Commit graph

1046 commits

Author SHA1 Message Date
Inseob Kim
ac8048a4f7 Move coredomain seapp contexts to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
Merged-In: Ib8d191a6c07278b51eec88cd8142adf6c1a45668
2023-08-08 15:11:08 +00:00
Treehugger Robot
3377a38d65 Merge "Revert "Update SELinux error"" into udc-d1-dev am: 0f46a31902
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24178926

Change-Id: I68f3638898f861784276508406773649d6d21c21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-28 09:49:05 +00:00
Treehugger Robot
0f46a31902 Merge "Revert "Update SELinux error"" into udc-d1-dev 2023-07-28 00:06:22 +00:00
Jason Chiu
65ce874b81 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I72d2747b0751ff8b462e59abf974dc3a1a1a1aea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:20 +00:00
Jason Chiu
27e2aeafa7 remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: I43897ecaaae1ecbcb30479f510637e2680406c40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:18 +00:00
Jason Chiu
36dc08bf81 Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Ic0fa67cd73840070825f3cb197ad00656b4c296b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-27 12:28:16 +00:00
Yunju Lee
72f7cbe324 Revert "Update SELinux error"
This reverts commit 8f56fc9709.

Reason for revert: b/291237127 is fixed

Bug: 291237127
Change-Id: I58e2636fb2ef1113a4305152948e07ed8a27a7d9
2023-07-24 15:10:01 +00:00
Jason Chiu
90a1f80488 Add hal_bootctl_default read permission to rootfs in Recovery mode
Fix the following avc denial:
avc:  denied  { read } for  pid=485 comm="android.hardwar" name="bin" dev="rootfs" ino=9529 scontext=u:r:hal_bootctl_default:s0 tcontext=u:object_r:rootfs:s0 tclass=dir permissive=0

Bug: 282670401
Change-Id: I23ab086ba21d6ffea8b48b4208933c031effc4d4
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:47 +00:00
Jason Chiu
54b0343059 remove rule for bootctrl hidl version 1.2
Bug: 282670401
Change-Id: I25d169c335fb551cf1862fdf6e6540485a2b8016
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:38 +00:00
Jason Chiu
17fa2e6fe5 Add rule for bootctrl AIDL
Bug: 282670401
Change-Id: I1b4c5e7ced0fe67bbbaca2b607e4ca7422e170e1
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 20:53:04 +08:00
Wilson Sung
358275a825 Update SELinux error am: 8f56fc9709
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24058780

Change-Id: I971f8532161a1e9e25fc3015a26bd497a9176be6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-17 09:15:38 +00:00
Wilson Sung
8f56fc9709 Update SELinux error
Test: scanBugreport
Bug: 291237127
Change-Id: Iacb47dce94f8ee2f71d382a9d0a22a6570345e2d
2023-07-17 13:50:09 +08:00
Krzysztof Kosiński
b069918c11 Remove bug map entry for unknown property reads in camera HAL. am: 583baf021c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23935721

Change-Id: I3397af974f95726b175abcea36a44a02e304cb5d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-14 22:12:18 +00:00
Krzysztof Kosiński
583baf021c Remove bug map entry for unknown property reads in camera HAL.
Fixed by avoiding reading a property with the name "218".

Bug: 286508419
Test: check log for denials when running the camera on zuma device.
Change-Id: I3632868187d263ed787f5abf729c4e5c10a4f4c4
2023-07-14 07:12:51 +00:00
Treehugger Robot
7eba1f29bc Merge "Add GPU power hint sysfs node to sepolicy for Zuma" into udc-d1-dev am: 8bcc8a1242
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23643602

Change-Id: I21783e724b86aa309cdd464420858f543f549e68
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-13 19:00:41 +00:00
Treehugger Robot
8bcc8a1242 Merge "Add GPU power hint sysfs node to sepolicy for Zuma" into udc-d1-dev 2023-07-13 17:47:48 +00:00
Badhri Jagan Sridharan
3e1e0b9b68 Merge "Add USB wakeup sources sepolicy contexts" into udc-d1-dev am: 20eade41f0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23864376

