Commit graph

38 commits

Author SHA1 Message Date
Jenny Ho
014051a9f7 create hal_health_default.te for Battery Defender access file node
Bug: 205073003
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: I946b85e8b595601f56df26c567d31df76f7a5a5b
2021-11-15 01:53:50 +00:00
Adam Shih
830fa53e9f update error on ROM 7908395
Bug: 206045367
Bug: 206045604
Bug: 206045368
Bug: 206045605
Bug: 206045471
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I8b1a0ae9686f47d684428bb79650a7bb0dfe9904
2021-11-12 02:21:53 +00:00
Joseph Jang
b4393a0bf3 Fix SELinux error coming from hal_identity_citadel
Bug: 205657024
Change-Id: Ic23b631eb63cf13ba7e08215590e73386d2a3126
2021-11-11 14:52:05 +08:00
Adam Shih
ab13d5a1f7 update error on ROM 7904131
Bug: 205904432
Bug: 205904322
Bug: 205904438
Bug: 205904406
Bug: 205904310
Bug: 205904436
Bug: 205904402
Bug: 205904552
Bug: 205904323
Bug: 205904442
Bug: 205904367
Bug: 205904452
Bug: 205904403
Bug: 205904379
Bug: 205904328
Bug: 205904286
Bug: 205904380
Bug: 205904401
Bug: 205904381
Bug: 205904208
Bug: 205904433
Bug: 205904327
Bug: 205904553
Bug: 205904361
Bug: 205904441
Bug: 205904324
Bug: 205904207
Bug: 205904404
Bug: 205904330
Bug: 205904439
Bug: 205904435
Bug: 205904384
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I64432a24d562d5868f21a317e5bfd6f25ad24900
2021-11-11 09:47:32 +08:00
Adam Shih
e3bb63ab1b Make display related libraries reachable
Bug: 205780068
Bug: 205779849
Test: boot with no relevant error
Change-Id: I806ecb779690346674816b793a5da21acf1be59b
2021-11-11 01:15:49 +00:00
Adam Shih
53371742c2 update error on ROM 7900024
Bug: 205780088
Bug: 205779872
Bug: 205779877
Bug: 205780065
Bug: 205779906
Bug: 205779737
Bug: 205779871
Bug: 205780093
Bug: 205779850
Bug: 205779736
Bug: 205780090
Bug: 205779798
Bug: 205780186
Bug: 205779849
Bug: 205779799
Bug: 205780067
Bug: 205779581
Bug: 205779869
Bug: 205780068
Test: pts-tradefed run pts -m PtsSELinuxTest

Change-Id: I979411b162c42ace670c35fcfd6ba286f0ea02fb
2021-11-10 11:06:37 +08:00
Adam Shih
95c4e650c8 update error on ROM 7895525
Bug: 205657177
Bug: 205657040
Bug: 205657133
Bug: 205656936
Bug: 205656937
Bug: 205657024
Bug: 205655569
Bug: 205656951
Bug: 205657039
Bug: 205657063
Bug: 205657092
Bug: 205657025
Bug: 205655298
Bug: 205657135
Bug: 205657093
Bug: 205657132
Bug: 205657090
Bug: 205656950
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I71c27247f9a19fe23a3602bf29793b1f0efc8bc8
2021-11-09 05:45:36 +00:00
Roger Wang
5f1a03bf0e Wifi: Add sepolicy files for hal_wifi_ext service
This commit adds the sepolicy related files for hal_wifi_ext service.

avc msg:
avc: denied { set } for property=vendor.wlan.firmware.version pid=682 uid=1010 gid=1010 scontext=u:r:hal_wifi_ext:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=1'
avc: denied { call } for scontext=u:r:hal_wifi_ext:s0 tcontext=u:r:grilservice_app:s0:c143,c258,c512,c768 tclass=binder permissive=1

