Commit Graph

3645 Commits

Author SHA1 Message Date
Jaihind Yadav
85a1c173c7 creating 31.0 preuilt sepolicy from android-S sepolicy.
Change-Id: I562cf94dfe4bc722c56c9f64db006e7635f67f1e
2021-10-06 18:46:10 +05:30
qctecmdr
597f2ec7f0 Merge "Remove violator rule in qvirtmgr." 2021-09-08 10:42:20 -07:00
qctecmdr
b9ab250e8e Merge "Sepolicy for ro.vendor.bootreceiver.enable" 2021-09-08 04:52:21 -07:00
Shashank Sivakumar
52459fc5c9 Remove violator rule in qvirtmgr.
Change-Id: I07b27bfda84be137cf2307c6e31ac84ae97856e5
2021-09-07 22:52:24 -07:00
Devanshi Bansal
92cfbbea7a sepolicy: add sepolicy for vendor_hal_displayconfig_service
Change-Id: I81f432ffb4cc5513fcf91b53f0e1a7c5bc077cbd
2021-09-07 20:48:45 -07:00
Divyanand Rangu
3bcc850a84 Sepolicy for ro.vendor.bootreceiver.enable
Set sepolicy permissions to Allow ro.vendor.bootreceiver.enable
to be updated from vendor side init.

Change-Id: I2b4929b70a7eab398eb1e32dd3c0914841f6e47e
2021-09-08 08:58:04 +05:30
qctecmdr
03b61db6f0 Merge "sepolicy: Allow kernel to access tracefs instances" 2021-09-07 17:53:09 -07:00
qctecmdr
a59c4a093c Merge "Add sepolicy to suppress the denials for vendor_persist_camera_prop" 2021-09-07 10:23:18 -07:00
Weijie Wang
4049c09d86 Allow radio_cdma_ecm_prop accessible to platform apps
Change-Id: I3a94cd1f39715686fe7608e77df767e86fd844a9
2021-09-06 22:47:22 -07:00
Qimeng Pan
ff33021ea5 Add sepolicy to suppress the denials for vendor_persist_camera_prop
vendor_persist_camera_prop is not necessary for 3rd party apps, so
don't audit it for appdomain to suppress the denial logs.

vendor_persist_camera_prop is the context of below prop, which are
added to standard Android SDK APIs, so all app may touch it.
 - vendor.camera.aux.packagelist
 - persist.vendor.camera.privapp.list

Change-Id: I1198ed3c3441aec5a33f2b781d29100b9d4648af
CRs-Fixed: 3027102
2021-09-06 21:06:33 -07:00
qctecmdr
d4135c5b49 Merge "sepolicy:qcc: read vendor_qcc_prop" 2021-09-06 16:10:12 -07:00
Kamal Agrawal
619ae9e2ac sepolicy: Allow kernel to access tracefs instances
Add policy to allow kernel to access tracefs instances.
Fix is for below error:
W kworker/u16:6: type=1400 audit(0.0:8): avc: denied { search } for
name="instances" dev="tracefs" ino=10847 scontext=u:r:kernel:s0
tcontext=u:object_r:debugfs_tracing_instances:s0 tclass=dir permissive=0

Change-Id: I306353ffbc2675a45bee14d17672fc8829cd374e
2021-09-06 15:00:14 +05:30
Harikrishnan Hariharan
7a7141041d Allow location service to read property radio_cdma_ecm_prop
Change-Id: Ie840160eb04420212ef5e20aa53b18f30834e641
CRs-Fixed: 3029071
2021-09-04 11:01:19 +05:30
ShawnShin
4c26e7e4cb sepolicy:qcc: read vendor_qcc_prop
add authmgr and netstat for vendor reference to read access to vendor_qcc_prop

Change-Id: I602dfa1b7a6887148fef96b3d7aeb796324363b2
2021-08-30 15:18:43 -07:00
Swarn Singh
d5fde440c2 Add sepolicy support for qtiwifiservice platform_app
This commit defines required sepolicy rules for qtiwifiservice apk
requires to interact with IWificfr HAL and wpa_supplicant HAL.

