Commit graph

239 commits

Author SHA1 Message Date
Treehugger Robot
a47912cabc Merge "trusty: Fix selinux denials for block devices" into main 2023-11-29 02:37:08 +00:00
Alec Foster
4d742a4ced Merge "Revert^2 "Add IQfpExtendedFingerprint to service_contexts."" into main 2023-11-28 18:14:33 +00:00
Donnie Pollitz
662dc87e32 trusty: Fix selinux denials for block devices
Bug: 312894027
Test: Confirmed avc denial is gone on boot
Change-Id: Iaa87cdef24214a2b6f6eba2af917c03bbbb4bfb5
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-11-28 09:20:41 +01:00
guibing
6c797e281a zumapro: sepolicy: update ospm selinux settings.
Use the similar setting from zuma: ag/23270943 and ag/22980665

Bug: 300516041
Test: Power hal works without related avc errors.
Change-Id: I45fb13299f153f0f472e21f54af393147c7fbd7c
2023-11-28 00:36:38 +00:00
Alec Foster
c659e9d5c7 Revert^2 "Add IQfpExtendedFingerprint to service_contexts."
8eb45bceb6
Bug: 313504369

Change-Id: I978eb6434d959412548d6bd6d59985374e29674f
2023-11-27 22:29:06 +00:00
Kamal Shafi
83f48c2556 sepolicy: move lwis dev sepolicy to device folder
- Remove lwis dev device specific sepolicy from zumapro

Bug: 312869113
Test: build
Change-Id: I12e8e703fb3a58a5be4f4b6dd0ade188cf4d8c0e
2023-11-27 10:09:13 +00:00
Treehugger Robot
659d928c41 Merge "sepolicy: add front camera taotie eeprom sepolicy" into main 2023-11-23 07:59:57 +00:00
Kamal Shafi
daeea509ef sepolicy: add front camera taotie eeprom sepolicy
Add missing sepolicy for front camera eeprom.

Bug: 312849126
Test: build
Change-Id: I032624791c1dc114d4513d633c72b4f415bc7c5f
2023-11-23 06:21:03 +00:00
Wilson Sung
7d7ebbc370 Move lwis declaration to vendor
Bug: 312143882
Test: make selinux_policy
Change-Id: Ice60742e2b1d2c863dbb55f31e5e38c4d8768fcb
2023-11-23 02:23:02 +00:00
Wilson Sung
2a66f04eee Move legacy zuma/file_contexts to vendor
Bug: 312143882
Change-Id: I992762f507a49edfcb4f25bf26594bbb03f191a1
2023-11-22 11:34:18 +00:00
Treehugger Robot
aed9527a37 Merge "Move sg_device related policy" into main 2023-11-22 09:39:24 +00:00
Wilson Sung
b880b46c91 Move file_context to vendor
Bug: 312143882
Change-Id: Idadeb768371ec170fce8851a381d6ab9e5d31bfc
2023-11-22 08:39:03 +00:00
Donnie Pollitz
25c848aea9 Merge "Fix SELinux permissions for trusty_userdata partition" into main 2023-11-22 08:07:38 +00:00
Randall Huang
a5f3627328 Move sg_device related policy
Bug: 312582937
Test: make selinux_policy
Change-Id: Ic64acb35898e8517141e2fcffb4e2ff71b3b5345
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-11-22 14:42:38 +08:00
Wilson Sung
c967ee5dc3 Move sg_device related policy
Bug: 312143882
Test: make selinux_policy
Change-Id: I68b00a6577a01cf04f67b6b277bce6fe1faef618
2023-11-22 02:44:43 +00:00
Donnie Pollitz
6ebd0711a4 Fix SELinux permissions for trusty_userdata partition
Bug: 301677815
Test: Trusty storage port tests passing
Change-Id: Ibbcbd4523e31a3c79035fe16bc1bec3ed60205fa
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-11-21 09:15:50 +01:00
Wilson Sung
9cb23f8b7a Merge "Move vendor_persist_type to vendor" into main 2023-11-21 02:30:00 +00:00
Devika Krishnadas
006925c584 Merge "Add Pixel Mapper as a sp-HAL" into main 2023-11-20 18:17:28 +00:00
Wilson Sung
75f9200a13 Move vendor_persist_type to vendor
radio needs this type

Bug: 312143882
Change-Id: I95b7d4dc0b867234972955eac0be6b8204ce3ecc
2023-11-20 12:34:01 +00:00
Wilson Sung
19c23bb5e4 Merge "Revert "Add IQfpExtendedFingerprint to service_contexts."" into main 2023-11-20 08:42:11 +00:00
Wilson Sung
8eb45bceb6 Revert "Add IQfpExtendedFingerprint to service_contexts."
Revert submission 25333146-sba4500_redux

