Commit graph

800 commits

Author SHA1 Message Date
Nina Chen
c17830992f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 393978045
Flag: EXEMPT bugfix
Change-Id: Ia9ac79924046d5d5897733db12b98eb20273387c
2025-02-03 19:28:19 +08:00
Enzo Liao
ca25298baa RamdumpService: Fix the SELinux errors from introducing Firebase Analytics.
Fix it by ag/31334770 and remove the tracking bug number.

Bug: 386149336
Flag: EXEMPT bugfix
Change-Id: Iaa73666fb731f81302913822aa628669654ef66d
2025-01-21 14:18:24 +08:00
Treehugger Robot
bf9ff8d25d Merge "Remove sced sepolicy rule" into main 2025-01-14 23:40:47 -08:00
Treehugger Robot
74856c5fe1 Merge "Update SELinux error" into main 2025-01-12 23:03:44 -08:00
Nina Chen
ae8b31fc56 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 388949710
Flag: EXEMPT bugfix
Change-Id: I04806d6f1e03f81d0f981898dcc668bfc5b2513a
2025-01-12 21:59:31 -08:00
Xiaofan Jiang
cc502045b7 zumapro: update selinux to allow UMI on user build
Bug: 375335464

[   68.189198] type=1400 audit(1722986580.568:59): avc:  denied  { unlink } for  comm="binder:892_2" name="modem_svc_socket" dev="dm-52" ino=20239 scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1
[   68.189448] type=1400 audit(1722986580.568:60): avc:  denied  { create } for  comm="binder:892_2" name="modem_svc_socket" scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1
[   68.189448] type=1400 audit(1722986580.568:60): avc:  denied  { write } for  comm="binder:892_2" name="modem_svc_socket" scontext=u:r:modem_svc_sit:s0 tcontext=u:object_r:radio_vendor_data_file:s0 tclass=sock_file permissive=1

Flag: EXEMPT Critical modem system service
Change-Id: I43a3e33dc95eee8b06086ac438ce6d4cf038e2f5
2025-01-10 03:17:16 +00:00
Terry Huang
055d2792a1 Remove sced sepolicy rule
Bug: 381778782
Test: gts pass
Flag: EXEMPT bugfix

Change-Id: I9ee42b6f9330149bc4b010f9b66eaa2ed5711e64
2025-01-09 09:15:45 +08:00
Hung-Yeh Lee
86a67d00f3 display: mark dual display related nodes as sysfs_display
auditd  : type=1400 audit(0.0:8): avc:  denied  { write } for  comm="binder:497_1" name="expected_present_time_ns" dev="sysfs" ino=84293 scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0
auditd  : type=1400 audit(0.0:186): avc:  denied  { write } for  comm="binder:497_6" name="frame_interval_ns" dev="sysfs" ino=84294 scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 379245673
Test: reboot and logcat
Flag: EXEMPT sepolicy
Change-Id: I724e8884770dbdc5569d378f9a2d8e415bdb9ca9
2025-01-02 15:30:13 +08:00
Wilson Sung
47091d3760 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 386149336
Flag: EXEMPT update sepolicy
Change-Id: Ia6c47df7b264d75e4cbcf68109a9fb447d9c1422
2024-12-26 00:33:22 -08:00
Nina Chen
dc2ef84217 Update SELinux error.
Test: SELinuxUncheckedDenialBootTest
Bug: 385858548
Bug: 385858779

