Commit graph

517 commits

Author SHA1 Message Date
Hung-Yeh Lee
5a8206a8e4 sepolicy: add persist.vendor.primarydisplay. to vendor_display_prop
Copy sepolicy from zuma to fix the following avc denied:
auditd  : type=1107 audit(0.0:11): uid=0 auid=4294967295
ses=4294967295 subj=u:r:init:s0 msg='avc: denied  { set } for
property=persist.vendor.primarydisplay.op.peak_refresh_rate pid=510
uid=1000 gid=1003 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:vendor_default_prop:s0
tclass=property_service permissive=0'

Bug: 286063708
Bug: 286063029
Bug: 317754250
Test: Run VtsHalGraphicsComposer3_TargetTest
Change-Id: Ib5e83927ebebf05a640d127d9d11e94df101f224
2024-01-03 11:58:04 +08:00
Wilson Sung
cc395b9c2b Update error on ROM 11262681
Bug: 318308344
Test: SELinuxUncheckedDenialBootTest
Change-Id: Iafeb3ff1bc6ddeb93810bff26aff82399bcda679
2024-01-02 03:23:04 +00:00
Treehugger Robot
f64c0520fe Merge "Allow systemui to write protolog file" into main 2023-12-29 11:32:37 +00:00
Treehugger Robot
fe24ab7d3f Merge "Update error on ROM 11260603" into main 2023-12-29 09:58:35 +00:00
Wilson Sung
2b26409d08 Update error on ROM 11260603
Bug: 318033504
Test: SELinuxUncheckedDenialBootTest
Change-Id: I86190052aaaebc94f1eb7e670e1a7da312d537a3
2023-12-29 05:04:50 +00:00
Wilson Sung
720ab6329b Update error on ROM 11259228
Bug: 318032188
Test: SELinuxUncheckedDenialBootTest
Change-Id: I6d3f31d49cc64ee911367de6e61d5e4e1b7e280b
2023-12-29 04:33:07 +00:00
Wilson Sung
bdb5c3c383 Merge changes I1c22cd8a,I11427ca4 into main
* changes:
  Enforce system_suspend
  Enforce fastbootd
2023-12-27 13:38:16 +00:00
Wilson Sung
df88fd4e1c Add dc-main wakeup node
Bug: 308381292
Test: boot-to-home
Change-Id: I0165b4afab3b62bf4fec4ce6864cc1e8c6fc841a
2023-12-27 16:42:52 +08:00
Wilson Sung
594b74b447 Enforce system_suspend
Bug: 308381292
Test: boot-to-home
Change-Id: I1c22cd8af868183afbfe567a31af6069b81eebe0
2023-12-27 14:16:49 +08:00
Wilson Sung
415278abac Enforce fastbootd
Fix: 307468887
Test: boot-to-home and flash rom
Change-Id: I11427ca4d17a83c278463cc68e4935148a0d57b6
2023-12-27 13:52:31 +08:00
Wilson Sung
4cad299072 Allow systemui to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui the write access to
  wm_trace_data_file

