Commit graph

304 commits

Author SHA1 Message Date
Wilson Sung
3e6b9d6153 Merge "Add system_ui required policy" into udc-d1-dev am: ee80374f9d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21853742

Change-Id: I07b3321df4a2efe88485513d7538cd19500f3744
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-08 07:15:57 +00:00
Wilson Sung
ee80374f9d Merge "Add system_ui required policy" into udc-d1-dev 2023-03-08 06:40:42 +00:00
Yang Qi
c8d64fb72f Add CccDkTimeSyncService for Digital Key Support for Zuma am: d8c17a3814
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21809919

Change-Id: I456973e22f9297a3d39805703f7fcb52be2f791e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-08 05:50:25 +00:00
Wilson Sung
5488482211 Add system_ui required policy
Bug: 264266705
Bug: 268572197
Bug: 269813282
Change-Id: I6457f4a675d32578188c01ae581442300ac56a5b
2023-03-08 10:58:39 +08:00
Yang Qi
5c390da06d Merge "Add CccDkTimeSyncService for Digital Key Support for Zuma" 2023-03-07 19:16:08 +00:00
Yang Qi
d8c17a3814 Add CccDkTimeSyncService for Digital Key Support for Zuma
Test: Build and Run
Bug: 270511447
Merged-In: I0195bfe5f8eed70556891ddfeae81c486373ddbb
Change-Id: I0195bfe5f8eed70556891ddfeae81c486373ddbb
2023-03-07 02:52:34 +00:00
Adam Shih
a5a9f978f7 Merge "move camera dump to gs-common" into udc-dev am: 5dd0fffa9a am: 8507994334
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21784301

Change-Id: Ib647273dc6ccefd134c5c9c53c2259274de30d4c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-07 00:39:47 +00:00
Adam Shih
d1bce36c49 Merge "move camera dump to gs-common" into udc-dev am: 5dd0fffa9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21784301

Change-Id: I40cce627880f57be080685502693c0d73dc53cac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-07 00:04:42 +00:00
Adam Shih
952b486aaf Move common display dump to gs-common am: 51bd259bbf am: ba72e77586
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21644566

Change-Id: I2288201c1655cee48eb4b47c0022eafe56d8c9e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-06 23:45:44 +00:00
Adam Shih
5dd0fffa9a Merge "move camera dump to gs-common" into udc-dev 2023-03-06 23:29:45 +00:00
Adam Shih
8e2e4dc222 Move common display dump to gs-common am: 51bd259bbf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21644566

Change-Id: I31f0efd65637b205164c9ee767f23cd24893cd09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-06 23:11:09 +00:00
Yang Qi
a6c8402aa9 Add CccDkTimeSyncService for Digital Key Support for Zuma
Test: Build and Run
Bug: 270511447
Change-Id: I0195bfe5f8eed70556891ddfeae81c486373ddbb
2023-03-06 22:49:15 +00:00
Adam Shih
51bd259bbf Move common display dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: I71ad4e2e08ba19c36dc633732ce39e8086a94d6e
2023-03-06 06:33:53 +00:00
Adam Shih
7b84f2fc56 move camera dump to gs-common
Bug: 240530709
Test: adb bugreport
Create empty files starting with the following prefix
/data/vendor/camera/profiler/session-ended-
/data/vendor/camera/profiler/high-drop-rate-
/data/vendor/camera/profiler/watchdog-
/data/vendor/camera/profiler/camera-ended-
and do adb bugreport and make sure they end up in dumpstate_board.bin

Change-Id: I90e6d5142e7d512dafa6b8712d7fb252327359a5
2023-03-06 02:34:48 +00:00
Jeremy DeHaan
f33a422c17 Allow HWC to access panel model
Bug: 217472351
Change-Id: I2831eb402d15ceb0962325ce827a1ca3cca00109
Signed-off-by: Jeremy DeHaan <jdehaan@google.com>
2023-03-03 13:48:53 -08:00
TreeHugger Robot
f344cb000a Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev am: 4eab0326df am: 7790b93e01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552481

