Commit graph

1222 commits

Author SHA1 Message Date
TreeHugger Robot
b7ce4ed92d Merge "Add sepolicy for sensor HAL accessing AOC sysfs node." into sc-dev am: 2391c852bd am: 702902ab26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14327406

Change-Id: I80c3ea093f437522e0ff7abde0a4141a15c1ae08
2021-05-19 11:02:55 +00:00
Eddie Lan
cd0809040e Merge "Add sepolicy for fpc AIDL HAL" into sc-dev am: 2d4071ca8c am: cc4e6fa558
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14282485

Change-Id: I117a78d405efee730eb9ad4c184c4a89a2706f17
2021-05-19 10:48:05 +00:00
TreeHugger Robot
263693185e Merge "Provide fastbootd permissions to invoke the set_active command" into sc-dev am: 1256869c5c am: d9ca54da9b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14391698

Change-Id: Ib6a1292eebdde4e6ffc483009c6e9e7498c1017c
2021-05-19 09:47:47 +00:00
Maurice Lam
d733108c8f DO NOT MERGE. Revert Exo selinux policies for S
Bug: 188074060
Test: Forrest
Change-Id: I3465d10c3731ae49fec6e6fb7f2873cf2e5b9c23
2021-05-19 09:07:56 +00:00
TreeHugger Robot
d6d9fbd94e Merge "logger_app: Fix avc error" into sc-dev am: dc4db7d1cc am: 34471d4e60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636312

Change-Id: I2eb01590196f48dbed7b3f185cf0aeb9276c9b2e
2021-05-19 08:57:55 +00:00
yixuanjiang
aa8edecbd9 Add sepolicy for aocdump to access wlan_logs folder am: 494ac0cfe3 am: ddb8f48006
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636311

Change-Id: I08550b20be580ab828ead72d656d7a8a6e50be30
2021-05-19 08:57:51 +00:00
TreeHugger Robot
bf71be56f2 Merge "logger_app: Fix avc error" into sc-dev am: dc4db7d1cc am: b79874f1b2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636312

Change-Id: Ie1867dc41ddbadc37ca5c70843e015585af3a666
2021-05-19 08:48:05 +00:00
TreeHugger Robot
b79874f1b2 Merge "logger_app: Fix avc error" into sc-dev am: dc4db7d1cc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636312

Change-Id: I4ec355ab7418f960c967984aded20fa9322030b7
2021-05-19 08:43:40 +00:00
TreeHugger Robot
34471d4e60 Merge "logger_app: Fix avc error" into sc-dev am: dc4db7d1cc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636312

Change-Id: Id6de718c78cbca19c45ef9a1a9feda9d95ecb476
2021-05-19 08:38:09 +00:00
yixuanjiang
cb9d2b7724 Add sepolicy for aocdump to access wlan_logs folder am: 494ac0cfe3 am: 826c703c8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636311

Change-Id: I8b6d7779a5d3b5c945c7b8206f510135d8d0424a
2021-05-19 08:36:47 +00:00
yixuanjiang
ddb8f48006 Add sepolicy for aocdump to access wlan_logs folder am: 494ac0cfe3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636311

Change-Id: I86a482f9ad157738fd4163d4490069ebb764e21e
2021-05-19 08:36:16 +00:00
TreeHugger Robot
dc4db7d1cc Merge "logger_app: Fix avc error" into sc-dev 2021-05-19 08:31:39 +00:00
yixuanjiang
826c703c8c Add sepolicy for aocdump to access wlan_logs folder am: 494ac0cfe3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14636311

Change-Id: Iefe2f8ef7f6cda5896da75634a3eaa9560be44ff
2021-05-19 08:10:35 +00:00
SalmaxChang
b486ddedc5 logger_app: Fix avc error
avc: denied { search } for name="ramdump" dev="dm-7" ino=316 scontext=u:r:logger_app:s0:c17,c257,c512,c768 tcontext=u:object_r:ramdump_vendor_data_file:s0 tclass=dir permissive=0
avc: denied { search } for name="ssrdump" dev="dm-11" ino=292 scontext=u:r:logger_app:s0:c23,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0

Bug: 188601292
Bug: 188611595

Change-Id: If6b204bf0d5c502cf09c9fe70bcd572cfe2db016
2021-05-19 07:39:36 +00:00
yixuanjiang
494ac0cfe3 Add sepolicy for aocdump to access wlan_logs folder
Add related sepolicies on aoc dump when pixel logger using
wlan config

Bug: 188411088
Signed-off-by: yixuanjiang <yixuanjiang@google.com>
Change-Id: I7a786f25b9094cc9ebeef79e4aff5522bde17d19
2021-05-19 14:11:42 +08:00
Jinting Lin
2ffb2eb505 Merge "logger_app: Fix avc errors" into sc-dev am: c57a3fc989
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14608140

Change-Id: Id284f7befba9cc5f404087efab266d2a94b983e7
2021-05-19 02:39:22 +00:00
Jinting Lin
c57a3fc989 Merge "logger_app: Fix avc errors" into sc-dev 2021-05-19 02:18:39 +00:00
Tri Vo
00566d516b Merge "Fix file_contexts path for trusty_metricsd" into sc-dev am: 6a558ac02b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14605122

Change-Id: I73654ca4cb0e8dac699db1b99a1722b85101f2f4
2021-05-18 22:38:38 +00:00
Tri Vo
6a558ac02b Merge "Fix file_contexts path for trusty_metricsd" into sc-dev 2021-05-18 22:18:39 +00:00
Tri Vo
970f15b13d Fix file_contexts path for trusty_metricsd
Bug: 188417701
Bug: 173423860
Test: trusty_metricsd starts
Change-Id: I212c2d449441ac4b9238c8f7171982b253d4b6e0
2021-05-18 19:39:42 +00:00
Yu-Chi Cheng
8f44cf052c Merge "Renamed edgetpu_service to edgetpu_app_service." into sc-dev am: 8ebeb48b39
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14607191

Change-Id: I9c17d89a677f02dfb329933db057fcf9257ce68b
2021-05-18 19:23:15 +00:00
Yu-Chi Cheng
8ebeb48b39 Merge "Renamed edgetpu_service to edgetpu_app_service." into sc-dev 2021-05-18 19:13:21 +00:00
TreeHugger Robot
87f6042d23 Merge "Remove platform certification from imsservice" into sc-dev am: 6a5cfd86f5 am: b33a1a4042 am: 067716b11c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14343989

Change-Id: I6e70c1f4dd5d11149ed0781181899c476dcde245
2021-05-18 18:13:58 +00:00
Roger Fang
3d9dfa1e58 Merge changes from topic "IAudioMetricExt@1.0" into sc-dev am: 834331af79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14281930

Change-Id: If56802dd85f6a6be85982ff7bbd2139f7a5518ea
2021-05-18 17:38:54 +00:00
Gary Jian
b724a106ed Add permission to access audiometricext hal for grilservice_app am: b9e4f7a759
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13885467

Change-Id: I7b4da71ea18f09d42bacffd9aa28644b38b92513
2021-05-18 17:38:52 +00:00
Roger Fang
834331af79 Merge changes from topic "IAudioMetricExt@1.0" into sc-dev
* changes:
  sepolicy: gs101: add IAudioMetricExt settings
  Add permission to access audiometricext hal for grilservice_app
2021-05-18 17:21:48 +00:00
TreeHugger Robot
9f7e2553f4 Merge "Update gs101 sepolicy for contexthub HAL" into sc-dev am: ff7948fc48 am: 81e7e0d374 am: 268781c624
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14354723

