Commit graph

1132 commits

Author SHA1 Message Date
TreeHugger Robot
7c2bce5823 Merge "enforce incidentd" into udc-dev am: 5488c59d9a am: 908501be50
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21981862

Change-Id: Ic5fd2ef5bff18f7b8c749309461bcc1a8d0fbe17
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 06:12:18 +00:00
Jasmine Cha
df03bc9034 audio: move set property in vendor_init to gs-common am: 684d922d59 am: 777ee2e945
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21974564

Change-Id: I30cbbba5405c2efeb193173cfece67e9b280000c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 06:11:52 +00:00
Adam Shih
46d5345bc9 enforce hal_dumpstate_default
Bug: 266035810
Test: adb bugreport
Change-Id: Iec0d9b7d5d9327dd7ca96ab7f4c1a26c3fde6a3e
2023-03-13 14:10:45 +08:00
TreeHugger Robot
908501be50 Merge "enforce incidentd" into udc-dev am: 5488c59d9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21981862

Change-Id: Ic5339c6d2f2948e8c60f314a3fde1c39a67134e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:56:31 +00:00
TreeHugger Robot
468d72e588 Merge "enforce incidentd" into udc-dev am: 5488c59d9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21981862

Change-Id: I8ce8e3f3ae9b4aaf4f6ffe71c8f3fd3d65eb679e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:56:27 +00:00
TreeHugger Robot
5488c59d9a Merge "enforce incidentd" into udc-dev 2023-03-13 05:40:12 +00:00
Jasmine Cha
e91c3cff4c audio: move set property in vendor_init to gs-common am: 684d922d59
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21974564

Change-Id: Ia7ba15f5d0f80b8b8ec30d4ffe8ae998668a3df6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:38:15 +00:00
Jasmine Cha
777ee2e945 audio: move set property in vendor_init to gs-common am: 684d922d59
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21974564

Change-Id: I7df21f6988b4a2546eb3099b9b60c7828666e3b6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:38:09 +00:00
Rex Lin
e7616e3934 [SELinux] Fix hal_uwb_default dev access errors
Allow hal_uwb_default to access /dev/uci

Bug: 263048994
Test: http://ab/I86600010139623509
Change-Id: I6324044822f74d1f0d14cc9c6d057dce0dfcc9ee
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-03-13 05:16:30 +00:00
Wilson Sung
4bdc1c25c6 Merge changes I9868bdfd,I1085decf into udc-d1-dev am: 6b9e3f74b6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21947244

Change-Id: I96b2f88eabdc5ad1666ece7e8ae1e802579e95a4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-13 05:00:45 +00:00
Wilson Sung
6b9e3f74b6 Merge changes I9868bdfd,I1085decf into udc-d1-dev
* changes:
  Enforce insmod-sh
  Allow insmod-sh lockdown in userdebug
2023-03-13 04:26:34 +00:00
Adam Shih
bbbc3e3926 enforce incidentd
Bug: 264490034
Bug: 259302023
Test: adb bugreport
Change-Id: Ie77eded2b6bdd5bd993e500cf8d8d481e5fe7a57
2023-03-13 11:52:29 +08:00
Jasmine Cha
684d922d59 audio: move set property in vendor_init to gs-common
Bug: 259161622
Test: build pass

Change-Id: I4232a7e33c75c2dc7475e0888da7019d59de52d1
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-13 10:53:58 +08:00
Ziyi Cui
3e6ba1f4e3 zuma-sepolicy: pixelstats: enable pixelstats access to perf-metrics
enable pixelstats access to sysfs path
Bug: 246799997
Test: Verified the existence of atom and correctness of atom stats
Change-Id: I874f7ff06b91b028cd6bbffd682429763c264d9f
Signed-off-by: Ziyi Cui <ziyic@google.com>
2023-03-12 23:02:24 +00:00
Jeremy DeHaan
df48ca07fd Merge "Allow HWC to access panel model" into udc-dev am: 3a29cc604b am: 83126173b7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21776404

Change-Id: I3f06b70a593af904e0c31fed7f33c412d3a50b14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 20:06:24 +00:00
Jeremy DeHaan
09e286f1ca Merge "Allow HWC to access panel model" into udc-dev am: 3a29cc604b am: dbe0ec8114
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21776404

Change-Id: Iff8da61c479f876d643a06bee39eeeae3b9c640b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 19:13:19 +00:00
Jeremy DeHaan
dbe0ec8114 Merge "Allow HWC to access panel model" into udc-dev am: 3a29cc604b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21776404

Change-Id: I11fcf68d1418505e99c243bb1657d6e818c1e0bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 18:18:39 +00:00
Jeremy DeHaan
83126173b7 Merge "Allow HWC to access panel model" into udc-dev am: 3a29cc604b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21776404

Change-Id: I4c16dc7e470a1f07fafd29996502bdba66dd88ba
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 18:18:27 +00:00
Jeremy DeHaan
3a29cc604b Merge "Allow HWC to access panel model" into udc-dev 2023-03-10 17:48:34 +00:00
Wilson Sung
0d8ede8308 Enforce insmod-sh
Fix: 264490091
Test: Boot-to-home without insmod-sh avc error
Change-Id: I9868bdfd8fad7ac37c8d1104fb1fab10a7e8f79a
2023-03-10 16:25:24 +08:00
Wilson Sung
eae6bfb835 Allow insmod-sh lockdown in userdebug
Bug: 272166723
Change-Id: I1085decf2a00597992a95996b1a2875be08ba1f1
2023-03-10 16:23:39 +08:00
Enzo Liao
3f905ee1d0 SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma.
It needs to access a file pushed by hosts of test suites (details: http://go/pd-client-for-lab#heading=h.wtp07hbqvwgx)