Change-Id: I9c2fd984191deb9421cef4b96ddbaa807f1cf4eb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 19:47:23 +00:00
TreeHugger Robot
8e2035cc18 Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev am: 4eab0326df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552481

Change-Id: I9f39b65bc479a4fc0541404062330137a9fcb63c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 19:22:05 +00:00
Donnie Pollitz
c24ebe57c1 sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306 am: 8958b2e84b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: If4f7afa3407b7a124ee55d95ac5a3e774a9842a7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:53:42 +00:00
Dinesh Yadav
ea868cc5bf Merge "Make gxp_device an mlstrustedobject" into udc-d1-dev am: 85829f2265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21701040

Change-Id: I28e061683cfd0bed9cd17ebf907cd3d45429bf84
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:32:58 +00:00
Donnie Pollitz
8958b2e84b sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: I55b973823df7b0ad935ab38c0c22c63c0c1674cd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:27:10 +00:00
TreeHugger Robot
4eab0326df Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev 2023-03-03 12:01:40 +00:00
Dinesh Yadav
85829f2265 Merge "Make gxp_device an mlstrustedobject" into udc-d1-dev 2023-03-03 03:12:15 +00:00
Dinesh Yadav
01c5409eb8 Make gxp_device an mlstrustedobject
This is needed as google_camera_app needs write access to gxp.

Test: Tested with private build "P51261040" with Tot google3 gca-dogfood app & found no selinux violations.

Bug: 264139000
Change-Id: Ic1a262cc40578ebd2305efe851e54cf857bd02c1
2023-03-02 15:41:37 +00:00
Ernie Hsu
11bbec30bc Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab am: fbbc198801
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I5e45ca88e24d8b4b67dd65326cece156cf38905d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 10:10:31 +00:00
Ernie Hsu
fbbc198801 Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I90171c56ccbb152a1cf7fbca77bb1d56311bebaa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 09:19:35 +00:00
Donnie Pollitz
e31ad0b306 sepolicy: Fix hal_confirmationui_default avc denials
* Allow for dumpstate

Bug: 261933368
Bug: 264489634
Test: Ran com.google.android.selinux.pts.SELinuxTest#scanBugreport
Change-Id: Id70d2a920172e649e4497f4ea1a4ecad33963edc
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-02 09:08:16 +00:00
Ernie Hsu
899ad9c1ab Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev 2023-03-02 08:38:54 +00:00
Hiroshi Akiyama
c0587fbf36 Update sepolicy for BCL IRQ durations to dumpstate
Bug: 269752322
Test: adb bugreport
Change-Id: Icd524bd32ed41c3de72f0e1b13428d76e871d203
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
Merged-In: Icd524bd32ed41c3de72f0e1b13428d76e871d203
2023-03-02 06:03:23 +00:00
Wilson Sung
8fa2055112 Add sensor boot-to-home required policy am: d0105abe01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: I95c23468276681b97969e2fe6376e914aed2fe1f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:49 +00:00
Hiroshi Akiyama
b45a7465cf Merge "Update sepolicy for BCL IRQ durations to dumpstate" 2023-03-02 04:21:56 +00:00
Hiroshi Akiyama
a13ce6baf4 Update sepolicy for BCL IRQ durations to dumpstate
Bug: 269752322
Test: adb bugreport
Change-Id: Icd524bd32ed41c3de72f0e1b13428d76e871d203
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
2023-03-02 03:04:08 +00:00
Wilson Sung
4e36ecc334 Merge "Add sensor boot-to-home required policy" to master
Test: boot-to-home
Fix: 261105336
Change-Id: I2a12d4cf87b00d8dc117ced7062a97016d75275c
2023-03-02 10:42:55 +08:00
Wilson Sung
d0105abe01 Add sensor boot-to-home required policy
Test: boot-to-home
Fix: 261105336
Change-Id: I772ff7a294cc5d2448361c164d4e671a41c92c8d
2023-03-02 02:39:15 +00:00
Wilson Sung
fc8f4f8f24 Allow hal_thermal_default to read iio/odpm sysfs nodes
Bug: 260366399
Bug: 261651187
Bug: 264204525
Change-Id: I7358b7740f6c30bd7b05e29e931a4c11226c6253
2023-03-01 16:21:33 +00:00
Ernie Hsu
4d90089d25 move mediacodec_samsung build config and sepolicy to gs-common
Bug: 263444717
Test: build pass, camera record, youtube
Change-Id: I8fa4d79495b3971429b977a63aed811ef8d62ddb
2023-03-01 10:12:22 +00:00
Kenny Root
0f36fcebb2 Merge "Add GSA logs policy" 2023-03-01 05:51:40 +00:00
Richard Chang
fb7193c798 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b am: 92ec39e932
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: Icf93e34b300bfd10e00afd6e58317b07a246290c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 05:15:53 +00:00
Richard Chang
92ec39e932 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: I066aaa3efd492aea906ac778be9ff8c3e696850d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:53 +00:00
Armelle Laine
39a9021703 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I7774f4fba285cd3a8b65c9c78245da5ee39d9c61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:29 +00:00
Richard Chang
3c52a9ab3b Merge "sepolicy: update init.te for zram device" into udc-dev 2023-03-01 04:28:58 +00:00
Kenny Root
076591d107 Add GSA logs policy
This adds a label to the sysfs files for GSA logs to allow dumpstate to
read them during a bugreport.

