Commit graph

54 commits

Author SHA1 Message Date
Uma Mehta
d3e3fdd5ea sepolicy: Add qva mediaextractor process permissions
- Add permission to read parser enable property and
  osal debug property

CRs-Fixed: 2402865

Change-Id: I002eeb74993af1d782095eefc6476bb50ae7d326
2019-02-21 18:10:37 +05:30
qctecmdr Service
0c9dc10a75 Merge "FR53463: Location generic and qva sepolicy changes." 2019-02-21 03:13:23 -08:00
qctecmdr Service
7ecdf9605e Merge "sepolicy: allowed v1.2 HALs for DRM and clearkey" 2019-02-21 02:42:11 -08:00
Harikrishnan Hariharan
a1dad7f9a8 FR53463: Location generic and qva sepolicy changes.
Location sepolicy changes for SElinux support for common
vendor image as part of FR53463.

Change-Id: I3eed6eed7a44c1aed50b667671f875597da64db1
CRs-Fixed: 2341061
2019-02-21 16:11:54 +05:30
Indranil
bc08ccc617 sepolicy: Change policy for wfd
WFD requires revision in it's SEAndroid policies due
to an OS upgrade and design re-architecure to conform
to system-wide mandates.

Change-Id: I3cd532c638b4bf6ee7ea8589fc64448cc08403f5
2019-02-21 12:07:34 +05:30
qctecmdr Service
e7994ced68 Merge "sepolicy : removed wfdservice access to tee_device" 2019-02-20 09:38:20 -08:00
qctecmdr Service
ce0a718d48 Merge "Sepolicy: set the property for dataadpl to start on bootup" 2019-02-20 08:21:00 -08:00
qctecmdr Service
63ba7b1ed6 Merge "Add SE policy for Bluetooth SAR HAL" 2019-02-20 08:21:00 -08:00
Murthy Nidadavolu
8a721d67b2 sepolicy: allowed v1.2 HALs for DRM and clearkey
v1.2 HALs to run for widevine and clearkey

Change-Id: I6df2a73aa943059172643c20691e8be21d6775ce
2019-02-20 16:47:29 +05:30
qctecmdr Service
6fbbe4eec8 Merge "sepolicy: Add missing mirrorlink rules" 2019-02-19 20:14:00 -08:00
Subramanian Srinivasan
b1777f4010 Add SE policy for Bluetooth SAR HAL
Add SE policy for Bluetooth SAR HAL

Change-Id: Iad048c3572baffb1333a0800a86207d518151dc4
2019-02-18 13:17:47 -08:00
Aman Gupta
9723220937 Sepolicy: set the property for dataadpl to start on bootup
set the property for dataadpl to start on bootup

Change-Id: I04bd132c50330839d26b177bf2ef2774664a2885
2019-02-18 01:26:02 -08:00
Ravi Kumar Siddojigari
ca429c825f sepolicy : removed wfdservice access to tee_device
Based on the  b/120243891 tee_device are not allowed to access
by coredomains (in full treble enabled devices) so removed
the access in wfdservice.te

Change-Id: I6608e08ac8ead3f4823b5443e86d937bd2b472ca
2019-02-18 12:56:17 +05:30
qctecmdr Service
d5df8025f1 Merge "sepolicy : add sepolicy rules require for DPM" 2019-02-17 06:34:57 -08:00
himta ram
b0dca15f04 sepolicy: add sepolicy support for fm
added separate hal_fm_hwservice for fm app.
intialize server and client for hal_fm.
made system_app to be a client of hal_fm

Change-Id: I2a9d9bebb77cecd535017856031e45f077724e94
2019-02-15 20:15:09 -08:00
Indranil
cbdbbf3527 sepolicy: Add missing mirrorlink rules
Add rules which were accidently deleted by other gerrits

Change-Id: Id42b518aee6bed91667e9439ca902e2424ba9fdc
2019-02-15 15:55:36 +05:30
Devi Sandeep Endluri V V
705d80ecdd sepolicy : add sepolicy rules require for DPM
Added sepolicy rules required for DPM.

CRs-fixed: 2395418
Change-Id: Id8b08c827735e826e0cd220b2d380092058992a8
2019-02-13 22:40:45 -08:00
Ravi Kumar Siddojigari
0bbc2777cd sepolicy : merge of sepolicy.lnx.5.0 to sepolicy.lnx.5.9
as part of keeping common system image syncing the public and
private folder of 2 components.

