platform_system_sepolicy/private/credstore.te
Tri Vo 99f88846ff credstore: Add missing permissions
Bug: 261214100
Test: CtsIdentityTestCases
Change-Id: I6a70ed279f65d1cb4bfa0d53fa0e0f25d00d44b5
2023-01-17 16:07:19 -08:00

17 lines
635 B
Text

typeattribute credstore coredomain;
init_daemon_domain(credstore)
# talk to Identity Credential
hal_client_domain(credstore, hal_identity)
# talk to keymint, specifically for IRemotelyProvisionedComponent/default
hal_client_domain(credstore, hal_keymint)
# credstore needs to get keys from the remotely provisioned pool
allow credstore remotelyprovisionedkeypool_service:service_manager find;
allow credstore keystore:keystore2 get_attestation_key;
# credstore needs to get keys from the RKPD
get_prop(credstore, device_config_remote_key_provisioning_native_prop)
allow credstore remote_provisioning_service:service_manager find;