blob: c36875ccb9f754f9a34518fedc9bdc9d2a50bbe8 [file] [log] [blame]
Victor Hsiehb415c732021-12-14 11:06:23 -08001# Declare ART properties for CompOS
2system_public_prop(dalvik_config_prop)
3system_restricted_prop(device_config_runtime_native_prop)
4
Inseob Kim5ee61a72021-09-17 19:31:45 +09005# Don't audit legacy ctl. property handling. We only want the newer permission check to appear
6# in the audit log
7dontaudit domain {
8 ctl_console_prop
9 ctl_default_prop
10 ctl_fuse_prop
11}:property_service set;
12
Inseob Kime1389972021-07-19 07:48:34 +000013###
14### Neverallow rules
15###
16
17neverallow {
18 domain
19 -init
20 -microdroid_manager
21} vmsecret_keymint_prop:property_service set;
22
23neverallow {
24 domain
25 -init
26 -microdroid_manager
27 -hal_keymint_server
28} vmsecret_keymint_prop:file no_rw_file_perms;
Jiyong Park27bb6c62021-09-06 15:39:31 +090029
30# microdroid_manager_roothash_prop can only be set by microdroid_manager
31# and read by apkdmverity
32neverallow {
33 domain
34 -init
35 -microdroid_manager
36} microdroid_manager_roothash_prop:property_service set;
37
38neverallow {
39 domain
40 -init
41 -microdroid_manager
42 -apkdmverity
43} microdroid_manager_roothash_prop:file no_rw_file_perms;