Wilson Sung
e4e854fcd9
Add Ims process label
...
Bug: 260522282
Test: boot-to-home, no avc error
Change-Id: I8f3c7c64ecace4ca7ddd69275a093606a8492204
2023-04-21 03:38:17 +00:00
kadirpili
92636953cf
zuma: Allow GRIL Service to access radio_vendor_data_file
...
Bug: 274737512
Change-Id: I90c008172af7bd0d8b7bf2b214f422c4165f3769
(cherry picked from commit 5c31a6f55ac18dd941e50b455c38a37efa12354f)
2023-04-20 03:37:22 +00:00
Wilson Sung
ab9b7f7609
Label ims_remote_app and rcs_service_app
...
Bug: 260522282
Change-Id: I4bf27e30eda51794d2047da9ca17044632ec3786
2023-04-20 00:13:52 +08:00
Kah Xuan Lim
6e8c79e7db
Modem ML: Grant access to modem ML data dir
...
Bug: 229801544
Change-Id: Ia2e9c5a48ad935a49f3b8a9c6bceae3f4f833b4e
2023-04-12 08:48:57 +00:00
Adam Shih
46fd63b761
comply with VTS requirements am: 22e1c0756a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22344148
Change-Id: I02d1e5a2af5bb6d3009d2b7687dff6080f56724f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 03:08:17 +00:00
Adam Shih
22e1c0756a
comply with VTS requirements
...
Bug: 275142299
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Built pass on target-userdebug and aosp_target-userdebug
Change-Id: I6a114aa2aa92f7b06cfd5bbd1f73d34b5477b109
2023-03-30 13:28:43 +08:00
TreeHugger Robot
6cbdc36e1b
Merge "Move pixel dumpstate to gs-common" into udc-d1-dev
2023-03-29 16:06:45 +00:00
Adam Shih
b19966b929
Merge "Revert "comply with VTS requirements"" into udc-dev am: 97c56013be
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22328024
Change-Id: Ic5841fefdd7576548fff66fc340259814e542df9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 03:12:09 +00:00
Adam Shih
97c56013be
Merge "Revert "comply with VTS requirements"" into udc-dev
2023-03-29 02:49:09 +00:00
Adam Shih
a0b5162488
Revert "comply with VTS requirements"
...
Revert submission 22302106-dumpstate aidl
Reason for revert: build failed on udc-d1-dev
Reverted changes: /q/submissionid:22302106-dumpstate+aidl
Change-Id: I6bd0ec81272827498ce36bee556fd89acc6b20ca
2023-03-29 02:45:20 +00:00
Adam Shih
026cb8d935
Merge "comply with VTS requirements" into udc-dev am: 7cb203f3c2
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22306662
Change-Id: I03432b1457e7b251ac5f5f9d7e10e3b4485260cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 00:47:11 +00:00
Adam Shih
7cb203f3c2
Merge "comply with VTS requirements" into udc-dev
2023-03-28 23:58:03 +00:00
Mingguang Xu
203dd313e7
Merge "Add permissions to connect radioext to twoshay." into udc-dev am: 57e322c17c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21956466
Change-Id: Ib70d523bc36e1a789b003374207094f2eaf722d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-28 23:09:15 +00:00
Mingguang Xu
57e322c17c
Merge "Add permissions to connect radioext to twoshay." into udc-dev
2023-03-28 23:03:46 +00:00
Adam Shih
d4a7ff694a
comply with VTS requirements
...
Bug: 275142299
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Built pass on target-userdebug and aosp_target-userdebug
Change-Id: Ifd75afdf2365687eed9598f74dd4cf3241be2964
2023-03-28 03:28:55 +00:00
RD Babiera
a82406ee28
Merge "Revert "comply with VTS requirements"" into udc-dev am: 3616de2c26
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22298904
Change-Id: I49798505d571f538127fc5d2b9474cce3992421c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 22:31:37 +00:00
RD Babiera
3616de2c26
Merge "Revert "comply with VTS requirements"" into udc-dev
2023-03-27 21:52:39 +00:00
RD Babiera
8720ececf1
Revert "comply with VTS requirements"
...
