Commit graph

1920 commits

Author SHA1 Message Date
Xin Li
6e7ca6c43a [automerger skipped] Merge Android U (ab/10368041) am: 70d0cf7ca5 -s ours
am skip reason: Merged-In I899bc4150d6d32b0ede035c96487da50849b6256 with SHA-1 3ab8be18a5 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24181570

Change-Id: I8c8b0810b4f857d2f21fec85cf184ab95de80427
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-28 23:59:22 +00:00
Xin Li
70d0cf7ca5 Merge Android U (ab/10368041)
Bug: 291102124
Merged-In: I899bc4150d6d32b0ede035c96487da50849b6256
Change-Id: I2d7cb958d68b1b20b31921f04c77a5ff91aca8eb
2023-08-15 00:04:03 -07:00
Inseob Kim
a3707836b2 [automerger skipped] Move coredomain policies to system_ext/product am: 656f7b5aa1 am: c83b44626a -s ours
am skip reason: Merged-In If768b5cb9f3b4024893117d8e3bf49adb7c5b070 with SHA-1 da30985fa5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: Iaf6051e44cd3378c415db967aeed879a0a51a734
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 04:35:44 +00:00
Inseob Kim
c83b44626a Move coredomain policies to system_ext/product am: 656f7b5aa1
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: I707df3267d51354e846376617b59943af6c04e30
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 03:49:14 +00:00
Inseob Kim
656f7b5aa1 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
Merged-In: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
(cherry picked from commit da30985fa5)
2023-08-09 15:06:04 +09:00
Inseob Kim
da30985fa5 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
Merged-In: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
2023-08-08 14:37:48 +00:00
Ken Yang
3054cb6eec SELinux: fix the wakeup avc denials
Fix the wakeup avc denials in a more common place

Bug: 292076108
Change-Id: I52627f19cb0fec3dd0851d21d0608048ebc7d45d
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-25 13:12:32 +00:00
David Anderson
a7e9f0a873 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I29b1070280c3e88e976dab3c02b110786ca8f11b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 23:22:17 +00:00
David Anderson
a03ec9af21 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Id20a32d6a80e058caebf2047e59a1b5a3e519f43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 22:41:44 +00:00
David Anderson
439827c49d Allow fastbootd to flash dtbo. am: e96a14a9d2
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ifc30a96202cbeb38896f3545502b582168dcf53e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 21:57:26 +00:00
David Anderson
e96a14a9d2 Allow fastbootd to flash dtbo.
This line is copied from gs101-sepolicy, and fixes the following denial:

audit: type=1400 audit(1689093038.396:14): avc:  denied  { write } for  pid=409 comm="fastbootd" name="sda24" dev="tmpfs" ino=493 scontext=u:r:fastbootd:s0 tcontext=u:object_r:custom_ab_block_device:s0 tclass=blk_file permissive=0

Bug: N/A
Test: fastboot flashall in fastbootd
Change-Id: I765aedeb204cc862434a56a97f242640465f84b8
2023-07-11 10:27:47 -07:00
Xin Li
c9d5097e56 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I903de348dca44cf893578b33b13743269685a480
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 00:32:37 +00:00
Xin Li
dc4a87253c [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I07063c3d9cf1418132ec611701713baa7b783f59
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 23:10:28 +00:00
Xin Li
7e4592c70a [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I27e4864161d3db815ad9cedad4da2af6ee082826
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 22:57:43 +00:00
Xin Li
aaef0b7773 Merge Android 13 QPR3
Bug: 275386652
Merged-In: Idc925c7a1f1111840a64664aa50c39442c3a0f8f
Change-Id: I2f0a022715577d395a6d9d2c8ec6b9a7f37fe509
2023-06-21 15:14:53 -07:00
Jenny Ho
3ab8be18a5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I899bc4150d6d32b0ede035c96487da50849b6256
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:50:10 +00:00
Jenny Ho
ee160b5880 Add permissions for maxfg_base/maxfg_secondary
Bug: 284878175
Change-Id: I3fe3030ecd36773405f0e70b767d4a28062d91ad
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-05-30 12:09:30 +08:00
Donnie Pollitz
36ea330be0 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ic51e258b34e4525f669a67d5eecd18b781bf6010
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:49:20 +00:00
Donnie Pollitz
955ae6825f Allow vendor_init to fix permissions of TEE data file
Background:
* vendor_init needs to be able to possibly fix ownership of
  tee_data_file

