Commit graph

440 commits

Author SHA1 Message Date
Wilson Sung
039124e7a4 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 312590044
Change-Id: I24e5462f111f05d051d398487a5931d808cf3002
2023-11-22 03:15:40 +00:00
Wilson Sung
d48c63c215 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 305600857
Change-Id: I4715b66f1b1c051c8d83cffefdf4f3de6e5971ef
2023-10-16 12:19:18 +08:00
Desmond Huang
c62d6871b3 Relocate common tracking denial entries
Bug: 299029620
Change-Id: I587e53a54e6bf4e3ccaa572cb35c28b4a0bc1eed
2023-09-15 03:39:48 +00:00
Desmond Huang
6f2589ec74 Remove obsolete entries
Bug: 299029620
Change-Id: Ib4782148b3e1167fd0113e5ec3eced7348a0cac2
2023-09-15 03:37:16 +00:00
Tai Kuo
1a65e5d5e4 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I2bd35a6bc942536505f62d4122f0de892f243802
2023-09-12 16:45:09 +08:00
Yunju Lee
72f7cbe324 Revert "Update SELinux error"
This reverts commit 8f56fc9709.

Reason for revert: b/291237127 is fixed

Bug: 291237127
Change-Id: I58e2636fb2ef1113a4305152948e07ed8a27a7d9
2023-07-24 15:10:01 +00:00
Wilson Sung
8f56fc9709 Update SELinux error
Test: scanBugreport
Bug: 291237127
Change-Id: Iacb47dce94f8ee2f71d382a9d0a22a6570345e2d
2023-07-17 13:50:09 +08:00
Krzysztof Kosiński
583baf021c Remove bug map entry for unknown property reads in camera HAL.
Fixed by avoiding reading a property with the name "218".

