TreeHugger Robot
90730e60fd
Merge "sepolicy: label required wakeup nodes for system suspend"
2023-02-07 04:20:28 +00:00
sukiliu
341afe161d
Update error on ROM 9558720
...
Bug: 267843291
Bug: 267843408
Bug: 267843310
Bug: 267843409
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4d8f448d9019232222f2e8385bb2f4b3cf5f5336
2023-02-07 11:29:45 +08:00
TreeHugger Robot
0d013cb30e
Merge "Fix denials for radio service to access files under /data/venodr/radio"
2023-02-07 03:08:30 +00:00
Darren Hsu
1934546586
sepolicy: label required wakeup nodes for system suspend
...
Bug: 260366031
Bug: 264204215
Test: run singleCommand pts -m PtsSELinuxTestCases
Change-Id: Icf8c4669156a0017655981fda8619ce0a75dce4d
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-02-07 10:12:30 +08:00
Timmy Li
5533264ba9
Merge "Add UW cornerfolk to file_contexts"
2023-02-07 02:09:54 +00:00
timmyli
d784c55c20
Add UW cornerfolk to file_contexts
...
Device needs access to cornerfolk. Evidence log in comments.
Bug: 267696227
Test: log check
Change-Id: If6bd49b76038673ad12fc6a1e7abd10b4cd3407e
2023-02-07 02:09:46 +00:00
TreeHugger Robot
30036eeebc
Merge "Remove dontaudit for nfc"
2023-02-07 02:08:28 +00:00
TreeHugger Robot
161099cfe2
Merge "Remove dontaudit for st54spi"
2023-02-07 02:08:21 +00:00
TreeHugger Robot
cdc2d14883
Merge "sepolicy: label ODPM device nodes for hal_power_stats"
2023-02-07 02:05:46 +00:00
Darren Hsu
9964fd2901
sepolicy: label ODPM device nodes for hal_power_stats
...
Bug: 268002261
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I1dfd7760c4a958e0b31258a8379f3c68eb054f35
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-02-06 21:44:17 +08:00
Donnie Pollitz
1fd0c782b4
sepolicy: Fix trusty_metricsd avc denials
...
* Suez data collection missing
Bug: 264489526
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I667e35c68139a3368655cab4ea40acb529bb65ef
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:31 +00:00
Donnie Pollitz
1df4e2dde8
sepolicy: Fix trusty_apploader avc denials
...
* File permissions missing
Bug: 263305034
Test: ran com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I5d0a56a4c31c66610414341118c4089d2c11f3e9
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-02-06 08:57:22 +00:00
George
aa76e6db12
Remove dontaudit for st54spi
...
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for st54spi
Bug: 264489677
Test: manually check dumpsys secure_element
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I587caa423d3e1d23d9666fb732c0cc350934538f
2023-02-06 07:27:12 +00:00
Jenny Ho
6f15645932
Merge "Add permission for logbuffer_bd"
2023-02-06 03:53:19 +00:00
Hongbo Zeng
a82ea96b40
Fix denials for radio service to access files under /data/venodr/radio
...
Bug: 263792405
Test: get PASS result with go/ril-config-service-test and the original
denial logs in https://b/263792405#comment17 are gone
Change-Id: Id6d64bb3e159b083e1a1b4c8e728e992fb9b1502
2023-02-06 03:47:01 +00:00
Jenny Ho
4e6cfb143d
Add permission for logbuffer_bd
...
Bug: 242679204
Change-Id: I7376f10dc183bac805c89d6905e70a7b92694471
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 14:06:06 +08:00
Jenny Ho
31f750da2b
sepolicy: add sepolicy for disable.battery.defender
...
[ 7.536208] type=1107 audit(1671575809.144:22): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { set } for property=vendor.battery.defender.disable pid=381 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:vendor_battery_defender_prop:s0 tclass=property_service permissive=1'
Bug: 263305106
Change-Id: Ia7adfe7f128c6390128447b9363ecd3615694fb1
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-02-05 13:09:28 +08:00
Ken Yang
af9057e7fb
WLC: Add required sysfs_wlc sepolicies
...
