Merge "Limit special file permissions to the keymint server domain" am: 2a7198811a

Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/2283654

Change-Id: I13b875ddf03403e353ed6839ddcececa2eb8150a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Seth Moore 2022-11-03 19:12:39 +00:00 committed by Automerger Merge Worker
commit eeeebd2ebe

View file

@ -4,5 +4,5 @@ hal_attribute_service(hal_keymint, hal_keymint_service)
hal_attribute_service(hal_keymint, hal_remotelyprovisionedcomponent_service) hal_attribute_service(hal_keymint, hal_remotelyprovisionedcomponent_service)
binder_call(hal_keymint_server, servicemanager) binder_call(hal_keymint_server, servicemanager)
allow hal_keymint tee_device:chr_file rw_file_perms; allow hal_keymint_server tee_device:chr_file rw_file_perms;
allow hal_keymint ion_device:chr_file r_file_perms; allow hal_keymint_server ion_device:chr_file r_file_perms;