Skip to content
Snippets Groups Projects
  1. Feb 08, 2023
  2. Feb 06, 2023
  3. Feb 02, 2023
  4. Jan 31, 2023
  5. Jan 25, 2023
  6. Jan 24, 2023
  7. Jan 23, 2023
  8. Jan 22, 2023
  9. Jan 20, 2023
  10. Jan 19, 2023
  11. Jan 18, 2023
  12. Jan 17, 2023
  13. Jan 16, 2023
  14. Jan 12, 2023
    • qctecmdr's avatar
    • kparmar's avatar
      meta-qti-auto-sepolicy: Add rules for AVC denials · 4797d506
      kparmar authored
      Provide unix_dgram_socket access to various services
      engine_Service, loc_hald_t, slim_daemon
      
      Change-Id: I51de6e01fa6a66ab657a1214cc41aedd514704e0
      CRs-Fixed: 3373179
      4797d506
    • Ashutosh Kaushik's avatar
      meta-qti-auto-sepolicy: SE policy rules for qwes on SA525M · b10d9183
      Ashutosh Kaushik authored
      qwesd.fc:
      1. Added contexts for /dev/socket/qwes/* & /dev/socket/qwes/qwes_ipc which
      are used to create socket node for qwes_ipc.
      2. Created context for create_qwes_ipc initscript which is used to initialize
      /dev/socket/qwes path and set the permissions & ownerships for it.
      qwesd.te:
      1. Added types for qwes_mink_socket_t: used to define type for qwes_ipc socket
      2. Added types for /dev/dma_heap/qcom,qseecom & /dev/dma_heap/qcom,qseecom-ta,
      which are required to load QWES TA using qseecom_start_app_v2 API
      3. Added filesystem assosciate permissions for qwes_mink_socket_t to properly assign
      contexts for the qwes_ipc node.
      4. Added write permission to the qwes_ipc socket to bind to it & access the socket.
      5. Added permissions for qwesd to access /dev/dma_heap/qcom,qseecom node to read,ioctl,open the
      chr driver node.
      6. Added permission for qwesd to process signals
      7. Added qwesd permissions for /dev/dma_heap/qcom,qseecom-ta node.
      8. Allowing qwesd to be restartable in debug/engg build environments.
      9. Added types for create_qwes_ipc init script.
      10. Added permissions for create_qwes_ipc script to create the /dev/socket/qwes/ directory.
      11. Added permisisons for create_qwes_ipc to write logs to /dev/kmsg
      12. Added create_qwes_ipc permissions to write to /etc/ to set the permission & access data using
      chmod/chown on the /dev/socket/qwes/ path
      vendor.fc:
      1. Added context for /dev/dma_heap/qcom,qseecom-ta dev node.
      vendor.te:
      1. Added types for /dev/dma_heap/qcom,qseecom-ta dev node.
      
      Change-Id: Ic07d9cb8b82ffc5b1b524e39212b1bb6914f06be
      b10d9183
    • Gu, Ruixuan's avatar
      meta-qti-auto-sepolicy: Fix denials for dhcpcd · 85d617a7
      Gu, Ruixuan authored
      Add rules for dhcpcd feature
      
      Change-Id: I74ebaee14c2470ba5346557dbd56436c3502cd32
      85d617a7
  15. Jan 09, 2023
  16. Jan 04, 2023
  17. Dec 31, 2022
  18. Dec 29, 2022
  19. Dec 23, 2022
  20. Dec 15, 2022
    • Rishi Gupta's avatar
      meta-qti-auto-sepolicy: add dbus rules for telux audio server · 5a36a9f4
      Rishi Gupta authored
      Fix following three avc denials:
      
      avc: denied { search } comm="telux_audio_ser" name="dbus"
      dev="tmpfs" ino=96 scontext=system_u:system_r:
      telux_audio_server_t:s0-s15:c0.c1023 tcontext=system_u:
      object_r:system_dbusd_var_run_t:s0 tclass=dir
      
      avc: denied { write } comm="telux_audio_ser"
      name="system_bus_socket" dev="tmpfs" scontext=system_u:
      system_r:telux_audio_server_t:s0-s15:c0.c1023 tcontext=
      system_u:object_r:system_dbusd_var_run_t:s0 tclass=
      sock_file
      
      avc: denied { connectto } comm="telux_audio_ser"
      path="/run/dbus/system_bus_socket" scontext=system_u:
      system_r:telux_audio_server_t:s0-s15:c0.c1023 tcontext=
      system_u:system_r:system_dbusd_t:s0-s15:c0.c1023
      tclass=unix_stream_socket
      
      Change-Id: I3bb5122b1edc2da3aa1a1f6c04be227c0d1341ad
      5a36a9f4
  21. Dec 08, 2022
  22. Dec 07, 2022
Loading