Revert submission 22242215-dumpstate aidl
Reason for revert: DroidMonitor-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?branch=git_udc-d1-dev&target=aosp_husky-userdebug&lkgb=9826121&lkbb=9829863&fkbb=9826130 , bug b/275279368.
Reverted changes: /q/submissionid:22242215-dumpstate+aidl
Change-Id: Ida32309c468074a5671c30aa28cf801c1695d786
2023-03-27 20:58:33 +00:00
Adam Shih
036fb44a5d
Move pixel dumpstate to gs-common
...
Bug: 240530709
Test: adb bugreport
Change-Id: I10f98673ea507f841d9d3f33d737c4e73c1b5b19
Merged-In: I4c46a2495ea07b9e44f56c4c6be726621e0ebf65
(cherry picked from commit 8538fd33da
)
2023-03-27 17:57:22 +00:00
Alan
afafafd8a4
Add permissions to connect radioext to twoshay.
...
Connection through grilantennatuningservice binder call.
Test: manual
Bug: 258970389
Change-Id: I419b40042cce363428f72fa723adf89bcf269ef4
2023-03-27 17:07:16 +08:00
TreeHugger Robot
84aab225cf
Merge "comply with VTS requirements" into udc-dev am: c83e5be8d9
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22286084
Change-Id: I0b9cf28cdfb549e2c3571e144f73f59d0004bc02
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 06:27:52 +00:00
TreeHugger Robot
c83e5be8d9
Merge "comply with VTS requirements" into udc-dev
2023-03-27 06:05:51 +00:00
Adam Shih
e124d5aea9
comply with VTS requirements
...
Bug: 275036679
Bug: 275034315
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Change-Id: I1c89d7662351ffae5409c3f81b4360579fdc00ae
2023-03-27 12:07:24 +08:00
Neo Yu
70749d1b96
Merge "sepolicy: allow hal_radioext_default binder call with servicemanager" into udc-dev am: 5b1689534f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22222570
Change-Id: I2d2a07056322f6971050e9299e17201b95773eaf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 03:07:31 +00:00
Neo Yu
5b1689534f
Merge "sepolicy: allow hal_radioext_default binder call with servicemanager" into udc-dev
2023-03-27 02:36:56 +00:00
Adam Shih
8538fd33da
Move pixel dumpstate to gs-common
...
Bug: 240530709
Test: adb bugreport
Change-Id: I10f98673ea507f841d9d3f33d737c4e73c1b5b19
Merged-In: I4c46a2495ea07b9e44f56c4c6be726621e0ebf65
2023-03-24 02:55:51 +00:00
neoyu
44ee5a2fb2
sepolicy: allow hal_radioext_default binder call with servicemanager
...
avc: denied { call } for comm="binder:795_2" scontext=u:r:hal_radioext_default:s0 tcontext=u:r:servicemanager:s0 tclass=binder permissive=0
Bug: 274374768
Test: verify by test rom
Change-Id: I31cfbd234756fdc41663cec766f6b3bf23063bc7
2023-03-24 02:30:44 +08:00
TreeHugger Robot
24536aa24c
Merge "Revert "Move pixel dumpstate to gs-common"" into udc-dev am: 3fae47e04b
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22215371
Change-Id: I3b6ed885d80985c85846b1ec6627c093ba94431f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-23 08:07:36 +00:00
Wilson Sung
3e68836e43
Revert "Move pixel dumpstate to gs-common"
...
Revert submission 22188471-dumpstate aidl
Reason for revert: Build break
Reverted changes: /q/submissionid:22188471-dumpstate+aidl
Bug: 274858145
Change-Id: I757111541257eecd4936572376fe42a4c866a1d6
2023-03-23 05:58:12 +00:00
Adam Shih
cad969da74
Merge "Move pixel dumpstate to gs-common" into udc-dev am: 0c17644417
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22188471
Change-Id: I58ded180038a8aa507095d31a069547b7f02efea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-23 05:52:55 +00:00
Adam Shih
ee45cfea78
Move pixel dumpstate to gs-common
...
