Commit graph

1915 commits

Author SHA1 Message Date
martinwu
18dcc41f77 [automerger skipped] [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a -s ours am: d5f7c7d958 -s ours
am skip reason: Merged-In Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1 with SHA-1 ee611cfb51 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357

Change-Id: Ib25d58e12409bbd4642610d4924d93ccae5b289d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 07:59:10 +00:00
martinwu
d5f7c7d958 [automerger skipped] [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a -s ours
am skip reason: Merged-In Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1 with SHA-1 ee611cfb51 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357

Change-Id: Ia2c8274ad5f9aacc3f9cf7e309476e1713319d00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:57:13 +00:00
martinwu
5f9732a97a [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
Merged-In: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-05-02 03:16:02 +00:00
Jinyoung Jeong
0e225eae79 Fix SELinux error for com.google.android.euicc am: f265749f1d am: 225f248217
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711

Change-Id: I1cf4cbd10f42579aca80065c475463b56dddbcf5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 04:05:29 +00:00
Jinyoung Jeong
225f248217 Fix SELinux error for com.google.android.euicc am: f265749f1d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711

Change-Id: Iafdb146e4a11cb17c47509a567fe338df242b76a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:23:24 +00:00
Jinyoung Jeong
f265749f1d Fix SELinux error for com.google.android.euicc
Bug: 279548423
Test: http://fusion2/b7c803be-2dca-4195-b91f-6c4939746b5b
Change-Id: Idd231c2412e8f597dea1bfa11f9d1a0fa1e17034
2023-04-30 02:51:45 +00:00
martinwu
ee611cfb51 [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-04-27 13:43:26 +00:00
Bruno BELANYI
1f70adac2c Remove 'hal_neuralnetworks_armnn' '/data' access exception am: a43d300aff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786254

Change-Id: Ifb381f79a52d93792e6f7197b96318fe497b954d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:05 +00:00
Bruno BELANYI
e213052ee3 Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: 01a2e70a17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786660

Change-Id: I7d2962067bb15252010771386faa91f654cf4948
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:00 +00:00
Bruno BELANYI
86f6851961 Add ArmNN config sysprops SELinux rules am: ee3fe73de0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786979

Change-Id: I257d7dccaf726da56b5f8125f9cd9bcf9b90003b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:44:55 +00:00
Bruno BELANYI
a43d300aff Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:bb69b32fc5b6f468561017f6bd5628626a571696)
Merged-In: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
Change-Id: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
2023-04-27 08:06:38 +00:00
Bruno BELANYI
01a2e70a17 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:4f1ca4a7ad3895f5a5adc25fc2cf3a532eac79f6)
Merged-In: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
Change-Id: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
2023-04-27 08:06:38 +00:00
Bruno BELANYI
ee3fe73de0 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:9d61da55a193a12b7552e67e67d968c46d4dec86)
Merged-In: I90af8201d5fae44f73d709491f272a113b44ca67
Change-Id: I90af8201d5fae44f73d709491f272a113b44ca67
2023-04-27 08:06:38 +00:00
Martin Wu
ce2150e7b2 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..." am: c6d08c1781
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22891378

Change-Id: Ibd8ed1afbd64eb0f6d582a2b79cb218b61227f57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:16:02 +00:00
Martin Wu
c6d08c1781 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..."
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I5b1c00cc6a1ae186eb51acc2c99171578c43bace
2023-04-27 02:20:48 +00:00
martinwu
364729d86f Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: b7e90ec616
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22817736

Change-Id: Ib6386af3b162751d71d3af08269eeb2f43c35fe4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:17:46 +00:00
martinwu
b7e90ec616 Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I0eb9352e349ae8f06e469e953f137b00204f1c3b
2023-04-27 01:38:24 +00:00
Wilson Sung
67082a4a05 Update error on ROM 9784808 am: 2b913d29a9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791801

Change-Id: I9c166ebbe791eb5948fd8676fd8e463d3891ba33
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 07:42:38 +00:00
Wilson Sung
2b913d29a9 Update error on ROM 9784808
Bug: 274727778
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I56784948658365e8c9ecdf63d163109d8f29e5c3
2023-04-26 07:00:21 +00:00
Joseph Jang
457cf699d8 Move recovery.te to device/google/gs-common/dauntless/sepolicy am: 2a5c26c9b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791802

Change-Id: I7202f910327717069a0d925c1268bb66aacee2e3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:57 +00:00
Joseph Jang
2a5c26c9b4 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: I80fbd9ef0c7e988de21d07ada57fc6a038b9b585
2023-04-24 08:05:10 +00:00
jimsun
c477b46828 rild: allow rild to ptrace am: 0f6b14dc95
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21876774

Change-Id: I47c2a25b8105a26be3579b00a089529f11750f00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:15 +00:00
jimsun
0f6b14dc95 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
2edb9d804a Update error on ROM 9954737 am: 4cc8eec22d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22696721

Change-Id: I5e9980ccb32216b6ee8f504f657bcb4f15ccd7f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-18 05:06:01 +00:00
Wilson Sung
4cc8eec22d Update error on ROM 9954737
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
36acecbde7 Use restricted vendor property for ARM runtime options am: c1ee9afdef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22381562

Change-Id: I46c362e310af43993bf1b8ae25548933bc5eed80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:28:51 +00:00
Bruno BELANYI
c1ee9afdef Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00
Leo Liou
640fe3d54b gs201: add sepolicy for ufs_firmware_update process am: 5adecc7433
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22132666

Change-Id: I5525cba7db182410722e9deb22e490bbec6ed23b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 10:26:03 +00:00
Leo Liou
5adecc7433 gs201: add sepolicy for ufs_firmware_update process
Allow the script to access the specified partition and sysfs.