Bug: 280325952
Test: Changed permissions and confirmed user transitions
Change-Id: I27681589c9d0b0aa88463e6476fb75119ea89e8a
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-05-26 07:17:39 +00:00
sashwinbalaji
29df1ad288 thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: I6a691341b37808102fd540fce39373498e18b379
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 06:18:24 +00:00
sashwinbalaji
1113c66dea thermal: thermal_metrics: Update selinux to reset stats
Bug: 193833982
Test: Local build and verify statsD logs
adb shell cmd stats print-logs && adb logcat -b all | grep -i 105045
Change-Id: I0dc1c557797d7fe97da7f0fcb2d600485526c979
2023-05-25 05:28:45 +00:00
Jin Jeong
aa606065a3 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: Ifa25563c9f0d157ce52f2d2d320c6cc166521c2a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:42 +00:00
Jin Jeong
35e908fd66 Revert "Fix LPA crash due to selinux denial" am: 980c71bea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: I7d6c19280280e63b194da9bdef8b8a80d057f364
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:36 +00:00
Jin Jeong
10ef6d8619 Revert "Fix SELinux error for com.google.android.euicc"
Revert submission 22899490-euicc_selinux_fix

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22899490-euicc_selinux_fix

Change-Id: I50ff4f8e48389d034c3f6c716dad1a81e9b73e64
2023-05-24 01:07:09 +00:00
Jin Jeong
980c71bea4 Revert "Fix LPA crash due to selinux denial"
Revert submission 22955599-euicc_selinux_fix2

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22955599-euicc_selinux_fix2

Change-Id: I2799c61ab5464e5551168f471740afe76edd1113
2023-05-24 01:07:09 +00:00
Anthony Zhang
143c8076c2 [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: Iaa3d014c486c6179609a481811103665c141f3b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 19:19:13 +00:00
Anthony Zhang
7f19e81d61 [DO NOT MERGE] Allow fingerprint to access persist property
Bug: 258901849
Test: Local test on enrollment/delete, version update

Change-Id: I96acb79b3e600e0a4dd7b7a1cf494b20a876ca63
2023-05-22 18:36:54 +00:00
Luis Delgado de Mendoza Garcia
7a14a3a96f Add chre channel sepolicy entries am: 3992c42501
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: I71ae96a9e7ff8861fd8b1835948d3e9c04a1d8c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:36:06 +00:00
Luis Delgado de Mendoza Garcia
3992c42501 Add chre channel sepolicy entries
Bug: 281814892
Fix: 281814892
Test: in-device verification.
Change-Id: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
Merged-In: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
2023-05-16 22:49:12 +00:00
Wilson Sung
f19eec56a0 Update SELinux error am: d19337894a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633

Change-Id: Idf9dd1e06cdec3e1ffb5d7ae425fba99d54e071b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 07:45:07 +00:00
Adam Shih
2d2286d7c2 Introduce new sepoilcy owner am: 5cd759d295 am: 307e2c2fc8 am: 5e82524935
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: I2b7511a7aefba2354513e21ff49169637367451e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 04:22:40 +00:00
Adam Shih
5e82524935 Introduce new sepoilcy owner am: 5cd759d295 am: 307e2c2fc8
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: I8509e07c52ca5a75b4a9c10ffc3398a7c608c441
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 03:37:37 +00:00
Adam Shih
307e2c2fc8 Introduce new sepoilcy owner am: 5cd759d295
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: Idc925c7a1f1111840a64664aa50c39442c3a0f8f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 02:59:55 +00:00
Wilson Sung
d19337894a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 282096141
Change-Id: I0725e78a76436a0904205f83655755bf7c76c05f
2023-05-12 12:09:08 +08:00
Adam Shih
5cd759d295 Introduce new sepoilcy owner
Bug: 281631102
Test: N/A
Change-Id: I9bb7c6299f970a410481dd541523bec6df68cf23
2023-05-12 02:11:38 +00:00
Adam Shih
b39ed5f5ab add missing permission for gs201 power dump am: 2a02fe5fc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23125499

