Commit graph

504 commits

Author SHA1 Message Date
Megha Patil
3b48faef9c Merge "Add System Property to Specify NTN Demo Mode Enabled" into main 2024-01-23 10:35:10 +00:00
Megha Patil
ab78d95fb8 Add System Property to Specify NTN Demo Mode Enabled
"telephony.ril.ntn_demo_mode" Property is added which specifies
RIL about NTN Demo Mode.

BUG: b/321178074
Test: Set the property in the service.
Change-Id: I8baca9ceaf364b579293679cabe26c33e0a4ec1e
2024-01-23 10:34:57 +00:00
Darren Hsu
16453defb3 sepolicy: allow hal_power_stats to read sysfs_display
avc:  denied  { read } for  name="available_disp_stats"
dev="sysfs" ino=76162 scontext=u:r:hal_power_stats_default:s0
tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 321871433
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I84e3a561f60bec7f75c14359dc0a31216590a335
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2024-01-23 17:42:11 +08:00
Wilson Sung
e52dfde528 Update error on ROM 11340999
Bug: 321733124
Test: SELinuxUncheckedDenialBootTest
Change-Id: I1eca905eea9854be71926750b5d898c84c4794bd
2024-01-22 17:45:51 +00:00
Ted Wang
4f5d6c7812 Allow GrilService to access bluetooth extension HAL
Bug: 320403892
Test: Manual
Change-Id: I83834154563f9e77aaaf5ed786259a331497a378
2024-01-19 08:11:41 +00:00
Treehugger Robot
52ef38dcf1 Merge "fingerprint: fix SELinux denials" into main 2024-01-18 17:31:31 +00:00
Kadi Narmamatov
d9634912a6 Merge "rfsd: add new property to sepolicy" into main 2024-01-18 10:01:47 +00:00
kadirpili
8f0acd4186 rfsd: add new property to sepolicy
Avoid Access denied finding property "vendor.cbd.modem_bin_type" error message and give access for rfsd to access the property

Bug: 307481296
Bug: 317735109

Change-Id: Icd287f863fd6d309297ce984f4ce387fb5d3ae24
2024-01-18 08:30:02 +00:00
Treehugger Robot
5a084bb6ba Merge "aoc: add sysfs file entry" into main 2024-01-18 04:00:25 +00:00
chenkris
e01b41b519 fingerprint: fix SELinux denials
Fix following AVC denials:
1. SELinux : avc:  denied  { find } for interface=vendor.goodix.hardware.biometrics.fingerprint::IGoodixFingerprintDaemon sid=u:r:hal_fingerprint_default:s0 pid=2948 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:default_android_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 315737323
Test: boot with no relevant error
Change-Id: I9f32e2bc771c5bfd8ebf26344342b8813f0b4930
2024-01-18 02:12:10 +00:00
mikeyuewang
ebdc5d769b Remove this tracking as the denial has been fixed by b/287683516
Bug: 287683516

Change-Id: I9a9c7ac6d226fb6a859b69f0c4eca4857f65cf84
2024-01-17 21:22:06 +00:00
yixuanjiang
86b073086f aoc: add sysfs file entry
Test: Local
Bug: 314719343
Change-Id: I31e08e4f86b075f52b1483c17405074928b26f70
Signed-off-by: yixuanjiang <yixuanjiang@google.com>
2024-01-17 18:12:27 +08:00
Angela Wu
365355875e Merge "Set up zumapro selinux policy for /dev/video12 access for hardware JPG encoder. (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:ea768217f5f8f2ab32a3f76b4329378c5731aa24)" into main 2024-01-15 03:20:02 +00:00
Angela Wu
0b7ef4e53b Set up zumapro selinux policy for /dev/video12 access for hardware JPG encoder.
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:ea768217f5f8f2ab32a3f76b4329378c5731aa24)

Bug: b/296330134
Test: https://android-build.corp.google.com/builds/abtd/run/L22000030001255046

