Commit graph

133 commits

Author SHA1 Message Date
Wilson Sung
d6744d5856 label Extcon files
Fix: 317753346
Test: Boot with target files labeled correctly
Change-Id: I9941ec615c21a16f2235b6abfd8b3e62a0d913b2
2023-12-26 18:26:15 +08:00
Wilson Sung
d4ef02f267 Update error on ROM 11254151
Bug: 317754250
Bug: 317753346
Bug: 317754251
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b139e37942093efe413c78bcf4ccc777c50d371
2023-12-26 09:07:40 +00:00
Wilson Sung
1fe9320c5c Update error on ROM 11253256
Bug: 317735109
Test: SELinuxUncheckedDenialBootTest
Change-Id: I86d5ab2ac42b2014eeffe704ed695112ca6fdce8
2023-12-26 03:42:52 +00:00
Randall Huang
83346b954b storage: remove pixelstats_vendor tracking_denials
Bug: 307468925
Test: pixel/022
Change-Id: I7a1b29e0087cc500db9f7e824b3bda5c68d93d8f
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-12-26 10:53:43 +08:00
Wilson Sung
fb17bd5b94 Update error on ROM 11240525
Bug: 317315498
Bug: 317316031
Test: SELinuxUncheckedDenialBootTest
Change-Id: I9739736d2f5399e9a4d88f8923f095fa223610ff
2023-12-21 07:30:09 +00:00
Chien Kun Niu
14ca9862d2 hal_usb_impl: allow fwk_stats_service
12-18 11:12:58.401   443   443 I auditd  : avc:  denied  { find } for
pid=865 uid=1000 name=android.frameworks.stats.IStats/default
scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:fwk_stats_service:s0
tclass=service_manager permissive=0

Bug: 316989074
Change-Id: I74867901f513926379cd2ba35140a5ccb582467f
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-12-20 11:22:42 +08:00
Wilson Sung
20689064e3 Update error on ROM 11230529
Bug: 316989074
Bug: 316989258
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4a1f615e129ee3a3c2c9a1545ea15bc9ebc246ec
2023-12-19 06:03:26 +00:00
Treehugger Robot
b5908f969a Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into main 2023-12-18 10:41:05 +00:00
Wilson Sung
b818c2835e Merge "Enforce vendor_init and allow tee and display access" into main 2023-12-18 10:09:15 +00:00
Wilson Sung
c90cff2628 Merge "Enforce system_server" into main 2023-12-18 10:09:12 +00:00
Darren Hsu
38c42d88ac sepolicy: allow hal_power_stats to read sysfs_edgetpu
Bug: 316238807
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I5b146cf8bf6fc7b6d135a38a568b016d1e125f2a
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-12-18 18:00:06 +08:00
Treehugger Robot
a3d47e9c02 Merge "Remove dontaudit hal_usb_impl" into main 2023-12-18 08:24:16 +00:00
Wilson Sung
c8be909cd1 Enforce system_server
Fix: 307468690
Fix: 308381611
Test: make selinux_policy
Change-Id: Ie5044b8b18077d4077b7c6c8a16544498368a7d2
2023-12-18 04:48:14 +00:00
Wilson Sung
3d57d2da26 Enforce vendor_init and allow tee and display access
Fix: 307468733
Fix: 308381748
Fix: 312372803
Test: make selinux_policy
Change-Id: Ic9c987e34bf8337e9a743371a00fd910442fab10
2023-12-18 04:42:33 +00:00
Chien Kun Niu
d728e700c5 Remove dontaudit hal_usb_impl
The log does not show anymore.
12-04 08:13:49.098   415   415 I auditd  : avc:  denied  { find }
for pid=841 uid=1000 name=android.frameworks.stats.IStats/default
scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:fwk_stats_service:s0
tclass=service_manager permissive=0

