Commit graph

725 commits

Author SHA1 Message Date
Hiroshi Akiyama
ea65836d59 Merge "Update missing dump_power sepolicy" into main 2023-10-15 23:45:47 +00:00
Hiroshi Akiyama
400a9d2068 Update missing dump_power sepolicy
Bug: 304851502
Test: adb bugreport and check dumpstate_board.txt
Change-Id: I1aed85ec3c1106381a395867a6eb90c11a8a1f84
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
2023-10-14 05:02:16 +00:00
jonerlin
5883c27036 allow hal_bluetooth_btlinux write sysfs file am: 127ca27edc am: a49aa2bdf1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24947936

Change-Id: I52e9eb48b5e73a6f388a3fb446d1e402bdca4468
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-13 03:14:04 +00:00
jonerlin
a49aa2bdf1 allow hal_bluetooth_btlinux write sysfs file am: 127ca27edc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24947936

Change-Id: I183c49c5209e811166a96d2a9e2819bd29373b7c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-13 02:56:21 +00:00
Treehugger Robot
9b0ab2c62c Merge "hal_sensors_default: Add permission to AOC reset sysfs node." into main 2023-10-13 02:43:10 +00:00
Rick Chen
c31ec37715 hal_sensors_default: Add permission to AOC reset sysfs node.
[21675.099727] type=1400 audit(1697127034.684:751): avc:  denied  { write } for  comm="binder:912_1" name="reset" dev="sysfs" ino=102250 scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:sysfs_aoc_reset:s0 tclass=file permissive=0

Bug: 304681766
Test: Modify sensor HAL to trigger SSR when init.
      No avc denied log when sensor HAL access AOC reset sysfs node.
Change-Id: Iede0fa94a627c5e0d3166bec05ef7041154d8efe
Signed-off-by: Rick Chen <rickctchen@google.com>
2023-10-13 02:41:28 +00:00
jonerlin
127ca27edc allow hal_bluetooth_btlinux write sysfs file
Bug: 294747612
Test: v2/pixel-pts/release/bootstress/1200counts/suspend-resume
Change-Id: I62147f0b32156ede2a4e18e5a2bcb77fc2c91831
2023-10-13 09:00:07 +08:00
Brian Duddie
48527a1e6f Merge "Revert "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: c387226619 am: d1ddce264c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24948148

Change-Id: Ic95a0ecc1722769c2ac9ac7711ae93ea85a16ce0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-12 23:20:21 +00:00
Brian Duddie
d1ddce264c Merge "Revert "bluetooth: Allow triggering AOC reset from BT HAL"" into udc-qpr-dev am: c387226619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24948148

Change-Id: I59fbb4f03909803a422ff9a9abd17cae32eb7014
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-12 22:48:59 +00:00
Matthew Sedam
b2592218d6 Merge "Allow CHRE to access the IStats service for the zuma target" into main 2023-10-09 18:18:57 +00:00
Chia-Chi Teng
0aa787efa8 Revert "bluetooth: Allow triggering AOC reset from BT HAL"
Revert submission 24871772-bt-aoc-coredump

Reason for revert: b/300076774 root cause identified as b/299038059

Reverted changes: /q/submissionid:24871772-bt-aoc-coredump

Bug: 299038059
Change-Id: Ibd021c6b983c2eb390c268cf89f30e2e8ee54d21
2023-10-06 22:04:57 +00:00
Roy Luo
aa5218c8a7 Support metric upload in USB HAL
Grant access to stats service.
Sample error logs: avc:  denied  { find } for pid=949 uid=1000
name=android.frameworks.stats.IStats/default
scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:fwk_stats_service:s0
tclass=service_manager permissive=0

Bug: 297224564
Test: no audit log in logcat after command execution
Change-Id: I4a80e11e63ec164dff73288e93aac851ffebb696
2023-10-04 20:02:39 +00:00
Matthew Sedam
ad0075acd6 Allow CHRE to access the IStats service for the zuma target
Bug: 298459533
Test: Use stats service from chre
Change-Id: Ie4c9a24d3cd331621136c7c21989685631d87519
2023-10-02 20:52:36 +00:00
Brian Duddie
1af5314ec0 bluetooth: Allow triggering AOC reset from BT HAL am: 858f999657 am: 89d7732591
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24869257

Change-Id: I3381cfdfff17ca8c2f77fa5043775a5f80ea028e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-27 22:50:28 +00:00
Brian Duddie
89d7732591 bluetooth: Allow triggering AOC reset from BT HAL am: 858f999657
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24869257

Change-Id: I5bdeb95ad44c69d2b8cd04f12dc7cde49580084c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-27 21:45:56 +00:00
Brian Duddie
858f999657 bluetooth: Allow triggering AOC reset from BT HAL
Supports debugging and recovery from fatal errors that do not trigger
AOC SSR on their own.

