Wilson Sung
f2d0dbb66a
update error on ROM 9900526
...
Bug: 277155496
Bug: 277300017
Bug: 277300125
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I2a2f230589695b0240abb26909c94fd4cf2420bf
2023-04-07 14:43:36 +08:00
Adam Shih
46fd63b761
comply with VTS requirements am: 22e1c0756a
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22344148
Change-Id: I02d1e5a2af5bb6d3009d2b7687dff6080f56724f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-06 03:08:17 +00:00
Dinesh Yadav
d9a75c1639
Merge "Allow google_camera_app to access edgetpu" into udc-d1-dev
2023-04-06 02:34:35 +00:00
Sayanna Chandula
387145ed85
Remove hal_thermal_default bug from bug_map
...
SELinux errors are fixed and hence removing from bug map
Bug: 272166987
Test: Build and boot on device
Change-Id: Ic0d314486a2ed6fbc1c4497b122827b17f5b9022
Signed-off-by: Sayanna Chandula <sayanna@google.com>
2023-04-05 22:26:40 +00:00
Dinesh Yadav
478b11708f
Allow google_camera_app to access edgetpu
...
These permissions are needed by GCA-release & GCA-dogfood to access
edgetpu.
Bug: 264490031
Change-Id: Idd9dff906c86f9e83f1dc67698c23387e174d99c
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-04-04 06:11:47 +00:00
Adam Shih
22e1c0756a
comply with VTS requirements
...
Bug: 275142299
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Built pass on target-userdebug and aosp_target-userdebug
Change-Id: I6a114aa2aa92f7b06cfd5bbd1f73d34b5477b109
2023-03-30 13:28:43 +08:00
TreeHugger Robot
8041addc24
Merge "sepolicy: fix VTS failure for system suspend [RESTRICT AUTOMERGE]" into udc-d1-dev
2023-03-30 01:52:41 +00:00
TreeHugger Robot
4bb2e02b1c
Merge "Add logd selinux allow permissions" into udc-d1-dev
2023-03-30 01:44:29 +00:00
TreeHugger Robot
6cbdc36e1b
Merge "Move pixel dumpstate to gs-common" into udc-d1-dev
2023-03-29 16:06:45 +00:00
Darren Hsu
bc15f1c8ee
sepolicy: fix VTS failure for system suspend [RESTRICT AUTOMERGE]
...
Bug: 275143652
Test: run vts -m SuspendSepolicyTests
Change-Id: I7cb5fdb18e7b16d98961bfed11da21496e8fa026
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-03-29 18:46:56 +08:00
Donnie Pollitz
885a790f2d
Add logd selinux allow permissions
...
Bug: 261105354
Bug: 264489639
Test: Ran atest SELinuxTest#scanAvcDeniedLogRightAfterReboot
Change-Id: I377dbb3bbdecd6780c1bdfb3aab53ee3c754c163
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-29 09:24:47 +02:00
TreeHugger Robot
866b23080c
Merge "Update SELinux error" into udc-d1-dev
2023-03-29 05:35:51 +00:00
Wilson Sung
5227dfe6ab
Update SELinux error
...
Test: SELinuxUncheckedDenialBootTest
Bug: 275646098
Test: scanBugreport
Bug: 275646003
Test: scanAvcDeniedLogRightAfterReboot
Bug: 275645636
Change-Id: Iedd660e3937792d5ac58f384605300b39f6dfcb0
2023-03-29 12:17:48 +08:00
Adam Shih
b19966b929
Merge "Revert "comply with VTS requirements"" into udc-dev am: 97c56013be
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22328024
Change-Id: Ic5841fefdd7576548fff66fc340259814e542df9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 03:12:09 +00:00
TreeHugger Robot
83588e636f
Merge "Keep name "dmabuf_system_secure_heap_device" for secure playback" into udc-d1-dev
2023-03-29 02:56:22 +00:00
Adam Shih
97c56013be
Merge "Revert "comply with VTS requirements"" into udc-dev
2023-03-29 02:49:09 +00:00
Adam Shih
a0b5162488
Revert "comply with VTS requirements"
...
