Commit graph

4550 commits

Author SHA1 Message Date
TreeHugger Robot
87f6042d23 Merge "Remove platform certification from imsservice" into sc-dev am: 6a5cfd86f5 am: b33a1a4042 am: 067716b11c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14343989

Change-Id: I6e70c1f4dd5d11149ed0781181899c476dcde245
2021-05-18 18:13:58 +00:00
Roger Fang
3d9dfa1e58 Merge changes from topic "IAudioMetricExt@1.0" into sc-dev am: 834331af79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14281930

Change-Id: If56802dd85f6a6be85982ff7bbd2139f7a5518ea
2021-05-18 17:38:54 +00:00
Gary Jian
b724a106ed Add permission to access audiometricext hal for grilservice_app am: b9e4f7a759
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13885467

Change-Id: I7b4da71ea18f09d42bacffd9aa28644b38b92513
2021-05-18 17:38:52 +00:00
Roger Fang
834331af79 Merge changes from topic "IAudioMetricExt@1.0" into sc-dev
* changes:
  sepolicy: gs101: add IAudioMetricExt settings
  Add permission to access audiometricext hal for grilservice_app
2021-05-18 17:21:48 +00:00
TreeHugger Robot
9f7e2553f4 Merge "Update gs101 sepolicy for contexthub HAL" into sc-dev am: ff7948fc48 am: 81e7e0d374 am: 268781c624
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14354723

Change-Id: I8485dfc27c7c55ecf65e953708426babf2b5aa1c
2021-05-18 16:42:31 +00:00
TreeHugger Robot
e661572624 Merge "sepolicy:gs101: allow init-insmod-sh to access sysfs_leds nodes" into sc-dev am: c134ed985a am: 56305a9427 am: 4176a39915
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14357213

Change-Id: I57ca717aba8ceb55035814d0eaf233fca92ee3fc
2021-05-18 16:42:22 +00:00
TreeHugger Robot
cb5e052aec Merge "change persist.camera to persit.vendor.camera" into sc-dev am: 2c4b0fd96a am: 82f13cbf48 am: b41e03b3a6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14356785

Change-Id: Ifb927bf6f387d294b39092517a5aec21c8017cbb
2021-05-18 16:42:17 +00:00
TreeHugger Robot
c64692dc40 Merge "Add sepolicy for sensor HAL to read lhbm" into sc-dev am: 7a4cd3a6e0 am: 04b1f2cdec am: a8f126d70c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14299201

Change-Id: I54fa74806e8400d5e012a6dbe6c606d00bb9f8f9
2021-05-18 16:42:11 +00:00
Kevin DuBois
0afea3c02d Merge "sepolicy: update gpu nnhal file" into sc-dev am: 811dbd6611
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14551347

Change-Id: Ia73a117f48808441194e827384ebf88ee671c127
2021-05-18 15:28:16 +00:00
Kevin DuBois
811dbd6611 Merge "sepolicy: update gpu nnhal file" into sc-dev 2021-05-18 15:07:05 +00:00
Quinn Yan
3175af2d48 Merge "Add the TPU AIDL NNAPI HAL to the sepolicy." into sc-dev am: d2558a05b3 am: 5145ae8e4c am: e11173811e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14506028

Change-Id: I387df14cf83a29032cb5595f2be42eb4c74d9c63
2021-05-18 13:29:12 +00:00
SHUCHI LILU
360a59388c Merge "Update avc error on ROM 7358093" into sc-dev am: 60bf6343be am: 64a1e16887 am: 218a434cd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542522

Change-Id: I223178f7c40891ed4826ce95516ab9feda8a4df9
2021-05-18 13:28:35 +00:00
Midas Chien
c88435dc47 Merge "Allowed PowerHAL service access Display node" into sc-dev am: b610fd307e am: d2e21ded9a am: c5d3b92fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14308761

Change-Id: I0e8573afece7fe30bb218bde22510bfeb29935bd
2021-05-18 13:28:28 +00:00
SalmaxChang
f4b979cf7f rfsd: fix permission error am: 30b9f8f277 am: 272b4e5590 am: 4c134fec1b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467419

