Commit graph

540 commits

Author SHA1 Message Date
sukiliu
2f95d1ab49 Update avc error on ROM 8388849 am: 97326bf38b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17530928

Change-Id: I3cd290900175d9c80bd5035b028ec5e8754e8167
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 07:35:58 +00:00
sukiliu
97326bf38b Update avc error on ROM 8388849
Bug: 221384939
Bug: 227694693
Bug: 227695036
Test: PtsSELinuxTestCases
Change-Id: I0768e29a0a162c6f568a5186602b01f1375a1ca5
2022-04-01 11:55:09 +08:00
Taesoon Park
6409f46ba8 Add permission to access vendor.ims property to vendor ims app am: 9211922e70
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17465256

Change-Id: Ia93e4b9df47ac0e0cee17da277ba6c324cb0efab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-01 01:29:04 +00:00
Taesoon Park
9211922e70 Add permission to access vendor.ims property to vendor ims app
Vendor IMS Service read a SystemProperty starts with
persist.vendor.ims prefix, but it does not have a permission to
access it.
This change create a permission to access the SystemProperties start
with 'persist.vendor.ims.' prefix from vendor ims service.

Bug: 204714230
Test: Test results in b/225430461#comment40 enabling the property

Signed-off-by: Taesoon Park <ts89.park@samsung.com>
Change-Id: Ied50f377a3069eac65836ea999dfe021f4e4ed5d
2022-04-01 01:19:26 +00:00
chungkai
a66699f706 sched: move sysfs to procfs am: 2dc6f70afc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500884

Change-Id: I003de1eea466f47583c97b19a730a967dd9aa251
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 07:23:26 +00:00
chungkai
2dc6f70afc sched: move sysfs to procfs
Modify name from sysfs_vendor_sched to proc_vendor_sched

Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ieb829e96ac1db2a1aa28fc416182450d128cac5c
2022-03-31 07:00:20 +00:00
Ocean Chen
16f97b2c95 sepolicy: add smart_idle_maint_enabled_prop for pixelstats am: b36cf348d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17149390

Change-Id: If726e1e96c5ca8052e7a22e577695c1ae1cabef5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 03:24:37 +00:00
Ocean Chen
b36cf348d0 sepolicy: add smart_idle_maint_enabled_prop for pixelstats
pixelstats get this sysprop hit the avc denied
persist.device_config.storage_native_boot.smart_idle_maint_enabled

pixelstats-vend: type=1400 audit(0.0:22): avc: denied { read }
for name="u:object_r:device_config_storage_native_boot_prop:s0"
dev="tmpfs" ino=171 scontext=u:r:pixelstats_vendor:s0
tcontext=u:object_r:device_config_storage_native_boot_prop:s0
tclass=file permissive=0

Bug: 215443809
Test: local build and run pixelstats

Signed-off-by: Ocean Chen <oceanchen@google.com>
Change-Id: Iedb4fa00c5e18cda6c799c3461bf8298bcf357eb
2022-03-31 03:02:47 +00:00
SalmaxChang
fbcc37b1d8 hal_dumpstate_default: fix avc error am: 8e9be24a81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17500885

Change-Id: I26c00f6bbda92ca9d6de26889bf3778539b9906b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:12 +00:00
sukiliu
35f673409a Update avc error on ROM 8374246 am: 6379865b9d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474502

Change-Id: I999e0d343f0a6207c2a5e40b506164b8c287fb7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:06 +00:00
sukiliu
ff32951fe8 Update avc error on ROM 8378382 am: 3d3ae38c43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17474499

Change-Id: I1ea88e1320e697551c5991b1e5c320da9de1581e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-31 02:31:01 +00:00
SalmaxChang
8e9be24a81 hal_dumpstate_default: fix avc error
avc: denied { search } for comm="dumpstate@1.1-s" name="modem_stat" dev="dm-42" ino=328 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:modem_stat_data_file:s0 tclass=dir

