Commit graph

2022 commits

Author SHA1 Message Date
TreeHugger Robot
60382bf1d1 Merge "Use label persist_ss_file" into sc-dev am: 6550281b13 am: 0bf84fa3c0 am: 240f424f7f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: Ief8ee49a442b52588dd4d263f16630041cf7fa42
2021-06-16 06:45:42 +00:00
Adam Shih
2cdde93f15 Merge "remove vcd from user ROM" into sc-dev 2021-06-16 06:40:28 +00:00
TreeHugger Robot
12454301ca Merge "Use label persist_ss_file" into sc-dev am: 6550281b13 am: a0e1a8e2e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: Ibae22f2f82d9535fb30162fa85905599c04bac59
2021-06-16 06:33:37 +00:00
TreeHugger Robot
240f424f7f Merge "Use label persist_ss_file" into sc-dev am: 6550281b13 am: 0bf84fa3c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I14fa68f9b1f25af6f98badc583505fa4c39d3755
2021-06-16 06:33:18 +00:00
TreeHugger Robot
0bf84fa3c0 Merge "Use label persist_ss_file" into sc-dev am: 6550281b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I4336b65c246f69138f6534fc76ea12ead51f786e
2021-06-16 06:04:59 +00:00
TreeHugger Robot
a0e1a8e2e4 Merge "Use label persist_ss_file" into sc-dev am: 6550281b13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I7cfd671dd52f5422b317a6cd2f12847f65ee9a13
2021-06-16 06:04:10 +00:00
TreeHugger Robot
6550281b13 Merge "Use label persist_ss_file" into sc-dev 2021-06-16 05:45:04 +00:00
SHUCHI LILU
ef2e448dad Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: e79f75aa16 am: 537f9f01a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: Iabaf0d3a91c2b14309fe3f55074c3ef4a6dc4219
2021-06-16 04:39:14 +00:00
SHUCHI LILU
537f9f01a7 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: e79f75aa16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I052084f819b62d04b9c1f307f337497910163f5b
2021-06-16 04:18:20 +00:00
SHUCHI LILU
e79f75aa16 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I754282c66d68a873edd9b89919890d293bf90084
2021-06-16 04:01:22 +00:00
SHUCHI LILU
f360be9acd Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: 994d1f49da am: a97f039001
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: Iec26a1cc851e319ee524fbfe27a89f246f643be7
2021-06-16 02:45:56 +00:00
SHUCHI LILU
a97f039001 Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640 am: 994d1f49da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: I3f55acc9eebab648af2f454f2835df7c6d4aab2f
2021-06-16 02:07:02 +00:00
SHUCHI LILU
994d1f49da Merge "Update avc error on ROM 7457955" into sc-dev am: 5624d07640
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14980573

Change-Id: If63ce2fb708833204108e529a8b9962cceff5d4c
2021-06-16 01:48:37 +00:00
SHUCHI LILU
5624d07640 Merge "Update avc error on ROM 7457955" into sc-dev 2021-06-16 01:25:10 +00:00
Wenhao Wang
dc0cdc36f3 Use label persist_ss_file
The label "persist_ss_file" was created for "/mnt/vendor/persist/ss(/.*)?".
But we erroneously didn't assign the label to the path.
This patch fixes the error.

Bug: 173971240
Bug: 173032298
Test: Trusty storage tests
Change-Id: I8e891ebd90ae47ab8a4aad1c2b0a3bbb734174d8
2021-06-15 17:24:01 -07:00
David Anderson
dfc3d86927 Fix denial when flashing vendor_boot in fastbootd.
This mirrors the same sepolicy line in previous Pixel devices.

