Commit graph

42 commits

Author SHA1 Message Date
matthuang
306f6c5e8c Allow sensor hal to access uhid devices.
Bug: 262056923
Test: Screen is off when put a magnet close to hall sensor.
Change-Id: I2031c167f242b10b0a03076f0bc4184dd21e2cd5
2023-01-31 17:30:19 +08:00
Ken Yang
22698e6f3d Merge "WLC: Remove unused wireless_charger policies" 2023-01-13 14:41:31 +00:00
CJ Fan
7b208430ee Merge "Add sepolicy to allow lights to access display" into tm-qpr-dev am: bf9c2e4756 am: e34325cdfc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20858889

Change-Id: Ib0685955f5278f66d8eff77bf93be122433fa0b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-07 00:38:09 +00:00
Ken Yang
12579828b0 WLC: Remove unused wireless_charger policies
Bug: 263830018
Change-Id: I5378ad328d4a431413d296afd68d79f5c72bec5e
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-05 07:37:13 +00:00
TreeHugger Robot
2f8dfe7e15 Merge "Add sepolicy for sysfs_touch type." 2023-01-04 04:13:53 +00:00
Chungjui Fan
74bdc8089b Add sepolicy to allow lights to access display
Avc denied logs in b/264023021#comment2

Bug: 264023021
Change-Id: Ib8527aa6cb65511488495e58bca51287107d6d53
Signed-off-by: Chungjui Fan <chungjuifan@google.com>
2023-01-04 03:52:30 +00:00
Super Liu
5df51157c3 Add sepolicy for sysfs_touch type.
Bug: 263108813
Test: TreeHugger build pass.
Signed-off-by: Super Liu <supercjliu@google.com>
Change-Id: I83edfd28a116fe61cec323aecc30089b3298550f
2023-01-04 02:16:36 +00:00
TreeHugger Robot
315edc8f9b Merge "WLC: Add device specific sepolicy for wireless_charger" 2022-12-26 11:11:22 +00:00
Ken Yang
02379ea5d9 WLC: Add device specific sepolicy for wireless_charger
Bug: 263561134
Bug: 237600973
Change-Id: I95af98c9b7c2244522ba7e943b769e3e454edc20
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-23 11:21:59 +00:00
Darren Hsu
6f45c41a76 sepolicy: allow binder call for hal_power_stats and hal_bluetooth
avc: denied { call } for comm="bluetooth@1.1-s"
scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:r:hal_power_stats_default:s0 tclass=binder permissive=0

avc: denied { call } for scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:r:hal_power_stats_default:s0 tclass=binder permissive=1

avc: denied { read } for comm="android.hardwar"
name="u:object_r:boot_status_prop:s0" dev="tmpfs" ino=109
scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:object_r:boot_status_prop:s0 tclass=file permissive=0

Bug: 215487801 , 262386677
Test: captured bugreport and didn't see powerstats avc denials
Change-Id: I34840b7f8031084270477635c2bde5d702a0507c
Signed-off-by: Darren Hsu <darrenhsu@google.com>
(cherry picked from commit ccd9f49f2b)
2022-12-14 07:23:00 +00:00
Adam Shih
483f42925d align sysfs_touch_gti type
Bug: 256521567
Test: build pass
Change-Id: I2452e2551ea47a3bbf1c4b084259e73c37e02f04
2022-12-06 12:01:08 +08:00
Adam Shih
d5db8fa0e2 rename sysfs_touch
Bug: 256521567
Test: adb bugreport
Change-Id: Ic10339198209b7e1c8874610f69c515a95d6e7da
2022-12-02 13:08:28 +08:00
Adam Shih
33c84b77d2 fix declaration missing error
Bug: 260175281
Test: build pass
Change-Id: Ibe07a278639afa3d0783785374502607ba81eb6e
2022-11-25 14:09:21 +08:00
Adam Shih
e1e330d587 remove obsolete entry
Bug: 260175281
Test: build pass
Change-Id: I0f6d070416b5fac8711434b84fc9c552b8a6a64d
2022-11-24 10:55:04 +08:00
Ryan Ki Sing Chung
48d74244ca Revert "Revert "CastAuth: SELinux rules for the MediaDrm plugin"" am: c3ea668daa am: 5e4bde23de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20116451

Change-Id: I18383b804b1c3206111fdffa0c7caf29309f5a0a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-05 04:38:36 +00:00
Ryan Ki Sing Chung
68f76df95e Revert "CastAuth: SELinux rules for the MediaDrm plugin" am: fae580c5ce am: abd3be9d76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20110003

Change-Id: I0ad5e50db923d6125e8557f640a85808bd2b5644
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-05 02:41:59 +00:00
Ryan Ki Sing Chung
c3ea668daa Revert "Revert "CastAuth: SELinux rules for the MediaDrm plugin""
This reverts commit fae580c5ce.

