Commit graph

1330 commits

Author SHA1 Message Date
Safayat Ullah
2c7187af19 display: add persist property to vendor_display_prop am: ea09b155f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: If21c57942053863ff2157d88a4810a81b30a03f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 13:34:23 +00:00
Safayat Ullah
ea09b155f2 display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I60747df56c6993251bc736994da828814bcdf607
Merged-In: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 09:06:57 +00:00
Sebastian Pickl
00b4a62dd1 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I79952f32ed00fface67437449575e7750959bca5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:25 +00:00
Sebastian Pickl
7ee5ae18de Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I3e4c175289017c75c26df4029421b61ad4efcfbe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:24 +00:00
Sebastian Pickl
ae9ab242e8 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev 2023-08-24 10:06:57 +00:00
Sebastian Pickl
84f1209636 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."
Revert submission 23834879-CHRE BT LOG

Reason for revert: fixes broken test b/297255998 verified by go/abtd: https://android-build.googleplex.com/builds/abtd/run/L30000000962735539
Bug:297255998

Reverted changes: /q/submissionid:23834879-CHRE+BT+LOG

Change-Id: I56b800260303834ed76dedf354b5a32af00b3684
2023-08-24 09:47:19 +00:00
Yixuan Wang
4773f8519d Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I819f616efd223718dd98bb8e953d3b020a296e80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:30 +00:00
Yixuan Wang
2058641a14 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: Id8058dbdf765871ba8e762ed10dd1af309642351
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:24 +00:00
Yixuan Wang
0fcc802265 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev 2023-08-23 19:29:45 +00:00
Kris Chen
beed400798 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I61b5d78945f4606a1a8924c2ba9e1e4b887d5895
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:08:39 +00:00
Kris Chen
12c2d23a4b Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: Ibcac24727053aac68e937156421b16b9ab892200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:04:41 +00:00
Kris Chen
4a49dbceac Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I9f99fc149fc832a44d45d09b563ba8bc913a12d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:39:06 +00:00
Kris Chen
7f3e2b9212 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I6a6014a9efe1d543b559bc9142766d0765468339
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:33:12 +00:00
Nicole Lee
61d25d70ff Add rules for letting logger app send the command to ril am: 3c5d001e7d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24465106

Change-Id: Ie4811b143d31103f5efbdf941fbfdff4e6c1ac93
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 02:40:44 +00:00
Seungjae Yoo
34eb573ac9 Label dtbo partition as dtbo_block_device am: 8256e72c4a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24438745

Change-Id: Ia4dc306e5e6fdb008c890b538804fba528319806
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-18 09:28:08 +00:00
Nicole Lee
3c5d001e7d Add rules for letting logger app send the command to ril
avc:  denied  { find } for interface=vendor.samsung_slsi.telephony.hardware.radioExternal::IOemSlsiRadioExternal sid=u:r:logger_app:s0:c3,c257,c512,c768 pid=3217 scontext=u:r:logger_app:s0:c3,c257,c512,c768 tcontext=u:object_r:hal_exynos_rild_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 293351399
Test: Verify SetDebugTrace funciton on p23
Change-Id: I1e51954886a7ea8bf5d31213634d4df34619eb33
2023-08-18 07:59:11 +00:00
Seungjae Yoo
8256e72c4a Label dtbo partition as dtbo_block_device
Bug: 291191362
Test: m

Merged-In: Iccca8de440cad7e9cd12015e0271262a217c457b
Change-Id: Iccca8de440cad7e9cd12015e0271262a217c457b
2023-08-18 00:38:06 +00:00
Kris Chen
c9d21c380f Allow hal_power_default to access sysfs_scsi_devices_0000
Fix the following avc denial:
avc:  denied  { write } for  name="clkgate_enable" dev="sysfs"
ino=69304 scontext=u:r:hal_power_default:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

Bug: 290709897
Test: enroll fingerprint
Change-Id: Ib153087839d59e1839ceed4373a9be6f42e89619
2023-08-17 12:59:19 +00:00
Ilya Matyukhin
41056381db Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev am: 013ec5ce54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24343631

Change-Id: Icd84167a866d6bf8cf7fa2c0661320882acfaf6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-16 21:26:07 +00:00
Ilya Matyukhin
013ec5ce54 Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev 2023-08-16 20:38:34 +00:00
Wilson Sung
eb6368402e Supress kernel avc log before SELinux initialized am: 746bd9ad3c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24393095

Change-Id: Ib00fc07da24ed16e6b77f39985724eea892a1e50
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 02:25:22 +00:00
Ilya Matyukhin
33540f5a05 zuma: Add sysfs_faceauth_gcma_heap type
Bug: 288156745
Test: build
Change-Id: I937b37542d8ff5a9e9e0d4d9b53c8300820a1826
2023-08-11 05:37:59 +00:00
Wilson Sung
746bd9ad3c Supress kernel avc log before SELinux initialized
Fix: 295430975
Change-Id: I11fe6c6705f7c4f7b3730b8f4b40229b083c0a13
2023-08-11 12:40:55 +08:00
Inseob Kim
5eb322b197 Move coredomain seapp contexts to system_ext am: ac8048a4f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24354514

