Wilson Sung
856d2c480e
Allow kernel to access firmware and zram
...
Bug: 260522245
Change-Id: I964ac1e30e0181f4d6edc71f2e066b7bd515186b
2023-02-08 05:08:04 +00:00
TreeHugger Robot
9cce214473
Merge "Add required sepolicy rules for Camera function"
2023-02-08 05:00:08 +00:00
TreeHugger Robot
4e02d08f95
Merge "[SELinux] Fix hal_uwb_default dumpstate errors"
2023-02-08 01:43:53 +00:00
George Lee
0322b923b7
Remove tracking denial for system_boot_reason
...
Bug: 263525155
Test: Local boot
Change-Id: Iab1411871a66c60a604ee8b0fce0505a88973792
Signed-off-by: George Lee <geolee@google.com>
2023-02-07 17:07:19 +00:00
Wilson Sung
5f48d4f516
Add required sepolicy rules for Camera function
...
Bug: 263184920
Bug: 263305107
Change-Id: Idadf878564333a931b90da2415efe109e75e222a
2023-02-07 21:20:12 +08:00
Rex Lin
f1f25dc94f
[SELinux] Fix hal_uwb_default dumpstate errors
...
Bug: 263048994
Test: http://ab/I62800010129138096
Change-Id: I4fc3dedb8e35e4d7520acded58d66f5206565afb
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-02-07 08:17:54 +00:00
Ernie Hsu
0e1559162e
Merge "Fix sepolicy for mediacodec_google and mediacodec_samsung"
2023-02-07 07:57:52 +00:00
TreeHugger Robot
9f95eb9cd1
Merge "Update error on ROM 9558720"
2023-02-07 06:06:39 +00:00
Ernie Hsu
f7adc840df
Fix sepolicy for mediacodec_google and mediacodec_samsung
...
mediacodec_google and mediacodec_samsung could be audited
Test: atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
No fail associated with mediacodec_google and mediacodec_samsung
Bug: 262794938
Bug: 262794428
Bug: 262793919
Change-Id: I0ebac8c5c25ae89ecc8907f0f141f5ec1d8aaa0b
2023-02-07 05:48:58 +00:00
sukiliu
341afe161d
Update error on ROM 9558720
...
Bug: 267843291
Bug: 267843408
Bug: 267843310
Bug: 267843409
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4d8f448d9019232222f2e8385bb2f4b3cf5f5336
2023-02-07 11:29:45 +08:00
Darren Hsu
1934546586
sepolicy: label required wakeup nodes for system suspend
...
Bug: 260366031
Bug: 264204215
Test: run singleCommand pts -m PtsSELinuxTestCases
Change-Id: Icf8c4669156a0017655981fda8619ce0a75dce4d
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-02-07 10:12:30 +08:00
TreeHugger Robot
30036eeebc
Merge "Remove dontaudit for nfc"
2023-02-07 02:08:28 +00:00
TreeHugger Robot
161099cfe2
Merge "Remove dontaudit for st54spi"
2023-02-07 02:08:21 +00:00
Donnie Pollitz
1fd0c782b4
sepolicy: Fix trusty_metricsd avc denials
...
* Suez data collection missing
Bug: 264489526
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I667e35c68139a3368655cab4ea40acb529bb65ef
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:31 +00:00
Donnie Pollitz
1df4e2dde8
sepolicy: Fix trusty_apploader avc denials
...
* File permissions missing
Bug: 263305034
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I5d0a56a4c31c66610414341118c4089d2c11f3e9
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:22 +00:00
George
aa76e6db12
Remove dontaudit for st54spi
...
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for st54spi
Bug: 264489677
Test: manually check dumpsys secure_element
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I587caa423d3e1d23d9666fb732c0cc350934538f
2023-02-06 07:27:12 +00:00
Jenny Ho
31f750da2b
sepolicy: add sepolicy for disable.battery.defender
...
[ 7.536208] type=1107 audit(1671575809.144:22): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=vendor.battery.defender.disable pid=381 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=property_service permissive=1'
Bug: 263305106
Change-Id: Ia7adfe7f128c6390128447b9363ecd3615694fb1
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 13:09:28 +08:00
George
40b805af57
Remove dontaudit for nfc
...
