Commit graph

1350 commits

Author SHA1 Message Date
Jack Wu
c5964bf33a sepolicy: gs101: allows pixelstat to access pca file nodes am: d6c1a50bba am: 2c79c75768
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15360184

Change-Id: I1dcf34ae4ab3fb1a9fda23334d4ed7e0f4723b2c
2021-07-27 02:47:03 +00:00
Jack Wu
2c79c75768 sepolicy: gs101: allows pixelstat to access pca file nodes am: d6c1a50bba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15360184

Change-Id: Ic3efb76715139aa335995b95e7756f23b5de226c
2021-07-27 02:29:16 +00:00
Jack Wu
d6c1a50bba sepolicy: gs101: allows pixelstat to access pca file nodes
07-23 14:24:45.512  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:10): avc: denied { open } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:45.512  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:11): avc: denied { getattr } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:12): avc: denied { read } for name="chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:13): avc: denied { open } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:14): avc: denied { getattr } for path="/sys/devices/platform/10d50000.hsi2c/i2c-5/5-0057/chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
07-23 14:24:57.536  1000  3001  3001 I pixelstats-vend: type=1400 audit(0.0:15): avc: denied { write } for name="chg_stats" dev="sysfs" ino=72245 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1

Bug: 194386750
Test: manually test, no avc: denied
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: I1a16edb5bb7820f62b3ce598aa50eba2d9455927
2021-07-24 06:42:39 +00:00
TreeHugger Robot
df6e6f021b Merge "Add SE policies for memtrack HAL" into sc-dev am: b3225f0f6c am: 5cdaa6a45f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283133

Change-Id: I7959cb1161e4a8e86b7344f487fb63e6bbb4e17b
2021-07-23 21:43:22 +00:00
TreeHugger Robot
10d4b623ec Merge "Add SE policies for memtrack HAL" into sc-dev am: b3225f0f6c am: cd16e38ab2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283133

Change-Id: I9a34df30f890f98711cdea42b6fc75492e66ddb4
2021-07-23 21:42:04 +00:00
TreeHugger Robot
cd16e38ab2 Merge "Add SE policies for memtrack HAL" into sc-dev am: b3225f0f6c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283133

Change-Id: I552351e0eac65c20d795b1682852896943f948c8
2021-07-23 21:24:50 +00:00
TreeHugger Robot
5cdaa6a45f Merge "Add SE policies for memtrack HAL" into sc-dev am: b3225f0f6c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283133

Change-Id: Iff4c3146f074c8dc40af1598002629bd9c0d46f3
2021-07-23 21:24:35 +00:00
TreeHugger Robot
b3225f0f6c Merge "Add SE policies for memtrack HAL" into sc-dev 2021-07-23 20:52:52 +00:00
Ankit Goyal
0f9820830c Add SE policies for memtrack HAL
Bug: 191966412
Test: adb shell dumpsys meminfo
Change-Id: Ia7ec64840d2bb7c3ae0d61304e109d2ceb9e5f78
2021-07-24 02:18:36 +08:00
Max Shi
fdd51fb96e Allow USF sensor HAL to read camera persist files. am: 0bd50d1eb5 am: 0f58b38401
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15352099

Change-Id: Id8dae3cb84473c38fdedcb15437e566e941edbde
2021-07-23 00:04:03 +00:00
Max Shi
c53dbeaf0e Allow USF sensor HAL to read camera persist files. am: 0bd50d1eb5 am: 50486c63f3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15352099

Change-Id: I79a5f932ccafd7dafa28f6978d524b4eccf809a4
2021-07-23 00:03:25 +00:00
Max Shi
50486c63f3 Allow USF sensor HAL to read camera persist files. am: 0bd50d1eb5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15352099

Change-Id: Id31975a653e79362c0dea9a86b52944d340f2fee
2021-07-22 23:46:11 +00:00
Max Shi
0f58b38401 Allow USF sensor HAL to read camera persist files. am: 0bd50d1eb5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15352099

Change-Id: I585215a1e0266ebb52ccec18834c4f0e68ec6c69
2021-07-22 23:45:02 +00:00
Max Shi
0bd50d1eb5 Allow USF sensor HAL to read camera persist files.
USF sensor HAL requires access to camera persist files to determine if
the camera module has been replaced (e.g. via repair), which may affect
calibration of the magnetometer.

