Commit graph

744 commits

Author SHA1 Message Date
chiayupei
8686077cf1 hal_sensors_default: Allow sensors HAL to access AoC sysfs and properties. am: eaeec28c23
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17799083

Change-Id: Iafe48b445d456eef6fbf98ed4ed7c3550a3a260d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 02:16:32 +00:00
chiayupei
eaeec28c23 hal_sensors_default: Allow sensors HAL to access AoC sysfs and properties.
Bug: 202901227
Test: Verify pass by checking device log.

Signed-off-by: chiayupei <chiayupei@google.com>
Change-Id: I67e0fcc4ad89ff3c1945f6fdd83d01f14fcdcbec
2022-04-19 01:57:08 +00:00
Alex Hong
572c9385f2 Update the SELinux context for dumpstate HAL service am: 09ef2e08c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699359

Change-Id: Ib383ca5b7ddfa353b83d89faeea0c7db986760e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:51:12 +00:00
Alex Hong
09ef2e08c5 Update the SELinux context for dumpstate HAL service
Test: atest VtsHalDumpstateTargetTest pass
Bug: 223118410
Change-Id: Ie237579f974bab8bf8d35211367457be178a262b
2022-04-18 07:45:28 +00:00
Jerry Huang
14fa939e02 Allow mediacodec_google to access gpu_device am: 9bc45b2d60 am: 907fa780c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: Ia9cf89db957fbcbe2c5fdd508c21ea91b71fba39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:42:04 +00:00
Jerry Huang
907fa780c6 Allow mediacodec_google to access gpu_device am: 9bc45b2d60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: I4dc3946a1ac18c1c1b88c4c9dbf9baa6612d7cfd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:20:30 +00:00
Jerry Huang
9bc45b2d60 Allow mediacodec_google to access gpu_device
Bug: 228794372
Test: android.media.decoder.cts.DecoderTest#testAV1HdrToSdr

The change is for following error:
04-08 17:02:44.020  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70491): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.028  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70492): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.040  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70493): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.048  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70494): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0

Change-Id: Ie22903807fcc12d931cbdd36678ae1d4a3776a3d
2022-04-18 13:34:04 +08:00
sukiliu
9b19670fde Update avc error on ROM 8459635 am: aa794b4e43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764697

Change-Id: I45ef7c52bfc599f9e9f303d91848f12af491ff83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 01:22:54 +00:00
sukiliu
aa794b4e43 Update avc error on ROM 8459635
Bug: 229354991
Test: PtsSELinuxTestCases
Change-Id: I6b5d7d5b1368021bd927dedf786081c600289974
2022-04-18 01:05:57 +00:00
Joshua McCloskey
e3492d9b53 Allow platform apps to access FP Hal am: 2dc0bbd55b am: 93f0eac9b7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: Icd927343b5116c882505d1c773b8166b8fc1af2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:40:01 +00:00
Joshua McCloskey
93f0eac9b7 Allow platform apps to access FP Hal am: 2dc0bbd55b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: I7be27da8b3ee59516612c3f71804ca6799c047f2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:13:03 +00:00
Joshua McCloskey
2dc0bbd55b Allow platform apps to access FP Hal
Bug: 227247855
Test: Verified manually that the fingerprint extension is working.
Change-Id: Id5550ca770942d02ad0796ed0d4e8584c434b680
2022-04-15 21:39:58 +00:00
Oleg Matcovschi
cddeaf3f73 selinux: remove dpm_[ab] from custom_ab_block_device's am: a79b98eb25
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764346

Change-Id: I048cca075f5c22dd518b9ab9da288f5318570945
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 19:54:27 +00:00
Oleg Matcovschi
a79b98eb25 selinux: remove dpm_[ab] from custom_ab_block_device's
Signed-off-by: Oleg Matcovschi <omatcovschi@google.com>
Change-Id: I774065f331b1f2970b0fee5a41faa097fa88caf8
2022-04-15 19:08:17 +00:00
chungkai
96e63091b4 sepolicy: fix avc denials am: d80900ae17 am: efb75b5ced
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: Ie80951fd60033081bda78a7cdb327ff0a7f5fe5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 07:01:26 +00:00
chungkai
efb75b5ced sepolicy: fix avc denials am: d80900ae17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I13bbf5aaa37f0855cce70a0ef06ac50fc1ad9006
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 06:39:45 +00:00
chungkai
d80900ae17 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 228947596
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I2e9fa011c049e32011c5880218dd679e03316e24
2022-04-15 02:56:55 +00:00
chungkai
56b70920b6 sepolicy: fix avc denials am: d37777dd33 am: 49e28ad8c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I0f1e5b791a88ab62c3432307b6ea12f8e2165264
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:21:37 +00:00
Harpreet Eli Sangha
9ec5f1f14f Add CccDkTimeSyncService for Digital Key Support am: 1a0b0ce0c4 am: a7eb4ce4f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755764

