Samuel Gosselin
64111ee561
genfs_contexts: add raw s2mpg12mfd and s2mpg13mfd node.
...
This adds the appropriate raw i2c numberings to the sepolicy
for the 6.1 kernel driver which does not use the i2c vendor
hook to rename these numberings. This is required for the
thermal hal to work.
Test:
Boot to Android Home on WHI PRO with 6.1 kernel, no
Thermal HAL crashes.
Bug: 276464780
Signed-off-by: Samuel Gosselin <sgosselin@google.com>
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:83712c5243166cafa3a057d5347515e04947cde8 )
Merged-In: I8c2633b33cef8ca2b55029190fe42bd66b17390f
Change-Id: I8c2633b33cef8ca2b55029190fe42bd66b17390f
2023-05-17 18:08:56 +00:00
Luis Delgado de Mendoza Garcia
60eb785f97
[automerger skipped] Add chre channel sepolicy entries am: 3992c42501
am: 0a15da974d
-s ours
...
am skip reason: Merged-In I3151d25c4a1cd7a858b84e0c8989dc160d368ca5 with SHA-1 c2d912818c
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545
Change-Id: I08deeb46e00b459934b25e3636ee2fb8d53af044
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-17 00:18:41 +00:00
Luis Delgado de Mendoza Garcia
0a15da974d
Add chre channel sepolicy entries am: 3992c42501
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545
Change-Id: Iada40c9422558bd1b3575e07378cb4a12e8c9ef0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:35:56 +00:00
Luis Delgado de Mendoza Garcia
3992c42501
Add chre channel sepolicy entries
...
Bug: 281814892
Fix: 281814892
Test: in-device verification.
Change-Id: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
Merged-In: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
2023-05-16 22:49:12 +00:00
Wilson Sung
23ca430833
Update SELinux error am: d19337894a
am: 468ba9b0d6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633
Change-Id: I87a6a1344b2525b112129a773642009d06cf151f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 08:30:53 +00:00
Wilson Sung
468ba9b0d6
Update SELinux error am: d19337894a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633
Change-Id: I2152c8c6960ce3b86323663b66eb9c2b7fda723a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 07:49:19 +00:00
Wilson Sung
d19337894a
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 282096141
Change-Id: I0725e78a76436a0904205f83655755bf7c76c05f
2023-05-12 12:09:08 +08:00
Adam Shih
5d36e67f21
add missing permission for gs201 power dump am: 2a02fe5fc5
am: b6d409b1bd
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23125499
Change-Id: Ic83dbc5d4928f69293aeb55d04503d52d8bc2a66
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 06:23:01 +00:00
Adam Shih
b6d409b1bd
add missing permission for gs201 power dump am: 2a02fe5fc5
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23125499
Change-Id: I50c8f3cf3bdfcd595266c9abbc38806e6eb53dc7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 05:37:52 +00:00
Luis Delgado de Mendoza Garcia
c2d912818c
Add chre channel sepolicy entries
...
Bug: 241960170
Test: in-device verification.
Change-Id: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
2023-05-10 17:20:09 +00:00
Adam Shih
2a02fe5fc5
add missing permission for gs201 power dump
...
Bug: 281602658
Test: adb bugreport
Change-Id: Ibf765c9da65d2c9f6a3825c91cb22771f583457a
2023-05-10 10:56:55 +08:00
Zixuan Lan
8db0b6abef
remove fixed selinux bug from bug map. am: 96789e18c7
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23039510
Change-Id: I3cf8a3322547c7c2ba63e45ceee41dd2dab531b3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-10 01:13:44 +00:00
Zixuan Lan
96789e18c7
remove fixed selinux bug from bug map.
...
TPU permission was fixed to avoid error in hal_camera_defaul.The corresponding bug for tracking should be removed from the bug map. Please see bug for more details.
Bug: 275001783
Test: logcat grep for selinux error
Change-Id: I7a1bf9fd994187f969b68b9fc3504a5411b0807f
2023-05-04 22:36:33 +00:00
Jinyoung Jeong
33f9e124e4
Fix LPA crash due to selinux denial am: 2d7181e3fc
am: b662770e6e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22949545
Change-Id: I0b882be3452b2b6d928a3e38f63819f56363823d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:57:59 +00:00
Hongbo Zeng
119748f522
Fix denials for radio service to access files under /data/venodr/radio am: 306bf73c79
am: 2fa90460e1
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22899484
Change-Id: I74e199f64c3dd9e1f57914db338b49e588086ae6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:57:36 +00:00
Jinyoung Jeong
b662770e6e
Fix LPA crash due to selinux denial am: 2d7181e3fc
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22949545
Change-Id: I483b75a2278f74e6377757665170cb46c52866b1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:57:35 +00:00
Jinyoung Jeong
2d7181e3fc
Fix LPA crash due to selinux denial
...
