Skip to content
Snippets Groups Projects
Commit ab318e30 authored by Paul Crowley's avatar Paul Crowley
Browse files

Allow access to the metadata partition for metadata encryption.

Bug: 63927601
Test: Enable metadata encryption in fstab on Taimen, check boot success.
Change-Id: Id425c47d48f413d6ea44ed170835a52d0af39f9f
parent 43ef5f21
No related branches found
No related tags found
No related merge requests found
allow e2fs devpts:chr_file { read write };
allow e2fs metadata_block_device:blk_file rw_file_perms;
typeattribute fsck coredomain; typeattribute fsck coredomain;
init_daemon_domain(fsck) init_daemon_domain(fsck)
allow fsck metadata_block_device:blk_file rw_file_perms;
...@@ -556,8 +556,14 @@ neverallow { ...@@ -556,8 +556,14 @@ neverallow {
# The metadata block device is set aside for device encryption and # The metadata block device is set aside for device encryption and
# verified boot metadata. It may be reset at will and should not # verified boot metadata. It may be reset at will and should not
# be used by other domains. # be used by other domains.
neverallow { domain -init -recovery -vold } metadata_block_device:blk_file neverallow {
{ append link rename write open read ioctl lock }; domain
-init
-recovery
-vold
-e2fs
-fsck
} metadata_block_device:blk_file { append link rename write open read ioctl lock };
# No domain other than recovery and update_engine can write to system partition(s). # No domain other than recovery and update_engine can write to system partition(s).
neverallow { domain -recovery -update_engine } system_block_device:blk_file { write append }; neverallow { domain -recovery -update_engine } system_block_device:blk_file { write append };
......
...@@ -44,7 +44,6 @@ allow fsck rootfs:dir r_dir_perms; ...@@ -44,7 +44,6 @@ allow fsck rootfs:dir r_dir_perms;
neverallow fsck { neverallow fsck {
boot_block_device boot_block_device
frp_block_device frp_block_device
metadata_block_device
recovery_block_device recovery_block_device
root_block_device root_block_device
swap_block_device swap_block_device
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment