blob: a9cae31d66461b71f04f1a8bc2f02dda2c15a538 [file] [log] [blame]
Armelle Laineacfeaa62025-02-27 22:17:51 -08001type hal_widevine_system, domain, coredomain;
2hal_server_domain(hal_widevine_system, hal_drm)
3
4type hal_widevine_system_exec, exec_type, system_file_type, file_type;
5init_daemon_domain(hal_widevine_system)
6
7allow hal_widevine_system self:vsock_socket { create_socket_perms_no_ioctl };
Armelle Laine267e4b22025-03-16 16:34:23 +00008
9get_prop(hal_widevine_system, drm_config_prop)
10get_prop(hal_widevine_system, trusty_widevine_vm_sys_prop)
Armelle Laine967f7182025-03-17 10:28:50 +000011
12allow hal_widevine_system mediadrm_system_data_file:dir { create search add_name rw_dir_perms };
13allow hal_widevine_system mediadrm_system_data_file:file { getattr create open read write };
14