Commit Graph

126 Commits

Author SHA1 Message Date
JohnnLee
2f42af0095 Remove obsolete entries
Test: adb bugreport
Bug: 238143398
Bug: 239887174
Change-Id: I4d9d3f82be1d7a9b28d4476f4f7c4c3bc745f98e
2023-05-10 16:12:48 +08:00
Automerger Merge Worker
6d0d4ffda8 Merge "Update error on ROM 9892479 am: c1c6e069f6 am: 6ce29d087a" 2023-04-10 02:14:54 +00:00
Wilson Sung
03efa43f01 Update error on ROM 9892479 am: c1c6e069f6 am: 6ce29d087a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22525983

Change-Id: I7edf58b87e8c0beb16a6bfddf43b0d8bb74cd120
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 02:14:51 +00:00
Wilson Sung
365292d73d Update error on ROM 9892479 am: c1c6e069f6 am: 073237da5b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22525983

Change-Id: Id9bb7eb623b9400f56a3a920576cc93caa5d2c01
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 02:14:48 +00:00
Wilson Sung
6ce29d087a Update error on ROM 9892479 am: c1c6e069f6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22525983

Change-Id: I741c9eac7ae7a8abbf87c18c017e70a9d2d3866e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:49 +00:00
Wilson Sung
073237da5b Update error on ROM 9892479 am: c1c6e069f6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22525983

Change-Id: I7a4d5a503422f960295fb30f1c093f0f35426ca9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:42 +00:00
Wilson Sung
c1c6e069f6 Update error on ROM 9892479
Bug: 277155327
Bug: 277300226
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I2690bcd7b3ae0d869f39851d5fb692378cbb6e9a
2023-04-07 15:09:26 +08:00
Wilson Sung
bd16083802 Update SELinux error am: 90d58d2553 am: d63e4c068b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22244483

Change-Id: I9ec610c2ce00f0fd77816c6edb6d2dc75d55a0e5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:06:19 +00:00
Wilson Sung
e4ce2b33d4 Update SELinux error am: 90d58d2553 am: 6fefb96a12
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22244483

Change-Id: I1099eff60b5dbfac7be39b3d6c346945821c5cde
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:05:41 +00:00
Wilson Sung
6fefb96a12 Update SELinux error am: 90d58d2553
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22244483

Change-Id: I9cbc2d9c0e1bbb6cf54ae7811c7fa2ac3207b39a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:22 +00:00
Wilson Sung
d63e4c068b Update SELinux error am: 90d58d2553
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/22244483

Change-Id: I2576354c63391db88cad856bef3c4a464962463d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:20 +00:00
Wilson Sung
90d58d2553 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275002086
Test: scanBugreport
Bug: 239887174
Test: scanAvcDeniedLogRightAfterReboot
Bug: 239887174
Change-Id: I9a0a1b3ef0642700a4555258c9e8aff7ec82e084
2023-03-24 11:11:28 +08:00
Yen-Chao Chen
cb063cf6ce Suppress avc denials of sysfs am: f446026014 am: c03d408bb4 am: cf61d5959d am: 86f85bd033
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: I66d1d8fe205e09a71e2879bfd7b408de37c80c0a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 05:07:20 +00:00
Yen-Chao Chen
706a39f268 Suppress avc denials of sysfs am: f446026014 am: c03d408bb4 am: cf61d5959d am: bf9c406fbe
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: I97c5ee4133a3822a33f71e686f944eef2b546db5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 05:06:14 +00:00
Yen-Chao Chen
86f85bd033 Suppress avc denials of sysfs am: f446026014 am: c03d408bb4 am: cf61d5959d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: I7c194edda3b7ef6e93f0a05bb03963d64df64dc5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:54 +00:00
Yen-Chao Chen
bf9c406fbe Suppress avc denials of sysfs am: f446026014 am: c03d408bb4 am: cf61d5959d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: Ia0c8b12c75da13ee44cfbc9d96fb033c35ec42da
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 04:30:02 +00:00
Yen-Chao Chen
cf61d5959d Suppress avc denials of sysfs am: f446026014 am: c03d408bb4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: I64cc0d6b9cfd5945a6ccf7f927450c2ad9be838e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 03:51:30 +00:00
Yen-Chao Chen
c03d408bb4 Suppress avc denials of sysfs am: f446026014
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21570169

