Commit graph

1906 commits

Author SHA1 Message Date
Robb Glasser
13cdb1a7ad Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367 am: 0e855aa924
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: If5b2e6ca7aae3b9a97cf154126116acc26399b54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:53:55 +00:00
Robb Glasser
6652430fc4 Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b am: 5325bbdf2f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ifed619dba499bd940ff2c7019b7c3d6ef6e5998e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:53:05 +00:00
Robb Glasser
0e855aa924 Remove HAL sensors dontaudits. am: 46c4571485 am: 76ff3ba367
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I0bbc8360988917f283cdd4013142f68258077bdc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:34:39 +00:00
Robb Glasser
5325bbdf2f Remove HAL sensors dontaudits. am: 46c4571485 am: b93c3b981b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib0f872ffa8e66cee2fe4b12adb02463b450d42fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:33:37 +00:00
Robb Glasser
76ff3ba367 Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: I003515c35a34416c0c49fe1267ba9ed54c9e2f8c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:43 +00:00
Robb Glasser
b93c3b981b Remove HAL sensors dontaudits. am: 46c4571485
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19281889

Change-Id: Ib1b79c1528832a2705dcee251e2b239cef63455e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-14 02:07:41 +00:00
Robb Glasser
46c4571485 Remove HAL sensors dontaudits.
Sensors HAL sepolicy is written, but the dontaudit parts were not
cleaned up at the time. Removing these as they are no longer needed.

Bug: 227695036
Test: No denials as expected.
Change-Id: Idc0ed7f380cb07bfc7695ef3019f335fd8fad0a2
2022-07-13 11:06:04 -07:00
Adam Shih
9899069adb Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238705599
Change-Id: Ia78ce7f5b2adc41f7d64b99279681acce647e8bb
2022-07-12 12:49:17 +08:00
Adam Shih
1e606d96f1 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238571150
Change-Id: Idb8c4f3e99d23e73fe2e63beec1142d1207c0a05
2022-07-11 10:24:25 +08:00
Kyle Tso
6ddb00d0c5 Add logbuffer file_contexts am: c2ed52536e am: 6218ff00ec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Iaa6476fe43b2975bfe3c38f045f93b7a57ba61e3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:57:47 +00:00
Kyle Tso
6218ff00ec Add logbuffer file_contexts am: c2ed52536e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19065329

Change-Id: Ibd266344d154338c48672da6d949edd10cc7da40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-09 07:40:25 +00:00
Kyle Tso
c2ed52536e Add logbuffer file_contexts
Bug: 237082721
Signed-off-by: Kyle Tso <kyletso@google.com>
Change-Id: Ieaf04f7381db1febe5a3899a727b6a49726bf10b
2022-07-09 07:22:55 +00:00
Daniel Angell
3adb31f004 Remove dontaudit rules related to storageproxyd's /data access.
Removing dontaudits for both tracking_denials/tee.te and
whitechapel_pro/tee.te results in no new audit log messages related to
storageproxyd, so they can both be removed.

Bug: 215649571
Test: adb logcat | grep -iE 'storageproxyd'

Change-Id: I8dc735bcaf0725c8d4eab4587f7a7fce21f4e25c
2022-07-07 18:37:23 +00:00
Star Chang
b37cb131ce wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952 am: 83eec39629
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie344b22cbf59832fe4bd73f13a78308f32f13a4f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:46:32 +00:00
Star Chang
9e803338be wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952 am: 30af05ede4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ie4a340374c5e59bdba96528b6d717c2ce0c72281
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:45:57 +00:00
Star Chang
83eec39629 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 932cf00952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: I12a467b4ef37fa13ff82e1adc66d504430247e74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:15:02 +00:00
Star Chang
30af05ede4 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305 am: 407c14d952
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If4468131df2226ac09aa0a20892147bd872e4a4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 07:14:42 +00:00
Star Chang
932cf00952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: If9f48a717ec9ae82dda176dfcd1a5b26651028ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:32 +00:00
Star Chang
407c14d952 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware am: c466a68305
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19132092

Change-Id: Ia20b4d2e67577ccb0fa1f3ef7176f62161ad5ddc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-07 06:51:31 +00:00
Star Chang
c466a68305 wifi_sniffer: Add policy to allow wifi sniffer to access wifi firmware
related files.

Add policy to allow wifi_sniffer daemon to access wifi firmware related
files.

