Steve Pfetsch
321cee7e61
wahoo: dumpstate: add touch firmware versions to dumpstate
...
Bug: 38207199
Change-Id: I2b21f92f64847286a34d7d52a932bd1f825fe000
2017-06-19 10:44:15 -07:00
Thierry Strudel
1b5fe2a540
Merge changes from topic 'merge-msm8998-AU210' into oc-dr1-dev
...
* changes:
netmgrd: Change binary location to netutils
Introduce cne server and apiservice hal
Update IMS and radio SE policies based on AU 194 drop
Adding contexts and allows for time_daemon
2017-06-17 00:09:08 +00:00
TreeHugger Robot
4eb8e11c2c
Merge "Add spn-conf.xml for wahoo" into oc-dr1-dev
2017-06-16 23:36:33 +00:00
Thierry Strudel
77199d72f8
Merge "suppress spurious module loading denials" into oc-dr1-dev
2017-06-16 22:29:12 +00:00
Ecco Park
1cbbad1f55
Merge "wifi: add the read permission for /proc/ath_pktlog/cld" into oc-dr1-dev
2017-06-16 20:33:07 +00:00
Ecco Park
ca38bc851d
wifi: add the read permission for /proc/ath_pktlog/cld
...
Error:
type=1400 audit(1497566325.222:1870): avc: denied { read
} for pid=963 comm="cnss_diag" name="cld" dev="proc" ino=4026533982
scontext=u:r:wcnss_service:s0 tcontext=u:object_r:proc:s0 tclass=file
permissive=0
Bug: 36823983
Change-Id: Ie231bedccfc75d020e7a467d9b87b0e44e46fad2
Signed-off-by: Ecco Park <eccopark@google.com >
2017-06-16 11:09:51 -07:00
Thierry Strudel
4c80a57708
Merge "Add tangomapper and tango cts to tango_core SE context" into oc-dr1-dev
2017-06-16 17:00:51 +00:00
Subash Abhinov Kasiviswanathan
664f2d4397
netmgrd: Change binary location to netutils
...
Generic system partition binaries are no accessible on latest
versions of AOSP. As a result, use the netutils wrapper equivalents
of ip[6]tables, ip and tc. Fix the following denials -
type=1400 audit(1495499715.886:76): avc: denied { use } for pid=1370
comm="tc-wrapper-1.0" path="pipe:[28029]" dev="pipefs" ino=28029
scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0 tclass=fd
permissive=0
type=1400 audit(159.269:260): avc: denied { write } for pid=1612
comm="ndc-wrapper-1.0" path="pipe:[30233]" dev="pipefs" ino=30233
scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0
tclass=fifo_file permissive=0
type=1400 audit(159.269:267): avc: denied { read } for pid=1612
comm="ndc-wrapper-1.0" path="pipe:[30809]" dev="pipefs" ino=30809
scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0
tclass=fifo_file permissive=0
type=1400 audit(10632.149:134): avc: denied { read write } for
pid=1523 comm="ndc-wrapper-1.0" path="socket:[28342]" dev="sockfs"
ino=28342 scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0
tclass=netlink_socket permissive=0
type=1400 audit(3510988.283:134): avc: denied { module_request } for
pid=773 comm="netmgrd" kmod="netdev-rmnet_ipa0"
scontext=u:r:netmgrd:s0 tcontext=u:r:kernel:s0 tclass=system
permissive=0
type=1400 audit(1496866410.453:216): avc: denied { read } for
pid=810 comm="netmgrd" name="timestamp_switch" dev="sysfs" ino=27263
scontext=u:r:netmgrd:s0 tcontext=u:object_r:sysfs_timestamp_switch:s0
tclass=file permissive=0
type=1400 audit(1496882073.170:67506) avc: denied { open } for pid=822
comm="netmgrd" path="/sys/module/diagchar/parameters/timestamp_switch"
dev="sysfs" ino=27263 scontext=u:r:netmgrd:s0
tcontext=u:object_r:sysfs_timestamp_switch:s0 tclass=file permissive=0
audit(1496448874.298:224) avc: denied { read write } for pid=3976
comm="iptables-wrappe" path="socket:[35109]" dev="sockfs" ino=35109
scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0
tclass=tcp_socket permissive=1
audit(1496448785.385:139) avc: denied { getattr } for pid=1709
comm="ndc" path="pipe:[31264]" dev="pipefs" ino=31264
scontext=u:r:netutils_wrapper:s0 tcontext=u:r:netmgrd:s0
tclass=fifo_file permissive=1
CRs-Fixed: 2054108
Test: Verified that the LTE data and WiFi calling works
Bug: 62258789
Change-Id: I91e663ab35369f75d33ef4788c87bde14605f6b9
2017-06-16 09:21:30 -07:00
Jayachandran C
8466d682ec
Introduce cne server and apiservice hal
...