The sysfs_wlc is still required for certain services like
hal_health_default. Add these sepolicies to pass the tests.
Bug: 267171670
Change-Id: If2b5b007f4a24e91b2be83bb20676eb449b9415f
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-05 01:00:01 +00:00
George
40b805af57
Remove dontaudit for nfc
...
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for nfc
Bug: 263185547
Bug: 264490053
Test: atest NfcNciInstrumentationTests
Test: atest NfcNciUnitTests
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: Idc9eced1ae7248cf0883a5e42db2c5e55cb65c3b
2023-02-04 22:37:34 +08:00
Welly Hsu
a8526b30e0
Merge "Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot"
2023-02-04 05:55:56 +00:00
Joseph Jang
114b7b8f09
Merge "citadel: Remove citadel.te for sepolicy testing"
2023-02-03 02:08:12 +00:00
Cyan_Hsieh
79bd040d55
Add gcf partition to OTA domain
...
This allows the OTA mechanism to write to the bootloader slot to
perform the actual OTA
Bug: 263218204
Change-Id: Iec3f3aa73344f4e9a305bc3c1c3f2db7624aca93
2023-02-02 18:08:51 +08:00
TreeHugger Robot
075f213ece
Merge "hal_graphics_composer_default: fix sepolicy denials"
2023-02-02 06:11:49 +00:00
TreeHugger Robot
e9d7a18f5d
Merge "selinux: fix mitigation_vendor_file access"
2023-02-02 04:40:09 +00:00
Nicole Lee
7c21f689ea
Merge "logger_app: allow logger_app to access vendor_slog_file"
2023-02-02 04:11:39 +00:00
Nicole Lee
704656a367
Merge "logger_app: allow logger_app to access vendor_rild_prop"
2023-02-02 04:11:28 +00:00
Nicole Lee
34f87b6396
Merge "logger_app: allow logger_app to access sysfs_sscoredump_level and vendor_ramdump_prop"
2023-02-02 04:11:18 +00:00
Nicole Lee
5bdbf4194b
Merge "logger_app: allow logger_app to access logd_prop"
2023-02-02 04:11:03 +00:00
Nicole Lee
20dedc5cc6
Merge "logger_app: allow logger_app to access logpersistd_logging_prop"
2023-02-02 04:10:50 +00:00
TreeHugger Robot
de674e9f3b
Merge "logger_app: allow logger_app to access vendor_audio_prop"
2023-02-02 04:09:35 +00:00
Nicole Lee
140780f8a4
Merge "logger_app: allow logger_app to access vendor_wifi_sniffer_prop"
2023-02-02 03:06:45 +00:00
Nicole Lee
3d78ff1a51
Merge "logger_app: allow logger_app to access vendor_tcpdump_log_prop"
2023-02-02 03:06:33 +00:00
Nicole Lee
1c8be3059d
Merge "logger_app: allow access vendor_gps_file, vendor_gps_prop, vendor_logger_prop"
2023-02-02 03:06:23 +00:00
Nicole Lee
227fa788cc
Merge "logger_app: allow logger_app access vendor_modem_prop"
2023-02-02 03:06:14 +00:00
Nicole Lee
89a469803c
Merge "logger_app: allow logger_app to access vendor_ssrdump_prop"
2023-02-02 03:06:05 +00:00
Nicole Lee
3a825a5184
Merge "logger_app: allow logger_app to access radio files"
2023-02-02 03:05:50 +00:00
George Lee
574ebbacf8
selinux: fix mitigation_vendor_file access
...
Bug: 266118091
Test: Local test to confirm error doesn't show up
Change-Id: Ie9e55230211f20efc7bba448bfc335799d0e1d56
Signed-off-by: George Lee <geolee@google.com>
2023-02-01 17:55:12 +00:00
Doug Zobel
b0394ebf56
Merge "Add sepolicy for PCIe link statistics"
2023-02-01 15:04:04 +00:00
Safayat Ullah
7ce9680b98
hal_graphics_composer_default: fix sepolicy denials
...
