Allow shell to change RKP properties am: d3bd68607e

Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/2456270

Change-Id: I2cf629ec5325c22199dcfe4619441a6e3d67add9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Seth Moore 2023-02-25 04:56:10 +00:00 committed by Automerger Merge Worker
commit 98524e7333
2 changed files with 4 additions and 0 deletions

View file

@ -632,6 +632,7 @@ neverallow {
domain
-init
-remote_prov_app
-shell
} remote_prov_prop:property_service set;
neverallow {

View file

@ -101,6 +101,9 @@ set_prop(shell, power_debug_prop)
# Allow shell to set this property used for rollback tests
set_prop(shell, rollback_test_prop)
# Allow shell to set RKP properties for testing purposes
set_prop(shell, remote_prov_prop)
# Allow shell to get encryption policy of /data/local/tmp/, for CTS
allowxperm shell shell_data_file:dir ioctl {
FS_IOC_GET_ENCRYPTION_POLICY