Replace protobuf over socket with hidl.
Bug: 38043081
Bug: 37153322
Change-Id: I9884386a8d66f1abd5a1a37ec7c6ff8fcccde33f
2017-06-16 09:21:30 -07:00
Jayachandran C
25591f24ea
Update IMS and radio SE policies based on AU 194 drop
...
Permissive to enforce for ims and cnd domains
Introduce new CNE HIDL service
Remove CNE talking to cnd via socket and move to HIDL
Allow IMS to access sysfs data and diag files
Allow radio to access telephony monitor property
Bug: 38043081
Change-Id: I1775d6aea4de9843fdbedd06ebd71ec213f38189
2017-06-16 09:21:30 -07:00
Max Bires
b7c0dc9aaf
Adding contexts and allows for time_daemon
...
denied { write } for pid=741 comm="time_daemon" name="time" dev="sda10"
ino=335873 scontext=u:r:time_daemon:s0
tcontext=u:object_r:system_data_file:s0 tclass=dir
denied { search } for pid=825 comm="time_daemon" name="time" dev="sda10"
ino=335873 scontext=u:r:time_daemon:s0
tcontext=u:object_r:time_data_file:s0 tclass=dir
denied { create } for pid=894 comm="time_daemon" name="ats_13"
scontext=u:r:time_daemon:s0 tcontext=u:object_r:time_data_file:s0
tclass=file
denied { create } for pid=820 comm="time_daemon" name="ats_13"
scontext=u:r:time_daemon:s0 tcontext=u:object_r:persist_file:s0
tclass=file
denied { search } for pid=834 comm="time_daemon" name="time" dev="sda4"
ino=23 scontext=u:r:time_daemon:s0
tcontext=u:object_r:persist_time_file:s0 tclass=dir
denied { write } for pid=865 comm="time_daemon" name="time" dev="sda4"
ino=23 scontext=u:r:time_daemon:s0
tcontext=u:object_r:persist_time_file:s0 tclass=dir
Bug: 34784662
Bug: 38415848
Test: time works
Change-Id: I4e859761f32bb0e203e1047f5c491602efcc43b0
(cherry picked from commit 59425a13e6 )
2017-06-16 09:21:30 -07:00
TreeHugger Robot
daa2ff2508
Merge "Fix denials for xtra-daemon file creation" into oc-dr1-dev
2017-06-16 01:43:21 +00:00
TreeHugger Robot
ef7dedbfe8
Merge "Remove treble violations from sepolicy" into oc-dr1-dev
2017-06-16 01:06:24 +00:00
Jeff Vander Stoep
a287c3bb29
suppress spurious module loading denials
...
We only load modules during boot, on only by a single script:
init.insmod.sh
Other denials are caused by code we don't rely on that
automatically looks for modules.
Bug: 34784662
Test: build policy
Change-Id: Iccdbe52582e9960f49ecb4ba9b472cf792e48fe6
2017-06-15 15:38:56 -07:00
Ranjith Kagathi Ananda
e84735870c
Add tangomapper and tango cts to tango_core SE context
...
* Add com.google.tango.* to tango_core SE context
* Replace the key.pem used for tango apps for userbuild.
