Commit graph

2106 commits

Author SHA1 Message Date
Inseob Kim
0a40b3bb98 Move coredomain policies to system_ext/product am: da30985fa5 am: 0827b82595
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24354374

Change-Id: I21a6ae897a80a8954639e15ebb16218a0e324350
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 07:35:43 +00:00
Inseob Kim
0827b82595 Move coredomain policies to system_ext/product am: da30985fa5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24354374

Change-Id: I527239025a4b81d9d989dcba6ba2c63d6840a683
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 06:50:56 +00:00
Inseob Kim
da30985fa5 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
Merged-In: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
2023-08-08 14:37:48 +00:00
Ken Yang
89e7477c43 SELinux: fix the wakeup avc denials am: 3054cb6eec am: f0c6f18d7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: I7888b49da09ad91b2d6b31d2c335841edd5a6514
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 03:13:07 +00:00
Ken Yang
f0c6f18d7d SELinux: fix the wakeup avc denials am: 3054cb6eec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: Ia49778517e9c64e4b7539fa81ec4170cef01961c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 02:30:35 +00:00
Ken Yang
3054cb6eec SELinux: fix the wakeup avc denials
Fix the wakeup avc denials in a more common place

Bug: 292076108
Change-Id: I52627f19cb0fec3dd0851d21d0608048ebc7d45d
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-25 13:12:32 +00:00
Utku Utkan
2fb35adebd Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 34bda7b2b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24124266

Change-Id: I0675ba6da1fff3561ec1ab23711526657ccc3c93
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 18:49:47 +00:00
Utku Utkan
34bda7b2b8 Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Reason for revert: Relanding the original topic after copying the certificates under `device/google` for `without-vendor` branches

Reverted changes: /q/submissionid:24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Bug: 287069860
Test: m && flashall
Change-Id: I5326b61822d367beaff0ac97a34708d306c60007
2023-07-18 20:37:28 -07:00
Inseob Kim
3539653f98 Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: c420cef154
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24122569

Change-Id: I192d7d1ba78d7381d3dd122cacbdd7a37d16d67d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 02:50:45 +00:00
Inseob Kim
c420cef154 Revert "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24056607-pixel-camera-services-extensions-sepolicy

Reason for revert: build breakage on git_main-without-vendor

Reverted changes: /q/submissionid:24056607-pixel-camera-services-extensions-sepolicy

Change-Id: I9869874507230f59ac3b8cdc2538e4f223216b45
2023-07-19 01:15:39 +00:00
Utku Utkan
47f7d7ef72 Introduce CameraServices seinfo tag for PixelCameraServices am: d45ff39442
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24030396

Change-Id: I1ecfa136567806f140067eaed98766c6da66d2ee
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 21:49:07 +00:00
Utku Utkan
d45ff39442 Introduce CameraServices seinfo tag for PixelCameraServices
Bug: 287069860
Test: m && flashall && check against 'avc: denied' errors
Change-Id: I41b435ae0a34fe9c797b9316887c4b56091a26a5
2023-07-13 09:11:06 -07:00
David Anderson
d06d2415a5 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873 am: 96009e517c
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I1ccfdb2e8605b5cec757b8ad8d7be6fb414cb9c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 00:52:30 +00:00
David Anderson
96009e517c Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ie086b1fb169292469ec153039beee50ae782276d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 00:07:32 +00:00
David Anderson
a7e9f0a873 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I29b1070280c3e88e976dab3c02b110786ca8f11b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 23:22:17 +00:00
David Anderson
a03ec9af21 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Id20a32d6a80e058caebf2047e59a1b5a3e519f43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 22:41:44 +00:00
David Anderson
439827c49d Allow fastbootd to flash dtbo. am: e96a14a9d2
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ifc30a96202cbeb38896f3545502b582168dcf53e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 21:57:26 +00:00
David Anderson
e96a14a9d2 Allow fastbootd to flash dtbo.
This line is copied from gs101-sepolicy, and fixes the following denial:

audit: type=1400 audit(1689093038.396:14): avc:  denied  { write } for  pid=409 comm="fastbootd" name="sda24" dev="tmpfs" ino=493 scontext=u:r:fastbootd:s0 tcontext=u:object_r:custom_ab_block_device:s0 tclass=blk_file permissive=0

