Commit Graph

135 Commits

Author SHA1 Message Date
chrisl7 8f99859250 sepolicy: bengal: Add pwr and powermodule sepolicy rules
[1] - From Kalama

Change-Id: Idff6ec9ce21ac4dc02b6ebfebc72dfdb0067fa8e
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-09-10 10:51:43 +05:30
chrisl7 4a249ab6a6 sepolicy: Label qrtr-lookup
Change-Id: Ia8646d38855bb0bf3509f844162b7709856be350
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-09-10 10:51:43 +05:30
Kunmun 49e886f064 Revert "common: sepolicy: Add back vendor/vm-system sepolicy rules"
This reverts commit a418e39350.

Reason for revert: Already present in sepolicy_vndr hence conflicts with the build and don't really seem any point in having it.

Change-Id: I6ef50d7e7e57c7478b42526cb6aa386ece78c639
2023-09-03 06:56:19 +00:00
Jprimero15 3fc6f16cd1 common: sepolicy: legacy: wfd_vendor_debug_prop -> vendor_wfd_vendor_debug_prop
* Fixes build error on userdebug and eng.

Change-Id: I38ffaa1448c410196a7c69e80e28b985604f79d8
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-09-01 12:49:25 +00:00
Pritama Biswas 7e737118ec Revert "sepolicy: add sysfs for eDP in sysfs_graphics"
This reverts commit eae6a85528090134fec879839bc69dd313cff553.

Change-Id: I5894038a408465cb480917dee323d360aa06b995
2023-08-31 12:06:56 +00:00
Padmanabham Bodda 13e7fa6b4f common: sepolicy_vndr: Add sepolicy for libOpenCL_adreno
Add sepolicy to fix avc denial

CRs-Fixed: 3565678
Change-Id: If96a27728c09bcbd4d4d81a5dca60ce8ed864826
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-31 12:05:52 +00:00
Arian cfb22b79fe common: sepolicy: Revert "QAPEService: Remove old perf_qesdk_client label"
This reverts commit 842b0284a827680a68c152f3c9ef5be8c2822eec.

[1] - https://gerrit.aospa.co/c/AOSPA/android_device_qcom_sepolicy_vndr/+/33656

Change-Id: I337605ed33e90a8a86d451ccdcf7e953da4d58a3
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-31 12:05:33 +00:00
Arian e9c58ad4d0 common: sepolicy: Revert "Removal of CVP and Panorama services/SE files"
This reverts commit c6ad06cd9e61d31bd350a0e317094d828af4f0c5.

[1] - https://gerrit.aospa.co/c/AOSPA/android_device_qcom_sepolicy_vndr/+/33659

Change-Id: I5040da91a9464b86e864b1b46f084ffd00a359ee
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-31 12:05:12 +00:00
Arian 0668088b6d common: sepolicy: Revert "Removal of SCVE Panorama services file"
This reverts commit e427726d40e6222e4030c79188892fbc12b18df8.

[1] - https://gerrit.aospa.co/c/AOSPA/android_device_qcom_sepolicy_vndr/+/33658

Change-Id: I0bdeed912809dde24e44899dd28051597f7b354b
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-31 12:04:56 +00:00
chrisl7 a418e39350 common: sepolicy: Add back vendor/vm-system sepolicy rules
Change-Id: Icfc80b7ac526b7cb3c8fcad2e1ddc2f3e7ab9bec
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-31 12:04:25 +00:00
chrisl7 6774b84b9b common: sepolicy: bengal: Add missing label partitions to 5.15 variant
[1] - I don't know why qcom left this missing, but it breaks flash build on sideload, as well as a possible OTA update.

Change-Id: I2f209f73b6199a93fe5e4745ac4410f6090daba0
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-26 23:16:13 +00:00
chrisl7 4b61c9162e common: sepolicy: kona: Remove duplicate sepolicy
[1] - bedc30ef74 (diff-09112ee2412ac4f3dccef5052cfbb1b943415434585d17d7d523bf06452c29bcR130)

Change-Id: Ic2bdb81c658bb4bccbac54ee15b2596a5f77a7ab
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-08-19 23:39:13 +00:00
PainKiller3 2ccc02a122
common: sepolicy: legacy: Restore WFD policy
* It was removed in 2b1d3d1de6 (diff-eee4628467d1bbed9c0d16dde6195afd47af1d2efb7ca18d829bc07bd0bb71c2)
* Fixes QTI Wifi Display on sdm845.

