Commit graph

844 commits

Author SHA1 Message Date
Treehugger Robot
cdb62d5474 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev 2023-05-03 08:20:05 +00:00
Horng Chuang
5a2189a5ae Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev 2023-05-03 03:26:50 +00:00
Tommy Kardach
6bf3b733ac Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev 2023-05-02 22:23:36 +00:00
Tommy Kardach
659c17d428 Allow P23 Camera HAL to acquire wake locks
Bug: 279977277
Test: mm && flash/test
Change-Id: I6150ccf788d5074ab9e2d29c6866c8a477a3ef71
2023-05-02 17:25:51 +00:00
Dan Moore
47eea99fb2 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev 2023-05-02 15:00:31 +00:00
Treehugger Robot
11ea9b76d6 Merge "Remove obsolete tracking entry" into udc-d1-dev 2023-05-02 07:12:52 +00:00
Treehugger Robot
470eda92e4 Merge "Enforce fastbootd" into udc-d1-dev 2023-05-02 04:54:37 +00:00
Treehugger Robot
5c70865797 Merge "sepolicy: ignore avc denial" into udc-d1-dev 2023-05-02 04:36:22 +00:00
Tom Huang
dd5df5791f Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev 2023-05-02 04:07:15 +00:00
Wilson Sung
8080b95d06 Enforce fastbootd
Fix: 264489957
Test: flash and no related avc error
Change-Id: Ibf616a98e9341310e18db6dda27d86adbf24deac
2023-05-02 11:42:59 +08:00
horngchuang
a6d7203408 Add sepolicy permission for new svarog sensor
Bug: 278473644
Test: Build and test for sensor denials
Change-Id: I2816a2ada49d4369b975ac22693994cff5cd6aec
2023-05-01 15:34:33 +00:00
Krzysztof Kosiński
9f7dec1023 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev 2023-04-28 22:18:37 +00:00
Dan Moore
4a0259ff34 Allow sensor HAL access to thermal HAL
The FIR temperature sensor must report an estimate of window temperature
so that the BTS SaMD can determine if the boundary condition between the
sensor and window is within accuracy specification.

Test: logcat previously reported access denied to thermal HAL. Access is
now granted and the Twindow elements are accessible.

Bug: 276738070
Change-Id: I72846053840e36ba8d3d59df9ba580c6c416e867
2023-04-28 12:13:32 -04:00
Kamal Shafi
47f407fa8d Correct sepolicy permission for new UW cam EEPROM
change imentet camera sensor EEPROM naming to its codename.

Bug: 279547216
Test: build pass
Change-Id: Ib831119318a0b4467f81f93c009a28831cebac25
2023-04-28 02:56:30 +00:00
Krzysztof Kosiński
5b2134d5c5 Enforce sepolicy for Google Camera App.
Added missing statement allowing GXP firmware access.

Bug: 264489778
Test: GCA smoke test in setenforce mode.
Change-Id: Ied2f675a2e11f7aebcf4e1e6ac49fc2e39dd2ecf
2023-04-27 19:53:25 +00:00
Chungkai Mei
fdd0ef451e sepolicy: ignore avc denial
ignore avc denial since it is debugfs

Bug: 271931921
Test: pass boot health check extra test https://android-build.googleplex.com/builds/abtd/run/L49300000960255489
Change-Id: Iceee4d347b5e90bce6d16054c6ee0c8091652a9b
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-04-27 14:24:40 +00:00
martinwu
09aaf3dfbc [TSV2] Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I45c894fa9378a7878bc853f7723162ebd6141115
2023-04-27 13:47:34 +00:00
Bruno BELANYI
83087bd818 Merge "Add ArmNN config sysprops SELinux rules" into udc-d1-dev 2023-04-27 08:06:48 +00:00
Carol Cheng
bb1f0f25bb Merge "Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"" into udc-d1-dev 2023-04-27 06:36:48 +00:00
Martin Wu
4e2023c263 Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I795de89a17c5ccee702fa3a59af03d48d89fbaf2
2023-04-27 02:21:00 +00:00
Andrew Chant
6641141f91 Merge "Use tof sensor codenames" into udc-d1-dev 2023-04-27 02:07:29 +00:00
Treehugger Robot
fe27339606 Merge "Add sepolicy for dumpstate to zip tcpdump into bugreport" into udc-d1-dev 2023-04-27 01:43:58 +00:00
martinwu
da1f9ffa79 Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I04ca96860c78baf24afd7deecff7dd4d470d9539
2023-04-26 14:17:56 +00:00
Kamal Shafi
eb22b7d648 Add sepolicy permission for new UW camera
sepolicy including imentet camera sensor and gt24p64e EEPROM