Change-Id: I0d3ee4e34ea238c410222c8caabe52573af06bb1
2021-05-18 13:28:21 +00:00
Manish Varma
6021febd2c genfs_contexts: fix path for st21nfc i2c devices am: 705ecbe0ab am: 4aa4640559 am: a5a368cdfc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538367

Change-Id: I2f4729c09419c0c852e1e5e47d8232deac3fcb25
2021-05-18 13:28:13 +00:00
Manish Varma
3f343b7b2c genfs_contexts: fix path for s2mpg1X i2c devices am: fd2a6b9a74 am: a592b23a80 am: 03657f8e3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538366

Change-Id: I51931583362903d08cc8962eb38f499493d7145d
2021-05-18 13:28:12 +00:00
Manish Varma
1f6bee9cb4 genfs_contexts: fix path for cs40l25a i2c devices am: 194fef8b5a am: 67d28bdf03 am: 459bdb2a40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538365

Change-Id: I9c538a63d33730aea7175754625d7af2fcdf028e
2021-05-18 13:28:11 +00:00
Manish Varma
739bbced69 genfs_contexts: fix path for max77759tcpc i2c devices am: 3868f8aa88 am: aaee225e77 am: db3f825375
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538364

Change-Id: Ide601be79ed433a0831c0b1432e5efa524dac52b
2021-05-18 13:28:10 +00:00
Manish Varma
a08d344be1 genfs_contexts: fix path for p9412 i2c devices am: b08c98c2b4 am: 9ba9e2a783 am: 529d215c31
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14535947

Change-Id: I653d91e668e5fbaa3004fbc0ecdc499a53b8aa19
2021-05-18 13:28:09 +00:00
TreeHugger Robot
8b4923b7c8 Merge changes from topic "186500818-set1" into sc-dev am: 775771b811 am: a019f35a3b am: c833549d8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14490413

Change-Id: I24fc274705adfec6ee3060a67829a9e6726550b6
2021-05-18 13:27:55 +00:00
Vineeta Srivastava
0bf4c5c898 Merge "Add sepolicy for the UDFPS antispoof property" into sc-dev am: 14a07e230a am: 4d42a986f8 am: 5e7734b411
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467424

Change-Id: I6251fb8f52360cfa753797212ad088ad3ff7fb54
2021-05-18 13:26:17 +00:00
jintinglin
3be06b2ec9 logger_app: Fix avc errors
avc: denied { read } for name="level" dev="sysfs" ino=57112 scontext=u:r:logger_app:s0:c29,c257,c512,c768 tcontext=u:object_r:sysfs_sscoredump_level:s0 tclass=file permissive=0 app=com.android.pixellogger

Bug: 187909426
Change-Id: I2037b1d2613736c8e1789bc96bfd4be0168444e0
2021-05-18 18:46:00 +08:00
Roger Fang
9de2688cd4 sepolicy: gs101: add IAudioMetricExt settings
E init    : Could not start service 'audiometricext' as part of class 'hal': File /vendor/bin/hw/vendor.google.audiometricext@1.0-service-vendor(labeled "u:object_r:vendor_file:s0")

vendor.google.a: type=1400 audit(0.0:3): avc: denied { read } for name="u:object_r:hwservicemanager_prop:s0" dev="tmpfs" ino=188 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:hwservicemanager_prop:s0 tclass=file permissive=1

E SELinux : avc:  denied  { find } for interface=vendor.google.audiometricext::IAudioMetricExt sid=u:r:hal_audiometricext_default:s0 pid=819 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:default_android_hwservice:s0 tclass=hwservice_manager permissive=1

E SELinux : avc:  denied  { add } for interface=android.hidl.base::IBase sid=u:r:hal_audiometricext_default:s0 pid=795 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:hidl_base_hwservice:s0 tclass=hwservice_manager permissive=1

Bug: 180627405
Test: manually test passed
Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: I91d76eb0ad5850e75ad865304d83f3025b981915
2021-05-18 05:06:58 +00:00
Gary Jian
b9e4f7a759 Add permission to access audiometricext hal for grilservice_app
Bug: 182526894
Test: Manual
Change-Id: I3ca85be7e5ab244e2dea2c6f7768f59c07b44525
2021-05-18 02:18:56 +00:00
TreeHugger Robot
3075216794 Merge "genfs_contexts: Specify correct GPU clock hint node" into sc-dev am: ac53196839
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14599591

