Commit graph

181 commits

Author SHA1 Message Date
Nina Chen
30570259fe Update SELinux error
Flag: EXEMPT sepolicy
Test: SELinuxUncheckedDenialBootTest
Bug: 382362300
Bug: 366116096
Change-Id: I8cf6742ded1f3b90b46909ee0ac47c9f33258466
2024-12-05 06:43:47 +00:00
Nina Chen
100436811e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 381327278
Flag: EXEMPT sepolicy
Change-Id: I359cc10c3a6f5bd5b20c4b1022f39f40484aa950
2024-11-28 03:00:00 +00:00
Nina Chen
0d60be5645 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 380989493
Flag: EXEMPT NDK
Change-Id: Iffaff71c72b03d58d2abcbe44007c2be469050bd
2024-11-26 05:28:21 +00:00
Nina Chen
9faa3999ef Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 379245474
Bug: 379245673
Bug: 379245788
Bug: 379244519
Bug: 379245853
Flag: EXEMPT NDK
Change-Id: Ic1c8e73773ed71eea7be46187231fde6b5283e8a
2024-11-15 11:02:02 +00:00
Nina Chen
351ceac512 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 379206528
Bug: 379206406
Flag: EXEMPT NDK
Change-Id: I82ca7cb985e9fd755dba5d29139a2b9a9f638f9a
2024-11-15 06:53:58 +00:00
Xiaofan Jiang
30306a34b5 shamp: remove fixed bug from bugmap
Bug: 360060705

Flag: NONE clean up bugmap

Change-Id: I7d71aefa766e870e8bccb100ed5ad796dbbab36b
2024-11-13 20:35:03 +00:00
Spade Lee
1239bde036 Merge "sepolicy: add label for logbuffer" into main 2024-11-13 17:00:10 +00:00
Spade Lee
f8891af46e sepolicy: add label for logbuffer
- Add logbuffer_device label for ln8411, dc_mains, dual_batt
- Remove from tracking_deniel

Bug: 377895720
Flag: EXEMPT bugfix
Change-Id: Ia542c089bcf0eb6bb4ea3e026d43937390720b22
Signed-off-by: Spade Lee <spadelee@google.com>
2024-11-12 01:46:58 +00:00
Nina Chen
2fe912350e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 378004800
Flag: EXEMPT NDK
Change-Id: I5cdb5950053f291969b660758a3eac4deda3995c
2024-11-08 03:37:57 +00:00
Nina Chen
31d6e22220 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 377787445
Flag: EXEMPT NDK
Change-Id: I96db3485005cdaed405c8d117b1d50b5f29b533f
2024-11-07 06:39:17 +00:00
Nina Chen
d03f77df69 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 377412254
Flag: EXEMPT NDK
Change-Id: I1345afdb481e9f84f2dd5fe745ebf594cbc33c66
2024-11-05 05:25:33 +00:00
Nina Chen
dde3987124 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 375564898
Bug: 375564818
Bug: 375563932
Bug: 375564360
Bug: 375521075
Flag: EXEMPT NDK
Change-Id: I582e58598cf0c89de4b9aa904c84cbb065eba36b
2024-10-25 09:11:49 +00:00
Mike McTernan
f43ae7b448 Revert "sepolicy:tracking_denials: add btlinux vendor_aoc_prop"
This reverts commit 55bd5b089d.

Reason for revert: Underlying bug fixed

Flag: EXEMPT bug fix
Bug: 353262026
Change-Id: Id04ffeb508ea7450449c0934bec646e8f7f1356f
2024-10-04 09:00:36 +00:00
Yen-Chao Chen
693260c964 remove b/350830796 and b/350830680 from bug map
Bug: 350830796
Bug: 350830680
Test: build pass
Flag: EXEMPT bugfix
Change-Id: Ic3c163ce4dd6b97289ec22f97a0c87052b049ea4
Signed-off-by: Yen-Chao Chen <davidycchen@google.com>
2024-09-30 09:24:36 +00:00
YiKai Peng
bf729b7266 Update SELinux error
solution: Ie9f8fc5cce8e62b06931b77aa8cd16a3c9516fb5

Test: NA
Bug: 350830879
Flag: EXEMPT bugfix
Change-Id: I390af5bde405dc35f2cf37163975a851250c7dd2
Signed-off-by: YiKai Peng <kenpeng@google.com>
2024-09-27 05:11:22 +00:00
Feiyu Chen
80af57220f Merge "Remove b/340369535 hal_audio_default from bug map" into main 2024-09-27 00:41:38 +00:00
Feiyu Chen
a0407eaeae Remove b/340369535 hal_audio_default from bug map
It's fixed 4 months ago

