Commit graph

664 commits

Author SHA1 Message Date
Jason Chiu
a31f1a6d5c Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488 am: 7aa9a5e3c0 am: fe9e70cbbb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I3c4125d31626e02e59523a5fd4c249a3311986b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 20:39:14 +00:00
Jason Chiu
67addf1851 remove rule for bootctrl hidl version 1.2 am: 54b0343059 am: b9e73326ee am: 8bceac530e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: I9411d0f4e94a85fd3814cf3317b560016bcd9697
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 20:39:12 +00:00
Jason Chiu
7aa9a5e3c0 Add hal_bootctl_default read permission to rootfs in Recovery mode am: 90a1f80488
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24143123

Change-Id: I3bc9799d166ad41bbbb547884a9993a352b3f6c3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:19 +00:00
Jason Chiu
b9e73326ee remove rule for bootctrl hidl version 1.2 am: 54b0343059
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24146702

Change-Id: Ia4efc4cdc0cb92c62c4ddcb7b6f458c4149657a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:16 +00:00
Jason Chiu
cbb8fed21e Add rule for bootctrl AIDL am: 17fa2e6fe5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24141842

Change-Id: Idbac1303702c0845fd549564f28b20f2bf9f0a03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-21 02:59:13 +00:00
Jason Chiu
3aa432be32 Merge "Add rule for bootctrl AIDL"
Bug: 282670401
Change-Id: I1b4c5e7ced0fe67bbbaca2b607e4ca7422e170e1
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 21:00:41 +08:00
Jason Chiu
90a1f80488 Add hal_bootctl_default read permission to rootfs in Recovery mode
Fix the following avc denial:
avc:  denied  { read } for  pid=485 comm="android.hardwar" name="bin" dev="rootfs" ino=9529 scontext=u:r:hal_bootctl_default:s0 tcontext=u:object_r:rootfs:s0 tclass=dir permissive=0

Bug: 282670401
Change-Id: I23ab086ba21d6ffea8b48b4208933c031effc4d4
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:47 +00:00
Jason Chiu
54b0343059 remove rule for bootctrl hidl version 1.2
Bug: 282670401
Change-Id: I25d169c335fb551cf1862fdf6e6540485a2b8016
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 12:56:38 +00:00
Jason Chiu
17fa2e6fe5 Add rule for bootctrl AIDL
Bug: 282670401
Change-Id: I1b4c5e7ced0fe67bbbaca2b607e4ca7422e170e1
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
2023-07-20 20:53:04 +08:00
Utku Utkan
c2e654730b Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: 62b083db4d am: 4f7d7213fe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24124264

Change-Id: Ie2bb0cfcf9613d1e12da3fea6887000c4761fb5b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 19:58:33 +00:00
Utku Utkan
62b083db4d Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Reason for revert: Relanding the original topic after copying the certificates under `device/google` for `without-vendor` branches

Reverted changes: /q/submissionid:24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Bug: 287069860
Test: m && flashall
Change-Id: Icc801ca310c0e512769ed84d185dd6149ae5f22b
2023-07-18 20:37:42 -07:00
Inseob Kim
ffec72585d Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: 1ef04d8dda am: ef514a009d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24122567

Change-Id: I11407eb1d65424f34d3ebe601a6c16e660dd8e4d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 03:33:46 +00:00
Inseob Kim
1ef04d8dda Revert "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24056607-pixel-camera-services-extensions-sepolicy

Reason for revert: build breakage on git_main-without-vendor

Reverted changes: /q/submissionid:24056607-pixel-camera-services-extensions-sepolicy

Change-Id: I42e68b982d521acb9b9a088d58ff521be25beb7e
2023-07-19 01:15:27 +00:00
Utku Utkan
ed8790420e Introduce CameraServices seinfo tag for PixelCameraServices am: c3cf1b7cf0 am: 5dfb9ad64d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24030833

Change-Id: I628cb17d6053851612608f82700e518a043c2884
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 22:35:36 +00:00
Utku Utkan
c3cf1b7cf0 Introduce CameraServices seinfo tag for PixelCameraServices
Bug: 287069860
Test: m && flashall && check against 'avc: denied' errors
Change-Id: I843c7e0577d88a7e84cb939135fe89f5923ea294
2023-07-18 12:18:35 -07:00
Dinesh Yadav
67b64c50b4 Merge "[Cleanup]: Move gxp sepolicies to gs-common for P23" into main 2023-07-14 04:00:25 +00:00
Treehugger Robot
00cc329f1c Merge "Add GPU power hint sysfs node to sepolicy for Zuma" into udc-d1-dev am: 8bcc8a1242 am: a5187246a1 am: d079eb063f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23643602

