Commit graph

634 commits

Author SHA1 Message Date
Nishok Kumar S
dd9262e2ca Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93 am: b4db422486
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: I9d563cbffa56704441ba57c0b8926f13cc86a79e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:37:56 +00:00
Nishok Kumar S
52f975bec0 Label GCA-Eng app am: 4a6cfb5a9c am: a96da52aca
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I636721df2d3b17c04d7ebcdb84178a3c6f1ebc00
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 10:37:55 +00:00
Nishok Kumar S
b4db422486 Use google_camera_app label for GCA-Next fishfood app. am: 145f7b5b93
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18344645

Change-Id: Ifd964c84766eb6cbeccf47816c6633bdb0f28d36
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:45 +00:00
Nishok Kumar S
a96da52aca Label GCA-Eng app am: 4a6cfb5a9c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18331264

Change-Id: I539f9e1904b074f5fbf22ef52874ba0da5e6e082
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-13 09:39:44 +00:00
Nishok Kumar S
145f7b5b93 Use google_camera_app label for GCA-Next fishfood app.
Bug: 230773733
Test: Build selinux and test with GCA-Next on device.
Change-Id: I757e7de2293e25bd027262a5fbf4ece2a44f10d1
2022-05-13 05:31:34 +00:00
Nishok Kumar S
4a6cfb5a9c Label GCA-Eng app
- Add policies for GCA-Eng to access GXP device.
 - Allow GCA-Eng to access edgetpu service.

Test: Build selinux and test GCA-Eng on device with
      adb shell setprop camera.artemis_dsp TRUE

Bug: 230773733
Change-Id: I8d04f6e1aef0899b3862ddbb80174cd086156d92
2022-05-13 05:18:09 +00:00
Asad Abbas Ali
300c77c7ad Allow chre to communicate with fwk_stats_service. am: 7f89d68af2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18184949

Change-Id: Ia9cd87ac7d913dea52176a4d894fd043c98f55ed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 16:30:32 +00:00
Asad Abbas Ali
7f89d68af2 Allow chre to communicate with fwk_stats_service.
Bug: 230788686
Test: Logged atoms using CHRE + log atom extension.
Change-Id: I45a207996a28bbe61bbfd4288eaf28e2257cdf52
2022-05-06 16:15:06 +00:00
eddielan
975157ae00 sepolicy: Add SW35 HIDL factory service into sepolicy am: aeb9bd0406
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18188088

Change-Id: Idce850a2c0c0b7a79257cad6dd7eaadcca9dcfb6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-06 06:47:22 +00:00
eddielan
aeb9bd0406 sepolicy: Add SW35 HIDL factory service into sepolicy
Bug: 231549391
Test: Build Pass
Change-Id: If5c1bc5ddf6a1fa753ac65b6b4c5983775f2f704
2022-05-06 12:22:59 +08:00
Kris Chen
ab4d1f19cc Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: 2f711e875f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I37c2d3103f3fb2c5290381c244ad552731e51924
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 03:25:03 +00:00
Kris Chen
ae663f1618 Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210 am: c789f02906
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I17e19556c41528d6f1eb2ed096cf5c34ed41aa5a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 03:24:46 +00:00
Kris Chen
2f711e875f Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I43f89e4465035e5f5aa2797007d419ae1d2040c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:35:13 +00:00
Kris Chen
c789f02906 Allow hal_fingerprint_default to access hal_pixel_display_service am: 3162407210
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013067

Change-Id: I674cb3dd987a1d94c8412d028f880bdac04c00ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-05 02:35:10 +00:00
Kris Chen
3162407210 Allow hal_fingerprint_default to access hal_pixel_display_service
Fix the following avc denial:
avc: denied { find } for pid=1158 uid=1000 name=com.google.hardware.pixel.display.IDisplay/default scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:hal_pixel_display_service:s0 tclass=service_manager permissive=0
avc: denied { call } for scontext=u:r:hal_fingerprint_default:s0 tcontext=u:r:hal_graphics_composer_default:s0 tclass=binder permissive=0

