Pablo Gamito | 9a90b92 | 2024-08-26 14:16:59 +0000 | [diff] [blame] | 1 | type adaptive_auth_service, system_server_service, service_manager_type; |
| 2 | type ambient_context_service, app_api_service, system_server_service, service_manager_type; |
| 3 | type attention_service, system_server_service, service_manager_type; |
| 4 | type bg_install_control_service, system_api_service, system_server_service, service_manager_type; |
| 5 | type compos_service, service_manager_type; |
| 6 | type communal_service, app_api_service, system_server_service, service_manager_type; |
| 7 | type dynamic_system_service, system_api_service, system_server_service, service_manager_type; |
| 8 | type feature_flags_service, app_api_service, system_server_service, service_manager_type; |
| 9 | type gsi_service, service_manager_type; |
| 10 | type incidentcompanion_service, app_api_service, system_api_service, system_server_service, service_manager_type; |
| 11 | type logcat_service, system_server_service, service_manager_type; |
| 12 | type logd_service, service_manager_type; |
| 13 | type mediatuner_service, app_api_service, service_manager_type; |
sandeepbandaru | 600e395 | 2024-02-19 09:40:54 +0000 | [diff] [blame] | 14 | type on_device_intelligence_service, app_api_service, system_server_service, service_manager_type, isolated_compute_allowed_service; |
Pablo Gamito | 9a90b92 | 2024-08-26 14:16:59 +0000 | [diff] [blame] | 15 | type profcollectd_service, service_manager_type; |
Pablo Gamito | 521d1be | 2024-08-27 09:13:19 +0000 | [diff] [blame^] | 16 | type protolog_configuration_service, app_api_service, system_api_service, system_server_service, service_manager_type; |
Pablo Gamito | 9a90b92 | 2024-08-26 14:16:59 +0000 | [diff] [blame] | 17 | type resolver_service, system_server_service, service_manager_type; |
| 18 | type rkpd_registrar_service, service_manager_type; |
| 19 | type rkpd_refresh_service, service_manager_type; |
| 20 | type safety_center_service, app_api_service, system_api_service, system_server_service, service_manager_type; |
| 21 | type stats_service, service_manager_type; |
| 22 | type statsbootstrap_service, system_server_service, service_manager_type; |
| 23 | type statscompanion_service, system_server_service, service_manager_type; |
| 24 | type statsmanager_service, system_api_service, system_server_service, service_manager_type; |
Roman Kalukiewicz | d416f1b | 2024-08-06 00:18:32 +0000 | [diff] [blame] | 25 | |
| 26 | is_flag_enabled(RELEASE_SUPERVISION_SERVICE, ` |
| 27 | type supervision_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; |
| 28 | ') |
Collin Fijalkovich | 6f4cfe8 | 2020-12-11 14:51:32 -0800 | [diff] [blame] | 29 | type tracingproxy_service, system_server_service, service_manager_type; |
Billy Lau | 8bb3ed7 | 2022-01-19 13:44:25 -0800 | [diff] [blame] | 30 | type transparency_service, system_server_service, service_manager_type; |
Inseob Kim | 094e8e8 | 2023-11-17 18:03:46 +0900 | [diff] [blame] | 31 | |
| 32 | is_flag_enabled(RELEASE_AVF_ENABLE_DEVICE_ASSIGNMENT, ` |
| 33 | type vfio_handler_service, service_manager_type; |
| 34 | ') |
Alan Stokes | 38131e7 | 2024-02-20 11:06:37 +0000 | [diff] [blame] | 35 | is_flag_enabled(RELEASE_AVF_ENABLE_LLPVM_CHANGES, ` |
| 36 | type virtualization_maintenance_service, service_manager_type; |
| 37 | ') |
Seungjae Yoo | f60a1e0 | 2024-05-20 14:15:22 +0900 | [diff] [blame] | 38 | is_flag_enabled(RELEASE_AVF_ENABLE_NETWORK, ` |
Seungjae Yoo | c9df293 | 2024-06-17 00:38:19 +0000 | [diff] [blame] | 39 | type vm_tethering_service, system_server_service, service_manager_type; |
| 40 | type vmnic_service, service_manager_type; |
Seungjae Yoo | f60a1e0 | 2024-05-20 14:15:22 +0900 | [diff] [blame] | 41 | ') |
Aidan Wolter | 56d74cd | 2024-08-20 19:19:37 +0000 | [diff] [blame] | 42 | is_flag_enabled(RELEASE_AVF_ENABLE_MICROFUCHSIA, ` |
| 43 | type microfuchsia_service, service_manager_type; |
| 44 | ') |
Inseob Kim | 094e8e8 | 2023-11-17 18:03:46 +0900 | [diff] [blame] | 45 | |
Steven Moreland | 92f72cd | 2019-08-01 14:05:05 -0700 | [diff] [blame] | 46 | type uce_service, service_manager_type; |
Tom Chan | 4409ea4 | 2023-12-18 21:57:49 +0000 | [diff] [blame] | 47 | type wearable_sensing_service, app_api_service, system_server_service, service_manager_type; |
Inseob Kim | 75806ef | 2024-03-27 17:18:41 +0900 | [diff] [blame] | 48 | |
| 49 | ### |
| 50 | ### Neverallow rules |
| 51 | ### |
| 52 | |
| 53 | # servicemanager handles registering or looking up named services. |
| 54 | # It does not make sense to register or lookup something which is not a service. |
| 55 | # Trigger a compile error if this occurs. |
| 56 | neverallow domain ~{ service_manager_type vndservice_manager_type }:service_manager { add find }; |