Commit graph

638 commits

Author SHA1 Message Date
Sungwoo choi
8dd51f11ad sepolicy: declare hal_vendor_radio_external_service
Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

Change-Id: Id523192adf8ab2d60f1778b97274f5357d06707c
Signed-off-by: Sungwoo choi <sungwoo48.choi@samsung.com>
2024-06-28 12:53:44 +00:00
Daniel Trofimiuk
d44695709c sepolicy: add rules for using aidl from RCS Service
allow to find hal_vendor_radio_external_service

Enable AIDL for V requirement

AVC log in b/281968564#comment208 and go/v-ril-hal-migration

Bug: 281968564
Test: telephony function test
Flag: EXEMPT HAL interface change

Change-Id: I39544e24ebe732e4ebab1044eade998ef534ebf6
Signed-off-by: Daniel Trofimiuk <d.trofimiuk@samsung.com>
2024-06-28 12:49:25 +00:00
Jack Wu
ee58427ea3 add permission for rt9471 sysfs
Bug: 347914940
Test: adb bugreport
Flag: EXEMPT bugfix
Change-Id: I155c58d857f676fc3a2ff6c2fe9be6262405c7b9
Signed-off-by: Jack Wu <wjack@google.com>
2024-06-19 16:13:33 +08:00
Kiwon Park
04cd87f1de [automerger skipped] Merge "Revert "Add setupwizard_feature_prop as one of properties allowe..."" into 24D1-dev am: 2af9745bc8 -s ours
am skip reason: Merged-In I8c8473f5a9c0cf9c53a95943101976d4b7103580 with SHA-1 33de53de68 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27828775

Change-Id: I832ac558cc338607af93f062bac9d41daf49c0b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-15 00:31:11 +00:00
Achigo Liu
c606d0cdc5 [automerger skipped] Revert "Add setupwizard_feature_prop as one of properties allowe..." am: 8a95fcc899 -s ours
am skip reason: Merged-In I8c8473f5a9c0cf9c53a95943101976d4b7103580 with SHA-1 33de53de68 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27828775

Change-Id: Ifdd47b2f374967d92b6bc076096e73859b2f424e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-15 00:31:07 +00:00
Kiwon Park
2af9745bc8 Merge "Revert "Add setupwizard_feature_prop as one of properties allowe..."" into 24D1-dev 2024-06-15 00:24:49 +00:00
Kiwon Park
4e6cd49893 Merge "Revert "Add setupwizard_feature_prop as one of properties allowed to be read"" into main 2024-06-14 00:06:27 +00:00
Achigo Liu
8a95fcc899 Revert "Add setupwizard_feature_prop as one of properties allowe..."
Revert submission 27717640-bootstrap

Reason for revert: mount vendor partition failed when OTA

Reverted changes: /q/submissionid:27717640-bootstrap

Change-Id: I8602fb3b435af864061b0c0f4f742684e228f34e
Merged-In: I8c8473f5a9c0cf9c53a95943101976d4b7103580
2024-06-13 17:36:55 +00:00
Kiwon Park
33de53de68 Revert "Add setupwizard_feature_prop as one of properties allowed to be read"
This reverts commit 26efc37a3d.

Reason for revert: Doesn't fix the issues in factory testing

Change-Id: I8c8473f5a9c0cf9c53a95943101976d4b7103580
2024-06-13 17:24:30 +00:00
Cheng Chang
92c5aff54d gps: Move type declaration to device folder am: 8fa884d01c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27574819

Change-Id: I8d7cd44249f8912b9fab64d24ff53381e20fc05b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-12 07:27:17 +00:00
Cheng Chang
8fa884d01c gps: Move type declaration to device folder
Bug: 343280252
Test: b/343280252 compile and abtd test
Change-Id: I492ea0b14953cf5b0111ac70bf82240522a15494
2024-06-11 07:52:11 +00:00
Lynn Yeh
6da60d7cb9 [automerger skipped] Merge "gps: maintain one solution" into 24D1-dev am: 97d62f485d -s ours
am skip reason: Merged-In I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5 with SHA-1 e2546691fe is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27080484

Change-Id: I1f4d698b3042601a74f0d2a803ed56773e3aba29
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 02:49:59 +00:00
Wayne Lin
6a3ccbfd4c [automerger skipped] gps: maintain one solution am: 89a73294a0 -s ours
am skip reason: Merged-In I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5 with SHA-1 e2546691fe is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27080484

Change-Id: I224c35c1899edf97f261416ef612ff307a41b7b4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 02:49:52 +00:00
Lynn Yeh
97d62f485d Merge "gps: maintain one solution" into 24D1-dev 2024-06-11 02:25:19 +00:00
Kiwon Park
0f9276399f [automerger skipped] Add setupwizard_feature_prop as one of properties allowed to be read am: 070be283a7 -s ours
am skip reason: Merged-In I7282cfdbd621dd0e77f08c8ff7287f9693fa060a with SHA-1 26efc37a3d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27698242

