Commit graph

1828 commits

Author SHA1 Message Date
Tri Vo
13f3fdc8ff storageproxyd: Remove setuid/setgid SELinux permissions
Bug: 205904330
Test: fingerprint enrollment/authentication
Change-Id: Ied64163f1142c1dd05274867c2863592e49042f3
2022-07-22 17:30:42 +00:00
sukiliu
eabd743991 Remove regmap from list
Bug: 227286343
Test: PtsSELinuxTestCases
Change-Id: I0df048e6944623d992f66688550e534c038714d9
2022-07-22 04:19:13 +00:00
Edmond Chung
45ae1ce63f Allow vendor_init to set camera properties am: c09b0f9873 am: ed1f75b8aa am: 087f96ccf0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I9bf633cebf8fc4dbd5fe1459d46f682399d2b20f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:35:32 +00:00
Edmond Chung
b9337d2ab3 Allow vendor_init to set camera properties am: c09b0f9873 am: 135261452d am: 12154623dc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I6c2f9ec9433c1d2be00baebf59172f5cd6a48132
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:35:13 +00:00
Edmond Chung
087f96ccf0 Allow vendor_init to set camera properties am: c09b0f9873 am: ed1f75b8aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: Ic462b751b4d3e3d2d18da39e76d5bf7dd1696a3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:18:35 +00:00
Edmond Chung
12154623dc Allow vendor_init to set camera properties am: c09b0f9873 am: 135261452d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: If7fccd0c50043a74ea95f49426930b87779ef0f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:08:54 +00:00
Edmond Chung
ed1f75b8aa Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I6dd674a0a9dfde23a38137d67a4db4437395600a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:46:05 +00:00
Edmond Chung
135261452d Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I895cb20aa12d6611d09338c2e0dab1748a74aa68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:45:56 +00:00
Edmond Chung
c09b0f9873 Allow vendor_init to set camera properties
Bug: 239368308
Test: Camera CTS
Change-Id: Ia34804235729d5230123431a4b315bb2967c4cc8
2022-07-22 01:44:15 +00:00
Jack Wu
49b9a9a859 Update SELinux error am: c50018a543 am: fb3b2b7988
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19379646

Change-Id: I2319322791af38d9d4e44591a18f56d1a8f6dd3b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-21 18:42:52 +00:00
Jack Wu
fb3b2b7988 Update SELinux error am: c50018a543
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19379646

Change-Id: I384a3a37914704e167ce7e4363fb319d44111b61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-21 18:24:16 +00:00
Jack Wu
c50018a543 Update SELinux error
Bug: 238398889
Test: no avc denied in TreeHugger verified
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: Ia18714461cb9f30fe110917489adddee98de194f
2022-07-21 21:44:03 +08:00
Adam Shih
ebd7170495 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 239632439
Change-Id: I42608d6fc5b3128915f7801e9000548a12ce7efa
2022-07-20 09:12:17 +08:00
matthuang
fdccd0cf8f Add security context for com.google.usf.non_wake_up/wakeup. am: 1c7154c453 am: 645ab36c29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320259

Change-Id: Ie4bcb4c86598a7dbbef05f22daa64b84fb54a5f2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 07:37:23 +00:00
matthuang
645ab36c29 Add security context for com.google.usf.non_wake_up/wakeup. am: 1c7154c453
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320259

Change-Id: I1347e599954db1455332c5e1304705a65e790770
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 07:09:06 +00:00
matthuang
1c7154c453 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I86c787d59203464fc3b8b2b94b4883cbd07196b0
2022-07-19 06:53:48 +00:00
Adam Shih
2c3812aac3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 239484651
Bug: 239484612
Change-Id: If07a3611f40324d985a387c6dd7f2570c90c7c11
2022-07-19 09:07:27 +08:00
Robin Peng
209af1944d init-insmod-sh: fix avc error am: dfc95d0774 am: 8368a0a967
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320251

Change-Id: Ic192f137eaf63c16cb942cd13490a62bfde27c9c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-18 10:58:50 +00:00
Robin Peng
8368a0a967 init-insmod-sh: fix avc error am: dfc95d0774
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320251

Change-Id: I4253cddfc840c0a72ebd9943a21fac8be2b2981d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-18 10:31:40 +00:00
Robin Peng
dfc95d0774 init-insmod-sh: fix avc error
avc: denied { set } for property=vendor.all.modules.ready pid=1238 uid=0 gid=0 scontext=u:r:init-insmod-sh:s0 tcontext=u:object_r:vendor_ready_prop:s0 tclass=property_service permissive=0

Bug: 238853979
Signed-off-by: Robin Peng <robinpeng@google.com>
Change-Id: Ic8d7af3c1d73f3079e126b66b38d728fe4d70ea4
2022-07-18 04:54:57 +00:00
Adam Shih
52ec99ce41 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 239364360
Change-Id: I6ea0b1a4fabd7ac29470afa48a0d84beccf0af28
2022-07-18 10:55:53 +08:00
Adam Shih
5eda61d1e0 Update SELinux error
Bug: 234547283
Change-Id: I81b2885e2b7c7f77f76bc6048c901dfc4226a4fb
2022-07-15 00:30:06 +00:00
Robb Glasser
13cdb1a7ad Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367 am: 0e855aa924
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: If5b2e6ca7aae3b9a97cf154126116acc26399b54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:53:55 +00:00
Robb Glasser
6652430fc4 Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b am: 5325bbdf2f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ifed619dba499bd940ff2c7019b7c3d6ef6e5998e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:53:05 +00:00
Robb Glasser
0e855aa924 Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I0bbc8360988917f283cdd4013142f68258077bdc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:34:39 +00:00
Robb Glasser
5325bbdf2f Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib0f872ffa8e66cee2fe4b12adb02463b450d42fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:33:37 +00:00
Robb Glasser
76ff3ba367 Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I003515c35a34416c0c49fe1267ba9ed54c9e2f8c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:43 +00:00
Robb Glasser
b93c3b981b Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib1b79c1528832a2705dcee251e2b239cef63455e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:41 +00:00
Robb Glasser
46c4571485 Remove HAL sensors dontaudits.
Sensors HAL sepolicy is written, but the dontaudit parts were not
cleaned up at the time. Removing these as they are no longer needed.

