Commit graph

1384 commits

Author SHA1 Message Date
sukiliu
02b322b273 Update avc error on ROM 8388849 am: 97326bf38b am: 2f95d1ab49
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: Iaabe48e01ac0c5534a2f920ab6638f2ed8948243
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:49:55 +00:00
sukiliu
6be9cbeb9a Update avc error on ROM 8388849 am: 97326bf38b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: Ie3331c90cf0d2de60f38f694861e02ad1a8e6d5c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:36:44 +00:00
sukiliu
2f95d1ab49 Update avc error on ROM 8388849 am: 97326bf38b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: I3cd290900175d9c80bd5035b028ec5e8754e8167
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:35:58 +00:00
sukiliu
97326bf38b Update avc error on ROM 8388849
Bug: 221384939
Bug: 227694693
Bug: 227695036
Test: PtsSELinuxTestCases
Change-Id: I0768e29a0a162c6f568a5186602b01f1375a1ca5
2022-04-01 11:55:09 +08:00
Taesoon Park
22f957df9d Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 45d538c645 am: 2db00c7973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia0c18c33a6dcb21204413d11d1f40c31e1e9cbf6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:39:09 +00:00
Taesoon Park
b215763c9c Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 6409f46ba8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ifb8229ab57ffdb15420d92f6f24c116a13573379
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:10:00 +00:00
Taesoon Park
2db00c7973 Add permission to access vendor.ims property to vendor ims app am: 9211922e70 am: 45d538c645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ica4a2c64a99687a9aec0289d338c5c93a973d3b3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 02:09:36 +00:00
Taesoon Park
45d538c645 Add permission to access vendor.ims property to vendor ims app am: 9211922e70
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia3c34bb10d68af53a47e8939ffea389e6d57e542
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 01:45:59 +00:00
Taesoon Park
6409f46ba8 Add permission to access vendor.ims property to vendor ims app am: 9211922e70
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia93e4b9df47ac0e0cee17da277ba6c324cb0efab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 01:29:04 +00:00
Taesoon Park
9211922e70 Add permission to access vendor.ims property to vendor ims app
Vendor IMS Service read a SystemProperty starts with
persist.vendor.ims prefix, but it does not have a permission to
access it.
This change create a permission to access the SystemProperties start
with 'persist.vendor.ims.' prefix from vendor ims service.

Bug: 204714230
Test: Test results in b/225430461#comment40 enabling the property

Signed-off-by: Taesoon Park <ts89.park@samsung.com>
Change-Id: Ied50f377a3069eac65836ea999dfe021f4e4ed5d
2022-04-01 01:19:26 +00:00
chungkai
4deaf937b6 sched: move sysfs to procfs am: 2dc6f70afc am: a66699f706
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: Id4547d16ca3ae61f6191afa78253c0308894baa3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:43:54 +00:00
chungkai
ec14f07ee1 sched: move sysfs to procfs am: 2dc6f70afc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: I4910c36d52b42bd2e800890c34b19136587b4191
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:23:28 +00:00
chungkai
a66699f706 sched: move sysfs to procfs am: 2dc6f70afc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: I003de1eea466f47583c97b19a730a967dd9aa251
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:23:26 +00:00
chungkai
2dc6f70afc sched: move sysfs to procfs
Modify name from sysfs_vendor_sched to proc_vendor_sched

Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ieb829e96ac1db2a1aa28fc416182450d128cac5c
2022-03-31 07:00:20 +00:00
Ocean Chen
8557b1f255 sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0 am: 16f97b2c95
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: I10ef015dab9758032554bb829e2cbab1e3aa8e9f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:47:28 +00:00
Ocean Chen
7a2a70daeb sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: I17c3de914774d744b3b0d0e3000c96a840c1354b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:24:47 +00:00
Ocean Chen
16f97b2c95 sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: If726e1e96c5ca8052e7a22e577695c1ae1cabef5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:24:37 +00:00
Ocean Chen
b36cf348d0 sepolicy: add smart_idle_maint_enabled_prop for pixelstats
pixelstats get this sysprop hit the avc denied
persist.device_config.storage_native_boot.smart_idle_maint_enabled

pixelstats-vend: type=1400 audit(0.0:22): avc: denied { read }
for name="u:object_r:device_config_storage_native_boot_prop:s0"
dev="tmpfs" ino=171 scontext=u:r:pixelstats_vendor:s0
tcontext=u:object_r:device_config_storage_native_boot_prop:s0
tclass=file permissive=0

