Commit graph

2173 commits

Author SHA1 Message Date
Jasmine Cha
839ddde474 audio: remove denials list for dcservice
Bug: 299553227
Test: boot to home with test build b/299553227#comment8

Change-Id: I9ee23a9aa753d891d233e337908c2091d63f3834
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-12-28 05:10:34 +00:00
Lei Ju
5a4795ccd7 Merge "[zuma] Update chre sepolicy for socket connection" into main 2023-12-28 03:50:00 +00:00
Ján Sebechlebský
26b57fcdc6 Merge "Remove bug_map entry for dumpstate <-> virtual_camera" into main 2023-12-27 15:31:07 +00:00
Jan Sebechlebsky
76ea521186 Remove bug_map entry for dumpstate <-> virtual_camera
The denial was fixed in aosp/2852613.

Bug: 312894238
Test: N/A
Change-Id: I3121489729e23afa10904cb97f547e965e0c68f4
2023-12-27 14:04:36 +01:00
Lei Ju
8587126f45 [zuma] Update chre sepolicy for socket connection
With multiclient HAL, the socket server domain changes from chre to
hal_contexthub_default.

Bug: 248615564
Test: updated the sepolicies and observed that avc violation logs
      disappears.
Change-Id: I4b2d27b436c9d81bd0d0cdc5b3c1540884c37fec
2023-12-27 00:02:57 -08:00
timtmlin
404089ca94 Remove obsolete entries
Bug: 315720601
Bug: 315720874
Test: make
Change-Id: I538c76e009c6d29c9d2cac39778decc679446906
2023-12-27 15:23:58 +08:00
Wilson Sung
5b30dbfbb3 Allow SysUI to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui_app the write access to
  wm_trace_data_file

Bug: 251513116
Fix: 288049075
Test: make sepolicy
Change-Id: Ifa5a5281c6e8c7ecedcd601fc8cc58c4be6bdc3b
2023-12-27 11:01:12 +08:00
Shiyong Li
569134db41 Merge "display: support primary display preferred mode property" into main 2023-12-22 19:54:46 +00:00
Chi Zhang
f965c0b222 Merge "Allow GRIL to get power stats." into main 2023-12-22 19:29:06 +00:00
Kadi Narmamatov
09c85a0567 Merge "rfsd: add new property to sepolicy" into main 2023-12-22 09:10:49 +00:00
Shiyong Li
d26ab660b8 display: support primary display preferred mode property
Bug: 315895938
Test: check default mode after factory reset
Change-Id: Ia5a4c12537d50faf54ed5ea82d24e52a623c34e3
Signed-off-by: Shiyong Li <shiyongli@google.com>
2023-12-21 20:12:45 +00:00
Wilson Sung
79ba49730b Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 317316633
Change-Id: I8c1b97d6c65ec06e0a13e1447538f7cebf21d962
2023-12-21 07:37:01 +00:00
kadirpili
5c28db1f6b rfsd: add new property to sepolicy
Bug: 307481296
Change-Id: Icd287f863fd6d309297ce984f4ce387fb5d3ae24
2023-12-20 07:27:32 +00:00
Chi Zhang
a2e8969139 Allow GRIL to get power stats.
SELinux : avc:  denied  { find } for pid=3147 uid=10219 name=android.hardware.power.stats.IPowerStats/default scontext=u:r:grilservice_app:s0:c219,c256,c512,c768 tcontext=u:object_r:hal_power_stats_service:s0 tclass=service_manager permissive=1

Bug: 286187143
Test: build and boot
Change-Id: I6df25e78ba8fa8efaa7f51aed8e981ac382dcd29
2023-12-19 12:22:08 -08:00
Wilson Sung
f8f64b668c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316991604
Change-Id: Ic90ace8d5b6ac787030f6fd26d96f41677fcca42
2023-12-19 06:27:10 +00:00
Wilson Sung
31c017f325 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 316816737
Bug: 316816642
Change-Id: Ie61999d23158c81e2acb4d23eb106cb6f61f9b88
2023-12-18 03:28:40 +00:00
Imo Richard Umoren
b3e48816fa Twoshay: Add SELinux Permissions for CHRE [Zuma]
Adds connection and write permissions for chre socket to SELinux policy.
Used for the Wallaby nanoapp.

