Commit graph

578 commits

Author SHA1 Message Date
TreeHugger Robot
15a45ce32f Merge "Enforce pixel_stats" into udc-d1-dev 2023-03-14 07:18:22 +00:00
Wilson Sung
a37fd0cd9d Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272628396
Test: scanBugreport
Bug: 272628762
Test: scanAvcDeniedLogRightAfterReboot
Bug: 272628396
Bug: 267714573
Change-Id: Ice1b62f4092a00af2f9112efa84859465fa5061d
2023-03-14 13:46:46 +08:00
Wilson Sung
9f8b8971db Merge "Enforce system ui app" into udc-d1-dev 2023-03-14 05:44:27 +00:00
Wilson Sung
95eea9a04b Enforce pixel_stats
Fix: 264483357
Fix: 264483319
Fix: 264483568
Fix: 264489783
Test: boot-to-home and no pixel_stats avc error
Change-Id: I0b68fa3853c65056d7da78a436a3d38888af8f19
2023-03-14 13:40:49 +08:00
TreeHugger Robot
d5554312e8 Merge "label systemui sub apps" into udc-dev am: 27c8c4c1e0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21988006

Change-Id: I61bb2409787130b12d75e539f369bb73a5690ea6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 04:48:12 +00:00
Enzo Liao
40dce15c10 Merge "SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma." into udc-dev am: 6eb86755a6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21947242

Change-Id: Ia65c61152f4631dc9ffeb6675d05dbc562781a40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 04:47:21 +00:00
TreeHugger Robot
27c8c4c1e0 Merge "label systemui sub apps" into udc-dev 2023-03-14 04:29:20 +00:00
Enzo Liao
6eb86755a6 Merge "SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma." into udc-dev 2023-03-14 04:04:41 +00:00
Sayanna Chandula
8f8acbb026 Merge "thermal: remove tracking denials for hal_thermal" into udc-d1-dev 2023-03-14 03:51:09 +00:00
Adam Shih
4e5621a2e5 label systemui sub apps
Bug: 270518075
Test: screenshot > press sharing button
Change-Id: I10c59809afc3e897775e7cfccde9e2432bb78163
2023-03-14 11:07:12 +08:00
Sayanna Chandula
d610423377 thermal: remove tracking denials for hal_thermal
Bug: 264490033
Test: Test thermal service after flashing the build

Change-Id: Ifb0fa5272a89527d8cba4a2292737f3af941f95a
Signed-off-by: Sayanna Chandula <sayanna@google.com>
2023-03-14 02:27:37 +00:00
TreeHugger Robot
fcffe3c099 Merge "Enforce hal_sensors_default" into udc-d1-dev 2023-03-14 02:25:33 +00:00
TreeHugger Robot
25c992012f Merge "enforce hal_dumpstate_default" into udc-dev am: 3906f53197
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21982724

Change-Id: I3249dd6a9df32bfa09f83f11e76755ae9d74873c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 01:55:34 +00:00
TreeHugger Robot
3906f53197 Merge "enforce hal_dumpstate_default" into udc-dev 2023-03-14 01:10:42 +00:00
TreeHugger Robot
c86e5b15e4 Merge "Enforce chre" into udc-d1-dev 2023-03-14 01:09:29 +00:00
Ziyi Cui
1682d9c973 Merge "zuma-sepolicy: pixelstats: enable pixelstats access to perf-metrics" into udc-d1-dev 2023-03-13 17:44:01 +00:00
Wilson Sung
1371c7c6a9 Enforce chre
Fix: 264489633
Change-Id: Ib4c7a217dce35f1d923a3ba5c012b11508b19c5b
2023-03-13 08:10:57 +00:00
Adam Shih
7356735963 enforce dumpstate am: ea9c12efb3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21982725

Change-Id: I6853bb4cd85f1651e32e15e01f1c4abc9384b505
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 08:00:07 +00:00
Wilson Sung
ba953cdb9a Enforce system ui app
Bug: 264266705
Change-Id: Ice811ba94f065a56db47b390847b4f15798a50f5
2023-03-13 14:56:42 +08:00
Wilson Sung
ffeed9d629 Enforce hal_sensors_default
Bug: 264489637
Change-Id: I6f0384a0bf4ae5c3ac6d1ebe5b865ea43b86c3c2
2023-03-13 14:54:20 +08:00
Adam Shih
ea9c12efb3 enforce dumpstate
Bug: 264489270
Test: adb bugreport
Change-Id: Idb3c29ff306b825dba9422dca5f1ec1a1d65d8f4
2023-03-13 06:26:34 +00:00
TreeHugger Robot
eecb5380e3 Merge "[SELinux] Fix hal_uwb_default dev access errors" into udc-d1-dev 2023-03-13 06:17:37 +00:00
Adam Shih
46d5345bc9 enforce hal_dumpstate_default
Bug: 266035810
Test: adb bugreport
Change-Id: Iec0d9b7d5d9327dd7ca96ab7f4c1a26c3fde6a3e
2023-03-13 14:10:45 +08:00
TreeHugger Robot
908501be50 Merge "enforce incidentd" into udc-dev am: 5488c59d9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21981862

Change-Id: Ic5339c6d2f2948e8c60f314a3fde1c39a67134e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:56:31 +00:00
TreeHugger Robot
5488c59d9a Merge "enforce incidentd" into udc-dev 2023-03-13 05:40:12 +00:00
Jasmine Cha
777ee2e945 audio: move set property in vendor_init to gs-common am: 684d922d59
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21974564