Bug: 286508419
Test: check log for denials when running the camera on zuma device.
Change-Id: I3632868187d263ed787f5abf729c4e5c10a4f4c4
2023-07-14 07:12:51 +00:00
Wilson Sung
5c63d0ef54 Move systemui seapp_contexts to private
Fix: 289480799
Bug: 288227521
Change-Id: Ifc4288125d454569a66151c3c61e000ffd3526ac
2023-07-11 15:24:10 +08:00
Wilson Sung
83671d2646 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289480799
Change-Id: I6c013d99b9b004b0a39d0b1861fa89da46bc846d
2023-07-10 14:21:22 +08:00
Wilson Sung
7a77620145 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289856761
Test: scanBugreport
Bug: 289856761
Test: scanAvcDeniedLogRightAfterReboot
Bug: 289856761
Change-Id: I4a3dcd037b1f63b8d06edab5a5ef4919ce75b8bc
2023-07-04 11:17:41 +08:00
TreeHugger Robot
043ae16d5f Merge "Add kernel vendor_fw_file dir read permission" into udc-d1-dev 2023-06-21 10:47:39 +00:00
Treehugger Robot
d8b11ef832 Merge "Supress kernel avc log before SELinux initialized" into udc-d1-dev 2023-06-21 09:59:33 +00:00
Treehugger Robot
81237d3843 Merge "Update SELinux error" into udc-d1-dev 2023-06-21 08:02:49 +00:00
Wilson Sung
3657f78cb0 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-06-21 16:02:41 +08:00
Wilson Sung
0b77875c4a Supress kernel avc log before SELinux initialized
Bug: 288049349
Fix: 288049229
Change-Id: I5087a77e65ecdbaa868a7257342f5d99f424880a
2023-06-21 16:02:29 +08:00
Wilson Sung
8818dd2de5 Update SELinux error
Test: scanBugreport
Bug: 288049050
Bug: 288049522
Bug: 288049561
Bug: 288049349
Bug: 288049075
Test: scanAvcDeniedLogRightAfterReboot
Bug: 288049229
Change-Id: I939cd8981e64eadb0fa047b09162a02056ec2abf
2023-06-21 06:04:23 +00:00
Wilson Sung
f82fc11c11 Remove unused trace_marker dontaudit
Fix: 260366195
Change-Id: I7ece6549a64740c878dc92ce4b011136eb313533
2023-06-20 14:34:01 +08:00
Wilson Sung
0561b1bd1e Update SELinux error
Test: scanBugreport
Bug: 287898138
Change-Id: I297e59df3774a32305d72706ee6a160f111dee7a
2023-06-19 06:45:37 +00:00
Wilson Sung
94fd2403a7 Remove obsolete bug_map and dontaudit
Fix: 287154997
Fix: 281815537
Fix: 279680264
Fix: 264600171
Fix: 264483456
Fix: 264600171
Fix: 264600171
Fix: 274374769
Fix: 274727372
Fix: 279680070
Fix: 280706610
Fix: 279680213
Fix: 272628762
Fix: 274374992
Fix: 283725554
Fix: 274374722
Fix: 272166737
Fix: 272166787
Fix: 264483532
Fix: 264483753
Fix: 264483754
Fix: 281815594
Fix: 269964574
Fix: 269964574
Fix: 280705998
Fix: 269964558
Fix: 264599934
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 275645636
Fix: 275646003
Fix: 267714573
Fix: 272166664
Fix: 267714573
Fix: 268566481
Fix: 273143844
Fix: 277155496
Fix: 267260619
Fix: 261933310
Fix: 262794429
Fix: 267261048
Change-Id: I1e6da1e43b1aaa398d496cd7b1f3b6267fd39e21
2023-06-19 06:45:30 +00:00
Wilson Sung
5fb350f09f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 286508419
Test: scanBugreport
Bug: 286508419
Test: scanAvcDeniedLogRightAfterReboot
Bug: 286508419
Change-Id: I1ba324133f5f4e14c5a7d43cfea25d98bda9faa9
2023-06-14 15:30:08 +08:00
Zixuan Lan
bdee55bb57 Merge "remove 280706211 from bug map" into udc-d1-dev 2023-06-06 13:02:17 +00:00
Allen Xu
78b62802e4 Add sepolicy for ConnectivityMonitor
Bug: 264489520
Test: v2/pixel-pts/base
Change-Id: I669a538fe3d0a03422638d7d19fc62a793246f6b
2023-06-06 02:01:38 +00:00
Zixuan Lan
76b53940a9 remove 280706211 from bug map
Bug: 280706211
Test: adb log
Change-Id: I167041363a27c294a3c8d2d2fb145ce751a34db7
2023-06-06 08:30:25 +08:00
Wilson Sung
d73217d81f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 283725554
Test: scanBugreport
Bug: 283725554
Bug: 283725302
Test: scanAvcDeniedLogRightAfterReboot
Bug: 283725554
Change-Id: Ie482a46311c1dc1153ef04889e82971a09361e49
2023-05-22 15:01:49 +08:00
Grace Chen
e151f78f5a Remove selinux error bug reference after fixing
Bug: 264483151
Test: None, simple bug removal
Change-Id: Id93085566c772e6b434777955b62b1ccaba64ae2
2023-05-18 17:54:20 -07:00
Wilson Sung
2e511cf418 Remove fixed SELinux bug from bug_map
Fix: 280706292
Bug: 280522410
Change-Id: I5b35759d2b89246e65683fbbc3ca877af04ef25b
2023-05-11 14:10:41 +08:00
Wilson Sung
17a784cf97 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281815594
Test: scanBugreport
Bug: 281815594
Bug: 281815537
Test: scanAvcDeniedLogRightAfterReboot
Bug: 281815594
Fix: 281645191
Change-Id: Ia1e72cdee3ca535eb978ad8becad94c9c4d8c2cd
2023-05-11 04:06:31 +00:00
Zixuan Lan
288623d4d4 remove fixed selinux bug from bug map.
TPU permission was fixed to avoid error in hal_camera_defaul.The corresponding bug for tracking should be removed from the bug map. Please see bug for more details.
Bug: 275001641
Test: logcat grep for selinux error

Change-Id: I3622a1877f94b41d03d1bcb1c16a404db4b3ea8d
2023-05-09 16:38:38 -07:00
Zheng Pan
705cc4abf8 Merge "Allow systemui to find adbd" into udc-d1-dev 2023-05-09 20:21:14 +00:00
Wilson Sung
fd60d077ad Allow systemui to find adbd
Bug: 276415118
Fix: 272628396
Test: connect to adb with no avc error
Change-Id: I07496d663628f62ed975785d794854d1cdc77040
2023-05-09 05:22:16 +00:00
Wilson Sung
e7a70d62b5 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 280706211
Bug: 280706292
Test: scanBugreport
Bug: 280706211
Bug: 280706610
Bug: 280705998
Test: scanAvcDeniedLogRightAfterReboot
Bug: 280706211
Change-Id: I67e0d2ec15b3ea057688644ba5c41c8fb5755128
2023-05-04 12:40:51 +08:00
Kyle Tso
649f19fc94 Allow accessing dumpstate from hal_usb_impl
Fix SELinux errors.

