Commit graph

879 commits

Author SHA1 Message Date
Grace Chen
e151f78f5a Remove selinux error bug reference after fixing
Bug: 264483151
Test: None, simple bug removal
Change-Id: Id93085566c772e6b434777955b62b1ccaba64ae2
2023-05-18 17:54:20 -07:00
Xu Han
639d91fb93 Merge "Add permission for nautilus devices" into udc-d1-dev 2023-05-17 16:48:55 +00:00
Luke Chang
3d16072afb Merge "sepolicy: label cpd cl2 & cl1 target_residency" into udc-d1-dev 2023-05-17 10:09:06 +00:00
Xu Han
bdc91f6477 Add permission for nautilus devices
Bug: 283015605
Test: Build
Change-Id: I986a2798a4a5ca927a1a2aaea61edca9fa59b2c5
2023-05-17 03:59:43 +00:00
lukechang
73e88c0a83 sepolicy: label cpd cl2 & cl1 target_residency
Test: build and boot to home
Bug: 277390134

Merged-In: I127ffc74aa68976de4aaa4a750b4043def4e2759
Change-Id: I127ffc74aa68976de4aaa4a750b4043def4e2759
Signed-off-by: lukechang <lukechang@google.com>
2023-05-17 02:11:41 +00:00
TreeHugger Robot
3203ccc21a Merge "Add chre channel sepolicy entries" into udc-d1-dev 2023-05-16 23:04:18 +00:00
Luis Delgado de Mendoza Garcia
a3f0628f68 Add chre channel sepolicy entries
Bug: 275143652
Fix: 275143652
Test: in-device verification.
Change-Id: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
Merged-In: Iba27ad45a38b491ebdfa0191f5af02aafa9f90e2
2023-05-16 21:43:09 +00:00
Treehugger Robot
05abdf9f26 Merge "uwb: add permissions for factory uwb calib file" into udc-d1-dev 2023-05-15 16:54:11 +00:00
Wilson Sung
2e511cf418 Remove fixed SELinux bug from bug_map
Fix: 280706292
Bug: 280522410
Change-Id: I5b35759d2b89246e65683fbbc3ca877af04ef25b
2023-05-11 14:10:41 +08:00
Wilson Sung
17a784cf97 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281815594
Test: scanBugreport
Bug: 281815594
Bug: 281815537
Test: scanAvcDeniedLogRightAfterReboot
Bug: 281815594
Fix: 281645191
Change-Id: Ia1e72cdee3ca535eb978ad8becad94c9c4d8c2cd
2023-05-11 04:06:31 +00:00
Zixuan Lan
288623d4d4 remove fixed selinux bug from bug map.
TPU permission was fixed to avoid error in hal_camera_defaul.The corresponding bug for tracking should be removed from the bug map. Please see bug for more details.
Bug: 275001641
Test: logcat grep for selinux error

Change-Id: I3622a1877f94b41d03d1bcb1c16a404db4b3ea8d
2023-05-09 16:38:38 -07:00
Zheng Pan
705cc4abf8 Merge "Allow systemui to find adbd" into udc-d1-dev 2023-05-09 20:21:14 +00:00
Wilson Sung
e797557f08 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 10:06:38 +00:00
Mahesh Kallelil
1f885d0bcd Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on P23
Bug: 278501642
Change-Id: I102583e37ec2e3852fd901a75bbb06de9ac6f77c
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-05-09 00:20:07 -07:00
Treehugger Robot
254911d666 Merge "Update SELinux error" into udc-d1-dev 2023-05-09 07:15:25 +00:00
Luke Chang
f86a07903b Merge "sepolicy: label cpd cl2 & cl1" into udc-d1-dev 2023-05-09 06:09:33 +00:00
Wilson Sung
fd60d077ad Allow systemui to find adbd
Bug: 276415118
Fix: 272628396
Test: connect to adb with no avc error
Change-Id: I07496d663628f62ed975785d794854d1cdc77040
2023-05-09 05:22:16 +00:00
Wilson Sung
6ee8a855f9 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Test: scanBugreport
Bug: 280706211
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I84d50fc4e4f05d0228bc3713cf1b216bf12a72cd
2023-05-09 10:07:46 +08:00
Hasan Awais
14b2c135bb uwb: add permissions for factory uwb calib file
needed for copying the factory calib file from persist to
/data/vendor/uwb, along with converting the file to a valid format
for uwb HAL

