gatekeeperd.te 770 Bytes
Newer Older
1 2 3 4 5 6 7 8
type gatekeeperd, domain;
type gatekeeperd_exec, exec_type, file_type;

# gatekeeperd
init_daemon_domain(gatekeeperd)
binder_use(gatekeeperd)
allow gatekeeperd tee_device:chr_file rw_file_perms;

9
# need to find KeyStore and add self
10 11
allow gatekeeperd gatekeeper_service:service_manager { add find };

12
# Need to add auth tokens to KeyStore
13
use_keystore(gatekeeperd)
14 15
allow gatekeeperd keystore:keystore_key { add_auth };

16 17 18 19
# For permissions checking
allow gatekeeperd system_server:binder call;
allow gatekeeperd permission_service:service_manager find;

Andres Morales's avatar
Andres Morales committed
20
# for SID file access
21 22
allow gatekeeperd gatekeeper_data_file:dir rw_dir_perms;
allow gatekeeperd gatekeeper_data_file:file create_file_perms;
Andres Morales's avatar
Andres Morales committed
23

24
neverallow { domain -gatekeeperd } gatekeeper_service:service_manager add;