Bug: N/A
Test: fastboot flashall in fastbootd
Change-Id: I765aedeb204cc862434a56a97f242640465f84b8
2023-07-11 10:27:47 -07:00
Samuel Huang
e4b6e55e35 Revert "Revert "Create telephony.ril.silent_reset system_ext pro..." am: d02a8eef29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23841769

Change-Id: I09f53d8147f813aaaeea55b57d1cfb97b0dd0001
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-07 02:32:58 +00:00
Samuel Huang
d02a8eef29 Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."
Revert submission 23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Reason for revert: The root cause is missing property definition in gs101-sepolicy. This CL can be merged safely. Verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L48900000961646046

Reverted changes: /q/submissionid:23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Bug: 286476107
Change-Id: Ia80e4400ff555a637c42193cab3e3acf72bc36a2
2023-07-07 01:45:23 +00:00
Sebastian Pickl
d3ef7a804c Revert "Allow bthal to access vendor bluetooth folder" am: 41ed8e83ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23874549

Change-Id: Ib4ecdceb5d125c05bce9a6c9edc4b24cbc53a8c0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 12:02:20 +00:00
Sebastian Pickl
41ed8e83ea Revert "Allow bthal to access vendor bluetooth folder"
Revert submission 23844270-P22-vendor-log-udc-qpr

Reason for revert: causes selinux tests to fail b/289989584

go/abtd: https://android-build.googleplex.com/builds/abtd/run/L37600000961782595

Bug:289989584

Reverted changes: /q/submissionid:23844270-P22-vendor-log-udc-qpr

Change-Id: I4e9ccf17050702a6405c549340e7fe97eba0eb65
2023-07-05 10:11:12 +00:00
Patty Huang
3e1348f4fc Allow bthal to access vendor bluetooth folder am: 1a52c8b952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23854004

Change-Id: I0d9ef1e480423715137fcbf7b9651753a9c8fa24
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 07:07:56 +00:00
Patty Huang
1a52c8b952 Allow bthal to access vendor bluetooth folder
Bug:289055382
Test: enable vendor debug log and check the vendor snoop log contain the
vendor log

Change-Id: I89164330998d7fbea45dab65931c2a3db22a4c92
2023-06-30 11:55:35 +08:00
Sebastian Pickl
b617ab420a Revert "Create telephony.ril.silent_reset system_ext property fo..." am: 4d0eeef36f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23817869

Change-Id: I032ae4c04d68265389f8575378bc9364af6f897b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 11:16:33 +00:00
Sebastian Pickl
4d0eeef36f Revert "Create telephony.ril.silent_reset system_ext property fo..."
Revert submission 23736941-tpsr-ril-property

Reason for revert: culprit for b/289014054 verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L54800000961620143

Bug: 289014054

Reverted changes: /q/submissionid:23736941-tpsr-ril-property

Change-Id: I4fa5b2803392e0db03bb622392f3d4afab6a45ea
2023-06-27 10:05:45 +00:00
Xin Li
041513071c [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours am: c9d5097e56 -s ours am: 645f996b23 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I79e95a7ffa397de68457910bd23b1117806e018c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 07:25:45 +00:00
Samuel Huang
5e8765956e Create telephony.ril.silent_reset system_ext property for RILD restart am: 513fa361c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23748040

