Commit graph

1920 commits

Author SHA1 Message Date
Wilson Sung
c5784b51a2 Update SELinux error am: d19337894a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633

Change-Id: Ibd1ead0534140e089e2b7ec4e04c0c266db76b91
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 07:49:17 +00:00
Wilson Sung
d19337894a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 282096141
Change-Id: I0725e78a76436a0904205f83655755bf7c76c05f
2023-05-12 12:09:08 +08:00
Adam Shih
07197068f4 add missing permission for gs201 power dump am: 2a02fe5fc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23125499

Change-Id: I5c7d300e78edec76508780697647d56e6464e104
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 05:37:52 +00:00
Adam Shih
2a02fe5fc5 add missing permission for gs201 power dump
Bug: 281602658
Test: adb bugreport
Change-Id: Ibf765c9da65d2c9f6a3825c91cb22771f583457a
2023-05-10 10:56:55 +08:00
Jinyoung Jeong
8bf7b7ad4c Fix LPA crash due to selinux denial am: 2d7181e3fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22949545

Change-Id: I0b797f8b9f4e2765ab5723acf4c7b3d6b907c9c0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:58:10 +00:00
Jinyoung Jeong
2d7181e3fc Fix LPA crash due to selinux denial
Bug: 280336861
Test: No crash found during LPA basic tests: download eSIM,
enable/disalbe eSIM.

Change-Id: Ie4fd8fccce5ec98cf0b2afff9a41f27206e52626
2023-05-02 14:10:00 +00:00
Hongbo Zeng
368fe6a9b2 Fix denials for radio service to access files under /data/venodr/radio am: 306bf73c79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22899484

Change-Id: Id7fcb81f9a7dc1d5800bcd751ce62d725063f5fa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 12:44:12 +00:00
Hongbo Zeng
306bf73c79 Fix denials for radio service to access files under /data/venodr/radio
Bug: 270561266
Test: get PASS result with go/ril-config-service-test and the original
      denial logs in http://b/270561266#comment8 are gone

Change-Id: I17155852bb2408b4389a86d32228292885e14c46
2023-05-02 08:05:31 +00:00
martinwu
61688ce596 [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357

Change-Id: I613db64df9dd7dcbb9e1f8348bd9aad8c642d323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:58:27 +00:00
martinwu
5f9732a97a [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
Merged-In: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-05-02 03:16:02 +00:00
Jinyoung Jeong
51c6b27dd9 Fix SELinux error for com.google.android.euicc am: f265749f1d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711

Change-Id: Ib5e025dfaf83647ea62f5cdab53758668129ec3a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:23:21 +00:00
Jinyoung Jeong
f265749f1d Fix SELinux error for com.google.android.euicc
Bug: 279548423
Test: http://fusion2/b7c803be-2dca-4195-b91f-6c4939746b5b
Change-Id: Idd231c2412e8f597dea1bfa11f9d1a0fa1e17034
2023-04-30 02:51:45 +00:00
Bruno BELANYI
6745934d1c Remove 'hal_neuralnetworks_armnn' '/data' access exception am: a43d300aff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786254

Change-Id: I66bb78102a66eee8490c1dfc095c69c4b6fc09dd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:15 +00:00
Bruno BELANYI
a76bb4240d Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: 01a2e70a17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786660

Change-Id: Ia8f409ba3c1c92e8ee8ad206b6284d3d139d9f95
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:09 +00:00
Bruno BELANYI
e94e4513ea Add ArmNN config sysprops SELinux rules am: ee3fe73de0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786979

Change-Id: Ie1552d16a42fc3f8ab5557372638708937facb01
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:00 +00:00
Bruno BELANYI
a43d300aff Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:bb69b32fc5b6f468561017f6bd5628626a571696)
Merged-In: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
Change-Id: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
2023-04-27 08:06:38 +00:00
Bruno BELANYI
01a2e70a17 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:4f1ca4a7ad3895f5a5adc25fc2cf3a532eac79f6)
Merged-In: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
Change-Id: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
2023-04-27 08:06:38 +00:00
Bruno BELANYI
ee3fe73de0 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:9d61da55a193a12b7552e67e67d968c46d4dec86)
Merged-In: I90af8201d5fae44f73d709491f272a113b44ca67
Change-Id: I90af8201d5fae44f73d709491f272a113b44ca67
2023-04-27 08:06:38 +00:00
Martin Wu
89476a3d15 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..." am: c6d08c1781
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22891378

Change-Id: I3109f9c24e5f0a042c396b8deef9a985695f5e42
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:15:46 +00:00
Martin Wu
c6d08c1781 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..."
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I5b1c00cc6a1ae186eb51acc2c99171578c43bace
2023-04-27 02:20:48 +00:00
martinwu
67495c9b14 Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: b7e90ec616
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22817736

Change-Id: Ie81e23d283b5e728296390ba7ced6508e15afc40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:17:57 +00:00
martinwu
b7e90ec616 Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I0eb9352e349ae8f06e469e953f137b00204f1c3b
2023-04-27 01:38:24 +00:00
Wilson Sung
2daec05481 Update error on ROM 9784808 am: 2b913d29a9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791801

Change-Id: I53f57effc548b312b1447a513d39c0cedc40510b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 07:43:23 +00:00
Wilson Sung
2b913d29a9 Update error on ROM 9784808
Bug: 274727778
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I56784948658365e8c9ecdf63d163109d8f29e5c3
2023-04-26 07:00:21 +00:00
Joseph Jang
1a82f277a8 Move recovery.te to device/google/gs-common/dauntless/sepolicy am: 2a5c26c9b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791802

