Commit graph

1256 commits

Author SHA1 Message Date
KRIS CHEN
4108dc59c6 Merge "Add sepolicy rules for fingerprint hal" into sc-dev am: ba9051de47
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15223175

Change-Id: I610ada122ff075bff8ef9e446fa91ceac293bf09
2021-07-08 02:22:04 +00:00
Bo-Yuan Ye
20dd1ef66c [3A Coordinator] Enable to property_set for log.tag. prefix
major changes:
        1. add log_tag_prop for hal_camera_default

Test: go/p21-camera-test-checklist
Bug: 191923902
Change-Id: I767c235666c6761af6d21178d829a0f7cb8d42c8
2021-07-08 10:15:23 +08:00
KRIS CHEN
ba9051de47 Merge "Add sepolicy rules for fingerprint hal" into sc-dev 2021-07-08 02:05:03 +00:00
Myung-jong Kim
99e75b6ab9 [RCS] Update sepolicy for RCS
Fix seapp_contexts sepolicy for shannon-rcs, where
:shannonrcsservice process exceptions are not handled

Bug: 190581528
Signed-off-by: Myung-jong Kim <mj610.kim@samsung.com>
Change-Id: I15cbf103cea70f6db878305a8fca6b35aa521f9b
2021-07-07 10:57:12 -07:00
Maciej Zenczykowski
b181dcf9f5 Merge "add sepolicy for set_usb_irq.sh" into sc-dev am: 9b270f0fc5 am: cb63eaae07 am: fec4ea662f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15219696

Change-Id: I59ef2ad246ce2e059837c1aa6932a13286e5369c
2021-07-07 17:01:11 +00:00
Kris Chen
a5c9028ced Add sepolicy rules for fingerprint hal
Fix following avc denial:
servicemanager: type=1400 audit(0.0:8): avc: denied { call } for scontext=u:r:servicemanager:s0 tcontext=u:r:hal_fingerprint_default:s0 tclass=binder permissive=0

Bug: 192040144
Test: No above avc denial in logcat.
Change-Id: I1b93474cac4ccb24736bc97665a7ca533ef0a7d3
2021-07-08 00:59:49 +08:00
Maciej Zenczykowski
fec4ea662f Merge "add sepolicy for set_usb_irq.sh" into sc-dev am: 9b270f0fc5 am: cb63eaae07
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15219696

Change-Id: I5698d2394de8dc8d2afcd91f2ad7d8945c432aab
2021-07-07 16:48:04 +00:00
Maciej Zenczykowski
1886ddd1af Merge "add sepolicy for set_usb_irq.sh" into sc-dev am: 9b270f0fc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15219696

Change-Id: I02f1d2dd5a9837c90a67db03f83cb9d8e7e6708a
2021-07-07 16:36:33 +00:00
Maciej Zenczykowski
9b270f0fc5 Merge "add sepolicy for set_usb_irq.sh" into sc-dev 2021-07-07 16:23:13 +00:00
Maciej Żenczykowski
714075eba7 add sepolicy for set_usb_irq.sh
Bug: 185092876
Test: TreeHugger, booted on oriole, enabled/disabled tethering
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: I7361a4390197e04b27eaf153a696e3f800f79b55
2021-07-07 16:22:33 +00:00
Randall Huang
e7313f6a03 Fix overlayfs avc denied am: d328008234 am: decd3637ef am: 86a1fff3a1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15211714

Change-Id: I5c0085680d4d5149e30ace21231f44d6a0d64c98
2021-07-07 02:37:54 +00:00
Randall Huang
decd3637ef Fix overlayfs avc denied am: d328008234
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15211714

Change-Id: Iebb750cacabf23753ce15d8d075d1e11867cb34b
2021-07-07 02:07:58 +00:00
Randall Huang
d328008234 Fix overlayfs avc denied
avc: denied { rename } for comm="init" name="#b" dev="dm-6" ino=52
scontext=u:r:init:s0 tcontext=u:object_r:overlayfs_file:s0
tclass=file permissive=1

avc: denied { unlink } for comm="init" name="#b" dev="dm-6" ino=53
scontext=u:r:init:s0 tcontext=u:object_r:overlayfs_file:s0
tclass=chr_file permissive=1

Bug: 192617244
Test: boot & adb remount
Signed-off-by: Randall Huang <huangrandall@google.com>
Change-Id: I740ff317520439034d2bf6e0659b1418bf6dac5c
2021-07-06 18:19:04 +08:00
TreeHugger Robot
e0de88e4dc Merge "Add system file of INT clock to sysfs_fabric group" into sc-dev am: 8318f84aef am: 658fee07c2 am: 34ab6a3951
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15152132

Change-Id: Ide59e16a43a606b1d432ac88c1be150a7bea420e
2021-07-06 01:58:32 +00:00
TreeHugger Robot
658fee07c2 Merge "Add system file of INT clock to sysfs_fabric group" into sc-dev am: 8318f84aef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15152132