Change-Id: Ia2bffa5155b001b67ac6c4f9b0cc156c4afb5ad6
2019-02-12 18:57:48 +05:30
Smita Ghosh
26ff9f0b2b Sepolicy: add support for capabilityconfigstore
1. Define domain for capabilityconfigstore
3. Add type for /data/vendor/configstore folder
4. Allow capabilityconfigstore HIDL Server access/r/w it.

Change-Id: Ic5fdf44f55d2647d34c9bdf574d60bc445256a48
2019-02-08 14:55:41 -08:00
qctecmdr Service
72fda2a24a Merge "Move qdss sysfs file definition from target folder to common" 2019-02-06 22:24:25 -08:00
Biswajit Paul
3a9b15b59f Move qdss sysfs file definition from target folder to common
This CL fixes the compilation issue due to missing definition
of sysfs_qdss_dev on target other than msmnile. Also fix some
warning while I am here.

Change-Id: I3bc035f13fb0fe13650dac3c2d4b022e789d9f7b
2019-02-06 22:09:14 -08:00
Tyler Wear
c01d674958 Single System Image
Move vendor add sepolicy to specific folder.

Change-Id: Idd18772b023ddf05c6a08d0516383738d823e644
CRs-fixed: 2382338
2019-02-06 17:16:31 +05:30
James Shao
48d8241486 Sepolicy update patch to enable Connection Security
Change-Id: I69c7e449120a9a448d79128a0eeeea2ee6b8d3a1
2019-02-05 14:50:12 -08:00
qctecmdr Service
90f20fd4af Merge "sepolicy: Add sepolicy rules/files for mirrolrink" 2019-02-03 18:51:09 -08:00
Weiyin Jiang
fb4d38659c audiohalext: add config store interfaces to audio_hwservice
Add AHAL extension interfaces to audio hwservice.

Change-Id: I054fd3dcc1b27b0a32b52ba05152290f744fd0c6
2019-02-01 00:52:11 -08:00
Indranil
ff4a101598 sepolicy: Add sepolicy rules/files for mirrolrink
Add sepolicy rules/files for mirrolrink component

Change-Id: I8123e81079468facd9345cf2c30411699557a893
2019-01-30 19:39:49 +05:30
qctecmdr Service
e8e7e08cf2 Merge "sepolicy: add selinux rule for audio ftm test" 2019-01-29 17:40:00 -08:00
Xiaojun Sang
ea2bc4cb6d sepolicy: add selinux rule for audio ftm test
allow mm-audio-ftm to run and access data and config file.

Change-Id: I61803ceb1f746505e846c042c1152ea981289c18
2019-01-30 08:48:33 +08:00
Tapas Dey
bfe7af7df2 sepolicy: Add NFC sepolicy rules
Added missing sepolicy rules to fix NFC
enablement issue.

Change-Id: Ib0f6fa8dac34d91eb0664f5285727c4fbb6e39ee
2019-01-29 19:39:18 +05:30
qctecmdr Service
d765654f62 Merge "sepolicy: add audio rules to qva folder" 2019-01-28 01:39:21 -08:00
qctecmdr Service
7e7eb94c2d Merge "sepolicy :: Addition of sepolicy for cvphal" 2019-01-28 01:02:46 -08:00
qctecmdr Service
4cd8dfb4ac Merge "FR53056 for Connection Security." 2019-01-28 00:44:42 -08:00
Vikram Panduranga
d1c36a1d5e sepolicy: add audio rules to qva folder
Add delta audio rules that are needed to
support value add features into qva folder.

Change-Id: I39ab747df98b067b78e7009d198f7a7837d5bd4d
2019-01-24 11:27:48 -08:00
James Shao
6f4bddb347 FR53056 for Connection Security.
Enable SSG sepolicy on latest Android versions.
Port LA.1.0 Connection Security sepolicy to LA.2.0.
sepolicy.lnx.4.0 to sepolicy.lnx.5.9

Change-Id: I20c2f5b099baa4664f48e72225cd962a09893991
2019-01-24 09:56:23 -08:00
suchawla
6deb2681cc sepolicy :: Addition of sepolicy for cvphal
Cvp is a new computer vision hardware
which interacts with DSP and video driver.
Adding new ion mem permission for cvp domains.

