Commit graph

579 commits

Author SHA1 Message Date
Ernie Hsu
4d90089d25 move mediacodec_samsung build config and sepolicy to gs-common
Bug: 263444717
Test: build pass, camera record, youtube
Change-Id: I8fa4d79495b3971429b977a63aed811ef8d62ddb
2023-03-01 10:12:22 +00:00
Richard Chang
2f31611036 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: I128719b2f9e1af2a649913faabcca8dc3e94e749
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:50 +00:00
Armelle Laine
0da9e2ff96 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I66c16c9377b4af6c924adfee4b983acff7993e0e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:39:44 +00:00
Richard Chang
3c52a9ab3b Merge "sepolicy: update init.te for zram device" into udc-dev 2023-03-01 04:28:58 +00:00
Armelle Laine
d38c507ef6 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev 2023-03-01 03:41:09 +00:00
Richard Chang
ee8c7c2df2 sepolicy: update init.te for zram device
Bug: 269221861
Bug: 270633329
Test: Boot
Change-Id: I050e9a72006dcd0b71ba1232e38e5f96bce4c967
2023-03-01 02:04:24 +00:00
TreeHugger Robot
312d50fd92 Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: Ie65327b364ad73df29b337d2de4ad8df51fbfb08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:30 +00:00
TreeHugger Robot
627e6c1648 Merge "Update bug_map" into udc-dev 2023-02-28 23:56:31 +00:00
Xu Han
fe5bb58212 Update bug_map
Bug: 264483024
Test: Build.
Change-Id: I9a1574b5997d9ac5d26100254c7e20b81930df50
2023-02-28 09:34:58 -08:00
Cody Heiner
609c49485d Allow twoshay → systemui_app binder call for zuma devices (2) am: dc0b4fc9e9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21591811

Change-Id: I04b8ce8cb19be7c8634c78fb7e73e308eba9081d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-27 22:46:45 +00:00
Armelle Laine
d27961dc1b Define selinux properties for /dev/block/by-name/trusty_persist
Bug: 247013568
Test: - Verify that this change is a NOP for devices with TDP already
        created on top of the legacy f2fs partition /mnt/vendor/persist/ss
      - Verify that this change creates a valid symlink on a manually
        migrated block device
Change-Id: I226f365c6afbb5fa91ec1c9c1943f8dddac8183a
2023-02-27 22:42:08 +00:00
Cody Heiner
dc0b4fc9e9 Allow twoshay → systemui_app binder call for zuma devices (2)
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Note: this is a re-submit of ag/21529713, after sorting out the
SEPolicy issues described in b/270444888.

Test: flash P23 and Bluejay devices with this change plus ag/21591673,
  run `adb shell device_config put twoshay_native test_flag_name test_flag_value`,
  → TouchContextService.java logs corresponding property changed message.

Bug: 270444888

Change-Id: I40d70cf19930eb334ba3250d58a0cbc39b50764b
2023-02-24 18:19:09 -08:00
Wilson Sung
d5f419a6d4 Add SSR property access and remove obsolete denials am: 546b787a40
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552480

Change-Id: I4f6a1cfab59730efc3002351d7c66313651657e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 12:20:23 +00:00
Wilson Sung
546b787a40 Add SSR property access and remove obsolete denials
Bug: 268572164
Change-Id: I5756510b2eb2696aade93dd6b15a111f5dca58ef
2023-02-24 10:33:45 +00:00
Amy Hsu
0089c57d7d Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev am: ae4c77ebda
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503754

Change-Id: I39e6bc8af10f8a5025168ec84ef41cf0aabb22dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 08:59:26 +00:00
Amy Hsu
ae4c77ebda Merge "Revise sepolicy because of refactor HbmSvManager" into udc-dev 2023-02-24 08:14:49 +00:00
Suki Liu
e0d1b24d12 Merge "Update SELinux error" into udc-dev am: e476047167
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21571001

Change-Id: I7624d1a1234dccbc7cc741878879e8a2ff8828ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:15:39 +00:00
Adam Shih
fcf2a4aa78 Merge "Move HWC dump to gs-common" into udc-dev am: 9675dc064a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533829

