Commit graph

1146 commits

Author SHA1 Message Date
Donnie Pollitz
c24ebe57c1 sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306 am: 8958b2e84b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: If4f7afa3407b7a124ee55d95ac5a3e774a9842a7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:53:42 +00:00
Dinesh Yadav
ea868cc5bf Merge "Make gxp_device an mlstrustedobject" into udc-d1-dev am: 85829f2265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21701040

Change-Id: I28e061683cfd0bed9cd17ebf907cd3d45429bf84
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:32:58 +00:00
Donnie Pollitz
8958b2e84b sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: I55b973823df7b0ad935ab38c0c22c63c0c1674cd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:27:10 +00:00
Donnie Pollitz
105d3b4aa2 sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: Ida4600755a38935ec2506a0c245a1f0e5d0556a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:04:52 +00:00
Jörg Wagner
d8c6712f5b Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 6834d6f59f)
Merged-In: I785106b6d2d05e21bf60fcd6da3d716b32e1bc1d
Change-Id: I0469e2f24abe7a9458305d5752ae655cf4f42547
2023-03-03 15:23:39 +00:00
Nicole Lee
bc1beba926 logger_app: allow logger_app to access vendor_usb_config_prop
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=397 scontext=u:r:logger_app:s0:c13,c257,c512,c768 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0 app=com.android.pixellogger

Bug:270579027
Test: Enable debug port by Pixel Logger
Change-Id: I0274a25142d671b03966e56a2ffd9926683e4991
2023-03-03 12:55:29 +00:00
TreeHugger Robot
4eab0326df Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev 2023-03-03 12:01:40 +00:00
Dinesh Yadav
85829f2265 Merge "Make gxp_device an mlstrustedobject" into udc-d1-dev 2023-03-03 03:12:15 +00:00
Dinesh Yadav
01c5409eb8 Make gxp_device an mlstrustedobject
This is needed as google_camera_app needs write access to gxp.

Test: Tested with private build "P51261040" with Tot google3 gca-dogfood app & found no selinux violations.

Bug: 264139000
Change-Id: Ic1a262cc40578ebd2305efe851e54cf857bd02c1
2023-03-02 15:41:37 +00:00
Nicolas Geoffray
fc21747ab4 Merge "Allow ssr_detector_app directory/file creation in system_app_data_file." 2023-03-02 15:39:10 +00:00
Nicolas Geoffray
311722d720 Allow ssr_detector_app directory/file creation in system_app_data_file.
Bug: 260557058
Bug: 264483352
Test: m
Change-Id: Ia9a2b1fbf14ae018580ab0abe515dd180610bad4
2023-03-02 14:10:36 +00:00
Ernie Hsu
f13709f4c2 Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab am: d46fdc0b46
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I946d41a8fd932db6f44eeb1fc5b6092db67e6b66
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 10:11:38 +00:00
Ernie Hsu
11bbec30bc Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab am: fbbc198801
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I5e45ca88e24d8b4b67dd65326cece156cf38905d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 10:10:31 +00:00
Ernie Hsu
d46fdc0b46 Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I00c2445ce1210da89bb8d60a8e151f43ef389473
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 09:19:42 +00:00
Ernie Hsu
fbbc198801 Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I90171c56ccbb152a1cf7fbca77bb1d56311bebaa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 09:19:35 +00:00
Donnie Pollitz
e31ad0b306 sepolicy: Fix hal_confirmationui_default avc denials
* Allow for dumpstate

Bug: 261933368
Bug: 264489634
Test: Ran com.google.android.selinux.pts.SELinuxTest#scanBugreport
Change-Id: Id70d2a920172e649e4497f4ea1a4ecad33963edc
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-02 09:08:16 +00:00
Ernie Hsu
899ad9c1ab Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev 2023-03-02 08:38:54 +00:00
Hiroshi Akiyama
3e2845abf7 [automerger skipped] Update sepolicy for BCL IRQ durations to dumpstate am: c0587fbf36 -s ours
am skip reason: Merged-In Icd524bd32ed41c3de72f0e1b13428d76e871d203 with SHA-1 a13ce6baf4 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21695208

