Commit graph

3283 commits

Author SHA1 Message Date
Nicolas Geoffray
ed07258d24 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755 am: 5db7a3cc58
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: Ic617201bc7a2ad7cbbda299f8867a7caff023aed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 20:18:06 +00:00
Nicolas Geoffray
5db7a3cc58 Also put .ShannonImsService in the vendor_ims_app domain. am: 356b4a4755
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2335444

Change-Id: I123395fa5a397e17aeaf7cec155cf00be7af8682
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-08 19:31:29 +00:00
Nicolas Geoffray
356b4a4755 Also put .ShannonImsService in the vendor_ims_app domain.
For consistency when running com.shannon.imsservice code.

Test: m
Bug: 260557058
Change-Id: I5242479d32eb9362326544516c06e6a52cd30a6e
2022-12-08 14:39:19 +00:00
Nicolas Geoffray
74042321e2 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664 am: a18011cd14
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: Ie3562efa20cadd63f2bfbaa5949f28c78d49ded5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:31:48 +00:00
Nicolas Geoffray
a18011cd14 Allow ssr_detector_app to create files of type system_app_data_file. am: 594052a664
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2327637

Change-Id: I9e14e98f8c66f18e7256dffeaa7eebe5a4f54567
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-05 17:01:25 +00:00
Nicolas Geoffray
594052a664 Allow ssr_detector_app to create files of type system_app_data_file.
Bug: 260557058
Test: m
Change-Id: I8545deddd64d7eec61c5065f364a87b8726b1472
2022-12-05 13:56:52 +00:00
Ziyi Cui
5bab2f680d Merge "[ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics" into tm-qpr-dev am: 4df65fdfaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20591018

Change-Id: Ia0d0df801fa04d6b9a44158115acda5f7a50e5b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 07:03:12 +00:00
Ziyi Cui
8e5cf6ccf1 [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics am: 1a39bb777e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20591018

Change-Id: I833905b09a613e3ae13cc06e943b39bc202b1d98
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 07:03:10 +00:00
Ziyi Cui
b3b59f8f88 Merge changes from topic "temp_residency_metrics" into tm-qpr-dev am: 7b5ec97f7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20590705

Change-Id: Ief5cae20292865a5a9e44089f406e8157dd7bb87
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 06:59:43 +00:00
Ziyi Cui
bb69de3087 [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics am: 86d7d36fcf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20527590

Change-Id: I8a812f509a63c4e5a7877195b78058b1a100eef1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-01 06:59:36 +00:00
Ziyi Cui
4df65fdfaf Merge "[ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics" into tm-qpr-dev 2022-12-01 06:31:37 +00:00
Ziyi Cui
7b5ec97f7d Merge changes from topic "temp_residency_metrics" into tm-qpr-dev
* changes:
  gs101-sepolicy:dumpstate: allow dumpstate access sysfs_vendor_metrics
  [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics
2022-12-01 06:27:28 +00:00
Treehugger Robot
707e529cfe [automerger skipped] Merge "Allow Trusty storageproxy property" am: 76089fcd5f am: 217490dd40 -s ours
am skip reason: Merged-In If995d35be490fbca6c99ef9f73f2842f5c488bd4 with SHA-1 502c76f22b is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2310384

Change-Id: Ie4cee4190ce8f20dae88f5cd8cf1359c8ae8f857
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-30 22:04:58 +00:00
Treehugger Robot
217490dd40 Merge "Allow Trusty storageproxy property" am: 76089fcd5f
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2310384

Change-Id: Icaeb14ac6313cd34257a704eadea4baa5d5f4a2d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-30 21:35:14 +00:00
Treehugger Robot
76089fcd5f Merge "Allow Trusty storageproxy property" 2022-11-30 21:06:13 +00:00
Stephen Crane
427fabf934 Allow Trusty storageproxy property am: 502c76f22b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20546072

Change-Id: I76fb4e52ef76a6d268043243f57f688eadcd4e00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-30 01:15:17 +00:00
Ziyi Cui
1a39bb777e [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to perf-metrics
enable pixelstats access to sysfs path, define sysfs_perfmetrics

Bug: 227809911
Bug: 232541623
Test: Verified the existence of atom and correctness of resume latency, irq stats
Change-Id: Ia0da1afb96b7f364d018d48d5cc8768c7b67f067
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:39:51 +00:00
Ziyi Cui
713d3ebf05 gs101-sepolicy:dumpstate: allow dumpstate access sysfs_vendor_metrics
Test: "adb bugreport" includes metrics capture.

