Commit Graph

1905 Commits

Author SHA1 Message Date
Jenny Ho
3ab8be18a5 Add permissions for maxfg_base/maxfg_secondary am: ee160b5880
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23467290

Change-Id: I899bc4150d6d32b0ede035c96487da50849b6256
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 01:50:10 +00:00
Jenny Ho
ee160b5880 Add permissions for maxfg_base/maxfg_secondary
Bug: 284878175
Change-Id: I3fe3030ecd36773405f0e70b767d4a28062d91ad
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2023-05-30 12:09:30 +08:00
Donnie Pollitz
36ea330be0 Allow vendor_init to fix permissions of TEE data file am: 955ae6825f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23412161

Change-Id: Ic51e258b34e4525f669a67d5eecd18b781bf6010
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:49:20 +00:00
Donnie Pollitz
955ae6825f Allow vendor_init to fix permissions of TEE data file
Background:
* vendor_init needs to be able to possibly fix ownership of
  tee_data_file

Bug: 280325952
Test: Changed permissions and confirmed user transitions
Change-Id: I27681589c9d0b0aa88463e6476fb75119ea89e8a
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-05-26 07:17:39 +00:00
sashwinbalaji
29df1ad288 thermal: thermal_metrics: Update selinux to reset stats am: 1113c66dea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23078641

Change-Id: I6a691341b37808102fd540fce39373498e18b379
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 06:18:24 +00:00
sashwinbalaji
1113c66dea thermal: thermal_metrics: Update selinux to reset stats
Bug: 193833982
Test: Local build and verify statsD logs
adb shell cmd stats print-logs && adb logcat -b all | grep -i 105045
Change-Id: I0dc1c557797d7fe97da7f0fcb2d600485526c979
2023-05-25 05:28:45 +00:00
Jin Jeong
aa606065a3 Revert "Fix SELinux error for com.google.android.euicc" am: 10ef6d8619
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163634

Change-Id: Ifa25563c9f0d157ce52f2d2d320c6cc166521c2a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:42 +00:00
Jin Jeong
35e908fd66 Revert "Fix LPA crash due to selinux denial" am: 980c71bea4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23167565

Change-Id: I7d6c19280280e63b194da9bdef8b8a80d057f364
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:42:36 +00:00
Jin Jeong
10ef6d8619 Revert "Fix SELinux error for com.google.android.euicc"
Revert submission 22899490-euicc_selinux_fix

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22899490-euicc_selinux_fix

Change-Id: I50ff4f8e48389d034c3f6c716dad1a81e9b73e64
2023-05-24 01:07:09 +00:00
Jin Jeong
980c71bea4 Revert "Fix LPA crash due to selinux denial"
Revert submission 22955599-euicc_selinux_fix2

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22955599-euicc_selinux_fix2

Change-Id: I2799c61ab5464e5551168f471740afe76edd1113
2023-05-24 01:07:09 +00:00
Anthony Zhang
143c8076c2 [DO NOT MERGE] Allow fingerprint to access persist property am: 7f19e81d61
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23286924

Change-Id: Iaa3d014c486c6179609a481811103665c141f3b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-22 19:19:13 +00:00
Anthony Zhang
7f19e81d61 [DO NOT MERGE] Allow fingerprint to access persist property
Bug: 258901849
Test: Local test on enrollment/delete, version update

Change-Id: I96acb79b3e600e0a4dd7b7a1cf494b20a876ca63
2023-05-22 18:36:54 +00:00
Luis Delgado de Mendoza Garcia
7a14a3a96f Add chre channel sepolicy entries am: 3992c42501
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22829545

Change-Id: I71ae96a9e7ff8861fd8b1835948d3e9c04a1d8c8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-16 23:36:06 +00:00
Luis Delgado de Mendoza Garcia
3992c42501 Add chre channel sepolicy entries
Bug: 281814892
Fix: 281814892
Test: in-device verification.
Change-Id: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
Merged-In: I3151d25c4a1cd7a858b84e0c8989dc160d368ca5
2023-05-16 22:49:12 +00:00
Wilson Sung
f19eec56a0 Update SELinux error am: d19337894a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23163633