Change-Id: I94af7d6ba7a52b5747781bb763f05e5c05b65715
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 03:56:23 +00:00
Inseob Kim
ac8048a4f7 Move coredomain seapp contexts to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
Merged-In: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
2023-08-08 15:11:08 +00:00
Wilson Sung
e93cda1238 Supress kernel avc log before SELinux initialized am: 2d2ec40c1a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24319337

Change-Id: I9df6960739466feb4e249141d16d0b2d2e3b7467
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 03:59:19 +00:00
Wilson Sung
2d2ec40c1a Supress kernel avc log before SELinux initialized
Fix: 281814849
Fix: 292059050
Change-Id: Ie83557668ded8ab17bf77e60ed21db33e9f4f580
2023-08-04 07:32:39 +00:00
Treehugger Robot
1b1abb7ac9 Merge "gps: maintain one solution" into udc-qpr-dev am: 61939d2308
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24259847

Change-Id: Ie350939f0b0fb03dfc400e7ca89cf3b46214ecac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-01 05:15:48 +00:00
Treehugger Robot
61939d2308 Merge "gps: maintain one solution" into udc-qpr-dev 2023-08-01 04:40:51 +00:00
Cheng Chang
cd3d87535f gps: maintain one solution
Bug: 288813677
Test: compile for different devices and check binary.
Test: verification test at b/288813677.
Change-Id: I7ee13ab2641aee0256d4ddb5ba27070b51dbc5e5
2023-07-31 02:26:40 +00:00
Treehugger Robot
e1153b6555 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 91cd7cbad8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: If65e8446a432d2466a306da78ca40e04ece27efc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 18:17:35 +00:00
Treehugger Robot
91cd7cbad8 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I2aaa3eee203c5859a8f6cb57ee3612498f2d882e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 18:02:52 +00:00
Treehugger Robot
563532e1a2 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902 am: 3377a38d65
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I87762ed51ab7acc8d9889e8565451badeba56610
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 10:32:14 +00:00
Treehugger Robot
3377a38d65 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I68f3638898f861784276508406773649d6d21c21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 09:49:05 +00:00
Treehugger Robot
0f46a31902 Merge "Revert "Update SELinux error"" into udc-d1-dev 2023-07-28 00:06:22 +00:00
Jason Chiu
5eb65dec3a Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 65ce874b81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I4f3d173599f6c719baba66dd8f2fdae854a00371
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:23 +00:00
Jason Chiu
b7f9178a76 remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: 27e2aeafa7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ic3e8ecf57f805fd32e6973dbfc708704002753bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:19 +00:00
Jason Chiu
d88644ea2f Add rule for bootctrl AIDL am: 17fa2e6fe5 am: 36dc08bf81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Iafe0815e93e1a7b8e00b729acff21253a40cf748
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 13:12:11 +00:00
Jason Chiu
65ce874b81 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I72d2747b0751ff8b462e59abf974dc3a1a1a1aea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:20 +00:00
Jason Chiu
27e2aeafa7 remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: I43897ecaaae1ecbcb30479f510637e2680406c40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:18 +00:00
Jason Chiu
36dc08bf81 Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Ic0fa67cd73840070825f3cb197ad00656b4c296b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:16 +00:00
Jason Chiu
fe9e70cbbb Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 7aa9a5e3c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I8f36ce99361c4ce5d54b0ca52ff6f790de495457
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:50 +00:00
Jason Chiu
8bceac530e remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: b9e73326ee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ib1165fd100b06806f479b42785c1b68149cac6d8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:48 +00:00
Jason Chiu
1882450326 Add rule for bootctrl AIDL am: 17fa2e6fe5 am: cbb8fed21e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: If43e26b093fe9f77712a03e54506f86702be9485
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 19:41:45 +00:00
Yunju Lee
72f7cbe324 Revert "Update SELinux error"
This reverts commit 8f56fc9709.

Reason for revert: b/291237127 is fixed

Bug: 291237127
Change-Id: I58e2636fb2ef1113a4305152948e07ed8a27a7d9
2023-07-24 15:10:01 +00:00
Jason Chiu
7aa9a5e3c0 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I3bc9799d166ad41bbbb547884a9993a352b3f6c3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:19 +00:00
Jason Chiu
b9e73326ee remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ia4efc4cdc0cb92c62c4ddcb7b6f458c4149657a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:16 +00:00
Jason Chiu
cbb8fed21e Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Idbac1303702c0845fd549564f28b20f2bf9f0a03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:13 +00:00
Jason Chiu
90a1f80488 Add hal_bootctl_default read permission to rootfs in Recovery mode
Fix the following avc denial:
avc:  denied  { read } for  pid=485 comm="android.hardwar" name="bin" dev="rootfs" ino=9529 scontext=u:r:hal_bootctl_default:s0 tcontext=u:object_r:rootfs:s0 tclass=dir permissive=0

Bug: 282670401
Change-Id: I23ab086ba21d6ffea8b48b4208933c031effc4d4
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:47 +00:00
Jason Chiu
54b0343059 remove rule for bootctrl hidl version 1.2
Bug: 282670401
Change-Id: I25d169c335fb551cf1862fdf6e6540485a2b8016
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:38 +00:00