Commit graph

761 commits

Author SHA1 Message Date
Wilson Sung
c7854c06ea Update SELinux error
Test: scanBugreport
Bug: 353418158
Test: scanAvcDeniedLogRightAfterReboot
Bug: 353418189
Flag: EXEMPT bugfix
Change-Id: I5ce38640b68ca64749b07fd04d79e444d82ce206
2024-07-16 06:14:01 +00:00
Mike McTernan
55bd5b089d sepolicy:tracking_denials: add btlinux vendor_aoc_prop
Flag: EXEMPT bug fix
Bug: 353262026
Test: ABTD
Change-Id: I28a9e49eab75087aa424af1fd2cc5ead28285a2b
2024-07-15 19:18:29 +00:00
Martin Liu
0df50bf182 allow power hal to access vendor_mm files
I auditd  : type=1400 audit(0.0:79): avc:  denied  { write } for  comm="NodeLooperThrea" name="vendor_mm" dev="sysfs" ino=56518 scontext=u:r:hal_power_default:s0 tcontext=u:object_r:sysfs_vendor_mm:s0 tclass=dir permissive=0

Bug: 351708752
Test: check avc error
Flag: EXEMPT adding avc rule
Change-Id: Ibcc22d3157c0108dfc879b906fd500e13628d293
Signed-off-by: Martin Liu <liumartin@google.com>
2024-07-15 12:52:25 +00:00
Mike McTernan
a03bdd961a trusty: storageproxy: add fs_ready_rw property context
Flag: EXEMPT bug fix
Bug: 350362101
Test: ABTD
Change-Id: I6c5f4a550b00f4a2de03e6313448a4918ac4a425
2024-07-15 10:41:49 +01:00
Cheng Gu
6d465a9099 Update tracking_denials/bug_map.
Removes denial tracking of b/322916328.

Fix: 322916328
Test: none
Flag: EXEMPT bugfix
Change-Id: Ib16f0897f3a438fe147a0919897163407b857443
2024-07-15 05:39:33 +00:00
Liana Kazanova
9349b26f01 Merge "Revert "Delete sepolicy for legacy VR services."" into main 2024-07-11 22:40:20 +00:00
Liana Kazanova
3240bd79ed Revert "Delete sepolicy for legacy VR services."
This reverts commit 44db75e814.

Reason for revert: Droidmonitor created revert due to b/352465601. Will be verifying through ABTD before submission

Change-Id: I47918f16fbc5745758abf906017c68ef95a708f4
2024-07-11 20:56:16 +00:00
Jeremy DeHaan
4e0127be0e Allow HWC to access frame_rate node am: d5304a1144
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27815978

Change-Id: I1120124b8943793b3a40e390c7d243d0cc000f20
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-07-11 17:44:59 +00:00
Treehugger Robot
a61880366c Merge "Delete sepolicy for legacy VR services." into main 2024-07-11 03:56:41 +00:00
Krzysztof Kosiński
44db75e814 Delete sepolicy for legacy VR services.
None of the zumapro devices include these services.

Bug: 234559097
Test: presubmit
Flag: EXEMPT dead code removal
Change-Id: Iad24884869a1abd5daed60ef032b3f6c016aaf2d
2024-07-10 22:20:52 +00:00
Vishvam Mazumdar
88e0059ef0 Merge "Add SELinux policy to allow CPU Idle Histogram Stats in dumpstate." into main 2024-07-10 21:41:10 +00:00
Vishvam Mazumdar
d6b8239e73 Add SELinux policy to allow CPU Idle Histogram Stats in dumpstate.
This change is to allow the CPU Idle Histogram Stats to be dumped in
bugreports so that there is more insight into the idle behavior of
devices in the field.