Bug: 229716695
Bug: 224573604
Test: build and test fingerprint on device
Change-Id: I104af7f50715090fe0c2aa6845848bf77ab3e3ae
2022-05-05 02:03:43 +00:00
Jenny Ho
e1578b6a4d sepolicy: allow access debugfs charger register dump am: 5e426a95d0 am: f9e379b88a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ifea2b1ad0d2cb9eb86216a271c49bd9b03909cce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 17:51:32 +00:00
Labib
709dfed23a Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8 am: 77af035a89
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I459e4e2cc235010bca74581b4a01769f77d83609
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 17:51:22 +00:00
Jenny Ho
c26bb54bb0 sepolicy: allow access debugfs charger register dump am: 5e426a95d0 am: ff33c561a8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ia0cec31297a8b396eb79f349998cb9d33a6c1e98
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 07:40:47 +00:00
Jenny Ho
ff33c561a8 sepolicy: allow access debugfs charger register dump am: 5e426a95d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ie517da7264b8a3fdc7652f80f07c7a0584718cdc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 07:17:46 +00:00
Jenny Ho
f9e379b88a sepolicy: allow access debugfs charger register dump am: 5e426a95d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18013064

Change-Id: Ib90d53f60f7e30ae600602e4b08038ffd978c65e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 07:17:36 +00:00
Jenny Ho
5e426a95d0 sepolicy: allow access debugfs charger register dump
Bug: 230360103
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Ieedff4d6475706d4d932913e6d647ca401e56966
2022-05-03 06:54:05 +00:00
Labib
7098b220d5 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8 am: 22388f50f5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I99066d6e0950cf332b2af47c55cfd85841376bc4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:59:45 +00:00
Labib
7795860591 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 7f89bf6be8 am: 9a185b7f49
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I413961c420656703bc641daa649bf91448dd784c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:59:21 +00:00
Labib
22388f50f5 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: Iae1bb5c50d3c31c55620b5d1460260142404e1ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:42:07 +00:00
Labib
77af035a89 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 177a3796e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I0b83f116a5333924ae661ca3ccad0b08e101da39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:42:05 +00:00
Labib
9a185b7f49 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8 am: 7f89bf6be8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: I6033a5d87e2849d39198ba58b9889c9f07fa4895
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:30:50 +00:00
Labib
177a3796e8 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: Iec721cea68d7eae8715537b887911c0f848e1e6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:07:36 +00:00
Labib
7f89bf6be8 Give RadioExt permission to write to sysfs node am: 4c8dbb65b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17981512

Change-Id: Ia21d71094878ef44659873ecb813e7c4dffafb8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-03 05:05:01 +00:00
Labib
4c8dbb65b8 Give RadioExt permission to write to sysfs node
Bug: 212601547
Test: Manual
Change-Id: I8c7341833aeacebfedba6e8e05d2696012043d32
2022-04-28 16:58:34 +08:00
Wei Wang
9edfe0c428 allow udfps hal to access trusty am: d85f93ec30 am: cb5e132eab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17992165

Change-Id: Iadb9038b0138fcef7b5da697c76ff7f8f21f2cde
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-28 02:08:54 +00:00
Wei Wang
f1981415e4 allow udfps hal to access trusty am: d85f93ec30 am: 8b0b46b1c3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17992165

Change-Id: I3d5edc8f30e594cda57d69582969ae57675893b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-28 02:08:38 +00:00
Wei Wang
cb5e132eab allow udfps hal to access trusty am: d85f93ec30
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17992165

Change-Id: I5256e98ef31df5201f1e824cf1e2d276411bc7d7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-28 01:17:17 +00:00
Wei Wang
8b0b46b1c3 allow udfps hal to access trusty am: d85f93ec30
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17992165

Change-Id: Ic4125cc7f4b34be8562db31019be2ee8d7e27b14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-28 01:15:51 +00:00
Wei Wang
d85f93ec30 allow udfps hal to access trusty
Bug: 229350721
Bug: 230492593
Test: UDFPS with stress
Signed-off-by: Wei Wang <wvw@google.com>
Change-Id: Ib1abe0e0318689528a6658f3597f1c11ad9fa1c3
2022-04-27 13:20:02 -07:00
Stephane Lee
ff30e014ce Fix permissions for ODPM permanently by adding all buses am: 85e5caf85e am: 3237df5318
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966244

