Chiawei Wang
2d240b30a8
Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915
Change-Id: I74c9d026da00446746d0e2cbd4eb3570b99e0527
2021-06-03 09:06:10 +00:00
Chiawei Wang
9cfc661bee
Merge "pixelstats: fix permission errors" into sc-dev
2021-06-03 08:45:12 +00:00
Chiawei Wang
9d5830ac19
pixelstats: fix permission errors
...
1. sysfs_dma_heap erros are fixed by ag/13926718
2. debugfs_mgm error is fixed by ag/14683912
Bug: 188114896
Bug: 183338421
Bug: 188495492
Test: pts-tradefed run pts -m PtsSELinuxTest
http://sponge2/6cbd0af0-5414-4f2c-aea0-99b4981360a4
Signed-off-by: Chiawei Wang <chiaweiwang@google.com>
Change-Id: Icd2fa4e7f168d15fd4cec3000bc0e7a33eab4d3e
2021-06-03 02:52:33 +00:00
Rick Yiu
b6b7564259
Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev am: b530a26f1f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14774943
Change-Id: Id352df8328a33017692f2a0df544b9db1556d1cf
2021-06-03 01:20:00 +00:00
Rick Yiu
b530a26f1f
Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev
2021-06-03 00:56:00 +00:00
Peter Csaszar
7a3703432e
pixel-selinux: Add mlstrustedobject for SJTAG am: 7ea6a44719
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14794010
Change-Id: I943d236681c0c24d2c6f6a70eda2081c78abf9df
2021-06-02 20:59:29 +00:00
Peter Csaszar
7ea6a44719
pixel-selinux: Add mlstrustedobject for SJTAG
...
This CL adds the "mlstrustedobject" to types for files involved in the
SJTAG authentication flow, in order to address MLS-based AVC denials.
Bug: 189466122
Test: No more AVC denials when activating SJTAG in BetterBug
Signed-off-by: Peter Csaszar <pcsaszar@google.com>
Change-Id: Ieb88653830ce95751eee5cf26c26fd6302067bce
2021-06-02 12:23:01 -07:00
Aaron Ding
86e17fa6a1
pixel-selinux: add SJTAG policies am: 9f8d552411
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14795132
Change-Id: I6ffbe3fc2053c12c4ef0138a9add21674955f2cb
2021-06-02 06:28:53 +00:00
Aaron Ding
59a7ae7afe
remove sysfs_type from vendor_page_pinner_debugfs am: 2dbe515943
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14782004
Change-Id: Ifad186cc34fef21b4686fe328ca904b62ae86357
2021-06-02 06:28:49 +00:00
Rick Yiu
9e8bd699e9
gs101-sepolicy: Refine policy for sysfs_vendor_sched
...
Chagne it to directory based.
Bug: 182509410
Test: device boot normally
Change-Id: I1cfaa95cf07e1e829e747eb99ed39ab64d3ddac1
2021-06-02 04:52:45 +00:00
Aaron Ding
9f8d552411
pixel-selinux: add SJTAG policies
...
This reverts commit b078284e5d
.
Bug: 184768605
Change-Id: Ib0080e2ba3edf7fa654155fb4a7403d52ad2494a
2021-06-02 10:25:51 +08:00
Aaron Ding
2dbe515943
remove sysfs_type from vendor_page_pinner_debugfs
...
Bug: 186500818
Change-Id: If97126a3d46d96342faf89b9698218b6a480a84b
2021-06-01 17:38:28 +08:00
David Chao
6026cf5181
Grant powerhal access to thermal_link_device and sysfs_thermal
...
Bug: 188579571
Test: boot
Change-Id: I8e4675e2817fe3778236618e0dba76f1233e77e2
2021-06-01 05:17:13 +00:00
Aaron Ding
5825ee37e3
Revert "pixel-selinux: add SJTAG policies" am: b078284e5d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14528664
Change-Id: I05c1e374972a89fe6d5dcd75f4c8fe41b383f3ff
2021-05-31 18:46:59 +00:00
Aaron Ding
b078284e5d
Revert "pixel-selinux: add SJTAG policies"
...
This reverts commit bc525e1a49
.