Change-Id: I6cba1bb2496f377f865514968352317212d82f8b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-06-11 00:27:39 +00:00
Kiwon Park
2a1f537456 Merge "Add setupwizard_feature_prop as one of properties allowed to be read" into main 2024-06-07 17:42:02 +00:00
Mike Wang
45d36ab2be Merge "Grant the Pixel Modem Service access to the SubscriptionManager." into main 2024-06-06 22:50:03 +00:00
Kiwon Park
070be283a7 Add setupwizard_feature_prop as one of properties allowed to be read
06-05 20:45:54.890420  root   351   351 W libc    : Unable to set property "setupwizard.feature.provisioning_profile_mode" to "true": error code: 0x18
06-05 20:45:54.894967  root   350   350 E init    : Unable to set property 'setupwizard.feature.provisioning_profile_mode' from uid:0 gid:0 pid:351: SELinux permission check failed

Test: manual
Bug: 336903409
Change-Id: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
Merged-In: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
2024-06-06 21:42:07 +00:00
Kiwon Park
26efc37a3d Add setupwizard_feature_prop as one of properties allowed to be read
06-05 20:45:54.890420  root   351   351 W libc    : Unable to set property "setupwizard.feature.provisioning_profile_mode" to "true": error code: 0x18
06-05 20:45:54.894967  root   350   350 E init    : Unable to set property 'setupwizard.feature.provisioning_profile_mode' from uid:0 gid:0 pid:351: SELinux permission check failed

Test: manual
Bug: 336903409
Change-Id: I7282cfdbd621dd0e77f08c8ff7287f9693fa060a
2024-06-06 21:41:56 +00:00
Shinru Han
34de4a725d Merge "gps: maintain one solution" into main 2024-06-04 06:41:30 +00:00
mikeyuewang
785df18f1e Grant the Pixel Modem Service access to the SubscriptionManager.
Bug: 344624813

avc denial: avc: denied { find } for pid=2372 uid=10303 name=isub scontext=u:r:pixel_modem_app:s0:c47,c257,c512,c768 tcontext=u:object_r:radio_service:s0 tclass=service_manager permissive=0

Change-Id: I2e74ae8b364a30895e2769504efcd604f19adfa7
2024-06-03 18:54:26 +00:00
Roy Luo
26d46a3e99 Merge "Support sending vendor command to GL852G via libusbhost" into main 2024-05-29 23:00:12 +00:00
Cheng Gu
5fb9dde89f Update SELinux error am: 48326b2e0b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27560145

Change-Id: I7f2898939e93b6ac6e1c2c76fb992df0ecc37f60
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-29 04:26:48 +00:00
emilchung
a9766745d1 Remove tracking denials of hal_sensors_default.
Fix: 308381687
Test: no avc denied of hal_sensors_default
Change-Id: I19305dc921ae96752c4213cc284d4f578bac07a2
2024-05-29 02:24:16 +00:00
Cheng Gu
48326b2e0b Update SELinux error
Bug: 317754251
Test: adb reboot and observe log
Change-Id: I7dcf9782ce2be632410e956871f74e874ddaf3a1
2024-05-28 22:31:47 +00:00
Roy Luo
ff802c138e Support sending vendor command to GL852G via libusbhost
libusbhost need access to USB device fs.

Bug: 261923350
Bug: 340665903
Test: no audit log in logcat after command execution
Change-Id: I4b0c8cc750eff12d2494504f9f215d5b1bab35fd
2024-05-22 00:49:12 +00:00
Frank Yu
3ef50e762f Update sepolicy for all device that use radioext 1.7 interface.
Bug: 340791912
Test: v2/pixel-health-guard/device-boot-health-check-extra
Change-Id: Icd7b482d88f52fbde6b281ef58857bfa6a9edea8
2024-05-20 03:17:49 +00:00
Wilson Sung
62cf04edbf [automerger skipped] Update SELinux error am: b65f4dacb2 -s ours
am skip reason: Merged-In I0d70966f03b0207388388fbc47e45de55a7385c3 with SHA-1 924e6c6cd3 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27392263

Change-Id: I5fc143ef7cbe16c19c70851412aec5fa575cecdb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-17 06:57:22 +00:00
Wilson Sung
b65f4dacb2 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Merged-In: I0d70966f03b0207388388fbc47e45de55a7385c3
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
(cherry picked from commit 924e6c6cd3)
2024-05-17 03:50:29 +00:00
Treehugger Robot
fd7f96c57c Merge "Allow hwc to access te_rate_hz & te_option" into main 2024-05-15 01:41:45 +00:00
Donnie Pollitz
c7ce4188a0 [automerger skipped] Merge "Add permission for storageproxy to create symlinks for ss" into 24D1-dev am: c41ed2ee7f -s ours
am skip reason: Merged-In I3f0559ee062c1b5393a2a35f957fbc8528bb58de with SHA-1 dd71a9cf27 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27067771

