Commit graph

90942 commits

Author SHA1 Message Date
Treehugger Robot
bc2895cb84 Merge "Replace partition-specific toybox make module with soong modules" into main am: 7d90faa8b7
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3393539

Change-Id: I7e5ed9648ea5f9b256ae76cddfdae011e5bce2ef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-05 20:47:22 +00:00
Treehugger Robot
7d90faa8b7 Merge "Replace partition-specific toybox make module with soong modules" into main 2024-12-05 20:24:08 +00:00
Jihoon Kang
44eca61ab9 Replace partition-specific toybox make module with soong modules
toybox no longer sets recovery_available
property, thus this make module is no longer generated. Thus,
replace the entry with the soong modules to prevent missing
dependencies make error.

This change also specifies `recovery` property in
shell_and_utilities_recovery to allow soong generated recovery partition
to correctly install the dependencies of the phony module.

Test: m nothing
Bug: 381888358
Change-Id: I314e8031d23a9f579101ca1d5499969af4e3a9d3
2024-12-05 18:50:11 +00:00
Treehugger Robot
30935be2b2 Merge "gatekeeperd_service_fuzzer: Add signal() to handle SIGPIPE" into main am: 8186c63621
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3382007

Change-Id: Ife3eecf4b55e3a6d108b5e8e62256116447b0c9b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-05 07:51:47 +00:00
Treehugger Robot
8186c63621 Merge "gatekeeperd_service_fuzzer: Add signal() to handle SIGPIPE" into main 2024-12-05 07:25:38 +00:00
Treehugger Robot
131fb17876 Merge "Update trusty to use secretkeeper hal V1" into main am: 43772f2bc2
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3390499

Change-Id: Iabab95513c63353dcbc99ed9a3f44a216b8759fc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-04 21:50:54 +00:00
Treehugger Robot
43772f2bc2 Merge "Update trusty to use secretkeeper hal V1" into main 2024-12-04 21:22:00 +00:00
Dennis Shen
30650d6d57 Merge "Start aconfigd socket defined in configinfra mainline module" into main am: 894577050b
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3284475

Change-Id: I6180d86db5c2ed8bba8664f741d00df08ebfcf0b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-04 15:57:02 +00:00
Dennis Shen
894577050b Merge "Start aconfigd socket defined in configinfra mainline module" into main 2024-12-04 15:17:58 +00:00
Treehugger Robot
4f6c94845f Merge "trusty: utils: rpmb_dev: secure storage support for test VM" into main am: 63051ccde0
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3369411

Change-Id: Ic6ae4769ad553b5be19413661919fb79e2a5ad22
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-04 03:54:18 +00:00
Treehugger Robot
63051ccde0 Merge "trusty: utils: rpmb_dev: secure storage support for test VM" into main 2024-12-04 03:18:05 +00:00
Dennis Shen
683e3c0761 Start aconfigd socket defined in configinfra mainline module
Context: to have better future updatability. The responsiblity of
managing mainline module storage files and a socket service for flag
overrides will be moved to the configinfra mainline module. Later,
aconfigd on /system will only be repsopnsbile for managing platform
partition storage files.

Bug: b/369810972
Test: m, launch avd and then inspect the logcat log to confirm the
service is launched.

Change-Id: I490e5aa432fa4afa236689ad0999e5602f7d297e
2024-12-03 23:52:00 +00:00
Matt Gilbride
7a1cf9a52d Update trusty to use secretkeeper hal V1
The HAL has been updated to V2, but the trusty prebuilt implementation
does not yet have that code. Update trusty secretkeeper build to use V1
specifically instead of latest until the prebuilt has those changes.

Bug: 372223451
Test: TH
Change-Id: Ic2e9b578b50685d71b5597d8d34ac7ee36b6ddc9
2024-12-03 23:33:43 +00:00
Isaac Manjarres
54fcd05250 Merge "ashmem: Ensure all memfds have non-executable permissions by default" into main am: 445d2e0025
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3388580

Change-Id: I0764f39cae8029a14042d4196287adc870264a89
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-03 23:25:21 +00:00
Isaac Manjarres
445d2e0025 Merge "ashmem: Ensure all memfds have non-executable permissions by default" into main 2024-12-03 22:53:26 +00:00
Isaac J. Manjarres
ee7a713757 ashmem: Ensure all memfds have non-executable permissions by default
Currently, memfds are created with executable permissions, meaning that
one can load a binary into a memfd buffer and use fexecve() to run said
binary. This is not desirable for security reasons, and also does not
match with the behavior that the ashmem driver currently supports.

When the ashmem driver is in use, /dev/ashmem* does not have executable
permissions, so fexecve() cannot be used on those buffers. Linux kernels
6.3+ offer MFD_NOEXEC_SEAL as part of the memfd interface, which allows
one to create memfds with non-executable permissions. Furthermore, the
executable permissions cannot be changed on these memfds.

