Commit graph

529 commits

Author SHA1 Message Date
Mahesh Kallelil
8e513c2155 Allow dump_modem to read logbuffer and wakeup events am: 1f885d0bcd am: 56184ab96e am: af236c3219
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22834646

Change-Id: I38d6bd8125af59ec6373d699e58d6a2461eedc5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 12:42:59 +00:00
Mahesh Kallelil
1f885d0bcd Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on P23
Bug: 278501642
Change-Id: I102583e37ec2e3852fd901a75bbb06de9ac6f77c
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-05-09 00:20:07 -07:00
Luke Chang
f86a07903b Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev 2023-05-09 06:09:33 +00:00
Luke Chang
ab998b462c Merge "sepolicy: label cpd cl2 & cl1" 2023-05-09 04:54:33 +00:00
Jin Jeong
f4389a4333 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev am: e22788ae78 am: 53cfab53be am: 077bfe327c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22984822

Change-Id: I1cdf145a6810a3754b7cbd3e2b44471366db1ebd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 02:23:13 +00:00
Jin Jeong
e22788ae78 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev 2023-05-08 23:37:28 +00:00
lukechang
35f3c85c09 sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:49:45 +00:00
lukechang
9d44de7ecf sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Merged-In: Iad525a9c556ee436afb8cbd29156b6b593329e83
Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:39:21 +00:00
TreeHugger Robot
99c3feb294 Merge "Add tele sensor sepolicy permission" into udc-d1-dev am: b417627fb8 am: 899d3062b6 am: ebb31ef6bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020018

Change-Id: I2c9c384487f02bf9d8a12db6121982a611a903f1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-08 04:00:55 +00:00
TreeHugger Robot
b417627fb8 Merge "Add tele sensor sepolicy permission" into udc-d1-dev 2023-05-08 02:00:59 +00:00
Treehugger Robot
ab47a1ae3b Merge "Add sepolicy permission of new camera components" into udc-d1-dev am: 74e0e5fc37 am: ad2c33b44a am: 76ab0fefef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982823

Change-Id: Ia805db6bdaa4a25a8606473eb668ab9bcf029590
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:36:25 +00:00
Ted Wang
0a096b1aef Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev am: be9ee4c01d am: b1473d353f am: 15b8415e2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22344152

Change-Id: I072ce6c114d1c4cb0ba0604a8faf2284c64b19ad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:35:23 +00:00
TreeHugger Robot
27d8b200d6 Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev am: 1db3ac365d am: 55ecf93b7d am: 5b6de1f086
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22589719

Change-Id: I70e686a83c79305cd21fe972748c72056e64c433
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:34:49 +00:00
Treehugger Robot
74e0e5fc37 Merge "Add sepolicy permission of new camera components" into udc-d1-dev 2023-05-05 06:27:43 +00:00
Ted Wang
be9ee4c01d Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev 2023-05-05 06:19:10 +00:00
TreeHugger Robot
1db3ac365d Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev 2023-05-05 05:35:55 +00:00
George Chang
e5b9b50686 Allow systemui_app to access Nfc service am: 178e94cb81 am: 74937b19bb am: 2613956e78
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020017

Change-Id: Iaf5cd6da5e75a67a9d01eb700438d3336ade7528
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 02:32:33 +00:00
Manali Bhutiyani
cf161d6ce3 [display-stats] enable pixelstats access to display metrics on Zuma devices.
Bug: 259554507
Test: Build and boot on device
adb shell cmd stats print-stats | grep -i <atom-id>

Change-Id: Ifc47211063b98f727b3b0eb7f7ebd42e3c7bb99b
2023-05-04 20:56:24 +00:00
George Chang
178e94cb81 Allow systemui_app to access Nfc service
avc:  denied  { find } for pid=1867 uid=10249 name=nfc
scontext=u:r:systemui_app:s0:c249,c256,c512,c768
tcontext=u:object_r:nfc_service:s0 tclass=service_manager
permissive=0

Bug: 280531969
Test: manually check nfc signal after battery share on
Change-Id: I7c9092388d031e8714b8f3f4738db77776c66326
2023-05-04 09:52:14 +00:00
Kamal Shafi
e1464f8e53 Add tele sensor sepolicy permission
Bug: 280370254
Test: build pass
Change-Id: If76c157e272f40159bcd6aac08d4b3bc88991338
2023-05-04 09:18:55 +00:00
horngchuang
5e6e5b568b Add sepolicy permission of new camera components
Bug: 279885244
Bug: 280392819
Test: Build and test for sensor denials
Change-Id: Ib29b0287bc52f9c0fe6e3c18c272e6593507371b
2023-05-04 07:38:46 +00:00
Treehugger Robot
4bf45f603f Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev am: b3c7fb06fa am: fdb7364a3f am: 1264a719b2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982957

Change-Id: If0c30a3137e97a09df0b7cd9b8d64a4d8de6ceff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 18:00:22 +00:00
Treehugger Robot
b3c7fb06fa Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev 2023-05-03 15:42:14 +00:00
Jack Wu
06bd429e9e sepolicy: allows pixelstat to access pca file nodes am: 8d45937a38 am: 923f9f2f5e am: 4b33e0e2d2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22987856

Change-Id: I79ee04faddffa909f5529a81af5fdf68c3a2a879
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 15:33:44 +00:00
Treehugger Robot
03abfd7621 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev am: cdb62d5474 am: a43377782f am: 8efc7938fe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22896105

