Commit graph

1416 commits

Author SHA1 Message Date
Joseph Jang
ac6f4e0d00 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: If41449f97e729053caa98930cc7f2ef9fd6d844e
2023-04-24 08:09:23 +00:00
jimsun
26e3d2abd0 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I35ad31e6cc4e2942c671e51720f28a9abce3dcca
2023-04-18 07:48:32 +00:00
Bruno BELANYI
bf8675143b Merge "Use restricted vendor property for ARM runtime options" into udc-dev 2023-04-17 10:59:23 +00:00
Adam Shih
240c435174 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: I9092e2e004e3ad0b3667b948ed4d633cd50d088c
2023-04-07 13:02:21 +08:00
Victor Liu
d87df92740 Merge "uwb: add permission for ccc ranging" into udc-dev 2023-04-06 20:57:49 +00:00
feiyuchen
391f954d5d Allow camera HAL to access edgetpu_app_service in gs101
We are seeing SELinux error b/276911450. It turns out that I only added the SE policy for 2023 device ag/22248613, but I forgot to add it for gs101 and gs201. So I created this CL.

See more background in ag/22248613.

Test: For gs201, I tested on my Pixel7 and I saw no more error. For gs101, I just did mm.
Bug: 275016466
Bug: 276911450
Change-Id: I3d691128daa2d7115f80c378f7b42de334cd8ed5
2023-04-04 21:32:36 +00:00
Bruno BELANYI
7838603828 Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I963fb55fb92ef5f91426dbec913c901e58cacf64
2023-04-04 13:04:00 +00:00
Victor Liu
a55bb8682c uwb: add permission for ccc ranging
Bug: 255649425
Change-Id: I05aac586146bf25569b5f6251d2fd62b921631be
2023-03-31 14:04:13 -07:00
Adam Shih
7cc3817f71 Move power dump text section out of hal_dumpstate_default
Bug: 273380985
Test: adb bugreport
Change-Id: I77b59ea719055972429b2b8a1349e52e0e1fe395
2023-03-28 15:03:22 +08:00
Adam Shih
5bfe1bdd6d Move camera text dump to dump_gs101
Bug: 273380985
Test: adb bugreport
Change-Id: Iba138e608885a1215515ec8cc5f5e997dfcfcf3f
2023-03-27 10:37:02 +08:00
Adam Shih
e7ea94d8e1 Move cma dump to itself
Bug: 273380985
Test: adb bugreport
Change-Id: I40ecb631c7fbbea216f5c56857b92152c997e466
2023-03-24 13:56:31 +08:00
KRIS CHEN
2f8f23232a Merge "Allow fingerprint hal to read sysfs_leds" into udc-dev 2023-03-24 02:06:37 +00:00
Kris Chen
d678ee3226 Allow fingerprint hal to read sysfs_leds
Fix the following avc denials:
avc: denied { search } for name="backlight" dev="sysfs" ino=79316
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=dir permissive=1

avc: denied { read } for name="state" dev="sysfs" ino=79365
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=file permissive=1