Change-Id: I5f488b8c72afa86fabea4ac23e6fe6f87ce0b3d2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:21:29 +00:00
sukiliu
24a55545cc Update avc error on ROM 8453400 am: 81d9623cbe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755772

Change-Id: I8173752a333d620cba87995bda69117903496671
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:21:11 +00:00
chungkai
49e28ad8c1 sepolicy: fix avc denials am: d37777dd33
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I59b89c687d44c371fed1e83d2a8bce057bb88179
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:07:33 +00:00
chungkai
d37777dd33 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 226887726
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: If2ac4c137c1ea074907c363424e6018a5fd646e8
2022-04-15 01:01:47 +00:00
Harpreet Eli Sangha
a7eb4ce4f2 Add CccDkTimeSyncService for Digital Key Support am: 1a0b0ce0c4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755764

Change-Id: If10fb742322ba2bb732bd222990b00e712d00c54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:00:36 +00:00
sukiliu
81d9623cbe Update avc error on ROM 8453400
Bug: 229209076
Test: PtsSELinuxTestCases
Change-Id: I05f06fe0d62cbfbd4783ba9c57dea7d7a7a35fca
2022-04-15 00:52:48 +00:00
Harpreet Eli Sangha
1a0b0ce0c4 Add CccDkTimeSyncService for Digital Key Support
Test: Build and Run
Bug: 226659256
Signed-off-by: Harpreet Eli Sangha <eliptus@google.com>
Change-Id: I9dd53a864d53e525282bc49c13b09157fc8d2ece
2022-04-15 00:28:13 +00:00
Anthony Stange
5e69e1c762 Update SELinux to allow CHRE to talk to the Wifi HAL am: 403643929d am: abb060273b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17715921

Change-Id: I842c5555f62e5cb6a9ae6138bb8c96d6ec7fd478
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 16:36:02 +00:00
Anthony Stange
abb060273b Update SELinux to allow CHRE to talk to the Wifi HAL am: 403643929d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17715921

Change-Id: I2fc02c0b95b50587e57dcd4070977c9f0f8cf34f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 16:14:08 +00:00
Anthony Stange
403643929d Update SELinux to allow CHRE to talk to the Wifi HAL
Bug: 206614765
Test: Run locally
Change-Id: I2cab195d533e3e2c390094bd09b15b5e761eadf0
2022-04-14 15:23:22 +00:00
chungkai
757a3fc7d9 sepolicy: fix avc denials am: fbdb09a2f0 am: d45cf4d6d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750772

Change-Id: I51f07ba55b537303804b46034de3b000588a8cc9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 10:05:04 +00:00
chungkai
d45cf4d6d3 sepolicy: fix avc denials am: fbdb09a2f0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750772

Change-Id: I60f7a16bec1ac56aace2cde31a17afb009387a62
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 09:42:49 +00:00
chungkai
fbdb09a2f0 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 226887726
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ifc618e315e9d28cab6f602ce2c99ac7fe35fc189
2022-04-14 07:24:58 +00:00
TeYuan Wang
ec0b702744 sepolicy: label AUR as sysfs_thermal am: 951bad233c am: 28432f8076
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731168

Change-Id: Iff17f7bb5babeb0465e974ff187efd2012bbd6f6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 07:10:46 +00:00
TeYuan Wang
28432f8076 sepolicy: label AUR as sysfs_thermal am: 951bad233c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731168

Change-Id: I90c7de97164a2da58f79d361173d21c40adc3b4c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 06:48:20 +00:00
sukiliu
792db15271 Update avc error on ROM 8449600 am: f0810342eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750769

