Xin Li
594011b90b
[automerger skipped] Merge Android 12L am: 22c3ab8b6b
-s ours
...
am skip reason: Merged-In I7b9186af0cb135241e23504fa9d6f7c3d6718c7c with SHA-1 22f2ffcbee
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2012332
Change-Id: Ic29497624866c936ddf7a7f34f9539de55d73eb9
2022-03-08 10:19:17 +00:00
Xin Li
22c3ab8b6b
Merge Android 12L
...
Bug: 222710654
Merged-In: I7b9186af0cb135241e23504fa9d6f7c3d6718c7c
Change-Id: I60cda8853fd8575beb8617025479d08ccf816fbb
2022-03-08 00:15:28 +00:00
Roshan Pius
34c5b9b239
gs-sepolicy(uwb): Changes for new UCI stack
...
1. Rename uwb vendor app.
2. Rename uwb vendor HAL binary name & service name.
3. Allow vendor HAL to host the AOSP UWB HAL service.
4. Allow NFC HAL to access uwb calibration files.
Bug: 186585880
Test: Manual Tests
Change-Id: I2c7c2466f42317d643634e24b1efb1855e673d09
2022-03-06 18:15:16 -08:00
Tri Vo
da64016221
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
am: a5ccc7efa8
am: 56b17a34c8
am: ece657656a
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I4faaa95f8a3c8531470ed81f11c8b39ca558b23f
2022-03-04 19:59:13 +00:00
Tri Vo
adfd900367
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
am: a5ccc7efa8
am: 56b17a34c8
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: Ifbf1caca3b35aa80897b7555000ed8a5b82a1a2e
2022-03-04 19:26:55 +00:00
Tri Vo
ece657656a
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
am: a5ccc7efa8
am: 56b17a34c8
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I5829427d16236a1652301713f5a1bb4dc76d1420
2022-03-04 19:26:20 +00:00
Tri Vo
56b17a34c8
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
am: a5ccc7efa8
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I58998bc0820db2eeb6f2362a604aaff81159594e
2022-03-04 18:50:56 +00:00
Tri Vo
a5ccc7efa8
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
am: 22f2ffcbee
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: Ie2af054a900f32cbde1352ba9f708e163f76d86c
2022-03-04 18:29:27 +00:00
Tri Vo
22f2ffcbee
Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441
Change-Id: I7b9186af0cb135241e23504fa9d6f7c3d6718c7c
2022-03-04 18:06:53 +00:00
Tri Vo
fbf92e2ada
Merge "Don't audit storageproxyd unlabeled access"
2022-03-04 17:45:37 +00:00
Midas Chien
7dea42d711
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours am: 9285045f0b
-s ours am: 5e5133e7f6
-s ours am: 8b1611fbdc
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: Id5d23953f719aa78c8a7f1761a9bb249e682d02b
2022-03-04 13:54:27 +00:00
Midas Chien
8b1611fbdc
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours am: 9285045f0b
-s ours am: 5e5133e7f6
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: Ie922a17aa95c184a762bb6004982d11c0a39f888
2022-03-04 13:32:08 +00:00
Midas Chien
8c32b2ae3f
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours am: 9285045f0b
-s ours am: 5e5133e7f6
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: I8a7bcd3f93b1a8d9757302558859642a57e624d6
2022-03-04 13:31:58 +00:00
Midas Chien
5e5133e7f6
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours am: 9285045f0b
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: I29262cf0b26426b83493008aa2e569548e2fa436
2022-03-04 13:10:39 +00:00
Midas Chien
9285045f0b
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours am: b637545191
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: Iaf03b02cd8feadc0da6b1f7cb4d0d25f47907f39
2022-03-04 12:50:47 +00:00
Midas Chien
b637545191
[automerger skipped] [Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node am: 0e1e0e2830
-s ours
...
am skip reason: subject contains skip directive
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2009176
Change-Id: I5771c4702d7e76db359bba65f059f913d69d774f
2022-03-04 12:29:41 +00:00
Midas Chien
0e1e0e2830
[Do Not Merge] Allow composer to read panel_idle_handle_exit sysfs node
...
Change panel_idle_exit_handle selinux type to sysfs_display to allow
composer to access it.