Bug: b/315347346
Bug: b/314721681
Test: Manually tested on SB3 Proto 1.0
Change-Id: I4a01be73d76a577d8da07c36276349525c0fda68
2023-12-12 17:23:35 +00:00
Wilson Sung
259348f8f7 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315720601
Test: scanBugreport
Bug: 315720874
Bug: 315104803
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104803
Change-Id: If15ba27fec6c876984823f8bb214bb7db59f7fd2
2023-12-11 02:54:00 +00:00
Wilson Sung
2ecdf16781 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 315104235
Test: scanBugreport
Bug: 315104508
Bug: 315104235
Test: scanAvcDeniedLogRightAfterReboot
Bug: 315104941
Bug: 315104235
Change-Id: Icb01366f95e6ca4001246215e487d702131b6947
2023-12-06 10:44:09 +00:00
David Drysdale
7beccb101a Merge "Add Secretkeeper HAL" into main 2023-12-06 10:21:03 +00:00
David Drysdale
98448f5628 Add Secretkeeper HAL
Test: VtsAidlAuthGraphSessionTest
Bug: 306364873
Change-Id: I57de11a4c08476979e9283914a552a90254ee3fb
2023-12-05 10:39:26 +00:00
Ray Chi
7e755bb143 Add eusb_repeater to vendor_usb_debugfs context
Bug: 305145476
Test: adb bugreport
Change-Id: I8fe6eebb43ed80de486d93882879512d0918acee
2023-12-05 16:38:16 +08:00
Jason Chiu
47c545c8b0 zuma: move sepolicy related to bootctrl hal to gs-common
Bug: 265063384
Change-Id: Ic99547173f6eade30bce2d60051163336b27ca3b
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-12-05 00:45:55 +08:00
Wilson Sung
7e977d05b5 Merge "Update SELinux error" into main 2023-12-04 02:33:03 +00:00
Daniel Norman
5f8ba1c0d3 Removes duplicate hidraw_device type definition. am: f219d38925 am: f2e746b644
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25533485

Change-Id: Id71f76f518ee2dd74cb7dc4ce0cfc3253853fb1b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-02 01:52:12 +00:00
Daniel Norman
f2e746b644 Removes duplicate hidraw_device type definition. am: f219d38925
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25533485

Change-Id: Ie0b6287cb50284c1ae6fc6ab40f89506efb71887
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-02 01:02:35 +00:00
Daniel Norman
f219d38925 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Test: ls -z /dev/hidraw0
(cherry picked from commit 8ff4604573)
2023-12-02 00:01:28 +00:00
Daniel Norman
979e64b5f2 [automerger skipped] Removes duplicate hidraw_device type definition. am: 2729e96ec8 -s ours
am skip reason: Merged-In Ic46a7327bb2dab89f424cde2682a40f2b28a04db with SHA-1 8ff4604573 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25531285

Change-Id: I1f0d61fa7d734e739070c1e23cda82d727d66944
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-01 23:27:20 +00:00
Daniel Norman
2729e96ec8 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Test: ls -z /dev/hidraw0
Change-Id: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
Merged-In: Ic46a7327bb2dab89f424cde2682a40f2b28a04db
(cherry picked from commit 8ff4604573)
2023-12-01 19:24:56 +00:00
Dario Freni
2584e99c58 Merge "Revert "zuma: move sepolicy related to bootctrl hal to gs-common"" into main 2023-12-01 13:00:07 +00:00
Sebastian Pickl
fbe923d20a Revert "zuma: move sepolicy related to bootctrl hal to gs-common"
Revert submission 25477883-gs-common_bootctrl-aidl

