Commit graph

1046 commits

Author SHA1 Message Date
Donnie Pollitz
16440338de Allow vendor_init to fix permissions of TEE data file
Background:
* vendor_init needs to be able to possibly fix ownership of
  tee_data_file

Bug: 280325952
Test: Changed permissions and confirmed user transitions
Change-Id: I2363f9ff695209bbf7b6661c8e9eb3b376b84ace
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-05-24 16:45:28 +02:00
Jimmy Hu
9279426af4 Merge "Set sepolicy for shell script of disabling contaminant detection" into udc-d1-dev am: 86cb19bb2f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23341842

Change-Id: I6a938dee1103a1b2b445669a5258f7470729248c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 08:25:48 +00:00
Jimmy Hu
86cb19bb2f Merge "Set sepolicy for shell script of disabling contaminant detection" into udc-d1-dev 2023-05-24 08:14:01 +00:00
Jin Jeong
b4bac68874 Merge "Revert "[Zuma] Fix SeLinux error"" into udc-d1-dev am: f77e90366d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23167570

Change-Id: I88f2266fdc8cf1f50fb3bcc6391d8b7f55715f62
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:02 +00:00
Jin Jeong
f77e90366d Merge "Revert "[Zuma] Fix SeLinux error"" into udc-d1-dev 2023-05-24 01:07:12 +00:00
Wilson Sung
f2042a36ab Update SELinux error am: d73217d81f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23364725

Change-Id: I022bd1a22194279f776490d8af53452d92f3ce09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-23 09:44:10 +00:00
Wilson Sung
d73217d81f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 283725554
Test: scanBugreport
Bug: 283725554
Bug: 283725302
Test: scanAvcDeniedLogRightAfterReboot
Bug: 283725554
Change-Id: Ie482a46311c1dc1153ef04889e82971a09361e49
2023-05-22 15:01:49 +08:00
Kenny Root
b1e5122f5b Merge "Add GSA logs policy" into udc-d1-dev am: 107d3314a4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23268925

Change-Id: Ib9c3b04f95760982a04b3b545115cc13786985ef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 05:39:41 +00:00
Kenny Root
107d3314a4 Merge "Add GSA logs policy" into udc-d1-dev 2023-05-22 05:14:11 +00:00
Lawrence Huang
da39d4174a Merge "Add net_domain for GCA on zuma devices" into udc-d1-dev am: 7bf6643438
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23338581

Change-Id: Ia4e68a5f2b74985a1c8e15e43418a81dc22cc798
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-19 20:48:09 +00:00
Lawrence Huang
7bf6643438 Merge "Add net_domain for GCA on zuma devices" into udc-d1-dev 2023-05-19 19:59:58 +00:00
Jimmy Hu
70e6dd395b Set sepolicy for shell script of disabling contaminant detection
(ported from Ib2e3cf498851c0c9e5e74aacc9bf391549c0ad1a)

Bug: 263916675
Bug: 264231895
Test: setprop vendor.usb.contaminantdisable true
Change-Id: Ia451a6abc4a3c872c002efa323d06e9179bd656b
Signed-off-by: Jimmy Hu <hhhuuu@google.com>
2023-05-19 09:54:23 +00:00
Treehugger Robot
45b4e68788 Merge "Remove selinux error bug reference after fixing" into udc-d1-dev am: b295326a78
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23338576

Change-Id: I34dba1ef3b40020df96832e93b49ea8eb073e1fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-19 03:56:27 +00:00
Treehugger Robot
b295326a78 Merge "Remove selinux error bug reference after fixing" into udc-d1-dev 2023-05-19 03:07:49 +00:00
Prasanna Prapancham
a64fd32572 add 8411 to logbuffer am: 9138d3d1de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23302169

Change-Id: Ia3eb2c23e55ac4108fe44d285ba603a78f2f3f02
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-19 02:29:29 +00:00
Lawrence Huang
c64c508a51 Add net_domain for GCA on zuma devices
Bug: 277097939

