Commit graph

2759 commits

Author SHA1 Message Date
qctecmdr
75ca001e60 Merge "sepolicy: Policy fix for emmc based rpmb partition" 2019-04-17 15:10:35 -07:00
Tyler Wear
da8f3bb6a4 sepolicy: Policy fix for CND SSR
Add sepolicy rule to alow cnd process to perform
directory read on the SYSFS for SSR.

Change-Id: I5d8093b6d01584bcdbd0526f7335d7fcc601a4e5
2019-04-17 14:31:55 -07:00
Aman Gupta
c2e74e6de7 Sepolicy: Added rules for QTI HANA55 MHI node access
MHI node name retrival access policy rules

Change-Id: I513732f0c85db0c9a56920fad9f4331bd41e6f52
2019-04-17 13:40:50 -07:00
qctecmdr
e5544a4709 Merge "sepolicy: add sepolicy support for btconfigstore" 2019-04-17 11:10:31 -07:00
qctecmdr
8bbaa5353d Merge "sepolicy: Label new a2dp service as audio hw service" 2019-04-17 10:53:19 -07:00
qctecmdr
4c7f130826 Merge "QDMA sepolicy: removing read_logd permission for qdmastats" 2019-04-17 10:50:51 -07:00
Anuj Jalota
cedf94bb8c sepolicy: Declaring opencl.so as sp-hal for all the targets.
Change-Id: I57b831db4da8e62971e2b3961bbb181c70b57353
2019-04-17 17:52:16 +05:30
Srinu Jella
5ef06bbb32 sepolicy: Label new a2dp service as audio hw service
- Label the new a2dp HAL service as Audio he service
  so that Audio HAL process can load it and bluetooth
  host process can interact with new service.

Change-Id: If7a4c5f9dcf33edbef5647107cae4cfdf847c63f
2019-04-17 16:29:11 +05:30
Ramakant Singh
bd4ac11e91 sepolicy: Remove gralloc.qcom from SP HALs.
Change-Id: I31fed11610325293527928e54d82084a62b86343
2019-04-17 01:03:33 -07:00
Devi Sandeep Endluri V V
6204222d2f dpm : add ability to send signal to child process
-dpm need access to send signal to child process
while installing iptable rules with specific timeout.

CRs-Fixed: 2354745
Change-Id: I072f0a2d99dc5563b56815c25c6b7edb2e764175
2019-04-16 22:50:28 -07:00
Anmolpreet Kaur
f0ab1bd034 sepolicy: Policy fix for emmc based rpmb partition
Latest sepolicy rules in android Q enforce ioctl
restrictions on blk_file. This change adds sepolicy
rules to allow qseecom daemon process to perform ioctl
calls to rpmb partition in case of emmc based targets.

Change-Id: I884dbe35b5233eac195cfcfdaa73b359b671955d
Signed-off-by: Anmolpreet Kaur <anmolpre@codeaurora.org>
2019-04-16 21:52:06 -07:00
Nitin Shivpure
82ee6af929 sepolicy: add sepolicy support for btconfigstore
- Add separate hal_btconfigstore_hwservice
- Initialize server and client for hal_btconfigstore.
- Make system_app to be a client of hal_btconfigstore for FM.
- Make Bluetooth to be a client of hal_btconfigstore.

Change-Id: I680bcdb79836fbba22140f9e4bcfadeb7a70ed59
2019-04-16 21:40:17 -07:00
qctecmdr
e177d2f636 Merge "sepolicy: Policy fix for eMMC based rpmb partition" 2019-04-16 07:38:41 -07:00
qctecmdr
ef859b2d53 Merge "sepolicy: camera: add camera prop access permission" 2019-04-16 07:38:41 -07:00
qctecmdr
1c81b5fef4 Merge "wfd: Allow wfd processes to read video properties" 2019-04-16 07:38:27 -07:00
qctecmdr
844afc639a Merge "sepolicy: allow system_app to interact with soter hal" 2019-04-16 03:24:00 -07:00
qctecmdr
49df0132e3 Merge "sepolicy: allow mediacodec to access audio devices" 2019-04-16 03:23:02 -07:00
qctecmdr
b6d1d58154 Merge "wfd: Add polices for dumping of debug data" 2019-04-16 03:10:33 -07:00
qctecmdr
d605348b04 Merge "Adding perf hal permissions to iop hal" 2019-04-15 22:58:59 -07:00
Subbaraman Narayanamurthy
b4e06efc2b sepolicy: update access policy for charger script
Currently qti_init_shell label is applied for init.qti.charger.sh
however the script filename is changed to init.qti.chg_policy.sh
under charger_monitor project. Hence update access policy for
init.qti.chg_policy.sh and move them to qva/vendor/common along
with "hvdcp_opti" which seems to be the proper place.