Bug: 193727762
Test: Verify sensor HAL can open and read files under
Test: /mnt/vendor/persist/camera/
Change-Id: Icb9d7a46bf8465e1a72054ac9c8493ba18445ef3
2021-07-22 21:11:44 +00:00
Badhri Jagan Sridharan
f0f0de5d84 Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev am: 49804d8d6f am: 00b89f5d8d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283349

Change-Id: Iff45d60431f1b3bcdeb267c317d78b124bcf4748
2021-07-22 21:10:02 +00:00
Badhri Jagan Sridharan
f83fca5b70 Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev am: 49804d8d6f am: 31b15ff2bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283349

Change-Id: I9d73177b869072e6aa4fcc504a055a3a9682a72d
2021-07-22 21:09:12 +00:00
Badhri Jagan Sridharan
31b15ff2bb Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev am: 49804d8d6f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283349

Change-Id: I6fc802f74aaf7e1f7a7b8574ed5ace1886b9623c
2021-07-22 20:52:11 +00:00
Badhri Jagan Sridharan
00b89f5d8d Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev am: 49804d8d6f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15283349

Change-Id: I7ca2b0ea191d0fab866eca184a795091caa260ad
2021-07-22 20:50:56 +00:00
Badhri Jagan Sridharan
49804d8d6f Merge "Update Usb hal permissions to allow pushing overheat suez events" into sc-dev 2021-07-22 20:31:13 +00:00
George Lee
59666184b6 Merge "pixelstats: add bcl directory permission" into sc-dev am: 79a15eed2a am: a1b0983730
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145257

Change-Id: I34670302ecc1d9adf5baa26c9c8a6573cb47628e
2021-07-22 18:35:15 +00:00
George Lee
674a509d5d Merge "pixelstats: add bcl directory permission" into sc-dev am: 79a15eed2a am: ef556f7fee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145257

Change-Id: I7d41017bfda1e112667aef94a09dd645a69af9b5
2021-07-22 17:56:09 +00:00
George Lee
a1b0983730 Merge "pixelstats: add bcl directory permission" into sc-dev am: 79a15eed2a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145257

Change-Id: I5fe3e10576664cf3a73a210a5089d46574fcdf84
2021-07-22 17:48:25 +00:00
George Lee
ef556f7fee Merge "pixelstats: add bcl directory permission" into sc-dev am: 79a15eed2a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15145257

Change-Id: I4d0c92d3074ef8e3112b6dade853b6b53dbb3cfe
2021-07-22 17:26:15 +00:00
George Lee
79a15eed2a Merge "pixelstats: add bcl directory permission" into sc-dev 2021-07-22 17:03:33 +00:00
Gary Jian
7566282022 Merge "Allow to set vendor_rild_prop for oemrilservice_app" into sc-dev am: 9b5a97d65e am: 7adebe6c62
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15327671

Change-Id: I367078bd8adfdc278647ba8f6b19e845b064e5f0
2021-07-22 09:05:53 +00:00
Gary Jian
de4bd33a04 Merge "Allow to set vendor_rild_prop for oemrilservice_app" into sc-dev am: 9b5a97d65e am: 11d8a4eb7e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15327671

Change-Id: I3c1e0377927df7e55a85a7d1609b08d0279afd5b
2021-07-22 08:46:11 +00:00
Gary Jian
7adebe6c62 Merge "Allow to set vendor_rild_prop for oemrilservice_app" into sc-dev am: 9b5a97d65e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15327671

Change-Id: I942e721133992a86b4cab295e09a5fb99e5fa814
2021-07-22 08:42:08 +00:00
Gary Jian
11d8a4eb7e Merge "Allow to set vendor_rild_prop for oemrilservice_app" into sc-dev am: 9b5a97d65e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15327671

Change-Id: I8e2e152f7ca71a0e5aa462093ebc10604d408814
2021-07-22 08:27:53 +00:00
Gary Jian
9b5a97d65e Merge "Allow to set vendor_rild_prop for oemrilservice_app" into sc-dev 2021-07-22 08:16:42 +00:00
Petri Gynther
ed848b779b Add vbmeta_vendor_[ab] to file_contexts am: d12714ccc0 am: 056fbce364
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15276573

Change-Id: If619e378579d32cb1734dd69350b702006991f75
2021-07-22 00:23:54 +00:00
Petri Gynther
61f76249ec Add vbmeta_vendor_[ab] to file_contexts am: d12714ccc0 am: adee4062ad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15276573

Change-Id: Id2cbb2f9059a0cb3250582df866292f9fa7f795f
2021-07-22 00:22:42 +00:00
Petri Gynther
adee4062ad Add vbmeta_vendor_[ab] to file_contexts am: d12714ccc0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15276573

Change-Id: Ie5f417c81373d599403646c90ddeda78b84c0b7a
2021-07-21 23:50:44 +00:00
Petri Gynther
056fbce364 Add vbmeta_vendor_[ab] to file_contexts am: d12714ccc0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15276573

Change-Id: I7a64114eed37ee384dba61a492fbb58cc2a30831
2021-07-21 23:46:06 +00:00
Badhri Jagan Sridharan
1ebd84703b Update Usb hal permissions to allow pushing overheat suez events
Usb hal now pushes the Usb port overheat event through statsd.
Usb hal also accesses usbc-throttling stats to gather info.

