Commit graph

493 commits

Author SHA1 Message Date
Wilson Sung
b41fd56de0 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev am: 2dc224c7b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532246

Change-Id: I82eda4ee49a78b35b91c0ad8f3e81e2b525c73dc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:23:46 +00:00
Wilson Sung
0e5858d50e Merge "Remove touch_context_service to avoid compile error" into udc-dev am: dfd3296451
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21532245

Change-Id: I1de205b76e27cab0040e1054568a4020562e1a57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 05:22:30 +00:00
Wilson Sung
2dc224c7b9 Merge "Add hal_bootctl_default write permission to devinfo_block_device" into udc-dev 2023-02-22 04:49:33 +00:00
Wilson Sung
dfd3296451 Merge "Remove touch_context_service to avoid compile error" into udc-dev 2023-02-22 04:32:18 +00:00
Cody Heiner
baf09b5ab9 Allow twoshay → systemui_app binder call for zuma devices am: 9019c55645
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21529713

Change-Id: Id48b48c9e374dab6bf58b50bde30ea9f2387a56e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-22 04:04:00 +00:00
Wilson Sung
ca241fa76c Add hal_bootctl_default write permission to devinfo_block_device
Bug: 270236357
Change-Id: I40219dbd726ddebb277e592353bd9f0b249dd01f
2023-02-22 11:23:32 +08:00
Wilson Sung
328cbaaa41 Remove touch_context_service to avoid compile error
Bug: 270157082
Change-Id: I1d5d573ddb1d7323e7c66386928074fd06cfc484
2023-02-22 11:16:15 +08:00
Cody Heiner
9019c55645 Allow twoshay → systemui_app binder call for zuma devices
Splitting system_app (b/264266705) caused the avc denial below,
causing b/269981541. This change allows the denied binder call
and fixes the bug.

Denial message:
avc: denied { call } for scontext=u:r:twoshay:s0 tcontext=u:r:systemui_app:s0:c230,c256,c512,c768 tclass=binder permissive=0

Test: flash P23 device with ag/21526491 along with this change
  → twoshay runs normally.

Fixes: 269981541
Change-Id: Ib3cf6f44b6288ed5c7c773e2ad670d2fd0aeee96
2023-02-21 23:58:05 +00:00
Wilson Sung
393e31b676 Add hal_bootctl related policy am: bab5b72f86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: Ic3ea1d971850ee209d9cfc61ba448ff62bbde5f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:44 +00:00
Wilson Sung
06d8b16f05 Enforce kernel domain am: da09093d88
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503757

Change-Id: I1afd59c7608813cf9d3b0a24cf1425bab3a12695
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:43 +00:00
Wilson Sung
45c7bbe3cd Temporary allow kernel access same_process_hal am: 9457e5260e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503756

Change-Id: I75ddf39c43d69ea538d4a267145512ca710b22f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:04:42 +00:00
Wilson Sung
fa379e036e Remove vendor_fw_file related dontaudit am: 86931fb2ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21503752

Change-Id: I7a2f5722366ee38887ecdd5d5a43db0bfd8ccd26
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 23:00:36 +00:00
Wilson Sung
bab5b72f86 Add hal_bootctl related policy
Bug: 260522436
Bug: 264489609
Bug: 264483787
Change-Id: Iaa22899bb21ff41c1fa259830e5f49623ff8429b
2023-02-21 19:59:04 +08:00
Wilson Sung
da09093d88 Enforce kernel domain
Bug: 264490052
Test: boot-to-home
Change-Id: I383b689b5c26c08d66307b677e36b28f2ab6f7dd
2023-02-21 19:29:15 +08:00
Wilson Sung
9457e5260e Temporary allow kernel access same_process_hal
Add the access to unblock user build boot-to-home

Bug: 260522245
Change-Id: I98f77b2de4961120be9c6073afc18e12e2637e81
2023-02-21 19:28:25 +08:00
Wilson Sung
86931fb2ea Remove vendor_fw_file related dontaudit
Bug: 262794429
Bug: 261933155
Change-Id: I62b4037835a462b46b82df4059cdebf679c295b2
2023-02-21 15:00:58 +08:00
leochuang
62d244482e Update SELinux error am: 6747816919
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504315

