Commit graph

426 commits

Author SHA1 Message Date
Jenny Ho
31f750da2b sepolicy: add sepolicy for disable.battery.defender
[    7.536208] type=1107 audit(1671575809.144:22): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=vendor.battery.defender.disable pid=381 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=property_service permissive=1'

Bug: 263305106
Change-Id: Ia7adfe7f128c6390128447b9363ecd3615694fb1
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 13:09:28 +08:00
Ken Yang
af9057e7fb WLC: Add required sysfs_wlc sepolicies
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.

Bug: 267171670
Change-Id: If2b5b007f4a24e91b2be83bb20676eb449b9415f
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-05 01:00:01 +00:00
George
40b805af57 Remove dontaudit for nfc
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for nfc

Bug: 263185547
Bug: 264490053
Test: atest NfcNciInstrumentationTests
Test: atest NfcNciUnitTests
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: Idc9eced1ae7248cf0883a5e42db2c5e55cb65c3b
2023-02-04 22:37:34 +08:00
Welly Hsu
a8526b30e0 Merge "Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot" 2023-02-04 05:55:56 +00:00
Joseph Jang
114b7b8f09 Merge "citadel: Remove citadel.te for sepolicy testing" 2023-02-03 02:08:12 +00:00
Cyan_Hsieh
79bd040d55 Add gcf partition to OTA domain
This allows the OTA mechanism to write to the bootloader slot to
perform the actual OTA

Bug: 263218204
Change-Id: Iec3f3aa73344f4e9a305bc3c1c3f2db7624aca93
2023-02-02 18:08:51 +08:00
TreeHugger Robot
075f213ece Merge "hal_graphics_composer_default: fix sepolicy denials" 2023-02-02 06:11:49 +00:00
TreeHugger Robot
e9d7a18f5d Merge "selinux: fix mitigation_vendor_file access" 2023-02-02 04:40:09 +00:00
Nicole Lee
7c21f689ea Merge "logger_app: allow logger_app to access vendor_slog_file" 2023-02-02 04:11:39 +00:00
Nicole Lee
704656a367 Merge "logger_app: allow logger_app to access vendor_rild_prop" 2023-02-02 04:11:28 +00:00
Nicole Lee
34f87b6396 Merge "logger_app: allow logger_app to access sysfs_sscoredump_level and vendor_ramdump_prop" 2023-02-02 04:11:18 +00:00
Nicole Lee
5bdbf4194b Merge "logger_app: allow logger_app to access logd_prop" 2023-02-02 04:11:03 +00:00
Nicole Lee
20dedc5cc6 Merge "logger_app: allow logger_app to access logpersistd_logging_prop" 2023-02-02 04:10:50 +00:00
TreeHugger Robot
de674e9f3b Merge "logger_app: allow logger_app to access vendor_audio_prop" 2023-02-02 04:09:35 +00:00
Nicole Lee
140780f8a4 Merge "logger_app: allow logger_app to access vendor_wifi_sniffer_prop" 2023-02-02 03:06:45 +00:00
Nicole Lee
3d78ff1a51 Merge "logger_app: allow logger_app to access vendor_tcpdump_log_prop" 2023-02-02 03:06:33 +00:00
Nicole Lee
1c8be3059d Merge "logger_app: allow access vendor_gps_file, vendor_gps_prop, vendor_logger_prop" 2023-02-02 03:06:23 +00:00
Nicole Lee
227fa788cc Merge "logger_app: allow logger_app access vendor_modem_prop" 2023-02-02 03:06:14 +00:00
Nicole Lee
89a469803c Merge "logger_app: allow logger_app to access vendor_ssrdump_prop" 2023-02-02 03:06:05 +00:00
Nicole Lee
3a825a5184 Merge "logger_app: allow logger_app to access radio files" 2023-02-02 03:05:50 +00:00
George Lee
574ebbacf8 selinux: fix mitigation_vendor_file access
Bug: 266118091
Test: Local test to confirm error doesn't show up
Change-Id: Ie9e55230211f20efc7bba448bfc335799d0e1d56
Signed-off-by: George Lee <geolee@google.com>
2023-02-01 17:55:12 +00:00
Doug Zobel
b0394ebf56 Merge "Add sepolicy for PCIe link statistics" 2023-02-01 15:04:04 +00:00
Safayat Ullah
7ce9680b98 hal_graphics_composer_default: fix sepolicy denials
Bug: 263184738
Bug: 264489746
Test: There is no AVC denied log after reboot
Change-Id: I3c5bbc55f0a676d8906ec061e3c999995d02dd3f
2023-02-01 14:34:36 +00:00
Doug Zobel
7ea927f332 Add sepolicy for PCIe link statistics
PCIe link statistics collected by dumpstate and pixelstats.

