Commit Graph

4196 Commits

Author SHA1 Message Date
Steven Moreland
cfe911b5fa Merge "mediacodec_service: this service DNE" 2019-08-21 17:47:59 +00:00
Steven Moreland
3781ca3a3c mediacodec_service: this service DNE
Bug: 80317992
Test: automated only
Change-Id: I031b87a17a9b03b0a32d0fac10717bf57ef95d24
2019-08-21 17:35:08 +00:00
Treehugger Robot
2a9f6d14af Merge "Don't audit hwservice add -> find." 2019-08-21 17:28:58 +00:00
Steven Moreland
56078dad44 Don't audit hwservice add -> find.
Since an additional check related to getting the transport of a service
before registering it is more visible (this is moving a VTS test failure
to boot time for more visibility).

When adding a 'find' check on the 'add' path, this triggered some logs
here. 'find' has always been given with 'add' for other services, but
for a dontaudit, find has to be manually added.

Bug: 139274536
Test: TH
Change-Id: Ica4266dfaf17acc8c7bc8bd83054aa02811a4a37
2019-08-20 12:47:03 -07:00
Steven Moreland
b012b9e1c8 Remove 'uce' service to move into core policy.
Because it is used by the AOSP framework.

Bug: 136023468
Test: TH
Change-Id: I62a4e92b0dac4098d640cca515d0dd8680442779
Merged-In: I62a4e92b0dac4098d640cca515d0dd8680442779
(cherry picked from commit d19df6d3bc)
2019-08-19 12:38:57 -07:00
Xin Li
9b3dbd9116 DO NOT MERGE - Merge pie-platform-release (PPRL.190705.004) into master
Bug: 136196576
Change-Id: I898ed81fac4ab4e4d55bccff1cb2376748a44871
2019-07-09 11:23:49 -07:00
android-build-team Robot
30262f8868 Snap for 5622519 from 6fd4275212 to pi-platform-release
Change-Id: Iab4bdf4852b4a7e47d1c76abd91215b81913c1ad
2019-07-08 23:35:14 +00:00
android-build-team Robot
f39a470c3b Snap for 5600800 from 0f2d2b3d63 to pi-platform-release
Change-Id: Id082ec977d1a0f2bb776dfa0562c72c72cb39cf7
2019-07-08 18:34:52 +00:00
George Chang
34141cf3b9 Add com.nxp.mifare feature flag
Bug: 136627156
Test: Check system feature from PackageManager
Change-Id: I5fb4de92437967c37de3b7c5c9ff03d5c3f0d2e1
2019-07-05 12:07:11 +08:00
klinesjiang
96c2b2d303 Add sepolicy for RamdumpService to access property sys.boot.reason on Pixel 2
Denied pattern is:
avc: denied { read } for name="u:object_r:system_boot_reason_prop:s0" dev="tmpfs" ino=21223 scontext=u:r:ramdump_app:s0:c206,c256,c512,c768 tcontext=u:object_r:system_boot_reason_prop:s0 tclass=file permissive=0

Bug: 132220248
Merged-In: Id391450303a19b14a77ae564a0b79606f9c984fc
Change-Id: Id391450303a19b14a77ae564a0b79606f9c984fc
2019-06-26 03:25:48 +00:00
Treehugger Robot
59b083d504 Merge "Give IStats HAL access to fingerprint HAL" 2019-06-11 06:47:18 +00:00
Xin Li
86a4bcef94 Merge "DO NOT MERGE - Merge pie-platform-release (PPRL.190605.003) into master" 2019-06-10 19:54:58 +00:00
Treehugger Robot
7aab100641 Merge "Remove lines added to core policy." 2019-06-10 18:20:47 +00:00
The Android Open Source Project
95bada1e49 DO NOT MERGE - Merge pie-platform-release (PPRL.190605.003) into master
Bug: 134605042
Change-Id: Ia4e0aebef87d4e555886095ce2073db519b1ebc7
2019-06-10 09:32:23 -07:00
Felix
76f5a2774b Merge "sepolicy: Use BOARD_VENDOR_SEPOLICY_DIRS"
am: 465af7237d

Change-Id: I51e82e996827e5e8a6994de1a2895eb2f30bd2a2
2019-06-09 18:54:15 -07:00
Treehugger Robot
465af7237d Merge "sepolicy: Use BOARD_VENDOR_SEPOLICY_DIRS" 2019-06-10 01:41:27 +00:00
Xin Li
d29fbbf17a DO NOT MERGE - Merge pi-platform-release (PPRL.190605.003) into stage-aosp-master
Bug: 134605042
Change-Id: Id62df89a3187de0f25d2bddcf5f0dcac66c3751e
2019-06-05 15:18:13 -07:00
Joel Galenson
bc19390624 Remove lines added to core policy.
Test: Build.
Change-Id: I8b9a2c49637d59c565d2cf6eb701fdd548070b0d
2019-06-05 10:10:00 -07:00
android-build-team Robot
dd412a4d3d Snap for 5524043 from 7d3783e5f7 to pi-platform-release
Change-Id: I5584b46d6922897d41b601ce49e72d245ab451fb
2019-06-05 02:00:23 +00:00
Luke Huang
4d76153b25 netd socket related sepolicy rule cleanup
am: 026ef1f903

Change-Id: I381e30f537e441ef98ca08309f053e888ac31144
2019-06-02 23:48:53 -07:00
Luke Huang
026ef1f903 netd socket related sepolicy rule cleanup
netd socket is no longer used.