Revert submission 22302106-dumpstate aidl
Reason for revert: build failed on udc-d1-dev
Reverted changes: /q/submissionid:22302106-dumpstate+aidl
Change-Id: I6bd0ec81272827498ce36bee556fd89acc6b20ca
2023-03-29 02:45:20 +00:00
Adam Shih
026cb8d935
Merge "comply with VTS requirements" into udc-dev am: 7cb203f3c2
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22306662
Change-Id: I03432b1457e7b251ac5f5f9d7e10e3b4485260cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-29 00:47:11 +00:00
TreeHugger Robot
5d6157b523
Merge "Allow bootctl to access trusty device" into udc-d1-dev
2023-03-29 00:00:55 +00:00
Adam Shih
7cb203f3c2
Merge "comply with VTS requirements" into udc-dev
2023-03-28 23:58:03 +00:00
Mingguang Xu
203dd313e7
Merge "Add permissions to connect radioext to twoshay." into udc-dev am: 57e322c17c
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21956466
Change-Id: Ib70d523bc36e1a789b003374207094f2eaf722d5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-28 23:09:15 +00:00
Mingguang Xu
57e322c17c
Merge "Add permissions to connect radioext to twoshay." into udc-dev
2023-03-28 23:03:46 +00:00
Feiyu Chen
02cc06b4ab
Merge "Allow camera HAL to access edgetpu_app_service" into udc-dev am: 2d34b0b1f6
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22248613
Change-Id: Icf1b60bc90121ad358639abe52ea15b4b69bb652
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-28 09:19:09 +00:00
Feiyu Chen
2d34b0b1f6
Merge "Allow camera HAL to access edgetpu_app_service" into udc-dev
2023-03-28 08:43:23 +00:00
Donnie Pollitz
74e0bf60c2
Allow bootctl to access trusty device
...
Background:
* Boot Control needs to be able to blow AR fuses, which requires access
to the OTP port on trusty.
Bug: 267714941
Test: AVC denial doesn't show up in log
Change-Id: I5635f2358b379ae0ffe882ca9ee162a455f554f0
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-03-28 09:58:16 +02:00
Jerry Huang
912984c964
Keep name "dmabuf_system_secure_heap_device" for secure playback
...
Fixes the following denials:
03-13 14:31:22.796 W CodecLooper: type=1400 audit(0.0:284): avc: denied { read } for name="vstream-secure" dev="tmpfs" ino=865 scontext=u:r:untrusted_app_29:s0:c49,c257,c512,c768 tcontext=u:object_r:video_secure_heap_device:s0 tclass=chr_file permissive=0 app=com.google.android.exoplayer2.demo
03-13 14:31:22.796 I auditd : type=1400 audit(0.0:281): avc: denied { read } for comm="CodecLooper" name="vstream-secure" dev="tmpfs" ino=865 scontext=u:r:untrusted_app_29:s0:c49,c257,c512,c768 tcontext=u:object_r:video_secure_heap_device:s0 tclass=chr_file permissive=0 app=com.google.android.exoplayer2.demo
03-14 15:01:48.069 1429 1429 W CodecLooper: type=1400 audit(0.0:1469): avc: denied { read } for name="vstream-secure" dev="tmpfs" ino=807 scontext=u:r:untrusted_app_32:s0:c65,c257,c512,c768 tcontext=u:object_r:video_secure_heap_device:s0 tclass=chr_file permissive=0 app=com.disney.disneyplus
Bug: 268197530
Test: secure playback
Change-Id: I09a24fcf03f1f66b4c85d3b3949f33ad0d0f8dac
2023-03-28 15:04:43 +08:00
Boon Jun Soh
0a1cba518a
Use tof sensor codenames
...
