Edmond Chung
6b30dbc54c
gs101: Allow camera HAL to access interrupt handles
...
This is to allow camera HAL to modify IRQ affinity for different use
cases.
Bug: 196058977
Test: Camera use cases
Change-Id: I498b0ac763b735d05299e1f4b09de14e131fd6e3
2021-08-16 10:52:27 -07:00
Rick Yiu
9c7ca5fdd3
gs101-sepolicy: Use untrusted_app_all for vendor_sched denials am: 2ef3daba50
am: 1f4c69a11d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15531061
Change-Id: I59e7baee2e2c5a80d53b5a6f5c8712a2b09a36d3
2021-08-16 14:11:45 +00:00
Rick Yiu
1f4c69a11d
gs101-sepolicy: Use untrusted_app_all for vendor_sched denials am: 2ef3daba50
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15531061
Change-Id: I54a069f83c389b69a73d9d4d64a34177ba652d1c
2021-08-16 13:54:58 +00:00
Rick Yiu
2ef3daba50
gs101-sepolicy: Use untrusted_app_all for vendor_sched denials
...
Use untrusted_app_all to cover all Use untrusted_app versions.
Bug: 196109806
Test: no untrusted_app denials for vendor_sched
Change-Id: Ic6426b26b8a05f8a0bc7e2a4a4a293b2988812d3
2021-08-16 13:40:32 +00:00
Victor Liu
9d2d70e09b
allow uwb hal sys_nice access am: 39b5815a1e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15549222
Change-Id: Ib8b61cc66bd2919360e05434f147f495fcacb156
2021-08-13 02:41:53 +00:00
Victor Liu
39b5815a1e
allow uwb hal sys_nice access
...
hardware.qorvo.: type=1400 audit(0.0:9): avc: denied { sys_nice } for capability=23 scontext=u:r:hal_uwb_default:s0 tcontext=u:r:hal_uwb_default:s0 tclass=capability permissive=0
hardware.qorvo.: type=1400 audit(0.0:9): avc: denied { setsched } for scontext=u:r:hal_uwb_default:s0 tcontext=u:r:kernel:s0 tclass=process permissive=0
Bug: 196438549
Signed-off-by: Victor Liu <victorliu@google.com>
Change-Id: I742bae701cfcc7b4842cd63abbc8c275d82c8ba1
2021-08-12 16:11:06 -07:00
Victor Liu
e4ee9723f4
uwb: allow uwb to access the radio service am: 0c429efc07
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15521660
Change-Id: I4bc3d385c8895137bf62640c06592907ccd495b0
2021-08-12 21:57:10 +00:00
Victor Liu
0c429efc07
uwb: allow uwb to access the radio service
...
07-07 18:28:28.391 409 409 E SELinux : avc: denied { find } for pid=4609 uid=1083 name=isub scontext=u:r:uwb_vendor_app:s0:c59,c260,c512,c768 tcontext=u:object_r:radio_service:s0 tclass=service_manager permissive=0
Bug: 192833779
Test: on device, no avc denied message
Change-Id: I4a6b778dce6f493093d3a05683473bb60e9cfa5c
2021-08-10 22:47:35 +00:00
Siqi Lin
c8836d9832
Merge "sepolicy: gs101: allow dumpstate to access AoC stats" into sc-dev am: df73384b2e
am: 505d9d692e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15475450
Change-Id: I16b13385bd0a66983999b3b2f4518c0a07387068
2021-08-09 20:20:19 +00:00
Siqi Lin
505d9d692e
Merge "sepolicy: gs101: allow dumpstate to access AoC stats" into sc-dev am: df73384b2e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15475450
Change-Id: I7c546f38519158fa1237e713bb1200e304a82650
2021-08-09 20:05:08 +00:00
Siqi Lin
df73384b2e
Merge "sepolicy: gs101: allow dumpstate to access AoC stats" into sc-dev
2021-08-09 19:52:02 +00:00
TreeHugger Robot
f30a67df8a
Merge "Add sepolicy to allow camera HAL to read display backlight" into sc-dev am: cfcf725081
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15453996
Change-Id: I495b9411ea69f6aca5a201c3f6b4e8c464906a9f
2021-08-06 14:17:49 +00:00
TreeHugger Robot
cfcf725081
Merge "Add sepolicy to allow camera HAL to read display backlight" into sc-dev
2021-08-06 14:04:38 +00:00
Siqi Lin
57d81aa6c1
sepolicy: gs101: allow dumpstate to access AoC stats
...
Add AP wakeups from AoC DRAM exceptions to bugreports.
Bug: 186456919
Change-Id: I31df82addf1b5024b8e33c6284e5da1f473ac5d9
2021-08-05 10:47:13 -07:00
Alice Yang
0d7ab6ea8b
Add sepolicy to allow camera HAL to read display backlight
...
Add sepolicy to allow camera HAL to read display backlight to use in
gabc algorithm.
