As part of Treble, enforce that vendor's seapp_contexts can't label apps using coredomains. Apps installed to system/system_ext/product should be labeled with platform side sepolicy. This change marks violating domains that need to be fixed. Bug: 296512192 Test: build and see build log Change-Id: Iba8dbfe1260b481b2981e62d740552bf84c8004f
13 lines
504 B
Plaintext
13 lines
504 B
Plaintext
type brownout_detection_app, domain, coredomain;
|
|
|
|
# TODO(b/296512192): move brownout_detection_app out of vendor sepolicy
|
|
typeattribute brownout_detection_app vendor_seapp_assigns_coredomain_violators;
|
|
|
|
userdebug_or_eng(`
|
|
app_domain(brownout_detection_app)
|
|
net_domain(brownout_detection_app)
|
|
allow brownout_detection_app app_api_service:service_manager find;
|
|
allow brownout_detection_app system_api_service:service_manager find;
|
|
get_prop(brownout_detection_app, vendor_brownout_reason_prop)
|
|
')
|