Bug: 227424943
Change-Id: I44e2337129e814ed176ac270ae6c35e34089aa74
2022-03-31 02:15:19 +00:00
sukiliu
6379865b9d Update avc error on ROM 8374246
Bug: 227286343
Test: forrest with boot test
Change-Id: I44e32ac8d141dcb14c79ea4d8e78df3f88485dab
2022-03-31 02:14:40 +00:00
sukiliu
3d3ae38c43 Update avc error on ROM 8378382
Bug: 226850644
Test: PtsSELinuxTestCases
Change-Id: Ie6c6d8979dc63ebda7c699f10c2abb369a048ab0
2022-03-31 02:14:00 +00:00
Ray Chi
7fd923942a Revert "add sepolicy for set_usb_irq.sh" am: 3fdb24bdc1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17464004

Change-Id: I4933c6dc9dd7af1daace0f1bcaf97106ba4700d2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-30 05:00:33 +00:00
Ray Chi
3fdb24bdc1 Revert "add sepolicy for set_usb_irq.sh"
This reverts commit 6733f9667d.

Bug: 225789036
Test: build pass
Change-Id: If43c8db71c737d509b1dfd098503f564a06bf046
2022-03-29 15:45:30 +08:00
Kris Chen
659f0ab560 Allow hal_fingerprint_default to access sysfs_display am: 32f2e4b0e7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395784

Change-Id: Iecf25951e071664241e33b73583af1fbe27b83f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-29 02:06:05 +00:00
Kris Chen
32f2e4b0e7 Allow hal_fingerprint_default to access sysfs_display
Fix the following avc denial:
avc: denied { read } for name="panel_name" dev="sysfs" ino=71133 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_display:s0 tclass=file permissive=0

Bug: 223687187
Test: build and test fingerprint on device.
Change-Id: Ief1ccc7e2fa6b8b4dc1ecbd6d446cc49ee3936ce
2022-03-29 01:39:32 +00:00
Minchan Kim
145aa1f2bd sepolicy: allow dump page_pinner am: 3496931400
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17410608

Change-Id: I77ebf664d28637f578151faef02c8bc7f4406a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 16:53:30 +00:00
Minchan Kim
3496931400 sepolicy: allow dump page_pinner
Provide necessary sepolicy for dumpreport to access page_pinner
information in /sys/kernel/debug/page_pinner/{longterm_pinner,
alloc_contig_failed}

Bug: 226956571
Test: Run "adb bugreport <zip>" and verify it contains the output
      from page_pinner.
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I7b00d4930fbaa2061537cd8c84616c1053c829cf
2022-03-28 16:35:02 +00:00
Adam Shih
c94cff952d update error on ROM 8365560 am: 5cc8837eb6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17395798

Change-Id: I59263d45b9c7a57dc32ef7f5219afa81aec61c4b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 05:08:12 +00:00
Adam Shih
5cc8837eb6 update error on ROM 8365560
Bug: 227121550
Bug: 227122249
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iab96c7644e6c99d700a5f7b42fba30032d3624b7
2022-03-28 10:59:04 +08:00
Omer Osman
afdb7f17b7 Add hidraw device and Dynamic Sensor SE Linux policy am: e5cc5f7937
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17286308

Change-Id: Ia839f8717dc2a44d3bfd52077a471f6f301fc413
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-28 02:05:25 +00:00
Omer Osman
e5cc5f7937 Add hidraw device and Dynamic Sensor SE Linux policy
Test: Incoming HID data from Pixel Buds

Change-Id: I77489100e13d892fb7d3a7cee9734de044795dec
2022-03-27 23:26:29 +00:00
Lucas Wei
793e41d11d Label vendor_kernel_boot with boot_block_device for OTA updating am: ab9ec22267
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291643

Change-Id: I7228a6bdb0b5c931f0fc06a3b38d67d7666e0a3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 09:11:27 +00:00
Lucas Wei
ab9ec22267 Label vendor_kernel_boot with boot_block_device for OTA updating
Label with boot_block_device to allow further operations on
vendor_kernel_boot including OTA updating.

This is required for update_engine to be able to write to
vendor_kernel_boot on builds that are enforcing sepolicy.