Bug: 246799997
Test: "adb bugreport" includes metrics capture.
Change-Id: I48247f8378e52d15b264c37342dee5a938ba90a1
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:19:34 +00:00
Ziyi Cui
86d7d36fcf [ DO NOT MERGE ] gs101-sepolicy: pixelstats: enable pixelstats access to temp-residency-metrics
enable pixelstats access to sysfs path
Bug: 246799997
Test: Verified the existence of atom and correctness of atom stats
Change-Id: If329f2a65ed4cf347bd57150c637d38312f3dcb1
Signed-off-by: Ziyi Cui <ziyic@google.com>
2022-11-30 00:16:05 +00:00
Nicolas Geoffray
696c944e51 Allow ssr_detector_app writes to system_app_data_file. am: 1af71fc9ff am: 244284a31b
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2320310

Change-Id: Ia87808477911b933667159fa295aaa770bcb59e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-29 17:39:31 +00:00
Nicolas Geoffray
244284a31b Allow ssr_detector_app writes to system_app_data_file. am: 1af71fc9ff
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2320310

Change-Id: Ia7709417ea78e4b351eef8a67c7ab731dd050c83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-29 16:39:39 +00:00
Nicolas Geoffray
1af71fc9ff Allow ssr_detector_app writes to system_app_data_file.
Bug: 260557058
Test: m

(cherry picked from commit dc7ea2f09b)

Merged-In: I65697c3afb9cfd11d5235d15aa20633f1a96fdbb
Change-Id: Iaeb69d0c1e46e3e28cd75109ebfe3c494dd7c150
2022-11-28 17:32:28 +00:00
Stephen Crane
4519dff252 Allow Trusty storageproxy property
Allows the Trusty storageproxyd to set ro.vendor.trusty.storage.fs_ready
when the data filesystems are ready for use, and allows vendor init to
query and wait on this property.

Test: m raven-userdebug, flash, test app loading
Bug: 258018785
Change-Id: If995d35be490fbca6c99ef9f73f2842f5c488bd4
Merged-In: If995d35be490fbca6c99ef9f73f2842f5c488bd4
2022-11-23 20:24:52 +00:00
Stephen Crane
502c76f22b Allow Trusty storageproxy property
Allows the Trusty storageproxyd to set ro.vendor.trusty.storage.fs_ready
when the data filesystems are ready for use, and allows vendor init to
query and wait on this property.

Test: m raven-userdebug, flash, test app loading
Bug: 258018785
Change-Id: If995d35be490fbca6c99ef9f73f2842f5c488bd4
Merged-In: If995d35be490fbca6c99ef9f73f2842f5c488bd4
2022-11-23 00:36:27 +00:00
Joen Chen
805c8a476b Merge changes from topic "RRS_R4" into tm-qpr-dev am: 33f38db80f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20419725

Change-Id: If2198400b4c5f52eec07f6b5a688b0cd0b208b67
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-16 09:43:14 +00:00
joenchen
a5060e6616 RRS: Apply the default config from persist prop am: 90aeb6e15c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/19881052

Change-Id: I393898918b9d0a6d93f8f8d891527f59925ed3ad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-16 09:43:12 +00:00
Joen Chen
33f38db80f Merge changes from topic "RRS_R4" into tm-qpr-dev
* changes:
  Allow InputProcessor HAL to read display resolution
  RRS: Apply the default config from persist prop
2022-11-16 09:01:32 +00:00
Rick Chen
1fefc4e6de Allow CHRE to use EPOLLWAKEUP [DO NOT MERGE] am: bd36256bad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20407807

Change-Id: I8ced56e90a34167048d5e56153081c9ca2583aa9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-09 16:09:12 +00:00
Siarhei Vishniakou
c765567524 Allow InputProcessor HAL to read display resolution
Currently, there's no API to read the resolution from the system domain,
so the HAL has to read this from the sysprop provided by the display
code.

Allow the HAL to do so in this CL.

Bug: 244492960
Test: adb shell dmesg | grep input_processor
Change-Id: Ibdc3589234bbee8641e3c1f7a300b622803ca1a9
2022-11-09 03:45:55 +00:00
Rick Chen
bd36256bad Allow CHRE to use EPOLLWAKEUP [DO NOT MERGE]
avc: denied { block_suspend } for comm="UsfTransport" capability=36 scontext=u:r:chre:s0 tcontext=u:r:chre:s0 tclass=capability2 permissive=0

Bug: 238666865
Test: Check no chre avc denied.
Change-Id: Ifd2c37c58c548aec46a2c46891a1fc4d1f83f9be
Signed-off-by: Rick Chen <rickctchen@google.com>
2022-11-08 15:00:27 +00:00
joenchen
90aeb6e15c RRS: Apply the default config from persist prop
vendor_config plays as another role to control the display config during
the boot time. To change the default configuration of the user selected
mode, we use persist config to store the value.