Bug: 186500818
Change-Id: I0bab67d42530270a819598ac320a5946e5d7aa6d
Signed-off-by: Aaron Ding <aaronding@google.com>
2021-06-01 01:21:14 +08:00
Vova Sharaienko
977bc88d0b
Merge "hal_health_default: updated sepolicy" into sc-dev am: ce4002966a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14738712
Change-Id: I4ea468c2ebfdec8a35bfb02897f411bb8c814f22
2021-05-28 18:06:52 +00:00
Vova Sharaienko
ce4002966a
Merge "hal_health_default: updated sepolicy" into sc-dev
2021-05-28 17:42:45 +00:00
Rick Yiu
32838e85d8
Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev am: 6c5779d0af
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14692150
Change-Id: I1b2c4fb8582bf71543ea0c115f369dbb6f8abe9b
2021-05-28 01:44:23 +00:00
Rick Yiu
6c5779d0af
Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev
2021-05-28 01:16:34 +00:00
Vova Sharaienko
144b6b06b3
hal_health_default: updated sepolicy
...
This allows the android.hardware.health service to access
AIDL Stats service
Bug: 186578402
Test: Build, flash, boot & and logcat | grep "avc"
Change-Id: I1bfd8dbca4a8a87387c5fc0cc47b9f09a6d07ea4
2021-05-27 01:51:21 +00:00
Harpreet Eli Sangha
e952c414ec
Add CccDkTimeSyncService
...
Bug: 183676280
Test: Build and run example client.
Signed-off-by: Harpreet Eli Sangha <eliptus@google.com>
Change-Id: I862d5f3e8be3cf7d23489be374fabf26e29e0ca5
2021-05-26 16:59:51 +00:00
TreeHugger Robot
607ba868d5
Merge "Add sepolicy for Trusty keymint" into sc-dev am: 9e9c6a75da
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14414676
Change-Id: I770a835945c9c73226bcbeaf06120cadb6af5cd0
2021-05-26 13:46:37 +00:00
TreeHugger Robot
9e9c6a75da
Merge "Add sepolicy for Trusty keymint" into sc-dev
2021-05-26 13:23:20 +00:00
sukiliu
248d61e87a
Update avc error on ROM 7395282 am: 073a0f5ed1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14717075
Change-Id: I40f8e723d005fad45b4ba480fbc456cb34360910
2021-05-26 04:56:37 +00:00
sukiliu
073a0f5ed1
Update avc error on ROM 7395282
...
avc: denied { dac_override } for comm="rebalance_inter" capability=1 scontext=u:r:rebalance_interrupts_vendor:s0 tcontext=u:r:rebalance_interrupts_vendor:s0 tclass=capability permissive=0
Bug: 189275648
Test: PtsSELinuxTestCases
Change-Id: I637f1fcd901b8bf59096ba83c927b4d353f0405b
2021-05-26 11:11:03 +08:00
Shawn Willden
c5fdb59287
Add sepolicy for Trusty keymint
...
Bug: 177729159
Test: VtsAidlKeyMintTargetTest on P21
Change-Id: I993faa2a829d3ad4f1b920ff59ba4fd5ef8e7db7
2021-05-25 16:37:29 -06:00
TreeHugger Robot
1e8934b03c
Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev am: 477e19f032
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14704012
Change-Id: Id748c228fb796c76ccc01d3b19f829928c185adf
2021-05-25 19:07:26 +00:00
TreeHugger Robot
477e19f032
Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev
2021-05-25 18:45:37 +00:00
TreeHugger Robot
cb80570b92
Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev am: 57eefb5b13
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608138
Change-Id: I594759be23e922d975f395da8a1d363925dc30ca
2021-05-25 11:50:55 +00:00
TreeHugger Robot
57eefb5b13
Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev
2021-05-25 10:12:38 +00:00
Ocean Chen
b8aebc85e1
storage: update sepolicy for hardwareinfoservice
...
avc: denied { search } for name="0:0:0:0" dev="sysfs" ino=57525 scontext=u:r:hardware_info_app:s0:c512,c768 avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vpd_pg80" dev="sysfs" ino=57559 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="model" dev="sysfs" ino=57534 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vendor" dev="sysfs" ino=57533 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="rev" dev="sysfs" ino=57535 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="eol_info" dev="sysfs" ino=57020 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="life_time_estimation_a" dev="sysfs" ino=57021 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
Bug: 188755652
Test: reboot then check hardwareinfo and avc denined log
Change-Id: Ia03ebdd6b0b46b4c9ace5fbf1fc47a455a55abcb
2021-05-25 16:57:20 +08:00
Roger Fang
292faf8ed3
Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev am: 56cbfd5a0a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696016
Change-Id: I929b5c4b1f37c2e0d8bee655fc0141a5a0bbbd4e
2021-05-25 01:24:04 +00:00
Roger Fang
56cbfd5a0a
Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev
2021-05-25 01:02:39 +00:00
Ines Ayara
1a7f873b06
Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev am: dfb3783187
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14652412
Change-Id: I46ee22509e42f4baf7df226b2e2eedcf3ecfaa6c
2021-05-25 00:18:54 +00:00
Vinay Kalia
68849437bd
Allow mediacodec to access the vframe-secure DMA-BUF heap
...
