Commit graph

2235 commits

Author SHA1 Message Date
Inseob Kim
dc372f869b [automerger skipped] Move coredomain seapp contexts to system_ext am: ac8048a4f7 am: 5eb322b197 -s ours
am skip reason: Merged-In Ib8d191a6c07278b51eec88cd8142adf6c1a45668 with SHA-1 8f14aa12a1 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24354514

Change-Id: I530d41e884e7cbc058e74da48799835bfd2a8818
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 04:40:09 +00:00
Inseob Kim
5eb322b197 Move coredomain seapp contexts to system_ext am: ac8048a4f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24354514

Change-Id: I94af7d6ba7a52b5747781bb763f05e5c05b65715
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 03:56:23 +00:00
Inseob Kim
ac8048a4f7 Move coredomain seapp contexts to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
Merged-In: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
2023-08-08 15:11:08 +00:00
Inseob Kim
8f14aa12a1 Move coredomain seapp contexts to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
2023-08-08 21:05:21 +09:00
Roy Luo
8849e1a49a Support monitoring USB sysfs attributes in USB HAL
Grant access to USB sysfs attributes.

Bug: 285199434
Test: no audit log in logcat after command execution
Change-Id: Ia5f3333318b47f4e0a05140bd6b95e939197fde5
2023-08-07 19:49:09 +00:00
Wilson Sung
2d7bfbbf4d Supress kernel avc log before SELinux initialized am: 2d2ec40c1a am: e93cda1238
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24319337

Change-Id: Ib9a60e381cd91505dbfc33335674321a696c80af
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 04:41:48 +00:00
Wilson Sung
e93cda1238 Supress kernel avc log before SELinux initialized am: 2d2ec40c1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24319337

Change-Id: I9df6960739466feb4e249141d16d0b2d2e3b7467
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 03:59:19 +00:00
Wilson Sung
2d2ec40c1a Supress kernel avc log before SELinux initialized
Fix: 281814849
Fix: 292059050
Change-Id: Ie83557668ded8ab17bf77e60ed21db33e9f4f580
2023-08-04 07:32:39 +00:00
Treehugger Robot
e207f9e4ff Merge "gps: maintain one solution" into udc-qpr-dev am: 61939d2308 am: 1b1abb7ac9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24259847

Change-Id: I5662ab33e381357fbe3ab1aaf91304624c503bb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-01 05:56:23 +00:00
Treehugger Robot
1b1abb7ac9 Merge "gps: maintain one solution" into udc-qpr-dev am: 61939d2308
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24259847

Change-Id: Ie350939f0b0fb03dfc400e7ca89cf3b46214ecac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-01 05:15:48 +00:00
Treehugger Robot
61939d2308 Merge "gps: maintain one solution" into udc-qpr-dev 2023-08-01 04:40:51 +00:00
Cheng Chang
cd3d87535f gps: maintain one solution
Bug: 288813677
Test: compile for different devices and check binary.
Test: verification test at b/288813677.
Change-Id: I7ee13ab2641aee0256d4ddb5ba27070b51dbc5e5
2023-07-31 02:26:40 +00:00
Treehugger Robot
04e1c629f9 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 91cd7cbad8 am: e1153b6555
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I79639f3b6a0b8cf396959a29bcbbaba8669f3774
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 19:28:20 +00:00
Treehugger Robot
e1153b6555 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 91cd7cbad8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: If65e8446a432d2466a306da78ca40e04ece27efc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 18:17:35 +00:00
Treehugger Robot
91cd7cbad8 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I2aaa3eee203c5859a8f6cb57ee3612498f2d882e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 18:02:52 +00:00
Treehugger Robot
e30c4abfb6 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 3377a38d65 am: 563532e1a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I6f714c86a79872576ea8552f8b14adaa6156f358
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 14:37:02 +00:00
Treehugger Robot
563532e1a2 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 3377a38d65
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I87762ed51ab7acc8d9889e8565451badeba56610
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 10:32:14 +00:00
Treehugger Robot
3377a38d65 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I68f3638898f861784276508406773649d6d21c21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 09:49:05 +00:00
Treehugger Robot
0f46a31902 Merge "Revert "Update SELinux error"" into udc-d1-dev 2023-07-28 00:06:22 +00:00
Jason Chiu
2db1e0046f Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 65ce874b81 am: 5eb65dec3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: If43d7f85e36fa0b1187a33a07f9735c67c97f9bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:35:33 +00:00
Jason Chiu
05e87e1087 remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: 27e2aeafa7 am: b7f9178a76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ib79c46884070e3379f3ea51243a258a9e6796e38
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:35:31 +00:00
Jason Chiu
45253208c0 Add rule for bootctrl AIDL am: 17fa2e6fe5 am: 36dc08bf81 am: d88644ea2f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: I4c825e5161fd9336429880ff00b91eaa5e2a392a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:35:28 +00:00
Jason Chiu
5eb65dec3a Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 65ce874b81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I4f3d173599f6c719baba66dd8f2fdae854a00371
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:23 +00:00
Jason Chiu
b7f9178a76 remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: 27e2aeafa7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ic3e8ecf57f805fd32e6973dbfc708704002753bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:19 +00:00
Jason Chiu
d88644ea2f Add rule for bootctrl AIDL am: 17fa2e6fe5 am: 36dc08bf81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Iafe0815e93e1a7b8e00b729acff21253a40cf748
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:11 +00:00
Jason Chiu
65ce874b81 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I72d2747b0751ff8b462e59abf974dc3a1a1a1aea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:20 +00:00
Jason Chiu
27e2aeafa7 remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: I43897ecaaae1ecbcb30479f510637e2680406c40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:18 +00:00
Jason Chiu
36dc08bf81 Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Ic0fa67cd73840070825f3cb197ad00656b4c296b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:16 +00:00
Jason Chiu
a31f1a6d5c Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 7aa9a5e3c0 am: fe9e70cbbb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I3c4125d31626e02e59523a5fd4c249a3311986b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 20:39:14 +00:00
Jason Chiu
67addf1851 remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: b9e73326ee am: 8bceac530e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: I9411d0f4e94a85fd3814cf3317b560016bcd9697
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 20:39:12 +00:00
Jason Chiu
bd9241df07 Add rule for bootctrl AIDL am: 17fa2e6fe5 am: cbb8fed21e am: 1882450326
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: I5aa4575978be397e77eeaef2c9b09e7f393a7c02
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 20:39:10 +00:00
Jason Chiu
fe9e70cbbb Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 7aa9a5e3c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I8f36ce99361c4ce5d54b0ca52ff6f790de495457
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:50 +00:00
Jason Chiu
8bceac530e remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: b9e73326ee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ib1165fd100b06806f479b42785c1b68149cac6d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:48 +00:00
Jason Chiu
1882450326 Add rule for bootctrl AIDL am: 17fa2e6fe5 am: cbb8fed21e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: If43e26b093fe9f77712a03e54506f86702be9485
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:45 +00:00
Yunju Lee
72f7cbe324 Revert "Update SELinux error"
This reverts commit 8f56fc9709.

