Commit graph

5063 commits

Author SHA1 Message Date
Wilson Sung
7ebe356b25 [automerger skipped] Revert "Revert "Update error on ROM 9624328"" am: e70b98af09 -s ours
am skip reason: Merged-In I25b0f417af3e741719f959aed79e7e330687e117 with SHA-1 47570e0ed6 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I648005a9da414a45147f1b96a1b9713c6ac7701a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:44 +00:00
Ken Yang
09c84f9c05 [automerger skipped] WLC: cleanup the unused hal_wlc policies am: 58a6a1e772 -s ours
am skip reason: Merged-In I90b9e442082b8e03e76ce63aaee56e5882933449 with SHA-1 6f9844d137 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: If4a61aec985ac1afae878b8c55b6d7f4b0fce2d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:33 +00:00
Ken Yang
b916e536c6 [automerger skipped] WLC: cleanup WLC trakcing_denials am: 670b22c2c7 -s ours
am skip reason: Merged-In I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51 with SHA-1 da69d2a494 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Ia10406b389c96373271971825f431283aaead828
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:32 +00:00
Kah Xuan Lim
ac962b6c02 [automerger skipped] modem_svc_sit: grant modem property access am: 4e270f1615 -s ours
am skip reason: Merged-In Id5e66d94eb14c6979d3b93d54fd73634444cdea1 with SHA-1 77ce224141 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: Ide9a301546fbe8123e79635bcb9948975ed1fb53
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:07 +00:00
Wilson Sung
c58e5f5b99 [automerger skipped] allow bootctl to read devinfo am: 931ea0d342 -s ours
am skip reason: Merged-In I41d2763ffe40d7465a11cc86612fed9f92905eff with SHA-1 967da5da4f is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: I214b208e67770556f95b68b4831ba9257a3334f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:21 +00:00
Wilson Sung
794fc587fb [automerger skipped] Remove proc_vendor_sched obsolete denials am: 676c7a674c -s ours
am skip reason: Merged-In I308df50eefe611a0a87afc9a21387465487cc6ea with SHA-1 6545bc156a is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: I9651a19016960762493b45e73ae36fb87c4e10a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:19 +00:00
Nicole Lee
eed60fbd0b [automerger skipped] logger_app: don't audit default_prop and fix errors am: 7706be6c71 -s ours
am skip reason: Merged-In I8999372d243286586eb53602e167fa111d39a00f with SHA-1 ef1d13d86d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I2225951e84dbc4e43035a9c9835ae266df103e6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:17 +00:00
Wilson Sung
e70b98af09 Revert "Revert "Update error on ROM 9624328""
This reverts commit d8572861e3.

Remove hal_googlebattery related denied

Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Merged-In: I25b0f417af3e741719f959aed79e7e330687e117
Change-Id: I25b0f417af3e741719f959aed79e7e330687e117
2023-02-20 11:06:17 +00:00
Ken Yang
58a6a1e772 WLC: cleanup the unused hal_wlc policies
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit 6f9844d137)
Merged-In: I90b9e442082b8e03e76ce63aaee56e5882933449
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
2023-02-20 11:05:53 +00:00
Ken Yang
670b22c2c7 WLC: cleanup WLC trakcing_denials
Bug: 268566583
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit da69d2a494)
Merged-In: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
2023-02-20 11:05:25 +00:00
Kah Xuan Lim
4e270f1615 modem_svc_sit: grant modem property access
Log message gotten before adding the policy:
avc: denied { connectto } for comm="modem_svc_sit" path="/dev/socket/property_service" scontext=u:r:modem_svc_sit:s0 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1

Bug: 247669574
(cherry picked from commit 77ce224141)
Merged-In: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
Change-Id: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
2023-02-20 11:04:11 +00:00
Wilson Sung
931ea0d342 allow bootctl to read devinfo
Bug: 260522436
(cherry picked from commit 967da5da4f)
Merged-In: I41d2763ffe40d7465a11cc86612fed9f92905eff
Change-Id: I41d2763ffe40d7465a11cc86612fed9f92905eff
2023-02-20 11:02:28 +00:00
Wilson Sung
676c7a674c Remove proc_vendor_sched obsolete denials
Bug: 264490054
(cherry picked from commit 6545bc156a)
Change-Id: I308df50eefe611a0a87afc9a21387465487cc6ea
Merged-In: I308df50eefe611a0a87afc9a21387465487cc6ea
2023-02-20 11:01:42 +00:00
Nicole Lee
7706be6c71 logger_app: don't audit default_prop and fix errors
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:default_prop:s0" dev="tmpfs" ino=153 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
avc: denied { search } for name="ssrdump" dev="dm-44" ino=377 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
avc: denied { search } for name="coredump" dev="dm-44" ino=378 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_coredump_file:s0 tclass=dir permissive=0 app=com.android.pixellogger

