Commit graph

893 commits

Author SHA1 Message Date
Charlie Chen
73d2ff867c Merge changes from topic "remove_video_system_heap" into sc-dev am: 742daf873c am: bbe9ffe0e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14187064

Change-Id: I83a2c338e28a2e4ff5a57779f58bf8754a01374a
2021-05-15 08:01:20 +00:00
TreeHugger Robot
2099355da8 Merge "Allow power stats HAL read uwb power_stats sysfs node" into sc-dev am: a4d458026a am: 6b2103ed0c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14189309

Change-Id: I56f3c1c21396e97ec839923e98f39852ee9e03f0
2021-05-15 08:01:15 +00:00
Benjamin Schwartz
cbffb84350 Merge "Allow power stats HAL to read gnss stats" into sc-dev am: 948f48997b am: 09c2e2802a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14106551

Change-Id: Ic9409d79e53fa3351b647360461b5814b77a8911
2021-05-15 08:01:11 +00:00
Vova Sharaienko
180b8d1901 Merge "Stats: removed obsolete IStats HIDL sepolicies" into sc-dev am: d7e81afb35 am: 350b5e41c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14192518

Change-Id: I182f4be3960f7bd4e50171c528b379299c452ac6
2021-05-15 08:01:06 +00:00
Chris Lu
72fc27fecf display: remove dontaudit for hal_memtrack_default am: 86582e6ce0 am: bbabdc9504
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14187062

Change-Id: I67bf88fab71c3e85ea40b95c743b682902dd0220
2021-05-15 08:01:02 +00:00
Aaron Tsai
f08421e50c Fix avc denied for Silent Logging am: 204dc05aa4 am: ab5ab00a89
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14182163

Change-Id: I06c2be07f444556ca3a8c92be9851d1ee106756d
2021-05-15 08:00:57 +00:00
Adam Shih
c511ea832d Merge "change assigned bug" into sc-dev am: 65355b49a3 am: 6c77867c16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14167787

Change-Id: Ic99c235648350f5828969a1b64e2c1ca9d937a22
2021-05-15 08:00:53 +00:00
SalmaxChang
069758447d Add more modem properties am: f23a4423c4 am: eac287b429
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14173742

Change-Id: Iff34898b9b49f33638a83ebb763331256f081123
2021-05-15 08:00:49 +00:00
Roshan Pius
348c6e5d96 Uwb: Create a new Uwb system service am: 8119d482ed am: 2b15027412
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14057967

Change-Id: Ib131cb3b4afab98ff67b145379c47df1dec29da7
2021-05-15 08:00:44 +00:00
Ilya Matyukhin
1099e73569 Merge "Add sepolicy for SystemUIGoogle to write to lhbm" into sc-dev am: 75d0cce94f am: d22884d3cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14105113

Change-Id: I93631396ab0eb49ff336f0eafbb1e2cee14c8c48
2021-05-15 08:00:40 +00:00
Vova Sharaienko
00bef6431e wirelesscharger-adapter: updated sepolicy am: 72f80a3c90 am: b0a79e65a1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14176231

Change-Id: I9ced7dc9dbc40eb29bb3832016527037aae79855
2021-05-15 08:00:35 +00:00
Quinn Yan
631206bfa2 Merge "Add the TPU AIDL NNAPI HAL to the sepolicy." into sc-dev am: d2558a05b3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14506028

Change-Id: I4e88739fa33b60546468e2856b495ebffe301bab
2021-05-14 20:44:46 +00:00
Quinn Yan
d2558a05b3 Merge "Add the TPU AIDL NNAPI HAL to the sepolicy." into sc-dev 2021-05-14 20:15:37 +00:00
SHUCHI LILU
53f59f5d9b Merge "Update avc error on ROM 7358093" into sc-dev am: 60bf6343be
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542522

Change-Id: I7f581a8b4372a04bdcb49dea62d2e4c2d4980360
2021-05-14 09:37:01 +00:00
SHUCHI LILU
60bf6343be Merge "Update avc error on ROM 7358093" into sc-dev 2021-05-14 08:31:59 +00:00
sukiliu
53c9a79002 Update avc error on ROM 7358093
Bug: 188114822
Bug: 188114896
Test: PtsSELinuxTestCases
Change-Id: Ic5e865a921d0db981acfd936e1599a0ab220b975
2021-05-14 14:23:22 +08:00
Midas Chien
489478f82e Merge "Allowed PowerHAL service access Display node" into sc-dev am: b610fd307e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14308761