Change-Id: I1df9432041400808e94c1072f5bddf2eb9c18059
2023-08-01 19:28:01 +05:30
Gokul 2ccd0dbb2e Revert "sepolicy: generic: Label more discard_max_bytes sysfs" for Kona
Partially reverts commit: 2e80055990

Change-Id: I90905f82566c90996618c4b5b463798f86a08a19
2023-07-12 04:10:28 +00:00
Jprimero15 2b9c5a2d01 common: sepolicy: lahaina: Remove all duplicates
* already existed in sepolicy_vndr.

Change-Id: I43a0ae29821823c5988ab49c822cf244dc3253a9
2023-07-09 15:26:47 +00:00
enesykaya 5db051bcce common: sepolicy: Move hub_app to private
Change-Id: Iaab3e1f4486008ed9781598e22ccae368705cd16
2023-07-08 00:43:20 +03:00
Jprimero15 db236980f2 common: sepolicy: lahaina: Remove duplicated labels
Added at 6847922d6d
but already existed in sepolicy_vndr.

Change-Id: I5846db90f9f44986e948cd42d2fe89d0bb783ee5
2023-07-02 14:14:58 +00:00
BladeRunner-A2C 159fb0fde2
common: sepolicy: Remove duplicate declarations
Already defined at 'sepolicy_vndr'

Change-Id: I5664aa362c5cdb0b6c34f3aac1f16e134994b0c3
Signed-off-by: BladeRunner-A2C <john.smith@unused.email>
2023-06-30 21:02:00 +06:00
Michael Bestas 9e87365194 sepolicy: qva: label bengal extcon
Change-Id: Ie9f50b544665a8b66b172f35c0f45c5404628595
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:06:11 +00:00
Michael Bestas 4727d6c50e sepolicy: bengal: Label discard_max_bytes sysfs
Change-Id: I1cc993d353cf2966685a3276b4c97d86c7030326
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:06:04 +00:00
Quallenauge d9da0846c1 sepolicy: generic: Allow qti_init_shell to set proc_watermark_scale_factor.
Change-Id: I4a4812393c50ffec9d64dc1ad13514551c47985e
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:55 +00:00
Saikumar Vutukuri 43b7538598 sepolicy: generic: Sepolicy:Add rules for init-qti-dcvs-sh
Change-Id: Idd7c3635afd8fa6539d6d4a447cbb0962aefd684
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:48 +00:00
Michael Bestas 2e80055990 sepolicy: generic: Label more discard_max_bytes sysfs
Change-Id: I43e2c93d5915157c7a87a8f0799c45a54e251040
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:39 +00:00
dianlujitao e4a3635313 sepolicy: generic: Allow init write to discard_max_bytes
Change-Id: If22a1fe0036f49d5cfb3f3c21cd9c44b96ac6ae8
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:30 +00:00
Michael Bestas f058740ce4 sepolicy: generic: msmnile: Add some misc wakeup nodes for msmnile
* Can't have them in hardware/oplus/sepolicy/qti/vendor/genfs_contexts
   because it conflicts with generic/vendor/lahaina/genfs_contexts here.

Change-Id: I542e7b542aec7a7270095c82bfbd0c22941dc9cd
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:21 +00:00
LuK1337 71d2e76304 sepolicy: generic: msmnile: Add some misc wakeup nodes for msmnile
* Can't have them in hardware/oplus/sepolicy/qti/vendor/genfs_contexts
   because it conflicts with generic/vendor/kona/genfs_contexts here.

