Commit graph

284 commits

Author SHA1 Message Date
Wilson Sung
855cd95dce Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340723222
Bug: 340723303
Bug: 340723030
Test: scanBugreport
Bug: 340723303
Bug: 340722537
Bug: 340723222
Bug: 340722772
Test: scanAvcDeniedLogRightAfterReboot
Bug: 340723303
Bug: 340723030
Bug: 340723222
Change-Id: I91df897d8ae7d8e4b1b49a7eb20f6bb5fe99755c
2024-05-15 03:50:37 +00:00
Pablo Gamito
46c7063452 Revert "Remove donotaudit line for b/277155042" am: 6750917d2b am: d7cda09653
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/3048618

Change-Id: I41348026047641edee9d894d4d665bc23b13dbea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-04-19 21:33:13 +00:00
Pablo Gamito
6750917d2b Revert "Remove donotaudit line for b/277155042"
This reverts commit f1baab0530.

Fixes: 331693615
Reason for revert: b/331693615

Change-Id: I32d6dc1e1b89b430d34da6909590367defd0af9d
2024-04-19 10:48:29 +00:00
Hungyen Weng
3a2d59d8a9 Allow modem_svc to access modem files and perfetto
Bug: 331147031
Bug: 330730987

Test: Confirmed that modem_svc is able to access token db files in modem partition
Test: Confiemed that modem_svc can send traces to perfetto
Test: Confirmed v2/pixel-health-guard/device-boot-health-check-extra has no modem_svc avc denials.

Change-Id: I5fabd3177c758be533ca8bdef3cb3305afd6a5a6
2024-03-25 22:15:19 +00:00
Treehugger Robot
883cf12320 Merge "Update SELinux error" into main 2024-03-25 13:42:12 +00:00
Pablo Gamito
f2a869d688 Remove donotaudit line for b/277155042 am: f1baab0530 am: 96fd92b050
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/3009455

Change-Id: I19af3da60141ab46ca404d1f5a2de98753805469
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-03-25 09:28:27 +00:00
Jan Sebechlebsky
27e4e3cd9d Remove virtual_camera dumpstate denial entry from bug_map
Fix: 312894628
Test: N/A
Change-Id: Ia31780377ef121b9347eace64af470926220524b
2024-03-25 09:00:07 +00:00
Pablo Gamito
f1baab0530 Remove donotaudit line for b/277155042
Since this bug is now fixed

Fixes: 277155042
Test: scanBugreport
Change-Id: If2fdbcbd0b0c0edbcc6824235bbfc561e0f43378
2024-03-25 08:55:20 +00:00
Wilson Sung
629dd3eaf9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 331147031
Change-Id: I098aab7a986a8b2c659c006f50b5dade74ebcb5b
2024-03-25 07:56:34 +00:00
Wilson Sung
89224de0eb Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 329380904
Change-Id: I5ef59058c7c7487a8a9cb238767e019631c5ac63
2024-03-18 03:24:54 +00:00
Treehugger Robot
2a9b7e75e3 Merge "add dsim wakeup labels" into main 2024-03-04 02:58:52 +00:00
Krzysztof Kosiński
6f152690d9 Allow camera to acquire wakelocks.
This is already allowed on all other Google chips and used
for a face auth latency optimization.

Fix: 303391687
Test: check logs on raven
Change-Id: I6f70b70d1cf4c055ce9f3e76c1fca0ae0c3e070d
2024-02-23 03:01:52 +00:00
Peter Lin
7af07fe0e4 add dsim wakeup labels
Bug: 323086660
Bug: 321733124
test: ls sys/devices/platform/1c2c0000.drmdsim/1c2c0000.drmdsim.0/wakeup -Z
Change-Id: Ic47c14713727de1639e456fb6b2f0fc7d9810dc6
2024-02-17 08:13:04 +00:00
Andrea Zilio
e2e71d0850 Removed SE Linux error bugmap entry, as we have fixed this property usage.
Change-Id: I1093c7c7b7633a734d1108fa6e05c010dd1af4c6
Bug: 321730881
2024-01-31 15:25:21 +00:00
Wilson Sung
16de970cd0 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 323086679
Test: scanBugreport
Bug: 323087054
Bug: 316817111
Test: scanAvcDeniedLogRightAfterReboot
Bug: 323086660
Bug: 316817111
Change-Id: I03dc82e832048e9a165b738bea1903ed37b2231c
2024-01-31 02:59:05 +00:00
Wilson Sung
3116a34269 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Test: scanBugreport
Bug: 321730881
Bug: 316817111
Test: scanAvcDeniedLogRightAfterReboot
Bug: 316817111
Change-Id: I6f7abbb5402fd991d174a79a81c2d5e6c41c71d8
2024-01-22 17:53:08 +00:00
Mahesh Kallelil
ea7ccea15c Fix SELinux error in dump_modem
The cpif logbuffer did not have the right context and was
missing as part of the bugreport.