Bug: 214409109
Signed-off-by: Lucas Wei <lucaswei@google.com>
Change-Id: If239690ee168ecfd5c5b755451e389a4523c79b8
2022-03-25 08:55:00 +00:00
Darren Hsu
9d05616fa8 Allow hal_power_stats to read sysfs_aoc_dumpstate am: 85710448f3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17351092

Change-Id: I6913af827f44b7098c26ffd9f56d1e7f98c36d7c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 07:19:16 +00:00
Darren Hsu
85710448f3 Allow hal_power_stats to read sysfs_aoc_dumpstate
avc: denied { read } for comm="android.hardwar" name="restart_count"
dev="sysfs" ino=72823 scontext=u:r:hal_power_stats_default:s0
tcontext=u:object_r:sysfs_aoc_dumpstate:s0 tclass=file permissive=0

Bug: 226173008
Test: check bugreport without avc denials
Change-Id: I35d886dd05fdad821e38810fd848c7f451893e3f
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-03-25 06:59:34 +00:00
Ted Lin
9c59b398db Remove the tracking for vendor_battery_defender am: 4b75aab4b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342324

Change-Id: If643013008f26e6c890d9a43f2d7c4ef177eac68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 02:02:52 +00:00
Ted Lin
4b75aab4b8 Remove the tracking for vendor_battery_defender
The function is disabled.

Bug: 221384939
Test: adb bugreport
Change-Id: If8e8b8165329eb9ede86cb62f419a8cf06abb536
Signed-off-by: Ted Lin <tedlin@google.com>
2022-03-25 01:37:03 +00:00
Chris Kuiper
f5453f84aa Add rules to allow Sensor HAL write access to als_table am: 967571ee60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888

Change-Id: I8ddfebc5b8febe09cb48cb58f7f2ed9ee74386d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:21:03 +00:00
Chris Kuiper
967571ee60 Add rules to allow Sensor HAL write access to als_table
Sensor HAL needs write access to
/sys/class/backlight/panel0-backlight/als_table.

Bug: 226435017
Test: Observing logs
Change-Id: Idb592d601b92c6814493e0d28384e1013935b72f
2022-03-25 00:00:19 +00:00
chungkai
9bff8c59b6 sched: move sysfs to procfs am: 4fa67857c3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963

Change-Id: Ib855e5bdf15d24defa55f3b548144fd31ed96ecb
2022-03-24 18:16:44 +00:00
chungkai
4fa67857c3 sched: move sysfs to procfs
Modify name from sysfs_vendor_sched to proc_vendor_sched

Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I96dc6eb76dd533ff6fd54c27be7e4bc32bf5dbc7
2022-03-24 17:44:37 +00:00
Holmes Chou
15a914dbc1 camera: use codename for camera modules am: e0b06b9cbd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590

Change-Id: Ibb0e4a61baff6e2d9e405afdb29494a0263e1559
2022-03-24 13:38:18 +00:00
Holmes Chou
e0b06b9cbd camera: use codename for camera modules
use codename for camera modules
Bug: 209866857
Test: GCA, adb logcat

Change-Id: I55f6998d18a904c83ecdf328d1b0e5ca6a01427f
2022-03-24 13:11:16 +00:00
Ted Lin
213dd940ff hal_health_default: Fix avc denials am: 0adad90ab6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323

Change-Id: I8f57a0ab56e2d11109c6a65084983499ab1bd787
2022-03-24 05:53:09 +00:00
Ted Lin
0adad90ab6 hal_health_default: Fix avc denials
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2270): avc: denied { search } for name="thermal" dev="tmpfs" ino=1028 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2271): avc: denied { search } for name="thermal" dev="sysfs" ino=16790 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=dir permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2273): avc: denied { open } for path="/sys/devices/virtual/thermal/thermal_zone13/mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2272): avc: denied { write } for name="mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1

Bug:208721638
Test: adb bugreport
Change-Id: I4d9491862ff1bcc88f89b1478497ac569e3d1df1
Signed-off-by: Ted Lin <tedlin@google.com>
(cherry picked from commit 5b6a5292c3)
2022-03-24 05:26:09 +00:00
Adam Shih
fcae230ef4 enforce debugfs constraint on userdebug build am: de2696eb72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326