Bug: 314719241
Test: SELinuxUncheckedDenialBootTest

Change-Id: I969dd0cb4d98b14253c74379fed59ac4748c1a5e
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-12-15 17:43:39 +08:00
Wilson Sung
d4ba73d604 Merge "Enforce kernel" into main 2023-12-14 06:09:26 +00:00
Wilson Sung
a74a2a8c46 Update error on ROM 11213495
Bug: 316238807
Test: SELinuxUncheckedDenialBootTest
Change-Id: I07a1655ea915c3a189d6f0e2b2460c8f30db6c01
2023-12-14 02:44:03 +00:00
Wilson Sung
31e85f7c60 Merge "Enforce network_stack" into main 2023-12-13 11:13:15 +00:00
Wilson Sung
3155bae89e Merge "Update error on ROM 11189630" into main 2023-12-11 04:46:58 +00:00
Wilson Sung
7ebbc9cc66 Enforce network_stack
Fix: 307468731
Test: make selinux_policy
Change-Id: I4ddea23199ea7c595d1ba22c8a33aca899275930
2023-12-11 04:46:38 +00:00
Wilson Sung
42505b5257 Enforce kernel
Fix: 307468756
Test: boot and no related avc error
Change-Id: I284531a465cbeb264a04613aa0534cdb7f16dae2
2023-12-11 04:06:26 +00:00
Treehugger Robot
b179da365f Merge "Remove hal_uwb_default tracking denial" into main 2023-12-11 02:56:23 +00:00
Wilson Sung
f2df883237 Update error on ROM 11189630
Bug: 315105050
Test: SELinuxUncheckedDenialBootTest
Change-Id: I41998d0c1a7dc153372692a6a0d0559299ae90d3
2023-12-11 02:37:49 +00:00
Hasan Awais
5fcda36d97 Remove hal_uwb_default tracking denial
Bug: 307468767
Test: avc denials not found with UWB HAL
Change-Id: I2fb9f261d7ae21834acbaaf80dbab8a5ab41aa75
Signed-off-by: Hasan Awais <hasanawais@google.com>
2023-12-08 09:15:11 -08:00
Treehugger Robot
c4e14e8ffa Merge "Add insmod-sh policy" into main 2023-12-08 01:09:35 +00:00
Donnie Pollitz
32d3293bfa Remove tee tracking denial
Bug: 312894027
Bug: 314052376
Test: avc denials not found on boot: see b/312894027
Change-Id: I20c42056948f805e3eb7c6087cf7fde863f78d4e
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-12-07 13:07:17 +00:00
Wilson Sung
bf85d96523 Add insmod-sh policy
Fix: 307468923
Fix: 312372936
Test: make selinux_policy
Change-Id: Icd42c4a74b44b7e593dc7c0598f3d23c3f251a2c
2023-12-07 04:52:04 +00:00
Wilson Sung
b8f2e8f69f Remove uwb app
Bug: 312143882
Change-Id: I3807a60097cae74fb40c726620ef602ebe60e23d
2023-12-05 03:08:10 +00:00
Wilson Sung
eacc300b82 Update error on ROM 11172478
Bug: 314719343
Bug: 314719241
Test: SELinuxUncheckedDenialBootTest
Change-Id: If691fb512b2749ff3e49ca5c766c1e7dc30970a9
2023-12-04 08:47:47 +00:00
Treehugger Robot
2329a86a88 Merge "Add missing legacy genfs_contexts to tracking_denials" into main 2023-11-30 23:24:52 +00:00
Treehugger Robot
d1e65d3c84 Merge "Move service_contexts to vendor and tracking_denials" into main 2023-11-30 23:24:12 +00:00
Treehugger Robot
6825c00c06 Merge "Move legacy property.te to vendor and tracking_denials" into main 2023-11-30 23:22:54 +00:00
Treehugger Robot
f86a7057ef Merge "Move legacy property_contexts to vendor and tracking_denials" into main 2023-11-30 23:22:12 +00:00
Wilson Sung
c459e19f9f Add missing legacy genfs_contexts to tracking_denials
Bug: 312143882
Bug: 314036372
Test: make selinux_policy
Change-Id: If7ff2d5c93f8531998ec7f00862e4dc175ac383a
2023-11-30 18:35:46 +00:00
Wilson Sung
4e44355a8d Move service_contexts to vendor and tracking_denials
Bug: 312143882
Bug: 314080507
Test: make selinux_policy
Change-Id: Ia8474dc880c912b9a3db4401551a3eeed280bb47
2023-11-30 09:57:15 +00:00
Wilson Sung
1f829bd3f9 Move legacy property.te to vendor and tracking_denials
Bug: 312143882
Bug: 314065301
Test: make selinux_policy
Change-Id: I1e414cb04b71bf9aa47f8b60a78aad220bdf21b6
2023-11-30 09:11:00 +00:00
Wilson Sung
c467c70f33 Move legacy property_contexts to vendor and tracking_denials
Bug: 312143882
Bug: 314065298
Test: make selinux_policy
Change-Id: Ica7bbd24df3959af917896dbdc43d352e33add43
2023-11-30 08:48:52 +00:00
Wilson Sung
81b4d82d4c Remove unused rls_service
Binary not existed

