Commit graph

764 commits

Author SHA1 Message Date
Cheng Gu
48326b2e0b Update SELinux error
Bug: 317754251
Test: adb reboot and observe log
Change-Id: I7dcf9782ce2be632410e956871f74e874ddaf3a1
2024-05-28 22:31:47 +00:00
Roy Luo
ff802c138e Support sending vendor command to GL852G via libusbhost
libusbhost need access to USB device fs.

Bug: 261923350
Bug: 340665903
Test: no audit log in logcat after command execution
Change-Id: I4b0c8cc750eff12d2494504f9f215d5b1bab35fd
2024-05-22 00:49:12 +00:00
Frank Yu
3ef50e762f Update sepolicy for all device that use radioext 1.7 interface.
Bug: 340791912
Test: v2/pixel-health-guard/device-boot-health-check-extra
Change-Id: Icd7b482d88f52fbde6b281ef58857bfa6a9edea8
2024-05-20 03:17:49 +00:00
Wilson Sung
62cf04edbf [automerger skipped] Update SELinux error am: b65f4dacb2 -s ours
am skip reason: Merged-In I0d70966f03b0207388388fbc47e45de55a7385c3 with SHA-1 924e6c6cd3 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27392263

Change-Id: I5fc143ef7cbe16c19c70851412aec5fa575cecdb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-17 06:57:22 +00:00
Wilson Sung
b65f4dacb2 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Merged-In: I0d70966f03b0207388388fbc47e45de55a7385c3
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
(cherry picked from commit 924e6c6cd3)
2024-05-17 03:50:29 +00:00
Treehugger Robot
fd7f96c57c Merge "Allow hwc to access te_rate_hz & te_option" into main 2024-05-15 01:41:45 +00:00
Donnie Pollitz
c7ce4188a0 [automerger skipped] Merge "Add permission for storageproxy to create symlinks for ss" into 24D1-dev am: c41ed2ee7f -s ours
am skip reason: Merged-In I3f0559ee062c1b5393a2a35f957fbc8528bb58de with SHA-1 dd71a9cf27 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27067771

Change-Id: I7e5c1f6ba8adafab359f4594d70f97ccd5532f63
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-14 22:17:51 +00:00
Donnie Pollitz
cb30f22bea [automerger skipped] Add permission for storageproxy to create symlinks for ss am: e7837b9987 -s ours
am skip reason: Merged-In I3f0559ee062c1b5393a2a35f957fbc8528bb58de with SHA-1 dd71a9cf27 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27067771

Change-Id: I188ee0fd7c013dd874197f3d0cd9b9a1f186b6e8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-14 22:17:47 +00:00
Donnie Pollitz
c41ed2ee7f Merge "Add permission for storageproxy to create symlinks for ss" into 24D1-dev 2024-05-14 21:59:03 +00:00
Wilson Sung
924e6c6cd3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 340369535
Bug: 338347525 
Change-Id: I0d70966f03b0207388388fbc47e45de55a7385c3
2024-05-14 03:09:03 +00:00
Treehugger Robot
9519db1e1b Merge "sepolicy: allow hal_gnss_pixel to connect to hal_contexthub_default" into main 2024-05-13 08:09:15 +00:00
Cheng Chang
b9181de2ea sepolicy: allow hal_gnss_pixel to connect to hal_contexthub_default
avc:  denied  { call } for  scontext=u:r:hal_contexthub_default:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0

Bug: 339391267
Test: Verified the boot health at b/339391267#comment21.
Test: Verified the boot health at b/339391267#comment22.
Change-Id: I109d03e52f6576328b92ec0b18041da8fac502eb
2024-05-10 09:41:57 +00:00
Weizhung Ding
24015b5aeb Add HWC permission to access IStats AIDL am: 32a69c8d11
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27282714

Change-Id: Ia7f5f040fbe9b08384f5b61e398781f3fe9d3323
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-10 06:54:33 +00:00
Weizhung Ding
260af3904b add sysfs access permission on Zumapro devices. am: b5833b7ddf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27282713

Change-Id: Ibf10ea36cc1a257f0351daa7c154ba81a3d17226
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-10 06:54:30 +00:00
Weizhung Ding
32a69c8d11 Add HWC permission to access IStats AIDL
avc:  denied  { call } for  scontext=u:r:hal_graphics_composer_default:s0
tcontext=u:r:system_server:s0 tclass=binder permissive=0

Bug: 339598226
Test: Build and check log
Change-Id: I7e5ec165df0d397250b09f5981c1f45aea27bd4c
2024-05-09 11:49:47 +00:00
Weizhung Ding
b5833b7ddf add sysfs access permission on Zumapro devices.
Bug: 339598226
Test: build and check log
Change-Id: Ia7a7f0f8a5ffc63ab52f41d7a012260d73c54153
2024-05-09 11:49:19 +00:00
Shiyong Li
f99e596498 Merge "Add sepolicy for power_state sysfs node" into 24D1-dev am: 3806937561
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27059981