Bug: 340369535
Flag: DOCS_ONLY
Change-Id: If4a6f41703686620dd9614a5fbcbf837127c3173
2024-09-26 19:24:00 +00:00
weichinweng
644a742ac7 Remove SELinux error tracing bug
Bug: 350830390
Bug: 350830756
Bug: 350830758
Test: None
Change-Id: Ib33ceebb66573dbb38c87b120daa481b3756090d
2024-09-26 07:51:52 +00:00
Wilson Sung
a59097a64a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 369539751
Test: scanBugreport
Bug: 369539798
Bug: 369540515
Flag: EXEMPT NDK
Change-Id: Ib294a4c50801ddbd791ff3d05fe332f70bf17283
2024-09-25 12:46:13 +00:00
Nina Chen
1ded01dd86 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 369475712
Flag: EXEMPT NDK
Change-Id: Ib2752c70f24cd0ea35b13836556dc634d2721413
2024-09-25 06:30:45 +00:00
Nina Chen
2a4cb7b0a3 Update SELinux error
Test: scanBugreport
Bug: 368188020
Test: scanAvcDeniedLogRightAfterReboot
Bug: 368187536
Flag: EXEMPT NDK
Change-Id: I0cb8cf650332bf2d518871f87c2175a4f3a20678
2024-09-19 04:07:52 +00:00
Nina Chen
2c4cebf4d5 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 366116096
Change-Id: I202f9031b89dbfbbce9d7fda6f8f50120df1698f
2024-09-12 14:24:29 +08:00
Neo Yu
696b8a5777 Merge "Move sepolicy about hal_radioext_default to gs-common" into main 2024-09-06 01:41:13 +00:00
Wilson Sung
42fee8809a Move euiccpixel_app to vendor
Bug: 312143882
Test: make selinux_policy
Flag: EXEMPT sepolicy refactor
Change-Id: I0f6ac76860c90b8022a85cafb80350a708d278c1
2024-09-04 15:10:03 +00:00
Neo Yu
d5626145f3 Move sepolicy about hal_radioext_default to gs-common
Bug: 363665676
Test: verify with test roms
Flag: EXEMPT sepolicy refactor
Change-Id: I618742012138123329ae47c05c958e77f5573956
2024-09-01 14:25:00 +08:00
Nattharat Jariyanuntanaet
11c0bf5839 Merge "Update sepolicy for nfc antenna selftest values" into main 2024-08-30 05:06:06 +00:00
Wilson Sung
b5d284c3b5 Update SELinux error
Test: scanBugreport
Bug: 361726331
Flag: EXEMPT bugFix
Change-Id: Ib42816834dbb8258d5528a1c885a9a0945fe82d1
2024-08-23 09:49:29 +00:00
Nattharat Jariyanuntanaet
4599e2be44 Update sepolicy for nfc antenna selftest values
Allow persist.vendor.nfc.antenna. to be vendor public values for the NFC
companion app to access

avc:  denied  { read } for  name="u:object_r:vendor_nfc_antenna_prop:s0" dev="tmpfs" ino=414 scontext=u:r:untrusted_app:s0:c79,c257,c512,c768 tcontext=u:object_r:vendor_nfc_antenna_prop:s0 tclass=file permissive=0 app=com.google.android.apps.internal.nfcassistancetool

Bug: 361050657
Test: m selinux_policy
Flag: NONE add permission
Change-Id: I0e7c3580e4df332fa3d14c939eb5e588f7600601
2024-08-23 02:42:23 +00:00
Wilson Sung
36d0a8ffc8 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 360060705
Test: scanBugreport
Bug: 360060680
Test: scanAvcDeniedLogRightAfterReboot
Bug: 360060705
Flag: EXEMPT bugFix
Change-Id: Ia71aabae1c8bb6ad8b6d9cbeb925821c2612e116
2024-08-15 09:25:37 +00:00
Manali Bhutiyani
156e14bb70 Merge "DisplayPort Stats: add sysfs access permission on Zumapro devices" into main 2024-07-26 03:45:52 +00:00
Carlos Rodriguez
dd5b70f378 DisplayPort Stats: add sysfs access permission on Zumapro devices
07-25 14:13:16.736  5784  5784 W pixelstats-vend: type=1400 audit(0.0:21): avc:  denied  { read } for  name="fec_dsc_supported" dev="sysfs" ino=82516 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-25 14:13:16.736  5784  5784 W pixelstats-vend: type=1400 audit(0.0:22): avc:  denied  { read } for  name="fec_dsc_not_supported" dev="sysfs" ino=82517 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-25 14:13:16.736  5784  5784 W pixelstats-vend: type=1400 audit(0.0:23): avc:  denied  { read } for  name="max_res_other" dev="sysfs" ino=82515 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
07-25 14:13:16.736  5784  5784 W pixelstats-vend: type=1400 audit(0.0:24): avc:  denied  { read } for  name="max_res_1366_768" dev="sysfs" ino=82505 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 343602691
Bug: 317486088

