Commit graph

275 commits

Author SHA1 Message Date
Wilson Sung
08e5f90427 Remove UDFPS GHBM/LHBM property
Bug: 312143882
Test: make selinux_policy
Change-Id: I081a6ea005b05b43b0c7a56859c6a804c16a0bce
2023-11-22 03:40:37 +00:00
Wilson Sung
eddd28d140 Remove unused vendor_toe_device
Bug: 312143882
Test: make selinux_policy
Change-Id: I3298675615a0e75218be4cf4dac1a04f6aeeafe0
2023-11-22 03:37:16 +00:00
Wilson Sung
c967ee5dc3 Move sg_device related policy
Bug: 312143882
Test: make selinux_policy
Change-Id: I68b00a6577a01cf04f67b6b277bce6fe1faef618
2023-11-22 02:44:43 +00:00
Treehugger Robot
7a0d1c626e Merge "Label bootanim.color property" into main 2023-11-22 01:58:13 +00:00
Wilson Sung
afa1494fc6 Label bootanim.color property
Bug: 312143882
Test: make selinux_policy
Change-Id: Ie585dc92818e9dab81cfd6a2713e8114d272cd19
2023-11-21 10:58:51 +00:00
Donnie Pollitz
6ebd0711a4 Fix SELinux permissions for trusty_userdata partition
Bug: 301677815
Test: Trusty storage port tests passing
Change-Id: Ibbcbd4523e31a3c79035fe16bc1bec3ed60205fa
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-11-21 09:15:50 +01:00
Wilson Sung
74e5d6a064 Update error on ROM 11126833
Bug: 312372803
Bug: 312373134
Bug: 312372857
Bug: 312372936
Test: SELinuxUncheckedDenialBootTest
Change-Id: I162a984f233f245410fc04c2b94cf73a3e22a428
2023-11-21 07:16:32 +00:00
Wilson Sung
9cb23f8b7a Merge "Move vendor_persist_type to vendor" into main 2023-11-21 02:30:00 +00:00
Wilson Sung
7ce20ed41e Merge "Remove batt and NFC unused type" into main 2023-11-21 02:29:52 +00:00
Treehugger Robot
27c50c200e Merge "Remove legacy bug_map" into main 2023-11-20 23:14:24 +00:00
Devika Krishnadas
006925c584 Merge "Add Pixel Mapper as a sp-HAL" into main 2023-11-20 18:17:28 +00:00
Wilson Sung
3178313292 Remove batt and NFC unused type
Bug: 312143882
Test: make selinux_policy
Change-Id: I88ca31d5893143f8f368f576ef4b78e6219bbb74
2023-11-20 12:47:52 +00:00
Wilson Sung
574b29f866 Remove legacy bug_map
Bug: 312143882
Change-Id: Ic1102158edabae74aaca7c6d32b3ff3afe0c8710
2023-11-20 12:36:34 +00:00
Wilson Sung
75f9200a13 Move vendor_persist_type to vendor
radio needs this type

Bug: 312143882
Change-Id: I95b7d4dc0b867234972955eac0be6b8204ce3ecc
2023-11-20 12:34:01 +00:00
Wilson Sung
91dcd6ba19 Merge "Update error on ROM 11120060" into main 2023-11-20 12:01:27 +00:00
Wilson Sung
19c23bb5e4 Merge "Revert "Add IQfpExtendedFingerprint to service_contexts."" into main 2023-11-20 08:42:11 +00:00
Wilson Sung
8eb45bceb6 Revert "Add IQfpExtendedFingerprint to service_contexts."
Revert submission 25333146-sba4500_redux

Reason for revert: BB
Reverted changes: /q/submissionid:25333146-sba4500_redux
Bug: 312087854

Change-Id: I380eabae240d294f6c6ee6f1f0254e5976bc65ea
2023-11-20 06:40:56 +00:00
Wilson Sung
db4d015590 Update error on ROM 11120060
Bug: 312069580
Test: SELinuxUncheckedDenialBootTest
Change-Id: I94d03d02552f8ac8cad106f72917573b6027df73
2023-11-20 03:20:56 +00:00
Kyle Tso
38484e0653 Merge changes from topic "contaminantdisable-sepolicy-main" into main
* changes:
  hal_usb_impl: Add get_prop for vendor_usb_config_prop
  hal_usb_impl: Move hal_usb_impl and hal_usb_gadget_impl to vendor
2023-11-17 03:51:44 +00:00
Kyle Tso
48815490ff hal_usb_impl: Add get_prop for vendor_usb_config_prop
avc:  denied  { read } for  comm="android.hardwar" name="u:object_r:vendor_usb_config_prop:s0" dev="tmpfs" ino=391 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:vendor_usb_config_prop:s0 tclass=file permissive=0

Bug: 310560098
Change-Id: I86588715cae2696dd0e045c5b75dde55e0f84c1e
Signed-off-by: Kyle Tso <kyletso@google.com>
2023-11-17 02:53:38 +00:00
Tim Lin
648fffe4e8 Merge "sepolicy: define vendor_satellite_service domain" into main 2023-11-16 23:47:24 +00:00
YiKai Peng
411639b38b Merge "sepolicy: remove tracking_denials/hal_wireless_charger.te" into main 2023-11-16 09:57:16 +00:00
Devika Krishnadas
ef01242b5b Add Pixel Mapper as a sp-HAL
Bug: 267352318