To fix the denial message:
[85544.205505] type=1400 audit(1656381950.486:90): avc: denied { search
} for comm="wifi_sniffer" name="wifi" dev="sysfs" ino=97256
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=dir permissive=1
[85544.206027] type=1400 audit(1656381950.486:91): avc: denied { write }
for comm="wifi_sniffer" name="firmware_path" dev="sysfs" ino=97268
scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206206] type=1400 audit(1656381950.486:92): avc: denied { open }
for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1
[85544.206349] type=1400 audit(1656381950.486:93): avc: denied { getattr
} for comm="wifi_sniffer" path="/sys/wifi/firmware_path" dev="sysfs"
ino=97268 scontext=u:r:wifi_sniffer:s0 tcontext=u:object_r:sysfs_wifi:s0
tclass=file permissive=1

Bug: 237465412
Test: wifi_sniffer is workable
Change-Id: I5500be87d2b670e29c08d026872a6b304109f7a3
2022-07-07 06:15:48 +00:00
Jenny Ho
eeced97ca9 fix avc error for fg_model/registers
remove tracking with fix http://ag/19145061

Bug: 226271913
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: Idaa9e75a013dc7c78234bff041819c3c131f3793
2022-07-07 06:14:42 +00:00
Adam Shih
e87fbe539d Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 238260726
Bug: 238260742
Bug: 238260741
Change-Id: Ia3796d62a044b6c0e55c280918251f48143cfd0f
2022-07-07 10:23:05 +08:00
Adam Shih
2bd613cfe6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 227121550
Change-Id: I3e5c653a63b099aa44a880c4d1b2a327415f4d97
2022-07-06 01:24:15 +00:00
Denny cy Lee
7bb9a6aaf4 HwInfo: remove -sepolicy/tracking_denials/hardware_info_app.te
Bug: 208909060
Test: not avc log for hardware_info_app
Change-Id: I52dd55bcea0dd70f60d9156937861ef2036dc46d
Signed-off-by: Denny cy Lee <dennycylee@google.com>
2022-07-06 01:24:08 +00:00
Adam Shih
16e427a5a0 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours am: 16d8257567 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I34420aab930503c068baa3ee460e2d416e141650
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:13:05 +00:00
Adam Shih
7c6f0dd4bc [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9 am: 2a92d64cdb -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 c0ec14b9b1 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id085736a3b35da29a111ca4ae71460aa1d6bc3c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 01:12:57 +00:00
Adam Shih
16d8257567 [automerger skipped] Update error on ROM 8765438 am: 74ff6db973 am: 2fc31f23a8 -s ours
am skip reason: Merged-In I4b067085dc0c9f79b715505a5831cab63fda6381 with SHA-1 74ff6db973 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Ice227542ecee1a6359825027cd6ce5c90c3e6e90
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:37 +00:00
Adam Shih
2a92d64cdb Update error on ROM 8765438 am: 74ff6db973 am: dd8eab3bf9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: Id0e75a481c2c3f1d482d10af4d8bbbf37ff79f21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:53:23 +00:00
Adam Shih
2fc31f23a8 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I3ecdc79d72c83e9ec7496303f054da857a3b0cad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:16 +00:00
Adam Shih
dd8eab3bf9 Update error on ROM 8765438 am: 74ff6db973
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19174387

Change-Id: I4cacf54cd9bb9127de89ad5a77c489c26b5744bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-06 00:37:14 +00:00
Adam Shih
74ff6db973 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
Merged-In: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 03:11:33 +00:00
Adam Shih
c0ec14b9b1 Update error on ROM 8765438
Bug: 238037492
Bug: 237093466
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b067085dc0c9f79b715505a5831cab63fda6381
2022-07-05 11:10:34 +08:00
Alex Hong
3439f51f28 Remove googlebattery from dontaduit list
Bug: 237700766
Bug: 237491814
Test: PtsSELinuxTestCases
Change-Id: Ic4119e552827a490ba829a80cd10c5fc3ba1d35e
2022-07-01 16:59:04 +08:00
matthuang
58e7856f01 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877 am: 11ecc1dd92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: Ibe2f4ef31da08df20c7f3524bef19279c4935aab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 03:12:21 +00:00
matthuang
11ecc1dd92 Add acd-com.google.usf.non_wake_up file to AoC file context. am: a1b5481877
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18873692

Change-Id: I91928227a99bede90714c93841592e9a91aeff6d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-01 02:45:06 +00:00
matthuang
a1b5481877 Add acd-com.google.usf.non_wake_up file to AoC file context.
Bug: 195077076
Test: ls -lZ dev/acd-com.google.usf.non_wake_up
Change-Id: Ib97da81a01f566c7bd600512bb01fda27f34b217
2022-07-01 02:16:08 +00:00
SalmaxChang
5631fe741c ssr_detector_app: remove tracking denials
Avc errors already fixed. Remove tracking denials.