Bug: 312143882
Test: make selinux_policy
Change-Id: If51749d9c0b12d1a5ac8f3070cef30557202bdf8
2023-11-30 08:38:34 +00:00
Treehugger Robot
b429bebad7 Merge "Update error on ROM 11140098" into main 2023-11-30 07:46:21 +00:00
Treehugger Robot
dde9116594 Merge "Move legacy genfs_contexts to vendor" into main 2023-11-30 07:33:04 +00:00
Treehugger Robot
dca7f0c3c4 Merge "Move legacy file.te to vendor and tracking_denials" into main 2023-11-30 07:33:03 +00:00
Wilson Sung
b5238ed0fe Update error on ROM 11140098
Bug: 314052376
Test: SELinuxUncheckedDenialBootTest
Change-Id: I272af5fec9f9beb2ce62ffd29e1fc99fdfc1acc7
2023-11-30 06:58:30 +00:00
Wilson Sung
e531406f68 Move legacy file.te to vendor and tracking_denials
Bug: 312143882
Bug: 314035704
Test: make selinux_policy
Change-Id: Ibf5ac4c3e06bb2f5aab44e59073156181ab0b5a1
2023-11-30 05:07:58 +00:00
Wilson Sung
4ab2964a03 Move legacy genfs_contexts to vendor
Bug: 312143882
Bug: 314036370
Test: make selinux_policy
Change-Id: I5846fb7b26eee3ddc7c7ac67f6b60f4357ec3608
2023-11-30 05:05:48 +00:00
Wilson Sung
be32c237af Move legacy file_contexts to tracking_denials
Bug: 312143882
Bug: 314036372
Test: make selinux_policy
Change-Id: If8f325e6e0c9ffa1bfb463686d1df6ed82abd804
2023-11-30 05:05:28 +00:00
Treehugger Robot
a47912cabc Merge "trusty: Fix selinux denials for block devices" into main 2023-11-29 02:37:08 +00:00
Donnie Pollitz
662dc87e32 trusty: Fix selinux denials for block devices
Bug: 312894027
Test: Confirmed avc denial is gone on boot
Change-Id: Iaa87cdef24214a2b6f6eba2af917c03bbbb4bfb5
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-11-28 09:20:41 +01:00
Kamal Shafi
83f48c2556 sepolicy: move lwis dev sepolicy to device folder
- Remove lwis dev device specific sepolicy from zumapro

Bug: 312869113
Test: build
Change-Id: I12e8e703fb3a58a5be4f4b6dd0ade188cf4d8c0e
2023-11-27 10:09:13 +00:00
Wilson Sung
2dc63cb5cd Update error on ROM 11137748
Bug: 312894027
Test: SELinuxUncheckedDenialBootTest
Change-Id: I410a8f4717ef0cdb6298b5a26d48dd919cdd4c14
2023-11-23 10:49:03 +00:00
Treehugger Robot
60b251ed89 Merge "Move legacy app config to tracking_denials" into main 2023-11-22 23:26:29 +00:00