Change-Id: I81b56ac19c9b6305037ffda1c2fe72c0505ece6d
2021-07-06 01:27:27 +00:00
TreeHugger Robot
8318f84aef Merge "Add system file of INT clock to sysfs_fabric group" into sc-dev 2021-07-06 01:12:21 +00:00
Yu(Swim) Chih Ren
3aa97b5012 Add system file of INT clock to sysfs_fabric group
It is for power hal can access system file of INT clock

Bug: 168654554

Test: 1. Check file group of INT clock system file
      2. P21 Camera Test Checklist done

Change-Id: I1952c5d2ae39c338c9d2ccb8db49d1d119943c06
2021-07-06 00:33:55 +00:00
David Chen
81cf2f8a10 Merge "Allow twoshay to access fwk_stats_service and system_server" 2021-07-05 08:18:22 +00:00
Miller Liang
a8d0ff23c5 Merge "Fix AAudio avc denied" into sc-dev am: a21c6081c9 am: 8fc8ba0691
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15197030

Change-Id: I453bfbfc9ee0e6f7f0467ad012076e9bb7b68a3e
2021-07-05 02:57:23 +00:00
davidycchen
6e7338095b Allow twoshay to access fwk_stats_service and system_server
avc:  denied  { find } for pid=813 uid=0
name=android.frameworks.stats.IStats/default scontext=u:r:twoshay:s0
tcontext=u:object_r:fwk_stats_service:s0 tclass=service_manager

avc: denied { call } for scontext=u:r:twoshay:s0
tcontext=u:r:system_server:s0 tclass=binder

Bug: 179334953
Test: Make selinux_policy and push related files to the device.

Signed-off-by: davidycchen <davidycchen@google.com>
Change-Id: Ib95debbc9ce10919c5f935e8f70b340bb293b54a
2021-07-05 10:50:53 +08:00
Miller Liang
96e42a92ec Merge "Fix AAudio avc denied" into sc-dev am: a21c6081c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15197030

Change-Id: Icac39dfd3374ba28563a6b4254086dda6d5a9e72
2021-07-05 02:46:21 +00:00
Miller Liang
a21c6081c9 Merge "Fix AAudio avc denied" into sc-dev 2021-07-05 02:32:11 +00:00
millerliang
1e748ab270 Fix AAudio avc denied
E SELinux : avc:  denied  { find } for pid=765 uid=1041 name=audio
scontext=u:r:audioserver:s0 tcontext=u:object_r:audio_service:s0
tclass=service_manager permissive=0

Bug: 191103346
Test: build and run CtsNativeMediaAAudioTestCases
Change-Id: I8e9a41360a382ba5f461818b9f8d6658dd53c62a
2021-07-03 05:40:22 +00:00
TreeHugger Robot
6e8e0a52a0 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev am: 846cba7286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15164003

Change-Id: I69d7c6077426c73f871a3c0710f57d1c043d18c5
2021-07-01 08:25:49 +00:00
TreeHugger Robot
846cba7286 Merge "Fix hal_uwb_default dumpstate SELinux errors" into sc-dev 2021-07-01 08:07:05 +00:00
Michael Ayoubi
56beb62f69 Fix hal_uwb_default dumpstate SELinux errors
Fixes: b/192026913
Test: Run dumpstate and confirm no avc denials

Signed-off-by: Michael Ayoubi <mayoubi@google.com>
Change-Id: I3d818fb066a834663dc63b8757bd16c08a1a0e9e
2021-07-01 06:55:42 +00:00
Krzysztof Kosiński
fdfbdf2bd6 Allow Power Stats HAL to access EdgeTPU sysfs files. am: 6d6a7c96ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15162531

Change-Id: I19b0b15c286cab140ed77b7eb2c3a741641da6de
2021-06-30 23:58:01 +00:00
Krzysztof Kosiński
6d6a7c96ab Allow Power Stats HAL to access EdgeTPU sysfs files.
Should fix intermittent failures of SELinuxUncheckedDenialBootTest.

Bug: 192485697
Test: build, checked for denials in logcat
Change-Id: I3b9cafd99f9ff343e5ab5c67f5f268e5eb4382d6
2021-06-30 14:02:27 -07:00
Michael Ayoubi
0ed8e6763c Merge "allow recovery and fastboot to access secure elment" into sc-dev am: 075ba05575
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15152134

Change-Id: If808d197690820295f130d394c91a824a25ee834
2021-06-30 17:57:47 +00:00
Michael Ayoubi
075ba05575 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-30 17:39:40 +00:00
Jeffrey Carlyle
14fcd5ffaf allow recovery and fastboot to access secure elment
This is to enable clearing of secure element during a master reset.