Bug: 205073038
Test: Check no avc_deny on hal_wifi_ext
Change-Id: I5d9b59c56b723174543c0308dd6b0235e998e76c
Signed-off-by: Roger Wang <wangroger@google.com>
2021-11-05 11:08:11 +00:00
Adam Shih
0060a1335c let init.rc set GKI ready property
Bug: 205070818
Test: boot with no relevant error
Change-Id: I929a9d2cfbb5267b178fde09fc5e1f3dcc9ec3d0
2021-11-05 11:25:01 +08:00
Adam Shih
4c9dd893b8 fix platform_app property access
Bug: 205073024
Test: boot with no relevant error log
Change-Id: Ia230b025b89981ed797c95cdf76fe7efd56d3fa7
2021-11-05 11:24:57 +08:00
Adam Shih
64af79f39a update error on ROM 7886118
Bug: 205202540
Bug: 205202541
Bug: 205202542
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I21db6eb0ee47a9a4d002fc897c143eae0f0b614a
2021-11-05 10:36:11 +08:00
Adam Shih
f2353c6aed update error on ROM 7882509
Bug: 205073232
Bug: 205072921
Bug: 205073231
Bug: 205073165
Bug: 205073003
Bug: 205073229
Bug: 205073167
Bug: 205073164
Bug: 205073230
Bug: 205073038
Bug: 205073024
Bug: 205073117
Bug: 205073023
Bug: 205072922
Bug: 205073166
Bug: 205072689
Bug: 205073025
Bug: 205070818
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I84cc72176363ed31203b7f7afe0720c3153d2cc6
2021-11-04 14:09:41 +08:00
Adam Shih
c0d04c41b3 fix citadeld service access
Bug: 204718569
Test: boot with no relevant error
Change-Id: Iba8c01f34c4453c8001e56b25089b467c4de79ea
2021-11-01 10:45:13 +08:00
Adam Shih
8550b06ea4 update error on ROM 7870491
Bug: 204718569
Bug: 204718762
Bug: 204718449
Bug: 204718220
Bug: 204718450
Bug: 204718757
Bug: 204718809
Bug: 204718221
Bug: 204718782
Bug: 204718864
Bug: 204718865
Bug: 204717520
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Ic0b136fe876bcf67a94d7c35927c6bd0c6506005
2021-11-01 10:39:07 +08:00
Adam Shih
de48018a88 remove errors that were filed on the wrong ROM ID
Bug: 202906903
Bug: 202906772
Bug: 202907037
Test: boot with those errors appear again
Change-Id: I5bc173c18b0d2a94ac2146e1c6e405c542e0c9ba
2021-10-29 11:10:43 +08:00
Adam Shih
8cc3f28ac1 fix wlc_hwservice access
10-29 10:38:01.270   440   440 E SELinux : avc:  denied  { find } for pid=1594 uid=10210 name=com.google.input.ITouchContextService/default scontext=u:r:platform_app:s0:c512,c768 tcontext=u:object_r:touch_service:s0 tclass=service_manager permissive=1
10-29 10:38:01.277   440   440 E SELinux : avc:  denied  { find } for pid=1594 uid=10210 name=com.google.hardware.pixel.display.IDisplay/default scontext=u:r:platform_app:s0:c512,c768 tcontext=u:object_r:hal_pixel_display_service:s0 tclass=service_manager permissive=1
Bug: 202906787
Test: boot with no relevant error

Change-Id: I47ea0f1dfe6f3f7b024d4512e0ccd94bc0da93a1
2021-10-29 10:57:39 +08:00
Adam Shih
73845f7fcd fix rlsservice service access
Bug: 202906997
Test: boot with no relevant error
Change-Id: I964d11956b5f78c410aec230289abc1f6a045023
2021-10-29 10:21:00 +08:00
Adam Shih
c9392bd414 fix vendor_ims_app service access
Bug: 202906888
Test: boot with no relevant error
Change-Id: I25e967bed593b017f11b647c23cfd148738227e0
2021-10-29 10:19:38 +08:00
Adam Shih
d73b97b740 fix vendor_rcs_app service access
Bug: 202907058
Test: boot with no relevant error
Change-Id: Ie435cdadc54cb59b09dadba890a9d1cbdb94b458
2021-10-29 10:17:57 +08:00
Adam Shih
ee3287231f fix hal_usb_impl service access
Bug: 202906786
Test: boot with no relevant error
Change-Id: I99178488a97aa2d0b3d7e4775c88b00321084d63
2021-10-29 10:12:28 +08:00
Adam Shih
23b637e260 fix mediacodec_samsung service access
Bug: 202906949
Test: boot with no relevant errors
Change-Id: I015c58f1b223978cb0e61377f5fc6930477c9a53
2021-10-27 13:24:52 +08:00
Adam Shih
e171a156e2 fix mediacodec_google service access
Bug: 202906901
Test: boot with no relevant errors
Change-Id: I8ba645de225af4a25c52cc14eb05eb60a64ea202
2021-10-27 13:24:46 +08:00
Adam Shih
5e572d5c72 fix hal_camera_default service access
10-25 11:52:35.916   437   437 E SELinux : avc:  denied  { find } for pid=711 uid=1000 name=android.frameworks.stats.IStats/default scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:fwk_stats_service:s0 tclass=service_manager permissive=1
Bug: 202906784
Test: boot with no hal_camera_default errors

Change-Id: I0e21cc11808b973c859ddc2ddebc0db81f999d9f
2021-10-27 13:24:34 +08:00
Adam Shih
abf31d56d6 fix secure element service access
Bug: 202902683
Test: boot with no secure element errors
Change-Id: I84ee827d356e6a99af192cce9178fb4f408de5ec
2021-10-25 11:37:10 +08:00
Adam Shih
0ae5acc904 fix graphics_composer services denials
10-25 11:28:32.230   438   438 E SELinux : avc:  denied  { add } for pid=500 uid=1000 name=com.google.hardware.pixel.display.IDisplay/default scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:hal_pixel_display_service:s0 tclass=service_manager permissive=1
10-25 11:28:33.787   438   438 E SELinux : avc:  denied  { find } for pid=500 uid=1000 name=android.hardware.power.IPower/default scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:hal_power_service:s0 tclass=service_manager permissive=1
Bug: 202906947
Test: boot with no graphics_composer errors

