Commit graph

917 commits

Author SHA1 Message Date
Adam Shih
863629645e let sensor access aoc am: 1e88b530fa am: 73ce03bbd9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: I4b981ad2f32841afc31b9c35290929f5f7ba1347
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:39:52 +00:00
Adam Shih
9e10c64350 let sensor access aoc am: 1e88b530fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: I40ac3df71d11deba2bad8d90a6e7927608b611ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:17:17 +00:00
Siddharth Kapoor
5d6cf0ba3b Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 1b92d2d5d2 am: 57baa82fb5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: Ia8e488dd65a8f184af0419ea9fae375e2660fe2a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:16:45 +00:00
Adam Shih
73ce03bbd9 let sensor access aoc am: 1e88b530fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: Ia4534f9706a1fe8164453b8f92d5293ce62e3582
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:16:09 +00:00
Siddharth Kapoor
4e2778858c Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 23c89da785
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I4f4636065496d6d015266b420e59da6f19009e0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:46:05 +00:00
Siddharth Kapoor
57baa82fb5 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 1b92d2d5d2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: Ib338e02211ffa4903cb28927bfd8593914d3a8f6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:45:57 +00:00
Adam Shih
1e88b530fa let sensor access aoc
04-03 05:57:12.776   859   859 I auditd  : type=1400 audit(0.0:7): avc: denied { read } for comm="UsfHalWorker" name="services" dev="sysfs" ino=69355 scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:sysfs_aoc_dumpstate:s0 tclass=file permissive=0
04-03 05:57:12.776   859   859 I auditd  : type=1400 audit(0.0:8): avc: denied { write } for comm="UsfHalWorker" name="reset" dev="sysfs" ino=69363 scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:sysfs_aoc_reset:s0 tclass=file permissive=0

Bug: 228030183
Bug: 228030193
Test: boot with no relevant errors
Change-Id: I87fd1aa1dc9b9cf42b23fb0e7f5d4e5b6f845610
2022-04-07 04:37:49 +00:00
Siddharth Kapoor
1b92d2d5d2 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I8f7cbae7916b6bf21415d35afdeb653c243d2c6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:23:37 +00:00
Siddharth Kapoor
23c89da785 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I4720884741d8e4121aa9492ff1aa66d25a39d4d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:22:23 +00:00
Siddharth Kapoor
15f80f57bf Revert "Move ODPM file rule to pixel sepolicy"
Revert "Move ODPM file rule to pixel sepolicy"

Revert "Move ODPM file rule to pixel sepolicy"

Revert submission 17215583-odpm_sepolicy_refactor-tm-dev

Reason for revert: build failure tracked in b/228261711
Reverted Changes:
Ic9a89950a:Move ODPM file rule to pixel sepolicy
I24105669b:Move ODPM file rule to pixel sepolicy
I044a285ff:Move ODPM file rule to pixel sepolicy

Change-Id: Idbf5cd106f229c8a72b2ecbc6e5ffd20d9e06805
2022-04-07 04:06:29 +00:00
Jeremy DeHaan
249213ddb6 Update selinux policy for display information am: 18f8d933ab am: 573cc8efc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17599695

Change-Id: Icfc31a38101cd898fd1812fd6645a2a35d02ec88
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 19:42:56 +00:00
Jeremy DeHaan
573cc8efc5 Update selinux policy for display information am: 18f8d933ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17599695

Change-Id: I59aa272537c9f9566417847890637e05db374ef6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 19:24:05 +00:00
Jeremy DeHaan
18f8d933ab Update selinux policy for display information
Two new sysfs nodes were added to sysfs_display type and permission to
access sysfs_display nodes was added for the dumpstate service. This
allows display information to be captured during bug report generation.

