Commit graph

2109 commits

Author SHA1 Message Date
Daniel Chapin
6a6f65b5e5 Merge "Revert "Allow dump_power to read directories under "/sys/class/p..."" into main 2024-01-25 22:59:25 +00:00
Daniel Chapin
a5df4f07bf Revert "Allow dump_power to read directories under "/sys/class/p..."
Revert submission 25915320-320613177

Reason for revert: Droidfood blocking bug: 322294676

Reverted changes: /q/submissionid:25915320-320613177

Change-Id: I5545dcd73cdce5ae029444c313bf5dc3f642a5c0
2024-01-25 21:44:18 +00:00
Angela Wu
b042c7713f [automerger skipped] Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device am: 3b30421350 -s ours
am skip reason: Merged-In If77a097b4ca823322ef41b13d6283390dac69d6c with SHA-1 0d32d1c172 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25983001

Change-Id: I5424ea5b92ff1b9bff957b86bfabf6dccb766f22
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-25 02:19:53 +00:00
Treehugger Robot
ab46db5fef Merge "Add capacity_headroom to gpu sysfs" into main 2024-01-24 23:30:45 +00:00
Sean Callanan
d7decd5eee Add capacity_headroom to gpu sysfs
This allows userspace (notably the power HAL) to apply a boost to GPU
frequency independent of previously measured load.

Bug: 290625326
Test: boot, run modified Power HAL
Change-Id: Ia71266ee751a36a960706ac8aacc7fdefdf8a0f0
2024-01-24 21:46:23 +00:00
Angela Wu
3b30421350 Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device
Bug: 320410642
Test:m
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0d32d1c172c19186a7ac4fd3eb316a9b947d612d)
Merged-In: If77a097b4ca823322ef41b13d6283390dac69d6c
Change-Id: If77a097b4ca823322ef41b13d6283390dac69d6c
2024-01-24 09:47:42 +00:00
Wilson Sung
abb7616f3d Merge "Update Tracking Denial Bug Map" into main 2024-01-24 07:56:49 +00:00
Imo Richard Umoren
770a65f4a9 Update Tracking Denial Bug Map
Removes tracking denial for twoshay from bug map

Bug: b/315104941
Test: Manually tested on HK3 DVT
Change-Id: I6cd8f390e98fc98925ed807a2ff24a33c51c75cd
2024-01-22 18:32:09 +00:00
Kyle Tso
4e48a45727 Allow dump_power to read directories under "/sys/class/power_supply"
Bug: 320613177
Change-Id: I1a39ddb5fbbf4c62fa5b96e3562b34f2f2091c13
Signed-off-by: Kyle Tso <kyletso@google.com>
2024-01-22 08:52:59 +00:00
Wilson Sung
2d8e52e176 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 320693841
Change-Id: Ia3ffe885f02a8db86d6bd024d34135fd1ce30d7b
2024-01-17 17:42:53 +00:00
Angela Wu
740cebf8f0 Merge "Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device" into main 2024-01-17 00:32:01 +00:00
Wilson Sung
148d3558f8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 319403445
Change-Id: I470afdd191741401c197ae32bfff18e9d8b90a96
2024-01-16 19:20:02 +00:00
Angela Wu
0d32d1c172 Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device
Bug: 320410642
Test:m

Change-Id: If77a097b4ca823322ef41b13d6283390dac69d6c
2024-01-16 08:51:05 +00:00
Treehugger Robot
feffef59dd Merge "Allow Powerstats service to access refresh rate residency node" into main 2024-01-15 01:24:29 +00:00
Midas Chien
d6e79769c1 Allow Powerstats service to access refresh rate residency node
Bug: 315424658
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I86288b4f523b4463a46d710a6556fa6852d4bea0
2024-01-12 13:01:17 +00:00
Mahesh Kallelil
389a451f8f Merge "Remove modem_svc selinux error from denials bug_map" into main 2024-01-12 06:43:44 +00:00
Mahesh Kallelil
1d8bcd694b Remove modem_svc selinux error from denials bug_map
This property was removed and is not being used anymore. So
modem_svc will not need to read it.