Change-Id: If5dcf3b82fa17accf25704e913f47e450fdb6a94
2021-05-14 06:03:08 +00:00
Midas Chien
b610fd307e Merge "Allowed PowerHAL service access Display node" into sc-dev 2021-05-14 05:47:32 +00:00
qinyiyan
989855def7 Add the TPU AIDL NNAPI HAL to the sepolicy.
Test: Created Forrest build and flashed to phone.
Bug: 187846367
Change-Id: I3ada9ecf3f94a594185049ddb95f13a6853841ba
2021-05-13 22:23:48 -07:00
SalmaxChang
febf2cd145 rfsd: fix permission error am: 30b9f8f277
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467419

Change-Id: I142c8c1c85c8ffb50abf5b5479ea598735255adc
2021-05-14 04:45:43 +00:00
SalmaxChang
30b9f8f277 rfsd: fix permission error
[RfsService::File] Failed to open file (4) (reason:Permission denied)

Bug: 187148595
Change-Id: Ia553bbc1e1c86b7740b3925679a2da65d3314714
2021-05-14 04:19:50 +00:00
Manish Varma
ef7f771b9c genfs_contexts: fix path for st21nfc i2c devices am: 705ecbe0ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538367

Change-Id: Ib894e30bf0033777ac939e6c8eb0c6ff68c5f5ad
2021-05-14 03:00:54 +00:00
Manish Varma
7baa13c32c genfs_contexts: fix path for s2mpg1X i2c devices am: fd2a6b9a74
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538366

Change-Id: If2fe324271da57e0e3eb9623d26f493d7282929a
2021-05-14 03:00:53 +00:00
Manish Varma
1045fd2031 genfs_contexts: fix path for cs40l25a i2c devices am: 194fef8b5a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538365

Change-Id: I845f1ce03511dba85383f82b8eb2bb7f06b78d8d
2021-05-14 03:00:52 +00:00
Manish Varma
a273bf01b2 genfs_contexts: fix path for max77759tcpc i2c devices am: 3868f8aa88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538364

Change-Id: If29cb659f6a76a5915d909b7a66453e61336ac36
2021-05-14 03:00:51 +00:00
Manish Varma
5244598a27 genfs_contexts: fix path for p9412 i2c devices am: b08c98c2b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14535947

Change-Id: Ie2629aa0108804906fefdfd60864b5ee49acc1b6
2021-05-14 03:00:50 +00:00
Manish Varma
705ecbe0ab genfs_contexts: fix path for st21nfc i2c devices
Due to recent changes which modifies the device name for i2c devices,
st21nfc device names are now changed from ?-0008 to "i2c-st21nfc"

Bug: 188078957
Test: Verified haptic works and no avc denials when running following command:
$ dmesg | grep avc | grep sysfs
Signed-off-by: Manish Varma <varmam@google.com>
Change-Id: I17464d2d01fb64447dd8828eb8f91e38717fac4c
2021-05-13 17:43:26 -07:00
Manish Varma
fd2a6b9a74 genfs_contexts: fix path for s2mpg1X i2c devices
Due to recent changes which modifies the device name for i2c devices,
s2mpg1xmfd device names are now changed from ?-00?f to "i2c-s2mpg10mfd" or
"i2c-s2mpg11mfd"

Bug: 188078957
Test: Verified no avc denials when running following command:
$ dmesg | grep avc | grep sysfs

Signed-off-by: Manish Varma <varmam@google.com>
Change-Id: I2c58773613071147336b4f338e4c4034ce90e9bd
2021-05-13 17:42:08 -07:00
Manish Varma
194fef8b5a genfs_contexts: fix path for cs40l25a i2c devices
Due to recent changes which modifies the device name for i2c devices,
cs40l25a device names are now changed from ?-0043 to "i2c-cs40l25a"

Bug: 188078957
Test: Verified haptic works and no avc denials when running following command:
$ dmesg | grep avc | grep sysfs

Signed-off-by: Manish Varma <varmam@google.com>
Change-Id: I47c423661d788c467d4cd1602fbc145bd715c67a
2021-05-13 17:37:32 -07:00
Manish Varma
3868f8aa88 genfs_contexts: fix path for max77759tcpc i2c devices
Due to recent changes which modifies the device name for i2c devices,
max77759tcpc device names are now changed from ?-0025 to "i2c-max77759tcpc"

Bug: 188078957
Test: Verified charging works and no avc denials when running
$ dmesg | grep avc | grep sysfs