Bug: 240530709
Test: adb bugreport
Change-Id: I4c46a2495ea07b9e44f56c4c6be726621e0ebf65
Merged-In: I4c46a2495ea07b9e44f56c4c6be726621e0ebf65
2023-03-22 05:06:27 +00:00
Nicole Lee
f23893994b
Move logger_app dontaudit items out of tracking_denials am: aa4b374120
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22173747
Change-Id: If3e54f3595eac5942175b29250ca6888471876ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-22 00:17:23 +00:00
Nicole Lee
aa4b374120
Move logger_app dontaudit items out of tracking_denials
...
Bug: 269383459
Test: Open Pixel Logger and check logs
Change-Id: Id5b89a7eeaa5b06539113d4c86c64d6022080949
2023-03-21 10:11:58 +00:00
Mahesh Kallelil
6636bd227b
Merge "Update selinux-policy for ModemService." into udc-d1-dev
2023-03-16 22:43:34 +00:00
Jayachandran C
a7ec5ac379
Merge "Allow radio to find and invoke Audio HAL for updating the network info during improved WiFi calling" into udc-dev am: 3cda1dd51b
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22067882
Change-Id: I676634d568c0de4a029dc4609ceda2c38f56fce9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-16 20:20:07 +00:00
Mahesh Kallelil
df7ece2441
Update selinux-policy for ModemService.
...
Allowing the ModemService write access to the sysfs attribute
cp_temp which is used to update the thermal zones.
Test: Verified sysfs attribute security labels
Bug: 267485434
Change-Id: I8361e53f4e6aa82e6dc78e94af71ee26c06fb2f5
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2023-03-16 05:35:51 +00:00
Jayachandran C
8d1a560bf9
Allow radio to find and invoke Audio HAL for updating the network info during improved WiFi calling
...
This CL fixes the following denials
auditd : avc: denied { find } for interface=vendor.google.whitechapel.audio.audioext::IAudioExt sid=u:r:radio:s0 pid=2676 scontext=u:r:radio:s0 tcontext=u:object_r:hal_audio_ext_hwservice:s0 tclass=hwservice_manager permissive=0
auditd : type=1400 audit(0.0:2983): avc: denied { call } for comm="binder:2617_3" scontext=u:r:radio:s0 tcontext=u:r:hal_audio_default:s0 tclass=binder permissive=0
Bug: 267802258
Test: Live network testing and verified the AudioExt HAL message
Change-Id: Iffa2bcc9b8fa56c383cb765b7cbdf1ff667376c5
2023-03-15 08:22:09 +00:00
Enzo Liao
40dce15c10
Merge "SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma." into udc-dev am: 6eb86755a6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21947242
Change-Id: Ia65c61152f4631dc9ffeb6675d05dbc562781a40
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 04:47:21 +00:00
Enzo Liao
3f905ee1d0
SSRestarDetector: modify the SELinux policy to allow access files owned by system for Zuma.
...
It needs to access a file pushed by hosts of test suites (details: http://go/pd-client-for-lab#heading=h.wtp07hbqvwgx )
Bug: 234359369
Design: http://go/pd-client-for-lab
Test: manual (http://b/271555983#comment3 )
Change-Id: Id97d9c2d07197478ab8d6fcd1e9370dc794ff7d1
2023-03-10 15:37:15 +08:00
Jasmine Cha
3e639ffa42
Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482
Change-Id: Ic05e1165722a12b41d51f4339ed817383412219f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:19:45 +00:00
Jasmine Cha
d4de162a4f
audio: move sepolicy about audio to gs-common
...
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl
Change-Id: I5f537f18b33c84f30dae349880f8d00a22883b0b
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:09:29 +08:00
Nicole Lee
bc1beba926
logger_app: allow logger_app to access vendor_usb_config_prop
...
