Commit graph

741 commits

Author SHA1 Message Date
Treehugger Robot
05abdf9f26 Merge "uwb: add permissions for factory uwb calib file" into udc-d1-dev 2023-05-15 16:54:11 +00:00
Jin Jeong
b3c701b9c4 Revert "[Zuma] Fix SeLinux error"
This reverts commit 709ad06c0e.

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Change-Id: Ibe56941737506158ef963bba2ae00035c5c11069
2023-05-12 04:20:27 +00:00
Luis Delgado de Mendoza Garcia
f31c984cda Add chre channel sepolicy entries
Bug: 241960170
Test: in-device verification.
Change-Id: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
Merged-In: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
2023-05-11 13:08:29 +00:00
Luis Delgado de Mendoza Garcia
2a06b44cdc Add chre channel sepolicy entries
Bug: 241960170
Test: in-device verification.
Change-Id: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
2023-05-10 17:35:01 +00:00
leohsieh
b7db7f8eae Allow hal_fingerprint_default to access sysfs_aoc_udfps
Fix the following avc denial:
avc: denied { search } for name="17000000.aoc" dev="sysfs" ino=22035 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc:s0 tclass=dir permissive=0
avc: denied { write } for name="udfps_set_clock_source" dev="sysfs" ino=106891 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc_udfps:s0 tclass=file permissive=0
avc: denied { read } for name="udfps_get_disp_freq" dev="sysfs" ino=106893 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc_udfps:s0 tclass=file permissive=0

Bug: 267271482
Test: Verify fingerprint HAL process can read/write to the sysfs node.
Change-Id: I39a2e69b1c314d52944bb16ada61e7e6761561cf
2023-05-10 14:50:56 +08:00
Zheng Pan
9ca108ac70 Merge "Allow systemui to find adbd" into udc-d1-dev am: 705cc4abf8 am: a98b8a881f am: 5dcb7abfa7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23104216

Change-Id: I6c1a04b234ac35b8723adae4fa697af8374206b2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 23:03:04 +00:00
Zheng Pan
705cc4abf8 Merge "Allow systemui to find adbd" into udc-d1-dev 2023-05-09 20:21:14 +00:00
Mahesh Kallelil
8e513c2155 Allow dump_modem to read logbuffer and wakeup events am: 1f885d0bcd am: 56184ab96e am: af236c3219
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22834646

Change-Id: I38d6bd8125af59ec6373d699e58d6a2461eedc5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 12:42:59 +00:00
Mahesh Kallelil
1f885d0bcd Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on P23
Bug: 278501642
Change-Id: I102583e37ec2e3852fd901a75bbb06de9ac6f77c
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-05-09 00:20:07 -07:00
Luke Chang
f86a07903b Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev 2023-05-09 06:09:33 +00:00
Wilson Sung
fd60d077ad Allow systemui to find adbd
Bug: 276415118
Fix: 272628396
Test: connect to adb with no avc error
Change-Id: I07496d663628f62ed975785d794854d1cdc77040
2023-05-09 05:22:16 +00:00
Luke Chang
ab998b462c Merge "sepolicy: label cpd cl2 & cl1" 2023-05-09 04:54:33 +00:00
Jin Jeong
f4389a4333 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev am: e22788ae78 am: 53cfab53be am: 077bfe327c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22984822

Change-Id: I1cdf145a6810a3754b7cbd3e2b44471366db1ebd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-09 02:23:13 +00:00
Hasan Awais
14b2c135bb uwb: add permissions for factory uwb calib file
needed for copying the factory calib file from persist to
/data/vendor/uwb, along with converting the file to a valid format
for uwb HAL

