85acf6ef70
neverallow rules with allowlist should look like: neverallow { domain -allow1 -allow2 } ... Bug: 181744894 Test: m selinux_policy Test: pcregrep -M -r "neverallow\s+{(\s*#.*\s*)*\s+-" . Change-Id: Ibab72ccc1fbacb99b62fe127b4122e1ac22b938a
11 lines
250 B
Text
11 lines
250 B
Text
typeattribute lmkd coredomain;
|
|
|
|
init_daemon_domain(lmkd)
|
|
|
|
# Set sys.lmk.* properties.
|
|
set_prop(lmkd, system_lmk_prop)
|
|
|
|
# Set lmkd.* properties.
|
|
set_prop(lmkd, lmkd_prop)
|
|
|
|
neverallow { domain -init -lmkd -vendor_init } lmkd_prop:property_service set;
|