Bug: 274513871
Bug: 279820265
Test: local build passed
Change-Id: I4c4286cd5c200475cac3b9d58a81724d631c49e0
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-05-09 00:27:47 +00:00
Jin Jeong
e22788ae78 Merge "[Zuma] Fix SeLinux error" into udc-d1-dev 2023-05-08 23:37:28 +00:00
lukechang
9d44de7ecf sepolicy: label cpd cl2 & cl1
Test: build and boot to home
Bug: 277390134

Merged-In: Iad525a9c556ee436afb8cbd29156b6b593329e83
Change-Id: Iad525a9c556ee436afb8cbd29156b6b593329e83
Signed-off-by: lukechang <lukechang@google.com>
2023-05-08 08:39:21 +00:00
TreeHugger Robot
b417627fb8 Merge "Add tele sensor sepolicy permission" into udc-d1-dev 2023-05-08 02:00:59 +00:00
Treehugger Robot
74e0e5fc37 Merge "Add sepolicy permission of new camera components" into udc-d1-dev 2023-05-05 06:27:43 +00:00
Ted Wang
be9ee4c01d Merge "Add sepolicy for aidl bt extension hal" into udc-d1-dev 2023-05-05 06:19:10 +00:00
TreeHugger Robot
1db3ac365d Merge "[display-stats] enable pixelstats access to display metrics on Zuma devices." into udc-d1-dev 2023-05-05 05:35:55 +00:00
Manali Bhutiyani
cf161d6ce3 [display-stats] enable pixelstats access to display metrics on Zuma devices.
Bug: 259554507
Test: Build and boot on device
adb shell cmd stats print-stats | grep -i <atom-id>

Change-Id: Ifc47211063b98f727b3b0eb7f7ebd42e3c7bb99b
2023-05-04 20:56:24 +00:00
George Chang
178e94cb81 Allow systemui_app to access Nfc service
avc:  denied  { find } for pid=1867 uid=10249 name=nfc
scontext=u:r:systemui_app:s0:c249,c256,c512,c768
tcontext=u:object_r:nfc_service:s0 tclass=service_manager
permissive=0

Bug: 280531969
Test: manually check nfc signal after battery share on
Change-Id: I7c9092388d031e8714b8f3f4738db77776c66326
2023-05-04 09:52:14 +00:00
Kamal Shafi
e1464f8e53 Add tele sensor sepolicy permission
Bug: 280370254
Test: build pass
Change-Id: If76c157e272f40159bcd6aac08d4b3bc88991338
2023-05-04 09:18:55 +00:00
horngchuang
5e6e5b568b Add sepolicy permission of new camera components
Bug: 279885244
Bug: 280392819
Test: Build and test for sensor denials
Change-Id: Ib29b0287bc52f9c0fe6e3c18c272e6593507371b
2023-05-04 07:38:46 +00:00
Wilson Sung
e7a70d62b5 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Bug: 280706292
Test: scanBugreport
Bug: 280706211
Bug: 280706610
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I67e0d2ec15b3ea057688644ba5c41c8fb5755128
2023-05-04 12:40:51 +08:00
Treehugger Robot
b3c7fb06fa Merge "Allow accessing dumpstate from hal_usb_impl" into udc-d1-dev 2023-05-03 15:42:14 +00:00
Jack Wu
8d45937a38 sepolicy: allows pixelstat to access pca file nodes
Bug: 262520811
Test: no Permission denied while accessing the file node
Change-Id: I0b50d85ea7002c9ee16f4c34b472b45def7f374e
Signed-off-by: Jack Wu <wjack@google.com>
2023-05-03 09:31:08 +00:00
Treehugger Robot
cdb62d5474 Merge "Correct sepolicy permission for new UW cam EEPROM" into udc-d1-dev 2023-05-03 08:20:05 +00:00
Jinyoung Jeong
709ad06c0e [Zuma] Fix SeLinux error
Bug: 280522410
Test: no denial logs found for com.google.android.euicc b/280522410#comment3
Change-Id: I2837a71548cc8c8125b982313e2645ec8c913921
2023-05-03 07:44:44 +00:00
Horng Chuang
5a2189a5ae Merge "Add sepolicy permission for new svarog sensor" into udc-d1-dev 2023-05-03 03:26:50 +00:00
Kyle Tso
649f19fc94 Allow accessing dumpstate from hal_usb_impl
Fix SELinux errors.

