Commit graph

2235 commits

Author SHA1 Message Date
Treehugger Robot
207188241d Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev am: 4bb847b815
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24585767

Change-Id: I9df8bae38a17b05df787654de85517064fb7aaec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-30 17:35:13 +00:00
Treehugger Robot
4bb847b815 Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev 2023-08-30 16:29:24 +00:00
Yixuan Wang
bd654f00d9 Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."
Revert submission 24526613-revert-23834879-CHRE BT LOG-MHDBQNZAGV

Reason for revert: Fixed and tested with a followup cl

Reverted changes: /q/submissionid:24526613-revert-23834879-CHRE+BT+LOG-MHDBQNZAGV

Change-Id: I29866a91abfcfa380d772da447eb95344df43f8f
2023-08-29 19:17:32 +00:00
Safayat Ullah
6e969be173 [automerger skipped] display: add persist property to vendor_display_prop am: ea09b155f2 am: 2c7187af19 -s ours
am skip reason: Merged-In I2497960fbc76e56dd3a9c69d3fe274f0685744f8 with SHA-1 b27308445d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: Ifd6f9184a55de25ca13b0d4146181b2148371fc2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 14:24:57 +00:00
Safayat Ullah
2c7187af19 display: add persist property to vendor_display_prop am: ea09b155f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: If21c57942053863ff2157d88a4810a81b30a03f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 13:34:23 +00:00
Safayat Ullah
ea09b155f2 display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I60747df56c6993251bc736994da828814bcdf607
Merged-In: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 09:06:57 +00:00
Jasmine Cha
8fb992eacb audio: move related sepolicy of audio to gs-common
Bug: 297482504
Test: build pass

Change-Id: I9444b9e63f32bf898c845e42edbf682798bce300
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-08-29 16:45:47 +08:00
Safayat Ullah
b27308445d display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 08:01:45 +00:00
Kieran Cyphus
68fae0f171 Merge "DMD MDS: register proxy service and update MDS policy." into main 2023-08-28 01:42:43 +00:00
Sebastian Pickl
be13832180 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8 am: 00b4a62dd1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I71963049de8eb6c01ba75d32faeae378ca4ac84c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 11:33:44 +00:00
Sebastian Pickl
b5491c6650 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636 am: 7ee5ae18de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: If8ca0317f923da98e74ff8642b97f83894206b2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 11:33:41 +00:00
Sebastian Pickl
00b4a62dd1 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I79952f32ed00fface67437449575e7750959bca5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:25 +00:00
Sebastian Pickl
7ee5ae18de Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I3e4c175289017c75c26df4029421b61ad4efcfbe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:24 +00:00
Sebastian Pickl
ae9ab242e8 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev 2023-08-24 10:06:57 +00:00
Sebastian Pickl
84f1209636 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."
Revert submission 23834879-CHRE BT LOG

Reason for revert: fixes broken test b/297255998 verified by go/abtd: https://android-build.googleplex.com/builds/abtd/run/L30000000962735539
Bug:297255998

Reverted changes: /q/submissionid:23834879-CHRE+BT+LOG

Change-Id: I56b800260303834ed76dedf354b5a32af00b3684
2023-08-24 09:47:19 +00:00
Yixuan Wang
cf9a0ff772 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265 am: 4773f8519d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I70f328b984f29ef7bdc922bfb24352a963857da3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 20:01:35 +00:00
Yixuan Wang
890c3869c3 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316 am: 2058641a14
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: If2a3d433f56159e7a4264f52b53288afc557df61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 20:01:32 +00:00
Yixuan Wang
4773f8519d Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I819f616efd223718dd98bb8e953d3b020a296e80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:30 +00:00
Yixuan Wang
2058641a14 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: Id8058dbdf765871ba8e762ed10dd1af309642351
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:24 +00:00
Yixuan Wang
0fcc802265 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev 2023-08-23 19:29:45 +00:00
kierancyphus
9c6ec7fdd9 DMD MDS: register proxy service and update MDS policy.
MDS is a privileged app which get its permissions from `privapp-permissions-google-product.xml`, however, part of this work requires custom SEPolicy and so those permissions have been translated in SEPolicy.

