Commit graph

2235 commits

Author SHA1 Message Date
Inseob Kim
f05143f43c Revert "Label dtbo partition as dtbo_block_device"
This reverts commit 3773ca269e.

Reason for revert: b/319035582

Bug: 319035582
Test: boot
Change-Id: I3c2a5b5bc871aa506396c12d6e1fa036858c1273
2024-01-10 17:02:14 +09:00
Ken Yang
137c2ebd5a selinux: label wakeup for BMS I2C 0x36, 0x69
Bug: 319035561
Change-Id: Ib57dba71691f70b75fbae23208125fa750b32dc1
Signed-off-by: Ken Yang <yangken@google.com>
2024-01-10 06:14:37 +00:00
Lei Ju
52beafc4c4 [zuma] Use common settings for Contexthub HAL
Test: compilation
Bug: 248615564
Change-Id: I6691b23af6e532584f4dee9618c264b20b8873c0
2024-01-07 20:10:59 -08:00
Aaron Tsai
8b02313642 Remove tracking for b/316991604.
- no need to fix, so just remove the tracking record

Bug: 316991604
Test: manual test
Change-Id: Ifa70774650d3beaed5abd57297a3372f8d33661e
2024-01-08 02:58:11 +00:00
Treehugger Robot
d8c8e6f873 Merge "face: remove tracking for 305600857" into main 2024-01-08 01:06:39 +00:00
Nicole Lee
a03af7a36c Allows modem_svc to read the logging related properties am: 93020c0564 am: 8749626448
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I7934a5ed2936e9f42ed022fa1853974cab5019a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 01:00:09 +00:00
Nicole Lee
8749626448 Allows modem_svc to read the logging related properties am: 93020c0564
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I0f55efc6a18dd8e863debeaf47e32c67fbfdd6c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 00:29:58 +00:00
Nicole Lee
93020c0564 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
(cherry picked from commit 728e6baa64)
2024-01-05 04:40:14 +00:00
Ilya Matyukhin
0e9173dfa2 face: remove tracking for 305600857
The policy was fixed in:
Ia8e4599e7cd44c815e88a34ee7d9229a3391b598

Bug: 305600857
Test: adb logcat | grep "avc:"
Change-Id: I831acc083c118ca35d095d040aedcd9b85cfb3a5
2024-01-04 22:23:16 +00:00
Treehugger Robot
b808c32b7d Merge "Allows modem_svc to read the logging related properties" into main 2024-01-04 10:09:18 +00:00
Nicole Lee
728e6baa64 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
2024-01-02 08:50:36 +00:00
Kiyoung Kim
0d7dcca863 Remove SELinux error from b/313804706
Remove SELinux error from b/313804706 as the issue is solved now.

Bug: 313804706
Test: No selinux denial error from boot with husky-trunk_staging-userdebug build
Change-Id: I19c7fba663abac4d180b6a144f0aff5d108806f6
2024-01-02 04:30:16 +00:00
Jasmine Cha
839ddde474 audio: remove denials list for dcservice
Bug: 299553227
Test: boot to home with test build b/299553227#comment8

Change-Id: I9ee23a9aa753d891d233e337908c2091d63f3834
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-12-28 05:10:34 +00:00
Lei Ju
5a4795ccd7 Merge "[zuma] Update chre sepolicy for socket connection" into main 2023-12-28 03:50:00 +00:00
Ján Sebechlebský
26b57fcdc6 Merge "Remove bug_map entry for dumpstate <-> virtual_camera" into main 2023-12-27 15:31:07 +00:00
Jan Sebechlebsky
76ea521186 Remove bug_map entry for dumpstate <-> virtual_camera
The denial was fixed in aosp/2852613.

Bug: 312894238
Test: N/A
Change-Id: I3121489729e23afa10904cb97f547e965e0c68f4
2023-12-27 14:04:36 +01:00
Lei Ju
8587126f45 [zuma] Update chre sepolicy for socket connection
With multiclient HAL, the socket server domain changes from chre to
hal_contexthub_default.

