Commit graph

23940 commits

Author SHA1 Message Date
Suren Baghdasaryan
e13e08255e property_contexts: Add missing ro.lmk.swap_util_max property context am: 54d5669770
Change-Id: I12de7269924180cbdbf9e7b08607baec177048ce
2020-05-06 00:35:11 +00:00
Suren Baghdasaryan
54d5669770 property_contexts: Add missing ro.lmk.swap_util_max property context
ro.lmk.swap_util_max property allows vendors to specify max swap
utilization for lmkd to consider.

Bug: 147315292
Signed-off-by: Suren Baghdasaryan <surenb@google.com>
Change-Id: I1c126091766eddf6c680f0041077eb1aa422dfd2
2020-05-05 19:25:22 +00:00
Tom Cherry
4ac3913137 Merge "Prevent transition to coredomain except for system files and vice versa" am: 34ec1de351
Change-Id: I575774a577be246932c6d38b90662e400f9e494e
2020-05-05 17:54:37 +00:00
Tom Cherry
34ec1de351 Merge "Prevent transition to coredomain except for system files and vice versa" 2020-05-05 17:36:54 +00:00
vichang
05f0ff39c1 Merge "Revert "Add shared library into i18n APEX and add the required s..."" am: bdc32ce577
Change-Id: I95b5909b6c8896fd3cc7059a9ca148e4ad4964b9
2020-05-05 12:00:52 +00:00
vichang
bdc32ce577 Merge "Revert "Add shared library into i18n APEX and add the required s..."" 2020-05-05 11:46:51 +00:00
vichang
016098f923 Revert "Add shared library into i18n APEX and add the required s..."
Revert "Make com_android_i18n namespace visible"

Revert submission 1299494-i18nApex

Reason for revert: Breaking aosp_x86-eng on aosp-master
Reverted Changes:
I30fc3735b:Move ICU from ART APEX to i18n APEX
Icb7e98b5c:Calling @IntraCoreApi from core-icu4j should not c...
Ic7de63fe3:Move core-icu4j into I18n APEX
I65b97bdba:Make com_android_i18n namespace visible
Ia4c83bc15:Move v8 and libpac into i18n APEX
I10e6d4948:Move core-icu4j into i18n APEX
I8d989cad7:Move ICU from ART APEX into i18n APEX
I72216ca12:Move ICU into i18n APEX
Ief9dace85:Add shared library into i18n APEX and add the requ...
I7d97a10ba:Move libpac into i18n APEX
I90fff9c55:Move ICU from ART APEX into i18n APEX

Change-Id: I863878038af1290611b441f7f9190494cf0851b8
2020-05-05 11:11:30 +00:00
vichang
e823c191a3 Merge "Add shared library into i18n APEX and add the required sepolicy" am: c18f8052e9
Change-Id: I597fcf7929997a672c240ffb5f9cfd82d83fb7b8
2020-05-05 09:03:58 +00:00
vichang
c18f8052e9 Merge "Add shared library into i18n APEX and add the required sepolicy" 2020-05-05 08:52:21 +00:00
Jeff Vander Stoep
e95e0456b2 Gboard: Whitelist test failure am: aeebb9a42e
Change-Id: Id44e8fbb24be8b53d36adb6c0ec0736df00844a1
2020-05-04 11:15:13 +00:00
Jeff Vander Stoep
aeebb9a42e Gboard: Whitelist test failure
This is intended to be temporary workaround until the Gboard
developers fix their app.

Addresses
avc: denied { bind } for comm="ThreadPoolForeg"
scontext=u:r:untrusted_app:s0:c166,c256,c512,c768
tcontext=u:r:untrusted_app:s0:c166,c256,c512,c768
tclass=netlink_route_socket permissive=
app=com.google.android.inputmethod.latin

Bug: 155595000
Test: build
Change-Id: I432ac1462329efb4bc118c3967a099833e6eb813
2020-05-04 08:53:49 +00:00
Inseob Kim
b47a303a28 Merge "Rename surfaceflinger properties' contexts" am: 4f780e10ce
Change-Id: I144e289ef18711331e464723a62a078516f1a4ca
2020-05-04 05:36:28 +00:00
Inseob Kim
4f780e10ce Merge "Rename surfaceflinger properties' contexts" 2020-05-04 05:22:01 +00:00
Songchun Fan
08a9c932af Merge "Define vendor-specific property ro.incremental.enable" am: 10230b9749
Change-Id: I6a1f75f3b4f7f0be9da0bcf47e15308d11d1b8b0
2020-05-02 20:10:39 +00:00
Songchun Fan
10230b9749 Merge "Define vendor-specific property ro.incremental.enable" 2020-05-02 19:55:43 +00:00
Songchun Fan
9fdcbcd29b Define vendor-specific property ro.incremental.enable
[cherry-picking]

Make ro.incremental.enable a vendor-specific property. Allow
system_server and vold to read this property.

