Commit graph

36 commits

Author SHA1 Message Date
Adam Shih
4c3622d25a Merge "use gs-common insert module script" 2022-09-12 05:40:56 +00:00
Jeffrey Carlyle
55c282ab71 Merge "dck: allow st54spi devivce to be accessed by recovery and fastbootd" 2022-09-08 21:58:56 +00:00
Adam Shih
0ddf6e577f use gs-common insert module script
Bug: 243763292
Test: boot to home
Change-Id: Idbac83716d0eaca0b9806db901aea68bffd32f4b
2022-09-08 09:57:29 +08:00
TreeHugger Robot
5a314cab17 Merge "Add SE policies for HWC logs" 2022-09-07 12:28:32 +00:00
Jeffrey Carlyle
48422cd1ff dck: allow st54spi devivce to be accessed by recovery and fastbootd
This is needed so that Digital Car Keys can be cleared from the ST54
during a user data wipe.

Bug: 203234558
Test: data wipe in Android recovery mode on raven
Test: data wipe in Android recovery mode on c10
Test: data wipe in user mode fastbootd mode on raven
Test: data wipe in user mode fastbootd mode on c10
Signed-off-by: Jeffrey Carlyle <jcarlyle@google.com>
Change-Id: I5e1e8248ba188a68dd3c97795958e74e233701b9
2022-09-01 22:49:44 -07:00
Adam Shih
d13d0aaf56 Move dauntless settings to gs-common
Bug: 242479757
Test: build pass on all Gchip devices
Change-Id: I4b6c011015f6b94b5329650eb82ec5b95bbe2040
2022-08-30 13:32:02 +08:00
Taehwan Kim
8d9dc3aa30 sepolicy: supports Codec2 HIDL 1.2
Bug: 238360304
Test: Build PASS
Signed-off-by: Taehwan Kim <t_h.kim@samsung.com>
Change-Id: Id02e834bc4c19b09fac6c71199e2b0d62ddb4fd6
2022-08-22 05:31:08 +00:00
Wiwit Rifa'i
dee1f2e57d Add SE policies for HWC logs
Bug: 230361290
Change-Id: Ibca7f791bc4950bb6c1e4fd7ed5cbe5a98b48a5e
2022-08-16 14:02:21 +08:00
TreeHugger Robot
d8b62a3663 Merge "fix avc error for fg_model/registers" 2022-08-06 02:30:14 +00:00
TreeHugger Robot
4ba5c9ddf4 Merge "sepolicy:allow tof driver to communicate with lwis" 2022-08-03 06:56:32 +00:00
TreeHugger Robot
1d57ee38c7 Merge "HwInfo: Move hardware info sepolicy to pixel common" 2022-08-03 02:57:30 +00:00
Bruce Po
de8bc09743 Allow aocd to access acd-offload nodes
For T6 3-ch hotword feature, aocd daemon will access two new file nodes
(b/235648212), which will be used for transmitting audio to/from AOC.

BUG: 240744178
Change-Id: I98500d03e88052824af91c81ddeb9ed20f616969
2022-07-30 00:24:30 +00:00
Denny cy Lee
e286313bbd HwInfo: Move hardware info sepolicy to pixel common
Bug: 215271971
Test: no sepolicy for hardware info
Change-Id: If1b556c07a9a908b1a3edd8a551ff80cbc290b18
Signed-off-by: Denny cy Lee <dennycylee@google.com>
2022-07-29 02:56:01 +00:00
Tri Vo
82967d3579 Merge "tee: Remove tracking_denials/tee.te" 2022-07-27 17:24:21 +00:00
TreeHugger Robot
9be3188259 Merge "Remove vendor_service." 2022-07-27 11:12:43 +00:00
Jenny Ho
782f4952ff fix avc error for fg_model/registers
remove tracking with fix http://ag/19446314

Bug: 226271913
Signed-off-by: Jenny Ho <hsiufangho@google.com>
Change-Id: I745654dea17f87df0956f3a326d0c0346fd59ec6
2022-07-27 06:16:43 +00:00
Nick Chung
1b68580017 sepolicy:allow tof driver to communicate with lwis
Bug: 236828170
Test: build pass
Change-Id: I4300e025d987795e8fab3f0c1a3cb604e066b44c
2022-07-27 04:52:06 +00:00
Steven Moreland
5d26e2ecc1 Remove vendor_service.
We want to avoid associating types with where they can be used.

Bug: 237115222
Test: build
Change-Id: I6795d960aa2a3b3832be8e0f6a11cb0fc3337982
2022-07-27 00:01:46 +00:00
Tri Vo
6aa0b46766 tee: Remove tracking_denials/tee.te
Bug: 215649571
Bug: 205904330
Test: n/a
Change-Id: I8bdc6448420bb6a01093b315e99d420b4e5e040f
2022-07-26 13:26:00 -07:00
George Chang
e53e44b561 Update nfc from hidl to aidl service
Bug: 240125555
Test: build pass
Change-Id: Icfe2d117e0058d3dd8552defc27d5d20baaf9910
2022-07-26 06:39:49 +00:00
Cheng Chang
38e5c8d796 gps: change SEPolicy for sysfs node
Test: gps group has r/w permission
Bug: 238583504
Signed-off-by: Cheng Chang <chengcha@google.com>
Change-Id: I679999bdbb3cbcb0ffe9b49f4aa00d8714674da9
2022-07-20 06:51:48 +00:00
Robin Peng
dbd71b58f5 init-insmod-sh: fix avc error
avc: denied { set } for property=vendor.all.modules.ready pid=1238 uid=0 gid=0 scontext=u:r:init-insmod-sh:s0 tcontext=u:object_r:vendor_ready_prop:s0 tclass=property_service permissive=0