Bug: 267261163
Change-Id: I73a311d796eb520ede3849edc6384c965ec5c915
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-05-03 11:23:52 +08:00
Tommy Kardach
6bf3b733ac Merge "Allow P23 Camera HAL to acquire wake locks" into udc-d1-dev 2023-05-02 22:23:36 +00:00
Tommy Kardach
659c17d428 Allow P23 Camera HAL to acquire wake locks
Bug: 279977277
Test: mm && flash/test
Change-Id: I6150ccf788d5074ab9e2d29c6866c8a477a3ef71
2023-05-02 17:25:51 +00:00
Dan Moore
47eea99fb2 Merge "Allow sensor HAL access to thermal HAL" into udc-d1-dev 2023-05-02 15:00:31 +00:00
Treehugger Robot
11ea9b76d6 Merge "Remove obsolete tracking entry" into udc-d1-dev 2023-05-02 07:12:52 +00:00
Treehugger Robot
470eda92e4 Merge "Enforce fastbootd" into udc-d1-dev 2023-05-02 04:54:37 +00:00
Treehugger Robot
5c70865797 Merge "sepolicy: ignore avc denial" into udc-d1-dev 2023-05-02 04:36:22 +00:00
Tom Huang
dd5df5791f Merge "Add hidraw device sepolicy for headtracking" into udc-d1-dev 2023-05-02 04:07:15 +00:00
Wilson Sung
8080b95d06 Enforce fastbootd
Fix: 264489957
Test: flash and no related avc error
Change-Id: Ibf616a98e9341310e18db6dda27d86adbf24deac
2023-05-02 11:42:59 +08:00
horngchuang
a6d7203408 Add sepolicy permission for new svarog sensor
Bug: 278473644
Test: Build and test for sensor denials
Change-Id: I2816a2ada49d4369b975ac22693994cff5cd6aec
2023-05-01 15:34:33 +00:00
Krzysztof Kosiński
9f7dec1023 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev 2023-04-28 22:18:37 +00:00
Dan Moore
4a0259ff34 Allow sensor HAL access to thermal HAL
The FIR temperature sensor must report an estimate of window temperature
so that the BTS SaMD can determine if the boundary condition between the
sensor and window is within accuracy specification.

Test: logcat previously reported access denied to thermal HAL. Access is
now granted and the Twindow elements are accessible.

Bug: 276738070
Change-Id: I72846053840e36ba8d3d59df9ba580c6c416e867
2023-04-28 12:13:32 -04:00
Ted Wang
8831352474 Add sepolicy for aidl bt extension hal
Bug: 274906319
Test: build pass and manual test
Change-Id: Id54796fec22e790a197255f2db4ba23b4a58212d
2023-04-28 04:48:33 +00:00
Kamal Shafi
47f407fa8d Correct sepolicy permission for new UW cam EEPROM
change imentet camera sensor EEPROM naming to its codename.

Bug: 279547216
Test: build pass
Change-Id: Ib831119318a0b4467f81f93c009a28831cebac25
2023-04-28 02:56:30 +00:00
Krzysztof Kosiński
5b2134d5c5 Enforce sepolicy for Google Camera App.
Added missing statement allowing GXP firmware access.

Bug: 264489778
Test: GCA smoke test in setenforce mode.
Change-Id: Ied2f675a2e11f7aebcf4e1e6ac49fc2e39dd2ecf
2023-04-27 19:53:25 +00:00