blob: 5421dd59c260f5e77f6815809da7299d9455b304 [file] [log] [blame]
Inseob Kim75806ef2024-03-27 17:18:41 +09001# Do not allow domains to transition to vendor toolbox
2# or read, execute the vendor_toolbox file.
3full_treble_only(`
4 # Do not allow non-vendor domains to transition
5 # to vendor toolbox except for the allowlisted domains.
6 neverallow {
7 coredomain
8 -init
9 -modprobe
Paul Lawrence840b6072025-01-28 07:41:05 -080010 userdebug_or_eng(`-overlay_remounter')
Inseob Kim75806ef2024-03-27 17:18:41 +090011 } vendor_toolbox_exec:file { entrypoint execute execute_no_trans };
12')