Commit graph

2474 commits

Author SHA1 Message Date
Ted Lin
f504cca79a Remove the tracking for vendor_battery_defender am: 4b75aab4b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342324

Change-Id: If12f9cabf9900d4492d7e405f4ed877f2f3f2ae3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 02:02:33 +00:00
Ted Lin
4b75aab4b8 Remove the tracking for vendor_battery_defender
The function is disabled.

Bug: 221384939
Test: adb bugreport
Change-Id: If8e8b8165329eb9ede86cb62f419a8cf06abb536
Signed-off-by: Ted Lin <tedlin@google.com>
2022-03-25 01:37:03 +00:00
Chris Kuiper
e20b8b0bde Add rules to allow Sensor HAL write access to als_table am: 967571ee60 am: f5453f84aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888

Change-Id: I3ab1b246c094f1438b8bcf6bb4d167dd33872068
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:39:23 +00:00
Chris Kuiper
f5453f84aa Add rules to allow Sensor HAL write access to als_table am: 967571ee60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888

Change-Id: I8ddfebc5b8febe09cb48cb58f7f2ed9ee74386d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:21:03 +00:00
Chris Kuiper
ffebbdcd34 Add rules to allow Sensor HAL write access to als_table am: 967571ee60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17368888

Change-Id: Id038f0254f2c69e917c88cb2da0aa8f47b6861f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-03-25 00:20:47 +00:00
Chris Kuiper
967571ee60 Add rules to allow Sensor HAL write access to als_table
Sensor HAL needs write access to
/sys/class/backlight/panel0-backlight/als_table.

Bug: 226435017
Test: Observing logs
Change-Id: Idb592d601b92c6814493e0d28384e1013935b72f
2022-03-25 00:00:19 +00:00
chungkai
2df9c1b75b sched: move sysfs to procfs am: 4fa67857c3 am: 9bff8c59b6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963

Change-Id: I673097342a9c61b74b5dab7e7758ff2c12a92172
2022-03-24 18:35:30 +00:00
chungkai
9bff8c59b6 sched: move sysfs to procfs am: 4fa67857c3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963

Change-Id: Ib855e5bdf15d24defa55f3b548144fd31ed96ecb
2022-03-24 18:16:44 +00:00
chungkai
3eba3a1004 sched: move sysfs to procfs am: 4fa67857c3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17346963

Change-Id: I9152300c03241a0f025002c8325298b2412bbae4
2022-03-24 18:16:44 +00:00
chungkai
4fa67857c3 sched: move sysfs to procfs
Modify name from sysfs_vendor_sched to proc_vendor_sched

Test: without avc denial
Bug: 216207007
Signed-off-by: chungkai <chungkai@google.com>
Change-Id: I96dc6eb76dd533ff6fd54c27be7e4bc32bf5dbc7
2022-03-24 17:44:37 +00:00
Holmes Chou
baf62054ef camera: use codename for camera modules am: e0b06b9cbd am: 15a914dbc1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590

Change-Id: I5326b73fcb3cfc1f5cbc8aef0568116fe6996c9f
2022-03-24 14:00:24 +00:00
Holmes Chou
15a914dbc1 camera: use codename for camera modules am: e0b06b9cbd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590

Change-Id: Ibb0e4a61baff6e2d9e405afdb29494a0263e1559
2022-03-24 13:38:18 +00:00
Holmes Chou
91e48d04e6 camera: use codename for camera modules am: e0b06b9cbd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17071590

Change-Id: I316371a838cb4ed83103a9be3675bae736a6e570
2022-03-24 13:38:04 +00:00
Holmes Chou
e0b06b9cbd camera: use codename for camera modules
use codename for camera modules
Bug: 209866857
Test: GCA, adb logcat

Change-Id: I55f6998d18a904c83ecdf328d1b0e5ca6a01427f
2022-03-24 13:11:16 +00:00
Ted Lin
f07365851f hal_health_default: Fix avc denials am: 0adad90ab6 am: 213dd940ff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323

