Chungkai Mei
97f5b3c87a
Remove dontaudit since read early_wakeup completed
...
The display file node, early_wakeup, just for trigger the worker for
display and it doesn't have meaningful read function. But PowerHAL read
all nodes and try to dump their valuesi while triggering bugreport. As
the read operation has been completed, so we can remove the clause.
07-02 00:53:56.888 522 522 W android.hardwar: type=1400 audit(0.0:8): avc: denied { dac_read_search } for capability=2 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0
07-02 00:53:56.888 522 522 W android.hardwar: type=1400 audit(0.0:9): avc: denied { dac_override } for capability=1 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0
Bug: 267261305
Test: Boot to home
Change-Id: I6c058a1a85ada7e5d6eb1f8acafaac8231ae5329
Merged-In: I6c058a1a85ada7e5d6eb1f8acafaac8231ae5329
Signed-off-by: Chungkai Mei <chungkai@google.com>
(cherry picked from commit 55d41f1a3e89b1f4d2525d9925e3319ef59e2705)
(cherry picked from commit 1d966a0db9
)
2023-04-24 17:21:53 +00:00
Treehugger Robot
c84559a813
Merge changes from topic "260522202" into udc-d1-dev
...
* changes:
Remove untraceable rules
Enforce installd
2023-04-21 03:45:54 +00:00
Treehugger Robot
a8fe91bc3c
Merge "Remove hal_uwb_default bug from bug_map" into udc-d1-dev
2023-04-21 03:08:00 +00:00
Wilson Sung
dc75da30a1
Revert^2 "Enforce priv_app"
...
This reverts commit 61a95fc71a
.
Fix: 260522282
Change-Id: I0d5dd994d3acacfee854ae27669358cfc2c249fc
2023-04-20 00:14:18 +08:00
Rex Lin
814652dc6d
Remove hal_uwb_default bug from bug_map
...
SELinux errors are fixed and hence removing from bug map
Bug: 273639365
Test: Build and boot on device
Change-Id: I3a1ad3066840b507553b9365239673f6126b8ec6
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-04-19 14:54:11 +08:00
Wilson Sung
7ebc1ab0d5
Enforce installd
...
Fix: 260522202
Fix: 264490035
Test: Boot-to-home, no avc error
Change-Id: I2ec5a2771c53dcc520a2ea229f093d354b5c80fd
2023-04-19 12:41:35 +08:00
Alan Chen
c1f8b7a872
Merge "Remove dontaudit for hal_radioext_default to service_manager." into udc-d1-dev
2023-04-19 03:04:57 +00:00
Treehugger Robot
16f461a2cf
Merge "Enforce sepolicy for camera HAL." into udc-d1-dev
2023-04-18 23:18:00 +00:00
Dave Mankoff
633f19376e
Merge "Give SystemUI access to necessary selinux properties." into udc-d1-dev
2023-04-18 17:50:42 +00:00
Jonglin Lee
8da235e022
Merge "Revert "Enforce priv_app"" into udc-d1-dev
2023-04-18 17:50:13 +00:00
Jonglin Lee
61a95fc71a
Revert "Enforce priv_app"
...
This reverts commit af0ad04c3c
.
Reason for revert: RescueParty crash due to com.shannon.rcsservice crash
Bug: 278735899
Change-Id: I5bf91b077c23c63de728657bd9adb5623b708d95
2023-04-18 17:41:27 +00:00
Alan Chen
63f54f0a3a
Remove dontaudit for hal_radioext_default to service_manager.
...
The fix has been merged in the topic of ag/21956466 so this dontaudit line can be removed.
Test: manual
Bug: b/275646098
Change-Id: I95c25ffc926e48e589b7636beca1bef9583861d0
2023-04-18 17:47:09 +08:00
Krzysztof Kosiński
3f0d2fc09d
Enforce sepolicy for camera HAL.
...
Bug: 264489778
Test: GCA smoke test on Zuma device
Change-Id: Icaa7c94ab264d496840d33d970e5a87123b31c36
2023-04-18 09:02:32 +00:00
Treehugger Robot
4d7b687f9d
Merge "Enforce priv_app" into udc-d1-dev
2023-04-17 16:56:56 +00:00
Dave Mankoff
78b9dcdb69
Give SystemUI access to necessary selinux properties.
...
Other errors mentioned in the bugs are already absent.
Fixes: 269964574
Fixes: 272628396
Fixes: 272628174
Test: built and flash device. No selinux errors printed.
Change-Id: Ic285b1f5a2ce6973899011a7c6a596e807c3e933
2023-04-17 14:28:59 +00:00
Treehugger Robot
9ea22dde19
Merge "Enforce servicemanager" into udc-d1-dev
2023-04-14 03:53:11 +00:00
Wilson Sung
af0ad04c3c
Enforce priv_app
...