Signed-off-by: Manish Varma <varmam@google.com>
Change-Id: Ic1f6d018ce74348b4faa937720b50c7924bf9b7a
2021-05-13 17:36:59 -07:00
Manish Varma
b08c98c2b4 genfs_contexts: fix path for p9412 i2c devices
Due to recent changes which modifies the device name for i2c devices,
p9412 device names are now changed from ?-003c to "i2c-p9412"

Bug: 188078957
Test: Verified wlc works and no avc denials when running following command:
$ dmesg | grep avc | grep sysfs

Signed-off-by: Manish Varma <varmam@google.com>
Change-Id: Id0af1122f7182a866ab28c5317db139d8083a45d
2021-05-13 17:36:24 -07:00
TreeHugger Robot
768fb9a152 Merge changes from topic "186500818-set1" into sc-dev am: 775771b811
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14490413

Change-Id: I9a9735eb2ad617b1b564f6b7eb376e9f5b312ce7
2021-05-13 07:39:51 +00:00
Hridya Valsaraju
92448c6830 Label debugfs files correctly am: 9e6528da08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14490412

Change-Id: I2b511b5931ab3175615a99b0d23c15a55e14252c
2021-05-13 07:39:50 +00:00
TreeHugger Robot
775771b811 Merge changes from topic "186500818-set1" into sc-dev
* changes:
  Let debugfs be accessed only for non-user builds
  Label debugfs files correctly
2021-05-13 07:07:13 +00:00
Vineeta Srivastava
f4d2a0d365 Merge "Add sepolicy for the UDFPS antispoof property" into sc-dev am: 14a07e230a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467424

Change-Id: Iab230781e0e88d86bcc08deecf0a2deca3c99756
2021-05-12 22:19:10 +00:00
Vineeta Srivastava
14a07e230a Merge "Add sepolicy for the UDFPS antispoof property" into sc-dev 2021-05-12 21:45:44 +00:00
TreeHugger Robot
c232d79fdc Merge "Grant vendor_sched sysfs nodes access" into sc-dev am: d4f9ef4303
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14512449

Change-Id: Id53d3d71b57e49fc30f1079c6544a70f9c26fca5
2021-05-12 18:47:09 +00:00
TreeHugger Robot
d4f9ef4303 Merge "Grant vendor_sched sysfs nodes access" into sc-dev 2021-05-12 18:28:51 +00:00
TreeHugger Robot
5d91d63244 Merge "Add SELinux policy for allowing dumping GSC info" into sc-dev am: 1f594ec562
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14491675

Change-Id: I21e2facab7cb7b83c86d38788343eb8d7304585a
2021-05-12 10:25:05 +00:00
TreeHugger Robot
2264b80f38 Merge "correctly label networking gadgets" into sc-dev am: 7fd939fdd7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14495070

Change-Id: I21f3ceffcd4e137da42f94c204ada2bae896683f
2021-05-12 10:24:58 +00:00
TreeHugger Robot
1f594ec562 Merge "Add SELinux policy for allowing dumping GSC info" into sc-dev 2021-05-12 10:02:28 +00:00
TreeHugger Robot
7fd939fdd7 Merge "correctly label networking gadgets" into sc-dev 2021-05-12 07:38:42 +00:00
TreeHugger Robot
96d84253b8 Merge "bthal: allow bthal to access bluetooth kernel driver logbuffer_btlpm and logbuffer_btuart device node" into sc-dev am: 9b8e2b7ba8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14009545

Change-Id: Ia305e564de5aeac5f395f4bd20b2a793e1377db2
2021-05-12 07:33:40 +00:00
TreeHugger Robot
9b8e2b7ba8 Merge "bthal: allow bthal to access bluetooth kernel driver logbuffer_btlpm and logbuffer_btuart device node" into sc-dev 2021-05-12 07:06:45 +00:00
TreeHugger Robot
3e991c2d81 Merge "com.qorvo.uwb: signed with dedicated key and running as android.uid.uwb uid" into sc-dev am: e2a0158fdf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14506301

Change-Id: If8d04254549b617266e9c8fc097a80b285a890fe
2021-05-12 06:39:56 +00:00
TreeHugger Robot
e2a0158fdf Merge "com.qorvo.uwb: signed with dedicated key and running as android.uid.uwb uid" into sc-dev 2021-05-12 06:22:21 +00:00
jonerlin
cb3f59b89e bthal: allow bthal to access bluetooth kernel driver logbuffer_btlpm
and logbuffer_btuart device node

