Commit graph

1384 commits

Author SHA1 Message Date
Automerger Merge Worker
8b8d1c2c99 Merge "Allow mediacodec to access vendor_data_file am: 95845654bf am: 65993e19e8" into tm-d1-dev-plus-aosp am: 032ce42cd3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I2c2e39227d27754d7fd6813ada3f12842f9e4c6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:55:53 +00:00
Austin Wang
bf00994e42 Add P22 reverse wireless charging selinux policy am: e5f8377849 am: 53a167fcf0 am: 84ae81f114
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: I8bc0600b651e2a8d511f84ccd6a4cf1a376fd5f0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:51:07 +00:00
Jerry Huang
a1b11f5923 Allow mediacodec to access vendor_data_file am: 95845654bf am: dafeb57668 am: b9d25e06d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I54099be73c1a1f09df00edf8da3e6720e434e5b2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:51:03 +00:00
Jerry Huang
c9ee2df4d2 Allow mediacodec to access vendor_data_file am: 95845654bf am: dafeb57668 am: 29d8fcfa03
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I6422be602be4eef77ccfda29268cd681672b0c09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:50:46 +00:00
Austin Wang
591c086349 Add P22 reverse wireless charging selinux policy am: e5f8377849 am: 9ff2dc972a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: Ia4230c417087921de03a2239b5ff33408efd3283
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:46:47 +00:00
Jerry Huang
41fcd92bf1 Allow mediacodec to access vendor_data_file am: 95845654bf am: 33065ab679
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: Ied63122e6f9fa8de86a95aae8eeeb25fbd52f9d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:46:39 +00:00
Austin Wang
f2336f95c4 Add P22 reverse wireless charging selinux policy am: e5f8377849 am: 46d2740350
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: Ic2fed4e290d198298ad28a7a74112df4b73e1c89
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:40:14 +00:00
Austin Wang
eb52e384fc Add P22 reverse wireless charging selinux policy am: e5f8377849 am: 53a167fcf0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: I950f1f224cd77942d3718d040f3dce41dfc157b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:59 +00:00
Austin Wang
84ae81f114 Add P22 reverse wireless charging selinux policy am: e5f8377849 am: 53a167fcf0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: I228618e35faf413867c6d4f6c6b1222ce8185aa1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:55 +00:00
Automerger Merge Worker
032ce42cd3 Merge "Allow mediacodec to access vendor_data_file am: 95845654bf am: 65993e19e8" into tm-d1-dev-plus-aosp 2022-05-13 10:39:55 +00:00
Jerry Huang
b9d25e06d8 Allow mediacodec to access vendor_data_file am: 95845654bf am: dafeb57668
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: Id370dfbcc5081e085db3844edd7893ab1aa8b031
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:52 +00:00
Jerry Huang
d217f9119f Allow mediacodec to access vendor_data_file am: 95845654bf am: 65993e19e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I783c7a21ff21f490367777f05db80ea23fe4228a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:51 +00:00
Jerry Huang
29d8fcfa03 Allow mediacodec to access vendor_data_file am: 95845654bf am: dafeb57668
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I0b8c09ea5d2396af808728f468482c05bf2e3ffa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:39:49 +00:00
Nishok Kumar S
cae3a0b2a2 Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93 am: ebb393aac0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: Iee7200e1ce9aaee50bd362cfe3e7470df063e3ca
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:38:14 +00:00
Nishok Kumar S
00ce8ef6c0 Label GCA-Eng app am: 4a6cfb5a9c am: f021ddaf55
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I35a10ea14256cb4a2bf0fd66258f913430a99674
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:38:13 +00:00
Nishok Kumar S
dd9262e2ca Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93 am: b4db422486
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: I9d563cbffa56704441ba57c0b8926f13cc86a79e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:37:56 +00:00
Nishok Kumar S
52f975bec0 Label GCA-Eng app am: 4a6cfb5a9c am: a96da52aca
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I636721df2d3b17c04d7ebcdb84178a3c6f1ebc00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:37:55 +00:00
Austin Wang
53a167fcf0 Add P22 reverse wireless charging selinux policy am: e5f8377849
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: I92b12dd3c05b50244e3c67667ba2296fcf62fd1a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:49:54 +00:00
Jerry Huang
dafeb57668 Allow mediacodec to access vendor_data_file am: 95845654bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I4fd8e3a631a441dfedf06300f5f619706f7b75c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:49:28 +00:00
Austin Wang
46d2740350 Add P22 reverse wireless charging selinux policy am: e5f8377849
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: Ic38aa173a3363c726149086343ea53903e04c235
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:48:22 +00:00
Jerry Huang
65993e19e8 Allow mediacodec to access vendor_data_file am: 95845654bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: Ieb6ddf76f46e735e1a89c85c7221863bbe61bef9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:47:44 +00:00
Austin Wang
9ff2dc972a Add P22 reverse wireless charging selinux policy am: e5f8377849
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18350566

