Commit graph

1370 commits

Author SHA1 Message Date
Nicole Lee
8749626448 Allows modem_svc to read the logging related properties am: 93020c0564
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I0f55efc6a18dd8e863debeaf47e32c67fbfdd6c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 00:29:58 +00:00
Nicole Lee
93020c0564 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
(cherry picked from commit 728e6baa64)
2024-01-05 04:40:14 +00:00
Daniel Norman
f2e746b644 Removes duplicate hidraw_device type definition. am: f219d38925
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25533485

Change-Id: Ie0b6287cb50284c1ae6fc6ab40f89506efb71887
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-02 01:02:35 +00:00
Daniel Norman
f219d38925 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Test: ls -z /dev/hidraw0
(cherry picked from commit 8ff4604573)
2023-12-02 00:01:28 +00:00
Daniel Norman
2729e96ec8 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Test: ls -z /dev/hidraw0
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Merged-In: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
(cherry picked from commit 8ff4604573)
2023-12-01 19:24:56 +00:00
Kyle Tso
2816dc3328 hal_usb_impl: Add get_prop for vendor_usb_config_prop am: 5775ea074a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25353179

Change-Id: Ie03d8b8da3e6ca672906764bebfc29ef6d3cf97e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 14:25:25 +00:00
Kyle Tso
5775ea074a hal_usb_impl: Add get_prop for vendor_usb_config_prop
avc:  denied  { read } for  comm="android.hardwar" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=391 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0

Bug: 310560098
Change-Id: I86588715cae2696dd0e045c5b75dde55e0f84c1e
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-11-23 08:33:04 +00:00
Chia-Chi Teng
650409d4b4 Merge "Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: edac582d40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25400378

Change-Id: I92c8528073ca783dba8f9de5c51dde3616da47c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 07:39:22 +00:00
Chia-Chi Teng
edac582d40 Merge "Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev 2023-11-23 07:07:04 +00:00
Chia-Chi Teng
d240d1b4e2 Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"
eb2dcaedc8

Change-Id: Idb64a3e6d60747273159682102a5367b99fe6833
2023-11-16 22:37:36 +00:00
Angela Wu
4746ff1aee [automerger skipped] Allows GCA to access the hw_jpeg /dev/video12. am: 77ce612093 -s ours
am skip reason: Merged-In I97a96bddaaca9e95f0596cd4eff0d7e80d6023d6 with SHA-1 6216625ef8 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25321138

Change-Id: Iad6a9cc9166ae916b05fc137d5c39ed315f01309
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-15 09:06:56 +00:00
Angela Wu
77ce612093 Allows GCA to access the hw_jpeg /dev/video12.
Bug: 309578078
Test: https://android-build.corp.google.com/builds/abtd/run/L41100030000291922

Merged-In: I97a96bddaaca9e95f0596cd4eff0d7e80d6023d6
Change-Id: I5b1649ec393d2f998159299b0f4feddcde4da80f
2023-11-15 06:28:23 +00:00
Angela Wu
6216625ef8 Allows GCA to access the hw_jpeg /dev/video12.
Bug: 309578078
Test: https://android-build.corp.google.com/builds/abtd/run/L93200030000133974
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0dde58951666a96f788a8a75bf63cde34079d48a)
Merged-In: I5b1649ec393d2f998159299b0f4feddcde4da80f
Change-Id: I5b1649ec393d2f998159299b0f4feddcde4da80f
This change is essentially a re-submission of ag/25305073 to an upstream branch.

Change-Id: I97a96bddaaca9e95f0596cd4eff0d7e80d6023d6
2023-11-09 10:09:31 +00:00
Chia-Chi Teng
5c827dca3a Revert^2 "bluetooth: Allow triggering AOC reset from BT HAL" am: eb2dcaedc8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25205134

Change-Id: I075a05a8ccf755700923c9de7106b57f7f876830
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-31 17:56:21 +00:00
Chia-Chi Teng
eb2dcaedc8 Revert^2 "bluetooth: Allow triggering AOC reset from BT HAL"
This reverts commit 0aa787efa8.

