Commit graph

2249 commits

Author SHA1 Message Date
Roy Luo
371f678632 Revert^2 "Add udc sysfs to udc_sysfs fs context"
This reverts commit 66ba3214b8.

Reason for revert: fix breakage in next build with build-time flag in
selinux policy.

Fixed the following audit logs:
[  285.983545] type=1400 audit(1724270284.724:31): avc:  denied  { read } for  comm="android.hardwar" name="state" dev="sysfs" ino=85740 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:sysfs_udc:s0 tclass=file permissive=0

Bug: 339241080
Test: tested on Shiba trunk_staging and next builds
Flag: build.RELEASE_USB_UDC_SYSFS_SELINUX_POLICY_ENABLED
Change-Id: Ie4979f408a5bca0bb9b9762048ab716ddeeb4d2f
2024-08-21 22:15:22 +00:00
Wilson Sung
22ca32df91 Merge "Update SELinux error" into main 2024-08-19 06:14:28 +00:00
Xiaofan Jiang
390674b749 Merge "Revert^2 "zuma: update modem_svc sepolicy for UMI"" into main 2024-08-15 20:44:27 +00:00
Xiaofan Jiang
515a102ac8 Revert^2 "zuma: update modem_svc sepolicy for UMI"
c653101290

Change-Id: Ib1d18e33b87f03ee52bcbdff129c6d56b8a63a61
2024-08-15 19:25:35 +00:00
Priyanka Advani (xWF)
61ddb69d2c Merge "Revert "zuma: update modem_svc sepolicy for UMI"" into main 2024-08-15 18:30:35 +00:00
Priyanka Advani (xWF)
c653101290 Revert "zuma: update modem_svc sepolicy for UMI"
Revert submission 28762313

Reason for revert: Droidmonitor created revert due to b/360059249.

Reverted changes: /q/submissionid:28762313

Change-Id: I88cd8603351f5c5e1a546872f4f3aa1cae75dcd5
2024-08-15 16:14:57 +00:00
Wilson Sung
e24c2a8265 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 360060606
Test: scanBugreport
Bug: 360060992
Bug: 359428180
Test: scanAvcDeniedLogRightAfterReboot
Bug: 360060606
Bug: 359428180
Flag: EXEMPT bugFix
Change-Id: I3dfb16fdb309f01f543c826b155fc774b76faade
2024-08-15 09:25:35 +00:00
Xiaofan Jiang
dac2c5438b Merge "zuma: update modem_svc sepolicy for UMI" into main 2024-08-15 04:01:13 +00:00
Xiaofan Jiang
08b3cf20a7 zuma: update modem_svc sepolicy for UMI
Bug: 357139752

Flag: EXEMPT sepolicy

[   68.189198] type=1400 audit(1722986580.568:59): avc:  denied  { unlink } for  comm="binder:892_2" name="modem_svc_socket" dev="dm-52" ino=20239 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1
[   68.189448] type=1400 audit(1722986580.568:60): avc:  denied  { create } for  comm="binder:892_2" name="modem_svc_socket" scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1

