Commit graph

432 commits

Author SHA1 Message Date
Donnie Pollitz
4ce51ebfba Merge "Removing audit for system_suspend tee" into udc-d1-dev 2023-03-21 07:55:13 +00:00
Robert Lee
78603ddb7e Allow regmap debugfs permission
auditd  : type=1400 audit(0.0:7): avc: denied { search } for comm="kworker/u18:1" name="regmap" dev="debugfs" ino=1049 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0 tclass=dir permissive=0

Bug: 273891639
Test: builds
Change-Id: I9700d34e4d8a9d96d904fe5119a8bf4601bf8ea6
Signed-off-by: Robert Lee <lerobert@google.com>
2023-03-21 14:17:00 +08:00
Wilson Sung
aa45dde84e Allow systemui find radio_service
avc:  denied  { find } for pid=1810 uid=10231 name=phone scontext=u:r:systemui_app:s0:c231,c256,c512,c768 tcontext=u:object_r:radio_service:s0 tclass=service_manager permissive=0

Bug: 272628174
Bug: 272628396
Bug: 273674238
Test: boot-to-home and sim icon showed up
Change-Id: Ia7f84f53f131d868d356fd6d358188748c723757
2023-03-21 02:13:46 +00:00
Donnie Pollitz
8034369bdd Removing audit for system_suspend tee
Background:
* wakelock_use(tee) was added in previous CL: http://go/ag/21082565

Bug: 263305203
Test: Ran SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I6e8a6796ef5a7156b89ba89c74430f368727e2b8
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-20 11:26:10 +01:00
Darren Hsu
0198a5224a dumpstate: Suppress avc denial for power stats
Bug: 273639264
Test: presubmit test
Change-Id: I0b1d8b7516dc9bdfae6b8bca644b6ab52b971615
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-20 15:09:41 +08:00
TreeHugger Robot
d5ec3f993f Merge "Update SELinux error" into udc-d1-dev 2023-03-20 06:34:25 +00:00
TreeHugger Robot
155e0a8f36 Merge "Remove insmod obsolete denials" into udc-d1-dev 2023-03-20 05:25:02 +00:00
Welly Hsu
a8df97fe32 Move euiccpixel_app dontaudit items out of tracking_denials am: 97b397fc5e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22133463

Change-Id: I1e3fdf46b8d29354b2b231457edd9b2e90126474
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-20 04:30:27 +00:00
Wilson Sung
f19431da02 Remove insmod obsolete denials
Fix: 260522378
Fix: 272166723
Change-Id: I70956498f66643d0abc2496d3bdcd140e7ab8f7e
2023-03-20 12:07:21 +08:00
Wilson Sung
2eed10acc4 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 274374768
Bug: 274374722
Test: scanBugreport
Bug: 274374769
Bug: 274374768
Bug: 274374992
Bug: 274374722
Bug: 268566481
Bug: 273639264
Test: scanAvcDeniedLogRightAfterReboot
Bug: 274374768
Bug: 274374722
Bug: 268566481
Change-Id: I4ebac8c48937557b8d8544ecfe4da3ac71ecf64e
2023-03-20 12:05:59 +08:00
Welly Hsu
97b397fc5e Move euiccpixel_app dontaudit items out of tracking_denials
bug: 265286368
bug: 269218505
Change-Id: I7dec7ad23ee48cf719d6e7442e60ddcc13c02a8f
2023-03-20 10:13:05 +08:00
TreeHugger Robot
14c05d48e9 Merge "[SELinux] remove hal_uwb_default tracking denials" into udc-d1-dev 2023-03-20 01:41:49 +00:00
Donnie Pollitz
e8682690b2 Merge "Remove hal_bootctl_default audits" into udc-d1-dev 2023-03-16 12:03:04 +00:00
Rex Lin
a41dd62c1b [SELinux] remove hal_uwb_default tracking denials
Bug: 267260951
Bug: 264489750
Bug: 273639365
Test: http://ab/I19700010140844408
Change-Id: Ife918a080a4b0c716a46c78730965b5d7eb3f757
Signed-off-by: Rex Lin <rexcylin@google.com>
2023-03-16 14:51:12 +08:00
Ken Yang
7c2b9b482e Merge "SELinux: Remove charger_vendor.te" into udc-dev am: d9d0c0e471
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22099358