Reason for revert: b/291237127 is fixed

Bug: 291237127
Change-Id: I58e2636fb2ef1113a4305152948e07ed8a27a7d9
2023-07-24 15:10:01 +00:00
Jason Chiu
7aa9a5e3c0 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I3bc9799d166ad41bbbb547884a9993a352b3f6c3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:19 +00:00
Jason Chiu
b9e73326ee remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ia4efc4cdc0cb92c62c4ddcb7b6f458c4149657a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:16 +00:00
Jason Chiu
cbb8fed21e Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Idbac1303702c0845fd549564f28b20f2bf9f0a03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:13 +00:00
Jason Chiu
3aa432be32 Merge "Add rule for bootctrl AIDL"
Bug: 282670401
Change-Id: I1b4c5e7ced0fe67bbbaca2b607e4ca7422e170e1
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 21:00:41 +08:00
Jason Chiu
90a1f80488 Add hal_bootctl_default read permission to rootfs in Recovery mode
Fix the following avc denial:
avc:  denied  { read } for  pid=485 comm="android.hardwar" name="bin" dev="rootfs" ino=9529 scontext=u:r:hal_bootctl_default:s0 tcontext=u:object_r:rootfs:s0 tclass=dir permissive=0

Bug: 282670401
Change-Id: I23ab086ba21d6ffea8b48b4208933c031effc4d4
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:47 +00:00
Jason Chiu
54b0343059 remove rule for bootctrl hidl version 1.2
Bug: 282670401
Change-Id: I25d169c335fb551cf1862fdf6e6540485a2b8016
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:38 +00:00
Jason Chiu
17fa2e6fe5 Add rule for bootctrl AIDL
Bug: 282670401
Change-Id: I1b4c5e7ced0fe67bbbaca2b607e4ca7422e170e1
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 20:53:04 +08:00
Utku Utkan
c2e654730b Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 62b083db4d am: 4f7d7213fe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24124264

Change-Id: Ie2bb0cfcf9613d1e12da3fea6887000c4761fb5b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 19:58:33 +00:00
Utku Utkan
4f7d7213fe Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 62b083db4d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24124264

Change-Id: Iafecf9b6bfcc9982ca7ad609c7d4242df71a745c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 18:49:46 +00:00
Utku Utkan
62b083db4d Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Reason for revert: Relanding the original topic after copying the certificates under `device/google` for `without-vendor` branches

Reverted changes: /q/submissionid:24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Bug: 287069860
Test: m && flashall
Change-Id: Icc801ca310c0e512769ed84d185dd6149ae5f22b
2023-07-18 20:37:42 -07:00
Inseob Kim
ffec72585d Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: 1ef04d8dda am: ef514a009d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24122567

Change-Id: I11407eb1d65424f34d3ebe601a6c16e660dd8e4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 03:33:46 +00:00
Inseob Kim
ef514a009d Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: 1ef04d8dda
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24122567

Change-Id: Icc8049a6eb58141c8ab7109f5810306492f2f3d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 02:50:44 +00:00
Inseob Kim
1ef04d8dda Revert "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24056607-pixel-camera-services-extensions-sepolicy

Reason for revert: build breakage on git_main-without-vendor

Reverted changes: /q/submissionid:24056607-pixel-camera-services-extensions-sepolicy

Change-Id: I42e68b982d521acb9b9a088d58ff521be25beb7e
2023-07-19 01:15:27 +00:00
Utku Utkan
ed8790420e Introduce CameraServices seinfo tag for PixelCameraServices am: c3cf1b7cf0 am: 5dfb9ad64d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24030833

Change-Id: I628cb17d6053851612608f82700e518a043c2884
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 22:35:36 +00:00
Utku Utkan
5dfb9ad64d Introduce CameraServices seinfo tag for PixelCameraServices am: c3cf1b7cf0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24030833

Change-Id: I3ba20fc4bca8798a1bb84ace89f6097ea268041b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 21:49:07 +00:00