Change-Id: I365f5883dcc1e1cc00b70881cbb299079129bc65
2022-03-24 06:16:42 +00:00
Ted Lin
213dd940ff hal_health_default: Fix avc denials am: 0adad90ab6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323

Change-Id: I8f57a0ab56e2d11109c6a65084983499ab1bd787
2022-03-24 05:53:09 +00:00
Ted Lin
01fd681875 hal_health_default: Fix avc denials am: 0adad90ab6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342323

Change-Id: I5aa66b895e116b4336e9b1501441727ae09580cd
2022-03-24 05:52:55 +00:00
Ted Lin
0adad90ab6 hal_health_default: Fix avc denials
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2270): avc: denied { search } for name="thermal" dev="tmpfs" ino=1028 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2271): avc: denied { search } for name="thermal" dev="sysfs" ino=16790 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=dir permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2273): avc: denied { open } for path="/sys/devices/virtual/thermal/thermal_zone13/mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1
12-02 11:15:45.224   756   756 I health@2.1-serv: type=1400 audit(0.0:2272): avc: denied { write } for name="mode" dev="sysfs" ino=17285 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=1

Bug:208721638
Test: adb bugreport
Change-Id: I4d9491862ff1bcc88f89b1478497ac569e3d1df1
Signed-off-by: Ted Lin <tedlin@google.com>
(cherry picked from commit 5b6a5292c3)
2022-03-24 05:26:09 +00:00
Adam Shih
a64c706300 enforce debugfs constraint on userdebug build am: de2696eb72 am: fcae230ef4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326

Change-Id: I08077c437eec9024573b416c8782f75e33d9f74e
2022-03-24 04:39:43 +00:00
Adam Shih
fcae230ef4 enforce debugfs constraint on userdebug build am: de2696eb72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326

Change-Id: I2008bde5b787053f818a58452f629e5bee8e8ced
2022-03-24 04:12:13 +00:00
Adam Shih
3244ceef37 enforce debugfs constraint on userdebug build am: de2696eb72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326

Change-Id: I9017b4539131e88f31580127042cf26908137aed
2022-03-24 04:10:57 +00:00
Adam Shih
de2696eb72 enforce debugfs constraint on userdebug build
Bug: 225815474
Test: build pass
Change-Id: If9e32d4b67c342b56eea39701518a520a62df199
2022-03-24 01:05:18 +00:00
Yabin Cui
287a45f6fd [automerger skipped] Add SOC specific ETM sysfs paths am: 02c1ef8b85 am: f387f3dcd3 -s ours
am skip reason: Merged-In I10c8d250cf88b371ee573561d6678fc24f4e440c with SHA-1 02c1ef8b85 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17324045

Change-Id: If8737a8f9e654963177c42525323f027db12c1eb
2022-03-23 20:24:44 +00:00
Yabin Cui
045878aa5a [automerger skipped] Add SOC specific ETM sysfs paths am: 02c1ef8b85 -s ours
am skip reason: Merged-In I10c8d250cf88b371ee573561d6678fc24f4e440c with SHA-1 278d110fba is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17324045

Change-Id: If8f338bccdb77ccd0cfce338e52f9870996c9dfd
2022-03-23 20:09:10 +00:00
Yabin Cui
f387f3dcd3 Add SOC specific ETM sysfs paths am: 02c1ef8b85
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17324045

Change-Id: I0e5889c043eaea6827d91423c3adfc14073ea289
2022-03-23 20:07:38 +00:00
Yabin Cui
02c1ef8b85 Add SOC specific ETM sysfs paths
Bug: 225403280
Test: run profcollectd on c10
Change-Id: I10c8d250cf88b371ee573561d6678fc24f4e440c
Merged-In: I10c8d250cf88b371ee573561d6678fc24f4e440c
2022-03-23 19:45:48 +00:00
George Lee
586c4699e9 [automerger skipped] health: Grant sysfs_thermal access to health am: 17981f9fc0 am: 8e5d012c72 -s ours
am skip reason: Merged-In I4d9491862ff1bcc88f89b1478497ac569e3d1df1 with SHA-1 5b6a5292c3 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17312309