Change-Id: Id34f927edf557c108df3e70acb5e8fe57ddae3d7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 10:27:45 +00:00
Jack Wu
8d45937a38 sepolicy: allows pixelstat to access pca file nodes
Bug: 262520811
Test: no Permission denied while accessing the file node
Change-Id: I0b50d85ea7002c9ee16f4c34b472b45def7f374e
Signed-off-by: Jack Wu <wjack@google.com>
2023-05-03 09:31:08 +00:00
Treehugger Robot
cdb62d5474 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev 2023-05-03 08:20:05 +00:00
Jinyoung Jeong
709ad06c0e [Zuma] Fix SeLinux error
Bug: 280522410
Test: no denial logs found for com.google.android.euicc b/280522410#comment3
Change-Id: I2837a71548cc8c8125b982313e2645ec8c913921
2023-05-03 07:44:44 +00:00
Horng Chuang
bf13c5b01c Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev am: 5a2189a5ae am: 0f17ef32db am: de56475f2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22668237

Change-Id: Idc51f1cac6f6f8b441a90372de16d129c152c7ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 05:48:17 +00:00
Horng Chuang
5a2189a5ae Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev 2023-05-03 03:26:50 +00:00
Kyle Tso
649f19fc94 Allow accessing dumpstate from hal_usb_impl
Fix SELinux errors.

Bug: 267261163
Change-Id: I73a311d796eb520ede3849edc6384c965ec5c915
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-05-03 11:23:52 +08:00
Tommy Kardach
b0b0a9080d Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev am: 6bf3b733ac am: 1e317a26ad am: bf83401a50
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22915638

Change-Id: I14818b48d7d61617f236be906db75898fd192b52
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 00:11:11 +00:00
Tommy Kardach
6bf3b733ac Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev 2023-05-02 22:23:36 +00:00
Tommy Kardach
659c17d428 Allow P23 Camera HAL to acquire wake locks
Bug: 279977277
Test: mm && flash/test
Change-Id: I6150ccf788d5074ab9e2d29c6866c8a477a3ef71
2023-05-02 17:25:51 +00:00
Dan Moore
ce9357676d Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev am: 47eea99fb2 am: 57bea4ff01 am: b2af8c9026
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22932758

Change-Id: I4f63d020f599602fc01ee13647972315e358d463
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 17:05:44 +00:00
Dan Moore
47eea99fb2 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev 2023-05-02 15:00:31 +00:00
Treehugger Robot
66f77bbb93 Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4 am: bbfbf90c71 am: e2fea4a565
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: I26df5d3c976f239975c96ba86c62aab9b8962519
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:45:49 +00:00
Treehugger Robot
6cb57dd371 Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797 am: 222413abe5 am: 28ba80bbfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: I4e8c905d653469e84fb2062c9ae74027566c96c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:39:24 +00:00
Tom Huang
8fde4edfbf Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f am: 5c0053c5ec am: 34dd9a81d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: Id094f59aa2876b5742ae239f0f546ca9cda868e4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 12:37:13 +00:00
Treehugger Robot
470eda92e4 Merge "Enforce fastbootd" into udc-d1-dev 2023-05-02 04:54:37 +00:00
Treehugger Robot
5c70865797 Merge "sepolicy: ignore avc denial" into udc-d1-dev 2023-05-02 04:36:22 +00:00
Tom Huang
dd5df5791f Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev 2023-05-02 04:07:15 +00:00
Wilson Sung
8080b95d06 Enforce fastbootd
Fix: 264489957
Test: flash and no related avc error
Change-Id: Ibf616a98e9341310e18db6dda27d86adbf24deac
2023-05-02 11:42:59 +08:00
horngchuang
a6d7203408 Add sepolicy permission for new svarog sensor
Bug: 278473644
Test: Build and test for sensor denials
Change-Id: I2816a2ada49d4369b975ac22693994cff5cd6aec
2023-05-01 15:34:33 +00:00
Krzysztof Kosiński
1e74c58ae7 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev am: 9f7dec1023 am: bc2fb0e761 am: de77c8b0ac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22908419

Change-Id: I8bea0257ca6fbec1341283346e81c67748571fc3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-29 01:12:25 +00:00
Krzysztof Kosiński
9f7dec1023 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev 2023-04-28 22:18:37 +00:00
Dan Moore
4a0259ff34 Allow sensor HAL access to thermal HAL
The FIR temperature sensor must report an estimate of window temperature
so that the BTS SaMD can determine if the boundary condition between the
sensor and window is within accuracy specification.

Test: logcat previously reported access denied to thermal HAL. Access is
now granted and the Twindow elements are accessible.

Bug: 276738070
Change-Id: I72846053840e36ba8d3d59df9ba580c6c416e867
2023-04-28 12:13:32 -04:00
martinwu
d038ba2c5d [TSV2] Add sepolicy for dumpstate to zip tcpdump into bugreport am: 09aaf3dfbc am: 149ac2a92e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22899260

Change-Id: I52c702454a0435c445b190138618b05e09d1704e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-28 08:09:08 +00:00
Ted Wang
8831352474 Add sepolicy for aidl bt extension hal
Bug: 274906319
Test: build pass and manual test
Change-Id: Id54796fec22e790a197255f2db4ba23b4a58212d
2023-04-28 04:48:33 +00:00
Kamal Shafi
47f407fa8d Correct sepolicy permission for new UW cam EEPROM
change imentet camera sensor EEPROM naming to its codename.

Bug: 279547216
Test: build pass
Change-Id: Ib831119318a0b4467f81f93c009a28831cebac25
2023-04-28 02:56:30 +00:00