Ray Chi
035c81b8df
Revert "add sepolicy for set_usb_irq.sh" am: 3fdb24bdc1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17464004
Change-Id: I886d7f2afe80798d4166ee7a9edc7697bcf4c94e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-30 05:00:19 +00:00
Ray Chi
3fdb24bdc1
Revert "add sepolicy for set_usb_irq.sh"
...
This reverts commit 6733f9667d
.
Bug: 225789036
Test: build pass
Change-Id: If43c8db71c737d509b1dfd098503f564a06bf046
2022-03-29 15:45:30 +08:00
Kris Chen
e9cd4bb590
Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
am: 659f0ab560
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784
Change-Id: Ib1f08385f2b24a3371c5641ffa9e0bca9a36f1bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:07:21 +00:00
Kris Chen
659f0ab560
Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784
Change-Id: Iecf25951e071664241e33b73583af1fbe27b83f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:06:05 +00:00
Kris Chen
72403141aa
Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784
Change-Id: Ib80d12143916976b7f9617773e1e2d0f95a84466
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:05:35 +00:00
Kris Chen
32f2e4b0e7
Allow hal_fingerprint_default to access sysfs_display
...
Fix the following avc denial:
avc: denied { read } for name="panel_name" dev="sysfs" ino=71133 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_display:s0 tclass=file permissive=0
Bug: 223687187
Test: build and test fingerprint on device.
Change-Id: Ief1ccc7e2fa6b8b4dc1ecbd6d446cc49ee3936ce
2022-03-29 01:39:32 +00:00
Minchan Kim
a401f8c5ce
sepolicy: allow dump page_pinner am: 3496931400
am: 145aa1f2bd
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608
Change-Id: I1e444e504418fa9a3eceb8cb24b7cb581f12513d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 17:24:18 +00:00
Minchan Kim
145aa1f2bd
sepolicy: allow dump page_pinner am: 3496931400
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608
Change-Id: I77ebf664d28637f578151faef02c8bc7f4406a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 16:53:30 +00:00
Minchan Kim
56fb8cb807
sepolicy: allow dump page_pinner am: 3496931400
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608
Change-Id: Id4385572ff9f2fc059d351c817a764f5a4f0574d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 16:53:16 +00:00
Minchan Kim
3496931400
sepolicy: allow dump page_pinner
...
Provide necessary sepolicy for dumpreport to access page_pinner
information in /sys/kernel/debug/page_pinner/{longterm_pinner,
alloc_contig_failed}
Bug: 226956571
Test: Run "adb bugreport <zip>" and verify it contains the output
from page_pinner.
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I7b00d4930fbaa2061537cd8c84616c1053c829cf
2022-03-28 16:35:02 +00:00
Adam Shih
1a3c271d6b
update error on ROM 8365560 am: 5cc8837eb6
am: c94cff952d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798
Change-Id: I1a461593232938ad4729bc453e08e3cfe7024e7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:24:38 +00:00
Adam Shih
c94cff952d
update error on ROM 8365560 am: 5cc8837eb6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798
Change-Id: I59263d45b9c7a57dc32ef7f5219afa81aec61c4b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:08:12 +00:00
Adam Shih
14f5e47200
update error on ROM 8365560 am: 5cc8837eb6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798
Change-Id: I97e7b5e9675b31b9379816fa8d3e0878af42b8f4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:07:59 +00:00
Adam Shih
5cc8837eb6
update error on ROM 8365560
...
Bug: 227121550
Bug: 227122249
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iab96c7644e6c99d700a5f7b42fba30032d3624b7
2022-03-28 10:59:04 +08:00
Omer Osman
734e18e250
Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
am: afdb7f17b7
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308
Change-Id: If4bd2041a3aafa36403e1d57407996337fed397f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:28:05 +00:00
Omer Osman
afdb7f17b7
Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308
Change-Id: Ia839f8717dc2a44d3bfd52077a471f6f301fc413
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:05:25 +00:00
Omer Osman
f79916c309
Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308
Change-Id: I05d2debd765c63b99ecf9c66d91782dbc842ca43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:05:20 +00:00
Omer Osman
e5cc5f7937
Add hidraw device and Dynamic Sensor SE Linux policy
...
