Commit graph

4238 commits

Author SHA1 Message Date
TreeHugger Robot
a85442bd10 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012

Change-Id: Ib1fe025493a3021d69bf7f79c8809098933ba1b8
2021-05-25 19:05:23 +00:00
TreeHugger Robot
477e19f032 Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev 2021-05-25 18:45:37 +00:00
TreeHugger Robot
2755d9f535 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: cb80570b92 am: be0ea48cef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I7dbf7bd64e47bac0ee9313b4f9d55df779f0ba7e
2021-05-25 12:55:52 +00:00
TreeHugger Robot
91efdd8266 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: eeb41949c2 am: 667ba8cb19
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: Ibca092073fb4ce8cee4afe15f4d995d6fe80b9e3
2021-05-25 12:55:27 +00:00
TreeHugger Robot
be0ea48cef Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: cb80570b92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: Ifa1536ee09f4cd8b3c048001798d5a2b6368bd70
2021-05-25 11:58:29 +00:00
TreeHugger Robot
667ba8cb19 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13 am: eeb41949c2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I87d15c071e3de40b367badbe185db35cc14bb332
2021-05-25 11:51:11 +00:00
TreeHugger Robot
cb80570b92 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I594759be23e922d975f395da8a1d363925dc30ca
2021-05-25 11:50:55 +00:00
TreeHugger Robot
eeb41949c2 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138

Change-Id: I7a32e0b2bcef407665e75e58d0af2db52c08323b
2021-05-25 11:49:35 +00:00
TreeHugger Robot
57eefb5b13 Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev 2021-05-25 10:12:38 +00:00
Ocean Chen
b8aebc85e1 storage: update sepolicy for hardwareinfoservice
avc: denied { search } for name="0:0:0:0" dev="sysfs" ino=57525 scontext=u:r:hardware_info_app:s0:c512,c768 avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo

avc: denied { read } for name="vpd_pg80" dev="sysfs" ino=57559 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="model" dev="sysfs" ino=57534 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vendor" dev="sysfs" ino=57533 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="rev" dev="sysfs" ino=57535 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="eol_info" dev="sysfs" ino=57020 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="life_time_estimation_a" dev="sysfs" ino=57021 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo

Bug: 188755652
Test: reboot then check hardwareinfo and avc denined log
Change-Id: Ia03ebdd6b0b46b4c9ace5fbf1fc47a455a55abcb
2021-05-25 16:57:20 +08:00
Roger Fang
2ca5dff832 Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 21d7509c17 am: 594eecad3e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I1e7842f1594234b674714d5be3e637e9f5ff3fa5
2021-05-25 02:18:51 +00:00
Roger Fang
c35b8c491e Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 292faf8ed3 am: 8522122b5f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I11e4eb0a8c44b5098f0835c078a4f111230bcd37
2021-05-25 02:18:00 +00:00
Roger Fang
594eecad3e Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 21d7509c17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I1d70340b2152d73bec3d51651bb10f68e91952ae
2021-05-25 01:49:44 +00:00
Roger Fang
8522122b5f Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a am: 292faf8ed3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I9278fff7d05c8e65bd8a9e4d39cc4a1a380ca10f
2021-05-25 01:47:48 +00:00
Roger Fang
292faf8ed3 Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: I929b5c4b1f37c2e0d8bee655fc0141a5a0bbbd4e
2021-05-25 01:24:04 +00:00
Roger Fang
21d7509c17 Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016

Change-Id: If394b6c1a719b26a295b97980b94fb217442ef76
2021-05-25 01:22:03 +00:00
Ines Ayara
7593a655ed Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 304a92ea86 am: b311856023
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: Ie6de0c54669ccbad8f3d267596e370c62feaea56
2021-05-25 01:05:02 +00:00
Ines Ayara
cd4e8e3737 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 1a7f873b06 am: 23ccf9362e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I3c2abc270c2cada2124f86fa51687deb49225988
2021-05-25 01:04:03 +00:00
Roger Fang
56cbfd5a0a Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev 2021-05-25 01:02:39 +00:00
Ines Ayara
b311856023 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 304a92ea86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I1c76cbd2013a9a3b4c8ca34184796a5a2719fdba
2021-05-25 00:41:40 +00:00
Ines Ayara
23ccf9362e Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187 am: 1a7f873b06
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I330983da9a9c6d35f341c15cb5c367e3be7a6ce7
2021-05-25 00:39:48 +00:00
Ines Ayara
1a7f873b06 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: I46ee22509e42f4baf7df226b2e2eedcf3ecfaa6c
2021-05-25 00:18:54 +00:00
Ines Ayara
304a92ea86 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412

Change-Id: Ie52a7d786c4344a7ba0e8bf6bbba87ae7f9d0999
2021-05-25 00:16:44 +00:00
Vinay Kalia
68849437bd Allow mediacodec to access the vframe-secure DMA-BUF heap
This patch fixes the following denial:

HwBinder:751_2: type=1400 audit(0.0:9): avc: denied { open } for
path="/dev/dma_heap/vframe-secure" dev="tmpfs" ino=734
scontext=u:r:mediacodec:s0 tcontext=u:object_r:vframe_heap_device:s0
tclass=chr_file permissive=0

Bug: 188121584
Test: AV1 secure video playback

Signed-off-by: Vinay Kalia <vinaykalia@google.com>
Change-Id: I455b39914dd4316a427f5f756b4fb94a2c4db204
2021-05-24 23:57:28 +00:00
Ines Ayara
dfb3783187 Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev 2021-05-24 23:55:32 +00:00
Roger Fang
a97bfcc1e1 sepolicy: gs101: add permission for the hardware info dsp part number
Bug: 188757638
Test: Manually test passed

Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: Id0c3226411b058b613b92e67174f14e64c6c3a2b
2021-05-24 08:16:34 +00:00
Chase Wu
0924a30a37 Merge "genfs_contexts: fix path for cs40l25a i2c devices" into sc-v2-dev am: 80ab102382 am: 373fed0402
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14675588

Change-Id: I4c5e3bd7131eeca02c6acf1dcb0220dca87c8fc5
2021-05-24 01:35:39 +00:00
Chase Wu
373fed0402 Merge "genfs_contexts: fix path for cs40l25a i2c devices" into sc-v2-dev am: 80ab102382
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14675588

Change-Id: Id5204cd25e6fa512e485fc771cd1982b0e8f55dd
2021-05-24 01:20:31 +00:00
Chase Wu
80ab102382 Merge "genfs_contexts: fix path for cs40l25a i2c devices" into sc-v2-dev 2021-05-24 01:03:51 +00:00
Rick Yiu
5aeb1b9e45 gs101-sepolicy: Allow dumping vendor groups values
Fix:
avc: denied { read } for name="vendor_sched" dev="sysfs" ino=45566 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=dir permissive=0

avc: denied { read } for name="dump_task_group_ta" dev="proc" ino=4026532542 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=0

Bug: 172112042
Test: dump data as expected
Change-Id: I9945953dba4afddd34c1535c12193b1f00fdcef9
2021-05-22 21:30:47 +08:00
Grace Chen
9aac443958 Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c am: f8cf5a7354 am: 2930cbecc8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I3690feb255d227aebef57b9f33656590f5dcafc8
2021-05-21 19:54:23 +00:00
Grace Chen
b5b17de9f7 Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c am: ebadda8749 am: cd5abb427f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I6203e687fa579baa11bbe551cb1c0964f0d82791
2021-05-21 19:53:43 +00:00
Grace Chen
2930cbecc8 Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c am: f8cf5a7354
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I60b4d83788f3a3050341d5fea90500d193b69405
2021-05-21 19:39:12 +00:00
Grace Chen
cd5abb427f Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c am: ebadda8749
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I911c9d6ce67e9632b51dd1b6395cd59f59e1b29f
2021-05-21 19:37:36 +00:00
Grace Chen
ebadda8749 Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I62e7a0b9ff71f63221d6eaaad17a9333183912ec
2021-05-21 19:15:18 +00:00
Grace Chen
f8cf5a7354 Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065

Change-Id: I3ea91e07cb86b9ccbe5c27fdbd29eee2cb4512c6
2021-05-21 19:14:16 +00:00
Grace Chen
16a38b2b6c Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev 2021-05-21 19:10:52 +00:00
chasewu
168a6b0c72 genfs_contexts: fix path for cs40l25a i2c devices
Due to recent changes which modifies the device name for i2c devices,
cs40l25a device names are now changed from ?-0043 and ?-0042 to
"i2c-cs40l25a" and "i2c-cs40l25a-dual"

Bug: 188078957
Bug: 188651116
Test: manual check avc denied logs
Signed-off-by: chasewu <chasewu@google.com>
Change-Id: I97d3a030c94166f8e2cda7daa38166b1532b6d9f
2021-05-21 17:32:53 +08:00
TreeHugger Robot
af3d05b467 Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e am: 62e330941f am: 2181d522f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: I7666583ab9d9d165f4438c6f5f116eb7f1203fa3
2021-05-21 07:35:50 +00:00
TreeHugger Robot
fe9ca33bd0 Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e am: 257af6acb7 am: dc8c0f809d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: I32937a8dc1ed31ece7ec8e83f0d03349c5c90c13
2021-05-21 07:35:12 +00:00
TreeHugger Robot
2181d522f2 Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e am: 62e330941f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: I63745fe15fde523fadda9500cd759c9b71e12ee7
2021-05-21 07:21:25 +00:00
TreeHugger Robot
dc8c0f809d Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e am: 257af6acb7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: Ib3e9bc54dc3bb1e8bbebe07fe75ed5c23a132076
2021-05-21 07:19:35 +00:00
TreeHugger Robot
257af6acb7 Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: I57862e73bb90e64631501678dac852a7e4d96d45
2021-05-21 06:59:14 +00:00
TreeHugger Robot
62e330941f Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586

Change-Id: I1f5224c5e295837500f52c7f2a91c7cf0c12e748
2021-05-21 06:57:16 +00:00
TreeHugger Robot
b42a03fa9e Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev 2021-05-21 06:41:20 +00:00
SHUCHI LILU
85c06dce3c Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7 am: d041f55312 am: c685a924df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737

Change-Id: Icc29858c5a94063aeec2f8647eafaf207bbe5bcc
2021-05-21 02:53:56 +00:00
SHUCHI LILU
f680c33593 Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7 am: aeb7f90af4 am: 119ce0c72d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737

Change-Id: I857f5300f91a604aacc0154ec0c9fa3f11ff39bf
2021-05-21 02:53:03 +00:00
SHUCHI LILU
c685a924df Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7 am: d041f55312
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737

Change-Id: Id1b3d85c7bd1ad4e4c223d0b8664f04ba519294e
2021-05-21 02:45:49 +00:00
SHUCHI LILU
119ce0c72d Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7 am: aeb7f90af4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737

Change-Id: I24ff7f799fb7fbcf9ef61d95670f8838d7c8f361
2021-05-21 02:40:37 +00:00
SHUCHI LILU
d041f55312 Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737

Change-Id: Ifa70b0837abb760f0d98ed67c2ecb00687e4ba04
2021-05-21 02:24:48 +00:00