Treehugger Robot
a8fe91bc3c
Merge "Remove hal_uwb_default bug from bug_map" into udc-d1-dev
2023-04-21 03:08:00 +00:00
Wilson Sung
dc75da30a1
Revert^2 "Enforce priv_app"
...
This reverts commit 61a95fc71a
.
Fix: 260522282
Change-Id: I0d5dd994d3acacfee854ae27669358cfc2c249fc
2023-04-20 00:14:18 +08:00
Rex Lin
814652dc6d
Remove hal_uwb_default bug from bug_map
...
SELinux errors are fixed and hence removing from bug map
Bug: 273639365
Test: Build and boot on device
Change-Id: I3a1ad3066840b507553b9365239673f6126b8ec6
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-04-19 14:54:11 +08:00
Alan Chen
c1f8b7a872
Merge "Remove dontaudit for hal_radioext_default to service_manager." into udc-d1-dev
2023-04-19 03:04:57 +00:00
Treehugger Robot
16f461a2cf
Merge "Enforce sepolicy for camera HAL." into udc-d1-dev
2023-04-18 23:18:00 +00:00
Dave Mankoff
633f19376e
Merge "Give SystemUI access to necessary selinux properties." into udc-d1-dev
2023-04-18 17:50:42 +00:00
Jonglin Lee
8da235e022
Merge "Revert "Enforce priv_app"" into udc-d1-dev
2023-04-18 17:50:13 +00:00
Jonglin Lee
61a95fc71a
Revert "Enforce priv_app"
...
This reverts commit af0ad04c3c
.
Reason for revert: RescueParty crash due to com.shannon.rcsservice crash
Bug: 278735899
Change-Id: I5bf91b077c23c63de728657bd9adb5623b708d95
2023-04-18 17:41:27 +00:00
Alan Chen
63f54f0a3a
Remove dontaudit for hal_radioext_default to service_manager.
...
The fix has been merged in the topic of ag/21956466 so this dontaudit line can be removed.
Test: manual
Bug: b/275646098
Change-Id: I95c25ffc926e48e589b7636beca1bef9583861d0
2023-04-18 17:47:09 +08:00
Krzysztof Kosiński
3f0d2fc09d
Enforce sepolicy for camera HAL.
...
Bug: 264489778
Test: GCA smoke test on Zuma device
Change-Id: Icaa7c94ab264d496840d33d970e5a87123b31c36
2023-04-18 09:02:32 +00:00
Treehugger Robot
4d7b687f9d
Merge "Enforce priv_app" into udc-d1-dev
2023-04-17 16:56:56 +00:00
Dave Mankoff
78b9dcdb69
Give SystemUI access to necessary selinux properties.
...
Other errors mentioned in the bugs are already absent.
Fixes: 269964574
Fixes: 272628396
Fixes: 272628174
Test: built and flash device. No selinux errors printed.
Change-Id: Ic285b1f5a2ce6973899011a7c6a596e807c3e933
2023-04-17 14:28:59 +00:00
Treehugger Robot
9ea22dde19
Merge "Enforce servicemanager" into udc-d1-dev
2023-04-14 03:53:11 +00:00
Wilson Sung
af0ad04c3c
Enforce priv_app
...
Fix: 260366281
Fix: 260522282
Fix: 260768358
Fix: 260922442
Fix: 263185432
Fix: 264490074
Fix: 268572216
Change-Id: I2efbb1971c09506a7b1e0e5e0e3d22eda91018c1
2023-04-14 03:34:46 +00:00
TreeHugger Robot
89d4a4df13
Merge "Suppress bootanim behavior meant for Android Wear devices" into udc-d1-dev
2023-04-14 03:19:53 +00:00
Treehugger Robot
2ac0374b22
Merge changes Ie20be0af,Id9a80c47 into udc-d1-dev
...
* changes:
Enforce rebalance_interrupts_vendor
Enforce hwservicemanager
2023-04-14 03:18:10 +00:00
Yixuan Wang
1095231e38
Add hal_contexthub_default to zuma sepolicy; Remove dontaudit rules for
...
chre
[ 7.760870] type=1400 audit(1669944054.440:61): avc: denied { write } for comm="android.hardwar" name="chre" dev="tmpfs" ino=1099 scontext=u:r:hal_contexthub_default:s0 tcontext=u:object_r:chre_socket:s0 tclass=sock_file permissive=1
[ 12.519414] type=1400 audit(1669944059.196:138): avc: denied {connectto } for comm="android.hardwar" path="/dev/socket/chre"scontext=u:r:hal_contexthub_default:s0 tcontext=u:r:chre:s0 tclass=unix_stream_socket permissive=1
Bug: 264489794
Bug: 261105224
Test: atest scanAvcDeniedLogRightAfterReboot
Change-Id: I7bf13913188deedc987f82e54626a18357ab84c5
2023-04-13 06:43:41 +00:00
Wilson Sung
3df3008917
Suppress bootanim behavior meant for Android Wear devices
...
Fix: 260522279
Test: boot-to-home and no bootanim avc error
Change-Id: I29d4168720887bc2f90d5f7ad20367887f9cae51
2023-04-13 00:00:38 +00:00
Wilson Sung
5468e420e3
Enforce rebalance_interrupts_vendor
...
Fix: 264489565
Test: boot-to-home
Change-Id: Ie20be0afe1a95b8cb512b57019539eb52948a155
2023-04-12 22:58:13 +08:00
Wilson Sung
90f838f16f
Enforce hwservicemanager
...
Test: boot-to-home and no avc error
Fix: 264489781
Change-Id: Id9a80c478a2eae8472023f3bbcc514f30f5bfbab
2023-04-12 22:32:46 +08:00
Wilson Sung
527f215d20
Enforce servicemanager
...
Fix: 263429985
Fix: 264489962
Test: boot-to-home, no avc error
Change-Id: Ib3b0916bdbd09638f5b7b34f2d214690eed314ab
2023-04-12 22:14:16 +08:00
Wilson Sung
c2eedff70c
Add recovery related policy
...
Fix: 275143841
Fix: 264490092
Test: adb sideload and no avc error
Change-Id: I52003c9417560a6c5dab815a6929681710f0b0a4
2023-04-12 03:46:54 +08:00
Adam Shih
e188582ba8
remove obsolete entries
...
Bug: 264483390
Bug: 272166771
Bug: 264482983
Bug: 264600086
Bug: 264482983
Bug: 273638940
Test: adb bugreport
Change-Id: Ia89c409a20e6a4514c57389f82c57d8c265f1e81
2023-04-11 11:23:17 +08:00
Adam Shih
e5e6273048
enforce gmscore_app
...
Bug: 259302023
Test: boot with no relevant errors
Change-Id: I61cb95224096dbc999bc3c8051a4e4c6ad700522
2023-04-10 11:13:21 +08:00
Treehugger Robot
8da223020e
Merge "Revert "Revert "Enforce system ui app""" into udc-d1-dev
2023-04-07 10:04:20 +00:00
Gina Ko
bb27434f22
Revert "Revert "Enforce system ui app""
...
This reverts commit eeeae0265a
.
Reason for revert: b/274366326 was fixed
Change-Id: I9d9c4f4dd831aa80109cc53790f6b6491133fb42
2023-04-07 08:46:00 +00:00
Wilson Sung
f2d0dbb66a
update error on ROM 9900526
...
Bug: 277155496
Bug: 277300017
Bug: 277300125
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I2a2f230589695b0240abb26909c94fd4cf2420bf
2023-04-07 14:43:36 +08:00
Dinesh Yadav
d9a75c1639
Merge "Allow google_camera_app to access edgetpu" into udc-d1-dev
2023-04-06 02:34:35 +00:00
Sayanna Chandula
387145ed85
Remove hal_thermal_default bug from bug_map
...
SELinux errors are fixed and hence removing from bug map
Bug: 272166987
Test: Build and boot on device
Change-Id: Ic0d314486a2ed6fbc1c4497b122827b17f5b9022
Signed-off-by: Sayanna Chandula <sayanna@google.com>
2023-04-05 22:26:40 +00:00
Dinesh Yadav
478b11708f
Allow google_camera_app to access edgetpu
...
These permissions are needed by GCA-release & GCA-dogfood to access
edgetpu.
Bug: 264490031
Change-Id: Idd9dff906c86f9e83f1dc67698c23387e174d99c
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-04-04 06:11:47 +00:00
Donnie Pollitz
885a790f2d
Add logd selinux allow permissions
...
Bug: 261105354
Bug: 264489639
Test: Ran atest SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I377dbb3bbdecd6780c1bdfb3aab53ee3c754c163
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-29 09:24:47 +02:00
Wilson Sung
5227dfe6ab
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 275646098
Test: scanBugreport
Bug: 275646003
Test: scanAvcDeniedLogRightAfterReboot
Bug: 275645636
Change-Id: Iedd660e3937792d5ac58f384605300b39f6dfcb0
2023-03-29 12:17:48 +08:00
Gina Ko
5821d671f3
Merge "Allow systemui to find cameraserver_service" into udc-d1-dev
2023-03-27 05:32:14 +00:00
Neo Yu
58ff635b67
Remove the bug of hal_radioext_default because the fix is merged.