Change-Id: I478ce949320bcf89047a6bb62103b0c4a9f572e6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-02 03:15:26 +00:00
Yen-Chao Chen
f446026014 Suppress avc denials of sysfs
Bug: 267839070
Test: adb bugreport

Change-Id: I8d4aed4aba15efa0cc38574565e4a66bc3049321
Signed-off-by: Yen-Chao Chen <davidycchen@google.com>
2023-03-01 15:10:16 +08:00
Tai Kuo
8026d60db6 Revert "device-sepolicy: Add sepolicy for vibrator hal" am: 02be088bc5 am: 5925557552 am: 2d2a78c148
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21455936

Change-Id: I1d571368e7eaf7064ef613e6d25fb13052abd1e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-17 09:01:36 +00:00
Tai Kuo
b58cf03402 Revert "device-sepolicy: Add sepolicy for vibrator hal" am: 02be088bc5 am: 5925557552
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21455936

Change-Id: I0054a5f9b19edff784ae55c0acfb9fec79bc8153
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-17 07:57:48 +00:00
Tai Kuo
2d2a78c148 Revert "device-sepolicy: Add sepolicy for vibrator hal" am: 02be088bc5 am: 5925557552
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21455936

Change-Id: Ia68280abd245bd8bc7e1e939f82156b44919b355
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-17 07:47:47 +00:00
Tai Kuo
5925557552 Revert "device-sepolicy: Add sepolicy for vibrator hal" am: 02be088bc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21455936

Change-Id: Ie2e3086bf535add2e1ede16e374f8a78e2780216
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-17 06:23:10 +00:00
Tai Kuo
1bf6ebb51e Revert "device-sepolicy: Add sepolicy for vibrator hal" am: 02be088bc5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21455936

Change-Id: Iff67682598df71a00bf5c5eeabd0c682c9c427fe
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-17 01:45:33 +00:00
Tai Kuo
02be088bc5 Revert "device-sepolicy: Add sepolicy for vibrator hal"
This reverts commit b5eec482fd.

Bug: 198239103
Test: build pass on git_tm-qpr-dev-plus-aosp
Change-Id: Iee9305e6ba5abbc8df9b353ed5bbfeaa64f0b43b
2023-02-16 22:11:32 +08:00
Hsiu-Chang Chen
ae260626bc wlan: add cnss-daemon and related libraries am: 53746d9546 am: cc2eda58a1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21257900

Change-Id: Ifa5b92a131372c681371a48bb8c6fec715a20b34
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 10:08:06 +00:00
Hsiu-Chang Chen
cc2eda58a1 wlan: add cnss-daemon and related libraries am: 53746d9546
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/21257900

Change-Id: I8d0b0e4ec2218b6b569e282163749c77e1c7e627
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-15 09:16:10 +00:00
Hsiu-Chang Chen
53746d9546 wlan: add cnss-daemon and related libraries
cnss-daemon is necessary for CHRE function

Bug: 264524963
Test: Regression Test
Change-Id: Ic7b63617e30a9e6427b0ac280bf4763f9cc19f6e
2023-02-15 01:47:13 +00:00
Ken Yang
fa9c88aef8 WLC: Cleanup the sysfs_wlc policies
Bug: 263830018
Change-Id: I6b31c6127e01b946c51200683b511853f2d304b4
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-13 14:41:12 +00:00
Myles Watson
942a2a63f4 [automerger skipped] Lynx: Use common sepolicy for bt_device am: 966927efa3 -s ours
am skip reason: Merged-In Ic1b7469d64c79285d9d7993befbe173c9bca34aa with SHA-1 e5a1cde5d4 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20965192