Bug: 189493387
Test: fastboot flash vendor_boot on r4
Change-Id: Ie15c8e6e5c01b249e1e5e244666c461253279f0b
2021-06-15 15:34:55 -07:00
Armelle Laine
f317bd54ac Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 6e23660e3d am: 2898603355
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Ib4839a7915d05d95b56171c7b07b3b21eb6500b5
2021-06-15 17:46:52 +00:00
Armelle Laine
2898603355 Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 6e23660e3d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Ib37826f8d2e15f9f1e6c4429dcd9c270f7c1dea3
2021-06-15 17:20:52 +00:00
Armelle Laine
45fbb8c8fc Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 4847b5d1f4 am: 3c61f8891a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Ic2f96c3fc589a7067a7daa07a06c3e5c5a0b8431
2021-06-15 15:30:20 +00:00
sukiliu
673b8f1014 Update avc error on ROM 7457955
Bug: 191132545
Bug: 191133059
Test: PtsSELinuxTestCases
Change-Id: I6a8e7924819734e38c2b6f761eb738f3e4d21c32
2021-06-15 23:23:43 +08:00
Armelle Laine
3c61f8891a Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d am: 4847b5d1f4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: I2c3d321d5c1c964c60b0dda5b2a9a204df090890
2021-06-15 15:13:25 +00:00
Armelle Laine
4847b5d1f4 Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: I9c29b33df803b368a71d68ce59e0f16cf3a2b66c
2021-06-15 14:52:27 +00:00
Armelle Laine
6e23660e3d Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev am: 10e8126e2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14961880

Change-Id: Icc35b74bb0ac43562583282d2d39dc1eb9646642
2021-06-15 14:51:51 +00:00
Armelle Laine
10e8126e2d Merge "add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal" into sc-dev 2021-06-15 14:35:43 +00:00
linpeter
81aaf6cda3 Add sepolicy for hwcomposer to access lhbm sysfs
avc: denied { read write } for comm="android.hardwar" name="local_hbm_mode" dev="sysfs" ino=70189 scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:sysfs_lhbm:s0 tclass=file permissive=0

Bug: 190563896
test: check avc denied
Change-Id: I0f6abc1244d24781ff3318908b524a889490993d
2021-06-15 19:37:14 +08:00
Jiyoung
02ada4f463 vendor_telephony_app.te: add selinuxfs:file
- add selinuxfs:file for AP TCP dump
- allow userdebug or eng

Bug: 188422036

Signed-off-by: Jiyoung <ji_young.bae@samsung.com>
Change-Id: I9502f9f7320ca4ee298b38e40da0ccf11adfba7f
2021-06-15 15:06:39 +08:00
sukiliu
974ac04768 Move oriole bug map to whitechapel folder am: 90ae782e26 am: c8a74f7fce am: b220a0e873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I85f7e77e6937117a11f5a7e2ba71e35eb5741152
2021-06-15 06:43:25 +00:00
sukiliu
d1fe1b5c53 Move oriole bug map to whitechapel folder am: 90ae782e26 am: 8657bfaf73 am: e18a7658e9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: Idc1ae5052f021757094d0304ee791c5841134bc2
2021-06-15 06:43:18 +00:00
sukiliu
b220a0e873 Move oriole bug map to whitechapel folder am: 90ae782e26 am: c8a74f7fce
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I5faa78c559f4a6ddc0d7b92296d79b653b1a5e97
2021-06-15 06:30:33 +00:00
sukiliu
e18a7658e9 Move oriole bug map to whitechapel folder am: 90ae782e26 am: 8657bfaf73
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I7f8298eeb6d2988aa32f8cc4789f900ed57c04fb
2021-06-15 06:30:04 +00:00
sukiliu
8657bfaf73 Move oriole bug map to whitechapel folder am: 90ae782e26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I697e2270c71c1f5ce48318e9a3498ef05d954c82
2021-06-15 06:17:36 +00:00
sukiliu
c8a74f7fce Move oriole bug map to whitechapel folder am: 90ae782e26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14963698