Bug: 187917645
Test: build pass, go/p21-camera-test-checklist
Change-Id: I628ee2dedd48dd1360d0818137ba9139ae194029
2021-08-03 16:31:12 +00:00
Erik Staats
0965462752
Merge "Allow sensor HAL to read AoC dumpstate." into sc-dev am: 1b7ae244b0
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15444398
Change-Id: I0a50040b067368b556535064a715cbdeb0782a19
2021-08-03 15:49:33 +00:00
Erik Staats
1b7ae244b0
Merge "Allow sensor HAL to read AoC dumpstate." into sc-dev
2021-08-03 15:27:12 +00:00
Charles Chiu
07bc84365c
Merge "Allow init to set Camera properties." into sc-dev am: 50ebe02d44
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15427051
Change-Id: I28b126af98f58399256b3c2dd38b4762d642f781
2021-08-03 06:10:21 +00:00
Charles Chiu
50ebe02d44
Merge "Allow init to set Camera properties." into sc-dev
2021-08-03 05:52:49 +00:00
Erik Staats
ad42045b87
Allow sensor HAL to read AoC dumpstate.
...
Bug: 194021578
Test: Simulated communication failure and verified AoC services state
log.
Test: See details in testing done comment in
https://googleplex-android-review.git.corp.google.com/15444398 .
Change-Id: I76f376577abad26fe86b5ecb6a570716381227f0
2021-08-02 15:56:57 -07:00
Quinn Yan
b524c170cd
Merge "Revert the unnecessary sepolicy rules for hal_neuralnetworks_darwinn." into sc-dev am: be5aa28148
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15434450
Change-Id: I5e5b6e8802374ae99d282c44e5aef57f87a26c2e
2021-08-02 18:17:56 +00:00
Quinn Yan
be5aa28148
Merge "Revert the unnecessary sepolicy rules for hal_neuralnetworks_darwinn." into sc-dev
2021-08-02 18:01:50 +00:00
Charles Chiu
718a856e26
Allow init to set Camera properties.
...
Test: Camera CTS
Bug: 194656156
Change-Id: I2f8f89a02984bfb9fea96df7b0a1d4150c9fdd8d
2021-08-02 23:21:14 +08:00
Mark Chang
e0ef0186ca
[automerger skipped] Merge "[DO NOT MERGE] sepolicy: Add "dontaudit" for twoshay dac_override." into sc-dev am: f7fa1fa877
-s ours
...
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15416442
Change-Id: Ie3031405fe564edf4b097173e1e0b6ff7bc22d01
2021-07-31 00:12:54 +00:00
Mark Chang
f7fa1fa877
Merge "[DO NOT MERGE] sepolicy: Add "dontaudit" for twoshay dac_override." into sc-dev
2021-07-31 00:01:26 +00:00
qinyiyan
ee4e7f45ce
Revert the unnecessary sepolicy rules for hal_neuralnetworks_darwinn.
...
Bug: 194241380
Test: flashed forrest build and ran PtsSELinuxTestCases
Change-Id: Ie2f0572a368f09e522bc2cdfdf9da1859c1c44e7
2021-07-30 23:36:06 +00:00
TreeHugger Robot
23b7621849
Merge "Add vendor SELinux denial to allowlist" into sc-dev am: 4720a91c52
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15422669
Change-Id: Id95206a386275893599d7be18c15e48274f4a140
2021-07-30 13:25:13 +00:00
TreeHugger Robot
4720a91c52
Merge "Add vendor SELinux denial to allowlist" into sc-dev
2021-07-30 13:12:12 +00:00
Rick Yiu
5168b7a0f3
Merge "gs101: Remove vendor_sched" into sc-dev am: dba7013033
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15402045
Change-Id: I80c3982fd8f5565ad1f4a7fb9f1fa993c7e233dc
2021-07-30 07:05:37 +00:00
Rick Yiu
dba7013033
Merge "gs101: Remove vendor_sched" into sc-dev
2021-07-30 06:52:10 +00:00
Rick Yiu
7de8a5d4a7
gs101: Remove vendor_sched
...
Moved to system/sepolicy.
Bug: 194656257
Test: build pass
Change-Id: Ia5ea1bbc05bdc52b43cb403d99994bad70613e08
Merged-In: Ia5ea1bbc05bdc52b43cb403d99994bad70613e08
2021-07-30 03:13:39 +00:00
Mark Chang
a1aab562ca
[DO NOT MERGE] sepolicy: Add "dontaudit" for twoshay dac_override.
...
Bug: 193224954
Test: build pass and boot to home
Signed-off-by: Mark Chang <changmark@google.com>
Change-Id: I5c330564cc026e113c5d33d5d093dbcdb3ede5e4
2021-07-30 01:49:59 +00:00
Jaineel Mehta
0474bcf10e
Add vendor SELinux denial to allowlist
...