Reason for revert: Debug BT HCI timeout on UD2A build and P23 on main

Bug: 306646797
Test: presubmit PTS
Change-Id: Ia72ea9d0ba0209cce483d220b420933b243e05b3
2023-10-27 22:53:17 +00:00
jonerlin
a49aa2bdf1 allow hal_bluetooth_btlinux write sysfs file am: 127ca27edc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24947936

Change-Id: I183c49c5209e811166a96d2a9e2819bd29373b7c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-13 02:56:21 +00:00
jonerlin
127ca27edc allow hal_bluetooth_btlinux write sysfs file
Bug: 294747612
Test: v2/pixel-pts/release/bootstress/1200counts/suspend-resume
Change-Id: I62147f0b32156ede2a4e18e5a2bcb77fc2c91831
2023-10-13 09:00:07 +08:00
Brian Duddie
d1ddce264c Merge "Revert "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: c387226619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24948148

Change-Id: I59fbb4f03909803a422ff9a9abd17cae32eb7014
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-12 22:48:59 +00:00
Brian Duddie
c387226619 Merge "Revert "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev 2023-10-12 22:25:50 +00:00
Chia-Chi Teng
0aa787efa8 Revert "bluetooth: Allow triggering AOC reset from BT HAL"
Revert submission 24871772-bt-aoc-coredump

Reason for revert: b/300076774 root cause identified as b/299038059

Reverted changes: /q/submissionid:24871772-bt-aoc-coredump

Bug: 299038059
Change-Id: Ibd021c6b983c2eb390c268cf89f30e2e8ee54d21
2023-10-06 22:04:57 +00:00
Mike Wang
7eafbc0be0 Merge "Grant the MDS access to the IPowerStats hal service." into udc-qpr-dev am: fd78823dfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24610375

Change-Id: If95e8b46a87625618bce50a19690bf4773625e9a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-05 16:24:40 +00:00
Mike Wang
fd78823dfa Merge "Grant the MDS access to the IPowerStats hal service." into udc-qpr-dev 2023-10-05 15:55:47 +00:00
mikeyuewang
1ee598d5d2 Grant the MDS access to the IPowerStats hal service.
ref logs:
09-06 10:07:18.006   536   536 I auditd  : avc:  denied  { find } for pid=22543 uid=10225 name=android.hardware.power.stats.IPowerStats/default scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:object_r:hal_power_stats_service:s0 tclass=service_manager permissive=1
09-06 10:07:18.010 22543 22543 I auditd  : type=1400 audit(0.0:65): avc:  denied  { call } for  comm="pool-4-thread-1" scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:r:hal_power_stats_default:s0 tclass=binder permissive=1 app=com.google.mds

Test: Tested with MDS app and the MDS can get IPowerStats binder and
call the interface.

Bug: 297250368
Change-Id: I7b0eeabdafb49eb33d8016666f9c02f2616f898d
2023-09-28 15:22:00 +00:00
Brian Duddie
89d7732591 bluetooth: Allow triggering AOC reset from BT HAL am: 858f999657
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24869257

Change-Id: I5bdeb95ad44c69d2b8cd04f12dc7cde49580084c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-27 21:45:56 +00:00
Brian Duddie
858f999657 bluetooth: Allow triggering AOC reset from BT HAL
Supports debugging and recovery from fatal errors that do not trigger
AOC SSR on their own.

Bug: 300076774
Test: trigger SSR from BT HAL
Change-Id: I795b2c1830625e2cf05a9aa63c6f7ef273b01a87
2023-09-27 00:08:19 +00:00
Yixuan Wang
284bdc3fa5 Merge changes from topic "am-1b65f256ed6d44cb931295968c81bde7" into udc-qpr-dev-plus-aosp
* changes:
  Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
  Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
2023-09-15 18:38:02 +00:00
Yixuan Wang
0603f723f4 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: I307c73fcecb5e213ab186b4610a5be681262a680
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 18:14:42 +00:00
Yixuan Wang
cb920d586f Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Iba1c14faaf0c1e423f914ca860f83d75d5496a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 18:14:40 +00:00
Yixuan Wang
b02946bca9 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev am: adf19fcc76
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Ifbc5098189471983e87ef6e607b0a50e82b985a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 01:12:39 +00:00
Yixuan Wang
1c333dd6dc Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Id83469911f8d0f9bd997f53aa49176dc6c083bd5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 01:12:33 +00:00
Yixuan Wang
adf19fcc76 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev 2023-09-15 00:23:04 +00:00
Treehugger Robot
ed60a3086e Merge "Add required sepolicy rule for Camera" into udc-qpr-dev am: 64c085cfab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24418269