Bug: 215443809
Test: local build and run pixelstats

Signed-off-by: Ocean Chen <oceanchen@google.com>
Change-Id: Iedb4fa00c5e18cda6c799c3461bf8298bcf357eb
2022-03-31 03:02:47 +00:00
SalmaxChang
ab4d90eada hal_dumpstate_default: fix avc error am: 8e9be24a81 am: fbcc37b1d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500885

Change-Id: I898ee93a3507aa62b6eabe2c009839cd1083cbe1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:47:41 +00:00
sukiliu
9a5163a2ef Update avc error on ROM 8374246 am: 6379865b9d am: 35f673409a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474502

Change-Id: Ibb2008de7b5970e4ddc230fbf3e4cc550d6c4f07
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:47:34 +00:00
sukiliu
04a04c81f4 Update avc error on ROM 8378382 am: 3d3ae38c43 am: ff32951fe8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474499

Change-Id: I282a2652658fa6235add430447d230f57d2bb039
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:47:26 +00:00
SalmaxChang
85617f4e3b hal_dumpstate_default: fix avc error am: 8e9be24a81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500885

Change-Id: I2ace04d3dc6e7b52ab5160a98ba5ce9fd828e4aa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:43 +00:00
sukiliu
78df243bdc Update avc error on ROM 8374246 am: 6379865b9d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474502

Change-Id: I28555dc3f12ce0346fdb57727a41d6fb5ba61fd4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:21 +00:00
SalmaxChang
fbcc37b1d8 hal_dumpstate_default: fix avc error am: 8e9be24a81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500885

Change-Id: I26c00f6bbda92ca9d6de26889bf3778539b9906b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:12 +00:00
sukiliu
35f673409a Update avc error on ROM 8374246 am: 6379865b9d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474502

Change-Id: I999e0d343f0a6207c2a5e40b506164b8c287fb7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:06 +00:00
sukiliu
ff32951fe8 Update avc error on ROM 8378382 am: 3d3ae38c43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474499

Change-Id: I1ea88e1320e697551c5991b1e5c320da9de1581e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:01 +00:00
sukiliu
4575970f13 Update avc error on ROM 8378382 am: 3d3ae38c43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474499

Change-Id: Ifcf3b73b6e9e6462da6b68e65ab651628c83f2c6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:30:52 +00:00
SalmaxChang
8e9be24a81 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-42" ino=328 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 227424943
Change-Id: I44e2337129e814ed176ac270ae6c35e34089aa74
2022-03-31 02:15:19 +00:00
sukiliu
6379865b9d Update avc error on ROM 8374246
Bug: 227286343
Test: forrest with boot test
Change-Id: I44e32ac8d141dcb14c79ea4d8e78df3f88485dab
2022-03-31 02:14:40 +00:00
sukiliu
3d3ae38c43 Update avc error on ROM 8378382
Bug: 226850644
Test: PtsSELinuxTestCases
Change-Id: Ie6c6d8979dc63ebda7c699f10c2abb369a048ab0
2022-03-31 02:14:00 +00:00
Ray Chi
0bffd8e27e Revert "add sepolicy for set_usb_irq.sh" am: 3fdb24bdc1 am: 7fd923942a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17464004

Change-Id: I9c34d1b9e08d710f349906ecd5b5e31d9598f4e0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-30 05:18:11 +00:00
Ray Chi
7fd923942a Revert "add sepolicy for set_usb_irq.sh" am: 3fdb24bdc1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17464004

Change-Id: I4933c6dc9dd7af1daace0f1bcaf97106ba4700d2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-30 05:00:33 +00:00
Ray Chi
035c81b8df Revert "add sepolicy for set_usb_irq.sh" am: 3fdb24bdc1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17464004

Change-Id: I886d7f2afe80798d4166ee7a9edc7697bcf4c94e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-30 05:00:19 +00:00
Ray Chi
3fdb24bdc1 Revert "add sepolicy for set_usb_irq.sh"
This reverts commit 6733f9667d.