Bug: 225376485
Test: Manual - ran 'adb bugreport'
Change-Id: Ib121b0b21aa326e791e67c5bd24b3e70979a554c
2022-04-06 18:51:45 +00:00
Mason Wang
9167990af4 hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b am: 60592aae02 am: 18fa16a7aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I7c3ef346b4e5fbdf4c0e8c710f2e436161446d21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 11:27:50 +00:00
Mason Wang
18fa16a7aa hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b am: 60592aae02
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I75fb5c27d78a599d270538ae62ec8af9f6f57133
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 10:54:31 +00:00
Mason Wang
bf17e02cf7 hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b am: 020cb8c9de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I45f4c70de717e092c5cf4a7b4c5b4cf8e7f001ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 10:54:25 +00:00
Mason Wang
60592aae02 hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I303b4b33cd88445e2e277f63a9c0596d641a5ed4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 10:28:53 +00:00
Mason Wang
020cb8c9de hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I3fb72c06a72b72cbb0838b6d317a74948d6163b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 10:28:19 +00:00
Mason Wang
882527f08b hal_dumpstate_default: Fix avc denial of focaltech_touch.
Fixed following avc denial:
avc: denied { read } for name="focaltech_touch" dev="proc" ino=4026535419 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc_touch:s0 tclass=dir permissive=0

Bug: 199105131
Test: Verify pass by checking device log are w/o above errors when
trigger bugreport.

Change-Id: Id2af1f59cd397f0332fba94f68d9940f612a8e81
2022-04-06 10:03:14 +00:00
samou
b1cef38c36 Move ODPM file rule to pixel sepolicy am: ece8953942 am: 8c8727b061 am: 9710a28d1e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17213985

Change-Id: Idd070de61fe21298c039b8e6bc355fc1ca2b423d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 03:26:16 +00:00
samou
9710a28d1e Move ODPM file rule to pixel sepolicy am: ece8953942 am: 8c8727b061
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17213985

Change-Id: I97e7348827ef41e240376040cff4acb336df3fcb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 02:59:43 +00:00
samou
837e598a78 Move ODPM file rule to pixel sepolicy am: ece8953942 am: df3f4565cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17213985

Change-Id: I3ded387684ddeda364f8c721e95b664ad3a8da38
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 02:59:24 +00:00
samou
8c8727b061 Move ODPM file rule to pixel sepolicy am: ece8953942
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17213985

Change-Id: I21d1c1488efa4e00412962f16d2fe837d8ffeb27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 02:38:48 +00:00
samou
df3f4565cd Move ODPM file rule to pixel sepolicy am: ece8953942
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17213985

Change-Id: Idd9e78217ff996f571d7c03d1ccbc0ac44ebbadd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 02:37:54 +00:00
samou
ece8953942 Move ODPM file rule to pixel sepolicy
Bug: 213257759
Change-Id: I24105669b076061780addf5b038607f4d1957ee5
2022-04-06 02:09:38 +00:00
Anthony Stange
e524403b33 Add BT HAL SELinux policy am: ede5e0944a am: 2ff2776db0 am: f0c3cec6c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474643

Change-Id: Ic5670046df3510c826fe9a6b6a9422c3ba3bc42a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-04 17:02:38 +00:00
Anthony Stange
33546719a6 Add BT HAL SELinux policy am: ede5e0944a am: d2b2e29c89
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474643

Change-Id: I2c9ed7d6d14efc978ec179309e7b235962a1528e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-04 16:49:40 +00:00
Anthony Stange
f0c3cec6c1 Add BT HAL SELinux policy am: ede5e0944a am: 2ff2776db0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474643

Change-Id: I7628edd8494927418ae7e9effb3e68e7d9205d19
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-04 16:46:54 +00:00
Anthony Stange
d2b2e29c89 Add BT HAL SELinux policy am: ede5e0944a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474643

Change-Id: I5419086807dee3fbeb05d7e914a80158fb9f3ae3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-04 16:27:26 +00:00
Anthony Stange
2ff2776db0 Add BT HAL SELinux policy am: ede5e0944a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474643