Bug: 300076774
Test: trigger SSR from BT HAL
Change-Id: I795b2c1830625e2cf05a9aa63c6f7ef273b01a87
2023-09-27 00:08:19 +00:00
Sergey Volk
a1e0faee5b Allow HWC access to dp_hotplug_error_code in sysfs
When an error is detected, DisplayPort kernel driver writes hotplug error code into a sysfs file. Hardware composer reads the error code from sysfs and then needs to write 0 in there to reset the code.

Test: manual
Bug: 283461313
Change-Id: Ifadc2403d62b12b0661fd170fa6df36b6a199fc3
2023-09-21 02:56:08 +00:00
John Chang
acb925a4fe Merge "display: properties of vrr settings" into main 2023-09-18 21:38:01 +00:00
John Chang
85d45d6776 display: properties of vrr settings
Bug: 290843234
Test: verify getprop/setprop after reboot.
Change-Id: I1ff2b7069f0e6a5a9aef6ac2f6ac6d89b457dcc3
2023-09-18 14:19:11 +00:00
yixuanwang
0a4d3c2f89 Add selinux policy for chre vendor data directory
Bug: 278114604
Test: on device test
Change-Id: I33d1e73a375c86602ce632665fe96c5876347c52
2023-09-16 02:51:45 +00:00
Yixuan Wang
cb920d586f Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..." am: bd654f00d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24589942

Change-Id: Iba1c14faaf0c1e423f914ca860f83d75d5496a54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-15 18:14:40 +00:00
Yixuan Wang
adf19fcc76 Merge "Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."" into udc-qpr-dev 2023-09-15 00:23:04 +00:00
Tai Kuo
e45cb8ef52 Allow regmap debugfs for drivers probed by insmod am: 1a65e5d5e4 am: 8cf4f20ca3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24727593

Change-Id: Id56ae9157f1fb0278d9b70641818c6dcb1629b8d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-13 00:32:10 +00:00
Tai Kuo
8cf4f20ca3 Allow regmap debugfs for drivers probed by insmod am: 1a65e5d5e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24727593

Change-Id: Ia298dbfa2909cea74711f2f10b0bdca3c301a0a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-12 23:42:40 +00:00
Tai Kuo
1a65e5d5e4 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I2bd35a6bc942536505f62d4122f0de892f243802
2023-09-12 16:45:09 +08:00
Yixuan Wang
bd654f00d9 Revert "Revert "[DO NOT MERGE] Add selinux policy for chre vendo..."
Revert submission 24526613-revert-23834879-CHRE BT LOG-MHDBQNZAGV

Reason for revert: Fixed and tested with a followup cl

Reverted changes: /q/submissionid:24526613-revert-23834879-CHRE+BT+LOG-MHDBQNZAGV

Change-Id: I29866a91abfcfa380d772da447eb95344df43f8f
2023-08-29 19:17:32 +00:00
Safayat Ullah
2c7187af19 display: add persist property to vendor_display_prop am: ea09b155f2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24549050

Change-Id: If21c57942053863ff2157d88a4810a81b30a03f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 13:34:23 +00:00
Safayat Ullah
ea09b155f2 display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I60747df56c6993251bc736994da828814bcdf607
Merged-In: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 09:06:57 +00:00
Safayat Ullah
b27308445d display: add persist property to vendor_display_prop
Bug: 290162920
Test: no avc denied log
Change-Id: I2497960fbc76e56dd3a9c69d3fe274f0685744f8
2023-08-29 08:01:45 +00:00
Sebastian Pickl
b5491c6650 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636 am: 7ee5ae18de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: If8ca0317f923da98e74ff8642b97f83894206b2f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 11:33:41 +00:00
Sebastian Pickl
7ee5ae18de Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..." am: 84f1209636
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24526611