Bug: 238853979
Signed-off-by: Robin Peng <robinpeng@google.com>
Change-Id: I92aa94db50884ea6d499fad785ef49853d831f56
2022-07-18 04:55:14 +00:00
qinyiyan
7efce53e84 Fix build breakage. Remove debug_camera_app.te as it's not defined.
ERROR 'unknown type debug_camera_app' at token ';' on line 83026:
        allow debug_camera_app edgetpu_app_service:service_manager find;

bug: 238929529
Test: make selinux_policy -j128
Change-Id: Ia8a21d02bff5c2f0c62e333b6b800678a80a2c51
2022-07-13 17:18:37 -07:00
qinyiyan
b11f8d2103 Add edgetpu contexts and sepolicies.
bug: 236041918
Change-Id: Ie3d2833c3c297dad7304dca307778d2f6a155180
2022-07-12 15:24:20 -07:00
TreeHugger Robot
6de977c9ba Merge "HwInfo: remove -sepolicy/tracking_denials/hardware_info_app.te" 2022-07-06 01:24:09 +00:00
Ruofei Ma
f85ab24233 Merge "Add bigwave sepolicy" 2022-07-05 22:25:05 +00:00
Ruofei Ma
1afbff1320 Add bigwave sepolicy
Bug: 195687338

Change-Id: I8dae1b62b0516e173381893af3c90ae24b6b9b87
2022-07-05 22:24:35 +00:00
Denny cy Lee
d05407421d HwInfo: remove -sepolicy/tracking_denials/hardware_info_app.te
Bug: 208909060
Test: not avc log for hardware_info_app
Signed-off-by: Denny cy Lee <dennycylee@google.com>
Change-Id: I0678da7b9495e87130553fd967fc26015c3161e4
2022-07-04 03:18:06 +00:00
Hyunki00.koo
47c4e6c965 edgetpu/file_contexts
Signed-off-by: Hyunki00.koo <hyunki00.koo@samsung.com>
Change-Id: I6dfa880a0d4ceb80a54de24e3817b6c880fea7ba
2022-06-30 19:59:41 -07:00
Jaegeuk Kim
c36c283704 Update ufs path
Signed-off-by: Jaegeuk Kim <jaegeuk@google.com>
Change-Id: I8ea66435e131c7718ea5d2740fa8165d452f68f9
2022-06-24 00:03:00 -07:00
Nucca Chen
7ad5cc4d73 Remove clatd tracking_denial
Bug: 210363983
Change-Id: I5ee6763d73a82cc4ffe21270544eb68810be626c
Test: boot with no relevant error log
2022-06-13 07:19:36 +00:00
Jaegeuk Kim
28cec159fb Allow sysfs_devices_block to f2fs-tools
The fsck.f2fs checks the sysfs entries of block devices to get disk
information. Note that, the block device entries are device-specific.

1. fsck.f2fs
avc: denied { search } for comm="fsck.f2fs" name="0:0:0:0" dev="sysfs" ino=59803 scontext=u:r:fsck:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0
avc: denied { getattr } for comm="fsck.f2fs" path="/sys/devices/platform/14700000.ufs/host0/target0:0:0/0:0:0:0/block/sda/sda7/partition" dev="sysfs" ino=60672 scontext=u:r:fsck:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

2. mkfs.f2fs
avc: denied { search } for comm="make_f2fs" name="0:0:0:0" dev="sysfs" ino=59803 scontext=u:r:e2fs:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0
avc: denied { getattr } for comm="make_f2fs" path="/sys/devices/platform/14700000.ufs/host0/target0:0:0/0:0:0:0/block/sda/sda8/partition" dev="sysfs" ino=61046 scontext=u:r:e2fs:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

Bug: 172377740
Signed-off-by: Jaegeuk Kim <jaegeuk@google.com>
Change-Id: I409feec84565f965baa96b06a5b08bcfc1a8db02
2022-05-24 17:46:40 -07:00
Jason Macnak
d14bd06f34 Remove sysfs_gpu type definition
... as it has moved to system/sepolicy.

Bug: b/161819018
Test: presubmit
Change-Id: I107f92617bea56590b5af351341cc1c3b2844360
2022-04-19 18:03:57 +08:00
Aaron Ding
7b5994afd8 Create device Ripcurrent on Zuma platform
s/cloudripper/ripcurrent
s/gs201/zuma
s/pantah/ripcurrent

Bug: 229340586
Change-Id: If94759d6d555f3f9c8ee80331a31ef85082f03c7
Signed-off-by: Aaron Ding <aaronding@google.com>
2022-04-19 14:11:17 +08:00
Aaron Ding
e47b3d9991 Branch zuma from gs201
Branch zuma from gs201 sha1 63751751aa91275b083797278d638078b3a0bf7a

cp/pantah/ripcurrent
cp/gs201/zuma

Bug: 229340586
Change-Id: Ie692d8dbbf0fc4d3b376dc9fe3e930bd3955a88e
Signed-off-by: Aaron Ding <aaronding@google.com>
2022-04-19 14:10:58 +08:00
Bill Rassieur
e4a3061192 Initial empty repository 2022-03-15 09:21:45 -07:00