Commit graph

2474 commits

Author SHA1 Message Date
Inseob Kim
25680a4b79 [automerger skipped] Move coredomain policies to system_ext/product am: 656f7b5aa1 am: c83b44626a -s ours am: a3707836b2 -s ours am: 5ddd880bb1 -s ours
am skip reason: Merged-In If768b5cb9f3b4024893117d8e3bf49adb7c5b070 with SHA-1 da30985fa5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: I78a2f50e6c14ceae77bfa29e179f8ab0e653da6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 06:01:49 +00:00
Inseob Kim
5ddd880bb1 [automerger skipped] Move coredomain policies to system_ext/product am: 656f7b5aa1 am: c83b44626a -s ours am: a3707836b2 -s ours
am skip reason: Merged-In If768b5cb9f3b4024893117d8e3bf49adb7c5b070 with SHA-1 da30985fa5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: I5386db73205854348d31612667b69c4b43f66270
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 05:20:02 +00:00
Inseob Kim
a3707836b2 [automerger skipped] Move coredomain policies to system_ext/product am: 656f7b5aa1 am: c83b44626a -s ours
am skip reason: Merged-In If768b5cb9f3b4024893117d8e3bf49adb7c5b070 with SHA-1 da30985fa5 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: Iaf6051e44cd3378c415db967aeed879a0a51a734
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 04:35:44 +00:00
Inseob Kim
c83b44626a Move coredomain policies to system_ext/product am: 656f7b5aa1
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2671075

Change-Id: I707df3267d51354e846376617b59943af6c04e30
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-11 03:49:14 +00:00
Inseob Kim
583ea25a56 [automerger skipped] Move coredomain policies to system_ext/product am: da30985fa5 am: 0827b82595 am: 0a40b3bb98 -s ours
am skip reason: Merged-In If768b5cb9f3b4024893117d8e3bf49adb7c5b070 with SHA-1 62014f1726 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24354374

Change-Id: I0a3c44e27580bb82e74fcd8e7f8eac19d68b0c57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 08:17:52 +00:00
Inseob Kim
0a40b3bb98 Move coredomain policies to system_ext/product am: da30985fa5 am: 0827b82595
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24354374

Change-Id: I21a6ae897a80a8954639e15ebb16218a0e324350
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 07:35:43 +00:00
Inseob Kim
0827b82595 Move coredomain policies to system_ext/product am: da30985fa5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24354374

Change-Id: I527239025a4b81d9d989dcba6ba2c63d6840a683
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 06:50:56 +00:00
Inseob Kim
656f7b5aa1 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
Merged-In: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
(cherry picked from commit da30985fa5)
2023-08-09 15:06:04 +09:00
Inseob Kim
da30985fa5 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
Merged-In: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
2023-08-08 14:37:48 +00:00
Inseob Kim
62014f1726 Move coredomain policies to system_ext/product
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: If768b5cb9f3b4024893117d8e3bf49adb7c5b070
2023-08-08 21:33:28 +09:00
Roy Luo
36313e7bc9 Support monitoring USB sysfs attributes in USB HAL
Grant access to USB sysfs attributes.

Bug: 285199434
Test: no audit log in logcat after command execution
Change-Id: Ida489f0f8788100795613de900fd06317087d9cc
2023-08-04 17:25:06 +00:00
Ken Yang
e5bfccd0fd SELinux: fix sysfs_wlc avc denials
Bug: 291541479
Change-Id: I94bed765b89ee538f77398ce432315c907ac1a9a
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-28 03:47:38 +00:00
Ken Yang
7cd663c2b3 SELinux: fix the wakeup avc denials am: 3054cb6eec am: f0c6f18d7d am: 89e7477c43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: I92795e0179493e849c9cdd5eae502574b117404e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 04:23:37 +00:00
Ken Yang
89e7477c43 SELinux: fix the wakeup avc denials am: 3054cb6eec am: f0c6f18d7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: I7888b49da09ad91b2d6b31d2c335841edd5a6514
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 03:13:07 +00:00
Ken Yang
f0c6f18d7d SELinux: fix the wakeup avc denials am: 3054cb6eec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: Ia49778517e9c64e4b7539fa81ec4170cef01961c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 02:30:35 +00:00
Ken Yang
3054cb6eec SELinux: fix the wakeup avc denials
Fix the wakeup avc denials in a more common place

Bug: 292076108
Change-Id: I52627f19cb0fec3dd0851d21d0608048ebc7d45d
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-25 13:12:32 +00:00
Utku Utkan
27ce9336a3 Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 34bda7b2b8 am: 2fb35adebd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24124266

