Ken Yang
58a6a1e772
WLC: cleanup the unused hal_wlc policies
...
Bug: 264489562
Bug: 262455719
Bug: 260366297
Bug: 260363384
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit 6f9844d137
)
Merged-In: I90b9e442082b8e03e76ce63aaee56e5882933449
Change-Id: I90b9e442082b8e03e76ce63aaee56e5882933449
2023-02-20 11:05:53 +00:00
Ken Yang
670b22c2c7
WLC: cleanup WLC trakcing_denials
...
Bug: 268566583
Signed-off-by: Ken Yang <yangken@google.com>
(cherry picked from commit da69d2a494
)
Merged-In: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
Change-Id: I2b3fda7b1b84ff4407eee4017df351f9f1d3bb51
2023-02-20 11:05:25 +00:00
Wilson Sung
931ea0d342
allow bootctl to read devinfo
...
Bug: 260522436
(cherry picked from commit 967da5da4f
)
Merged-In: I41d2763ffe40d7465a11cc86612fed9f92905eff
Change-Id: I41d2763ffe40d7465a11cc86612fed9f92905eff
2023-02-20 11:02:28 +00:00
Wilson Sung
676c7a674c
Remove proc_vendor_sched obsolete denials
...
Bug: 264490054
(cherry picked from commit 6545bc156a
)
Change-Id: I308df50eefe611a0a87afc9a21387465487cc6ea
Merged-In: I308df50eefe611a0a87afc9a21387465487cc6ea
2023-02-20 11:01:42 +00:00
Nicole Lee
7706be6c71
logger_app: don't audit default_prop and fix errors
...
avc: denied { read } for comm="oid.pixellogger" name="u:object_r:default_prop:s0" dev="tmpfs" ino=153 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:default_prop:s0 tclass=file permissive=0 app=com.android.pixellogger
avc: denied { search } for name="ssrdump" dev="dm-44" ino=377 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_crashinfo_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
avc: denied { search } for name="coredump" dev="dm-44" ino=378 scontext=u:r:logger_app:s0:c8,c257,c512,c768 tcontext=u:object_r:sscoredump_vendor_data_coredump_file:s0 tclass=dir permissive=0 app=com.android.pixellogger
Bug: 264489961
Bug: 269383459
Test: Make sure no avc denied for logger_app when using Pixel Logger
(cherry picked from commit ef1d13d86d
)
Change-Id: I8999372d243286586eb53602e167fa111d39a00f
Merged-In: I8999372d243286586eb53602e167fa111d39a00f
2023-02-20 11:00:59 +00:00
Sean.JS Tsai
d8572861e3
Revert "Update error on ROM 9624328"
...
This reverts commit cf747f40d6
.
Reason for revert: <b/269976373>
Change-Id: I1bee9c1da2571ab753c2193491ebc71b288b66b2
2023-02-20 04:29:33 +00:00
sukiliu
cf747f40d6
Update error on ROM 9624328
...
Bug: 269813282
Bug: 269813059
Bug: 268566481
Bug: 269812912
Test: SELinuxUncheckedDenialBootTest
Change-Id: Id8cbfb7c55f2acdc3102b20cdbd2702b594992ba
2023-02-20 10:28:33 +08:00
Kuen-Han Tsai
d0ac5bffa3
SEPolicy: remove tracking denials for hal_usb
...
Remove tracking denials since there is no avc denials related to hal_usb
found in the bug report.
Bug: 264483531
Bug: 264483531
Bug: 264482981
Bug: 264600052
Bug: 264482981
Bug: 264600052
Bug: 261651112
Test: Capture bugreport and check any denials related to hal_usb
Change-Id: I535c94c1112fc51f80b80c99562b43afee32ddd6
2023-02-18 02:41:51 +00:00
Wilson Sung
3432cc6b0b
Enforce system_server and remove obsolete denials
...
Bug: 261519050
Bug: 262455682
Bug: 264489786
Test: boot to home and avc gone
Change-Id: I0a51e029a85af0a77faebfdcfe0b4dc26b71cca6
2023-02-16 05:35:19 +00:00
Wilson Sung
c43a6186bf
Add app_domain to con_monitor_app
...
Bug: 261782930
Bug: 264490077
Test: boot to home and avc gone
Change-Id: I86a0793c93549172ee60397b9735ddcfe0d20bac
2023-02-16 13:00:39 +08:00
Wilson Sung
ae2403dca7
Remove shell related denied
...
Bug: 260366321
Bug: 264489784
Change-Id: I21c5011358862ea911a3240aa0ff650d503514e9
2023-02-16 02:21:56 +00:00
Wilson Sung
4ea1dcff3a
Fix zram avc denied
...
