platform_system_sepolicy/private/wait_for_keymaster.te
Thiébaud Weksteen 97ba504c06 Add transfer permission to wait_for_keymaster
Bug: 188809569
Test: m sepolicy
Change-Id: I79ead2fdf258f824ef9b0bf13c8179a6b819ccd7
Merged-In: I79ead2fdf258f824ef9b0bf13c8179a6b819ccd7
(cherry picked from commit eb353bc228)
2021-05-21 15:41:08 +02:00

15 lines
536 B
Text

# wait_for_keymaster service
type wait_for_keymaster, domain, coredomain;
type wait_for_keymaster_exec, system_file_type, exec_type, file_type;
init_daemon_domain(wait_for_keymaster)
hal_client_domain(wait_for_keymaster, hal_keymaster)
allow wait_for_keymaster kmsg_device:chr_file w_file_perms;
# wait_for_keymaster needs to find keystore and call methods with the returned
# binder reference.
binder_use(wait_for_keymaster)
allow wait_for_keymaster keystore_service:service_manager find;
binder_call(wait_for_keymaster, keystore)