Test: build/flash
Test: adb bugreport
Bug: 344908619
Flag: EXEMPT bugfix
Change-Id: If19b9471cf91ddc6e16347e7a4ea18d3298783d5
Signed-off-by: Vishvam Mazumdar <vmazumdar@google.com>
2024-07-10 21:39:23 +00:00
Jeremy DeHaan
d5304a1144 Allow HWC to access frame_rate node
Flag: EXEMPT bugfix
Bug: 346461765
Change-Id: Id7b3195e76cdce3e612eb9c9d177af24145e70a2
Signed-off-by: Jeremy DeHaan <jdehaan@google.com>
(cherry picked from commit b3d863d552)
2024-07-09 18:57:35 +00:00
Jeremy DeHaan
b3d863d552 Allow HWC to access frame_rate node
Flag: EXEMPT bugfix
Bug: 346461765
Change-Id: Id7b3195e76cdce3e612eb9c9d177af24145e70a2
Signed-off-by: Jeremy DeHaan <jdehaan@google.com>
2024-07-04 19:47:10 +00:00
Wilson Sung
8b0c2f2379 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 350830429
Bug: 350830390
Test: scanBugreport
Bug: 350830756
Bug: 350830411
Bug: 350830657
Bug: 350830132
Bug: 350830796
Test: scanAvcDeniedLogRightAfterReboot
Bug: 350830879
Bug: 350830475
Bug: 350830680
Bug: 350830758
Change-Id: Id961fa8d79caea0bca4770beab722a4e1933f879
2024-07-03 01:56:07 +00:00
Madhav Iyengar
8a2f931739 Extend ag/28090723 to zumapro.
ag/28090723 missed giving the bthal access to AoC version for zumapro
devices as well as zuma devices. This fixes that.

Bug: 349661931
Flag: com.android.bluetooth.hal.flags.pixel_bt_aoc_offload_efw_xport
Test: bthal on zumapro can read AoC version property
Change-Id: Iec6558630f7cbac7dc83bd621a9d8dbcd9bed000
2024-07-02 00:26:55 +00:00
Tim Lin
45cf6e8e26 Revert^2 "sepolicy: sepolicy for dmd/sced AIDL HAL service"
Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration
Forrest build result in go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

def1ba3ef0

Change-Id: If2c811627e6c85220a965d248a87e81a3a193dd0
2024-07-01 08:33:31 +00:00
Tim Lin
3950f529e1 Revert^2 "sepolicy: declare hal_vendor_radio_external_service"
Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration
Forrest build result in go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

01d2c24a52

Change-Id: I7ed8d164b90cb035535f27d076f4ed1f2656d623
2024-07-01 08:33:04 +00:00
Tim Lin
1a213269f8 Revert^2 "sepolicy: add rules for using aidl from RCS Service"
Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration
Forrest build result in go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

fd96edd330

Change-Id: Iab4e71a06e28fd10ae0a636b9dd38b346309f193
2024-07-01 08:31:47 +00:00
Pechetty Sravani
fd96edd330 Revert "sepolicy: add rules for using aidl from RCS Service"
Revert submission 27917806-v_hal_migration_phase3

Reason for revert: Droidmonitor created revert due to b/350390759. Will be verifying through ABTD before submission.

Reverted changes: /q/submissionid:27917806-v_hal_migration_phase3

Change-Id: I6a91a1caee3f4e506d3dd2cfad48ceaa07731409
2024-07-01 06:10:59 +00:00
Pechetty Sravani
01d2c24a52 Revert "sepolicy: declare hal_vendor_radio_external_service"
Revert submission 27917806-v_hal_migration_phase3

Reason for revert: Droidmonitor created revert due to b/350390759. Will be verifying through ABTD before submission.

Reverted changes: /q/submissionid:27917806-v_hal_migration_phase3

Change-Id: I58c1591607808e8ab152c759264186411641ecf5
2024-07-01 06:10:59 +00:00
Pechetty Sravani
def1ba3ef0 Revert "sepolicy: sepolicy for dmd/sced AIDL HAL service"
Revert submission 27917806-v_hal_migration_phase3

Reason for revert: Droidmonitor created revert due to b/350390759. Will be verifying through ABTD before submission.

