Commit graph

561 commits

Author SHA1 Message Date
TreeHugger Robot
bd9251a800 Merge "Allow vendor_init to modify read_ahead_kb" 2023-02-08 05:20:57 +00:00
TreeHugger Robot
728de48e51 Merge "Add extcon related contexts" 2023-02-08 05:16:56 +00:00
Wilson Sung
5f27d9f524 Merge "Remove usb obsolete denials" 2023-02-08 05:15:48 +00:00
Wilson Sung
65575203b2 Remove usb obsolete denials
Bug: 261651009
Change-Id: I59f376d504e82e39feef1d96bfe3ec636dcf6ca0
2023-02-08 05:15:20 +00:00
Wilson Sung
856d2c480e Allow kernel to access firmware and zram
Bug: 260522245
Change-Id: I964ac1e30e0181f4d6edc71f2e066b7bd515186b
2023-02-08 05:08:04 +00:00
TreeHugger Robot
9cce214473 Merge "Add required sepolicy rules for Camera function" 2023-02-08 05:00:08 +00:00
Wilson Sung
fd39573ce5 Remove dontaudit vendor_init to set ssr properties
Bug: 267843409
Change-Id: I74a222e90b3dd0e2dad91632b73fcad1211a7974
2023-02-08 12:44:56 +08:00
Wilson Sung
5dbc57e7ae Allow vendor_init to modify proc_sched
Bug: 263185566
Change-Id: I4a333ffd423e88af81e4c244cc7140ebd826a170
2023-02-08 12:28:31 +08:00
Wilson Sung
df495af425 vendor_init: Add getattr to modem_img
Bug: 63185566
Change-Id: I29fd72ba5e1482d629bc28edfd7782c6f24fe68f
2023-02-08 12:26:10 +08:00
Wilson Sung
926deec5d4 Allow vendor_init to modify read_ahead_kb
Bug: 264489786
Change-Id: I26d5682b3b056c8c8e00fc08581c96dcbaa27ef9
2023-02-08 04:07:22 +00:00
Wilson Sung
cb79685556 Add extcon related contexts
Bug: 260366030
Change-Id: I9b15741820ad284e50593b5467407b773ae15ec8
2023-02-08 12:06:31 +08:00
Karuna Ramkumar
15da9ccf58 zuma: Allow HWC to access graphics allocator hal
Bug: 268268619
Change-Id: Iac85dc60b5201ab85fbf74bf3af6722ac31c5b94
2023-02-07 20:06:30 -08:00
TreeHugger Robot
4e02d08f95 Merge "[SELinux] Fix hal_uwb_default dumpstate errors" 2023-02-08 01:43:53 +00:00
George Lee
0322b923b7 Remove tracking denial for system_boot_reason
Bug: 263525155
Test: Local boot
Change-Id: Iab1411871a66c60a604ee8b0fce0505a88973792
Signed-off-by: George Lee <geolee@google.com>
2023-02-07 17:07:19 +00:00
Wilson Sung
5f48d4f516 Add required sepolicy rules for Camera function
Bug: 263184920
Bug: 263305107
Change-Id: Idadf878564333a931b90da2415efe109e75e222a
2023-02-07 21:20:12 +08:00
Rex Lin
f1f25dc94f [SELinux] Fix hal_uwb_default dumpstate errors
Bug: 263048994
Test: http://ab/I62800010129138096
Change-Id: I4fc3dedb8e35e4d7520acded58d66f5206565afb
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-02-07 08:17:54 +00:00
Ernie Hsu
0e1559162e Merge "Fix sepolicy for mediacodec_google and mediacodec_samsung" 2023-02-07 07:57:52 +00:00
TreeHugger Robot
9f95eb9cd1 Merge "Update error on ROM 9558720" 2023-02-07 06:06:39 +00:00
Ernie Hsu
f7adc840df Fix sepolicy for mediacodec_google and mediacodec_samsung
mediacodec_google and mediacodec_samsung could be audited

Test: atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
      No fail associated with mediacodec_google and mediacodec_samsung
Bug: 262794938
Bug: 262794428
Bug: 262793919
Change-Id: I0ebac8c5c25ae89ecc8907f0f141f5ec1d8aaa0b
2023-02-07 05:48:58 +00:00
TreeHugger Robot
90730e60fd Merge "sepolicy: label required wakeup nodes for system suspend" 2023-02-07 04:20:28 +00:00
sukiliu
341afe161d Update error on ROM 9558720
Bug: 267843291
Bug: 267843408
Bug: 267843310
Bug: 267843409
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4d8f448d9019232222f2e8385bb2f4b3cf5f5336
2023-02-07 11:29:45 +08:00
TreeHugger Robot
0d013cb30e Merge "Fix denials for radio service to access files under /data/venodr/radio" 2023-02-07 03:08:30 +00:00
Darren Hsu
1934546586 sepolicy: label required wakeup nodes for system suspend
Bug: 260366031
Bug: 264204215
Test: run singleCommand pts -m PtsSELinuxTestCases
Change-Id: Icf8c4669156a0017655981fda8619ce0a75dce4d
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-02-07 10:12:30 +08:00
Timmy Li
5533264ba9 Merge "Add UW cornerfolk to file_contexts" 2023-02-07 02:09:54 +00:00
timmyli
d784c55c20 Add UW cornerfolk to file_contexts
Device needs access to cornerfolk. Evidence log in comments.