Change-Id: If6eab7cb601ee0b5b78e09cc9c90bd305e480b4f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 06:24:53 +00:00
TeYuan Wang
951bad233c sepolicy: label AUR as sysfs_thermal
Bug: 171499494
Test: adb shell ls -Z /sys/devices/platform/100b0000.AUR
Change-Id: I0aa1b95c11d2af5fa2175c582068daad51360485
2022-04-14 06:23:35 +00:00
sukiliu
f0810342eb Update avc error on ROM 8449600
Bug: 229167195
Test: PtsSELinuxTestCases
Change-Id: I0b6cb1142aff6fbfbe828e014a5d9aad91b9817f
2022-04-14 05:58:56 +00:00
Denny cy Lee
469ce3962b Sepolicy: Pixel stats orientationCollector sepolicy am: d8eab32b49 am: 2c4cc89cdd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17652447

Change-Id: I7849c0b24b6ac1813ac71b1a914e3cfd043f3d5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 03:09:14 +00:00
Denny cy Lee
2c4cc89cdd Sepolicy: Pixel stats orientationCollector sepolicy am: d8eab32b49
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17652447

Change-Id: Iec661711780385e125c324d6b057e74a4996eb19
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 02:49:17 +00:00
Denny cy Lee
d8eab32b49 Sepolicy: Pixel stats orientationCollector sepolicy
Bug: 228547969
Test: adb shell cmd stats print-logs;[do wireless charge], and below log
found
03-31 22:52:21.798   801   809 I statsd  : { uid(1000) 1648738341
240287209019 (105009)0x10000->[S] 0x20000->0[I]  }

Signed-off-by: Denny cy Lee <dennycylee@google.com>
Change-Id: I5ef5279ba7c8bf0fd3d4cf0155f5bcad79eeb6b2
2022-04-14 02:01:13 +00:00
Jenny Ho
62e6c46060 sepolicy: add sepolicy for disable.battery.defender am: f1a9fb4da2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699361

Change-Id: I84efbf136d3024c3deb8a39d6bc1157ab298834a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 01:34:46 +00:00
Jenny Ho
f1a9fb4da2 sepolicy: add sepolicy for disable.battery.defender
Bug: 221384939
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Iba8f4e7abca98b5805eb75ba386c90581269f749
2022-04-14 01:06:58 +00:00
Robert Shih
651b7a0ffa Pixel 2022: MediaDrm AIDL sepolicy am: 38151187bf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17592563

Change-Id: I1c17646ed0ba9ba8b05be9cf280e62ff711deef2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 19:10:14 +00:00
Robert Shih
38151187bf Pixel 2022: MediaDrm AIDL sepolicy
Bug: 219538389
Bug: 221180205
Change-Id: I985230093d692fcf948049455fa465fce116d2a6
Test: atest VtsAidlHalDrmTargetTest
2022-04-13 18:38:21 +00:00
Darren Hsu
a709963403 sepolicy: lable p9412 wakeup for system suspend am: cf2cc47e79 am: 8af71b59c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731166

Change-Id: I3c20b7252a31152e1c4e5d4a2d71fa186a95aa45
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 11:20:26 +00:00
Darren Hsu
8af71b59c0 sepolicy: lable p9412 wakeup for system suspend am: cf2cc47e79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731166

Change-Id: Ic0c96ad1ef2bc91f5fce9196c4133b39c6a33a50
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 10:20:02 +00:00
Darren Hsu
cf2cc47e79 sepolicy: lable p9412 wakeup for system suspend
Bug: 226887726
Bug: 228947596
Test: do bugreport without avc denials
Change-Id: Ic8eab625a20c60a4bf78403ef10465074d782821
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-04-13 13:39:02 +08:00
Wayne Lin
059af1fafb gps: allow system server to send sensor data callback to GPS am: aab4f72223 am: 1ae80c59a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699754

Change-Id: I53819b994893a89ece85497ee52d4aaeba408ba3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 03:51:07 +00:00
Wayne Lin
1ae80c59a7 gps: allow system server to send sensor data callback to GPS am: aab4f72223
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699754

Change-Id: I4d29356b95bb185182a24190bc9c7ca5075e5ed2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 03:14:34 +00:00
Wayne Lin
aab4f72223 gps: allow system server to send sensor data callback to GPS
avc: denied { call } for scontext=u:r:system_server:s0 tcontext=u:r:gpsd:s0 tclass=binder permissive=0

Bug: 224772976
Test: build pass, verify no avc denied and gpsd can receive sensor callback
Change-Id: If3b58b5527f67732ea60b3dd943ae472aebb7aed
2022-04-13 02:54:24 +00:00
Albert Wang
75ee2a71a3 Add more xHCI wakeup path for suspend_control am: e914d6fcc3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17686710

Change-Id: I1991f78ae1dbbfe166e2f8f139f74912ea67cdff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-12 09:48:02 +00:00