Commit Graph

5048 Commits

Author SHA1 Message Date
Inseob Kim
98ebf2cf85 Add BUILD_BROKEN_TREBLE_SYSPROP_NEVERALLOW
A new sysprop neverallow rules are mandatory only for devices launching
with R or later. For devices already launched, neverallow rules can be
relaxed with adding following line to BoardConfig.mk:

BUILD_BROKEN_TREBLE_SYSPROP_NEVERALLOW := true

Bug: 131162102
Test: Set PRODUCT_SHIPPING_API_LEVEL := 30 and try building with
changing some system_public_prop to system_internal_prop
Test: m cts sepolicy_tests

Change-Id: Ia215fdcc39d82487446b9972325d8b344945965d
Merged-In: Ia215fdcc39d82487446b9972325d8b344945965d
(cherry picked from commit 7d61bcd7ec)
2019-10-15 09:29:27 +09:00
Joel Galenson
3344b0768d Add jiyong@ and smoreland@ to OWNERS file.
Test: None
Change-Id: Ib2df9f53963076db02dedf27f1cd2a345dde1e72
2019-09-27 07:51:34 -07:00
Ashwini Oruganti
d11bc88e29 Update bug_map to explicitly have the b/ prefix
This is part of a series of updates to bug_map across all of android
tree.

Bug: 141014771
Test: Generated a denial, verified that the bug id in the dmesg logs
remains unchanged.

Change-Id: Ida526ee3c583f575bcf3e4a05d078800140c8243
2019-09-23 14:16:43 -07:00
Treehugger Robot
70b042502f Merge "Don't create /data/hostapd" 2019-09-13 20:44:29 +00:00
Bowgo Tsai
844b9a2f5e Revert "Adding GSI keys"
This reverts commit 421986004d.
Wahoo has no first-stage ramdisk and there is no need to install
GSI keys there.

Bug: 140873290
Test: tree hugger

Change-Id: I4dfe0bb0d88dbbbcaa6742cef9f2405d3b7936d6
2019-09-12 13:28:00 +08:00
Treehugger Robot
78923f9b1e Merge "allow tee system_data_root_file:dir r_dir_perms;" 2019-09-10 04:14:17 +00:00
Paul Crowley
d85b44697a allow tee system_data_root_file:dir r_dir_perms;
aosp/1106014 introduces a new class system_data_root_file and
tee needs access to that as well as system_data_file.

09-09 20:26:53.639   645   645 I auditd  : type=1400 audit(0.0:9): avc: denied { read } for comm="qseecomd" name="/" dev="dm-2" ino=2 scontext=u:r:tee:s0 tcontext=u:object_r:system_data_root_file:s0 tclass=dir permissive=1
09-09 20:26:53.639   645   645 I qseecomd: type=1400 audit(0.0:9): avc: denied { read } for name="/" dev="dm-2" ino=2 scontext=u:r:tee:s0 tcontext=u:object_r:system_data_root_file:s0 tclass=dir permissive=1
09-09 20:26:53.639   645   645 I auditd  : type=1400 audit(0.0:10): avc: denied { open } for comm="qseecomd" path="/data" dev="dm-2" ino=2 scontext=u:r:tee:s0 tcontext=u:object_r:system_data_root_file:s0 tclass=dir permissive=1
09-09 20:26:53.639   645   645 I qseecomd: type=1400 audit(0.0:10): avc: denied { open } for path="/data" dev="dm-2" ino=2 scontext=u:r:tee:s0 tcontext=u:object_r:system_data_root_file:s0 tclass=dir permissive=1

Bug: 140402208
Test: Flash Taimen device, enroll fingerprint, check log for denials
Change-Id: Ie976d7bbe4aeba875b96b6b82a94734b71ba1cb9
2019-09-09 14:39:34 -07:00
Xin Li
5a76576146 DO NOT MERGE - Merge Android 10 into master
Bug: 139893257
Change-Id: I5a9a6dd645a962020d9e0064fbe38652a28770c4
2019-09-04 13:33:20 -07:00
Martin Stjernholm
e02bbf70a8 Update paths to the new ART APEX.
am: 0e56856cbb