Change-Id: I2008bde5b787053f818a58452f629e5bee8e8ced
2022-03-24 04:12:13 +00:00
Adam Shih
de2696eb72 enforce debugfs constraint on userdebug build
Bug: 225815474
Test: build pass
Change-Id: If9e32d4b67c342b56eea39701518a520a62df199
2022-03-24 01:05:18 +00:00
Yabin Cui
f387f3dcd3 Add SOC specific ETM sysfs paths am: 02c1ef8b85
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17324045

Change-Id: I0e5889c043eaea6827d91423c3adfc14073ea289
2022-03-23 20:07:38 +00:00
Yabin Cui
02c1ef8b85 Add SOC specific ETM sysfs paths
Bug: 225403280
Test: run profcollectd on c10
Change-Id: I10c8d250cf88b371ee573561d6678fc24f4e440c
Merged-In: I10c8d250cf88b371ee573561d6678fc24f4e440c
2022-03-23 19:45:48 +00:00
George Lee
8e5d012c72 health: Grant sysfs_thermal access to health am: 17981f9fc0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17312309

Change-Id: I88cc6908a9d5062b815f077b8e6c9cb38067d1ce
2022-03-23 05:33:21 +00:00
SalmaxChang
13a0910c39 modem_svc_sit: fix avc error am: ae6f085676
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17314904

Change-Id: I3ae7e26013ec250818fee64adedf5e0b568e50c7
2022-03-23 05:33:06 +00:00
SalmaxChang
a40641f2da vendor_init: fix avc error am: 6dd3de7813
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291644

Change-Id: I58b4e5d1a0bf09666a0f852f2567605ca021cc1a
2022-03-23 05:33:01 +00:00
George Lee
17981f9fc0 health: Grant sysfs_thermal access to health
health-service has trouble accessing /dev/thermal.  This change fixes
this.

Bug: 226009696
Test: dev/thermal/tz-by-name/soc/mode error:Permission denied no longer
exist
Signed-off-by: George Lee <geolee@google.com>
Change-Id: I8d112cb12f3aeb1c8d5433ca69415d0413f070a2
Merged-In: I4d9491862ff1bcc88f89b1478497ac569e3d1df1
2022-03-23 05:30:33 +00:00
SalmaxChang
ae6f085676 modem_svc_sit: fix avc error
avc: denied { write } for comm="modem_svc_sit" name="modem_stat" dev="dm-46" ino=333 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 225149029
Change-Id: Id1045d9488a200b6c64abbe02cf5e65926ba0203
2022-03-23 05:13:29 +00:00
SalmaxChang
6dd3de7813 vendor_init: fix avc error
avc: denied { getattr } for comm="init" name="/" dev="sda19" ino=2 scontext=u:r:vendor_init:s0 tcontext=u:object_r:modem_img_file:s0 tclass=filesystem permissive=0

Bug: 225151104
Change-Id: I508aa6b85039edc4b5a8746aaa602f1131768630
2022-03-22 07:57:59 +00:00
Kris Chen
3d1c17ffd7 Allow hal_fingerprint_default to access fwk_sensor_hwservice am: 997b8974ef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17288686

Change-Id: If57f3542180e8e0af17351c50415a8bab57306e5
2022-03-22 03:59:58 +00:00
Kris Chen
997b8974ef Allow hal_fingerprint_default to access fwk_sensor_hwservice
Fix the following avc denial:
avc:  denied  { find } for interface=android.frameworks.sensorservice::ISensorManager sid=u:r:hal_fingerprint_default:s0 pid=1258 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:fwk_sensor_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 197789721
Test: build and test fingerprint on device.
Change-Id: I7494f28e69e5a1b660dc7fbaa528b1088048723b
(cherry picked from commit 9b54bf3665abce7a6f5f5df22069a8ef081ad80e)
2022-03-22 03:39:35 +00:00