Change-Id: I03d99401f5444e5a42e570a039c4838f1141bec9
2024-01-15 02:27:34 +00:00
Allen Xu
3bfc494565 Merge "Update sepolicy for ConnectivityMonitor" into main 2024-01-12 18:52:11 +00:00
Treehugger Robot
a4450e572f Merge "Add wakeup node" into main 2024-01-12 07:13:24 +00:00
Wilson Sung
c9400f0dbb Add wakeup node
Bug: 319737316
Test: make sepolicy
Change-Id: I4ca5aa9a5ff7b9b58e220fba01cfcbf283cc25c5
2024-01-12 03:22:31 +00:00
Treehugger Robot
f391978522 Merge "sepolicy: enable enforcing for hal_power_stats" into main 2024-01-11 20:56:49 +00:00
Allen Xu
1e31efbc3a Update sepolicy for ConnectivityMonitor
Bug: 307468771
Test: v2/pixel-health-guard/device-boot-health-check-extra
Change-Id: I08caf6a8e48118151df72ad883490551af0c464c
2024-01-11 20:18:20 +00:00
Treehugger Robot
aaaf45379c Merge "Remove system_suspend dontaudit" into main 2024-01-11 01:40:29 +00:00
Darren Hsu
31a27225de sepolicy: enable enforcing for hal_power_stats
Bug: 307468729
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I2522e317542e441fe9cede3e314081478f8b6158
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2024-01-10 21:13:10 +08:00
Wilson Sung
84b93cfb16 Remove system_suspend dontaudit
Fix: 318032188
Test: make sepolicy
Change-Id: I216fb901e5cc2ffdb3906da2d88e830e29d0e476
2024-01-10 19:08:42 +08:00
Wilson Sung
b376cb8cd1 Update error on ROM 11294806
Bug: 319399862
Test: SELinuxUncheckedDenialBootTest
Change-Id: I99331843251adb8f994170714e6f2c7cc28f2b2b
2024-01-10 10:49:19 +00:00
Ken Yang
3bbde83710 selinux: label wakeup for BMS I2C 0x36, 0x69
Bug: 319035561
Change-Id: Id82f3fd351190102c87ff2a8c16d56a581a6e45d
Signed-off-by: Ken Yang <yangken@google.com>
2024-01-10 07:30:15 +00:00
Treehugger Robot
e15179f322 Merge "Label and sort wakeup nodes" into main 2024-01-10 06:45:17 +00:00
Mahesh Kallelil
e51f8b7f0e Merge "Allow dump_modem to read logbuffer and wakeup events" into main 2024-01-09 03:03:24 +00:00
Treehugger Robot
928bbf4682 Merge "thermal: remove tracking denials for hal_thermal" into main 2024-01-08 23:01:34 +00:00
Ramya Subramanian
55d942e762 thermal: remove tracking denials for hal_thermal
Bug: 307468692
Test: Tested thermal service with the file removed

Change-Id: Ic3f698f2be89c9ee86aa91fdcb139cfd95751c29
Signed-off-by: Ramya Subramanian <rsubr@google.com>
2024-01-08 18:14:18 +00:00
Guibing Cai
f94cf085fe Merge "zumapro: sepolicy: remove power hal denial tracker." into main 2024-01-08 18:10:45 +00:00
Wilson Sung
337ca68313 Label and sort wakeup nodes
Bug: 318032188
Test: make sepolicy
Change-Id: I8dfa35034657ff98957373818e98b5bf836e7a4b
2024-01-08 17:33:12 +08:00
Wilson Sung
95ab7f7ea9 Allow sysUI access nfc_service
Bug: 307468867
Test: make sepolicy
Change-Id: Iee2c35b92024c56ff6120d1b7c751b2021e5ae6e
2024-01-08 02:43:12 +00:00
Mahesh Kallelil
6285ad387d Allow dump_modem to read logbuffer and wakeup events
Updating sepolicy for dump_modem to read /dev/logbuffer_cpif. This is
required as part of bugreport.

Test: Tested bugreport on device
Bug: 318949647
Change-Id: Ica70258200432633681b8d222a56c21aac427d86
Signed-off-by: Mahesh Kallelil <kallelil@google.com>
2024-01-06 09:59:26 -08:00
Achigo Liu
e226fde393 Merge "Fixes adb user unauthorized on user builds" into main 2024-01-06 00:40:20 +00:00
Achigo Liu
90798eb40e Fixes adb user unauthorized on user builds
Allow systemui to find adbd

Bug: 318808947
Change-Id: Ifb88a64b851a64338191dd4f40b6b60a9bee5039
Signed-off-by: Achigo Liu <achigoliu@google.com>
2024-01-06 00:39:18 +00:00
guibing
e417775b17 zumapro: sepolicy: remove power hal denial tracker.
Remove the power hal denial tracker.
Add the missing devfreq related configuration.

