Commit graph

710 commits

Author SHA1 Message Date
Armelle Laine
39a9021703 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I7774f4fba285cd3a8b65c9c78245da5ee39d9c61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:29 +00:00
Armelle Laine
0da9e2ff96 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I66c16c9377b4af6c924adfee4b983acff7993e0e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:39:44 +00:00
Richard Chang
3c52a9ab3b Merge "sepolicy: update init.te for zram device" into udc-dev 2023-03-01 04:28:58 +00:00
Armelle Laine
d38c507ef6 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev 2023-03-01 03:41:09 +00:00
Kenny Root
076591d107 Add GSA logs policy
This adds a label to the sysfs files for GSA logs to allow dumpstate to
read them during a bugreport.

Bug: 271125313
Test: adb shell dumpstate
Change-Id: I8842c0bec972c4cfad15ca689f8e4ae7fa99e179
2023-02-28 18:33:23 -08:00
Richard Chang
ee8c7c2df2 sepolicy: update init.te for zram device
Bug: 269221861
Bug: 270633329
Test: Boot
Change-Id: I050e9a72006dcd0b71ba1232e38e5f96bce4c967
2023-03-01 02:04:24 +00:00
TreeHugger Robot
63f78e7b2e Merge "Update bug_map" into udc-dev am: 627e6c1648 am: 312d50fd92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: I1ea8df25e7cdd1a0e9283b01c51693caefb82893
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 01:54:20 +00:00
TreeHugger Robot
9986e1ef13 Merge "Update bug_map" into udc-dev am: 627e6c1648 am: 81390587ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: Iafb1c4276f8d1aa8a9e01090b44f76de8aade0db
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 01:50:18 +00:00
TreeHugger Robot
81390587ae Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: I6c9b8ad61f3ebc5cfab067016b0029b111bc4625
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:48 +00:00
TreeHugger Robot
312d50fd92 Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: Ie65327b364ad73df29b337d2de4ad8df51fbfb08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:30 +00:00
TreeHugger Robot
627e6c1648 Merge "Update bug_map" into udc-dev 2023-02-28 23:56:31 +00:00
Jonglin Lee
3c0dd54d80 Add perfmon policies am: 167eba3ad9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649593

Change-Id: Ibb15e72ed9d9bd5abbf5659bc3b7e925ec88d029
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-28 21:47:09 +00:00
Jonglin Lee
167eba3ad9 Add perfmon policies
Add perfmon policies to fix hotplug issues.

Bug: 271024526
Bug: 271007431
Change-Id: I974bd99224b983454c6af47f4a08a4fe20699834
Signed-off-by: Jonglin Lee <jonglin@google.com>
2023-02-28 10:19:26 -08:00
Xu Han
fe5bb58212 Update bug_map
Bug: 264483024
Test: Build.
Change-Id: I9a1574b5997d9ac5d26100254c7e20b81930df50
2023-02-28 09:34:58 -08:00
Cody Heiner
46a2c2df5e Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9 am: 2d46df5e9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: Iad3100b2d8e84db8e3a42db04205cc0cc7dd9fc4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 23:21:23 +00:00
Cody Heiner
09693b450a Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9 am: 609c49485d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: Ice0eb43e04ded0cf95309f5a9e4353413cbbdbb7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 23:21:06 +00:00
Cody Heiner
2d46df5e9a Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: I520655872e8d74b3cadc9f89f795173f5d3874e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 22:49:53 +00:00
Cody Heiner
609c49485d Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: I04b8ce8cb19be7c8634c78fb7e73e308eba9081d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 22:46:45 +00:00
Armelle Laine
d27961dc1b Define selinux properties for /dev/block/by-name/trusty_persist
Bug: 247013568
Test: - Verify that this change is a NOP for devices with TDP already
        created on top of the legacy f2fs partition /mnt/vendor/persist/ss
      - Verify that this change creates a valid symlink on a manually
        migrated block device
Change-Id: I226f365c6afbb5fa91ec1c9c1943f8dddac8183a
2023-02-27 22:42:08 +00:00
Armelle Laine
1731179cf1 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" 2023-02-27 20:07:35 +00:00
Cody Heiner
dc0b4fc9e9 Allow twoshay → systemui_app binder call for zuma devices (2)
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Note: this is a re-submit of ag/21529713, after sorting out the
SEPolicy issues described in b/270444888.

Test: flash P23 and Bluejay devices with this change plus ag/21591673,
  run `adb shell device_config put twoshay_native test_flag_name test_flag_value`,
  → TouchContextService.java logs corresponding property changed message.

Bug: 270444888

Change-Id: I40d70cf19930eb334ba3250d58a0cbc39b50764b
2023-02-24 18:19:09 -08:00
Wilson Sung
f69013330b Add SSR property access and remove obsolete denials am: 546b787a40 am: d5f419a6d4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552480

Change-Id: Iae1162526f5642964bd0f881306a2e767b7d0706
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 12:53:22 +00:00
Wilson Sung
d5f419a6d4 Add SSR property access and remove obsolete denials am: 546b787a40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552480

Change-Id: I4f6a1cfab59730efc3002351d7c66313651657e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 12:20:23 +00:00
Wilson Sung
b264162687 Merge "Add SSR property access and remove obsolete denials"
Bug: 268572164
Change-Id: I4285b0558dd2ff3bb8d4f54dfa1690828f65129a
2023-02-24 18:42:48 +08:00
Wilson Sung
546b787a40 Add SSR property access and remove obsolete denials
Bug: 268572164
Change-Id: I5756510b2eb2696aade93dd6b15a111f5dca58ef
2023-02-24 10:33:45 +00:00
Amy Hsu
c80e8b8a07 Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev am: ae4c77ebda am: 0089c57d7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503754

