Commit graph

2352 commits

Author SHA1 Message Date
Linux Build Service Account
e9c8c04efe Merge "Add sepolicy for chre daemon" 2018-03-14 09:19:59 -07:00
Mahesh Lanka
4a3de74d59 sepolicy: Add new vendor media file type
-Add new vendor media file type
-Add rule to allow MediaCodec Read/Write access to this file

Change-Id: I21f53fbf10208e6aab313abb3e9533195dc2fce3
2018-03-14 02:21:46 -07:00
Linux Build Service Account
d8263e65e8 Merge "Add appropriate selabel to ImageFv partition." 2018-03-13 18:03:14 -07:00
Sridhar Parasuram
deb1e89261 Add msm_irqbalance te file and policies
Change-Id: I05a56d22b1f587314ccbee0e31cae503b7c1635d
2018-03-13 12:26:07 -07:00
Sathish Ambley
a8591688ab Add sepolicy for chre daemon
Add sepolicy for chre daemon.

Change-Id: Ifd0f0dcd512af5727cd39cbaf549d0aeee145034
2018-03-13 09:44:19 -07:00
Tyler Wear
8b012e1d07 connectivity: provide dataservice app radio file permissions.
Bug: 38043081
Change-Id: Ifebefb01452ba2b9d8b8763b416c54d3b7f46568
2018-03-12 12:13:05 -07:00
padarshr
31ae26c28f Add appropriate selabel to ImageFv partition.
Since ImageFv is now an upgradable A/B partition,
adding appropriate selabel to it.

Change-Id: I188edb41aeb86945277d1ab4fabb885678c2a4ed
2018-03-12 19:27:03 +05:30
Ravi Kumar Siddojigari
1599867199 sepolicy : moving vendor testscripts to system
As vendor testscripts domain is moved to system  we
have to modify its startup and access based on this.

Change-Id: I1ceadac67912830feb09f6c013c4e77e3c5d4571
2018-03-09 15:53:03 -08:00
Sridhar Parasuram
f187b4ef2c Label qti-testscript
Change-Id: Ic022c3df0c0bbcc66b5a563a8f52b2f1b50f06f4
2018-03-09 15:53:02 -08:00
Sridhar Parasuram
93caf547ce Add create_dir_perms to data files for vendor_init
Change-Id: Icd550bb4eb696ca3ca1fb8932b869fa25187831c
2018-03-09 15:52:57 -08:00
Sridhar Parasuram
660e13e840 Add ctl property for msm_irqbalance
Change-Id: I2883b56a029e1ed321341a4d9d1421baf8b8ca5b
2018-03-09 13:48:10 -08:00
Linux Build Service Account
b135887cb0 Merge "Add rild as secure_element hal server" 2018-03-07 16:42:13 -08:00
Eric Chang
174a238ddc CA Certificate - sepolicy
Allow location to use cneapiclient for querying ca certificate

Change-Id: I8e10f744c3c40bfbda02988225d25a0992101c8e
2018-03-05 13:22:11 -08:00
Sandeep Gutta
ab7b7eccf8 Add rild as secure_element hal server
secure_elment to access UICC using rild.

Change-Id: If30c50fdc3f6fac7da8e26db7ab21b6ee6558a71
2018-03-05 11:02:30 +05:30
Linux Build Service Account
7055cd6ab9 Merge "allow rild to access diag_device" 2018-03-02 05:42:05 -08:00
Linux Build Service Account
244cd5ebee Merge "Fix issues related with qcrild" 2018-03-02 00:22:11 -08:00
Linux Build Service Account
fd415c3d2d Merge "move dataservice_app to radio process" 2018-03-02 00:22:10 -08:00
Hua Liu
0b66260b89 allow rild to access diag_device
Change-Id: I458decaa1eeca3e8d8d6e91ed70496f9c167fc00
2018-03-01 17:53:56 -08:00
Hua Liu
f827acffa7 Fix issues related with qcrild
- Associate qcrild with rild_exec context
- Create new property contexts for qcrild
and allow init_shell to set ctl properties
on these daemons to successfully start the
processes.

Change-Id: I4ca55577f489fdd5fb7a470b600a670dbcfa622a
2018-03-01 15:39:13 -08:00
Tyler Wear
05733f76b2 cnd: Net Admin
Fix cnd selinux rules.

Change-Id: I3449a85b7de9139e508814d6e99b3ad3bd2d1d50
CRs-fixed: 2187775
2018-03-01 11:08:22 -08:00
Tyler Wear
a65fea5e71 move dataservice_app to radio process
Bug: 38043081

Change-Id: I63866a0dbb934dd07da7c2acaf3fec6a36eea23e
2018-03-01 10:59:23 -08:00
Tyler Wear
5bf9d9af15 rcs: IMS system property
Read the system property for IMS module.

Change-Id: I0203bc2e7f2c801d3949f0287968043c7b142d95
2018-02-28 15:22:49 -08:00
Srinivas Girigowda
ee7b3626e6 wifi: Use wpa_data_file instead of wifi_vendor_data_file
system/sepolicy already defines wpa_data_file, Use that
instead of wifi_vendor_data_file

Change-Id: I916724ed60162b2b32247f07cca9c1a69363c9fb
CRs-Fixed: 2195448
2018-02-27 14:54:49 -08:00
Srinivas Girigowda
47fbf5a3dc hal_wifi_supplicant: Remove wpa_socket
Change-Id: If1b501dda7ff4d335955d59c85805d84756b5d7f
CRs-Fixed: 2195448
2018-02-27 14:54:35 -08:00
Linux Build Service Account
0cb2fd4757 Merge "Moving location sockets from /data to /dev" 2018-02-27 13:43:48 -08:00
Naseer Ahmed
0fda360207 sepolicy: Allow HWC to talk to allocator
Change-Id: I43fabb7db42a65eaea6cab5461f14405498e790d
2018-02-26 10:23:08 -08:00
Linux Build Service Account
b640da57bc Merge "Allow permissions to call CNE" 2018-02-24 00:06:53 -08:00
Linux Build Service Account
8343677b58 Merge "Update sysfs labeling" 2018-02-23 20:57:39 -08:00
Dante Russo
bd301074b6 Allow permissions to call CNE
Allow XTRA permissions to call CNE