Change-Id: Id35a52793ecd1d69bb8a54dc12101837f77d74e4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-09 05:21:38 +00:00
Shiyong Li
3806937561 Merge "Add sepolicy for power_state sysfs node" into 24D1-dev 2024-05-09 05:16:16 +00:00
Burney Yu
85e79a0734 Allow hwc to access te_rate_hz & te_option
Bug: 315094023
Test: can access sysfs node te_rate_hz & te_option
Change-Id: Ib2f657560dcbab5a96a26dfa98e2f3a477702e00
2024-05-09 10:18:19 +08:00
KRIS CHEN
e8be86e6c7 Merge "Allow fingerprint to access the folder /data/vendor/fingerprint" into main 2024-05-08 08:46:30 +00:00
chenkris
bbf5ed6dbd Allow fingerprint to access the folder /data/vendor/fingerprint
Fix the following avc denial:
android.hardwar: type=1400 audit(0.0:20): avc:  denied  { write } for  name="fingerprint" dev="dm-56" ino=36703 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:vendor_data_file:s0 tclass=dir permissive=0

Bug: 267766859
Test: Tested fingerprint under enforcing mode
Change-Id: Ib1ec4f13b24a511f056012168ff8919107c6c1dd
2024-05-08 06:58:36 +00:00
Wei Wang
dec7c70056 Merge "zumapro: sepolicy: Update gpu available_frequencies sepolicies." into 24D1-dev am: 6c9df27593
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27088243

Change-Id: I1946280379f379c5566dfee2c2735734380d5769
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-06 16:41:34 +00:00
Wei Wang
6c9df27593 Merge "zumapro: sepolicy: Update gpu available_frequencies sepolicies." into 24D1-dev 2024-05-06 16:24:33 +00:00
Treehugger Robot
fb8ece30b7 Merge "sepolicy: allow hal_power_stats to read modem sysfs node" into 24D1-dev am: 3bfa8edd2d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27206477

Change-Id: Ic215eecf37588272b21a384c89550e4bacedcb6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-06 04:34:04 +00:00
Treehugger Robot
3bfa8edd2d Merge "sepolicy: allow hal_power_stats to read modem sysfs node" into 24D1-dev 2024-05-06 04:15:32 +00:00
Wayne Lin
89a73294a0 gps: maintain one solution
Bug: 315915958
Test: build pass and GPS function works
Change-Id: I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5
Merged-In: I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5
2024-05-06 03:52:43 +00:00
Wayne Lin
e2546691fe gps: maintain one solution
Bug: 315915958
Test: build pass and GPS function works
Change-Id: I15572cbfc9bc4aa5ca966a7905c6aac63bc972d5
2024-05-06 03:09:11 +00:00
Nicole Lee
6e4b317a71 Allows modem_svc to read the logging related properties am: fc41724a97
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27176301

Change-Id: Id7b52b03bb7e09b91e73cfe3167cb87041618254
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-03 12:16:55 +00:00
Nicole Lee
fc41724a97 Allows modem_svc to read the logging related properties
avc:  denied  { read } for  comm="modem_svc_sit" name="u:object_r:vendor_logger_prop:s0" dev="tmpfs" ino=417 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:vendor_logger_prop:s0 tclass=file permissive=0

Bug: 337184337
Change-Id: I806eee53b4ed0414b08f6203fb07958d6e0e4be1
2024-05-03 09:48:58 +00:00
Darren Hsu
ae01acb475 sepolicy: allow hal_power_stats to read modem sysfs node
avc:  denied  { read } for  name="link_duration" dev="sysfs"
ino=50065 scontext=u:r:hal_power_stats_default:s0
tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 338278462
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I691955410fb2cc24f8a372c6176a4fb7490309c4
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2024-05-03 15:21:09 +08:00
Spade Lee
b5d740cdd1 Merge "sepolicy: add logbuffer_device r_file_perms" into 24D1-dev am: adbb0eda58
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27135775

Change-Id: I4c4cdf330cb3a702b8da08473d2f6362a10d2833
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-03 05:24:16 +00:00
Spade Lee
adbb0eda58 Merge "sepolicy: add logbuffer_device r_file_perms" into 24D1-dev 2024-05-03 04:51:31 +00:00
Shawn Yang
0dd672a938 Merge "[PMS]Add context for PixelModemService and allow the access to shared modem service." into main 2024-05-02 22:20:10 +00:00
Priyanka Advani
97dcd536a8 Merge "Revert "sepolicy: Allow PixelGnss to connect to Chre HAL"" into 24D1-dev am: dae4c8d652
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27192520

Change-Id: I5c9d2eb447a81a80586d7111f9dce93aca0c8f6a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-02 19:54:21 +00:00
Priyanka Advani
dae4c8d652 Merge "Revert "sepolicy: Allow PixelGnss to connect to Chre HAL"" into 24D1-dev 2024-05-02 19:42:59 +00:00
Priyanka Advani
4c6f1b0a81 Revert "sepolicy: Allow PixelGnss to connect to Chre HAL"
Revert submission 27007604-pps_topic

Reason for revert: Droid-monitor created revert due to breakages in b/338407263. Will be verifying through ABTD before submission.