Bug: 202182467
Test: ls -Z to check selinux type
Test: composer can access it in enforce mode
Merged-In: I5ca811f9500dc452fe6832dd772376da51f675a8
Change-Id: I5ca811f9500dc452fe6832dd772376da51f675a8
2022-03-04 10:48:08 +00:00
Midas Chien
77aa7d778e
Merge "Allow composer to read panel_idle_handle_exit sysfs node" into tm-dev am: 08c3646fc1
am: 2aef601024
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17005478
Change-Id: Id81b8895f498599251947e6f32dcce2ab15214e3
2022-03-04 07:45:10 +00:00
Midas Chien
b3e1b0b41f
Merge "Allow composer to read panel_idle_handle_exit sysfs node" into tm-dev am: 08c3646fc1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17005478
Change-Id: Ib0315b976910888fbb3e10afc9e47da982fd8058
2022-03-04 07:22:58 +00:00
Midas Chien
2aef601024
Merge "Allow composer to read panel_idle_handle_exit sysfs node" into tm-dev am: 08c3646fc1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17005478
Change-Id: I46a7ce198c316d163fbb3b6dee4d1c5e8edf589e
2022-03-04 07:21:52 +00:00
Midas Chien
08c3646fc1
Merge "Allow composer to read panel_idle_handle_exit sysfs node" into tm-dev
2022-03-04 06:55:05 +00:00
Tri Vo
03fef48542
Don't audit storageproxyd unlabeled access
...
Test: m sepolicy
Bug: 197502330
Change-Id: I794dac85e475434aaf024027c43c98dde60bee27
2022-03-03 13:12:17 -08:00
TreeHugger Robot
058dabbda9
Merge "Add sepolicy rules for fingerprint hal" into tm-dev am: c865c80379
am: bdc06d1db9
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033478
Change-Id: I4ec676163a69811a1b3a1c750d5b170e810219ee
2022-03-02 03:19:34 +00:00
Robert Lee
7751e41ad2
Fix selinux error for aocd am: e5cf8beff3
am: 2e5b1c4e48
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033481
Change-Id: I5292b87afd5537bb66b5b1ec875606478341d536
2022-03-02 03:19:02 +00:00
TreeHugger Robot
0a8e6fdf61
Merge "Add sepolicy rules for fingerprint hal" into tm-dev am: c865c80379
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033478
Change-Id: Icb1194793de57e5b709caba326571268403f603d
2022-03-02 02:58:36 +00:00
Robert Lee
c56fcea847
Fix selinux error for aocd am: e5cf8beff3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033481
Change-Id: Iab67ca429892fa837fb604a37646da0f123abf4c
2022-03-02 02:58:02 +00:00
TreeHugger Robot
bdc06d1db9
Merge "Add sepolicy rules for fingerprint hal" into tm-dev am: c865c80379
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033478
Change-Id: I13cc04e4616c765209cae2ed2d6f4a99baa78673
2022-03-02 02:57:14 +00:00
Robert Lee
2e5b1c4e48
Fix selinux error for aocd am: e5cf8beff3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/17033481
Change-Id: I773cdab996c4dff3d14d736634cfc033bc7b4a1f
2022-03-02 02:56:09 +00:00
TreeHugger Robot
c865c80379
Merge "Add sepolicy rules for fingerprint hal" into tm-dev
2022-03-02 02:40:58 +00:00
Robert Lee
e5cf8beff3
Fix selinux error for aocd
...
allow write permission to fix following error
auditd : type=1400 audit(0.0:4): avc: denied { write } for comm="aocd" name="aoc" dev="tmpfs" ino=497 scontext=u:r:aocd:s0 tcontext=u:object_r:aoc_device:s0 tclass=chr_file permissive=0
Bug: 198490099
Test: no avc deny when enable no_ap_restart
Change-Id: Ia72ee36137d78f969c28bf22647443cef45d186a
Signed-off-by: Robert Lee <lerobert@google.com>
2022-03-01 09:13:46 +00:00
Kris Chen
e0c6120237
Add sepolicy rules for fingerprint hal
...
Fix the following avc denial:
avc: denied { set } for property=vendor.gf.cali.state pid=1152 uid=1000 gid=1000 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'
Bug: 219372997
Bug: 220263520
Test: No above avc denial in logcat.
Change-Id: I93ace30c67e04bc836bfba050028a1f25af641d5
2022-03-01 15:05:42 +08:00
Midas Chien
acd4220ac9
Allow composer to read panel_idle_handle_exit sysfs node
...
Change panel_idle_exit_handle selinux type to sysfs_display to allow
composer to access it.
Bug: 202182467
Test: ls -Z to check selinux type
Test: composer can access it in enforce mode
Change-Id: I5ca811f9500dc452fe6832dd772376da51f675a8
2022-02-25 23:07:09 +08:00
Jason Macnak
28a21a48e0
Remove sysfs_gpu type definition
...
... as it has moved to system/sepolicy.
Bug: b/161819018
Test: presubmit
Change-Id: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
Merged-In: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
2022-02-24 22:23:41 +00:00
Jason Macnak
56b04c828e
Remove sysfs_gpu type definition
...
... as it has moved to system/sepolicy.