Bug: 227695036
Test: No denials as expected.
Change-Id: Idc0ed7f380cb07bfc7695ef3019f335fd8fad0a2
2022-07-13 11:06:04 -07:00
Adam Shih
9899069adb Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238705599
Change-Id: Ia78ce7f5b2adc41f7d64b99279681acce647e8bb
2022-07-12 12:49:17 +08:00
Adam Shih
1e606d96f1 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238571150
Change-Id: Idb8c4f3e99d23e73fe2e63beec1142d1207c0a05
2022-07-11 10:24:25 +08:00
Kyle Tso
6ddb00d0c5 Add logbuffer file_contexts am: c2ed52536e am: 6218ff00ec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Iaa6476fe43b2975bfe3c38f045f93b7a57ba61e3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:57:47 +00:00
Kyle Tso
6218ff00ec Add logbuffer file_contexts am: c2ed52536e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Ibd266344d154338c48672da6d949edd10cc7da40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:40:25 +00:00
Kyle Tso
c2ed52536e Add logbuffer file_contexts
Bug: 237082721
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: Ieaf04f7381db1febe5a3899a727b6a49726bf10b
2022-07-09 07:22:55 +00:00
Daniel Angell
3adb31f004 Remove dontaudit rules related to storageproxyd's /data access.
Removing dontaudits for both tracking_denials/tee.te and
whitechapel_pro/tee.te results in no new audit log messages related to
storageproxyd, so they can both be removed.

Bug: 215649571
Test: adb logcat | grep -iE 'storageproxyd'

Change-Id: I8dc735bcaf0725c8d4eab4587f7a7fce21f4e25c
2022-07-07 18:37:23 +00:00
Star Chang
b37cb131ce wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952 am: 83eec39629
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie344b22cbf59832fe4bd73f13a78308f32f13a4f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:46:32 +00:00
Star Chang
9e803338be wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952 am: 30af05ede4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie4a340374c5e59bdba96528b6d717c2ce0c72281
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:45:57 +00:00
Star Chang
83eec39629 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: I12a467b4ef37fa13ff82e1adc66d504430247e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:15:02 +00:00
Star Chang
30af05ede4 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If4468131df2226ac09aa0a20892147bd872e4a4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:14:42 +00:00
Star Chang
932cf00952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If9f48a717ec9ae82dda176dfcd1a5b26651028ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:32 +00:00
Star Chang
407c14d952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ia20b4d2e67577ccb0fa1f3ef7176f62161ad5ddc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:31 +00:00
Star Chang
c466a68305 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware
related files.

Add policy to allow wifi_sniffer daemon to access wifi firmware related
files.

To fix the denial message:
[85544.205505] type=1400 audit(1656381950.486:90): avc: denied { search
} for comm="wifi_sniffer" name="wifi" dev="sysfs" ino=97256
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=dir permissive=1
[85544.206027] type=1400 audit(1656381950.486:91): avc: denied { write }
for comm="wifi_sniffer" name="firmware_path" dev="sysfs" ino=97268
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206206] type=1400 audit(1656381950.486:92): avc: denied { open }
for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206349] type=1400 audit(1656381950.486:93): avc: denied { getattr
} for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1

Bug: 237465412
Test: wifi_sniffer is workable
Change-Id: I5500be87d2b670e29c08d026872a6b304109f7a3
2022-07-07 06:15:48 +00:00
Jenny Ho
eeced97ca9 fix avc error for fg_model/registers
remove tracking with fix http://ag/19145061

Bug: 226271913
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Idaa9e75a013dc7c78234bff041819c3c131f3793
2022-07-07 06:14:42 +00:00
Adam Shih
e87fbe539d Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238260726
Bug: 238260742
Bug: 238260741
Change-Id: Ia3796d62a044b6c0e55c280918251f48143cfd0f
2022-07-07 10:23:05 +08:00
Adam Shih
2bd613cfe6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 227121550
Change-Id: I3e5c653a63b099aa44a880c4d1b2a327415f4d97
2022-07-06 01:24:15 +00:00
Denny cy Lee
7bb9a6aaf4 HwInfo: remove -sepolicy/tracking_denials/hardware_info_app.te
Bug: 208909060
Test: not avc log for hardware_info_app
Change-Id: I52dd55bcea0dd70f60d9156937861ef2036dc46d
Signed-off-by: Denny cy Lee <dennycylee@google.com>
2022-07-06 01:24:08 +00:00
Adam Shih
16e427a5a0 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours am: 16d8257567 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I34420aab930503c068baa3ee460e2d416e141650
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:13:05 +00:00
Adam Shih
7c6f0dd4bc [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9 am: 2a92d64cdb -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 c0ec14b9b1 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id085736a3b35da29a111ca4ae71460aa1d6bc3c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:12:57 +00:00
Adam Shih
16d8257567 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Ice227542ecee1a6359825027cd6ce5c90c3e6e90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:37 +00:00
Adam Shih
2a92d64cdb Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id0e75a481c2c3f1d482d10af4d8bbbf37ff79f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:23 +00:00