Commit graph

180 commits

Author SHA1 Message Date
matthuang
1c7154c453 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I86c787d59203464fc3b8b2b94b4883cbd07196b0
2022-07-19 06:53:48 +00:00
sashwinbalaji
f131707b2a thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg file
Change-Id: I3d43a393d76e7245e48ebcf9592c7e230c58d9bd
2022-06-29 07:43:15 +00:00
Sam Ou
e85fc072c7 sepolicy: fix odpm avc denials am: 65bdbc4862 am: eee2b6fe84 am: c12c06c778
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ie39212fd1352be7e25f1d0f428787c03698e1578
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:28:37 +00:00
Sam Ou
eee2b6fe84 sepolicy: fix odpm avc denials am: 65bdbc4862
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: I4b40035d0cfe661da8f78d81fdc500f27f2ca619
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 06:48:49 +00:00
Sam Ou
65bdbc4862 sepolicy: fix odpm avc denials
add wakeup permissions for odpm driver
since we update acc_data based on alarmtimer

Bug: 236798116
Change-Id: Ib898eeebf0e26a723f260a2a8ddb5e5f64d255ed
Signed-off-by: Sam Ou <samou@google.com>
2022-06-27 06:29:03 +00:00
Jack Wu
3acd9670ae sepolicy: allows pixelstat to access pca file nodes am: 2ee67a6bf3 am: b0f67d6ab5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18868952

Change-Id: I8a18598a13eefd92de22e87166c1aba4f63cff39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-17 20:34:16 +00:00
Jack Wu
2ee67a6bf3 sepolicy: allows pixelstat to access pca file nodes
Bug: 235050913
Test: no Permission denied while accessing the file node
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: I7de0a374e1c98f4e9bbf36e39cb0131b0e9ffebc
2022-06-17 02:52:35 +00:00
Minchan Kim
7da3903226 allow hal_dumpstate_default to access cma debugfs am: 4bc7128afe am: 10398a5cbb am: 62afd7445e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18843535

Change-Id: Ibe84bcad191c6f5cea8f25894fce4e5b707a4f3f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-13 23:46:51 +00:00
Minchan Kim
4bc7128afe allow hal_dumpstate_default to access cma debugfs
It's useful for CMA memory debugging.

Bug: 233535442
Test: adb bugreport contains cma information in dumpstate_board.txt
Signed-off-by: Minchan Kim <minchan@google.com>
Change-Id: I65170d6b84f642e038a7901427c3673b40832af9
2022-06-13 22:35:38 +00:00
Oleg Matcovschi
e42f591b8d sepolicy: add sscoredump mali genfs rule am: c7bcfba2cb am: 06c0bb9b68 am: c622ae0997
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18839008

Change-Id: I49a2d975adf6056efbc089c1086c6ffdb29ef52a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-13 20:43:58 +00:00
Oleg Matcovschi
c7bcfba2cb sepolicy: add sscoredump mali genfs rule
Bug: 235492324
Signed-off-by: Oleg Matcovschi <omatcovschi@google.com>
Change-Id: I8a5db9b4d0a6f63819820213e20165dbe920ab07
2022-06-13 18:08:04 +00:00
Adam Shih
8d011823ed allow dumpstate to access sde partition
Bug: 221384768
Test: do bugreport without relevant error log
Change-Id: I26b0246f8d99a5efce8f7d1b65fa50faafb599e2
2022-06-13 13:11:12 +08:00
Ken Chen
dce5aed49a fix sepolicy for net devices am: d0bbe71217 am: 879752df15 am: 819f8714d7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18821530

Change-Id: I6590305eba442878f3e06c69b82f991b37a9778c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-10 15:36:34 +00:00
Ken Chen
d0bbe71217 fix sepolicy for net devices
bug: 222232008
Test: atest NetdSELinuxTest#CheckProperMTULabels
Change-Id: I99f70eefa3259a2da556fed6ced70f32d03ff4bb
2022-06-10 18:20:19 +08:00
Ankit Goyal
c4a5886408 Add SE policies for memtrack HAL am: 5be857af43 am: b6ff456519 am: ab71f17d11
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18638327

