Commit graph

2173 commits

Author SHA1 Message Date
Roy Luo
6c5b44f1bb hal_usb_impl: Grant read permission to usb overheat files
Carried over from WHI PRO setting.

Bug: 307583011
Test: no audit logs
Change-Id: I45bb396f2597a4a8c150ad2975ecfa427d44f2a9
2024-02-07 05:18:41 +00:00
Treehugger Robot
a1c60e8b9e Merge "Allow camera_app can access priv-app symlinks" into main 2024-02-06 09:32:27 +00:00
Wilson Sung
332714ffac Allow camera_app can access priv-app symlinks
Fix: 322417347
Test: make selinux_policy
Change-Id: I467667b3a824a2e8b93e47c61c28ed9015fd44c3
2024-02-06 08:36:39 +00:00
Hongbo Zeng
cfe12763f2 Allow con_monitor_app to read/write the folder /data/vendor/radio
Bug: 322266425
Test: after apply the patch, we can see the adum_log/adum_log_old files
      are included in dumpstate_board.bin successfully without denial

Change-Id: Ic488a84a1942fbc424b08aa0cbd4d526014152cd
2024-02-02 15:42:31 +00:00
Wilson Sung
fdc9af0d88 Update error on ROM 11396046
Bug: 323471016
Test: SELinuxUncheckedDenialBootTest
Change-Id: I79953f209f474b8d71e06e197795b0d55c3ffce3
2024-02-02 08:04:40 +00:00
Kyle Tso
98972beada Allow dump_power to read sysfs directories
dump_power needs to read the directories under /sys/class/power_supply.

Bug: 320613177
Bug: 322294676
Change-Id: I7bc55b90d67a1d05bb097955ed632d62535e0f40
Signed-off-by: Kyle Tso <kyletso@google.com>
2024-01-31 07:01:55 +00:00
Wilson Sung
bbd26c9cb8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 323086582
Test: scanBugreport
Bug: 323087490
Test: scanAvcDeniedLogRightAfterReboot
Bug: 323087197
Change-Id: I99006484464f82125a63be9c26eb8d8051c57840
2024-01-31 02:58:43 +00:00
Xin Li
6235550122 [automerger skipped] Merge Android 24Q1 Release (ab/11220357) am: a05a0cb116 -s ours
am skip reason: Merged-In I4a01be73d76a577d8da07c36276349525c0fda68 with SHA-1 b3e48816fa is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25972529

Change-Id: I3c95d14460c6bf995223a283b8856ffcbc7f72e5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-31 02:03:39 +00:00
Kadi Narmamatov
0d82eda10f Merge "Revert "rfsd: add new property to sepolicy"" into main 2024-01-30 08:36:00 +00:00
Kadi Narmamatov
aef38ed6a7 Revert "rfsd: add new property to sepolicy"
Revert submission 25709311-rfsd-efs-erase

Reason for revert: we don't need it for this repo, only for pro

Reverted changes: /q/submissionid:25709311-rfsd-efs-erase

Bug: 315104803

Change-Id: I54e24ae99087b102c1a2f677ce4a7b2cad670992
2024-01-30 07:02:22 +00:00
Kieran Cyphus
4562b9e4e1 Merge "liboemservice_proxy: Update sepolicy to hal" into main 2024-01-29 05:58:46 +00:00
Daniel Chapin
6a6f65b5e5 Merge "Revert "Allow dump_power to read directories under "/sys/class/p..."" into main 2024-01-25 22:59:25 +00:00
Daniel Chapin
a5df4f07bf Revert "Allow dump_power to read directories under "/sys/class/p..."
Revert submission 25915320-320613177

Reason for revert: Droidfood blocking bug: 322294676

Reverted changes: /q/submissionid:25915320-320613177

Change-Id: I5545dcd73cdce5ae029444c313bf5dc3f642a5c0
2024-01-25 21:44:18 +00:00
kierancyphus
0cdeda46b2 liboemservice_proxy: Update sepolicy to hal
This was wrongly configured originally, and has instead been modified to
follow the advice from
https://source.android.com/docs/core/architecture/aidl/aidl-hals#sepolicy.