Reason for revert: BB
Reverted changes: /q/submissionid:25333146-sba4500_redux
Bug: 312087854

Change-Id: I380eabae240d294f6c6ee6f1f0254e5976bc65ea
2023-11-20 06:40:56 +00:00
Kyle Tso
38484e0653 Merge changes from topic "contaminantdisable-sepolicy-main" into main
* changes:
  hal_usb_impl: Add get_prop for vendor_usb_config_prop
  hal_usb_impl: Move hal_usb_impl and hal_usb_gadget_impl to vendor
2023-11-17 03:51:44 +00:00
Kyle Tso
48815490ff hal_usb_impl: Add get_prop for vendor_usb_config_prop
avc:  denied  { read } for  comm="android.hardwar" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=391 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0

Bug: 310560098
Change-Id: I86588715cae2696dd0e045c5b75dde55e0f84c1e
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-11-17 02:53:38 +00:00
Devika Krishnadas
ef01242b5b Add Pixel Mapper as a sp-HAL
Bug: 267352318

Change-Id: Ib1f2b6e10ae4a6b590f6be761e23be859ba46e01
Signed-off-by: Devika Krishnadas <kdevika@google.com>
2023-11-16 01:24:03 +00:00
Chien Kun Niu
84ef937a19 hal_usb_impl: Move hal_usb_impl and hal_usb_gadget_impl to vendor
Move hal_usb_impl and hal_usb_gadget_impl to right space

Bug: 310816620
Change-Id: I04d3710dd7f4e52b204f537de73d18a1351a6836
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-11-15 17:50:29 +08:00
Alec Foster
46d2ea414e Add IQfpExtendedFingerprint to service_contexts.
Bug: 309966766
Bug: 309015469
Test: Fingerprint enroll successfully starts.
Test: adb logcat -b events -e avc -d | grep -iE "qfp"
Change-Id: Ie8f1c55057f8e32bae4db8b5ff22986f77c95dcf
2023-11-10 00:32:05 +00:00
samou
dd2b21c59b Allow dump_power to create thismeal.txt by executing battery_mitigation
Bug: 293899466
Change-Id: I648bd54c7ff0909afaddda45a2f091500ab9227e
Signed-off-by: samou <samou@google.com>
2023-11-03 09:58:26 +00:00
samou
eb67c49ec7 Update odpm scale value sepolicy
Bug: 290149543
Change-Id: I9682a43e3ca1488ef732580fe395b34e32a902cc
Signed-off-by: samou <samou@google.com>
2023-11-02 11:45:35 +00:00
Guibing Cai
2067882407 Merge "zumapro: sepolicy: Update gpu sysfs nodes sepolicies." into main 2023-10-30 16:49:45 +00:00
Daniel Okazaki
52ddf480c5 dump_power: adding dwell defend logs sepolicy
Bug: 306108267
Test: build/flash
Test: adb bugreport
Change-Id: I2dd8cbe12c88c5d5b776e299598d6573a0042711
Signed-off-by: Daniel Okazaki <dtokazaki@google.com>
2023-10-27 18:45:20 +00:00
guibing
cf06992020 zumapro: sepolicy: Update gpu sysfs nodes sepolicies.
Use similar gpu sysfs nodes sepolicies from zuma.

Bug: 300516438
Test: ls -lZ /sys/devices/platform/1f000000.mali
Change-Id: I7190c19c6122bf867a6bde939c4be006ae7432f9
2023-10-27 17:55:45 +00:00
Treehugger Robot
aa3595f165 Merge "Add sepolicy for Bluetooth HAL to access uart and lpm related device nodes" into main 2023-10-27 08:58:24 +00:00
Ted Wang
16dc4769c4 Add sepolicy for Bluetooth HAL to access uart and lpm related device nodes
Bug: 303046044
Test: Manually
Change-Id: I20db519f27c8e59cac0ad326078228c89565550f
2023-10-26 10:06:10 +00:00
samou
30de3456f5 Allow battery_motigation to access gpu cur_freq
Bug: 290149543
Change-Id: Iee0c935194f09dfa960f5b3a701d6e8abc0af17d
Signed-off-by: samou <samou@google.com>
2023-10-26 03:30:53 +00:00
Hiroshi Akiyama
65bb6f7c98 Migrate dump_power.sh to cpp for improved speed
Bug: 299133307
Test: adb bugreport and check dumpstate_board.txt
Change-Id: Ia12b5f4c050a719f994b0f7df8211533d48e0806
Signed-off-by: Hiroshi Akiyama <hiroshiakiyama@google.com>
2023-10-13 18:01:11 -07:00
Kuen-Han Tsai
92083a0f38 genfs_contexts: Modify USB SELinux policies
Add USB wakeup sources sepolicy contexts

