Commit graph

3880 commits

Author SHA1 Message Date
Jin Jeong
883f2b9994 Merge "Fix SELinux error for com.google.android.euicc" into udc-dev am: 5b3b2c2b1c am: f8fa7836dd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22878977

Change-Id: Ifa8e592f183c7f8c308037fd6044c95e3c5b969d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 04:05:29 +00:00
Jin Jeong
f8fa7836dd Merge "Fix SELinux error for com.google.android.euicc" into udc-dev am: 5b3b2c2b1c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22878977

Change-Id: I5d3898608774febaddbe38e750f8b629b0e7060d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:23:24 +00:00
Jin Jeong
5b3b2c2b1c Merge "Fix SELinux error for com.google.android.euicc" into udc-dev 2023-04-30 02:51:46 +00:00
Jinyoung Jeong
42a0c82065 Fix SELinux error for com.google.android.euicc
bug: 279548423
Test: http://fusion2/bb76429b-7d84-4e14-b127-8458abb3e2ed
Change-Id: I00bdf71f04eec985147189eb1b474c7ff6797023
2023-04-28 13:39:35 +00:00
martinwu
3055e06f0a [TSV2] Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Iea67de1e645592c6993a3ee6f2ca8e6bf3c6c949
2023-04-27 13:46:23 +00:00
Bruno BELANYI
af47588653 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev am: 88f5acac54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22787136

Change-Id: I9adc7d9c66163cc8f169d42d3561419593a4bb18
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:03 +00:00
Bruno BELANYI
0fa2fea833 Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: b4001ec206
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22786209

Change-Id: Ib278d5fc1ea4684f340cbf67ede663ac7c6d8494
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:44:56 +00:00
Bruno BELANYI
479f35bca6 Add ArmNN config sysprops SELinux rules am: a668555419
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22786488

Change-Id: I4b920885db6ccc40906ba9896319c2a4ab6036a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:44:55 +00:00
Bruno BELANYI
88f5acac54 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev
* changes:
  Remove 'hal_neuralnetworks_armnn' '/data' access exception
  Remove 'hal_neuralnetworks_armnn' sysprop exceptions
  Add ArmNN config sysprops SELinux rules
2023-04-27 08:06:48 +00:00
Martin Wu
9c3a8e8693 Revert "Remove tcpdump sepolicy from gs101 and move sepolicy to ..." am: e30ee618d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22891379

Change-Id: Iab01afe2a88ac49836691082caf05d376bc1a288
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:16:02 +00:00
Martin Wu
e30ee618d6 Revert "Remove tcpdump sepolicy from gs101 and move sepolicy to ..."
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I3d47d22250b435416c4ca44ff1956569662591ee
2023-04-27 02:20:55 +00:00
martinwu
905b34e0b2 Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common am: 6be45972bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22814097

Change-Id: Iaee6c5689b0cbf09d04228502721b16ed9813323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:17:46 +00:00
martinwu
6be45972bb Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I3d0cb388cf9b7c96d2856f46c0440b4017477480
2023-04-27 01:38:04 +00:00
Bruno BELANYI
9702cb57f2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:347dfbe925e2218189d82d37697540af25401a22)
Merged-In: Ic8bf0d51414461689ee5768821a2a1acda923c41
Change-Id: Ic8bf0d51414461689ee5768821a2a1acda923c41
2023-04-26 17:21:18 +00:00
Bruno BELANYI
b4001ec206 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:e4254a16aa516f5960f48732b078aad4ed63df6f)
Merged-In: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
Change-Id: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
2023-04-26 17:20:54 +00:00
Bruno BELANYI
a668555419 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0f99f3e63450befc661d38827e9afc853ca9257a)
Merged-In: I70c89dcc4b2bbe665d69cc4be1ac2f6cf8155a10
Change-Id: I70c89dcc4b2bbe665d69cc4be1ac2f6cf8155a10
2023-04-26 08:12:54 +00:00
Joseph Jang
a086d7c588 Merge "Move recovery.te to device/google/gs-common/dauntless/sepolicy" into udc-dev am: 37e90d3f3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22808538