Change-Id: I86ec11c12593a76069fbdcf5ed41cc05359938ad
2019-04-15 12:22:01 -07:00
Subbaraman Narayanamurthy
a91ce136d1 sepolicy: kona: Fix parallel charger path
Fix the device path for smb1355 parallel charger that can be used
on kona platforms.

Change-Id: I0d05cbe1239eeba5d0bd38f5cb204b68536ead3f
2019-04-15 12:12:36 -07:00
jkalsi
b20d9cf73e QDMA sepolicy: removing read_logd permission for qdmastats
Change-Id: Ic699c3af4bc806dfffe811eb9f126affb7ecf16b
2019-04-15 12:17:10 +05:30
Ramandeep Trehan
f7ab3e2a01 sepolicy: Policy fix for eMMC based rpmb partition
Add sepolicy rules to allow qseecom daemon process
to perform ioctl calls to rpmb partition in case of
eMMC based targets.

Change-Id: I1993a0cdf54dc949172afae8c095b4e253355e1c
2019-04-15 11:40:54 +05:30
qctecmdr
9d8decb80a Merge "Add rules for PPTP/L2TP VPN connection success" 2019-04-12 07:00:20 -07:00
Sauhard Pande
63146a889c sepolicy: camera: add camera prop access permission
Change-Id: I76102dec03f38426c41654c1dcac8316fc992798
2019-04-12 05:07:07 -07:00
qctecmdr
61d16198a6 Merge "Sepolicy: Add power off alarm rules" 2019-04-12 03:55:16 -07:00
ziqichen
ebe00485e2 sepolicy: allow system_app to interact with soter hal
add policies for soter to adapt to Android Q

Change-Id: I1c5079f2f2dfd7d937bbe35b9f9ae73bf9d2f1a7
2019-04-12 16:29:17 +08:00
qctecmdr
a946e1c166 Merge "sepolicy: Adding sepolicy for lmkd." 2019-04-12 01:05:13 -07:00
qctecmdr
6a2a57493b Merge "sepolicy: Add policies for soter" 2019-04-11 22:06:34 -07:00
Chalapathi Bathala
5e1f14729e [sepolicy] Add WIGIG device entry to genfs_contexts
[sepolicy] Add WIGIG device entry to genfs_contexts

Change-Id: I56e2eeeb9739e607bfbc33fcc06c96c3efd6084a
2019-04-11 18:40:43 -07:00
Lubin Yin
b238111218 sepolicy: Added ion permission for MLS screen capture
Change-Id: I735ad041cf52dd72f90a64e4c43223e0cce1a4e2
2019-04-11 13:25:26 -07:00
qctecmdr
18d948e94e Merge "SEPOLICY: Add vendor_adsprpc_prop property" 2019-04-11 04:50:55 -07:00
ziqichen
7972a74474 sepolicy: Add policies for soter
1. Allow access to tee device
2. Allow access to load firmware images
3. Allow access to interract with ion_device