Change-Id: I7e5c1f6ba8adafab359f4594d70f97ccd5532f63
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-14 22:17:51 +00:00
Donnie Pollitz
cb30f22bea [automerger skipped] Add permission for storageproxy to create symlinks for ss am: e7837b9987 -s ours
am skip reason: Merged-In I3f0559ee062c1b5393a2a35f957fbc8528bb58de with SHA-1 dd71a9cf27 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27067771

Change-Id: I188ee0fd7c013dd874197f3d0cd9b9a1f186b6e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-14 22:17:47 +00:00
Donnie Pollitz
c41ed2ee7f Merge "Add permission for storageproxy to create symlinks for ss" into 24D1-dev 2024-05-14 21:59:03 +00:00
Wilson Sung
924e6c6cd3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
2024-05-14 03:09:03 +00:00
Treehugger Robot
9519db1e1b Merge "sepolicy: allow hal_gnss_pixel to connect to hal_contexthub_default" into main 2024-05-13 08:09:15 +00:00
Cheng Chang
b9181de2ea sepolicy: allow hal_gnss_pixel to connect to hal_contexthub_default
avc:  denied  { call } for  scontext=u:r:hal_contexthub_default:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0

Bug: 339391267
Test: Verified the boot health at b/339391267#comment21.
Test: Verified the boot health at b/339391267#comment22.
Change-Id: I109d03e52f6576328b92ec0b18041da8fac502eb
2024-05-10 09:41:57 +00:00
Weizhung Ding
24015b5aeb Add HWC permission to access IStats AIDL am: 32a69c8d11
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27282714

Change-Id: Ia7f5f040fbe9b08384f5b61e398781f3fe9d3323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-10 06:54:33 +00:00
Weizhung Ding
260af3904b add sysfs access permission on Zumapro devices. am: b5833b7ddf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27282713

Change-Id: Ibf10ea36cc1a257f0351daa7c154ba81a3d17226
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-10 06:54:30 +00:00
Weizhung Ding
32a69c8d11 Add HWC permission to access IStats AIDL
avc:  denied  { call } for  scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:r:system_server:s0 tclass=binder permissive=0

Bug: 339598226
Test: Build and check log
Change-Id: I7e5ec165df0d397250b09f5981c1f45aea27bd4c
2024-05-09 11:49:47 +00:00
Weizhung Ding
b5833b7ddf add sysfs access permission on Zumapro devices.
Bug: 339598226
Test: build and check log
Change-Id: Ia7a7f0f8a5ffc63ab52f41d7a012260d73c54153
2024-05-09 11:49:19 +00:00
Shiyong Li
f99e596498 Merge "Add sepolicy for power_state sysfs node" into 24D1-dev am: 3806937561
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27059981

Change-Id: Id35a52793ecd1d69bb8a54dc12101837f77d74e4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-09 05:21:38 +00:00
Shiyong Li
3806937561 Merge "Add sepolicy for power_state sysfs node" into 24D1-dev 2024-05-09 05:16:16 +00:00
Burney Yu
85e79a0734 Allow hwc to access te_rate_hz & te_option
Bug: 315094023
Test: can access sysfs node te_rate_hz & te_option
Change-Id: Ib2f657560dcbab5a96a26dfa98e2f3a477702e00
2024-05-09 10:18:19 +08:00
KRIS CHEN
e8be86e6c7 Merge "Allow fingerprint to access the folder /data/vendor/fingerprint" into main 2024-05-08 08:46:30 +00:00
chenkris
bbf5ed6dbd Allow fingerprint to access the folder /data/vendor/fingerprint
Fix the following avc denial:
android.hardwar: type=1400 audit(0.0:20): avc:  denied  { write } for  name="fingerprint" dev="dm-56" ino=36703 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 267766859
Test: Tested fingerprint under enforcing mode
Change-Id: Ib1ec4f13b24a511f056012168ff8919107c6c1dd
2024-05-08 06:58:36 +00:00
Wei Wang
dec7c70056 Merge "zumapro: sepolicy: Update gpu available_frequencies sepolicies." into 24D1-dev am: 6c9df27593
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27088243

Change-Id: I1946280379f379c5566dfee2c2735734380d5769
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-06 16:41:34 +00:00
Wei Wang
6c9df27593 Merge "zumapro: sepolicy: Update gpu available_frequencies sepolicies." into 24D1-dev 2024-05-06 16:24:33 +00:00
Treehugger Robot
fb8ece30b7 Merge "sepolicy: allow hal_power_stats to read modem sysfs node" into 24D1-dev am: 3bfa8edd2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27206477

Change-Id: Ic215eecf37588272b21a384c89550e4bacedcb6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-06 04:34:04 +00:00
Treehugger Robot
3bfa8edd2d Merge "sepolicy: allow hal_power_stats to read modem sysfs node" into 24D1-dev 2024-05-06 04:15:32 +00:00
Wayne Lin
89a73294a0 gps: maintain one solution
Bug: 315915958
Test: build pass and GPS function works
Change-Id: I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5
Merged-In: I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5
2024-05-06 03:52:43 +00:00