Test: atest vts_treble_vintf_vendor_test:DeviceManifest/SingleAidlTest
Bug: 321867236

Change-Id: I75df4696660b2c052324313785b244c263ebd75b
2024-01-25 17:51:51 +08:00
Angela Wu
b042c7713f [automerger skipped] Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device am: 3b30421350 -s ours
am skip reason: Merged-In If77a097b4ca823322ef41b13d6283390dac69d6c with SHA-1 0d32d1c172 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25983001

Change-Id: I5424ea5b92ff1b9bff957b86bfabf6dccb766f22
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-25 02:19:53 +00:00
Treehugger Robot
ab46db5fef Merge "Add capacity_headroom to gpu sysfs" into main 2024-01-24 23:30:45 +00:00
Sean Callanan
d7decd5eee Add capacity_headroom to gpu sysfs
This allows userspace (notably the power HAL) to apply a boost to GPU
frequency independent of previously measured load.

Bug: 290625326
Test: boot, run modified Power HAL
Change-Id: Ia71266ee751a36a960706ac8aacc7fdefdf8a0f0
2024-01-24 21:46:23 +00:00
Angela Wu
3b30421350 Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device
Bug: 320410642
Test:m
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0d32d1c172c19186a7ac4fd3eb316a9b947d612d)
Merged-In: If77a097b4ca823322ef41b13d6283390dac69d6c
Change-Id: If77a097b4ca823322ef41b13d6283390dac69d6c
2024-01-24 09:47:42 +00:00
Weizhung Ding
3d156c0ad6 [displayport-stats] add sysfs access permission on Zuma devices.
Bug: 266898132
Test: Build
Change-Id: I4c5bd4729f837c843668c447abbbe4c34beb3fce
2024-01-24 08:28:40 +00:00
Wilson Sung
abb7616f3d Merge "Update Tracking Denial Bug Map" into main 2024-01-24 07:56:49 +00:00
Imo Richard Umoren
770a65f4a9 Update Tracking Denial Bug Map
Removes tracking denial for twoshay from bug map

Bug: b/315104941
Test: Manually tested on HK3 DVT
Change-Id: I6cd8f390e98fc98925ed807a2ff24a33c51c75cd
2024-01-22 18:32:09 +00:00
Kyle Tso
4e48a45727 Allow dump_power to read directories under "/sys/class/power_supply"
Bug: 320613177
Change-Id: I1a39ddb5fbbf4c62fa5b96e3562b34f2f2091c13
Signed-off-by: Kyle Tso <kyletso@google.com>
2024-01-22 08:52:59 +00:00
Xin Li
a05a0cb116 Merge Android 24Q1 Release (ab/11220357)
Bug: 319669529
Merged-In: I4a01be73d76a577d8da07c36276349525c0fda68
Change-Id: I44d74dbe5baa23c7b90c7a6703dee5e856801942
2024-01-17 22:13:21 -08:00
Wilson Sung
2d8e52e176 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 320693841
Change-Id: Ia3ffe885f02a8db86d6bd024d34135fd1ce30d7b
2024-01-17 17:42:53 +00:00
Angela Wu
740cebf8f0 Merge "Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device" into main 2024-01-17 00:32:01 +00:00
Wilson Sung
148d3558f8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 319403445
Change-Id: I470afdd191741401c197ae32bfff18e9d8b90a96
2024-01-16 19:20:02 +00:00
Angela Wu
0d32d1c172 Change the type of hw_jpg_device for selinux policy so that the GCA release flavor could access hw_jpg_device
Bug: 320410642
Test:m

Change-Id: If77a097b4ca823322ef41b13d6283390dac69d6c
2024-01-16 08:51:05 +00:00
Treehugger Robot
feffef59dd Merge "Allow Powerstats service to access refresh rate residency node" into main 2024-01-15 01:24:29 +00:00
Midas Chien
d6e79769c1 Allow Powerstats service to access refresh rate residency node
Bug: 315424658
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I86288b4f523b4463a46d710a6556fa6852d4bea0
2024-01-12 13:01:17 +00:00
Mahesh Kallelil
389a451f8f Merge "Remove modem_svc selinux error from denials bug_map" into main 2024-01-12 06:43:44 +00:00
Mahesh Kallelil
1d8bcd694b Remove modem_svc selinux error from denials bug_map
This property was removed and is not being used anymore. So
modem_svc will not need to read it.

