Modify SELinux rules to allow vold to use the keymaster HAL directly. am: b1c857c824

Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/2929772

Change-Id: I89c192fc02b8bb215cc52b8a4091930896595b21
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Peter Lee 2024-02-01 22:24:27 +00:00 committed by Automerger Merge Worker
commit 769bbce026
2 changed files with 2 additions and 0 deletions

View file

@ -328,6 +328,7 @@ neverallow { domain -vold -init } restorecon_prop:property_service set;
neverallow vold { neverallow vold {
domain domain
-hal_health_storage_server -hal_health_storage_server
-hal_keymaster_server
-system_suspend_server -system_suspend_server
-hal_bootctl_server -hal_bootctl_server
-hwservicemanager -hwservicemanager

View file

@ -335,6 +335,7 @@ neverallow { domain -vold -init } restorecon_prop:property_service set;
neverallow vold { neverallow vold {
domain domain
-hal_health_storage_server -hal_health_storage_server
-hal_keymaster_server
-system_suspend_server -system_suspend_server
-hal_bootctl_server -hal_bootctl_server
-hwservicemanager -hwservicemanager