Commit graph

4238 commits

Author SHA1 Message Date
Kyle Lin
1124aeaf32 Add policy for memlat governor needs create/delete perf events
[   31.756984] type=1400 audit(1620144320.436:11): avc: denied { perfmon } for comm="cpuhp/4" capability=38 scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=capability2 permissive=0
[   31.757246] type=1400 audit(1620144320.436:12): avc: denied { sys_admin } for comm="cpuhp/4" capability=21 scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=capability permissive=0
[   31.757352] type=1400 audit(1620144320.436:13): avc: denied { perfmon } for comm="cpuhp/4" capability=38 scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=capability2 permissive=0
[   31.757450] type=1400 audit(1620144320.436:14): avc: denied { sys_admin } for comm="cpuhp/4" capability=21 scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=capability permissive=0
...
...
[  215.584932] type=1400 audit(1620634018.936:191): avc: denied { cpu } for comm="cpuhp/4" scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=perf_event permissive=0

Bug: 187437491
Bug: 170479743
Test: build, boot and suspend/resume test 200 times.

Change-Id: I4fd3d3fb915ca518ffa226f25298c94faaf867f1
2021-05-10 16:18:58 +08:00
chenpaul
6297e8a5a7 Sniffer Logger: Add dontaudit getattr for sysfs_wifi
05-10 15:04:37.376 12958 12958 I auditd  : type=1400 audit(0.0:14): avc: denied { getattr } for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs" ino=81201 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0 tclass=file permissive=0

Bug: 187583019
Test: Sniffer Logger is workable
Change-Id: I6bce0bb58d951b6be39f58340b6418b328ffe386
2021-05-10 15:28:47 +08:00
JJ Lee
2a2ce4a0ae Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev am: df02b6ef77 am: 51c75a291e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14452416

Change-Id: I085a5e10dc22ac41c84c98614dbe3133c5971d40
2021-05-10 02:58:04 +00:00
JJ Lee
51c75a291e Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev am: df02b6ef77
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14452416

Change-Id: I9da7211554c5f2fdce509051caa4f3b2e381f9c1
2021-05-10 02:34:31 +00:00
JJ Lee
4be4faa1dc Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev am: df02b6ef77
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14452416

Change-Id: I51e769688205bbb6ea24e4afe736f22876e7b104
2021-05-10 02:31:46 +00:00
JJ Lee
7a46007222 Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev am: df02b6ef77
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14452416

Change-Id: I662932d3b069766e8c915578610b2524e8c8d396
2021-05-10 02:31:37 +00:00
JJ Lee
df02b6ef77 Merge "sepolicy: gs101: allow audio hal to use wakelock" into sc-dev 2021-05-10 02:14:07 +00:00
TreeHugger Robot
df80f0be9f Merge "vibrator: Remove temporary method" into sc-dev am: ec3144742f am: e853b4335e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467421

Change-Id: I6170cab39b5fec5c777500dab7506fafafba7000
2021-05-10 01:58:17 +00:00
TreeHugger Robot
eb15c49e77 Merge changes Ic697ffe8,Idcf38e09 into sc-dev am: a2d2ebd508 am: 41d657e591
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456725

Change-Id: I7c502814dadb2a5bb026fb856b0d8a6c7905085a
2021-05-10 01:57:50 +00:00
TreeHugger Robot
e853b4335e Merge "vibrator: Remove temporary method" into sc-dev am: ec3144742f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467421

Change-Id: I8abc6a5985a10691d2a6b2350aaf7c1b3b523056
2021-05-10 01:41:55 +00:00
TreeHugger Robot
41d657e591 Merge changes Ic697ffe8,Idcf38e09 into sc-dev am: a2d2ebd508
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456725

Change-Id: I31ebc93fd8a8a664f75e623c007482fa345a1248
2021-05-10 01:41:42 +00:00
TreeHugger Robot
11accc9f2f Merge "vibrator: Remove temporary method" into sc-dev am: ec3144742f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467421

Change-Id: I4a0d4f360b28e6a0496f8887488f76824d867808
2021-05-10 01:40:05 +00:00
TreeHugger Robot
26cf3f59ac Merge changes Ic697ffe8,Idcf38e09 into sc-dev am: a2d2ebd508
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456725

Change-Id: Ia366cfb74424fe2d8dbba868c92649fbc738fc47
2021-05-10 01:39:57 +00:00
TreeHugger Robot
bba2a7a0c9 Merge "vibrator: Remove temporary method" into sc-dev am: ec3144742f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467421

Change-Id: Ieb1405f8124528b337ee3273ebe79b6c522c2f44
2021-05-10 01:39:54 +00:00
TreeHugger Robot
0121aed44a Merge changes Ic697ffe8,Idcf38e09 into sc-dev am: a2d2ebd508
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456725

Change-Id: I55d5ff71adec66427fb69a36bfd17a8cc7a37d0b
2021-05-10 01:39:34 +00:00
TreeHugger Robot
ec3144742f Merge "vibrator: Remove temporary method" into sc-dev 2021-05-10 01:13:47 +00:00
TreeHugger Robot
a2d2ebd508 Merge changes Ic697ffe8,Idcf38e09 into sc-dev
* changes:
  Remove dumpstate AVC denials dontaudit for twoshay
  Allow dumpstate to access twoshay
2021-05-10 01:11:46 +00:00
TreeHugger Robot
73f7604819 Merge "Allow radioext to communicate with bt hal" into sc-dev am: c03c055812 am: 93008dc81a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456718

Change-Id: I04601b7854246242a3e73d12ceb0491c7428c3c4
2021-05-08 19:33:35 +00:00
TreeHugger Robot
93008dc81a Merge "Allow radioext to communicate with bt hal" into sc-dev am: c03c055812
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456718

Change-Id: I3d1fed21b348e309acf8c981d0295fc0c6db1597
2021-05-08 19:13:26 +00:00
TreeHugger Robot
c3c5ca4ddb Merge "Allow radioext to communicate with bt hal" into sc-dev am: c03c055812
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456718

Change-Id: Ie6e2ad1c7f522db72d1376aae37c5501f85e29be
2021-05-08 19:10:01 +00:00
TreeHugger Robot
4e4b697ebc Merge "Allow radioext to communicate with bt hal" into sc-dev am: c03c055812
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456718

Change-Id: Ieab3a480c6a09103b09b09f5f238f975ee4845ad
2021-05-08 19:09:55 +00:00
TreeHugger Robot
c03c055812 Merge "Allow radioext to communicate with bt hal" into sc-dev 2021-05-08 18:59:51 +00:00
TreeHugger Robot
73e866b8c8 Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev am: 296f8ddc5d am: cb8de215f8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14440528

Change-Id: I5f0f438dd488cb64579f777809ddf2ab31fd9926
2021-05-07 23:59:40 +00:00
TreeHugger Robot
cb8de215f8 Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev am: 296f8ddc5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14440528

Change-Id: I99470e75b9839107b8ea89232437d3c91a722a23
2021-05-07 23:45:52 +00:00
TreeHugger Robot
978d75fba7 Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev am: 296f8ddc5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14440528

Change-Id: I336b1e613abebe0e56faf3732dce5d3fea52b0dc
2021-05-07 23:43:53 +00:00
TreeHugger Robot
776d3de596 Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev am: 296f8ddc5d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14440528

Change-Id: I99208ec0b4e5af7ae08b16e7bc4dc2e1c1a9894d
2021-05-07 23:43:49 +00:00
TreeHugger Robot
296f8ddc5d Merge "iwlan: update sepolicy for qualifiednetworksservice" into sc-dev 2021-05-07 23:29:31 +00:00
chasewu
59161a5745 vibrator: Remove temporary method
Bug: 177176811
Test: no avc denied logs
Signed-off-by: chasewu <chasewu@google.com>
Change-Id: I424e15037b3e20824f5e072d88bdf71a50cfdabf
2021-05-07 18:33:15 +08:00
Seungah Lim
72e6339123 iwlan: update sepolicy for qualifiednetworksservice
Bug: 185942456
Test: VoLTE/VoWifi

Change-Id: I352bb933e577b11bb052a297d17776ff0a5f3a75
Signed-off-by: Seungah Lim <sss.lim@samsung.com>
2021-05-07 17:14:00 +08:00
Tai Kuo
8e3aaa30ff Remove dumpstate AVC denials dontaudit for twoshay
Bug: 187014717
Test: pts-tradefed run pts -m PtsSELinuxTest -t \
  com.google.android.selinux.pts.SELinuxTest#scanBugreport
Signed-off-by: Tai Kuo <taikuo@google.com>
Change-Id: Ic697ffe8f6ee15fb9d9330173a3c92aeca61de67
2021-05-07 14:56:22 +08:00
Tai Kuo
0e68aed154 Allow dumpstate to access twoshay
Bug: 173330981
Bug: 187014717
Test: no avc denials for twoshay was found.
Signed-off-by: Tai Kuo <taikuo@google.com>
Change-Id: Idcf38e0921fb4d6d617e7cd443425193aea3fe91
2021-05-07 14:55:43 +08:00
Jia-yi Chen
15c046878b Add high_capacity_start_cpu to u:object_r:sysfs_vendor_sched:s0
Bug: 186564130
Test: Boot & check powerhal log
Change-Id: I1a828f113266d4b3386b2f6fa74df050255113a9
2021-05-06 21:00:08 -07:00
Labib
a27f8c4480 Allow radioext to communicate with bt hal
Bug: 187447420
Change-Id: I1a1626502a6c3913846b957c3c0a31fdd99feb31
2021-05-07 09:20:02 +08:00
Tri Vo
b38ed0c788 Merge "trusty: sepolicy for metrics reporter" into sc-dev am: f7bec8b3c6 am: f40a4f7416
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14286451