Bug: 385829048
Flag: EXEMPT bugfix
Change-Id: I50e70778b62a5e6142882e99f73f7f3b4597cfa4
2024-12-24 19:11:16 -08:00
Nina Chen
f856a0c782 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 384376420
Flag: EXEMPT sepolicy
Change-Id: Ie204c23c4abbca1c508939fba51e25de63024b20
2024-12-18 11:49:20 +08:00
Jeremy Nei
7d8c9f71f1 Merge "display/hwc: Add write access to persist display file." into main 2024-12-17 04:56:00 -08:00
Treehugger Robot
fa7425af9d Merge "gps: Remove GNSS SELinux error bug from bug_map" into main 2024-12-17 02:58:47 -08:00
James Huang
67452ae3ab gps: Remove GNSS SELinux error bug from bug_map
Bug: 309550514
Bug: 309550905
Bug: 309551062
Flag: EXEMPT clean up bug_map
Test: no avc denial
Change-Id: Ie0446e3b93ba26cc9ac35f70c7cd4c1c45ed1cd9
2024-12-17 05:02:18 +00:00
Wayne Lin
38a097edeb remove b/378004800 and b/318310869 from bugmap
Bug: 318310869
Bug: 378004800
Test: no avc denial
Flag: EXEMPT clean up bugmap
Change-Id: Id4aebb7862309978d30c9e93a24437de27f61e49
2024-12-17 11:25:45 +08:00
Timmy Li
ee9544c6bb Revert "Remove hal_camera_default aconfig_storage_metadata_file ..."
Revert submission 30893287-hal_camera_default_ aconfig_storage_metadata_file

Reason for revert: b/384580942

Reverted changes: /q/submissionid:30893287-hal_camera_default_+aconfig_storage_metadata_file

Change-Id: Ib55a2e4e724c233cfba8bb47bcc84e7f6dcfe087
2024-12-16 16:32:25 -08:00
Jeremy Nei
1cc3b8e59b display/hwc: Add write access to persist display file.
12-06 21:50:44.540   466   466 W vndbinder:466_2: type=1400 audit(0.0:186): avc:  denied  { write } for  name="factory_c
al0.pb" dev="sda1" ino=40 scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:persist_display_file:s0 tcla
ss=file permissive=0

Bug: 369456857
Test: adb shell displaycolor_service 20000
Flag: EXEMPT not applicable
Change-Id: I97a1d8e701d02d37e7d3be80a92d311948863536
2024-12-16 06:11:35 +00:00
timmyli
13173c755d Remove hal_camera_default aconfig_storage_metadata_file from bug map
Bug: 383013471
Test: manual test to see no avc denial
Flag: EXEMPT bug fix
Change-Id: I616c416194e17a645e217a5f81d14ae08c4214d3
2024-12-15 19:44:33 -08:00
Xin Li
5af5c4b8c1 [automerger skipped] Merge 24Q4 into AOSP main am: fc65b36404 -s ours am: 485c7ed97d -s ours
am skip reason: Merged-In Id4f43ba150bd476426ace22c7d866ee87d5777a0 with SHA-1 0507349a4b is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/29527092

Change-Id: I2a686e2fa77e83968c87adf0f3aa896c086143e9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-13 21:24:30 -08:00
Xin Li
485c7ed97d [automerger skipped] Merge 24Q4 into AOSP main am: fc65b36404 -s ours
am skip reason: Merged-In Id4f43ba150bd476426ace22c7d866ee87d5777a0 with SHA-1 0507349a4b is already in history

Original change: https://android-review.googlesource.com/c/device/google/zumapro-sepolicy/+/3413663

Change-Id: Id92291358d1ed62df1476ff282fc4e11bea8beaa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-13 19:35:40 -08:00
Xin Li
fc65b36404 Merge 24Q4 into AOSP main
Bug: 370570306
Merged-In: Id4f43ba150bd476426ace22c7d866ee87d5777a0
Change-Id: Ie0de67f4d904363b95219cc4ef77505a85504a52
2024-12-13 11:15:10 -08:00
Nina Chen
41ee821bea Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Flag: EXEMPT sepolicy
Bug: 383949166
Change-Id: I1d850c23cc01802f2abc4350019b81dda61c8bbd
2024-12-12 22:40:33 -08:00
Roy Luo
d4889afd78 Merge "Add udc sysfs to udc_sysfs fs context" into main 2024-12-11 17:22:03 -08:00
Eileen Lai
8aad411722 Merge "modem_svc: move shared_modem_platform related sepolicy to gs-common" into main 2024-12-09 15:09:35 +00:00
Roy Luo
20707fd77f Add udc sysfs to udc_sysfs fs context
Meeded for system server to monitor usb gadget state.
Grant hal_usb_impl read access as it's needed by UsbDataSessionMonitor.
Starting at board level api 202504 due to its dependency on aosp/3337514

10956 10956 W android.hardwar: type=1400 audit(0.0:327): avc:  denied  { read } for  name="state" dev="sysfs" ino=84394 scontext=u:r:hal_usb_impl:s0 tcontext=u:object_r:sysfs_udc:s0 tclass=file permissive=0

