Commit graph

2402 commits

Author SHA1 Message Date
Adam Shih
63c8f737cf remove obsolete error am: 28a0ab4015 am: a0a04923c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17686703

Change-Id: Ie7e76987261ecd4e279f4d85035fbf823c19deac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-11 05:51:21 +00:00
Adam Shih
a0a04923c8 remove obsolete error am: 28a0ab4015
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17686703

Change-Id: Ice8313bee0f45ed509494a6b370f68591321aef6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-11 05:19:18 +00:00
Adam Shih
28a0ab4015 remove obsolete error
Bug: 207062833
Bug: 210363938
Bug: 220636850
Test: boot with no relevant error log
Change-Id: I4901be83358e860b4a699ce44013fa1b255ceaa5
2022-04-11 11:05:15 +08:00
Stephane Lee
ecacc0682c Fix off-mode (charger) sepolicy for the health interface am: 73b95396fd am: ddbaf098f8 am: b6bd708203
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17350882

Change-Id: I13b96737c13053571fe3c173dbcfd6c7679b7e6f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 04:08:31 +00:00
Stephane Lee
4cd2a557da ODPM: Add ODPM config file to be read by powerstats 2.0 am: 5ce2f99f38 am: 4b99160e35 am: 94be7a849d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17621550

Change-Id: I39644719809ee0e7ac9067dbec34f3eb99bbd178
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 04:08:13 +00:00
chungkai
9b779d0796 sepolicy: ignore avc denial am: 2a3100de6e am: 1aa53c1f48 am: d6cdacea46
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17617704

Change-Id: Iac1a8de84b8e8292b559aa16d66b8da9688544b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 04:07:49 +00:00
chungkai
e86dff0003 genfs_contexts: fix path for i2c peripheral device am: fb466b4915 am: cd880aa0e6 am: ea58ed59a0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17521224

Change-Id: I24323f8641b279ee2397986bd0a6b5f147487ad7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 04:07:47 +00:00
Stephane Lee
3ee99baeb9 Fix off-mode (charger) sepolicy for the health interface am: 73b95396fd am: 5a32605710
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17350882

Change-Id: Ia44606b7af75dbd2c7c7728067267b4dfa2e07f3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:24 +00:00
Stephane Lee
b6bd708203 Fix off-mode (charger) sepolicy for the health interface am: 73b95396fd am: ddbaf098f8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17350882

Change-Id: I2dc024c51555249d279cd54a9e844d7e148a3ef8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:19 +00:00
Stephane Lee
e868202588 ODPM: Add ODPM config file to be read by powerstats 2.0 am: 5ce2f99f38 am: 04f71ae091
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17621550

Change-Id: Ic3b96fe3e55b2ff58581b50e4320d52186224180
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:15 +00:00
Stephane Lee
94be7a849d ODPM: Add ODPM config file to be read by powerstats 2.0 am: 5ce2f99f38 am: 4b99160e35
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17621550

Change-Id: I9a1f4a756d0ccdfe8a7698c644087a4406524d41
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:11 +00:00
chungkai
c906700242 sepolicy: ignore avc denial am: 2a3100de6e am: aebc5fa20e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17617704

Change-Id: If7f932eb203c0d0eba27022a70dd3ab4a2a6c989
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:02 +00:00
chungkai
695bbd5671 genfs_contexts: fix path for i2c peripheral device am: fb466b4915 am: d2e0a2ef5e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17521224

Change-Id: I51f8bbb9f6bd068f9ec1aa51cb6b1e3902535e0f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:38:00 +00:00
chungkai
d6cdacea46 sepolicy: ignore avc denial am: 2a3100de6e am: 1aa53c1f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17617704

Change-Id: I13c195e318c3e514ff69b7add78f7f27ccaac1cb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:37:47 +00:00
chungkai
ea58ed59a0 genfs_contexts: fix path for i2c peripheral device am: fb466b4915 am: cd880aa0e6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17521224

Change-Id: Iccc166d45c486e4c26671c0ecf7d49cb61dea1ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:37:45 +00:00
Stephane Lee
ddbaf098f8 Fix off-mode (charger) sepolicy for the health interface am: 73b95396fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17350882

Change-Id: I8ad0bb623bf857ed55c381dad6a5c571dcd06409
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:29:06 +00:00
Stephane Lee
5a32605710 Fix off-mode (charger) sepolicy for the health interface am: 73b95396fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17350882

