Commit graph

794 commits

Author SHA1 Message Date
Wilson Sung
028c3dd417 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272628174
Change-Id: Ief58f990c70fc7a9a6fa1f18ce22c1c5847acaf9
2023-03-10 10:56:44 +08:00
Jasmine Cha
3e639ffa42 Merge "audio: move sepolicy about audio to gs-common" into udc-dev am: 6431ec8cfa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912482

Change-Id: Ic05e1165722a12b41d51f4339ed817383412219f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-10 02:19:45 +00:00
Jasmine Cha
6431ec8cfa Merge "audio: move sepolicy about audio to gs-common" into udc-dev 2023-03-10 02:06:05 +00:00
Wilson Sung
aa90037844 Add insmod-sh policy
Fix: 260366066
Change-Id: I0874c1f476b47a9ad3cee344986404958c96fd25
2023-03-10 02:04:36 +08:00
Darren Hsu
055b52e584 Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev am: 3867f2f21f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21912561

Change-Id: I2e1cde774f763e3f30b0e50484824483d5319c08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 07:54:54 +00:00
Darren Hsu
3867f2f21f Merge "sepolicy: label more paths for sysfs_odpm" into udc-dev 2023-03-09 07:20:30 +00:00
Wilson Sung
2492786d15 Merge "Add system_ui required policy" into udc-d1-dev 2023-03-09 07:05:32 +00:00
Wilson Sung
8c535e410a Add system_ui required policy
Bug: 264266705
Bug: 268572197
Bug: 269813282
Change-Id: I8d782a5879dd531c29328517f67245913808ae93
2023-03-09 12:57:39 +08:00
KRIS CHEN
4309d80318 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev am: 92c67c8422
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21896646

Change-Id: I232a8e1d378731c0a42d42b9450fee002efd15bb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-09 04:21:05 +00:00
KRIS CHEN
92c67c8422 Merge "Allow fingerprint hal to access display hibernation node" into udc-dev 2023-03-09 03:53:46 +00:00
Jasmine Cha
d4de162a4f audio: move sepolicy about audio to gs-common
Bug: 259161622
Test: build pass and check with audio ext hidl/aidl

Change-Id: I5f537f18b33c84f30dae349880f8d00a22883b0b
Signed-off-by: Jasmine Cha <chajasmine@google.com>
2023-03-09 10:09:29 +08:00
Darren Hsu
f3e948a640 sepolicy: label more paths for sysfs_odpm
Bug: 272164439
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: Iec1be5189d21ff6b2bdfe5056b526f01dc2b35e4
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-09 08:35:42 +08:00
Dai Li
f2200cdfa1 dma-heap: add dsp heap
Add dsp heap to zuma

Bug: 258813006
Change-Id: I953d1abb7cee15d041db1535df79c91cd25830f7
2023-03-08 20:43:53 +00:00
Kris Chen
cc2458e456 Allow fingerprint hal to access display hibernation node
Fix the following avc denial:
avc: denied { write } for name="hibernation" dev="sysfs" ino=75339
scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs:s0
tclass=file permissive=0

Bug: 256947811
Bug: 251239489
Bug: 267271482
Test: Perform udfps osc compensation.
Change-Id: I2cfb1353770734a19e7fcf1a10eb2fc7bf84a4f5
2023-03-08 09:10:24 +00:00
Chih Wei Chang
455363e7c0 Merge "Revert "Add system_ui required policy"" into udc-d1-dev 2023-03-08 08:17:46 +00:00
Chih Wei Chang
9966805569 Revert "Add system_ui required policy"
This reverts commit 5488482211.

Bug: 272204013

Reason for revert: DroidMonitor-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?branch=git_udc-d1-dev&target=aosp_shiba-userdebug&lkgb=9707521&lkbb=9708227&fkbb=9708227, bug 272204013

Change-Id: Ia2d74374325d594d9dbd1e5ba8b1510f8d432e4d
2023-03-08 08:11:30 +00:00
Wilson Sung
ee80374f9d Merge "Add system_ui required policy" into udc-d1-dev 2023-03-08 06:40:42 +00:00
Yang Qi
c8d64fb72f Add CccDkTimeSyncService for Digital Key Support for Zuma am: d8c17a3814
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21809919