Reverted changes: /q/submissionid:27007604-pps_topic

Change-Id: Ib66d30e7de4fe1880296d2c66a99c2e941c96135
2024-05-02 16:28:07 +00:00
Treehugger Robot
cf2ee92ffc Merge "sepolicy: Allow PixelGnss to connect to Chre HAL" into 24D1-dev am: 7cdb6ff8b0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27007604

Change-Id: Ie79136497bbe8b68fd02fb768927963c906bc844
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-05-02 13:36:24 +00:00
Treehugger Robot
7cdb6ff8b0 Merge "sepolicy: Allow PixelGnss to connect to Chre HAL" into 24D1-dev 2024-05-02 13:12:59 +00:00
Treehugger Robot
de8e4b1133 Merge "lights: Add LED sysfs sepolicy" into main 2024-05-02 00:31:33 +00:00
Chungjui Fan
91aa5ade23 lights: Add LED sysfs sepolicy
Bug: 307424586
Change-Id: I5b919d56a72d98c7173004b1380ca50e3691aacc
Signed-off-by: Chungjui Fan <chungjuifan@google.com>
2024-04-30 01:21:57 +00:00
YiKai Peng
660715f1f8 Merge "selinux: label wakeup for BMS I2C 0x5B, 0x61" into main 2024-04-29 06:30:42 +00:00
Spade Lee
098fb2dabc sepolicy: add logbuffer_device r_file_perms
avc: denied { read } for name="logbuffer_max77779fg_monitor" dev="tmpfs" ino=1034 scontext=u:r:pixelstats_vendor:s0 tcontext=u:object_r:logbuffer_device:s0 tclass=chr_file permissive=0

Bug: 335934710
Test: no denied read logbuffer
Change-Id: Ie9cc3d7d0dbfc480cc8ff0bab2d600b8abf688c7
Signed-off-by: Spade Lee <spadelee@google.com>
2024-04-28 17:33:28 +00:00
mikeyuewang
5ce4700d6f [PMS]Add context for PixelModemService and allow the access to shared modem service.
Bug: 335490443
Change-Id: Ie5c6b0191775d42d402632c46c34cafe77fe5e60
2024-04-26 17:02:26 +00:00
YiKai Peng
af3f9d9d62 selinux: label wakeup for BMS I2C 0x5B, 0x61
Bug: 335557235
Test: v2/pixel-health-guard/device-boot-health-check-extra
Change-Id: If41db4725810a851f4a6a1a05566c2547f142da9
Signed-off-by: YiKai Peng <kenpeng@google.com>
2024-04-26 07:28:52 +00:00
Enzo Liao
3f4e9ffdbd [automerger skipped] Merge "Move SELinux policies of RamdumpService and SSRestartDetector to /gs-common." into 24D1-dev am: 6b1e936fd8 -s ours
am skip reason: Merged-In I455630b347f9f234365fec371142582d2cc0640a with SHA-1 2761dbe28b is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27046301

Change-Id: I5e38851de729ea69bfda4c219c636af70a71c2cb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-04-25 08:31:23 +00:00
Enzo Liao
9b7516efde [automerger skipped] Move SELinux policies of RamdumpService and SSRestartDetector to /gs-common. am: e4ceb50a9c -s ours
am skip reason: Merged-In I455630b347f9f234365fec371142582d2cc0640a with SHA-1 2761dbe28b is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/27046301

Change-Id: I677b04af41d0a1c3cf614df64359443dc3e64b42
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-04-25 08:31:16 +00:00
Enzo Liao
6b1e936fd8 Merge "Move SELinux policies of RamdumpService and SSRestartDetector to /gs-common." into 24D1-dev 2024-04-25 08:22:07 +00:00
Cheng Chang
c4d1594131 sepolicy: Allow PixelGnss to connect to Chre HAL
avc:  denied  { call } for  scontext=u:r:hal_contexthub_default:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0

Bug: 330120749
Test: Verify PixelGnss HAL can connect to Chre HAL.
Test: Function test verification b/330120749.
Test: b/330120749#comment24 health boot check.
Test: b/330120749#comment25 health boot check.
Change-Id: I051cc19407ba168fadea4d51ed4aa1527e414bb7
2024-04-25 07:49:16 +00:00
Peter (YM)
f1834f0d8c zumapro: sepolicy: Update gpu available_frequencies sepolicies.
Apply similar group coverage to sysfs_devices_system_cpu, allow service
to read available frequences and avoid invalid behaiovr

Bug: 336698561
Test: ls -lZ /sys/devices/platform/1f000000.mali
Change-Id: I5a4f0766b4778fd8895e41d52f6d6b92f9d90de5
Signed-off-by: Peter (YM) <peterym@google.com>
2024-04-25 06:42:28 +00:00
Kevin Ying
b5629419fe Add sepolicy for power_state sysfs node
Bug: 329703995
Test: manual - use camera with DisplayMonitor update
Change-Id: Ifd738a1726ba1c2ff0931eac653737f9be7daa87
Signed-off-by: Kevin Ying <kevinying@google.com>
2024-04-24 19:10:44 +00:00