Bug: 251513116
Bug: 288049075
Test: make sepolicy
Change-Id: I47c9bbf13835b2e7eaac3e2b436e3b486ce02431
2023-12-27 10:59:28 +08:00
Wilson Sung
8345799166 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-12-27 10:41:21 +08:00
Wilson Sung
2b70f82f1d Move kernel from legacy to vendor
Bug: 312143882
Test: make sepolicy
Change-Id: I01b192c7d60cda8e52f6a3fffd5e0dec7a660172
2023-12-27 10:40:47 +08:00
Treehugger Robot
7f7d16f2e7 Merge "Enforce servicemanager" into main 2023-12-26 23:19:40 +00:00
Treehugger Robot
4998611c70 Merge "Enforce sysUI" into main 2023-12-26 23:19:04 +00:00
Treehugger Robot
594a751d77 Merge "label Extcon files" into main 2023-12-26 23:17:40 +00:00
Wilson Sung
744d309e44 Add wakeup node
Fix: 308381292
Test: make sepolicy
Change-Id: I32a45a3b862ffbe9f53f88ca97bdad52e5678931
2023-12-26 17:38:34 +00:00
Wilson Sung
050406d4bc Enforce servicemanager
Fix: 307468945
Test: make sepolicy
Change-Id: I2bad0fcac1d7a6388fb9790bcc9fcbe4cdb31a4a
2023-12-26 21:32:08 +08:00
Wilson Sung
2dad12b041 Enforce sysUI
Fix: 307468867
Test: boot-to-home
Change-Id: Ie6d28c523e905bc850ab8ce0fe22fd51b762bb80
2023-12-26 12:48:10 +00:00
Wilson Sung
d6744d5856 label Extcon files
Fix: 317753346
Test: Boot with target files labeled correctly
Change-Id: I9941ec615c21a16f2235b6abfd8b3e62a0d913b2
2023-12-26 18:26:15 +08:00
Wilson Sung
d4ef02f267 Update error on ROM 11254151
Bug: 317754250
Bug: 317753346
Bug: 317754251
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4b139e37942093efe413c78bcf4ccc777c50d371
2023-12-26 09:07:40 +00:00
Wilson Sung
1fe9320c5c Update error on ROM 11253256
Bug: 317735109
Test: SELinuxUncheckedDenialBootTest
Change-Id: I86d5ab2ac42b2014eeffe704ed695112ca6fdce8
2023-12-26 03:42:52 +00:00
Randall Huang
83346b954b storage: remove pixelstats_vendor tracking_denials
Bug: 307468925
Test: pixel/022
Change-Id: I7a1b29e0087cc500db9f7e824b3bda5c68d93d8f
Signed-off-by: Randall Huang <huangrandall@google.com>
2023-12-26 10:53:43 +08:00
Chi Zhang
001dd4139e Merge "Allow GRIL to get power stats." into main 2023-12-22 19:29:06 +00:00
Virkumar Karavate
727f2b5468 Merge "Allow pixelntnservice accessing SubscriptionManager" into main 2023-12-22 03:21:52 +00:00
Wilson Sung
3c5bb2ab43 Allow systemui_app access statsmanager_service
Bug: 283841311
Bug: 308381668
Fix: 308381668
Test: make sepolicy
Change-Id: I71888ee14637ab10d983709a4c74d8186d77d4bd
2023-12-21 11:25:37 +00:00
Wilson Sung
fb17bd5b94 Update error on ROM 11240525
Bug: 317315498
Bug: 317316031
Test: SELinuxUncheckedDenialBootTest
Change-Id: I9739736d2f5399e9a4d88f8923f095fa223610ff
2023-12-21 07:30:09 +00:00
Lei Ju
df72029b33 [zumapro] Remove duplicated file context settings for chre HAL
Bug: 248615564
Test: compilation
Change-Id: If21138ee1f85e1832ff3bf9a6d8dc16206f3b0ed
2023-12-20 16:46:33 -08:00
Treehugger Robot
e7795ba5ad Merge "hal_usb_impl: allow fwk_stats_service" into main 2023-12-20 06:05:25 +00:00
Chien Kun Niu
14ca9862d2 hal_usb_impl: allow fwk_stats_service
12-18 11:12:58.401   443   443 I auditd  : avc:  denied  { find } for
pid=865 uid=1000 name=android.frameworks.stats.IStats/default
scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:fwk_stats_service:s0
tclass=service_manager permissive=0

Bug: 316989074
Change-Id: I74867901f513926379cd2ba35140a5ccb582467f
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-12-20 11:22:42 +08:00
Zheng Pan
65e8b1c4df Merge "Revert "Move kernel from legacy to vendor"" into main 2023-12-20 02:44:25 +00:00
Zheng Pan
58f2081f97 Revert "Move kernel from legacy to vendor"
This reverts commit cbfa33fd92.

Reason for revert: b/317131577

Change-Id: Iafd9dc574c59f627b049ad7a955173d562d1444e
2023-12-20 02:32:04 +00:00
Chi Zhang
62184e7953 Allow GRIL to get power stats.
SELinux : avc:  denied  { find } for pid=3147 uid=10219 name=android.hardware.power.stats.IPowerStats/default scontext=u:r:grilservice_app:s0:c219,c256,c512,c768 tcontext=u:object_r:hal_power_stats_service:s0 tclass=service_manager permissive=1

