Commit graph

1339 commits

Author SHA1 Message Date
sukiliu
d9309ef34d Update avc error on ROM 7562467
avc: denied { read } for name="u:object_r:odsign_prop:s0" dev="tmpfs" ino=229 scontext=u:r:postinstall_dexopt:s0 tcontext=u:object_r:odsign_prop:s0 tclass=file permissive=0
avc: denied { read } for comm="otapreopt" name="u:object_r:odsign_prop:s0" dev="tmpfs" ino=229 scontext=u:r:postinstall_dexopt:s0 tcontext=u:object_r:odsign_prop:s0 tclass=file permissive=0

Bug: 194142604
Bug: 194065991
Test: PtsSELinuxTestCases
Change-Id: Ic3bb544f05ffff0df42f820d2f9cf6cd7cb24879
2021-07-20 10:03:30 +08:00
TreeHugger Robot
35ccf64620 Merge "Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot" into sc-dev am: f8b8e0cb53 am: 8b76ff03de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15316269

Change-Id: I5b462c51cf2b8024506b4907392a18d6d204b830
2021-07-19 21:22:48 +00:00
TreeHugger Robot
2706f2f475 Merge "Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot" into sc-dev am: f8b8e0cb53 am: dd0acb63a4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15316269

Change-Id: I9409592f8dfe46bfad18e232dbf313d084348260
2021-07-19 21:22:23 +00:00
TreeHugger Robot
dd0acb63a4 Merge "Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot" into sc-dev am: f8b8e0cb53
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15316269

Change-Id: Ia0bf59df027d801313955161d53139b7176c8b19
2021-07-19 21:10:22 +00:00
TreeHugger Robot
8b76ff03de Merge "Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot" into sc-dev am: f8b8e0cb53
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15316269

Change-Id: I0f77c7bfc41db1bdd361708218d5dd5750d5c682
2021-07-19 21:09:31 +00:00
TreeHugger Robot
f8b8e0cb53 Merge "Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot" into sc-dev 2021-07-19 20:54:38 +00:00
TreeHugger Robot
b6ca87033f Merge "Allow HAL to access sysfs." into sc-dev am: fc321aabe2 am: 56491c6712
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15308771

Change-Id: I83158b17a617cba5e70a0c68b4c6bc9bd4deae14
2021-07-19 19:07:59 +00:00
TreeHugger Robot
a4a693bcd5 Merge "Allow HAL to access sysfs." into sc-dev am: fc321aabe2 am: 299745791f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15308771

Change-Id: Ie869d006d0a5023eae8e1ce0a37d5691e98603a9
2021-07-19 19:07:21 +00:00
TreeHugger Robot
299745791f Merge "Allow HAL to access sysfs." into sc-dev am: fc321aabe2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15308771

Change-Id: If129d2a57a6d94ef42cc187b7d53eb5c5a536d80
2021-07-19 18:39:57 +00:00
TreeHugger Robot
56491c6712 Merge "Allow HAL to access sysfs." into sc-dev am: fc321aabe2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15308771

Change-Id: I2254f63fc551654694fa5ecda3b78cda80c76d5c
2021-07-19 18:39:16 +00:00
Andrew LeCain
4e4a1ba28e Merge "sepolicy allow fingerprint hal to read mfg_data" into sc-dev am: ff13d1adee am: d297941975
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15292860

Change-Id: Id7851b07a3dea8f10c8fbc92076d392efbb7362c
2021-07-19 18:23:25 +00:00
TreeHugger Robot
fc321aabe2 Merge "Allow HAL to access sysfs." into sc-dev 2021-07-19 18:22:13 +00:00
Andrew LeCain
950a16e796 Merge "sepolicy allow fingerprint hal to read mfg_data" into sc-dev am: ff13d1adee am: c854cd3e43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15292860

Change-Id: I0ceefa7b2f28075d40deb8db0e475b219665e67a
2021-07-19 18:18:41 +00:00
Andrew LeCain
d297941975 Merge "sepolicy allow fingerprint hal to read mfg_data" into sc-dev am: ff13d1adee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15292860

Change-Id: I53ca776b64edda2d1cabf505445f2f7768f04dc6
2021-07-19 18:06:19 +00:00
Andrew LeCain
c854cd3e43 Merge "sepolicy allow fingerprint hal to read mfg_data" into sc-dev am: ff13d1adee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15292860

Change-Id: I419c8ac06e29ad9bafadac397e3948794cd0f38d
2021-07-19 18:04:20 +00:00
Andrew LeCain
ff13d1adee Merge "sepolicy allow fingerprint hal to read mfg_data" into sc-dev 2021-07-19 17:46:18 +00:00
Stephane Lee
022b61751e Add cpm/pca9468 logbuffer directories so that bugreports can take a snapshot
Test: adb bugreport; check "dumpstate_board.txt"
Bug: 193894298
Change-Id: I222405ab6d78bd4367a91cc0f13b8d8a0f1ca578
2021-07-16 16:27:42 -07:00
Sina Hassani
e763f3cc9b Allow HAL to access sysfs.
This is so that it can read fw metrics from sysfs and dump them through
dumpsys.

