Commit graph

1024 commits

Author SHA1 Message Date
Steven Moreland
82c366063e Remove vendor_service. am: f10b9bf2cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19441143

Change-Id: Ib8a9d7fec295cdc8a9581f042bc082d83612d33a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-28 01:07:53 +00:00
Steven Moreland
f10b9bf2cd Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I6795d960aa2a3b3832be8e0f6a11cb0fc3337982
2022-07-26 23:53:54 +00:00
Adam Shih
5208624c3e sync bug_map with downstream am: b34d1c1ed0 am: fcb18faeb1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I8e49824f8c4c68d3af28cee59da2b2aece8fa0b2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:56:10 +00:00
Adam Shih
05991af46f sync bug_map with downstream am: b34d1c1ed0 am: 813e69784d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I93d1b34ef647501e7c99eed163a79f9b190f0b75
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:55:38 +00:00
Adam Shih
fcb18faeb1 sync bug_map with downstream am: b34d1c1ed0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: Id6d9092dd4f1e1b59b911a4bba12aca4f238248e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:32:08 +00:00
Adam Shih
813e69784d sync bug_map with downstream am: b34d1c1ed0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19349280

Change-Id: I11105def02ffc78d663ebfdf9548cf111429120b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-25 21:31:56 +00:00
Adam Shih
b34d1c1ed0 sync bug_map with downstream
Bug: 239403666
Test: boot
Change-Id: I7e95cc5169ce56f1bba031b4d8a83ab1d5c80b26
Merged-In: If07a3611f40324d985a387c6dd7f2570c90c7c11
2022-07-25 21:05:38 +00:00
Edmond Chung
087f96ccf0 Allow vendor_init to set camera properties am: c09b0f9873 am: ed1f75b8aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: Ic462b751b4d3e3d2d18da39e76d5bf7dd1696a3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:18:35 +00:00
Edmond Chung
12154623dc Allow vendor_init to set camera properties am: c09b0f9873 am: 135261452d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: If7fccd0c50043a74ea95f49426930b87779ef0f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 02:08:54 +00:00
Edmond Chung
ed1f75b8aa Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I6dd674a0a9dfde23a38137d67a4db4437395600a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:46:05 +00:00
Edmond Chung
135261452d Allow vendor_init to set camera properties am: c09b0f9873
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19381316

Change-Id: I895cb20aa12d6611d09338c2e0dab1748a74aa68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-22 01:45:56 +00:00
Edmond Chung
c09b0f9873 Allow vendor_init to set camera properties
Bug: 239368308
Test: Camera CTS
Change-Id: Ia34804235729d5230123431a4b315bb2967c4cc8
2022-07-22 01:44:15 +00:00
Jack Wu
fb3b2b7988 Update SELinux error am: c50018a543
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19379646

Change-Id: I384a3a37914704e167ce7e4363fb319d44111b61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-21 18:24:16 +00:00
Jack Wu
c50018a543 Update SELinux error
Bug: 238398889
Test: no avc denied in TreeHugger verified
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: Ia18714461cb9f30fe110917489adddee98de194f
2022-07-21 21:44:03 +08:00
matthuang
645ab36c29 Add security context for com.google.usf.non_wake_up/wakeup. am: 1c7154c453
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320259

Change-Id: I1347e599954db1455332c5e1304705a65e790770
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-19 07:09:06 +00:00
matthuang
1c7154c453 Add security context for com.google.usf.non_wake_up/wakeup.
Bug: 195077076
Test: Confirm there is no avc denied log.
Change-Id: I86c787d59203464fc3b8b2b94b4883cbd07196b0
2022-07-19 06:53:48 +00:00
Robin Peng
8368a0a967 init-insmod-sh: fix avc error am: dfc95d0774
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19320251

Change-Id: I4253cddfc840c0a72ebd9943a21fac8be2b2981d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-18 10:31:40 +00:00
Robin Peng
dfc95d0774 init-insmod-sh: fix avc error
avc: denied { set } for property=vendor.all.modules.ready pid=1238 uid=0 gid=0 scontext=u:r:init-insmod-sh:s0 tcontext=u:object_r:vendor_ready_prop:s0 tclass=property_service permissive=0

Bug: 238853979
Signed-off-by: Robin Peng <robinpeng@google.com>
Change-Id: Ic8d7af3c1d73f3079e126b66b38d728fe4d70ea4
2022-07-18 04:54:57 +00:00
Robb Glasser
0e855aa924 Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I0bbc8360988917f283cdd4013142f68258077bdc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:34:39 +00:00
Robb Glasser
5325bbdf2f Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib0f872ffa8e66cee2fe4b12adb02463b450d42fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:33:37 +00:00
Robb Glasser
76ff3ba367 Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I003515c35a34416c0c49fe1267ba9ed54c9e2f8c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:43 +00:00
Robb Glasser
b93c3b981b Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib1b79c1528832a2705dcee251e2b239cef63455e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:41 +00:00
Robb Glasser
46c4571485 Remove HAL sensors dontaudits.
Sensors HAL sepolicy is written, but the dontaudit parts were not
cleaned up at the time. Removing these as they are no longer needed.

