Merge "vold.te: stop allowing use of keymaster HAL directly"
diff --git a/public/vold.te b/public/vold.te
index 8927482..b0fb6d0 100644
--- a/public/vold.te
+++ b/public/vold.te
@@ -213,9 +213,6 @@
binder_call(vold, system_server)
allow vold permission_service:service_manager find;
-# talk to keymaster
-hal_client_domain(vold, hal_keymaster)
-
# talk to health storage HAL
hal_client_domain(vold, hal_health_storage)
@@ -330,7 +327,6 @@
neverallow vold {
domain
-hal_health_storage_server
- -hal_keymaster_server
-system_suspend_server
-hal_bootctl_server
-hwservicemanager