blob: 799ac3cb5d07b7f05798f4756b848d6b12e38d62 [file] [log] [blame]
Inseob Kim5ee61a72021-09-17 19:31:45 +09001# Don't audit legacy ctl. property handling. We only want the newer permission check to appear
2# in the audit log
3dontaudit domain {
4 ctl_console_prop
5 ctl_default_prop
6 ctl_fuse_prop
7}:property_service set;
8
Inseob Kime1389972021-07-19 07:48:34 +00009###
10### Neverallow rules
11###
12
13neverallow {
14 domain
15 -init
16 -microdroid_manager
17} vmsecret_keymint_prop:property_service set;
18
19neverallow {
20 domain
21 -init
22 -microdroid_manager
23 -hal_keymint_server
24} vmsecret_keymint_prop:file no_rw_file_perms;
Jiyong Park27bb6c62021-09-06 15:39:31 +090025
26# microdroid_manager_roothash_prop can only be set by microdroid_manager
27# and read by apkdmverity
28neverallow {
29 domain
30 -init
31 -microdroid_manager
32} microdroid_manager_roothash_prop:property_service set;
33
34neverallow {
35 domain
36 -init
37 -microdroid_manager
38 -apkdmverity
39} microdroid_manager_roothash_prop:file no_rw_file_perms;