Bug: 286187143
Test: build and boot
Change-Id: I42c78a68a145c4f390e43c457a241b7c8db577bf
2023-12-19 12:22:22 -08:00
Wilson Sung
20689064e3 Update error on ROM 11230529
Bug: 316989074
Bug: 316989258
Test: SELinuxUncheckedDenialBootTest
Change-Id: I4a1f615e129ee3a3c2c9a1545ea15bc9ebc246ec
2023-12-19 06:03:26 +00:00
Treehugger Robot
ab36ea0ced Merge "Move kernel from legacy to vendor" into main 2023-12-18 23:22:26 +00:00
Treehugger Robot
b5908f969a Merge "sepolicy: allow hal_power_stats to read sysfs_edgetpu" into main 2023-12-18 10:41:05 +00:00
Wilson Sung
b818c2835e Merge "Enforce vendor_init and allow tee and display access" into main 2023-12-18 10:09:15 +00:00
Wilson Sung
c90cff2628 Merge "Enforce system_server" into main 2023-12-18 10:09:12 +00:00
Darren Hsu
38c42d88ac sepolicy: allow hal_power_stats to read sysfs_edgetpu
Bug: 316238807
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I5b146cf8bf6fc7b6d135a38a568b016d1e125f2a
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-12-18 18:00:06 +08:00
Treehugger Robot
a3d47e9c02 Merge "Remove dontaudit hal_usb_impl" into main 2023-12-18 08:24:16 +00:00
Wilson Sung
cbfa33fd92 Move kernel from legacy to vendor
Bug: 312143882
Test: make sepolicy
Change-Id: I2ceb675b124aeeca2d94dd9c6095f0026df5a4bf
2023-12-18 07:56:26 +00:00
Wilson Sung
c8be909cd1 Enforce system_server
Fix: 307468690
Fix: 308381611
Test: make selinux_policy
Change-Id: Ie5044b8b18077d4077b7c6c8a16544498368a7d2
2023-12-18 04:48:14 +00:00
Wilson Sung
3d57d2da26 Enforce vendor_init and allow tee and display access
Fix: 307468733
Fix: 308381748
Fix: 312372803
Test: make selinux_policy
Change-Id: Ic9c987e34bf8337e9a743371a00fd910442fab10
2023-12-18 04:42:33 +00:00
KRIS CHEN
7d98399d40 Merge "fingerprint: fix SELinux denials" into main 2023-12-18 03:27:57 +00:00
Chien Kun Niu
d728e700c5 Remove dontaudit hal_usb_impl
The log does not show anymore.
12-04 08:13:49.098   415   415 I auditd  : avc:  denied  { find }
for pid=841 uid=1000 name=android.frameworks.stats.IStats/default
scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:fwk_stats_service:s0
tclass=service_manager permissive=0

Bug: 314719241
Test: SELinuxUncheckedDenialBootTest

Change-Id: I969dd0cb4d98b14253c74379fed59ac4748c1a5e
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-12-15 17:43:39 +08:00
chenkris
a7c90de740 fingerprint: fix SELinux denials
Fix following AVC denials:
1. Could not enable service: File /vendor/bin/hw/android.hardware.biometrics.fingerprint-service.goodix(labeled "u:object_r:vendor_file:s0") has incorrect label or no domain transition from u:r:init:s0 to another SELinux domain defined
2. Could not start service 'vendor.fps_hal' as part of class 'late_start': File /vendor/bin/hw/android.hardware.biometrics.fingerprint@2.1-service.goodix(labeled "u:object_r:vendor_file:s0") has incorrect label or no domain transition from u:r:init:s0 to another SELinux domain defined.
3. avc:  denied  { ioctl } for  path="/dev/goodix_fp" dev="tmpfs" ino=1499 ioctlcmd=0x6701 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=1

Bug: 315737323
Test: boot with no relevant error
Change-Id: Ideeac108b8470232a258254437086451550fcc8d
2023-12-15 07:58:49 +00:00
Wilson Sung
d4ba73d604 Merge "Enforce kernel" into main 2023-12-14 06:09:26 +00:00
Treehugger Robot
8eeb0e8997 Merge "Update error on ROM 11213495" into main 2023-12-14 05:31:05 +00:00
Wilson Sung
8f63998c24 Merge "Move dump_gsa to vendor" into main 2023-12-14 03:57:13 +00:00
Wilson Sung
a74a2a8c46 Update error on ROM 11213495
Bug: 316238807
Test: SELinuxUncheckedDenialBootTest
Change-Id: I07a1655ea915c3a189d6f0e2b2460c8f30db6c01
2023-12-14 02:44:03 +00:00