Commit graph

543 commits

Author SHA1 Message Date
Wilson Sung
11f7df1638 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev am: 2dc224c7b9 am: b41fd56de0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532246

Change-Id: Ia5f365e32eab587d4121fc7b6a05b7913f721991
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 06:33:16 +00:00
Wilson Sung
8f6a517f41 Merge "Remove touch_context_service to avoid compile error" into udc-dev am: dfd3296451 am: 0e5858d50e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532245

Change-Id: I15971b1ec0fd8ddf4a74284a0ad2c6959914ce10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 06:31:20 +00:00
Wilson Sung
b41fd56de0 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev am: 2dc224c7b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532246

Change-Id: I82eda4ee49a78b35b91c0ad8f3e81e2b525c73dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:23:46 +00:00
Wilson Sung
0e5858d50e Merge "Remove touch_context_service to avoid compile error" into udc-dev am: dfd3296451
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532245

Change-Id: I1de205b76e27cab0040e1054568a4020562e1a57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:22:30 +00:00
Wilson Sung
e148d76c21 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev am: 2dc224c7b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532246

Change-Id: Ia9f0aaa2adb046417417119b6517d3af854d760c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:20:07 +00:00
Wilson Sung
54928d8c4e Merge "Remove touch_context_service to avoid compile error" into udc-dev am: dfd3296451
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532245

Change-Id: Ifa8f7f79c4c9c1e741913367d7128983008fd693
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:18:00 +00:00
Cody Heiner
7229048556 Allow twoshay → systemui_app binder call for zuma devices am: 9019c55645 am: baf09b5ab9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21529713

Change-Id: Id247eb47d54b270e994d7316685303e59d77fbc8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:14:01 +00:00
Wilson Sung
2dc224c7b9 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev 2023-02-22 04:49:33 +00:00
Wilson Sung
dfd3296451 Merge "Remove touch_context_service to avoid compile error" into udc-dev 2023-02-22 04:32:18 +00:00
Cody Heiner
e4c5aedc21 Allow twoshay → systemui_app binder call for zuma devices am: 9019c55645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21529713

Change-Id: I100420439bdb38eac30b6fdb11b1aa668b687227
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 04:04:01 +00:00
Cody Heiner
baf09b5ab9 Allow twoshay → systemui_app binder call for zuma devices am: 9019c55645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21529713

Change-Id: Id48b48c9e374dab6bf58b50bde30ea9f2387a56e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 04:04:00 +00:00
Wilson Sung
ca241fa76c Add hal_bootctl_default write permission to devinfo_block_device
Bug: 270236357
Change-Id: I40219dbd726ddebb277e592353bd9f0b249dd01f
2023-02-22 11:23:32 +08:00
Wilson Sung
328cbaaa41 Remove touch_context_service to avoid compile error
Bug: 270157082
Change-Id: I1d5d573ddb1d7323e7c66386928074fd06cfc484
2023-02-22 11:16:15 +08:00
Wilson Sung
e6485106b6 Add hal_bootctl related policy am: bab5b72f86 am: 393e31b676
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: I3a060c0fe0d6d4a2e2b516e443b792ce54c186d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 01:36:44 +00:00
Wilson Sung
bfab4be3c4 Enforce kernel domain am: da09093d88 am: 06d8b16f05
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503757

Change-Id: I0012c8c383b097d56cecc624f82cacdfe5deb877
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 01:36:43 +00:00
Wilson Sung
9a8e9b5918 Temporary allow kernel access same_process_hal am: 9457e5260e am: 45c7bbe3cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503756

Change-Id: Ie3d5523b61c829f6ac1c6b895bf83668ff651830
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 01:36:41 +00:00
Wilson Sung
6c52227cd4 Remove vendor_fw_file related dontaudit am: 86931fb2ea am: fa379e036e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503752

Change-Id: I178aa114c7f7cd901798eaaca661c7c31100542a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 01:27:02 +00:00
Cody Heiner
9019c55645 Allow twoshay → systemui_app binder call for zuma devices
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Test: flash P23 device with ag/21526491 along with this change
  → twoshay runs normally.

