Modify SELinux rules to allow vold to use the keymaster HAL directly. am: b1c857c824 am: 769bbce026

Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/2929772

Change-Id: I6d9e77b0889fad22a6006972a1ba90ecd87fba8f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Peter Lee 2024-02-01 23:08:23 +00:00 committed by Automerger Merge Worker
commit d3db89de5b
2 changed files with 2 additions and 0 deletions

View file

@ -328,6 +328,7 @@ neverallow { domain -vold -init } restorecon_prop:property_service set;
neverallow vold {
domain
-hal_health_storage_server
-hal_keymaster_server
-system_suspend_server
-hal_bootctl_server
-hwservicemanager

View file

@ -338,6 +338,7 @@ neverallow { domain -vold -init } restorecon_prop:property_service set;
neverallow vold {
domain
-hal_health_storage_server
-hal_keymaster_server
-system_suspend_server
-hal_bootctl_server
-hwservicemanager