Change-Id: I5b7b0b5af1b0eac9513897494da5201f4fea6332
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 19:58:34 +00:00
Utku Utkan
2fb35adebd Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 34bda7b2b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24124266

Change-Id: I0675ba6da1fff3561ec1ab23711526657ccc3c93
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 18:49:47 +00:00
Utku Utkan
34bda7b2b8 Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Reason for revert: Relanding the original topic after copying the certificates under `device/google` for `without-vendor` branches

Reverted changes: /q/submissionid:24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Bug: 287069860
Test: m && flashall
Change-Id: I5326b61822d367beaff0ac97a34708d306c60007
2023-07-18 20:37:28 -07:00
Inseob Kim
1dae17837d Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: c420cef154 am: 3539653f98
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24122569

Change-Id: I15231b5d87ef4c47bf2413c28b48974fda7f10c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 03:33:47 +00:00
Inseob Kim
3539653f98 Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: c420cef154
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24122569

Change-Id: I192d7d1ba78d7381d3dd122cacbdd7a37d16d67d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 02:50:45 +00:00
Inseob Kim
c420cef154 Revert "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24056607-pixel-camera-services-extensions-sepolicy

Reason for revert: build breakage on git_main-without-vendor

Reverted changes: /q/submissionid:24056607-pixel-camera-services-extensions-sepolicy

Change-Id: I9869874507230f59ac3b8cdc2538e4f223216b45
2023-07-19 01:15:39 +00:00
Utku Utkan
c1f776c272 Introduce CameraServices seinfo tag for PixelCameraServices am: d45ff39442 am: 47f7d7ef72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24030396

Change-Id: Ie157ffc9d3d457df512c8c84eff1bd09634e627a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 22:35:37 +00:00
Utku Utkan
47f7d7ef72 Introduce CameraServices seinfo tag for PixelCameraServices am: d45ff39442
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24030396

Change-Id: I1ecfa136567806f140067eaed98766c6da66d2ee
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 21:49:07 +00:00
Dinesh Yadav
b29cf7645a [Cleanup]: Move gxp sepolicies to gs-common for P22
These policies are moved to gs-common as part of ag/24002524

Bug: 288368306
Change-Id: If7466983009021c642db998e1c30071ee548846e
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-07-14 04:00:23 +00:00
Utku Utkan
d45ff39442 Introduce CameraServices seinfo tag for PixelCameraServices
Bug: 287069860
Test: m && flashall && check against 'avc: denied' errors
Change-Id: I41b435ae0a34fe9c797b9316887c4b56091a26a5
2023-07-13 09:11:06 -07:00
David Anderson
91768e10c9 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873 am: 96009e517c am: d06d2415a5
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I74bd7c4a44e03d77acbc8207a6c848b990f1afc8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 01:31:45 +00:00
David Anderson
d06d2415a5 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873 am: 96009e517c
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I1ccfdb2e8605b5cec757b8ad8d7be6fb414cb9c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 00:52:30 +00:00
David Anderson
96009e517c Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ie086b1fb169292469ec153039beee50ae782276d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 00:07:32 +00:00
David Anderson
a7e9f0a873 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I29b1070280c3e88e976dab3c02b110786ca8f11b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 23:22:17 +00:00
David Anderson
a03ec9af21 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Id20a32d6a80e058caebf2047e59a1b5a3e519f43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 22:41:44 +00:00
David Anderson
439827c49d Allow fastbootd to flash dtbo. am: e96a14a9d2
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ifc30a96202cbeb38896f3545502b582168dcf53e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 21:57:26 +00:00
David Anderson
e96a14a9d2 Allow fastbootd to flash dtbo.
This line is copied from gs101-sepolicy, and fixes the following denial:

audit: type=1400 audit(1689093038.396:14): avc:  denied  { write } for  pid=409 comm="fastbootd" name="sda24" dev="tmpfs" ino=493 scontext=u:r:fastbootd:s0 tcontext=u:object_r:custom_ab_block_device:s0 tclass=blk_file permissive=0

Bug: N/A
Test: fastboot flashall in fastbootd
Change-Id: I765aedeb204cc862434a56a97f242640465f84b8
2023-07-11 10:27:47 -07:00
Samuel Huang
77de7a48b1 Revert "Revert "Create telephony.ril.silent_reset system_ext pro..." am: d02a8eef29 am: e4b6e55e35
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23841769

Change-Id: I07665711913e1cddd8d8e2968bfa340f8d77f232
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-07 03:10:44 +00:00
Samuel Huang
e4b6e55e35 Revert "Revert "Create telephony.ril.silent_reset system_ext pro..." am: d02a8eef29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23841769