Test: Tested bugreport on device
Bug: 305600375
Change-Id: I2101037d0044e706969f2582e29f923ae029458b
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2024-01-11 09:24:22 -08:00
timtmlin
c4181c461d Remove obsolete entries
Bug: 315720636
Bug: 315720725
Test: make
Change-Id: I485bbd472314199106a6f92f08796762cb440952
2023-12-27 15:44:26 +08:00
Wilson Sung
52fc41b1c2 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317734923
Test: scanBugreport
Bug: 317734418
Bug: 316817111
Test: scanAvcDeniedLogRightAfterReboot
Bug: 317734489
Bug: 316817111
Change-Id: Ibc5c35c327cbb1fb4433c63a9073503037d9c8cf
2023-12-26 03:44:21 +00:00
Wilson Sung
64e2ac2aa0 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317316478
Test: scanBugreport
Bug: 316817111
Test: scanAvcDeniedLogRightAfterReboot
Bug: 316817111
Change-Id: I0eaf3217d077d2465a2f4ac3f1e3b15b9236df4f
2023-12-21 07:37:17 +00:00
Wilson Sung
9fa7db53a1 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315907959
Test: scanBugreport
Bug: 315104713
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104713
Change-Id: Ib110dee4622befb0e4a04ade1c1805e822ce3b2e
2023-12-12 06:34:48 +00:00
Treehugger Robot
46cd746012 Merge "Fix rlsservice sepolicy" into main 2023-12-11 07:31:03 +00:00
Boon Jun Soh
548c2f184d Fix rlsservice sepolicy
Allows bugreport generation

Bug: 315255760
Bug: 309379598
Test: abd bugreport & ensure lack of rls avc denied logs
Change-Id: Ib3fc7b089c7aea4aea69f219d4c19847d39b0729
2023-12-11 14:39:32 +08:00
Wilson Sung
c42d6625f5 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315720636
Bug: 315104713
Test: scanBugreport
Bug: 315720725
Bug: 315104713
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315720636
Bug: 315104713
Change-Id: I6fdd21dd1d78aee006d3d5dbeb57ae6912f9b42e
2023-12-11 02:54:34 +00:00
Wilson Sung
484f609dee Update SELinux error
Test: scanBugreport
Bug: 312894628
Bug: 313804340
Change-Id: I87b384eac0c734444f0d722955b341a4611b7842
2023-11-30 07:14:31 +00:00
Wilson Sung
c11845e69e Update SELinux error
Test: scanBugreport
Bug: 309379598
Change-Id: I9c334cdb5e98c71a70f079fb984e57c154ab6a99
2023-11-06 08:01:12 +00:00
Wilson Sung
0c5fff7954 Update SELinux error
Test: scanBugreport
Bug: 305600375
Bug: 305600845
Bug: 305600595
Change-Id: I6bd13a82d02eb063435520be7705c67408b0269f
2023-10-16 05:53:42 +00:00
Wilson Sung
15261ed885 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 303391666
Bug: 303391687
Bug: 301948771
Change-Id: I16e38ca15d7a9995f7922b9c3be6a6f2f2238c2a
2023-10-04 11:53:34 +00:00
Desmond Huang
8e7549987f Relocate common tracking denial entries
Bug: 299029620
Change-Id: I57a75de7e0f0c5f31f2e8b0c5c9d60c3ebdb8844
2023-09-14 14:16:52 +08:00
Desmond Huang
2196ba412e Remove obsolete entries
Bug: 299029620
Change-Id: I8cb8d78099656d515feca434073a367908d5fddd
2023-09-14 14:15:38 +08:00
Wilson Sung
aadbdd8369 Merge "Update SELinux error"
Test: SELinuxUncheckedDenialBootTest
Bug: 291237382
Change-Id: Ie3f2e61a1103edcaeffb985a926de1480f2ea7ef
2023-07-17 11:13:24 +08:00
Wilson Sung
6efcea55dc Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 291237382
Change-Id: Ie3f2e61a1103edcaeffb985a926de1480f2ea7ef
2023-07-14 20:16:05 +08:00
Wilson Sung
1a68c31f73 Merge "Revert Update SELinux error"
This reverts commit 12abc8ef4a.