Change-Id: Ib1f2b6e10ae4a6b590f6be761e23be859ba46e01
Signed-off-by: Devika Krishnadas <kdevika@google.com>
2023-11-16 01:24:03 +00:00
Alec Foster
d3dc68df1b Merge "Add IQfpExtendedFingerprint to service_contexts." into main 2023-11-16 00:41:15 +00:00
Chien Kun Niu
84ef937a19 hal_usb_impl: Move hal_usb_impl and hal_usb_gadget_impl to vendor
Move hal_usb_impl and hal_usb_gadget_impl to right space

Bug: 310816620
Change-Id: I04d3710dd7f4e52b204f537de73d18a1351a6836
Signed-off-by: Chien Kun Niu <rickyniu@google.com>
2023-11-15 17:50:29 +08:00
YiKai Peng
453f8f58ff sepolicy: remove tracking_denials/hal_wireless_charger.te
Bug: 307468561
Test: Build/Flash
Change-Id: I36c20bc37329d33fa79dfe35434b773afc4b2324
Signed-off-by: YiKai Peng <kenpeng@google.com>
2023-11-15 08:35:27 +00:00
Megha Patil
48735bb478 Add a new property to track the current Binary
new propert to mirror the current binary
Bug: b/311102904

Test: Test the Enable Satellite Api
Change-Id: I0e207e8e9c48b0b081fb76a252649e7e0dc07210
2023-11-15 05:55:57 +00:00
Avinash Malipatil
ec2f055771 Merge "SEPolicy change to allow ImsMedia to set priority of audio threads." into main 2023-11-15 04:06:59 +00:00
Avinash Malipatil
6b3841bea3 SEPolicy change to allow ImsMedia to set priority of audio threads.
Setting real-time thread priority for audio threads is a must to handle voice stream during vowifi calls.

AVC Error: auditd  : avc:  denied  { find } for pid=9346 uid=1001 name=scheduling_policy scontext=u:r:radio:s0 tcontext=u:object_r:scheduling_policy_service:s0 tclass=service_manager permissive=0

Bug: 309727903
Bug: 308517246

Test: adb shell 'ps -Tl -p '
Change-Id: Ib37aa1018ee63433ad878d1319a0c8158754befd
2023-11-14 15:55:17 +00:00
Daniel Norman
f6ee9c4b50 Removes duplicate hidraw_device type definition.
This type is now defined by the platform.

Bug: 303522222
Change-Id: I1a53405c7b6f12d6318a7808fa2cb61e02696cba
Test: ls -z /dev/hidraw0
2023-11-10 22:52:51 +00:00
Alec Foster
46d2ea414e Add IQfpExtendedFingerprint to service_contexts.
Bug: 309966766
Bug: 309015469
Test: Fingerprint enroll successfully starts.
Test: adb logcat -b events -e avc -d | grep -iE "qfp"
Change-Id: Ie8f1c55057f8e32bae4db8b5ff22986f77c95dcf
2023-11-10 00:32:05 +00:00
Treehugger Robot
fac134469c Merge "Remove unused CS40L26 I2C paths" into main 2023-11-08 11:08:32 +00:00
Wilson Sung
c67fe4c115 Update error on ROM 11063387
Bug: 309732305
Test: SELinuxUncheckedDenialBootTest
Change-Id: Ie6ba6830346630f851bc2db7b5965686e865edb5
2023-11-08 16:06:29 +08:00
Mike Wang
5d3838f1eb Change the MDS to platform app in selinux ap context.
The MDS will be signed with platform key and become a platform app. To
make the selinux rules for modem_diagnostic_app work, need to set it to
platform app in app context.

Bug: 287683516

Test: Tested with both dev key or platform key signed MDS apps and the selinux rules works.
Change-Id: I19cce0963d85fd156e54f3c530431e1d465054b3
2023-11-08 05:19:22 +00:00
Jenny Ho
59b9e9ce4e sepolicy: remove tracking_denials/hal_health_default.te
local check there is no hal_health_default related sepolicy
error log, remove related .te file.