Change-Id: Ia20811303b891d08e79f0534ee46ed4ef3934d47
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 03:27:47 +00:00
Stephane Lee
73b95396fd Fix off-mode (charger) sepolicy for the health interface
Bug: 223537397
Test: Ensure that there are no selinux errors for charger_vendor in
   off-mode charging
Change-Id: I9074079a7ba67813da6b6ad7b110d964b9b7db6d
2022-04-08 03:13:51 +00:00
Stephane Lee
4b99160e35 ODPM: Add ODPM config file to be read by powerstats 2.0 am: 5ce2f99f38
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17621550

Change-Id: I3bd878b212f35cef8ca71a3bbcb28551c6d5257e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:53:52 +00:00
chungkai
1aa53c1f48 sepolicy: ignore avc denial am: 2a3100de6e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17617704

Change-Id: I25f2f431a19e8cd7dbca347865b85d2dbf46f836
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:53:22 +00:00
chungkai
cd880aa0e6 genfs_contexts: fix path for i2c peripheral device am: fb466b4915
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17521224

Change-Id: I9d6ae44e3c1d28b670796dc87e193281f9699c76
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:53:20 +00:00
Stephane Lee
04f71ae091 ODPM: Add ODPM config file to be read by powerstats 2.0 am: 5ce2f99f38
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17621550

Change-Id: Ia82142dcca16e6d54a30d52dec5e5ce1817e023f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:53:01 +00:00
chungkai
aebc5fa20e sepolicy: ignore avc denial am: 2a3100de6e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17617704

Change-Id: I8c8faf53f44f8bde1c43a22e3761d40904222366
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:52:52 +00:00
chungkai
d2e0a2ef5e genfs_contexts: fix path for i2c peripheral device am: fb466b4915
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17521224

Change-Id: Id75935027077c24888c2e168932b621dc75c0926
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-08 02:52:50 +00:00
Stephane Lee
5ce2f99f38 ODPM: Add ODPM config file to be read by powerstats 2.0
Test: Ensure that there are no sepolicy errors when
/data/vendor/powerstats/odpm_config exists
Bug: 228112997

Change-Id: I094c29c4d1a82bccfabde7a5511f4aa833c2cd35
2022-04-08 02:49:40 +00:00
chungkai
2a3100de6e sepolicy: ignore avc denial
dont audit since it's debugfs

Bug: 228181404
Test: forrest with boot test
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I77a385b73b5a9edafefa8e7d34a351594cd5cd06
2022-04-08 02:20:26 +00:00
chungkai
fb466b4915 genfs_contexts: fix path for i2c peripheral device
paths are changed when we enable parallel module loading and
reorder the initializtaion of devices.

Test: without avc denial
Bug: 227541760
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Icd74392e0684ac5614a83d14b936be880148f919
2022-04-08 02:20:26 +00:00
Adrian Salido
97c9228497 allow hwc access to persistent vendor display sysprop am: a1c2f220a7 am: ef36588f0e am: 79dde6d1f6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17226635

Change-Id: I9ae29f3abf3d2e6f3c46e1cad865660c3147068f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 16:48:26 +00:00
Adrian Salido
79dde6d1f6 allow hwc access to persistent vendor display sysprop am: a1c2f220a7 am: ef36588f0e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17226635

Change-Id: I7d35ba9d0539fc864af1592e451d1f85a92c17d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 16:32:52 +00:00
Adrian Salido
7fcb9ff99f allow hwc access to persistent vendor display sysprop am: a1c2f220a7 am: 94062fcca0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17226635

Change-Id: I5914a9273f55d8a47c6ca9d515c86a2af373bea7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 16:32:38 +00:00
Adrian Salido
ef36588f0e allow hwc access to persistent vendor display sysprop am: a1c2f220a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17226635

Change-Id: I820ddb93fc74c9bc8606e61f07217f7612e419f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 16:04:20 +00:00
Adrian Salido
94062fcca0 allow hwc access to persistent vendor display sysprop am: a1c2f220a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17226635

