Commit graph

2950 commits

Author SHA1 Message Date
Jinhee Kim
a62f7495fb sepolicy: gs101: allowed permissions required for network access am: 653e53d11d am: 9ca55393c9
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2214621

Change-Id: Ib062d4ee9a01a39c1b8db50b4bd47c45ed8f2fc6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-16 10:54:14 +00:00
Hana Kim
19e9846ba8 Sepolicy: add permission to allow create, connect udp socket am: 09e0e1b280 am: 6c17e1e6f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2200444

Change-Id: I0ea2a78c506c360ac10958b08304c6b62167946b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-16 10:54:11 +00:00
Jinhee Kim
9ca55393c9 sepolicy: gs101: allowed permissions required for network access am: 653e53d11d
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2214621

Change-Id: Icc54f4ea60062d0b56ac88692803b1171e8fb345
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-16 10:26:20 +00:00
Hana Kim
6c17e1e6f5 Sepolicy: add permission to allow create, connect udp socket am: 09e0e1b280
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2200444

Change-Id: I929947f0b0ee7c969530343fd779fb88a411a7bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-16 10:26:19 +00:00
Jinhee Kim
653e53d11d sepolicy: gs101: allowed permissions required for network access
avc: denied { write } for comm="Thread-102" name="dnsproxyd" dev="tmpfs" ino=1022 scontext=u:r:vendor_ims_app:s0:c251,c256,c512,c768 tcontext=u:object_r:dnsproxyd_socket:s0 tclass=sock_file permissive=0 app=com.shannon.imsservice
avc: denied { node_bind } for comm="Thread-102" src=50174 scontext=u:r:vendor_ims_app:s0:c251,c256,c512,c768 tcontext=u:object_r:node:s0 tclass=udp_socket permissive=0 app=com.shannon.imsservice

Bug: 242231557
Test: Build
Change-Id: Icc3762cef7f9766d845f1e1a56af1315fc97163b
Signed-off-by: Jinhee Kim <jinhee.k@samsung.com>
Signed-off-by: Kukjin Kim <kgene.kim@samsung.com>
2022-09-12 15:18:32 +08:00
Hana Kim
09e0e1b280 Sepolicy: add permission to allow create, connect udp socket
Bug: 226412527
Test: Build
Signed-off-by: Hana Kim <hanaa.kim@samsung.com>
Change-Id: Id9ba79ba87010326c53b6aec408e5cdb291122a6
2022-09-12 15:17:44 +08:00
Treehugger Robot
6481874c77 Merge "Add security context for com.google.usf.non_wake_up/wakeup." am: d6ff29d1ca am: a4d246abac
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183507

Change-Id: Ib9ba46ae5b7e0454927f18e48a85f03f6847ef83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 07:29:18 +00:00
Treehugger Robot
a4d246abac Merge "Add security context for com.google.usf.non_wake_up/wakeup." am: d6ff29d1ca
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183507

Change-Id: I89572f1c793f464011163d50c0ef19c95f3b13d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 06:59:40 +00:00
Treehugger Robot
d6ff29d1ca Merge "Add security context for com.google.usf.non_wake_up/wakeup." 2022-08-22 06:38:52 +00:00
Treehugger Robot
b2e001581b Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." am: 3cb1ea79c9 am: c56dc643a4
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183506

Change-Id: Ibd378b384da9da3b9a08c9d56e72ecc5b3fd8ddd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 04:44:16 +00:00
Treehugger Robot
c56dc643a4 Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." am: 3cb1ea79c9
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2183506

Change-Id: Id1cdbd151bd58bfca12ea328f749a54b54d4edb5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-22 04:24:22 +00:00
Treehugger Robot
3cb1ea79c9 Merge "Add acd-com.google.usf.non_wake_up file to AoC file context." 2022-08-22 04:10:13 +00:00
Xin Li
e6e50e6051 [automerger skipped] DO NOT MERGE - Merge Android 13 am: ac180b779b -s ours
am skip reason: Merged-In I03be37c9e50280d6fa2cfdd69dca83c0535b2e35 with SHA-1 b577060b2d is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2186421

Change-Id: Iac9b3c92887d80300bafde61f1dcd79d248feab6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-16 22:43:59 +00:00
Xin Li
ac180b779b DO NOT MERGE - Merge Android 13
Bug: 242648940
Merged-In: I03be37c9e50280d6fa2cfdd69dca83c0535b2e35
Change-Id: I8feb38896fbd83a590fefebc4f356582315630e7
2022-08-15 22:00:01 -07:00
matthuang
62ba653669 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I8600283d9ff2ebcb45df95e5259484a60921fb1a
Merged-In: I8600283d9ff2ebcb45df95e5259484a60921fb1a
2022-08-15 18:52:58 +08:00
matthuang
7e89415aaf Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: If9add3528bde47a618bd884ce28121b6fa32754c
Merged-In: If9add3528bde47a618bd884ce28121b6fa32754c
2022-08-15 18:46:52 +08:00
Steven Moreland
d524c356c4 [automerger skipped] Restore HAL type names. am: b577060b2d -s ours am: 0b3734e918 -s ours
am skip reason: skipped by user smoreland