Bug: 267696227
Test: log check
Change-Id: If6bd49b76038673ad12fc6a1e7abd10b4cd3407e
2023-02-07 02:09:46 +00:00
TreeHugger Robot
30036eeebc Merge "Remove dontaudit for nfc" 2023-02-07 02:08:28 +00:00
TreeHugger Robot
161099cfe2 Merge "Remove dontaudit for st54spi" 2023-02-07 02:08:21 +00:00
TreeHugger Robot
cdc2d14883 Merge "sepolicy: label ODPM device nodes for hal_power_stats" 2023-02-07 02:05:46 +00:00
Darren Hsu
9964fd2901 sepolicy: label ODPM device nodes for hal_power_stats
Bug: 268002261
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I1dfd7760c4a958e0b31258a8379f3c68eb054f35
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-02-06 21:44:17 +08:00
Donnie Pollitz
1fd0c782b4 sepolicy: Fix trusty_metricsd avc denials
* Suez data collection missing

Bug: 264489526
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I667e35c68139a3368655cab4ea40acb529bb65ef
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:31 +00:00
Donnie Pollitz
1df4e2dde8 sepolicy: Fix trusty_apploader avc denials
* File permissions missing

Bug: 263305034
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot

Change-Id: I5d0a56a4c31c66610414341118c4089d2c11f3e9
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:22 +00:00
George
aa76e6db12 Remove dontaudit for st54spi
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for st54spi

Bug: 264489677
Test: manually check dumpsys secure_element
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I587caa423d3e1d23d9666fb732c0cc350934538f
2023-02-06 07:27:12 +00:00
Jenny Ho
6f15645932 Merge "Add permission for logbuffer_bd" 2023-02-06 03:53:19 +00:00
Hongbo Zeng
a82ea96b40 Fix denials for radio service to access files under /data/venodr/radio
Bug: 263792405
Test: get PASS result with go/ril-config-service-test and the original
      denial logs in https://b/263792405#comment17 are gone
Change-Id: Id6d64bb3e159b083e1a1b4c8e728e992fb9b1502
2023-02-06 03:47:01 +00:00
Jenny Ho
4e6cfb143d Add permission for logbuffer_bd
Bug: 242679204
Change-Id: I7376f10dc183bac805c89d6905e70a7b92694471
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 14:06:06 +08:00
Jenny Ho
31f750da2b sepolicy: add sepolicy for disable.battery.defender
[    7.536208] type=1107 audit(1671575809.144:22): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=vendor.battery.defender.disable pid=381 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=property_service permissive=1'

Bug: 263305106
Change-Id: Ia7adfe7f128c6390128447b9363ecd3615694fb1
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 13:09:28 +08:00
Ken Yang
af9057e7fb WLC: Add required sysfs_wlc sepolicies
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.

Bug: 267171670
Change-Id: If2b5b007f4a24e91b2be83bb20676eb449b9415f
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-05 01:00:01 +00:00
George
40b805af57 Remove dontaudit for nfc
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for nfc

Bug: 263185547
Bug: 264490053
Test: atest NfcNciInstrumentationTests
Test: atest NfcNciUnitTests
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: Idc9eced1ae7248cf0883a5e42db2c5e55cb65c3b
2023-02-04 22:37:34 +08:00
Welly Hsu
a8526b30e0 Merge "Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot" 2023-02-04 05:55:56 +00:00
Joseph Jang
114b7b8f09 Merge "citadel: Remove citadel.te for sepolicy testing" 2023-02-03 02:08:12 +00:00
Cyan_Hsieh
79bd040d55 Add gcf partition to OTA domain
This allows the OTA mechanism to write to the bootloader slot to
perform the actual OTA

Bug: 263218204
Change-Id: Iec3f3aa73344f4e9a305bc3c1c3f2db7624aca93
2023-02-02 18:08:51 +08:00
TreeHugger Robot
075f213ece Merge "hal_graphics_composer_default: fix sepolicy denials" 2023-02-02 06:11:49 +00:00
TreeHugger Robot
e9d7a18f5d Merge "selinux: fix mitigation_vendor_file access" 2023-02-02 04:40:09 +00:00
Nicole Lee
7c21f689ea Merge "logger_app: allow logger_app to access vendor_slog_file" 2023-02-02 04:11:39 +00:00
Nicole Lee
704656a367 Merge "logger_app: allow logger_app to access vendor_rild_prop" 2023-02-02 04:11:28 +00:00
Nicole Lee
34f87b6396 Merge "logger_app: allow logger_app to access sysfs_sscoredump_level and vendor_ramdump_prop" 2023-02-02 04:11:18 +00:00
Nicole Lee
5bdbf4194b Merge "logger_app: allow logger_app to access logd_prop" 2023-02-02 04:11:03 +00:00
Nicole Lee
20dedc5cc6 Merge "logger_app: allow logger_app to access logpersistd_logging_prop" 2023-02-02 04:10:50 +00:00
TreeHugger Robot
de674e9f3b Merge "logger_app: allow logger_app to access vendor_audio_prop" 2023-02-02 04:09:35 +00:00
Nicole Lee
140780f8a4 Merge "logger_app: allow logger_app to access vendor_wifi_sniffer_prop" 2023-02-02 03:06:45 +00:00