Change-Id: I6c2118b15cf5ccc6505c80969c4090e3396238e4
2019-01-24 13:31:00 +05:30
qctecmdr Service
a23c904f84 Merge "sepolicy : removed duplicate definations from hwservice_contexts" 2019-01-23 21:36:05 -08:00
vijay.rayabarapu
ff7b884e6c Sepolicy: adding new line to property context file
Change-Id: Ic384df1fcd2bdc58ce017e44468dbfe8cfc9f42e
2019-01-23 12:19:18 -08:00
Ravi Kumar Siddojigari
00a7d989e1 sepolicy : removed duplicate definations from hwservice_contexts
build error as following are address by removing the duplicate defs
Multiple same specifications for vendor.qti.hardware.iop::IIop.
Multiple same specifications for vendor.qti.hardware.alarm::IAlarm.

Change-Id: I2b3de7d4155aaef141fbe9f7bb30161e214767cd
2019-01-22 22:26:09 -08:00
Huang Li
b47502c653 Sepolicy: Porting QMMI/FFBM Sepolicy from sepolicy 4.0 to 5.9.
Porting all relative sepolicy files for factory test.

Change-Id: I573bd39f5071a646bb38854027e066b09602b9f1
CRs-Fixed: 2374478,2374492,2374499,2374503
2019-01-21 13:14:43 +08:00
qctecmdr Service
8087eab689 Merge "Sepolicy: Address bootup denials for configstore" 2019-01-17 00:27:52 -08:00
qctecmdr Service
6ad10fec94 Merge "Camera: adding sepolicy for accessing vendor properties" 2019-01-13 23:15:19 -08:00
Mohamed Sunfeer
319cd450b9 sepolicy: Add selinux rules to disable SPU
Add disable SPU property to allow OEM to disable SPU.

Change-Id: I60a98f87d7557ea9263843ed8d475c091c5e634c
2019-01-11 16:40:21 +05:30
Sauhard Pande
1b99037858 Camera: adding sepolicy for accessing vendor properties
Issue: To access and read vendor.camera.aux.packagelist
and persist.vendor.camera.privapp.list. Needed to identify
priviledged app and dual camera exposure

Fix: Accessed only on system side thus added flags as
extended_core_property_type

Change-Id: I9518e88cdbc8411a9c070cc01a000442828715a4
2019-01-10 22:16:36 -08:00
Archit Srivastava
4631b2782b Sepolicy: Address bootup denials for configstore
Allowing surfaceflinger to check HDR and WCG Supported at run time from
hardware to override hardcoded values defined in $TARGET.mk

Change-Id: Id4857b9d790b73b787e20f7cbc46d3dcf34a47ea
2019-01-10 17:47:12 +05:30
Shaikh Shadul
f9adb88fe8 sepolicy: initial sensors policy changes for common image
Change-Id: I7bc74d7b90ef39d878cd4b096713c66f818b4fe6
2018-12-26 14:28:45 +05:30
Chalapathi Bathala
41c6bfc0aa sepolicy: add policies for mdm_helper
Add policies for mdm_helper

Change-Id: Ie233107671fd9566f822d54bc1cd0b22286ca6f3
2018-12-11 10:41:56 -08:00
Hemant Gupta
c21eb88d4b sepolicy : Address BT denials resulting in error popups
Address BT denials resulting in error popups.

Change-Id: Ifba5c183739663113dd58814fbf445ae51cefd77
2018-11-27 16:21:06 +05:30
Ravi Kumar Siddojigari
4106db5b4f sepolicy : cleanup and misc denials addressed .
as part of bringup addressed misc denials and code cleanup

Change-Id: Ifba5c183739663113dd58814fbf445ae51cefe77
2018-11-15 22:25:34 -08:00
Vara Prasad A V S G
1287d1c879 sepolicy : remove system_writes_vendor_properties_violators
As part of treble system /core services are not allowed  to
set vendor property .

if Property defined is part of system image then it can be set
or get by core/system services provided we define the property
as extended_core_property_type. So adding this to the property
that are added by vendor and used by core/system services.

Change-Id: I7ad8bc562be09126c082fc54f52499f5138fea5b
2018-11-15 03:41:05 -08:00
Siddeswar Aluganti
69f3ff2c7d Fix build errors.
Change-Id: If024d9253ad12fcbeab755f1e77421ec20f28b95
2018-11-14 14:37:31 -08:00