Change-Id: I2c9fe5900fcdaa1fbbfa0bf0ee923cc68819c4b9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-14 01:16:08 +00:00
Treehugger Robot
a5187246a1 Merge "Add GPU power hint sysfs node to sepolicy for Zuma" into udc-d1-dev am: 8bcc8a1242
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23643602

Change-Id: I5662604da8561e8e8729cd494ba35d1797339e82
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-13 19:02:40 +00:00
Treehugger Robot
8bcc8a1242 Merge "Add GPU power hint sysfs node to sepolicy for Zuma" into udc-d1-dev 2023-07-13 17:47:48 +00:00
Badhri Jagan Sridharan
5958be5bd0 Merge "Add USB wakeup sources sepolicy contexts" into udc-d1-dev am: 20eade41f0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23864376

Change-Id: I512b4db16ff18acc313dc0d0c94f78bf4743ddcc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-13 17:34:05 +00:00
Badhri Jagan Sridharan
20eade41f0 Merge "Add USB wakeup sources sepolicy contexts" into udc-d1-dev 2023-07-13 16:43:18 +00:00
Hasan Awais
ab0cc41a0d uwb: add permission to read SELinux state am: 4640c96bb4 am: 484e16d61b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24007918

Change-Id: I00b3af162bc57f840ac55d8ff881fa55034bc238
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 18:10:26 +00:00
Hasan Awais
4640c96bb4 uwb: add permission to read SELinux state
Allows UWB HAL to read selinuxfs to determine the state
Used for controlling access to debugfs

Bug: 288049522
Test: local build pass
Change-Id: I1237d001d27999c796bbb28629847f5a5639cd3e
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-07-10 17:12:33 +00:00
Dinesh Yadav
1278d8fc59 [Cleanup]: Move gxp sepolicies to gs-common for P23
These policies are moved to gs-common as part of ag/24002524

Bug: 288368306
Change-Id: Iaa15e497eafd54b1b702192a3c8f7fe0c908f8a1
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-07-10 05:13:16 +00:00
Yunju Lee
0a86789618 Add GPU power hint sysfs node to sepolicy for Zuma
Bug: 228076319
Bug: 278493002
Test: Perfetto trace inspection
Change-Id: I2f78c2e9175faa3f8af4b55e93e9b0f3d6bebdf2
2023-07-07 21:40:20 +00:00
Ruofei Ma
8ccd2bdb48 Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev am: f3258b9e00 am: d853f05f4e am: 545d486384
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23852417

Change-Id: I86ae0f4173db0618b55fdebf02cea1e9e1aacc3e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 05:28:39 +00:00
Ruofei Ma
a5365042c2 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev am: aa2084fe54 am: 5358c08714 am: a87ac085c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23850445

Change-Id: I06f846290147757f90432f5cb414b87329c8c271
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 05:26:15 +00:00
Ruofei Ma
545d486384 Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev am: f3258b9e00 am: d853f05f4e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23852417

Change-Id: I465659921f35ec199201b5d1284f2b0c6cc43d50
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 04:42:15 +00:00
Ruofei Ma
a87ac085c0 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev am: aa2084fe54 am: 5358c08714
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23850445

Change-Id: Ia939ab3855b0260c427d5d490e37f94a5ce35a27
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 04:40:28 +00:00
Ruofei Ma
99ff7c4007 Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev am: f3258b9e00
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23852417

Change-Id: I0976a47af9e3ccab16a391c9835885b88166ac95
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 03:33:06 +00:00
Ruofei Ma
4471c5e525 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev am: aa2084fe54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23850445