Bug: 295128467
Test: Change USB sepolicies and existing tests still pass.
Change-Id: Ic6c693a24c59cc3248d89208268bad6279b50003
Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
2023-10-04 15:44:47 +08:00
Tai Kuo
a3abd5ad39 Allow regmap debugfs for drivers probed by insmod
auditd  : type=1400 audit(0.0:731): avc:  denied  { search } for
comm="modprobe" name="regmap" dev="debugfs" ino=2057
scontext=u:r:insmod-sh:s0 tcontext=u:object_r:vendor_regmap_debugfs:s0
tclass=dir permissive=1 bug=b/274727542

vendor_kernel_boot and vendor_dlkm modules probe by insmod need this.
Move regmap debugfs from legacy/whitechapel_pro/ to vendor/.

Bug: 274727542
Bug: 289012421
Bug: 285343932
Test: ls -d /sys/kernel/debug/regmap/*-0043
Change-Id: I1db7a5a3413467b4e14954d994b071b206fe0300
2023-09-12 16:42:21 +08:00
Hasan Awais
c9a5c03e84 Merge "uwb: add permissions for factory uwb calib file" into main 2023-09-11 21:21:06 +00:00
Tommy Kardach
eb18168d82 Merge "Allow Camera HAL to acquire wake locks" into main 2023-09-11 20:04:11 +00:00
Hasan Awais
3ca2aca558 uwb: add permissions for factory uwb calib file
needed for copying the factory calib file from persist to
/data/vendor/uwb, along with converting the file to a valid format
for uwb HAL

Equivalent CL: ag/22980180

Bug: 296108382
Bug: 296108391
Test: local build passed
Change-Id: I576d21433e2d0b958ef876bd42c382dd2061796e
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-09-11 17:36:08 +00:00
Tommy Kardach
4d8b7ddfd6 Allow Camera HAL to acquire wake locks
Bug: 298439902
Bug: 298272647
Test: manual flash
Change-Id: Ide1bf19ff54e0ce517722c1a028ac946e87ed787
2023-09-08 09:30:55 -07:00
Jack Wu
a43564d968 fix incorrect max_secondary path
Bug: 299268124
Test: data is correct in dumpstate
Change-Id: I198b7117270ef078c698b2c30f479bcb510d6471
Signed-off-by: Jack Wu <wjack@google.com>
2023-09-07 20:10:19 +08:00
Treehugger Robot
fefaa5a45a Merge "Add the common CS40L26 I2C path" into main 2023-09-06 05:59:54 +00:00
Jack Wu
442592fc0c move google,charger SELinux config from legacy to vendor
Bug: 298923686
Test: no Permission denied while accessing the file node
Change-Id: Idea525f8067dd8d74065bcb128da4b25a04113dc
Signed-off-by: Jack Wu <wjack@google.com>
2023-09-05 17:12:38 +08:00
Tai Kuo
2bbb50d15b Add the common CS40L26 I2C path
Bug: 285343932
Test: No AVC denials for vibration and HAL dumpsys
Change-Id: I5a5baf70696748a19618157cd4e466e5f9ac4fdd
2023-09-04 19:28:45 +08:00
Wilson Sung
a202da5e8a sepolicy: allows pixelstat to access pca file nodes
Bug: 298628728
Test: no Permission denied while accessing the file node
Change-Id: I0a2ffa3eb583775fa8e6dae02367d156152ee386
Signed-off-by: Jack Wu <wjack@google.com>
2023-09-04 07:14:52 +00:00
Wilson Sung
863d41f6c6 Move vendor to legacy/zuma/vendor
Bug: 296187211
Change-Id: I28450565c4ee585060387ad988e7efbb1620eaee
2023-09-04 11:07:29 +08:00
Luis Delgado de Mendoza
3e84a7d11f Add sepolicy for chre.wakeup/non-wakeup channels.
Somehow this didn't transfer from previous platforms and needs to be added.

Bug: 296209514
Test: presubmits
Change-Id: I9ccaa515e1be3f882868400d25c2617dd4db61b6
2023-08-29 16:09:57 -07:00
Alec Foster
a0a3bf954f Merge "Add selinux policy for QFP UDFPS." into udc-qpr-dev am: 2ceb44240d am: adf57ce075
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24558016

Change-Id: I5eb748142276e85ad6780381f1b7a528550c8eb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 06:37:04 +00:00
Alec Foster
2ceb44240d Merge "Add selinux policy for QFP UDFPS." into udc-qpr-dev 2023-08-29 04:56:44 +00:00