Bug: 248615564
Test: updated the sepolicies and observed that avc violation logs
      disappears.
Change-Id: I4b2d27b436c9d81bd0d0cdc5b3c1540884c37fec
2023-12-27 00:02:57 -08:00
timtmlin
404089ca94 Remove obsolete entries
Bug: 315720601
Bug: 315720874
Test: make
Change-Id: I538c76e009c6d29c9d2cac39778decc679446906
2023-12-27 15:23:58 +08:00
Wilson Sung
5b30dbfbb3 Allow SysUI to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui_app the write access to
  wm_trace_data_file

Bug: 251513116
Fix: 288049075
Test: make sepolicy
Change-Id: Ifa5a5281c6e8c7ecedcd601fc8cc58c4be6bdc3b
2023-12-27 11:01:12 +08:00
Shiyong Li
569134db41 Merge "display: support primary display preferred mode property" into main 2023-12-22 19:54:46 +00:00
Chi Zhang
f965c0b222 Merge "Allow GRIL to get power stats." into main 2023-12-22 19:29:06 +00:00
Kadi Narmamatov
09c85a0567 Merge "rfsd: add new property to sepolicy" into main 2023-12-22 09:10:49 +00:00
Shiyong Li
d26ab660b8 display: support primary display preferred mode property
Bug: 315895938
Test: check default mode after factory reset
Change-Id: Ia5a4c12537d50faf54ed5ea82d24e52a623c34e3
Signed-off-by: Shiyong Li <shiyongli@google.com>
2023-12-21 20:12:45 +00:00
Wilson Sung
79ba49730b Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317316633
Change-Id: I8c1b97d6c65ec06e0a13e1447538f7cebf21d962
2023-12-21 07:37:01 +00:00
kadirpili
5c28db1f6b rfsd: add new property to sepolicy
Bug: 307481296
Change-Id: Icd287f863fd6d309297ce984f4ce387fb5d3ae24
2023-12-20 07:27:32 +00:00
Chi Zhang
a2e8969139 Allow GRIL to get power stats.
SELinux : avc:  denied  { find } for pid=3147 uid=10219 name=android.hardware.power.stats.IPowerStats/default scontext=u:r:grilservice_app:s0:c219,c256,c512,c768 tcontext=u:object_r:hal_power_stats_service:s0 tclass=service_manager permissive=1

Bug: 286187143
Test: build and boot
Change-Id: I6df25e78ba8fa8efaa7f51aed8e981ac382dcd29
2023-12-19 12:22:08 -08:00
Wilson Sung
f8f64b668c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316991604
Change-Id: Ic90ace8d5b6ac787030f6fd26d96f41677fcca42
2023-12-19 06:27:10 +00:00
Wilson Sung
31c017f325 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316816737
Bug: 316816642
Change-Id: Ie61999d23158c81e2acb4d23eb106cb6f61f9b88
2023-12-18 03:28:40 +00:00
Imo Richard Umoren
b3e48816fa Twoshay: Add SELinux Permissions for CHRE [Zuma]
Adds connection and write permissions for chre socket to SELinux policy.
Used for the Wallaby nanoapp.

Bug: b/315347346
Bug: b/314721681
Test: Manually tested on SB3 Proto 1.0
Change-Id: I4a01be73d76a577d8da07c36276349525c0fda68
2023-12-12 17:23:35 +00:00
Wilson Sung
259348f8f7 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315720601
Test: scanBugreport
Bug: 315720874
Bug: 315104803
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104803
Change-Id: If15ba27fec6c876984823f8bb214bb7db59f7fd2
2023-12-11 02:54:00 +00:00
Wilson Sung
2ecdf16781 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315104235
Test: scanBugreport
Bug: 315104508
Bug: 315104235
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104941
Bug: 315104235
Change-Id: Icb01366f95e6ca4001246215e487d702131b6947
2023-12-06 10:44:09 +00:00
David Drysdale
7beccb101a Merge "Add Secretkeeper HAL" into main 2023-12-06 10:21:03 +00:00
David Drysdale
98448f5628 Add Secretkeeper HAL
Test: VtsAidlAuthGraphSessionTest
Bug: 306364873
Change-Id: I57de11a4c08476979e9283914a552a90254ee3fb
2023-12-05 10:39:26 +00:00
Ray Chi
7e755bb143 Add eusb_repeater to vendor_usb_debugfs context
Bug: 305145476
Test: adb bugreport
Change-Id: I8fe6eebb43ed80de486d93882879512d0918acee
2023-12-05 16:38:16 +08:00
Jason Chiu
47c545c8b0 zuma: move sepolicy related to bootctrl hal to gs-common
Bug: 265063384
Change-Id: Ic99547173f6eade30bce2d60051163336b27ca3b
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-12-05 00:45:55 +08:00
Wilson Sung
7e977d05b5 Merge "Update SELinux error" into main 2023-12-04 02:33:03 +00:00
Daniel Norman
5f8ba1c0d3 Removes duplicate hidraw_device type definition. am: f219d38925 am: f2e746b644
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25533485

