Commit graph

956 commits

Author SHA1 Message Date
Sina Hassani
e763f3cc9b Allow HAL to access sysfs.
This is so that it can read fw metrics from sysfs and dump them through
dumpsys.

Test: Ran dumpsys and bugreport.
Bug: 193841666
Change-Id: I08c08e35bad35d0eefc3f6ad218fb47e24051b0c
2021-07-16 16:27:34 -07:00
Wenhao Wang
2668a75c61 Merge "Add wakelock access for storageproxyd" into sc-dev am: 5305955a86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15306271

Change-Id: I9bc3270349b159cfd1e1a9e33162c0169d23494a
2021-07-16 17:29:45 +00:00
Wenhao Wang
5305955a86 Merge "Add wakelock access for storageproxyd" into sc-dev 2021-07-16 17:12:01 +00:00
Alex Hong
603f871e41 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev am: ea6934fda9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15296508

Change-Id: Ie62db9de45aeb5244d1a53d35f2f216122378177
2021-07-16 06:45:21 +00:00
Alex Hong
ea6934fda9 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev 2021-07-16 06:28:32 +00:00
Namkyu Kim
4055c31faf sepolicy: gs101: support tetheroffload hal version 1.y
Support both 1.0 and 1.1.

Bug: 186539538
Test: run vts -m VtsHalTetheroffloadControlV1_0TargetTest
      run vts -m VtsHalTetheroffloadControlV1_1TargetTest

Signed-off-by: Namkyu Kim <namkyu78.kim@samsung.com>
Change-Id: I76a26dcd22e1c8985d470a39b9aeae618f459d00
2021-07-16 04:05:21 +00:00
Stephane Lee
0a7e3ad9ea Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev am: ea6996bc52
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15289584

Change-Id: Ia8765b15f56c4a4da76ce47c0e38ebaef351d4a7
2021-07-16 02:10:10 +00:00
Stephane Lee
ea6996bc52 Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev 2021-07-16 01:55:33 +00:00
Wenhao Wang
5c009fb96f Add wakelock access for storageproxyd
The storageproxyd needs a wakelock around the sequence of UFS commands

Bug: 193456223
Test: Trusty storage tests
Change-Id: I1efe3144c8bcc17c056fc3b9b796e080f77991d5
2021-07-15 17:10:31 -07:00
Andrew LeCain
d8d8580281 sepolicy allow fingerprint hal to read mfg_data
declares new device context for mfg_data_block_device
give fp HAL permission to read/write/open
give fp HAL permission to search block_device dir

Bug: 189135413
Test: sideload calibration in enforcing mode.
Change-Id: I19e0cd13fc452b42c3f35772c4bafd433dbcc8b1
2021-07-15 10:58:53 -07:00
TreeHugger Robot
9eca0031b0 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev am: f0dd8e2957
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15269315

Change-Id: I56fc4bbc6331e9b273f6deb9c324fcc2f48f7e74
2021-07-15 16:31:29 +00:00
TreeHugger Robot
f0dd8e2957 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev 2021-07-15 16:17:40 +00:00
sukiliu
5382253c4f Update avc error on ROM 7550575 am: 06ea8d9432
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283866

Change-Id: I8a9c4dc678122acb58cec715bfed8707cd4701f3
2021-07-15 09:00:29 +00:00
Darren Hsu
3050ed8ed9 Set sepolicy for shell script of disabling contaminant detection
The avc denials are listed in b/192208389#comment10.

Bug: 192208389
Test: Manually tested
Change-Id: Ib2e3cf498851c0c9e5e74aacc9bf391549c0ad1a
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2021-07-15 11:11:11 +08:00
sukiliu
06ea8d9432 Update avc error on ROM 7550575
Bug: 193726003
Bug: 193633303
Bug: 193548421
Test: PtsSELinuxTestCases
Change-Id: Id6cb13602eb9a69f7815a0301a5708577c663bd2
2021-07-15 09:33:58 +08:00
Stephane Lee
c7342a7824 odpm: Rename the odpm_config sepolicies to be more consistent
Test: Ensure that there are no sepolicy errors on odpm_config
Bug: 192674986
Change-Id: I3043a544511c8c3051e1bd10e9f6b668b251cf5f
2021-07-14 16:11:51 -07:00
Orion Hodson
ea548a455a Merge "Revert "Update avc error on ROM 7522385"" into sc-dev am: d4a7e81293
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15235283