Change-Id: Ie727156612f14c298a032468ca8c4567d6341f58
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-13 17:31:26 +00:00
Badhri Jagan Sridharan
20eade41f0 Merge "Add USB wakeup sources sepolicy contexts" into udc-d1-dev 2023-07-13 16:43:18 +00:00
Wilson Sung
f33940a050 Move systemui seapp_contexts to private am: 5c63d0ef54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24018505

Change-Id: Ibb9b6cb84e984021e632d14323d622b549e40179
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-12 07:03:26 +00:00
Wilson Sung
5c63d0ef54 Move systemui seapp_contexts to private
Fix: 289480799
Bug: 288227521
Change-Id: Ifc4288125d454569a66151c3c61e000ffd3526ac
2023-07-11 15:24:10 +08:00
Wilson Sung
1c8431e2b4 Update SELinux error am: 83671d2646
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24002585

Change-Id: Ib45ed15b3233364f3f81f0e972c475c8eacfcc17
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-10 10:20:45 +00:00
Wilson Sung
83671d2646 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289480799
Change-Id: I6c013d99b9b004b0a39d0b1861fa89da46bc846d
2023-07-10 14:21:22 +08:00
Yunju Lee
0a86789618 Add GPU power hint sysfs node to sepolicy for Zuma
Bug: 228076319
Bug: 278493002
Test: Perfetto trace inspection
Change-Id: I2f78c2e9175faa3f8af4b55e93e9b0f3d6bebdf2
2023-07-07 21:40:20 +00:00
Treehugger Robot
fe8aefb6a5 Merge "Update SELinux error" into udc-d1-dev am: 58c254fcaa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23875908

Change-Id: I00b23b4aa5953b1ec71b73c4a928d81af659d726
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 16:09:44 +00:00
Treehugger Robot
58c254fcaa Merge "Update SELinux error" into udc-d1-dev 2023-07-06 15:09:35 +00:00
Ruofei Ma
d853f05f4e Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev am: f3258b9e00
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23852417

Change-Id: I1794ae0ae12c8dda929e25f7d988a4a87a7428a0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 03:30:53 +00:00
Ruofei Ma
5358c08714 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev am: aa2084fe54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23850445

Change-Id: Idb18a29b7bf6da51892eee82b3b6d4f9f9503659
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 03:30:23 +00:00
Ruofei Ma
f3258b9e00 Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev 2023-07-06 02:49:56 +00:00
Ruofei Ma
aa2084fe54 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev 2023-07-06 02:49:51 +00:00
Wilson Sung
7a77620145 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289856761
Test: scanBugreport
Bug: 289856761
Test: scanAvcDeniedLogRightAfterReboot
Bug: 289856761
Change-Id: I4a3dcd037b1f63b8d06edab5a5ef4919ce75b8bc
2023-07-04 11:17:41 +08:00
Badhri Jagan Sridharan
62e714d81c Add USB wakeup sources sepolicy contexts
Bug: 289376260
Change-Id: I72711aea571dad5be7ff36ca7a7c59240aaa2226
Merged-In: I72711aea571dad5be7ff36ca7a7c59240aaa2226
Signed-off-by: Badhri Jagan Sridharan <badhri@google.com>
2023-06-30 19:36:01 +00:00
Wilson Sung
b8ec9b7fc4 Move sysUI contexts to system_ext am: 4862829753
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23840925

Change-Id: I375b899f1d97c6c994a2f2392d562814e4c3a0d4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-29 04:15:43 +00:00
Ruofei Ma
4ee8ce9cd6 Dec: SELinux policy change to allow uclamp.min set
To get better performance for 4K60FPS HDR video, we need
to boost the cpu when the load is too heavy for Bigwave
decoder.