Change-Id: I36d28dc8dc4e2e86b30f623023cf2757d35bccf0
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:11 +00:00
chrisl7 6c9c88bb3e common: sepolicy: Update SM8450 sepolicy rules
[1] - LA.VENDOR.1.0.r1-22200-WAIPIO.QSSI14.0

Change-Id: I26b9080ec5419d45f3b4d1efe793b61b4708de06
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:05:01 +00:00
chrisl7 6847922d6d sepolicy: Update SM8150-8350 sepolicy rules
[1] - LA.UM.9.14.1.r1-10000-QCM6490.QSSI13.0

Change-Id: I724f66c9c0076cfadcbb6ade745c9b83d5992e7f
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-06-26 13:03:57 +00:00
Jprimero15 c82350882a common: sepolicy: legacy: allow qti_init_shell to write on watermark_scale_factor
* https://github.com/AOSPA/android_device_qcom_common/blob/topaz/vendor/init/init.qcom.post_boot.sh#L824

Change-Id: I66139b318596d54dcb811620a2c4ecf8950b3b44
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-06-02 13:46:16 +00:00
Jprimero15 ce7c22c056 common: sepolicy: legacy: define wcnss_persist_file
Change-Id: I8068109c5abd85d390e9f93877186e991df0af9f
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-31 08:19:25 +00:00
Jprimero15 384d73e77c common: sepolicy: legacy: define proc_boot_reason
Change-Id: I24f29c536503fc45f12b036ec2a96eb2d413ea23
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-31 08:19:25 +00:00
Ahmed Harhash 2751d5571c
sepolicy: vendor: kona: Remove duplicate wakeup entries
Change-Id: I013f96dc9d2ec8dfef06f667fc9348e7d11ff3aa
2023-05-29 05:02:25 +03:00
Jprimero15 6c657541a4 common: sepolicy: legacy: More init denial fixes
Change-Id: Ia651fe66461e9ca7c915af3c3553c2f23fdaf8ec
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-28 01:30:23 +00:00
Jprimero15 a296eb57a5 common: sepolicy: legacy: More WIFI HAL denial fixes
Change-Id: I9f736317b8157838a65e3107d8c6aceb29a045a9
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-28 01:30:04 +00:00
Jprimero15 d41d3eb369 common: sepolicy: legacy: Label QTI GNSS HAL
Change-Id: I40207d672743bf367b21cd6f2453a1f8aee69993
Signed-off-by: Jprimero15 <jprimero155@gmail.com>
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-28 01:29:52 +00:00
Jprimero15 83ca0e2869 common: sepolicy: legacy: allow qti_init_shell to read boot_reason
[   15.742123] type=1400 audit(4539769.653:274): avc: denied { read } for comm="cat" name="boot_reason" dev="proc" ino=14760 scontext=u:r:qti_init_shell:s0 tcontext=u:object_r:proc_boot_reason:s0 tclass=file permissive=0

Signed-off-by: Jprimero15 <jprimero155@gmail.com>

Change-Id: I0014b14ae63a11123b827be4e3bcab16cfdb7484
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-28 01:29:41 +00:00
Jprimero15 9db506c58d common: sepolicy: legacy: Label init.qti.chg_policy.sh
* should not be limited to sdm710 and sdm845 because this is needed for charging component
* follow the format of other qti init shell labeling

Change-Id: Ie05fddd1dbf8e5789831f6ec5c7450607705b4f4
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-27 06:51:41 +00:00
Jprimero15 ec0d26d4e2 common: sepolicy: legacy: Unlabel /sys/vm/dirty_ratio
* labeled already on b6f0b6ffef

Change-Id: I8dd40a1dd589d3f20e62c66a4d3231ca57dbe815
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-19 15:38:51 +08:00
Jprimero15 900ea29a5d common: sepolicy: legacy: allow vendor_init to write on watermark_scale_factor
* [   34.822814] type=1400 audit(1684370886.288:56): avc: denied { write } for comm="init" name="watermark_scale_factor" dev="proc" ino=37383 scontext=u:r:vendor_init:s0 tcontext=u:object_r:proc_watermark_scale_factor:s0 tclass=file permissive=0

Change-Id: I9878d93608e60d45d611b3fe76120403cb05b875
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-19 04:52:08 +00:00
Juhyung Park 1e233bbfc8 sepolicy: location: fix socket accesses
These daemons need connecto vendor_location.