Bug: 272224875
Test: Camera CTS + PTS + unittests
Change-Id: Iedd90e285364b28add7298bae7662efbac31474c
2023-03-28 13:00:09 +08:00
Adam Shih
d4a7ff694a
comply with VTS requirements
...
Bug: 275142299
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Built pass on target-userdebug and aosp_target-userdebug
Change-Id: Ifd75afdf2365687eed9598f74dd4cf3241be2964
2023-03-28 03:28:55 +00:00
RD Babiera
a82406ee28
Merge "Revert "comply with VTS requirements"" into udc-dev am: 3616de2c26
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22298904
Change-Id: I49798505d571f538127fc5d2b9474cce3992421c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 22:31:37 +00:00
RD Babiera
3616de2c26
Merge "Revert "comply with VTS requirements"" into udc-dev
2023-03-27 21:52:39 +00:00
RD Babiera
8720ececf1
Revert "comply with VTS requirements"
...
Revert submission 22242215-dumpstate aidl
Reason for revert: DroidMonitor-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?branch=git_udc-d1-dev&target=aosp_husky-userdebug&lkgb=9826121&lkbb=9829863&fkbb=9826130 , bug b/275279368.
Reverted changes: /q/submissionid:22242215-dumpstate+aidl
Change-Id: Ida32309c468074a5671c30aa28cf801c1695d786
2023-03-27 20:58:33 +00:00
Adam Shih
036fb44a5d
Move pixel dumpstate to gs-common
...
Bug: 240530709
Test: adb bugreport
Change-Id: I10f98673ea507f841d9d3f33d737c4e73c1b5b19
Merged-In: I4c46a2495ea07b9e44f56c4c6be726621e0ebf65
(cherry picked from commit 8538fd33da
)
2023-03-27 17:57:22 +00:00
Wilson Sung
98c7894070
Merge "Move OTA context out of legacy folder" into udc-d1-dev
2023-03-27 14:27:28 +00:00
Alan
afafafd8a4
Add permissions to connect radioext to twoshay.
...
Connection through grilantennatuningservice binder call.
Test: manual
Bug: 258970389
Change-Id: I419b40042cce363428f72fa723adf89bcf269ef4
2023-03-27 17:07:16 +08:00
TreeHugger Robot
84aab225cf
Merge "comply with VTS requirements" into udc-dev am: c83e5be8d9
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22286084
Change-Id: I0b9cf28cdfb549e2c3571e144f73f59d0004bc02
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 06:27:52 +00:00
TreeHugger Robot
c83e5be8d9
Merge "comply with VTS requirements" into udc-dev
2023-03-27 06:05:51 +00:00
Gina Ko
5821d671f3
Merge "Allow systemui to find cameraserver_service" into udc-d1-dev
2023-03-27 05:32:14 +00:00
Neo Yu
e9aabf7e9e
Merge "Remove the bug of hal_radioext_default because the fix is merged." into udc-d1-dev
2023-03-27 04:17:02 +00:00
Adam Shih
e124d5aea9
comply with VTS requirements
...
Bug: 275036679
Bug: 275034315
Test:
atest VtsHalDumpstateTargetTest:PerInstanceAndMode/DumpstateAidlPerModeTest#TestOk/0_android_hardware_dumpstate_IDumpstateDevice_default_FULL
atest VtsHalDumpstateTargetTest:PerInstance/DumpstateAidlGeneralTest#TestInvalidModeArgument_Negative/0_android_hardware_dumpstate_IDumpstateDevice_default
Change-Id: I1c89d7662351ffae5409c3f81b4360579fdc00ae
2023-03-27 12:07:24 +08:00
Wilson Sung
6acea9d647
Move OTA context out of legacy folder
...
Bug: 275143841
Test: OTA
Change-Id: I4774b7c48c075afc1b02d8c34fded212cd0efffb
2023-03-27 11:44:51 +08:00
Dinesh Yadav
4a01ae23ad
Merge "Add certificate & label for GCA-ENG & GCA-Next" into udc-d1-dev
2023-03-27 03:13:24 +00:00
Neo Yu
58ff635b67
Remove the bug of hal_radioext_default because the fix is merged.