Bug: 274736629

Change-Id: I32d683084dd55354002d4fd4c266492df3839a35
Signed-off-by: Ruofei Ma <ruofeim@google.com>
2023-06-29 00:22:24 +00:00
Ruofei Ma
4bb2aa413d Revert "mediacodec_google: add hal_power"
This reverts commit 3346e879e6.

Reason for revert: This change is not needed since the performance boost implementation has changed

Change-Id: Icda43f23354e70503d3bb2efe0631a2d754a4920
2023-06-29 00:22:11 +00:00
Wilson Sung
4862829753 Move sysUI contexts to system_ext
Bug: 288227521
Change-Id: I3e5f2e76bf067f98b191b3b8ee6010c1abd95cb0
2023-06-28 14:10:06 +08:00
TreeHugger Robot
cae8b7f115 Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev am: 043ae16d5f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753755

Change-Id: I1cee789da99f85b5ac1c5485d53e577448ea806d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 11:43:07 +00:00
TreeHugger Robot
043ae16d5f Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev 2023-06-21 10:47:39 +00:00
Treehugger Robot
2a4fea9c9e Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev am: d8b11ef832
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753754

Change-Id: I03fdab2f74f5caf3b63ad5e869e2a95f43e76635
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 10:34:22 +00:00
Treehugger Robot
d8b11ef832 Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev 2023-06-21 09:59:33 +00:00
Treehugger Robot
47da87bda2 Merge "Update SELinux error" into udc-d1-dev am: 81237d3843
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23736939

Change-Id: I019165c5000c529f4a4de90c20e880b3501c3fd1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 09:03:51 +00:00
Treehugger Robot
81237d3843 Merge "Update SELinux error" into udc-d1-dev 2023-06-21 08:02:49 +00:00
Wilson Sung
3657f78cb0 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-06-21 16:02:41 +08:00
Wilson Sung
0b77875c4a Supress kernel avc log before SELinux initialized
Bug: 288049349
Fix: 288049229
Change-Id: I5087a77e65ecdbaa868a7257342f5d99f424880a
2023-06-21 16:02:29 +08:00
Wilson Sung
8818dd2de5 Update SELinux error
Test: scanBugreport
Bug: 288049050
Bug: 288049522
Bug: 288049561
Bug: 288049349
Bug: 288049075
Test: scanAvcDeniedLogRightAfterReboot
Bug: 288049229
Change-Id: I939cd8981e64eadb0fa047b09162a02056ec2abf
2023-06-21 06:04:23 +00:00
Treehugger Robot
c03753058f Merge "Remove unused trace_marker dontaudit" into udc-d1-dev am: 107d5bb0f9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23736932

Change-Id: Ib407f87305f84dda1edc1d440d03156ea7df90c2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 04:58:08 +00:00
Treehugger Robot
107d5bb0f9 Merge "Remove unused trace_marker dontaudit" into udc-d1-dev 2023-06-21 04:18:51 +00:00
Anthony Zhang
fbceb3b769 Merge "[DO NOT MERGE] Allow fingerprint to access persist property" into udc-d1-dev am: a594a23554
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: Ic77f4c7fcc9ee54afdbc70880979f1a094c69828
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:10:20 +00:00
Anthony Zhang
6096b4605d [DO NOT MERGE] Allow fingerprint to access persist property am: fb29e39ee1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23730231

Change-Id: Ib229248e32c537641601e0d60bd223570e713883
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-20 18:10:18 +00:00
Anthony Zhang
a594a23554 Merge "[DO NOT MERGE] Allow fingerprint to access persist property" into udc-d1-dev 2023-06-20 17:31:31 +00:00
Wilson Sung
f82fc11c11 Remove unused trace_marker dontaudit
Fix: 260366195
Change-Id: I7ece6549a64740c878dc92ce4b011136eb313533
2023-06-20 14:34:01 +08:00