Change-Id: Iebdf3ee606db9a0d74d3d2b631e7dc21984b054b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 05:41:10 +00:00
Suki Liu
e476047167 Merge "Update SELinux error" into udc-dev 2023-02-24 04:59:32 +00:00
Adam Shih
9675dc064a Merge "Move HWC dump to gs-common" into udc-dev 2023-02-24 03:17:38 +00:00
Amy Hsu
c186dbd6db Revise sepolicy because of refactor HbmSvManager
1. Set sepolicy correctly, make it the same as gs201.
2. Rename hbmsvmanager to pixeldisplayservice due to refactor.
3. Add arm_mali_platform_service for pixeldisplayservcice

Bug: 241498235
Bug: 262794939
Bug: 263185136
Bug: 264489797
Test: Verify LBE and shadow compensation functions.
      Make sure there is no avc denied.
Change-Id: I2a4bb5d6b863edc00b789fd6df8d46f90164d9f2
2023-02-24 02:06:35 +00:00
sukiliu
362a8ac82c Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 270633329
Change-Id: Ia7af3ec3ee9c8b80e22a8eb55fd61d58b6c73980
2023-02-24 09:59:58 +08:00
TreeHugger Robot
d716668597 Merge "Partially revert commit e70b98af09." into udc-dev am: 3d1d5e0b15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21546042

Change-Id: Iff0271baa6f339ab24cb81d3d928fa71cfe14640
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 16:45:01 +00:00
TreeHugger Robot
3d1d5e0b15 Merge "Partially revert commit e70b98af09." into udc-dev 2023-02-23 16:13:11 +00:00
Richard Chang
d90c71c987 Merge "sepolicy: clean up tracking_denials for zram" into udc-dev am: d207b85ab3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21549121

Change-Id: Ifb6a1d623d7c42d7a69a24ae7f8dc815cf0d2630
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 08:28:32 +00:00
Richard Chang
d207b85ab3 Merge "sepolicy: clean up tracking_denials for zram" into udc-dev 2023-02-23 07:37:28 +00:00
Ian Kasprzak
1b1fe4d3cc Partially revert commit e70b98af09.
Remove twoshay references, with commit 9019c55645
reverted it references a non-existent file.

Bug: b/270434708
Test: Verified with go/abtd build

Reason for revert: b/270434708 - Breaks git_udc-d1-dev-plus-aosp-without-vendor builds.

Change-Id: I5705d214218107226ae3dd4959406f3ec05afa90
2023-02-23 05:45:07 +00:00
Wilson Sung
a4ccb38798 Add chre policy am: fb2e376d26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21533834

Change-Id: Iff4cde7901e7d05627e7f9f7c0d27fc457bba4dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 05:14:46 +00:00
Wilson Sung
640d478d5a Remove camera dontaudit am: 6f141a6526
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503759

Change-Id: I29c37dc676b4754cc1ce9f4c2620e52d278c36a4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 05:14:45 +00:00
Richard Chang
e6f6cca02a sepolicy: clean up tracking_denials for zram
The zram SELinux errors didn't exist in recent build
(9633105, 9642683).
Remove the record in tracking_denials/init.te.

Bug: 269221861
Test: Check log
Change-Id: I4057aaf960aef885d4d894ae5dc51f93e71afd83
2023-02-23 03:57:57 +00:00
Wilson Sung
fb2e376d26 Add chre policy
Bug: 260522435
Bug: 261105224
Test: boot-to-home
Change-Id: Icd8f1ad497357bbbcb9e34509c736f3976ff0ac7
2023-02-23 11:05:15 +08:00
Wilson Sung
6f141a6526 Remove camera dontaudit
Bug: 267843409
Bug: 268226491
Change-Id: Idce5518072fc266b45c2fbc5269915b19ceb19e8
2023-02-23 11:04:47 +08:00
Ian Kasprzak
271f7404bc Merge "Revert "Allow twoshay → systemui_app binder call for zuma devices"" into udc-dev am: e3af6770ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21540614

Change-Id: Icd890d614ecec5e1b5688735fcbb8e0a49e6599f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 00:57:14 +00:00
Ian Kasprzak
e3af6770ab Merge "Revert "Allow twoshay → systemui_app binder call for zuma devices"" into udc-dev 2023-02-22 22:28:43 +00:00
Ian Kasprzak
cbf2b3fdb2 Revert "Allow twoshay → systemui_app binder call for zuma devices"
This reverts commit 9019c55645.

