Commit graph

2285 commits

Author SHA1 Message Date
Android Build Coastguard Worker
2e706c20d9 Snap for 12337246 from 5b80168d54 to 24Q4-release
Change-Id: Id8be2e2151e5c3fc73709fa92bfb198599c1758b
2024-09-07 21:03:03 +00:00
Xin Li
5b80168d54 [automerger skipped] Merge 24Q3 to AOSP main am: 39d96988e3 -s ours am: d1f03df8fc -s ours
am skip reason: Merged-In I9181b2344f2448b9debe1522528545ce90de8768 with SHA-1 fb98394c54 is already in history

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3258561

Change-Id: I411d96644364dcb9efdea5c1fe708b9651f8c12d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-09-07 03:29:31 +00:00
Xin Li
d1f03df8fc [automerger skipped] Merge 24Q3 to AOSP main am: 39d96988e3 -s ours
am skip reason: Merged-In I9181b2344f2448b9debe1522528545ce90de8768 with SHA-1 fb98394c54 is already in history

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3258561

Change-Id: Iedc2cb039f534e4d1e7b873bec0f4f4d41fb4ab6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-09-07 02:51:35 +00:00
Xin Li
39d96988e3 Merge 24Q3 to AOSP main
Bug: 357762254
Merged-In: I9181b2344f2448b9debe1522528545ce90de8768
Change-Id: Ic5351ce6b46a46820c6d73d4f924c6b92d30b06d
2024-09-05 17:02:39 -07:00
Android Build Coastguard Worker
d7f913bfc7 Snap for 12319997 from a73414799e to 24Q4-release
Change-Id: I07172b9ae176c7f16f32ac78bfd87d63f44cbeda
2024-09-04 23:03:30 +00:00
Randall Huang
a73414799e storage: move storage related device type to common folder
Bug: 364225000
Test: forrest build
Change-Id: I60597a3ad6f674b93267f41b3a27fdee6e923e59
Signed-off-by: Randall Huang <huangrandall@google.com>
2024-09-04 10:44:21 +08:00
Android Build Coastguard Worker
4f396416ed Snap for 12309590 from 8297fee02b to 24Q4-release
Change-Id: If58ee653816b60f1378c48e32c8a959c0a2b6e9d
2024-09-02 23:02:52 +00:00
Attis Chen
8297fee02b Merge "Label sysfs node power_mode as sysfs_display." into main 2024-09-02 04:54:18 +00:00
Android Build Coastguard Worker
2639243982 Snap for 12278291 from 432980a323 to 24Q4-release
Change-Id: Ie0a73e274c9e2ac52e19bdacf3cc79a056a6e298
2024-08-26 23:02:51 +00:00
Wilson Sung
432980a323 Update SELinux error
Test: scanBugreport
Bug: 361725982
Bug: 359428180
Test: scanAvcDeniedLogRightAfterReboot
Bug: 359428180
Flag: EXEMPT bugFix
Change-Id: I7e3ce34fdc02932250bcbd71e0a8864cfffaadff
2024-08-23 09:46:52 +00:00
Android Build Coastguard Worker
75b9e64c7b Snap for 12265118 from 371f678632 to 24Q4-release
Change-Id: I9331891359938c3c6658e63cdb7af82363acf750
2024-08-22 23:03:25 +00:00
Roy Luo
371f678632 Revert^2 "Add udc sysfs to udc_sysfs fs context"
This reverts commit 66ba3214b8.

Reason for revert: fix breakage in next build with build-time flag in
selinux policy.

Fixed the following audit logs:
[  285.983545] type=1400 audit(1724270284.724:31): avc:  denied  { read } for  comm="android.hardwar" name="state" dev="sysfs" ino=85740 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:sysfs_udc:s0 tclass=file permissive=0

Bug: 339241080
Test: tested on Shiba trunk_staging and next builds
Flag: build.RELEASE_USB_UDC_SYSFS_SELINUX_POLICY_ENABLED
Change-Id: Ie4979f408a5bca0bb9b9762048ab716ddeeb4d2f
2024-08-21 22:15:22 +00:00
attis
5bf0b2bd07 Label sysfs node power_mode as sysfs_display.
Label power_mode to sysfs_panel to let it be allowed in dumpstate.