Bug: 263184738
Bug: 264489746
Test: There is no AVC denied log after reboot
Change-Id: I3c5bbc55f0a676d8906ec061e3c999995d02dd3f
2023-02-01 14:34:36 +00:00
Doug Zobel
7ea927f332
Add sepolicy for PCIe link statistics
...
PCIe link statistics collected by dumpstate and pixelstats.
Test: adb logcat "pixelstats-vendor:D *:S"
Bug: 266689144
Change-Id: I9b7eef9a9e14c1be9e9e9feb3c608f7067e6fade
Signed-off-by: Doug Zobel <zobel@google.com>
2023-02-01 07:23:15 -06:00
Donnie Pollitz
eea50ca2bc
Merge "sepolicy: Fix tee avc denials"
2023-02-01 09:46:16 +00:00
Welly Hsu
74b12d8455
Remove dontaudit in euiccpixel for SELinuxUncheckedDenialBootTest and scanAvcDeniedLogRightAfterReboot
...
Issue: after introducing selinux rules in b/265286368
the dontaudit rules can be removed
bug: 260522413
bug: 262451641
bug: 261651113
bug: 260922186
bug: 261516808
bug: 260769064
bug: 265384119
bug: 264489745
Test: confirm SELinuxUncheckedDenialBootTest and
scanAvcDeniedLogRightAfterReboot tests can pass and no avc denials for euiccpixel
Change-Id: I07ae97d47bbb14c15da92611160b6a2a6af22a60
2023-02-01 16:34:17 +08:00
Long Ling
9f67cbb03b
Merge "Set context for sysfs file refresh_rate"
2023-02-01 02:37:48 +00:00
Nicole Lee
9c413c12e7
logger_app: allow logger_app to access vendor_slog_file
...
Bug: 264489961
Test: Confirm no selinux denial for vendor_slog_file
Change-Id: Idc5386336a196f39703f6d33e3a7a8491e860ea0
2023-01-31 16:38:48 +00:00
Nicole Lee
98e068e135
logger_app: allow logger_app to access vendor_rild_prop
...
Bug: 264489961
Test: Confirm no selinux denial for vendor_rild_prop
Change-Id: I07bb59cba17f11a6cfdaf40e92f6cd663d8ad903
2023-01-31 16:38:39 +00:00
Nicole Lee
e396b80465
logger_app: allow logger_app to access sysfs_sscoredump_level and vendor_ramdump_prop
...
Bug: 264489961
Test: Confirm no selinux denial for sysfs_sscoredump_level and vendor_ramdump_prop
Change-Id: I6c7e87d15505dd9cd80f571ab67925b7ec722ef6
2023-01-31 16:38:31 +00:00
Nicole Lee
cbb6754e58
logger_app: allow logger_app to access logd_prop
...
Bug: 264489961
Test: Confirm no selinux denial for logd_prop
Change-Id: I6db7b19dd9cf864768ba2442d39d9fcde16a71fe
2023-01-31 16:38:23 +00:00
Nicole Lee
bed125ec04
logger_app: allow logger_app to access logpersistd_logging_prop
...
Bug: 264489961
Test: Confirm no selinux denial for logpersistd_logging_prop
Change-Id: Ia8836e058bb3e471d388f9055252e6c3c42227ac
2023-01-31 16:38:14 +00:00
Nicole Lee
998e7618b9
logger_app: allow logger_app to access vendor_audio_prop
...
Bug: 264489961
Test: Confirm no selinux denial for vendor_audio_prop
Change-Id: I02b53cf4d39adf1bc69004502a21b130c925d6bc
2023-01-31 16:38:05 +00:00
Nicole Lee
64a8ed9b7b
logger_app: allow logger_app to access vendor_wifi_sniffer_prop
...
Bug: 264489961
Test: Confirm no selinux denial for vendor_wifi_sniffer_prop
Change-Id: Id6a5afed299c3ac869897015629d190640f40d8f
2023-01-31 16:37:54 +00:00