Commit graph

702 commits

Author SHA1 Message Date
Ken Yang
024703040d WLC: cleanup the unused hal_wlc policies am: 58a6a1e772
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: I8aafb32f9a5c0bcd8f74e382a2f893fa71433b7d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:41 +00:00
Ken Yang
c43be3da60 WLC: cleanup WLC trakcing_denials am: 670b22c2c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Iff19425d747d5c03e4e10ae284523ef659b29200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:12:35 +00:00
Kah Xuan Lim
c7adfd1151 modem_svc_sit: grant modem property access am: 4e270f1615
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: Iad92808f73b22345e16d7ca602e57d25f01d42a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:57 +00:00
Wilson Sung
3bf76884bb allow bootctl to read devinfo am: 931ea0d342
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: Iba6993ef61237c11fa1a1c2eb493e339f32f16f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:11:00 +00:00
Wilson Sung
d952aae49a Remove proc_vendor_sched obsolete denials am: 676c7a674c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: Ib6e4ec093a81dd47ce32d3a110cd525fd9a5afb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:58 +00:00
Nicole Lee
cf40697979 logger_app: don't audit default_prop and fix errors am: 7706be6c71
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I10e07e96719038edaa420519e4e705cff9e9da49
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:10:55 +00:00
Wilson Sung
7ebe356b25 [automerger skipped] Revert "Revert "Update error on ROM 9624328"" am: e70b98af09 -s ours
am skip reason: Merged-In I25b0f417af3e741719f959aed79e7e330687e117 with SHA-1 47570e0ed6 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508208

Change-Id: I648005a9da414a45147f1b96a1b9713c6ac7701a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:44 +00:00
Ken Yang
09c84f9c05 [automerger skipped] WLC: cleanup the unused hal_wlc policies am: 58a6a1e772 -s ours
am skip reason: Merged-In I90b9e442082b8e03e76ce63aaee56e5882933449 with SHA-1 6f9844d137 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508214

Change-Id: If4a61aec985ac1afae878b8c55b6d7f4b0fce2d3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:33 +00:00
Ken Yang
b916e536c6 [automerger skipped] WLC: cleanup WLC trakcing_denials am: 670b22c2c7 -s ours
am skip reason: Merged-In I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51 with SHA-1 da69d2a494 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508213

Change-Id: Ia10406b389c96373271971825f431283aaead828
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:32 +00:00
Kah Xuan Lim
ac962b6c02 [automerger skipped] modem_svc_sit: grant modem property access am: 4e270f1615 -s ours
am skip reason: Merged-In Id5e66d94eb14c6979d3b93d54fd73634444cdea1 with SHA-1 77ce224141 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508212

Change-Id: Ide9a301546fbe8123e79635bcb9948975ed1fb53
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:09:07 +00:00
Wilson Sung
c58e5f5b99 [automerger skipped] allow bootctl to read devinfo am: 931ea0d342 -s ours
am skip reason: Merged-In I41d2763ffe40d7465a11cc86612fed9f92905eff with SHA-1 967da5da4f is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508211

Change-Id: I214b208e67770556f95b68b4831ba9257a3334f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:21 +00:00
Wilson Sung
794fc587fb [automerger skipped] Remove proc_vendor_sched obsolete denials am: 676c7a674c -s ours
am skip reason: Merged-In I308df50eefe611a0a87afc9a21387465487cc6ea with SHA-1 6545bc156a is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508210

Change-Id: I9651a19016960762493b45e73ae36fb87c4e10a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:19 +00:00
Nicole Lee
eed60fbd0b [automerger skipped] logger_app: don't audit default_prop and fix errors am: 7706be6c71 -s ours
am skip reason: Merged-In I8999372d243286586eb53602e167fa111d39a00f with SHA-1 ef1d13d86d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508209

Change-Id: I2225951e84dbc4e43035a9c9835ae266df103e6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 23:08:17 +00:00
Wilson Sung
e70b98af09 Revert "Revert "Update error on ROM 9624328""
This reverts commit d8572861e3.