Use a release key instead of dummy key
* Resolve denials for tango_core:
avc: denied { search } for name="/" dev="sdd3" ino=2
scontext=u:r:tango_core:s0:c512,c768 tcontext=u:object_r:persist_file:s0
tclass=dir permissive=0
avc: denied { search } for name="sensors" dev="sdd3" ino=16
scontext=u:r:tango_core:s0:c512,c768
tcontext=u:object_r:persist_sensors_file:s0 tclass=dir permissive=0
avc: denied { getattr } for
path="/persist/sensors/calibration/calibration.xml" dev="sdd3" ino=38
scontext=u:r:tango_core:s0:c512,c768
tcontext=u:object_r:persist_sensors_file:s0 tclass=file permissive=1
avc: denied { open } for
path="/persist/sensors/calibration/calibration.xml" dev="sdd3" ino=38
scontext=u:r:tango_core:s0:c512,c768
tcontext=u:object_r:persist_sensors_file:s0 tclass=file permissive=1
avc: denied { read } for name="calibration.xml" dev="sdd3" ino=38
scontext=u:r:tango_core:s0:c512,c768
tcontext=u:object_r:persist_sensors_file:s0 tclass=file permissive=0
BUG=62581695
Test: Tested on walleye
Change-Id: Ifac77c8190e59d88c9f1a65ab451e7e060742082
2017-06-15 15:24:45 -07:00
Wyatt Riley
fc83072eed
Fix denials for xtra-daemon file creation
...
avc: denied { create } for name="xtra.sqlite" scontext=u:r:location:s0
tcontext=u:object_r:location_data_file:s0 tclass=file permissive=0
avc: denied { create } for name="nvparam.sqlite" scontext=u:r:location:s0
tcontext=u:object_r:location_data_file:s0 tclass=file permissive=0
avc: denied { create } for name="pcid.data" scontext=u:r:location:s0
tcontext=u:object_r:location_data_file:s0 tclass=file permissive=0
Thinner version of
https://partner-android-review.googlesource.com/#/c/840686/
Aligns with marlin
Bug: 62603830
Test: Build, run GPS, check denials
Change-Id: I8b0f11b73c09513a4c19232cfde03b378b93f8f3
2017-06-15 15:06:56 -07:00
Jeff Vander Stoep
bbc467932d
Add domain for widevine HAL
...
Address:
[ 14.701366] init: service drm-widevine-hal-1-0 does not have a
SELinux domain defined
avc: denied { ioctl } scontext=u:r:hal_drm_widevine:s0
tcontext=u:object_r:vndbinder_device:s0 tclass=chr_file
avc: denied { open } scontext=u:r:hal_drm_widevine:s0
tcontext=u:object_r:vndbinder_device:s0 tclass=chr_file
avc: denied { read write } scontext=u:r:hal_drm_widevine:s0
tcontext=u:object_r:vndbinder_device:s0 tclass=chr_file
Bug: 62075360
Test: built and booted xyz_test-userdebug
Test: added account and watched video on Play movies. Listened
to songs on Play Music
Change-Id: Id219da343b1268a7492b50f870334a1e7dc151d5
2017-06-15 21:45:31 +00:00
TreeHugger Robot
115b724ccd
Merge "supress spurious firmware_file denial" into oc-dr1-dev
2017-06-15 21:34:22 +00:00
Jeff Vander Stoep
97f996a846
supress spurious firmware_file denial
...
avc: denied { search } comm="cnss-daemon" scontext=u:r:wcnss_service:s0
tcontext=u:object_r:firmware_file:s0 tclass=dir
Test: build policy
Bug: 34784662
Change-Id: Ic89abbfdb2b36cb35c5a7f14abb21c9464b60561
2017-06-15 12:25:27 -07:00
Meng Wang
a3f7b11d87
Add spn-conf.xml for wahoo
...
Bug: 62646036
Test: make - spn-conf.xml appears in /system/etc
Test: manual - see the bug
Change-Id: I842c312319c8e1329c38f83ac0ecd214f9080578
2017-06-15 12:13:35 -07:00
Jeff Vander Stoep
da1ebb7d92
Remove treble violations from sepolicy
...