Reason for revert: Relanding with fix

Bug: 250900568
Change-Id: I242a8b710d7d44e7390a1d63e39f7ebd7d406a4c
2022-10-05 01:10:00 +00:00
Ryan Ki Sing Chung
fae580c5ce Revert "CastAuth: SELinux rules for the MediaDrm plugin"
This reverts commit c579440a1f.

Reason for revert: Broke continuous build
Bug: 250900568

Change-Id: I69982e605c645373c38040d4b8527180a4efcecc
2022-10-04 19:19:26 +00:00
Ryan Ki Sing Chung
62a04bd5d1 Merge "CastAuth: SELinux rules for the MediaDrm plugin" into tm-qpr-dev am: bf74335744 am: 5d7e5c4958
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20068298

Change-Id: I04f822bc4483599375e8d68c1242dc67f265b495
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-04 17:38:52 +00:00
Ryan Ki Sing Chung
bf74335744 Merge "CastAuth: SELinux rules for the MediaDrm plugin" into tm-qpr-dev 2022-10-04 16:00:28 +00:00
Ryan Chung
c579440a1f CastAuth: SELinux rules for the MediaDrm plugin
Bug: 229298787
Test: Access Cast creds with MediaDrm plugin
Change-Id: Iff9386dc1223a9f5a088d7ba2d2bc8bd73eebc00
2022-09-29 18:15:15 -07:00
TreeHugger Robot
a7dc42a1de Merge "Sepolicy for hall effect notification." into tm-qpr-dev am: 9ed2e6925e am: 47d4948fd9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20060645

Change-Id: Iba57e60d01874c335e23fcd24bbd9adc4809db49
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-29 17:14:22 +00:00
TreeHugger Robot
9ed2e6925e Merge "Sepolicy for hall effect notification." into tm-qpr-dev 2022-09-29 16:17:51 +00:00
Darren Hsu
e6e557f360 sepolicy: add sysfs_wakeup labels for acpm am: 36714befbb am: bf82087232
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/20070665

Change-Id: I66f48db7ac9e29fb1d8dde70879412111ac28dd8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-29 04:05:09 +00:00
matthuang
938a12a2dc Sepolicy for hall effect notification.
Bug: 241474630
Test: Check selinux log.
Change-Id: Ia4dc303849c98a7c067a2fb0426b7a7b6d3d0301
2022-09-28 10:54:39 +08:00
Darren Hsu
36714befbb sepolicy: add sysfs_wakeup labels for acpm
Bug: 248974063
Test: run vts -m SuspendSepolicyTests
Change-Id: Ie96d282d7a6b61bafff4b66f63ff320d80a3b4f2
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-09-28 09:49:33 +08:00
kuanyuhuang
9db85e1f94 Add binder call for grilservice and hal_bluetooth am: 39b4f3823a am: 67f5891c35
Original change: https://googleplex-android-review.googlesource.com/c/device/google/tangorpro-sepolicy/+/19998306

Change-Id: Ic92294881b2d9d8e65a455fe009e11aeb6e511bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-22 03:44:08 +00:00
kuanyuhuang
39b4f3823a Add binder call for grilservice and hal_bluetooth
Gril calls setBluetoothModeBasedTxPowerCap to bluetooh HAL
for SAR feature.

Bug: 244409539
Test: build pass and check grilservice can bind with IBluetoothSar
Change-Id: Ie563cdbe126371d50bb996a0d4d10fd5f52e8d6f
2022-09-21 08:47:27 +00:00
TreeHugger Robot
5c4efb3f22 Merge "RESTRICT AUTOMERGE sepolicy: allow binder call for hal_power_stats and hal_bluetooth" into tm-qpr-dev 2022-09-16 03:15:08 +00:00
Darren Hsu
ccd9f49f2b RESTRICT AUTOMERGE sepolicy: allow binder call for hal_power_stats and hal_bluetooth
avc: denied { call } for comm="bluetooth@1.1-s"
scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:r:hal_power_stats_default:s0 tclass=binder permissive=0

avc: denied { call } for scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:r:hal_power_stats_default:s0 tclass=binder permissive=1

avc: denied { read } for comm="android.hardwar"
name="u:object_r:boot_status_prop:s0" dev="tmpfs" ino=109
scontext=u:r:hal_bluetooth_synabtlinux:s0
tcontext=u:object_r:boot_status_prop:s0 tclass=file permissive=0