Change-Id: I7cccb22ef31e88eebae664dcd937553c7ed9428f
2024-08-15 03:53:07 +00:00
Gil Liu
cab53ff9d9 Merge "add hal_graphics_composer to access thermal temperature" into main 2024-07-29 06:10:29 +00:00
Treehugger Robot
6dd8b82b22 Merge "Correct the path of tcpm-source-psy device" into main 2024-07-26 02:04:31 +00:00
Mike Wang
a689f70d3c Merge "Add the selinux policy to allow the gril get/set vendor log properties." into main 2024-07-26 01:15:34 +00:00
Manali Bhutiyani
faaaf11fd9 Merge "DisplayPort Stats: add sysfs access permission on Zuma devices" into main 2024-07-25 15:46:01 +00:00
Carlos Rodriguez
6e54536670 DisplayPort Stats: add sysfs access permission on Zuma devices
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:48): avc:  denied  { read } for  name="fec_dsc_supported" dev="sysfs" ino=71618 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:49): avc:  denied  { read } for  name="fec_dsc_not_supported" dev="sysfs" ino=71619 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:50): avc:  denied  { read } for  name="max_res_other" dev="sysfs" ino=71617 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:51): avc:  denied  { read } for  name="max_res_1366_768" dev="sysfs" ino=71607 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:52): avc:  denied  { read } for  name="max_res_1440_900" dev="sysfs" ino=71608 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:53): avc:  denied  { read } for  name="max_res_1600_900" dev="sysfs" ino=71609 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:54): avc:  denied  { read } for  name="max_res_1920_1080" dev="sysfs" ino=71610 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:55): avc:  denied  { read } for  name="max_res_2560_1080" dev="sysfs" ino=71611 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-24 18:17:43.428 W/pixelstats-vend( 7494): type=1400 audit(0.0:56): avc:  denied  { read } for  name="max_res_2560_1440" dev="sysfs" ino=71612 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
.....

Bug: 343602691
Bug: 317486088

Flag: EXEMPT bugfix
Test: Built and flashed, errors are gone.

Change-Id: I49d177d2a997698b05f27bd4c448847ed3110e59
2024-07-24 23:49:52 +00:00
Daniel Chapin
cfbbd040df Merge "Revert "trusty: storageproxy: add fs_ready_rw property context"" into main 2024-07-24 21:48:57 +00:00
Daniel Chapin
6d6f71b74a Revert "trusty: storageproxy: add fs_ready_rw property context"
Revert submission 28318041-rw_storage

Reason for revert: Droidfood blocking bug b/355163562

Reverted changes: /q/submissionid:28318041-rw_storage

Change-Id: I0fa3edda88677966d42576d76616b837a4bbe70b
2024-07-24 20:17:33 +00:00
Kyle Tso
4358dc4f7e Correct the path of tcpm-source-psy device
Bug: 353804370
Flag: EXEMPT bugfix
Change-Id: I059a652d13ffdf186fb36edb11ef4c1dc6ac8648
Signed-off-by: Kyle Tso <kyletso@google.com>
2024-07-24 02:13:54 +00:00
Mike McTernan
b188015fba Merge "trusty: storageproxy: add fs_ready_rw property context" into main 2024-07-23 10:02:28 +00:00
gilliu
1dde3ea2ff add hal_graphics_composer to access thermal temperature
type=1400 audit(0.0:77): avc:  denied  { search } for  name="thermal"
dev="tmpfs" ino=1618 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:thermal_link_device:s0 tclass=dir permissive=0

type=1400 audit(0.0:74): avc:  denied  { search } for  name="thermal"
dev="sysfs" ino=21594 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=dir permissive=0

type=1400 audit(0.0:74): avc:  denied  { read } for  name="temp"
dev="sysfs" ino=73536 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=0

type=1400 audit(0.0:74): avc:  denied  { getattr } for
path="/sys/devices/virtual/thermal/thermal_zone12/temp" dev="sysfs"
ino=73537 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:sysfs_thermal:s0 tclass=file permissive=0

Bug: 343141590
Test: check no avc pattern on logcat from test image
Flag: NONE add permission
Change-Id: I87fce47644b07342d756e7594685eea0dded1926
2024-07-23 09:05:16 +00:00
Roy Luo
66ba3214b8 Revert "Add udc sysfs to udc_sysfs fs context"
Revert submission 27445245-339241080

Reason for revert: break husky-next-user (linux) build 12111903

Reverted changes: /q/submissionid:27445245-339241080
Bug: 339241080
Change-Id: If558e5bef47a0e617e4b4997f0ad9c8154b43ee9
2024-07-19 01:16:47 +00:00
Roy Luo
eb5a3cd47a Add udc sysfs to udc_sysfs fs context
This is needed for system server to monitor usb gadget state.
Grant hal_usb_impl read access as it's needed by UsbDataSessionMonitor.