Bug: 264489961
Bug: 269383459
Test: Make sure no avc denied for logger_app when using Pixel Logger
(cherry picked from commit ef1d13d86d)
Change-Id: I8999372d243286586eb53602e167fa111d39a00f
Merged-In: I8999372d243286586eb53602e167fa111d39a00f
2023-02-20 11:00:59 +00:00
TreeHugger Robot
9adfa9a961 Merge "Revert "Revert "Update error on ROM 9624328""" 2023-02-20 08:00:15 +00:00
Sean.JS Tsai
6f7bde4d0e Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286 am: f0e29936a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: Ie75b3d535e6dbe6d5dbad91fa69df58e61c25b27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 07:55:14 +00:00
Wilson Sung
47570e0ed6 Revert "Revert "Update error on ROM 9624328""
This reverts commit d8572861e3.

Remove hal_googlebattery related denied

Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Change-Id: I25b0f417af3e741719f959aed79e7e330687e117
2023-02-20 15:07:14 +08:00
Sean.JS Tsai
f0e29936a5 Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: I564275400b71dd3f2859b4a4cf7b4bcce56e0969
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:46:09 +00:00
Sean.JS Tsai
5c6a9053e5 Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: I6be9c22256297c1417b6f9f4c361ba1e818b540f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:44:47 +00:00
Po-Ya Hsu
6609511ef7 Revert "Temporary turn off DSP Saliency and ESP." am: b741a63df2 am: b429e1becb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21503764

Change-Id: I1384f7c76d5759848e588965ea30c4d48d40155a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:38:24 +00:00
Sean.JS Tsai
8838f4e286 Merge "Revert "Update error on ROM 9624328"" into udc-dev 2023-02-20 05:59:29 +00:00
Po-Ya Hsu
b429e1becb Revert "Temporary turn off DSP Saliency and ESP." am: b741a63df2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21503764

Change-Id: I15cff8716ab9b6fabfad4c552ee69ae122946626
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 05:30:08 +00:00
Po-Ya Hsu
850669237a Revert "Temporary turn off DSP Saliency and ESP." am: b741a63df2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21503764

Change-Id: I3156561f0ac260fb5c551f3d6c1082b06dc7b7dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 05:29:03 +00:00
TreeHugger Robot
0d91c28418 Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd am: f5aeedf6fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: Ia337af931a821f03c8c72f491113eea8e7bf043f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 05:23:43 +00:00
Sean.JS Tsai
d8572861e3 Revert "Update error on ROM 9624328"
This reverts commit cf747f40d6.

Reason for revert: <b/269976373>

Change-Id: I1bee9c1da2571ab753c2193491ebc71b288b66b2
2023-02-20 04:29:33 +00:00
Ken Yang
dd3eaa4dce Merge "WLC: cleanup the unused hal_wlc policies" 2023-02-20 04:21:11 +00:00
Ken Yang
91045cea32 Merge "WLC: cleanup WLC trakcing_denials" 2023-02-20 04:20:59 +00:00
TreeHugger Robot
f5aeedf6fc Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: I4c579890ef5ee1c6427b3b699223d3d9cea138be
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:16:13 +00:00
TreeHugger Robot
864bf07d5c Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: If0e5d0b805f5cf467d0ec8c66310919df9acd088
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:13:24 +00:00
Nathan Huckleberry
d727b5f6c4 Enable HCTR2 for filenames encryption am: d4aea9089b am: 213617c8c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21489264

Change-Id: I236bea9343adf4d74f3f2fb30b64e209b9a7c662
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:08:27 +00:00
Po-Ya Hsu
b741a63df2 Revert "Temporary turn off DSP Saliency and ESP."
This reverts commit 6191ab4e6b.

Reason for revert: Enable DSP Saliency and ESP by default.