Bug: 36570300
Bug: 36570130
Test: build and boot device
Change-Id: I248a31048a867a4e8a4a0c756936e9371d16d320
2017-06-15 11:26:24 -07:00
TreeHugger Robot
e6ee6b54ff
Merge "Fixing hal_imsrtp timestamp read issue" into oc-dr1-dev
2017-06-15 18:23:57 +00:00
TreeHugger Robot
2d85910d9f
Merge "Fixing a sensors issue" into oc-dr1-dev
2017-06-15 07:09:19 +00:00
Thierry Strudel
baf22be3bc
Merge "wahoo: voip rx controls" into oc-dr1-dev
2017-06-15 05:33:28 +00:00
Haynes Mathew George
853aecdf9b
wahoo: voip rx controls
...
mixer path additions
audio_platform info updates
Bug: 62393776
Test: hangout call
Change-Id: I7af811856846d8075e16ff8f540a7931d31581c9
Signed-off-by: David Lin <dtwlin@google.com >
2017-06-15 02:25:22 +00:00
Chris Thornton
2815735796
Merge "Remove unused modules and decrease buffer size to reduce fragmentation risk." into oc-dr1-dev
2017-06-15 01:00:16 +00:00
TreeHugger Robot
15f7fe745e
Merge "Deprecate ril.subscription.types" into oc-dr1-dev
2017-06-14 19:43:42 +00:00
Pankaj Kanwar
30e8e49e85
Merge "add missing cfg to product packages" into oc-dr1-dev
2017-06-14 18:59:36 +00:00
Niranjan Pendharkar
f24953f875
add missing cfg to product packages
...
IPACM_cfg.xml is needed for ipacm configuration and needs to be installed.
CP from Partner.
Bug: 34361337
Test: manual
Change-Id: Ib7c4855ab758221feb7d5eb179ebe664c57f341b
2017-06-14 18:58:59 +00:00
Sandeep Patil
9e75e0ed2c
rild: add radio to rild socket rule temporarily
...
The rule is added to ensure we dont break the radio to
rild communication once we remove the same rule from platform's
sepolicy for treble devices. This change MUST be reverted along with
the change to use HIDL between radio and rild domains.
Bug: 62616897
Bug: 62343727
Test: Build and boot.
Change-Id: I846389257bf9d40bac55299c24d2cf07c74e9092
Signed-off-by: Sandeep Patil <sspatil@google.com >
2017-06-14 09:12:50 -07:00
Thierry Strudel
e19f915247
Merge "Usb: HAL: Update wahoo HAL" into oc-dr1-dev
2017-06-14 05:40:55 +00:00
Badhri Jagan Sridharan
cb3e84691f
Usb: HAL: Update wahoo HAL
...
This CL rebases wahoo HAL based on the kernel change to update
sysfs interface.
https://partner-android-review.googlesource.com/#/c/836088/
Bug: 62272992
Test: Verify USB dialog on wahoo
Change-Id: I8bc8f494176c7648abeb9783fbd18dc837793bda
2017-06-13 17:23:08 -07:00
Max Bires
187628ed87
Fixing a sensors issue
...
denial:
denied { write } for pid=7720 comm="sensors.qcom" name="sensors"
dev="sdd3" ino=16 scontext=u:r:sensors:s0
tcontext=u:object_r:persist_sensors_file:s0 tclass=dir
Bug: 62555317
Bug: 34784662
Test: sensors domain works properly
Change-Id: Ibb41c6c699282383e80a4cb80784ccc544787d71
2017-06-13 16:31:58 -07:00
Max Bires
59733a30d1
Fixing hal_imsrtp timestamp read issue
...