Bug: 316816737
Change-Id: Iaee56d15ca69e91fe952eaa188d3aaec69edf5dc
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2024-01-11 09:48:44 -08:00
Inseob Kim
80e1b3708f Label dtbo_block_device with flag-guarding am: 0c15160cad am: f817f9b687 am: bd1ea77736
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I445a175dd8daabc19da05f9d08690955d836f21c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 04:07:09 +00:00
Inseob Kim
bd1ea77736 Label dtbo_block_device with flag-guarding am: 0c15160cad am: f817f9b687
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I88784ab20f5e4a4c97000784e426a446a769777c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 03:02:37 +00:00
Inseob Kim
f817f9b687 Label dtbo_block_device with flag-guarding am: 0c15160cad
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903809

Change-Id: I0f245e7f165401304b99d07ef7c064d9d86f0a74
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-11 02:31:13 +00:00
Inseob Kim
64fd14fdd8 Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c am: 478449e638 am: 93607ec24a
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: I9b7a68fd405327f22a08b9ba8759a45ee51a8b35
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 10:55:30 +00:00
Inseob Kim
93607ec24a Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c am: 478449e638
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: Ib54efad23c80ce27e140270759cada42332dd77b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 10:24:49 +00:00
Inseob Kim
478449e638 Revert "Label dtbo partition as dtbo_block_device" am: f05143f43c
Original change: https://android-review.googlesource.com/c/device/google/zuma-sepolicy/+/2903808

Change-Id: If197a913485f18554bf650c37c85911afa00a804
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-10 09:54:32 +00:00
Inseob Kim
0c15160cad Label dtbo_block_device with flag-guarding
Bug: 319035582
Test: run device assignment demo
Change-Id: I813be88391c9ff79d94e504149963160f1d74b2c
2024-01-10 17:02:34 +09:00
Inseob Kim
f05143f43c Revert "Label dtbo partition as dtbo_block_device"
This reverts commit 3773ca269e.

Reason for revert: b/319035582

Bug: 319035582
Test: boot
Change-Id: I3c2a5b5bc871aa506396c12d6e1fa036858c1273
2024-01-10 17:02:14 +09:00
Ken Yang
137c2ebd5a selinux: label wakeup for BMS I2C 0x36, 0x69
Bug: 319035561
Change-Id: Ib57dba71691f70b75fbae23208125fa750b32dc1
Signed-off-by: Ken Yang <yangken@google.com>
2024-01-10 06:14:37 +00:00
Lei Ju
52beafc4c4 [zuma] Use common settings for Contexthub HAL
Test: compilation
Bug: 248615564
Change-Id: I6691b23af6e532584f4dee9618c264b20b8873c0
2024-01-07 20:10:59 -08:00
Aaron Tsai
8b02313642 Remove tracking for b/316991604.
- no need to fix, so just remove the tracking record

Bug: 316991604
Test: manual test
Change-Id: Ifa70774650d3beaed5abd57297a3372f8d33661e
2024-01-08 02:58:11 +00:00
Treehugger Robot
d8c8e6f873 Merge "face: remove tracking for 305600857" into main 2024-01-08 01:06:39 +00:00
Nicole Lee
a03af7a36c Allows modem_svc to read the logging related properties am: 93020c0564 am: 8749626448
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I7934a5ed2936e9f42ed022fa1853974cab5019a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 01:00:09 +00:00
Nicole Lee
8749626448 Allows modem_svc to read the logging related properties am: 93020c0564
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25806672

Change-Id: I0f55efc6a18dd8e863debeaf47e32c67fbfdd6c5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-06 00:29:58 +00:00
Nicole Lee
93020c0564 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
(cherry picked from commit 728e6baa64)
2024-01-05 04:40:14 +00:00
Ilya Matyukhin
0e9173dfa2 face: remove tracking for 305600857
The policy was fixed in:
Ia8e4599e7cd44c815e88a34ee7d9229a3391b598

Bug: 305600857
Test: adb logcat | grep "avc:"
Change-Id: I831acc083c118ca35d095d040aedcd9b85cfb3a5
2024-01-04 22:23:16 +00:00
Treehugger Robot
b808c32b7d Merge "Allows modem_svc to read the logging related properties" into main 2024-01-04 10:09:18 +00:00
Nicole Lee
728e6baa64 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=387 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 316250607
Change-Id: If1942986a0804e24b13c021740f7df8f406e53c2
2024-01-02 08:50:36 +00:00
Kiyoung Kim
0d7dcca863 Remove SELinux error from b/313804706
Remove SELinux error from b/313804706 as the issue is solved now.

Bug: 313804706
Test: No selinux denial error from boot with husky-trunk_staging-userdebug build
Change-Id: I19c7fba663abac4d180b6a144f0aff5d108806f6
2024-01-02 04:30:16 +00:00