Change-Id: Ia70d861bddc2c3eba22876d6347f475e0cf26400
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 02:20:15 +00:00
Stephane Lee
7a04c33bb0 Allow hal_thermal_default to read iio/odpm sysfs nodes am: a492311ba4 am: 28bb996e11
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966242

Change-Id: I81b79fc90049d06f3e65cbaa17bddfed85c06e96
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 02:20:13 +00:00
Stephane Lee
bd30d9e7f2 Fix permissions for ODPM permanently by adding all buses am: 85e5caf85e am: df77f4ec83
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966244

Change-Id: I84feb2e6517758043ba8ede99534b2333a1a0462
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 02:16:43 +00:00
Stephane Lee
26842a33ec Allow hal_thermal_default to read iio/odpm sysfs nodes am: a492311ba4 am: fcca6c922c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966242

Change-Id: I1f1200c7fd4f0c87e24b9cbedc33bf3c07dbe93d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 02:16:42 +00:00
Stephane Lee
3237df5318 Fix permissions for ODPM permanently by adding all buses am: 85e5caf85e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966244

Change-Id: I58f62d4a9949a0c518b1f1b5f79889eda7fbcaf2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 01:27:33 +00:00
Stephane Lee
df77f4ec83 Fix permissions for ODPM permanently by adding all buses am: 85e5caf85e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966244

Change-Id: I16442188d825d07fcadd54178ab72eea8d0f3050
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 01:27:32 +00:00
Stephane Lee
28bb996e11 Allow hal_thermal_default to read iio/odpm sysfs nodes am: a492311ba4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966242

Change-Id: Iddd9e9e9500f5ac43d06f460b08632d9a66bd85e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 01:27:32 +00:00
Stephane Lee
fcca6c922c Allow hal_thermal_default to read iio/odpm sysfs nodes am: a492311ba4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17966242

Change-Id: If40508c787ceb286956d1654cc78506e68a8543f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-27 01:27:31 +00:00
Stephane Lee
85e5caf85e Fix permissions for ODPM permanently by adding all buses
You don't need wildcards on genfs, just need the base path

Bug: 229895015
Test: Ensure the device boots, verify permissions with ls -AlZ
Change-Id: Ib59693f0404db4e28b9959fcdf1cc4d483c5d1b1
2022-04-27 01:06:36 +00:00
Stephane Lee
a492311ba4 Allow hal_thermal_default to read iio/odpm sysfs nodes
Bug: 230031671
Test: There are no errors for iio or odpm nodes
Change-Id: Ifb204fa7b535c001838c7008b30b6e41744a01d1
2022-04-26 21:24:30 +00:00
Wei Wang
a9ab4448db Grant trusty to power hal am: 90f4106b80 am: 0c542ab35f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17928564

Change-Id: Ic257a044067e7423f24ddff1b426e7ec2ffba7f1
Ignore-AOSP-First: this is an automerge
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-26 17:37:34 +00:00
Wei Wang
ae95ea381c Grant trusty to power hal am: 90f4106b80 am: 6c85eeac05
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17928564

Change-Id: I0191d1ddbb508ca9cf654680d4a753355ca44041
Ignore-AOSP-First: this is an automerge
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-26 17:37:19 +00:00
Wei Wang
0c542ab35f Grant trusty to power hal am: 90f4106b80
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17928564

Change-Id: If11ffc0910580c59f4920b1354e6de27945feb30
Ignore-AOSP-First: this is an automerge
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-26 17:09:52 +00:00
Wei Wang
6c85eeac05 Grant trusty to power hal am: 90f4106b80
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17928564

Change-Id: Id5c126d9111917573c01778a8b42374ee0a1a3d6
Ignore-AOSP-First: this is an automerge
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-26 17:09:49 +00:00
Wei Wang
90f4106b80 Grant trusty to power hal
Bug: 229350721
Test: UDFPS with stress
Signed-off-by: Wei Wang <wvw@google.com>
Change-Id: Ia88d6cff1d21940e22ae5122dbfcf52de27ad700
2022-04-23 21:53:44 -07:00
Quang Luong
c99bd85fcc Revert "Add SEPolicy settings for android logging/tracing servic..." am: a36285b0de am: 83129ea904
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17898130

Change-Id: I2152d34279809f01eafdfaba968a1833c5b89e1b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-22 02:25:32 +00:00