Bug: 65862741
Test: built, flashed, booted
Change-Id: I8e3dd90d17b6c12377b8e445bf7d43202057bf21
Merged-In: Ifeaf308e51ebc89f0c1da82a7d831d2bd656a80d
2019-05-30 17:54:34 +08:00
Felix
f0489c2c31 sepolicy: Use BOARD_VENDOR_SEPOLICY_DIRS
BOARD_SEPOLICY_DIRS is deprecated.

Change-Id: I046282b2a2e8c541726fb29cb0044503322d4be9
2019-05-28 14:05:51 +02:00
Tao Bao
d8520dd7a5 Revert^2 "Deprecate PRODUCT_STATIC_BOOT_CONTROL_HAL.""
am: 7375122722

Change-Id: Icd7f2562eabb4ca252b823425fe288f62eac8ddf
2019-05-23 11:40:56 -07:00
Tao Bao
7375122722 Revert^2 "Deprecate PRODUCT_STATIC_BOOT_CONTROL_HAL.""
This reverts commit d83c2cc22b.

The previous landing broke checkbuild targets due to namespace issue.
See the commit message for hardware/qcom/msm8998 change.

Bug: 34254109
Test: Build and boot taimen on device to home screen.
Test: Sideload on taimen.
Change-Id: I775026345eb5fc0ec580ba4ca0282835106a1d35
Merged-In: I775026345eb5fc0ec580ba4ca0282835106a1d35
(cherry picked from commit 4fa8e49020)
2019-05-22 15:41:22 -07:00
Ryan Savitski
ac4bd2f7f9 Allow camera to notify traced of a notable event (walleye/taimen)
am: 12b6414919

Change-Id: I75dcaee848bbc9a2a2636625d7a9a89a1e8a127e
2019-05-20 09:37:44 -07:00
Ryan Savitski
12b6414919 Allow camera to notify traced of a notable event (walleye/taimen)
Most apps already have the permission to act as full producers
(isolated_app, ephemeral_app, priv_app, untrusted_app_all), but
the camera doesn't inherit that as it runs in its own domain.

Granting only the socket (i.e. ipc) permission, as:
* only that is needed at the moment.
* granting the shmem/fd permissions would require a broader change, as traced_tmpfs is declared in private/.

Specific denial:
05-20 13:56:20.303  7751  7751 W trigger_perfett: type=1400 audit(0.0:19): avc: denied { write } for name="traced_producer" dev="tmpfs" ino=7061 scontext=u:r:google_camera_app:s0:c181,c256,c512,c768 tcontext=u:object_r:traced_producer_socket:s0 tclass=sock_file permissive=0 app=com.google.android.GoogleCamera

Bug: 130543265
Tested: extrapolating from the same fix on crosshatch, tested manually on blueline-userdebug.
Change-Id: I53dc08a28d167f566b759d8f91d00a4828f4847f
2019-05-20 13:03:04 +00:00
Xin Li
43bf541287 [automerger skipped] DO NOT MERGE - Merge pie-platform-release (PPRL.190505.001) into master.
am: 5f92082d07 -s ours
am skip reason: subject contains skip directive

Change-Id: I3925c95d007c41f2df69fa983c0124c5ad49b2d1
2019-05-16 19:11:28 -07:00
Xin Li
5f92082d07 DO NOT MERGE - Merge pie-platform-release (PPRL.190505.001) into master.
Bug: 132622481
Change-Id: I9c6392122d5e64654992bc746cddc6e536ba0d4c
2019-05-15 16:55:26 -07:00
android-build-team Robot
0f2d2b3d63 Merge cherrypicks of [7496339, 7495273, 7495624, 7496340, 7496341, 7496342, 7496343, 7495658, 7494789, 7494790, 7494791, 7496344, 7496345, 7496346, 7496347, 7496574, 7496348, 7496575, 7496576, 7496260, 7496349, 7496350, 7496440, 7496577, 7496578, 7496261, 7495625, 7496442, 7496351] into pi-qpr3-release
Change-Id: I08c88184e155ba0203f752c11ec80edf883f37cc
2019-05-14 04:59:29 +00:00
Paul Scovanner
927430f260 [DO NOT MERGE] Update Wahoo SVN to 28
Bug:132634503
(cherry picked from commit 934ba6d552)

Change-Id: I342944708a569ccad9c72cca498f384be224154e
2019-05-14 04:56:30 +00:00
Xin Li
9dae2bb79d DO NOT MERGE - Merge pi-platform-release (PPRL.190505.001) into stage-aosp-master
Bug: 132622481
Change-Id: Ifd9c64ef9eaaf942a5556037c751090c406e05d7
2019-05-13 15:54:55 -07:00
Emilian Peev
5815725a91 Merge "Allow vendor read access to 'ro.camera' property"
am: 874e7fb771