Reverted changes: /q/submissionid:27917806-v_hal_migration_phase3

Change-Id: I8ce8e60548c03556fb7c28e592d911809399e054
2024-07-01 06:11:06 +00:00
Sungwoo choi
5a7d99b4a3 sepolicy: sepolicy for dmd/sced AIDL HAL service
declare a type of service
  hal_vendor_modem_logging_service : for modem logging
  hal_vendor_tcpdump_service : for tcpdump

Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

Change-Id: I24374cdecd7c811ac80bb1b2670168c9cc15be31
Signed-off-by: Sungwoo choi <sungwoo48.choi@samsung.com>
2024-06-28 12:56:22 +00:00
Sungwoo choi
8dd51f11ad sepolicy: declare hal_vendor_radio_external_service
Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

Change-Id: Id523192adf8ab2d60f1778b97274f5357d06707c
Signed-off-by: Sungwoo choi <sungwoo48.choi@samsung.com>
2024-06-28 12:53:44 +00:00
Daniel Trofimiuk
d44695709c sepolicy: add rules for using aidl from RCS Service
allow to find hal_vendor_radio_external_service

Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

Change-Id: I39544e24ebe732e4ebab1044eade998ef534ebf6
Signed-off-by: Daniel Trofimiuk <d.trofimiuk@samsung.com>
2024-06-28 12:49:25 +00:00
Jack Wu
ee58427ea3 add permission for rt9471 sysfs
Bug: 347914940
Test: adb bugreport
Flag: EXEMPT bugfix
Change-Id: I155c58d857f676fc3a2ff6c2fe9be6262405c7b9
Signed-off-by: Jack Wu <wjack@google.com>
2024-06-19 16:13:33 +08:00
Kiwon Park
04cd87f1de [automerger skipped] Merge "Revert "Add setupwizard_feature_prop as one of properties allowe..."" into 24D1-dev am: 2af9745bc8 -s ours
am skip reason: Merged-In I8c8473f5a9c0cf9c53a95943101976d4b7103580 with SHA-1 33de53de68 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27828775

Change-Id: I832ac558cc338607af93f062bac9d41daf49c0b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-15 00:31:11 +00:00
Achigo Liu
c606d0cdc5 [automerger skipped] Revert "Add setupwizard_feature_prop as one of properties allowe..." am: 8a95fcc899 -s ours
am skip reason: Merged-In I8c8473f5a9c0cf9c53a95943101976d4b7103580 with SHA-1 33de53de68 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27828775

Change-Id: Ifdd47b2f374967d92b6bc076096e73859b2f424e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-15 00:31:07 +00:00
Kiwon Park
2af9745bc8 Merge "Revert "Add setupwizard_feature_prop as one of properties allowe..."" into 24D1-dev 2024-06-15 00:24:49 +00:00
Kiwon Park
4e6cd49893 Merge "Revert "Add setupwizard_feature_prop as one of properties allowed to be read"" into main 2024-06-14 00:06:27 +00:00
Achigo Liu
8a95fcc899 Revert "Add setupwizard_feature_prop as one of properties allowe..."
Revert submission 27717640-bootstrap

Reason for revert: mount vendor partition failed when OTA

Reverted changes: /q/submissionid:27717640-bootstrap

Change-Id: I8602fb3b435af864061b0c0f4f742684e228f34e
Merged-In: I8c8473f5a9c0cf9c53a95943101976d4b7103580
2024-06-13 17:36:55 +00:00
Kiwon Park
33de53de68 Revert "Add setupwizard_feature_prop as one of properties allowed to be read"
This reverts commit 26efc37a3d.

Reason for revert: Doesn't fix the issues in factory testing

Change-Id: I8c8473f5a9c0cf9c53a95943101976d4b7103580
2024-06-13 17:24:30 +00:00
Cheng Chang
92c5aff54d gps: Move type declaration to device folder am: 8fa884d01c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27574819

Change-Id: I8d7cd44249f8912b9fab64d24ff53381e20fc05b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-12 07:27:17 +00:00
Cheng Chang
8fa884d01c gps: Move type declaration to device folder
Bug: 343280252
Test: b/343280252 compile and abtd test
Change-Id: I492ea0b14953cf5b0111ac70bf82240522a15494
2024-06-11 07:52:11 +00:00
Lynn Yeh
6da60d7cb9 [automerger skipped] Merge "gps: maintain one solution" into 24D1-dev am: 97d62f485d -s ours
am skip reason: Merged-In I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5 with SHA-1 e2546691fe is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27080484

Change-Id: I1f4d698b3042601a74f0d2a803ed56773e3aba29
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 02:49:59 +00:00
Wayne Lin
6a3ccbfd4c [automerger skipped] gps: maintain one solution am: 89a73294a0 -s ours
am skip reason: Merged-In I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5 with SHA-1 e2546691fe is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27080484

