Commit graph

2474 commits

Author SHA1 Message Date
sukiliu
abdd44b0fd Update avc error on ROM 8468959
Bug: 229677756
Test: PtsSELinuxTestCases
Change-Id: I0423fa9c02e1e16ecf8ec32d89046704f2667d64
2022-04-20 01:53:16 +00:00
Jason Macnak
3a3b7051cb [automerger skipped] Remove sysfs_gpu type definition am: a77fc2a6df am: 8ff82017cf am: d42e94b0f3 -s ours
am skip reason: Merged-In I107f92617bea56590b5af351341cc1c3b2844360 with SHA-1 a77fc2a6df is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17007102

Change-Id: I36d9c4aca7689be7bfb2e3a0b04c9905ce24d9da
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 17:12:21 +00:00
Jason Macnak
d42e94b0f3 Remove sysfs_gpu type definition am: a77fc2a6df am: 8ff82017cf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17007102

Change-Id: I25d2055ae6b029c9cfe336cfc5061a3fc309fef2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 16:48:39 +00:00
Jason Macnak
d3e2c760fa [automerger skipped] Remove sysfs_gpu type definition am: a77fc2a6df am: 5e49f73b7c -s ours
am skip reason: Merged-In I107f92617bea56590b5af351341cc1c3b2844360 with SHA-1 6ab671ae18 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17007102

Change-Id: Ibc18c9897adba2e8b32d5f755ccdbb0951218a2c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 16:47:18 +00:00
Jason Macnak
8ff82017cf Remove sysfs_gpu type definition am: a77fc2a6df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17007102

Change-Id: I09a5e41666931c7bb6f4bdaa67f8507aec59c7cc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 16:25:31 +00:00
Jason Macnak
5e49f73b7c Remove sysfs_gpu type definition am: a77fc2a6df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17007102

Change-Id: I621268fe203c8f2c6373ff55ad168d32bb15a2f6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 16:24:57 +00:00
Jason Macnak
a77fc2a6df Remove sysfs_gpu type definition
... as it has moved to system/sepolicy.

Bug: b/161819018
Test: presubmit
Change-Id: I107f92617bea56590b5af351341cc1c3b2844360
Merged-In: I107f92617bea56590b5af351341cc1c3b2844360
2022-04-19 15:59:04 +00:00
Ted Lin
10db70729b Sepolicy: add the system_app.te for hal_wlc am: 55f4e61c8c am: d2abadeef2 am: f956980194
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750775

Change-Id: Iff891a15e8759f314d10f0caa399489052b39584
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 07:17:57 +00:00
Ted Lin
f956980194 Sepolicy: add the system_app.te for hal_wlc am: 55f4e61c8c am: d2abadeef2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750775

Change-Id: I0217fef3318c35342d102aec120de2ddcb691b47
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 06:57:07 +00:00
Ted Lin
6c6ab958bd Sepolicy: add the system_app.te for hal_wlc am: 55f4e61c8c am: e5213f1820
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750775

Change-Id: I14946c7478a76bcb2aed53ca616e52e91be4ca80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 06:56:26 +00:00
Ted Lin
d2abadeef2 Sepolicy: add the system_app.te for hal_wlc am: 55f4e61c8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750775

Change-Id: I6bb1ca09ec11fa990f15f2c40ac4eaaf57f2b4a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 06:34:39 +00:00
Ted Lin
e5213f1820 Sepolicy: add the system_app.te for hal_wlc am: 55f4e61c8c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17750775

Change-Id: I4e0ad90285d75ae8ae8b8a2ea231980fabcf1d2e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 06:33:45 +00:00
Ted Lin
55f4e61c8c Sepolicy: add the system_app.te for hal_wlc
04-11 20:28:15.435   523   523 I auditd  : avc:  denied  { find } for interface=vendor.google.wireless_charger::IWirelessCharger sid=u:r:system_app:s0 pid=3755 scontext=u:r:system_app:s0 tcontext=u:object_r:hal_wlc_hwservice:s0 tclass=hwservice_manager permissive=0

Bug:229036607
Test: adb bugreport
Change-Id: I40562204b3517b2861b2a52466f9cde04a5321c5
Signed-off-by: Ted Lin <tedlin@google.com>
2022-04-19 06:11:19 +00:00
chiayupei
44c3d78413 hal_sensors_default: Allow sensors HAL to access AoC sysfs and properties. am: eaeec28c23 am: 8686077cf1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17799083

Change-Id: I46720865410689fa8a562eedecf9aa082393a881
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 02:38:56 +00:00
chiayupei
8686077cf1 hal_sensors_default: Allow sensors HAL to access AoC sysfs and properties. am: eaeec28c23
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17799083

Change-Id: Iafe48b445d456eef6fbf98ed4ed7c3550a3a260d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-19 02:16:32 +00:00
chiayupei
eaeec28c23 hal_sensors_default: Allow sensors HAL to access AoC sysfs and properties.
Bug: 202901227
Test: Verify pass by checking device log.