Test: adb logcat "pixelstats-vendor:D *:S"
Bug: 266689144
Change-Id: I9b7eef9a9e14c1be9e9e9feb3c608f7067e6fade
Signed-off-by: Doug Zobel <zobel@google.com>
2023-02-01 07:23:15 -06:00
Donnie Pollitz
eea50ca2bc Merge "sepolicy: Fix tee avc denials" 2023-02-01 09:46:16 +00:00
Welly Hsu
74b12d8455 Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot
Issue: after introducing selinux rules in b/265286368
the dontaudit rules can be removed

bug: 260522413
bug: 262451641
bug: 261651113
bug: 260922186
bug: 261516808
bug: 260769064
bug: 265384119
bug: 264489745

Test: confirm SELinuxUncheckedDenialBootTest and
scanAvcDeniedLogRightAfterReboot tests can pass and no avc denials for euiccpixel

Change-Id: I07ae97d47bbb14c15da92611160b6a2a6af22a60
2023-02-01 16:34:17 +08:00
Long Ling
9f67cbb03b Merge "Set context for sysfs file refresh_rate" 2023-02-01 02:37:48 +00:00
Nicole Lee
9c413c12e7 logger_app: allow logger_app to access vendor_slog_file
Bug: 264489961
Test: Confirm no selinux denial for vendor_slog_file
Change-Id: Idc5386336a196f39703f6d33e3a7a8491e860ea0
2023-01-31 16:38:48 +00:00
Nicole Lee
98e068e135 logger_app: allow logger_app to access vendor_rild_prop
Bug: 264489961
Test: Confirm no selinux denial for vendor_rild_prop
Change-Id: I07bb59cba17f11a6cfdaf40e92f6cd663d8ad903
2023-01-31 16:38:39 +00:00
Nicole Lee
e396b80465 logger_app: allow logger_app to access sysfs_sscoredump_level and vendor_ramdump_prop
Bug: 264489961
Test: Confirm no selinux denial for sysfs_sscoredump_level and vendor_ramdump_prop
Change-Id: I6c7e87d15505dd9cd80f571ab67925b7ec722ef6
2023-01-31 16:38:31 +00:00
Nicole Lee
cbb6754e58 logger_app: allow logger_app to access logd_prop
Bug: 264489961
Test: Confirm no selinux denial for logd_prop
Change-Id: I6db7b19dd9cf864768ba2442d39d9fcde16a71fe
2023-01-31 16:38:23 +00:00
Nicole Lee
bed125ec04 logger_app: allow logger_app to access logpersistd_logging_prop
Bug: 264489961
Test: Confirm no selinux denial for logpersistd_logging_prop
Change-Id: Ia8836e058bb3e471d388f9055252e6c3c42227ac
2023-01-31 16:38:14 +00:00
Nicole Lee
998e7618b9 logger_app: allow logger_app to access vendor_audio_prop
Bug: 264489961
Test: Confirm no selinux denial for vendor_audio_prop
Change-Id: I02b53cf4d39adf1bc69004502a21b130c925d6bc
2023-01-31 16:38:05 +00:00
Nicole Lee
64a8ed9b7b logger_app: allow logger_app to access vendor_wifi_sniffer_prop
Bug: 264489961
Test: Confirm no selinux denial for vendor_wifi_sniffer_prop
Change-Id: Id6a5afed299c3ac869897015629d190640f40d8f
2023-01-31 16:37:54 +00:00
Nicole Lee
eb05f7d02f logger_app: allow logger_app to access vendor_tcpdump_log_prop
Bug: 264489961
Test: Confirm no selinux denial for vendor_tcpdump_log_prop
Change-Id: I2c4e7e0d395f570f93a26dd0328982487426ac84
2023-01-31 16:36:24 +00:00
Nicole Lee
cddb6ad619 logger_app: allow access vendor_gps_file, vendor_gps_prop, vendor_logger_prop
Bug: 261519049
Bug: 261783031
Bug: 261933367