This patch fixes the following denial:
HwBinder:751_2: type=1400 audit(0.0:9): avc: denied { open } for
path="/dev/dma_heap/vframe-secure" dev="tmpfs" ino=734
scontext=u:r:mediacodec:s0 tcontext=u:object_r:vframe_heap_device:s0
tclass=chr_file permissive=0
Bug: 188121584
Test: AV1 secure video playback
Signed-off-by: Vinay Kalia <vinaykalia@google.com>
Change-Id: I455b39914dd4316a427f5f756b4fb94a2c4db204
2021-05-24 23:57:28 +00:00
Ines Ayara
dfb3783187
Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev
2021-05-24 23:55:32 +00:00
Roger Fang
a97bfcc1e1
sepolicy: gs101: add permission for the hardware info dsp part number
...
Bug: 188757638
Test: Manually test passed
Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: Id0c3226411b058b613b92e67174f14e64c6c3a2b
2021-05-24 08:16:34 +00:00
Chase Wu
80ab102382
Merge "genfs_contexts: fix path for cs40l25a i2c devices" into sc-v2-dev
2021-05-24 01:03:51 +00:00
Rick Yiu
5aeb1b9e45
gs101-sepolicy: Allow dumping vendor groups values
...
Fix:
avc: denied { read } for name="vendor_sched" dev="sysfs" ino=45566 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=dir permissive=0
avc: denied { read } for name="dump_task_group_ta" dev="proc" ino=4026532542 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=0
Bug: 172112042
Test: dump data as expected
Change-Id: I9945953dba4afddd34c1535c12193b1f00fdcef9
2021-05-22 21:30:47 +08:00
Grace Chen
ebadda8749
Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev am: 16a38b2b6c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14514065
Change-Id: I62e7a0b9ff71f63221d6eaaad17a9333183912ec
2021-05-21 19:15:18 +00:00
Grace Chen
16a38b2b6c
Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev
2021-05-21 19:10:52 +00:00
chasewu
168a6b0c72
genfs_contexts: fix path for cs40l25a i2c devices
...
Due to recent changes which modifies the device name for i2c devices,
cs40l25a device names are now changed from ?-0043 and ?-0042 to
"i2c-cs40l25a" and "i2c-cs40l25a-dual"
Bug: 188078957
Bug: 188651116
Test: manual check avc denied logs
Signed-off-by: chasewu <chasewu@google.com>
Change-Id: I97d3a030c94166f8e2cda7daa38166b1532b6d9f
2021-05-21 17:32:53 +08:00
TreeHugger Robot
257af6acb7
Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev am: b42a03fa9e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14160586
Change-Id: I57862e73bb90e64631501678dac852a7e4d96d45
2021-05-21 06:59:14 +00:00
TreeHugger Robot
b42a03fa9e
Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev
2021-05-21 06:41:20 +00:00
SHUCHI LILU
d041f55312
Merge "Update avc error on ROM 7380236" into sc-dev am: 5128ec7db7
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14660737
Change-Id: Ifa70b0837abb760f0d98ed67c2ecb00687e4ba04
2021-05-21 02:24:48 +00:00
SHUCHI LILU
5128ec7db7
Merge "Update avc error on ROM 7380236" into sc-dev
2021-05-21 02:08:56 +00:00
TreeHugger Robot
69ccb014e3
Merge "pixel-selinux: add SJTAG policies" into sc-dev am: 73b7ad4a3c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14604512
Change-Id: Idf3d758f0b1f6781bd8771d8bc82af7f599a42be
2021-05-21 01:14:52 +00:00
TreeHugger Robot
73b7ad4a3c
Merge "pixel-selinux: add SJTAG policies" into sc-dev
2021-05-21 00:49:42 +00:00
Maurice Lam
370ca9d7c9
[automerger skipped] Merge "DO NOT MERGE. Revert Exo selinux policies for S" into sc-dev am: 32848785da
-s ours
...
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14533075
Change-Id: I58c7628b630bb1c3b0d1433aa3dc0f5bf08a1c0a
2021-05-20 17:51:46 +00:00
Maurice Lam
32848785da
Merge "DO NOT MERGE. Revert Exo selinux policies for S" into sc-dev
2021-05-20 17:31:08 +00:00