Change-Id: If74ec57479b0702d5f6e16c761cdb5d1c1ca22ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 07:46:43 +00:00
Hiroshi Akiyama
c0587fbf36 Update sepolicy for BCL IRQ durations to dumpstate
Bug: 269752322
Test: adb bugreport
Change-Id: Icd524bd32ed41c3de72f0e1b13428d76e871d203
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
Merged-In: Icd524bd32ed41c3de72f0e1b13428d76e871d203
2023-03-02 06:03:23 +00:00
Wilson Sung
ca89cde996 Add sensor boot-to-home required policy am: d0105abe01 am: 8fa2055112
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: I9ed4cf02461f03cb42462b5dce3bbab20a2f18c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 05:07:53 +00:00
Wilson Sung
27f0beff37 Add sensor boot-to-home required policy am: d0105abe01 am: 819a8ad315
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: I8b050d6e9eeedb653acf0bd1995479acd0b9a964
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 05:06:39 +00:00
Wilson Sung
819a8ad315 Add sensor boot-to-home required policy am: d0105abe01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: Ia81ba6db8dd706968fc627379a7ca1ec0273af79
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:49 +00:00
Wilson Sung
8fa2055112 Add sensor boot-to-home required policy am: d0105abe01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: I95c23468276681b97969e2fe6376e914aed2fe1f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:49 +00:00
Hiroshi Akiyama
b45a7465cf Merge "Update sepolicy for BCL IRQ durations to dumpstate" 2023-03-02 04:21:56 +00:00
Hiroshi Akiyama
a13ce6baf4 Update sepolicy for BCL IRQ durations to dumpstate
Bug: 269752322
Test: adb bugreport
Change-Id: Icd524bd32ed41c3de72f0e1b13428d76e871d203
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
2023-03-02 03:04:08 +00:00
Wilson Sung
4e36ecc334 Merge "Add sensor boot-to-home required policy" to master
Test: boot-to-home
Fix: 261105336
Change-Id: I2a12d4cf87b00d8dc117ced7062a97016d75275c
2023-03-02 10:42:55 +08:00
Wilson Sung
d0105abe01 Add sensor boot-to-home required policy
Test: boot-to-home
Fix: 261105336
Change-Id: I772ff7a294cc5d2448361c164d4e671a41c92c8d
2023-03-02 02:39:15 +00:00
Wilson Sung
fc8f4f8f24 Allow hal_thermal_default to read iio/odpm sysfs nodes
Bug: 260366399
Bug: 261651187
Bug: 264204525
Change-Id: I7358b7740f6c30bd7b05e29e931a4c11226c6253
2023-03-01 16:21:33 +00:00
Ernie Hsu
4d90089d25 move mediacodec_samsung build config and sepolicy to gs-common
Bug: 263444717
Test: build pass, camera record, youtube
Change-Id: I8fa4d79495b3971429b977a63aed811ef8d62ddb
2023-03-01 10:12:22 +00:00
Kenny Root
0f36fcebb2 Merge "Add GSA logs policy" 2023-03-01 05:51:40 +00:00
Richard Chang
68ed00878b Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b am: 2f31611036
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: If5dcd916cd78b538f5d5e9a68f8a76fdd03e5175
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 05:16:38 +00:00
Richard Chang
fb7193c798 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b am: 92ec39e932
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: Icf93e34b300bfd10e00afd6e58317b07a246290c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 05:15:53 +00:00
Armelle Laine
ab3b587970 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6 am: 0da9e2ff96
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I3054c7f5b73b57c4d5ce1b28afe410730ceec71f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 05:15:31 +00:00
Armelle Laine
2c30225d68 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6 am: 39a9021703
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: Ifd00df6d99b890a24a73d50dab3b9b42c740c856
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 05:15:14 +00:00
Richard Chang
92ec39e932 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: I066aaa3efd492aea906ac778be9ff8c3e696850d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:53 +00:00
Richard Chang
2f31611036 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: I128719b2f9e1af2a649913faabcca8dc3e94e749
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:50 +00:00
Armelle Laine
39a9021703 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I7774f4fba285cd3a8b65c9c78245da5ee39d9c61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:29 +00:00
Armelle Laine
0da9e2ff96 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I66c16c9377b4af6c924adfee4b983acff7993e0e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:39:44 +00:00
Richard Chang
3c52a9ab3b Merge "sepolicy: update init.te for zram device" into udc-dev 2023-03-01 04:28:58 +00:00
Armelle Laine
d38c507ef6 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev 2023-03-01 03:41:09 +00:00
Kenny Root
076591d107 Add GSA logs policy
This adds a label to the sysfs files for GSA logs to allow dumpstate to
read them during a bugreport.

Bug: 271125313
Test: adb shell dumpstate
Change-Id: I8842c0bec972c4cfad15ca689f8e4ae7fa99e179
2023-02-28 18:33:23 -08:00
Richard Chang
ee8c7c2df2 sepolicy: update init.te for zram device
Bug: 269221861
Bug: 270633329
Test: Boot
Change-Id: I050e9a72006dcd0b71ba1232e38e5f96bce4c967
2023-03-01 02:04:24 +00:00
TreeHugger Robot
63f78e7b2e Merge "Update bug_map" into udc-dev am: 627e6c1648 am: 312d50fd92
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: I1ea8df25e7cdd1a0e9283b01c51693caefb82893
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 01:54:20 +00:00
TreeHugger Robot
9986e1ef13 Merge "Update bug_map" into udc-dev am: 627e6c1648 am: 81390587ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: Iafb1c4276f8d1aa8a9e01090b44f76de8aade0db
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 01:50:18 +00:00
TreeHugger Robot
81390587ae Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: I6c9b8ad61f3ebc5cfab067016b0029b111bc4625
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:48 +00:00
TreeHugger Robot
312d50fd92 Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: Ie65327b364ad73df29b337d2de4ad8df51fbfb08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:30 +00:00
TreeHugger Robot
627e6c1648 Merge "Update bug_map" into udc-dev 2023-02-28 23:56:31 +00:00
Jonglin Lee
3c0dd54d80 Add perfmon policies am: 167eba3ad9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649593

Change-Id: Ibb15e72ed9d9bd5abbf5659bc3b7e925ec88d029
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-28 21:47:09 +00:00
Jonglin Lee
167eba3ad9 Add perfmon policies
Add perfmon policies to fix hotplug issues.

Bug: 271024526
Bug: 271007431
Change-Id: I974bd99224b983454c6af47f4a08a4fe20699834
Signed-off-by: Jonglin Lee <jonglin@google.com>
2023-02-28 10:19:26 -08:00
Xu Han
fe5bb58212 Update bug_map
Bug: 264483024
Test: Build.
Change-Id: I9a1574b5997d9ac5d26100254c7e20b81930df50
2023-02-28 09:34:58 -08:00