platform_system_sepolicy/public/hal_rebootescrow.te
Steven Moreland 82f7900341 Make AIDL HAL client attribute an exclusive client.
Like HIDL HALs, if we have a service which is allowed to access
hal_<foo>_service, we want that service to have the attribute
hal_<foo>_client.

Unlike HIDL HALs, some AIDL services are allowed to get ahold of all
HALs, so these have to be exempted from this check.

Fixes: 168152053
Test: neverallows pass
Change-Id: I4bce6d9441c2921c3ea40f2b01fef4030c02a28a
2020-09-11 00:02:00 +00:00

6 lines
203 B
Text

# HwBinder IPC from client to server
binder_call(hal_rebootescrow_client, hal_rebootescrow_server)
hal_attribute_service(hal_rebootescrow, hal_rebootescrow_service)
binder_use(hal_rebootescrow_server)