Change-Id: I7df21f6988b4a2546eb3099b9b60c7828666e3b6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:38:09 +00:00
Rex Lin
e7616e3934 [SELinux] Fix hal_uwb_default dev access errors
Allow hal_uwb_default to access /dev/uci

Bug: 263048994
Test: http://ab/I86600010139623509
Change-Id: I6324044822f74d1f0d14cc9c6d057dce0dfcc9ee
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-03-13 05:16:30 +00:00
Wilson Sung
6b9e3f74b6 Merge changes I9868bdfd,I1085decf into udc-d1-dev
* changes:
  Enforce insmod-sh
  Allow insmod-sh lockdown in userdebug
2023-03-13 04:26:34 +00:00
Adam Shih
bbbc3e3926 enforce incidentd
Bug: 264490034
Bug: 259302023
Test: adb bugreport
Change-Id: Ie77eded2b6bdd5bd993e500cf8d8d481e5fe7a57
2023-03-13 11:52:29 +08:00
Jasmine Cha
684d922d59 audio: move set property in vendor_init to gs-common
Bug: 259161622
Test: build pass

Change-Id: I4232a7e33c75c2dc7475e0888da7019d59de52d1
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-13 10:53:58 +08:00
Ziyi Cui
3e6ba1f4e3 zuma-sepolicy: pixelstats: enable pixelstats access to perf-metrics
enable pixelstats access to sysfs path
Bug: 246799997
Test: Verified the existence of atom and correctness of atom stats
Change-Id: I874f7ff06b91b028cd6bbffd682429763c264d9f
Signed-off-by: Ziyi Cui <ziyic@google.com>
2023-03-12 23:02:24 +00:00
Jeremy DeHaan
83126173b7 Merge "Allow HWC to access panel model" into udc-dev am: 3a29cc604b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21776404

Change-Id: I4c16dc7e470a1f07fafd29996502bdba66dd88ba
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 18:18:27 +00:00
Jeremy DeHaan
3a29cc604b Merge "Allow HWC to access panel model" into udc-dev 2023-03-10 17:48:34 +00:00
Wilson Sung
0d8ede8308 Enforce insmod-sh
Fix: 264490091
Test: Boot-to-home without insmod-sh avc error
Change-Id: I9868bdfd8fad7ac37c8d1104fb1fab10a7e8f79a
2023-03-10 16:25:24 +08:00
Wilson Sung
eae6bfb835 Allow insmod-sh lockdown in userdebug
Bug: 272166723
Change-Id: I1085decf2a00597992a95996b1a2875be08ba1f1
2023-03-10 16:23:39 +08:00
Enzo Liao
3f905ee1d0 SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma.
It needs to access a file pushed by hosts of test suites (details: http://go/pd-client-for-lab#heading=h.wtp07hbqvwgx)

Bug: 234359369
Design: http://go/pd-client-for-lab
Test: manual (http://b/271555983#comment3)
Change-Id: Id97d9c2d07197478ab8d6fcd1e9370dc794ff7d1
2023-03-10 15:37:15 +08:00
Wilson Sung
028c3dd417 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272628174
Change-Id: Ief58f990c70fc7a9a6fa1f18ce22c1c5847acaf9
2023-03-10 10:56:44 +08:00
Jasmine Cha
3e639ffa42 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: Ic05e1165722a12b41d51f4339ed817383412219f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:19:45 +00:00
Jasmine Cha
6431ec8cfa Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Wilson Sung
aa90037844 Add insmod-sh policy
Fix: 260366066
Change-Id: I0874c1f476b47a9ad3cee344986404958c96fd25
2023-03-10 02:04:36 +08:00
Darren Hsu
055b52e584 Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: I2e1cde774f763e3f30b0e50484824483d5319c08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 07:54:54 +00:00
Darren Hsu
3867f2f21f Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev 2023-03-09 07:20:30 +00:00
Wilson Sung
2492786d15 Merge "Add system_ui required policy" into udc-d1-dev 2023-03-09 07:05:32 +00:00
Wilson Sung
8c535e410a Add system_ui required policy
Bug: 264266705
Bug: 268572197
Bug: 269813282
Change-Id: I8d782a5879dd531c29328517f67245913808ae93
2023-03-09 12:57:39 +08:00
KRIS CHEN
4309d80318 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I232a8e1d378731c0a42d42b9450fee002efd15bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:21:05 +00:00
KRIS CHEN
92c67c8422 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev 2023-03-09 03:53:46 +00:00
Jasmine Cha
d4de162a4f audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: I5f537f18b33c84f30dae349880f8d00a22883b0b
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:09:29 +08:00
Darren Hsu
f3e948a640 sepolicy: label more paths for sysfs_odpm
Bug: 272164439
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: Iec1be5189d21ff6b2bdfe5056b526f01dc2b35e4
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-09 08:35:42 +08:00
Kris Chen
cc2458e456 Allow fingerprint hal to access display hibernation node
Fix the following avc denial:
avc: denied { write } for name="hibernation" dev="sysfs" ino=75339
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs:s0
tclass=file permissive=0

Bug: 256947811
Bug: 251239489
Bug: 267271482
Test: Perform udfps osc compensation.
Change-Id: I2cfb1353770734a19e7fcf1a10eb2fc7bf84a4f5
2023-03-08 09:10:24 +00:00
Chih Wei Chang
455363e7c0 Merge "Revert "Add system_ui required policy"" into udc-d1-dev 2023-03-08 08:17:46 +00:00