Change-Id: I62d38502ca0ea92aebd0258a7ececba8b4fd842e
2019-05-10 11:47:31 -07:00
Treehugger Robot
874e7fb771 Merge "Allow vendor read access to 'ro.camera' property" 2019-05-10 18:35:42 +00:00
Tao Bao
568277c5c1 Merge "AB_OTA_UPDATER is BoardConfig variable."
am: aa1f12d326

Change-Id: I93cd994848f0f9b72bc5a476d9f2fe2a474bbe81
2019-05-09 11:07:06 -07:00
Tao Bao
aa1f12d326 Merge "AB_OTA_UPDATER is BoardConfig variable." 2019-05-09 17:40:14 +00:00
Tao Bao
0221fd9684 AB_OTA_UPDATER is BoardConfig variable.
Bug: 130433003
Test: TreeHugger
Change-Id: I70c7a884df45781e8b14339edd02985ba3de02fd
2019-05-08 20:54:19 -07:00
android-build-team Robot
e580748606 Snap for 5450365 from af48631202 to pi-platform-release
Change-Id: Ifdd557d0055ca74f9a7511d42cdafa805ee44f48
2019-05-07 21:48:27 +00:00
android-build-team Robot
6fd4275212 Snap for 5526913 from 9424dc7bc5 to pi-qpr3-b-release
Change-Id: I5215a562afc40c5b063f0829e28a752e0d152dd1
2019-05-03 09:21:07 +00:00
Jack Yu
8b37892ee5 Merge "Enable aid block route setting and disable P2P polling mask"
am: 1abb1387e4

Change-Id: I842727bf7421ada729e00be42f3bf0111e1e8ded
2019-05-02 03:15:59 -07:00
Treehugger Robot
1abb1387e4 Merge "Enable aid block route setting and disable P2P polling mask" 2019-05-02 10:01:59 +00:00
Jack Yu
cba0e786b2 Enable aid block route setting and disable P2P polling mask
1. Align CE behavior on pixel devices
2. Disable P2P polling mask

Bug: 130509605
Test: Nfc on/off, CE/Tag
Change-Id: I51cd0b035638fef5fab623a90475a175ec898cf5
2019-05-02 06:50:17 +00:00
Joel Galenson
34acff6c64 Track SELinux denial.
am: 7e93d026d3

Change-Id: I26052f38c68d57c48943543529105c9718602928
2019-04-30 13:56:04 -07:00
Joel Galenson
7e93d026d3 Track SELinux denial.
This should help fix presubmit tests.

Bug: 131636647
Test: None.
Change-Id: I2bc7a7e46bd3b59edac6e503ec8cc71bfcaf04db
2019-04-30 08:01:39 -07:00
Emilian Peev
dc752c40b8 Allow vendor read access to 'ro.camera' property
The Camera HIDL wrapper needs access to
properties "ro.camera.req.fmq.size" and
"ro.camera.res.fmq.size" which control
the fast message queue size. Cases exist
where the default size is not sufficient.
The precise amount can be controlled by
the respective device configuration which
can set the previously mentioned properties.

Bug: 77865891
Test: Manual using application
Change-Id: I468bde2ee356e0d1d20f781fe6a3af48143cc4b2
2019-04-26 15:41:25 +00:00
Yifan Hong
dfc5936cd0 Merge "atcmdfwd: framework matrix -> device matrix"
am: fc54210685

Change-Id: I4a12e64b4788d8170bf52bc69075bcd39ad29328
2019-04-23 22:39:26 -07:00
Yifan Hong
fc54210685 Merge "atcmdfwd: framework matrix -> device matrix" 2019-04-24 05:21:24 +00:00
Joel Galenson
51e6a30b7b Track SELinux denial.
am: d9737f672b

Change-Id: Ic33fa7feba1e2381a9a9cf8fd5b9e39d12b5efb8
2019-04-23 15:28:50 -07:00
Yifan Hong
0280375d96 atcmdfwd: framework matrix -> device matrix
The HAL is served from a system app and used by
a vendor daemon.

Test: ls /system/app/atfwd/atfwd.apk
Test: ls /vendor/bin/ATFWD-daemon
Test: lshal
Bug: 130714844
Change-Id: I87e10fa56ac84ddd7e4210ac2bc4f1338265e1e9
Merged-In: I87e10fa56ac84ddd7e4210ac2bc4f1338265e1e9
2019-04-23 14:56:54 -07:00
Joel Galenson
d9737f672b Track SELinux denial.
This should help fix presubmit tests.

Bug: 131096543
Test: Build.
Change-Id: I19a854deb221a3c0f882618bb233da73c3463969
2019-04-23 12:14:03 -07:00
Maggie White
e5c5594bb5 Give IStats HAL access to fingerprint HAL
Give binder access to the stats HAL from the fingerprint HAL.
This is necessary because we're deprecating IPixelStats.

Bug: 122904980
Change-Id: I15c1a07680819f252b0e7c072598ff4fb29a1ce2
Signed-off-by: Maggie White <maggiewhite@google.com>
2019-04-16 13:24:58 -07:00