Change-Id: Idf9dd1e06cdec3e1ffb5d7ae425fba99d54e071b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 07:45:07 +00:00
Adam Shih
2d2286d7c2 Introduce new sepoilcy owner am: 5cd759d295 am: 307e2c2fc8 am: 5e82524935
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: I2b7511a7aefba2354513e21ff49169637367451e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 04:22:40 +00:00
Adam Shih
5e82524935 Introduce new sepoilcy owner am: 5cd759d295 am: 307e2c2fc8
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: I8509e07c52ca5a75b4a9c10ffc3398a7c608c441
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 03:37:37 +00:00
Adam Shih
307e2c2fc8 Introduce new sepoilcy owner am: 5cd759d295
Original change: https://android-review.googlesource.com/c/device/google/gs201-sepolicy/+/2586605

Change-Id: Idc925c7a1f1111840a64664aa50c39442c3a0f8f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-15 02:59:55 +00:00
Wilson Sung
d19337894a Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 282096141
Change-Id: I0725e78a76436a0904205f83655755bf7c76c05f
2023-05-12 12:09:08 +08:00
Adam Shih
5cd759d295 Introduce new sepoilcy owner
Bug: 281631102
Test: N/A
Change-Id: I9bb7c6299f970a410481dd541523bec6df68cf23
2023-05-12 02:11:38 +00:00
Adam Shih
b39ed5f5ab add missing permission for gs201 power dump am: 2a02fe5fc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/23125499

Change-Id: I9fa0c89636bf3b961733ba91e5079d900ee031b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-11 05:38:59 +00:00
Adam Shih
2a02fe5fc5 add missing permission for gs201 power dump
Bug: 281602658
Test: adb bugreport
Change-Id: Ibf765c9da65d2c9f6a3825c91cb22771f583457a
2023-05-10 10:56:55 +08:00
Jinyoung Jeong
cc89605283 Fix LPA crash due to selinux denial am: 2d7181e3fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22949545

Change-Id: I161d19ec1cc786e85a6bf1ccfe5f0bed76ac98bc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:53:21 +00:00
Jinyoung Jeong
2d7181e3fc Fix LPA crash due to selinux denial
Bug: 280336861
Test: No crash found during LPA basic tests: download eSIM,
enable/disalbe eSIM.

Change-Id: Ie4fd8fccce5ec98cf0b2afff9a41f27206e52626
2023-05-02 14:10:00 +00:00
Hongbo Zeng
3d706a6ba4 Fix denials for radio service to access files under /data/venodr/radio am: 306bf73c79
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22899484

Change-Id: I1131ba266eb951d636cc5fc96bb8e370f87dc414
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 13:00:38 +00:00
Hongbo Zeng
306bf73c79 Fix denials for radio service to access files under /data/venodr/radio
Bug: 270561266
Test: get PASS result with go/ril-config-service-test and the original
      denial logs in http://b/270561266#comment8 are gone

Change-Id: I17155852bb2408b4389a86d32228292885e14c46
2023-05-02 08:05:31 +00:00
martinwu
25b8c58d06 [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: 5f9732a97a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22938357

Change-Id: Ic6b7025f009b00532c5669400090c0c5136707b7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:59:24 +00:00
martinwu
5f9732a97a [TSV2] Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
Merged-In: Ic804a3a4739ec5a9604320cb8e0fdae91b8429c1
2023-05-02 03:16:02 +00:00
Jinyoung Jeong
13cb55bee1 Fix SELinux error for com.google.android.euicc am: f265749f1d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22874711

Change-Id: I3d72968e6cf50c8db5a61269f52c2e7ed57888c1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:19:13 +00:00
Jinyoung Jeong
f265749f1d Fix SELinux error for com.google.android.euicc
Bug: 279548423
Test: http://fusion2/b7c803be-2dca-4195-b91f-6c4939746b5b
Change-Id: Idd231c2412e8f597dea1bfa11f9d1a0fa1e17034
2023-04-30 02:51:45 +00:00
Bruno BELANYI
0676395ee0 Remove 'hal_neuralnetworks_armnn' '/data' access exception am: a43d300aff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786254

Change-Id: Ibe2bf72c2ab156f6c3e08a2dacdb29df51edfdbf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:48 +00:00
Bruno BELANYI
93ef539d30 Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: 01a2e70a17
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786660

Change-Id: I7d58cb0fab0fa4fdba7362b5733248a8cf3dad09
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:42 +00:00
Bruno BELANYI
bd3d06a0af Add ArmNN config sysprops SELinux rules am: ee3fe73de0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22786979