Change-Id: I7c2a39a18128af2c47bef09340738028fea686cc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-21 04:32:47 +00:00
leochuang
6747816919 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 269964558
Bug: 267714573
Bug: 269964574
Bug: 269812912
Change-Id: I61a274c01c6921b9b7e3df8814cf83f43bba342a
2023-02-21 02:16:40 +00:00
Wilson Sung
19d86dcfc0 Revert "Revert "Update error on ROM 9624328"" am: e70b98af09
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I99c6e1a5473691fbca41957b934b270f8493e2cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:59 +00:00
Ken Yang
024703040d WLC: cleanup the unused hal_wlc policies am: 58a6a1e772
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: I8aafb32f9a5c0bcd8f74e382a2f893fa71433b7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:41 +00:00
Ken Yang
c43be3da60 WLC: cleanup WLC trakcing_denials am: 670b22c2c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Iff19425d747d5c03e4e10ae284523ef659b29200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:35 +00:00
Kah Xuan Lim
c7adfd1151 modem_svc_sit: grant modem property access am: 4e270f1615
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: Iad92808f73b22345e16d7ca602e57d25f01d42a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:57 +00:00
Wilson Sung
3bf76884bb allow bootctl to read devinfo am: 931ea0d342
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: Iba6993ef61237c11fa1a1c2eb493e339f32f16f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:00 +00:00
Wilson Sung
d952aae49a Remove proc_vendor_sched obsolete denials am: 676c7a674c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: Ib6e4ec093a81dd47ce32d3a110cd525fd9a5afb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:58 +00:00
Nicole Lee
cf40697979 logger_app: don't audit default_prop and fix errors am: 7706be6c71
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I10e07e96719038edaa420519e4e705cff9e9da49
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:55 +00:00
Wilson Sung
e70b98af09 Revert "Revert "Update error on ROM 9624328""
This reverts commit d8572861e3.

Remove hal_googlebattery related denied

Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Merged-In: I25b0f417af3e741719f959aed79e7e330687e117
Change-Id: I25b0f417af3e741719f959aed79e7e330687e117
2023-02-20 11:06:17 +00:00
Ken Yang
58a6a1e772 WLC: cleanup the unused hal_wlc policies
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit 6f9844d137)
Merged-In: I90b9e442082b8e03e76ce63aaee56e5882933449
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
2023-02-20 11:05:53 +00:00
Ken Yang
670b22c2c7 WLC: cleanup WLC trakcing_denials
Bug: 268566583
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit da69d2a494)
Merged-In: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
2023-02-20 11:05:25 +00:00
Kah Xuan Lim
4e270f1615 modem_svc_sit: grant modem property access
Log message gotten before adding the policy:
avc: denied { connectto } for comm="modem_svc_sit" path="/dev/socket/property_service" scontext=u:r:modem_svc_sit:s0 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1

Bug: 247669574
(cherry picked from commit 77ce224141)
Merged-In: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
Change-Id: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
2023-02-20 11:04:11 +00:00
Wilson Sung
931ea0d342 allow bootctl to read devinfo
Bug: 260522436
(cherry picked from commit 967da5da4f)
Merged-In: I41d2763ffe40d7465a11cc86612fed9f92905eff
Change-Id: I41d2763ffe40d7465a11cc86612fed9f92905eff
2023-02-20 11:02:28 +00:00
Wilson Sung
676c7a674c Remove proc_vendor_sched obsolete denials
Bug: 264490054
(cherry picked from commit 6545bc156a)
Change-Id: I308df50eefe611a0a87afc9a21387465487cc6ea
Merged-In: I308df50eefe611a0a87afc9a21387465487cc6ea
2023-02-20 11:01:42 +00:00
Nicole Lee
7706be6c71 logger_app: don't audit default_prop and fix errors
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:default_prop:s0" dev="tmpfs" ino=153 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
avc: denied { search } for name="ssrdump" dev="dm-44" ino=377 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
avc: denied { search } for name="coredump" dev="dm-44" ino=378 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_coredump_file:s0 tclass=dir permissive=0 app=com.android.pixellogger