Bug: 339241080
Test: tested on Tokay
Flag: android.hardware.usb.flags.enable_udc_sysfs_usb_state_update
Change-Id: Iab79eec9a836d70792dfaa64eb24a5c013dc85aa
2024-12-09 13:21:14 +00:00
Jeremy Nei
1f96101a5e Merge "port display sysfs access" into main 2024-12-09 07:40:27 +00:00
Nina Chen
db19f527d7 Update SELinux error
copy bug_map entry from zuma

Test: SELinuxUncheckedDenialBootTest
Bug: 383013471
Flag: EXEMPT sepolicy
Change-Id: I514eb622b02f13b23aa3f9fe9c699b856a196c00
2024-12-09 11:43:18 +08:00
Rohan Narayanan
f5da0210e3 Merge "Add hal_shared_modem_platform to modem_diagnostic_app.te" into main 2024-12-06 20:05:22 +00:00
Dinesh Yadav
4814233812 Merge "Allow tachyon service to make binder calls to GCA" into main 2024-12-06 16:20:42 +00:00
Eileen Lai
862fbd7fe0 modem_svc: move shared_modem_platform related sepolicy to gs-common
Bug: 372400955

Change-Id: I9b69d1754f718faac51e89bb10c3a2ba604d2bae
Flag: NONE local testing only
2024-12-06 12:58:34 +00:00
Dinesh Yadav
1e5b6fb9eb Allow tachyon service to make binder calls to GCA
This permission is needed for tachyon service to call callbacks.

AVC Error seen when tachyon tries accessing GCA:
12-02 11:40:03.212  6987  6987 W com.google.edge: type=1400 audit(0.0:17): avc:  denied  { call } for  scontext=u:r:edgetpu_tachyon_server:s0 tcontext=u:r:google_camera_app:s0:c145,c256,c512,c768 tclass=binder permissive=0
12-03 07:12:26.424  4166  4166 W com.google.edge: type=1400 audit(0.0:254): avc:  denied  { call } for  scontext=u:r:edgetpu_tachyon_server:s0 tcontext=u:r:debug_camera_app:s0:c67,c257,c512,c768 tclass=binder permissive=0

Bug: 381787911
Flag: EXEMPT updates device sepolicy only
Change-Id: Iaa61d70cdffb75024c497482f4c0a6cab493bec3
2024-12-06 04:07:23 +00:00
Nina Chen
84aa7bf7a2 Merge "Update SELinux error" into main 2024-12-05 06:58:47 +00:00
Nina Chen
30570259fe Update SELinux error
Flag: EXEMPT sepolicy
Test: SELinuxUncheckedDenialBootTest
Bug: 382362300
Bug: 366116096
Change-Id: I8cf6742ded1f3b90b46909ee0ac47c9f33258466
2024-12-05 06:43:47 +00:00
Joner Lin
07c6dcc88f Merge "allow hal_bluetooth_btlinux write sysfs file" into main 2024-12-05 05:12:18 +00:00
jonerlin
a9b6884b3a allow hal_bluetooth_btlinux write sysfs file
12-04 19:32:23.040000  1002   784   784 I auditd  : type=1400 audit(0.0:30): avc:  denied  { write } for  comm="binder:784_2" name="uart_dbg" dev="sysfs" ino=60136 scontext=u:r:hal_bluetooth_btlinux:s0 tcontext=u:object_r:sysfs_bt_uart:s0 tclass=file permissive=0
12-04 19:32:23.040000  1002   784   784 W binder:784_2: type=1400 audit(0.0:30): avc:  denied  { write } for  name="uart_dbg" dev="sysfs" ino=60136 scontext=u:r:hal_bluetooth_btlinux:s0 tcontext=u:object_r:sysfs_bt_uart:s0 tclass=file permissive=0

Bug: 376774204
Test: v2/pixel-pts/release/bootstress/1200counts/suspend-resume
Flag: EXEMPT project configuration patch
Change-Id: I6c1a28d0e5e22b03b088d64d550fd475d796ae67
2024-12-05 02:41:13 +00:00
Jeremy Nei
c22f870169 port display sysfs access
Adds color_data access to sysfs_display