Fixes: 269981541
Change-Id: Ib3cf6f44b6288ed5c7c773e2ad670d2fd0aeee96
2023-02-21 23:58:05 +00:00
Wilson Sung
0e7828c0a5 Add hal_bootctl related policy am: bab5b72f86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: Ibcb404bff2c8d72121d4aa8e9d1ee13932d4b471
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:06:50 +00:00
Wilson Sung
722ee868e6 Enforce kernel domain am: da09093d88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503757

Change-Id: I311c9b36ff69366af3d90e9c4ee6cc64768de951
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:06:48 +00:00
Wilson Sung
0747bf2abc Temporary allow kernel access same_process_hal am: 9457e5260e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503756

Change-Id: I6f8eac71b9743b82e7cae48a53675b9db4080f01
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:06:47 +00:00
Wilson Sung
393e31b676 Add hal_bootctl related policy am: bab5b72f86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: Ic3ea1d971850ee209d9cfc61ba448ff62bbde5f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:44 +00:00
Wilson Sung
06d8b16f05 Enforce kernel domain am: da09093d88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503757

Change-Id: I1afd59c7608813cf9d3b0a24cf1425bab3a12695
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:43 +00:00
Wilson Sung
45c7bbe3cd Temporary allow kernel access same_process_hal am: 9457e5260e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503756

Change-Id: I75ddf39c43d69ea538d4a267145512ca710b22f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:42 +00:00
Wilson Sung
f5b16f4093 Remove vendor_fw_file related dontaudit am: 86931fb2ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503752

Change-Id: I88027931977acd7f0d6df4e5c6a43f427fd54ef6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:01:45 +00:00
Wilson Sung
fa379e036e Remove vendor_fw_file related dontaudit am: 86931fb2ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503752

Change-Id: I7a2f5722366ee38887ecdd5d5a43db0bfd8ccd26
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:00:36 +00:00
Wilson Sung
bab5b72f86 Add hal_bootctl related policy
Bug: 260522436
Bug: 264489609
Bug: 264483787
Change-Id: Iaa22899bb21ff41c1fa259830e5f49623ff8429b
2023-02-21 19:59:04 +08:00
Wilson Sung
da09093d88 Enforce kernel domain
Bug: 264490052
Test: boot-to-home
Change-Id: I383b689b5c26c08d66307b677e36b28f2ab6f7dd
2023-02-21 19:29:15 +08:00
Wilson Sung
9457e5260e Temporary allow kernel access same_process_hal
Add the access to unblock user build boot-to-home

Bug: 260522245
Change-Id: I98f77b2de4961120be9c6073afc18e12e2637e81
2023-02-21 19:28:25 +08:00
Wilson Sung
86931fb2ea Remove vendor_fw_file related dontaudit
Bug: 262794429
Bug: 261933155
Change-Id: I62b4037835a462b46b82df4059cdebf679c295b2
2023-02-21 15:00:58 +08:00
leochuang
407036361c Update SELinux error am: 6747816919 am: 62d244482e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504315

Change-Id: Ie93d259107be8337eae48d9e97ea0af5138679d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 05:44:53 +00:00
leochuang
62d244482e Update SELinux error am: 6747816919
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504315

Change-Id: I7c2a39a18128af2c47bef09340738028fea686cc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 04:32:47 +00:00
leochuang
f1eebd6ddf Update SELinux error am: 6747816919
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504315

