39f497013c
Remove some allow rules for odsign, since it no longer directly modifies CompOs files. Instead allow it to run compos_verify_key in its own domain. Grant compos_verify_key what it needs to access the CompOs files and start up the VM. Currently we directly connect to the CompOs VM; that will change once some in-flight CLs have landed. As part of this I moved the virtualizationservice_use macro to te_macros so I can use it here. I also expanded it to include additional grants needed by any VM client that were previously done for individual domains (and then deleted those rules as now redundant). I also removed the grant of VM access to all apps; instead we allow it for untrusted apps, on userdebug or eng builds only. (Temporarily at least.) Bug: 193603140 Test: Manual - odsign successfully runs the VM at boot when needed. Change-Id: I62f9ad8c7ea2fb9ef2d468331e26822d08e3c828 |
||
---|---|---|
.. | ||
Android.bp | ||
apex.test-file_contexts | ||
com.android.adbd-file_contexts | ||
com.android.appsearch-file_contexts | ||
com.android.art-file_contexts | ||
com.android.art.debug-file_contexts | ||
com.android.bluetooth.updatable-file_contexts | ||
com.android.bootanimation-file_contexts | ||
com.android.cellbroadcast-file_contexts | ||
com.android.compos-file_contexts | ||
com.android.conscrypt-file_contexts | ||
com.android.cronet-file_contexts | ||
com.android.extservices-file_contexts | ||
com.android.geotz-file_contexts | ||
com.android.gki-file_contexts | ||
com.android.i18n-file_contexts | ||
com.android.ipsec-file_contexts | ||
com.android.media-file_contexts | ||
com.android.media.swcodec-file_contexts | ||
com.android.mediaprovider-file_contexts | ||
com.android.neuralnetworks-file_contexts | ||
com.android.os.statsd-file_contexts | ||
com.android.permission-file_contexts | ||
com.android.resolv-file_contexts | ||
com.android.runtime-file_contexts | ||
com.android.scheduling-file_contexts | ||
com.android.sdkext-file_contexts | ||
com.android.telephony-file_contexts | ||
com.android.tethering-file_contexts | ||
com.android.tzdata-file_contexts | ||
com.android.uwb-file_contexts | ||
com.android.virt-file_contexts | ||
com.android.vndk-file_contexts | ||
com.android.wifi-file_contexts |