Change-Id: Ib44be45f890b5c1913a05c5bf928b26830dbfd2c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-01 00:24:42 +00:00
Ankit Goyal
5be857af43 Add SE policies for memtrack HAL
Bug: 220360577
Test: adb shell dumpsys meminfo
Change-Id: I4dfc0c016ccf980b4f7dabd2fb70d2466b69b5cc
2022-05-31 23:25:27 +00:00
Taeju Park
561f288e51 Pixel-EM-DriverV2: sepolicy: allows Power HAL to am: eb4d432dd8 am: f292277bbd am: 57f67fa7a1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18635845

Change-Id: Idaeec47d1883e0ad3c7883ed4a5a027647f28b5a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-31 22:08:18 +00:00
Taeju Park
eb4d432dd8 Pixel-EM-DriverV2: sepolicy: allows Power HAL to
modify em_profile related sysfs nodes

Bug: 170647767
Signed-off-by: Taeju Park <taeju@google.com>
Change-Id: I160741f172a5713535852e7fb0d12126ddf0395e
2022-05-31 20:38:29 +00:00
Jenny Ho
b5d2b601bb sepolicy: allow access debugfs charger register dump am: 5e426a95d0 am: ff33c561a8 am: c26bb54bb0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ic874dc00411a152cb84a5c66742743dffd467ccc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 08:45:49 +00:00
Jenny Ho
5e426a95d0 sepolicy: allow access debugfs charger register dump
Bug: 230360103
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Ieedff4d6475706d4d932913e6d647ca401e56966
2022-05-03 06:54:05 +00:00
Labib
ea9c058272 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: b68668828d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I1a3b4c1c894a547a2a4f4e34270124476f3b2568
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:30:34 +00:00
Labib
177a3796e8 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: Iec721cea68d7eae8715537b887911c0f848e1e6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:07:36 +00:00
Labib
4c8dbb65b8 Give RadioExt permission to write to sysfs node
Bug: 212601547
Test: Manual
Change-Id: I8c7341833aeacebfedba6e8e05d2696012043d32
2022-04-28 16:58:34 +08:00
Stephane Lee
7a62941f36 Fix permissions for ODPM permanently by adding all buses am: 85e5caf85e am: df77f4ec83 am: bd30d9e7f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966244

Change-Id: I9e510554eae6ceeb0189d390384dae21a46bf4af
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 02:36:48 +00:00
Stephane Lee
85e5caf85e Fix permissions for ODPM permanently by adding all buses
You don't need wildcards on genfs, just need the base path

Bug: 229895015
Test: Ensure the device boots, verify permissions with ls -AlZ
Change-Id: Ib59693f0404db4e28b9959fcdf1cc4d483c5d1b1
2022-04-27 01:06:36 +00:00
Wei Wang
8307f850e0 Grant trusty to power hal am: 90f4106b80 am: 6c85eeac05 am: ae95ea381c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17928564

Change-Id: Ia44c194133e280d40fa6964e933e9b43cb551423
Ignore-AOSP-First: this is an automerge
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-26 18:00:44 +00:00
Wei Wang
90f4106b80 Grant trusty to power hal
Bug: 229350721
Test: UDFPS with stress
Signed-off-by: Wei Wang <wvw@google.com>
Change-Id: Ia88d6cff1d21940e22ae5122dbfcf52de27ad700
2022-04-23 21:53:44 -07:00
Chung-Kai (Michael) Mei
263a0fbc7d Revert "genfs_contexts: fix path for i2c peripheral device" am: ac45672cc5 am: 30daffff0f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17865266

Change-Id: Ie01963871c54ed681f56929ff3dc1e0fff439db5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 09:16:04 +00:00
Chung-Kai (Michael) Mei
26b3d89302 Revert "genfs_contexts: fix path for i2c peripheral device" am: ac45672cc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17865266

Change-Id: I5b4670792368963bd1fe1b6015523bd9dd0f00d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 08:02:41 +00:00
Chung-Kai (Michael) Mei
ac45672cc5 Revert "genfs_contexts: fix path for i2c peripheral device"
This reverts commit 4db0feed32.