Bug: 316816737
Change-Id: Iaee56d15ca69e91fe952eaa188d3aaec69edf5dc
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2024-01-11 09:48:44 -08:00
Inseob Kim
80e1b3708f Label dtbo_block_device with flag-guarding am: 0c15160cad am: f817f9b687 am: bd1ea77736
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I445a175dd8daabc19da05f9d08690955d836f21c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 04:07:09 +00:00
Inseob Kim
bd1ea77736 Label dtbo_block_device with flag-guarding am: 0c15160cad am: f817f9b687
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I88784ab20f5e4a4c97000784e426a446a769777c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 03:02:37 +00:00
Inseob Kim
f817f9b687 Label dtbo_block_device with flag-guarding am: 0c15160cad
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I0f245e7f165401304b99d07ef7c064d9d86f0a74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 02:31:13 +00:00
Inseob Kim
64fd14fdd8 Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c am: 478449e638 am: 93607ec24a
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: I9b7a68fd405327f22a08b9ba8759a45ee51a8b35
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 10:55:30 +00:00
Inseob Kim
93607ec24a Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c am: 478449e638
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: Ib54efad23c80ce27e140270759cada42332dd77b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 10:24:49 +00:00
Inseob Kim
478449e638 Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: If197a913485f18554bf650c37c85911afa00a804
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 09:54:32 +00:00
Inseob Kim
0c15160cad Label dtbo_block_device with flag-guarding
Bug: 319035582
Test: run device assignment demo
Change-Id: I813be88391c9ff79d94e504149963160f1d74b2c
2024-01-10 17:02:34 +09:00
Inseob Kim
f05143f43c Revert "Label dtbo partition as dtbo_block_device"
This reverts commit 3773ca269e.

Reason for revert: b/319035582

Bug: 319035582
Test: boot
Change-Id: I3c2a5b5bc871aa506396c12d6e1fa036858c1273
2024-01-10 17:02:14 +09:00
Ken Yang
137c2ebd5a selinux: label wakeup for BMS I2C 0x36, 0x69
Bug: 319035561
Change-Id: Ib57dba71691f70b75fbae23208125fa750b32dc1
Signed-off-by: Ken Yang <yangken@google.com>
2024-01-10 06:14:37 +00:00
Lei Ju
52beafc4c4 [zuma] Use common settings for Contexthub HAL
Test: compilation
Bug: 248615564
Change-Id: I6691b23af6e532584f4dee9618c264b20b8873c0
2024-01-07 20:10:59 -08:00
Aaron Tsai
8b02313642 Remove tracking for b/316991604.
- no need to fix, so just remove the tracking record

Bug: 316991604
Test: manual test
Change-Id: Ifa70774650d3beaed5abd57297a3372f8d33661e
2024-01-08 02:58:11 +00:00
Treehugger Robot
d8c8e6f873 Merge "face: remove tracking for 305600857" into main 2024-01-08 01:06:39 +00:00
Nicole Lee
a03af7a36c Allows modem_svc to read the logging related properties am: 93020c0564 am: 8749626448
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I7934a5ed2936e9f42ed022fa1853974cab5019a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 01:00:09 +00:00
Nicole Lee
8749626448 Allows modem_svc to read the logging related properties am: 93020c0564
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I0f55efc6a18dd8e863debeaf47e32c67fbfdd6c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 00:29:58 +00:00
Nicole Lee
93020c0564 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
(cherry picked from commit 728e6baa64)
2024-01-05 04:40:14 +00:00
Ilya Matyukhin
0e9173dfa2 face: remove tracking for 305600857
The policy was fixed in:
Ia8e4599e7cd44c815e88a34ee7d9229a3391b598

Bug: 305600857
Test: adb logcat | grep "avc:"
Change-Id: I831acc083c118ca35d095d040aedcd9b85cfb3a5
2024-01-04 22:23:16 +00:00
Treehugger Robot
b808c32b7d Merge "Allows modem_svc to read the logging related properties" into main 2024-01-04 10:09:18 +00:00
Nicole Lee
728e6baa64 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
2024-01-02 08:50:36 +00:00
Kiyoung Kim
0d7dcca863 Remove SELinux error from b/313804706
Remove SELinux error from b/313804706 as the issue is solved now.