Change-Id: I459963d7b623b4fd7731c4f03c6ecf4ee393d498
2019-09-02 03:42:28 -07:00
Paul Crowley
c51d71fcdd Don't create /data/hostapd
This directory isn't actually used, and vendor_init shouldn't be
creating things in /data

Bug: 140259336
Test: Set up a hotspot, check logs for issues.
Change-Id: I923be96d69d783476cfb65acdeae063e1b4d4f87
2019-08-30 15:10:02 -07:00
Martin Stjernholm
0e56856cbb Update paths to the new ART APEX.
Test: Presubmits
Bug: 135753770
Exempt-From-Owner-Approval: Approved internally
Change-Id: I98378100456dce927ccc253301a398d70d1b7368
Merged-In: I98378100456dce927ccc253301a398d70d1b7368
2019-08-27 16:47:29 +01:00
Xin Li
7be7adcf7c DO NOT MERGE - Merge build QP1A.190711.019 into stage-aosp-master
Bug: 139893257
Change-Id: If2e3e77ea1515fe32394638395ba4dec1e98c80f
2019-08-23 06:45:04 +00:00
Xin Li
3afbd8a227 DO NOT MERGE - Merge build QP1A.190711.001 into stage-aosp-master history
Bug: 139893257
Change-Id: Ia7c2c665274505301853ce3663fafff7e5618877
2019-08-23 06:42:05 +00:00
Steven Moreland
2cab3fed16 Merge "mediacodec_service: this service DNE"
am: cfe911b5fa

Change-Id: I90efa832bf38d80541e14792e08310f57d515a0b
2019-08-21 10:55:52 -07:00
Steven Moreland
cfe911b5fa Merge "mediacodec_service: this service DNE" 2019-08-21 17:47:59 +00:00
Steven Moreland
73b9711e82 Merge "Don't audit hwservice add -> find."
am: 2a9f6d14af

Change-Id: I14ab86b475540888ecd6db669814d22ce82c284f
2019-08-21 10:40:42 -07:00
Steven Moreland
3781ca3a3c mediacodec_service: this service DNE
Bug: 80317992
Test: automated only
Change-Id: I031b87a17a9b03b0a32d0fac10717bf57ef95d24
2019-08-21 17:35:08 +00:00
Treehugger Robot
2a9f6d14af Merge "Don't audit hwservice add -> find." 2019-08-21 17:28:58 +00:00
Steven Moreland
56078dad44 Don't audit hwservice add -> find.
Since an additional check related to getting the transport of a service
before registering it is more visible (this is moving a VTS test failure
to boot time for more visibility).

When adding a 'find' check on the 'add' path, this triggered some logs
here. 'find' has always been given with 'add' for other services, but
for a dontaudit, find has to be manually added.

Bug: 139274536
Test: TH
Change-Id: Ica4266dfaf17acc8c7bc8bd83054aa02811a4a37
2019-08-20 12:47:03 -07:00
Steven Moreland
d62b539bd2 [automerger skipped] Remove 'uce' service to move into core policy.
am: b012b9e1c8 -s ours
am skip reason: change_id I62a4e92b0dac4098d640cca515d0dd8680442779 with SHA1 c71438f85b is in history

Change-Id: I6d9eb3d796ca5adefe0e0d92e6481d93c57456e1
2019-08-20 12:11:57 -07:00
Steven Moreland
5309642ce8 Merge "Remove 'uce' service to move into core policy." into stage-aosp-master 2019-08-19 21:38:00 +00:00
Steven Moreland
b012b9e1c8 Remove 'uce' service to move into core policy.
Because it is used by the AOSP framework.

Bug: 136023468
Test: TH
Change-Id: I62a4e92b0dac4098d640cca515d0dd8680442779
Merged-In: I62a4e92b0dac4098d640cca515d0dd8680442779
(cherry picked from commit d19df6d3bc)
2019-08-19 12:38:57 -07:00
Steven Moreland
c71438f85b Remove 'uce' service to move into core policy.
Because it is used by the AOSP framework.