CRs-Fixed: 2195094
Change-Id: I895966bbb888e4d6141befe62171e56379debe7c
2018-02-23 12:01:53 -08:00
Naseer Ahmed
704a55d170 sepolicy: Add policy for qti allocator and mapper
Change-Id: I532940d043bc51515bbf89deea283a60628528d9
2018-02-23 11:29:40 -08:00
Shaikh Shadul
f6c02fd2d2 sepolicy: allow init-qcom-sensors-sh to start sensors daemons
Add rules to allow init-qcom-sensors-sh to start sensors
daemons sscrpcd, sensors.qti from sensors script.

Change-Id: Ifde06f15fea9d306f3783694724d3116481a2c06
2018-02-23 08:48:28 -08:00
Sridhar Parasuram
db8636ccde Update sysfs labeling
Change-Id: Ib698defb6e2accebda58c853c5c0be23becfedcb
2018-02-23 08:01:27 -08:00
Sridhar Parasuram
1a761eb564 Update labeling for audio_data_file
Change-Id: I04af86a64198c7e96f018a74aaf32ebed7bbc8b2
2018-02-21 13:53:03 -08:00
Linux Build Service Account
dc58c3ab0c Merge "cnd: Net Admin" into sepolicy.lnx.4.9 2018-02-20 10:43:43 -08:00
Dante Russo
9a6a2b8090 Moving location sockets from /data to /dev
Keeping sockets in /data/vendor/location prevents
unmounting of /data partition after build load
CRs-Fixed: 2175510
Change-Id: I5b4b7a2cdc07a042795f0950725ce2d9c3518cf3
2018-02-15 10:20:40 -08:00
Sridhar Parasuram
486aa76037 Add wifi_data_file to data_between_core_and_vendor_violators
This change is needed until upstream fixes the wifi hal

Change-Id: Ie8c7b0df204d2274b3b0624ee5a9f47976c7fb20
2018-02-14 11:22:44 -08:00
Sridhar Parasuram
32aac06248 Remove policies using dac_override and dac_read_search capability
Change-Id: I591163c182f8c564f696fd3dd899041de24bdb6b
2018-02-14 11:22:43 -08:00
Tyler Wear
8f8b9beb46 cnd: Net Admin
Add net admin permission to CND.

Change-Id: I217d409b3813824de8822e719dc654df4a5c48fb
CRs-fixed: 2187775
2018-02-13 18:06:59 -08:00
Tyler Wear
660907d4dd Data SE Linux Cleanup
Sepolicy changes related to data modules needed for
the general cleanup effort.

Change-Id: I8b0247295e25faadfe63be9079055d76576958d3
2018-02-09 16:29:57 -08:00
Sridhar Parasuram
cc31c50446 Address new neverallow policies
Change-Id: I3fa9d205956c5a89f610893a9fd8d855b0383fd6
2018-02-05 11:06:24 -08:00
Sridhar Parasuram
ea1eb0b08c Address denials and cleanup
Change-Id: Id83d5c31fc168834b3cb89e7b32691770c4b7914
2018-02-02 10:20:11 -08:00
Linux Build Service Account
f607fe78fe Merge "sepolicy: added new sepolicy files for chre" into sepolicy.lnx.4.9 2018-01-31 14:45:45 -08:00
Sridhar Parasuram
b73ca02e5a Add a separate te file for the following shell scripts
* init.qcom.sensors.sh
    * init.qti.ims.sh
    * init.qcom.crashdata.sh

Add te files for ims, crashdata and sensors shell scripts

Change-Id: If482df2e2ef2dc257b79cece2bb1eb5f812007d2
2018-01-31 10:07:05 -08:00
Sridhar Parasuram
7962575a24 Add test policies
Change-Id: Ib8f60653e57388941e17d86be4495366930db89b
2018-01-31 10:07:00 -08:00
Biswajit Paul
237fb5193c sepolicy: added new sepolicy files for chre
Added new sepolicy files and socket node to make chre
daemon working

Change-Id: Iabb3a631aaf9aebaabf4cdbae23ca5ea5a3dda44
2018-01-29 11:43:47 -08:00
Sridhar Parasuram
48d5ab5d3c Add policies for init-qti-fbe-sh
Change-Id: Id768c70019a80d46a6e371d3573e700925209fdf
2018-01-25 11:57:12 -08:00
Sridhar Parasuram
df17efd8b1 Remove init-sh files that are not needed
Change-Id: I4b588c258f1d50b956bace1b61d0964fa0848c10
2018-01-25 11:57:07 -08:00
Sridhar Parasuram
77eb26c3a3 Remove the keymaster passthrough
Change-Id: I5d2497d5e6ff450a3be99e2a638b503d69c9e444
2018-01-24 17:08:14 -08:00
Sridhar Parasuram
9e70bfd3ac Move common files inside vendor to vendor/common
Change-Id: I0e5f67069463b6bd2bbfee355d95d490e64adad6
2018-01-24 14:29:45 -08:00
Sridhar Parasuram
8f9839c487 Address denials needed for bootup
Change-Id: I0cf893edf163692b637a490c3759dd13f5c74925
2018-01-23 16:51:32 -08:00