Change-Id: I456973e22f9297a3d39805703f7fcb52be2f791e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-08 05:50:25 +00:00
Wilson Sung
a5be4a940e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272166423
Bug: 272166664
Bug: 272166847
Bug: 272166722
Bug: 272166827
Bug: 272166723
Test: scanBugreport
Bug: 272166423
Bug: 267714573
Bug: 272166771
Bug: 272166847
Bug: 272166722
Bug: 272166827
Bug: 272166723
Bug: 272166737
Test: scanAvcDeniedLogRightAfterReboot
Bug: 272166723
Bug: 272166787
Bug: 272166423
Bug: 267714573
Bug: 272166847
Bug: 272166987
Bug: 272166827
Change-Id: If02d479d3606b63bd43bb94c93b2108c4fafe96d
2023-03-08 11:19:02 +08:00
Wilson Sung
5488482211 Add system_ui required policy
Bug: 264266705
Bug: 268572197
Bug: 269813282
Change-Id: I6457f4a675d32578188c01ae581442300ac56a5b
2023-03-08 10:58:39 +08:00
Shashank Sharma
3d765451c5 Remove firmware as same_process_hal_file
Bug: 260522245
Bug: 262794429

Change-Id: I7d49ee7c76fbf2cdf87a2a7de4a406c356f50444
2023-03-07 05:01:16 +00:00
Yang Qi
d8c17a3814 Add CccDkTimeSyncService for Digital Key Support for Zuma
Test: Build and Run
Bug: 270511447
Merged-In: I0195bfe5f8eed70556891ddfeae81c486373ddbb
Change-Id: I0195bfe5f8eed70556891ddfeae81c486373ddbb
2023-03-07 02:52:34 +00:00
Adam Shih
d1bce36c49 Merge "move camera dump to gs-common" into udc-dev am: 5dd0fffa9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21784301

Change-Id: I40cce627880f57be080685502693c0d73dc53cac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-07 00:04:42 +00:00
Adam Shih
5dd0fffa9a Merge "move camera dump to gs-common" into udc-dev 2023-03-06 23:29:45 +00:00
Adam Shih
8e2e4dc222 Move common display dump to gs-common am: 51bd259bbf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21644566

Change-Id: I31f0efd65637b205164c9ee767f23cd24893cd09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-06 23:11:09 +00:00
Adam Shih
51bd259bbf Move common display dump to gs-common
Bug: 269212897
Test: adb bugreport
Change-Id: I71ad4e2e08ba19c36dc633732ce39e8086a94d6e
2023-03-06 06:33:53 +00:00
Adam Shih
7b84f2fc56 move camera dump to gs-common
Bug: 240530709
Test: adb bugreport
Create empty files starting with the following prefix
/data/vendor/camera/profiler/session-ended-
/data/vendor/camera/profiler/high-drop-rate-
/data/vendor/camera/profiler/watchdog-
/data/vendor/camera/profiler/camera-ended-
and do adb bugreport and make sure they end up in dumpstate_board.bin

Change-Id: I90e6d5142e7d512dafa6b8712d7fb252327359a5
2023-03-06 02:34:48 +00:00
TreeHugger Robot
26e0b7b7fc Merge "logger_app: allow logger_app to access vendor_usb_config_prop" into udc-d1-dev 2023-03-06 01:49:33 +00:00
Jeremy DeHaan
f33a422c17 Allow HWC to access panel model
Bug: 217472351
Change-Id: I2831eb402d15ceb0962325ce827a1ca3cca00109
Signed-off-by: Jeremy DeHaan <jdehaan@google.com>
2023-03-03 13:48:53 -08:00
TreeHugger Robot
8e2035cc18 Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev am: 4eab0326df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552481

Change-Id: I9f39b65bc479a4fc0541404062330137a9fcb63c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 19:22:05 +00:00
Donnie Pollitz
8958b2e84b sepolicy: Fix hal_confirmationui_default avc denials am: e31ad0b306
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21504841

Change-Id: I55b973823df7b0ad935ab38c0c22c63c0c1674cd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-03 17:27:10 +00:00
Jörg Wagner
d8c6712f5b Update Mali DDK to r40 : Additional SELinux settings
Expose DDK's dynamic configuration options through the Android Sysprop
interface, following recommendations from Arm's Android Integration
Manual.

