platform_system_sepolicy/private/wait_for_keymaster.te
Satya Tangirala a999004528 Keystore 2.0: sepolicy changes for vold to use keystore2
Vold needs to be able to search for keystore2 and keystore2 maintenance
services, and call methods provided by those services.

Bug: 181910578
Change-Id: I6e336c3bfaabe158b850dc175b6c9a942dd717be
2021-04-07 02:14:33 -07:00

15 lines
563 B
Text

# wait_for_keymaster service
type wait_for_keymaster, domain, coredomain;
type wait_for_keymaster_exec, system_file_type, exec_type, file_type;
init_daemon_domain(wait_for_keymaster)
hal_client_domain(wait_for_keymaster, hal_keymaster)
allow wait_for_keymaster kmsg_device:chr_file w_file_perms;
# wait_for_keymaster needs to find keystore and call methods with the returned
# binder reference.
allow wait_for_keymaster servicemanager:binder call;
allow wait_for_keymaster keystore_service:service_manager find;
allow wait_for_keymaster keystore:binder call;