Change-Id: If26d8b1d603af03114155180884efaaba2de27f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:52 +00:00
Joseph Jang
2a5c26c9b4 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: I80fbd9ef0c7e988de21d07ada57fc6a038b9b585
2023-04-24 08:05:10 +00:00
jimsun
5bdbb594be rild: allow rild to ptrace am: 0f6b14dc95
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/21876774

Change-Id: I4ec24257f452e475272a9535e1dd21cecf94595a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:14 +00:00
jimsun
0f6b14dc95 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
b70e63a6de Update error on ROM 9954737 am: 4cc8eec22d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22696721

Change-Id: I21e6891828e09955d72558eb942578a13861cd8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-18 05:06:12 +00:00
Wilson Sung
4cc8eec22d Update error on ROM 9954737
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
be0ea597f0 Use restricted vendor property for ARM runtime options am: c1ee9afdef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22381562

Change-Id: If2ae2398fae5c8b39e51c2f2f47fb11a95b5b033
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:29:24 +00:00
Bruno BELANYI
c1ee9afdef Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00
Leo Liou
71068ddd6d gs201: add sepolicy for ufs_firmware_update process am: 5adecc7433
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22132666

Change-Id: I85257a9819bffd0b5a92d3ec1296fc161595a38f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 10:26:02 +00:00
Leo Liou
5adecc7433 gs201: add sepolicy for ufs_firmware_update process
Allow the script to access the specified partition and sysfs.

Bug: 273305212
Test: full build and test ffu flow
Change-Id: Iefeacea2d4c07e7a5b39713c9575e86bd25ce008
Signed-off-by: Leo Liou <leoliou@google.com>
2023-04-17 09:58:11 +00:00
kadirpili
3ec6b3f87c gs201: Allow GRIL Service to access radio_vendor_data_file am: 1af348b01f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22213304

Change-Id: Ibd5ad2e0a5875b642e7788823a83977d487c2aae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 06:15:48 +00:00
kadirpili
1af348b01f gs201: Allow GRIL Service to access radio_vendor_data_file
Bug: 274737512
Change-Id: I1c0b045f8a25c5d58be02c2036d2fcaad7d9a8e7
2023-04-14 06:57:50 +00:00
Xin Li
2540d05123 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours am: 551330137f -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I3e21b3af19e14ed50e8d714ffe6ddff1c1f0543e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:13:21 +00:00
Xin Li
551330137f [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours am: ba5a2d3863 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Iefd6904aee50936e373590b4d54f492986aaf4dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:09 +00:00
Xin Li
ba5a2d3863 [automerger skipped] Merge TQ2A.230405.003 am: 8cff198ae3 am: 4c44de9655 -s ours
am skip reason: Merged-In I971732c6a40700a85df61170dcf1c3660307b96c with SHA-1 03fb0f6ceb is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: I12f4ac63bb185203b115ae3f77ade5588bd50b10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:23:00 +00:00
Xin Li
4c44de9655 Merge TQ2A.230405.003 am: 8cff198ae3
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2530209

Change-Id: Ibeb863ad3557474eed5f5c8a529f12ed3c8c7768
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:58 +00:00
Minchan Kim
84a917c01c remove dump_gs201 sepolicy am: dc35b4158b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529799

Change-Id: Ibe6ea359df9c31166b616ebc0b488e27ecc74184
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 06:58:24 +00:00
Minchan Kim
d55660c311 move vendor_cma_debugfs into gs-common am: b7393fd8d8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22529798

Change-Id: I0a82d9378491a6fa0c785c96375b92d2dec3acd0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 06:58:18 +00:00
Minchan Kim
dc35b4158b remove dump_gs201 sepolicy
Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I39c01692d959a63c091f98969a69ab35b2debe1a
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Minchan Kim
b7393fd8d8 move vendor_cma_debugfs into gs-common
The CMA dump is common feature for pixel devices so move
it to gs-common.

Bug: 276901078
Test: dumpstate_board.txt on adb bugreport includes the info
Change-Id: I3997e27e3037f013338de5bc36687c63338769aa
Signed-off-by: Minchan Kim <minchan@google.com>
2023-04-12 06:09:00 +00:00
Tommy Kardach
3bbb950763 Update sepolicy for Camera HAL am: 3430e752af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22195719

Change-Id: Id716b3b93066f70536e0f89e25b89bc2566141a0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-11 20:28:17 +00:00
Tommy Kardach
3430e752af Update sepolicy for Camera HAL
Edit SE policay for WHI_PRO to allow
camera HAL to acquire wake locks

Bug: 249567788
Test: Flash and manual testing
Change-Id: I450b0b53000c5b9649e354350ec80af3528120fb
2023-04-11 19:45:33 +00:00
Xin Li
8cff198ae3 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I971732c6a40700a85df61170dcf1c3660307b96c
Change-Id: I33994bb345a46d8ac3f3a751fdff402f4ce5c68f
2023-04-10 23:55:29 -07:00
Adam Shih
00147ddada use dumpsate from gs-common am: 9519323a98
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524762

Change-Id: Ife90f52149915ad7bffc5e542c7507f774e279b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:23 +00:00
Wilson Sung
c2bace2e28 Update error on ROM 9890523 am: 4d92dd61f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22524766

Change-Id: I8622af2b6d6bdee27a378a2e92efeaeb0125aa75
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:02 +00:00
Adam Shih
9519323a98 use dumpsate from gs-common
Bug: 273380985
Test: adb bugreport
Change-Id: Ibd54c0049480810e2aa14074e0ec9c4d611d51ff
2023-04-10 01:11:14 +00:00