Bug: 227695036
Test: No denials as expected.
Change-Id: Idc0ed7f380cb07bfc7695ef3019f335fd8fad0a2
2022-07-13 11:06:04 -07:00
Kyle Tso
6218ff00ec Add logbuffer file_contexts am: c2ed52536e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Ibd266344d154338c48672da6d949edd10cc7da40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:40:25 +00:00
Kyle Tso
c2ed52536e Add logbuffer file_contexts
Bug: 237082721
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: Ieaf04f7381db1febe5a3899a727b6a49726bf10b
2022-07-09 07:22:55 +00:00
Star Chang
83eec39629 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: I12a467b4ef37fa13ff82e1adc66d504430247e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:15:02 +00:00
Star Chang
30af05ede4 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If4468131df2226ac09aa0a20892147bd872e4a4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:14:42 +00:00
Star Chang
932cf00952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If9f48a717ec9ae82dda176dfcd1a5b26651028ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:32 +00:00
Star Chang
407c14d952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ia20b4d2e67577ccb0fa1f3ef7176f62161ad5ddc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:31 +00:00
Star Chang
c466a68305 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware
related files.

Add policy to allow wifi_sniffer daemon to access wifi firmware related
files.

To fix the denial message:
[85544.205505] type=1400 audit(1656381950.486:90): avc: denied { search
} for comm="wifi_sniffer" name="wifi" dev="sysfs" ino=97256
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=dir permissive=1
[85544.206027] type=1400 audit(1656381950.486:91): avc: denied { write }
for comm="wifi_sniffer" name="firmware_path" dev="sysfs" ino=97268
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206206] type=1400 audit(1656381950.486:92): avc: denied { open }
for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206349] type=1400 audit(1656381950.486:93): avc: denied { getattr
} for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1

Bug: 237465412
Test: wifi_sniffer is workable
Change-Id: I5500be87d2b670e29c08d026872a6b304109f7a3
2022-07-07 06:15:48 +00:00
Adam Shih
16d8257567 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Ice227542ecee1a6359825027cd6ce5c90c3e6e90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:37 +00:00
Adam Shih
2a92d64cdb Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id0e75a481c2c3f1d482d10af4d8bbbf37ff79f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:23 +00:00
Adam Shih
2fc31f23a8 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I3ecdc79d72c83e9ec7496303f054da857a3b0cad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:16 +00:00
Adam Shih
dd8eab3bf9 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I4cacf54cd9bb9127de89ad5a77c489c26b5744bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:14 +00:00
Adam Shih
74ff6db973 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
Merged-In: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 03:11:33 +00:00
matthuang
11ecc1dd92 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: I91928227a99bede90714c93841592e9a91aeff6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:06 +00:00
matthuang
a1b5481877 Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: Ib97da81a01f566c7bd600512bb01fda27f34b217
2022-07-01 02:16:08 +00:00
SalmaxChang
6cb0e32470 ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6e559d5541d26742effd95d0f421ea18d1d58e20
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:36:00 +00:00
SalmaxChang
90058742f5 ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6ab19b09ec866b6667623a335440f351d73b86b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:35:36 +00:00
SalmaxChang
69172f08c9 ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ib3fb750345c86fc2c8f66ad27a73cec264884c3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:28 +00:00
SalmaxChang
3a3a53efaf ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ic2d4855d462d99b380160a446e201196c74e5930
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:25 +00:00
SalmaxChang
a7127617ba ssr_detector_app: remove tracking denials
Avc errors already fixed. Remove tracking denials.

Bug: 207571417
Bug: 205202542
Change-Id: I97d5f732e038dbdaf7885bdb9ca63bc518a97d51
2022-06-29 15:52:43 +00:00
xiaofanj
a0de630cd7 modem_svc_sit: create oem test iodev am: da328e0a0f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18768560

Change-Id: I36bb28394d68d266130135665f565f4be68569ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-28 03:34:47 +00:00
xiaofanj
da328e0a0f modem_svc_sit: create oem test iodev
- Create radio_test_device for oem_test iodev.
- Grant modem_svc_sit to access radio_test_device.

Bug: 231380480

Signed-off-by: Xiaofan Jiang <xiaofanj@google.com>
Change-Id: Id06deedadf04c70b57e405a05533ed85764bdd1d
Merged-In: Id06deedadf04c70b57e405a05533ed85764bdd1d
2022-06-28 03:16:08 +00:00
Sam Ou
da2ba2a04c sepolicy: fix odpm avc denials am: 65bdbc4862 am: 30d46d274b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ibd2aea9997607f1b444ca652a98ac84a877548b4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:11:22 +00:00
Sam Ou
c12c06c778 sepolicy: fix odpm avc denials am: 65bdbc4862 am: eee2b6fe84
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ic9b3c402e49d92a64bbe432fe2c1dc8d9e26b6fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:11:02 +00:00
Sam Ou
30d46d274b sepolicy: fix odpm avc denials am: 65bdbc4862
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ieb89884ee444ba9eb06e23f8ab4d20a96fa8c323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 06:48:52 +00:00
Sam Ou
eee2b6fe84 sepolicy: fix odpm avc denials am: 65bdbc4862
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: I4b40035d0cfe661da8f78d81fdc500f27f2ca619
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 06:48:49 +00:00
Sam Ou
65bdbc4862 sepolicy: fix odpm avc denials
add wakeup permissions for odpm driver
since we update acc_data based on alarmtimer

Bug: 236798116
Change-Id: Ib898eeebf0e26a723f260a2a8ddb5e5f64d255ed
Signed-off-by: Sam Ou <samou@google.com>
2022-06-27 06:29:03 +00:00
sukiliu
c9d05f0e26 [Do not merge] Remove regmap from list am: 1f681630c4 am: 9eadb411f8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18845251

Change-Id: I933bdd49496eb4a5ca9aaf03c78ce40153bb8de4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 04:18:01 +00:00