Bug: 264489961
Bug: 269383459
Test: Make sure no avc denied for logger_app when using Pixel Logger
(cherry picked from commit ef1d13d86d)
Change-Id: I8999372d243286586eb53602e167fa111d39a00f
Merged-In: I8999372d243286586eb53602e167fa111d39a00f
2023-02-20 11:00:59 +00:00
Sean.JS Tsai
f0e29936a5 Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: I564275400b71dd3f2859b4a4cf7b4bcce56e0969
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:46:09 +00:00
Sean.JS Tsai
8838f4e286 Merge "Revert "Update error on ROM 9624328"" into udc-dev 2023-02-20 05:59:29 +00:00
Sean.JS Tsai
d8572861e3 Revert "Update error on ROM 9624328"
This reverts commit cf747f40d6.

Reason for revert: <b/269976373>

Change-Id: I1bee9c1da2571ab753c2193491ebc71b288b66b2
2023-02-20 04:29:33 +00:00
TreeHugger Robot
f5aeedf6fc Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: I4c579890ef5ee1c6427b3b699223d3d9cea138be
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:16:13 +00:00
TreeHugger Robot
ea203448fd Merge "Update error on ROM 9624328" into udc-dev 2023-02-20 03:28:27 +00:00
sukiliu
cf747f40d6 Update error on ROM 9624328
Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Test: SELinuxUncheckedDenialBootTest
Change-Id: Id8cbfb7c55f2acdc3102b20cdbd2702b594992ba
2023-02-20 10:28:33 +08:00
TreeHugger Robot
dfd3d8e7c5 Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: Ice2cb63d7abc67b3185532be682db8841d018c1a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:51:17 +00:00
TreeHugger Robot
c012a8a10a Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev 2023-02-18 13:46:15 +00:00
Kuen-Han Tsai
e4af4e0824 SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I639171077e99d6e17698e7a1905712ab7d4446a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 04:54:12 +00:00
Kuen-Han Tsai
d0ac5bffa3 SEPolicy: remove tracking denials for hal_usb
Remove tracking denials since there is no avc denials related to hal_usb
found in the bug report.

Bug: 264483531
Bug: 264483531
Bug: 264482981
Bug: 264600052
Bug: 264482981
Bug: 264600052
Bug: 261651112
Test: Capture bugreport and check any denials related to hal_usb
Change-Id: I535c94c1112fc51f80b80c99562b43afee32ddd6
2023-02-18 02:41:51 +00:00
neoyu
4ff3dbefcd Fix avc denied for hal_radioext_default am: c0da946f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: I1cbdf50e1f0dc138076cf70b8229885f60482c60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 02:23:12 +00:00
neoyu
c0da946f48 Fix avc denied for hal_radioext_default
avc: denied { call } for comm="HwBinder:782_1" scontext=u:r:hal_radioext_default:s0 tcontext=u:r:hal_bluetooth_btlinux:s0 tclass=binder permissive=0

Bug: 269684065
Test: manual
Change-Id: I5ebf280feafabf4688718197c79bd6c4cac6e8fe
2023-02-17 08:39:47 +00:00
Ken Tsou
10e84d8327 hal_health_default: allow to access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 07:00:37 +00:00
Wilson Sung
3432cc6b0b Enforce system_server and remove obsolete denials
Bug: 261519050
Bug: 262455682
Bug: 264489786
Test: boot to home and avc gone
Change-Id: I0a51e029a85af0a77faebfdcfe0b4dc26b71cca6
2023-02-16 05:35:19 +00:00
Wilson Sung
c43a6186bf Add app_domain to con_monitor_app
Bug: 261782930
Bug: 264490077
Test: boot to home and avc gone
Change-Id: I86a0793c93549172ee60397b9735ddcfe0d20bac
2023-02-16 13:00:39 +08:00
TreeHugger Robot
061a2d7f82 Merge "Remove shell related denied" 2023-02-16 04:01:25 +00:00
Jayachandran C
b85f29bb54 Merge "Revert "Add selinux rules for platform_apps to access vendor_ims_app udp socket for read/write of RTP packets."" 2023-02-16 02:59:18 +00:00
Jayachandran C
75fc4f2051 Merge "Allow radio to access IMS stack's socket for sending/receiving RTP packets and aoc_device for codec encoding/decoding" 2023-02-16 02:59:18 +00:00