Bug: 271072126
Test: Authenticate fingerprint.
Change-Id: I67f5502bc7b4b1d6e14cf493f1bc6575980bcd0d
2023-03-21 12:19:07 +00:00
Jörg Wagner
cb6bad65e7 Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 74d31a1568)
Merged-In: I5c69a8bafe3a4c738c124facb1f437ec721cc3ea
Change-Id: I7e6734cb79b38898eb65a0194b37381a1367fc36
2023-03-21 10:31:51 +00:00
Adam Shih
4d9aa0b28f use devfreq dump from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: I0ea6767fd7640c2ee1be66f659f94c15cb4766cd
2023-03-21 12:41:23 +08:00
Jasmine Cha
3b3aa9e921 Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Jasmine Cha
b263562360 audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: Ie1499be82e405c2ddf4cd1a62ee7ff2823befd8e
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:10:18 +08:00
Adam Shih
7d3f25d95b Move display dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: Id40661687bbd04d7eba4790dc5fe17ca5c79e47d
2023-03-07 13:01:05 +08:00
Ken Tsou
6964113b1c hal_health_default: allow to access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 07:02:01 +00:00
Lucas Wei
6ef92ee0d1 Merge "votable: Update don't audit file entry" 2023-02-16 06:00:51 +00:00
Lucas Wei
5a70bbb335 votable: Update don't audit file entry
Test: No votable avc errors in dmesg
Bug: 247905787
Change-Id: I95ab4dd7750e9b0f26d41fece50dc6d0aa73dd41
Signed-off-by: Lucas Wei <lucaswei@google.com>
2023-02-15 02:49:08 +00:00
Treehugger Robot
580fb1061d Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f am: 60fc07a2f5
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I269fe35ddd8dc13df7b275a84f86955e2853563a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 20:44:30 +00:00
Treehugger Robot
60fc07a2f5 Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f am: 114e2a377f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: I624db1bdd6fbe5de7d774954f5390fb0af884b77
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 19:41:20 +00:00
Treehugger Robot
114e2a377f Merge "Map AIDL Gatekeeper to same policy as HIDL version" am: b72bb4c53f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2424201

Change-Id: Ib469bb013d0c7335e2da4f429cde4c5df9395ed5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-14 18:56:35 +00:00
Treehugger Robot
b72bb4c53f Merge "Map AIDL Gatekeeper to same policy as HIDL version" 2023-02-14 17:48:17 +00:00
Adam Shih
9a7bb8df86 Move memory dump to gs-common
Bug: 240530709
Test: adb bugreport
Change-Id: I78433d8d170af54a4daee6c9a9218ce35e78e730
2023-02-13 14:56:30 +08:00
Subrahmanyaman
b4ec2efe4b Map AIDL Gatekeeper to same policy as HIDL version
Bug: 268342724
Test: VtsHalGatekeeperTargetTest
Change-Id: I050860bfeb0e87830e554ed19bc1efe54e7db0a5
2023-02-08 18:37:15 +00:00
Ken Yang
8e9fa12996 Merge "WLC: Add required sysfs_wlc sepolicies" 2023-02-05 02:30:37 +00:00
Ray Chi
4003532648 [ DO NOT MERGE ] usb: Add sepolicy for extcon access am: 9828cc747a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21219300

Change-Id: I2c4f5571065ac696d32f5050d6b94f7957ddce3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-04 04:37:04 +00:00
Nicolas Geoffray
f485d48f43 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108 am: fa4c9c92e0
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Ia166fb782bc79702f9f064cf326af5872bfc1fb4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:54:42 +00:00
Nicolas Geoffray
fa4c9c92e0 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e am: 0090218108
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: Iab23f2032100e1105e1f1edaee8a4dd90f7ec2d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 16:25:08 +00:00
Nicolas Geoffray
0090218108 Allow ssr_detector_app directory creation in system_app_data_file. am: 514eb95f8e
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2419089

Change-Id: I510f6f8cc0dc2c609ec46a901738374bfd9d3217
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 15:34:58 +00:00
Taylor Nelms
c2769f1ede Modify permissions to allow dumpstate process to access decon_counters node am: ae39e117c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/21041858

Change-Id: I469375e8d9bf2fed575bbb9f972f4eeaa45fbb15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-03 13:47:31 +00:00
Nicolas Geoffray
514eb95f8e Allow ssr_detector_app directory creation in system_app_data_file.
Bug: 260557058
Test: m
Change-Id: Iad7bb0609d7ca3ae89d6583ba3638e36300538a1
2023-02-03 13:06:50 +00:00
Ray Chi
9828cc747a [ DO NOT MERGE ] usb: Add sepolicy for extcon access
USB gadget hal will access extcon folder so that this patch
will add new rule to allow USB gadget hal to access extcon.

Bug: 263435622
Test: verified pass
Change-Id: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
2023-02-02 15:22:33 +08:00
Ken Yang
fcb9c033a1 WLC: Add required sysfs_wlc sepolicies
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.