Change-Id: I4174cbcacb7149427814ca67703799ab02b992e4
2021-10-25 11:31:39 +08:00
Adam Shih
be8aedd6ac fix hal_fingerprint_default denails
10-25 11:19:03.649   430   430 E SELinux : avc:  denied  { find } for pid=958 uid=1000 name=android.hardware.power.IPower/default scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:hal_power_service:s0 tclass=service_manager permissive=1
10-25 11:19:04.509   430   430 E SELinux : avc:  denied  { find } for pid=958 uid=1000 name=android.frameworks.stats.IStats/default scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:fwk_stats_service:s0 tclass=service_manager permissive=1
Bug: 202906981
Test: boot with no fingerprint errors

Change-Id: I95dcda0698c7fcec1e4874b95b598bc987e83e58
2021-10-25 11:24:26 +08:00
Adam Shih
9cb1f625ba fix hal_weaver_citadel denials
Bug: 202907040
Test: boot with nno relevant errors
Change-Id: Ieb7a57518b433cc6cd2849afb58c8616b409db13
2021-10-25 11:09:06 +08:00
Adam Shih
fc1ec67aa4 fix init_citadel service access
Bug: 202906904
Test: boot to home with no relevant error
Change-Id: I6729ced49cbbecbc33234e311fb81652a065fe39
2021-10-20 10:41:56 +08:00
Adam Shih
ecc3a24449 fix identity service access
10-20 10:32:58.701   438   438 E SELinux : avc:  denied  { find } for pid=742 uid=9999 name=android.hardware.citadel.ICitadeld scontext=u:r:hal_identity_citadel:s0 tcontext=u:object_r:citadeld_service:s0 tclass=service_manager permissive=1
Bug: 202906902
Test: boot to home with no relevant error

Change-Id: Ia6e09343843f9a5c96e06998ba5c50fb64948d7f
2021-10-20 10:35:18 +08:00
Adam Shih
4c20c40f50 Fix hal_keymint_citadel service access
10-20 10:24:31.155   432   432 E SELinux : avc:  denied  { find } for pid=481 uid=1064 name=android.hardware.citadel.ICitadeld scontext=u:r:hal_keymint_citadel:s0 tcontext=u:object_r:citadeld_service:s0 tclass=service_manager permissive=1
Bug: 202907039
Test: boot to home with no keymint errors

Change-Id: I7935fe52a9774f8fca67336be9c9d47fe2675756
2021-10-20 10:26:18 +08:00
Adam Shih
e9d02e08f5 fix widevine drm access
Bug: 202906980
Test: boot with no relevant logs

Change-Id: Idc37f7e1441d9fae1f570bc53ff67a7a48656ed3
2021-10-20 10:06:10 +08:00
Adam Shih
56bef214d3 fix citadeld's service access
Bug: 202906931
Test: boot with no relevant logs
Change-Id: Ic65c6f218f69a1afa14fcd1b6eb0feacf48ea54f
2021-10-20 09:54:52 +08:00
Adam Shih
a39f2e902e remove unlabeled dontaudits
The log shows up when we remount the phone, causing modem images going
back to default file contexts: "unlabeled"
Bug: 202906831
Test: Boot to home with no relevant log

Change-Id: I69baced268782d9b38c1a56c62b3c63ae55733e4
2021-10-20 09:46:02 +08:00
Adam Shih
bfd5097be2 dispatch service related error
Bug: 202906787
Test: pts-tradefed run pts -m PtsSELinuxTest

Change-Id: Ifbdf1de156994572b8fedfd18180d3821ef1594c
2021-10-14 10:50:12 +08:00
Adam Shih
c1ffe9c177 Initialize gs201 to zero
Bug: 196916111
Test: boot to home with all services launched
Change-Id: I3453fc01cec5fd7b2b2a44a6f20c64e818ce1acd
2021-08-18 09:46:14 +08:00
Ocean Chen
827b204adb storage: update sepolicy for hardwareinfoservice
Bug: 188793183
Test: run pixel/022
Change-Id: I921c4eae0744278896007183a7947f281925b24f
2021-08-17 16:25:46 +00:00
Richard Hsu
02ccab0539 [Bringup] Update SEPolicy for TPU (Janeiro) for PRO.
Reuse the same SEPolicy for edgetpu gs101 for gs201.
1. gs101 sepolicy has been refactored into an edgetpu directory, which
is meant to be reused. We only need to match the gs201 side to mirror
that. This CL references Adam's ag/14911633.
2. In a separete CL, add /dev/janeiro into the common gs101 sepolicy.

Bug: 191185522

Test: run_tflite_test_odc passes.
https://paste.googleplex.com/5466657955774464

Change-Id: Idd9e47a3c8da70f9dd4696cb7db7d4439e9897d6
2021-06-17 17:22:43 -07:00
Pat Tjin
d3a63de64b clone sepolicy from gs101
s/gs101/gs201/g

Bug: 186836335
Test: Boot
Signed-off-by: Pat Tjin <pattjin@google.com>
Change-Id: Ifa0d083f7317c38eb02c8228c2804cbd4d5ee19f
2021-05-20 17:51:49 -07:00