...
Bug: 274374768
Test: verify by test rom
Change-Id: Ia9665e5223997cf498f9320dfd0b1dbdacaae0b2
2023-03-27 11:08:25 +08:00
Gina Ko
ce85639700
Allow systemui to find cameraserver_service
...
avc: denied { find } for pid=2435 uid=10235 name=media.camera
scontext=u:r:systemui_app:s0:c235,c256,c512,c768
tcontext=u:object_r:cameraserver_service:s0 tclass=service_manager permissive=0
Bug: 272628174
Bug: 269964574
Bug: 274734888
Test: Manual. Able to turn on/off flashlight from QS.
Change-Id: Icedf70b06bd06eb5b819a00c9157b4f475e9a126
2023-03-25 00:18:23 -07:00
TreeHugger Robot
b5a5ffb5e7
Merge "Update SELinux error" into udc-d1-dev
2023-03-24 05:07:42 +00:00
Darren Hsu
2965ba405c
sepolicy: remove power stats from bug map
...
Bug: 272166847
Test: N/A
Change-Id: If920d18418f87f14a1826dbe061cef4632a9646f
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-24 11:43:42 +08:00
Wilson Sung
599f4f5382
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 275001641
Test: scanBugreport
Bug: 268566481
Test: scanAvcDeniedLogRightAfterReboot
Bug: 268566481
Change-Id: I5a7ea66483985b6ca99162666d155fef69d65360
2023-03-24 11:11:17 +08:00
Darren Hsu
128550da69
Merge "Revert "Enforce system ui app"" into udc-d1-dev
2023-03-24 00:48:36 +00:00
Dave Mankoff
eeeae0265a
Revert "Enforce system ui app"
...
This reverts commit ba953cdb9a
.
Reason for revert: http://b/274366326#comment22 . We can check this back in once we know what's going on.
Bug: 274366326
Bug: 264266705
Change-Id: I879cdec377e71af9142c82078bd3c022295c98c5
2023-03-23 19:44:22 +00:00
Darren Hsu
8e028f0a03
sepolicy: label odpm paths for system suspend
...
Bug: 272166423
Test: run singleCommand pts -m PtsSELinuxTestCases
Change-Id: I0295cc09cd8eb46b19edcec0d74440e497440423
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-23 14:13:43 +08:00
TreeHugger Robot
0b1499354d
Merge "Enforce bootdevice_sysdev" into udc-d1-dev
2023-03-23 03:36:47 +00:00
TreeHugger Robot
75b82f7092
Merge "Enforce systesm_app" into udc-d1-dev
2023-03-23 03:32:48 +00:00
TreeHugger Robot
a8dfe1fd3c
Merge "Update SELinux error" into udc-d1-dev
2023-03-23 03:27:12 +00:00
Welly Hsu
e0adad9eb0
Remove euiccpixel_app dontaudit from gmscore_app am: a133586e4e
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22188469
Change-Id: I48f0e1eb633c44a4c6445c6423d10e500be6f6c7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-22 14:41:23 +00:00
Wilson Sung
6bf3029916
Enforce systesm_app
...
Fix: 260768379
Fix: 260922048
Fix: 264490076
Test: boot-to-home, no related avc error
Change-Id: If9ead09340f5d810ec549f4c83015f3301f1113c
2023-03-22 16:01:09 +08:00
Wilson Sung
a1739828f2
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 274727372
Bug: 274727542
Test: scanBugreport
Bug: 274727542
Bug: 268566481
Test: scanAvcDeniedLogRightAfterReboot
Bug: 274727542
Bug: 268566481
Change-Id: Ie846f2f7146e52c4e094d9fd7cfa1fa68e3e21df
2023-03-22 15:38:52 +08:00
Wilson Sung
503ae703df
Enforce bootdevice_sysdev
...
Fix: 264489743
Test: boot-to-home and no avc errors
Change-Id: I14648c8d7b1b334c3d02971ffbf20b1f9b5a9354
2023-03-22 15:35:45 +08:00
TreeHugger Robot
a112b65748
Merge "[SELinux] remove uwb remaining tracking denials" into udc-d1-dev
2023-03-22 05:30:57 +00:00
Welly Hsu
a133586e4e
Remove euiccpixel_app dontaudit from gmscore_app
...
bug: 265383359
Change-Id: I6ee7d37187725408e0f443a40affe4c4e50dac91
2023-03-22 13:27:32 +08:00