Remove hal_googlebattery related denied

Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Merged-In: I25b0f417af3e741719f959aed79e7e330687e117
Change-Id: I25b0f417af3e741719f959aed79e7e330687e117
2023-02-20 11:06:17 +00:00
Ken Yang
58a6a1e772 WLC: cleanup the unused hal_wlc policies
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit 6f9844d137)
Merged-In: I90b9e442082b8e03e76ce63aaee56e5882933449
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
2023-02-20 11:05:53 +00:00
Ken Yang
670b22c2c7 WLC: cleanup WLC trakcing_denials
Bug: 268566583
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit da69d2a494)
Merged-In: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
2023-02-20 11:05:25 +00:00
Kah Xuan Lim
4e270f1615 modem_svc_sit: grant modem property access
Log message gotten before adding the policy:
avc: denied { connectto } for comm="modem_svc_sit" path="/dev/socket/property_service" scontext=u:r:modem_svc_sit:s0 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1

Bug: 247669574
(cherry picked from commit 77ce224141)
Merged-In: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
Change-Id: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
2023-02-20 11:04:11 +00:00
Wilson Sung
931ea0d342 allow bootctl to read devinfo
Bug: 260522436
(cherry picked from commit 967da5da4f)
Merged-In: I41d2763ffe40d7465a11cc86612fed9f92905eff
Change-Id: I41d2763ffe40d7465a11cc86612fed9f92905eff
2023-02-20 11:02:28 +00:00
Wilson Sung
676c7a674c Remove proc_vendor_sched obsolete denials
Bug: 264490054
(cherry picked from commit 6545bc156a)
Change-Id: I308df50eefe611a0a87afc9a21387465487cc6ea
Merged-In: I308df50eefe611a0a87afc9a21387465487cc6ea
2023-02-20 11:01:42 +00:00
Nicole Lee
7706be6c71 logger_app: don't audit default_prop and fix errors
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:default_prop:s0" dev="tmpfs" ino=153 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
avc: denied { search } for name="ssrdump" dev="dm-44" ino=377 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
avc: denied { search } for name="coredump" dev="dm-44" ino=378 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_coredump_file:s0 tclass=dir permissive=0 app=com.android.pixellogger

Bug: 264489961
Bug: 269383459
Test: Make sure no avc denied for logger_app when using Pixel Logger
(cherry picked from commit ef1d13d86d)
Change-Id: I8999372d243286586eb53602e167fa111d39a00f
Merged-In: I8999372d243286586eb53602e167fa111d39a00f
2023-02-20 11:00:59 +00:00
TreeHugger Robot
9adfa9a961 Merge "Revert "Revert "Update error on ROM 9624328""" 2023-02-20 08:00:15 +00:00
Sean.JS Tsai
6f7bde4d0e Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286 am: f0e29936a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: Ie75b3d535e6dbe6d5dbad91fa69df58e61c25b27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 07:55:14 +00:00
Wilson Sung
47570e0ed6 Revert "Revert "Update error on ROM 9624328""
This reverts commit d8572861e3.

Remove hal_googlebattery related denied

Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Change-Id: I25b0f417af3e741719f959aed79e7e330687e117
2023-02-20 15:07:14 +08:00
Sean.JS Tsai
f0e29936a5 Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: I564275400b71dd3f2859b4a4cf7b4bcce56e0969
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:46:09 +00:00
Sean.JS Tsai
5c6a9053e5 Merge "Revert "Update error on ROM 9624328"" into udc-dev am: 8838f4e286
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21502536

Change-Id: I6be9c22256297c1417b6f9f4c361ba1e818b540f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 06:44:47 +00:00
Sean.JS Tsai
8838f4e286 Merge "Revert "Update error on ROM 9624328"" into udc-dev 2023-02-20 05:59:29 +00:00
TreeHugger Robot
0d91c28418 Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd am: f5aeedf6fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: Ia337af931a821f03c8c72f491113eea8e7bf043f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 05:23:43 +00:00
Sean.JS Tsai
d8572861e3 Revert "Update error on ROM 9624328"
This reverts commit cf747f40d6.

Reason for revert: <b/269976373>

Change-Id: I1bee9c1da2571ab753c2193491ebc71b288b66b2
2023-02-20 04:29:33 +00:00
Ken Yang
dd3eaa4dce Merge "WLC: cleanup the unused hal_wlc policies" 2023-02-20 04:21:11 +00:00
Ken Yang
91045cea32 Merge "WLC: cleanup WLC trakcing_denials" 2023-02-20 04:20:59 +00:00
TreeHugger Robot
f5aeedf6fc Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: I4c579890ef5ee1c6427b3b699223d3d9cea138be
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:16:13 +00:00
TreeHugger Robot
864bf07d5c Merge "Update error on ROM 9624328" into udc-dev am: ea203448fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21482714

