Commit graph

16 commits

Author SHA1 Message Date
Thiébaud Weksteen
8b8ae291d4 Merge "Remove duplicate service entries" into main 2024-10-17 06:30:19 +00:00
chenkris
0e859b87a1 Allow fingerprint HAL to access IGoodixFingerprintDaemon
Fix the following avc denial:
E SELinux : avc:  denied  { add } for pid=6578 uid=1000 name=vendor.goodix.hardware.biometrics.fingerprint.IGoodixFingerprintDaemon/default scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:default_android_service:s0 tclass=service_manager permissive=0

Flag: EXEMPT NDK
Bug: 368993793
Test: Tested fingerprint under enforcing mode
Change-Id: Iafed80d22d40e98cb0811ca84051066360f3dff8
2024-10-16 07:50:44 +00:00
Thiébaud Weksteen
f39431c3c8 Remove duplicate service entries
These entries are defined in the platform policy.

Flag: EXEMPT bugfix
Bug: 367832910
Test: TH
Change-Id: I113222c692b971c698684f762294565b96f8d0cb
2024-10-01 14:48:40 +10:00
Kah Xuan Lim
6914e7a49b Modem ML: Add sepolicy for TFLiteService
Add the sepolicy required to:
- Introduce modemml_tflite_service which runs on the system server.
- Allow modem_ml_svc_sit to access the new service.
- Allow system_server to access NNAPI TPU service.

Relevant logs before the sepolicy changes are made:

```
auditd  : avc:  denied  { find } for pid=1000 uid=1001 name=com.android.server.modemml.ITFLiteService/default scontext=u:r:modem_ml_svc_sit:s0 tcontext=u:object_r:modemml_tflite_service:s0 tclass=service_manager permissive=1
```

```
11-14 03:03:44.392  1064  1064 I auditd  : type=1400 audit(0.0:9): avc:  denied  { call } for  comm="modem_ml_svc_si" scontext=u:r:modem_ml_svc_sit:s0 tcontext=u:r:system_server:s0 tclass=binder permissive=1
```

```
SELinux : avc:  denied  { find } for pid=1115 uid=1000 name=android.hardware.neuralnetworks.IDevice/google-edgetpu scontext=u:r:system_server:s0 tcontext=u:object_r:edgetpu_nnapi_service:s0 tclass=service_manager permissive=1
```

Bug: 307449478

Change-Id: I14c2aa02eca08a026d100af6eea11ac9ac9e4fc7
2024-03-06 13:35:33 +08:00
Sungtak Lee
f8aaa7afa0 Add AIDL media.c2 into service_contexts
Bug: 321808716
Change-Id: Ieff24ebd4c5ce6201faecf819828f21cb598de67
2024-02-27 18:14:13 +00:00
Wilson Sung
c7973bf59a Move uwb service to vendor
Bug: 312143882
Test: make selinux_policy
Change-Id: I6266383542ab6a6db6cdcd6891e79aae6f6beb41
2023-12-05 03:16:18 +00:00
Wilson Sung
4e44355a8d Move service_contexts to vendor and tracking_denials
Bug: 312143882
Bug: 314080507
Test: make selinux_policy
Change-Id: Ia8474dc880c912b9a3db4401551a3eeed280bb47
2023-11-30 09:57:15 +00:00
Alec Foster
c659e9d5c7 Revert^2 "Add IQfpExtendedFingerprint to service_contexts."
8eb45bceb6
Bug: 313504369

Change-Id: I978eb6434d959412548d6bd6d59985374e29674f
2023-11-27 22:29:06 +00:00
Wilson Sung
8eb45bceb6 Revert "Add IQfpExtendedFingerprint to service_contexts."
Revert submission 25333146-sba4500_redux

Reason for revert: BB
Reverted changes: /q/submissionid:25333146-sba4500_redux
Bug: 312087854

Change-Id: I380eabae240d294f6c6ee6f1f0254e5976bc65ea
2023-11-20 06:40:56 +00:00
Alec Foster
46d2ea414e Add IQfpExtendedFingerprint to service_contexts.
Bug: 309966766
Bug: 309015469
Test: Fingerprint enroll successfully starts.
Test: adb logcat -b events -e avc -d | grep -iE "qfp"
Change-Id: Ie8f1c55057f8e32bae4db8b5ff22986f77c95dcf
2023-11-10 00:32:05 +00:00
Wilson Sung
863d41f6c6 Move vendor to legacy/zuma/vendor
Bug: 296187211
Change-Id: I28450565c4ee585060387ad988e7efbb1620eaee
2023-09-04 11:07:29 +08:00
Vania Januar
dbe23f1ab5 Revert "Revert^2 commit 2c99c990d3""
This reverts commit 9bd666007d.

Reason for revert: build break b/297170337

Change-Id: I2459b680bb3153d3d7e0f17761b4a825da942bcc
2023-08-23 12:58:42 +00:00
Wilson Sung
9bd666007d Revert^2 commit 2c99c990d3"
This reverts commit 5d2c755531.

Bug: 297129706
Change-Id: Ia8301a139559e8abf119a0964d7a06914aacf55e
2023-08-23 17:57:57 +08:00
Chiachang Wang
5d2c755531 Revert commit 2c99c990d3
This reverts commit 2c99c990d3.

Reason for revert: <Build break>

Change-Id: I030b4f5c59383478355ac2cee8363f45c8101041
2023-08-23 04:16:56 +00:00
Wilson Sung
355f0df8fd Sync zuma-sepolicy to legacy folder
Duplicate from zuma-sepolicy 7f3e2b9

Test: make selinux_policy
Bug: 296187211
Change-Id: If686fbdcf058849479019e8b37bb1d57a0215ed6
Signed-off-by: Wilson Sung <wilsonsung@google.com>
2023-08-22 15:37:56 +08:00
Robin Peng
bff99af2da init zumapro from zuma sha 43d5907677d0f
Bug: 272725898
Change-Id: If35d9efdda9dd3b8d8b24008f0738a0cbbe5bd9b
2023-03-31 14:16:57 +00:00