Change-Id: I8485dfc27c7c55ecf65e953708426babf2b5aa1c
2021-05-18 16:42:31 +00:00
TreeHugger Robot
e661572624 Merge "sepolicy:gs101: allow init-insmod-sh to access sysfs_leds nodes" into sc-dev am: c134ed985a am: 56305a9427 am: 4176a39915
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14357213

Change-Id: I57ca717aba8ceb55035814d0eaf233fca92ee3fc
2021-05-18 16:42:22 +00:00
TreeHugger Robot
cb5e052aec Merge "change persist.camera to persit.vendor.camera" into sc-dev am: 2c4b0fd96a am: 82f13cbf48 am: b41e03b3a6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14356785

Change-Id: Ifb927bf6f387d294b39092517a5aec21c8017cbb
2021-05-18 16:42:17 +00:00
TreeHugger Robot
c64692dc40 Merge "Add sepolicy for sensor HAL to read lhbm" into sc-dev am: 7a4cd3a6e0 am: 04b1f2cdec am: a8f126d70c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14299201

Change-Id: I54fa74806e8400d5e012a6dbe6c606d00bb9f8f9
2021-05-18 16:42:11 +00:00
Kevin DuBois
0afea3c02d Merge "sepolicy: update gpu nnhal file" into sc-dev am: 811dbd6611
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14551347

Change-Id: Ia73a117f48808441194e827384ebf88ee671c127
2021-05-18 15:28:16 +00:00
Kevin DuBois
811dbd6611 Merge "sepolicy: update gpu nnhal file" into sc-dev 2021-05-18 15:07:05 +00:00
Quinn Yan
3175af2d48 Merge "Add the TPU AIDL NNAPI HAL to the sepolicy." into sc-dev am: d2558a05b3 am: 5145ae8e4c am: e11173811e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14506028

Change-Id: I387df14cf83a29032cb5595f2be42eb4c74d9c63
2021-05-18 13:29:12 +00:00
SHUCHI LILU
360a59388c Merge "Update avc error on ROM 7358093" into sc-dev am: 60bf6343be am: 64a1e16887 am: 218a434cd8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542522

Change-Id: I223178f7c40891ed4826ce95516ab9feda8a4df9
2021-05-18 13:28:35 +00:00
Midas Chien
c88435dc47 Merge "Allowed PowerHAL service access Display node" into sc-dev am: b610fd307e am: d2e21ded9a am: c5d3b92fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14308761

Change-Id: I0e8573afece7fe30bb218bde22510bfeb29935bd
2021-05-18 13:28:28 +00:00
SalmaxChang
f4b979cf7f rfsd: fix permission error am: 30b9f8f277 am: 272b4e5590 am: 4c134fec1b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467419

Change-Id: I0d3ee4e34ea238c410222c8caabe52573af06bb1
2021-05-18 13:28:21 +00:00
Manish Varma
6021febd2c genfs_contexts: fix path for st21nfc i2c devices am: 705ecbe0ab am: 4aa4640559 am: a5a368cdfc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538367

Change-Id: I2f4729c09419c0c852e1e5e47d8232deac3fcb25
2021-05-18 13:28:13 +00:00
Manish Varma
3f343b7b2c genfs_contexts: fix path for s2mpg1X i2c devices am: fd2a6b9a74 am: a592b23a80 am: 03657f8e3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538366

Change-Id: I51931583362903d08cc8962eb38f499493d7145d
2021-05-18 13:28:12 +00:00
Manish Varma
1f6bee9cb4 genfs_contexts: fix path for cs40l25a i2c devices am: 194fef8b5a am: 67d28bdf03 am: 459bdb2a40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538365

Change-Id: I9c538a63d33730aea7175754625d7af2fcdf028e
2021-05-18 13:28:11 +00:00
Manish Varma
739bbced69 genfs_contexts: fix path for max77759tcpc i2c devices am: 3868f8aa88 am: aaee225e77 am: db3f825375
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14538364

