Commit graph

2021 commits

Author SHA1 Message Date
Ken Yang
f0c6f18d7d SELinux: fix the wakeup avc denials am: 3054cb6eec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/24192194

Change-Id: Ia49778517e9c64e4b7539fa81ec4170cef01961c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-26 02:30:35 +00:00
Ken Yang
3054cb6eec SELinux: fix the wakeup avc denials
Fix the wakeup avc denials in a more common place

Bug: 292076108
Change-Id: I52627f19cb0fec3dd0851d21d0608048ebc7d45d
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-25 13:12:32 +00:00
David Anderson
96009e517c Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21 am: a7e9f0a873
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ie086b1fb169292469ec153039beee50ae782276d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 00:07:32 +00:00
David Anderson
a7e9f0a873 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d am: a03ec9af21
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: I29b1070280c3e88e976dab3c02b110786ca8f11b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 23:22:17 +00:00
David Anderson
a03ec9af21 Allow fastbootd to flash dtbo. am: e96a14a9d2 am: 439827c49d
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Id20a32d6a80e058caebf2047e59a1b5a3e519f43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 22:41:44 +00:00
David Anderson
439827c49d Allow fastbootd to flash dtbo. am: e96a14a9d2
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2652408

Change-Id: Ifc30a96202cbeb38896f3545502b582168dcf53e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 21:57:26 +00:00
David Anderson
e96a14a9d2 Allow fastbootd to flash dtbo.
This line is copied from gs101-sepolicy, and fixes the following denial:

audit: type=1400 audit(1689093038.396:14): avc:  denied  { write } for  pid=409 comm="fastbootd" name="sda24" dev="tmpfs" ino=493 scontext=u:r:fastbootd:s0 tcontext=u:object_r:custom_ab_block_device:s0 tclass=blk_file permissive=0

Bug: N/A
Test: fastboot flashall in fastbootd
Change-Id: I765aedeb204cc862434a56a97f242640465f84b8
2023-07-11 10:27:47 -07:00
Xin Li
645f996b23 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours am: c9d5097e56 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I702a5374d5ddff6d17ae5f49e79654ab7d85ab81
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 01:14:07 +00:00
Xin Li
c9d5097e56 [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours am: dc4a87253c -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I903de348dca44cf893578b33b13743269685a480
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 00:32:37 +00:00
Xin Li
dc4a87253c [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours am: 7e4592c70a -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I07063c3d9cf1418132ec611701713baa7b783f59
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 23:10:28 +00:00
Xin Li
7e4592c70a [automerger skipped] Merge Android 13 QPR3 am: aaef0b7773 -s ours
am skip reason: Merged-In Idc925c7a1f1111840a64664aa50c39442c3a0f8f with SHA-1 307e2c2fc8 is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2635310

Change-Id: I27e4864161d3db815ad9cedad4da2af6ee082826
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 22:57:43 +00:00
Xin Li
aaef0b7773 Merge Android 13 QPR3
Bug: 275386652
Merged-In: Idc925c7a1f1111840a64664aa50c39442c3a0f8f
Change-Id: I2f0a022715577d395a6d9d2c8ec6b9a7f37fe509
2023-06-21 15:14:53 -07:00
Jenny Ho
abb6cc1a80 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 3ab8be18a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I96b77bcbb6ab773d41b861f4770e07f41b6b834a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 02:36:08 +00:00
Jenny Ho
eef3026fd5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880 am: 34ee73b7f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: Ib71b8ae6c48db75778ec84a2d5a5b2efec88244c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 02:33:59 +00:00
Jenny Ho
34ee73b7f2 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: Ie6144135cf653d281c7bef84fb4469daefbad095
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:54:32 +00:00
Jenny Ho
3ab8be18a5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I899bc4150d6d32b0ede035c96487da50849b6256
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:50:10 +00:00
Jenny Ho
ee160b5880 Add permissions for maxfg_base/maxfg_secondary
Bug: 284878175
Change-Id: I3fe3030ecd36773405f0e70b767d4a28062d91ad
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-05-30 12:09:30 +08:00
Donnie Pollitz
d662abd90e Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: 36ea330be0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I44a0090b6a0be88fd606596fae0a236ef9bcdd40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 09:01:41 +00:00
Donnie Pollitz
62bfe3afc4 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f am: a2cb6ab6eb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: I891e9032a5bacf115410ad81ccd07580645da9d6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 08:59:32 +00:00
Donnie Pollitz
a2cb6ab6eb Allow vendor_init to fix permissions of TEE data file am: 955ae6825f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ibf91aa97b122e3a5f39053c6ed01e62b3783403c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:53:44 +00:00
Donnie Pollitz
36ea330be0 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ic51e258b34e4525f669a67d5eecd18b781bf6010
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:49:20 +00:00
Donnie Pollitz
955ae6825f Allow vendor_init to fix permissions of TEE data file
Background:
* vendor_init needs to be able to possibly fix ownership of
  tee_data_file