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for nfc
Bug: 263185547
Bug: 264490053
Test: atest NfcNciInstrumentationTests
Test: atest NfcNciUnitTests
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: Idc9eced1ae7248cf0883a5e42db2c5e55cb65c3b
2023-02-04 22:37:34 +08:00
Welly Hsu
a8526b30e0
Merge "Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot"
2023-02-04 05:55:56 +00:00
Joseph Jang
114b7b8f09
Merge "citadel: Remove citadel.te for sepolicy testing"
2023-02-03 02:08:12 +00:00
TreeHugger Robot
075f213ece
Merge "hal_graphics_composer_default: fix sepolicy denials"
2023-02-02 06:11:49 +00:00
Nicole Lee
1c8be3059d
Merge "logger_app: allow access vendor_gps_file, vendor_gps_prop, vendor_logger_prop"
2023-02-02 03:06:23 +00:00
Nicole Lee
227fa788cc
Merge "logger_app: allow logger_app access vendor_modem_prop"
2023-02-02 03:06:14 +00:00
Nicole Lee
89a469803c
Merge "logger_app: allow logger_app to access vendor_ssrdump_prop"
2023-02-02 03:06:05 +00:00
Nicole Lee
3a825a5184
Merge "logger_app: allow logger_app to access radio files"
2023-02-02 03:05:50 +00:00
Safayat Ullah
7ce9680b98
hal_graphics_composer_default: fix sepolicy denials
...
Bug: 263184738
Bug: 264489746
Test: There is no AVC denied log after reboot
Change-Id: I3c5bbc55f0a676d8906ec061e3c999995d02dd3f
2023-02-01 14:34:36 +00:00
Donnie Pollitz
eea50ca2bc
Merge "sepolicy: Fix tee avc denials"
2023-02-01 09:46:16 +00:00
Welly Hsu
74b12d8455
Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot
...
Issue: after introducing selinux rules in b/265286368
the dontaudit rules can be removed
bug: 260522413
bug: 262451641
bug: 261651113
bug: 260922186
bug: 261516808
bug: 260769064
bug: 265384119
bug: 264489745
Test: confirm SELinuxUncheckedDenialBootTest and
scanAvcDeniedLogRightAfterReboot tests can pass and no avc denials for euiccpixel
Change-Id: I07ae97d47bbb14c15da92611160b6a2a6af22a60
2023-02-01 16:34:17 +08:00
Nicole Lee
cddb6ad619
logger_app: allow access vendor_gps_file, vendor_gps_prop, vendor_logger_prop
...
Bug: 261519049
Bug: 261783031
Bug: 261933367
Test: Confirm no selinux denial for these 3 tcontexts
Change-Id: I6f919e193693f7521778321f677214ea9f3b4d84
2023-01-31 16:32:41 +00:00
Nicole Lee
b713236048
logger_app: allow logger_app access vendor_modem_prop
...
Bug: 260522268
Bug: 264600053
Test: Confirm no selinux denial for tcontext vendor_modem_prop
Change-Id: Ic4ed0cdd7fa33c1dd4c812528b26b4a19cf6537b
2023-01-31 16:32:32 +00:00
Nicole Lee
e6975cb6e5
logger_app: allow logger_app to access vendor_ssrdump_prop
...
Bug: 260366439
Test: Confirm no selinux denial for tcontext vendor_ssrdump_prop
Change-Id: I74009bdd3d8b0fa691a2d0132655dc08fcd50977
2023-01-31 16:32:24 +00:00
Nicole Lee
30e96b25ce
logger_app: allow logger_app to access radio files
...
Bug: 260366439
Bug: 260522268
Bug: 260769144
Bug: 261519049
Bug: 264600084
Test: Confirm no selinux denial for tcontext radio_vendor_data_file
Change-Id: I2a917d78e685aad5608e64f4d076cc50cdb064cc
2023-01-31 16:32:16 +00:00
sukiliu
383189e5f2
Update error on ROM 9541712
...
Bug: 267260951
Bug: 267261048
Bug: 267260619
Bug: 267260716
Bug: 267261305
Bug: 267261163
Bug: 267260675
Bug: 267261265
Bug: 267260717
Test: scanBugreport
Change-Id: I293fe1bc19f5f2d8f320d4e9feea051fc623ef8d
2023-01-31 14:18:11 +08:00
Joseph Jang
245e4205d1
citadel: Remove citadel.te for sepolicy testing
...
