Commit graph

1943 commits

Author SHA1 Message Date
jimsun
0f6b14dc95 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
2edb9d804a Update error on ROM 9954737 am: 4cc8eec22d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22696721

Change-Id: I5e9980ccb32216b6ee8f504f657bcb4f15ccd7f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-18 05:06:01 +00:00
Wilson Sung
4cc8eec22d Update error on ROM 9954737
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
36acecbde7 Use restricted vendor property for ARM runtime options am: c1ee9afdef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22381562

Change-Id: I46c362e310af43993bf1b8ae25548933bc5eed80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:28:51 +00:00
Bruno BELANYI
c1ee9afdef Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00
Leo Liou
640fe3d54b gs201: add sepolicy for ufs_firmware_update process am: 5adecc7433
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22132666

Change-Id: I5525cba7db182410722e9deb22e490bbec6ed23b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 10:26:03 +00:00
Leo Liou
5adecc7433 gs201: add sepolicy for ufs_firmware_update process
Allow the script to access the specified partition and sysfs.

Bug: 273305212
Test: full build and test ffu flow
Change-Id: Iefeacea2d4c07e7a5b39713c9575e86bd25ce008
Signed-off-by: Leo Liou <leoliou@google.com>
2023-04-17 09:58:11 +00:00
kadirpili
52bceb2b75 gs201: Allow GRIL Service to access radio_vendor_data_file am: 1af348b01f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22213304

Change-Id: Id769672ecd92451c14f8daad175efeecd5cbd3fb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 06:15:50 +00:00
kadirpili
1af348b01f gs201: Allow GRIL Service to access radio_vendor_data_file
Bug: 274737512
Change-Id: I1c0b045f8a25c5d58be02c2036d2fcaad7d9a8e7
2023-04-14 06:57:50 +00:00
Xin Li
c28af0a680 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours am: 551330137f -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: If238593b7e3a51bc35d829c8847b32d477b421e7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:08:47 +00:00
Xin Li
551330137f [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Iefd6904aee50936e373590b4d54f492986aaf4dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:09 +00:00
Xin Li
ba5a2d3863 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I12f4ac63bb185203b115ae3f77ade5588bd50b10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:23:00 +00:00
Xin Li
4c44de9655 Merge TQ2A.230405.003 am: 8cff198ae3
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Ibeb863ad3557474eed5f5c8a529f12ed3c8c7768
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:58 +00:00
Minchan Kim
995f5bee72 remove dump_gs201 sepolicy am: dc35b4158b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529799

Change-Id: I1f86e778ac640c3deddd3520c2573794e243e887
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 09:49:14 +00:00
Minchan Kim
1dbb72a1b2 move vendor_cma_debugfs into gs-common am: b7393fd8d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529798

Change-Id: Ibc6f0f1cc047271a2db924669239b33c34860c91
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 09:49:08 +00:00
Minchan Kim
dc35b4158b remove dump_gs201 sepolicy
Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I39c01692d959a63c091f98969a69ab35b2debe1a
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Minchan Kim
b7393fd8d8 move vendor_cma_debugfs into gs-common
The CMA dump is common feature for pixel devices so move
it to gs-common.

Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I3997e27e3037f013338de5bc36687c63338769aa
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Tommy Kardach
9905ae28fb Update sepolicy for Camera HAL am: 3430e752af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22195719

Change-Id: I8131586dd90dc3220f03fe8cf7231e8abb5ad6e6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-11 20:28:06 +00:00
Tommy Kardach
3430e752af Update sepolicy for Camera HAL
Edit SE policay for WHI_PRO to allow
camera HAL to acquire wake locks