Bug: 280336861
Test: No crash found during LPA basic tests: download eSIM,
enable/disalbe eSIM.
Change-Id: Ie4fd8fccce5ec98cf0b2afff9a41f27206e52626
2023-05-02 14:10:00 +00:00
Hongbo Zeng
2fa90460e1
Fix denials for radio service to access files under /data/venodr/radio am: 306bf73c79
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22899484
Change-Id: I90966fc0a068091900b8229762c7c03427b39890
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 12:34:24 +00:00
Hongbo Zeng
306bf73c79
Fix denials for radio service to access files under /data/venodr/radio
...
Bug: 270561266
Test: get PASS result with go/ril-config-service-test and the original
denial logs in http://b/270561266#comment8 are gone
Change-Id: I17155852bb2408b4389a86d32228292885e14c46
2023-05-02 08:05:31 +00:00
martinwu
18dcc41f77
[automerger skipped] [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a
-s ours am: d5f7c7d958
-s ours
...
am skip reason: Merged-In Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1 with SHA-1 ee611cfb51
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357
Change-Id: Ib25d58e12409bbd4642610d4924d93ccae5b289d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 07:59:10 +00:00
martinwu
d5f7c7d958
[automerger skipped] [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a
-s ours
...
am skip reason: Merged-In Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1 with SHA-1 ee611cfb51
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357
Change-Id: Ia2c8274ad5f9aacc3f9cf7e309476e1713319d00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:57:13 +00:00
martinwu
5f9732a97a
[TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
...
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
2. Dump bugreport
3. Pull dumpstate_board.bin and chagne it to zip
4. Unzip dumpstate_board.zip and check if tcpdump files
are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
Merged-In: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-05-02 03:16:02 +00:00
Jinyoung Jeong
0e225eae79
Fix SELinux error for com.google.android.euicc am: f265749f1d
am: 225f248217
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711
Change-Id: I1cf4cbd10f42579aca80065c475463b56dddbcf5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 04:05:29 +00:00
Jinyoung Jeong
225f248217
Fix SELinux error for com.google.android.euicc am: f265749f1d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711
Change-Id: Iafdb146e4a11cb17c47509a567fe338df242b76a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:23:24 +00:00
Jinyoung Jeong
f265749f1d
Fix SELinux error for com.google.android.euicc
...
Bug: 279548423
Test: http://fusion2/b7c803be-2dca-4195-b91f-6c4939746b5b
Change-Id: Idd231c2412e8f597dea1bfa11f9d1a0fa1e17034
2023-04-30 02:51:45 +00:00
martinwu
ee611cfb51
[TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
...
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
2. Dump bugreport
3. Pull dumpstate_board.bin and chagne it to zip
4. Unzip dumpstate_board.zip and check if tcpdump files
are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-04-27 13:43:26 +00:00
Bruno BELANYI
1f70adac2c
Remove 'hal_neuralnetworks_armnn' '/data' access exception am: a43d300aff
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786254
Change-Id: Ifb381f79a52d93792e6f7197b96318fe497b954d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:05 +00:00
Bruno BELANYI
e213052ee3
Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: 01a2e70a17
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786660
Change-Id: I7d2962067bb15252010771386faa91f654cf4948
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:00 +00:00
Bruno BELANYI
86f6851961
Add ArmNN config sysprops SELinux rules am: ee3fe73de0
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786979
Change-Id: I257d7dccaf726da56b5f8125f9cd9bcf9b90003b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:44:55 +00:00
Bruno BELANYI
a43d300aff
Remove 'hal_neuralnetworks_armnn' '/data' access exception
...
The mali driver has been configured not to look there anymore.
Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:bb69b32fc5b6f468561017f6bd5628626a571696 )
Merged-In: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
Change-Id: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
2023-04-27 08:06:38 +00:00
Bruno BELANYI
01a2e70a17
Remove 'hal_neuralnetworks_armnn' sysprop exceptions
...
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:4f1ca4a7ad3895f5a5adc25fc2cf3a532eac79f6 )
Merged-In: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
Change-Id: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
2023-04-27 08:06:38 +00:00
Bruno BELANYI
ee3fe73de0
Add ArmNN config sysprops SELinux rules
...