This matches the expected behavior that ashmem provided, so allow memfd
usage only if MFD_NOEXEC_SEAL is supported, and create memfds with
non-executable permissions by default.

Bug: 111903542
Change-Id: Ibb2c2be3c118ead44fc12bcd2b63dcf6f83c9b03
Signed-off-by: Isaac J. Manjarres <isaacmanjarres@google.com>
2024-12-03 10:13:28 -08:00
Treehugger Robot
0b0b273f42 Merge "fs_mgr: Support nosymfollow mount option" into main am: 92487860cf
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3368571

Change-Id: I82b1d4118294d26033ba8decee4482be71d5bd95
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-03 17:36:16 +00:00
Treehugger Robot
92487860cf Merge "fs_mgr: Support nosymfollow mount option" into main 2024-12-03 17:11:18 +00:00
Treehugger Robot
f670036b82 Merge "libsnapshot: Cleanup temp metadata during rollback" into main am: 326534aace
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3388019

Change-Id: I49676341c3d86b8ad52c44dd2cc08653d0725b4a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-02 22:51:58 +00:00
Treehugger Robot
326534aace Merge "libsnapshot: Cleanup temp metadata during rollback" into main 2024-12-02 22:31:01 +00:00
Treehugger Robot
be00d31ac5 Merge changes I0586f761,I9fc71f9c,I0ad1f449 into main am: 85050a06e1
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3377032

Change-Id: I0f691b82207853c7edd53079c91d1c7e38d67c3b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-02 19:20:44 +00:00
Treehugger Robot
85050a06e1 Merge changes I0586f761,I9fc71f9c,I0ad1f449 into main
* changes:
  libprocessgroup: Remove ramdisk_available from libcgrouprc
  libprocessgroup: Remove vendor_ramdisk_available from libcgrouprc
  libprocessgroup: Remove recovery_available from libcgrouprc
2024-12-02 19:03:46 +00:00
Akilesh Kailash
00a32314ac libsnapshot: Cleanup temp metadata during rollback
Bug: 380471512
Test: Test rollback and check metadata is cleared
Change-Id: I4ebd5d9842409fa32c58bb482ffc0066817a5a05
Signed-off-by: Akilesh Kailash <akailash@google.com>
2024-12-02 10:58:46 -08:00
Eric Biggers
a3ce66437c Merge "Fix the dm-verity Merkle tree caches to not expire so quickly" into main am: 6dc0ed1758
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3377529

Change-Id: Id336c8aea1a2abf9cf9d8dfbfcf735109f1103d6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-02 18:38:10 +00:00
Eric Biggers
6dc0ed1758 Merge "Fix the dm-verity Merkle tree caches to not expire so quickly" into main 2024-12-02 18:11:34 +00:00
T.J. Mercier
8972ce18d2 libprocessgroup: Remove ramdisk_available from libcgrouprc
...which no longer appears to be required.

Bug: 349105928
Change-Id: I0586f76147d9519ef6a520a10164e1b0f5e5c9b8
2024-12-02 17:41:12 +00:00
T.J. Mercier
62f8723f67 libprocessgroup: Remove vendor_ramdisk_available from libcgrouprc
...which no longer appears to be required.

Bug: 349105928
Change-Id: I9fc71f9cf3238dcc935da63ce1a3b0b69d9cccc1
2024-12-02 17:41:12 +00:00
T.J. Mercier
f26b13aeb1 libprocessgroup: Remove recovery_available from libcgrouprc
...which no longer appears to be required.

Bug: 349105928
Change-Id: I0ad1f44912fdaf98c05b60402c0166c535155775
2024-12-02 17:41:12 +00:00
Treehugger Robot
7aa226893f Merge "Update comments to point to the new location of event.logtags." into main am: e7a16c3aa0
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3376093

Change-Id: Ie9e6be7b00e6a49a0ff4f32bc60066d04e43889d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-12-02 15:13:49 +00:00
Treehugger Robot
e7a16c3aa0 Merge "Update comments to point to the new location of event.logtags." into main 2024-12-02 14:48:01 +00:00
Akhilesh Sanikop
8366faad18 gatekeeperd_service_fuzzer: Add signal() to handle SIGPIPE
Adding signal handler to avoid abort() due to
broken pipe.