Bug: 244492960
Test: Boot w/ and w/o user selected configs and check the resolution
Change-Id: Ic3eb4e1c8a2c5eed83d10799a1965dd7a6be58e1
2022-11-08 14:09:00 +00:00
Jenny Ho
393e0efb9b Add permission for logbuffer_bd am: 632c5dba75
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20307975

Change-Id: I148592298e9f5a15406bd95418b228385e412ae7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-03 00:59:41 +00:00
Gabriel Biren
21cd48363a Merge "Update gs101 sepolicy to allow the wifi_ext AIDL service." am: 1010b1cceb am: 41505f9991
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2262723

Change-Id: I6e5f2649b6b2679d6e9883c61009f3907414cee6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-31 21:39:48 +00:00
Gabriel Biren
41505f9991 Merge "Update gs101 sepolicy to allow the wifi_ext AIDL service." am: 1010b1cceb
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2262723

Change-Id: Ie2801e8af27484ca08826b4ab93b0f462f45d2d2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-31 21:10:53 +00:00
Gabriel Biren
1010b1cceb Merge "Update gs101 sepolicy to allow the wifi_ext AIDL service." 2022-10-31 20:46:08 +00:00
Jenny Ho
632c5dba75 Add permission for logbuffer_bd
Bug: 242679204
Change-Id: I134bf8611441274e8438fa06b5ca6c186efb331a
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2022-10-28 22:22:24 +08:00
Lucas Wei
c14d875df7 [automerger skipped] Merge "votable: update SEpolicy error" into tm-qpr-dev am: 0278f60839 -s ours
am skip reason: Merged-In Ia6dfb7796ab46b0ac339b98465ccd91624b655ed with SHA-1 5851e17605 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20106620

Change-Id: I56f8382c101f3f8a176671d447aea71299784e05
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-24 09:54:01 +00:00
Lucas Wei
48123156ed [automerger skipped] votable: update SEpolicy error am: 91960cb2d7 -s ours
am skip reason: Merged-In Ia6dfb7796ab46b0ac339b98465ccd91624b655ed with SHA-1 5851e17605 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20106620

Change-Id: If985d0a33037835b808928c6528162be210a1aa2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-24 09:53:55 +00:00
Lucas Wei
121d50927c Merge "sepolicy: fix odpm avc denials" into tm-qpr-dev am: 4a487ac890
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20067818

Change-Id: Ifc7951728bc578a8c472a217a74e72c82ed846cd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-24 09:53:50 +00:00
Lucas Wei
0278f60839 Merge "votable: update SEpolicy error" into tm-qpr-dev 2022-10-24 09:07:24 +00:00
Lucas Wei
4a487ac890 Merge "sepolicy: fix odpm avc denials" into tm-qpr-dev 2022-10-24 09:07:24 +00:00
Sam Ou
0127869bfd sepolicy: fix odpm avc denials
add wakeup permissions for odpm driver
since we update acc_data based on alarmtimer

Bug: 250813284
Change-Id: Id7f70d02475a03e53a206dde3b8efa584cacef85
Merged-In: Id7f70d02475a03e53a206dde3b8efa584cacef85
Signed-off-by: Sam Ou <samou@google.com>
Signed-off-by: Lucas Wei <lucaswei@google.com>
2022-10-24 05:03:01 +00:00
Lucas Wei
91960cb2d7 votable: update SEpolicy error
Bug: 247905787
Signed-off-by: Lucas Wei <lucaswei@google.com>
Change-Id: Ia6dfb7796ab46b0ac339b98465ccd91624b655ed
Merged-In: Ia6dfb7796ab46b0ac339b98465ccd91624b655ed
2022-10-23 15:25:20 +00:00
Lucas Wei
5851e17605 votable: update SEpolicy error
Bug: 247905787
Signed-off-by: Lucas Wei <lucaswei@google.com>
Change-Id: Ia6dfb7796ab46b0ac339b98465ccd91624b655ed
2022-10-23 23:23:41 +08:00
Tri Vo
c15a4ae32b Merge "Updated confirmationui HAL binary name." am: 5b81f62700 am: 61fac0d61a
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2251759

Change-Id: Ibdc4235e0eddf452922dd0304117bb04b5b2ff56
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-20 17:53:16 +00:00
Tri Vo
61fac0d61a Merge "Updated confirmationui HAL binary name." am: 5b81f62700
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2251759

Change-Id: I39f8ef135703c75ae7487fb5ea32e3deee9baf79
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-20 17:07:32 +00:00
Gabriel Biren
24160a4bcb Update gs101 sepolicy to allow the wifi_ext AIDL service.
Bug: 205044134
Test: Start wifi on an Oriole device using both the
      HIDL and AIDL versions of wifi_ext.
Change-Id: I45cbc86e4d4feb2aa99641175108dd9745c1715e
2022-10-20 16:54:19 +00:00
Tri Vo
5b81f62700 Merge "Updated confirmationui HAL binary name." 2022-10-20 16:51:56 +00:00
Chungjui Fan
8753d9d07c sepolicy: gs101: allow fastbootd to access gsc device node am: 8d802db37a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/20210023

Change-Id: Ic59f5c3967ba09506234161c7a0058b40642851e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-19 12:31:55 +00:00
Chungjui Fan
8d802db37a sepolicy: gs101: allow fastbootd to access gsc device node
avc:  denied  { getattr } for  pid=469 comm="fastbootd"
path="/dev/gsc0" dev="tmpfs" ino=470 scontext=u:r:fastbootd:s0
tcontext=u:object_r:citadel_device:s0
tclass=chr_file permissive=0

Bug: 248301125

Change-Id: Ic1aec8874636437b9b8d795b46fae72fa8533302
Signed-off-by: Chungjui Fan <chungjuifan@google.com>
2022-10-17 12:26:10 +00:00