1*e4a36f41SAndroid Build Coastguard Workeris_flag_enabled(RELEASE_AVF_ENABLE_EARLY_VM, ` 2*e4a36f41SAndroid Build Coastguard Worker # Domain for a child process that manages early VMs available before /data mount, on behalf of 3*e4a36f41SAndroid Build Coastguard Worker # its parent. 4*e4a36f41SAndroid Build Coastguard Worker type early_virtmgr, domain, coredomain; 5*e4a36f41SAndroid Build Coastguard Worker type early_virtmgr_exec, system_file_type, exec_type, file_type; 6*e4a36f41SAndroid Build Coastguard Worker 7*e4a36f41SAndroid Build Coastguard Worker use_bootstrap_libs(early_virtmgr) 8*e4a36f41SAndroid Build Coastguard Worker 9*e4a36f41SAndroid Build Coastguard Worker # Let early_virtmgr create files and directories inside /mnt/vm/early. 10*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr vm_data_file:dir create_dir_perms; 11*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr vm_data_file:file create_file_perms; 12*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr vm_data_file:sock_file create_file_perms; 13*e4a36f41SAndroid Build Coastguard Worker 14*e4a36f41SAndroid Build Coastguard Worker # Allow early_virtmgr to communicate use, read and write over the adb connection. 15*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr adbd:fd use; 16*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr adbd:unix_stream_socket { getattr read write }; 17*e4a36f41SAndroid Build Coastguard Worker 18*e4a36f41SAndroid Build Coastguard Worker # Allow writing VM logs to the shell console 19*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr devpts:chr_file { read write getattr ioctl }; 20*e4a36f41SAndroid Build Coastguard Worker 21*e4a36f41SAndroid Build Coastguard Worker # Let the early_virtmgr domain use Binder. 22*e4a36f41SAndroid Build Coastguard Worker binder_use(early_virtmgr) 23*e4a36f41SAndroid Build Coastguard Worker 24*e4a36f41SAndroid Build Coastguard Worker # When early_virtmgr execs a file with the crosvm_exec label, run it in the crosvm domain. 25*e4a36f41SAndroid Build Coastguard Worker domain_auto_trans(early_virtmgr, crosvm_exec, crosvm) 26*e4a36f41SAndroid Build Coastguard Worker 27*e4a36f41SAndroid Build Coastguard Worker # Let early_virtmgr kill crosvm. 28*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr crosvm:process sigkill; 29*e4a36f41SAndroid Build Coastguard Worker 30*e4a36f41SAndroid Build Coastguard Worker # Allow early_virtmgr to read apex-info-list.xml and access the APEX files listed there. 31*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr apex_info_file:file r_file_perms; 32*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr apex_data_file:dir search; 33*e4a36f41SAndroid Build Coastguard Worker 34*e4a36f41SAndroid Build Coastguard Worker # Ignore harmless denials on /proc/self/fd 35*e4a36f41SAndroid Build Coastguard Worker dontaudit early_virtmgr self:dir write; 36*e4a36f41SAndroid Build Coastguard Worker 37*e4a36f41SAndroid Build Coastguard Worker # Let early_virtmgr to accept vsock connection from the guest VMs 38*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr self:vsock_socket { create_socket_perms_no_ioctl listen accept }; 39*e4a36f41SAndroid Build Coastguard Worker 40*e4a36f41SAndroid Build Coastguard Worker # Allow early_virtmgr to inspect all hypervisor capabilities. 41*e4a36f41SAndroid Build Coastguard Worker get_prop(early_virtmgr, hypervisor_prop) 42*e4a36f41SAndroid Build Coastguard Worker get_prop(early_virtmgr, hypervisor_pvmfw_prop) 43*e4a36f41SAndroid Build Coastguard Worker get_prop(early_virtmgr, hypervisor_restricted_prop) 44*e4a36f41SAndroid Build Coastguard Worker get_prop(early_virtmgr, hypervisor_virtualizationmanager_prop) 45*e4a36f41SAndroid Build Coastguard Worker 46*e4a36f41SAndroid Build Coastguard Worker # Allow early_virtmgr to read file system DT for VM reference DT and AVF debug policy 47*e4a36f41SAndroid Build Coastguard Worker r_dir_file(early_virtmgr, proc_dt_avf) 48*e4a36f41SAndroid Build Coastguard Worker r_dir_file(early_virtmgr, sysfs_dt_avf) 49*e4a36f41SAndroid Build Coastguard Worker 50*e4a36f41SAndroid Build Coastguard Worker # early_virtmgr to be client of secretkeeper HAL. It ferries SecretManagement messages from pVM 51*e4a36f41SAndroid Build Coastguard Worker # to HAL. 52*e4a36f41SAndroid Build Coastguard Worker hal_client_domain(early_virtmgr, hal_secretkeeper); 53*e4a36f41SAndroid Build Coastguard Worker 54*e4a36f41SAndroid Build Coastguard Worker # Allow reading files under /proc/[crosvm pid]/, for collecting CPU & memory usage inside VM. 55*e4a36f41SAndroid Build Coastguard Worker r_dir_file(early_virtmgr, crosvm); 56*e4a36f41SAndroid Build Coastguard Worker 57*e4a36f41SAndroid Build Coastguard Worker # Allow early_virtmgr to: 58*e4a36f41SAndroid Build Coastguard Worker # 1) bind to a vsock port less than 1024, because early VMs use static CIDs less than 1024 59*e4a36f41SAndroid Build Coastguard Worker # 2) call RLIMIT_MEMLOCK for itself 60*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr self:global_capability_class_set { net_bind_service ipc_lock sys_resource }; 61*e4a36f41SAndroid Build Coastguard Worker 62*e4a36f41SAndroid Build Coastguard Worker # early_virtmgr may print messages to kmsg_debug_device. 63*e4a36f41SAndroid Build Coastguard Worker allow early_virtmgr kmsg_debug_device:chr_file w_file_perms; 64*e4a36f41SAndroid Build Coastguard Worker 65*e4a36f41SAndroid Build Coastguard Worker ### 66*e4a36f41SAndroid Build Coastguard Worker ### Neverallow rules 67*e4a36f41SAndroid Build Coastguard Worker ### 68*e4a36f41SAndroid Build Coastguard Worker 69*e4a36f41SAndroid Build Coastguard Worker # Only crosvm and early_virtmgr can access vm_data_file 70*e4a36f41SAndroid Build Coastguard Worker neverallow { domain -crosvm -early_virtmgr -init } vm_data_file:dir no_w_dir_perms; 71*e4a36f41SAndroid Build Coastguard Worker neverallow { domain -crosvm -early_virtmgr } vm_data_file:file no_rw_file_perms; 72*e4a36f41SAndroid Build Coastguard Worker 73*e4a36f41SAndroid Build Coastguard Worker # No other domains can accept vsock connection from the guest VMs 74*e4a36f41SAndroid Build Coastguard Worker neverallow { domain -early_virtmgr } early_virtmgr:vsock_socket { accept bind create connect listen }; 75*e4a36f41SAndroid Build Coastguard Worker') 76