Bug: 307468758
Test: Power hal works without related avc errors.
Change-Id: I038bc7701deeada4d70ef2ed17d5db64ba5b4d03
2024-01-05 21:58:20 +00:00
Aaron Tsai
a51aa5a582 Merge "Fix avc denied for hal_radioext_default" into main 2024-01-05 02:58:01 +00:00
Aaron Tsai
7c0879939a Fix avc denied for hal_radioext_default
01-02 03:20:32.967   421   421 I auditd  : avc:  denied  { find } for pid=900 uid=1001 name=vendor.google.bluetooth_ext.IBTChannelAvoidance/default scontext=u:r:hal_radioext_default:s0 tcontext=u:object_r:hal_bluetooth_coexistence_service:s0 tclass=service_manager permissive=0

Bug: 318308344
Test: manual test
Change-Id: Ied0dd27d86cfc4512c08a26d02499ba9b816ed78
2024-01-03 09:47:09 +00:00
Hung-Yeh Lee
5a8206a8e4 sepolicy: add persist.vendor.primarydisplay. to vendor_display_prop
Copy sepolicy from zuma to fix the following avc denied:
auditd  : type=1107 audit(0.0:11): uid=0 auid=4294967295
ses=4294967295 subj=u:r:init:s0 msg='avc: denied  { set } for
property=persist.vendor.primarydisplay.op.peak_refresh_rate pid=510
uid=1000 gid=1003 scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:object_r:vendor_default_prop:s0
tclass=property_service permissive=0'

Bug: 286063708
Bug: 286063029
Bug: 317754250
Test: Run VtsHalGraphicsComposer3_TargetTest
Change-Id: Ib5e83927ebebf05a640d127d9d11e94df101f224
2024-01-03 11:58:04 +08:00
Wilson Sung
cc395b9c2b Update error on ROM 11262681
Bug: 318308344
Test: SELinuxUncheckedDenialBootTest
Change-Id: Iafeb3ff1bc6ddeb93810bff26aff82399bcda679
2024-01-02 03:23:04 +00:00
Treehugger Robot
f64c0520fe Merge "Allow systemui to write protolog file" into main 2023-12-29 11:32:37 +00:00
Treehugger Robot
fe24ab7d3f Merge "Update error on ROM 11260603" into main 2023-12-29 09:58:35 +00:00
Wilson Sung
2b26409d08 Update error on ROM 11260603
Bug: 318033504
Test: SELinuxUncheckedDenialBootTest
Change-Id: I86190052aaaebc94f1eb7e670e1a7da312d537a3
2023-12-29 05:04:50 +00:00
Wilson Sung
720ab6329b Update error on ROM 11259228
Bug: 318032188
Test: SELinuxUncheckedDenialBootTest
Change-Id: I6d3f31d49cc64ee911367de6e61d5e4e1b7e280b
2023-12-29 04:33:07 +00:00
Wilson Sung
bdb5c3c383 Merge changes I1c22cd8a,I11427ca4 into main
* changes:
  Enforce system_suspend
  Enforce fastbootd
2023-12-27 13:38:16 +00:00
Wilson Sung
df88fd4e1c Add dc-main wakeup node
Bug: 308381292
Test: boot-to-home
Change-Id: I0165b4afab3b62bf4fec4ce6864cc1e8c6fc841a
2023-12-27 16:42:52 +08:00
Wilson Sung
594b74b447 Enforce system_suspend
Bug: 308381292
Test: boot-to-home
Change-Id: I1c22cd8af868183afbfe567a31af6069b81eebe0
2023-12-27 14:16:49 +08:00
Wilson Sung
415278abac Enforce fastbootd
Fix: 307468887
Test: boot-to-home and flash rom
Change-Id: I11427ca4d17a83c278463cc68e4935148a0d57b6
2023-12-27 13:52:31 +08:00
Wilson Sung
4cad299072 Allow systemui to write protolog file
This is enabled on debuggable builds only, includes
- Grant mlstrustedsubject typeattribute to wm_trace_data_file
- Grant systemui the write access to
  wm_trace_data_file

Bug: 251513116
Bug: 288049075
Test: make sepolicy
Change-Id: I47c9bbf13835b2e7eaac3e2b436e3b486ce02431
2023-12-27 10:59:28 +08:00
Wilson Sung
8345799166 Add kernel vendor_fw_file dir read permission
Fix: 288049349
Change-Id: I76751deb04e5b6a4362917c76764cddc74d0f76d
2023-12-27 10:41:21 +08:00
Wilson Sung
2b70f82f1d Move kernel from legacy to vendor
Bug: 312143882
Test: make sepolicy
Change-Id: I01b192c7d60cda8e52f6a3fffd5e0dec7a660172
2023-12-27 10:40:47 +08:00