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=397 scontext=u:r:logger_app:s0:c13,c257,c512,c768 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
Bug:270579027
Test: Enable debug port by Pixel Logger
Change-Id: I0274a25142d671b03966e56a2ffd9926683e4991
2023-03-03 12:55:29 +00:00
Kah Xuan Lim
4e270f1615
modem_svc_sit: grant modem property access
...
Log message gotten before adding the policy:
avc: denied { connectto } for comm="modem_svc_sit" path="/dev/socket/property_service" scontext=u:r:modem_svc_sit:s0 tcontext=u:r:init:s0 tclass=unix_stream_socket permissive=1
Bug: 247669574
(cherry picked from commit 77ce224141
)
Merged-In: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
Change-Id: Id5e66d94eb14c6979d3b93d54fd73634444cdea1
2023-02-20 11:04:11 +00:00
Nicole Lee
7706be6c71
logger_app: don't audit default_prop and fix errors
...
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:default_prop:s0" dev="tmpfs" ino=153 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
avc: denied { search } for name="ssrdump" dev="dm-44" ino=377 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
avc: denied { search } for name="coredump" dev="dm-44" ino=378 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_coredump_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
Bug: 264489961
Bug: 269383459
Test: Make sure no avc denied for logger_app when using Pixel Logger
(cherry picked from commit ef1d13d86d
)
Change-Id: I8999372d243286586eb53602e167fa111d39a00f
Merged-In: I8999372d243286586eb53602e167fa111d39a00f
2023-02-20 11:00:59 +00:00
neoyu
c0da946f48
Fix avc denied for hal_radioext_default
...
avc: denied { call } for comm="HwBinder:782_1" scontext=u:r:hal_radioext_default:s0 tcontext=u:r:hal_bluetooth_btlinux:s0 tclass=binder permissive=0
Bug: 269684065
Test: manual
Change-Id: I5ebf280feafabf4688718197c79bd6c4cac6e8fe
2023-02-17 08:39:47 +00:00
Jayachandran C
b85f29bb54
Merge "Revert "Add selinux rules for platform_apps to access vendor_ims_app udp socket for read/write of RTP packets.""
2023-02-16 02:59:18 +00:00
Jayachandran C
75fc4f2051
Merge "Allow radio to access IMS stack's socket for sending/receiving RTP packets and aoc_device for codec encoding/decoding"
2023-02-16 02:59:18 +00:00
Neo Yu
a5eb63a4ca
Merge "Fix avc denied for hal_radioext_default"
2023-02-16 00:34:33 +00:00
Jayachandran C
f54ab444ac
Allow radio to access IMS stack's socket for sending/receiving RTP packets and aoc_device for codec encoding/decoding
...
This fixes the follow denials
Vendor ImsStack denials
================
type=1400 audit(0.0:9): avc: denied { read write } for comm="pool-28-thread-" path="socket:[109431]" dev="sockfs" ino=109431 scontext=u:r:radio:s0 tcontext=u:r:vendor_ims_app:s0:c7,c257,c512,c768 tclass=udp_socket permissive=0 app=com.shannon.imsservice
AOC denials
===========
type=1400 audit(0.0:11): avc: denied { write } for name="acd-audio_rtp_tx" dev="tmpfs" ino=1185 scontext=u:r:radio:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=0
type=1400 audit(0.0:12): avc: denied { read } for name="acd-audio_rtp_rx" dev="tmpfs" ino=1186 scontext=u:r:radio:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=0
Bug: 259178236
Test: Manually verified on the device with AOC
Change-Id: I000c0c72d8a37ab5680caddd499977db66939bfa
2023-02-15 22:20:56 +00:00
Jayachandran C
8a51382598
Revert "Add selinux rules for platform_apps to access vendor_ims_app udp socket for read/write of RTP packets."
...
This reverts commit ebe77e31f4
.
Reason for revert: Re-worked as part of ag/21259162
Bug: 259178236
Change-Id: I0494e71339c335b2efc2f23d4087f19184cfd1b5
2023-02-15 21:31:26 +00:00