Bug: 249567788
Test: Flash and manual testing
Change-Id: I450b0b53000c5b9649e354350ec80af3528120fb
2023-04-11 19:45:33 +00:00
Xin Li
8cff198ae3 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I971732c6a40700a85df61170dcf1c3660307b96c
Change-Id: I33994bb345a46d8ac3f3a751fdff402f4ce5c68f
2023-04-10 23:55:29 -07:00
Adam Shih
5a0bb72bf0 Remove obsolete entries
Bug: 268147113
Bug: 237491813
Bug: 239484651
Bug: 268566483
Test: adb bugreport
Change-Id: Iceafe7e413a3ffe5d342a222f76093c7110639e6
2023-04-11 11:29:41 +08:00
Adam Shih
15ec2c4d63 use dumpsate from gs-common am: 9519323a98
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524762

Change-Id: I236bbd1daad4c2fdd804fb65c5791074f157a983
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:27 +00:00
Wilson Sung
842cc3f0ac Update error on ROM 9890523 am: 4d92dd61f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524766

Change-Id: I05877b25da3e5baa4dffc4cc3e0cd69808b7cb70
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:15 +00:00
Adam Shih
9519323a98 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: Ibd54c0049480810e2aa14074e0ec9c4d611d51ff
2023-04-10 01:11:14 +00:00
Wilson Sung
4d92dd61f2 Update error on ROM 9890523
Bug: 277155245
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Iffbc691cff0e3a8d19ca3acef918cb4c1243feae
2023-04-07 07:07:40 +00:00
Victor Liu
88e12f2f08 uwb: add permission for ccc ranging am: 187dcc4e08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21965706

Change-Id: I44c6a7083e8c950c2bc2a7c95dd6a737dd5964ec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 21:29:09 +00:00
Victor Liu
187dcc4e08 uwb: add permission for ccc ranging
Bug: 255649425
Change-Id: I83ce369e52f382d76723b2b045e09607483a0a6a
2023-04-06 20:57:42 +00:00
Roy Luo
4b7fa3fe06 Support sending vendor command to GL852G via libusbhost am: 1f54dc7256
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22129755

Change-Id: Ib56fd37ddbe745c4753c038e30558aa217e6cdd2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 02:23:12 +00:00
Roy Luo
1f54dc7256 Support sending vendor command to GL852G via libusbhost
libusbhost need access to USB device fs.

Bug: 261923350
Test: no audit log in logcat after command execution
Change-Id: I4b0c8cc750eff12d2494504f9f215d5b1bab35fd
2023-04-06 01:54:13 +00:00
feiyuchen
e9ef3e9409 Allow camera HAL to access edgetpu_app_service in gs201 am: 0161b6fbfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22462510

Change-Id: I0a4d400fd800e3d19eaf34f4cec607ece4897e7a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-05 23:34:24 +00:00
feiyuchen
0161b6fbfa Allow camera HAL to access edgetpu_app_service in gs201
We are seeing SELinux error b/276911450. It turns out that I only added the SE policy for 2023 device ag/22248613, but I forgot to add it for gs101 and gs201. So I created this CL.

See more background in ag/22248613.

Test: For gs201, I tested on my Pixel7 and I saw no more error. For gs101, I just did mm.
Bug: 275016466
Bug: 276911450
Change-Id: I223770eb0bc7e09a5dfb4f4188b7fc605c3d1a61
2023-04-04 21:32:06 +00:00
Wilson Sung
cc4e8cdabe Update SELinux error am: 33b2f0043c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22357289

Change-Id: Ib4fd85fa779ca4a177fcbb3efbea548271b24bbc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-31 05:23:15 +00:00
Wilson Sung
33b2f0043c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 276386138
Bug: 276385494
Change-Id: Idcd05416ca84e0b47629637f8d3287a40d80a6ab
2023-03-31 10:55:21 +08:00
Adam Shih
f690cc6219 Move power dump out of hal_dumpstate_default am: 933e6a172b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22326747