Bug: 260522041
Bug: 264490055
Test: boot to home and avc errors gone
Change-Id: I37532bb66c8f00f4307187e12bdab811c007b614
2023-02-15 08:23:49 +00:00
TreeHugger Robot
386ec7e920
Merge "Remove logger_app in bug_map"
2023-02-15 07:05:52 +00:00
Welly Hsu
5a441a9ca3
Merge "Remove unnecessary dontaudit for context euiccpixel_app"
2023-02-15 05:27:41 +00:00
Wilson Sung
c1a0ef2fe6
Enforce bootanim and platform_app
...
Bug: 264489606
Bug: 264490036
Change-Id: I16ed01bbb93ae2b5d5d6609ffd1f2bc0e3dc39ca
2023-02-15 10:36:08 +08:00
Shashank Sharma
7cd2e4b765
Merge "arm_mali_platform_service: register gpu selinux service"
2023-02-15 02:11:19 +00:00
Welly Hsu
0b3bc92066
Remove unnecessary dontaudit for context euiccpixel_app
...
bug: 260522203
bug: 260922442
bug: 262455954
bug: 260522040
bug: 260768358
bug: 261933311
Test:
1. m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
2. eSIM OS version check & OS upgrade successfully without avc error
Change-Id: I6e0771a5794a42af5e187e35881e6de06e01fff0
2023-02-15 02:08:27 +00:00
George Chang
378fc6f5cf
Merge "Remove dontaudit for secure_element"
2023-02-15 00:33:49 +00:00
Shashank Sharma
7cbda60f3e
arm_mali_platform_service: register gpu selinux service
...
Fix avc denied issues.
Bug: 261105374
Bug: 260768402
Bug: 260922162
Bug: 261105092
Bug: 264483754
Test: No AVC denied logs after reboot.
Change-Id: I6448b3e0df9b5deeb953498fa623810eadb3ff67
2023-02-14 23:34:14 +00:00
TreeHugger Robot
996a7ad4ff
Merge "storage: remove init tracking_denials rule"
2023-02-14 22:51:57 +00:00
Dinesh Yadav
dec248fa9a
Merge "Remove b/264321380 from bug map"
2023-02-14 11:33:11 +00:00
Nicole Lee
95bf6d4b20
Remove logger_app in bug_map
...
Bug: 264600084
Bug: 264600053
Change-Id: I5aa4dc83806c001e2cd3808cb998c39e4e3bd524
2023-02-14 09:29:29 +00:00
Randall Huang
eafa9d0fbe
Merge "storage: remove dumpstate tracking_denial rule"
2023-02-14 08:35:13 +00:00
TreeHugger Robot
dd28add0e4
Merge "Revert "Revert "update error on ROM 9588633"""
2023-02-14 08:06:21 +00:00
Randall Huang
f6600b7f72
storage: remove init tracking_denials rule
...
Bug: 262794360
Test: boot to home
Change-Id: Iaea58cc0a1a572a651f7cb01d9b4ba19ff515269
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-02-14 15:51:57 +08:00
Randall Huang
da5df9cd20
storage: remove dumpstate tracking_denial rule
...
Bug: 261933169
Test: no scsi avc denial when generating bugreport
Change-Id: Iecf98c248a2ad28d05095b7c91b8695dd92486be
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-02-14 07:13:54 +00:00
Wilson Sung
cc76d0f05b
Revert "Revert "update error on ROM 9588633""
...
This reverts commit 9290d7c45b
.
Add hal_googlebattery related denied to bug_map
Bug: 268566583
Bug: 268572197
Bug: 268572164
Change-Id: Iabfcfb28f69c118707fb64c34e2882ea0a49a776
2023-02-14 15:05:12 +08:00
Ken Yang
8893d42439
Remove hal_vibrator_default in bug_map
...
Remove hal_vibrator_default in bug_map due to my incorrect rebase
Bug: 264483356
Change-Id: I25310ad9f6d2c16d90f20969cbfc792f34584c93
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-14 06:56:52 +00:00
Dinesh Yadav
1dbaa50d8c
Remove b/264321380 from bug map
...
This bug was created to track the selinux violations caused when
camera hal tried to access gxp. This has been resolved by ag/21003929
Bug: 264321380
Change-Id: I33458cb7a1a657aba8be62362b62be52d881420f
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-02-14 05:49:34 +00:00
George
39733f8622
Remove dontaudit for secure_element
...
SELinuxUncheckedDenialBootTest
scanAvcDeniedLogRightAfterReboot
no avc denials for secure_element
Bug: 264490093
Bug: 262794969
Bug: 261651095
Bug: 260922187
Bug: 260768672
Test: manually check dumpsys secure_element
Test: run cts -m CtsOmapiTestCases
Test: m atest && atest-dev com.google.android.selinux.pts.SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: Ic06f9d0bf61bc8f30e0f285403a99e2c73384418
2023-02-13 12:36:51 +00:00
Randall Huang
eb3e643acd
Storage: remove hal_health_storage tracking denials rules
...
