Skip to content
Snippets Groups Projects
  1. Mar 21, 2018
    • Treehugger Robot's avatar
      cd175e0e
    • Treehugger Robot's avatar
      Merge "Fix mapping file build." · cc4b960f
      Treehugger Robot authored
      cc4b960f
    • Chenbo Feng's avatar
      Allow netd to setup xt_bpf iptable rules · 5c95c168
      Chenbo Feng authored
      To better record the network traffic stats for each network interface.
      We use xt_bpf netfilter module to do the iface stats accounting instead
      of the cgroup bpf filter we currently use for per uid stats accounting.
      The xt_bpf module will take pinned eBPF program as iptables rule and run
      the program when packet pass through the netfilter hook. To setup the
      iptables rules. netd need to be able to access bpf filesystem and run the
      bpf program at boot time. The program used will still be created and
      pinned by the bpfloader process.
      
      Test: With selinux enforced, run "iptables -L -t raw" should show the
      xt_bpf related rule present in bw_raw_PREROUTING chain.
      Bug: 72111305
      
      Change-Id: I11efe158d6bd5499df6adf15e8123a76cd67de04
      5c95c168
    • Tri Vo's avatar
      silence innocuous denials to /proc and /sys · 422fb98e
      Tri Vo authored
      Bug: 74182216
      Test: build bullhead, sailfish sepolicy
      Change-Id: I6d0635a49c025870c9ecb46147e6c9a1c407fe16
      422fb98e
    • Tri Vo's avatar
    • Tri Vo's avatar
      Revert "silence innocuous denials to /proc and /sys" · cee3f687
      Tri Vo authored
      This reverts commit 09b1d962.
      
      Reason for revert: bullhead broken
      
      Change-Id: Ib4562f944cdc2618cc3ed3beb4f612f0ef8b3223
      cee3f687
    • Tri Vo's avatar
      Fix mapping file build. · bbb8f5bd
      Tri Vo authored
      Location of mapping files has changed from private/mapping/V.v.cil to
      private/compat/V.v/V.v.cil
      Change the build rule for current_mapping.cil to reflect that.
      
      Test: Build current mapping file with  BOARD_SEPOLICY_VERS := 27.0 and
      make sure that $OUT/obj/ETC/27.0.cil_intermediates/27.0.cil is not empty
      Change-Id: I996a717e1c659265cb067da5d621d71ff3b3b63b
      bbb8f5bd
  2. Mar 20, 2018
  3. Mar 19, 2018
  4. Mar 18, 2018
  5. Mar 16, 2018
  6. Mar 15, 2018
    • padarshr's avatar
      Init: Enable init to relabel symlinks for recovery_block_device. · bc14ee3c
      padarshr authored
      Allow init the ability to relabel recovery block devices. In the case
      where we have recovery as a chain partition, due to its presence in
      early mount node, init, in first stage itself would require relabel
      permissions for the restorecon operation on recovery block device.
      
      Bug: 73642793
      Test: On bootup, recovery partition gets the appropriate se-label.
            Perform OTA on non-A/B device with recovery as chain partition,
            now the recovery partition gets upgraded successfully, now that
            it has the correct se-label.
      
      Change-Id: I370c510320e78ab78c9c55573073415b4983d0f6
      bc14ee3c
    • Bowgo Tsai's avatar
      Mark some odm properties as vendor-init-settable · a47a1c25
      Bowgo Tsai authored
      Bug: 64195575
      Test: boot a device
      Change-Id: I7f7deb5e2c5c6e0a75cf22eb610a7973b5be0d7e
      a47a1c25
Loading