Fix: 260366281
Fix: 260522282
Fix: 260768358
Fix: 260922442
Fix: 263185432
Fix: 264490074
Fix: 268572216
Change-Id: I2efbb1971c09506a7b1e0e5e0e3d22eda91018c1
2023-04-14 03:34:46 +00:00
TreeHugger Robot
89d4a4df13
Merge "Suppress bootanim behavior meant for Android Wear devices" into udc-d1-dev
2023-04-14 03:19:53 +00:00
Treehugger Robot
2ac0374b22
Merge changes Ie20be0af,Id9a80c47 into udc-d1-dev
...
* changes:
Enforce rebalance_interrupts_vendor
Enforce hwservicemanager
2023-04-14 03:18:10 +00:00
Yixuan Wang
1095231e38
Add hal_contexthub_default to zuma sepolicy; Remove dontaudit rules for
...
chre
[ 7.760870] type=1400 audit(1669944054.440:61): avc: denied { write } for comm="android.hardwar" name="chre" dev="tmpfs" ino=1099 scontext=u:r:hal_contexthub_default:s0 tcontext=u:object_r:chre_socket:s0 tclass=sock_file permissive=1
[ 12.519414] type=1400 audit(1669944059.196:138): avc: denied {connectto } for comm="android.hardwar" path="/dev/socket/chre"scontext=u:r:hal_contexthub_default:s0 tcontext=u:r:chre:s0 tclass=unix_stream_socket permissive=1
Bug: 264489794
Bug: 261105224
Test: atest scanAvcDeniedLogRightAfterReboot
Change-Id: I7bf13913188deedc987f82e54626a18357ab84c5
2023-04-13 06:43:41 +00:00
Wilson Sung
3df3008917
Suppress bootanim behavior meant for Android Wear devices
...
Fix: 260522279
Test: boot-to-home and no bootanim avc error
Change-Id: I29d4168720887bc2f90d5f7ad20367887f9cae51
2023-04-13 00:00:38 +00:00
Wilson Sung
5468e420e3
Enforce rebalance_interrupts_vendor
...
Fix: 264489565
Test: boot-to-home
Change-Id: Ie20be0afe1a95b8cb512b57019539eb52948a155
2023-04-12 22:58:13 +08:00
Wilson Sung
90f838f16f
Enforce hwservicemanager
...
Test: boot-to-home and no avc error
Fix: 264489781
Change-Id: Id9a80c478a2eae8472023f3bbcc514f30f5bfbab
2023-04-12 22:32:46 +08:00
Wilson Sung
527f215d20
Enforce servicemanager
...
Fix: 263429985
Fix: 264489962
Test: boot-to-home, no avc error
Change-Id: Ib3b0916bdbd09638f5b7b34f2d214690eed314ab
2023-04-12 22:14:16 +08:00
Wilson Sung
c2eedff70c
Add recovery related policy
...
Fix: 275143841
Fix: 264490092
Test: adb sideload and no avc error
Change-Id: I52003c9417560a6c5dab815a6929681710f0b0a4
2023-04-12 03:46:54 +08:00
Adam Shih
e188582ba8
remove obsolete entries
...
Bug: 264483390
Bug: 272166771
Bug: 264482983
Bug: 264600086
Bug: 264482983
Bug: 273638940
Test: adb bugreport
Change-Id: Ia89c409a20e6a4514c57389f82c57d8c265f1e81
2023-04-11 11:23:17 +08:00
Adam Shih
e5e6273048
enforce gmscore_app
...
Bug: 259302023
Test: boot with no relevant errors
Change-Id: I61cb95224096dbc999bc3c8051a4e4c6ad700522
2023-04-10 11:13:21 +08:00
Treehugger Robot
8da223020e
Merge "Revert "Revert "Enforce system ui app""" into udc-d1-dev
2023-04-07 10:04:20 +00:00
Gina Ko
bb27434f22
Revert "Revert "Enforce system ui app""
...
This reverts commit eeeae0265a
.
Reason for revert: b/274366326 was fixed
Change-Id: I9d9c4f4dd831aa80109cc53790f6b6491133fb42
2023-04-07 08:46:00 +00:00
Wilson Sung
f2d0dbb66a
update error on ROM 9900526
...
Bug: 277155496
Bug: 277300017
Bug: 277300125
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I2a2f230589695b0240abb26909c94fd4cf2420bf
2023-04-07 14:43:36 +08:00
Dinesh Yadav
d9a75c1639
Merge "Allow google_camera_app to access edgetpu" into udc-d1-dev
2023-04-06 02:34:35 +00:00
Sayanna Chandula
387145ed85
Remove hal_thermal_default bug from bug_map
...
SELinux errors are fixed and hence removing from bug map
Bug: 272166987
Test: Build and boot on device
Change-Id: Ic0d314486a2ed6fbc1c4497b122827b17f5b9022
Signed-off-by: Sayanna Chandula <sayanna@google.com>
2023-04-05 22:26:40 +00:00
Dinesh Yadav
478b11708f
Allow google_camera_app to access edgetpu
...