Bug: 264490032
Test: boot to home
Change-Id: I825b33ba513e135754a969a108d13096a326745a
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-02-13 17:14:36 +08:00
Randall Huang
2c859d0485
storage: remove vold tracking_denials rules
...
Bug: 264483567
Test: boot to home
Change-Id: Iad702bf293ea374174034239c81ea3499c837cf0
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-02-13 16:58:39 +08:00
Andrew Chant
f861570a64
Merge "Revert "update error on ROM 9588633""
2023-02-11 01:33:03 +00:00
Andrew Chant
9290d7c45b
Revert "update error on ROM 9588633"
...
This reverts commit 8c2f12f39d
.
Reason for revert: Broke the zuma build
Bug: 268566583
device/google/zuma-sepolicy/tracking_denials/systemui_app.te:6:ERROR 'unknown type hal_googlebattery' at token ';' on line 100380:
dontaudit systemui_app hal_googlebattery:binder { call };
dontaudit systemui_app default_android_service:service_manager { find };
checkpolicy: error(s) encountered while parsing configuration
Change-Id: I1286020227bdd73c14833489613237f82573d02f
2023-02-11 01:27:19 +00:00
Wilson Sung
e338667584
vendor_init: Add getattr to sg
...
Bug: 260522244
Change-Id: I9f447ecb635280048ca0d785f00b6c851a9dedf3
2023-02-10 18:35:47 +08:00
Wilson Sung
6cf7ce5cc0
Allow vendor_init chown gvotables
...
Bug: 267736435
Bug: 260366195
Change-Id: I0a27a7fb3719d57449fb3d7f4c4d746d09419a75
2023-02-10 18:34:51 +08:00
Wilson Sung
594dee4dc4
Allow vendor_init create link for bootdevice_sysdev
...
Bug: 263185566
Change-Id: I3a041c8dbd33c538d3971b793c64e4ea7c310190
2023-02-10 16:24:06 +08:00
Wilson Sung
8c2f12f39d
update error on ROM 9588633
...
Bug: 268566583
Bug: 268572197
Bug: 268572164
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I6eba194f27258a0c2acbcb739c3a69dfa7b77b56
2023-02-10 11:57:07 +08:00
Tom Huang
dfe1f3799b
Merge "Add BT hal sepolicy for allowing accessing AoC device node"
2023-02-10 02:23:42 +00:00
kuanyuhuang
3ce317ca5f
Add BT hal sepolicy for allowing accessing AoC device node
...
Allow BT hal to access device and aoc_device.
Test: manual and check avc log
Bug: 265587172
Change-Id: I62e9fb3f0278af7e0365f88bb3723cb47a266b81
2023-02-09 09:34:10 +00:00
TreeHugger Robot
c7edca28e2
Merge changes Ia32c4b01,I4746bca6
...
* changes:
Permissive systemui during bringup stage
label SystemUI app
2023-02-09 07:05:46 +00:00
More Kuo
459ad4638f
Merge "Bluetooth: remove dontaudit for hal_bluetooth_btlinux"
2023-02-09 04:38:39 +00:00
Welly Hsu
782f4c6e6b
Merge "Update ofl_app selinux policy"
2023-02-09 03:47:53 +00:00
Wilson Sung
5af20ce7a5
Permissive systemui during bringup stage
...
Bug: 264266705
Change-Id: Ia32c4b016aad4f47c437e62069e55990297dad82
2023-02-09 11:44:09 +08:00
Wilson Sung
f88300dc69
label SystemUI app
...
Bug: 264266705
Bug: 262794428
Change-Id: I4746bca6291d57ee36c0565d15ee5320380e1bc0
2023-02-09 11:33:54 +08:00
TreeHugger Robot
f43519dad8
Merge "dontaudit kernel search allow debugfs"
2023-02-09 02:12:22 +00:00
Welly Hsu
b8e66572cc
Update ofl_app selinux policy
...
bug: 264489564
test: Use ofl_app (OFLBasicAgent app) will not face avc error
Change-Id: I55061f6b067e054ec605cd6a196406e48c1271e6
2023-02-08 17:39:34 +08:00
TreeHugger Robot
f61bc3e16a
Merge "WLC: Fix hal_wireless_charger sepolicies"
2023-02-08 09:16:22 +00:00
Ken Yang
c3048691a9
WLC: Fix hal_wireless_charger sepolicies
...
Bug: 264483390
Bug: 264483533
Bug: 264483152
Bug: 263429589
Change-Id: If06e0b0c429e78e71f7be2d6418ccab0ab115414
Signed-off-by: Ken Yang <yangken@google.com>
2023-02-08 08:14:36 +00:00
Wilson Sung
da49f90167
Allow vendor_init to set slog properties
...
Bug: 267843409
Change-Id: Ib98b7127bb4381ce5dfb5522b3652637a533f593
2023-02-08 15:32:26 +08:00