Change-Id: I538afe38e3ed3eb630d05efb74137ec15881cee2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-04 16:27:09 +00:00
Anthony Stange
ede5e0944a Add BT HAL SELinux policy
Bug: 193474802
Test: presubmits
Change-Id: I0ce730c119b60fdfec6e31dea88f5edbf69048ed
2022-04-04 15:55:43 +00:00
sukiliu
7ba9b197c0 Update avc error on ROM 8388849 am: 97326bf38b am: 6be9cbeb9a am: 96a37c7a80
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: Ica002e09ccdbdb6fa0913cfbdccf1535281f0131
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 08:16:07 +00:00
sukiliu
96a37c7a80 Update avc error on ROM 8388849 am: 97326bf38b am: 6be9cbeb9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: I97dc576a52d5c506889c338eca6c079ba68b3563
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:57:07 +00:00
sukiliu
02b322b273 Update avc error on ROM 8388849 am: 97326bf38b am: 2f95d1ab49
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: Iaabe48e01ac0c5534a2f920ab6638f2ed8948243
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:49:55 +00:00
sukiliu
6be9cbeb9a Update avc error on ROM 8388849 am: 97326bf38b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: Ie3331c90cf0d2de60f38f694861e02ad1a8e6d5c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:36:44 +00:00
sukiliu
2f95d1ab49 Update avc error on ROM 8388849 am: 97326bf38b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: I3cd290900175d9c80bd5035b028ec5e8754e8167
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:35:58 +00:00
sukiliu
97326bf38b Update avc error on ROM 8388849
Bug: 221384939
Bug: 227694693
Bug: 227695036
Test: PtsSELinuxTestCases
Change-Id: I0768e29a0a162c6f568a5186602b01f1375a1ca5
2022-04-01 11:55:09 +08:00
Taesoon Park
22f957df9d Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 45d538c645 am: 2db00c7973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia0c18c33a6dcb21204413d11d1f40c31e1e9cbf6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:39:09 +00:00
Taesoon Park
b215763c9c Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 6409f46ba8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ifb8229ab57ffdb15420d92f6f24c116a13573379
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:10:00 +00:00
Taesoon Park
2db00c7973 Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 45d538c645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ica4a2c64a99687a9aec0289d338c5c93a973d3b3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:09:36 +00:00
Taesoon Park
45d538c645 Add permission to access vendor.ims property to vendor ims app am: 9211922e70
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia3c34bb10d68af53a47e8939ffea389e6d57e542
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 01:45:59 +00:00
Taesoon Park
6409f46ba8 Add permission to access vendor.ims property to vendor ims app am: 9211922e70
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia93e4b9df47ac0e0cee17da277ba6c324cb0efab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 01:29:04 +00:00
Taesoon Park
9211922e70 Add permission to access vendor.ims property to vendor ims app
Vendor IMS Service read a SystemProperty starts with
persist.vendor.ims prefix, but it does not have a permission to
access it.
This change create a permission to access the SystemProperties start
with 'persist.vendor.ims.' prefix from vendor ims service.

Bug: 204714230
Test: Test results in b/225430461#comment40 enabling the property

Signed-off-by: Taesoon Park <ts89.park@samsung.com>
Change-Id: Ied50f377a3069eac65836ea999dfe021f4e4ed5d
2022-04-01 01:19:26 +00:00
chungkai
4deaf937b6 sched: move sysfs to procfs am: 2dc6f70afc am: a66699f706
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: Id4547d16ca3ae61f6191afa78253c0308894baa3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:43:54 +00:00
chungkai
ec14f07ee1 sched: move sysfs to procfs am: 2dc6f70afc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: I4910c36d52b42bd2e800890c34b19136587b4191
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:23:28 +00:00
chungkai
a66699f706 sched: move sysfs to procfs am: 2dc6f70afc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: I003de1eea466f47583c97b19a730a967dd9aa251
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:23:26 +00:00
chungkai
2dc6f70afc sched: move sysfs to procfs
Modify name from sysfs_vendor_sched to proc_vendor_sched

Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ieb829e96ac1db2a1aa28fc416182450d128cac5c
2022-03-31 07:00:20 +00:00
Ocean Chen
8557b1f255 sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0 am: 16f97b2c95
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: I10ef015dab9758032554bb829e2cbab1e3aa8e9f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:47:28 +00:00
Ocean Chen
7a2a70daeb sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: I17c3de914774d744b3b0d0e3000c96a840c1354b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:24:47 +00:00
Ocean Chen
16f97b2c95 sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: If726e1e96c5ca8052e7a22e577695c1ae1cabef5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:24:37 +00:00