Change-Id: Ide601be79ed433a0831c0b1432e5efa524dac52b
2021-05-18 13:28:10 +00:00
Manish Varma
a08d344be1 genfs_contexts: fix path for p9412 i2c devices am: b08c98c2b4 am: 9ba9e2a783 am: 529d215c31
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14535947

Change-Id: I653d91e668e5fbaa3004fbc0ecdc499a53b8aa19
2021-05-18 13:28:09 +00:00
TreeHugger Robot
8b4923b7c8 Merge changes from topic "186500818-set1" into sc-dev am: 775771b811 am: a019f35a3b am: c833549d8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14490413

Change-Id: I24fc274705adfec6ee3060a67829a9e6726550b6
2021-05-18 13:27:55 +00:00
Vineeta Srivastava
0bf4c5c898 Merge "Add sepolicy for the UDFPS antispoof property" into sc-dev am: 14a07e230a am: 4d42a986f8 am: 5e7734b411
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14467424

Change-Id: I6251fb8f52360cfa753797212ad088ad3ff7fb54
2021-05-18 13:26:17 +00:00
jintinglin
3be06b2ec9 logger_app: Fix avc errors
avc: denied { read } for name="level" dev="sysfs" ino=57112 scontext=u:r:logger_app:s0:c29,c257,c512,c768 tcontext=u:object_r:sysfs_sscoredump_level:s0 tclass=file permissive=0 app=com.android.pixellogger

Bug: 187909426
Change-Id: I2037b1d2613736c8e1789bc96bfd4be0168444e0
2021-05-18 18:46:00 +08:00
Roger Fang
9de2688cd4 sepolicy: gs101: add IAudioMetricExt settings
E init    : Could not start service 'audiometricext' as part of class 'hal': File /vendor/bin/hw/vendor.google.audiometricext@1.0-service-vendor(labeled "u:object_r:vendor_file:s0")

vendor.google.a: type=1400 audit(0.0:3): avc: denied { read } for name="u:object_r:hwservicemanager_prop:s0" dev="tmpfs" ino=188 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:hwservicemanager_prop:s0 tclass=file permissive=1

E SELinux : avc:  denied  { find } for interface=vendor.google.audiometricext::IAudioMetricExt sid=u:r:hal_audiometricext_default:s0 pid=819 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:default_android_hwservice:s0 tclass=hwservice_manager permissive=1

E SELinux : avc:  denied  { add } for interface=android.hidl.base::IBase sid=u:r:hal_audiometricext_default:s0 pid=795 scontext=u:r:hal_audiometricext_default:s0 tcontext=u:object_r:hidl_base_hwservice:s0 tclass=hwservice_manager permissive=1

Bug: 180627405
Test: manually test passed
Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: I91d76eb0ad5850e75ad865304d83f3025b981915
2021-05-18 05:06:58 +00:00
Gary Jian
b9e4f7a759 Add permission to access audiometricext hal for grilservice_app
Bug: 182526894
Test: Manual
Change-Id: I3ca85be7e5ab244e2dea2c6f7768f59c07b44525
2021-05-18 02:18:56 +00:00
TreeHugger Robot
3075216794 Merge "genfs_contexts: Specify correct GPU clock hint node" into sc-dev am: ac53196839
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14599591

Change-Id: Ifc1411973f3dcb258d3673e05d8d519e9132cd64
2021-05-18 00:54:21 +00:00
TreeHugger Robot
843c90e0ae Merge "Grant dumpstate hal read permission of camera hal dump files" into sc-dev am: 09a98d233d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14604511

Change-Id: I96a4843b04f81194053e1c552757b76bb6f0a134
2021-05-18 00:53:51 +00:00
TreeHugger Robot
ac53196839 Merge "genfs_contexts: Specify correct GPU clock hint node" into sc-dev 2021-05-18 00:50:53 +00:00
TreeHugger Robot
09a98d233d Merge "Grant dumpstate hal read permission of camera hal dump files" into sc-dev 2021-05-18 00:42:12 +00:00