Change-Id: I224c35c1899edf97f261416ef612ff307a41b7b4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 02:49:52 +00:00
Lynn Yeh
97d62f485d Merge "gps: maintain one solution" into 24D1-dev 2024-06-11 02:25:19 +00:00
Kiwon Park
0f9276399f [automerger skipped] Add setupwizard_feature_prop as one of properties allowed to be read am: 070be283a7 -s ours
am skip reason: Merged-In I7282cfdbd621dd0e77f08c8ff7287f9693fa060a with SHA-1 26efc37a3d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27698242

Change-Id: I6cba1bb2496f377f865514968352317212d82f8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 00:27:39 +00:00
Kiwon Park
2a1f537456 Merge "Add setupwizard_feature_prop as one of properties allowed to be read" into main 2024-06-07 17:42:02 +00:00
Mike Wang
45d36ab2be Merge "Grant the Pixel Modem Service access to the SubscriptionManager." into main 2024-06-06 22:50:03 +00:00
Kiwon Park
070be283a7 Add setupwizard_feature_prop as one of properties allowed to be read
06-05 20:45:54.890420  root   351   351 W libc    : Unable to set property "setupwizard.feature.provisioning_profile_mode" to "true": error code: 0x18
06-05 20:45:54.894967  root   350   350 E init    : Unable to set property 'setupwizard.feature.provisioning_profile_mode' from uid:0 gid:0 pid:351: SELinux permission check failed

Test: manual
Bug: 336903409
Change-Id: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
Merged-In: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
2024-06-06 21:42:07 +00:00
Kiwon Park
26efc37a3d Add setupwizard_feature_prop as one of properties allowed to be read
06-05 20:45:54.890420  root   351   351 W libc    : Unable to set property "setupwizard.feature.provisioning_profile_mode" to "true": error code: 0x18
06-05 20:45:54.894967  root   350   350 E init    : Unable to set property 'setupwizard.feature.provisioning_profile_mode' from uid:0 gid:0 pid:351: SELinux permission check failed

Test: manual
Bug: 336903409
Change-Id: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
2024-06-06 21:41:56 +00:00
Shinru Han
34de4a725d Merge "gps: maintain one solution" into main 2024-06-04 06:41:30 +00:00
mikeyuewang
785df18f1e Grant the Pixel Modem Service access to the SubscriptionManager.
Bug: 344624813

avc denial: avc: denied { find } for pid=2372 uid=10303 name=isub scontext=u:r:pixel_modem_app:s0:c47,c257,c512,c768 tcontext=u:object_r:radio_service:s0 tclass=service_manager permissive=0

Change-Id: I2e74ae8b364a30895e2769504efcd604f19adfa7
2024-06-03 18:54:26 +00:00
Roy Luo
26d46a3e99 Merge "Support sending vendor command to GL852G via libusbhost" into main 2024-05-29 23:00:12 +00:00
Cheng Gu
5fb9dde89f Update SELinux error am: 48326b2e0b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27560145

Change-Id: I7f2898939e93b6ac6e1c2c76fb992df0ecc37f60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-29 04:26:48 +00:00
emilchung
a9766745d1 Remove tracking denials of hal_sensors_default.
Fix: 308381687
Test: no avc denied of hal_sensors_default
Change-Id: I19305dc921ae96752c4213cc284d4f578bac07a2
2024-05-29 02:24:16 +00:00
Cheng Gu
48326b2e0b Update SELinux error
Bug: 317754251
Test: adb reboot and observe log
Change-Id: I7dcf9782ce2be632410e956871f74e874ddaf3a1
2024-05-28 22:31:47 +00:00
Roy Luo
ff802c138e Support sending vendor command to GL852G via libusbhost
libusbhost need access to USB device fs.

Bug: 261923350
Bug: 340665903
Test: no audit log in logcat after command execution
Change-Id: I4b0c8cc750eff12d2494504f9f215d5b1bab35fd
2024-05-22 00:49:12 +00:00
Frank Yu
3ef50e762f Update sepolicy for all device that use radioext 1.7 interface.
Bug: 340791912
Test: v2/pixel-health-guard/device-boot-health-check-extra
Change-Id: Icd7b482d88f52fbde6b281ef58857bfa6a9edea8
2024-05-20 03:17:49 +00:00