Test: Incoming HID data from Pixel Buds
Change-Id: I77489100e13d892fb7d3a7cee9734de044795dec
2022-03-27 23:26:29 +00:00
Lucas Wei
a938018ae5
Label vendor_kernel_boot with boot_block_device for OTA updating am: ab9ec22267
am: 793e41d11d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291643
Change-Id: Ic763ff0873d5eecc43eaa6de5f37741d945c7e3d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 09:26:33 +00:00
Lucas Wei
cb6545146a
Label vendor_kernel_boot with boot_block_device for OTA updating am: ab9ec22267
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291643
Change-Id: I866f30a7ebd0aed08b44da70a2638b6f59cf8e38
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 09:11:37 +00:00
Lucas Wei
793e41d11d
Label vendor_kernel_boot with boot_block_device for OTA updating am: ab9ec22267
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291643
Change-Id: I7228a6bdb0b5c931f0fc06a3b38d67d7666e0a3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 09:11:27 +00:00
Lucas Wei
ab9ec22267
Label vendor_kernel_boot with boot_block_device for OTA updating
...
Label with boot_block_device to allow further operations on
vendor_kernel_boot including OTA updating.
This is required for update_engine to be able to write to
vendor_kernel_boot on builds that are enforcing sepolicy.
Bug: 214409109
Signed-off-by: Lucas Wei <lucaswei@google.com>
Change-Id: If239690ee168ecfd5c5b755451e389a4523c79b8
2022-03-25 08:55:00 +00:00
Darren Hsu
b877b6e9e1
Allow hal_power_stats to read sysfs_aoc_dumpstate am: 85710448f3
am: 9d05616fa8
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17351092
Change-Id: I08b51dab7e91df001682d6c4cc77b7bd3ed42f15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 07:44:40 +00:00
Darren Hsu
cfad5ee6a1
Allow hal_power_stats to read sysfs_aoc_dumpstate am: 85710448f3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17351092
Change-Id: I7b7048296e3304eae213939e5648e20039e9acd0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 07:19:34 +00:00
Darren Hsu
9d05616fa8
Allow hal_power_stats to read sysfs_aoc_dumpstate am: 85710448f3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17351092
Change-Id: I6913af827f44b7098c26ffd9f56d1e7f98c36d7c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 07:19:16 +00:00
Darren Hsu
85710448f3
Allow hal_power_stats to read sysfs_aoc_dumpstate
...
avc: denied { read } for comm="android.hardwar" name="restart_count"
dev="sysfs" ino=72823 scontext=u:r:hal_power_stats_default:s0
tcontext=u:object_r:sysfs_aoc_dumpstate:s0 tclass=file permissive=0
Bug: 226173008
Test: check bugreport without avc denials
Change-Id: I35d886dd05fdad821e38810fd848c7f451893e3f
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-25 06:59:34 +00:00
Ted Lin
cb078be9f0
Remove the tracking for vendor_battery_defender am: 4b75aab4b8
am: 9c59b398db
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342324
Change-Id: I358c8178c3f29a5141e2d4fdf58dc657eb77ba40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 02:26:25 +00:00
Ted Lin
9c59b398db
Remove the tracking for vendor_battery_defender am: 4b75aab4b8
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342324
Change-Id: If643013008f26e6c890d9a43f2d7c4ef177eac68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 02:02:52 +00:00
Ted Lin
f504cca79a
Remove the tracking for vendor_battery_defender am: 4b75aab4b8
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342324
Change-Id: If12f9cabf9900d4492d7e405f4ed877f2f3f2ae3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 02:02:33 +00:00
Ted Lin
4b75aab4b8
Remove the tracking for vendor_battery_defender
...
The function is disabled.
Bug: 221384939
Test: adb bugreport
Change-Id: If8e8b8165329eb9ede86cb62f419a8cf06abb536
Signed-off-by: Ted Lin <tedlin@google.com>
2022-03-25 01:37:03 +00:00
Chris Kuiper
e20b8b0bde
Add rules to allow Sensor HAL write access to als_table am: 967571ee60
am: f5453f84aa
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888
Change-Id: I3ab1b246c094f1438b8bcf6bb4d167dd33872068
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:39:23 +00:00
Chris Kuiper
f5453f84aa
Add rules to allow Sensor HAL write access to als_table am: 967571ee60
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888
Change-Id: I8ddfebc5b8febe09cb48cb58f7f2ed9ee74386d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:21:03 +00:00
Chris Kuiper
ffebbdcd34
Add rules to allow Sensor HAL write access to als_table am: 967571ee60
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888
Change-Id: Id038f0254f2c69e917c88cb2da0aa8f47b6861f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:20:47 +00:00
Chris Kuiper
967571ee60
Add rules to allow Sensor HAL write access to als_table
...
Sensor HAL needs write access to
/sys/class/backlight/panel0-backlight/als_table.