This fixes the following errors:

05-18 17:37:02.904  1487  1487 I LOWI-9.0.0.89.d: [MessageQ_Client] connecting to server [/dev/socket/location/mq/location-mq-s]
05-18 17:37:02.904  1487  1487 E LOWI-9.0.0.89.d: [MessageQ_Client] connect error: 13, [Permission denied]
05-18 17:37:02.904  1487  1487 E LOWI-9.0.0.89.d: [MessageQ_Client] connect failed 3
05-18 17:37:02.904  1487  1487 W LOWI-9.0.0.89.d: [LOWIController] retry count 4
05-18 17:37:02.903  1487  1487 W lowi-server: type=1400 audit(0.0:66): avc: denied { connectto } for path="/dev/socket/location/mq/location-mq-s" scontext=u:r:vendor_location_lowi_server:s0 tcontext=u:r:vendor_location:s0 tclass=unix_stream_socket permissive=0 srawcon="" trawcon=""

Change-Id: Ia5e2a365648f47bc8e6a17baff6e7a580641ffb7
Signed-off-by: Juhyung Park <qkrwngud825@gmail.com>
2023-05-18 19:24:43 +09:00
Juhyung Park cd16ba98c6 sepolicy: vendor_qti_init_shell: allow R/W to UFS nodes
This allows post_boot script to change values related to UFS,
such as clkscale_enable.

Change-Id: I8426971a108755a7f5ecfa87ad1e6bae6a7740ea
Signed-off-by: Juhyung Park <qkrwngud825@gmail.com>
2023-05-18 19:24:43 +09:00
Juhyung Park 4f238d4e15 sepolicy: vendor_qti_init_shell: allow R/W to swap nodes
This allows post_boot script to change values related to swap.

Change-Id: I7a72d3d0bcd9b57ac9cb75e9d5f5993ac8802778
Signed-off-by: Juhyung Park <qkrwngud825@gmail.com>
2023-05-18 19:24:42 +09:00
Jprimero15 8ded1d1d3e common: sepolicy: legacy: allow surfaceflinger to search hal_graphics_composer_default
* 05-17 11:51:43.193 W/binder:718_2(718): type=1400 audit(0.0:296): avc: denied { search } for name="667" dev="proc" ino=60796 scontext=u:r:surfaceflinger:s0 tcontext=u:r:hal_graphics_composer_default:s0 tclass=dir permissive=0

Change-Id: I4b0afddef711247963a98c0b9d48ac1d81a37138
Signed-off-by: Jprimero15 <jprimero15@aospa.co>
2023-05-18 07:33:48 +00:00
Mashopy 994059496a sepolicy: vendor: kona: Remove duplicate entries
Change-Id: Ib9ea4cd6a8b3d57c1c3727f34b3d610307587a33
2023-05-14 19:46:22 +02:00
chrisl7 e27d9d435e sepolicy: Import missing SM8450 sepolicy definition from LA.VENDOR.1.0.r1-21200-WAIPIO.QSSI13.0
Change-Id: I17b7efdd84e3f95fd1db796473a1cc2e926619ad
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-05-14 06:52:21 -04:00
Mashopy e6e1d5e363 sepolicy: common: Allow ueventd to search for vendor_persist_wcnss_service_file dir
Change-Id: Iecc01d9a61f8f8ccb2646f3a58aeffc1f7b58ee6
2023-05-11 02:09:31 +00:00
Mashopy 1cb09986ee sepolicy: kona: Fix some sysfs_wakeup node
Found by SuspendSepolicyTests.sh

Change-Id: Ic9abc73025f93f2c40d69d92068c2ceabc085999
2023-05-11 02:09:19 +00:00
chrisl7 db2202c52b sepolicy: qva: Fix vendor_qcc_trd_2 denials
Change-Id: Id005c897cb2b1cc77d9aa9eef9304499f29f0070
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-04-17 10:36:08 +00:00
chrisl7 909a0dfee4 sepolicy: qva: Add missing hvdcp sepolicy definitions
Change-Id: I1ddcb79c7d4de6276b65d21a14bed1689267c7a1
Signed-off-by: chrisl7 <wandersonrodriguesf1@gmail.com>
2023-04-17 07:35:40 +00:00
Jake Weinstein 72c649838a common: sepolicy: lahaina: Remove qwesd policy
This is in common sepolicy_vndr now.

Change-Id: I58b8bd8bf7296751fbade8de8fb4eefab688a13e
2023-03-14 01:16:51 -03:00