Commit graph

467 commits

Author SHA1 Message Date
Wilson Sung
cdc4acc647 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340722729
Change-Id: I8f11ea5848724f18765cca2dda91a7d916b82f72
2024-05-15 03:50:08 +00:00
kadirpili
22844d59ca rsfd: add get_prop for cbd property
Bug: 323086582

Test: flash ROM and check for rfsd sepolicy logs

Change-Id: I6f8c555614386fda784b4532a4b004d5fe857bc6
2024-04-10 05:52:54 +00:00
Wilson Sung
110a712be9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 330081782
Change-Id: I43805cda5b66b30999578b7a842fda6fe296003d
2024-03-18 03:23:52 +00:00
Treehugger Robot
48a81fa140 Merge "add dsim wakeup labels" into main 2024-02-27 13:14:49 +00:00
Peter Lin
161bbcd1e6 add dsim wakeup labels
Bug: 320693841
Bug: 321733124
test: ls sys/devices/platform/19440000.drmdsim/19440000.drmdsim.0/wakeup -Z
Change-Id: Ie99007455ef3879c8ee0aa1fa20801e4baf5e978
2024-02-17 08:11:13 +00:00
Wilson Sung
fdc9af0d88 Update error on ROM 11396046
Bug: 323471016
Test: SELinuxUncheckedDenialBootTest
Change-Id: I79953f209f474b8d71e06e197795b0d55c3ffce3
2024-02-02 08:04:40 +00:00
Wilson Sung
bbd26c9cb8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 323086582
Test: scanBugreport
Bug: 323087490
Test: scanAvcDeniedLogRightAfterReboot
Bug: 323087197
Change-Id: I99006484464f82125a63be9c26eb8d8051c57840
2024-01-31 02:58:43 +00:00
Imo Richard Umoren
770a65f4a9 Update Tracking Denial Bug Map
Removes tracking denial for twoshay from bug map

Bug: b/315104941
Test: Manually tested on HK3 DVT
Change-Id: I6cd8f390e98fc98925ed807a2ff24a33c51c75cd
2024-01-22 18:32:09 +00:00
Wilson Sung
2d8e52e176 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 320693841
Change-Id: Ia3ffe885f02a8db86d6bd024d34135fd1ce30d7b
2024-01-17 17:42:53 +00:00
Wilson Sung
148d3558f8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 319403445
Change-Id: I470afdd191741401c197ae32bfff18e9d8b90a96
2024-01-16 19:20:02 +00:00
Mahesh Kallelil
389a451f8f Merge "Remove modem_svc selinux error from denials bug_map" into main 2024-01-12 06:43:44 +00:00
Mahesh Kallelil
1d8bcd694b Remove modem_svc selinux error from denials bug_map
This property was removed and is not being used anymore. So
modem_svc will not need to read it.

Bug: 316816737
Change-Id: Iaee56d15ca69e91fe952eaa188d3aaec69edf5dc
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2024-01-11 09:48:44 -08:00
Aaron Tsai
8b02313642 Remove tracking for b/316991604.
- no need to fix, so just remove the tracking record

Bug: 316991604
Test: manual test
Change-Id: Ifa70774650d3beaed5abd57297a3372f8d33661e
2024-01-08 02:58:11 +00:00
Treehugger Robot
d8c8e6f873 Merge "face: remove tracking for 305600857" into main 2024-01-08 01:06:39 +00:00
Ilya Matyukhin
0e9173dfa2 face: remove tracking for 305600857
The policy was fixed in:
Ia8e4599e7cd44c815e88a34ee7d9229a3391b598

Bug: 305600857
Test: adb logcat | grep "avc:"
Change-Id: I831acc083c118ca35d095d040aedcd9b85cfb3a5
2024-01-04 22:23:16 +00:00
Kiyoung Kim
0d7dcca863 Remove SELinux error from b/313804706
Remove SELinux error from b/313804706 as the issue is solved now.