Bug: 339241080
Test: tested on Shiba
Flag: android.hardware.usb.flags.enable_udc_sysfs_usb_state_update
Change-Id: Iab3c20569cb22d7524ca303f6cb3eaf40aa2161d
2024-07-18 22:56:15 +00:00
Sergey Volk
7c7ec16cad [automerger skipped] Add sepolicy for DisplayPort wakeup node am: fb98394c54 -s ours
am skip reason: Merged-In I9181b2344f2448b9debe1522528545ce90de8768 with SHA-1 77518a2614 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/28360816

Change-Id: I2bda43ad3b6983cae7aa2e7dd4dfb836ebee226c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-18 13:08:49 +00:00
Mike Wang
ef8937f64c Add the selinux policy to allow the gril get/set vendor log properties.
avc logs:
2024-07-17 06:00:41.024 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:96): avc: denied { read } for name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=416 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0 app=com.google.android.grilservice
2024-07-17 06:00:41.024 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:97): avc: denied { read } for name="u:object_r:vendor_modem_prop:s0" dev="tmpfs" ino=418 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_modem_prop:s0 tclass=file permissive=0 app=com.google.android.grilservice
2024-07-17 06:00:49.592 8674-8674 binder:8674_1 com.google.android.grilservice W type=1400 audit(0.0:99): avc: denied { write } for name="property_service" dev="tmpfs" ino=861 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:property_socket:s0 tclass=sock_file permissive=0 app=com.google.android.grilservice

2024-07-17 16:46:54.748 1-1 /system/bin/init init I type=1107 audit(0.0:103): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=persist.vendor.verbose_logging_enabled pid=2152 uid=10238 gid=10238 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_logger_prop:s0 tclass=property_service permissive=1'
2024-07-17 16:49:33.256 1-1 /system/bin/init init I type=1107 audit(0.0:116): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=persist.vendor.modem.extensive_logging_enabled pid=2152 uid=10238 gid=10238 scontext=u:r:grilservice_app:s0:c238,c256,c512,c768 tcontext=u:object_r:vendor_modem_prop:s0 tclass=property_service permissive=1'


Bug: 293947661
Change-Id: Iec1cc221a543543da28416a5bc7d7ddacde959c5
2024-07-17 20:23:43 +00:00
Sergey Volk
fb98394c54 Add sepolicy for DisplayPort wakeup node
Bug: 348125717
Test: ls -Z /sys/devices/platform/110f0000.drmdp/wakeup
Flag: NONE (follow up fix for merged non-flagged CL pa/2839256)
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:77518a261471f7884e5b7c8ca73442df5c11e48e)
Merged-In: I9181b2344f2448b9debe1522528545ce90de8768
Change-Id: I9181b2344f2448b9debe1522528545ce90de8768
2024-07-17 14:37:46 +00:00
Mike McTernan
49c9c8c3d7 trusty: storageproxy: add fs_ready_rw property context
Flag: EXEMPT bug fix
Bug: 350362101
Test: ABTD
Change-Id: I397a89ceb5a6a832043abb3792b0101ad89c97a7
2024-07-15 10:13:47 +01:00
Aaron Tsai
489a6e7843 Add permission for setting gril property
05-22 18:20:50.608   914   914 I auditd  : type=1400 audit(0.0:97): avc:  denied  { write } for  comm="radioext@1.0-se" name="property_service" dev="tmpfs" ino=849 scontext=u:r:hal_radioext_default:s0 tcontext=u:object_r:property_socket:s0 tclass=sock_file permissive=0

Bug: 343012301
Bug: 203824024
Test: manual test
Flag: EXEMPT bugfix
Change-Id: Ic08a1e1c6a0db29e329f121c813bebadbee5a5e9
2024-07-12 03:17:06 +00:00
Liana Kazanova
7334ac44b3 [automerger skipped] Revert "Delete sepolicy for legacy VR services." am: 6b8e432e3e am: 8bb7844138 -s ours
am skip reason: Merged-In I79bc66b80c36df398fe872f4e99b86e9a828479c with SHA-1 09d569ecde is already in history. Merged-In was found from reverted change.