Reason for revert: b/270434708 - Breaks git_udc-d1-dev-plus-aosp-without-vendor builds.

Change-Id: Iab5bf42754760dedbe26dd684c373ba9ec3af70b
2023-02-22 22:28:33 +00:00
Adam Shih
90d9b97221 Move HWC dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: I616f0af4d9ba466d62d87e7fc912c8c3201f7f65
2023-02-22 13:55:50 +08:00
Wilson Sung
b41fd56de0 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev am: 2dc224c7b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532246

Change-Id: I82eda4ee49a78b35b91c0ad8f3e81e2b525c73dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:23:46 +00:00
Wilson Sung
0e5858d50e Merge "Remove touch_context_service to avoid compile error" into udc-dev am: dfd3296451
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532245

Change-Id: I1de205b76e27cab0040e1054568a4020562e1a57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:22:30 +00:00
Wilson Sung
2dc224c7b9 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev 2023-02-22 04:49:33 +00:00
Wilson Sung
dfd3296451 Merge "Remove touch_context_service to avoid compile error" into udc-dev 2023-02-22 04:32:18 +00:00
Cody Heiner
baf09b5ab9 Allow twoshay → systemui_app binder call for zuma devices am: 9019c55645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21529713

Change-Id: Id48b48c9e374dab6bf58b50bde30ea9f2387a56e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 04:04:00 +00:00
Wilson Sung
ca241fa76c Add hal_bootctl_default write permission to devinfo_block_device
Bug: 270236357
Change-Id: I40219dbd726ddebb277e592353bd9f0b249dd01f
2023-02-22 11:23:32 +08:00
Wilson Sung
328cbaaa41 Remove touch_context_service to avoid compile error
Bug: 270157082
Change-Id: I1d5d573ddb1d7323e7c66386928074fd06cfc484
2023-02-22 11:16:15 +08:00
Cody Heiner
9019c55645 Allow twoshay → systemui_app binder call for zuma devices
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Test: flash P23 device with ag/21526491 along with this change
  → twoshay runs normally.

Fixes: 269981541
Change-Id: Ib3cf6f44b6288ed5c7c773e2ad670d2fd0aeee96
2023-02-21 23:58:05 +00:00
Wilson Sung
393e31b676 Add hal_bootctl related policy am: bab5b72f86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: Ic3ea1d971850ee209d9cfc61ba448ff62bbde5f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:44 +00:00
Wilson Sung
06d8b16f05 Enforce kernel domain am: da09093d88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503757

Change-Id: I1afd59c7608813cf9d3b0a24cf1425bab3a12695
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:43 +00:00
Wilson Sung
45c7bbe3cd Temporary allow kernel access same_process_hal am: 9457e5260e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503756

Change-Id: I75ddf39c43d69ea538d4a267145512ca710b22f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:42 +00:00
Wilson Sung
fa379e036e Remove vendor_fw_file related dontaudit am: 86931fb2ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503752

Change-Id: I7a2f5722366ee38887ecdd5d5a43db0bfd8ccd26
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:00:36 +00:00
Wilson Sung
bab5b72f86 Add hal_bootctl related policy
Bug: 260522436
Bug: 264489609
Bug: 264483787
Change-Id: Iaa22899bb21ff41c1fa259830e5f49623ff8429b
2023-02-21 19:59:04 +08:00
Wilson Sung
da09093d88 Enforce kernel domain
Bug: 264490052
Test: boot-to-home
Change-Id: I383b689b5c26c08d66307b677e36b28f2ab6f7dd
2023-02-21 19:29:15 +08:00