Change-Id: Ie9d8e1f5a3c4e5dcfccbeda821cbd4d61bf71ad7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:56 +00:00
Joseph Jang
37e90d3f3a Merge "Move recovery.te to device/google/gs-common/dauntless/sepolicy" into udc-dev 2023-04-26 03:24:40 +00:00
Joseph Jang
ac6f4e0d00 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: If41449f97e729053caa98930cc7f2ef9fd6d844e
2023-04-24 08:09:23 +00:00
Adam Shih
6adde197a2 [automerger skipped] Update error on ROM 9930000 am: 843b0ad6b4 -s ours
am skip reason: Merged-In I38a3f852e2f5f0f6895db15141825909361a267d with SHA-1 e10e338032 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22802738

Change-Id: I215d23548ce4461fefe952cb42705409d5ab2885
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-24 03:45:12 +00:00
Adam Shih
843b0ad6b4 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
Merged-In: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-24 09:58:14 +08:00
jimsun
7b6f60771c rild: allow rild to ptrace am: 26e3d2abd0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22122889

Change-Id: Ie95ac070579f4c3cf3cfcaf95e2d371dadc5610a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:15 +00:00
jimsun
26e3d2abd0 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I35ad31e6cc4e2942c671e51720f28a9abce3dcca
2023-04-18 07:48:32 +00:00
Bruno BELANYI
f47334e3f1 Merge "Use restricted vendor property for ARM runtime options" into udc-dev am: bf8675143b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22381263

Change-Id: Ic1621074f7b2281c3176467a33884acc12d2a5c0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:28:50 +00:00
Bruno BELANYI
bf8675143b Merge "Use restricted vendor property for ARM runtime options" into udc-dev 2023-04-17 10:59:23 +00:00
Treehugger Robot
f57e39a7a1 Merge "Update error on ROM 9930000" into udc-d1-dev 2023-04-13 03:41:52 +00:00
Adam Shih
e10e338032 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-13 10:15:11 +08:00
Xin Li
2714763638 [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours am: 9505121ada -s ours am: ab4e3e986a -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: Ia20b14fcd634184ff89e3760d75ef999d490f07f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:08:39 +00:00
Xin Li
ab4e3e986a [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours am: 9505121ada -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: I07cabb680ee2172a60bdc37f9a61a2af528844d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:06 +00:00
Xin Li
9505121ada [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: Ie91202c445df25847c5bcd37cf8224e7bae6536e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:22:54 +00:00
Xin Li
26cfa34cb7 Merge TQ2A.230405.003 am: 82232b6423
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: I92a1d4dff4571e4aa8f11ca6f71978d549bfc812
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:54 +00:00
Mike McTernan
87f81bd91f confirmationui: Allow securedpud to access the systemsuspend HAL. am: b46b936df8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22574497

Change-Id: I708d02ca3b7a7bbeae5405b533f24b033ce5e1a7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 10:45:43 +00:00
Adam Shih
69f0507e29 Remove obsolete entries
Bug: 269218638
Bug: 269218638
Bug: 269370106
Bug: 268411073
Bug: 276385941
Bug: 276385941
Bug: 268147283
Bug: 269045042
Bug: 238263438
Bug: 238143262
Bug: 264483156
Bug: 264483673
Bug: 269045042
Bug: 270247432
Test: adb bugreport
Change-Id: I29268e10a370146b5d3405edfdec35645a3adc35
Merged-In: If99cfe07ec85c285d2acdc712d5120c7ee6f06d9
2023-04-12 08:44:44 +08:00
Mike McTernan
b46b936df8 confirmationui: Allow securedpud to access the systemsuspend HAL.
In order to use a wakelock, securedpud needs access to binder and the
system_suspend_service HAL.