...
Bug: 274374768
Test: verify by test rom
Change-Id: Ia9665e5223997cf498f9320dfd0b1dbdacaae0b2
2023-03-27 11:08:25 +08:00
Neo Yu
70749d1b96
Merge "sepolicy: allow hal_radioext_default binder call with servicemanager" into udc-dev am: 5b1689534f
...
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22222570
Change-Id: I2d2a07056322f6971050e9299e17201b95773eaf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-27 03:07:31 +00:00
Neo Yu
5b1689534f
Merge "sepolicy: allow hal_radioext_default binder call with servicemanager" into udc-dev
2023-03-27 02:36:56 +00:00
Gina Ko
ce85639700
Allow systemui to find cameraserver_service
...
avc: denied { find } for pid=2435 uid=10235 name=media.camera
scontext=u:r:systemui_app:s0:c235,c256,c512,c768
tcontext=u:object_r:cameraserver_service:s0 tclass=service_manager permissive=0
Bug: 272628174
Bug: 269964574
Bug: 274734888
Test: Manual. Able to turn on/off flashlight from QS.
Change-Id: Icedf70b06bd06eb5b819a00c9157b4f475e9a126
2023-03-25 00:18:23 -07:00
feiyuchen
f0dc7907b0
Allow camera HAL to access edgetpu_app_service
...
Today the EdgeTpu metrics logging library (used by EdgeTpu library used by camera HAL) has a dependency on edgetpu_app_service, in order to call its UserIsAuthorized API to know whether to log the metrics (We don't want to log metrics for 3P apps), see b/275016466.
This is not ideal, because strictly speaking, camera HAL doesn't need such dependency.
Still, this is fine and there is no security risk, because today even untrusted apps can call edgetpu_app_service: http://cs/android-internal/device/google/gs-common/edgetpu/sepolicy/untrusted_app_all.te;l=2;rcl=f4b62d12c171d4e294d8251e34197ab555c40673
Bug: 266084950
Test: Just mm
Change-Id: I6c0e4411370e4b300b9ceb3ad804688d873371cd
2023-03-24 17:01:49 +00:00
Dinesh Yadav
84aa699ac8
Add certificate & label for GCA-ENG & GCA-Next
...
This commit makes following changes:
- Add selinux policies for GCA-Eng & GCA-Next to access GXP device &
edgetpu services.
- Refactor code to push policies for Google Camera app from
legacy/whitechapel_pro/* to vendor/*
Tested:
- flashed both GCA-Eng & GCA-Next apps and observed no crashes due to gxp or edgetpu.
- scontext changed from "untrusted_app_32" to "debug_camera_app" in both cases.
Bug: 264490031
Change-Id: I51f69168eebd6c7e54e512b7abde8dd6bbe7c443
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-03-24 12:56:53 +00:00
Adam Shih
ebc5ee8dab
[automerger skipped] Merge "Move pixel dumpstate to gs-common" into udc-dev am: 2b921528f1
-s ours
...
am skip reason: Merged-In I4c46a2495ea07b9e44f56c4c6be726621e0ebf65 with SHA-1 ee45cfea78
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22236029
Change-Id: I6d02ee84161d92b4b2723cf6b08ccc76bc51ab81
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:23:08 +00:00
Adam Shih
79ea18119e
[automerger skipped] Move pixel dumpstate to gs-common am: 8538fd33da
-s ours
...
am skip reason: Merged-In I4c46a2495ea07b9e44f56c4c6be726621e0ebf65 with SHA-1 ee45cfea78
is already in history
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22236029
Change-Id: Ia5202a87a85fa610fc08f0b9ec8be23592c98585
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:23:07 +00:00
Adam Shih
2b921528f1
Merge "Move pixel dumpstate to gs-common" into udc-dev
2023-03-24 05:54:52 +00:00