Bug: 267261163
Change-Id: I73a311d796eb520ede3849edc6384c965ec5c915
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-05-03 11:23:52 +08:00
Treehugger Robot
11ea9b76d6 Merge "Remove obsolete tracking entry" into udc-d1-dev 2023-05-02 07:12:52 +00:00
Treehugger Robot
470eda92e4 Merge "Enforce fastbootd" into udc-d1-dev 2023-05-02 04:54:37 +00:00
Wilson Sung
8080b95d06 Enforce fastbootd
Fix: 264489957
Test: flash and no related avc error
Change-Id: Ibf616a98e9341310e18db6dda27d86adbf24deac
2023-05-02 11:42:59 +08:00
Krzysztof Kosiński
9f7dec1023 Merge "Enforce sepolicy for Google Camera App." into udc-d1-dev 2023-04-28 22:18:37 +00:00
Krzysztof Kosiński
5b2134d5c5 Enforce sepolicy for Google Camera App.
Added missing statement allowing GXP firmware access.

Bug: 264489778
Test: GCA smoke test in setenforce mode.
Change-Id: Ied2f675a2e11f7aebcf4e1e6ac49fc2e39dd2ecf
2023-04-27 19:53:25 +00:00
martinwu
09aaf3dfbc [TSV2] Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I45c894fa9378a7878bc853f7723162ebd6141115
2023-04-27 13:47:34 +00:00
Carol Cheng
bb1f0f25bb Merge "Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"" into udc-d1-dev 2023-04-27 06:36:48 +00:00
Martin Wu
4e2023c263 Revert "Add sepolicy for dumpstate to zip tcpdump into bugreport"
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I795de89a17c5ccee702fa3a59af03d48d89fbaf2
2023-04-27 02:21:00 +00:00
Treehugger Robot
fe27339606 Merge "Add sepolicy for dumpstate to zip tcpdump into bugreport" into udc-d1-dev 2023-04-27 01:43:58 +00:00
martinwu
da1f9ffa79 Add sepolicy for dumpstate to zip tcpdump into bugreport
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I04ca96860c78baf24afd7deecff7dd4d470d9539
2023-04-26 14:17:56 +00:00
Salmax Chang
5ddf0079c6 Remove obsolete tracking entry
Bug: 264489567
Bug: 261651131
Change-Id: Ibf1116ea7b393f3c1e6eec0794e492b5dc2fd1ad
2023-04-26 17:15:36 +08:00
Wilson Sung
74494540d6 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 279680070
Test: scanBugreport
Bug: 279680070
Bug: 279680213
Bug: 279680264
Test: scanAvcDeniedLogRightAfterReboot
Bug: 279680070
Change-Id: I0a5aadfed90377aeee60a15aaab212c7709d091a
2023-04-26 15:10:44 +08:00
Treehugger Robot
8ebffeef84 Merge "Remove 'hal_neuralnetworks_armnn' '/data' access exception" into udc-d1-dev 2023-04-26 05:07:41 +00:00
Treehugger Robot
8f8f545307 Merge "Remove hal_power_default bug from bug_map" into udc-d1-dev 2023-04-26 04:59:43 +00:00
Bruno BELANYI
f9d70ef1b2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Fix: 205779871
Test: manual - reboot device and check the absence of AVC denials
Change-Id: I7bf68036522553a2919076fc6243a577086ffb3a
Merged-In: I7bf68036522553a2919076fc6243a577086ffb3a
(cherry picked from commit deec8fec9d)
2023-04-26 03:35:52 +00:00
Nicolas Geoffray
42b382da0c Remove old debug map entries.
Fix: 264483352
Change-Id: Ie47107328f58dc4f1d4070e93c0cd09e88cee021
Merged-In: Ie47107328f58dc4f1d4070e93c0cd09e88cee021
(cherry picked from commit af3702bffd)
2023-04-26 03:33:31 +00:00
Chungkai Mei
c01d4b7d9b Remove hal_power_default bug from bug_map
SELinux errors are fixed and hence removing from bug map

Bug: 273638876
Test: Build and boot on device
Change-Id: I4ca6180ad286970d36ce204cd4c44e75962b26e0
Merged-In: I4ca6180ad286970d36ce204cd4c44e75962b26e0
Signed-off-by: Chungkai Mei <chungkai@google.com>
(cherry picked from commit 8051a8759a)
2023-04-26 03:32:21 +00:00