Signed-off-by: chiayupei <chiayupei@google.com>
Change-Id: I67e0fcc4ad89ff3c1945f6fdd83d01f14fcdcbec
2022-04-19 01:57:08 +00:00
Jason Macnak
6ab671ae18 Remove sysfs_gpu type definition
... as it has moved to system/sepolicy.

Bug: b/161819018
Test: presubmit
Change-Id: I107f92617bea56590b5af351341cc1c3b2844360
2022-04-18 22:48:37 +00:00
Alex Hong
c51ef5da57 Update the SELinux context for dumpstate HAL service am: 09ef2e08c5 am: 572c9385f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699359

Change-Id: I4011892e01d20c35f43a397dc141f3baf6279eef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 13:33:38 +00:00
Jerry Huang
7bcc9da819 Allow mediacodec_google to access gpu_device am: 9bc45b2d60 am: 907fa780c6 am: 14fa939e02
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: I5473d5b2bdef49db8d721ff6a0559c6e231bacd9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 08:05:08 +00:00
Alex Hong
572c9385f2 Update the SELinux context for dumpstate HAL service am: 09ef2e08c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17699359

Change-Id: Ib383ca5b7ddfa353b83d89faeea0c7db986760e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:51:12 +00:00
Alex Hong
09ef2e08c5 Update the SELinux context for dumpstate HAL service
Test: atest VtsHalDumpstateTargetTest pass
Bug: 223118410
Change-Id: Ie237579f974bab8bf8d35211367457be178a262b
2022-04-18 07:45:28 +00:00
Jerry Huang
1d04d76967 Allow mediacodec_google to access gpu_device am: 9bc45b2d60 am: f5bbe7b88a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: Ibcfbd72b04db4c68a8b84c050451429a8bec521d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:42:26 +00:00
Jerry Huang
14fa939e02 Allow mediacodec_google to access gpu_device am: 9bc45b2d60 am: 907fa780c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: Ia9cf89db957fbcbe2c5fdd508c21ea91b71fba39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:42:04 +00:00
Jerry Huang
907fa780c6 Allow mediacodec_google to access gpu_device am: 9bc45b2d60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: I4dc3946a1ac18c1c1b88c4c9dbf9baa6612d7cfd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:20:30 +00:00
Jerry Huang
f5bbe7b88a Allow mediacodec_google to access gpu_device am: 9bc45b2d60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17731167

Change-Id: Id2e4061ed41734a687dc5268da2487d99ad78763
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 07:19:17 +00:00
Jerry Huang
9bc45b2d60 Allow mediacodec_google to access gpu_device
Bug: 228794372
Test: android.media.decoder.cts.DecoderTest#testAV1HdrToSdr

The change is for following error:
04-08 17:02:44.020  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70491): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.028  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70492): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.040  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70493): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0
04-08 17:02:44.048  1046  7284  7284 W HwBinder:7284_3: type=1400 audit(0.0:70494): avc: denied { getattr } for path="/dev/mali0" dev="tmpfs" ino=1052 scontext=u:r:mediacodec_google:s0 tcontext=u:object_r:gpu_device:s0 tclass=chr_file permissive=0

Change-Id: Ie22903807fcc12d931cbdd36678ae1d4a3776a3d
2022-04-18 13:34:04 +08:00
sukiliu
2b3e031ead Update avc error on ROM 8459635 am: aa794b4e43 am: 9b19670fde
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764697

Change-Id: I0b6f5a0070907e870baea3e0912cfd7e822eeec1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 02:09:21 +00:00
sukiliu
9b19670fde Update avc error on ROM 8459635 am: aa794b4e43
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764697

Change-Id: I45ef7c52bfc599f9e9f303d91848f12af491ff83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-18 01:22:54 +00:00
sukiliu
aa794b4e43 Update avc error on ROM 8459635
Bug: 229354991
Test: PtsSELinuxTestCases
Change-Id: I6b5d7d5b1368021bd927dedf786081c600289974
2022-04-18 01:05:57 +00:00
Joshua McCloskey
cf51eaf2cb Allow platform apps to access FP Hal am: 2dc0bbd55b am: 93f0eac9b7 am: e3492d9b53
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: I380d7bff2b1d6288b40f52de7e83ffdf2cbfd283
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 23:30:13 +00:00
Joshua McCloskey
e3492d9b53 Allow platform apps to access FP Hal am: 2dc0bbd55b am: 93f0eac9b7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: Icd927343b5116c882505d1c773b8166b8fc1af2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:40:01 +00:00
Joshua McCloskey
d376d62308 Allow platform apps to access FP Hal am: 2dc0bbd55b am: d386974cac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: I1d9ed90bdb1230be3277e95937d066847167a485
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:39:33 +00:00
Joshua McCloskey
93f0eac9b7 Allow platform apps to access FP Hal am: 2dc0bbd55b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: I7be27da8b3ee59516612c3f71804ca6799c047f2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:13:03 +00:00
Joshua McCloskey
d386974cac Allow platform apps to access FP Hal am: 2dc0bbd55b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17625014