avc log:
08-20 20:24:11.292  9339  9339 W dump_display: type=1400 audit(0.0:2372): avc:  denied  { read } for  name="power_mode" dev="sysfs" ino=85501 scontext=u:r:dump_display:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Test: ls -Z, adb bugreport.
Flag: EXEMPT bugfix
Bug: 358505990
Change-Id: I7b6051de3e8f1b2813c681a176266fe3c7518991
Signed-off-by: attis <attis@google.com>
2024-08-21 17:08:49 +08:00
Android Build Coastguard Worker
56bc4aeee0 Snap for 12247339 from 22ca32df91 to 24Q4-release
Change-Id: I1f8758463034bd05d8359495823f9ef558e02c57
2024-08-19 23:03:16 +00:00
Wilson Sung
22ca32df91 Merge "Update SELinux error" into main 2024-08-19 06:14:28 +00:00
Android Build Coastguard Worker
f98c602ae0 Snap for 12241618 from 390674b749 to 24Q4-release
Change-Id: I25ea415a6f1de8f83f614521b15bee7aaa4c06e5
2024-08-17 01:03:09 +00:00
Android Build Coastguard Worker
7640337af6 Snap for 12235414 from dac2c5438b to 24Q4-release
Change-Id: I9c7699f942226e7a46b1e81c52a7a34c340b49f5
2024-08-15 23:03:03 +00:00
Xiaofan Jiang
390674b749 Merge "Revert^2 "zuma: update modem_svc sepolicy for UMI"" into main 2024-08-15 20:44:27 +00:00
Xiaofan Jiang
515a102ac8 Revert^2 "zuma: update modem_svc sepolicy for UMI"
c653101290

Change-Id: Ib1d18e33b87f03ee52bcbdff129c6d56b8a63a61
2024-08-15 19:25:35 +00:00
Priyanka Advani (xWF)
61ddb69d2c Merge "Revert "zuma: update modem_svc sepolicy for UMI"" into main 2024-08-15 18:30:35 +00:00
Priyanka Advani (xWF)
c653101290 Revert "zuma: update modem_svc sepolicy for UMI"
Revert submission 28762313

Reason for revert: Droidmonitor created revert due to b/360059249.

Reverted changes: /q/submissionid:28762313

Change-Id: I88cd8603351f5c5e1a546872f4f3aa1cae75dcd5
2024-08-15 16:14:57 +00:00
Wilson Sung
e24c2a8265 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 360060606
Test: scanBugreport
Bug: 360060992
Bug: 359428180
Test: scanAvcDeniedLogRightAfterReboot
Bug: 360060606
Bug: 359428180
Flag: EXEMPT bugFix
Change-Id: I3dfb16fdb309f01f543c826b155fc774b76faade
2024-08-15 09:25:35 +00:00
Xiaofan Jiang
dac2c5438b Merge "zuma: update modem_svc sepolicy for UMI" into main 2024-08-15 04:01:13 +00:00
Xiaofan Jiang
08b3cf20a7 zuma: update modem_svc sepolicy for UMI
Bug: 357139752

Flag: EXEMPT sepolicy

[   68.189198] type=1400 audit(1722986580.568:59): avc:  denied  { unlink } for  comm="binder:892_2" name="modem_svc_socket" dev="dm-52" ino=20239 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1
[   68.189448] type=1400 audit(1722986580.568:60): avc:  denied  { create } for  comm="binder:892_2" name="modem_svc_socket" scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1

Change-Id: I7cccb22ef31e88eebae664dcd937553c7ed9428f
2024-08-15 03:53:07 +00:00
Android Build Coastguard Worker
64677f7038 Snap for 12153359 from cab53ff9d9 to 24Q4-release
Change-Id: I18ed3e1064c7e3a2741b8c8071a598d6ce69f711
2024-07-29 23:03:10 +00:00
Gil Liu
cab53ff9d9 Merge "add hal_graphics_composer to access thermal temperature" into main 2024-07-29 06:10:29 +00:00
Android Build Coastguard Worker
4a78288f7f Snap for 12147630 from 6dd8b82b22 to 24Q4-release
Change-Id: I2ee51ccb6954cc1fca5121768e19cbc34ee6f9d3
2024-07-27 01:03:19 +00:00
Treehugger Robot
6dd8b82b22 Merge "Correct the path of tcpm-source-psy device" into main 2024-07-26 02:04:31 +00:00
Mike Wang
a689f70d3c Merge "Add the selinux policy to allow the gril get/set vendor log properties." into main 2024-07-26 01:15:34 +00:00
Android Build Coastguard Worker
22fd0a6d9a Snap for 12140224 from faaaf11fd9 to 24Q4-release
Change-Id: I0d318b7091e69b50508f3a4589128ec098dc28d8
2024-07-25 23:03:03 +00:00
Manali Bhutiyani
faaaf11fd9 Merge "DisplayPort Stats: add sysfs access permission on Zuma devices" into main 2024-07-25 15:46:01 +00:00
Android Build Coastguard Worker
b6e27c63f4 Merge cherrypicks of ['googleplex-android-review.googlesource.com/28469518'] into 24Q4-release.
Change-Id: Ia6954ff1f9f485c2787e92eb132c28c85d259ab0
2024-07-25 00:33:45 +00:00
Daniel Chapin
1a430facff Revert "trusty: storageproxy: add fs_ready_rw property context"
Revert submission 28318041-rw_storage