Bug: 280325952
Test: Changed permissions and confirmed user transitions
Change-Id: I27681589c9d0b0aa88463e6476fb75119ea89e8a
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-05-26 07:17:39 +00:00
sashwinbalaji
711cf086a9 thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea am: 29df1ad288
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: Id496e32bc9f0255c68e86605ba237d23cab6bbce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 07:07:49 +00:00
sashwinbalaji
083335d39b thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea am: 6bc46c8cd5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: I5d426b52828b29550d126854f5a7b2d39cde6661
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 07:03:07 +00:00
sashwinbalaji
6bc46c8cd5 thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: I2037d2de006c26cba1b2114f776678aca7c4a808
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 06:22:41 +00:00
sashwinbalaji
29df1ad288 thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: I6a691341b37808102fd540fce39373498e18b379
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 06:18:24 +00:00
sashwinbalaji
1113c66dea thermal: thermal_metrics: Update selinux to reset stats
Bug: 193833982
Test: Local build and verify statsD logs
adb shell cmd stats print-logs && adb logcat -b all | grep -i 105045
Change-Id: I0dc1c557797d7fe97da7f0fcb2d600485526c979
2023-05-25 05:28:45 +00:00
Jin Jeong
15d383b430 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619 am: aa606065a3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: Iccab57deadb4965a765bebb85368345bab672c8c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 02:30:58 +00:00
Jin Jeong
a82c726a4e Revert "Fix LPA crash due to selinux denial" am: 980c71bea4 am: 35e908fd66
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: I92d2d75c4d0f66999b9bd0ac2f688c195b53af11
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 02:30:52 +00:00
Jin Jeong
9b291f9755 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619 am: 5627fe6f60
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: I3ba572b0238412fc510d6f1ed82723904e1392a5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 02:26:14 +00:00
Jin Jeong
3588c019b2 Revert "Fix LPA crash due to selinux denial" am: 980c71bea4 am: 42760593ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: Ic17a94ed766998b8eaa711ae12b75e3e597d913b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 02:26:08 +00:00
Jin Jeong
5627fe6f60 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: I66ec119e485273f9d1562bb272ab7c25541e98b3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:47:08 +00:00
Jin Jeong
42760593ae Revert "Fix LPA crash due to selinux denial" am: 980c71bea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: Ib285406b29c598ab5cec6db6ab0d2f9d57343a0f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:47:01 +00:00
Jin Jeong
aa606065a3 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: Ifa25563c9f0d157ce52f2d2d320c6cc166521c2a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:42 +00:00
Jin Jeong
35e908fd66 Revert "Fix LPA crash due to selinux denial" am: 980c71bea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: I7d6c19280280e63b194da9bdef8b8a80d057f364
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:36 +00:00
Jin Jeong
10ef6d8619 Revert "Fix SELinux error for com.google.android.euicc"
Revert submission 22899490-euicc_selinux_fix

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22899490-euicc_selinux_fix

Change-Id: I50ff4f8e48389d034c3f6c716dad1a81e9b73e64
2023-05-24 01:07:09 +00:00
Jin Jeong
980c71bea4 Revert "Fix LPA crash due to selinux denial"
Revert submission 22955599-euicc_selinux_fix2