Change-Id: I9f5909ed237c73266372bb22dc2378dc14f62a79
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:40:38 +00:00
Bruno BELANYI
a43d300aff Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:bb69b32fc5b6f468561017f6bd5628626a571696)
Merged-In: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
Change-Id: Ie651cd788e6f057cd902d1c14880bd1ad71ec5a5
2023-04-27 08:06:38 +00:00
Bruno BELANYI
01a2e70a17 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:4f1ca4a7ad3895f5a5adc25fc2cf3a532eac79f6)
Merged-In: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
Change-Id: Ief9f33ea3aca3f6b0756c92feb1753462e86b894
2023-04-27 08:06:38 +00:00
Bruno BELANYI
ee3fe73de0 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:9d61da55a193a12b7552e67e67d968c46d4dec86)
Merged-In: I90af8201d5fae44f73d709491f272a113b44ca67
Change-Id: I90af8201d5fae44f73d709491f272a113b44ca67
2023-04-27 08:06:38 +00:00
Martin Wu
ce4a8fe577 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..." am: c6d08c1781
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22891378

Change-Id: I8164db9870fc8cbe41b97c7083c3f69b825e99ae
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:11:47 +00:00
Martin Wu
c6d08c1781 Revert "Remove tcpdump sepolicy from gs201 and move sepolicy to ..."
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I5b1c00cc6a1ae186eb51acc2c99171578c43bace
2023-04-27 02:20:48 +00:00
martinwu
f269ec2d3c Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common am: b7e90ec616
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22817736

Change-Id: I482ed6a5804bb67140e6b7ad55ed7cfc5591b18a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:18:17 +00:00
martinwu
b7e90ec616 Remove tcpdump sepolicy from gs201 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I0eb9352e349ae8f06e469e953f137b00204f1c3b
2023-04-27 01:38:24 +00:00
Wilson Sung
f5c3a99197 Update error on ROM 9784808 am: 2b913d29a9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791801

Change-Id: I24e473bc7a18028dada6465d2e6333fce7433a6f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 07:37:59 +00:00
Wilson Sung
2b913d29a9 Update error on ROM 9784808
Bug: 274727778
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I56784948658365e8c9ecdf63d163109d8f29e5c3
2023-04-26 07:00:21 +00:00
Joseph Jang
eaee6f1757 Move recovery.te to device/google/gs-common/dauntless/sepolicy am: 2a5c26c9b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22791802

Change-Id: I9af98e544063fdcd2e77ad2a0a48de99489ff310
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:07:33 +00:00
Joseph Jang
2a5c26c9b4 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: I80fbd9ef0c7e988de21d07ada57fc6a038b9b585
2023-04-24 08:05:10 +00:00
Xin Li
e97e77fc5d [automerger skipped] Merge Android 13 QPR3 tm-qpr-dev-plus-aosp-without-vendor@9936994 am: 3ea4094def -s ours am: 31724cdda3 -s ours
am skip reason: Merged-In I0ecc64407118107860db434f0eb22cab0f55a2ba with SHA-1 b38886146a is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22723205

Change-Id: I116084046971ddbe9391a67ea014620df2e8578e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-21 22:34:05 +00:00
Xin Li
31724cdda3 [automerger skipped] Merge Android 13 QPR3 tm-qpr-dev-plus-aosp-without-vendor@9936994 am: 3ea4094def -s ours
am skip reason: Merged-In I0ecc64407118107860db434f0eb22cab0f55a2ba with SHA-1 b38886146a is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/22723205

Change-Id: I6218c957148b75ac9f341107dc809176d232a90a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-21 18:15:13 +00:00
Xin Li
3ea4094def Merge Android 13 QPR3 tm-qpr-dev-plus-aosp-without-vendor@9936994
Bug: 275386652
Merged-In: I0ecc64407118107860db434f0eb22cab0f55a2ba
Change-Id: I639a8e3b3933efe9b7fc0fff92aef8bead4bd8a1
2023-04-18 16:32:09 -07:00
jimsun
0f6b14dc95 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I4720650488eca100372d148313e04d6d8950ead5
2023-04-18 07:48:20 +00:00
Wilson Sung
4cc8eec22d Update error on ROM 9954737
Bug: 278639040
Bug: 278639040
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I0d71ec80ea0136f90336d8f80cb75b38b61ebced
2023-04-18 11:27:57 +08:00
Bruno BELANYI
c1ee9afdef Use restricted vendor property for ARM runtime options
They need to be read by everything that links with libmali, but we don't
expect anybody to actually write to them.

Bug: b/272740524
Test: CtsDeqpTestCases (dEQP-VK.protected_memory.stack.stacksize_*)
Change-Id: I4cd468302da02603cccd9b4b98cb95745129daf5
2023-04-17 10:59:19 +00:00