" into sc-dev am: 502b653380
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963703

Change-Id: Id09fec7d2642bf8e67bd9425240408bc40728164
2021-06-17 01:43:19 +00:00
Yu-Chi Cheng
101842ba63 Allowed EdgeTPU compilation services (tflite and nnapi) to access am: 643e5a7123 am: 067e314a35
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15004632

Change-Id: I887964815acf4b80d14c51bec8cf21978fe54ad7
2021-06-17 01:29:36 +00:00
Yu-Chi Cheng
a46c57c1b2 Allowed EdgeTPU compilation services (tflite and nnapi) to access am: 643e5a7123 am: 66aac3e71f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15004632

Change-Id: Ia5c85b77e9dc6a4458c1e2f79b590f556c95569d
2021-06-17 01:29:19 +00:00
TreeHugger Robot
502b653380 Merge "vendor_telephony_app.te: add selinuxfs:file" into sc-dev 2021-06-17 01:14:20 +00:00
Yu-Chi Cheng
66aac3e71f Allowed EdgeTPU compilation services (tflite and nnapi) to access am: 643e5a7123
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15004632

Change-Id: I6d0883541ad8f5796cc0ef7ae8ca7fb9827ce5f2
2021-06-17 01:09:50 +00:00
Yu-Chi Cheng
067e314a35 Allowed EdgeTPU compilation services (tflite and nnapi) to access am: 643e5a7123
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15004632

Change-Id: I1c51e2b2c1d0afb0f3660ccc30cf1db51888d644
2021-06-17 01:08:59 +00:00
Yu-Chi Cheng
643e5a7123 Allowed EdgeTPU compilation services (tflite and nnapi) to access
overcommit_memory info.

This is required as part of the compilation process, likely part of
the jemalloc which was added recently.

Bug: 190790251
Test: verified on local P21 device.
Change-Id: I4d90ea92afd7beaa4c4efa6ed509d703764932a1
2021-06-16 16:17:14 -07:00
Craig Dooley
3031b077a3 Allow hal_dumpstate to collect AoC statistics
Bug: 188114650
Signed-off-by: Craig Dooley <dooleyc@google.com>
Change-Id: Iba5525af2c651070b9a5f7769c0439ef320d666b
2021-06-16 17:18:55 +00:00
TreeHugger Robot
939fb40006 Merge "Add sepolicy for hwcomposer to access lhbm sysfs" into sc-dev am: 11ebd6122e am: 632d66fb17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14234767

Change-Id: Iaa50e2fe622b0ddf8f4a04a4a84d152c90c4c58d
2021-06-16 14:24:41 +00:00
TreeHugger Robot
fc7440d590 Merge "Add sepolicy for hwcomposer to access lhbm sysfs" into sc-dev am: 11ebd6122e am: 41e4576f08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14234767

Change-Id: Ibd1300cb652041eaf78338aeb386bb1b1587c403
2021-06-16 14:21:03 +00:00
TreeHugger Robot
632d66fb17 Merge "Add sepolicy for hwcomposer to access lhbm sysfs" into sc-dev am: 11ebd6122e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14234767

Change-Id: Id3396b6103d217649292ec4338e72d4a52fdf18e
2021-06-16 14:05:25 +00:00
TreeHugger Robot
41e4576f08 Merge "Add sepolicy for hwcomposer to access lhbm sysfs" into sc-dev am: 11ebd6122e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14234767

Change-Id: I68363c30b1d6c3668434d277c542ef31a0d2419b
2021-06-16 14:04:36 +00:00
TreeHugger Robot
11ebd6122e Merge "Add sepolicy for hwcomposer to access lhbm sysfs" into sc-dev 2021-06-16 13:51:37 +00:00
Adam Shih
31bf6f0384 Merge "remove vcd from user ROM" into sc-dev am: 2cdde93f15 am: f6940b0869
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934449

Change-Id: Ieffc9613783fbbfe0f77202cb5c9fbaea2e25cf7
2021-06-16 07:09:38 +00:00
Adam Shih
ee90e93ae7 Merge "remove vcd from user ROM" into sc-dev am: 2cdde93f15 am: 56f9c7730f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934449

Change-Id: I1a765518eb1b37354ba9ea0d5cd75e913de448cd
2021-06-16 07:09:17 +00:00
Adam Shih
56f9c7730f Merge "remove vcd from user ROM" into sc-dev am: 2cdde93f15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934449

Change-Id: Idceee76892481baf7c7c6339f088f003a7e735f3
2021-06-16 06:54:18 +00:00
Adam Shih
f6940b0869 Merge "remove vcd from user ROM" into sc-dev am: 2cdde93f15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934449