Test: ./gatekeeperd_service_fuzzer
Bug: 376201407
Change-Id: Ifca08860d11f56eb8e0d490c6b6956f8774cfa70
2024-11-29 15:02:21 +05:30
Dennis Shen
f716e1e0ce Merge "Deprecate cc_binary aconfigd and the controlling flag" into main am: db80953238
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3376683

Change-Id: Idfd6463c179d460df776adf024def33a72f66583
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-27 13:48:25 +00:00
Dennis Shen
db80953238 Merge "Deprecate cc_binary aconfigd and the controlling flag" into main 2024-11-27 13:33:23 +00:00
David Drysdale
e59a7fb20c Merge "Move Trusty C++ KeyMint to v4" into main am: bc6efddf79
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3375712

Change-Id: I47ec3395aaa9a13ce7e8f3bc2ac514d0663f4371
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-27 08:31:21 +00:00
David Drysdale
bc6efddf79 Merge "Move Trusty C++ KeyMint to v4" into main 2024-11-27 07:18:20 +00:00
Treehugger Robot
2809871edc Merge "libutils OWNERS for shayba@" into main am: 17cd008055
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3378962

Change-Id: Ie9f3f675d4378e3e48052c6261cfb6a90b53f2b0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-27 01:13:22 +00:00
Treehugger Robot
17cd008055 Merge "libutils OWNERS for shayba@" into main 2024-11-27 00:28:02 +00:00
Steven Moreland
27dd6f8e62 libutils OWNERS for shayba@
For Looper work, but not scoped down to this
unless you want it to be.

Bug: N/A
Test: N/A
Change-Id: I14bf8d21af357ef7b9151cca49b0cf40dde0e3ca
2024-11-26 23:44:17 +00:00
Dennis Shen
52d2446b4e Deprecate cc_binary aconfigd and the controlling flag
cc_binary aconfigd is replaced with rust_binary aconfigd-system. The
replacement is flag guarded and is already in TF full for more than a
week. Thus delete the flag and deprecate old cc_binary aconfigd.

Test: m
Change-Id: Ib128adc2ef8178e02222f77e6b89bcc7ac83c1da
2024-11-26 15:26:52 +00:00
Treehugger Robot
3b4612e7da Merge "libprefetch: rename property name" into main am: 7c066103a3
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3376861

Change-Id: I5d4190cb20e59941497893887492dd508c228690
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-26 09:03:46 +00:00
Treehugger Robot
7c066103a3 Merge "libprefetch: rename property name" into main 2024-11-26 08:38:29 +00:00
Akilesh Kailash
3df083a498 libprefetch: rename property name
Bug: 362507272
Test: Build
Change-Id: I39627fdcbbe5458e6fbc9dfaa1aa620844d56f8b
Signed-off-by: Akilesh Kailash <akailash@google.com>
2024-11-25 21:46:56 -08:00
Eric Lin
9731ea7b67 Update comments to point to the new location of event.logtags.
event.logtags was moved from system/core/logcat to system/logging/logcat in Android 12 by aosp/1454058.

Change-Id: Ia3cedee549145eddb0484ec589a9599a156bea14
BUG: 168791309
Flag: DOCS_ONLY
Test: Local build
2024-11-26 04:24:56 +00:00
Eric Biggers
cadad290a7 Fix the dm-verity Merkle tree caches to not expire so quickly
Bug: 335233956
Test: cat /sys/module/dm_bufio/parameters/max_age_seconds
Change-Id: I20e4df7dd3eb2ac1f462510e900568e946195faf
2024-11-26 03:24:44 +00:00
Automerger Merge Worker
f6ad6dc896 Merge "Merge "snapuserd: Use GTEST_SKIP in snapuserd_test." into android15-tests-dev am: a8537415c1" into main am: f7b584086c
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3365128

Change-Id: Ibec698c323f0962738a3e952c74001dbadd24bab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-25 22:54:54 +00:00
Automerger Merge Worker
f7b584086c Merge "Merge "snapuserd: Use GTEST_SKIP in snapuserd_test." into android15-tests-dev am: a8537415c1" into main 2024-11-25 22:25:24 +00:00
Treehugger Robot
c1f5c76fa9 Merge "snapuserd: Use GTEST_SKIP in snapuserd_test." into android15-tests-dev am: a8537415c1
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3365128

Change-Id: I12b0472a65d5c11ece024801392cc265cf0c5049
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-25 22:25:19 +00:00
Treehugger Robot
a8537415c1 Merge "snapuserd: Use GTEST_SKIP in snapuserd_test." into android15-tests-dev 2024-11-25 22:05:44 +00:00
Dennis Shen
0f3c97ac6a Merge "move aconfigd platform init service from init.rc into aconfigd.rc" into main am: c532409c5c
Original change: https://android-review.googlesource.com/c/platform/system/core/+/3344222

Change-Id: Ia16c72f825d9346fa1c16760250b03346c810573
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-11-25 17:45:08 +00:00
Dennis Shen
c532409c5c Merge "move aconfigd platform init service from init.rc into aconfigd.rc" into main 2024-11-25 17:27:03 +00:00