Change-Id: Iadfc1be5f9e6830693aed9d9b619815c7d1f9caf
(cherry picked from commit e979543b99)
2023-05-19 01:53:03 +00:00
Grace Chen
e151f78f5a Remove selinux error bug reference after fixing
Bug: 264483151
Test: None, simple bug removal
Change-Id: Id93085566c772e6b434777955b62b1ccaba64ae2
2023-05-18 17:54:20 -07:00
Prasanna Prapancham
9138d3d1de add 8411 to logbuffer
Test: Flash local build and collect bugreport
Bug: 277799048
Change-Id: I877a91999a2f17df5ea90d3d2257b93bfd67e8e6
Signed-off-by: Prasanna Prapancham <prapancham@google.com>
(cherry picked from commit c1715483d1)
2023-05-17 22:52:57 +00:00
Kenny Root
7be3a71942 Add GSA logs policy
This adds a label to the sysfs files for GSA logs to allow dumpstate to
read them during a bugreport.

(cherry picked from commit 076591d107)

Bug: 271125313
Test: adb shell dumpstate
Change-Id: I8842c0bec972c4cfad15ca689f8e4ae7fa99e179
Merged-In: I8842c0bec972c4cfad15ca689f8e4ae7fa99e179
2023-05-17 17:36:35 +00:00
Xu Han
cb92b8fcdc Merge "Add permission for nautilus devices" into udc-d1-dev am: 639d91fb93
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23279761

Change-Id: Ib51a391011a30f9c142bc9bd3bb15ea576c88bbb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-17 17:21:48 +00:00
Xu Han
639d91fb93 Merge "Add permission for nautilus devices" into udc-d1-dev 2023-05-17 16:48:55 +00:00
Luke Chang
de2132476f Merge "sepolicy: label cpd cl2 & cl1 target_residency" into udc-d1-dev am: 3d16072afb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23270943

Change-Id: I0809900155d08d626e730b338feee23516254ec3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-17 11:01:10 +00:00
Luke Chang
3d16072afb Merge "sepolicy: label cpd cl2 & cl1 target_residency" into udc-d1-dev 2023-05-17 10:09:06 +00:00
Xu Han
bdc91f6477 Add permission for nautilus devices
Bug: 283015605
Test: Build
Change-Id: I986a2798a4a5ca927a1a2aaea61edca9fa59b2c5
2023-05-17 03:59:43 +00:00
lukechang
73e88c0a83 sepolicy: label cpd cl2 & cl1 target_residency
Test: build and boot to home
Bug: 277390134

Merged-In: I127ffc74aa68976de4aaa4a750b4043def4e2759
Change-Id: I127ffc74aa68976de4aaa4a750b4043def4e2759
Signed-off-by: lukechang <lukechang@google.com>
2023-05-17 02:11:41 +00:00
TreeHugger Robot
455a2dcd69 Merge "Add chre channel sepolicy entries" into udc-d1-dev am: 3203ccc21a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22953495

Change-Id: Ib2d8972837eb6bbd894d2bc31c529c105375d2f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:54:49 +00:00
TreeHugger Robot
3203ccc21a Merge "Add chre channel sepolicy entries" into udc-d1-dev 2023-05-16 23:04:18 +00:00
Luis Delgado de Mendoza Garcia
a3f0628f68 Add chre channel sepolicy entries
Bug: 275143652
Fix: 275143652
Test: in-device verification.
Change-Id: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
Merged-In: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
2023-05-16 21:43:09 +00:00
Treehugger Robot
e1766dcd82 Merge "uwb: add permissions for factory uwb calib file" into udc-d1-dev am: 05abdf9f26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22980180

Change-Id: I8383f4ed2858abd05dceeef3fc7d7720e42a3031
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 17:33:21 +00:00
Treehugger Robot
05abdf9f26 Merge "uwb: add permissions for factory uwb calib file" into udc-d1-dev 2023-05-15 16:54:11 +00:00
Jin Jeong
b3c701b9c4 Revert "[Zuma] Fix SeLinux error"
This reverts commit 709ad06c0e.

