Commit graph

1072 commits

Author SHA1 Message Date
Treehugger Robot
e2fea4a565 Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4 am: bbfbf90c71
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: Ic50fe5b40461df6fac51b5a0a97ec479792c7cfa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 10:38:32 +00:00
Treehugger Robot
28ba80bbfa Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797 am: 222413abe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: Icee56690788d7ef2b5c354bb0903e21d568e8f96
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 10:34:32 +00:00
Tom Huang
27de572652 Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f am: a903ddebb1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: I9a920c193d1bfbf9c91221a6ea868208c4e88c66
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 10:33:00 +00:00
Tom Huang
34dd9a81d9 Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f am: 5c0053c5ec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: Ia744b032d92be1de1b00ca1787fa446bba8606c7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 10:29:49 +00:00
Treehugger Robot
6b61366417 Merge "Remove obsolete tracking entry" into udc-d1-dev am: 11ea9b76d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22880900

Change-Id: I73a0f09e483cb91805b3530ab513ee39529f4146
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:40:27 +00:00
Treehugger Robot
03f88f77fc Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: Ib41b87547cb4610fa30cbb49a79bf72e9944b7e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:34:22 +00:00
Treehugger Robot
dc5aac4409 Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: Ia489a4cd3d15e82f6d506bacedcadb514367eb14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:07:40 +00:00
Tom Huang
5c0053c5ec Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: I4f083a33f9e8a5af927496df1189d1085f19e616
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:07:31 +00:00
Treehugger Robot
8c3cc91d38 Merge "Remove obsolete tracking entry" into udc-d1-dev am: 11ea9b76d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22880900

Change-Id: Iea5e3f6a0f41992b26dd08419d2721278954adb2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 08:34:44 +00:00
Treehugger Robot
bbfbf90c71 Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: I9c4a6ef2c0721d66241e5e5425b1cf4e44d34a26
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 08:33:43 +00:00
Treehugger Robot
222413abe5 Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: I03cffa3b2f0ca4daef371d6316e06d9e3a9fce61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 08:32:15 +00:00
Tom Huang
a903ddebb1 Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: If5e1ad9871cf5612f6ff1ef78079c3fb95fcaf46
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 08:32:02 +00:00
Treehugger Robot
11ea9b76d6 Merge "Remove obsolete tracking entry" into udc-d1-dev 2023-05-02 07:12:52 +00:00
Treehugger Robot
470eda92e4 Merge "Enforce fastbootd" into udc-d1-dev 2023-05-02 04:54:37 +00:00
Treehugger Robot
5c70865797 Merge "sepolicy: ignore avc denial" into udc-d1-dev 2023-05-02 04:36:22 +00:00
Tom Huang
dd5df5791f Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev 2023-05-02 04:07:15 +00:00
Wilson Sung
8080b95d06 Enforce fastbootd
Fix: 264489957
Test: flash and no related avc error
Change-Id: Ibf616a98e9341310e18db6dda27d86adbf24deac
2023-05-02 11:42:59 +08:00
horngchuang
a6d7203408 Add sepolicy permission for new svarog sensor
Bug: 278473644
Test: Build and test for sensor denials
Change-Id: I2816a2ada49d4369b975ac22693994cff5cd6aec
2023-05-01 15:34:33 +00:00
Krzysztof Kosiński
e5d28c14af Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev am: 9f7dec1023 am: fc8dcdd504
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22908419

Change-Id: I171cbff976edabed3891713dba286969db2da713
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 23:47:51 +00:00
Krzysztof Kosiński
de77c8b0ac Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev am: 9f7dec1023 am: bc2fb0e761
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22908419

Change-Id: I4f8967f5656c83147282f036bd83e23eddccc363
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 23:42:25 +00:00
Krzysztof Kosiński
fc8dcdd504 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev am: 9f7dec1023
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22908419

Change-Id: I79336102f4c82c4971cddbaf5839becf9c8bc818
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 23:02:10 +00:00
Krzysztof Kosiński
bc2fb0e761 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev am: 9f7dec1023
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22908419

Change-Id: I871183bddb6cca48ce185235fcab8a8509959a48
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 23:00:27 +00:00
Krzysztof Kosiński
9f7dec1023 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev 2023-04-28 22:18:37 +00:00
Dan Moore
4a0259ff34 Allow sensor HAL access to thermal HAL
The FIR temperature sensor must report an estimate of window temperature
so that the BTS SaMD can determine if the boundary condition between the
sensor and window is within accuracy specification.

Test: logcat previously reported access denied to thermal HAL. Access is
now granted and the Twindow elements are accessible.

Bug: 276738070
Change-Id: I72846053840e36ba8d3d59df9ba580c6c416e867
2023-04-28 12:13:32 -04:00
martinwu
149ac2a92e [TSV2] Add sepolicy for dumpstate to zip tcpdump into bugreport am: 09aaf3dfbc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22899260

Change-Id: I0a894186a7b618d703fb4aeefcac5e62d7e472f6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 07:16:37 +00:00
Ted Wang
8831352474 Add sepolicy for aidl bt extension hal
Bug: 274906319
Test: build pass and manual test
Change-Id: Id54796fec22e790a197255f2db4ba23b4a58212d
2023-04-28 04:48:33 +00:00
Kamal Shafi
47f407fa8d Correct sepolicy permission for new UW cam EEPROM
change imentet camera sensor EEPROM naming to its codename.

Bug: 279547216
Test: build pass
Change-Id: Ib831119318a0b4467f81f93c009a28831cebac25
2023-04-28 02:56:30 +00:00
Krzysztof Kosiński
5b2134d5c5 Enforce sepolicy for Google Camera App.
Added missing statement allowing GXP firmware access.

