Commit graph

1898 commits

Author SHA1 Message Date
Wilson Sung
2daec05481 Update error on ROM 9784808 am: 2b913d29a9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791801

Change-Id: I53f57effc548b312b1447a513d39c0cedc40510b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 07:43:23 +00:00
Wilson Sung
2b913d29a9 Update error on ROM 9784808
Bug: 274727778
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I56784948658365e8c9ecdf63d163109d8f29e5c3
2023-04-26 07:00:21 +00:00
Joseph Jang
1a82f277a8 Move recovery.te to device/google/gs-common/dauntless/sepolicy am: 2a5c26c9b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791802

Change-Id: If26d8b1d603af03114155180884efaaba2de27f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:52 +00:00
Joseph Jang
2a5c26c9b4 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: I80fbd9ef0c7e988de21d07ada57fc6a038b9b585
2023-04-24 08:05:10 +00:00
jimsun
5bdbb594be rild: allow rild to ptrace am: 0f6b14dc95
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21876774

Change-Id: I4ec24257f452e475272a9535e1dd21cecf94595a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:14 +00:00
jimsun
0f6b14dc95 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
b70e63a6de Update error on ROM 9954737 am: 4cc8eec22d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22696721

Change-Id: I21e6891828e09955d72558eb942578a13861cd8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-18 05:06:12 +00:00
Wilson Sung
4cc8eec22d Update error on ROM 9954737
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
be0ea597f0 Use restricted vendor property for ARM runtime options am: c1ee9afdef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22381562

Change-Id: If2ae2398fae5c8b39e51c2f2f47fb11a95b5b033
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:29:24 +00:00
Bruno BELANYI
c1ee9afdef Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00
Leo Liou
71068ddd6d gs201: add sepolicy for ufs_firmware_update process am: 5adecc7433
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22132666

Change-Id: I85257a9819bffd0b5a92d3ec1296fc161595a38f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 10:26:02 +00:00
Leo Liou
5adecc7433 gs201: add sepolicy for ufs_firmware_update process
Allow the script to access the specified partition and sysfs.

Bug: 273305212
Test: full build and test ffu flow
Change-Id: Iefeacea2d4c07e7a5b39713c9575e86bd25ce008
Signed-off-by: Leo Liou <leoliou@google.com>
2023-04-17 09:58:11 +00:00
kadirpili
3ec6b3f87c gs201: Allow GRIL Service to access radio_vendor_data_file am: 1af348b01f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22213304

Change-Id: Ibd5ad2e0a5875b642e7788823a83977d487c2aae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 06:15:48 +00:00
kadirpili
1af348b01f gs201: Allow GRIL Service to access radio_vendor_data_file
Bug: 274737512
Change-Id: I1c0b045f8a25c5d58be02c2036d2fcaad7d9a8e7
2023-04-14 06:57:50 +00:00
Xin Li
2540d05123 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours am: 551330137f -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I3e21b3af19e14ed50e8d714ffe6ddff1c1f0543e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:13:21 +00:00
Xin Li
551330137f [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Iefd6904aee50936e373590b4d54f492986aaf4dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:09 +00:00
Xin Li
ba5a2d3863 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I12f4ac63bb185203b115ae3f77ade5588bd50b10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:23:00 +00:00
Xin Li
4c44de9655 Merge TQ2A.230405.003 am: 8cff198ae3
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Ibeb863ad3557474eed5f5c8a529f12ed3c8c7768
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:58 +00:00
Minchan Kim
84a917c01c remove dump_gs201 sepolicy am: dc35b4158b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529799

Change-Id: Ibe6ea359df9c31166b616ebc0b488e27ecc74184
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 06:58:24 +00:00
Minchan Kim
d55660c311 move vendor_cma_debugfs into gs-common am: b7393fd8d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529798

Change-Id: I0a82d9378491a6fa0c785c96375b92d2dec3acd0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 06:58:18 +00:00
Minchan Kim
dc35b4158b remove dump_gs201 sepolicy
Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I39c01692d959a63c091f98969a69ab35b2debe1a
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Minchan Kim
b7393fd8d8 move vendor_cma_debugfs into gs-common
The CMA dump is common feature for pixel devices so move
it to gs-common.

Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I3997e27e3037f013338de5bc36687c63338769aa
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Tommy Kardach
3bbb950763 Update sepolicy for Camera HAL am: 3430e752af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22195719

Change-Id: Id716b3b93066f70536e0f89e25b89bc2566141a0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-11 20:28:17 +00:00
Tommy Kardach
3430e752af Update sepolicy for Camera HAL
Edit SE policay for WHI_PRO to allow
camera HAL to acquire wake locks

Bug: 249567788
Test: Flash and manual testing
Change-Id: I450b0b53000c5b9649e354350ec80af3528120fb
2023-04-11 19:45:33 +00:00
Xin Li
8cff198ae3 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I971732c6a40700a85df61170dcf1c3660307b96c
Change-Id: I33994bb345a46d8ac3f3a751fdff402f4ce5c68f
2023-04-10 23:55:29 -07:00
Adam Shih
00147ddada use dumpsate from gs-common am: 9519323a98
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524762

Change-Id: Ife90f52149915ad7bffc5e542c7507f774e279b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:23 +00:00
Wilson Sung
c2bace2e28 Update error on ROM 9890523 am: 4d92dd61f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524766

Change-Id: I8622af2b6d6bdee27a378a2e92efeaeb0125aa75
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:02 +00:00
Adam Shih
9519323a98 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: Ibd54c0049480810e2aa14074e0ec9c4d611d51ff
2023-04-10 01:11:14 +00:00
Wilson Sung
4d92dd61f2 Update error on ROM 9890523
Bug: 277155245
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iffbc691cff0e3a8d19ca3acef918cb4c1243feae
2023-04-07 07:07:40 +00:00
Victor Liu
1b1128bd55 uwb: add permission for ccc ranging am: 187dcc4e08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21965706