Bug: 277988592
Bug: 279547216
Test: build pass
Change-Id: I01e2bc558eba7cf03c11818d9c806e6053808fd1
2023-04-26 11:32:33 +00:00
kuanyuhuang
477d58d695 Add hidraw device sepolicy for headtracking
Test: make and incoming HID data from Pixel Buds Pro
Bug: 276163506
Change-Id: I10833e215962ad007ad32a0d713e9b37ae888fdb
2023-04-26 09:20:11 +00:00
Salmax Chang
5ddf0079c6 Remove obsolete tracking entry
Bug: 264489567
Bug: 261651131
Change-Id: Ibf1116ea7b393f3c1e6eec0794e492b5dc2fd1ad
2023-04-26 17:15:36 +08:00
Bruno BELANYI
61df5feff7 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:aac79fd4d9bec6517b2932cfca1e1c84b7711cc8)
Merged-In: I77b29468258520265e5f660452794aff068ca07d
Change-Id: I77b29468258520265e5f660452794aff068ca07d
2023-04-26 08:12:29 +00:00
Wilson Sung
74494540d6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 279680070
Test: scanBugreport
Bug: 279680070
Bug: 279680213
Bug: 279680264
Test: scanAvcDeniedLogRightAfterReboot
Bug: 279680070
Change-Id: I0a5aadfed90377aeee60a15aaab212c7709d091a
2023-04-26 15:10:44 +08:00
Treehugger Robot
8ebffeef84 Merge "Remove 'hal_neuralnetworks_armnn' '/data' access exception" into udc-d1-dev 2023-04-26 05:07:41 +00:00
Treehugger Robot
8f8f545307 Merge "Remove hal_power_default bug from bug_map" into udc-d1-dev 2023-04-26 04:59:43 +00:00
Treehugger Robot
471a0c621a Merge "Remove old debug map entries." into udc-d1-dev 2023-04-26 04:59:25 +00:00
Joseph Jang
49269dd7dc Merge "Move recovery.te to device/google/gs-common/dauntless/sepolicy" into udc-d1-dev 2023-04-26 04:41:05 +00:00
Bruno BELANYI
f9d70ef1b2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Fix: 205779871
Test: manual - reboot device and check the absence of AVC denials
Change-Id: I7bf68036522553a2919076fc6243a577086ffb3a
Merged-In: I7bf68036522553a2919076fc6243a577086ffb3a
(cherry picked from commit deec8fec9d)
2023-04-26 03:35:52 +00:00
Nicolas Geoffray
42b382da0c Remove old debug map entries.
Fix: 264483352
Change-Id: Ie47107328f58dc4f1d4070e93c0cd09e88cee021
Merged-In: Ie47107328f58dc4f1d4070e93c0cd09e88cee021
(cherry picked from commit af3702bffd)
2023-04-26 03:33:31 +00:00
Chungkai Mei
c01d4b7d9b Remove hal_power_default bug from bug_map
SELinux errors are fixed and hence removing from bug map

