Commit graph

907 commits

Author SHA1 Message Date
Zixuan Lan
c7bf80dd24 remove fixed selinux bug from bug map. am: 288623d4d4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23040174

Change-Id: I420a0e14dec2b62a81bd860950599f2e4bc08310
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-10 01:28:43 +00:00
Zixuan Lan
288623d4d4 remove fixed selinux bug from bug map.
TPU permission was fixed to avoid error in hal_camera_defaul.The corresponding bug for tracking should be removed from the bug map. Please see bug for more details.
Bug: 275001641
Test: logcat grep for selinux error

Change-Id: I3622a1877f94b41d03d1bcb1c16a404db4b3ea8d
2023-05-09 16:38:38 -07:00
Zheng Pan
a98b8a881f Merge "Allow systemui to find adbd" into udc-d1-dev am: 705cc4abf8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23104216

Change-Id: I0f37291b0dd6ca03020fff173603fcea1cb517a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 21:12:20 +00:00
Zheng Pan
705cc4abf8 Merge "Allow systemui to find adbd" into udc-d1-dev 2023-05-09 20:21:14 +00:00
Wilson Sung
f4499ed385 Merge "Update SELinux error" into udc-d1-dev am: e797557f08
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23015883

Change-Id: I8ff067a88f7754d007f26c0a273c2a91edbf0bf1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 10:29:22 +00:00
Mahesh Kallelil
56184ab96e Allow dump_modem to read logbuffer and wakeup events am: 1f885d0bcd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22834646

Change-Id: I2c96c9fce37659d5cd4ed5258bdb647c7b7b8981
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 10:28:59 +00:00
Wilson Sung
e797557f08 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 10:06:38 +00:00
Treehugger Robot
5dbbb257fb Merge "Update SELinux error" into udc-d1-dev am: 254911d666
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23100096

Change-Id: I6ef7907e508e29b621c24b3b061edd1e019e453a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 08:59:18 +00:00
Luke Chang
590c58bc44 Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev am: f86a07903b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22980665

Change-Id: Ia1c127dc965d6b8997a0b265bdc46c298d40ccfd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 08:55:59 +00:00
Mahesh Kallelil
1f885d0bcd Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on P23
Bug: 278501642
Change-Id: I102583e37ec2e3852fd901a75bbb06de9ac6f77c
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-05-09 00:20:07 -07:00
Treehugger Robot
254911d666 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 07:15:25 +00:00
Luke Chang
f86a07903b Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev 2023-05-09 06:09:33 +00:00
Wilson Sung
fd60d077ad Allow systemui to find adbd
Bug: 276415118
Fix: 272628396
Test: connect to adb with no avc error
Change-Id: I07496d663628f62ed975785d794854d1cdc77040
2023-05-09 05:22:16 +00:00
Wilson Sung
6ee8a855f9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Test: scanBugreport
Bug: 280706211
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I84d50fc4e4f05d0228bc3713cf1b216bf12a72cd
2023-05-09 10:07:46 +08:00
Jin Jeong
62a999aff6 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev am: e22788ae78
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22984822

Change-Id: I61a44b6ddbc189fd34e5146c2fb16af13e83d8db
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 00:18:53 +00:00
Jin Jeong
e22788ae78 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev 2023-05-08 23:37:28 +00:00
lukechang
9d44de7ecf sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Merged-In: Iad525a9c556ee436afb8cbd29156b6b593329e83
Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:39:21 +00:00
TreeHugger Robot
899d3062b6 Merge "Add tele sensor sepolicy permission" into udc-d1-dev am: b417627fb8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020018

Change-Id: I2b27f715f84d664965ce7dfef14d59cee4788b22
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-08 02:32:21 +00:00
TreeHugger Robot
b417627fb8 Merge "Add tele sensor sepolicy permission" into udc-d1-dev 2023-05-08 02:00:59 +00:00
Treehugger Robot
0c91639fd5 Merge "Add sepolicy permission of new camera components" into udc-d1-dev am: 74e0e5fc37
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982823

Change-Id: Ic57a119ec1d8bd364567cb99ff603a703b1b6767
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 06:47:47 +00:00
Ted Wang
08f24f30a6 Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev am: be9ee4c01d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22344152

Change-Id: Ib6a3152e7cdaa68a880fe0e94c7a5ea633db24e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 06:47:14 +00:00
Treehugger Robot
74e0e5fc37 Merge "Add sepolicy permission of new camera components" into udc-d1-dev 2023-05-05 06:27:43 +00:00
Ted Wang
be9ee4c01d Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev 2023-05-05 06:19:10 +00:00
TreeHugger Robot
55ecf93b7d Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev am: 1db3ac365d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22589719

Change-Id: I9c31d1f117be3993b6114a7b636095a9229050b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 06:05:33 +00:00
TreeHugger Robot
1db3ac365d Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev 2023-05-05 05:35:55 +00:00
George Chang
74937b19bb Allow systemui_app to access Nfc service am: 178e94cb81
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020017

Change-Id: Ia2a718ce595dbb51c0a4b7fac05a8f5053547b8a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 00:18:59 +00:00
Manali Bhutiyani
cf161d6ce3 [display-stats] enable pixelstats access to display metrics on Zuma devices.
Bug: 259554507
Test: Build and boot on device
adb shell cmd stats print-stats | grep -i <atom-id>