Change-Id: I2ca2dca14d150aa5cdd05ab077001781723521d7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:47:31 +00:00
Jerry Huang
33065ab679 Allow mediacodec to access vendor_data_file am: 95845654bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188091

Change-Id: I55afdf2c20cc151b40c3346512b48e10c31cc1d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:47:16 +00:00
Nishok Kumar S
b4db422486 Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: Ifd964c84766eb6cbeccf47816c6633bdb0f28d36
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:45 +00:00
Nishok Kumar S
a96da52aca Label GCA-Eng app am: 4a6cfb5a9c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I539f9e1904b074f5fbf22ef52874ba0da5e6e082
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:44 +00:00
Nishok Kumar S
ebb393aac0 Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: I72867e1f8262f1868e231ef5bbd43fc154853360
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:37 +00:00
Nishok Kumar S
f021ddaf55 Label GCA-Eng app am: 4a6cfb5a9c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I22f1a5efcc4263ae03165effa7f69e0f09f196a5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:36 +00:00
Austin Wang
e5f8377849 Add P22 reverse wireless charging selinux policy
Allow Settings to call hal_wlc

Error:

05-13 09:28:20.508  1000  7293  7293 W ndroid.settings: type=1400 audit(0.0:29): avc: denied { call } for scontext=u:r:system_app:s0 tcontext=u:r:hal_wlc:s0 tclass=binder permissive=0

Bug: 231420451
Test: Enable battery share from settings and charge another device.
Change-Id: Ic761bee47ea41f6db8b1838fb3fc2a9f7ef7bb5c
2022-05-13 09:28:03 +00:00
Jerry Huang
95845654bf Allow mediacodec to access vendor_data_file
For dumping output buffer of HDR to SDR fliter.

This patch fixes the following denial:

05-10 21:42:49.427   890   890 W HwBinder:890_4: type=1400 audit(0.0:2944): avc: denied { search } for name="data" dev="dm-41" ino=105 scontext=u:r:mediacodec_samsung:s0 tcontext=u:object_r:system_data_file:s0:c512,c768 tclass=dir permissive=0

05-10 21:42:49.499   890   890 W HwBinder:890_4: type=1400 audit(0.0:2946): avc: denied { getattr } for name="/" dev="dmabuf" ino=1 scontext=u:r:mediacodec_samsung:s0 tcontext=u:object_r:unlabeled:s0 tclass=filesystem permissive=0

05-10 21:46:27.735   885   885 W google.hardware: type=1400 audit(0.0:3198): avc: denied { search } for name="data" dev="dm-41" ino=105 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:system_data_file:s0:c512,c768 tclass=dir permissive=0

05-10 21:46:27.795   885   885 W google.hardware: type=1400 audit(0.0:3200): avc: denied { getattr } for name="/" dev="dmabuf" ino=1 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:unlabeled:s0 tclass=filesystem permissive=0

Bug: 229360116
Test: atest android.media.decoder.cts.DecoderTest
Change-Id: I11403b20e8608f50907db561b8232b1b64bea298
2022-05-13 09:24:38 +00:00
Nishok Kumar S
145f7b5b93 Use google_camera_app label for GCA-Next fishfood app.
Bug: 230773733
Test: Build selinux and test with GCA-Next on device.
Change-Id: I757e7de2293e25bd027262a5fbf4ece2a44f10d1
2022-05-13 05:31:34 +00:00
Nishok Kumar S
4a6cfb5a9c Label GCA-Eng app
- Add policies for GCA-Eng to access GXP device.
 - Allow GCA-Eng to access edgetpu service.

Test: Build selinux and test GCA-Eng on device with
      adb shell setprop camera.artemis_dsp TRUE

Bug: 230773733
Change-Id: I8d04f6e1aef0899b3862ddbb80174cd086156d92
2022-05-13 05:18:09 +00:00
Krzysztof Kosiński
26b2d2e33e Add dontaudit statements to camera HAL policy.
The autogenerated dontaudit statements in tracking_denials are
actually the correct policy. Move them to the correct file and
add comments.

