Commit graph

2109 commits

Author SHA1 Message Date
John Chang
85d45d6776 display: properties of vrr settings
Bug: 290843234
Test: verify getprop/setprop after reboot.
Change-Id: I1ff2b7069f0e6a5a9aef6ac2f6ac6d89b457dcc3
2023-09-18 14:19:11 +00:00
Wilson Sung
488d348114 Merge changes from topic "b299029620_cleanup" into main
* changes:
  Relocate common tracking denial entries
  Remove obsolete entries
2023-09-18 02:54:32 +00:00
yixuanwang
0a4d3c2f89 Add selinux policy for chre vendor data directory
Bug: 278114604
Test: on device test
Change-Id: I33d1e73a375c86602ce632665fe96c5876347c52
2023-09-16 02:51:45 +00:00
Yixuan Wang
eae42fd8f4 Merge changes from topic "am-1b65f256ed6d44cb931295968c81bde7" into udc-qpr-dev-plus-aosp am: 284bdc3fa5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I7806e779a085c025de63d728eb0c52340db9612d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 20:07:37 +00:00
Yixuan Wang
43f05a7e41 [automerger skipped] Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76 am: b02946bca9 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I0a663d71d92d175823b7878aa37b6c032471cf58
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 20:07:34 +00:00
Yixuan Wang
ca2ba97013 [automerger skipped] Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76 am: 0603f723f4 -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I6e7230b804267bea465fb976bfa906240db91b83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 20:04:23 +00:00
Yixuan Wang
6100be27ef [automerger skipped] Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9 am: cb920d586f -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I6df3d77eaa660e9474dfc76a0691b8222fd7fba0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 20:04:21 +00:00
Yixuan Wang
284bdc3fa5 Merge changes from topic "am-1b65f256ed6d44cb931295968c81bde7" into udc-qpr-dev-plus-aosp
* changes:
  Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
  Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
2023-09-15 18:38:02 +00:00
Yixuan Wang
0603f723f4 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I307c73fcecb5e213ab186b4610a5be681262a680
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 18:14:42 +00:00
Yixuan Wang
cb920d586f Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Iba1c14faaf0c1e423f914ca860f83d75d5496a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 18:14:40 +00:00
Desmond Huang
c62d6871b3 Relocate common tracking denial entries
Bug: 299029620
Change-Id: I587e53a54e6bf4e3ccaa572cb35c28b4a0bc1eed
2023-09-15 03:39:48 +00:00
Desmond Huang
6f2589ec74 Remove obsolete entries
Bug: 299029620
Change-Id: Ib4782148b3e1167fd0113e5ec3eced7348a0cac2
2023-09-15 03:37:16 +00:00
Yixuan Wang
b02946bca9 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Ifbc5098189471983e87ef6e607b0a50e82b985a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 01:12:39 +00:00
Yixuan Wang
1c333dd6dc Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Id83469911f8d0f9bd997f53aa49176dc6c083bd5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 01:12:33 +00:00
Yixuan Wang
adf19fcc76 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev 2023-09-15 00:23:04 +00:00
Treehugger Robot
e3aa243bcf Merge "Add required sepolicy rule for Camera" into udc-qpr-dev am: 64c085cfab am: ed60a3086e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24418269

Change-Id: Id7f41df36e3fec35001a4188e4dd023c84f704f0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-14 04:14:40 +00:00
Treehugger Robot
ed60a3086e Merge "Add required sepolicy rule for Camera" into udc-qpr-dev am: 64c085cfab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24418269

Change-Id: I28d9a36decdc7e2646ee17450804fae715cbc4f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-14 04:04:59 +00:00
Treehugger Robot
64c085cfab Merge "Add required sepolicy rule for Camera" into udc-qpr-dev 2023-09-14 03:20:33 +00:00
Woody Lin
9687d162bc Add vendor_sjtag_lock_state_prop and init-check_ap_pd_auth-sh
1. Add init-check_ap_pd_auth-sh for the vendor daemon script
   `/vendor/bin/init.check_ap_pd_auth.sh`.
2. Add policy for properties `ro.vendor.sjtag_{ap,gsa}_is_unlocked` for
   init, init-check_ap_pd_auth-sh and ssr_detector to access them.

SjtagService: type=1400 audit(0.0:1005): avc:  denied  { open } for  path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=379 scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1
SjtagService: type=1400 audit(0.0:1006): avc:  denied  { getattr } for  path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=379 scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1
SjtagService: type=1400 audit(0.0:1007): avc:  denied  { map } for  path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=379 scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1
SjtagService: type=1400 audit(0.0:1008): avc:  denied  { write } for  name="property_service" dev="tmpfs" ino=446 scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:object_r:property_socket:s0 tclass=sock_file permissive=1
SjtagService: type=1400 audit(0.0:1009): avc:  denied  { connectto } for  path="/dev/socket/property_service" scontext=u:r:ssr_detector_app:s0:c512,c768 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1

Bug: 299043634
Change-Id: I6b2abf69fca9b4765f2dfb7ed82e6546159e96e9
2023-09-14 10:48:08 +08:00
Tai Kuo
e45cb8ef52 Allow regmap debugfs for drivers probed by insmod am: 1a65e5d5e4 am: 8cf4f20ca3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24727593

Change-Id: Id56ae9157f1fb0278d9b70641818c6dcb1629b8d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-13 00:32:10 +00:00
Tai Kuo
8cf4f20ca3 Allow regmap debugfs for drivers probed by insmod am: 1a65e5d5e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24727593

Change-Id: Ia298dbfa2909cea74711f2f10b0bdca3c301a0a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-12 23:42:40 +00:00
Pointer Kung
be9c098a46 Add required sepolicy rule for Camera
Grant access for TNR max_freq to let libperfmgr can control it via powerhint.