Change-Id: If63f0cc156d98db3ec2eb5ca4749a60e0b76a32c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-16 03:54:38 +00:00
Wilson Sung
1efd7ed479 Merge "Remove obsolete denials" into udc-d1-dev 2023-03-16 03:25:49 +00:00
Wilson Sung
7eaf780e42 Remove obsolete denials
Bug: 261933310
Test: take the bugreport and no incidentd avc error
Change-Id: I84274ed4c3b8c3d373a353f879cd7001b26c1703
2023-03-16 03:25:22 +00:00
Ken Yang
d9d0c0e471 Merge "SELinux: Remove charger_vendor.te" into udc-dev 2023-03-16 03:11:31 +00:00
TreeHugger Robot
320064782b Merge changes I7b641636,Iecbf6ff7 into udc-d1-dev
* changes:
  usb: remove bug number in bug_map
  usb: allow hal_usb_gadget_impl sysfs_batteryinfo permission
2023-03-16 03:07:04 +00:00
Kris Chen
b8419230f2 enforce trusty_apploader am: b2f238ff01
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22096222

Change-Id: I8f4e7f64b44b4c98a3ba8f75cd254f87548325da
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-16 02:41:47 +00:00
Kris Chen
b2f238ff01 enforce trusty_apploader
Bug: 264489569
Test: Boot
Change-Id: I75f73d76f535a5755a164725c606872561461487
2023-03-16 02:06:43 +00:00
Neo Yu
c3675e5a3d Merge "remove tracking_denials for hal_radioext_default.te" into udc-dev am: ba6c42df00
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22096224

Change-Id: Ib4ef07b70d69f11f1389da85176d10d791ef5929
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-16 01:26:55 +00:00
Tom Huang
a926b7b0f0 Merge "BT: remove tracking denials hal_bluetooth_btlinux" into udc-dev am: c200250bfb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22085790

Change-Id: Id18125fdfeff9c271c7b0f9a67463b4da103367f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-16 01:26:39 +00:00
Neo Yu
ba6c42df00 Merge "remove tracking_denials for hal_radioext_default.te" into udc-dev 2023-03-16 01:25:37 +00:00
Tom Huang
c200250bfb Merge "BT: remove tracking denials hal_bluetooth_btlinux" into udc-dev 2023-03-16 00:56:49 +00:00
TreeHugger Robot
793698a58d Merge "Remove hal_cas_default dontaudit" into udc-d1-dev 2023-03-16 00:55:54 +00:00
TreeHugger Robot
8570030518 Merge "Enforce vendor_init" into udc-d1-dev 2023-03-16 00:55:17 +00:00
Wilson Sung
9781434612 Enforce vendor_init
Fix: 264490095
Test: boot-to-home
Change-Id: I612896a0da7e9e2fd60772cbbd4b439e4824d7bc
2023-03-16 00:23:53 +08:00
Wilson Sung
c0c4ee3a9b Enforce init
Fix: 264489678
Test: boot-to-home and no init avc error
Change-Id: I580f6d9af0874a1165c43a77008b43fab5d0091f
2023-03-16 00:06:35 +08:00
Ken Yang
8ff0eed309 SELinux: Remove charger_vendor.te
Bug: 264489675
Change-Id: I9ed521778291ea712ec4ef7f312ae890be3402e7
Signed-off-by: Ken Yang <yangken@google.com>
2023-03-15 15:34:23 +00:00
neoyu
4701e96275 remove tracking_denials for hal_radioext_default.te
The SELinux error has been fixed and this file could be removed.

Bug: 269813076
Test: build pass
Change-Id: I2dfcc00575a277ed7f020a9df8193a5f069d2ed9
2023-03-15 21:30:53 +08:00
Donnie Pollitz
bef163efd5 Remove hal_bootctl_default audits
* As of ToT, this denial is no longer occurring, removing don't audit.

Bug: 267843310
Test: Ran `adb shell dmesg | grep avc ; adb logcat -d | grep avc`

Change-Id: Id40709e436b9b21ad664148e25bed4eab1aff4ff
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-15 12:44:11 +00:00
Chien Kun Niu
8783417f2f usb: remove bug number in bug_map
Bug: 272166827
Test: Presubmit build Pass
Change-Id: I7b641636d52995dc9c098af6e7397702f0dcf4ab
2023-03-15 19:19:44 +08:00
Wilson Sung
8141ff4e3e Remove hal_cas_default dontaudit
Fix: 267260716
Test: take bugreport and no related avc error
Change-Id: If7a7b7f0395ef3a82d2f837ca2732e08f363e87c
2023-03-15 19:02:58 +08:00
TreeHugger Robot
b6d212049b Merge "Enforce isolated_app and untrusted_app" into udc-d1-dev 2023-03-15 06:03:04 +00:00
kuanyuhuang
605235f79c BT: remove tracking denials hal_bluetooth_btlinux
Local build with deleting tracking_denials/hal_bluetooth_btlinux.te
and adb shell getenforce ==> Enforcing.
Tested by BT funtions(playing music, share contacts, transfer file) and
no Bluetooth avc: denied logs.

