Commit graph

2844 commits

Author SHA1 Message Date
Xin Li
aa2787c19b [automerger skipped] Empty merge of sc-v2-dev-plus-aosp-without-vendor@8433047 am: 7a573b067c -s ours am: 104e2d21c2 -s ours am: 7111ceb7e8 -s ours
am skip reason: Merged-In I7f65597f91db5a16d4f9de4f6bb018bd5b50a965 with SHA-1 e60773b926 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17805214

Change-Id: If7d12942a5f6ab72e9f8d4d4c0f3699462dcb063
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-20 13:54:16 +00:00
Xin Li
7111ceb7e8 [automerger skipped] Empty merge of sc-v2-dev-plus-aosp-without-vendor@8433047 am: 7a573b067c -s ours am: 104e2d21c2 -s ours
am skip reason: Merged-In I7f65597f91db5a16d4f9de4f6bb018bd5b50a965 with SHA-1 e60773b926 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17805214

Change-Id: Icd2489bcc9f6e26fb8e76c0a774ca174e38fada5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-20 05:55:38 +00:00
Chung-Kai (Michael) Mei
0dc722363f Merge "sepolicy: fix avc denials" into tm-dev am: 1875f214c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17800050

Change-Id: I1952ee068a8dd42b7503cebe6bbb428194e5b3ff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-20 03:02:04 +00:00
Chung-Kai (Michael) Mei
1875f214c6 Merge "sepolicy: fix avc denials" into tm-dev 2022-04-20 02:21:49 +00:00
Jason Macnak
d069ba4218 Merge "Remove sysfs_gpu type definition" into tm-dev am: d02d83f5c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17006942

Change-Id: I795ccdf8ba183f1d17ec21bba043826ff20819d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 16:24:56 +00:00
Jason Macnak
d02d83f5c0 Merge "Remove sysfs_gpu type definition" into tm-dev 2022-04-19 15:59:07 +00:00
TreeHugger Robot
d7e21baa91 Merge "Grant policy for EWP feature" into tm-dev am: dd5c94ef1c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17614595

Change-Id: I1695975184868790666c489c97d4c76dc215e892
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 12:03:58 +00:00
TreeHugger Robot
dd5c94ef1c Merge "Grant policy for EWP feature" into tm-dev 2022-04-19 11:40:02 +00:00
chungkai
19073ba66c sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 229670628
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I6747e6d36731664d7f2fd88382c8a6189c936860
2022-04-19 06:10:34 +00:00
Xin Li
104e2d21c2 [automerger skipped] Empty merge of sc-v2-dev-plus-aosp-without-vendor@8433047 am: 7a573b067c -s ours
am skip reason: Merged-In I7f65597f91db5a16d4f9de4f6bb018bd5b50a965 with SHA-1 e60773b926 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17805214

Change-Id: I403afd3d5e0c240130d398c28118334b3d8934bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 04:21:15 +00:00
Jason Macnak
f2be252260 Remove sysfs_gpu type definition
... as it has moved to system/sepolicy.

Bug: b/161819018
Test: presubmit
Change-Id: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
Merged-In: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
2022-04-18 22:45:55 +00:00
Xin Li
7a573b067c Empty merge of sc-v2-dev-plus-aosp-without-vendor@8433047
Bug: 226662282
Merged-In: I7f65597f91db5a16d4f9de4f6bb018bd5b50a965
Change-Id: I9a8579c87c05c1329fd5670f63d1edd848782334
2022-04-18 20:43:19 +00:00
Joshua Mccloskey
3a5f0310bf Merge "Allow platform apps to access FP Hal" into tm-dev am: 23d2a657fe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17624936

Change-Id: I7010b533a8d2b7ad8e406c7fb09db37cd780417e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:12:14 +00:00
Joshua Mccloskey
23d2a657fe Merge "Allow platform apps to access FP Hal" into tm-dev 2022-04-15 21:39:59 +00:00
Chung-Kai (Michael) Mei
51066df6e8 Merge "genfs_contexts: fix path for i2c peripheral device" into tm-dev am: 9309ec2609
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17751064

Change-Id: I688e2b44600519afdd1e218ff08f31c091851b4e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:28:21 +00:00
Chung-Kai (Michael) Mei
9309ec2609 Merge "genfs_contexts: fix path for i2c peripheral device" into tm-dev 2022-04-15 01:01:25 +00:00
Joshua McCloskey
517ab7da4d Allow platform apps to access FP Hal
Bug: 227247855
Test: Verified manually that the fingerprint extension is working.
Change-Id: Ia8fedcb373e23bf2103803195f844bf90b1807bc
2022-04-14 21:44:11 +00:00
Anthony Stange
53775b7e66 Merge "Update SELinux to allow CHRE to talk to the Wifi HAL" into tm-dev am: 0cfdc0266c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17722708

Change-Id: I3a38beec03eee17f5d770832be5d8a83e654633b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 16:14:06 +00:00
Anthony Stange
0cfdc0266c Merge "Update SELinux to allow CHRE to talk to the Wifi HAL" into tm-dev 2022-04-14 15:23:23 +00:00
chungkai
953583844f genfs_contexts: fix path for i2c peripheral device
paths are changed when we enable parallel module loading and
reorder the initializtaion of devices.