Change-Id: Iaacd7378866b20c65de3ea27a3ae5e08fa39a215
CRs-Fixed: 3020979
2021-08-24 17:12:03 +05:30
Manoj Basapathi
80576d66be sepolicy : add attributes to mwqem Adapter HAL
-Update sepolicy attributes to mwqem adapter HAL

CRs-Fixed: 3015739
Change-Id: Ia98a8ee27be9b8c4eebb6a075f4aee36b24797c9
2021-08-19 17:29:28 +05:30
Samyak Jain
98536d139b selinux for sxrservice and sxrsplitauxservice
add sepolicy for sxrservice and sxrsplitauxservice

Change-Id: If31f4fe36ce684b9937fca5507ef974a4457e7ae
2021-08-16 10:24:17 +05:30
qctecmdr
8867713ddb Merge "sepolicy: Add policy to access Limits HAL by SF" 2021-08-10 12:22:58 -07:00
qctecmdr
c50c4df458 Merge "sepolicy: Add qesdk app domain as trusted subject" 2021-08-10 11:54:12 -07:00
qctecmdr
4e73661bc3 Merge "sepolicy: Add sepolicy changes for wificfr server" 2021-08-10 11:23:43 -07:00
Bipin Kumar
e13550c6e3 sepolicy: Add policy to access Limits HAL by SF
Change-Id: Ia742cbdca593799eb23809d0aaccc0839411f69e
2021-08-10 06:25:43 -07:00
Swarn Singh
d8a2147502 sepolicy: Add sepolicy changes for wificfr server
Change-Id: I0f75e617f5aaba7da19ba846ee37d37afa80120a
CRs-Fixed: 2889522
2021-08-05 15:01:48 +05:30
Benergy Meenan Ravuri
724e328df2 sepolicy: Add qesdk app domain as trusted subject
Add qesdk app domain as trusted subject

Change-Id: Ie5378ed4a156afe54186b697f13e87492f52d291
2021-08-04 23:47:04 +05:30
Kakarla Uday Kanth Reddy
68b77ec347 Add sepolicy rules under vendor_qtelephony domain
Add sepolicy rules under vendor_Qtelephony domain for uimlpaservice
which connects with SMDP server for profile download via socket
connection

Change-Id: I29a3663f10c52f9bc6df3823ba5817e38ace11d3
2021-08-03 06:44:28 -07:00
ShawnShin
bef34ed7fb sepolicy: authmgr using hidl through native lib
avc:  denied  { find  } for
interface=vendor.qti.hardware.qccvndhal::IQccvndhal sid=u:r:
platform_app:s0:c512,c768 pid=3859
scontext=u:r:platform_app:s0:c512,c768
tcontext=u:object_r:vendor_hal_qccvndhal_hwservice:s0
tclass=hwservice_manager permissive=0

Change-Id: Ib7339e83b0280b2528bc7cfdb01e86f31a576ee7
2021-07-30 12:41:06 -07:00
Maryia Maskaliova
314839d51a Removed rule for mediaprovider_app perf-hal access
Remove permissions for mediaprovider_app to interact
with perf-hal

Change-Id: Ibde9381553fd2d9d474eee6ca4c5aac32a89222a
2021-07-27 12:19:54 -07:00
qctecmdr
cc391f9c83 Merge "Selinux enabled for xrcb_app." 2021-07-22 15:09:40 -07:00
qctecmdr
1b88c99e22 Merge "Allow radio_cdma_ecm_prop accessible to priv apps" 2021-07-22 13:08:58 -07:00
Ashwani Jha
4de60122b0 Selinux enabled for xrcb_app.
This change enables xrcb application to facilitate
communication between QXR Client apk and QXR hal service.

Change-Id: I8fc2759d5d4710d735de86aca0bd31d1069611f6
2021-07-22 13:08:51 -07:00
qctecmdr
154aac708d Merge "sepolicy:permission for untrusted_app to access" 2021-07-22 10:56:32 -07:00
Avinash Nalluri
4b013bf171 Allow radio_cdma_ecm_prop accessible to priv apps
Change-Id: I108adb10a845294b11966b26af7f764417e4490f
CRs-Fixed: 2996994
2021-07-21 16:11:45 -07:00
Maryia Maskaliova
bed4283d86 sepolicy: allow untrusted apps to access perf hal
Added rules to allow a subset of untrusted apps to
access perf hal

Change-Id: Ida19d111c270797503785ca09a0b3f28c22a75c6
2021-07-21 09:04:19 -07:00
Taiyab Haque
a14e33b18a sepolicy:permission for untrusted_app to access
permission for untrusted_app with sdk version 30
to access qesdk.