Bug: 313804706
Test: No selinux denial error from boot with husky-trunk_staging-userdebug build
Change-Id: I19c7fba663abac4d180b6a144f0aff5d108806f6
2024-01-02 04:30:16 +00:00
Jasmine Cha
839ddde474 audio: remove denials list for dcservice
Bug: 299553227
Test: boot to home with test build b/299553227#comment8

Change-Id: I9ee23a9aa753d891d233e337908c2091d63f3834
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-12-28 05:10:34 +00:00
Lei Ju
5a4795ccd7 Merge "[zuma] Update chre sepolicy for socket connection" into main 2023-12-28 03:50:00 +00:00
Ján Sebechlebský
26b57fcdc6 Merge "Remove bug_map entry for dumpstate <-> virtual_camera" into main 2023-12-27 15:31:07 +00:00
Jan Sebechlebsky
76ea521186 Remove bug_map entry for dumpstate <-> virtual_camera
The denial was fixed in aosp/2852613.

Bug: 312894238
Test: N/A
Change-Id: I3121489729e23afa10904cb97f547e965e0c68f4
2023-12-27 14:04:36 +01:00
Lei Ju
8587126f45 [zuma] Update chre sepolicy for socket connection
With multiclient HAL, the socket server domain changes from chre to
hal_contexthub_default.

Bug: 248615564
Test: updated the sepolicies and observed that avc violation logs
      disappears.
Change-Id: I4b2d27b436c9d81bd0d0cdc5b3c1540884c37fec
2023-12-27 00:02:57 -08:00
timtmlin
404089ca94 Remove obsolete entries
Bug: 315720601
Bug: 315720874
Test: make
Change-Id: I538c76e009c6d29c9d2cac39778decc679446906
2023-12-27 15:23:58 +08:00
Wilson Sung
5b30dbfbb3 Allow SysUI to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui_app the write access to
  wm_trace_data_file

Bug: 251513116
Fix: 288049075
Test: make sepolicy
Change-Id: Ifa5a5281c6e8c7ecedcd601fc8cc58c4be6bdc3b
2023-12-27 11:01:12 +08:00
Shiyong Li
569134db41 Merge "display: support primary display preferred mode property" into main 2023-12-22 19:54:46 +00:00
Chi Zhang
f965c0b222 Merge "Allow GRIL to get power stats." into main 2023-12-22 19:29:06 +00:00
Kadi Narmamatov
09c85a0567 Merge "rfsd: add new property to sepolicy" into main 2023-12-22 09:10:49 +00:00
Shiyong Li
d26ab660b8 display: support primary display preferred mode property
Bug: 315895938
Test: check default mode after factory reset
Change-Id: Ia5a4c12537d50faf54ed5ea82d24e52a623c34e3
Signed-off-by: Shiyong Li <shiyongli@google.com>
2023-12-21 20:12:45 +00:00
Wilson Sung
79ba49730b Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317316633
Change-Id: I8c1b97d6c65ec06e0a13e1447538f7cebf21d962
2023-12-21 07:37:01 +00:00
kadirpili
5c28db1f6b rfsd: add new property to sepolicy
Bug: 307481296
Change-Id: Icd287f863fd6d309297ce984f4ce387fb5d3ae24
2023-12-20 07:27:32 +00:00
Chi Zhang
a2e8969139 Allow GRIL to get power stats.
SELinux : avc:  denied  { find } for pid=3147 uid=10219 name=android.hardware.power.stats.IPowerStats/default scontext=u:r:grilservice_app:s0:c219,c256,c512,c768 tcontext=u:object_r:hal_power_stats_service:s0 tclass=service_manager permissive=1

Bug: 286187143
Test: build and boot
Change-Id: I6df25e78ba8fa8efaa7f51aed8e981ac382dcd29
2023-12-19 12:22:08 -08:00