Change-Id: I543184268827663ee5bbd96299a3e5d109f6807d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 03:07:56 +00:00
Xin Li
645f996b23 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours am: c9d5097e56 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I702a5374d5ddff6d17ae5f49e79654ab7d85ab81
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 01:14:07 +00:00
Xin Li
c9d5097e56 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I903de348dca44cf893578b33b13743269685a480
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 00:32:37 +00:00
Xin Li
dc4a87253c [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I07063c3d9cf1418132ec611701713baa7b783f59
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 23:10:28 +00:00
Xin Li
7e4592c70a [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I27e4864161d3db815ad9cedad4da2af6ee082826
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 22:57:43 +00:00
Xin Li
aaef0b7773 Merge Android 13 QPR3
Bug: 275386652
Merged-In: Idc925c7a1f1111840a64664aa50c39442c3a0f8f
Change-Id: I2f0a022715577d395a6d9d2c8ec6b9a7f37fe509
2023-06-21 15:14:53 -07:00
Samuel Huang
513fa361c8 Create telephony.ril.silent_reset system_ext property for RILD restart
RILD listens for changes to this property. If the value changes to 1, RILD will restart itself and set this property back to 0.

The TelephonyGoogle app will set this property to 1 when it receives a request from the SCONE app. Since TelephonyGoogle runs in the com.android.phone process, we also need to give the radio domain permission to set the telephony.ril.silent_reset property.

Bug: 286476107
Test: manual
Change-Id: I689e75f4ebf3f44915bd7f795755f297935e7946
2023-06-21 06:34:45 +00:00
Jenny Ho
d835c2acb6 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 34ee73b7f2 am: d1c4337008
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: If3011680a0b76f01d2e9226969d822425ede5d23
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 03:23:27 +00:00
Jenny Ho
a3ee75181b Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 3ab8be18a5 am: abb6cc1a80
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I81f08eaad0c6e5df788bc63f3626ec3e58f72d39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 03:20:37 +00:00
Jenny Ho
57349ee2c0 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 34ee73b7f2 am: eef3026fd5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: Ibd7d0565d65ebb298423694e96c65027d2cf77c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 03:20:24 +00:00
Jenny Ho
abb6cc1a80 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 3ab8be18a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I96b77bcbb6ab773d41b861f4770e07f41b6b834a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 02:36:08 +00:00
Jenny Ho
d1c4337008 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 34ee73b7f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I016c6ca4cc81bffaf267870159f47e7c1a6674f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 02:35:57 +00:00
Jenny Ho
eef3026fd5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 34ee73b7f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: Ib71b8ae6c48db75778ec84a2d5a5b2efec88244c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 02:33:59 +00:00
Jenny Ho
34ee73b7f2 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: Ie6144135cf653d281c7bef84fb4469daefbad095
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:54:32 +00:00
Jenny Ho
3ab8be18a5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I899bc4150d6d32b0ede035c96487da50849b6256
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:50:10 +00:00
Jenny Ho
ee160b5880 Add permissions for maxfg_base/maxfg_secondary
Bug: 284878175
Change-Id: I3fe3030ecd36773405f0e70b767d4a28062d91ad
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-05-30 12:09:30 +08:00
Donnie Pollitz
16918db007 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: a2cb6ab6eb am: 54bb70bae8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I3b776b3a1fac9efd629722729fe424ab09d89fb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:50:11 +00:00
Donnie Pollitz
15843f30f0 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: 36ea330be0 am: d662abd90e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ia712aa77fea866bcf988aa5d106bcb25b726d8c0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:47:37 +00:00
Donnie Pollitz
5c37b6e55d Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: a2cb6ab6eb am: 62bfe3afc4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I403e8fd93c3609ccfab021704dae6113c4a23333
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:47:16 +00:00
Donnie Pollitz
d662abd90e Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: 36ea330be0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I44a0090b6a0be88fd606596fae0a236ef9bcdd40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:01:41 +00:00
Donnie Pollitz
54bb70bae8 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: a2cb6ab6eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I263b4d56605ba014b273a3089b9bcc853189e788
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:01:35 +00:00
Donnie Pollitz
62bfe3afc4 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: a2cb6ab6eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I891e9032a5bacf115410ad81ccd07580645da9d6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 08:59:32 +00:00
Donnie Pollitz
a2cb6ab6eb Allow vendor_init to fix permissions of TEE data file am: 955ae6825f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ibf91aa97b122e3a5f39053c6ed01e62b3783403c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:53:44 +00:00