Skip to content
Snippets Groups Projects
Commit 186c82ff authored by Andres Morales's avatar Andres Morales Committed by Gerrit Code Review
Browse files

Merge "Allow gatekeeperd to check Android permissions"

parents 03a6f64f 13abb170
No related branches found
No related tags found
No related merge requests found
...@@ -7,9 +7,15 @@ binder_use(gatekeeperd) ...@@ -7,9 +7,15 @@ binder_use(gatekeeperd)
binder_service(gatekeeperd) binder_service(gatekeeperd)
allow gatekeeperd tee_device:chr_file rw_file_perms; allow gatekeeperd tee_device:chr_file rw_file_perms;
# need to find KeyStore and add self
allow gatekeeperd gatekeeper_service:service_manager { add find }; allow gatekeeperd gatekeeper_service:service_manager { add find };
# Need to add auth tokens to KeyStore
allow gatekeeperd keystore:keystore_key { add_auth }; allow gatekeeperd keystore:keystore_key { add_auth };
# For permissions checking
allow gatekeeperd system_server:binder call;
allow gatekeeperd permission_service:service_manager find;
neverallow { domain -gatekeeperd -system_server } gatekeeper_service:service_manager find; neverallow { domain -gatekeeperd -system_server } gatekeeper_service:service_manager find;
neverallow { domain -gatekeeperd } gatekeeper_service:service_manager add; neverallow { domain -gatekeeperd } gatekeeper_service:service_manager add;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment