Commit graph

1796 commits

Author SHA1 Message Date
Kyle Tso
6218ff00ec Add logbuffer file_contexts am: c2ed52536e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Ibd266344d154338c48672da6d949edd10cc7da40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:40:25 +00:00
Kyle Tso
c2ed52536e Add logbuffer file_contexts
Bug: 237082721
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: Ieaf04f7381db1febe5a3899a727b6a49726bf10b
2022-07-09 07:22:55 +00:00
Daniel Angell
3adb31f004 Remove dontaudit rules related to storageproxyd's /data access.
Removing dontaudits for both tracking_denials/tee.te and
whitechapel_pro/tee.te results in no new audit log messages related to
storageproxyd, so they can both be removed.

Bug: 215649571
Test: adb logcat | grep -iE 'storageproxyd'

Change-Id: I8dc735bcaf0725c8d4eab4587f7a7fce21f4e25c
2022-07-07 18:37:23 +00:00
Star Chang
b37cb131ce wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952 am: 83eec39629
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie344b22cbf59832fe4bd73f13a78308f32f13a4f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:46:32 +00:00
Star Chang
9e803338be wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952 am: 30af05ede4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie4a340374c5e59bdba96528b6d717c2ce0c72281
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:45:57 +00:00
Star Chang
83eec39629 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: I12a467b4ef37fa13ff82e1adc66d504430247e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:15:02 +00:00
Star Chang
30af05ede4 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If4468131df2226ac09aa0a20892147bd872e4a4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:14:42 +00:00
Star Chang
932cf00952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If9f48a717ec9ae82dda176dfcd1a5b26651028ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:32 +00:00
Star Chang
407c14d952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ia20b4d2e67577ccb0fa1f3ef7176f62161ad5ddc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:31 +00:00
Star Chang
c466a68305 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware
related files.

Add policy to allow wifi_sniffer daemon to access wifi firmware related
files.

To fix the denial message:
[85544.205505] type=1400 audit(1656381950.486:90): avc: denied { search
} for comm="wifi_sniffer" name="wifi" dev="sysfs" ino=97256
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=dir permissive=1
[85544.206027] type=1400 audit(1656381950.486:91): avc: denied { write }
for comm="wifi_sniffer" name="firmware_path" dev="sysfs" ino=97268
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206206] type=1400 audit(1656381950.486:92): avc: denied { open }
for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206349] type=1400 audit(1656381950.486:93): avc: denied { getattr
} for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1

Bug: 237465412
Test: wifi_sniffer is workable
Change-Id: I5500be87d2b670e29c08d026872a6b304109f7a3
2022-07-07 06:15:48 +00:00
Jenny Ho
eeced97ca9 fix avc error for fg_model/registers
remove tracking with fix http://ag/19145061

Bug: 226271913
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Idaa9e75a013dc7c78234bff041819c3c131f3793
2022-07-07 06:14:42 +00:00
Adam Shih
e87fbe539d Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238260726
Bug: 238260742
Bug: 238260741
Change-Id: Ia3796d62a044b6c0e55c280918251f48143cfd0f
2022-07-07 10:23:05 +08:00
Adam Shih
2bd613cfe6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 227121550
Change-Id: I3e5c653a63b099aa44a880c4d1b2a327415f4d97
2022-07-06 01:24:15 +00:00
Denny cy Lee
7bb9a6aaf4 HwInfo: remove -sepolicy/tracking_denials/hardware_info_app.te
Bug: 208909060
Test: not avc log for hardware_info_app
Change-Id: I52dd55bcea0dd70f60d9156937861ef2036dc46d
Signed-off-by: Denny cy Lee <dennycylee@google.com>
2022-07-06 01:24:08 +00:00
Adam Shih
16e427a5a0 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours am: 16d8257567 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I34420aab930503c068baa3ee460e2d416e141650
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:13:05 +00:00
Adam Shih
7c6f0dd4bc [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9 am: 2a92d64cdb -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 c0ec14b9b1 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id085736a3b35da29a111ca4ae71460aa1d6bc3c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:12:57 +00:00
Adam Shih
16d8257567 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Ice227542ecee1a6359825027cd6ce5c90c3e6e90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:37 +00:00
Adam Shih
2a92d64cdb Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id0e75a481c2c3f1d482d10af4d8bbbf37ff79f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:23 +00:00
Adam Shih
2fc31f23a8 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I3ecdc79d72c83e9ec7496303f054da857a3b0cad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:16 +00:00
Adam Shih
dd8eab3bf9 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I4cacf54cd9bb9127de89ad5a77c489c26b5744bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:14 +00:00
Adam Shih
74ff6db973 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
Merged-In: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 03:11:33 +00:00
Adam Shih
c0ec14b9b1 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 11:10:34 +08:00
Alex Hong
3439f51f28 Remove googlebattery from dontaduit list
Bug: 237700766
Bug: 237491814
Test: PtsSELinuxTestCases
Change-Id: Ic4119e552827a490ba829a80cd10c5fc3ba1d35e
2022-07-01 16:59:04 +08:00
matthuang
58e7856f01 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877 am: 11ecc1dd92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: Ibe2f4ef31da08df20c7f3524bef19279c4935aab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 03:12:21 +00:00
matthuang
11ecc1dd92 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: I91928227a99bede90714c93841592e9a91aeff6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:06 +00:00
matthuang
a1b5481877 Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: Ib97da81a01f566c7bd600512bb01fda27f34b217
2022-07-01 02:16:08 +00:00
SalmaxChang
5631fe741c ssr_detector_app: remove tracking denials
Avc errors already fixed. Remove tracking denials.

Bug: 205202542
Change-Id: I08522d563de58e4bc2be2c4a1bea54bbeac6adb8
2022-06-30 07:39:34 +00:00
sukiliu
b5edce085f Update avc error on ROM 8780665
Bug: 237491813
Bug: 237492145
Bug: 237491814
Bug: 237492146
Bug: 237492091
Test: PtsSELinuxTestCases
Change-Id: I615453d58ea17306ceefe6195bc95974de0f259b
2022-06-30 05:53:29 +00:00
SalmaxChang
ec3f03ee7a ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9 am: 6cb0e32470
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I00832bf3c76d97951cee3cfddc2bf5b548ca5071
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 18:30:16 +00:00
SalmaxChang
073c59da08 [automerger skipped] ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf am: 90058742f5 -s ours
am skip reason: skipped by user salmaxchang

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I2b3175ecde53fb5d0cdd69c74ba8590d849e6ad2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 18:30:05 +00:00
SalmaxChang
6cb0e32470 ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6e559d5541d26742effd95d0f421ea18d1d58e20
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:36:00 +00:00
SalmaxChang
90058742f5 ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6ab19b09ec866b6667623a335440f351d73b86b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:35:36 +00:00
SalmaxChang
69172f08c9 ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ib3fb750345c86fc2c8f66ad27a73cec264884c3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:28 +00:00
SalmaxChang
3a3a53efaf ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ic2d4855d462d99b380160a446e201196c74e5930
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:25 +00:00
SalmaxChang
a7127617ba ssr_detector_app: remove tracking denials
Avc errors already fixed. Remove tracking denials.

Bug: 207571417
Bug: 205202542
Change-Id: I97d5f732e038dbdaf7885bdb9ca63bc518a97d51
2022-06-29 15:52:43 +00:00
sashwinbalaji
f131707b2a thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg file
Change-Id: I3d43a393d76e7245e48ebcf9592c7e230c58d9bd
2022-06-29 07:43:15 +00:00
xiaofanj
0a11e59639 [automerger skipped] modem_svc_sit: create oem test iodev am: da328e0a0f am: a0de630cd7 -s ours
am skip reason: Merged-In Id06deedadf04c70b57e405a05533ed85764bdd1d with SHA-1 b3576ef751 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18768560

Change-Id: I0ce76b9180a3cd22452535e501b9ec54a63168a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-28 03:52:57 +00:00
xiaofanj
a0de630cd7 modem_svc_sit: create oem test iodev am: da328e0a0f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18768560

Change-Id: I36bb28394d68d266130135665f565f4be68569ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-28 03:34:47 +00:00
xiaofanj
da328e0a0f modem_svc_sit: create oem test iodev
- Create radio_test_device for oem_test iodev.
- Grant modem_svc_sit to access radio_test_device.

Bug: 231380480

Signed-off-by: Xiaofan Jiang <xiaofanj@google.com>
Change-Id: Id06deedadf04c70b57e405a05533ed85764bdd1d
Merged-In: Id06deedadf04c70b57e405a05533ed85764bdd1d
2022-06-28 03:16:08 +00:00
Sam Ou
7bf0763083 sepolicy: fix odpm avc denials am: 65bdbc4862 am: 30d46d274b am: da2ba2a04c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ia02fc75749b5078912d9a28470a9e295954c367e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:28:46 +00:00
Sam Ou
e85fc072c7 sepolicy: fix odpm avc denials am: 65bdbc4862 am: eee2b6fe84 am: c12c06c778
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ie39212fd1352be7e25f1d0f428787c03698e1578
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:28:37 +00:00
Sam Ou
da2ba2a04c sepolicy: fix odpm avc denials am: 65bdbc4862 am: 30d46d274b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ibd2aea9997607f1b444ca652a98ac84a877548b4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:11:22 +00:00
Sam Ou
c12c06c778 sepolicy: fix odpm avc denials am: 65bdbc4862 am: eee2b6fe84
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ic9b3c402e49d92a64bbe432fe2c1dc8d9e26b6fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:11:02 +00:00
Sam Ou
30d46d274b sepolicy: fix odpm avc denials am: 65bdbc4862
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ieb89884ee444ba9eb06e23f8ab4d20a96fa8c323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 06:48:52 +00:00
Sam Ou
eee2b6fe84 sepolicy: fix odpm avc denials am: 65bdbc4862
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: I4b40035d0cfe661da8f78d81fdc500f27f2ca619
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 06:48:49 +00:00
Sam Ou
65bdbc4862 sepolicy: fix odpm avc denials
add wakeup permissions for odpm driver
since we update acc_data based on alarmtimer

Bug: 236798116
Change-Id: Ib898eeebf0e26a723f260a2a8ddb5e5f64d255ed
Signed-off-by: Sam Ou <samou@google.com>
2022-06-27 06:29:03 +00:00
sukiliu
b018d1469e [automerger skipped] [Do not merge] Remove regmap from list am: 1f681630c4 am: 9eadb411f8 am: c9d05f0e26 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18845251

Change-Id: I3e360001cae829f62dcb11fdd5a4e81e65215b03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 04:35:27 +00:00
sukiliu
2c9df67e81 [automerger skipped] [Do not merge] Remove regmap from list am: 1f681630c4 am: 1a1716f53e am: 4e9fbe7074 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18845251

Change-Id: I70a89b0bb732d8f960e2f57b1f2f930a8bd67855
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 04:35:20 +00:00
sukiliu
c9d05f0e26 [Do not merge] Remove regmap from list am: 1f681630c4 am: 9eadb411f8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18845251

Change-Id: I933bdd49496eb4a5ca9aaf03c78ce40153bb8de4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 04:18:01 +00:00
sukiliu
4e9fbe7074 [Do not merge] Remove regmap from list am: 1f681630c4 am: 1a1716f53e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18845251

Change-Id: I9c5f9b9f083074d932233c365d31b4b8894dbc0d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 04:17:44 +00:00