denied { read } for pid=1148 comm="ims_rtp_daemon"
name="timestamp_switch" dev="sysfs" ino=27258 scontext=u:r:hal_imsrtp:s0
tcontext=u:object_r:sysfs_timestamp_switch:s0 tclass=file
Bug: 34784662
Test: this denial no longer appears
Change-Id: I7760173500d8b9c5abbc3eeded1ffba04c49988f
2017-06-13 14:52:26 -07:00
TreeHugger Robot
b47fc7b552
Merge "haptics: move playback mode setting to on()" into oc-dr1-dev
2017-06-13 21:08:22 +00:00
TreeHugger Robot
d76cf1df96
Merge "audio: add policy configuation for mmap no irq mode" into oc-dr1-dev
2017-06-13 19:26:46 +00:00
TreeHugger Robot
d116fc4734
Merge "AOD: Use double tap coordinates to trigger Ambient Indication" into oc-dr1-dev
2017-06-13 19:00:40 +00:00
Pankaj Kanwar
b9bf282710
Merge "move ipacm to vendor and sepolicy definitions" into oc-dr1-dev
2017-06-13 15:58:05 +00:00
Steve Pfetsch
9e70df5937
Merge "wahoo: Fix display calibration data denial" into oc-dr1-dev
2017-06-13 07:13:40 +00:00
Thierry Strudel
d083d94b56
Merge "init.hardware.rc: set ro.boot.hardware.revision as ro.revision" into oc-dr1-dev
2017-06-13 05:27:03 +00:00
Thierry Strudel
fa36ca91a9
init.hardware.rc: set ro.boot.hardware.revision as ro.revision
...
Bug: 62350763
Change-Id: I224a81e4e364a6a8a73980f7d7bbeebafdb2a6de
Signed-off-by: Thierry Strudel <tstrudel@google.com >
2017-06-12 22:25:10 -07:00
Meng Wang
9dc57606ec
Deprecate ril.subscription.types
...
Bug: 62454369
Test: manual - 'CDMA subscription' UI gone
Change-Id: I7478f738d410db114cb88de2cc9831289f7c7fb0
2017-06-12 21:49:47 -07:00
David Lin
9a0a8d2f42
haptics: move playback mode setting to on()
...
This patch moves the device playback mode configuration from off() to
on() to avoid the unnecessarily switching from rtp to waveform mode for
consecutive waveform playbacks.
Bug: 62507430
Test: vts, haptic stresss test
Change-Id: I0f7c1f6263dcb4da59695c1619aade47f7381541
Signed-off-by: David Lin <dtwlin@google.com >
2017-06-13 02:41:40 +00:00
Niranjan Pendharkar
253cdd58b5
move ipacm to vendor and sepolicy definitions
...
add ipacm/offload related definitions to init and sepolicies
CP from Partner.
Bug: 34361337
Test: manual
Change-Id: I7264a500b4c0db82dad4d8b6c3768787693106f9
2017-06-13 02:29:24 +00:00
Jayachandran C
7723ec091e
Move netmgr logging path to /data/vendor as per treble rules
...
Netmgr logging path changed from /data/misc to /data/vendor
Test: Verified bugreport collecting netmgr logs
Bug: 62504502
Change-Id: Iba7f585597e30d8dfedae5bb2a73a759aeb0c737
2017-06-13 01:30:42 +00:00
TreeHugger Robot
e138c4bd57
Merge "Add Wahoo SELinux Policy" into oc-dr1-dev
2017-06-12 23:39:48 +00:00
Zhijun He
c066dd944a
mm-camera: enable gravity sensor
...
For lens sag correction
Bug: 62205237
Change-Id: I16e7620c34dd2fd2d1f1ea7ea684a6c5504eaf5f
2017-06-12 21:05:51 +00:00
Naseer Ahmed
3cae7d39da
wahoo: Fix display calibration data denial
...
Bug: 62434319
Change-Id: Iefbeb15e42490234ae8c0d4c0eb5f7d59fa2b9d6
2017-06-12 13:21:47 -07:00
Eric Laurent
2cac386a0b
audio: add policy configuation for mmap no irq mode
...
Bug: 33398120
Test: build taimen-eng
Change-Id: I0d83ef83b536de0613a20ccf6a72baf8f64f0ff5
2017-06-12 18:06:43 +00:00
Polina Bondarenko
6f7dab1ce3
Enable carrierlock feature for pixel 2017 devices.
...
Bug: 62401470
Test: add/remove simlock.
Change-Id: I5f2e56c8cb5267f4563c5f2a2331b63563c6a77d
(cherry picked from commit a733dc60d4 )
2017-06-12 10:58:16 +00:00