Change-Id: I28d9a36decdc7e2646ee17450804fae715cbc4f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-14 04:04:59 +00:00
Treehugger Robot
64c085cfab Merge "Add required sepolicy rule for Camera" into udc-qpr-dev 2023-09-14 03:20:33 +00:00
Tai Kuo
8cf4f20ca3 Allow regmap debugfs for drivers probed by insmod am: 1a65e5d5e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24727593

Change-Id: Ia298dbfa2909cea74711f2f10b0bdca3c301a0a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-12 23:42:40 +00:00
Pointer Kung
be9c098a46 Add required sepolicy rule for Camera
Grant access for TNR max_freq to let libperfmgr can control it via powerhint.

Bug: 298595475
Test: adb shell cat cur_freq, GCA, CTS
Change-Id: Ibea9d8b60a41802ba7d685daa591471a9e8cbd91
2023-09-12 09:16:01 +00:00
Tai Kuo
1a65e5d5e4 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I2bd35a6bc942536505f62d4122f0de892f243802
2023-09-12 16:45:09 +08:00
Treehugger Robot
207188241d Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev am: 4bb847b815
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24585767

Change-Id: I9df8bae38a17b05df787654de85517064fb7aaec
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-30 17:35:13 +00:00
Treehugger Robot
4bb847b815 Merge "audio: move related sepolicy of audio to gs-common" into udc-qpr-dev 2023-08-30 16:29:24 +00:00
Yixuan Wang
bd654f00d9 Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."
Revert submission 24526613-revert-23834879-CHRE BT LOG-MHDBQNZAGV

Reason for revert: Fixed and tested with a followup cl

Reverted changes: /q/submissionid:24526613-revert-23834879-CHRE+BT+LOG-MHDBQNZAGV

Change-Id: I29866a91abfcfa380d772da447eb95344df43f8f
2023-08-29 19:17:32 +00:00
Safayat Ullah
2c7187af19 display: add persist property to vendor_display_prop am: ea09b155f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: If21c57942053863ff2157d88a4810a81b30a03f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 13:34:23 +00:00
Safayat Ullah
ea09b155f2 display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I60747df56c6993251bc736994da828814bcdf607
Merged-In: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 09:06:57 +00:00
Jasmine Cha
8fb992eacb audio: move related sepolicy of audio to gs-common
Bug: 297482504
Test: build pass

Change-Id: I9444b9e63f32bf898c845e42edbf682798bce300
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-08-29 16:45:47 +08:00
Sebastian Pickl
00b4a62dd1 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev am: ae9ab242e8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I79952f32ed00fface67437449575e7750959bca5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:25 +00:00
Sebastian Pickl
7ee5ae18de Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I3e4c175289017c75c26df4029421b61ad4efcfbe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:24 +00:00
Sebastian Pickl
ae9ab242e8 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev 2023-08-24 10:06:57 +00:00
Sebastian Pickl
84f1209636 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."
Revert submission 23834879-CHRE BT LOG

Reason for revert: fixes broken test b/297255998 verified by go/abtd: https://android-build.googleplex.com/builds/abtd/run/L30000000962735539
Bug:297255998

Reverted changes: /q/submissionid:23834879-CHRE+BT+LOG

Change-Id: I56b800260303834ed76dedf354b5a32af00b3684
2023-08-24 09:47:19 +00:00
Yixuan Wang
4773f8519d Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev am: 0fcc802265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: I819f616efd223718dd98bb8e953d3b020a296e80
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:30 +00:00
Yixuan Wang
2058641a14 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: Id8058dbdf765871ba8e762ed10dd1af309642351
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:24 +00:00
Yixuan Wang
0fcc802265 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev 2023-08-23 19:29:45 +00:00
Kris Chen
beed400798 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 7f3e2b9212
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I61b5d78945f4606a1a8924c2ba9e1e4b887d5895
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:08:39 +00:00