Change-Id: Ifc1411973f3dcb258d3673e05d8d519e9132cd64
2021-05-18 00:54:21 +00:00
TreeHugger Robot
843c90e0ae Merge "Grant dumpstate hal read permission of camera hal dump files" into sc-dev am: 09a98d233d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14604511

Change-Id: I96a4843b04f81194053e1c552757b76bb6f0a134
2021-05-18 00:53:51 +00:00
TreeHugger Robot
ac53196839 Merge "genfs_contexts: Specify correct GPU clock hint node" into sc-dev 2021-05-18 00:50:53 +00:00
TreeHugger Robot
09a98d233d Merge "Grant dumpstate hal read permission of camera hal dump files" into sc-dev 2021-05-18 00:42:12 +00:00
Yu-Chi Cheng
e8ee41f9af Renamed edgetpu_service to edgetpu_app_service.
edgetpu_service was splitted into two in previous change:
edgetpu_service and edgetpu_vendor_service, where the new
vendor service for vendor clients, and the old service keeps
serving app clients.

This change updated the SELinux policy to rename the edgetpu_service
into edgetpu_app_service to make the purpose clearer.

Bug: 188463446
Test: Oriole + GCA
Change-Id: I3a133319edc84fc02ef211934d0542575580da14
2021-05-17 15:38:24 -07:00
Zhijun He
a8ceb3a751 Grant dumpstate hal read permission of camera hal dump files
Test: Build and capture bugreport
Bug: 178737594
Change-Id: Iae9792a75dec574ff9fe0d246a7c166221565b16
2021-05-17 14:23:46 -07:00
Minchan Kim
2d7105504c sepolicy: gs101: allow duump page_pinner am: 304a32c17e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14472545

Change-Id: Ibae22fcdcc54e799d249da2049877764ff81f79f
2021-05-17 18:49:05 +00:00
TreeHugger Robot
cf875452ff Merge "Grant vendor_sched sysfs nodes access" into sc-dev am: d4f9ef4303 am: 1fbb91ef97 am: 292337148c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14512449

Change-Id: I550e0ba737fe9c66aa6e9eb906d4a49f6d501f64
2021-05-17 17:02:21 +00:00
TreeHugger Robot
832ffb5dc7 Merge "Add SELinux policy for allowing dumping GSC info" into sc-dev am: 1f594ec562 am: e723f80ba9 am: 6432a7bc7a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14491675

Change-Id: Ie16aea227c99d56ed832c48de1b1565bf82c4830
2021-05-17 17:02:02 +00:00
TreeHugger Robot
f7019f3647 Merge "correctly label networking gadgets" into sc-dev am: 7fd939fdd7 am: b3ae9a8c03 am: 8a1ed47bba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14495070

Change-Id: I86101c58b829c283d05e3b7ff3225e331d74e856
2021-05-17 17:01:48 +00:00
TreeHugger Robot
ae5a7ec6ed Merge "bthal: allow bthal to access bluetooth kernel driver logbuffer_btlpm and logbuffer_btuart device node" into sc-dev am: 9b8e2b7ba8 am: e7fe59fb13 am: 0c4611ecb0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14009545

Change-Id: Iaa8806ecaae37a4097ac122a34b41d8949e2fd3a
2021-05-17 17:00:43 +00:00
Minchan Kim
304a32c17e sepolicy: gs101: allow duump page_pinner
Provide necessary sepolicy for dumpreport to access page_pinner
information in /sys/kernel/debug/page_pinner/{longterm_pinner,
alloc_contig_failed}

Bug: 187552095
Test: Run "adb bugreport <zip>" and verify it contains the output
      from page_pinner.
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I2abc48f2a156718fd4bed3b51bdd285c6bf9f175
2021-05-17 09:18:50 -07:00
TreeHugger Robot
9164ea0848 Merge "com.qorvo.uwb: signed with dedicated key and running as android.uid.uwb uid" into sc-dev am: e2a0158fdf am: 6d2c152bcf am: 7a4d420378
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14506301