Bug: 261718474

(cherry picked from commit 6834d6f59f)
Merged-In: I785106b6d2d05e21bf60fcd6da3d716b32e1bc1d
Change-Id: I0469e2f24abe7a9458305d5752ae655cf4f42547
2023-03-03 15:23:39 +00:00
Nicole Lee
bc1beba926 logger_app: allow logger_app to access vendor_usb_config_prop
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=397 scontext=u:r:logger_app:s0:c13,c257,c512,c768 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0 app=com.android.pixellogger

Bug:270579027
Test: Enable debug port by Pixel Logger
Change-Id: I0274a25142d671b03966e56a2ffd9926683e4991
2023-03-03 12:55:29 +00:00
TreeHugger Robot
4eab0326df Merge "Allow hal_thermal_default to read iio/odpm sysfs nodes" into udc-dev 2023-03-03 12:01:40 +00:00
Dinesh Yadav
85829f2265 Merge "Make gxp_device an mlstrustedobject" into udc-d1-dev 2023-03-03 03:12:15 +00:00
Dinesh Yadav
01c5409eb8 Make gxp_device an mlstrustedobject
This is needed as google_camera_app needs write access to gxp.

Test: Tested with private build "P51261040" with Tot google3 gca-dogfood app & found no selinux violations.

Bug: 264139000
Change-Id: Ic1a262cc40578ebd2305efe851e54cf857bd02c1
2023-03-02 15:41:37 +00:00
Ernie Hsu
fbbc198801 Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev am: 899ad9c1ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21553180

Change-Id: I90171c56ccbb152a1cf7fbca77bb1d56311bebaa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 09:19:35 +00:00
Donnie Pollitz
e31ad0b306 sepolicy: Fix hal_confirmationui_default avc denials
* Allow for dumpstate

Bug: 261933368
Bug: 264489634
Test: Ran com.google.android.selinux.pts.SELinuxTest#scanBugreport
Change-Id: Id70d2a920172e649e4497f4ea1a4ecad33963edc
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-02 09:08:16 +00:00
Ernie Hsu
899ad9c1ab Merge "move mediacodec_samsung build config and sepolicy to gs-common" into udc-dev 2023-03-02 08:38:54 +00:00
Hiroshi Akiyama
c0587fbf36 Update sepolicy for BCL IRQ durations to dumpstate
Bug: 269752322
Test: adb bugreport
Change-Id: Icd524bd32ed41c3de72f0e1b13428d76e871d203
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
Merged-In: Icd524bd32ed41c3de72f0e1b13428d76e871d203
2023-03-02 06:03:23 +00:00
Wilson Sung
8fa2055112 Add sensor boot-to-home required policy am: d0105abe01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21552482

Change-Id: I95c23468276681b97969e2fe6376e914aed2fe1f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:49 +00:00
Wilson Sung
d0105abe01 Add sensor boot-to-home required policy
Test: boot-to-home
Fix: 261105336
Change-Id: I772ff7a294cc5d2448361c164d4e671a41c92c8d
2023-03-02 02:39:15 +00:00
Wilson Sung
fc8f4f8f24 Allow hal_thermal_default to read iio/odpm sysfs nodes
Bug: 260366399
Bug: 261651187
Bug: 264204525
Change-Id: I7358b7740f6c30bd7b05e29e931a4c11226c6253
2023-03-01 16:21:33 +00:00
Ernie Hsu
4d90089d25 move mediacodec_samsung build config and sepolicy to gs-common
Bug: 263444717
Test: build pass, camera record, youtube
Change-Id: I8fa4d79495b3971429b977a63aed811ef8d62ddb
2023-03-01 10:12:22 +00:00
Richard Chang
92ec39e932 Merge "sepolicy: update init.te for zram device" into udc-dev am: 3c52a9ab3b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21578379

Change-Id: I066aaa3efd492aea906ac778be9ff8c3e696850d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:53 +00:00
Armelle Laine
39a9021703 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev am: d38c507ef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21617065

Change-Id: I7774f4fba285cd3a8b65c9c78245da5ee39d9c61
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 04:40:29 +00:00
Richard Chang
3c52a9ab3b Merge "sepolicy: update init.te for zram device" into udc-dev 2023-03-01 04:28:58 +00:00
Armelle Laine
d38c507ef6 Merge "Define selinux properties for /dev/block/by-name/trusty_persist" into udc-dev 2023-03-01 03:41:09 +00:00
Richard Chang
ee8c7c2df2 sepolicy: update init.te for zram device
Bug: 269221861
Bug: 270633329
Test: Boot
Change-Id: I050e9a72006dcd0b71ba1232e38e5f96bce4c967
2023-03-01 02:04:24 +00:00
TreeHugger Robot
81390587ae Merge "Update bug_map" into udc-dev am: 627e6c1648
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21649588

Change-Id: I6c9b8ad61f3ebc5cfab067016b0029b111bc4625
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-01 00:54:48 +00:00