Reason for revert: Droidfood blocking bug b/355163562

Reverted changes: /q/submissionid:28318041-rw_storage
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:6d6f71b74a93ed80f72cbb70ceaf89676251e3a2)
Merged-In: I0fa3edda88677966d42576d76616b837a4bbe70b
Change-Id: I0fa3edda88677966d42576d76616b837a4bbe70b
2024-07-25 00:32:37 +00:00
Carlos Rodriguez
6e54536670 DisplayPort Stats: add sysfs access permission on Zuma devices
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:48): avc:  denied  { read } for  name="fec_dsc_supported" dev="sysfs" ino=71618 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:49): avc:  denied  { read } for  name="fec_dsc_not_supported" dev="sysfs" ino=71619 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:50): avc:  denied  { read } for  name="max_res_other" dev="sysfs" ino=71617 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:51): avc:  denied  { read } for  name="max_res_1366_768" dev="sysfs" ino=71607 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:52): avc:  denied  { read } for  name="max_res_1440_900" dev="sysfs" ino=71608 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:53): avc:  denied  { read } for  name="max_res_1600_900" dev="sysfs" ino=71609 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:54): avc:  denied  { read } for  name="max_res_1920_1080" dev="sysfs" ino=71610 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:55): avc:  denied  { read } for  name="max_res_2560_1080" dev="sysfs" ino=71611 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:56): avc:  denied  { read } for  name="max_res_2560_1440" dev="sysfs" ino=71612 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
.....

Bug: 343602691
Bug: 317486088

Flag: EXEMPT bugfix
Test: Built and flashed, errors are gone.

Change-Id: I49d177d2a997698b05f27bd4c448847ed3110e59
2024-07-24 23:49:52 +00:00
Android Build Coastguard Worker
efcc1ddac6 Snap for 12135134 from b188015fba to 24Q4-release
Change-Id: I8adb8ec692e7496b94ce0eada70713523847d962
2024-07-24 23:03:11 +00:00
Daniel Chapin
cfbbd040df Merge "Revert "trusty: storageproxy: add fs_ready_rw property context"" into main 2024-07-24 21:48:57 +00:00
Android Build Coastguard Worker
b421a28e2d Merge cherrypicks of ['googleplex-android-review.googlesource.com/28469518'] into 24Q4-release.
Change-Id: I7cbb2e6b41faee7d65fb7038c83c606108580695
2024-07-24 21:02:24 +00:00
Daniel Chapin
7ae91b1650 Revert "trusty: storageproxy: add fs_ready_rw property context"
Revert submission 28318041-rw_storage

Reason for revert: Droidfood blocking bug b/355163562

Reverted changes: /q/submissionid:28318041-rw_storage
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:6d6f71b74a93ed80f72cbb70ceaf89676251e3a2)
Merged-In: I0fa3edda88677966d42576d76616b837a4bbe70b
Change-Id: I0fa3edda88677966d42576d76616b837a4bbe70b
2024-07-24 21:01:27 +00:00
Daniel Chapin
6d6f71b74a Revert "trusty: storageproxy: add fs_ready_rw property context"
Revert submission 28318041-rw_storage

Reason for revert: Droidfood blocking bug b/355163562

Reverted changes: /q/submissionid:28318041-rw_storage

Change-Id: I0fa3edda88677966d42576d76616b837a4bbe70b
2024-07-24 20:17:33 +00:00
Kyle Tso
4358dc4f7e Correct the path of tcpm-source-psy device
Bug: 353804370
Flag: EXEMPT bugfix
Change-Id: I059a652d13ffdf186fb36edb11ef4c1dc6ac8648
Signed-off-by: Kyle Tso <kyletso@google.com>
2024-07-24 02:13:54 +00:00
Android Build Coastguard Worker
3abed13498 Snap for 12129055 from b188015fba to 24Q4-release
Change-Id: I6c2dc68512451287ee97dc448ac36bc095d3c6a9
2024-07-23 23:03:20 +00:00
Mike McTernan
b188015fba Merge "trusty: storageproxy: add fs_ready_rw property context" into main 2024-07-23 10:02:28 +00:00
gilliu
1dde3ea2ff add hal_graphics_composer to access thermal temperature
type=1400 audit(0.0:77): avc:  denied  { search } for  name="thermal"
dev="tmpfs" ino=1618 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=0

type=1400 audit(0.0:74): avc:  denied  { search } for  name="thermal"
dev="sysfs" ino=21594 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=dir permissive=0

type=1400 audit(0.0:74): avc:  denied  { read } for  name="temp"
dev="sysfs" ino=73536 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=0

type=1400 audit(0.0:74): avc:  denied  { getattr } for
path="/sys/devices/virtual/thermal/thermal_zone12/temp" dev="sysfs"
ino=73537 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=0