Bug: 271125313
Test: adb shell dumpstate
Change-Id: I8842c0bec972c4cfad15ca689f8e4ae7fa99e179
2023-02-28 18:33:23 -08:00
Richard Chang
ee8c7c2df2 sepolicy: update init.te for zram device
Bug: 269221861
Bug: 270633329
Test: Boot
Change-Id: I050e9a72006dcd0b71ba1232e38e5f96bce4c967
2023-03-01 02:04:24 +00:00
Jonglin Lee
3c0dd54d80 Add perfmon policies am: 167eba3ad9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649593

Change-Id: Ibb15e72ed9d9bd5abbf5659bc3b7e925ec88d029
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-28 21:47:09 +00:00
Jonglin Lee
167eba3ad9 Add perfmon policies
Add perfmon policies to fix hotplug issues.

Bug: 271024526
Bug: 271007431
Change-Id: I974bd99224b983454c6af47f4a08a4fe20699834
Signed-off-by: Jonglin Lee <jonglin@google.com>
2023-02-28 10:19:26 -08:00
Cody Heiner
09693b450a Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9 am: 609c49485d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: Ice0eb43e04ded0cf95309f5a9e4353413cbbdbb7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 23:21:06 +00:00
Armelle Laine
d27961dc1b Define selinux properties for /dev/block/by-name/trusty_persist
Bug: 247013568
Test: - Verify that this change is a NOP for devices with TDP already
        created on top of the legacy f2fs partition /mnt/vendor/persist/ss
      - Verify that this change creates a valid symlink on a manually
        migrated block device
Change-Id: I226f365c6afbb5fa91ec1c9c1943f8dddac8183a
2023-02-27 22:42:08 +00:00
Armelle Laine
1731179cf1 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" 2023-02-27 20:07:35 +00:00
Cody Heiner
dc0b4fc9e9 Allow twoshay → systemui_app binder call for zuma devices (2)
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Note: this is a re-submit of ag/21529713, after sorting out the
SEPolicy issues described in b/270444888.

Test: flash P23 and Bluejay devices with this change plus ag/21591673,
  run `adb shell device_config put twoshay_native test_flag_name test_flag_value`,
  → TouchContextService.java logs corresponding property changed message.

Bug: 270444888

Change-Id: I40d70cf19930eb334ba3250d58a0cbc39b50764b
2023-02-24 18:19:09 -08:00
Wilson Sung
b264162687 Merge "Add SSR property access and remove obsolete denials"
Bug: 268572164
Change-Id: I4285b0558dd2ff3bb8d4f54dfa1690828f65129a
2023-02-24 18:42:48 +08:00
Wilson Sung
546b787a40 Add SSR property access and remove obsolete denials
Bug: 268572164
Change-Id: I5756510b2eb2696aade93dd6b15a111f5dca58ef
2023-02-24 10:33:45 +00:00