Bug: 267171670
Change-Id: Ic4dca7a34e8ed9b096a650b1df4bb58290425117
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-31 15:02:51 +00:00
Taylor Nelms
ae39e117c1 Modify permissions to allow dumpstate process to access decon_counters node
Bug: 240346564
Test: Build for Oriole device with "user" build,
check bugreport for decon_counters content
Merged-In: I71883632857e76cfead39b16560b3695e13a6746
Change-Id: I010a9e8809192a5a1ee5842d5ac973d874836cea
Signed-off-by: Taylor Nelms <tknelms@google.com>
2023-01-19 14:14:25 +00:00
Victor Barr
5eea830c6e Move Support for DBA HAL in common edgetpu packages
Previously supported in some cases. Now extend it to all common cases.

Bug: 263394888
Test: Built and ran DBA HAL on Android Device
Change-Id: I70db1fae6b9f5787c635bb2fcbabc7ee0e064a9f
2023-01-17 18:42:26 +00:00
Ken Yang
fc2efe09bd Merge "WLC: Cleanup the sysfs_wlc policies" 2023-01-13 14:41:30 +00:00
Kyle Zhang
bfbf488408 Merge "Add hal_drm_widevine for Widevine exec sepolicy" 2023-01-11 05:37:46 +00:00
Ken Yang
a49c3a5479 WLC: Cleanup the sysfs_wlc policies
The sepolicy must be self-contained without including wirelss_charger to
avoid build break in AOSP

Bug: 263830018
Change-Id: I4eee380ae61f83c5563ee8842a94fd1fb9e520ef
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-10 16:02:31 +00:00
Kyle Zhang
902db3961f Add hal_drm_widevine for Widevine exec sepolicy
Bug: 243699259
Test: atp v2/widevine-eng/drm_compliance
Change-Id: Ifede19e690cb7b7333016df08fb146a0ec8f7409
2023-01-06 03:14:20 +00:00
Chungkai Mei
f5ee8054e0 sepolicy: fix avc denial
fix avc denial when applying aosp/2333702

Bug: 261678056
Test: boot without avc denial
Change-Id: I4674a5cb13f2f06f011c380699353b1a561ad290
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-01-05 09:40:42 +00:00
Ken Yang
8c2188f24e Merge "WLC: Add gs101 specific sepolicy for wireless_charger" 2022-12-21 08:36:14 +00:00
Taylor Nelms
66bf88de5d Merge "Modify permissions to allow dumpstate process to access decon_counters node" 2022-12-21 01:41:40 +00:00
Ken Yang
33f94a5428 WLC: Add gs101 specific sepolicy for wireless_charger
Bug: 237600973
Change-Id: If25a921ba9f0261c7f71cb88425526f307df9064
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-21 00:49:26 +00:00
Devin Moore
d1ba957ec2 Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f am: ae8eb694fa
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I16211b9a52338bbf7569508877305dbc66d5228b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 21:46:17 +00:00
Devin Moore
ae8eb694fa Allow pixelstats hal to talk to the new AIDL sensorservice am: aede443b86 am: 3b4beeb98f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2364600

Change-Id: I74400a040ba88d35a9eda207eb6eabf712627799
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-20 20:57:13 +00:00
Devin Moore
aede443b86 Allow pixelstats hal to talk to the new AIDL sensorservice
This is being used in libsensorndkbridge now, so permissions are
required.

Test: m
Bug: 205764765
Change-Id: I65945c8b259538d274da23d8ecc6cf4d2362dcbd
2022-12-19 23:42:23 +00:00
TreeHugger Robot
5aa010e054 Merge "modem_svc_sit: grant the modem property access" into tm-qpr-dev am: ca047e8607 am: ad5f8a13d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20502509

Change-Id: I79eaaa294adfa16f32362e2c5134f783c8aaa352
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-19 14:23:42 +00:00