Change-Id: Ic9d77aa8d816734a5f65882270eb9efa95017805
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-12 23:35:11 +00:00
Myles Watson
966927efa3 Lynx: Use common sepolicy for bt_device
Bug: 205758693
Test: build
Ignore-AOSP-First: Some devices in internal define bt_device
Change-Id: Ic1b7469d64c79285d9d7993befbe173c9bca34aa
(cherry picked from commit e5a1cde5d4)
Merged-In: Ic1b7469d64c79285d9d7993befbe173c9bca34aa
2023-01-12 21:30:13 +00:00
Myles Watson
e5a1cde5d4 Lynx: Use common sepolicy for bt_device
Bug: 205758693
Test: build
Ignore-AOSP-First: Some devices in internal define bt_device
Change-Id: Ic1b7469d64c79285d9d7993befbe173c9bca34aa
2023-01-10 06:44:54 -08:00
Ken Yang
c70f56e2df WLC: Add device specific sepolicy for wireless_charger
Bug: 237600973
Change-Id: I9d219c3abf02266cc8200c70840a65aedb17ee7b
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-20 00:59:17 +00:00
Vic Huang
35d63da2f6 No avc denied in SELinuxUncheckedDenialBootTest am: 5b9f54e76d am: c4f1017469
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20615132

Change-Id: Ie45f778807057fbfb3632a92169366636f7fd5d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-02 17:08:12 +00:00
Vic Huang
c4f1017469 No avc denied in SELinuxUncheckedDenialBootTest am: 5b9f54e76d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20615132

Change-Id: I68e23620268af291bcd94c0bf8d71bcbc7bdc127
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-02 16:34:02 +00:00
Vic Huang
5b9f54e76d No avc denied in SELinuxUncheckedDenialBootTest
DeviceBootTest.DeviceBootTest.SELinuxUncheckedDenialBootTest

avc: denied { call } for comm="oid.grilservice" scontext=u:r:grilservice_app:s0:c227,c256,c512,c768 tcontext=u:r:hal_bluetooth_default:s0 tclass=binder permissive=0 app=com.google.android.grilservice

Bug: 259198345
Change-Id: Ie3800e3197f04b83ba8789c82518cbb721e1fe37
2022-12-02 15:52:36 +00:00
Chris Paulo
50b8efd9eb device-sepolicy: Add sepolicy for vibrator hal am: b5eec482fd am: 2c6be03c0d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19981337

Change-Id: I81c821acf7f0e94f91dc32d259da8635aedb7ced
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-16 21:20:50 +00:00
Chris Paulo
2c6be03c0d device-sepolicy: Add sepolicy for vibrator hal am: b5eec482fd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19981337

Change-Id: I379f4a0ee8e457202e70ba5cadd4a6e97c7b2e8f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-16 20:52:07 +00:00
Chris Paulo
b5eec482fd device-sepolicy: Add sepolicy for vibrator hal
Added sepolicy for vibrator hal specific to device

uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc: denied { read } for property=vibrator.adaptive_haptics.enabled pid=0 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1'
avc: denied { open } for comm="odrefresh" path="/dev/__properties__/u:object_r:adaptive_haptics_prop:s0" dev="tmpfs" ino=80 scontext=u:r:odrefresh:s0 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1
avc: denied { getattr } for comm="odrefresh" path="/dev/__properties__/u:object_r:adaptive_haptics_prop:s0" dev="tmpfs" ino=80 scontext=u:r:odrefresh:s0 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1
avc: denied { map } for comm="odrefresh" path="/dev/__properties__/u:object_r:adaptive_haptics_prop:s0" dev="tmpfs" ino=80 scontext=u:r:odrefresh:s0 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1
avc: denied { write } for comm="android.hardwar" name="chre" dev="tmpfs" ino=1094 scontext=u:r:hal_vibrator_default:s0 tcontext=u:object_r:chre_socket:s0 tclass=sock_file permissive=1
avc: denied { connectto } for comm="android.hardwar" path="/dev/socket/chre" scontext=u:r:hal_vibrator_default:s0 tcontext=u:r:chre:s0 tclass=unix_stream_socket permissive=1
avc: denied { open } for comm="binder:8084_3" path="/dev/__properties__/u:object_r:adaptive_haptics_prop:s0" dev="tmpfs" ino=80 scontext=u:r:gmscore_app:s0:c512,c768 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1 app=com.google.android.gms
avc: denied { getattr } for comm="binder:8084_3" path="/dev/__properties__/u:object_r:adaptive_haptics_prop:s0" dev="tmpfs" ino=80 scontext=u:r:gmscore_app:s0:c512,c768 tcontext=u:object_r:adaptive_haptics_prop:s0 tclass=file permissive=1 app=com.google.android.gms