Change-Id: I3f14e221b24d8f526d99846a5fe9d13aac87ed31
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-30 19:07:32 +00:00
Adam Shih
933e6a172b Move power dump out of hal_dumpstate_default
Bug: 273380509
Test: adb bugreport
Change-Id: I0963af3f8f90b4f05724df31017b0d21d10c59ca
2023-03-30 02:20:37 +00:00
Wilson Sung
dc9266924b Update SELinux error am: bb30528185
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22323069

Change-Id: I57af757a9c07d08ef7cba9a27caa38f6179d80d6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 07:07:56 +00:00
Wilson Sung
bb30528185 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275645892
Change-Id: Ib6aa5d2fe4a401cadc02a60b06725156f37aaccf
2023-03-29 10:49:39 +08:00
Adam Shih
d684dbf72d create a dump for gs201 am: a334895789
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22308282

Change-Id: Ic07a72d7db7adc85f7dccfa4ce55c43e246fc09d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 00:47:22 +00:00
Adam Shih
a334895789 create a dump for gs201
Bug: 273380509
Test: adb bugreport
Change-Id: Ic47e0d43d9a5aef4381880eabbba74633ee260a1
2023-03-28 12:52:52 +08:00
Adam Shih
0f15253ceb use radio dump in gs-common am: 86faa5607c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22248646

Change-Id: I501ba2e2e98842372bf5b7bb7dde77bc77419729
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 06:28:25 +00:00
Adam Shih
86faa5607c use radio dump in gs-common
Bug: 273380509
Test: adb bugreport
Change-Id: I5e4318a427c0b503c47fb81ddb9e813fa9a41ab4
Merged-In: I5e4318a427c0b503c47fb81ddb9e813fa9a41ab4
2023-03-27 03:19:49 +00:00
Wilson Sung
b6c0387763 Update SELinux error am: dcc7112f6f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22244005

Change-Id: I77fdbc1a802f24db742e417028cb5fec38073248
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:05 +00:00
Wilson Sung
dcc7112f6f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275001783
Change-Id: I6514b7efbd02a5ddcb65ab329f0f01cc2d61e50a
2023-03-24 11:11:48 +08:00
Kris Chen
23e3bb495b Allow fingerprint hal to read sysfs_leds am: ba0b76de16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22175407

Change-Id: I70086ed3ce7102c42f54f5a4c22e0064ae1ac891
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 02:41:26 +00:00
Kris Chen
ba0b76de16 Allow fingerprint hal to read sysfs_leds
Fix the following avc denials:
avc: denied { search } for name="backlight" dev="sysfs" ino=79316
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=dir permissive=1

avc: denied { read } for name="state" dev="sysfs" ino=79365
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0
tclass=file permissive=1

Bug: 271072126
Test: Authenticate fingerprint.
Change-Id: I9f346cb72ef660712b2bfb610df959667958c36a
2023-03-24 02:06:34 +00:00
Adam Shih
b48c15ff36 use gs-common gps dump am: 1cdfdb4262
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22191063

Change-Id: I4e295cfc2630dcd368cc4be3e1211036f32c907d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-23 02:56:26 +00:00
Adam Shih
1cdfdb4262 use gs-common gps dump
Bug: 273380509
Test: adb bugreport
Change-Id: I7d5fa2f086aeab1b94fe33b3f419d5fb58bfbda5
2023-03-22 12:26:10 +08:00
Jörg Wagner
8f5f03eeb5 Update Mali DDK to r40 : Additional SELinux settings am: 28503a8706
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22168613

Change-Id: I61e2dca3144b674837260726d2a40f7518908a44
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-21 15:15:22 +00:00
Jörg Wagner
28503a8706 Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 4183daf7f1)
Merged-In: I75457d2d4f6e37bdd85329bac7fd81327cfff628
Change-Id: Ic40d6576537fc6699e3315040236e79aba16af18
2023-03-21 10:32:25 +00:00
Adam Shih
e71e5e62a2 use gxp dump in gs-common am: 831323cd81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22162945

Change-Id: Idc6b90daf364952e2310b5cb0fa22b8a74e6d912
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-21 05:56:50 +00:00