Change-Id: If7435e9c62811ef3c9757f22f06018c32a8d3597
Test: None
Bug: 194281028
2021-07-29 21:23:34 +00:00
TreeHugger Robot
8ab71529ce
Merge "gs101: Allow camera hal to create file in persist camera folder" into sc-dev am: 750888bc5b
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15354010
Change-Id: Ia321b3fa069583efadda94caab9b72a484f5631b
2021-07-29 09:14:51 +00:00
TreeHugger Robot
750888bc5b
Merge "gs101: Allow camera hal to create file in persist camera folder" into sc-dev
2021-07-29 08:40:36 +00:00
Michael Eastwood
8cda72b001
Merge "Allow hal_dumpstate_default to access vendor_camera_debug_prop" into sc-dev am: 9bfbb3c0d4
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15406130
Change-Id: Ida4fbd33da5d2ded18be388f989e27936b3bd955
2021-07-28 21:55:14 +00:00
Michael Eastwood
9bfbb3c0d4
Merge "Allow hal_dumpstate_default to access vendor_camera_debug_prop" into sc-dev
2021-07-28 21:36:38 +00:00
Michael Eastwood
30bd5e8ed6
Allow hal_dumpstate_default to access vendor_camera_debug_prop
...
Bug: 193365129
Test: atest com.google.android.selinux.pts.SELinuxTest#scanBugreport
Change-Id: I43e389d46e8116844bb9ca4259e5ea28e86c50f4
2021-07-27 17:22:47 -07:00
TreeHugger Robot
a96235b57b
Merge "Add AoC wakeup stats to dump state" into sc-dev am: fead41d573
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15393321
Change-Id: Ia4cb5725b748fcccd901a28ca2e3dbb354c3e44e
2021-07-27 19:44:07 +00:00
TreeHugger Robot
fead41d573
Merge "Add AoC wakeup stats to dump state" into sc-dev
2021-07-27 19:23:06 +00:00
Jack Wu
2c79c75768
sepolicy: gs101: allows pixelstat to access pca file nodes am: d6c1a50bba
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15360184
Change-Id: Ic3efb76715139aa335995b95e7756f23b5de226c
2021-07-27 02:29:16 +00:00
Max Kogan
5374497df5
Add AoC wakeup stats to dump state
...
Need add support for wakeup stats to track AoC to AP messages
resulting in frequent wake-ups.
Bug: 192668026
Change-Id: I073406cc101e114135c863b0e0b86357e93c0415
2021-07-26 22:45:16 +00:00
Jack Wu
d6c1a50bba
sepolicy: gs101: allows pixelstat to access pca file nodes
...
07-23 14:24:45.512 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:10): avc: denied { open } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:45.512 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:11): avc: denied { getattr } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:12): avc: denied { read } for name="chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:13): avc: denied { open } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:14): avc: denied { getattr } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536 1000 3001 3001 I pixelstats-vend: type=1400 audit(0.0:15): avc: denied { write } for name="chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
Bug: 194386750
Test: manually test, no avc: denied
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: I1a16edb5bb7820f62b3ce598aa50eba2d9455927
2021-07-24 06:42:39 +00:00
TreeHugger Robot
cd16e38ab2
Merge "Add SE policies for memtrack HAL" into sc-dev am: b3225f0f6c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283133
Change-Id: I552351e0eac65c20d795b1682852896943f948c8
2021-07-23 21:24:50 +00:00
TreeHugger Robot
b3225f0f6c
Merge "Add SE policies for memtrack HAL" into sc-dev
2021-07-23 20:52:52 +00:00
Ankit Goyal
0f9820830c
Add SE policies for memtrack HAL
...
Bug: 191966412
Test: adb shell dumpsys meminfo
Change-Id: Ia7ec64840d2bb7c3ae0d61304e109d2ceb9e5f78
2021-07-24 02:18:36 +08:00
Max Shi
50486c63f3
Allow USF sensor HAL to read camera persist files. am: 0bd50d1eb5
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15352099
Change-Id: Id31975a653e79362c0dea9a86b52944d340f2fee
2021-07-22 23:46:11 +00:00
Max Shi
0bd50d1eb5
Allow USF sensor HAL to read camera persist files.
...
USF sensor HAL requires access to camera persist files to determine if
the camera module has been replaced (e.g. via repair), which may affect
calibration of the magnetometer.
Bug: 193727762
Test: Verify sensor HAL can open and read files under
Test: /mnt/vendor/persist/camera/
Change-Id: Icb9d7a46bf8465e1a72054ac9c8493ba18445ef3
2021-07-22 21:11:44 +00:00
Badhri Jagan Sridharan
31b15ff2bb
Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev am: 49804d8d6f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283349
Change-Id: I6fc802f74aaf7e1f7a7b8574ed5ace1886b9623c
2021-07-22 20:52:11 +00:00
Badhri Jagan Sridharan
49804d8d6f
Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev
2021-07-22 20:31:13 +00:00