Bug: 226435017
Test: Observing logs
Change-Id: Idb592d601b92c6814493e0d28384e1013935b72f
2022-03-25 00:00:19 +00:00
chungkai
2df9c1b75b
sched: move sysfs to procfs am: 4fa67857c3
am: 9bff8c59b6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963
Change-Id: I673097342a9c61b74b5dab7e7758ff2c12a92172
2022-03-24 18:35:30 +00:00
chungkai
9bff8c59b6
sched: move sysfs to procfs am: 4fa67857c3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963
Change-Id: Ib855e5bdf15d24defa55f3b548144fd31ed96ecb
2022-03-24 18:16:44 +00:00
chungkai
3eba3a1004
sched: move sysfs to procfs am: 4fa67857c3
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963
Change-Id: I9152300c03241a0f025002c8325298b2412bbae4
2022-03-24 18:16:44 +00:00
chungkai
4fa67857c3
sched: move sysfs to procfs
...
Modify name from sysfs_vendor_sched to proc_vendor_sched
Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I96dc6eb76dd533ff6fd54c27be7e4bc32bf5dbc7
2022-03-24 17:44:37 +00:00
Holmes Chou
baf62054ef
camera: use codename for camera modules am: e0b06b9cbd
am: 15a914dbc1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590
Change-Id: I5326b73fcb3cfc1f5cbc8aef0568116fe6996c9f
2022-03-24 14:00:24 +00:00
Holmes Chou
15a914dbc1
camera: use codename for camera modules am: e0b06b9cbd
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590
Change-Id: Ibb0e4a61baff6e2d9e405afdb29494a0263e1559
2022-03-24 13:38:18 +00:00
Holmes Chou
91e48d04e6
camera: use codename for camera modules am: e0b06b9cbd
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590
Change-Id: I316371a838cb4ed83103a9be3675bae736a6e570
2022-03-24 13:38:04 +00:00
Holmes Chou
e0b06b9cbd
camera: use codename for camera modules
...
use codename for camera modules
Bug: 209866857
Test: GCA, adb logcat
Change-Id: I55f6998d18a904c83ecdf328d1b0e5ca6a01427f
2022-03-24 13:11:16 +00:00
Ted Lin
f07365851f
hal_health_default: Fix avc denials am: 0adad90ab6
am: 213dd940ff
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323
Change-Id: I365f5883dcc1e1cc00b70881cbb299079129bc65
2022-03-24 06:16:42 +00:00
Ted Lin
213dd940ff
hal_health_default: Fix avc denials am: 0adad90ab6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323
Change-Id: I8f57a0ab56e2d11109c6a65084983499ab1bd787
2022-03-24 05:53:09 +00:00
Ted Lin
01fd681875
hal_health_default: Fix avc denials am: 0adad90ab6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323
Change-Id: I5aa66b895e116b4336e9b1501441727ae09580cd
2022-03-24 05:52:55 +00:00
Ted Lin
0adad90ab6
hal_health_default: Fix avc denials
...
12-02 11:15:45.224 756 756 I health@2.1-serv: type=1400 audit(0.0:2270): avc: denied { search } for name="thermal" dev="tmpfs" ino=1028 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=1
12-02 11:15:45.224 756 756 I health@2.1-serv: type=1400 audit(0.0:2271): avc: denied { search } for name="thermal" dev="sysfs" ino=16790 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=dir permissive=1
12-02 11:15:45.224 756 756 I health@2.1-serv: type=1400 audit(0.0:2273): avc: denied { open } for path="/sys/devices/virtual/thermal/thermal_zone13/mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1
12-02 11:15:45.224 756 756 I health@2.1-serv: type=1400 audit(0.0:2272): avc: denied { write } for name="mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1
Bug:208721638
Test: adb bugreport
Change-Id: I4d9491862ff1bcc88f89b1478497ac569e3d1df1
Signed-off-by: Ted Lin <tedlin@google.com>
(cherry picked from commit 5b6a5292c3
)
2022-03-24 05:26:09 +00:00
Adam Shih
a64c706300
enforce debugfs constraint on userdebug build am: de2696eb72
am: fcae230ef4
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326
Change-Id: I08077c437eec9024573b416c8782f75e33d9f74e
2022-03-24 04:39:43 +00:00
Adam Shih
fcae230ef4
enforce debugfs constraint on userdebug build am: de2696eb72
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326
Change-Id: I2008bde5b787053f818a58452f629e5bee8e8ced
2022-03-24 04:12:13 +00:00
Adam Shih
3244ceef37
enforce debugfs constraint on userdebug build am: de2696eb72
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326
Change-Id: I9017b4539131e88f31580127042cf26908137aed
2022-03-24 04:10:57 +00:00
Adam Shih
de2696eb72
enforce debugfs constraint on userdebug build
...
Bug: 225815474
Test: build pass
Change-Id: If9e32d4b67c342b56eea39701518a520a62df199
2022-03-24 01:05:18 +00:00