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Change-Id: Ibe56941737506158ef963bba2ae00035c5c11069
2023-05-12 04:20:27 +00:00
Wilson Sung
6be3026f0f Remove fixed SELinux bug from bug_map am: 2e511cf418
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23156963

Change-Id: I0d9db68056fd36b51302cf4906370e6d951ad573
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 18:39:11 +00:00
Wilson Sung
2e511cf418 Remove fixed SELinux bug from bug_map
Fix: 280706292
Bug: 280522410
Change-Id: I5b35759d2b89246e65683fbbc3ca877af04ef25b
2023-05-11 14:10:41 +08:00
Wilson Sung
806dfc977c Update SELinux error am: 17a784cf97
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23125888

Change-Id: I9c64aee39c85fc94bc05413970bd6367dc1e8684
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 04:48:55 +00:00
Wilson Sung
17a784cf97 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281815594
Test: scanBugreport
Bug: 281815594
Bug: 281815537
Test: scanAvcDeniedLogRightAfterReboot
Bug: 281815594
Fix: 281645191
Change-Id: Ia1e72cdee3ca535eb978ad8becad94c9c4d8c2cd
2023-05-11 04:06:31 +00:00
Zixuan Lan
c7bf80dd24 remove fixed selinux bug from bug map. am: 288623d4d4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23040174

Change-Id: I420a0e14dec2b62a81bd860950599f2e4bc08310
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-10 01:28:43 +00:00
Zixuan Lan
288623d4d4 remove fixed selinux bug from bug map.
TPU permission was fixed to avoid error in hal_camera_defaul.The corresponding bug for tracking should be removed from the bug map. Please see bug for more details.
Bug: 275001641
Test: logcat grep for selinux error

Change-Id: I3622a1877f94b41d03d1bcb1c16a404db4b3ea8d
2023-05-09 16:38:38 -07:00
Zheng Pan
a98b8a881f Merge "Allow systemui to find adbd" into udc-d1-dev am: 705cc4abf8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23104216

Change-Id: I0f37291b0dd6ca03020fff173603fcea1cb517a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 21:12:20 +00:00
Zheng Pan
705cc4abf8 Merge "Allow systemui to find adbd" into udc-d1-dev 2023-05-09 20:21:14 +00:00
Wilson Sung
f4499ed385 Merge "Update SELinux error" into udc-d1-dev am: e797557f08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23015883

Change-Id: I8ff067a88f7754d007f26c0a273c2a91edbf0bf1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 10:29:22 +00:00
Mahesh Kallelil
56184ab96e Allow dump_modem to read logbuffer and wakeup events am: 1f885d0bcd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22834646

Change-Id: I2c96c9fce37659d5cd4ed5258bdb647c7b7b8981
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 10:28:59 +00:00
Wilson Sung
e797557f08 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 10:06:38 +00:00
Treehugger Robot
5dbbb257fb Merge "Update SELinux error" into udc-d1-dev am: 254911d666
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23100096

Change-Id: I6ef7907e508e29b621c24b3b061edd1e019e453a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 08:59:18 +00:00
Luke Chang
590c58bc44 Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev am: f86a07903b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22980665

Change-Id: Ia1c127dc965d6b8997a0b265bdc46c298d40ccfd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 08:55:59 +00:00
Mahesh Kallelil
1f885d0bcd Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on P23
Bug: 278501642
Change-Id: I102583e37ec2e3852fd901a75bbb06de9ac6f77c
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-05-09 00:20:07 -07:00
Treehugger Robot
254911d666 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 07:15:25 +00:00
Luke Chang
f86a07903b Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev 2023-05-09 06:09:33 +00:00
Wilson Sung
fd60d077ad Allow systemui to find adbd
Bug: 276415118
Fix: 272628396
Test: connect to adb with no avc error
Change-Id: I07496d663628f62ed975785d794854d1cdc77040
2023-05-09 05:22:16 +00:00
Wilson Sung
6ee8a855f9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Test: scanBugreport
Bug: 280706211
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I84d50fc4e4f05d0228bc3713cf1b216bf12a72cd
2023-05-09 10:07:46 +08:00
Hasan Awais
14b2c135bb uwb: add permissions for factory uwb calib file
needed for copying the factory calib file from persist to
/data/vendor/uwb, along with converting the file to a valid format
for uwb HAL

Bug: 274513871
Bug: 279820265
Test: local build passed
Change-Id: I4c4286cd5c200475cac3b9d58a81724d631c49e0
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-05-09 00:27:47 +00:00