Reason for revert: related patch is merged, so it's duplicated

Fix: 229940065
Change-Id: I898dd52f4857983323fec9f72e797bd2f759f724
2022-04-21 07:28:09 +00:00
chungkai
671bbb1107 genfs_contexts: fix path for i2c peripheral device am: 4db0feed32 am: e9b8bcee10
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17866185

Change-Id: Id01cb27905686589b839a59d0d80fe6838cfc6d0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 07:06:31 +00:00
Stephane Lee
fa50c902b1 Fix boot issues with hal_thermal_default am: 9fdfcb53b5 am: 1b99d23ddd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17877853

Change-Id: Ibcdb13986b535c1d839838222c41bd438883d8c4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 07:06:24 +00:00
chungkai
75b598a98b genfs_contexts: fix path for i2c peripheral device am: 4db0feed32
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17866185

Change-Id: Ie6c3f511a21fa3c50af2c8a138ca81c601eb26ca
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 06:49:05 +00:00
Stephane Lee
adc37c2bdf Fix boot issues with hal_thermal_default am: 9fdfcb53b5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17877853

Change-Id: Ie32473dbd4dd7f663da8a7cd687ffb548a717034
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 06:48:59 +00:00
chungkai
4db0feed32 genfs_contexts: fix path for i2c peripheral device
add original paths since we reverted enable load
module in parallel for other issues

Test: without avc denial
Bug: 229670628
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ie7a2a78eae5d6965beedc0de640ec56acb6a7b2a
2022-04-21 06:33:21 +00:00
Stephane Lee
9fdfcb53b5 Fix boot issues with hal_thermal_default
Bug: 229895015
Test: Ensure the device boots, verify permissions with ls -AlZ
Change-Id: I0f95bb7eb58e6ce22a0f66a70408fdf56d94b1b3
2022-04-21 06:30:34 +00:00
chungkai
3902918365 sepolicy: fix avc denials am: 32bf1ffbf7 am: 3a8df849f1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17800453

Change-Id: I78260403080263c6f8971c1d0c4a3b72b59d899b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-20 03:28:27 +00:00
chungkai
3ab10a4ca3 sepolicy: fix avc denials am: 32bf1ffbf7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17800453

Change-Id: Iafb00b0878360210b8c55ca21f90cb814758eeab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-20 03:02:50 +00:00
chungkai
32bf1ffbf7 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 226887726
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I4af39bb6e620a59e02417a06c1dabd45df360fc3
2022-04-20 02:22:31 +00:00
chungkai
319be9e317 sepolicy: fix avc denials am: d80900ae17 am: beefac99c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I77bbb44d3cb34d695e34712e02abcfbc7cff5c99
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 07:01:04 +00:00
chungkai
efb75b5ced sepolicy: fix avc denials am: d80900ae17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I13bbf5aaa37f0855cce70a0ef06ac50fc1ad9006
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 06:39:45 +00:00
chungkai
d80900ae17 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 228947596
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I2e9fa011c049e32011c5880218dd679e03316e24
2022-04-15 02:56:55 +00:00
chungkai
7c43e4e343 sepolicy: fix avc denials am: d37777dd33 am: e240db0a69
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I797704ae23193241683e11714866745cbebe0599
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:28:11 +00:00
chungkai
49e28ad8c1 sepolicy: fix avc denials am: d37777dd33
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I59b89c687d44c371fed1e83d2a8bce057bb88179
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:07:33 +00:00
chungkai
d37777dd33 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 226887726
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: If2ac4c137c1ea074907c363424e6018a5fd646e8
2022-04-15 01:01:47 +00:00
chungkai
6e56ba1c25 sepolicy: fix avc denials am: fbdb09a2f0 am: 0653304229
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750772

Change-Id: Icdef8f232937f8fe76a2aea73314a10c9b6c9f66
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 10:06:01 +00:00
chungkai
d45cf4d6d3 sepolicy: fix avc denials am: fbdb09a2f0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750772

Change-Id: I60f7a16bec1ac56aace2cde31a17afb009387a62
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 09:42:49 +00:00
chungkai
fbdb09a2f0 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 226887726
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: Ifc618e315e9d28cab6f602ce2c99ac7fe35fc189
2022-04-14 07:24:58 +00:00
TeYuan Wang
55af6cbfe5 sepolicy: label AUR as sysfs_thermal am: 951bad233c am: 5389906449
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731168

Change-Id: I57b4e2d0e4b9eccfad70b2aa84827919c9e97b00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 07:10:17 +00:00
TeYuan Wang
28432f8076 sepolicy: label AUR as sysfs_thermal am: 951bad233c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731168

Change-Id: I90c7de97164a2da58f79d361173d21c40adc3b4c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-14 06:48:20 +00:00