Change-Id: I3e4c175289017c75c26df4029421b61ad4efcfbe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-24 10:51:24 +00:00
Sebastian Pickl
ae9ab242e8 Merge "Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."" into udc-qpr-dev 2023-08-24 10:06:57 +00:00
Sebastian Pickl
84f1209636 Revert "[DO NOT MERGE] Add selinux policy for chre vendor data d..."
Revert submission 23834879-CHRE BT LOG

Reason for revert: fixes broken test b/297255998 verified by go/abtd: https://android-build.googleplex.com/builds/abtd/run/L30000000962735539
Bug:297255998

Reverted changes: /q/submissionid:23834879-CHRE+BT+LOG

Change-Id: I56b800260303834ed76dedf354b5a32af00b3684
2023-08-24 09:47:19 +00:00
Yixuan Wang
2058641a14 [DO NOT MERGE] Add selinux policy for chre vendor data directory am: 22d9b28316
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23834879

Change-Id: Id8058dbdf765871ba8e762ed10dd1af309642351
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-23 19:52:24 +00:00
Yixuan Wang
0fcc802265 Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev 2023-08-23 19:29:45 +00:00
Kris Chen
7e2cb4f5f6 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac am: 12c2d23a4b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I64a4f98723a7d5425062c5144402d60af9a55661
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:44:46 +00:00
Kris Chen
12c2d23a4b Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f am: 4a49dbceac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: Ibcac24727053aac68e937156421b16b9ab892200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 07:04:41 +00:00
Kris Chen
4a49dbceac Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I9f99fc149fc832a44d45d09b563ba8bc913a12d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:39:06 +00:00
Kris Chen
7f3e2b9212 Allow hal_power_default to access sysfs_scsi_devices_0000 am: c9d21c380f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24458368

Change-Id: I6a6014a9efe1d543b559bc9142766d0765468339
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-21 06:33:12 +00:00
Seungjae Yoo
34eb573ac9 Label dtbo partition as dtbo_block_device am: 8256e72c4a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24438745

Change-Id: Ia4dc306e5e6fdb008c890b538804fba528319806
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-18 09:28:08 +00:00
Renato Grottesi
fa4f421d41 Merge "Cleanup unused ArmNN settings." into main 2023-08-18 04:31:47 +00:00
Seungjae Yoo
8256e72c4a Label dtbo partition as dtbo_block_device
Bug: 291191362
Test: m

Merged-In: Iccca8de440cad7e9cd12015e0271262a217c457b
Change-Id: Iccca8de440cad7e9cd12015e0271262a217c457b
2023-08-18 00:38:06 +00:00
Seungjae Yoo
7961d4ee51 Merge "Label dtbo partition as dtbo_block_device" into main 2023-08-17 22:32:36 +00:00
Kris Chen
c9d21c380f Allow hal_power_default to access sysfs_scsi_devices_0000
Fix the following avc denial:
avc:  denied  { write } for  name="clkgate_enable" dev="sysfs"
ino=69304 scontext=u:r:hal_power_default:s0 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0

Bug: 290709897
Test: enroll fingerprint
Change-Id: Ib153087839d59e1839ceed4373a9be6f42e89619
2023-08-17 12:59:19 +00:00
Renato Grottesi
96f1f214a2 Cleanup unused ArmNN settings.
Test: pre-submit
Bug: 294463729
Change-Id: Ic417154724c4ddc06925ee2de1bd419dddfa1413
2023-08-17 09:03:35 +00:00
Ilya Matyukhin
ee710b08c1 Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev am: 013ec5ce54 am: 41056381db
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24343631

Change-Id: I43c243eff3bfbf14828f29f13789b1a3eb9f38c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-16 22:10:07 +00:00
Ilya Matyukhin
41056381db Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev am: 013ec5ce54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24343631

Change-Id: Icd84167a866d6bf8cf7fa2c0661320882acfaf6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-16 21:26:07 +00:00
Ilya Matyukhin
013ec5ce54 Merge "zuma: Add sysfs_faceauth_gcma_heap type" into udc-qpr-dev 2023-08-16 20:38:34 +00:00
Seungjae Yoo
3773ca269e Label dtbo partition as dtbo_block_device
Bug: 291191362
Test: m

Change-Id: Iccca8de440cad7e9cd12015e0271262a217c457b
2023-08-16 11:16:37 +09:00
Wilson Sung
33db592c7a Supress kernel avc log before SELinux initialized am: 746bd9ad3c am: eb6368402e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/24393095

Change-Id: If9ce34cb0f0b44998215f20d1be88578f0e8f56b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 03:26:28 +00:00