Bug: 273638876
Test: Build and boot on device
Change-Id: I4ca6180ad286970d36ce204cd4c44e75962b26e0
Merged-In: I4ca6180ad286970d36ce204cd4c44e75962b26e0
Signed-off-by: Chungkai Mei <chungkai@google.com>
(cherry picked from commit 8051a8759a)
2023-04-26 03:32:21 +00:00
Treehugger Robot
dd9d69e132 Merge "Add sepolicy permission for new project" into udc-d1-dev 2023-04-26 02:34:56 +00:00
Treehugger Robot
e94c391ebb Merge "Remove dontaudit since read early_wakeup completed" into udc-d1-dev 2023-04-26 02:25:01 +00:00
Treehugger Robot
0cdcdbf433 Merge "Allow InputProcessor HAL to read display resolution" into udc-d1-dev 2023-04-26 02:19:40 +00:00
TreeHugger Robot
d1c31b785d Merge "Add memtrack" into udc-d1-dev 2023-04-25 21:44:08 +00:00
horngchuang
4c3cd890be Add sepolicy permission for new project
Bug: 279542096
Test: Build and test for sensor denials
Change-Id: I3d6b7ce33e101bd9eeacefae128239af3512b67f
2023-04-25 08:09:29 +00:00
Andrew Chant
55ef8a9026 Allow InputProcessor HAL to read display resolution
Cherry-pick of Change I23285c21a82748c63fbe20988af42884b9261b66
from Siarhei Vishniakou <svv@google.com>:

Currently, there's no API to read the resolution from the system domain,
so the HAL has to read this from the sysprop provided by the display
code.

Allow the HAL to do so in this CL.

Bug: 236200710
Bug: 279510160
Change-Id: I449232d91533b6b9a40f2a6c4a91c511f5b38e3c
2023-04-24 16:59:04 -07:00
timmyli
c09931ad38 Allow camera hal to access aoc device
Camera team needs to talk to aoc device in order to use libusf.
It will do this instead of talking to rlsservice. Soon, we can
remove rlsservice from the se policy for camera hal.

Bug: 277959222
Test: manual test, logs provided in comments
Change-Id: I7453fd94891dcc0c1c587bccb3bb6cff80f46e8b
2023-04-24 20:05:57 +00:00
Chungkai Mei
97f5b3c87a Remove dontaudit since read early_wakeup completed
The display file node, early_wakeup, just for trigger the worker for
display and it doesn't have meaningful read function. But PowerHAL read
all nodes and try to dump their valuesi while triggering bugreport. As
the read operation has been completed, so we can remove the clause.

07-02 00:53:56.888   522   522 W android.hardwar: type=1400 audit(0.0:8): avc: denied { dac_read_search } for capability=2 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0
07-02 00:53:56.888   522   522 W android.hardwar: type=1400 audit(0.0:9): avc: denied { dac_override } for capability=1 scontext=u:r:hal_power_default:s0 tcontext=u:r:hal_power_default:s0 tclass=capability permissive=0

Bug: 267261305
Test: Boot to home
Change-Id: I6c058a1a85ada7e5d6eb1f8acafaac8231ae5329
Merged-In: I6c058a1a85ada7e5d6eb1f8acafaac8231ae5329
Signed-off-by: Chungkai Mei <chungkai@google.com>
(cherry picked from commit 55d41f1a3e89b1f4d2525d9925e3319ef59e2705)
(cherry picked from commit 1d966a0db9)
2023-04-24 17:21:53 +00:00
Joseph Jang
6d754405ff Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: Icb4f899d76e1a5e1d6f6f2cee4c1c7f46105338c
2023-04-24 08:01:42 +00:00
Ankit Goyal
5e4db7517c Add memtrack
Bug: 279108265
Test: dumpsys meminfo
Change-Id: Ib46c89811aa3aa1a5573076f9dc69e7222f56ea4
2023-04-20 23:18:56 -07:00
Treehugger Robot
d90ebc1fdb Merge "Add Ims process label" into udc-d1-dev 2023-04-21 04:40:24 +00:00
Treehugger Robot
c84559a813 Merge changes from topic "260522202" into udc-d1-dev
* changes:
  Remove untraceable rules
  Enforce installd
2023-04-21 03:45:54 +00:00
Wilson Sung
e4e854fcd9 Add Ims process label
Bug: 260522282
Test: boot-to-home, no avc error
Change-Id: I8f3c7c64ecace4ca7ddd69275a093606a8492204
2023-04-21 03:38:17 +00:00
Treehugger Robot
a8fe91bc3c Merge "Remove hal_uwb_default bug from bug_map" into udc-d1-dev 2023-04-21 03:08:00 +00:00
Treehugger Robot
c3a5e6769c Merge "zuma: Allow GRIL Service to access radio_vendor_data_file" into udc-d1-dev 2023-04-21 02:43:46 +00:00