Test: without avc denial on R4/O6 when booting
Bug: 22754176
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ibcd5138170449e24115a0de5c3beda79914d1dc1
2022-04-14 04:45:41 +00:00
Anthony Stange
613bdcdec8 Update SELinux to allow CHRE to talk to the Wifi HAL
Bug: 206614765
Test: Run locally
Change-Id: I73bcf96ed1cab0a101e5f84852a1d82258b9c690
2022-04-12 20:58:12 +00:00
TreeHugger Robot
cc3d4cb61c Merge "sepolicy: Add policy for persist.vendor.udfps" into tm-dev am: 4e91f5530e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17180644

Change-Id: Ia1944b5875693f9aaddec3fcf5ba9a3bf29d0d5a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 11:16:04 +00:00
TreeHugger Robot
4e91f5530e Merge "sepolicy: Add policy for persist.vendor.udfps" into tm-dev 2022-04-12 10:56:32 +00:00
Darren Hsu
bf9775b008 sepolicy: label charger wakeups for system suspend am: 3c11d8d1c5 am: 4df95c6d08 am: 9b9e2b4f3c am: acb5cc9e03
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2060630

Change-Id: I8d5451d9f90035d9a2096da9f93b1236c956c25b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 04:49:28 +00:00
Darren Hsu
acb5cc9e03 sepolicy: label charger wakeups for system suspend am: 3c11d8d1c5 am: 4df95c6d08 am: 9b9e2b4f3c
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2060630

Change-Id: Ib0aa15719df8e4e0e7eb673b389d4e0b6be99640
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 04:19:48 +00:00
Darren Hsu
9b9e2b4f3c sepolicy: label charger wakeups for system suspend am: 3c11d8d1c5 am: 4df95c6d08
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2060630

Change-Id: I6648d98e50b0c8c01206071537fedbe4083e1f11
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 04:04:56 +00:00
Darren Hsu
4df95c6d08 sepolicy: label charger wakeups for system suspend am: 3c11d8d1c5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2060630

Change-Id: I058cb3909d972cc5784e507fcb26b46196c33aa4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 03:39:39 +00:00
Badhri Jagan Sridharan
798cd60026 Merge "Allow usb hal to read contaminantdisable property" into tm-dev am: 93b8189c2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17649293

Change-Id: I334c2578b4f6ad9488c670f5ea0c4a470cb30cdb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-11 22:44:22 +00:00
Badhri Jagan Sridharan
93b8189c2b Merge "Allow usb hal to read contaminantdisable property" into tm-dev 2022-04-11 22:22:28 +00:00
Patty
40cd670c9f Grant policy for EWP feature
Bug: 220121592
Test: Manual
Change-Id: I274a9519c40915cf65de45a3d8cf452faf16c8b4
2022-04-11 14:40:02 +08:00
Darren Hsu
3c11d8d1c5 sepolicy: label charger wakeups for system suspend
Bug: 226887726
Test: do bugreport without avc denials
Change-Id: I779b646846da90cdc710145e959644efc4733b3b
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-04-11 10:56:33 +08:00
Badhri Jagan Sridharan
a2f5fc80f4 [automerge] Allow usb hal to read contaminantdisable property 2p: 8606aa8a51
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17649293

Bug: 227792357
Change-Id: I0c6937f89bfadf38eb55dbb42a5d55ba8419750d
2022-04-08 00:26:04 +00:00
Badhri Jagan Sridharan
8606aa8a51 Allow usb hal to read contaminantdisable property
avc: denied { read } for comm="android.hardwar" name="u:object_r:vendor_usb_config_prop:s0"
dev="tmpfs" ino=367 scontext=u:r:hal_usb_impl:s0
tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0

Bug: 227792357
Change-Id: Id4d5ef7c214f0c0f672db28991b9fbe0152530b7
2022-04-07 17:21:15 -07:00
Chung-Kai (Michael) Mei
64e14e7379 Merge changes from topic "gs101_parallel_load_sepolicy" into tm-dev am: 9a909d4058
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17614589

Change-Id: I815bb946971fca3762647a3de3e00690557ecb95
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 10:30:36 +00:00
Chung-Kai (Michael) Mei
9a909d4058 Merge changes from topic "gs101_parallel_load_sepolicy" into tm-dev
* changes:
  sepolicy: ignore avc denial
  genfs_contexts: fix path for i2c peripheral devices
2022-04-07 09:33:26 +00:00
Siddharth Kapoor
c4db9c9fee Merge "Revert "Move ODPM file rule to pixel sepolicy"" into tm-dev am: 9d3a25fb29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17609198