Change-Id: I17886936dcdb44b4d824be04dc4e13ae7c9d502c
CRs-Fixed: 2985891
2021-07-20 10:54:04 +05:30
qctecmdr
5cd71f300f Merge "Selinux: add vendor_perfetto_dump domain" 2021-07-15 02:58:26 -07:00
Pavan Kumar M
4ff9ed9d88 sepolicy: Adding rcs property
Adding vendor_persist_rcs_prop for
rcs single registration service.

Change-Id: I6ee572ab15b1a2bcf37a15f6b40449b69fd284cc
2021-07-14 14:34:04 +05:30
Zhiqing Xiong
7e58b8dfb3 Selinux: add vendor_perfetto_dump domain
Define allow rules for perfetto dump

Change-Id: Icb094cb0f340ecf0ab20dcd1394c02b92b653be7
CRs-Fixed: 2963240
2021-07-13 14:47:51 +08:00
Taiyab Haque
cc12a0d845 sepolicy: rules for vendor_qesdk_app
rules for vendor_qesdk_app

Change-Id: I58fe8af7e7f0a7b1050fefb35aa478d3ce095c2d
CRs-Fixed: 2941819
2021-07-06 12:38:38 +05:30
Shawn Shin
cd12cadf37 sepolicy:qcc-tr: add qccvndhal
to remove poll in qccvndhal for netstat

Change-Id: I3fde82784ca305be81e4a8c672d820d45c503312
2021-07-01 17:12:23 -07:00
qctecmdr
5431aebfcb Merge "Update uim_remote service/client under qtlephony domain" 2021-07-01 10:51:16 -07:00
qctecmdr
8c6ba1b100 Merge "Sepolicy: Added SEpolicy for hal_perf attribute" 2021-06-28 21:25:34 -07:00
Jaihind Yadav
07828b6176 adding required infra to test treblesepolicy test.
treblesepolicy test requires these *.cil file to
be set by partner so adding required changes to do
so.

Change-Id: I0691776ceae5921d0c9254eda62790ae161968c0
2021-06-27 05:16:53 -07:00
Devaunsh Sambhav
1350bfb56c QcRilAudio Stable AIDL: SE policy change.
Change-Id: I88af004e93b7fb1f96aea31234ff37dabf664f25
CRs-Fixed: 2975002
2021-06-25 11:58:10 -07:00
Richa Agarwal
a2083deda0 Allow WLC access to build_bootimage property
Created new domain for workloadclassifier service
and added sepolicy rule for it.

Change-Id: Ic07ba81d2172579e77db4a9dca2417e64c284a00
2021-06-24 12:07:45 -07:00
qctecmdr
fbe4b37b7f Merge "sepolicy: Enable wfdservice as 32 & 64-bit executable" 2021-06-24 00:12:13 -07:00
Kakarla Uday Kanth Reddy
f79da563f4 Update uim_remote service/client under qtlephony domain
Update uim_remote service/client under qtlephony domain

Change-Id: I973363431ad7ce3a0120d101c5992b18a71b94f7
2021-06-23 23:37:35 -07:00
phaneendra Reddy
ee58e3684f Sepolicy: Added SEpolicy for hal_perf attribute
Added fm_app rule to hal_perf attribute
as avc denial issue is seen with fm app.

CRs-Fixed: 2946175
Change-Id: Ife41800f194c4f754062e5301368f31ef1d87d8f
2021-06-21 00:03:56 -07:00
Manoj Basapathi
dc41715794 sepolicy : add attributes to data HALs
-Update sepolicy attributes to data factory,
cacert and iwlan service HALs.

CRs-Fixed: 2971946
Change-Id: Ifc13d8d5329e6f3de6c88d1f519039b467c72cb2
2021-06-15 17:26:08 +05:30
Mahesh Raja Bhogineni
ed63f3aab9 sepolicy: Enable wfdservice as 32 & 64-bit executable
Change-Id: I4509a4a619e555f5f78b7c2996baed8f4a899bd4
2021-06-07 17:20:27 +05:30
Taiyab Haque
639c212528 QESDK: SELinux policy for QESDK
SELinux rule for QESDK
CRs-Fixed: 2933136

Change-Id: I3754a9e201b780d7f3628e996578b90d10caa5b1
2021-06-02 23:27:28 +05:30
appadura
6f7bb5ada1 qvirtmgr: Define selinux qcrosvm type & policies
Change-Id: I26a0f48fa7e9da2ab67728a75651ab2a4e53310b
2021-05-31 17:15:39 -07:00