Test: Ran dumpsys and bugreport.
Bug: 193841666
Change-Id: I08c08e35bad35d0eefc3f6ad218fb47e24051b0c
2021-07-16 16:27:34 -07:00
Wenhao Wang
235e505ec0 Merge "Add wakelock access for storageproxyd" into sc-dev am: 5305955a86 am: 2668a75c61
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15306271

Change-Id: Id88ff0bb4c37025aaf9ae2a44740339f7f21cdec
2021-07-16 17:42:37 +00:00
Wenhao Wang
563d5cd06d Merge "Add wakelock access for storageproxyd" into sc-dev am: 5305955a86 am: e4e2f33f14
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15306271

Change-Id: I6c5948116b72226356517e7806a2f6a1f23fdd48
2021-07-16 17:42:11 +00:00
Wenhao Wang
e4e2f33f14 Merge "Add wakelock access for storageproxyd" into sc-dev am: 5305955a86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15306271

Change-Id: I133982ece59c9dc571b858b189375d31b4f02542
2021-07-16 17:30:31 +00:00
Wenhao Wang
2668a75c61 Merge "Add wakelock access for storageproxyd" into sc-dev am: 5305955a86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15306271

Change-Id: I9bc3270349b159cfd1e1a9e33162c0169d23494a
2021-07-16 17:29:45 +00:00
Wenhao Wang
5305955a86 Merge "Add wakelock access for storageproxyd" into sc-dev 2021-07-16 17:12:01 +00:00
Alex Hong
2a0fc76fb6 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev am: ea6934fda9 am: 77236f96d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15296508

Change-Id: I43bd4ce43de474d3f8fdb0bba08cfde634fe52bc
2021-07-16 07:03:48 +00:00
Alex Hong
f4db4f24d3 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev am: ea6934fda9 am: 603f871e41
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15296508

Change-Id: I7f1ff767b49acf6d69d0e29a7b653d0c7e33e837
2021-07-16 06:55:30 +00:00
Alex Hong
77236f96d6 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev am: ea6934fda9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15296508

Change-Id: Id9c0bdad2c43886630107cbbbc7f51459481ddf9
2021-07-16 06:46:06 +00:00
Alex Hong
603f871e41 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev am: ea6934fda9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15296508

Change-Id: Ie62db9de45aeb5244d1a53d35f2f216122378177
2021-07-16 06:45:21 +00:00
Alex Hong
ea6934fda9 Merge "sepolicy: gs101: support tetheroffload hal version 1.y" into sc-dev 2021-07-16 06:28:32 +00:00
Namkyu Kim
4055c31faf sepolicy: gs101: support tetheroffload hal version 1.y
Support both 1.0 and 1.1.

Bug: 186539538
Test: run vts -m VtsHalTetheroffloadControlV1_0TargetTest
      run vts -m VtsHalTetheroffloadControlV1_1TargetTest

Signed-off-by: Namkyu Kim <namkyu78.kim@samsung.com>
Change-Id: I76a26dcd22e1c8985d470a39b9aeae618f459d00
2021-07-16 04:05:21 +00:00
Stephane Lee
804e13cb8c Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev am: ea6996bc52 am: 0a7e3ad9ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15289584

Change-Id: I2218337eea58263408b8e782e1bdbeebe3cca62b
2021-07-16 02:30:30 +00:00
Stephane Lee
3d97807081 Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev am: ea6996bc52 am: b37fe8c071
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15289584

Change-Id: I237fac500741e1c15ca6fb7d3cf3c0e1a19a647a
2021-07-16 02:30:03 +00:00
Stephane Lee
b37fe8c071 Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev am: ea6996bc52
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15289584

Change-Id: I587aad68aafb8b4229fd76f2a35d94ccc4a51987
2021-07-16 02:11:29 +00:00
Stephane Lee
0a7e3ad9ea Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev am: ea6996bc52
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15289584