Change-Id: I74da1b4b3bcb1f7c7625c01a61590e8ea24da47c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:22:33 +00:00
Siddharth Kapoor
9d3a25fb29 Merge "Revert "Move ODPM file rule to pixel sepolicy"" into tm-dev 2022-04-07 04:06:31 +00:00
Siddharth Kapoor
86e649b033 [automerge] Revert "Move ODPM file rule to pixel sepolicy" 2p: 13f85a37f3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17609198

Change-Id: I1c17b6ecf4850e214e5c3beb88d26c70a368368c
2022-04-07 03:30:21 +00:00
Siddharth Kapoor
13f85a37f3 Revert "Move ODPM file rule to pixel sepolicy"
Revert "Move ODPM file rule to pixel sepolicy"

Revert submission 17215583-odpm_sepolicy_refactor-tm-dev

Reason for revert: build failure tracked in b/228261711
Reverted Changes:
Ic9a89950a:Move ODPM file rule to pixel sepolicy
I24105669b:Move ODPM file rule to pixel sepolicy
I044a285ff:Move ODPM file rule to pixel sepolicy

Change-Id: I36abfddaa5903739f9c5bf65d3c1cd506db9e604
2022-04-07 03:29:56 +00:00
chungkai
384218408f sepolicy: ignore avc denial
dont audit since it's debugfs

Bug: 228181404
Test: forrest with boot test
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I7f2a85e2a405c78c9d8d11e9c2fdfdc5e87f7931
2022-04-06 09:21:24 +00:00
chungkai
8a19d8be9c genfs_contexts: fix path for i2c peripheral devices
paths are changed when we enable parallel module loading and
reorder the initializtaion of devices.

Test: without avc denial on Raven
Bug: 227541760
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I7d835205696fd727e9be24fcf010ed44bcd5d6ae
2022-04-06 09:15:46 +00:00
Albert Wang
cd8219c7be Add more xHCI wakeup path for suspend_control am: e60773b926 am: 092298b579 am: aed8848fb0 am: 7839be7474
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2052478

Change-Id: I1cfb6ac90a4eb6b3d9d6f046b30622936c27244e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 09:03:45 +00:00
Albert Wang
7839be7474 Add more xHCI wakeup path for suspend_control am: e60773b926 am: 092298b579 am: aed8848fb0
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2052478

Change-Id: I251a791b13d863de275ceffc3ba926db9a458c07
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 08:42:39 +00:00
Albert Wang
aed8848fb0 Add more xHCI wakeup path for suspend_control am: e60773b926 am: 092298b579
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2052478

Change-Id: Ieaa74f326039e13ec8409167112c11b16cb47480
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 08:15:54 +00:00
Albert Wang
092298b579 Add more xHCI wakeup path for suspend_control am: e60773b926
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2052478

Change-Id: Ib07b92bf159c8b69dcdc7bc17e7f19a44aab20f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 08:00:41 +00:00
Sam Ou
24ef7db4f3 Merge "Move ODPM file rule to pixel sepolicy" into tm-dev am: de81154964
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17215583

Change-Id: I277d684d530ac6e4e96138c80bdc2021a7067220
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 02:37:54 +00:00
Sam Ou
de81154964 Merge "Move ODPM file rule to pixel sepolicy" into tm-dev 2022-04-06 02:09:38 +00:00
Xin Li
ed68f78914 [automerger skipped] Merge Android 12 QPR3 ab/8391262 am: 815b133c28 -s ours am: 4295b8c5bb -s ours am: 6c7329e78a -s ours
am skip reason: Merged-In I1ae4b99a9fa4fc95f96ee1f36dc500f453653ca7 with SHA-1 24b4d1b601 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17543362

Change-Id: Ibfff57b71a0653f295b56b6f55e8b46d6029cddb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-03 08:29:44 +00:00
Xin Li
6c7329e78a [automerger skipped] Merge Android 12 QPR3 ab/8391262 am: 815b133c28 -s ours am: 4295b8c5bb -s ours
am skip reason: Merged-In I1ae4b99a9fa4fc95f96ee1f36dc500f453653ca7 with SHA-1 24b4d1b601 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17543362

Change-Id: Iccd31c0bb403d722d24d093730327b024e4342ec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-03 07:43:50 +00:00
Xin Li
4295b8c5bb [automerger skipped] Merge Android 12 QPR3 ab/8391262 am: 815b133c28 -s ours
am skip reason: Merged-In I1ae4b99a9fa4fc95f96ee1f36dc500f453653ca7 with SHA-1 24b4d1b601 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17543362

Change-Id: I3183293f6ba3e1858233ce35170f935f3b03c1ff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-03 07:11:50 +00:00