Commit graph

761 commits

Author SHA1 Message Date
Treehugger Robot
b10f81a6ad Merge "Move coredomain seapp contexts to system_ext" into main 2023-08-11 05:00:10 +00:00
Inseob Kim
63200470b8 Move coredomain seapp contexts to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble
violation.

Bug: 280547417
Test: TH
Change-Id: Ifcaa41df790cb2b720775563cc4cd5cdf10e5c50
2023-08-10 17:00:56 +09:00
Wilson Sung
253b166ae9 Permissive systemui during bringup stage am: 08dbe5a438 am: 76e8935bbd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24324496

Change-Id: I1ef00a14537cbb75ee48a8e375db6d963128af15
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 02:24:16 +00:00
Wilson Sung
76e8935bbd Permissive systemui during bringup stage am: 08dbe5a438
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24324496

Change-Id: If650c51dda5b996d77779394b1d54f08fb327c0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 01:40:33 +00:00
Wilson Sung
08dbe5a438 Permissive systemui during bringup stage
Bug: 294300348
Change-Id: I83fcda2cfd3d683cd6c36132e497e9d17a44efe5
2023-08-08 17:51:31 +08:00
Randall Huang
9a9e914b69 Merge "[Cleanup]: Move gxp sepolicies to gs-common" into main 2023-08-01 02:53:18 +00:00
Jenny Ho
d614bc2241 add permission for dc-mains am: ad31020715 am: da1b083bc3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24250060

Change-Id: Idc4b120992c9a1281c5fd2e70231e7dd807c6fe1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-31 23:50:29 +00:00
Jenny Ho
da1b083bc3 add permission for dc-mains am: ad31020715
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24250060

Change-Id: Ibc88cf2185039d68bb501f4b7341e580ba4f8f71
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-31 23:04:58 +00:00
Dinesh Yadav
42c99d739e [Cleanup]: Move gxp sepolicies to gs-common
These policies are moved to gs-common as part of ag/24002524

Bug: 288368306
Change-Id: I38f6e695e6f896c094275455cf3c0d79d0b1820f
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-07-31 10:46:25 +00:00
Jenny Ho
ad31020715 add permission for dc-mains
Bug: 290542674
Change-Id: I30bb1e796b1863c035b2c4b4baa7695a80a31d60
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-07-31 16:11:10 +08:00
Jenny Ho
f9d55c5ae9 Merge "Add sepolicy to allow dump battery charger and FG data" into udc-qpr-dev am: 01401737a7 am: d4c26880c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24127765

Change-Id: I21a2cac6a63553b3f8206ca4de4b5a6c53535039
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-20 09:35:18 +00:00
Jenny Ho
d4c26880c5 Merge "Add sepolicy to allow dump battery charger and FG data" into udc-qpr-dev am: 01401737a7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24127765

Change-Id: I86db84fa405e70c89c8195e5ce9957e17c4b4fde
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-20 08:49:24 +00:00
Jenny Ho
01401737a7 Merge "Add sepolicy to allow dump battery charger and FG data" into udc-qpr-dev 2023-07-20 08:14:28 +00:00
Utku Utkan
c063206e8b Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: c0ed974888 am: 7bdc153b15
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24123701

Change-Id: I1cfee20345fc93ed265ae3fcb40c32da54aecb09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 19:58:34 +00:00
Utku Utkan
7bdc153b15 Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices" am: c0ed974888
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24123701

Change-Id: Iaca7b7523c1ddfeddc236b41a9805ed9b67976f4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 18:49:47 +00:00
Jenny Ho
207d448245 Add sepolicy to allow dump battery charger and FG data
W cat     : type=1400 audit(0.0:308): avc:  denied  { read } for  name="registers_dump" dev="sysfs" ino=78205 scontext=u:r:dump_power:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
W cat     : type=1400 audit(0.0:309): avc:  denied  { read } for  name="registers" dev="debugfs" ino=33 scontext=u:r:dump_power:s0 tcontext=u:object_r:debugfs:s0 tclass=file permissive=0
W cat     : type=1400 audit(0.0:311): avc:  denied  { read } for  name="model_ok" dev="debugfs" ino=26186 scontext=u:r:dump_power:s0 tcontext=u:object_r:debugfs:s0 tclass=file permissive=0
W cat     : type=1400 audit(0.0:312): avc:  denied  { read } for  name="registers" dev="debugfs" ino=26192 scontext=u:r:dump_power:s0 tcontext=u:object_r:debugfs:s0 tclass=file permissive=0
W cat     : type=1400 audit(0.0:313): avc:  denied  { read } for  name="debug_registers" dev="debugfs" ino=26193 scontext=u:r:dump_power:s0 tcontext=u:object_r:debugfs:s0 tclass=file permissive=0

Bug: 290542674
Change-Id: I7d8fa1efdf9c1c233643089273ddfd786b44ce15
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-07-19 11:51:34 +00:00
Utku Utkan
c0ed974888 Revert^2 "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Reason for revert: Relanding the original topic after copying the certificates under `device/google` for `without-vendor` branches