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2171622

Change-Id: I72c5783bcaad73c6cfff12688f0f1a9c4658008a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 19:49:44 +00:00
Steven Moreland
0b3734e918 [automerger skipped] Restore HAL type names. am: b577060b2d -s ours
am skip reason: skipped by user smoreland

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2171622

Change-Id: Ib3e5940f7132201773088487d892a0c23fd22f7c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 19:28:53 +00:00
Steven Moreland
b577060b2d Restore HAL type names.
Sed'd. TH not configured on AOSP. This is the change that is applied already internally.

Change-Id: I03be37c9e50280d6fa2cfdd69dca83c0535b2e35
2022-08-01 18:41:26 +00:00
Steven Moreland
235c5c3ba6 [automerger skipped] Merge "Remove vendor_service." am: c6545d33ff -s ours am: f200aa0cee -s ours
am skip reason: Merged-In I4766227e2261d0d57be090933926ff3b439694f6 with SHA-1 b20e917ebf is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2155037

Change-Id: I2ab3c0e8d7fdb7e26e7b0b0ab79caf9ce39a93d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 17:52:32 +00:00
Steven Moreland
1cd11b0bae [automerger skipped] Remove vendor_service. am: 2808c8b289 -s ours am: 8354f470a4 -s ours
am skip reason: Merged-In I4766227e2261d0d57be090933926ff3b439694f6 with SHA-1 b20e917ebf is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2155037

Change-Id: I1151cb806654e2e37f1ea1f862dfff41810c1759
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 17:52:30 +00:00
Steven Moreland
f200aa0cee [automerger skipped] Merge "Remove vendor_service." am: c6545d33ff -s ours
am skip reason: Merged-In I4766227e2261d0d57be090933926ff3b439694f6 with SHA-1 b20e917ebf is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2155037

Change-Id: Ieb341a369cd4d986dbfc47b0106202cd4a6e7e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 17:26:20 +00:00
Steven Moreland
8354f470a4 [automerger skipped] Remove vendor_service. am: 2808c8b289 -s ours
am skip reason: Merged-In I4766227e2261d0d57be090933926ff3b439694f6 with SHA-1 b20e917ebf is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2155037

Change-Id: I43b7480f97cc201f0b092ffa73ed0d92cab75296
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 17:26:18 +00:00
Steven Moreland
c6545d33ff Merge "Remove vendor_service." 2022-08-01 17:07:40 +00:00
Steven Moreland
4783ac2aff [automerger skipped] Remove vendor_service. am: b20e917ebf -s ours
am skip reason: Merged-In I4766227e2261d0d57be090933926ff3b439694f6 with SHA-1 81ccf8d719 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19469145

Change-Id: Ie309da7f885d4a61d47270cf7c122f78846cca87
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-29 23:07:04 +00:00
Steven Moreland
b20e917ebf Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
Merged-In: I4766227e2261d0d57be090933926ff3b439694f6
(cherry picked from commit 81ccf8d719)
2022-07-29 18:34:05 +00:00
Steven Moreland
be1bd1eebb Merge "Remove vendor_service." into tm-dev-plus-aosp 2022-07-28 00:46:47 +00:00
Tri Vo
e4f4a40a0c storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a am: a68844f3e1
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: Ie1ea9408063ebcf2ba49850d7ac208111328f116
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 20:09:28 +00:00
Tri Vo
a68844f3e1 storageproxyd: Remove setuid/setgid SELinux permissions am: 78011e9f3a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2154700

Change-Id: I611a9f1ecd6157c3d1f65c250c698a9ee00a0915
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-27 19:43:32 +00:00
Steven Moreland
81ccf8d719 Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
2022-07-27 16:50:03 +00:00
Steven Moreland
2808c8b289 Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Merged-In: I4766227e2261d0d57be090933926ff3b439694f6
Change-Id: I4766227e2261d0d57be090933926ff3b439694f6
2022-07-27 00:28:49 +00:00
Tri Vo
78011e9f3a storageproxyd: Remove setuid/setgid SELinux permissions
Bug: 205904330
Test: boot
Change-Id: Iefecc29752781151679e9f798330a36d14447df9
2022-07-15 11:07:47 -07:00
Xin Li
25bb42eb54 [automerger skipped] Merge tm-dev-plus-aosp-without-vendor@8763363 am: 351260db12 -s ours
am skip reason: Merged-In Ib9625eefc367738bcd6594884b1f3b5e3ab5be54 with SHA-1 de88097de5 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19093699