Bug: 313804706
Test: No selinux denial error from boot with husky-trunk_staging-userdebug build
Change-Id: I19c7fba663abac4d180b6a144f0aff5d108806f6
2024-01-02 04:30:16 +00:00
Jasmine Cha
839ddde474 audio: remove denials list for dcservice
Bug: 299553227
Test: boot to home with test build b/299553227#comment8

Change-Id: I9ee23a9aa753d891d233e337908c2091d63f3834
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-12-28 05:10:34 +00:00
Ján Sebechlebský
26b57fcdc6 Merge "Remove bug_map entry for dumpstate <-> virtual_camera" into main 2023-12-27 15:31:07 +00:00
Jan Sebechlebsky
76ea521186 Remove bug_map entry for dumpstate <-> virtual_camera
The denial was fixed in aosp/2852613.

Bug: 312894238
Test: N/A
Change-Id: I3121489729e23afa10904cb97f547e965e0c68f4
2023-12-27 14:04:36 +01:00
timtmlin
404089ca94 Remove obsolete entries
Bug: 315720601
Bug: 315720874
Test: make
Change-Id: I538c76e009c6d29c9d2cac39778decc679446906
2023-12-27 15:23:58 +08:00
Wilson Sung
5b30dbfbb3 Allow SysUI to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui_app the write access to
  wm_trace_data_file

Bug: 251513116
Fix: 288049075
Test: make sepolicy
Change-Id: Ifa5a5281c6e8c7ecedcd601fc8cc58c4be6bdc3b
2023-12-27 11:01:12 +08:00
Wilson Sung
79ba49730b Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317316633
Change-Id: I8c1b97d6c65ec06e0a13e1447538f7cebf21d962
2023-12-21 07:37:01 +00:00
Wilson Sung
f8f64b668c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316991604
Change-Id: Ic90ace8d5b6ac787030f6fd26d96f41677fcca42
2023-12-19 06:27:10 +00:00
Wilson Sung
31c017f325 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316816737
Bug: 316816642
Change-Id: Ie61999d23158c81e2acb4d23eb106cb6f61f9b88
2023-12-18 03:28:40 +00:00
Wilson Sung
259348f8f7 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315720601
Test: scanBugreport
Bug: 315720874
Bug: 315104803
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104803
Change-Id: If15ba27fec6c876984823f8bb214bb7db59f7fd2
2023-12-11 02:54:00 +00:00
Wilson Sung
2ecdf16781 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315104235
Test: scanBugreport
Bug: 315104508
Bug: 315104235
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104941
Bug: 315104235
Change-Id: Icb01366f95e6ca4001246215e487d702131b6947
2023-12-06 10:44:09 +00:00
Wilson Sung
14dda6e255 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 314054292
Test: scanBugreport
Bug: 313804706
Bug: 312894238
Change-Id: Ibf9517b585dcd8e06c62075d85dc55eb8ed7d18d
2023-11-30 07:14:04 +00:00
Wilson Sung
039124e7a4 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 312590044
Change-Id: I24e5462f111f05d051d398487a5931d808cf3002
2023-11-22 03:15:40 +00:00
Wilson Sung
d48c63c215 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 305600857
Change-Id: I4715b66f1b1c051c8d83cffefdf4f3de6e5971ef
2023-10-16 12:19:18 +08:00
Desmond Huang
c62d6871b3 Relocate common tracking denial entries
Bug: 299029620
Change-Id: I587e53a54e6bf4e3ccaa572cb35c28b4a0bc1eed
2023-09-15 03:39:48 +00:00
Desmond Huang
6f2589ec74 Remove obsolete entries
Bug: 299029620
Change-Id: Ib4782148b3e1167fd0113e5ec3eced7348a0cac2
2023-09-15 03:37:16 +00:00
Tai Kuo
1a65e5d5e4 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I2bd35a6bc942536505f62d4122f0de892f243802
2023-09-12 16:45:09 +08:00
Yunju Lee
72f7cbe324 Revert "Update SELinux error"
This reverts commit 8f56fc9709.

Reason for revert: b/291237127 is fixed

Bug: 291237127
Change-Id: I58e2636fb2ef1113a4305152948e07ed8a27a7d9
2023-07-24 15:10:01 +00:00
Wilson Sung
8f56fc9709 Update SELinux error
Test: scanBugreport
Bug: 291237127
Change-Id: Iacb47dce94f8ee2f71d382a9d0a22a6570345e2d
2023-07-17 13:50:09 +08:00
Krzysztof Kosiński
583baf021c Remove bug map entry for unknown property reads in camera HAL.
Fixed by avoiding reading a property with the name "218".