This is a copy of 022dd13252865e131127da6596f5ada71fbf104f (ag/23056498) which can't be cherry picked because it was previously merged and reverted on main.

Test: Manually flash device
Bug: 270279779
Change-Id: If93515aa6b37bcbe8ec34241da1fa144d61e3d5d
2023-08-22 06:41:36 +00:00
Kris Chen
3f2bf29e1f Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212 am: beed400798
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I73f79b88b8605c20e3c0eb71699b84f08d6a5b94
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:45:10 +00:00
Kris Chen
7e2cb4f5f6 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac am: 12c2d23a4b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I64a4f98723a7d5425062c5144402d60af9a55661
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:44:46 +00:00
Kris Chen
beed400798 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I61b5d78945f4606a1a8924c2ba9e1e4b887d5895
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:08:39 +00:00
Kris Chen
12c2d23a4b Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: Ibcac24727053aac68e937156421b16b9ab892200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:04:41 +00:00
Kris Chen
4a49dbceac Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I9f99fc149fc832a44d45d09b563ba8bc913a12d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:39:06 +00:00
Kris Chen
7f3e2b9212 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I6a6014a9efe1d543b559bc9142766d0765468339
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:33:12 +00:00
Nicole Lee
c21ab073a4 Add rules for letting logger app send the command to ril am: 3c5d001e7d am: 61d25d70ff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24465106

Change-Id: I960f16e413999fa9e831a5535a39d7b4a62c899c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 03:16:18 +00:00
Nicole Lee
61d25d70ff Add rules for letting logger app send the command to ril am: 3c5d001e7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24465106

Change-Id: Ie4811b143d31103f5efbdf941fbfdff4e6c1ac93
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 02:40:44 +00:00
Seungjae Yoo
0612fa8de5 [automerger skipped] Label dtbo partition as dtbo_block_device am: 8256e72c4a am: 34eb573ac9 -s ours
am skip reason: Merged-In Iccca8de440cad7e9cd12015e0271262a217c457b with SHA-1 3773ca269e is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24438745

Change-Id: I81162dcf5812bb778f3c5d476da929542ee26ab3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-18 10:05:39 +00:00
Seungjae Yoo
34eb573ac9 Label dtbo partition as dtbo_block_device am: 8256e72c4a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24438745

Change-Id: Ia4dc306e5e6fdb008c890b538804fba528319806
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-18 09:28:08 +00:00
Treehugger Robot
438b7da691 Merge "Revert "DMD MDS: register proxy service and update MDS policy."" into main 2023-08-18 08:55:00 +00:00
Nicole Lee
3c5d001e7d Add rules for letting logger app send the command to ril
avc:  denied  { find } for interface=vendor.samsung_slsi.telephony.hardware.radioExternal::IOemSlsiRadioExternal sid=u:r:logger_app:s0:c3,c257,c512,c768 pid=3217 scontext=u:r:logger_app:s0:c3,c257,c512,c768 tcontext=u:object_r:hal_exynos_rild_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 293351399
Test: Verify SetDebugTrace funciton on p23
Change-Id: I1e51954886a7ea8bf5d31213634d4df34619eb33
2023-08-18 07:59:11 +00:00
Hsin-Yi Chen
f4b5074d48 Revert "DMD MDS: register proxy service and update MDS policy."
This reverts commit 2f5496582d.