Bug: 182508814
Test: master reset on device with keys; verified no keys after reset
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I9bb569e09f8cd6f5640757bd0d10a14ef32946ff
2021-06-30 15:19:22 +09:00
Gazi Yamin Iqbal
737622596d Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev am: 2e1cafdfd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15100489

Change-Id: I537e8c41624e8d8d85590d550691f6cda7266853
2021-06-30 05:58:42 +00:00
Gazi Yamin Iqbal
2e1cafdfd8 Merge "gs101-sepolicy: allow rlsservice to read display status files" into sc-dev 2021-06-30 05:41:19 +00:00
George Lee
4aa936d63b pixelstats: add bcl directory permission
Bug: 186806028
Test: Local test
$>cmd stats print-logs
$>logcat | grep <atom id>

Signed-off-by: George Lee <geolee@google.com>
Change-Id: I7288a9ab44e2387d37c5442297cf80f5b5428c8f
2021-06-29 16:08:38 -07:00
Kevin Han
fcd18a6e4d Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev am: 1d54c8dd21
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145159

Change-Id: Ie5ffd99597f2b00758126fabf8032c94a8208a16
2021-06-29 19:51:41 +00:00
Kevin Han
1d54c8dd21 Merge "Revert "allow recovery and fastboot to access secure elment"" into sc-dev 2021-06-29 19:33:01 +00:00
Kevin Han
fd47b11162 Revert "allow recovery and fastboot to access secure elment"
Revert "add gs101-specific recovery library"

Revert "recovery: enable support for device-specific WipeSe impl..."

Revert "clear secure element of Digital Car Keys during factory ..."

Revert submission 14983788-clear_keys

Reason for revert: b/192373955
Reverted Changes:
Ia8fc29e6c:add gs101-specific recovery library
Icc1eabfd4:clear secure element of Digital Car Keys during fa...
I943d97b26:recovery: enable support for device-specific WipeS...
I15c7fbd7f:allow recovery and fastboot to access secure elmen...

Change-Id: Ic576b40641171298ad840bedbd4a9f7b67052d95
2021-06-29 19:19:24 +00:00
TreeHugger Robot
7432c08ac9 Merge "allow recovery and fastboot to access secure elment" into sc-dev am: be3d2bf325
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14681841

Change-Id: I642763bd029fdaa6fe11b440af187a37feeb7966
2021-06-29 18:03:40 +00:00
TreeHugger Robot
be3d2bf325 Merge "allow recovery and fastboot to access secure elment" into sc-dev 2021-06-29 17:50:35 +00:00
TreeHugger Robot
3de1991b67 Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev am: 432ed9b527
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15135682

Change-Id: I84c80310cbd1897fe7ef1bac5d9b6c8bc024412e
2021-06-29 17:24:18 +00:00
TreeHugger Robot
432ed9b527 Merge "Fix denial when flashing vendor_boot in fastbootd." into sc-dev 2021-06-29 17:04:07 +00:00
David Anderson
2354e3a924 Fix denial when flashing vendor_boot in fastbootd.
This mirrors the same sepolicy line in previous Pixel devices.

Bug: 189493387
Test: fastboot flash vendor_boot on r4
Change-Id: Ie15c8e6e5c01b249e1e5e244666c461253279f0b
2021-06-28 21:06:05 -07:00
Neo Yu
0dd75c76a6 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev am: 9c27ce91c8 am: 145c181a70 am: 6b8b748b87
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126897

Change-Id: Ie1ac5d1ec702b19fb97167767100d85b0f35aa5f
2021-06-29 03:51:17 +00:00
Neo Yu
145c181a70 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev am: 9c27ce91c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15126897

Change-Id: Icefd3f8fb6cd01b2596e1ec41720bdbdd39b8a5c
2021-06-29 03:22:07 +00:00
Neo Yu
9c27ce91c8 Merge "Fix avc denied for getprop "vendor.radio.call_end_reason"" into sc-dev 2021-06-29 03:05:02 +00:00
TreeHugger Robot
ba8db505db Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev am: 22f27cb215 am: 03488b260f am: 90d03e4684
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456728

Change-Id: I7c8b3c67931a73550040b20e2e2e14e59343649d
2021-06-29 02:00:41 +00:00
TreeHugger Robot
03488b260f Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev am: 22f27cb215
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14456728

Change-Id: If3f1fa43325948305419f2b1e5995855bde42a4c
2021-06-29 01:31:17 +00:00
neoyu
93944a8b1c Fix avc denied for getprop "vendor.radio.call_end_reason"
06-10 11:13:02.867 10224  2377  2377 W libc    : Access denied finding property "vendor.radio.call_end_reason"

Bug: 191204793
Test: error is gone with this fix
Change-Id: I50c1d21ba4e2343aa2cee0c533b8c3dbe535e4b5
2021-06-29 01:18:12 +00:00
TreeHugger Robot
22f27cb215 Merge "Sepolicy: Pixel stats wireless charger sepolicy" into sc-dev 2021-06-29 01:16:35 +00:00
David Lin
4b6bc8cb32 ssr_detector_app: Add additional vendor dir and crgroup allow for debug
Bug: 192126013

Signed-off-by: David Lin <dtwlin@google.com>
Change-Id: Idadf81cf92099804f300f87fb1bedf9bed7decbd
2021-06-28 21:52:51 +00:00