Bug: 343141590
Test: check no avc pattern on logcat from test image
Flag: NONE add permission
Change-Id: I87fce47644b07342d756e7594685eea0dded1926
2024-07-23 09:05:16 +00:00
Android Build Coastguard Worker
f692e379f4 Snap for 12116631 from 66ba3214b8 to 24Q4-release
Change-Id: I14053f84c47b37fdfa9ab6e7c5cf2b2caed74f9e
2024-07-20 01:03:05 +00:00
Roy Luo
66ba3214b8 Revert "Add udc sysfs to udc_sysfs fs context"
Revert submission 27445245-339241080

Reason for revert: break husky-next-user (linux) build 12111903

Reverted changes: /q/submissionid:27445245-339241080
Bug: 339241080
Change-Id: If558e5bef47a0e617e4b4997f0ad9c8154b43ee9
2024-07-19 01:16:47 +00:00
Android Build Coastguard Worker
af4e4ba84d Snap for 12110738 from 7c7ec16cad to 24Q4-release
Change-Id: I59adebc8d27108abef2e5d7bde3fb5fd28607666
2024-07-18 23:03:04 +00:00
Roy Luo
eb5a3cd47a Add udc sysfs to udc_sysfs fs context
This is needed for system server to monitor usb gadget state.
Grant hal_usb_impl read access as it's needed by UsbDataSessionMonitor.

Bug: 339241080
Test: tested on Shiba
Flag: android.hardware.usb.flags.enable_udc_sysfs_usb_state_update
Change-Id: Iab3c20569cb22d7524ca303f6cb3eaf40aa2161d
2024-07-18 22:56:15 +00:00
Sergey Volk
7c7ec16cad [automerger skipped] Add sepolicy for DisplayPort wakeup node am: fb98394c54 -s ours
am skip reason: Merged-In I9181b2344f2448b9debe1522528545ce90de8768 with SHA-1 77518a2614 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/28360816

Change-Id: I2bda43ad3b6983cae7aa2e7dd4dfb836ebee226c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-18 13:08:49 +00:00
Mike Wang
ef8937f64c Add the selinux policy to allow the gril get/set vendor log properties.
avc logs:
2024-07-17 06:00:41.024 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:96): avc: denied { read } for name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=416 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0 app=com.google.android.grilservice
2024-07-17 06:00:41.024 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:97): avc: denied { read } for name="u:object_r:vendor_modem_prop:s0" dev="tmpfs" ino=418 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_modem_prop:s0 tclass=file permissive=0 app=com.google.android.grilservice
2024-07-17 06:00:49.592 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:99): avc: denied { write } for name="property_service" dev="tmpfs" ino=861 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:property_socket:s0 tclass=sock_file permissive=0 app=com.google.android.grilservice

2024-07-17 16:46:54.748 1-1 /system/bin/init init I type=1107 audit(0.0:103): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=persist.vendor.verbose_logging_enabled pid=2152 uid=10238 gid=10238 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_logger_prop:s0 tclass=property_service permissive=1'
2024-07-17 16:49:33.256 1-1 /system/bin/init init I type=1107 audit(0.0:116): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=persist.vendor.modem.extensive_logging_enabled pid=2152 uid=10238 gid=10238 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_modem_prop:s0 tclass=property_service permissive=1'


Bug: 293947661
Change-Id: Iec1cc221a543543da28416a5bc7d7ddacde959c5
2024-07-17 20:23:43 +00:00
Sergey Volk
fb98394c54 Add sepolicy for DisplayPort wakeup node
Bug: 348125717
Test: ls -Z /sys/devices/platform/110f0000.drmdp/wakeup
Flag: NONE (follow up fix for merged non-flagged CL pa/2839256)
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:77518a261471f7884e5b7c8ca73442df5c11e48e)
Merged-In: I9181b2344f2448b9debe1522528545ce90de8768
Change-Id: I9181b2344f2448b9debe1522528545ce90de8768
2024-07-17 14:37:46 +00:00