platform_system_sepolicy/public/hal_rebootescrow.te
Kenny Root 76ea325a3d Support Resume on Reboot
When an OTA is downloaded, the RecoverySystem can be triggered to store
the user's lock screen knowledge factor in a secure way using the
IRebootEscrow HAL. This will allow the credential encrypted (CE)
storage, keymaster credentials, and possibly others to be unlocked when
the device reboots after an OTA.

Bug: 63928581
Test: make
Test: boot emulator with default implementation
Test: boot Pixel 4 with default implementation
Change-Id: I1f02e7a502478715fd642049da01eb0c01d112f6
2019-12-09 14:25:04 -08:00

7 lines
277 B
Text

# HwBinder IPC from client to server
binder_call(hal_rebootescrow_client, hal_rebootescrow_server)
add_service(hal_rebootescrow_server, hal_rebootescrow_service)
binder_use(hal_rebootescrow_server)
allow hal_rebootescrow_client hal_rebootescrow_service:service_manager find;