Bug: 274513871
Bug: 279820265
Test: local build passed
Change-Id: I4c4286cd5c200475cac3b9d58a81724d631c49e0
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-05-09 00:27:47 +00:00
Jin Jeong
e22788ae78 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev 2023-05-08 23:37:28 +00:00
Martin Liu
e4e930185a Add sepolicies for gcma_camera heaps
Bug: 275481134
Test: launch camera
Change-Id: I2efe897826d3c32bb85c815207865c0db557ea9f
Signed-off-by: Martin Liu <liumartin@google.com>
2023-05-08 23:54:55 +08:00
lukechang
35f3c85c09 sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:49:45 +00:00
lukechang
9d44de7ecf sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Merged-In: Iad525a9c556ee436afb8cbd29156b6b593329e83
Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:39:21 +00:00
sashwinbalaji
771b533133 thermal: thermal_metrics: Update selinux to reset stats
Bug: 193833982
Test: Local build and verify statsD logs
adb shell cmd stats print-logs && adb logcat -b all | grep -i 105045
Change-Id: I09afbea9386724f0abf6b9cab5838e89a060a5fd
2023-05-08 05:15:39 +00:00
TreeHugger Robot
99c3feb294 Merge "Add tele sensor sepolicy permission" into udc-d1-dev am: b417627fb8 am: 899d3062b6 am: ebb31ef6bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020018

Change-Id: I2c9c384487f02bf9d8a12db6121982a611a903f1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-08 04:00:55 +00:00
TreeHugger Robot
b417627fb8 Merge "Add tele sensor sepolicy permission" into udc-d1-dev 2023-05-08 02:00:59 +00:00
Treehugger Robot
ab47a1ae3b Merge "Add sepolicy permission of new camera components" into udc-d1-dev am: 74e0e5fc37 am: ad2c33b44a am: 76ab0fefef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982823

Change-Id: Ia805db6bdaa4a25a8606473eb668ab9bcf029590
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:36:25 +00:00
Ted Wang
0a096b1aef Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev am: be9ee4c01d am: b1473d353f am: 15b8415e2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22344152

Change-Id: I072ce6c114d1c4cb0ba0604a8faf2284c64b19ad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:35:23 +00:00
TreeHugger Robot
27d8b200d6 Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev am: 1db3ac365d am: 55ecf93b7d am: 5b6de1f086
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22589719

Change-Id: I70e686a83c79305cd21fe972748c72056e64c433
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 07:34:49 +00:00
Treehugger Robot
74e0e5fc37 Merge "Add sepolicy permission of new camera components" into udc-d1-dev 2023-05-05 06:27:43 +00:00
Ted Wang
be9ee4c01d Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev 2023-05-05 06:19:10 +00:00
TreeHugger Robot
1db3ac365d Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev 2023-05-05 05:35:55 +00:00
George Chang
e5b9b50686 Allow systemui_app to access Nfc service am: 178e94cb81 am: 74937b19bb am: 2613956e78
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23020017

Change-Id: Iaf5cd6da5e75a67a9d01eb700438d3336ade7528
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-05 02:32:33 +00:00
Manali Bhutiyani
cf161d6ce3 [display-stats] enable pixelstats access to display metrics on Zuma devices.
Bug: 259554507
Test: Build and boot on device
adb shell cmd stats print-stats | grep -i <atom-id>

Change-Id: Ifc47211063b98f727b3b0eb7f7ebd42e3c7bb99b
2023-05-04 20:56:24 +00:00
George Chang
178e94cb81 Allow systemui_app to access Nfc service
avc:  denied  { find } for pid=1867 uid=10249 name=nfc
scontext=u:r:systemui_app:s0:c249,c256,c512,c768
tcontext=u:object_r:nfc_service:s0 tclass=service_manager
permissive=0

Bug: 280531969
Test: manually check nfc signal after battery share on
Change-Id: I7c9092388d031e8714b8f3f4738db77776c66326
2023-05-04 09:52:14 +00:00
Kamal Shafi
e1464f8e53 Add tele sensor sepolicy permission
Bug: 280370254
Test: build pass
Change-Id: If76c157e272f40159bcd6aac08d4b3bc88991338
2023-05-04 09:18:55 +00:00
horngchuang
5e6e5b568b Add sepolicy permission of new camera components
Bug: 279885244
Bug: 280392819
Test: Build and test for sensor denials
Change-Id: Ib29b0287bc52f9c0fe6e3c18c272e6593507371b
2023-05-04 07:38:46 +00:00
Treehugger Robot
4bf45f603f Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev am: b3c7fb06fa am: fdb7364a3f am: 1264a719b2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22982957