Bug: 234359369
Design: http://go/pd-client-for-lab
Test: manual (http://b/271555983#comment3)
Change-Id: Id97d9c2d07197478ab8d6fcd1e9370dc794ff7d1
2023-03-10 15:37:15 +08:00
Wilson Sung
8705c515e3 Update SELinux error am: 028c3dd417
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21947619

Change-Id: I1a741000b3429a26d8622328ab1c147dde9aac98
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 04:34:32 +00:00
Enzo Liao
f88e9fc5bd Merge "SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma." 2023-03-10 03:07:31 +00:00
Wilson Sung
028c3dd417 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272628174
Change-Id: Ief58f990c70fc7a9a6fa1f18ce22c1c5847acaf9
2023-03-10 10:56:44 +08:00
Jasmine Cha
dbc882f47e Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa am: cf7b251dc2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: I03e24554dd063ec68265c6f8113bd1bc060515b8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:39:26 +00:00
Jasmine Cha
c65b325672 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa am: 3e639ffa42
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: I63b941f03a068e510c76efa040f7886748480340
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:22:29 +00:00
Jasmine Cha
3e639ffa42 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: Ic05e1165722a12b41d51f4339ed817383412219f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:19:45 +00:00
Jasmine Cha
cf7b251dc2 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: I28ac6516a9fb56d4e431f6160ccf44dfef6baa1d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:18:12 +00:00
Jasmine Cha
6431ec8cfa Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Wilson Sung
ed2ae24f2e Add insmod-sh policy am: aa90037844
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21932219

Change-Id: I018f0ed4c0054d672d4af432381fea76d5a28975
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 00:54:44 +00:00
Alice Sheng
726291157f Add sepolicy for RA9530 nodes.
Bug: 270440233
Test: No selinux denials related to wireless
Change-Id: I790052270a20c3324c7b9a9f674dc48a7d003c6f
2023-03-09 14:34:13 -08:00
Wilson Sung
aa90037844 Add insmod-sh policy
Fix: 260366066
Change-Id: I0874c1f476b47a9ad3cee344986404958c96fd25
2023-03-10 02:04:36 +08:00
Darren Hsu
df453ea221 Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f am: 055b52e584
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: I759cc445f88549e2cc006314c73e91afed09d68e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 08:29:06 +00:00
Darren Hsu
080b747bcd Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f am: 2caf9aa778
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: I6c058342009fbeed632fbc03a519ce7fa77bcc43
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 08:26:58 +00:00
Darren Hsu
055b52e584 Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: I2e1cde774f763e3f30b0e50484824483d5319c08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 07:54:54 +00:00
Darren Hsu
2caf9aa778 Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: Icebd907a6ea7f3e42799ee168fcc87b781d63e15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 07:54:34 +00:00
Wilson Sung
e7a7783e9b Merge "Add system_ui required policy" into udc-d1-dev am: 2492786d15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912560

Change-Id: I0c121dc88f19bde54ef2380c9523613d9403ceda
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 07:31:36 +00:00
Darren Hsu
3867f2f21f Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev 2023-03-09 07:20:30 +00:00
Wilson Sung
2492786d15 Merge "Add system_ui required policy" into udc-d1-dev 2023-03-09 07:05:32 +00:00
Wilson Sung
8c535e410a Add system_ui required policy
Bug: 264266705
Bug: 268572197
Bug: 269813282
Change-Id: I8d782a5879dd531c29328517f67245913808ae93
2023-03-09 12:57:39 +08:00
KRIS CHEN
3d408c2b96 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422 am: f9fe08e2a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I16cf8697d5117fb70fbda22b92ff3f605b56ff01
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:52:35 +00:00
KRIS CHEN
88da4d5f3e Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422 am: 4309d80318
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I2f633d4cc5d4792b8689e46a488d767c0e07532a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:51:37 +00:00
KRIS CHEN
f9fe08e2a5 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I51f3c085ba4861bffdc25f4849f53e73ccd91e66
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:21:31 +00:00
KRIS CHEN
4309d80318 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I232a8e1d378731c0a42d42b9450fee002efd15bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:21:05 +00:00
KRIS CHEN
92c67c8422 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev 2023-03-09 03:53:46 +00:00
Jasmine Cha
d4de162a4f audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: I5f537f18b33c84f30dae349880f8d00a22883b0b
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:09:29 +08:00
Darren Hsu
f3e948a640 sepolicy: label more paths for sysfs_odpm
Bug: 272164439
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: Iec1be5189d21ff6b2bdfe5056b526f01dc2b35e4
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-09 08:35:42 +08:00
Dai Li
f2200cdfa1 dma-heap: add dsp heap
Add dsp heap to zuma

Bug: 258813006
Change-Id: I953d1abb7cee15d041db1535df79c91cd25830f7
2023-03-08 20:43:53 +00:00
Kris Chen
cc2458e456 Allow fingerprint hal to access display hibernation node
Fix the following avc denial:
avc: denied { write } for name="hibernation" dev="sysfs" ino=75339
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs:s0
tclass=file permissive=0

Bug: 256947811
Bug: 251239489
Bug: 267271482
Test: Perform udfps osc compensation.
Change-Id: I2cfb1353770734a19e7fcf1a10eb2fc7bf84a4f5
2023-03-08 09:10:24 +00:00