Commit graph

1330 commits

Author SHA1 Message Date
Anthony Zhang
bdda1f3563 [DO NOT MERGE] Allow fingerprint to access persist property am: fb29e39ee1 am: 6096b4605d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: Ief35f2761e877322522b4879383bf9a8da2b1af3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:54:30 +00:00
Anthony Zhang
2f78573928 Merge "[DO NOT MERGE] Allow fingerprint to access persist property" into udc-d1-dev am: a594a23554
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: I7db822716e72399a9038e1ab1501150e4db88760
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:12:45 +00:00
Anthony Zhang
b0c6280ba5 [DO NOT MERGE] Allow fingerprint to access persist property am: fb29e39ee1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: I484b590b74da12bdf34de1bd84132a327d8387f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:12:44 +00:00
Anthony Zhang
fbceb3b769 Merge "[DO NOT MERGE] Allow fingerprint to access persist property" into udc-d1-dev am: a594a23554
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: Ic77f4c7fcc9ee54afdbc70880979f1a094c69828
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:10:20 +00:00
Anthony Zhang
6096b4605d [DO NOT MERGE] Allow fingerprint to access persist property am: fb29e39ee1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: Ib229248e32c537641601e0d60bd223570e713883
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:10:18 +00:00
Anthony Zhang
a594a23554 Merge "[DO NOT MERGE] Allow fingerprint to access persist property" into udc-d1-dev 2023-06-20 17:31:31 +00:00
Wilson Sung
f82fc11c11 Remove unused trace_marker dontaudit
Fix: 260366195
Change-Id: I7ece6549a64740c878dc92ce4b011136eb313533
2023-06-20 14:34:01 +08:00
Wilson Sung
61bbf0e529 Update SELinux error am: 0561b1bd1e am: 78f862e8ed
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23726793

Change-Id: I9f7659967897083db3fd026525bb907bfa40491a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 10:23:04 +00:00
Wilson Sung
06f2d05799 Remove obsolete bug_map and dontaudit am: 94fd2403a7 am: 324af7e2a0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23657127

Change-Id: I164a18ccdc77a6f0dd05f062578e522fafe8917b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 10:23:02 +00:00
Wilson Sung
d1f81b978c Update SELinux error am: 0561b1bd1e am: 23683d360c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23726793

Change-Id: I719680512ea1bb723dde78205330f054ea07769c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 10:17:15 +00:00
Wilson Sung
8460688dfb Remove obsolete bug_map and dontaudit am: 94fd2403a7 am: 385d8910b5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23657127

Change-Id: I818d1856cfe9f6cc731ebb94747ad42a606a80a7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 10:17:13 +00:00
Wilson Sung
78f862e8ed Update SELinux error am: 0561b1bd1e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23726793

Change-Id: Ibcef6ef61c7fe4fe864bd83179af5fa294f63808
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 09:39:19 +00:00
Wilson Sung
324af7e2a0 Remove obsolete bug_map and dontaudit am: 94fd2403a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23657127

Change-Id: I6f72c9b5b16e23d3062a5b52e3e761984119a7eb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 09:39:14 +00:00
Wilson Sung
23683d360c Update SELinux error am: 0561b1bd1e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23726793

Change-Id: I4bafe9717f682cfb0a2da65de21b414edcbc62bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 09:35:07 +00:00
Wilson Sung
385d8910b5 Remove obsolete bug_map and dontaudit am: 94fd2403a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23657127

Change-Id: Ic6a1f3525323749ab01b9a8d4b634e17c0df58ba
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 09:35:05 +00:00
Wilson Sung
0561b1bd1e Update SELinux error
Test: scanBugreport
Bug: 287898138
Change-Id: I297e59df3774a32305d72706ee6a160f111dee7a
2023-06-19 06:45:37 +00:00
Wilson Sung
94fd2403a7 Remove obsolete bug_map and dontaudit
Fix: 287154997
Fix: 281815537
Fix: 279680264
Fix: 264600171
Fix: 264483456
Fix: 264600171
Fix: 264600171
Fix: 274374769
Fix: 274727372
Fix: 279680070
Fix: 280706610
Fix: 279680213
Fix: 272628762
Fix: 274374992
Fix: 283725554
Fix: 274374722
Fix: 272166737
Fix: 272166787
Fix: 264483532
Fix: 264483753
Fix: 264483754
Fix: 281815594
Fix: 269964574
Fix: 269964574
Fix: 280705998
Fix: 269964558
Fix: 264599934
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 275645636
Fix: 275646003
Fix: 267714573
Fix: 272166664
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 277155496
Fix: 267260619
Fix: 261933310
Fix: 262794429
Fix: 267261048
Change-Id: I1e6da1e43b1aaa398d496cd7b1f3b6267fd39e21
2023-06-19 06:45:30 +00:00
Treehugger Robot
a6df16ff3d Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into udc-d1-dev am: a3e9615016 am: af63d1adeb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23720970