Flag: EXEMPT bugfix
Test: Android built and flashed and error is gone
Change-Id: I594536581ea468d40c9153bdc1bdd6b1ab7282fd
2024-07-25 21:14:55 +00:00
Spade Lee
8d61b53a50 sepolicy: removes dump_power tracking denial
avc:  denied  { read } for  name="maxfg_history" dev="tmpfs" ino=1144 scontext=u:r:dump_power:s0 tcontext=u:object_r:battery_history_device:s0 tclass=chr_file permissive=0

Bug: 353418158
Test: atest-dev com.google.android.selinux.pts.SELinuxTest#scanBugreport => PASS
Flag: EXEMPT bugfix
Change-Id: Ie71eb273915eca6b38281a5f7a8a2b8a6bdcf4c8
Signed-off-by: Spade Lee <spadelee@google.com>
2024-07-18 10:19:43 +00:00
Wilson Sung
19c65ba48e Merge "Update SELinux error" into main 2024-07-17 04:31:22 +00:00
Wilson Sung
c7854c06ea Update SELinux error
Test: scanBugreport
Bug: 353418158
Test: scanAvcDeniedLogRightAfterReboot
Bug: 353418189
Flag: EXEMPT bugfix
Change-Id: I5ce38640b68ca64749b07fd04d79e444d82ce206
2024-07-16 06:14:01 +00:00
Mike McTernan
55bd5b089d sepolicy:tracking_denials: add btlinux vendor_aoc_prop
Flag: EXEMPT bug fix
Bug: 353262026
Test: ABTD
Change-Id: I28a9e49eab75087aa424af1fd2cc5ead28285a2b
2024-07-15 19:18:29 +00:00
Cheng Gu
6d465a9099 Update tracking_denials/bug_map.
Removes denial tracking of b/322916328.

Fix: 322916328
Test: none
Flag: EXEMPT bugfix
Change-Id: Ib16f0897f3a438fe147a0919897163407b857443
2024-07-15 05:39:33 +00:00
Wilson Sung
8b0c2f2379 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 350830429
Bug: 350830390
Test: scanBugreport
Bug: 350830756
Bug: 350830411
Bug: 350830657
Bug: 350830132
Bug: 350830796
Test: scanAvcDeniedLogRightAfterReboot
Bug: 350830879
Bug: 350830475
Bug: 350830680
Bug: 350830758
Change-Id: Id961fa8d79caea0bca4770beab722a4e1933f879
2024-07-03 01:56:07 +00:00
Cheng Gu
5fb9dde89f Update SELinux error am: 48326b2e0b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27560145

Change-Id: I7f2898939e93b6ac6e1c2c76fb992df0ecc37f60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-29 04:26:48 +00:00
emilchung
a9766745d1 Remove tracking denials of hal_sensors_default.
Fix: 308381687
Test: no avc denied of hal_sensors_default
Change-Id: I19305dc921ae96752c4213cc284d4f578bac07a2
2024-05-29 02:24:16 +00:00
Cheng Gu
48326b2e0b Update SELinux error
Bug: 317754251
Test: adb reboot and observe log
Change-Id: I7dcf9782ce2be632410e956871f74e874ddaf3a1
2024-05-28 22:31:47 +00:00
Wilson Sung
b65f4dacb2 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Merged-In: I0d70966f03b0207388388fbc47e45de55a7385c3
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
(cherry picked from commit 924e6c6cd3)
2024-05-17 03:50:29 +00:00
Wilson Sung
924e6c6cd3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
2024-05-14 03:09:03 +00:00
Enzo Liao
e4ceb50a9c Move SELinux policies of RamdumpService and SSRestartDetector to /gs-common.
New paths (ag/26620507):
  RamdumpService: device/google/gs-common/ramdump_app
  SSRestartDetector: device/google/gs-common/ssr_detector_app