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22955599-euicc_selinux_fix2

Change-Id: I2799c61ab5464e5551168f471740afe76edd1113
2023-05-24 01:07:09 +00:00
Anthony Zhang
28bc5a68e0 [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61 am: f8bcbec08a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: I34fa2f7c8b5ffe3d1d08b8fd84681d22b25ec413
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 20:00:34 +00:00
Anthony Zhang
301d7d4311 [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61 am: 143c8076c2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: I2e89660afd10ac65cb3e48f2ddb1a10a89218c6c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 19:47:50 +00:00
Anthony Zhang
f8bcbec08a [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: Iefb182caafd96e46b9743e39066cb00c5d6bd933
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 19:23:36 +00:00
Anthony Zhang
143c8076c2 [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: Iaa3d014c486c6179609a481811103665c141f3b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 19:19:13 +00:00
Anthony Zhang
7f19e81d61 [DO NOT MERGE] Allow fingerprint to access persist property
Bug: 258901849
Test: Local test on enrollment/delete, version update

Change-Id: I96acb79b3e600e0a4dd7b7a1cf494b20a876ca63
2023-05-22 18:36:54 +00:00
Samuel Gosselin
09ba7e1b23 genfs_contexts: add raw s2mpg12mfd and s2mpg13mfd node. am: 918335e2a9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286925

Change-Id: I71816d985ff994f9672048aec26ffce5d9ae618a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-18 01:02:32 +00:00
Samuel Gosselin
918335e2a9 genfs_contexts: add raw s2mpg12mfd and s2mpg13mfd node.
This adds the appropriate raw i2c numberings to the sepolicy
for the 6.1 kernel driver which does not use the i2c vendor
hook to rename these numberings. This is required for the
thermal hal to work.

Test:
Boot to Android Home on WHI PRO with 6.1 kernel, no
Thermal HAL crashes.

Bug: 276464780
Signed-off-by: Samuel Gosselin <sgosselin@google.com>
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:83712c5243166cafa3a057d5347515e04947cde8)
Merged-In: I8c2633b33cef8ca2b55029190fe42bd66b17390f
Change-Id: I8c2633b33cef8ca2b55029190fe42bd66b17390f
(cherry picked from commit 64111ee561)
2023-05-17 18:09:48 +00:00
Luis Delgado de Mendoza Garcia
d5de1f21ec [automerger skipped] Add chre channel sepolicy entries am: 3992c42501 am: 7a14a3a96f -s ours
am skip reason: Merged-In I3151d25c4a1cd7a858b84e0c8989dc160d368ca5 with SHA-1 3992c42501 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: I3aa3319a15df9a86fabe79ee209ac402fdf833ba
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-17 00:21:35 +00:00
Luis Delgado de Mendoza Garcia
8f6514031c Add chre channel sepolicy entries am: 3992c42501 am: 0a15da974d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: Icfda18794f722598aae37a5930475fdb5d93d439
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-17 00:17:19 +00:00
Luis Delgado de Mendoza Garcia
7a14a3a96f Add chre channel sepolicy entries am: 3992c42501
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: I71ae96a9e7ff8861fd8b1835948d3e9c04a1d8c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:36:06 +00:00
Luis Delgado de Mendoza Garcia
0a15da974d Add chre channel sepolicy entries am: 3992c42501
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: Iada40c9422558bd1b3575e07378cb4a12e8c9ef0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:35:56 +00:00
Luis Delgado de Mendoza Garcia
3992c42501 Add chre channel sepolicy entries
Bug: 281814892
Fix: 281814892
Test: in-device verification.
Change-Id: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
Merged-In: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
2023-05-16 22:49:12 +00:00
Wilson Sung
ec383cedda Update SELinux error am: d19337894a am: f19eec56a0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633

Change-Id: I37000425db8dd9c27bcd86f3a6aafa31053ddd17
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 08:31:25 +00:00