Commit graph

883 commits

Author SHA1 Message Date
Konstantin Vyshetsky
d01c7c938b convert_to_ext4.sh: add sepolicy am: 07af2808d5 am: a8e3ff791c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19391424

Change-Id: I05cf9212bb0c85ddf082e90146fe1a2cb9ef322b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 18:32:08 +00:00
Konstantin Vyshetsky
a8e3ff791c convert_to_ext4.sh: add sepolicy am: 07af2808d5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19391424

Change-Id: Id303addc42a444642f827605404dca79044efd37
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 18:17:27 +00:00
Konstantin Vyshetsky
07af2808d5 convert_to_ext4.sh: add sepolicy
Add entries for convert_to_ext4.sh executable.

Bug: 239632964
Signed-off-by: Konstantin Vyshetsky <vkon@google.com>
Change-Id: I0d89aa88dab0ae5a4cf3d7b2e4423d1761868bea
2022-08-01 18:00:49 +00:00
lucaslin
bff13cbb06 [automerger skipped] Add sepolicy for dumpstate to zip tcpdump into bugreport am: 81616f3ad0 am: e798862ff6 -s ours
am skip reason: Merged-In I01b9b25a6236bcfa1ce2b89afb3ed1bc2ef49cae with SHA-1 81616f3ad0 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19466304

Change-Id: Idbb6775c21f72db8e2a93a87d3d379f5878ade99
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 13:11:31 +00:00
lucaslin
b4a1e44f64 Add sepolicy for dumpstate to zip tcpdump into bugreport am: 81616f3ad0 am: 2bfca77c08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19466304

Change-Id: I7ca58e12747568d1fb7e31c0321c899955785c4c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 13:11:26 +00:00
lucaslin
e798862ff6 Add sepolicy for dumpstate to zip tcpdump into bugreport am: 81616f3ad0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19466304

Change-Id: I97d34e9e6d64f470e79d33bd0d277d9f3694d03a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 12:46:32 +00:00
lucaslin
2bfca77c08 Add sepolicy for dumpstate to zip tcpdump into bugreport am: 81616f3ad0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19466304

Change-Id: I8b70cb968c26cc1b5705c308e29a0c4e0bf53e0a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-01 12:46:23 +00:00
lucaslin
81616f3ad0 Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 239634976
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I01b9b25a6236bcfa1ce2b89afb3ed1bc2ef49cae
Merged-In: I01b9b25a6236bcfa1ce2b89afb3ed1bc2ef49cae
(cherry picked from commit ee1b7d6bb4)
2022-08-01 03:00:17 +00:00
Steven Moreland
be28c1d05c Remove vendor_service. am: f10b9bf2cd am: 82c366063e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19441143

Change-Id: I40c6999858b58274485e150fb2c108a099331b2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 01:58:01 +00:00
Steven Moreland
82c366063e Remove vendor_service. am: f10b9bf2cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19441143

Change-Id: Ib8a9d7fec295cdc8a9581f042bc082d83612d33a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 01:07:53 +00:00
Steven Moreland
f10b9bf2cd Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I6795d960aa2a3b3832be8e0f6a11cb0fc3337982
2022-07-26 23:53:54 +00:00
Adam Shih
5208624c3e sync bug_map with downstream am: b34d1c1ed0 am: fcb18faeb1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I8e49824f8c4c68d3af28cee59da2b2aece8fa0b2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:56:10 +00:00
Adam Shih
05991af46f sync bug_map with downstream am: b34d1c1ed0 am: 813e69784d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I93d1b34ef647501e7c99eed163a79f9b190f0b75
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:55:38 +00:00
Adam Shih
fcb18faeb1 sync bug_map with downstream am: b34d1c1ed0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: Id6d9092dd4f1e1b59b911a4bba12aca4f238248e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:32:08 +00:00
Adam Shih
813e69784d sync bug_map with downstream am: b34d1c1ed0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I11105def02ffc78d663ebfdf9548cf111429120b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:31:56 +00:00
Adam Shih
b34d1c1ed0 sync bug_map with downstream
Bug: 239403666
Test: boot
Change-Id: I7e95cc5169ce56f1bba031b4d8a83ab1d5c80b26
Merged-In: If07a3611f40324d985a387c6dd7f2570c90c7c11
2022-07-25 21:05:38 +00:00
Edmond Chung
087f96ccf0 Allow vendor_init to set camera properties am: c09b0f9873 am: ed1f75b8aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: Ic462b751b4d3e3d2d18da39e76d5bf7dd1696a3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:18:35 +00:00
Edmond Chung
12154623dc Allow vendor_init to set camera properties am: c09b0f9873 am: 135261452d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: If7fccd0c50043a74ea95f49426930b87779ef0f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:08:54 +00:00
Edmond Chung
ed1f75b8aa Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I6dd674a0a9dfde23a38137d67a4db4437395600a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:46:05 +00:00
Edmond Chung
135261452d Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I895cb20aa12d6611d09338c2e0dab1748a74aa68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:45:56 +00:00
Edmond Chung
c09b0f9873 Allow vendor_init to set camera properties
Bug: 239368308
Test: Camera CTS
Change-Id: Ia34804235729d5230123431a4b315bb2967c4cc8
2022-07-22 01:44:15 +00:00
Jack Wu
fb3b2b7988 Update SELinux error am: c50018a543
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19379646