Change-Id: Ieb5700288ed53a6d904fe01d790567b1d1704b55
2021-06-16 06:53:24 +00:00
Adam Shih
2cdde93f15 Merge "remove vcd from user ROM" into sc-dev 2021-06-16 06:40:28 +00:00
TreeHugger Robot
12454301ca Merge "Use label persist_ss_file" into sc-dev am: 6550281b13 am: a0e1a8e2e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: Ibae22f2f82d9535fb30162fa85905599c04bac59
2021-06-16 06:33:37 +00:00
TreeHugger Robot
240f424f7f Merge "Use label persist_ss_file" into sc-dev am: 6550281b13 am: 0bf84fa3c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I14fa68f9b1f25af6f98badc583505fa4c39d3755
2021-06-16 06:33:18 +00:00
TreeHugger Robot
0bf84fa3c0 Merge "Use label persist_ss_file" into sc-dev am: 6550281b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I4336b65c246f69138f6534fc76ea12ead51f786e
2021-06-16 06:04:59 +00:00
TreeHugger Robot
a0e1a8e2e4 Merge "Use label persist_ss_file" into sc-dev am: 6550281b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I7cfd671dd52f5422b317a6cd2f12847f65ee9a13
2021-06-16 06:04:10 +00:00
TreeHugger Robot
6550281b13 Merge "Use label persist_ss_file" into sc-dev 2021-06-16 05:45:04 +00:00
SHUCHI LILU
537f9f01a7 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: e79f75aa16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I052084f819b62d04b9c1f307f337497910163f5b
2021-06-16 04:18:20 +00:00
SHUCHI LILU
e79f75aa16 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I754282c66d68a873edd9b89919890d293bf90084
2021-06-16 04:01:22 +00:00
SHUCHI LILU
a97f039001 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: 994d1f49da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I3f55acc9eebab648af2f454f2835df7c6d4aab2f
2021-06-16 02:07:02 +00:00
SHUCHI LILU
994d1f49da Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: If63ce2fb708833204108e529a8b9962cceff5d4c
2021-06-16 01:48:37 +00:00
SHUCHI LILU
5624d07640 Merge "Update avc error on ROM 7457955" into sc-dev 2021-06-16 01:25:10 +00:00
Wenhao Wang
dc0cdc36f3 Use label persist_ss_file
The label "persist_ss_file" was created for "/mnt/vendor/persist/ss(/.*)?".
But we erroneously didn't assign the label to the path.
This patch fixes the error.

Bug: 173971240
Bug: 173032298
Test: Trusty storage tests
Change-Id: I8e891ebd90ae47ab8a4aad1c2b0a3bbb734174d8
2021-06-15 17:24:01 -07:00
Armelle Laine
2898603355 Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 6e23660e3d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Ib37826f8d2e15f9f1e6c4429dcd9c270f7c1dea3
2021-06-15 17:20:52 +00:00
sukiliu
673b8f1014 Update avc error on ROM 7457955
Bug: 191132545
Bug: 191133059
Test: PtsSELinuxTestCases
Change-Id: I6a8e7924819734e38c2b6f761eb738f3e4d21c32
2021-06-15 23:23:43 +08:00
Armelle Laine
3c61f8891a Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 4847b5d1f4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: I2c3d321d5c1c964c60b0dda5b2a9a204df090890
2021-06-15 15:13:25 +00:00
Armelle Laine
4847b5d1f4 Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: I9c29b33df803b368a71d68ce59e0f16cf3a2b66c
2021-06-15 14:52:27 +00:00
Armelle Laine
6e23660e3d Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Icc35b74bb0ac43562583282d2d39dc1eb9646642
2021-06-15 14:51:51 +00:00
Armelle Laine
10e8126e2d Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev 2021-06-15 14:35:43 +00:00
linpeter
81aaf6cda3 Add sepolicy for hwcomposer to access lhbm sysfs
avc: denied { read write } for comm="android.hardwar" name="local_hbm_mode" dev="sysfs" ino=70189 scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:sysfs_lhbm:s0 tclass=file permissive=0

Bug: 190563896
test: check avc denied
Change-Id: I0f6abc1244d24781ff3318908b524a889490993d
2021-06-15 19:37:14 +08:00
Jiyoung
02ada4f463 vendor_telephony_app.te: add selinuxfs:file
- add selinuxfs:file for AP TCP dump
- allow userdebug or eng

Bug: 188422036

Signed-off-by: Jiyoung <ji_young.bae@samsung.com>
Change-Id: I9502f9f7320ca4ee298b38e40da0ccf11adfba7f
2021-06-15 15:06:39 +08:00
sukiliu
b220a0e873 Move oriole bug map to whitechapel folder am: 90ae782e26 am: c8a74f7fce
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I5faa78c559f4a6ddc0d7b92296d79b653b1a5e97
2021-06-15 06:30:33 +00:00
sukiliu
e18a7658e9 Move oriole bug map to whitechapel folder am: 90ae782e26 am: 8657bfaf73
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I7f8298eeb6d2988aa32f8cc4789f900ed57c04fb
2021-06-15 06:30:04 +00:00
sukiliu
8657bfaf73 Move oriole bug map to whitechapel folder am: 90ae782e26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I697e2270c71c1f5ce48318e9a3498ef05d954c82
2021-06-15 06:17:36 +00:00
sukiliu
c8a74f7fce Move oriole bug map to whitechapel folder am: 90ae782e26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I20a6b1f291236b26224ca0fe94196b2ca91bd548
2021-06-15 06:16:50 +00:00
sukiliu
90ae782e26 Move oriole bug map to whitechapel folder
Bug: 190563896
Bug: 190671898
Test: PtsSELinuxTestCases
Change-Id: I15f1a6d2ebab9c5794a79abccf3530eb4bfc8307
2021-06-15 04:39:50 +00:00
TreeHugger Robot
8314b7f628 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: d8aa5c7972
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I808fa351bb12654bbaa66248d9f10e6ce62f16e8
2021-06-15 02:08:19 +00:00
TreeHugger Robot
67bd98cff1 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: ebcba2c62d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: Iec8b071a423c5243b9c1d8322ebc9e5698b48f88
2021-06-15 02:08:07 +00:00
TreeHugger Robot
ebcba2c62d Merge "remove obsolete entries" into sc-dev am: 441bae6d1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I4d47c91c175d8a10e0cec3e974e684f3c44b6c63
2021-06-15 01:54:55 +00:00