Bug: b/161819018
Test: presubmit
Change-Id: I6fcafa87541ed0cbaf3ba74fa5ff4dbdebd533f7
2022-02-24 22:16:08 +00:00
Edwin Wong
1407c2c46c
Merge "whitechapel: sepolicy for Widevine AIDL HAL" into tm-dev am: 6b7fff8497
am: 511fa44942
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16952398
Change-Id: Ia16c7a2038f770433749016f9b848c77b4400cc3
2022-02-23 17:47:34 +00:00
Edwin Wong
511fa44942
Merge "whitechapel: sepolicy for Widevine AIDL HAL" into tm-dev am: 6b7fff8497
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16952398
Change-Id: Ib242c34e2529238d776ec2bfaa3df9d262ae9bbd
2022-02-23 17:18:39 +00:00
Edwin Wong
7fa281bef7
Merge changes from topic "gs101-drm-aidl-tm-dev" into tm-mainline-prod am: 04f5b072fe
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16952398
Change-Id: I49312e57c049080aa458630cde2eb0937b7f28f7
2022-02-23 16:50:03 +00:00
Edwin Wong
6b7fff8497
Merge "whitechapel: sepolicy for Widevine AIDL HAL" into tm-dev
2022-02-23 01:08:19 +00:00
Edwin Wong
04f5b072fe
Merge changes from topic "gs101-drm-aidl-tm-dev" into tm-mainline-prod
...
* changes:
[automerge] whitechapel: sepolicy for Widevine AIDL HAL 2p: cb04f5981f
whitechapel: sepolicy for Widevine AIDL HAL
2022-02-23 01:08:19 +00:00
Edwin Wong
e5b9a2dd37
Merge changes from topic "gs101-drm-aidl-tm-dev"
...
* changes:
[automerge] whitechapel: sepolicy for Widevine AIDL HAL 2p: cb04f5981f
2p: cd2ded60aa
[automerge] whitechapel: sepolicy for Widevine AIDL HAL 2p: cb04f5981f
whitechapel: sepolicy for Widevine AIDL HAL
2022-02-23 01:08:19 +00:00
Aaron Tsai
dfd957cf04
[automerger skipped] Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
am: 84bacff9ab
am: e704af0ed7
am: 4aadbb9b12
-s ours
...
am skip reason: Merged-In I73d45f3cf1fe0bd918bb4856ce554e81702e4ff9 with SHA-1 05565c1f14
is already in history
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: I2df36cd58685e606a240a79f401d6fb4d70235db
2022-02-22 03:46:45 +00:00
Aaron Tsai
c308db7b79
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
am: 84bacff9ab
am: e704af0ed7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: Ib123b407465af30ad4cabc2520f165651b856e48
2022-02-22 02:50:12 +00:00
Aaron Tsai
4aadbb9b12
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
am: 84bacff9ab
am: e704af0ed7
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: If65e0ca5ffae9149ed910919734ab0c295e68b4e
2022-02-22 02:48:51 +00:00
Aaron Tsai
e704af0ed7
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
am: 84bacff9ab
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: I6e91791926ff7d840c7317fbf5d9656338960132
2022-02-22 02:29:22 +00:00
Aaron Tsai
84bacff9ab
Fix selinux error for system_app am: 05565c1f14
am: d2d83c8e2d
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: Ibdbeeee937e4c856adfebad71a956a343b820dfa
2022-02-22 01:56:28 +00:00
Aaron Tsai
d2d83c8e2d
Fix selinux error for system_app am: 05565c1f14
...
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/1992670
Change-Id: Ia3c6c0aae82c19a5d1c019cce2700c5e64c8bb11
2022-02-22 01:35:41 +00:00
TreeHugger Robot
34d31c907b
Merge "[automerge] Temporarily don't audit hal_fingerprint to fix avc denial 2p: 5e2e261148
"
2022-02-21 16:17:54 +00:00
Shubham Dubey
7384b16034
[automerge] Temporarily don't audit hal_fingerprint to fix avc denial 2p: 5e2e261148
2p: 207c47f797
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16963324
Change-Id: I07d124191b6dd6e4a29834b1a62122cd787779af
2022-02-21 13:07:41 +00:00
Presubmit Automerger Backend
207c47f797
[automerge] Temporarily don't audit hal_fingerprint to fix avc denial 2p: 5e2e261148
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16963324
Change-Id: I7bec529ed0e22e9f7cee5d3d10312f2ed782082c
2022-02-21 13:07:35 +00:00
Presubmit Automerger Backend
aa76244476
[automerge] Temporarily don't audit hal_fingerprint to fix avc denial 2p: 5e2e261148
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/16963324
Change-Id: Ibb2d6ae298945f1d3478a896a2ae796359d3c535
2022-02-21 13:07:35 +00:00