Change-Id: I384a3a37914704e167ce7e4363fb319d44111b61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-21 18:24:16 +00:00
Jack Wu
c50018a543 Update SELinux error
Bug: 238398889
Test: no avc denied in TreeHugger verified
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: Ia18714461cb9f30fe110917489adddee98de194f
2022-07-21 21:44:03 +08:00
matthuang
645ab36c29 Add security context for com.google.usf.non_wake_up/wakeup. am: 1c7154c453
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320259

Change-Id: I1347e599954db1455332c5e1304705a65e790770
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 07:09:06 +00:00
matthuang
1c7154c453 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I86c787d59203464fc3b8b2b94b4883cbd07196b0
2022-07-19 06:53:48 +00:00
Robin Peng
8368a0a967 init-insmod-sh: fix avc error am: dfc95d0774
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320251

Change-Id: I4253cddfc840c0a72ebd9943a21fac8be2b2981d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-18 10:31:40 +00:00
Robin Peng
dfc95d0774 init-insmod-sh: fix avc error
avc: denied { set } for property=vendor.all.modules.ready pid=1238 uid=0 gid=0 scontext=u:r:init-insmod-sh:s0 tcontext=u:object_r:vendor_ready_prop:s0 tclass=property_service permissive=0

Bug: 238853979
Signed-off-by: Robin Peng <robinpeng@google.com>
Change-Id: Ic8d7af3c1d73f3079e126b66b38d728fe4d70ea4
2022-07-18 04:54:57 +00:00
Robb Glasser
0e855aa924 Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I0bbc8360988917f283cdd4013142f68258077bdc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:34:39 +00:00
Robb Glasser
5325bbdf2f Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib0f872ffa8e66cee2fe4b12adb02463b450d42fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:33:37 +00:00
Robb Glasser
76ff3ba367 Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I003515c35a34416c0c49fe1267ba9ed54c9e2f8c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:43 +00:00
Robb Glasser
b93c3b981b Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib1b79c1528832a2705dcee251e2b239cef63455e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:41 +00:00
Robb Glasser
46c4571485 Remove HAL sensors dontaudits.
Sensors HAL sepolicy is written, but the dontaudit parts were not
cleaned up at the time. Removing these as they are no longer needed.

Bug: 227695036
Test: No denials as expected.
Change-Id: Idc0ed7f380cb07bfc7695ef3019f335fd8fad0a2
2022-07-13 11:06:04 -07:00
Kyle Tso
6218ff00ec Add logbuffer file_contexts am: c2ed52536e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Ibd266344d154338c48672da6d949edd10cc7da40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:40:25 +00:00
Kyle Tso
c2ed52536e Add logbuffer file_contexts
Bug: 237082721
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: Ieaf04f7381db1febe5a3899a727b6a49726bf10b
2022-07-09 07:22:55 +00:00
Star Chang
83eec39629 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: I12a467b4ef37fa13ff82e1adc66d504430247e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:15:02 +00:00
Star Chang
30af05ede4 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If4468131df2226ac09aa0a20892147bd872e4a4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:14:42 +00:00
Star Chang
932cf00952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If9f48a717ec9ae82dda176dfcd1a5b26651028ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:32 +00:00
Star Chang
407c14d952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ia20b4d2e67577ccb0fa1f3ef7176f62161ad5ddc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:31 +00:00
Star Chang
c466a68305 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware
related files.

Add policy to allow wifi_sniffer daemon to access wifi firmware related
files.

To fix the denial message:
[85544.205505] type=1400 audit(1656381950.486:90): avc: denied { search
} for comm="wifi_sniffer" name="wifi" dev="sysfs" ino=97256
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=dir permissive=1
[85544.206027] type=1400 audit(1656381950.486:91): avc: denied { write }
for comm="wifi_sniffer" name="firmware_path" dev="sysfs" ino=97268
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206206] type=1400 audit(1656381950.486:92): avc: denied { open }
for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206349] type=1400 audit(1656381950.486:93): avc: denied { getattr
} for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1

Bug: 237465412
Test: wifi_sniffer is workable
Change-Id: I5500be87d2b670e29c08d026872a6b304109f7a3
2022-07-07 06:15:48 +00:00
Adam Shih
16d8257567 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Ice227542ecee1a6359825027cd6ce5c90c3e6e90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:37 +00:00
Adam Shih
2a92d64cdb Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id0e75a481c2c3f1d482d10af4d8bbbf37ff79f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:23 +00:00
Adam Shih
2fc31f23a8 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I3ecdc79d72c83e9ec7496303f054da857a3b0cad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:16 +00:00
Adam Shih
dd8eab3bf9 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I4cacf54cd9bb9127de89ad5a77c489c26b5744bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:14 +00:00
Adam Shih
74ff6db973 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
Merged-In: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 03:11:33 +00:00
matthuang
11ecc1dd92 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: I91928227a99bede90714c93841592e9a91aeff6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:06 +00:00
matthuang
a1b5481877 Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: Ib97da81a01f566c7bd600512bb01fda27f34b217
2022-07-01 02:16:08 +00:00
SalmaxChang
6cb0e32470 ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6e559d5541d26742effd95d0f421ea18d1d58e20
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:36:00 +00:00
SalmaxChang
90058742f5 ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6ab19b09ec866b6667623a335440f351d73b86b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:35:36 +00:00
SalmaxChang
69172f08c9 ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ib3fb750345c86fc2c8f66ad27a73cec264884c3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:28 +00:00
SalmaxChang
3a3a53efaf ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ic2d4855d462d99b380160a446e201196c74e5930
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:25 +00:00