Change-Id: I56e876d5f45045d887be9d8812f72f8ad8dd50b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 21:29:19 +00:00
Victor Liu
187dcc4e08 uwb: add permission for ccc ranging
Bug: 255649425
Change-Id: I83ce369e52f382d76723b2b045e09607483a0a6a
2023-04-06 20:57:42 +00:00
Roy Luo
dabd899063 Support sending vendor command to GL852G via libusbhost am: 1f54dc7256
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22129755

Change-Id: Icc5b3e6ede7b2dc3de136b35a82dc6edca8e55e0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 02:23:09 +00:00
Roy Luo
1f54dc7256 Support sending vendor command to GL852G via libusbhost
libusbhost need access to USB device fs.

Bug: 261923350
Test: no audit log in logcat after command execution
Change-Id: I4b0c8cc750eff12d2494504f9f215d5b1bab35fd
2023-04-06 01:54:13 +00:00
feiyuchen
75b17801c5 Allow camera HAL to access edgetpu_app_service in gs201 am: 0161b6fbfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22462510

Change-Id: I9f030286a6e9633bd35dfa39920d8c594492eda7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-05 23:25:45 +00:00
feiyuchen
0161b6fbfa Allow camera HAL to access edgetpu_app_service in gs201
We are seeing SELinux error b/276911450. It turns out that I only added the SE policy for 2023 device ag/22248613, but I forgot to add it for gs101 and gs201. So I created this CL.

See more background in ag/22248613.

Test: For gs201, I tested on my Pixel7 and I saw no more error. For gs101, I just did mm.
Bug: 275016466
Bug: 276911450
Change-Id: I223770eb0bc7e09a5dfb4f4188b7fc605c3d1a61
2023-04-04 21:32:06 +00:00
Wilson Sung
6aa3aeaf9e Update SELinux error am: 33b2f0043c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22357289

Change-Id: I88e660fe6faa40577415334787a3115752896a60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-31 05:19:20 +00:00
Wilson Sung
33b2f0043c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 276386138
Bug: 276385494
Change-Id: Idcd05416ca84e0b47629637f8d3287a40d80a6ab
2023-03-31 10:55:21 +08:00
Adam Shih
1b78d6458a Move power dump out of hal_dumpstate_default am: 933e6a172b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22326747

Change-Id: Ia72529a82541d2824e4690d31f926a1d41e24183
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-30 18:25:50 +00:00
Adam Shih
933e6a172b Move power dump out of hal_dumpstate_default
Bug: 273380509
Test: adb bugreport
Change-Id: I0963af3f8f90b4f05724df31017b0d21d10c59ca
2023-03-30 02:20:37 +00:00
Wilson Sung
fda66eadf9 Update SELinux error am: bb30528185
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22323069

Change-Id: I09e03d3f246c3662b7b7c573522259705071681b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 07:06:42 +00:00
Wilson Sung
bb30528185 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275645892
Change-Id: Ib6aa5d2fe4a401cadc02a60b06725156f37aaccf
2023-03-29 10:49:39 +08:00
Adam Shih
5d152e53f0 create a dump for gs201 am: a334895789
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22308282

Change-Id: I6a9720fcf9532dc164c9b138c55030a12c08793a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 00:43:49 +00:00
Adam Shih
a334895789 create a dump for gs201
Bug: 273380509
Test: adb bugreport
Change-Id: Ic47e0d43d9a5aef4381880eabbba74633ee260a1
2023-03-28 12:52:52 +08:00
Adam Shih
b1d0b4878e use radio dump in gs-common am: 86faa5607c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22248646

Change-Id: Iaefd21e2a738481e474f14b8e5110a99ab866bfa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 06:28:16 +00:00
Adam Shih
86faa5607c use radio dump in gs-common
Bug: 273380509
Test: adb bugreport
Change-Id: I5e4318a427c0b503c47fb81ddb9e813fa9a41ab4
Merged-In: I5e4318a427c0b503c47fb81ddb9e813fa9a41ab4
2023-03-27 03:19:49 +00:00
Wilson Sung
da3cb0debc Update SELinux error am: dcc7112f6f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22244005

Change-Id: Icd2f241bd9aad1862a6a1aee0008194cf8876cb6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:16 +00:00
Wilson Sung
dcc7112f6f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275001783
Change-Id: I6514b7efbd02a5ddcb65ab329f0f01cc2d61e50a
2023-03-24 11:11:48 +08:00
Kris Chen
a5720137e4 Allow fingerprint hal to read sysfs_leds am: ba0b76de16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22175407

Change-Id: Iea5c36950b8b9584fb0a1b0e7c1e5f59828474c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 02:41:39 +00:00
Kris Chen
ba0b76de16 Allow fingerprint hal to read sysfs_leds
Fix the following avc denials:
avc: denied { search } for name="backlight" dev="sysfs" ino=79316
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=dir permissive=1

avc: denied { read } for name="state" dev="sysfs" ino=79365
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=file permissive=1

Bug: 271072126
Test: Authenticate fingerprint.
Change-Id: I9f346cb72ef660712b2bfb610df959667958c36a
2023-03-24 02:06:34 +00:00
Adam Shih
aa35944b12 use gs-common gps dump am: 1cdfdb4262
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22191063

Change-Id: I9395a66fb14873a919f00bb0a04f01756b774a8a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-23 02:56:31 +00:00