Change-Id: Id61b9caf74a1c05577202aa4a57010468ad9859c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 16:03:26 +00:00
Adrian Salido
a1c2f220a7 allow hwc access to persistent vendor display sysprop
Test: check avc denials while switching resolution
Bug: 217399988
Change-Id: Ia3a3ab394ec23ea3150a8cf4638e045cd1e9cac9
2022-04-07 15:40:54 +00:00
Adam Shih
697a4e9860 let sensor access aoc am: 1e88b530fa am: 9e10c64350 am: 6d2ad66a5c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: Ic8488eb4879dbfd6df8ad489c146f12b84d9f72f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 06:05:32 +00:00
Adam Shih
6d2ad66a5c let sensor access aoc am: 1e88b530fa am: 9e10c64350
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: I5ae04443b02d4e3c7e1f8bda6ce389703fa964b4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:40:39 +00:00
Adam Shih
863629645e let sensor access aoc am: 1e88b530fa am: 73ce03bbd9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: I4b981ad2f32841afc31b9c35290929f5f7ba1347
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:39:52 +00:00
Adam Shih
9e10c64350 let sensor access aoc am: 1e88b530fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: I40ac3df71d11deba2bad8d90a6e7927608b611ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:17:17 +00:00
Siddharth Kapoor
5d6cf0ba3b Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 1b92d2d5d2 am: 57baa82fb5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: Ia8e488dd65a8f184af0419ea9fae375e2660fe2a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:16:45 +00:00
Adam Shih
73ce03bbd9 let sensor access aoc am: 1e88b530fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609183

Change-Id: Ia4534f9706a1fe8164453b8f92d5293ce62e3582
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 05:16:09 +00:00
Siddharth Kapoor
4e2778858c Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 23c89da785
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I4f4636065496d6d015266b420e59da6f19009e0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:46:05 +00:00
Siddharth Kapoor
57baa82fb5 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf am: 1b92d2d5d2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: Ib338e02211ffa4903cb28927bfd8593914d3a8f6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:45:57 +00:00
Adam Shih
1e88b530fa let sensor access aoc
04-03 05:57:12.776   859   859 I auditd  : type=1400 audit(0.0:7): avc: denied { read } for comm="UsfHalWorker" name="services" dev="sysfs" ino=69355 scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:sysfs_aoc_dumpstate:s0 tclass=file permissive=0
04-03 05:57:12.776   859   859 I auditd  : type=1400 audit(0.0:8): avc: denied { write } for comm="UsfHalWorker" name="reset" dev="sysfs" ino=69363 scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:sysfs_aoc_reset:s0 tclass=file permissive=0

Bug: 228030183
Bug: 228030193
Test: boot with no relevant errors
Change-Id: I87fd1aa1dc9b9cf42b23fb0e7f5d4e5b6f845610
2022-04-07 04:37:49 +00:00
Siddharth Kapoor
1b92d2d5d2 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I8f7cbae7916b6bf21415d35afdeb653c243d2c6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:23:37 +00:00
Siddharth Kapoor
23c89da785 Revert "Move ODPM file rule to pixel sepolicy" am: 15f80f57bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17609199

Change-Id: I4720884741d8e4121aa9492ff1aa66d25a39d4d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-07 04:22:23 +00:00
Siddharth Kapoor
15f80f57bf Revert "Move ODPM file rule to pixel sepolicy"
Revert "Move ODPM file rule to pixel sepolicy"

Revert "Move ODPM file rule to pixel sepolicy"

Revert submission 17215583-odpm_sepolicy_refactor-tm-dev

Reason for revert: build failure tracked in b/228261711
Reverted Changes:
Ic9a89950a:Move ODPM file rule to pixel sepolicy
I24105669b:Move ODPM file rule to pixel sepolicy
I044a285ff:Move ODPM file rule to pixel sepolicy

Change-Id: Idbf5cd106f229c8a72b2ecbc6e5ffd20d9e06805
2022-04-07 04:06:29 +00:00
Jeremy DeHaan
249213ddb6 Update selinux policy for display information am: 18f8d933ab am: 573cc8efc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17599695

Change-Id: Icfc31a38101cd898fd1812fd6645a2a35d02ec88
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 19:42:56 +00:00
Jeremy DeHaan
573cc8efc5 Update selinux policy for display information am: 18f8d933ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17599695

Change-Id: I59aa272537c9f9566417847890637e05db374ef6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 19:24:05 +00:00
Jeremy DeHaan
18f8d933ab Update selinux policy for display information
Two new sysfs nodes were added to sysfs_display type and permission to
access sysfs_display nodes was added for the dumpstate service. This
allows display information to be captured during bug report generation.

Bug: 225376485
Test: Manual - ran 'adb bugreport'
Change-Id: Ib121b0b21aa326e791e67c5bd24b3e70979a554c
2022-04-06 18:51:45 +00:00
Mason Wang
9167990af4 hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b am: 60592aae02 am: 18fa16a7aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I7c3ef346b4e5fbdf4c0e8c710f2e436161446d21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 11:27:50 +00:00
Mason Wang
18fa16a7aa hal_dumpstate_default: Fix avc denial of focaltech_touch. am: 882527f08b am: 60592aae02
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17524943

Change-Id: I75fb5c27d78a599d270538ae62ec8af9f6f57133
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-06 10:54:31 +00:00