Bug: 205780065
Bug: 218585004
Test: build & camera check
Change-Id: Ie0338f0d2a6fd0c589777a82c22a014e462bd5c2
2022-05-10 05:36:53 +00:00
Asad Abbas Ali
417f7069c4 Allow chre to communicate with fwk_stats_service. am: 7f89d68af2 am: 300c77c7ad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18184949

Change-Id: I77f7121aba052409891cf9635f829cd9c66705e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 18:43:02 +00:00
Asad Abbas Ali
300c77c7ad Allow chre to communicate with fwk_stats_service. am: 7f89d68af2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18184949

Change-Id: Ia9cd87ac7d913dea52176a4d894fd043c98f55ed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 16:30:32 +00:00
Asad Abbas Ali
7f89d68af2 Allow chre to communicate with fwk_stats_service.
Bug: 230788686
Test: Logged atoms using CHRE + log atom extension.
Change-Id: I45a207996a28bbe61bbfd4288eaf28e2257cdf52
2022-05-06 16:15:06 +00:00
George Chang
eb1d4ec87c Update nfc from hidl to aidl service
Bug: 216290344
Test: atest NfcNciInstrumentationTests
Test: atest VtsAidlHalNfcTargetTest
Change-Id: If1f57af334033f9bd7174c052767715c9916700f
2022-05-06 08:50:35 +00:00
eddielan
4a8b5a4e01 sepolicy: Add SW35 HIDL factory service into sepolicy am: aeb9bd0406 am: 975157ae00
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188088

Change-Id: I21ebf2a1fa936efaf92a1ef22e5518007734b0d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 07:09:51 +00:00
eddielan
975157ae00 sepolicy: Add SW35 HIDL factory service into sepolicy am: aeb9bd0406
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188088

Change-Id: Idce850a2c0c0b7a79257cad6dd7eaadcca9dcfb6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 06:47:22 +00:00
eddielan
aeb9bd0406 sepolicy: Add SW35 HIDL factory service into sepolicy
Bug: 231549391
Test: Build Pass
Change-Id: If5c1bc5ddf6a1fa753ac65b6b4c5983775f2f704
2022-05-06 12:22:59 +08:00
Kris Chen
22214473d8 Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: 2f711e875f am: ab4d1f19cc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I817e2983da5eeb4eac8e2d349d3e36ada0cd6f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 04:35:19 +00:00
Kris Chen
ce72c2890c Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: c789f02906 am: ae663f1618
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I97bfe9b1d3dd7998fc1fd63ada9f78aa36a3f9c6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 04:34:42 +00:00
Kris Chen
ab4d1f19cc Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: 2f711e875f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I37c2d3103f3fb2c5290381c244ad552731e51924
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 03:25:03 +00:00
Kris Chen
ae663f1618 Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: c789f02906
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I17e19556c41528d6f1eb2ed096cf5c34ed41aa5a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 03:24:46 +00:00
Kris Chen
2f711e875f Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I43f89e4465035e5f5aa2797007d419ae1d2040c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:35:13 +00:00
Kris Chen
c789f02906 Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I674cb3dd987a1d94c8412d028f880bdac04c00ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:35:10 +00:00
Kris Chen
3162407210 Allow hal_fingerprint_default to access hal_pixel_display_service
Fix the following avc denial:
avc: denied { find } for pid=1158 uid=1000 name=com.google.hardware.pixel.display.IDisplay/default scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:hal_pixel_display_service:s0 tclass=service_manager permissive=0
avc: denied { call } for scontext=u:r:hal_fingerprint_default:s0 tcontext=u:r:hal_graphics_composer_default:s0 tclass=binder permissive=0

Bug: 229716695
Bug: 224573604
Test: build and test fingerprint on device
Change-Id: I104af7f50715090fe0c2aa6845848bf77ab3e3ae
2022-05-05 02:03:43 +00:00
Jenny Ho
7e6ad9c3d3 sepolicy: allow access debugfs charger register dump am: 5e426a95d0 am: f9e379b88a am: e1578b6a4d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: I9c7464b36192f0e772a0f5f1a97c66e828969cfc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-04 00:52:55 +00:00
Labib
f631ddd9e0 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8 am: 77af035a89 am: 709dfed23a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: Id4d8cb6c1439ad29af2f4151dbf12867d6aeefe9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-04 00:51:14 +00:00
Jenny Ho
e1578b6a4d sepolicy: allow access debugfs charger register dump am: 5e426a95d0 am: f9e379b88a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ifea2b1ad0d2cb9eb86216a271c49bd9b03909cce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 17:51:32 +00:00
Labib
709dfed23a Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8 am: 77af035a89
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I459e4e2cc235010bca74581b4a01769f77d83609
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 17:51:22 +00:00