Change-Id: I26f9fba860b8e8c4ac3f789b2e706b756597baa0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 09:33:09 +00:00
Amy Hsu
64432e87a4 Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev am: ae4c77ebda
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503754

Change-Id: Ia8f236afbb9e940d0cb28662d03719671f2b2c31
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 08:59:54 +00:00
Amy Hsu
0089c57d7d Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev am: ae4c77ebda
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503754

Change-Id: I39e6bc8af10f8a5025168ec84ef41cf0aabb22dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 08:59:26 +00:00
Amy Hsu
ae4c77ebda Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev 2023-02-24 08:14:49 +00:00
Suki Liu
3f5195c678 Merge "Update SELinux error" into udc-dev am: e476047167 am: e0d1b24d12
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21571001

Change-Id: I37da08eb4c399eae6e44e9be684e1c97bb6d4e16
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:41:16 +00:00
Adam Shih
57a6a7f897 Merge "Move HWC dump to gs-common" into udc-dev am: 9675dc064a am: fcf2a4aa78
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533829

Change-Id: Idec0beb597167cbc8c35c7442e8f4c3b6896f6c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:35:53 +00:00
Suki Liu
e0d1b24d12 Merge "Update SELinux error" into udc-dev am: e476047167
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21571001

Change-Id: I7624d1a1234dccbc7cc741878879e8a2ff8828ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:15:39 +00:00
Adam Shih
fcf2a4aa78 Merge "Move HWC dump to gs-common" into udc-dev am: 9675dc064a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533829

Change-Id: Iebdf3ee606db9a0d74d3d2b631e7dc21984b054b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 05:41:10 +00:00
Suki Liu
41b9c8d4ce Merge "Update SELinux error" into udc-dev am: e476047167
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21571001

Change-Id: I33b65ed85d563132a531b27a757df04ca2f58137
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 05:40:50 +00:00
Suki Liu
e476047167 Merge "Update SELinux error" into udc-dev 2023-02-24 04:59:32 +00:00
Adam Shih
965fa5a7dc Merge "Move HWC dump to gs-common" into udc-dev am: 9675dc064a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533829

Change-Id: I04fc66b217b2cf30d035b50f60aef655ccd02dcf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 04:05:26 +00:00
Adam Shih
9675dc064a Merge "Move HWC dump to gs-common" into udc-dev 2023-02-24 03:17:38 +00:00
Amy Hsu
c186dbd6db Revise sepolicy because of refactor HbmSvManager
1. Set sepolicy correctly, make it the same as gs201.
2. Rename hbmsvmanager to pixeldisplayservice due to refactor.
3. Add arm_mali_platform_service for pixeldisplayservcice

Bug: 241498235
Bug: 262794939
Bug: 263185136
Bug: 264489797
Test: Verify LBE and shadow compensation functions.
      Make sure there is no avc denied.
Change-Id: I2a4bb5d6b863edc00b789fd6df8d46f90164d9f2
2023-02-24 02:06:35 +00:00
sukiliu
362a8ac82c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 270633329
Change-Id: Ia7af3ec3ee9c8b80e22a8eb55fd61d58b6c73980
2023-02-24 09:59:58 +08:00
TreeHugger Robot
53a1a9dbf7 Merge "Partially revert commit e70b98af09." into udc-dev am: 3d1d5e0b15 am: d716668597
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21546042

Change-Id: I8aedd5804fbdab372225c26cedbb812c4de5582d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 18:10:48 +00:00
TreeHugger Robot
d716668597 Merge "Partially revert commit e70b98af09." into udc-dev am: 3d1d5e0b15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21546042

Change-Id: Iff0271baa6f339ab24cb81d3d928fa71cfe14640
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 16:45:01 +00:00
TreeHugger Robot
a0af1bfb89 Merge "Partially revert commit e70b98af09." into udc-dev am: 3d1d5e0b15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21546042

Change-Id: I18305418bd4ff9003d3e8d85adc314d298ace405
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 16:44:45 +00:00
TreeHugger Robot
3d1d5e0b15 Merge "Partially revert commit e70b98af09." into udc-dev 2023-02-23 16:13:11 +00:00
Jörg Wagner
aa24e4e805 Merge "Update Mali DDK to r40 : Additional SELinux settings" 2023-02-23 13:18:05 +00:00
Richard Chang
d9d12a2df5 Merge "sepolicy: clean up tracking_denials for zram" into udc-dev am: d207b85ab3 am: d90c71c987
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21549121

Change-Id: If407d7034030e13fc19b381cb2f39c81417a2874
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 09:04:14 +00:00
Richard Chang
f27096658d Merge "sepolicy: clean up tracking_denials for zram" into udc-dev am: d207b85ab3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21549121

Change-Id: I7e57e4e321919521a1461f3011e028dc2e965143
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 08:31:06 +00:00
Richard Chang
d90c71c987 Merge "sepolicy: clean up tracking_denials for zram" into udc-dev am: d207b85ab3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21549121

Change-Id: Ifb6a1d623d7c42d7a69a24ae7f8dc815cf0d2630
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 08:28:32 +00:00
Richard Chang
d207b85ab3 Merge "sepolicy: clean up tracking_denials for zram" into udc-dev 2023-02-23 07:37:28 +00:00
Wilson Sung
e8e8037ecd Add chre policy am: fb2e376d26 am: a4ccb38798
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533834

Change-Id: I936fba49e515417b3b74a5bdd44d006b65f300dd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 06:03:37 +00:00
Wilson Sung
f6813e983b Remove camera dontaudit am: 6f141a6526 am: 640d478d5a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503759

Change-Id: I15e25c6faac9aaca4d1028367cc9740ddbf786b8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 06:03:35 +00:00