Bug: 225789036
Test: build pass
Change-Id: If43c8db71c737d509b1dfd098503f564a06bf046
2022-03-29 15:45:30 +08:00
Kris Chen
e9cd4bb590 Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7 am: 659f0ab560
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784

Change-Id: Ib1f08385f2b24a3371c5641ffa9e0bca9a36f1bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:07:21 +00:00
Kris Chen
659f0ab560 Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784

Change-Id: Iecf25951e071664241e33b73583af1fbe27b83f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:06:05 +00:00
Kris Chen
72403141aa Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784

Change-Id: Ib80d12143916976b7f9617773e1e2d0f95a84466
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:05:35 +00:00
Kris Chen
32f2e4b0e7 Allow hal_fingerprint_default to access sysfs_display
Fix the following avc denial:
avc: denied { read } for name="panel_name" dev="sysfs" ino=71133 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_display:s0 tclass=file permissive=0

Bug: 223687187
Test: build and test fingerprint on device.
Change-Id: Ief1ccc7e2fa6b8b4dc1ecbd6d446cc49ee3936ce
2022-03-29 01:39:32 +00:00
Minchan Kim
a401f8c5ce sepolicy: allow dump page_pinner am: 3496931400 am: 145aa1f2bd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608

Change-Id: I1e444e504418fa9a3eceb8cb24b7cb581f12513d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 17:24:18 +00:00
Minchan Kim
145aa1f2bd sepolicy: allow dump page_pinner am: 3496931400
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608

Change-Id: I77ebf664d28637f578151faef02c8bc7f4406a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 16:53:30 +00:00
Minchan Kim
56fb8cb807 sepolicy: allow dump page_pinner am: 3496931400
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608

Change-Id: Id4385572ff9f2fc059d351c817a764f5a4f0574d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 16:53:16 +00:00
Minchan Kim
3496931400 sepolicy: allow dump page_pinner
Provide necessary sepolicy for dumpreport to access page_pinner
information in /sys/kernel/debug/page_pinner/{longterm_pinner,
alloc_contig_failed}

Bug: 226956571
Test: Run "adb bugreport <zip>" and verify it contains the output
      from page_pinner.
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I7b00d4930fbaa2061537cd8c84616c1053c829cf
2022-03-28 16:35:02 +00:00
Adam Shih
1a3c271d6b update error on ROM 8365560 am: 5cc8837eb6 am: c94cff952d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798

Change-Id: I1a461593232938ad4729bc453e08e3cfe7024e7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:24:38 +00:00
Adam Shih
c94cff952d update error on ROM 8365560 am: 5cc8837eb6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798

Change-Id: I59263d45b9c7a57dc32ef7f5219afa81aec61c4b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:08:12 +00:00
Adam Shih
14f5e47200 update error on ROM 8365560 am: 5cc8837eb6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798

Change-Id: I97e7b5e9675b31b9379816fa8d3e0878af42b8f4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:07:59 +00:00
Adam Shih
5cc8837eb6 update error on ROM 8365560
Bug: 227121550
Bug: 227122249
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iab96c7644e6c99d700a5f7b42fba30032d3624b7
2022-03-28 10:59:04 +08:00
Omer Osman
734e18e250 Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937 am: afdb7f17b7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308

Change-Id: If4bd2041a3aafa36403e1d57407996337fed397f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:28:05 +00:00
Omer Osman
afdb7f17b7 Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308

Change-Id: Ia839f8717dc2a44d3bfd52077a471f6f301fc413
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:05:25 +00:00
Omer Osman
f79916c309 Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308

Change-Id: I05d2debd765c63b99ecf9c66d91782dbc842ca43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:05:20 +00:00
Omer Osman
e5cc5f7937 Add hidraw device and Dynamic Sensor SE Linux policy
Test: Incoming HID data from Pixel Buds

Change-Id: I77489100e13d892fb7d3a7cee9734de044795dec
2022-03-27 23:26:29 +00:00