Change-Id: I9fa0c89636bf3b961733ba91e5079d900ee031b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 05:38:59 +00:00
Adam Shih
2a02fe5fc5 add missing permission for gs201 power dump
Bug: 281602658
Test: adb bugreport
Change-Id: Ibf765c9da65d2c9f6a3825c91cb22771f583457a
2023-05-10 10:56:55 +08:00
Jinyoung Jeong
cc89605283 Fix LPA crash due to selinux denial am: 2d7181e3fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22949545

Change-Id: I161d19ec1cc786e85a6bf1ccfe5f0bed76ac98bc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:53:21 +00:00
Jinyoung Jeong
2d7181e3fc Fix LPA crash due to selinux denial
Bug: 280336861
Test: No crash found during LPA basic tests: download eSIM,
enable/disalbe eSIM.

Change-Id: Ie4fd8fccce5ec98cf0b2afff9a41f27206e52626
2023-05-02 14:10:00 +00:00
Hongbo Zeng
3d706a6ba4 Fix denials for radio service to access files under /data/venodr/radio am: 306bf73c79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22899484

Change-Id: I1131ba266eb951d636cc5fc96bb8e370f87dc414
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 13:00:38 +00:00
Hongbo Zeng
306bf73c79 Fix denials for radio service to access files under /data/venodr/radio
Bug: 270561266
Test: get PASS result with go/ril-config-service-test and the original
      denial logs in http://b/270561266#comment8 are gone

Change-Id: I17155852bb2408b4389a86d32228292885e14c46
2023-05-02 08:05:31 +00:00
martinwu
25b8c58d06 [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357

Change-Id: Ic6b7025f009b00532c5669400090c0c5136707b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:59:24 +00:00
martinwu
5f9732a97a [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
Merged-In: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-05-02 03:16:02 +00:00
Jinyoung Jeong
13cb55bee1 Fix SELinux error for com.google.android.euicc am: f265749f1d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711

Change-Id: I3d72968e6cf50c8db5a61269f52c2e7ed57888c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:19:13 +00:00
Jinyoung Jeong
f265749f1d Fix SELinux error for com.google.android.euicc
Bug: 279548423
Test: http://fusion2/b7c803be-2dca-4195-b91f-6c4939746b5b
Change-Id: Idd231c2412e8f597dea1bfa11f9d1a0fa1e17034
2023-04-30 02:51:45 +00:00
Bruno BELANYI
0676395ee0 Remove 'hal_neuralnetworks_armnn' '/data' access exception am: a43d300aff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786254

Change-Id: Ibe2bf72c2ab156f6c3e08a2dacdb29df51edfdbf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:48 +00:00
Bruno BELANYI
93ef539d30 Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: 01a2e70a17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786660

Change-Id: I7d58cb0fab0fa4fdba7362b5733248a8cf3dad09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:42 +00:00
Bruno BELANYI
bd3d06a0af Add ArmNN config sysprops SELinux rules am: ee3fe73de0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786979

Change-Id: I9f5909ed237c73266372bb22dc2378dc14f62a79
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:38 +00:00
Bruno BELANYI
a43d300aff Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:bb69b32fc5b6f468561017f6bd5628626a571696)
Merged-In: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
Change-Id: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
2023-04-27 08:06:38 +00:00
Bruno BELANYI
01a2e70a17 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:4f1ca4a7ad3895f5a5adc25fc2cf3a532eac79f6)
Merged-In: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
Change-Id: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
2023-04-27 08:06:38 +00:00