Bug: 136023468
Test: TH
Change-Id: I62a4e92b0dac4098d640cca515d0dd8680442779
Merged-In: I62a4e92b0dac4098d640cca515d0dd8680442779
(cherry picked from commit d19df6d3bc)
2019-08-19 12:29:37 -07:00
Xin Li
c7ca86a1bb DO NOT MERGE - Merge qt-dev-plus-aosp-without-vendor (5713463) into stage-aosp-master
Bug: 134405016
Change-Id: I7a6223a470187e4a6a683abfb906c12e8885e6b3
2019-08-14 12:04:02 -07:00
android-build-team Robot
0ff41cc5db Merge cherrypicks of [9169765, 9170440, 9170173, 9170474, 9170250, 9170251, 9170252, 9170462, 9170463, 9170464, 9170264, 9170422, 9170465] into qt-release
Change-Id: Iadea1fc5eeaf36bbfe23d78fdb66b4e5bc847231
2019-08-08 21:26:26 +00:00
Paul Scovanner
ad88fc1f7b Update Wahoo SVN to 32
Bug:139074978
Change-Id: I807f1d97205680ae0ac531c1b28101cef986cfda
(cherry picked from commit bc9e7660da)
2019-08-08 21:25:18 +00:00
Paul Scovanner
1833a81300 Update Wahoo SVN to 31
Bug:126590667
Change-Id: I048357eb4b33d84c4fac303c0f5dd44aae7614cb
(cherry picked from commit d46799a735)
2019-08-08 21:25:14 +00:00
Xin Li
33df4478de [automerger skipped] DO NOT MERGE - Merge pie-platform-release (PPRL.190705.004) into master
am: 9b3dbd9116 -s ours
am skip reason: subject contains skip directive

Change-Id: Ied8638255f9a371cbc9eb8669a3c38f0acf03678
2019-07-09 15:07:22 -07:00
Xin Li
9b3dbd9116 DO NOT MERGE - Merge pie-platform-release (PPRL.190705.004) into master
Bug: 136196576
Change-Id: I898ed81fac4ab4e4d55bccff1cb2376748a44871
2019-07-09 11:23:49 -07:00
George Chang
251d47231f Add com.nxp.mifare feature flag
am: 34141cf3b9

Change-Id: I2a38ed212b10baae812d8efb8f23cc2c0eea76da
2019-07-09 02:14:04 -07:00
android-build-team Robot
a473178427 Snap for 5713174 from 2aeb9b87f3 to qt-release
Change-Id: I4a711a9e1cc55d38838ec301f3abbfd21a783e06
2019-07-09 03:07:47 +00:00
Pawin Vongmasa
ff14dad13b Add missing performance points
am: 2aeb9b87f3

Change-Id: Iaa98dcca605ddc9ea842516befd20daaf07ea71e
2019-07-08 17:26:17 -07:00
android-build-team Robot
30262f8868 Snap for 5622519 from 6fd4275212 to pi-platform-release
Change-Id: Iab4bdf4852b4a7e47d1c76abd91215b81913c1ad
2019-07-08 23:35:14 +00:00
android-build-team Robot
f39a470c3b Snap for 5600800 from 0f2d2b3d63 to pi-platform-release
Change-Id: Id082ec977d1a0f2bb776dfa0562c72c72cb39cf7
2019-07-08 18:34:52 +00:00
George Chang
34141cf3b9 Add com.nxp.mifare feature flag
Bug: 136627156
Test: Check system feature from PackageManager
Change-Id: I5fb4de92437967c37de3b7c5c9ff03d5c3f0d2e1
2019-07-05 12:07:11 +08:00
Pawin Vongmasa
2aeb9b87f3 Add missing performance points
Test: cts-tradefed run cts -m CtsMediaTestCases \
-t android.media.cts.MediaCodecListTest#testAllHardwareAcceleratedVideoCodecsPublishPerformancePoints