Bug: 193615568
Signed-off-by: Badhri Jagan Sridharan <badhri@google.com>
Change-Id: I4918458bc7a8a25d7655b66d1fe40eafc7ccb070
2021-07-21 14:38:55 -07:00
Sungwoo choi
b47cdf282a Allow to set vendor_rild_prop for oemrilservice_app
Bug: 193367138
Test: make sure no denied logs in oemrilservice_app when access the
radio property

Signed-off-by: Sungwoo choi <sungwoo48.choi@samsung.com>
Change-Id: I9014002476df7b4e650f7a5a2f153e4eca47d23d
2021-07-21 08:01:44 +00:00
Petri Gynther
d12714ccc0 Add vbmeta_vendor_[ab] to file_contexts
Bug: 181909612
Test: build + install + boot to home
Change-Id: Ibb7bd8e5a61d86de1b51a3780a5bfa8cf4caf59b
2021-07-20 23:41:31 -07:00
sukiliu
8db9300fee Update avc error on ROM 7566803 am: 411aa59779 am: 8dfbba48d1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15343071

Change-Id: I38bb7bb68cf50cbb03652809e7dddadb44328346
2021-07-21 06:14:01 +00:00
sukiliu
f7c4032235 Update avc error on ROM 7566803 am: 411aa59779 am: d1f198d5eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15343071

Change-Id: Id602f32ef1157321a7bc399bfb5398ccec4f3ca4
2021-07-21 06:13:41 +00:00
sukiliu
d1f198d5eb Update avc error on ROM 7566803 am: 411aa59779
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15343071

Change-Id: I71dbe7cfb4ff8f409e9565e4a636ca8c4a3844ce
2021-07-21 06:02:08 +00:00
sukiliu
8dfbba48d1 Update avc error on ROM 7566803 am: 411aa59779
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15343071

Change-Id: I5a350cde5a79354fa11d1892425ca0f98e64003c
2021-07-21 06:00:47 +00:00
sukiliu
411aa59779 Update avc error on ROM 7566803
avc: denied { read } for name="platform:1cc40000.sysmmu--platform:1ce00000.abrolhos" dev="sysfs" ino=21006 scontext=u:r:hal_neuralnetworks_darwinn:s0 tcontext=u:object_r:sysfs:s0 tclass=dir permissive=0

Bug: 194241380
Test: PtsSELinuxTestCases
Change-Id: If7ee99a36bca88fffc37c12dc306e0453afb1395
2021-07-21 09:36:05 +08:00
TreeHugger Robot
e813912c48 Merge "ims: allow finding mediametrics_service for vendor_ims_app" into sc-dev am: b3cc71258b am: 2260028f16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15302265

Change-Id: Ibb4101ddaebda394a4a678633fb27f57842e54a1
2021-07-20 13:30:51 +00:00
Alex Hong
361ee2d046 Allow suspend_control to access the AOC wakeup node am: f0589d11df am: 2727807154
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15334275

Change-Id: I56d662d091bca5b89103868724caaa92aefd2075
2021-07-20 13:30:49 +00:00
TreeHugger Robot
090c2fb351 Merge "ims: allow finding mediametrics_service for vendor_ims_app" into sc-dev am: b3cc71258b am: 0c411447d7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15302265

Change-Id: I42629d18ea3fe0bf41db5800fad4529308128578
2021-07-20 13:30:34 +00:00
Alex Hong
10892fb570 Allow suspend_control to access the AOC wakeup node am: f0589d11df am: 5cc647e87d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15334275

Change-Id: I19641fc130eb75e7220b4a070de6dd95f8f6a0a8
2021-07-20 13:30:29 +00:00
TreeHugger Robot
0c411447d7 Merge "ims: allow finding mediametrics_service for vendor_ims_app" into sc-dev am: b3cc71258b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15302265

Change-Id: Ie50b322dca7fc0292a200a721870c6679456c5b5
2021-07-20 13:13:02 +00:00
Alex Hong
5cc647e87d Allow suspend_control to access the AOC wakeup node am: f0589d11df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15334275

Change-Id: Ibfbe41ba694a27408dbd3ff6bdb5632d55a9a05e
2021-07-20 13:12:56 +00:00
TreeHugger Robot
2260028f16 Merge "ims: allow finding mediametrics_service for vendor_ims_app" into sc-dev am: b3cc71258b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15302265

Change-Id: Ib3679aac5321fee05088ae34fd6aee63e9345599
2021-07-20 13:12:08 +00:00
Alex Hong
2727807154 Allow suspend_control to access the AOC wakeup node am: f0589d11df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/15334275

Change-Id: I5279e246ce4ce654b76dc8fb213833c60ea32430
2021-07-20 13:12:04 +00:00
TreeHugger Robot
b3cc71258b Merge "ims: allow finding mediametrics_service for vendor_ims_app" into sc-dev 2021-07-20 13:00:25 +00:00