Change-Id: I51fbbb574a58e93487ccfb4289b44b99973784c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 02:59:07 +00:00
Treehugger Robot
70578d9eeb Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into udc-d1-dev am: a3e9615016 am: 6c37bd03ee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23720970

Change-Id: I2646ed87072a5e6aebb41fee785b0281a45c3173
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 02:53:30 +00:00
Treehugger Robot
af63d1adeb Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into udc-d1-dev am: a3e9615016
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23720970

Change-Id: Ia4b379de76b03ce2e4fb66b42992806e7e40965f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 02:13:15 +00:00
Treehugger Robot
6c37bd03ee Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into udc-d1-dev am: a3e9615016
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23720970

Change-Id: I796a8fd929bf0d2d76d89d8edfb397b84acb989b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-19 02:09:07 +00:00
Treehugger Robot
a3e9615016 Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into udc-d1-dev 2023-06-19 01:35:28 +00:00
Treehugger Robot
31a91022bd Merge "Update SELinux error" into udc-d1-dev am: 344c7f46c1 am: 461409cecd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23667878

Change-Id: Ife4dac76505f121b8948f886a08a1f5df015b892
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-17 07:46:49 +00:00
Treehugger Robot
1658327140 Merge "Update SELinux error" into udc-d1-dev am: 344c7f46c1 am: a8b6a0ffa6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23667878

Change-Id: I23defbb8d24c34e1f4107f91ee44a3d621b138a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-17 07:40:42 +00:00
Treehugger Robot
461409cecd Merge "Update SELinux error" into udc-d1-dev am: 344c7f46c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23667878

Change-Id: I376e5acd176e648021dd03e1d5bd576469ea1f5c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-17 07:01:34 +00:00
Treehugger Robot
a8b6a0ffa6 Merge "Update SELinux error" into udc-d1-dev am: 344c7f46c1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23667878

Change-Id: I2f57c78df9524faa34ebc8c52b4a25a4847f2864
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-17 06:55:59 +00:00
Treehugger Robot
344c7f46c1 Merge "Update SELinux error" into udc-d1-dev 2023-06-17 06:10:56 +00:00
Anthony Zhang
fb29e39ee1 [DO NOT MERGE] Allow fingerprint to access persist property
For zuma devices.

Bug: 258901849
Test: Local test on enrollment/delete, version update
Change-Id: I2c10bde2940778e0a434c2a073eb5793efeea455
2023-06-16 09:37:10 -07:00
Darren Hsu
f4f3f57534 sepolicy: allow hal_power_stats to read sysfs_edgetpu
Bug: 253702169
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: Ica2274f6e61cc35f7baf089ecc7b6c35f0914aeb
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-06-16 17:21:50 +08:00
Dinesh Yadav
f2ea110859 Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE] am: 100dd2387d am: 2bd05aeaad
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23468178

Change-Id: Ic122fd605153609244a3ffbf36021386c83ee1b1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-15 04:43:14 +00:00
Dinesh Yadav
57575e4ee2 Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE] am: 100dd2387d am: a95fa016e1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23468178

Change-Id: I76996f49845acb4a6739b2c0d781232ceb24b44d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-15 04:37:29 +00:00
Dinesh Yadav
2bd05aeaad Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE] am: 100dd2387d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23468178

Change-Id: I4bd79f57f2a063aef60e8dab049460636633ccea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-15 03:57:29 +00:00
Dinesh Yadav
a95fa016e1 Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE] am: 100dd2387d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23468178

Change-Id: Ic93c5c244e98865bfd567238fcc916ac04d9811d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-15 03:53:35 +00:00
Darren Hsu
0893338352 sepolicy: lable NFC sysfs path for hal_power_stats am: 3c8fb109b8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23667874