Change-Id: If0e5d0b805f5cf467d0ec8c66310919df9acd088
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-20 04:13:24 +00:00
TreeHugger Robot
ea203448fd Merge "Update error on ROM 9624328" into udc-dev 2023-02-20 03:28:27 +00:00
sukiliu
cf747f40d6 Update error on ROM 9624328
Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Test: SELinuxUncheckedDenialBootTest
Change-Id: Id8cbfb7c55f2acdc3102b20cdbd2702b594992ba
2023-02-20 10:28:33 +08:00
Ken Yang
6f9844d137 WLC: cleanup the unused hal_wlc policies
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-20 00:58:13 +00:00
Ken Yang
da69d2a494 WLC: cleanup WLC trakcing_denials
Bug: 268566583
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-20 00:42:35 +00:00
TreeHugger Robot
d19076e7ff Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a am: dfd3d8e7c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: I7beb6ec7071cba88880bf0f1c8ce17ec0a54fb0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 16:01:39 +00:00
TreeHugger Robot
dfd3d8e7c5 Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: Ice2cb63d7abc67b3185532be682db8841d018c1a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:51:17 +00:00
TreeHugger Robot
213f91ad98 Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev am: c012a8a10a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475626

Change-Id: I897ae56dfb2a8fb577cc1ca3340a9feecab8c15b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 14:49:15 +00:00
TreeHugger Robot
c012a8a10a Merge "hal_health_default: allow to access persist.vendor.shutdown.*" into udc-dev 2023-02-18 13:46:15 +00:00
Kuen-Han Tsai
f939579c6e SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3 am: e4af4e0824
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I3d48ca424b1490004894b0809d6b9c03f3a17532
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 06:04:38 +00:00
Kuen-Han Tsai
e4af4e0824 SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I639171077e99d6e17698e7a1905712ab7d4446a6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 04:54:12 +00:00
Kuen-Han Tsai
f0173dff8a SEPolicy: remove tracking denials for hal_usb am: d0ac5bffa3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21486210

Change-Id: I949f460625696b1de5b5a89caeef9b59869b9e1d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 04:48:21 +00:00
neoyu
9ae44843ad Fix avc denied for hal_radioext_default am: c0da946f48 am: 4ff3dbefcd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: Ia082d38a7ea7079fd0f7d2cd86b3d7c3d847d10d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 03:27:40 +00:00
Kuen-Han Tsai
d0ac5bffa3 SEPolicy: remove tracking denials for hal_usb
Remove tracking denials since there is no avc denials related to hal_usb
found in the bug report.

Bug: 264483531
Bug: 264483531
Bug: 264482981
Bug: 264600052
Bug: 264482981
Bug: 264600052
Bug: 261651112
Test: Capture bugreport and check any denials related to hal_usb
Change-Id: I535c94c1112fc51f80b80c99562b43afee32ddd6
2023-02-18 02:41:51 +00:00
neoyu
4ff3dbefcd Fix avc denied for hal_radioext_default am: c0da946f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: I1cbdf50e1f0dc138076cf70b8229885f60482c60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 02:23:12 +00:00
neoyu
e4e8a1df0f Fix avc denied for hal_radioext_default am: c0da946f48
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21475628

Change-Id: Id91591d00b8ba8a606dfc9938d82a89fb861756a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-18 02:21:37 +00:00
neoyu
c0da946f48 Fix avc denied for hal_radioext_default
avc: denied { call } for comm="HwBinder:782_1" scontext=u:r:hal_radioext_default:s0 tcontext=u:r:hal_bluetooth_btlinux:s0 tclass=binder permissive=0

Bug: 269684065
Test: manual
Change-Id: I5ebf280feafabf4688718197c79bd6c4cac6e8fe
2023-02-17 08:39:47 +00:00
Ken Tsou
10e84d8327 hal_health_default: allow to access persist.vendor.shutdown.*
msg='avc: denied { set } for property=persist.vendor.shutdown.voltage_avg pid=908 uid=1000 gid=1000 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service permissive=0'

Bug: 266181615
Change-Id: Ia87610f0363bbfbe4fe446244b44818c273841f4
Signed-off-by: Ken Tsou <kentsou@google.com>
2023-02-17 07:00:37 +00:00
Kah Xuan Lim
77ce224141 modem_svc_sit: grant modem property access
Log message gotten before adding the policy:
avc: denied { connectto } for comm="modem_svc_sit" path="/dev/socket/property_service" scontext=u:r:modem_svc_sit:s0 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1

Bug: 247669574
Change-Id: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
2023-02-17 06:24:53 +00:00