Bug: 136536656
Change-Id: Iab2a1ae6a2365fb01e0c66d818974849cb8cf596
2019-07-04 04:48:49 -07:00
Adam Seaton
987bf8f8eb Update Wahoo SVN to 30 for Q release
am: 26ea1f7b49

Change-Id: Idea14af947f2b8a12a5311ea992176cc0e9704cb
2019-07-03 23:06:00 -07:00
android-build-team Robot
1f53a0a096 Snap for 5706892 from 26ea1f7b49 to qt-release
Change-Id: I506e2ac007fd6d71e743fc8bee68b923c4188f97
2019-07-04 03:05:01 +00:00
Adam Seaton
26ea1f7b49 Update Wahoo SVN to 30 for Q release
Bug:136220150
Change-Id: I00a79b87364bf613acd2594b65bdef50a46c70c6
2019-07-03 17:10:20 +00:00
Xin Li
adf50d12d8 [automerger skipped] DO NOT MERGE - Merge qt-dev-plus-aosp-without-vendor (5699924) into stage-aosp-master
am: 7079bb5d75 -s ours
am skip reason: subject contains skip directive

Change-Id: Ia1020e2ee8b5298e710f4e0cd06698896a24d02e
2019-07-02 10:01:10 -07:00
Xin Li
7079bb5d75 DO NOT MERGE - Merge qt-dev-plus-aosp-without-vendor (5699924) into stage-aosp-master
Bug: 134405016
Change-Id: Iabc35a41afa0d200bb126abc10a809f36bd4a46a
2019-07-01 20:59:11 +00:00
klinesjiang
a228ac6c74 Add sepolicy for RamdumpService to access property sys.boot.reason on Pixel 2 am: 96c2b2d303
am: ec2781bb15

Change-Id: I71e3cda76940abad949155690fd873b608e4a9d4
2019-07-01 05:52:06 -07:00
klinesjiang
ec2781bb15 Add sepolicy for RamdumpService to access property sys.boot.reason on Pixel 2
am: 96c2b2d303

Change-Id: Ib3514d491df8674341e1586f8f1af181a5f246aa
2019-07-01 05:43:10 -07:00
klinesjiang
96c2b2d303 Add sepolicy for RamdumpService to access property sys.boot.reason on Pixel 2
Denied pattern is:
avc: denied { read } for name="u:object_r:system_boot_reason_prop:s0" dev="tmpfs" ino=21223 scontext=u:r:ramdump_app:s0:c206,c256,c512,c768 tcontext=u:object_r:system_boot_reason_prop:s0 tclass=file permissive=0

Bug: 132220248
Merged-In: Id391450303a19b14a77ae564a0b79606f9c984fc
Change-Id: Id391450303a19b14a77ae564a0b79606f9c984fc
2019-06-26 03:25:48 +00:00
android-build-team Robot
cca7c07e90 Snap for 5685999 from a07062c52a to qt-release
Change-Id: I93ffa5bb7fdcb5dbbf1abe477b0c3908baaaf701
2019-06-25 12:42:00 +00:00
Tao Bao
b1f5d95707 Merge "Include misc_writer." into qt-dev
am: a07062c52a

Change-Id: Ic5d3afed2e03febe7139205a79b446bb5f797ba2
2019-06-24 16:10:33 -07:00
Tao Bao
a07062c52a Merge "Include misc_writer." into qt-dev 2019-06-24 22:13:36 +00:00
android-build-team Robot
64b10a8884 Snap for 5674462 from ec4f0d31b7 to qt-release
Change-Id: I078911b965303b551d203ae4b4d0f0897b6fe60f
2019-06-20 03:03:24 +00:00
Peiyong Lin
28f8c81a72 Merge "Disable WCG on Pixel 2017." into qt-dev
am: ec4f0d31b7

Change-Id: I588df7c7e3ffd6048d9bbaacad19c189835f1d97
2019-06-19 15:59:50 -07:00
Peiyong Lin
ec4f0d31b7 Merge "Disable WCG on Pixel 2017." into qt-dev 2019-06-19 22:18:10 +00:00