Change-Id: I39a8ce7402950e78469ba04412f430381f0d9f12
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 22:12:56 +00:00
Xin Li
351260db12 Merge tm-dev-plus-aosp-without-vendor@8763363
Bug: 236760014
Merged-In: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
Change-Id: I0f66cef4179df45ee56af588df1fe1b82b0f642a
2022-06-27 23:37:34 +00:00
sashwinbalaji
7bb947b88e thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8 am: 6ffe88201a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: I71bd9b49f2dc76e1e50f0b35bd404f7c8660d5d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 09:07:19 +00:00
sashwinbalaji
6ffe88201a thermal: added property persist.vendor.disable.thermal.dfs.control am: 1a4cd82bc8
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2133444

Change-Id: Ifc9b8e1d980dee52194a08805052f28bb2b7df8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 08:49:10 +00:00
sashwinbalaji
1a4cd82bc8 thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg files
Change-Id: Ia2a274ec3424bfeec25ae24e762f8ad41cb7ae86
2022-06-24 13:54:24 +08:00
SalmaxChang
ba3c6036fc hal_dumpstate_default: fix avc error am: de88097de5 am: 12053bbe8d
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: I9167e7032d77a57f41f2592378b551b60f09a375
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 02:24:59 +00:00
SalmaxChang
12053bbe8d hal_dumpstate_default: fix avc error am: de88097de5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2130236

Change-Id: Iaabe145decca9d0129a8f74a92782e5fe7ddcbcd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-21 02:05:20 +00:00
SalmaxChang
de88097de5 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-44" ino=341 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 235963885
Change-Id: Ib9625eefc367738bcd6594884b1f3b5e3ab5be54
2022-06-20 15:55:16 +08:00
Xin Li
00e8d1827d [automerger skipped] Merge "Merge Android 12 QPR 3" am: cd158e3668 -s ours am: 4492e80320 -s ours
am skip reason: Merged-In I289ba5aa69251d8575f4bd65fbeb7a38c3e03886 with SHA-1 203f473af5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2126116

Change-Id: Id71e7f97e4ac0c7151e4532605e7b35f5f673de8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-17 00:15:10 +00:00
Xin Li
13407053a9 [automerger skipped] Merge Android 12 QPR 3 am: 83d71652ff -s ours am: 5354139d04 -s ours
am skip reason: Merged-In I289ba5aa69251d8575f4bd65fbeb7a38c3e03886 with SHA-1 203f473af5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2126116

Change-Id: Ib611f0ae04b30e7a0fab7d851d6d31b365069580
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-17 00:14:09 +00:00
Xin Li
4492e80320 [automerger skipped] Merge "Merge Android 12 QPR 3" am: cd158e3668 -s ours
am skip reason: Merged-In I289ba5aa69251d8575f4bd65fbeb7a38c3e03886 with SHA-1 203f473af5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2126116

Change-Id: Ie3e238c3b0ea13cd17d338cd71330f0d6c5ccf00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 19:58:08 +00:00
Xin Li
5354139d04 [automerger skipped] Merge Android 12 QPR 3 am: 83d71652ff -s ours
am skip reason: Merged-In I289ba5aa69251d8575f4bd65fbeb7a38c3e03886 with SHA-1 203f473af5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2126116

Change-Id: Idcda8aa81ae6d216530d101021f435cf01817d1d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 19:57:01 +00:00
Xin Li
cd158e3668 Merge "Merge Android 12 QPR 3" 2022-06-16 18:51:58 +00:00
TreeHugger Robot
f3cb1d1dbd Merge "allow rlsservice read vendor camera property" into tm-dev am: b20c0652ad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/18849046

Change-Id: Ibd20fe601db9a6c55bf665cd61c4f93866987a7b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-16 12:18:03 +00:00
TreeHugger Robot
b20c0652ad Merge "allow rlsservice read vendor camera property" into tm-dev 2022-06-16 12:02:28 +00:00
Jidong Sun
cfdb5b22ac [automerger skipped] Merge "gs101: Allow BootControl to access sysfs blow_ar" am: 81d0d5f20f am: 2de41dde3e -s ours
am skip reason: Merged-In I120672722a5ab8b5cadf0dce6d872e00c9fae642 with SHA-1 f276625942 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2120677

Change-Id: I67a9efe888d6955541457815320ab35939778ccd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-15 21:40:35 +00:00
Jidong Sun
2de41dde3e Merge "gs101: Allow BootControl to access sysfs blow_ar" am: 81d0d5f20f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2120677

Change-Id: I708cc536675f2a3f5c6693ea5f2ece2aa2b78b07
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-15 21:20:04 +00:00
Jidong Sun
81d0d5f20f Merge "gs101: Allow BootControl to access sysfs blow_ar" 2022-06-15 20:53:26 +00:00