Bug: 215487801
Test: captured bugreport and didn't see powerstats avc denials
Change-Id: I34840b7f8031084270477635c2bde5d702a0507c
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-09-14 10:44:38 +00:00
TreeHugger Robot
30226d2510 Merge "Migrate LED sepolicy used by dumpstate to gs201" into tm-qpr-dev 2022-09-14 02:59:20 +00:00
Darren Hsu
f3b6df78da sepolicy: add missing sysfs_wakeup labels
Bug: 245434941
Test: run vts -m SuspendSepolicyTests
Change-Id: I4873bbba4e6e276722037680056d4e003f8a0da9
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-09-12 16:04:21 +08:00
Chungjui Fan
f7be842d13 Migrate LED sepolicy used by dumpstate to gs201
Bug: 242300919
Change-Id: I1b7f4be6670ef645df932207ece4746fcedb9e39
2022-09-08 09:12:30 +00:00
Badhri Jagan Sridharan
aebc367bfa Port pogo sepolicy for target
This is port of <0fe78c45624ac71c303f28d214d04f5382744110>
and <b85ae23600ba9db57d9ea4343769f928e5dc58dd> from previous
target.

Bug: 242751127
Signed-off-by: Badhri Jagan Sridharan <badhri@google.com>
Change-Id: I20205c63dc226c6863215b29e11b8c4b626b6010
2022-08-24 21:05:19 +00:00
Super Liu
834dc1b842 Allow vendor_init to read gesture_prop.
Logs:
07-15 04:04:39.052     1     1 I auditd  : type=1107 audit(0.0:4): uid=0
auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { read
} for property=persist.sys.tap_gesture pid=0 uid=0 gid=0
scontext=u:r:vendor_init:s0 tcontext=u:object_r:gesture_prop:s0
tclass=file permissive=0'
07-15 04:04:39.087     1     1 E init    :
/vendor/etc/init/hw/init.tangorpro.rc: 48: ParseTriggers() failed:
unexported property trigger found: persist.sys.tap_gesture

Test: check Treehugger build for sepolicy.
Bug: 201610482
Signed-off-by: Super Liu <supercjliu@google.com>
Change-Id: I2072ce786bf9f3590487b1807672e993764cc6f0
2022-07-18 10:26:10 +08:00
TreeHugger Robot
32185368bd Merge "Add sepolicy to support lights HAL" into tm-qpr-dev 2022-07-06 04:46:25 +00:00
horngchuang
ae3a1d0737 sepolicy: Correct the camera sepolicy for T6Pro
Bug: 233171614
Test: local build Pass, boot to Home
Change-Id: Id0af2fb48e4e79e7900a9e3fb33224e5f8f52bc4
2022-06-29 07:46:20 +00:00
Chungjui Fan
24d426e003 Add sepolicy to support lights HAL
Bug: 230288032
Test: atest VtsHalLightTargetTest
Change-Id: I4fd54341d4ef6a91cb84f0881725985f05abf2d5
2022-06-29 14:33:33 +08:00
Jack Wu
07b7d71e5b sepolicy: allows dock power supply permission
Bug: 232723240
Test: can dump dock power supply in dumpstate
Signed-off-by: Jack Wu <wjack@google.com>
Change-Id: I955d72393bbe3413e56e6931a35e8cfa046001be
Signed-off-by: Jonglin Lee <jonglin@google.com>
2022-06-22 17:05:36 -07:00
Super Liu
2d23765f0b sepolicy: allow system_server to read sysfs_touch.
Bug: 231385413
Test: presubmit pass.
Signed-off-by: Super Liu <supercjliu@google.com>
Change-Id: Ica2e457d951e3de28fa7271eef03437c3203a373
2022-05-04 13:27:00 +08:00
Super Liu
b72de76e7b Initial touch sepolicy.
Bug: 193467774
Test: check touch sepolicy attribute from TreeHugger build rom.
Signed-off-by: Super Liu <supercjliu@google.com>
Change-Id: Ie3ccb47133dd9812ea91df59e1f9124bea1867c6
2022-05-04 11:07:08 +08:00
Roger Liao
aa2098ee18 Initial device tangorpro sepolicy
Bug: 220073297
Change-Id: Icbae09127d46c74aaa49bf417be263e62ce0c0ca
2022-03-09 15:50:55 +08:00