Change-Id: I03c47276db396ec87b7f6bb27af99fa4033e7b52
2021-05-06 16:29:52 +00:00
Tri Vo
f40a4f7416 Merge "trusty: sepolicy for metrics reporter" into sc-dev am: f7bec8b3c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14286451

Change-Id: I9723772bdbd3c02e6af0e7348d45a3717a19cc0c
2021-05-06 16:09:53 +00:00
Tri Vo
7c585329ec Merge "trusty: sepolicy for metrics reporter" into sc-dev am: f7bec8b3c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14286451

Change-Id: I65819ea555dafbd575e26c1f9e45fbb1ce8617ff
2021-05-06 16:08:19 +00:00
Tri Vo
da485f1270 Merge "trusty: sepolicy for metrics reporter" into sc-dev am: f7bec8b3c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14286451

Change-Id: I3442adb02d7ae36f4533c2b94154a7c32ca9ea6f
2021-05-06 16:08:09 +00:00
Tri Vo
f7bec8b3c6 Merge "trusty: sepolicy for metrics reporter" into sc-dev 2021-05-06 15:52:51 +00:00
JJ Lee
43735f0fc3 sepolicy: gs101: allow audio hal to use wakelock
Bug: 178789331
Test: build pass
Signed-off-by: JJ Lee <leejj@google.com>
Change-Id: I1d5c9ea8726f2e53bc05e0ecd5dedddede274794
2021-05-06 19:43:24 +08:00
Aaron Tsai
e4773d1db2 Fix avc denied for shannon-ims am: 6a9a85cd07 am: 71aa99edff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14410097

Change-Id: I8935b75ce3632935b127d7c1a4038886d40461bf
2021-05-06 11:07:46 +00:00
Aaron Tsai
71aa99edff Fix avc denied for shannon-ims am: 6a9a85cd07
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14410097

Change-Id: I84e986338a7985fe26cdf179bd1734771956defa
2021-05-06 10:53:09 +00:00
Aaron Tsai
c49f82b712 Fix avc denied for shannon-ims am: 6a9a85cd07
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14410097

Change-Id: I480df5510301d889390c92f2cad68c0fb4e489e5
2021-05-06 10:51:12 +00:00
Aaron Tsai
2cea3621b0 Fix avc denied for shannon-ims am: 6a9a85cd07
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14410097

Change-Id: I5289bf698f1bfad5074d446beff9aeeace50e27d
2021-05-06 10:49:37 +00:00
Aaron Tsai
6a9a85cd07 Fix avc denied for shannon-ims
04-01 19:10:22.956 10272  2327  2327 W Binder:2327_4: type=1400 audit(0.0:8): avc: denied { read } for name="u:object_r:default_prop:s0" dev="tmpfs" ino=139 scontext=u:r:vendor_ims_app:s0:c16,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.shannon.imsservice
04-01 19:10:22.960 10272  2327  4608 E libc    : Access denied finding property "persist.dbg.wfc_avail_ovr0"
04-01 19:10:22.981 10272  2327  4608 E libc    : Access denied finding property "persist.dbg.vt_avail_ovr0"
04-01 19:10:22.982 10272  2327  4980 E libc    : Access denied finding property "persist.dbg.volte_avail_ovr0"

Bug: 183935382
Bug: 184858478
Test: verified with the forrest ROM and error log goneFix
Change-Id: I0754c6be7f74ed73533e9570c7d1916320ab2897
2021-05-06 09:04:03 +00:00
TreeHugger Robot
647dcaf48d Merge "HardwareInfo: Add sepolicy for display" into sc-dev am: 6978eeaea4 am: 5bb2c8ab79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13824666

Change-Id: I30ae225a60b80f8167c4dd9a3723725d6e53ab3c
2021-05-06 06:31:05 +00:00
TreeHugger Robot
51380a7089 Merge "wlc fwupdate implementation" into sc-dev am: 577f562727 am: 9fccfb01ce
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14063269

Change-Id: Ie01bf8328923a33c63ae7070dac41e687afdeec5
2021-05-06 06:30:22 +00:00
TreeHugger Robot
5f2f2a672b Merge "HardwareInfo: Add sepolicy for display" into sc-dev am: 6978eeaea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13824666

Change-Id: I79da8abcc3cdaab61fe2932fa8da8ab9f6400eef
2021-05-06 06:13:04 +00:00
TreeHugger Robot
89e2f50371 Merge "HardwareInfo: Add sepolicy for display" into sc-dev am: 6978eeaea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13824666

Change-Id: Id3e71b7c4c9b920ec277716861ec6a9b2e6b12a4
2021-05-06 06:12:55 +00:00
TreeHugger Robot
5bb2c8ab79 Merge "HardwareInfo: Add sepolicy for display" into sc-dev am: 6978eeaea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13824666

Change-Id: Ifa6682feee948555974d8776d60accb4cc3b356e
2021-05-06 06:07:06 +00:00
TreeHugger Robot
6978eeaea4 Merge "HardwareInfo: Add sepolicy for display" into sc-dev 2021-05-06 06:03:18 +00:00