Change-Id: Ia8765b15f56c4a4da76ce47c0e38ebaef351d4a7
2021-07-16 02:10:10 +00:00
Stephane Lee
ea6996bc52 Merge "odpm: Rename the odpm_config sepolicies to be more consistent" into sc-dev 2021-07-16 01:55:33 +00:00
Wenhao Wang
5c009fb96f Add wakelock access for storageproxyd
The storageproxyd needs a wakelock around the sequence of UFS commands

Bug: 193456223
Test: Trusty storage tests
Change-Id: I1efe3144c8bcc17c056fc3b9b796e080f77991d5
2021-07-15 17:10:31 -07:00
Andrew LeCain
d8d8580281 sepolicy allow fingerprint hal to read mfg_data
declares new device context for mfg_data_block_device
give fp HAL permission to read/write/open
give fp HAL permission to search block_device dir

Bug: 189135413
Test: sideload calibration in enforcing mode.
Change-Id: I19e0cd13fc452b42c3f35772c4bafd433dbcc8b1
2021-07-15 10:58:53 -07:00
TreeHugger Robot
c89296ff73 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev am: f0dd8e2957 am: 9eca0031b0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15269315

Change-Id: Ifa6e5a1a8bdb7c8afc6fdbe5ac03f44cb3d468da
2021-07-15 16:45:28 +00:00
TreeHugger Robot
34c83c5bdd Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev am: f0dd8e2957 am: 18ba5fc434
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15269315

Change-Id: Iee0a79fe68c84c92e55f9565d50301c8d6c45504
2021-07-15 16:45:05 +00:00
TreeHugger Robot
18ba5fc434 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev am: f0dd8e2957
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15269315

Change-Id: I6c76bc3520f86a8aa85172a38fbfe8ebec6d934c
2021-07-15 16:32:23 +00:00
TreeHugger Robot
9eca0031b0 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev am: f0dd8e2957
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15269315

Change-Id: I56fc4bbc6331e9b273f6deb9c324fcc2f48f7e74
2021-07-15 16:31:29 +00:00
TreeHugger Robot
f0dd8e2957 Merge "Set sepolicy for shell script of disabling contaminant detection" into sc-dev 2021-07-15 16:17:40 +00:00
sukiliu
ad022ab512 Update avc error on ROM 7550575 am: 06ea8d9432 am: 5382253c4f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283866

Change-Id: I2a6e59ecfa630338fe7425b19fd8ca4c91ec69a5
2021-07-15 09:29:19 +00:00
sukiliu
3ea8096eda Update avc error on ROM 7550575 am: 06ea8d9432 am: 65cda2d3a4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283866

Change-Id: Iaae31f3e2cd9607991b74fe4ec025b7586736bec
2021-07-15 09:28:31 +00:00
sukiliu
65cda2d3a4 Update avc error on ROM 7550575 am: 06ea8d9432
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283866

Change-Id: I5fd96bc2ab734e30683c77519fdf45594cb7904d
2021-07-15 09:01:40 +00:00
sukiliu
5382253c4f Update avc error on ROM 7550575 am: 06ea8d9432
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283866

Change-Id: I8a9c4dc678122acb58cec715bfed8707cd4701f3
2021-07-15 09:00:29 +00:00
Darren Hsu
3050ed8ed9 Set sepolicy for shell script of disabling contaminant detection
The avc denials are listed in b/192208389#comment10.

Bug: 192208389
Test: Manually tested
Change-Id: Ib2e3cf498851c0c9e5e74aacc9bf391549c0ad1a
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2021-07-15 11:11:11 +08:00
sukiliu
06ea8d9432 Update avc error on ROM 7550575
Bug: 193726003
Bug: 193633303
Bug: 193548421
Test: PtsSELinuxTestCases
Change-Id: Id6cb13602eb9a69f7815a0301a5708577c663bd2
2021-07-15 09:33:58 +08:00
Stephane Lee
c7342a7824 odpm: Rename the odpm_config sepolicies to be more consistent
Test: Ensure that there are no sepolicy errors on odpm_config
Bug: 192674986
Change-Id: I3043a544511c8c3051e1bd10e9f6b668b251cf5f
2021-07-14 16:11:51 -07:00
Orion Hodson
c508030c93 Merge "Revert "Update avc error on ROM 7522385"" into sc-dev am: d4a7e81293 am: ea548a455a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15235283

Change-Id: I1978089b667020a7182793bfc98aa1073eda750e
2021-07-14 09:38:57 +00:00
Orion Hodson
8df410d879 Merge "Revert "Update avc error on ROM 7522385"" into sc-dev am: d4a7e81293 am: b611de527f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15235283

Change-Id: I57f0580a78435a461b85fb52c0eb525a89a50c59
2021-07-14 09:38:38 +00:00