Bug: 298595475
Test: adb shell cat cur_freq, GCA, CTS
Change-Id: Ibea9d8b60a41802ba7d685daa591471a9e8cbd91
2023-09-12 09:16:01 +00:00
Tai Kuo
1a65e5d5e4 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I2bd35a6bc942536505f62d4122f0de892f243802
2023-09-12 16:45:09 +08:00
Treehugger Robot
216f86b0c2 Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev am: 4bb847b815 am: 207188241d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24585767

Change-Id: Ia622fbf9e355e3e04e4dd732776d30657b02ff2d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-30 18:24:30 +00:00
Treehugger Robot
207188241d Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev am: 4bb847b815
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24585767

Change-Id: I9df8bae38a17b05df787654de85517064fb7aaec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-30 17:35:13 +00:00
Treehugger Robot
4bb847b815 Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev 2023-08-30 16:29:24 +00:00
Yixuan Wang
bd654f00d9 Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."
Revert submission 24526613-revert-23834879-CHRE BT LOG-MHDBQNZAGV

Reason for revert: Fixed and tested with a followup cl

Reverted changes: /q/submissionid:24526613-revert-23834879-CHRE+BT+LOG-MHDBQNZAGV

Change-Id: I29866a91abfcfa380d772da447eb95344df43f8f
2023-08-29 19:17:32 +00:00
Safayat Ullah
6e969be173 [automerger skipped] display: add persist property to vendor_display_prop am: ea09b155f2 am: 2c7187af19 -s ours
am skip reason: Merged-In I2497960fbc76e56dd3a9c69d3fe274f0685744f8 with SHA-1 b27308445d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: Ifd6f9184a55de25ca13b0d4146181b2148371fc2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 14:24:57 +00:00
Safayat Ullah
2c7187af19 display: add persist property to vendor_display_prop am: ea09b155f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: If21c57942053863ff2157d88a4810a81b30a03f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 13:34:23 +00:00
Safayat Ullah
ea09b155f2 display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I60747df56c6993251bc736994da828814bcdf607
Merged-In: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 09:06:57 +00:00
Jasmine Cha
8fb992eacb audio: move related sepolicy of audio to gs-common
Bug: 297482504
Test: build pass

Change-Id: I9444b9e63f32bf898c845e42edbf682798bce300
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-08-29 16:45:47 +08:00
Safayat Ullah
b27308445d display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 08:01:45 +00:00
Kieran Cyphus
68fae0f171 Merge "DMD MDS: register proxy service and update MDS policy." into main 2023-08-28 01:42:43 +00:00
Sebastian Pickl
be13832180 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8 am: 00b4a62dd1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I71963049de8eb6c01ba75d32faeae378ca4ac84c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 11:33:44 +00:00
Sebastian Pickl
b5491c6650 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636 am: 7ee5ae18de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: If8ca0317f923da98e74ff8642b97f83894206b2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 11:33:41 +00:00
Sebastian Pickl
00b4a62dd1 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I79952f32ed00fface67437449575e7750959bca5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:25 +00:00
Sebastian Pickl
7ee5ae18de Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I3e4c175289017c75c26df4029421b61ad4efcfbe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:24 +00:00
Sebastian Pickl
ae9ab242e8 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev 2023-08-24 10:06:57 +00:00
Sebastian Pickl
84f1209636 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."
Revert submission 23834879-CHRE BT LOG

Reason for revert: fixes broken test b/297255998 verified by go/abtd: https://android-build.googleplex.com/builds/abtd/run/L30000000962735539
Bug:297255998

Reverted changes: /q/submissionid:23834879-CHRE+BT+LOG

Change-Id: I56b800260303834ed76dedf354b5a32af00b3684
2023-08-24 09:47:19 +00:00
Yixuan Wang
cf9a0ff772 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265 am: 4773f8519d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I70f328b984f29ef7bdc922bfb24352a963857da3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 20:01:35 +00:00
Yixuan Wang
890c3869c3 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316 am: 2058641a14
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: If2a3d433f56159e7a4264f52b53288afc557df61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 20:01:32 +00:00
Yixuan Wang
4773f8519d Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I819f616efd223718dd98bb8e953d3b020a296e80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:30 +00:00
Yixuan Wang
2058641a14 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: Id8058dbdf765871ba8e762ed10dd1af309642351
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:24 +00:00
Yixuan Wang
0fcc802265 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev 2023-08-23 19:29:45 +00:00
kierancyphus
9c6ec7fdd9 DMD MDS: register proxy service and update MDS policy.
MDS is a privileged app which get its permissions from `privapp-permissions-google-product.xml`, however, part of this work requires custom SEPolicy and so those permissions have been translated in SEPolicy.

This is a copy of 022dd13252865e131127da6596f5ada71fbf104f (ag/23056498) which can't be cherry picked because it was previously merged and reverted on main.

Test: Manually flash device
Bug: 270279779
Change-Id: If93515aa6b37bcbe8ec34241da1fa144d61e3d5d
2023-08-22 06:41:36 +00:00
Kris Chen
3f2bf29e1f Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212 am: beed400798
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I73f79b88b8605c20e3c0eb71699b84f08d6a5b94
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:45:10 +00:00
Kris Chen
7e2cb4f5f6 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac am: 12c2d23a4b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I64a4f98723a7d5425062c5144402d60af9a55661
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:44:46 +00:00
Kris Chen
beed400798 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I61b5d78945f4606a1a8924c2ba9e1e4b887d5895
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:08:39 +00:00
Kris Chen
12c2d23a4b Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: Ibcac24727053aac68e937156421b16b9ab892200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:04:41 +00:00
Kris Chen
4a49dbceac Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I9f99fc149fc832a44d45d09b563ba8bc913a12d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:39:06 +00:00