Change-Id: I0ff7aeba35e96f3ba82de61d49e9f596ff2b4f6e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 22:12:14 +00:00
Joshua McCloskey
2dc0bbd55b Allow platform apps to access FP Hal
Bug: 227247855
Test: Verified manually that the fingerprint extension is working.
Change-Id: Id5550ca770942d02ad0796ed0d4e8584c434b680
2022-04-15 21:39:58 +00:00
Oleg Matcovschi
81ed057c7d selinux: remove dpm_[ab] from custom_ab_block_device's am: a79b98eb25 am: cddeaf3f73
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764346

Change-Id: Iac746a89d0f4205b16ed7bc8e4855cdff5ca7ebe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 20:11:24 +00:00
Oleg Matcovschi
cddeaf3f73 selinux: remove dpm_[ab] from custom_ab_block_device's am: a79b98eb25
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764346

Change-Id: I048cca075f5c22dd518b9ab9da288f5318570945
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 19:54:27 +00:00
Oleg Matcovschi
a79b98eb25 selinux: remove dpm_[ab] from custom_ab_block_device's
Signed-off-by: Oleg Matcovschi <omatcovschi@google.com>
Change-Id: I774065f331b1f2970b0fee5a41faa097fa88caf8
2022-04-15 19:08:17 +00:00
chungkai
5ab420e9ca sepolicy: fix avc denials am: d80900ae17 am: efb75b5ced am: 96e63091b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I25c5b096e2986b91923f61f37733754852fe845b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 07:24:04 +00:00
chungkai
96e63091b4 sepolicy: fix avc denials am: d80900ae17 am: efb75b5ced
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: Ie80951fd60033081bda78a7cdb327ff0a7f5fe5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 07:01:26 +00:00
chungkai
319be9e317 sepolicy: fix avc denials am: d80900ae17 am: beefac99c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I77bbb44d3cb34d695e34712e02abcfbc7cff5c99
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 07:01:04 +00:00
chungkai
efb75b5ced sepolicy: fix avc denials am: d80900ae17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: I13bbf5aaa37f0855cce70a0ef06ac50fc1ad9006
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 06:39:45 +00:00
chungkai
beefac99c7 sepolicy: fix avc denials am: d80900ae17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17764688

Change-Id: Ifddf30c6372afeb5e5b36236ae4562fa8bafffda
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 06:39:39 +00:00
chungkai
d80900ae17 sepolicy: fix avc denials
add potential paths for i2c peripheral devices
sine we enable parallel module loading

Bug: 228947596
Test: do bugreport without avc denials
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I2e9fa011c049e32011c5880218dd679e03316e24
2022-04-15 02:56:55 +00:00
chungkai
63751751aa sepolicy: fix avc denials am: d37777dd33 am: 49e28ad8c1 am: 56b70920b6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I4798c75c139f45dbaabc364903bfbd121d0d0267
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:44:27 +00:00
Harpreet Eli Sangha
f531db2f06 Add CccDkTimeSyncService for Digital Key Support am: 1a0b0ce0c4 am: a7eb4ce4f2 am: 9ec5f1f14f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755764

Change-Id: I9a0a82dd29822ea0d3b3cbb2a74d2475a86a659b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:44:06 +00:00
sukiliu
a6398a7291 Update avc error on ROM 8453400 am: 81d9623cbe am: 24a55545cc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755772

Change-Id: Ifc044e0045866ed6601e53e534a560fd6cad1606
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:43:57 +00:00
chungkai
7c43e4e343 sepolicy: fix avc denials am: d37777dd33 am: e240db0a69
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I797704ae23193241683e11714866745cbebe0599
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:28:11 +00:00
Harpreet Eli Sangha
545ae1e2d2 Add CccDkTimeSyncService for Digital Key Support am: 1a0b0ce0c4 am: 559e696193
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755764

Change-Id: I7150f2c558f08444d32a2fb93469897d449572cc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:28:00 +00:00
chungkai
56b70920b6 sepolicy: fix avc denials am: d37777dd33 am: 49e28ad8c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17755771

Change-Id: I0f1e5b791a88ab62c3432307b6ea12f8e2165264
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-15 01:21:37 +00:00