Change-Id: Ie10fdf67607a0cdf76e9b6877f296a1370a978ba
2021-05-17 15:45:06 +00:00
Wei Wang
f89b58e4ac Merge "Revert "Grant vendor_sched sysfs nodes access"" into sc-dev am: 53ae55618a am: c515c8345d am: 6883250a44
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14509955

Change-Id: Ib553fe84ec690d58c491e017ae3ca1e385bb2d70
2021-05-17 15:05:41 +00:00
TreeHugger Robot
74b9e1e145 Merge "Sniffer Logger: Add dontaudit getattr for sysfs_wifi" into sc-dev am: 004c299011 am: 223f9da106 am: 8966b0738f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14485438

Change-Id: I8d91d3c920f066cb7ed12e247e29e6d30e438c31
2021-05-17 14:51:52 +00:00
Sidath Senanayake
828114d410 genfs_contexts: Specify correct GPU clock hint node
Bug: 188404581
Bug: 188034128
Signed-off-by: Sidath Senanayake <sidaths@google.com>
Change-Id: Id69f5cf8c95081fea7784520838a3f85aa58589c
2021-05-17 15:44:19 +01:00
Wei Wang
cb3efaa340 Merge "Grant vendor_sched sysfs nodes access" into sc-dev am: 3a2d20a1a2 am: a04548a17c am: 82e3d3146f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14462495

Change-Id: Id16c3fd3cd5370c86c9ffbeedc4ff5141960f097
2021-05-17 14:28:15 +00:00
sukiliu
8ed18dc446 Update avc error on ROM 7349999 am: 99853e483b am: d5d461cc4e am: 7a1938e846
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14500956

Change-Id: I8db5256fde25bf063f6407e48c9234232df5785a
2021-05-17 14:06:04 +00:00
Peter Csaszar
c1f4edead1 pixel-selinux: add SJTAG policies am: bc525e1a49 am: 6ff24d2a06 am: d39d9e517f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14489636

Change-Id: I30814d03394d87a1009618b709d7bc0a26cf0018
2021-05-17 12:05:19 +00:00
Wei Wang
d348574869 Merge "Add policy for memlat governor needs create/delete perf events" into sc-dev am: 551505ae05 am: 8181bbaaac am: ff1bb37173
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14486216

Change-Id: I9b0844c573b6742b6a9b2b44bf9ed0b5048eecfb
2021-05-17 07:08:20 +00:00
Jia-yi Chen
14fe4108f0 Merge "Add high_capacity_start_cpu to u:object_r:sysfs_vendor_sched:s0" into sc-dev am: 06a0792bf1 am: 1912dc976e am: 344b354f8b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14460156

Change-Id: I710d900d9b1ac49bf038abc6aa2d46bae943a9d7
2021-05-17 07:08:11 +00:00
JJ Lee
66d7ed975d Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev am: df02b6ef77 am: 51c75a291e am: 2a2ce4a0ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14452416

Change-Id: I9455603978406f34f41be37124ae0ef340321dc7
2021-05-17 07:07:28 +00:00
TreeHugger Robot
b3d62141dc Merge "vibrator: Remove temporary method" into sc-dev am: ec3144742f am: e853b4335e am: df80f0be9f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467421

Change-Id: I4cc152563263416ae2601e16303e3d0e81c51c65
2021-05-17 07:07:08 +00:00
TreeHugger Robot
f909b51e46 Merge changes Ic697ffe8,Idcf38e09 into sc-dev am: a2d2ebd508 am: 41d657e591 am: eb15c49e77
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456725

Change-Id: Ib2667e9dbe8bc98e9651fafeba9aa143740a59a7
2021-05-17 07:07:03 +00:00
TreeHugger Robot
e248e30edb Merge "Allow radioext to communicate with bt hal" into sc-dev am: c03c055812 am: 93008dc81a am: 73f7604819
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456718

Change-Id: Ie375c0b56617064e9a55763659a4f238f5b42802
2021-05-17 07:06:58 +00:00
TreeHugger Robot
d31171629a Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev am: 296f8ddc5d am: cb8de215f8 am: 73e866b8c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14440528

Change-Id: I7b561e1688c0da825498186427c798ce12f01f12
2021-05-17 07:06:51 +00:00