These permissions are needed by GCA-release & GCA-dogfood to access
edgetpu.
Bug: 264490031
Change-Id: Idd9dff906c86f9e83f1dc67698c23387e174d99c
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-04-04 06:11:47 +00:00
Donnie Pollitz
885a790f2d
Add logd selinux allow permissions
...
Bug: 261105354
Bug: 264489639
Test: Ran atest SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I377dbb3bbdecd6780c1bdfb3aab53ee3c754c163
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-29 09:24:47 +02:00
Wilson Sung
5227dfe6ab
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 275646098
Test: scanBugreport
Bug: 275646003
Test: scanAvcDeniedLogRightAfterReboot
Bug: 275645636
Change-Id: Iedd660e3937792d5ac58f384605300b39f6dfcb0
2023-03-29 12:17:48 +08:00
Gina Ko
5821d671f3
Merge "Allow systemui to find cameraserver_service" into udc-d1-dev
2023-03-27 05:32:14 +00:00
Neo Yu
58ff635b67
Remove the bug of hal_radioext_default because the fix is merged.
...
Bug: 274374768
Test: verify by test rom
Change-Id: Ia9665e5223997cf498f9320dfd0b1dbdacaae0b2
2023-03-27 11:08:25 +08:00
Gina Ko
ce85639700
Allow systemui to find cameraserver_service
...
avc: denied { find } for pid=2435 uid=10235 name=media.camera
scontext=u:r:systemui_app:s0:c235,c256,c512,c768
tcontext=u:object_r:cameraserver_service:s0 tclass=service_manager permissive=0
Bug: 272628174
Bug: 269964574
Bug: 274734888
Test: Manual. Able to turn on/off flashlight from QS.
Change-Id: Icedf70b06bd06eb5b819a00c9157b4f475e9a126
2023-03-25 00:18:23 -07:00
TreeHugger Robot
b5a5ffb5e7
Merge "Update SELinux error" into udc-d1-dev
2023-03-24 05:07:42 +00:00
Darren Hsu
2965ba405c
sepolicy: remove power stats from bug map
...
Bug: 272166847
Test: N/A
Change-Id: If920d18418f87f14a1826dbe061cef4632a9646f
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-24 11:43:42 +08:00
Wilson Sung
599f4f5382
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 275001641
Test: scanBugreport
Bug: 268566481
Test: scanAvcDeniedLogRightAfterReboot
Bug: 268566481
Change-Id: I5a7ea66483985b6ca99162666d155fef69d65360
2023-03-24 11:11:17 +08:00
Darren Hsu
128550da69
Merge "Revert "Enforce system ui app"" into udc-d1-dev
2023-03-24 00:48:36 +00:00
Dave Mankoff
eeeae0265a
Revert "Enforce system ui app"
...
This reverts commit ba953cdb9a
.
Reason for revert: http://b/274366326#comment22 . We can check this back in once we know what's going on.
Bug: 274366326
Bug: 264266705
Change-Id: I879cdec377e71af9142c82078bd3c022295c98c5
2023-03-23 19:44:22 +00:00
Darren Hsu
8e028f0a03
sepolicy: label odpm paths for system suspend
...
Bug: 272166423
Test: run singleCommand pts -m PtsSELinuxTestCases
Change-Id: I0295cc09cd8eb46b19edcec0d74440e497440423
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-23 14:13:43 +08:00
TreeHugger Robot
0b1499354d
Merge "Enforce bootdevice_sysdev" into udc-d1-dev
2023-03-23 03:36:47 +00:00
TreeHugger Robot
75b82f7092
Merge "Enforce systesm_app" into udc-d1-dev
2023-03-23 03:32:48 +00:00
TreeHugger Robot
a8dfe1fd3c
Merge "Update SELinux error" into udc-d1-dev
2023-03-23 03:27:12 +00:00
Welly Hsu
e0adad9eb0
Remove euiccpixel_app dontaudit from gmscore_app am: a133586e4e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22188469
Change-Id: I48f0e1eb633c44a4c6445c6423d10e500be6f6c7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-22 14:41:23 +00:00
Wilson Sung
6bf3029916
Enforce systesm_app
...
Fix: 260768379
Fix: 260922048
Fix: 264490076
Test: boot-to-home, no related avc error
Change-Id: If9ead09340f5d810ec549f4c83015f3301f1113c
2023-03-22 16:01:09 +08:00
Wilson Sung
a1739828f2
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 274727372
Bug: 274727542
Test: scanBugreport
Bug: 274727542
Bug: 268566481
Test: scanAvcDeniedLogRightAfterReboot
Bug: 274727542
Bug: 268566481
Change-Id: Ie846f2f7146e52c4e094d9fd7cfa1fa68e3e21df
2023-03-22 15:38:52 +08:00