Change-Id: Ia370863825c449a693fc0776f7573c2cb95da998
2021-07-14 09:22:27 +00:00
Orion Hodson
d4a7e81293 Merge "Revert "Update avc error on ROM 7522385"" into sc-dev 2021-07-14 09:08:32 +00:00
TreeHugger Robot
29508b1969 Merge "Add create perm for tee" into sc-dev am: e7aab2cbdd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15276267

Change-Id: I836c68f5138bc60a1ae4b1a74a8b634b2dbd9ac9
2021-07-14 01:20:32 +00:00
TreeHugger Robot
e7aab2cbdd Merge "Add create perm for tee" into sc-dev 2021-07-14 01:01:53 +00:00
Wenhao Wang
c60e44c29e Add create perm for tee
The storageproxyd needs to create persist/ss from scratch.
So we add the create perm.

Bug: 193489307
Test: Trusty storage tests
Change-Id: Ida1c07acac26494ae6bba0392fb2da0425803608
2021-07-13 16:26:17 -07:00
TreeHugger Robot
e24d28c448 Merge "Revert "Update avc error on ROM 7526917"" into sc-dev am: 0afce44985
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15265928

Change-Id: I68f17cac42d705859eb3f22e694666f2f21f510e
2021-07-13 17:17:12 +00:00
TreeHugger Robot
0afce44985 Merge "Revert "Update avc error on ROM 7526917"" into sc-dev 2021-07-13 17:03:43 +00:00
Michael Ayoubi
04d9f1ac13 Revert "Update avc error on ROM 7526917"
This reverts commit 81a8e5b4ce.

Reason for revert: <Qorvo Version P2-S4(ag/15139489) which caused these errors got reverted from sc-dev in ag/15224151. It will now go into master>

Bug: 192924316
Change-Id: I772053cf512ba555a5fa657d39f957ac51f013c1
2021-07-13 17:03:26 +00:00
Chris Fries
0d6a29a714 Merge "suppress error for ag/15263334" into sc-dev am: 5de8701fae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15258522

Change-Id: I2d10c68c79ec36bdef20d89076bb3846844fdb25
2021-07-13 15:51:38 +00:00
Chris Fries
5de8701fae Merge "suppress error for ag/15263334" into sc-dev 2021-07-13 15:37:16 +00:00
Stephane Lee
ce93f1c3bf Add DC Charging to server configurable parameters; ensure the sysfs node is writable am: 2046513eb7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15180033

Change-Id: Id86535b96a58f1561b501c5c91ef43306031053c
2021-07-13 08:46:09 +00:00
Adam Shih
9d7e88c27e suppress error for ag/15263334
Bug: 193474772
Test: boot with no relevant error found
Change-Id: Ia3f49fbf9e623c6b81d6c595e19e275f64521dfe
2021-07-13 09:57:18 +08:00
Stephane Lee
2046513eb7 Add DC Charging to server configurable parameters; ensure the sysfs node is writable
hal_googlebattery will be writing to:
/sys/devices/platform/google,cpm/dc_ctl

Test: Ensure there are no errors on logcat | grep google_battery@
Bug: 183772980

Change-Id: Id4490d6de161eefe63c36c01d497696b16c6292d
2021-07-12 13:27:54 -07:00
SHUCHI LILU
d083bb9bfd Merge "Update avc error on ROM 7539530" into sc-dev am: 4aa650714c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15250405

Change-Id: I091a161f8c984c7a718d504aa3ef1da40655a4f8
2021-07-12 04:04:41 +00:00
SHUCHI LILU
4aa650714c Merge "Update avc error on ROM 7539530" into sc-dev 2021-07-12 03:45:34 +00:00
Salmax Chang
dc5f944d31 Merge "init: change overlayfs_file rule to dontaudit" into sc-dev am: 3582ffbdbf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15243218

Change-Id: If111d5fe0ec75703abb1ca01a40820165e41d0c1
2021-07-12 02:54:39 +00:00
Salmax Chang
3582ffbdbf Merge "init: change overlayfs_file rule to dontaudit" into sc-dev 2021-07-12 02:40:43 +00:00
sukiliu
a06677ce7a Update avc error on ROM 7539530
avc: denied { read } for name="u:object_r:vendor_camera_debug_prop:s0" dev="tmpfs" ino=300 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:vendor_camera_debug_prop:s0 tclass=file permissive=0
avc: denied { read } for comm="dumpstate@1.1-s" name="u:object_r:vendor_camera_debug_prop:s0" dev="tmpfs" ino=300 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:vendor_camera_debug_prop:s0 tclass=file permissive=0

Bug: 193365129
Test: PtsSELinuxTestCases
Change-Id: I1d0258ec4ce2abbf8f899add86be2076c0c72be0
2021-07-12 09:49:17 +08:00
Long Ling
c8efc49b29 Merge "Allowed HWC HAL access TUI status node" into sc-dev am: 5a7c666290
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15177771

Change-Id: I035cfe3c25903178bab1823d5f3ea61e2ad900e1
2021-07-10 02:35:42 +00:00
Long Ling
5a7c666290 Merge "Allowed HWC HAL access TUI status node" into sc-dev 2021-07-10 02:19:43 +00:00
SalmaxChang
12370586c9 init: change overlayfs_file rule to dontaudit
Workaround for modem_img being unlabeled after disable-verity.