Bug: 298102808
Design: go/sys-software-logging
Test: Manual
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:2761dbe28b294be5199aba6ee73013427e8d627f)
Merged-In: I455630b347f9f234365fec371142582d2cc0640a
Change-Id: I455630b347f9f234365fec371142582d2cc0640a
2024-04-22 03:03:12 +00:00
Enzo Liao
2761dbe28b Move SELinux policies of RamdumpService and SSRestartDetector to /gs-common.
New paths (ag/26620507):
  RamdumpService: device/google/gs-common/ramdump_app
  SSRestartDetector: device/google/gs-common/ssr_detector_app

Bug: 298102808
Design: go/sys-software-logging
Test: Manual
Change-Id: I455630b347f9f234365fec371142582d2cc0640a
2024-04-08 19:23:52 +08:00
Spade Lee
aac2240ca4 sepolicy: allow kernel to search vendor debugfs
audit: type=1400 audit(1710259012.824:4): avc:  denied  { search } for  pid=128 comm="kworker/3:1" name="max77779fg" dev="debugfs" ino=24204 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_maxfg_debugfs:s0 tclass=dir permissive=0
audit: type=1400 audit(1710427790.680:2): avc:  denied  { search } for  pid=10 comm="kworker/u16:1" name="gvotables" dev="debugfs" ino=10582 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_votable_debugfs:s0 tclass=dir permissive=1
audit: type=1400 audit(1710427790.680:3): avc:  denied  { search } for  pid=211 comm="kworker/u16:4" name="google_charger" dev="debugfs" ino=16673 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_charger_debugfs:s0 tclass=dir permissive=1

Bug: 328016570
Bug: 329317898
Test: check all debugfs folders are correctly mounted
Change-Id: Ib25cc13a329b40bebe87fab43e955e2e4395de9e
Signed-off-by: Spade Lee <spadelee@google.com>
2024-04-02 07:35:39 +00:00
Spade Lee
bac2d41b9c sepolicy: allow kernel to search vendor debugfs
audit: type=1400 audit(1710259012.824:4): avc:  denied  { search } for  pid=128 comm="kworker/3:1" name="max77779fg" dev="debugfs" ino=24204 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_maxfg_debugfs:s0 tclass=dir permissive=0
audit: type=1400 audit(1710427790.680:2): avc:  denied  { search } for  pid=10 comm="kworker/u16:1" name="gvotables" dev="debugfs" ino=10582 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_votable_debugfs:s0 tclass=dir permissive=1
audit: type=1400 audit(1710427790.680:3): avc:  denied  { search } for  pid=211 comm="kworker/u16:4" name="google_charger" dev="debugfs" ino=16673 scontext=u:r:kernel:s0 tcontext=u:object_r:vendor_charger_debugfs:s0 tclass=dir permissive=1

Bug: 328016570
Bug: 329317898
Test: check all debugfs folders are correctly mounted
Change-Id: Ib25cc13a329b40bebe87fab43e955e2e4395de9e
Signed-off-by: Spade Lee <spadelee@google.com>
2024-03-20 18:13:22 +00:00
derickhong
1f38fe473a Update SELinux error
Bug: 326869289
Test: adb shell dmesg | grep avc ; adb logcat -d | grep avc
Change-Id: I57090ee64cafc5c2a9d98ec02152fdc9eb495591
2024-03-20 07:39:32 +00:00
John Chang
46d2322311 Move display properties from tracking_denials to vendor
Bug: 328001545
Test: Test MRR Version 2 is properly configured
Change-Id: Ib586398670b21bb88cd122647880149daa628d0d
2024-03-08 16:32:30 +00:00
John Chang
21601cc866 Move display properties from tracking_denials to vendor
Bug: 328001545
Test: Test MRR Version 2 is properly configured
Change-Id: Ib586398670b21bb88cd122647880149daa628d0d
2024-03-08 16:23:52 +00:00
John Chang
ff239639f8 display: change vrr.enabled to xrr.version
Bug: 328001545
Test: Test MRR Version 2 is properly configured
Change-Id: I02291bb537fe5a09ab8a1aa755426f45465883a9
2024-03-07 22:19:51 +00:00