Bug: 198239103
Test: Verified functionality
Signed-off-by: Chris Paulo <chrispaulo@google.com>
Change-Id: Ib118b553eab1db6f9fadaebeae0d57eb329294e3
2022-11-15 05:27:55 +00:00
Hsiu-Chang Chen
07be62d1ab Fix avc denied for init-insmod-sh am: cf6ebcdd6f am: 679626004d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20302372

Change-Id: I0d29948c32050fc893b3fc34ed46ae6810847d6b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-30 04:56:35 +00:00
Hsiu-Chang Chen
679626004d Fix avc denied for init-insmod-sh am: cf6ebcdd6f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20302372

Change-Id: If04d86a030a328552c5b3b805a0576f5296f0df3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-30 04:20:58 +00:00
Hsiu-Chang Chen
cf6ebcdd6f Fix avc denied for init-insmod-sh
qrtr.ko doesn't request net_admin permission now
05-30 05:12:58.524   492   492 I auditd  : type=1400 audit(0.0:4):
avc: denied { net_admin } for comm="modprobe" capability=12
scontext=u:r:init-insmod-sh:s0 tcontext=u:r:init-insmod-sh:s0
tclass=capability permissive=0

Bug: 234311675
Test: verified with the forrest ROM and error log gone
Change-Id: I72fb5441b977b6ba67d19416049a2776c3aebd12
2022-10-28 12:35:02 +08:00
Hsiu-Chang Chen
63b5468da9 Add sepolicy rules for hal_wifi_default am: b2c724f0ed am: 32cd0dbba0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20194047

Change-Id: I492d79005fcd85fb84f29baec08d6a95d766ea01
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-17 09:31:44 +00:00
Hsiu-Chang Chen
32cd0dbba0 Add sepolicy rules for hal_wifi_default am: b2c724f0ed
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/20194047

Change-Id: Ic9d33b41d0c656219248274c43799fd96c179730
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-17 08:45:12 +00:00
Hsiu-Chang Chen
b2c724f0ed Add sepolicy rules for hal_wifi_default
In PDK build, it uses default wifi hal instead
wifi_ext hal. Need to add rules for hal_wifi_default
as well as we added for hal_wifi_ext

Bug: 253544307
Test: Wifi can be enabled in PDK builds
Change-Id: I57ad330c2467ae99b9c5190fbdc2f02e998b2fc1
2022-10-15 02:50:33 +00:00
Hsiu-Chang Chen
852dfa55f8 Add sepolicy for tcpdump_logger am: ea80cb5016 am: f068419777
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19739489

Change-Id: Ib7a73b5066d30e2d039abae54de1368741e043fb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-26 03:18:07 +00:00
Hsiu-Chang Chen
f068419777 Add sepolicy for tcpdump_logger am: ea80cb5016
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19739489

Change-Id: I8e3b4edee868db2bc3bdd1e3f1589bc26f061fcb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-26 02:39:01 +00:00
Hsiu-Chang Chen
674508eccc Add sepolicy for wifi_sniffer and wifi_perf_diag am: e465f1a856 am: 6122c700d7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19738530

Change-Id: I30803fd319b090e50fbce8688825d4902d979699
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-25 09:25:11 +00:00
Hsiu-Chang Chen
ea80cb5016 Add sepolicy for tcpdump_logger
avc: denied { search } for name="wifi" dev="dm-44" ino=329 scontext=u:r:tcpdump_logger:s0 tcontext=u:object_r:vendor_wifi_vendor_data_file:s0 tclass=dir

Bug: 243764714
Test: PixelLogger works normally
Change-Id: I4ee93dbe10bae08e01053656a8429c57bb3651c8
2022-08-25 16:56:44 +08:00
Hsiu-Chang Chen
6122c700d7 Add sepolicy for wifi_sniffer and wifi_perf_diag am: e465f1a856
Original change: https://googleplex-android-review.googlesource.com/c/device/google/lynx-sepolicy/+/19738530

Change-Id: I84dc888428a7ce086b342b4f91c8300b001bc964
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-25 08:56:12 +00:00