Bug: 258342843
Test: Stability test passed (b/264671175)

Change-Id: Ib1ec0525511748567e96cbfdf830073687c85b8b
2023-02-20 03:52:33 +00:00
TreeHugger Robot
ea203448fd Merge "Update error on ROM 9624328" into udc-dev 2023-02-20 03:28:27 +00:00
Nathan Huckleberry
213617c8c5 Enable HCTR2 for filenames encryption am: d4aea9089b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21489264

Change-Id: If82987b77de0bee14ef689a5a16c5160c63ce5fc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 02:59:19 +00:00
Nathan Huckleberry
850c9837ac Enable HCTR2 for filenames encryption am: d4aea9089b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma/+/21489264

Change-Id: Ifda13eb5ab3bb4a6f5379780dd09881cc5718778
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 02:59:10 +00:00
sukiliu
cf747f40d6 Update error on ROM 9624328
Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Test: SELinuxUncheckedDenialBootTest
Change-Id: Id8cbfb7c55f2acdc3102b20cdbd2702b594992ba
2023-02-20 10:28:33 +08:00
Randall Huang
5e2783f956 Merge "Enable HCTR2 for filenames encryption" 2023-02-20 02:15:24 +00:00
Ken Yang
6f9844d137 WLC: cleanup the unused hal_wlc policies
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-20 00:58:13 +00:00
Ken Yang
da69d2a494 WLC: cleanup WLC trakcing_denials
Bug: 268566583
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-20 00:42:35 +00:00
TreeHugger Robot
d19076e7ff Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a am: dfd3d8e7c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: I7beb6ec7071cba88880bf0f1c8ce17ec0a54fb0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 16:01:39 +00:00
TreeHugger Robot
dfd3d8e7c5 Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: Ice2cb63d7abc67b3185532be682db8841d018c1a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:51:17 +00:00
TreeHugger Robot
213f91ad98 Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: I897ae56dfb2a8fb577cc1ca3340a9feecab8c15b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:49:15 +00:00
TreeHugger Robot
c012a8a10a Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev 2023-02-18 13:46:15 +00:00
Kuen-Han Tsai
f939579c6e SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3 am: e4af4e0824
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I3d48ca424b1490004894b0809d6b9c03f3a17532
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 06:04:38 +00:00
Kuen-Han Tsai
e4af4e0824 SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I639171077e99d6e17698e7a1905712ab7d4446a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 04:54:12 +00:00
Kuen-Han Tsai
f0173dff8a SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I949f460625696b1de5b5a89caeef9b59869b9e1d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 04:48:21 +00:00
neoyu
9ae44843ad Fix avc denied for hal_radioext_default am: c0da946f48 am: 4ff3dbefcd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: Ia082d38a7ea7079fd0f7d2cd86b3d7c3d847d10d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 03:27:40 +00:00
Kuen-Han Tsai
d0ac5bffa3 SEPolicy: remove tracking denials for hal_usb
Remove tracking denials since there is no avc denials related to hal_usb
found in the bug report.

Bug: 264483531
Bug: 264483531
Bug: 264482981
Bug: 264600052
Bug: 264482981
Bug: 264600052
Bug: 261651112
Test: Capture bugreport and check any denials related to hal_usb
Change-Id: I535c94c1112fc51f80b80c99562b43afee32ddd6
2023-02-18 02:41:51 +00:00
neoyu
4ff3dbefcd Fix avc denied for hal_radioext_default am: c0da946f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: I1cbdf50e1f0dc138076cf70b8229885f60482c60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 02:23:12 +00:00
neoyu
e4e8a1df0f Fix avc denied for hal_radioext_default am: c0da946f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: Id91591d00b8ba8a606dfc9938d82a89fb861756a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 02:21:37 +00:00
Nathan Huckleberry
d4aea9089b Enable HCTR2 for filenames encryption
Fix prefix-correlation weakness in filenames encryption by switching to
AES-256-HCTR2.  Enabling HCTR2 fixes a longstanding known weakness in
filenames encryption.

Also enable HCTR2 for adoptable storage.  Pixel phones don't have an SD
card slot.  So they can only have adoptable storage through the "Virtual
SD Card", which is for testing only.

Bug: 265046004
Test: Equivalent changes were tested on P21 since I don't have a P23.
Will be tested with storage-qa.

Change-Id: I0666eb07c4b93b1bab4da41e3b4f5019ac38c213
2023-02-18 02:03:15 +00:00