Change-Id: Ief308c99d8f56d080aafb2b643cfc7ed0b92b1fa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-14 11:50:18 +00:00
Wilson Sung
5fb350f09f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 286508419
Test: scanBugreport
Bug: 286508419
Test: scanAvcDeniedLogRightAfterReboot
Bug: 286508419
Change-Id: I1ba324133f5f4e14c5a7d43cfea25d98bda9faa9
2023-06-14 15:30:08 +08:00
Darren Hsu
3c8fb109b8 sepolicy: lable NFC sysfs path for hal_power_stats
Bug: 270498656
Test: capture a bugreport and ensure that there is
no avc denials for power stats
Change-Id: Ie765f6267ceacbc0b11426f4ee81ea0670195ddb
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-06-14 13:58:33 +08:00
Joerg Wagner
029fcb5e8a Merge "Prepare for Mali r44p0 UMD update" into udc-qpr-dev am: d19ec7a5b6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23599640

Change-Id: I76600fc5e3c949e8ec780b666f1b955cd35f18f2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-13 06:51:27 +00:00
Joerg Wagner
d19ec7a5b6 Merge "Prepare for Mali r44p0 UMD update" into udc-qpr-dev 2023-06-13 06:03:15 +00:00
Dinesh Yadav
100dd2387d Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE]
gxp_logging service will periodically check the sysfs files exposed by
the gxp kernel driver and report stats to Suez framework.
These policies are needed to report the metrics.

Tested:
Found no violation with these policies on a P23 device

Bug: 278514198
Change-Id: I8c3e57dfe4e9a6caab425f2424d07e83f5e7b9c6
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-06-13 03:37:56 +00:00
Ruofei Ma
4e97198c56 Merge "mediacodec_google: add hal_power" into udc-d1-dev am: abd1dee381 am: cac09c20ba
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23618633

Change-Id: I630b7889376612d003848f323b1bc3caba5678e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 16:40:40 +00:00
Ruofei Ma
46e587c075 Merge "mediacodec_google: add hal_power" into udc-d1-dev am: abd1dee381 am: a0f664f798
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23618633

Change-Id: I98e4ef057003235ecb66c2cd9ed0837dbf001e6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 16:37:58 +00:00
Ruofei Ma
cac09c20ba Merge "mediacodec_google: add hal_power" into udc-d1-dev am: abd1dee381
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23618633

Change-Id: Ib439b6d6464dcdaab8337ada3558780579363843
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 15:53:18 +00:00
Ruofei Ma
a0f664f798 Merge "mediacodec_google: add hal_power" into udc-d1-dev am: abd1dee381
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23618633

Change-Id: Icc85ce19bc59035553f2902a493cb7681ace2b6e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 15:50:45 +00:00
Ruofei Ma
abd1dee381 Merge "mediacodec_google: add hal_power" into udc-d1-dev 2023-06-12 15:17:42 +00:00
TreeHugger Robot
b18d19409a Merge changes from topic "283841311" into udc-d1-dev am: 032d9942de am: 00ed1044ff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23629344

Change-Id: I3e80089107c6fa2e72061b56c4c68e44427d796d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 08:01:33 +00:00
TreeHugger Robot
62ad33134c Merge changes from topic "283841311" into udc-d1-dev am: 032d9942de am: 0450d548a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23629344

Change-Id: Id066ca9d7b254964311413f4ae6f6d7cd555dbcd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 07:55:50 +00:00
TreeHugger Robot
00ed1044ff Merge changes from topic "283841311" into udc-d1-dev am: 032d9942de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23629344

Change-Id: Id39de7c6a03f11dd3d74e3ce9f9a0deca58873a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 07:18:17 +00:00
TreeHugger Robot
0450d548a2 Merge changes from topic "283841311" into udc-d1-dev am: 032d9942de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23629344

Change-Id: I214bf272f8cd35697063ffd39501cd65a2fb9c3f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 07:14:00 +00:00
TreeHugger Robot
032d9942de Merge changes from topic "283841311" into udc-d1-dev
* changes:
  Allow systemui_app access statsmanager_service
  Move systemui_app to system_ext
2023-06-12 06:30:36 +00:00
Krzysztof Kosiński
311f9e5d45 Remove Google Camera access to GXP firmware. am: 35910a3e8b am: 9332337e8e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23612126

Change-Id: I6b99371098f13305543471dedeed452cc9517181
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 02:46:33 +00:00