Bug: 296329753
Reason for revert: broken build

Change-Id: I9336cebf8d4947450f5d3e2f0ec4df839aca3574
2023-08-18 07:40:37 +00:00
Renato Grottesi
fa4f421d41 Merge "Cleanup unused ArmNN settings." into main 2023-08-18 04:31:47 +00:00
Seungjae Yoo
8256e72c4a Label dtbo partition as dtbo_block_device
Bug: 291191362
Test: m

Merged-In: Iccca8de440cad7e9cd12015e0271262a217c457b
Change-Id: Iccca8de440cad7e9cd12015e0271262a217c457b
2023-08-18 00:38:06 +00:00
Seungjae Yoo
7961d4ee51 Merge "Label dtbo partition as dtbo_block_device" into main 2023-08-17 22:32:36 +00:00
Kris Chen
c9d21c380f Allow hal_power_default to access sysfs_scsi_devices_0000
Fix the following avc denial:
avc:  denied  { write } for  name="clkgate_enable" dev="sysfs"
ino=69304 scontext=u:r:hal_power_default:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

Bug: 290709897
Test: enroll fingerprint
Change-Id: Ib153087839d59e1839ceed4373a9be6f42e89619
2023-08-17 12:59:19 +00:00
Renato Grottesi
96f1f214a2 Cleanup unused ArmNN settings.
Test: pre-submit
Bug: 294463729
Change-Id: Ic417154724c4ddc06925ee2de1bd419dddfa1413
2023-08-17 09:03:35 +00:00
Kieran Cyphus
a294bcb262 Merge "DMD MDS: register proxy service and update MDS policy." into main 2023-08-17 02:30:26 +00:00
Ilya Matyukhin
ee710b08c1 Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev am: 013ec5ce54 am: 41056381db
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24343631

Change-Id: I43c243eff3bfbf14828f29f13789b1a3eb9f38c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-16 22:10:07 +00:00
Ilya Matyukhin
41056381db Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev am: 013ec5ce54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24343631

Change-Id: Icd84167a866d6bf8cf7fa2c0661320882acfaf6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-16 21:26:07 +00:00
Ilya Matyukhin
013ec5ce54 Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev 2023-08-16 20:38:34 +00:00
Seungjae Yoo
3773ca269e Label dtbo partition as dtbo_block_device
Bug: 291191362
Test: m

Change-Id: Iccca8de440cad7e9cd12015e0271262a217c457b
2023-08-16 11:16:37 +09:00
Wilson Sung
33db592c7a Supress kernel avc log before SELinux initialized am: 746bd9ad3c am: eb6368402e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24393095

Change-Id: If9ce34cb0f0b44998215f20d1be88578f0e8f56b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 03:26:28 +00:00
Wilson Sung
eb6368402e Supress kernel avc log before SELinux initialized am: 746bd9ad3c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24393095

Change-Id: Ib00fc07da24ed16e6b77f39985724eea892a1e50
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 02:25:22 +00:00
kierancyphus
2f5496582d DMD MDS: register proxy service and update MDS policy.
MDS is a privileged app which get its permissions from `privapp-permissions-google-product.xml`, however, part of this work requires custom SEPolicy and so those permissions have been translated in SEPolicy.

Test: Manually flash device
Bug: 270279779
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:022dd13252865e131127da6596f5ada71fbf104f)
Merged-In: I47c1a1163a7d40089d36960ed11822505a7a0a7a
Change-Id: I47c1a1163a7d40089d36960ed11822505a7a0a7a
2023-08-14 02:10:34 +00:00
Ilya Matyukhin
33540f5a05 zuma: Add sysfs_faceauth_gcma_heap type
Bug: 288156745
Test: build
Change-Id: I937b37542d8ff5a9e9e0d4d9b53c8300820a1826
2023-08-11 05:37:59 +00:00
Wilson Sung
746bd9ad3c Supress kernel avc log before SELinux initialized
Fix: 295430975
Change-Id: I11fe6c6705f7c4f7b3730b8f4b40229b083c0a13
2023-08-11 12:40:55 +08:00
Roy Luo
41a2c13c6a Merge "Support monitoring USB sysfs attributes in USB HAL" into main 2023-08-10 04:33:29 +00:00