Change-Id: I09f53d8147f813aaaeea55b57d1cfb97b0dd0001
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-07 02:32:58 +00:00
Samuel Huang
d02a8eef29 Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."
Revert submission 23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Reason for revert: The root cause is missing property definition in gs101-sepolicy. This CL can be merged safely. Verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L48900000961646046

Reverted changes: /q/submissionid:23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Bug: 286476107
Change-Id: Ia80e4400ff555a637c42193cab3e3acf72bc36a2
2023-07-07 01:45:23 +00:00
Sebastian Pickl
91585993ad Revert "Allow bthal to access vendor bluetooth folder" am: 41ed8e83ea am: d3ef7a804c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23874549

Change-Id: I67ec25d1297413c4504f6830f766d086585667e6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 12:43:27 +00:00
Sebastian Pickl
d3ef7a804c Revert "Allow bthal to access vendor bluetooth folder" am: 41ed8e83ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23874549

Change-Id: Ib4ecdceb5d125c05bce9a6c9edc4b24cbc53a8c0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 12:02:20 +00:00
Sebastian Pickl
41ed8e83ea Revert "Allow bthal to access vendor bluetooth folder"
Revert submission 23844270-P22-vendor-log-udc-qpr

Reason for revert: causes selinux tests to fail b/289989584

go/abtd: https://android-build.googleplex.com/builds/abtd/run/L37600000961782595

Bug:289989584

Reverted changes: /q/submissionid:23844270-P22-vendor-log-udc-qpr

Change-Id: I4e9ccf17050702a6405c549340e7fe97eba0eb65
2023-07-05 10:11:12 +00:00
Patty Huang
8bece71dbe Allow bthal to access vendor bluetooth folder am: 1a52c8b952 am: 3e1348f4fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23854004

Change-Id: I2349fab8fc749e60ce6c2425ea4af9a4f9cbca6e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 07:49:36 +00:00
Patty Huang
3e1348f4fc Allow bthal to access vendor bluetooth folder am: 1a52c8b952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23854004

Change-Id: I0d9ef1e480423715137fcbf7b9651753a9c8fa24
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-05 07:07:56 +00:00
Patty Huang
1a52c8b952 Allow bthal to access vendor bluetooth folder
Bug:289055382
Test: enable vendor debug log and check the vendor snoop log contain the
vendor log

Change-Id: I89164330998d7fbea45dab65931c2a3db22a4c92
2023-06-30 11:55:35 +08:00
DesmondH
3219a0a19f Remove obsolete entries
Fix: 274727778
Change-Id: I1334cd68043d6ef8c36a42fb47d888f9b061bfb4
2023-06-28 05:28:11 +00:00
Sebastian Pickl
706b9b4328 Revert "Create telephony.ril.silent_reset system_ext property fo..." am: 4d0eeef36f am: b617ab420a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23817869

Change-Id: I3c55e93124e9fb9b86ee4a9eeebf524d3b6e309a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 12:03:39 +00:00
Sebastian Pickl
b617ab420a Revert "Create telephony.ril.silent_reset system_ext property fo..." am: 4d0eeef36f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23817869

Change-Id: I032ae4c04d68265389f8575378bc9364af6f897b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 11:16:33 +00:00
Sebastian Pickl
4d0eeef36f Revert "Create telephony.ril.silent_reset system_ext property fo..."
Revert submission 23736941-tpsr-ril-property

Reason for revert: culprit for b/289014054 verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L54800000961620143

Bug: 289014054

Reverted changes: /q/submissionid:23736941-tpsr-ril-property

Change-Id: I4fa5b2803392e0db03bb622392f3d4afab6a45ea
2023-06-27 10:05:45 +00:00
Xin Li
d16b5fbdf9 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours am: c9d5097e56 -s ours am: 645f996b23 -s ours am: 041513071c -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I1ac1cb0f39b271cea2fbd871da4806295fab199e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 08:05:58 +00:00
Xin Li
041513071c [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours am: c9d5097e56 -s ours am: 645f996b23 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I79e95a7ffa397de68457910bd23b1117806e018c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 07:25:45 +00:00
Samuel Huang
4ad090fbed Create telephony.ril.silent_reset system_ext property for RILD restart am: 513fa361c8 am: 5e8765956e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23748040

Change-Id: I07a7f558bb96efb5fa164db6a2041883853cb948
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 03:55:53 +00:00
Samuel Huang
5e8765956e Create telephony.ril.silent_reset system_ext property for RILD restart am: 513fa361c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23748040

Change-Id: I543184268827663ee5bbd96299a3e5d109f6807d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 03:07:56 +00:00