Change-Id: I28bbba859b673990f752fed64098a8e56a9cb99a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 03:32:45 +00:00
Ruofei Ma
f3258b9e00 Merge "Dec: SELinux policy change to allow uclamp.min set" into udc-d1-dev 2023-07-06 02:49:56 +00:00
Ruofei Ma
aa2084fe54 Merge "Revert "mediacodec_google: add hal_power"" into udc-d1-dev 2023-07-06 02:49:51 +00:00
Badhri Jagan Sridharan
62e714d81c Add USB wakeup sources sepolicy contexts
Bug: 289376260
Change-Id: I72711aea571dad5be7ff36ca7a7c59240aaa2226
Merged-In: I72711aea571dad5be7ff36ca7a7c59240aaa2226
Signed-off-by: Badhri Jagan Sridharan <badhri@google.com>
2023-06-30 19:36:01 +00:00
Badhri Jagan Sridharan
4f16f36a78 Add USB wakeup sources sepolicy contexts
Bug: 289376260
Change-Id: I72711aea571dad5be7ff36ca7a7c59240aaa2226
Signed-off-by: Badhri Jagan Sridharan <badhri@google.com>
2023-06-30 02:13:27 +00:00
Wilson Sung
5915cd099a Move sysUI contexts to system_ext am: 4862829753 am: b8ec9b7fc4 am: 0998a42154
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23840925

Change-Id: Ibc19fce60a0c362923f89ae8f9af65164ce16a82
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-29 05:48:49 +00:00
Wilson Sung
0998a42154 Move sysUI contexts to system_ext am: 4862829753 am: b8ec9b7fc4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23840925

Change-Id: I9963b7fa09e1f22ba868cd3abe3fcb090a46cc39
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-29 04:59:33 +00:00
Wilson Sung
bd6892b9d3 Move sysUI contexts to system_ext am: 4862829753
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23840925

Change-Id: Iae1889fe451b09d41160689c24d2888a1a4da796
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-29 04:17:50 +00:00
Ruofei Ma
4ee8ce9cd6 Dec: SELinux policy change to allow uclamp.min set
To get better performance for 4K60FPS HDR video, we need
to boost the cpu when the load is too heavy for Bigwave
decoder.

Bug: 274736629

Change-Id: I32d683084dd55354002d4fd4c266492df3839a35
Signed-off-by: Ruofei Ma <ruofeim@google.com>
2023-06-29 00:22:24 +00:00
Ruofei Ma
4bb2aa413d Revert "mediacodec_google: add hal_power"
This reverts commit 3346e879e6.

Reason for revert: This change is not needed since the performance boost implementation has changed

Change-Id: Icda43f23354e70503d3bb2efe0631a2d754a4920
2023-06-29 00:22:11 +00:00
Wilson Sung
4862829753 Move sysUI contexts to system_ext
Bug: 288227521
Change-Id: I3e5f2e76bf067f98b191b3b8ee6010c1abd95cb0
2023-06-28 14:10:06 +08:00
TreeHugger Robot
95453db458 Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev am: 043ae16d5f am: 62b8a1fed8 am: 4841655987
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753755

Change-Id: Ib628b70bb7c0dd455e456be91714217479e7ed06
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 11:49:09 +00:00
Treehugger Robot
124d76da0e Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev am: d8b11ef832 am: 2a4fea9c9e am: bac6c337b1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753754

Change-Id: I75815cc322f7cb7c0a3d1d07fede9c988569923f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 11:48:29 +00:00
TreeHugger Robot
62b8a1fed8 Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev am: 043ae16d5f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753755

Change-Id: I64ce27f29959da86f4a3effdc2700c9edd12c365
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 11:02:13 +00:00
Treehugger Robot
bac6c337b1 Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev am: d8b11ef832 am: 2a4fea9c9e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753754

Change-Id: Id590901414e2cfd34eeecb7747cec3a122ca4134
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 10:57:38 +00:00
TreeHugger Robot
043ae16d5f Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev 2023-06-21 10:47:39 +00:00
Treehugger Robot
e25310025c Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev am: d8b11ef832
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23753754

Change-Id: I7c9fa2e932b7547fee5aacf6a82177513f8d59ef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 10:38:30 +00:00
Treehugger Robot
d8b11ef832 Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev 2023-06-21 09:59:33 +00:00
Wilson Sung
3657f78cb0 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-06-21 16:02:41 +08:00
Wilson Sung
0b77875c4a Supress kernel avc log before SELinux initialized
Bug: 288049349
Fix: 288049229
Change-Id: I5087a77e65ecdbaa868a7257342f5d99f424880a
2023-06-21 16:02:29 +08:00