Reason for revert: breaking builds b/314240126

Bug: 314240126

Reverted changes: /q/submissionid:25477883-gs-common_bootctrl-aidl

Change-Id: I84dda0a7c98ed1d1f7958734761c9c1a0bd9d169
2023-12-01 11:30:45 +00:00
Treehugger Robot
421b5abf97 Merge "zuma: move sepolicy related to bootctrl hal to gs-common" into main 2023-12-01 03:57:28 +00:00
Treehugger Robot
124e7aa639 Merge "Suppress avc error log on debugfs's usb folder." into main 2023-11-30 23:26:22 +00:00
Luis Delgado De Mendoza
76972151b2 Merge "Add sepolicy entries for new BT channel" into main 2023-11-30 16:21:41 +00:00
Wilson Sung
14dda6e255 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 314054292
Test: scanBugreport
Bug: 313804706
Bug: 312894238
Change-Id: Ibf9517b585dcd8e06c62075d85dc55eb8ed7d18d
2023-11-30 07:14:04 +00:00
Khoa Hong
fb1c8b60bb Suppress avc error log on debugfs's usb folder.
The XHCI driver in kernel will write debugging information to DebugFS on
some USB host operations (for example: plugging in a USB headphone). We
are not using those information right now.

Bug: 311088739
Test: No error when plugging a USB headphone in.
Change-Id: I3a8e2290e97967c02453eadff440d8bbeefa31b1
2023-11-30 14:50:52 +08:00
Jason Chiu
23feade4db zuma: move sepolicy related to bootctrl hal to gs-common
Bug: 265063384
Change-Id: I230ca394c5d1b6e68dd8b4d51ea06568810eb4e0
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-11-27 17:45:29 +08:00
Treehugger Robot
9c8cb72283 Merge "allow vendor init to access percpu_pagelist_high_fraction" into main 2023-11-27 01:45:54 +00:00
Kyle Tso
9bd6f5ebd1 hal_usb_impl: Add get_prop for vendor_usb_config_prop am: 5775ea074a am: 2816dc3328
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25353179

Change-Id: I8745571157eb29f5809b338383c11aa64a1c67ba
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 14:58:34 +00:00
Kyle Tso
2816dc3328 hal_usb_impl: Add get_prop for vendor_usb_config_prop am: 5775ea074a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25353179

Change-Id: Ie03d8b8da3e6ca672906764bebfc29ef6d3cf97e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 14:25:25 +00:00
Kyle Tso
5775ea074a hal_usb_impl: Add get_prop for vendor_usb_config_prop
avc:  denied  { read } for  comm="android.hardwar" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=391 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0

Bug: 310560098
Change-Id: I86588715cae2696dd0e045c5b75dde55e0f84c1e
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-11-23 08:33:04 +00:00
Chia-Chi Teng
59af5f70be Merge "Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: edac582d40 am: 650409d4b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25400378

Change-Id: I2003f92080f61363c0549d36a2a95c0ddf651a6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 08:11:42 +00:00
Chia-Chi Teng
650409d4b4 Merge "Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: edac582d40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/25400378

Change-Id: I92c8528073ca783dba8f9de5c51dde3616da47c9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-11-23 07:39:22 +00:00
Martin Liu
b25d110b38 allow vendor init to access percpu_pagelist_high_fraction
Bug: 309409009
Test: boot
Change-Id: I2a4b34e3318b5de8688fe25133d7839165a2566d
Signed-off-by: Martin Liu <liumartin@google.com>
2023-11-23 15:35:07 +08:00
Chia-Chi Teng
edac582d40 Merge "Revert^3 "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev 2023-11-23 07:07:04 +00:00
Randall Huang
60b467ac40 Move sg_device related policy
Bug: 312582937
Test: make selinux_policy
Change-Id: Ic6e1f6228764cd2ddc96d574a10838ca4bc05332
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-11-22 14:21:06 +08:00
Wilson Sung
039124e7a4 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 312590044
Change-Id: I24e5462f111f05d051d398487a5931d808cf3002
2023-11-22 03:15:40 +00:00
Bryan Lavrich
70a5a27331 Merge "aoc: add sysfs file entry" into main 2023-11-20 20:22:27 +00:00
Devika Krishnadas
9fcc03e099 Merge "Add Pixel Mapper as a sp-HAL" into main 2023-11-20 18:17:28 +00:00
Luis Delgado de Mendoza
e5f95d1fc7 Add sepolicy entries for new BT channel
Bug: 308452948
Test: Validated locally on husky.
Change-Id: I68bce4f12b086168bdcbe6193b07dd1c11097c2d
2023-11-17 20:03:39 -08:00