Bug: 286508419
Test: check log for denials when running the camera on zuma device.
Change-Id: I3632868187d263ed787f5abf729c4e5c10a4f4c4
2023-07-14 07:12:51 +00:00
Wilson Sung
5c63d0ef54 Move systemui seapp_contexts to private
Fix: 289480799
Bug: 288227521
Change-Id: Ifc4288125d454569a66151c3c61e000ffd3526ac
2023-07-11 15:24:10 +08:00
Wilson Sung
83671d2646 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289480799
Change-Id: I6c013d99b9b004b0a39d0b1861fa89da46bc846d
2023-07-10 14:21:22 +08:00
Wilson Sung
7a77620145 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289856761
Test: scanBugreport
Bug: 289856761
Test: scanAvcDeniedLogRightAfterReboot
Bug: 289856761
Change-Id: I4a3dcd037b1f63b8d06edab5a5ef4919ce75b8bc
2023-07-04 11:17:41 +08:00
TreeHugger Robot
043ae16d5f Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev 2023-06-21 10:47:39 +00:00
Treehugger Robot
d8b11ef832 Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev 2023-06-21 09:59:33 +00:00
Treehugger Robot
81237d3843 Merge "Update SELinux error" into udc-d1-dev 2023-06-21 08:02:49 +00:00
Wilson Sung
3657f78cb0 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-06-21 16:02:41 +08:00
Wilson Sung
0b77875c4a Supress kernel avc log before SELinux initialized
Bug: 288049349
Fix: 288049229
Change-Id: I5087a77e65ecdbaa868a7257342f5d99f424880a
2023-06-21 16:02:29 +08:00
Wilson Sung
8818dd2de5 Update SELinux error
Test: scanBugreport
Bug: 288049050
Bug: 288049522
Bug: 288049561
Bug: 288049349
Bug: 288049075
Test: scanAvcDeniedLogRightAfterReboot
Bug: 288049229
Change-Id: I939cd8981e64eadb0fa047b09162a02056ec2abf
2023-06-21 06:04:23 +00:00
Wilson Sung
f82fc11c11 Remove unused trace_marker dontaudit
Fix: 260366195
Change-Id: I7ece6549a64740c878dc92ce4b011136eb313533
2023-06-20 14:34:01 +08:00
Wilson Sung
0561b1bd1e Update SELinux error
Test: scanBugreport
Bug: 287898138
Change-Id: I297e59df3774a32305d72706ee6a160f111dee7a
2023-06-19 06:45:37 +00:00
Wilson Sung
94fd2403a7 Remove obsolete bug_map and dontaudit
Fix: 287154997
Fix: 281815537
Fix: 279680264
Fix: 264600171
Fix: 264483456
Fix: 264600171
Fix: 264600171
Fix: 274374769
Fix: 274727372
Fix: 279680070
Fix: 280706610
Fix: 279680213
Fix: 272628762
Fix: 274374992
Fix: 283725554
Fix: 274374722
Fix: 272166737
Fix: 272166787
Fix: 264483532
Fix: 264483753
Fix: 264483754
Fix: 281815594
Fix: 269964574
Fix: 269964574
Fix: 280705998
Fix: 269964558
Fix: 264599934
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 275645636
Fix: 275646003
Fix: 267714573
Fix: 272166664
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 277155496
Fix: 267260619
Fix: 261933310
Fix: 262794429
Fix: 267261048
Change-Id: I1e6da1e43b1aaa398d496cd7b1f3b6267fd39e21
2023-06-19 06:45:30 +00:00
Wilson Sung
5fb350f09f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 286508419
Test: scanBugreport
Bug: 286508419
Test: scanAvcDeniedLogRightAfterReboot
Bug: 286508419
Change-Id: I1ba324133f5f4e14c5a7d43cfea25d98bda9faa9
2023-06-14 15:30:08 +08:00
Zixuan Lan
bdee55bb57 Merge "remove 280706211 from bug map" into udc-d1-dev 2023-06-06 13:02:17 +00:00
Allen Xu
78b62802e4 Add sepolicy for ConnectivityMonitor
Bug: 264489520
Test: v2/pixel-pts/base
Change-Id: I669a538fe3d0a03422638d7d19fc62a793246f6b
2023-06-06 02:01:38 +00:00