xref: /aosp_15_r20/system/sepolicy/prebuilts/api/34.0/private/virtualizationservice.te (revision e4a36f4174b17bbab9dc043f4a65dc8d87377290)
1*e4a36f41SAndroid Build Coastguard Workertype virtualizationservice, domain, coredomain;
2*e4a36f41SAndroid Build Coastguard Workertype virtualizationservice_exec, system_file_type, exec_type, file_type;
3*e4a36f41SAndroid Build Coastguard Worker
4*e4a36f41SAndroid Build Coastguard Worker# The domain needs to be a 'mlstrustedsubject' to change the memlock rlimit of
5*e4a36f41SAndroid Build Coastguard Worker# the virtualizationmanager domain running at a more constrained MLS level.
6*e4a36f41SAndroid Build Coastguard Workertypeattribute virtualizationservice mlstrustedsubject;
7*e4a36f41SAndroid Build Coastguard Worker
8*e4a36f41SAndroid Build Coastguard Worker# When init runs a file labelled with virtualizationservice_exec, run it in the
9*e4a36f41SAndroid Build Coastguard Worker# virtualizationservice domain.
10*e4a36f41SAndroid Build Coastguard Workerinit_daemon_domain(virtualizationservice)
11*e4a36f41SAndroid Build Coastguard Worker
12*e4a36f41SAndroid Build Coastguard Worker# Let the virtualizationservice domain use Binder.
13*e4a36f41SAndroid Build Coastguard Workerbinder_use(virtualizationservice)
14*e4a36f41SAndroid Build Coastguard Worker
15*e4a36f41SAndroid Build Coastguard Worker# Let the virtualizationservice domain register the virtualization_service with ServiceManager.
16*e4a36f41SAndroid Build Coastguard Workeradd_service(virtualizationservice, virtualization_service)
17*e4a36f41SAndroid Build Coastguard Worker
18*e4a36f41SAndroid Build Coastguard Worker# Allow calling into the system server to find "permission_service".
19*e4a36f41SAndroid Build Coastguard Workerbinder_call(virtualizationservice, system_server)
20*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice permission_service:service_manager find;
21*e4a36f41SAndroid Build Coastguard Worker
22*e4a36f41SAndroid Build Coastguard Worker# Let virtualizationservice remove memlock rlimit of virtualizationmanager. This is necessary
23*e4a36f41SAndroid Build Coastguard Worker# to mlock VM memory and page tables.
24*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice self:capability sys_resource;
25*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice virtualizationmanager:process setrlimit;
26*e4a36f41SAndroid Build Coastguard Worker
27*e4a36f41SAndroid Build Coastguard Worker# Let virtualizationservice set the owner of a VM's temporary directory.
28*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice self:capability chown;
29*e4a36f41SAndroid Build Coastguard Worker
30*e4a36f41SAndroid Build Coastguard Worker# Let virtualizationservice create and delete temporary directories of VMs. To remove old
31*e4a36f41SAndroid Build Coastguard Worker# directories, it needs the permission to unlink the files created by virtualizationmanager.
32*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice virtualizationservice_data_file:dir create_dir_perms;
33*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice virtualizationservice_data_file:{ file sock_file } unlink;
34*e4a36f41SAndroid Build Coastguard Worker
35*e4a36f41SAndroid Build Coastguard Worker# Allow to use fd (e.g. /dev/pts/0) inherited from adbd so that we can redirect output from
36*e4a36f41SAndroid Build Coastguard Worker# crosvm to the console
37*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice adbd:fd use;
38*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice adbd:unix_stream_socket { read write };
39*e4a36f41SAndroid Build Coastguard Worker
40*e4a36f41SAndroid Build Coastguard Worker# Let virtualizationservice to accept vsock connection from the guest VMs to singleton services
41*e4a36f41SAndroid Build Coastguard Worker# such as the guest tombstone server.
42*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice self:vsock_socket { create_socket_perms_no_ioctl listen accept };
43*e4a36f41SAndroid Build Coastguard Worker
44*e4a36f41SAndroid Build Coastguard Worker# Allow virtualizationservice to read/write its own sysprop. Only the process can do so.
45*e4a36f41SAndroid Build Coastguard Workerset_prop(virtualizationservice, virtualizationservice_prop)
46*e4a36f41SAndroid Build Coastguard Worker
47*e4a36f41SAndroid Build Coastguard Worker# Allow writing stats to statsd
48*e4a36f41SAndroid Build Coastguard Workerunix_socket_send(virtualizationservice, statsdw, statsd)
49*e4a36f41SAndroid Build Coastguard Worker
50*e4a36f41SAndroid Build Coastguard Worker# Allow virtualization service to talk to tombstoned to push guest tombstones
51*e4a36f41SAndroid Build Coastguard Workerunix_socket_connect(virtualizationservice, tombstoned_crash, tombstoned)
52*e4a36f41SAndroid Build Coastguard Worker
53*e4a36f41SAndroid Build Coastguard Worker# Append to tombstone files passed as fds from tombstoned
54*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice tombstone_data_file:file { append getattr };
55*e4a36f41SAndroid Build Coastguard Workerallow virtualizationservice tombstoned:fd use;
56*e4a36f41SAndroid Build Coastguard Worker
57*e4a36f41SAndroid Build Coastguard Workerneverallow {
58*e4a36f41SAndroid Build Coastguard Worker  domain
59*e4a36f41SAndroid Build Coastguard Worker  -init
60*e4a36f41SAndroid Build Coastguard Worker  -virtualizationservice
61*e4a36f41SAndroid Build Coastguard Worker} virtualizationservice_prop:property_service set;
62*e4a36f41SAndroid Build Coastguard Worker
63*e4a36f41SAndroid Build Coastguard Workerneverallow {
64*e4a36f41SAndroid Build Coastguard Worker  domain
65*e4a36f41SAndroid Build Coastguard Worker  -init
66*e4a36f41SAndroid Build Coastguard Worker  -virtualizationmanager
67*e4a36f41SAndroid Build Coastguard Worker  -virtualizationservice
68*e4a36f41SAndroid Build Coastguard Worker} virtualizationservice_data_file:file { open create };
69*e4a36f41SAndroid Build Coastguard Worker
70*e4a36f41SAndroid Build Coastguard Workerneverallow virtualizationservice {
71*e4a36f41SAndroid Build Coastguard Worker  domain
72*e4a36f41SAndroid Build Coastguard Worker  -virtualizationmanager
73*e4a36f41SAndroid Build Coastguard Worker  -virtualizationservice
74*e4a36f41SAndroid Build Coastguard Worker}:process setrlimit;
75