Change-Id: I20a6b1f291236b26224ca0fe94196b2ca91bd548
2021-06-15 06:16:50 +00:00
sukiliu
90ae782e26 Move oriole bug map to whitechapel folder
Bug: 190563896
Bug: 190671898
Test: PtsSELinuxTestCases
Change-Id: I15f1a6d2ebab9c5794a79abccf3530eb4bfc8307
2021-06-15 04:39:50 +00:00
TreeHugger Robot
14e0fab271 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: d8aa5c7972 am: 8314b7f628
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: If85b7eec532292b3fc903d916c4eed9a78ad90eb
2021-06-15 02:21:44 +00:00
TreeHugger Robot
f51643c9fc Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: ebcba2c62d am: 67bd98cff1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I6bf028823b92899a70875850d2d3ce80376607da
2021-06-15 02:21:01 +00:00
TreeHugger Robot
8314b7f628 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: d8aa5c7972
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I808fa351bb12654bbaa66248d9f10e6ce62f16e8
2021-06-15 02:08:19 +00:00
TreeHugger Robot
67bd98cff1 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a am: ebcba2c62d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: Iec8b071a423c5243b9c1d8322ebc9e5698b48f88
2021-06-15 02:08:07 +00:00
TreeHugger Robot
ebcba2c62d Merge "remove obsolete entries" into sc-dev am: 441bae6d1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I4d47c91c175d8a10e0cec3e974e684f3c44b6c63
2021-06-15 01:54:55 +00:00
TreeHugger Robot
d8aa5c7972 Merge "remove obsolete entries" into sc-dev am: 441bae6d1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14934444

Change-Id: I31f6c2733c5cb977a8625ba473d506bfa50dbcc9
2021-06-15 01:54:09 +00:00
TreeHugger Robot
441bae6d1a Merge "remove obsolete entries" into sc-dev 2021-06-15 01:39:02 +00:00
Rick Yiu
57cccedd8b Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082 am: 6976531ebe am: b7d809111c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: I968771288ea94d176800d3301ddfdb0f508cb768
2021-06-15 01:11:51 +00:00
Rick Yiu
62a23399e3 Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082 am: 25ce780b9c am: cc502abf3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: I7bcbe9db7374589c95acbdeafed1f0d701ef6ecd
2021-06-15 01:11:39 +00:00
Rick Yiu
b7d809111c Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082 am: 6976531ebe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: I42bcfc55c789fdecf0a92dcfd0b6d07e9583765c
2021-06-15 00:58:01 +00:00
Rick Yiu
cc502abf3a Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082 am: 25ce780b9c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: Id22713f2f247609bbc304bb36ae85616598a9d64
2021-06-15 00:57:39 +00:00
Rick Yiu
25ce780b9c Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: If015ce9946b16186eb8ed75c63ac8cfadde14266
2021-06-15 00:41:32 +00:00
Rick Yiu
6976531ebe Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev am: aa315a6082
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14943962

Change-Id: Ie3aebe5d9b8e6bae0f8e0df65f0bd6a5b8d0d178
2021-06-15 00:40:39 +00:00
Rick Yiu
aa315a6082 Merge "gs101-sepolicy: Fix avc denial for permissioncontroller_app" into sc-dev 2021-06-15 00:28:52 +00:00
Armelle Laine
5bb07db1de add se-policy to /dev/trusty-log0 so it can be accessed by dumpstate hal
reuse logbuffer_device group as dumpstate hal already has read perms
on this group.

Bug: 188285071
Test: adb bugreport to include a trusty section in dumpstate_board.txt
Change-Id: I623a5d450bdbe2ceef4fe460bf31bfe740d847b2
2021-06-13 23:59:37 +00:00
Richard Hsu
7d405598c1 Merge "[BugFix] SEPolicy for libedgetpu_darwinn2.so logging to stats service" into sc-dev am: 753e62f39c am: 4eb4b8c73c am: db24463bc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14555068

Change-Id: Ie3ad3239e8e24ddf34f1f24285bea923b032900d
2021-06-13 06:57:03 +00:00
Richard Hsu
be99d7ed77 Merge "[BugFix] SEPolicy for libedgetpu_darwinn2.so logging to stats service" into sc-dev am: 753e62f39c am: 64d8da84f2 am: 63e64193ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14555068

Change-Id: Ie26a3d35465e1f6f7e1875a8a46194d4bf4ad572
2021-06-13 06:56:51 +00:00