Bug: 287169829
Change-Id: If92a6a0fc90d70a49999ce6004bcbd5d58565e51
2023-07-10 14:49:05 +08:00
Wilson Sung
31e0460cba Revert "Update SELinux error"
This reverts commit 12abc8ef4a.

Bug: 287169829
Change-Id: If92a6a0fc90d70a49999ce6004bcbd5d58565e51
2023-07-05 08:06:38 +00:00
changyan
015a929f1f Merge "Update SELinux error"
Test: SELinuxUncheckedDenialBootTest
Bug: 287169829
Change-Id: I5def721ca380c01de836b03988aec397abc28b8a
2023-06-17 06:59:57 +00:00
DesmondH
918140b833 Remove fixed or obsolete entries
Bug: 277989397
Change-Id: I38a21959e9ff361ec4b54fd98849e4c5a789f87d
2023-06-14 17:02:02 +00:00
Wilson Sung
12abc8ef4a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 287169829
Change-Id: I0a245d81ae243a0461c19583e19912566062bb71
2023-06-14 15:30:31 +08:00
DesmondH
1dc0476a0a Remove obsolete entries
Bug: 275002227
Fix: 232714489
Fix: 269218654
Fix: 281814691
Fix: 176868297
Fix: 184593993
Change-Id: Iab4e5928bca173c76cb083e608edd67d5f7aad52
2023-06-02 03:21:58 +00:00
JohnnLee
886c8e0200 Merge "Update SELinux error" into master
Original change: https://googleplex-android-review.git.corp.google.com/c/device/google/gs101-sepolicy/+/23126085

Test: SELinuxUncheckedDenialBootTest
Bug: 281814691
Change-Id: If0219526eb58de371e09ba49617c6da5d6dffcfa
2023-05-12 02:32:02 +00:00
Wilson Sung
20364fe3b3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281814691
Change-Id: I2f73f5b75aec1145dee615499a7442400defbf8a
2023-05-11 06:43:02 +00:00
JohnnLee
4876a744a5 Remove obsolete entries
Test: adb bugreport
Bug: 268146971
Bug: 238825802
Bug: 269964825
Bug: 277989067
Bug: 238263568
Change-Id: I67da2c4ea8bf1da24b9dcecde7019007e3182ff7
2023-05-10 03:15:02 +00:00
Bruno BELANYI
88f5acac54 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev
* changes:
  Remove 'hal_neuralnetworks_armnn' '/data' access exception
  Remove 'hal_neuralnetworks_armnn' sysprop exceptions
  Add ArmNN config sysprops SELinux rules
2023-04-27 08:06:48 +00:00
Bruno BELANYI
9702cb57f2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:347dfbe925e2218189d82d37697540af25401a22)
Merged-In: Ic8bf0d51414461689ee5768821a2a1acda923c41
Change-Id: Ic8bf0d51414461689ee5768821a2a1acda923c41
2023-04-26 17:21:18 +00:00
Bruno BELANYI
b4001ec206 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:e4254a16aa516f5960f48732b078aad4ed63df6f)
Merged-In: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
Change-Id: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
2023-04-26 17:20:54 +00:00
Adam Shih
843b0ad6b4 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
Merged-In: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-24 09:58:14 +08:00
Bruno BELANYI
347dfbe925 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: b/205779871
Test: manual - reboot device and check the absence of AVC denials
Change-Id: Ic8bf0d51414461689ee5768821a2a1acda923c41
2023-04-20 09:15:03 +00:00
Bruno BELANYI
e4254a16aa Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: b/205202540
Test: manual - reboot device and check the absence of AVC denials
Change-Id: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
2023-04-19 11:31:03 +00:00
Treehugger Robot
cb29d1729a Merge "Update error on ROM 9930000" into udc-d1-dev am: f57e39a7a1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22601619

Change-Id: I24c7525779db72feb6e3467fe2b26ed3db099d90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-13 04:38:53 +00:00
Adam Shih
e10e338032 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-13 10:15:11 +08:00
Adam Shih
69f0507e29 Remove obsolete entries
Bug: 269218638
Bug: 269218638
Bug: 269370106
Bug: 268411073
Bug: 276385941
Bug: 276385941
Bug: 268147283
Bug: 269045042
Bug: 238263438
Bug: 238143262
Bug: 264483156
Bug: 264483673
Bug: 269045042
Bug: 270247432
Test: adb bugreport
Change-Id: I29268e10a370146b5d3405edfdec35645a3adc35
Merged-In: If99cfe07ec85c285d2acdc712d5120c7ee6f06d9
2023-04-12 08:44:44 +08:00