* add sepolicy rules to let bthal can access bluetooth kernel device
  nodes dev/logbuffer_btlpm and dev/logbuffer_tty16 in engineer
  or user debug build

Bug: 177794127
Test: Manually
Change-Id: I5253719df82ca7ef8e64cbd3f2b0ff6d3f088edc
2021-05-12 13:27:40 +08:00
Wei Wang
1e378dbfa3 Merge "Revert "Grant vendor_sched sysfs nodes access"" into sc-dev am: 53ae55618a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14509955

Change-Id: Ib6ade70fbfd568b17f9ca1ff49b8dc0c78590bb0
2021-05-12 04:26:57 +00:00
Thierry Strudel
03f4884884 com.qorvo.uwb: signed with dedicated key and running as android.uid.uwb uid
Test:
05-11 21:05:48.077   786   786 I qorvo.uwb.main: UWB HAL start
05-11 21:05:48.078   412   412 I servicemanager: Found hardware.qorvo.uwb.IUwb/default in device VINTF manifest.
05-11 21:05:50.960  1639  1639 W PackageSettings: Missing permission state for package: com.qorvo.uwbtestapp.system
05-11 21:05:53.530  1639  1639 V StorageManagerService: Package com.qorvo.uwb does not have legacy storage
05-11 21:05:53.548  1639  1639 V StorageManagerService: Package com.qorvo.uwbtestapp.system does not have legacy storage
05-11 21:05:56.571  1639  1902 I am_proc_start: [0,3055,1083,com.qorvo.uwb,added application,com.qorvo.uwb]
05-11 21:05:56.571  1639  1902 I ActivityManager: Start proc 3055:com.qorvo.uwb/1083 for added application com.qorvo.uwb
05-11 21:05:56.653  1639  2264 I am_proc_bound: [0,3055,com.qorvo.uwb]
05-11 21:05:56.709  3055  3055 I TetheringManager: registerTetheringEventCallback:com.qorvo.uwb
05-11 21:05:56.710  3055  3055 V GraphicsEnvironment: ANGLE Developer option for 'com.qorvo.uwb' set to: 'default'
05-11 21:06:05.045  1639  1900 I am_pss  : [3055,1083,com.qorvo.uwb,5719040,4239360,0,88702976,2,0,6]
05-11 21:06:07.233  1639  1981 I am_compact: [3055,com.qorvo.uwb,all,84816,39052,44628,0,-816,0,-816,816,26,0,0,-800,0,1921532,-768]
05-11 21:06:38.442   786   786 I qorvo.Uwb: open
05-11 21:06:38.443   786   786 I qorvo.uwb.McpsUtils: ListHardware
05-11 21:06:38.443   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse
05-11 21:06:38.443   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse: Read message
05-11 21:06:38.443   786   786 I qorvo.uwb.IeeeUtils: ListDevices
05-11 21:06:38.443   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse
05-11 21:06:38.443   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse: Read message
05-11 21:06:38.443   786   786 I qorvo.uwb.UwbIface: Load calibration on wpan0, hw index: 0
05-11 21:06:38.445   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse
05-11 21:06:38.445   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse: Read message
05-11 21:06:38.445   786   786 I qorvo.uwb.UwbIface: Load properties on wpan0, hw index: 0
05-11 21:06:38.446   786   786 I qorvo.Uwb: getIface
05-11 21:06:38.449   786   786 I qorvo.uwb.UwbIface: firaController
05-11 21:06:38.449   786   786 I qorvo.Uwb: listHardwareIndex
05-11 21:06:38.449   786   786 I qorvo.uwb.McpsUtils: ListHardware
05-11 21:06:38.449   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse
05-11 21:06:38.450   786   786 I qorvo.uwb.NlSocket: SendAndAwaitResponse: Read message
05-11 21:06:38.450   786   786 I qorvo.Uwb: getIface
05-11 21:06:38.450   786   786 I qorvo.uwb.UwbIface: cccController

Bug: 187766150
Signed-off-by: Thierry Strudel <tstrudel@google.com>
Change-Id: Ie667a666a445e907aa99542f1c52046522b5dd02
2021-05-12 04:07:58 +00:00
Taeju Park
1d0e8106f3 Grant vendor_sched sysfs nodes access
Bug: 182509410
Signed-off-by: Taeju Park <taeju@google.com>
Change-Id: I68bf0c6e4f7b53a871a3393cb317bf6c79ace5e3
2021-05-11 21:03:30 -07:00