Bug: 307468788
Change-Id: I8c12a2fb76241f9c9f096dddbf3a81f5f041359b
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-11-07 16:14:10 +00:00
Weizhung Ding
1b4f6b7035 Merge "sync legacy sysfs_display permission" into main 2023-11-07 08:32:12 +00:00
Wilson Sung
1755eb8be7 Merge "Update error on ROM 11060498" into main 2023-11-07 07:30:00 +00:00
Treehugger Robot
cd12e6947e Merge "sensors: Move USF related sepolicy to gs-common." into main 2023-11-07 06:49:08 +00:00
Wilson Sung
c56335f89d Update error on ROM 11060498
Bug: 309551158
Bug: 309551159
Bug: 309550514
Bug: 309550905
Bug: 309551062
Test: SELinuxUncheckedDenialBootTest
Change-Id: Ic8d05cea6a18c240f9fcf801ceaeabe3f51ae03c
2023-11-07 05:41:43 +00:00
Rick Chen
e759711bf5 sensors: Move USF related sepolicy to gs-common.
Bug: 305120274
Test: Compile pass.
Change-Id: Id2d47bcf49d21bc7144145d07fd54bddf3e9033c
Signed-off-by: Rick Chen <rickctchen@google.com>
2023-11-06 23:20:31 +08:00
Weizhung Ding
873751ee60 sync legacy sysfs_display permission
Test: build
Bug: 308381451
Change-Id: I470500ec44b08bcb2c106d27100bef0a9e301742
2023-11-06 14:03:25 +00:00
Sam Ou
b3aafb8368 Merge changes from topic "thismeal_enhancement" into main
* changes:
  Allow dump_power to create thismeal.txt by executing battery_mitigation
  Update odpm scale value sepolicy
2023-11-06 10:36:49 +00:00
Tai Kuo
956c643267 Remove unused CS40L26 I2C paths
Bug: 285343932
Bug: 307468462
Test: No AVC denials.
Change-Id: Id25e88e536500b9c205acf87900b597d611a9b63
2023-11-06 17:56:58 +08:00
Wilson Sung
a7a818547a Merge "Update error on ROM 11021299" into main 2023-11-06 09:35:26 +00:00
Wilson Sung
94b82378b6 Update error on ROM 11021299
Bug: 308380763
Bug: 308381394
Bug: 308381432
Bug: 308381409
Bug: 308381338
Bug: 308381747
Bug: 308381292
Bug: 308381668
Bug: 308381451
Bug: 308381687
Bug: 308381222
Bug: 308381263
Bug: 308381279
Bug: 308381611
Bug: 308381748
Test: SELinuxUncheckedDenialBootTest
Change-Id: If24f3fcb5a1830ef834119d05e49f23193ae132e
2023-11-06 08:16:57 +00:00
Mike Wang
3c9256f338 Merge "Add selinux policy change to allow MDS access Samsung OemRil hal." into main 2023-11-06 02:30:55 +00:00
samou
dd2b21c59b Allow dump_power to create thismeal.txt by executing battery_mitigation
Bug: 293899466
Change-Id: I648bd54c7ff0909afaddda45a2f091500ab9227e
Signed-off-by: samou <samou@google.com>
2023-11-03 09:58:26 +00:00
mikeyuewang
eed49f4c46 Add selinux policy change to allow MDS access Samsung OemRil hal.
Bug: 301641283

selinux log:
11-03 15:32:38.850  2643  2643 I auditd  : type=1400 audit(0.0:1616): avc:  denied  { call } for  comm="binder:2643_3" scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:r:rild:s0 tclass=binder permissive=1 app=com.google.mds
11-03 15:32:38.850  2643  2643 I binder:2643_3: type=1400 audit(0.0:1616): avc:  denied  { call } for  scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:r:rild:s0 tclass=binder permissive=1 app=com.google.mds
11-03 15:32:38.854  2643  2643 I auditd  : type=1400 audit(0.0:1617): avc:  denied  { transfer } for  comm="binder:2643_3" scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:r:rild:s0 tclass=binder permissive=1 app=com.google.mds
11-03 15:32:38.854  2643  2643 I binder:2643_3: type=1400 audit(0.0:1617): avc:  denied  { transfer } for  scontext=u:r:modem_diagnostic_app:s0:c512,c768 tcontext=u:r:rild:s0 tclass=binder permissive=1 app=com.google.mds
11-03 15:32:38.854  1095  1095 I auditd  : type=1400 audit(0.0:1618): avc:  denied  { call } for  comm="HwBinder:1095_1" scontext=u:r:rild:s0 tcontext=u:r:modem_diagnostic_app:s0:c512,c768 tclass=binder permissive=1
11-03 15:32:38.854  1095  1095 I HwBinder:1095_1: type=1400 audit(0.0:1618): avc:  denied  { call } for  scontext=u:r:rild:s0 tcontext=u:r:modem_diagnostic_app:s0:c512,c768 tclass=binder permissive=1


Change-Id: Ia71844db230302fd3120b28b3ade2e55443ec078
2023-11-03 07:36:16 +00:00
samou
eb67c49ec7 Update odpm scale value sepolicy
Bug: 290149543
Change-Id: I9682a43e3ca1488ef732580fe395b34e32a902cc
Signed-off-by: samou <samou@google.com>
2023-11-02 11:45:35 +00:00
Sungwoo choi
b750cf8179 sepolicy: define vendor_satellite_service domain
vendor_satellite_service domain is for VendorSatelliteService.
  package: com.samsung.slsi.telephony.satelliteservice
  policy: vendor_satellite_service.te

Bug: 303240366
Bug: 304696411
Test: make

Change-Id: Ib7024d0397eda6d7f4e0809a1824dc550948207d
Signed-off-by: Sungwoo choi <sungwoo48.choi@samsung.com>
2023-10-31 20:06:44 +08:00