Inseob Kim 3a3a2ec43d Start tracking vendor seapp coredomain violations (2)
As part of Treble, enforce that vendor's seapp_contexts can't label apps
using coredomains. Apps installed to system/system_ext/product should be
labeled with platform side sepolicy.

This change marks violating domains that need to be fixed.

Bug: 296512192
Test: build and see build log
Change-Id: Iba8dbfe1260b481b2981e62d740552bf84c8004f
2023-08-21 20:56:03 +09:00

13 lines
504 B
Plaintext

type brownout_detection_app, domain, coredomain;
# TODO(b/296512192): move brownout_detection_app out of vendor sepolicy
typeattribute brownout_detection_app vendor_seapp_assigns_coredomain_violators;
userdebug_or_eng(`
app_domain(brownout_detection_app)
net_domain(brownout_detection_app)
allow brownout_detection_app app_api_service:service_manager find;
allow brownout_detection_app system_api_service:service_manager find;
get_prop(brownout_detection_app, vendor_brownout_reason_prop)
')