Bug: 264489608
Test: local build
Change-Id: I1ba1868419d47b087ce96054a63a06b25484e0f5
2023-03-15 05:13:53 +00:00
Wilson Sung
63a66ef59e Enforce isolated_app and untrusted_app
Fix: 264489642
Fix: 264972745
Fix: 267261265
Test: boot-to-home and no related avc error
Change-Id: I4770a076f6a5159db6ffea0661b52b449df9c55a
2023-03-15 12:24:43 +08:00
Wilson Sung
389ddb027e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 273638876
Test: scanBugreport
Bug: 273639365
Bug: 273143844
Bug: 273639264
Bug: 273638940
Bug: 273638876
Test: scanAvcDeniedLogRightAfterReboot
Bug: 273638876
Bug: 268566481
Change-Id: I2229a7c7e29dad303f7ef60c8d7f770b6a77a044
2023-03-15 11:38:05 +08:00
Quinn Yan
e825edbf28 Merge "Remove the tracking_denials for edgetpu project. Fix the wrong sysfs directory for edgetpu." into udc-dev am: fe4ffed5de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22082013

Change-Id: I3a6e12bb4e7f9e81deb4b0cf9c1d59102370efef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-15 01:42:42 +00:00
Quinn Yan
fe4ffed5de Merge "Remove the tracking_denials for edgetpu project. Fix the wrong sysfs directory for edgetpu." into udc-dev 2023-03-15 01:26:24 +00:00
qinyiyan
1f30d7d1f9 Remove the tracking_denials for edgetpu project.
Fix the wrong sysfs directory for edgetpu.

Test: No avc denails seen with the selinx=enforcing
Bug: 264489387,264489676
Change-Id: I5d4d249a0b906e3e5d765ed8830fd915db8aa66e
2023-03-14 17:01:19 -07:00
TreeHugger Robot
15a45ce32f Merge "Enforce pixel_stats" into udc-d1-dev 2023-03-14 07:18:22 +00:00
Wilson Sung
a37fd0cd9d Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 272628396
Test: scanBugreport
Bug: 272628762
Test: scanAvcDeniedLogRightAfterReboot
Bug: 272628396
Bug: 267714573
Change-Id: Ice1b62f4092a00af2f9112efa84859465fa5061d
2023-03-14 13:46:46 +08:00
Wilson Sung
9f8b8971db Merge "Enforce system ui app" into udc-d1-dev 2023-03-14 05:44:27 +00:00
Wilson Sung
95eea9a04b Enforce pixel_stats
Fix: 264483357
Fix: 264483319
Fix: 264483568
Fix: 264489783
Test: boot-to-home and no pixel_stats avc error
Change-Id: I0b68fa3853c65056d7da78a436a3d38888af8f19
2023-03-14 13:40:49 +08:00
Sayanna Chandula
8f8acbb026 Merge "thermal: remove tracking denials for hal_thermal" into udc-d1-dev 2023-03-14 03:51:09 +00:00
Sayanna Chandula
d610423377 thermal: remove tracking denials for hal_thermal
Bug: 264490033
Test: Test thermal service after flashing the build

Change-Id: Ifb0fa5272a89527d8cba4a2292737f3af941f95a
Signed-off-by: Sayanna Chandula <sayanna@google.com>
2023-03-14 02:27:37 +00:00
TreeHugger Robot
fcffe3c099 Merge "Enforce hal_sensors_default" into udc-d1-dev 2023-03-14 02:25:33 +00:00
TreeHugger Robot
25c992012f Merge "enforce hal_dumpstate_default" into udc-dev am: 3906f53197
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21982724

Change-Id: I3249dd6a9df32bfa09f83f11e76755ae9d74873c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-14 01:55:34 +00:00
TreeHugger Robot
3906f53197 Merge "enforce hal_dumpstate_default" into udc-dev 2023-03-14 01:10:42 +00:00