gs-common: move sepolicy related to bootctrl hal aidl to gs-common

Bug: 265063384
Change-Id: Id9e1f4f7bc9fc5754f7ebadb97f7443f1117e961
Signed-off-by: Jason Chiu <jasoncschiu@google.com>
This commit is contained in:
Jason Chiu 2023-11-27 16:58:15 +08:00
parent c3102b06fc
commit 1473a277b8
5 changed files with 17 additions and 0 deletions

View file

@ -3,3 +3,4 @@ PRODUCT_PACKAGES += \
android.hardware.boot-service.default_recovery-pixel
PRODUCT_SOONG_NAMESPACES += device/google/gs-common/bootctrl/aidl
BOARD_VENDOR_SEPOLICY_DIRS += device/google/gs-common/bootctrl/sepolicy/aidl

View file

@ -0,0 +1,5 @@
# devinfo block device
type devinfo_block_device, dev_type;
# OTA
type sda_block_device, dev_type;

View file

@ -0,0 +1,2 @@
# sysfs
type sysfs_ota, sysfs_type, fs_type;

View file

@ -0,0 +1 @@
/vendor/bin/hw/android\.hardware\.boot-service\.default-pixel u:object_r:hal_bootctl_default_exec:s0

View file

@ -0,0 +1,8 @@
allow hal_bootctl_default devinfo_block_device:blk_file rw_file_perms;
allow hal_bootctl_default sda_block_device:blk_file rw_file_perms;
allow hal_bootctl_default sysfs_ota:file rw_file_perms;
allow hal_bootctl_default tee_device:chr_file rw_file_perms;
recovery_only(`
allow hal_bootctl_default rootfs:dir r_dir_perms;
')