Bug: 205202542
Change-Id: I08522d563de58e4bc2be2c4a1bea54bbeac6adb8
2022-06-30 07:39:34 +00:00
sukiliu
b5edce085f Update avc error on ROM 8780665
Bug: 237491813
Bug: 237492145
Bug: 237491814
Bug: 237492146
Bug: 237492091
Test: PtsSELinuxTestCases
Change-Id: I615453d58ea17306ceefe6195bc95974de0f259b
2022-06-30 05:53:29 +00:00
SalmaxChang
ec3f03ee7a ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9 am: 6cb0e32470
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I00832bf3c76d97951cee3cfddc2bf5b548ca5071
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 18:30:16 +00:00
SalmaxChang
073c59da08 [automerger skipped] ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf am: 90058742f5 -s ours
am skip reason: skipped by user salmaxchang

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I2b3175ecde53fb5d0cdd69c74ba8590d849e6ad2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 18:30:05 +00:00
SalmaxChang
6cb0e32470 ssr_detector_app: remove tracking denials am: a7127617ba am: 69172f08c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6e559d5541d26742effd95d0f421ea18d1d58e20
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:36:00 +00:00
SalmaxChang
90058742f5 ssr_detector_app: remove tracking denials am: a7127617ba am: 3a3a53efaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: I6ab19b09ec866b6667623a335440f351d73b86b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:35:36 +00:00
SalmaxChang
69172f08c9 ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ib3fb750345c86fc2c8f66ad27a73cec264884c3c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:28 +00:00
SalmaxChang
3a3a53efaf ssr_detector_app: remove tracking denials am: a7127617ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18992387

Change-Id: Ic2d4855d462d99b380160a446e201196c74e5930
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-29 16:10:25 +00:00
SalmaxChang
a7127617ba ssr_detector_app: remove tracking denials
Avc errors already fixed. Remove tracking denials.

Bug: 207571417
Bug: 205202542
Change-Id: I97d5f732e038dbdaf7885bdb9ca63bc518a97d51
2022-06-29 15:52:43 +00:00
sashwinbalaji
f131707b2a thermal: added property persist.vendor.disable.thermal.dfs.control
Updated the sepolicy to access tmu register

Bug: 235156080
Test: Used local build to verify security context of tmu_reg file
Change-Id: I3d43a393d76e7245e48ebcf9592c7e230c58d9bd
2022-06-29 07:43:15 +00:00
xiaofanj
0a11e59639 [automerger skipped] modem_svc_sit: create oem test iodev am: da328e0a0f am: a0de630cd7 -s ours
am skip reason: Merged-In Id06deedadf04c70b57e405a05533ed85764bdd1d with SHA-1 b3576ef751 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18768560

Change-Id: I0ce76b9180a3cd22452535e501b9ec54a63168a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-28 03:52:57 +00:00
xiaofanj
a0de630cd7 modem_svc_sit: create oem test iodev am: da328e0a0f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/18768560

Change-Id: I36bb28394d68d266130135665f565f4be68569ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-28 03:34:47 +00:00
xiaofanj
da328e0a0f modem_svc_sit: create oem test iodev
- Create radio_test_device for oem_test iodev.
- Grant modem_svc_sit to access radio_test_device.

Bug: 231380480

Signed-off-by: Xiaofan Jiang <xiaofanj@google.com>
Change-Id: Id06deedadf04c70b57e405a05533ed85764bdd1d
Merged-In: Id06deedadf04c70b57e405a05533ed85764bdd1d
2022-06-28 03:16:08 +00:00
Sam Ou
7bf0763083 sepolicy: fix odpm avc denials am: 65bdbc4862 am: 30d46d274b am: da2ba2a04c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/19035052

Change-Id: Ia02fc75749b5078912d9a28470a9e295954c367e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-06-27 07:28:46 +00:00