Change-Id: I08f32a1b663a40921528dabb26e285a6db7ea58d
2022-03-23 05:47:32 +00:00
SalmaxChang
704954b7dd modem_svc_sit: fix avc error am: ae6f085676 am: 13a0910c39
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17314904

Change-Id: I0a71f49dc8d028d60a77bd2e9c5c31402323a28c
2022-03-23 05:47:25 +00:00
SalmaxChang
70a614ec80 vendor_init: fix avc error am: 6dd3de7813 am: a40641f2da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291644

Change-Id: Idff086bac5ca7eb1a2bfa7b0d09705e5f555dd72
2022-03-23 05:47:17 +00:00
George Lee
8e5d012c72 health: Grant sysfs_thermal access to health am: 17981f9fc0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17312309

Change-Id: I88cc6908a9d5062b815f077b8e6c9cb38067d1ce
2022-03-23 05:33:21 +00:00
George Lee
644a47d5a4 [automerger skipped] health: Grant sysfs_thermal access to health am: 17981f9fc0 -s ours
am skip reason: Merged-In I4d9491862ff1bcc88f89b1478497ac569e3d1df1 with SHA-1 5b6a5292c3 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17312309

Change-Id: Ibffa6cda778adf0b1a3509e3590c355f61bac5b8
2022-03-23 05:33:07 +00:00
SalmaxChang
13a0910c39 modem_svc_sit: fix avc error am: ae6f085676
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17314904

Change-Id: I3ae7e26013ec250818fee64adedf5e0b568e50c7
2022-03-23 05:33:06 +00:00
SalmaxChang
a40641f2da vendor_init: fix avc error am: 6dd3de7813
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291644

Change-Id: I58b4e5d1a0bf09666a0f852f2567605ca021cc1a
2022-03-23 05:33:01 +00:00
SalmaxChang
3ae795cf8b modem_svc_sit: fix avc error am: ae6f085676
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17314904

Change-Id: I0962f68685aaabc68f74fd001c2b5edcc92ac10e
2022-03-23 05:33:00 +00:00
SalmaxChang
cf09620f3c vendor_init: fix avc error am: 6dd3de7813
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17291644

Change-Id: Ic7d9db340241626de5f9852e4ddc01bbf6c8b84b
2022-03-23 05:32:52 +00:00
George Lee
17981f9fc0 health: Grant sysfs_thermal access to health
health-service has trouble accessing /dev/thermal.  This change fixes
this.

Bug: 226009696
Test: dev/thermal/tz-by-name/soc/mode error:Permission denied no longer
exist
Signed-off-by: George Lee <geolee@google.com>
Change-Id: I8d112cb12f3aeb1c8d5433ca69415d0413f070a2
Merged-In: I4d9491862ff1bcc88f89b1478497ac569e3d1df1
2022-03-23 05:30:33 +00:00
SalmaxChang
ae6f085676 modem_svc_sit: fix avc error
avc: denied { write } for comm="modem_svc_sit" name="modem_stat" dev="dm-46" ino=333 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 225149029
Change-Id: Id1045d9488a200b6c64abbe02cf5e65926ba0203
2022-03-23 05:13:29 +00:00
Yabin Cui
278d110fba Add SOC specific ETM sysfs paths
Bug: 225403280
Test: run profcollectd on c10
Change-Id: I10c8d250cf88b371ee573561d6678fc24f4e440c
2022-03-22 16:53:23 +00:00
SalmaxChang
6dd3de7813 vendor_init: fix avc error
avc: denied { getattr } for comm="init" name="/" dev="sda19" ino=2 scontext=u:r:vendor_init:s0 tcontext=u:object_r:modem_img_file:s0 tclass=filesystem permissive=0

Bug: 225151104
Change-Id: I508aa6b85039edc4b5a8746aaa602f1131768630
2022-03-22 07:57:59 +00:00
Kris Chen
b89f8faaca Allow hal_fingerprint_default to access fwk_sensor_hwservice am: 997b8974ef am: 3d1c17ffd7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17288686