Reverted changes: /q/submissionid:24122569-revert-24056607-pixel-camera-services-extensions-sepolicy-OFSULTXSBL

Bug: 287069860
Test: m && flashall
Change-Id: I01fc4a31db761cb3dbb5dc93eb9e0b4d569b82f7
2023-07-18 20:37:58 -07:00
Inseob Kim
ad7b23e263 Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: faf722a9cd am: 10ea99e493
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24122566

Change-Id: I0e0e43a71a428ce72b0bfa42974357eae630c65b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 03:33:47 +00:00
Inseob Kim
10ea99e493 Revert "Introduce CameraServices seinfo tag for PixelCameraServices" am: faf722a9cd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24122566

Change-Id: Ic11742e1fe66db9edc99fd36adcb54c89755fe03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-19 02:50:45 +00:00
Inseob Kim
faf722a9cd Revert "Introduce CameraServices seinfo tag for PixelCameraServices"
Revert submission 24056607-pixel-camera-services-extensions-sepolicy

Reason for revert: build breakage on git_main-without-vendor

Reverted changes: /q/submissionid:24056607-pixel-camera-services-extensions-sepolicy

Change-Id: I61599734edc5d80ca25beb4707549502318accaa
2023-07-19 01:15:21 +00:00
Utku Utkan
300a280812 Introduce CameraServices seinfo tag for PixelCameraServices am: 5b6bd7a496 am: 484de2c094
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24056607

Change-Id: Ibda7f1543f19f7d34baa1d230ec13491f588ac10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 22:35:37 +00:00
Utku Utkan
484de2c094 Introduce CameraServices seinfo tag for PixelCameraServices am: 5b6bd7a496
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24056607

Change-Id: I6403984c77ed54da3772ec619a3b11119fa94bad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 21:49:07 +00:00
Utku Utkan
5b6bd7a496 Introduce CameraServices seinfo tag for PixelCameraServices
Bug: 287069860
Test: m && flashall && check against 'avc: denied' errors
Change-Id: I190f58ce9bcdc5c121e9329eb34030eeaf4d8709
2023-07-18 12:18:35 -07:00
Joerg Wagner
3ef6e5849b Prepare for Mali r44p0 UMD update am: ca2f1c7d86 am: 5931554289
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24110385

Change-Id: I59b994724cfd3054b8e929ada1b2626d7ba9abf7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 11:11:35 +00:00
Joerg Wagner
5931554289 Prepare for Mali r44p0 UMD update am: ca2f1c7d86
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/24110385

Change-Id: I92c93e63d1a588a6f61ecbb2aa6c4a2285b37e7a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-18 10:28:40 +00:00
Joerg Wagner
ca2f1c7d86 Prepare for Mali r44p0 UMD update
Add selinux rule to allow new V2 interface file alongside of V1 used up to r43p0.
The V1 entry will be removed once the r44p0 UMD update completes.
This decouples small changes from large, potentially intrusive ones in
other repositories.

Bug: 284254900
Change-Id: Ia928f871d8ea1fdbfb963cecb8fc4a99947e443e
2023-07-18 10:10:18 +02:00
Jenny Ho
882f1e5b56 Add sepolicy for max77779fg am: eb242f21f6 am: c3e06879af
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23938991

Change-Id: Ic96dcfaf7f0a790e00cc462b483530b65962b5bc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 05:22:12 +00:00
Jenny Ho
c3e06879af Add sepolicy for max77779fg am: eb242f21f6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23938991

Change-Id: I58536156d51914eb9456980a1ce711afb71fbaee
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-11 04:45:13 +00:00
Jenny Ho
eb242f21f6 Add sepolicy for max77779fg
Bug: 290315763
Change-Id: I71249d99b972f7966f8b1b3a4978d62985f27d49
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-07-07 08:03:46 +00:00
Samuel Huang
fc5d18b8e0 Merge "Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."" into udc-qpr-dev am: 66fe034e16 am: fb59bd71c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23841766

Change-Id: I517ede059166b8a6f5377a50a68d45b1f6d40d67
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-07 03:10:44 +00:00
Samuel Huang
fb59bd71c6 Merge "Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."" into udc-qpr-dev am: 66fe034e16
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23841766

Change-Id: I5d47009b90cebe9e7ce2282798bda159a149a68f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-07 02:32:58 +00:00
Samuel Huang
66fe034e16 Merge "Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."" into udc-qpr-dev 2023-07-07 01:45:24 +00:00
Samuel Huang
d460f878fe Revert "Revert "Create telephony.ril.silent_reset system_ext pro..."
Revert submission 23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Reason for revert: The root cause is missing property definition in gs101-sepolicy. This CL can be merged safely. Verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L48900000961646046

Reverted changes: /q/submissionid:23817868-revert-23736941-tpsr-ril-property-WQVGKEVBKX

Bug: 286476107
Change-Id: I81a350f1df3c9071945e484277ed7fab5ae4c60e
2023-06-28 10:28:06 +00:00
Sebastian Pickl
d55c72eeab Merge "Revert "Create telephony.ril.silent_reset system_ext property fo..."" into udc-qpr-dev am: 98d8fc9d9b am: 661b2d8795
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23817866