Test: manual
BUG: 155212902
Change-Id: I8ff8837af635fa8e7b5bb02e5f6de5ac15b5023b
Merged-In: I8ff8837af635fa8e7b5bb02e5f6de5ac15b5023b
2020-05-01 10:27:51 -07:00
Treehugger Robot
d121571c12 Merge "allow media transcoding service to use activity service" am: 0785b6bfba
Change-Id: I51c0657bf07def4796e4352622b9365aca17e34a
2020-05-01 17:17:53 +00:00
Treehugger Robot
0785b6bfba Merge "allow media transcoding service to use activity service" 2020-05-01 17:04:19 +00:00
Treehugger Robot
bca8911773 Merge "mediaserver, mediaextractor, drmserver: allow vendor_overlay_file" am: b2fa463c43
Change-Id: I192290aa977a86c9e2a1d8790e8b884a2b95e044
2020-04-30 17:38:01 +00:00
Treehugger Robot
b2fa463c43 Merge "mediaserver, mediaextractor, drmserver: allow vendor_overlay_file" 2020-04-30 17:17:42 +00:00
Bob Badour
c42b12f5ef Add METADATA to sepolicy: PublicDomain=UNENCUMBERED am: ffdc7e8415
Change-Id: Ica016574d32aba077e14d9856da9bfb15aa0aa40
2020-04-29 22:49:58 +00:00
Tom Cherry
69fcac4c7e Prevent transition to coredomain except for system files and vice versa
Add a neverallow to prevent coredomain from accessing entrypoint for
files other than system_file_type and postinstall_file.  Add the
complementary neverallow to prevent domains other than coredomain from
accessing entrypoint for files other than vendor_file_type and
init_exec (for vendor_init).

Bug: 155124994
Test: build
Change-Id: I6e0cb7fb445b96b82e434e949b59c299aee1ad8b
2020-04-29 14:02:43 -07:00
Bob Badour
ffdc7e8415 Add METADATA to sepolicy: PublicDomain=UNENCUMBERED
Bug: 68860345
Bug: 69058154
Bug: 151953481

Test: no code changes
Change-Id: I88e8dcd0b23555f686b29781e545810efc5cafe7
2020-04-29 13:12:58 -07:00
Chong Zhang
f31e642494 allow media transcoding service to use activity service
Allow media transcoding service to get uid states from
activity manager for scheduling transcoding jobs.

bug: 145233472
bug: 154734285
test: mediatranscodingservice_tests (unit tests)
Change-Id: I96cfa52b323e9ae3841eca5519e9182347a5672b
2020-04-29 11:44:53 -07:00
Przemyslaw Szczepaniak
326fc92b86 Merge "Allow neuralnetworks hal service to read files from /sdcard" am: 2ea9264ea3
Change-Id: I731d0143e9755f40704293569bd8eab7339ec0c3
2020-04-29 11:57:27 +00:00
Przemyslaw Szczepaniak
2ea9264ea3 Merge "Allow neuralnetworks hal service to read files from /sdcard" 2020-04-29 11:49:31 +00:00
Jeongik Cha
832a8a9389 mediaserver, mediaextractor, drmserver: allow vendor_overlay_file
MediaPlayer cannot load a video from RRO packages.
So, add allow rules which is necessary to play the video.

Bug: b/154795779
Test: check if MediaPlayer can load a video in RRO
Change-Id: I06eed146b6e70a548b6b4f4faf56ba2bccd68140
2020-04-29 11:52:45 +09:00
Inseob Kim
721d921aa5 Rename surfaceflinger properties' contexts
Cleaning up exported*_system_prop and moving surfaceflinger properties
to new property contexts.

Bug: 152468529
Bug: 154885206
Test: boot cf_x86 and crosshatch
Change-Id: I7f8a684e9cbabce2f55a5292d7b2283ac0716cd9
2020-04-29 10:43:06 +09:00
Vladimir Marko
1b5370ebf6 Merge "Add missing dalvik.vm properties." am: ff21e32dd3
Change-Id: Ied428c2a18463663c2b518c3f5d3f29de1dd5a00
2020-04-28 08:51:12 +00:00
Vladimir Marko
ff21e32dd3 Merge "Add missing dalvik.vm properties." 2020-04-28 08:39:29 +00:00
Przemysław Szczepaniak
94be98073d Allow neuralnetworks hal service to read files from /sdcard
Bug: 138457453
Test: tflite nnapi benchmark app against /sdcard file
Change-Id: I368629f9177141d59eb5862cd29dd65da68d3ad7
2020-04-28 08:08:48 +00:00
Ioannis Ilkos
6d89f47641 Merge "Enable tracing of the ion/ion_stat events" am: e597605e01
Change-Id: I7364756d418c170570322e14221aa0a9692fc04c
2020-04-27 14:06:04 +00:00
Ioannis Ilkos
e597605e01 Merge "Enable tracing of the ion/ion_stat events" 2020-04-27 13:57:50 +00:00
Vladimir Marko
1062aa7d6c Add missing dalvik.vm properties.
Add missing properties identified by
  SRC=frameworks/native/cmds/installd/dexopt.cpp; \
  CTX=system/sepolicy/private/property_contexts; \
  for i in `grep -oE 'dalvik\.vm\.[^"]*' $SRC`; do \
    grep -qF "$i " $CTX || echo "$i"; \
  done