Bug: 369456857
Test: adb shell displaycolor_service 20000
Flag: EXEMPT N/A
Change-Id: Id2a00d138daad44d7135d5bd5652b128c1c63e46
2024-12-04 09:26:21 +00:00
Rohan Narayanan
afb2839d6e Add hal_shared_modem_platform to modem_diagnostic_app.te
This is needed to access the modem platform HAL.
FLAG: EXEMPT HAL interface change
Test: manual testing of selinux
Bug: 351024952

Change-Id: I95fc6b997e08ae46089ed90a1060c23274f6cd58
2024-12-04 01:57:48 +00:00
Jack Wu
57bf47fc5c add permission for hl7132 sysfs
Bug: 381457533
Test: adb bugreport
Flag: EXEMPT bugfix
Change-Id: I640957b4834e35f0c3aa9d3cd789865eff019dd3
Signed-off-by: Jack Wu <wjack@google.com>
2024-11-29 12:41:11 +08:00
Nina Chen
100436811e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 381327278
Flag: EXEMPT sepolicy
Change-Id: I359cc10c3a6f5bd5b20c4b1022f39f40484aa950
2024-11-28 03:00:00 +00:00
Mike Wang
6b1787d6f2 Merge "Update the PMS app seinfo for the certification change." into main 2024-11-27 16:25:53 +00:00
mikeyuewang
ec3dae0ee3 Update the PMS app seinfo for the certification change.
Bug: 375656221

Flag: EXEMPT selinux app context change.
Change-Id: If9bd9a3818b2f117cf26a13c2ae6940b53963b92
2024-11-27 16:23:53 +00:00
Nina Chen
81bc3731f1 Merge "Update SELinux error" into main 2024-11-26 05:28:35 +00:00
Nina Chen
0d60be5645 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 380989493
Flag: EXEMPT NDK
Change-Id: Iffaff71c72b03d58d2abcbe44007c2be469050bd
2024-11-26 05:28:21 +00:00
Treehugger Robot
dfaca94e55 Merge "Support access to radioext service over AIDL" into main 2024-11-26 05:17:15 +00:00
Julius Snipes
2bf44fa62f Merge "logger_app: allow logger_app to access persist.vendor.tcpdump.capture.len for logger_app" into main 2024-11-22 21:41:33 +00:00
Liana Kazanova (xWF)
62f34d8794 Revert "modem_svc: move shared_modem_platform related sepolicy t..."
Revert submission 30519089-move_modem_sepolicy

Reason for revert: DroidMonitor: Potential culprit for http://b/380274930 - verifying through ABTD before revert submission. This is part of the standard investigation process, and does not mean your CL will be reverted.

Reverted changes: /q/submissionid:30519089-move_modem_sepolicy

Change-Id: I74d37465d49e31c84d5e51bb0f020988a41b66ab
2024-11-21 17:54:10 +00:00
Eileen Lai
7e11c79345 modem_svc: move shared_modem_platform related sepolicy to gs-common
Bug: 372400955

Change-Id: I92d9a64c339f2b99e1fdc531145a950c3428dd82
Flag: NONE local testing only
2024-11-21 08:13:22 +00:00
Boon Jun
78eaa18cf3 Support access to radioext service over AIDL
11-13 17:08:24.418   396   396 E SELinux : avc:  denied  { find } for pid=15273 uid=1000 name=vendor.google.radio_ext.IRadioExt/default scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:hal_radio_ext_service:s0 tclass=service_manager permissive=0

Bug: 377991853
Bug: 371878208
Test: Open camera & observe connection to radio
Flag: EXEMPT bugfix
Change-Id: I1c53381f2aef1def44f7a717a9998acc826fe6aa
2024-11-20 10:30:05 +00:00
Nina Chen
9faa3999ef Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 379245474
Bug: 379245673
Bug: 379245788
Bug: 379244519
Bug: 379245853
Flag: EXEMPT NDK
Change-Id: Ic1c8e73773ed71eea7be46187231fde6b5283e8a
2024-11-15 11:02:02 +00:00
Nina Chen
23bcb285e8 Merge "Update SELinux error" into main 2024-11-15 06:57:24 +00:00