Change-Id: I3374070e0d2b6c30addfd6f8e33f44be0fbbcb64
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 04:30:51 +00:00
leochuang
6747816919 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269964558
Bug: 267714573
Bug: 269964574
Bug: 269812912
Change-Id: I61a274c01c6921b9b7e3df8814cf83f43bba342a
2023-02-21 02:16:40 +00:00
Wilson Sung
5b57683191 [automerger skipped] Revert "Revert "Update error on ROM 9624328"" am: e70b98af09 am: 19d86dcfc0 -s ours
am skip reason: Merged-In I25b0f417af3e741719f959aed79e7e330687e117 with SHA-1 e70b98af09 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I24ac53854687eca475273299e30dd1628c35609d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:21:15 +00:00
Ken Yang
76dbfec0be [automerger skipped] WLC: cleanup the unused hal_wlc policies am: 58a6a1e772 am: 024703040d -s ours
am skip reason: Merged-In I90b9e442082b8e03e76ce63aaee56e5882933449 with SHA-1 58a6a1e772 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: I8599f729c13302272f2e255261b09a7ba03620ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:50 +00:00
Ken Yang
d07cc77fe5 [automerger skipped] WLC: cleanup WLC trakcing_denials am: 670b22c2c7 am: c43be3da60 -s ours
am skip reason: Merged-In I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51 with SHA-1 670b22c2c7 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Ie7e75c3f4ec4fae2986b5cc9ee6b1f7fcdedd50a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:49 +00:00
Kah Xuan Lim
218fd53e24 [automerger skipped] modem_svc_sit: grant modem property access am: 4e270f1615 am: c7adfd1151 -s ours
am skip reason: Merged-In Id5e66d94eb14c6979d3b93d54fd73634444cdea1 with SHA-1 4e270f1615 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: I22ef0f4a48a327abd4428f15c7dd1618b1ced577
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:38 +00:00
Wilson Sung
10d51509d6 [automerger skipped] allow bootctl to read devinfo am: 931ea0d342 am: 3bf76884bb -s ours
am skip reason: Merged-In I41d2763ffe40d7465a11cc86612fed9f92905eff with SHA-1 931ea0d342 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: Ic1852041e0d578db96cf48c0e5e0a108a5ac1a3a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:11 +00:00
Wilson Sung
c0f75d7921 [automerger skipped] Remove proc_vendor_sched obsolete denials am: 676c7a674c am: d952aae49a -s ours
am skip reason: Merged-In I308df50eefe611a0a87afc9a21387465487cc6ea with SHA-1 676c7a674c is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: I888010b9169a85259c48cfc8cefe5a8c9ad96547
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:09 +00:00
Nicole Lee
7ee114dd54 [automerger skipped] logger_app: don't audit default_prop and fix errors am: 7706be6c71 am: cf40697979 -s ours
am skip reason: Merged-In I8999372d243286586eb53602e167fa111d39a00f with SHA-1 7706be6c71 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I0e43c6f77ce597138d47fad193dc14d2d29da7cb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 00:20:08 +00:00
Wilson Sung
19d86dcfc0 Revert "Revert "Update error on ROM 9624328"" am: e70b98af09
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I99c6e1a5473691fbca41957b934b270f8493e2cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:59 +00:00
Ken Yang
024703040d WLC: cleanup the unused hal_wlc policies am: 58a6a1e772
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: I8aafb32f9a5c0bcd8f74e382a2f893fa71433b7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:41 +00:00
Ken Yang
c43be3da60 WLC: cleanup WLC trakcing_denials am: 670b22c2c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Iff19425d747d5c03e4e10ae284523ef659b29200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:35 +00:00
Kah Xuan Lim
c7adfd1151 modem_svc_sit: grant modem property access am: 4e270f1615
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: Iad92808f73b22345e16d7ca602e57d25f01d42a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:57 +00:00
Wilson Sung
3bf76884bb allow bootctl to read devinfo am: 931ea0d342
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: Iba6993ef61237c11fa1a1c2eb493e339f32f16f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:00 +00:00
Wilson Sung
d952aae49a Remove proc_vendor_sched obsolete denials am: 676c7a674c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: Ib6e4ec093a81dd47ce32d3a110cd525fd9a5afb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:58 +00:00
Nicole Lee
cf40697979 logger_app: don't audit default_prop and fix errors am: 7706be6c71
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I10e07e96719038edaa420519e4e705cff9e9da49
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:55 +00:00
Wilson Sung
7ebe356b25 [automerger skipped] Revert "Revert "Update error on ROM 9624328"" am: e70b98af09 -s ours
am skip reason: Merged-In I25b0f417af3e741719f959aed79e7e330687e117 with SHA-1 47570e0ed6 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I648005a9da414a45147f1b96a1b9713c6ac7701a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:44 +00:00
Ken Yang
09c84f9c05 [automerger skipped] WLC: cleanup the unused hal_wlc policies am: 58a6a1e772 -s ours
am skip reason: Merged-In I90b9e442082b8e03e76ce63aaee56e5882933449 with SHA-1 6f9844d137 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: If4a61aec985ac1afae878b8c55b6d7f4b0fce2d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:33 +00:00