platform_system_sepolicy/private/lmkd.te
Inseob Kim 85acf6ef70 Fix broken neverallow rules
neverallow rules with allowlist should look like:

    neverallow { domain -allow1 -allow2 } ...

Bug: 181744894
Test: m selinux_policy
Test: pcregrep -M -r "neverallow\s+{(\s*#.*\s*)*\s+-" .
Change-Id: Ibab72ccc1fbacb99b62fe127b4122e1ac22b938a
2021-03-10 10:44:22 +09:00

11 lines
250 B
Text

typeattribute lmkd coredomain;
init_daemon_domain(lmkd)
# Set sys.lmk.* properties.
set_prop(lmkd, system_lmk_prop)
# Set lmkd.* properties.
set_prop(lmkd, lmkd_prop)
neverallow { domain -init -lmkd -vendor_init } lmkd_prop:property_service set;