Test: Confirm no selinux denial for these 3 tcontexts
Change-Id: I6f919e193693f7521778321f677214ea9f3b4d84
2023-01-31 16:32:41 +00:00
Nicole Lee
b713236048 logger_app: allow logger_app access vendor_modem_prop
Bug: 260522268
Bug: 264600053

Test: Confirm no selinux denial for tcontext vendor_modem_prop
Change-Id: Ic4ed0cdd7fa33c1dd4c812528b26b4a19cf6537b
2023-01-31 16:32:32 +00:00
Nicole Lee
e6975cb6e5 logger_app: allow logger_app to access vendor_ssrdump_prop
Bug: 260366439

Test: Confirm no selinux denial for tcontext vendor_ssrdump_prop
Change-Id: I74009bdd3d8b0fa691a2d0132655dc08fcd50977
2023-01-31 16:32:24 +00:00
Nicole Lee
30e96b25ce logger_app: allow logger_app to access radio files
Bug: 260366439
Bug: 260522268
Bug: 260769144
Bug: 261519049
Bug: 264600084

Test: Confirm no selinux denial for tcontext radio_vendor_data_file
Change-Id: I2a917d78e685aad5608e64f4d076cc50cdb064cc
2023-01-31 16:32:16 +00:00
sukiliu
383189e5f2 Update error on ROM 9541712
Bug: 267260951
Bug: 267261048
Bug: 267260619
Bug: 267260716
Bug: 267261305
Bug: 267261163
Bug: 267260675
Bug: 267261265
Bug: 267260717
Test: scanBugreport
Change-Id: I293fe1bc19f5f2d8f320d4e9feea051fc623ef8d
2023-01-31 14:18:11 +08:00
Joseph Jang
245e4205d1 citadel: Remove citadel.te for sepolicy testing
Test: VtsHalWeaverTargetTest
      VtsAidlSharedSecretTargetTest
      VtsHalIdentityTargetTest
      VtsHalRemotelyProvisionedComponentTargetTest
      VtsAidlKeyMintTargetTest
Bug: 264489777
Change-Id: I787aef6a0a924706ba2afccefff770408bb78294
2023-01-31 05:21:49 +00:00
Long Ling
ab6c98702b Set context for sysfs file refresh_rate
Bug: 263821118
Change-Id: Id8865c4499b6af103a7acd1fbbe6da0724cb83b3
2023-01-26 18:51:53 -08:00
TreeHugger Robot
1746a6cc59 Merge "Add rule for secure_element AIDL" 2023-01-27 02:00:45 +00:00
Donnie Pollitz
34fe057526 sepolicy: Fix tee avc denials
tee policies were missing

Bug: 263304957
Bug: 263429986
Bug: 264489524
Test: boot and scanAvcDeniedLogRightAfterReboot passed

Change-Id: Ia3191496be005dbbbe331a14f7d45adace34b3fc
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-01-24 15:22:57 +01:00
Grace Chen
82ae431064 Merge "Fix selinux denials on hal_secure_element_uicc" 2023-01-24 02:10:51 +00:00
Grace Chen
e881d9d401 Fix selinux denials on hal_secure_element_uicc
Bug: 264489780
Test: Confirm no more selinux denials
Change-Id: Ib159acaf8701d0ac7e3325addd7baca6a41f0cee
2023-01-23 15:36:04 -08:00
Grace Chen
c93ba80fc4 Add rule for secure_element AIDL
Add secureelement aidl

b/261565407

Change-Id: I79f35e8231d9eae81b90528269410c169bb1a035
2023-01-23 18:46:01 +00:00
Dinesh Yadav
3de9d17052 Merge "Allow camera HAL and GCA to access GXP device." 2023-01-18 07:33:32 +00:00
TreeHugger Robot
30fe55378d Merge "Fix avc denied and remove tracking_denials for hal_usb_gadget_impl" 2023-01-17 06:07:41 +00:00
Ernie Hsu
87aa440b72 Merge "Remove tracking_denials for media related module" 2023-01-17 05:51:00 +00:00