Reverted change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3163729

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3168500

Change-Id: I154da94bae3e3abd483c0f586820589937b424af
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-11 23:32:22 +00:00
Liana Kazanova
8bb7844138 Revert "Delete sepolicy for legacy VR services." am: 6b8e432e3e
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3168500

Change-Id: I8a7841bfc2b850111a3688b18fb11eb260fd4a40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-11 23:06:02 +00:00
Liana Kazanova
6b8e432e3e Revert "Delete sepolicy for legacy VR services."
This reverts commit 8a81e8bf61.

Reason for revert: Droidmonitor created revert due to b/352465601. Will be verifying through ABTD before submission

Change-Id: I7543fe9078e88300d12c8a09867bdd1ecf5c8005
2024-07-11 20:56:43 +00:00
PODISHETTY KUMAR
2bbbc8b955 Merge "Revert "Delete sepolicy for legacy VR services."" into main 2024-07-11 14:50:32 +00:00
PODISHETTY KUMAR
62fd727327 Revert "Delete sepolicy for legacy VR services."
This reverts commit 09d569ecde.

Reason for revert: <Droidmonitor created revert due to b/352465601. Will be verifying through ABTD before submission.>

Change-Id: Ia71e697e180b569480be9f029d9e729f42d5f855
2024-07-11 14:43:27 +00:00
Krzysztof Kosiński
2b44cfa2c1 [automerger skipped] Delete sepolicy for legacy VR services. am: 8a81e8bf61 am: e7a890e411 -s ours
am skip reason: Merged-In I79bc66b80c36df398fe872f4e99b86e9a828479c with SHA-1 09d569ecde is already in history

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3163729

Change-Id: I3aef53b57d614687bd9e20985541a2256018cdd3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-11 08:58:24 +00:00
Krzysztof Kosiński
e7a890e411 Delete sepolicy for legacy VR services. am: 8a81e8bf61
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3163729

Change-Id: I42d710d82d1e43c88df080460be760c59ba50d4f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-11 08:24:38 +00:00
Krzysztof Kosiński
8a81e8bf61 Delete sepolicy for legacy VR services.
None of the zuma devices include these services.

Bug: 234559097
Test: presubmit
Flag: EXEMPT dead code removal
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:09d569ecdeaba2951e005a713ec82bded4be234e)
Merged-In: I79bc66b80c36df398fe872f4e99b86e9a828479c
Change-Id: I79bc66b80c36df398fe872f4e99b86e9a828479c
2024-07-11 07:25:53 +00:00
Treehugger Robot
d49d60035c Merge "Delete sepolicy for legacy VR services." into main 2024-07-11 03:56:40 +00:00
Krzysztof Kosiński
09d569ecde Delete sepolicy for legacy VR services.
None of the zuma devices include these services.

Bug: 234559097
Test: presubmit
Flag: EXEMPT dead code removal
Change-Id: I79bc66b80c36df398fe872f4e99b86e9a828479c
2024-07-10 22:19:13 +00:00
Vishvam Mazumdar
c802ed6d63 Merge "Add SELinux policy to allow CPU Idle Histogram Stats in dumpstate." into main 2024-07-10 21:41:10 +00:00
Vishvam Mazumdar
1dac9a1726 Add SELinux policy to allow CPU Idle Histogram Stats in dumpstate.
This change is to allow the CPU Idle Histogram Stats to be dumped in
bugreports so that there is more insight into the idle behavior of
devices in the field.