Change-Id: Iad8b3eec7c5c9abc23d2df8d09e4b9b3e7b59ccb
2022-03-22 04:15:55 +00:00
Kris Chen
3d1c17ffd7 Allow hal_fingerprint_default to access fwk_sensor_hwservice am: 997b8974ef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17288686

Change-Id: If57f3542180e8e0af17351c50415a8bab57306e5
2022-03-22 03:59:58 +00:00
Kris Chen
a312c79491 Allow hal_fingerprint_default to access fwk_sensor_hwservice am: 997b8974ef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17288686

Change-Id: I68502cce84067dd230bec8e4b02491b5f6bb79fd
2022-03-22 03:59:50 +00:00
Peter Csaszar
0f9c31fb33 [automerger skipped] pixel-selinux: Port PRO SJTAG policies to tm-dev am: 466adbb2da am: 0b35cf6a3b -s ours
am skip reason: Merged-In I5ec50d9ff7cd0e08ade7acce21e73751e93a0aff with SHA-1 4041f814be is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17299051

Change-Id: I89786ea8bd4d67e255a1c03f41fea2dbc57912a6
2022-03-22 03:52:39 +00:00
Roshan Pius
db3c865121 gs-policy: Remove obsolete uwb vendor service rules am: 046601d414 am: d8a25b0f0c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17294749

Change-Id: I662ee5a78965812848a52ecb7afbf2a57c017549
2022-03-22 03:52:15 +00:00
Kris Chen
997b8974ef Allow hal_fingerprint_default to access fwk_sensor_hwservice
Fix the following avc denial:
avc:  denied  { find } for interface=android.frameworks.sensorservice::ISensorManager sid=u:r:hal_fingerprint_default:s0 pid=1258 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:fwk_sensor_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 197789721
Test: build and test fingerprint on device.
Change-Id: I7494f28e69e5a1b660dc7fbaa528b1088048723b
(cherry picked from commit 9b54bf3665abce7a6f5f5df22069a8ef081ad80e)
2022-03-22 03:39:35 +00:00
Peter Csaszar
0b35cf6a3b pixel-selinux: Port PRO SJTAG policies to tm-dev am: 466adbb2da
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17299051

Change-Id: If1cc0d3afa539a104b2ad99b9bebdc18c98bd622
2022-03-22 03:30:37 +00:00
Peter Csaszar
a2a1b7f0a2 [automerger skipped] pixel-selinux: Port PRO SJTAG policies to tm-dev am: 466adbb2da -s ours
am skip reason: Merged-In I5ec50d9ff7cd0e08ade7acce21e73751e93a0aff with SHA-1 4041f814be is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17299051

Change-Id: Ie53882049dae4879e6420ede4961e83681bd0905
2022-03-22 03:30:31 +00:00
Roshan Pius
d8a25b0f0c gs-policy: Remove obsolete uwb vendor service rules am: 046601d414
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17294749

Change-Id: If87ae2d622842f33f4d71568fcf8918847762ee3
2022-03-22 03:30:17 +00:00
Roshan Pius
8eae925778 gs-policy: Remove obsolete uwb vendor service rules am: 046601d414
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17294749

Change-Id: I5562c289af945a110b2be5280170e0a5b948f6b4
2022-03-22 03:29:57 +00:00
Peter Csaszar
466adbb2da pixel-selinux: Port PRO SJTAG policies to tm-dev
These are the SELinux policies for the sysfs files of the SJTAG
kernel interface for WHI-PRO-based devices, now migrated to the
tm-dev branch. The files are in the following directories:

  /sys/devices/platform/sjtag_ap/interface/
  /sys/devices/platform/sjtag_gsa/interface/

Bug: 207571417
Bug: 224022297
Signed-off-by: Peter Csaszar <pcsaszar@google.com>
Merged-in: I5ec50d9ff7cd0e08ade7acce21e73751e93a0aff
Change-Id: I56da5763c31ab098859cbc633660897646fe7f3e
2022-03-22 03:17:40 +00:00