Change-Id: Id71f76f518ee2dd74cb7dc4ce0cfc3253853fb1b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-02 01:52:12 +00:00
Daniel Norman
f2e746b644 Removes duplicate hidraw_device type definition. am: f219d38925
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25533485

Change-Id: Ie0b6287cb50284c1ae6fc6ab40f89506efb71887
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-02 01:02:35 +00:00
Daniel Norman
f219d38925 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Test: ls -z /dev/hidraw0
(cherry picked from commit 8ff4604573)
2023-12-02 00:01:28 +00:00
Daniel Norman
979e64b5f2 [automerger skipped] Removes duplicate hidraw_device type definition. am: 2729e96ec8 -s ours
am skip reason: Merged-In Ic46a7327bb2dab89f424cde2682a40f2b28a04db with SHA-1 8ff4604573 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25531285

Change-Id: I1f0d61fa7d734e739070c1e23cda82d727d66944
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-01 23:27:20 +00:00
Daniel Norman
2729e96ec8 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Test: ls -z /dev/hidraw0
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Merged-In: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
(cherry picked from commit 8ff4604573)
2023-12-01 19:24:56 +00:00
Dario Freni
2584e99c58 Merge "Revert "zuma: move sepolicy related to bootctrl hal to gs-common"" into main 2023-12-01 13:00:07 +00:00
Sebastian Pickl
fbe923d20a Revert "zuma: move sepolicy related to bootctrl hal to gs-common"
Revert submission 25477883-gs-common_bootctrl-aidl

Reason for revert: breaking builds b/314240126

Bug: 314240126

Reverted changes: /q/submissionid:25477883-gs-common_bootctrl-aidl

Change-Id: I84dda0a7c98ed1d1f7958734761c9c1a0bd9d169
2023-12-01 11:30:45 +00:00
Treehugger Robot
421b5abf97 Merge "zuma: move sepolicy related to bootctrl hal to gs-common" into main 2023-12-01 03:57:28 +00:00
Treehugger Robot
124e7aa639 Merge "Suppress avc error log on debugfs's usb folder." into main 2023-11-30 23:26:22 +00:00
Luis Delgado De Mendoza
76972151b2 Merge "Add sepolicy entries for new BT channel" into main 2023-11-30 16:21:41 +00:00
Wilson Sung
14dda6e255 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 314054292
Test: scanBugreport
Bug: 313804706
Bug: 312894238
Change-Id: Ibf9517b585dcd8e06c62075d85dc55eb8ed7d18d
2023-11-30 07:14:04 +00:00
Khoa Hong
fb1c8b60bb Suppress avc error log on debugfs's usb folder.
The XHCI driver in kernel will write debugging information to DebugFS on
some USB host operations (for example: plugging in a USB headphone). We
are not using those information right now.

Bug: 311088739
Test: No error when plugging a USB headphone in.
Change-Id: I3a8e2290e97967c02453eadff440d8bbeefa31b1
2023-11-30 14:50:52 +08:00
Jason Chiu
23feade4db zuma: move sepolicy related to bootctrl hal to gs-common
Bug: 265063384
Change-Id: I230ca394c5d1b6e68dd8b4d51ea06568810eb4e0
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-11-27 17:45:29 +08:00
Treehugger Robot
9c8cb72283 Merge "allow vendor init to access percpu_pagelist_high_fraction" into main 2023-11-27 01:45:54 +00:00