Bug: 273305212
Test: full build and test ffu flow
Change-Id: Iefeacea2d4c07e7a5b39713c9575e86bd25ce008
Signed-off-by: Leo Liou <leoliou@google.com>
2023-04-17 09:58:11 +00:00
kadirpili
52bceb2b75 gs201: Allow GRIL Service to access radio_vendor_data_file am: 1af348b01f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22213304

Change-Id: Id769672ecd92451c14f8daad175efeecd5cbd3fb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 06:15:50 +00:00
kadirpili
1af348b01f gs201: Allow GRIL Service to access radio_vendor_data_file
Bug: 274737512
Change-Id: I1c0b045f8a25c5d58be02c2036d2fcaad7d9a8e7
2023-04-14 06:57:50 +00:00
Xin Li
c28af0a680 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours am: 551330137f -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: If238593b7e3a51bc35d829c8847b32d477b421e7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:08:47 +00:00
Xin Li
551330137f [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Iefd6904aee50936e373590b4d54f492986aaf4dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:09 +00:00
Xin Li
ba5a2d3863 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I12f4ac63bb185203b115ae3f77ade5588bd50b10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:23:00 +00:00
Xin Li
4c44de9655 Merge TQ2A.230405.003 am: 8cff198ae3
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Ibeb863ad3557474eed5f5c8a529f12ed3c8c7768
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:58 +00:00
Minchan Kim
995f5bee72 remove dump_gs201 sepolicy am: dc35b4158b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529799

Change-Id: I1f86e778ac640c3deddd3520c2573794e243e887
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 09:49:14 +00:00
Minchan Kim
1dbb72a1b2 move vendor_cma_debugfs into gs-common am: b7393fd8d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529798

Change-Id: Ibc6f0f1cc047271a2db924669239b33c34860c91
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 09:49:08 +00:00
Minchan Kim
dc35b4158b remove dump_gs201 sepolicy
Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I39c01692d959a63c091f98969a69ab35b2debe1a
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Minchan Kim
b7393fd8d8 move vendor_cma_debugfs into gs-common
The CMA dump is common feature for pixel devices so move
it to gs-common.

Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I3997e27e3037f013338de5bc36687c63338769aa
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Tommy Kardach
9905ae28fb Update sepolicy for Camera HAL am: 3430e752af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22195719

Change-Id: I8131586dd90dc3220f03fe8cf7231e8abb5ad6e6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-11 20:28:06 +00:00
Tommy Kardach
3430e752af Update sepolicy for Camera HAL
Edit SE policay for WHI_PRO to allow
camera HAL to acquire wake locks

Bug: 249567788
Test: Flash and manual testing
Change-Id: I450b0b53000c5b9649e354350ec80af3528120fb
2023-04-11 19:45:33 +00:00
Xin Li
8cff198ae3 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I971732c6a40700a85df61170dcf1c3660307b96c
Change-Id: I33994bb345a46d8ac3f3a751fdff402f4ce5c68f
2023-04-10 23:55:29 -07:00
Adam Shih
5a0bb72bf0 Remove obsolete entries
Bug: 268147113
Bug: 237491813
Bug: 239484651
Bug: 268566483
Test: adb bugreport
Change-Id: Iceafe7e413a3ffe5d342a222f76093c7110639e6
2023-04-11 11:29:41 +08:00
Adam Shih
15ec2c4d63 use dumpsate from gs-common am: 9519323a98
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524762

Change-Id: I236bbd1daad4c2fdd804fb65c5791074f157a983
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:27 +00:00
Wilson Sung
842cc3f0ac Update error on ROM 9890523 am: 4d92dd61f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524766

Change-Id: I05877b25da3e5baa4dffc4cc3e0cd69808b7cb70
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:15 +00:00
Adam Shih
9519323a98 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: Ibd54c0049480810e2aa14074e0ec9c4d611d51ff
2023-04-10 01:11:14 +00:00
Wilson Sung
4d92dd61f2 Update error on ROM 9890523
Bug: 277155245
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iffbc691cff0e3a8d19ca3acef918cb4c1243feae
2023-04-07 07:07:40 +00:00
Victor Liu
88e12f2f08 uwb: add permission for ccc ranging am: 187dcc4e08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21965706

Change-Id: I44c6a7083e8c950c2bc2a7c95dd6a737dd5964ec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 21:29:09 +00:00
Victor Liu
187dcc4e08 uwb: add permission for ccc ranging
Bug: 255649425
Change-Id: I83ce369e52f382d76723b2b045e09607483a0a6a
2023-04-06 20:57:42 +00:00
Roy Luo
4b7fa3fe06 Support sending vendor command to GL852G via libusbhost am: 1f54dc7256
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22129755

Change-Id: Ib56fd37ddbe745c4753c038e30558aa217e6cdd2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 02:23:12 +00:00