Test: build/flash
Test: adb bugreport
Bug: 344908619
Flag: EXEMPT bugfix
Change-Id: Ic1096564423a009a0180d7f771da8184688c1842
Signed-off-by: Vishvam Mazumdar <vmazumdar@google.com>
2024-07-10 21:39:07 +00:00
Wilson Sung
ea95f2b4a4 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 350832030
Bug: 350832258
Change-Id: Idd45bcee641af96f442ec2cd4443a3964d73f429
2024-07-03 02:05:06 +00:00
Treehugger Robot
a44d754cfa Merge "Give bthal permission to read AoC version." into main 2024-06-28 05:50:59 +00:00
Madhav Iyengar
00484704f8 Give bthal permission to read AoC version.
Bug: 349661931
Flag: com.android.bluetooth.hal.flags.pixel_bt_aoc_offload_efw_xport
Test: Allows bthal to choose between USF and EFW transports to
communicate with AoC based on version.

Change-Id: I3edbcafd4ee5d0c875618c1a1c1b89e1bbd4d1ec
2024-06-28 01:15:50 +00:00
Sergey Volk
e406b07a85 Merge "Add sepolicy for DisplayPort wakeup node" into main 2024-06-28 00:30:01 +00:00
Sergey Volk
77518a2614 Add sepolicy for DisplayPort wakeup node
Bug: 348125717
Test: ls -Z /sys/devices/platform/110f0000.drmdp/wakeup
Flag: NONE (follow up fix for merged non-flagged CL pa/2839256)
Change-Id: I9181b2344f2448b9debe1522528545ce90de8768
2024-06-26 20:53:57 +00:00
Xin Li
6794f8de27 [automerger skipped] Merge 24Q3 (ab/11976889) to aosp-main-future am: 1398498663 -s ours
am skip reason: Merged-In Ief591d28aaea4223f05917d29bc896edec065613 with SHA-1 5ff76196c8 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/27908528

Change-Id: I9417fe46a2e10ad3d4231520cd43976e442835fa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-20 19:56:58 +00:00
Xin Li
1398498663 Merge 24Q3 (ab/11976889) to aosp-main-future
Bug: 347831320
Merged-In: Ief591d28aaea4223f05917d29bc896edec065613
Change-Id: I67f7818f77210af410f58ed070b0443af4dbcf56
2024-06-18 14:13:25 -07:00
Xin Li
528ffcec22 [automerger skipped] Merge Android 14 QPR3 to AOSP main am: 9af99be0b2 -s ours am: 00177acdd0 -s ours
am skip reason: Merged-In I61f611a2fcb900fcb4bb035c2abfbb19a840fddb with SHA-1 42aa8de219 is already in history

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3131996

Change-Id: I8702f8ff010a643436cbab8689384bf2e3833c86
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-18 05:56:06 +00:00
Xin Li
00177acdd0 [automerger skipped] Merge Android 14 QPR3 to AOSP main am: 9af99be0b2 -s ours
am skip reason: Merged-In I61f611a2fcb900fcb4bb035c2abfbb19a840fddb with SHA-1 42aa8de219 is already in history

Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/3131996

Change-Id: Ica9df917ccf440e316760fae33ed9beff3f7bf27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-17 20:42:11 +00:00
Xin Li
9af99be0b2 Merge Android 14 QPR3 to AOSP main
Bug: 346855327
Merged-In: I61f611a2fcb900fcb4bb035c2abfbb19a840fddb
Change-Id: I01a531331e180880cca379ac6f4b6199f2bebd5e
2024-06-13 10:49:16 -07:00
Cheng Chang
7969077e3b gps: Move hal_gnss_pixel declaration to device folder am: 5ff76196c8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/27576137

Change-Id: Ic16f628926a47350f0e0caf7293e1cfa4521a7fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-12 07:27:17 +00:00
Cheng Chang
5ff76196c8 gps: Move hal_gnss_pixel declaration to device folder
Bug: 343280252
Test: b/343280252 compile and abtd test
Change-Id: Ief591d28aaea4223f05917d29bc896edec065613
2024-06-11 06:23:21 +00:00