Change-Id: Ifc47211063b98f727b3b0eb7f7ebd42e3c7bb99b
2023-05-04 20:56:24 +00:00
George Chang
178e94cb81 Allow systemui_app to access Nfc service
avc:  denied  { find } for pid=1867 uid=10249 name=nfc
scontext=u:r:systemui_app:s0:c249,c256,c512,c768
tcontext=u:object_r:nfc_service:s0 tclass=service_manager
permissive=0

Bug: 280531969
Test: manually check nfc signal after battery share on
Change-Id: I7c9092388d031e8714b8f3f4738db77776c66326
2023-05-04 09:52:14 +00:00
Kamal Shafi
e1464f8e53 Add tele sensor sepolicy permission
Bug: 280370254
Test: build pass
Change-Id: If76c157e272f40159bcd6aac08d4b3bc88991338
2023-05-04 09:18:55 +00:00
horngchuang
5e6e5b568b Add sepolicy permission of new camera components
Bug: 279885244
Bug: 280392819
Test: Build and test for sensor denials
Change-Id: Ib29b0287bc52f9c0fe6e3c18c272e6593507371b
2023-05-04 07:38:46 +00:00
Wilson Sung
e7a70d62b5 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Bug: 280706292
Test: scanBugreport
Bug: 280706211
Bug: 280706610
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I67e0d2ec15b3ea057688644ba5c41c8fb5755128
2023-05-04 12:40:51 +08:00
Treehugger Robot
fdb7364a3f Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev am: b3c7fb06fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982957

Change-Id: Ia74b455412d430da3ea5a3509d087d9c82aea521
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 16:12:47 +00:00
Treehugger Robot
b3c7fb06fa Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev 2023-05-03 15:42:14 +00:00
Jack Wu
923f9f2f5e sepolicy: allows pixelstat to access pca file nodes am: 8d45937a38
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22987856

Change-Id: I05c8ca4fcd1273a5636d9ccff229aff5ec0ae807
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 14:06:07 +00:00
Jack Wu
8d45937a38 sepolicy: allows pixelstat to access pca file nodes
Bug: 262520811
Test: no Permission denied while accessing the file node
Change-Id: I0b50d85ea7002c9ee16f4c34b472b45def7f374e
Signed-off-by: Jack Wu <wjack@google.com>
2023-05-03 09:31:08 +00:00
Treehugger Robot
a43377782f Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev am: cdb62d5474
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22896105

Change-Id: Iad5319efdd82be6d1349fb7b4ec05b8bc17b500e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 08:54:01 +00:00
Treehugger Robot
cdb62d5474 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev 2023-05-03 08:20:05 +00:00
Jinyoung Jeong
709ad06c0e [Zuma] Fix SeLinux error
Bug: 280522410
Test: no denial logs found for com.google.android.euicc b/280522410#comment3
Change-Id: I2837a71548cc8c8125b982313e2645ec8c913921
2023-05-03 07:44:44 +00:00
Horng Chuang
0f17ef32db Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev am: 5a2189a5ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22668237

Change-Id: I83d5b0218b54bcac0a31a34971f7f5b9c39879ff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 04:22:11 +00:00
Horng Chuang
5a2189a5ae Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev 2023-05-03 03:26:50 +00:00
Kyle Tso
649f19fc94 Allow accessing dumpstate from hal_usb_impl
Fix SELinux errors.

Bug: 267261163
Change-Id: I73a311d796eb520ede3849edc6384c965ec5c915
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-05-03 11:23:52 +08:00
Tommy Kardach
1e317a26ad Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev am: 6bf3b733ac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22915638

Change-Id: I2d66703cd4fe7ac51373bb704c441bf6282d561f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 22:45:42 +00:00
Tommy Kardach
6bf3b733ac Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev 2023-05-02 22:23:36 +00:00
Tommy Kardach
659c17d428 Allow P23 Camera HAL to acquire wake locks
Bug: 279977277
Test: mm && flash/test
Change-Id: I6150ccf788d5074ab9e2d29c6866c8a477a3ef71
2023-05-02 17:25:51 +00:00
Dan Moore
57bea4ff01 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev am: 47eea99fb2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22932758

Change-Id: I3f450687c9be51b9c1d9cb7cb691f6535e011004
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 15:36:56 +00:00
Dan Moore
47eea99fb2 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev 2023-05-02 15:00:31 +00:00
Treehugger Robot
6b61366417 Merge "Remove obsolete tracking entry" into udc-d1-dev am: 11ea9b76d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22880900

Change-Id: I73a0f09e483cb91805b3530ab513ee39529f4146
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:40:27 +00:00
Treehugger Robot
03f88f77fc Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: Ib41b87547cb4610fa30cbb49a79bf72e9944b7e2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:34:22 +00:00
Treehugger Robot
dc5aac4409 Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: Ia489a4cd3d15e82f6d506bacedcadb514367eb14
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:07:40 +00:00
Tom Huang
5c0053c5ec Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: I4f083a33f9e8a5af927496df1189d1085f19e616
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 09:07:31 +00:00