Change-Id: Ibedc9b5e4eef94dc737f21a85cc7a974dab3d8aa
2019-04-11 17:26:09 +08:00
qctecmdr
aca7245cf7 Merge "sepolicy : Removed netadmin capability for location" 2019-04-11 01:10:08 -07:00
qctecmdr
edd0f7d44b Merge "sepolicy : Added wifihal sock perms and allow clients to connect" 2019-04-10 22:20:29 -07:00
qctecmdr
2c586da413 Merge "sepolicy: Added socket perms to location to connect to wpa ctrl socket" 2019-04-10 16:54:16 -07:00
qctecmdr
13f06ea405 Merge "sepolicy: Cleanup legacy redefinitions from wfd" 2019-04-10 11:37:44 -07:00
qctecmdr
9aa1426883 Merge "sepolicy: Change policy for wfd on legacy targets" 2019-04-10 11:37:44 -07:00
qctecmdr
930915e763 Merge "sepolicy: Add access policy for hvdcp_opti properties" 2019-04-10 08:29:32 -07:00
qctecmdr
57e979f818 Merge "Initial Sepolicy definition for lito" 2019-04-10 05:20:45 -07:00
Indranil
cf2a5ffa10 wfd: Allow wfd processes to read video properties
With separation of video properties into system/vendor buckets,
WFD needs to amend the rules accordingly.

Change-Id: I5570ac3045b5f6c11afe9765192d7a2bc4bb5e1f
2019-04-10 04:45:32 -07:00
Indranil
a2c91d7ca0 wfd: Add rules for access to OSAL debug framework
With migration of code on WFD source from system to vendor and
to system_app for WFD sink, add rules for access to OSAL logmask
file and OSAL debug properties(to allow for parser log debugging).

Change-Id: I209685d4336f0466421f286ecc50d81c1d9b9aa1
2019-04-10 04:44:55 -07:00
Indranil
cc9337be71 wfd: Add polices for dumping of debug data
Rules need to be added for dumping since WFD spans across
both system/vendor context post-QSSI re-architecture.

Change-Id: I11b0410af67eb2127d4d04e009ff8dbea81f2058
2019-04-10 04:44:16 -07:00
Vinay Gannevaram
606163f5ea sepolicy : Removed netadmin capability for location
Removed net admin capabilites for lowi. From now nl msgs of lowi
would route to wifihal via control socket.
Wifi hal allows its authenticated clients to send nl msgs to it.
Lowi module is one of its clients and hence added socket permissions
to access wifihal control interface

CRs-Fixed: 2424268
Change-Id: I18aba9169b23e8b0c9260cbf1e7a52bf59e0030d
2019-04-10 03:01:51 -07:00
Vinay Gannevaram
1eaea11a3c sepolicy : Added wifihal sock perms and allow clients to connect
Added wifihal directory in /dev/sockets path.
Wifi hal allows its authenticated clients to send nl msgs to it.
Lowi module is one of its clients and hence added socket permissions
to access wifihal control interface.

CRs-Fixed: 2424252
Change-Id: I9aa7b54f2f944d59148508eace3c658a23e5d2d8
2019-04-10 03:01:01 -07:00
qctecmdr
5db8ade2e8 Merge "QTI: cleanup of selinux denials for QTI" 2019-04-10 02:19:27 -07:00
Tharun Kumar Merugu
e0c312a1ff SEPOLICY: Add vendor_adsprpc_prop property
Add vendor_adsprpc_prop property to support the OS-upgrade.

Change-Id: Ie68d96a5e871b1fcc9920c24a393b60d6eb602f3
2019-04-09 18:19:55 +05:30
richagar
294b8479ae Adding perf hal permissions to iop hal
Added hal_client_domain(hal_iop_default, hal_perf)
to hal_iop_default.te

Change-Id: I5266702086a2d8b40eb91ca5c487cce9893bd312
2019-04-09 17:51:01 +05:30
Vinay Gannevaram
9b3711ccdc sepolicy: Added socket perms to location to connect to wpa ctrl socket
Lowi interacts with wpa supplicant for scan and anqp query via ctrl
communication. As the wpa control socket is in /data/vendor/ path
the required sepolicy changes are needed for location module

CRs-Fixed: 2431133
Change-Id: Icaef72229bc028c446c8d60c0b471de9583c63ae
2019-04-09 04:25:59 -07:00
richagar
16da6b2ff8 sepolicy: Adding sepolicy for lmkd.
Added lmkd.te and hwservicemanager.te

Change-Id: Ie63202497c3542d6b534aa654db22e3c71427c4c
2019-04-09 16:54:04 +05:30