Test: aosp_taimen-userdebug boots.
Change-Id: I0678e0bfb1d50045ade37f504311ad39801f2135
2020-04-27 12:05:47 +01:00
Inseob Kim
77b6d05729 Add boot_status_prop for boot completed props am: 4ed4737aaf
Change-Id: I3e12a1f42c2376ae6e86c9f019443abc7ab86dc2
2020-04-27 07:39:32 +00:00
Inseob Kim
4ed4737aaf Add boot_status_prop for boot completed props
Assigning a new context boot_status_prop for following two properties:
- sys.boot_completed
- dev.bootcomplete

Bug: 154885206
Test: boot cf_x86 and crosshatch, see no denials
Change-Id: Ieadabf90a9a1b54b52a1283bd648c11c95d558dd
Merged-In: Ieadabf90a9a1b54b52a1283bd648c11c95d558dd
(cherry picked from commit 2973c96055)
2020-04-27 15:34:53 +09:00
Ioannis Ilkos
2e03e77f0a Enable tracing of the ion/ion_stat events
These events supersede the ion_heap_grow / ion_heap_shrink events on
4.19+ kernels.

Bug: 154302786
Test: build, run on cuttlefish with new kernel, ls -lZ /sys/kernel/tracing/events/ion/ion_stat/enable
Change-Id: I262d8c3269d4261701361ad4b1bdc322f1f03969
2020-04-24 10:10:35 +01:00
Treehugger Robot
c46d10d651 Merge "Add get_prop(domain, surfaceflinger_prop)" am: ca10be483b
Change-Id: I717c7a9a95397f4ea1be7e38e6250c24e031dbf5
2020-04-24 08:17:40 +00:00
Treehugger Robot
ca10be483b Merge "Add get_prop(domain, surfaceflinger_prop)" 2020-04-24 08:01:52 +00:00
Sundong Ahn
b2e82f4707 Add get_prop(domain, surfaceflinger_prop)
The ro.surface_flinger.* properties are using instead of configstore.
Add get_prop (domain, surfaceflinger_prop) to domain.te so that it can
be used on all systems in the same way as configstore.

Bug: 124531214
Test: read properties in java (ag/11226921)
Change-Id: Ifc8a53ea544c761d85e370e177913db91d8a33a2
2020-04-24 15:21:01 +09:00
Maciej Żenczykowski
e392d76cca Merge "property_contexts: Add ro.kernel.ebpf.supported" am: 7da6b5a351
Change-Id: I9505553303a91fc64b7f3b144072070407a965c4
2020-04-24 04:47:47 +00:00
Maciej Żenczykowski
7da6b5a351 Merge "property_contexts: Add ro.kernel.ebpf.supported" 2020-04-24 04:41:34 +00:00
Felix
0ee31c1aab property_contexts: Add ro.kernel.ebpf.supported
This prop allows vendors to specify whether their devices
have basic eBPF compatibility (ie. Linux kernel 4.9 with P VINTF).

Make it exported_default_prop because the shared library
libbpf_android is used in a lot of places.

See: https://r.android.com/1261922

Bug: 151753987
Signed-off-by: Felix <google@ix5.org>
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: Ifd9af558d84ea1619a6af7fce81b700fdfb22b9f
2020-04-24 01:34:28 +00:00
Jeffrey Vander Stoep
1ac6278863 Merge "Revert "mediaprovider: fixed sharedUserId bug"" am: 7bf9669a6c
Change-Id: Ieefdc1cfc7f0eab7595597722eb44cc4b1dd9462
2020-04-23 17:52:27 +00:00
Jeffrey Vander Stoep
7bf9669a6c Merge "Revert "mediaprovider: fixed sharedUserId bug"" 2020-04-23 17:36:28 +00:00
Jeffrey Vander Stoep
3b9683ff53 Revert "mediaprovider: fixed sharedUserId bug"
This reverts commit 2498d1c46e.

Reason for revert: b/154825574

Change-Id: I20ad5efc26fe076fb98503f59673892c491a1293
2020-04-23 17:33:55 +00:00
Petri Gynther
94facebd7c Merge "Allow adb shell user to collect vmstat" am: 6866e41bc5
Change-Id: I441588be9f00ecf3faa49a33a6c5abfa4f760103
2020-04-23 17:07:43 +00:00
Petri Gynther
6866e41bc5 Merge "Allow adb shell user to collect vmstat" 2020-04-23 16:55:08 +00:00
Yiming Jing
9401a2b157 Merge "Remove duplicate neverallow for hal_audio_server" am: b9c331e5ca
Change-Id: Idb830df96735875889d8de41f1c81498726576ab
2020-04-23 16:05:09 +00:00
Yiming Jing
b9c331e5ca Merge "Remove duplicate neverallow for hal_audio_server" 2020-04-23 15:37:37 +00:00