Bug: 193113005

Change-Id: I64b528d9952849ff73bcd583211d33c3b220438d
2021-07-09 23:27:30 +08:00
Orion Hodson
da1f469dc8 Revert "Update avc error on ROM 7522385"
This reverts commit 46dfc784f5.

Bug: 192895524
Test: PtsSELinuxTestCases
Change-Id: Iaf00b567fbd3df575ea009036c2e35f6a7a87d90
2021-07-09 15:51:12 +01:00
Meng Wang
70052ef1c1 Merge "[RCS] Update sepolicy for RCS" into sc-dev am: 1c6e5c01eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15185251

Change-Id: Ib935cc9132f6b7239e973b43bd13b160b7df2747
2021-07-08 17:28:23 +00:00
Meng Wang
1c6e5c01eb Merge "[RCS] Update sepolicy for RCS" into sc-dev 2021-07-08 17:14:51 +00:00
TreeHugger Robot
b2b7ac7cdb Merge "[3A Coordinator] Enable to property_set for log.tag. prefix" into sc-dev am: 95756a2c79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15223178

Change-Id: Ia36378397d340c61fd8d3f0ce601cbcfc83f06e9
2021-07-08 06:59:59 +00:00
TreeHugger Robot
95756a2c79 Merge "[3A Coordinator] Enable to property_set for log.tag. prefix" into sc-dev 2021-07-08 05:55:52 +00:00
SHUCHI LILU
cc3d5bb968 Merge "Update avc error on ROM 7527858" into sc-dev am: 54780f7ae3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15222136

Change-Id: I8d938fa6851835f1948964c373764a10dbcf36d8
2021-07-08 03:04:39 +00:00
SHUCHI LILU
54780f7ae3 Merge "Update avc error on ROM 7527858" into sc-dev 2021-07-08 02:53:28 +00:00
KRIS CHEN
11ce7d0f20 Merge "Add sepolicy rules for fingerprint hal" into sc-dev am: ba9051de47
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15223175

Change-Id: I52fc30783edc40b0e4a27307719a95e5ade1b4a4
2021-07-08 02:21:15 +00:00
Bo-Yuan Ye
20dd1ef66c [3A Coordinator] Enable to property_set for log.tag. prefix
major changes:
        1. add log_tag_prop for hal_camera_default

Test: go/p21-camera-test-checklist
Bug: 191923902
Change-Id: I767c235666c6761af6d21178d829a0f7cb8d42c8
2021-07-08 10:15:23 +08:00
KRIS CHEN
ba9051de47 Merge "Add sepolicy rules for fingerprint hal" into sc-dev 2021-07-08 02:05:03 +00:00
Myung-jong Kim
99e75b6ab9 [RCS] Update sepolicy for RCS
Fix seapp_contexts sepolicy for shannon-rcs, where
:shannonrcsservice process exceptions are not handled

Bug: 190581528
Signed-off-by: Myung-jong Kim <mj610.kim@samsung.com>
Change-Id: I15cbf103cea70f6db878305a8fca6b35aa521f9b
2021-07-07 10:57:12 -07:00
Kris Chen
a5c9028ced Add sepolicy rules for fingerprint hal
Fix following avc denial:
servicemanager: type=1400 audit(0.0:8): avc: denied { call } for scontext=u:r:servicemanager:s0 tcontext=u:r:hal_fingerprint_default:s0 tclass=binder permissive=0

Bug: 192040144
Test: No above avc denial in logcat.
Change-Id: I1b93474cac4ccb24736bc97665a7ca533ef0a7d3
2021-07-08 00:59:49 +08:00
Maciej Zenczykowski
cb63eaae07 Merge "add sepolicy for set_usb_irq.sh" into sc-dev am: 9b270f0fc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15219696

Change-Id: Id1c777f39de6b69e459b7c0f6fb4042f78a19798
2021-07-07 16:35:39 +00:00