Test: VtsHalWeaverTargetTest
VtsAidlSharedSecretTargetTest
VtsHalIdentityTargetTest
VtsHalRemotelyProvisionedComponentTargetTest
VtsAidlKeyMintTargetTest
Bug: 264489777
Change-Id: I787aef6a0a924706ba2afccefff770408bb78294
2023-01-31 05:21:49 +00:00
Donnie Pollitz
34fe057526
sepolicy: Fix tee avc denials
...
tee policies were missing
Bug: 263304957
Bug: 263429986
Bug: 264489524
Test: boot and scanAvcDeniedLogRightAfterReboot passed
Change-Id: Ia3191496be005dbbbe331a14f7d45adace34b3fc
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-01-24 15:22:57 +01:00
Grace Chen
82ae431064
Merge "Fix selinux denials on hal_secure_element_uicc"
2023-01-24 02:10:51 +00:00
Grace Chen
e881d9d401
Fix selinux denials on hal_secure_element_uicc
...
Bug: 264489780
Test: Confirm no more selinux denials
Change-Id: Ib159acaf8701d0ac7e3325addd7baca6a41f0cee
2023-01-23 15:36:04 -08:00
Dinesh Yadav
3de9d17052
Merge "Allow camera HAL and GCA to access GXP device."
2023-01-18 07:33:32 +00:00
TreeHugger Robot
30fe55378d
Merge "Fix avc denied and remove tracking_denials for hal_usb_gadget_impl"
2023-01-17 06:07:41 +00:00
Ernie Hsu
87aa440b72
Merge "Remove tracking_denials for media related module"
2023-01-17 05:51:00 +00:00
Chung-Kai (Michael) Mei
ee6c28322a
Merge "sepolicy: fix avc denial"
2023-01-17 04:53:35 +00:00
Chungkai Mei
cc0f6a604d
sepolicy: fix avc denial
...
fix avc denial
Test: boot passed and no avc log after boot
Bug: 264483355
Change-Id: Idd9ef9ca7c988141bffd2d9d7e561efe8066cba4
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-01-17 04:53:13 +00:00
Ray Chi
6baa4fa226
Fix avc denied and remove tracking_denials for hal_usb_gadget_impl
...
Bug: 264946043
Test: no avc denied for hal_usb_gadget_impl
Change-Id: Ib52e6d089a0e3e73c619f35849af0aed478c1f65
2023-01-17 04:37:49 +00:00
Ernie Hsu
c2a4092ee6
Remove tracking_denials for media related module
...
All bugs in modified te files were already fixed
Bug: 264490072
Bug: 264489679
Bug: 264490012
Bug: 264489523
Test: test video recording/playback under enforcing mode
Change-Id: Iac7dc597f58dcc5f7bd936ddb607aa7158467a34
2023-01-17 03:45:37 +00:00
Dinesh Yadav
b068bb3f64
Allow camera HAL and GCA to access GXP device.
...
The camera HAL and Google Camera App
need selinux permission to run workloads on Aurora DSP. This
change adds the selinux rules too allow these clients to
access the GXP device in order to execute workloads on DSP.
Bug: 264321380
Test: Verified that the camera HAL service and GCA app is able to access the GXP device.
Change-Id: I125650b4841b4cbdc50077a0d80b113b02699de8
2023-01-17 03:21:04 +00:00
TreeHugger Robot
ef4c754dc4
Merge "Fix avc denied and remove tracking_denials for hal_usb_impl"
2023-01-16 09:55:32 +00:00
Dinesh Yadav
1ac5ca8485
Merge "Add SEPolicy settings for android logging/tracing service for GXP"
2023-01-16 08:05:51 +00:00
Ray Chi
0801e5e421
Fix avc denied and remove tracking_denials for hal_usb_impl
...
Fix avc denial for hal_usb_impl.
Bug: 263048760
Test: no avc denied for hal_usb_impl
Change-Id: Iaeea9d1f99f715c0f856a3a9f9fcd2e8d371f3d3
2023-01-16 15:40:48 +08:00
Chungkai Mei
171bfb004b
sepolicy: fix avc denial
...
fix avc denial
Test: bott passed and no avc log after boot
Bug: 260769063
Bug: 261105028
Bug: 260366126
Bug: 261650934
Bug: 262178497
Bug: 262315567
Bug: 262633072
Change-Id: I926d535fe6871726b5cd0602e436f6b5a3a9e736
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-01-16 02:55:37 +00:00
sukiliu
3b97d74811
Update error on ROM 9492984
...
Bug: 265587172
Test: SELinuxUncheckedDenialBootTest
Change-Id: I69402149121da5bbb0f2f89ca59c3ca458945d50
2023-01-16 09:36:14 +08:00