Bug: 274851247
Test: manual, trigger TUI and check for AVC denials
Change-Id: Ibd27d32e092269f91d6557ebddcd27d4ccf1355a
2023-04-11 13:04:53 +00:00
Xin Li
82232b6423 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
Change-Id: I61dd94e23d10e5405135626487ddadddb1f89f9f
2023-04-10 23:55:29 -07:00
Wilson Sung
9f61b3a044 Update SELinux error am: c41cb55d4f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22530832

Change-Id: I3de424a9d10ead26317a288a82965ceff4ce49be
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 05:24:56 +00:00
Wilson Sung
c41cb55d4f Update SELinux error
Test: scanBugreport
Bug: 277528855
Change-Id: Ia59cd4045433f2e82a602672fe533e27e87b0275
2023-04-10 11:02:52 +08:00
Adam Shih
9360e36aeb Merge "use dumpsate from gs-common" into udc-dev am: d186da49ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22328249

Change-Id: I6a0697a450ea04aa578c4883330c0b6f0a8511fa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:26 +00:00
Adam Shih
d186da49ea Merge "use dumpsate from gs-common" into udc-dev 2023-04-10 01:11:17 +00:00
Wilson Sung
cf49233ca2 Update error on ROM 9891405 am: 816622f352
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22525943

Change-Id: I8cfb59b5e72b508c4d67b5fa8d6b382b60827428
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-07 08:44:03 +00:00
Wilson Sung
816622f352 Update error on ROM 9891405
Bug: 277155042
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Ic2129188db52ec85a8afaf92c507a42695e82804
2023-04-07 14:56:21 +08:00
Adam Shih
240c435174 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: I9092e2e004e3ad0b3667b948ed4d633cd50d088c
2023-04-07 13:02:21 +08:00
Victor Liu
2af298588a Merge "uwb: add permission for ccc ranging" into udc-dev am: d87df92740
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21965690

Change-Id: Iee589f33b02bf5a052469fde2bd6b29e0f364512
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 21:29:09 +00:00
Victor Liu
d87df92740 Merge "uwb: add permission for ccc ranging" into udc-dev 2023-04-06 20:57:49 +00:00
feiyuchen
97df720a19 Allow camera HAL to access edgetpu_app_service in gs101 am: 391f954d5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22463634

Change-Id: If16892c57abf4d38fac27012783a2e97c50ce07e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-05 23:24:05 +00:00
feiyuchen
391f954d5d Allow camera HAL to access edgetpu_app_service in gs101
We are seeing SELinux error b/276911450. It turns out that I only added the SE policy for 2023 device ag/22248613, but I forgot to add it for gs101 and gs201. So I created this CL.

See more background in ag/22248613.

Test: For gs201, I tested on my Pixel7 and I saw no more error. For gs101, I just did mm.
Bug: 275016466
Bug: 276911450
Change-Id: I3d691128daa2d7115f80c378f7b42de334cd8ed5
2023-04-04 21:32:36 +00:00
Bruno BELANYI
7838603828 Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I963fb55fb92ef5f91426dbec913c901e58cacf64
2023-04-04 13:04:00 +00:00
Victor Liu
a55bb8682c uwb: add permission for ccc ranging
Bug: 255649425
Change-Id: I05aac586146bf25569b5f6251d2fd62b921631be
2023-03-31 14:04:13 -07:00
Wilson Sung
fa24247c90 Merge "Update SELinux error" into udc-dev am: 083b5fe640
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22371623

Change-Id: Iad86d5505a210d5320cb35bab875bdeacd7af180
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-31 10:50:19 +00:00
Wilson Sung
d00d896387 Update SELinux error am: 28afe7393f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22241484

Change-Id: I03fe9842ff4ae8127ff3abd124c80131ff1fb1d4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-31 10:48:32 +00:00