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:9d61da55a193a12b7552e67e67d968c46d4dec86 )
Merged-In: I90af8201d5fae44f73d709491f272a113b44ca67
Change-Id: I90af8201d5fae44f73d709491f272a113b44ca67
2023-04-27 08:06:38 +00:00
Martin Wu
ce2150e7b2
Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..." am: c6d08c1781
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22891378
Change-Id: Ibd8ed1afbd64eb0f6d582a2b79cb218b61227f57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:16:02 +00:00
Martin Wu
c6d08c1781
Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..."
...
Revert submission 22814097-Fix-tcpdump-sepolicy
Reason for revert: build break
Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy
Change-Id: I5b1c00cc6a1ae186eb51acc2c99171578c43bace
2023-04-27 02:20:48 +00:00
martinwu
364729d86f
Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: b7e90ec616
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22817736
Change-Id: Ib6386af3b162751d71d3af08269eeb2f43c35fe4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:17:46 +00:00
martinwu
b7e90ec616
Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
...
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
2. Dump bugreport
3. Pull dumpstate_board.bin and chagne it to zip
4. Unzip dumpstate_board.zip and check if tcpdump files
are there.
Change-Id: I0eb9352e349ae8f06e469e953f137b00204f1c3b
2023-04-27 01:38:24 +00:00
Wilson Sung
67082a4a05
Update error on ROM 9784808 am: 2b913d29a9
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791801
Change-Id: I9c166ebbe791eb5948fd8676fd8e463d3891ba33
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 07:42:38 +00:00
Wilson Sung
2b913d29a9
Update error on ROM 9784808
...
Bug: 274727778
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I56784948658365e8c9ecdf63d163109d8f29e5c3
2023-04-26 07:00:21 +00:00
Joseph Jang
457cf699d8
Move recovery.te to device/google/gs-common/dauntless/sepolicy am: 2a5c26c9b4
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791802
Change-Id: I7202f910327717069a0d925c1268bb66aacee2e3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:57 +00:00
Joseph Jang
2a5c26c9b4
Move recovery.te to device/google/gs-common/dauntless/sepolicy
...
Bug: 279381809
Change-Id: I80fbd9ef0c7e988de21d07ada57fc6a038b9b585
2023-04-24 08:05:10 +00:00
jimsun
c477b46828
rild: allow rild to ptrace am: 0f6b14dc95
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21876774
Change-Id: I47c2a25b8105a26be3579b00a089529f11750f00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:15 +00:00
jimsun
0f6b14dc95
rild: allow rild to ptrace
...
06-20 18:47:41.940000 8708 8708 I auditd : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000 8708 8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
2edb9d804a
Update error on ROM 9954737 am: 4cc8eec22d
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22696721
Change-Id: I5e9980ccb32216b6ee8f504f657bcb4f15ccd7f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-18 05:06:01 +00:00
Wilson Sung
4cc8eec22d
Update error on ROM 9954737
...
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
36acecbde7
Use restricted vendor property for ARM runtime options am: c1ee9afdef
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22381562
Change-Id: I46c362e310af43993bf1b8ae25548933bc5eed80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:28:51 +00:00
Bruno BELANYI
c1ee9afdef
Use restricted vendor property for ARM runtime options
...
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.
Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00
Leo Liou
640fe3d54b
gs201: add sepolicy for ufs_firmware_update process am: 5adecc7433
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22132666
Change-Id: I5525cba7db182410722e9deb22e490bbec6ed23b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 10:26:03 +00:00
Leo Liou
5adecc7433
gs201: add sepolicy for ufs_firmware_update process
...
Allow the script to access the specified partition and sysfs.
Bug: 273305212
Test: full build and test ffu flow
Change-Id: Iefeacea2d4c07e7a5b39713c9575e86bd25ce008
Signed-off-by: Leo Liou <leoliou@google.com>
2023-04-17 09:58:11 +00:00
kadirpili
52bceb2b75
gs201: Allow GRIL Service to access radio_vendor_data_file am: 1af348b01f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22213304
Change-Id: Id769672ecd92451c14f8daad175efeecd5cbd3fb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 06:15:50 +00:00
kadirpili
1af348b01f
gs201: Allow GRIL Service to access radio_vendor_data_file
...
Bug: 274737512
Change-Id: I1c0b045f8a25c5d58be02c2036d2fcaad7d9a8e7
2023-04-14 06:57:50 +00:00