Change-Id: Ib9ca7865e06bb10c965a83f761441bd51d077179
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 12:03:40 +00:00
Sebastian Pickl
661b2d8795 Merge "Revert "Create telephony.ril.silent_reset system_ext property fo..."" into udc-qpr-dev am: 98d8fc9d9b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23817866

Change-Id: I94056ba1842ded3d25cdee41ab633d8e8806097c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 11:16:34 +00:00
Sebastian Pickl
98d8fc9d9b Merge "Revert "Create telephony.ril.silent_reset system_ext property fo..."" into udc-qpr-dev 2023-06-27 10:37:16 +00:00
Sebastian Pickl
0c5d6dd888 Revert "Create telephony.ril.silent_reset system_ext property fo..."
Revert submission 23736941-tpsr-ril-property

Reason for revert: culprit for b/289014054 verified by abtd run: https://android-build.googleplex.com/builds/abtd/run/L54800000961620143

Bug: 289014054

Reverted changes: /q/submissionid:23736941-tpsr-ril-property

Change-Id: I2b845e6600e613eaa10788274cb028903d5df82e
2023-06-27 10:05:38 +00:00
Firman Prayoga
fdbf24d5b1 Merge "zumapro-sepolicy: Update camera device nodes" into udc-qpr-dev am: 6da1510a72 am: 3e50fbdbde
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23753466

Change-Id: Iaece406aa9c0dce158f7c4764635928a5894e1ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 08:36:19 +00:00
Firman Prayoga
3e50fbdbde Merge "zumapro-sepolicy: Update camera device nodes" into udc-qpr-dev am: 6da1510a72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23753466

Change-Id: I1025197ec941463bda37056b14ff5e9fb9bd23ed
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 07:25:53 +00:00
Firman Prayoga
6da1510a72 Merge "zumapro-sepolicy: Update camera device nodes" into udc-qpr-dev 2023-06-27 06:53:45 +00:00
Samuel Huang
8b8c9237d0 Merge "Create telephony.ril.silent_reset system_ext property for RILD restart" into udc-qpr-dev am: 45e235438a am: b66542c605
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23728212

Change-Id: I8bb92fa67c20d2bff02db6af0229a5c53778a867
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 03:55:54 +00:00
Samuel Huang
b66542c605 Merge "Create telephony.ril.silent_reset system_ext property for RILD restart" into udc-qpr-dev am: 45e235438a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23728212

Change-Id: Iba4233f74d3821f9f44d11d2b35db6b6469cbecf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 03:07:56 +00:00
Samuel Huang
45e235438a Merge "Create telephony.ril.silent_reset system_ext property for RILD restart" into udc-qpr-dev 2023-06-27 02:21:20 +00:00
Yixuan Wang
47867f8ff1 Add selinux policy for chre vendor data directory am: ea65f1e6bd am: 7372e55b9a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23782897

Change-Id: I7da75ed9b49c1db7586dd7b02176b6711decc280
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 02:29:58 +00:00
Yixuan Wang
7372e55b9a Add selinux policy for chre vendor data directory am: ea65f1e6bd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23782897

Change-Id: I06c28cf2c7e875fc7d3234f8b15fe90cc0fd8203
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-26 01:44:40 +00:00
Yixuan Wang
ea65f1e6bd Add selinux policy for chre vendor data directory
Bug: 278114604
Test: on device test
Change-Id: Ic8f0256c43ab3bc7c7bd30484f47e77bb970ce56
2023-06-22 18:18:28 +00:00
Firman Prayoga
0e6e839823 zumapro-sepolicy: Update camera device nodes
Bug: 288215624
Test: Boot, set camera mode, no selinux error
Change-Id: I9a636d60a5352d991cd199f7c9bb227554311ef7
2023-06-21 10:46:36 +00:00
Samuel Huang
7d7f055d46 Create telephony.ril.silent_reset system_ext property for RILD restart
RILD listens for changes to this property. If the value changes to 1, RILD will restart itself and set this property back to 0.

The TelephonyGoogle app will set this property to 1 when it receives a request from the SCONE app. Since TelephonyGoogle runs in the com.android.phone process, we also need to give the radio domain permission to set the telephony.ril.silent_reset property.

Bug: 286476107
Test: manual
Change-Id: I363b44a1a44184df05449ceb97089bb9e0211550
2023-06-21 06:35:13 +00:00
sashwinbalaji
d3d9c6e1cd thermal: thermal_metrics: Update selinux to reset stats am: 7bf1eb8960 am: 1df6cf3af2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23433016

Change-Id: I976b33a17bd55437198b527d4b2034485e957ca8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 18:40:42 +00:00
sashwinbalaji
1df6cf3af2 thermal: thermal_metrics: Update selinux to reset stats am: 7bf1eb8960
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/23433016

Change-Id: I3b75234232cc66c7a478e1eca72769281e72f64b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 17:13:56 +00:00