Bug: 264489778
Test: GCA smoke test in setenforce mode.
Change-Id: Ied2f675a2e11f7aebcf4e1e6ac49fc2e39dd2ecf
2023-04-27 19:53:25 +00:00
Chungkai Mei
fdd0ef451e sepolicy: ignore avc denial
ignore avc denial since it is debugfs

Bug: 271931921
Test: pass boot health check extra test https://android-build.googleplex.com/builds/abtd/run/L49300000960255489
Change-Id: Iceee4d347b5e90bce6d16054c6ee0c8091652a9b
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-04-27 14:24:40 +00:00
martinwu
09aaf3dfbc [TSV2] Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I45c894fa9378a7878bc853f7723162ebd6141115
2023-04-27 13:47:34 +00:00
Bruno BELANYI
9c4ffd3dd2 Merge "Add ArmNN config sysprops SELinux rules" into udc-d1-dev am: 83087bd818
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22786211

Change-Id: I08085e0fb372ded139063aeedb3b7dd38e1da2c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:36:53 +00:00
Bruno BELANYI
83087bd818 Merge "Add ArmNN config sysprops SELinux rules" into udc-d1-dev 2023-04-27 08:06:48 +00:00
Carol Cheng
fd882830cc Merge "Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"" into udc-d1-dev am: bb1f0f25bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22891380

Change-Id: Ie0a44ba0d36b95a842a28b47d5a62f78cf30f6e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:11:50 +00:00
Carol Cheng
bb1f0f25bb Merge "Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"" into udc-d1-dev 2023-04-27 06:36:48 +00:00
Martin Wu
4e2023c263 Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I795de89a17c5ccee702fa3a59af03d48d89fbaf2
2023-04-27 02:21:00 +00:00
Andrew Chant
ffa498bd79 Merge "Use tof sensor codenames" into udc-d1-dev am: 6641141f91
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22307463

Change-Id: Ic8acdfb36ad3945c93bf336b91ef9cd2a69a8bd8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:20:37 +00:00
Andrew Chant
6641141f91 Merge "Use tof sensor codenames" into udc-d1-dev 2023-04-27 02:07:29 +00:00
Treehugger Robot
8a3c78df60 Merge "Add sepolicy for dumpstate to zip tcpdump into bugreport" into udc-d1-dev am: fe27339606
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22838381

Change-Id: I69f575b3857d391561c1f214833e28d3bee2eb30
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 01:56:24 +00:00
Kamal Shafi
fedde4710a Add sepolicy permission for new UW camera am: eb22b7d648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22880541

Change-Id: Icf6c3862d91bd7312bc822772314c2816b16f596
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 01:55:40 +00:00
Treehugger Robot
fe27339606 Merge "Add sepolicy for dumpstate to zip tcpdump into bugreport" into udc-d1-dev 2023-04-27 01:43:58 +00:00
martinwu
da1f9ffa79 Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I04ca96860c78baf24afd7deecff7dd4d470d9539
2023-04-26 14:17:56 +00:00
Kamal Shafi
eb22b7d648 Add sepolicy permission for new UW camera
sepolicy including imentet camera sensor and gt24p64e EEPROM

Bug: 277988592
Bug: 279547216
Test: build pass
Change-Id: I01e2bc558eba7cf03c11818d9c806e6053808fd1
2023-04-26 11:32:33 +00:00
Wilson Sung
3107cd8aa5 Update SELinux error am: 74494540d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22873618

Change-Id: I624f57e7815c7617e8956de1f5144c3e167637c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 09:51:05 +00:00
kuanyuhuang
477d58d695 Add hidraw device sepolicy for headtracking
Test: make and incoming HID data from Pixel Buds Pro
Bug: 276163506
Change-Id: I10833e215962ad007ad32a0d713e9b37ae888fdb
2023-04-26 09:20:11 +00:00
Salmax Chang
5ddf0079c6 Remove obsolete tracking entry
Bug: 264489567
Bug: 261651131
Change-Id: Ibf1116ea7b393f3c1e6eec0794e492b5dc2fd1ad
2023-04-26 17:15:36 +08:00
Bruno BELANYI
61df5feff7 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:aac79fd4d9bec6517b2932cfca1e1c84b7711cc8)
Merged-In: I77b29468258520265e5f660452794aff068ca07d
Change-Id: I77b29468258520265e5f660452794aff068ca07d
2023-04-26 08:12:29 +00:00
Wilson Sung
74494540d6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 279680070
Test: scanBugreport
Bug: 279680070
Bug: 279680213
Bug: 279680264
Test: scanAvcDeniedLogRightAfterReboot
Bug: 279680070
Change-Id: I0a5aadfed90377aeee60a15aaab212c7709d091a
2023-04-26 15:10:44 +08:00
Treehugger Robot
74272bfe60 Merge "Remove 'hal_neuralnetworks_armnn' '/data' access exception" into udc-d1-dev am: 8ebffeef84
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22786212

Change-Id: If5fe6067ec2fcea498366aeb59feb5ab9f403e26
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 05:13:10 +00:00
Treehugger Robot
381f2fb49e Merge "Remove hal_power_default bug from bug_map" into udc-d1-dev am: 8f8f545307
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22873619

Change-Id: I592a54f761941a31cbbe69ba18e21bc2dc1f0a37
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 05:12:34 +00:00
Treehugger Robot
f69eaca047 Merge "Remove old debug map entries." into udc-d1-dev am: 471a0c621a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874902

Change-Id: I9b1d926ebd6a33269d3c2cf754eebf638cab7aec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 05:11:59 +00:00