blob: 58942b61acdbe4f2bce60532f6d26d07d59f0ad3 [file] [log] [blame]
Inseob Kime1389972021-07-19 07:48:34 +00001###
2### Neverallow rules
3###
4
5neverallow {
6 domain
7 -init
8 -microdroid_manager
9} vmsecret_keymint_prop:property_service set;
10
11neverallow {
12 domain
13 -init
14 -microdroid_manager
15 -hal_keymint_server
16} vmsecret_keymint_prop:file no_rw_file_perms;
Jiyong Park27bb6c62021-09-06 15:39:31 +090017
18# microdroid_manager_roothash_prop can only be set by microdroid_manager
19# and read by apkdmverity
20neverallow {
21 domain
22 -init
23 -microdroid_manager
24} microdroid_manager_roothash_prop:property_service set;
25
26neverallow {
27 domain
28 -init
29 -microdroid_manager
30 -apkdmverity
31} microdroid_manager_roothash_prop:file no_rw_file_perms;