Change-Id: If0c30a3137e97a09df0b7cd9b8d64a4d8de6ceff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 18:00:22 +00:00
Treehugger Robot
b3c7fb06fa Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev 2023-05-03 15:42:14 +00:00
Jack Wu
06bd429e9e sepolicy: allows pixelstat to access pca file nodes am: 8d45937a38 am: 923f9f2f5e am: 4b33e0e2d2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22987856

Change-Id: I79ee04faddffa909f5529a81af5fdf68c3a2a879
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 15:33:44 +00:00
Treehugger Robot
03abfd7621 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev am: cdb62d5474 am: a43377782f am: 8efc7938fe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22896105

Change-Id: Id34f927edf557c108df3e70acb5e8fe57ddae3d7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 10:27:45 +00:00
Jack Wu
8d45937a38 sepolicy: allows pixelstat to access pca file nodes
Bug: 262520811
Test: no Permission denied while accessing the file node
Change-Id: I0b50d85ea7002c9ee16f4c34b472b45def7f374e
Signed-off-by: Jack Wu <wjack@google.com>
2023-05-03 09:31:08 +00:00
Treehugger Robot
cdb62d5474 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev 2023-05-03 08:20:05 +00:00
Jinyoung Jeong
709ad06c0e [Zuma] Fix SeLinux error
Bug: 280522410
Test: no denial logs found for com.google.android.euicc b/280522410#comment3
Change-Id: I2837a71548cc8c8125b982313e2645ec8c913921
2023-05-03 07:44:44 +00:00
Horng Chuang
bf13c5b01c Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev am: 5a2189a5ae am: 0f17ef32db am: de56475f2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22668237

Change-Id: Idc51f1cac6f6f8b441a90372de16d129c152c7ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 05:48:17 +00:00
Horng Chuang
5a2189a5ae Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev 2023-05-03 03:26:50 +00:00
Kyle Tso
649f19fc94 Allow accessing dumpstate from hal_usb_impl
Fix SELinux errors.

Bug: 267261163
Change-Id: I73a311d796eb520ede3849edc6384c965ec5c915
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-05-03 11:23:52 +08:00
Tommy Kardach
b0b0a9080d Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev am: 6bf3b733ac am: 1e317a26ad am: bf83401a50
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22915638

Change-Id: I14818b48d7d61617f236be906db75898fd192b52
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-03 00:11:11 +00:00
Tommy Kardach
6bf3b733ac Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev 2023-05-02 22:23:36 +00:00
Tommy Kardach
659c17d428 Allow P23 Camera HAL to acquire wake locks
Bug: 279977277
Test: mm && flash/test
Change-Id: I6150ccf788d5074ab9e2d29c6866c8a477a3ef71
2023-05-02 17:25:51 +00:00
Dan Moore
ce9357676d Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev am: 47eea99fb2 am: 57bea4ff01 am: b2af8c9026
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22932758

Change-Id: I4f63d020f599602fc01ee13647972315e358d463
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 17:05:44 +00:00
Dan Moore
47eea99fb2 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev 2023-05-02 15:00:31 +00:00
Treehugger Robot
66f77bbb93 Merge "Enforce fastbootd" into udc-d1-dev am: 470eda92e4 am: bbfbf90c71 am: e2fea4a565
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22649706

Change-Id: I26df5d3c976f239975c96ba86c62aab9b8962519
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:45:49 +00:00
Treehugger Robot
6cb57dd371 Merge "sepolicy: ignore avc denial" into udc-d1-dev am: 5c70865797 am: 222413abe5 am: 28ba80bbfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22246611

Change-Id: I4e8c905d653469e84fb2062c9ae74027566c96c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:39:24 +00:00
Tom Huang
8fde4edfbf Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev am: dd5df5791f am: 5c0053c5ec am: 34dd9a81d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22874908

Change-Id: Id094f59aa2876b5742ae239f0f546ca9cda868e4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 12:37:13 +00:00