xref: /aosp_15_r20/system/sepolicy/private/early_virtmgr.te (revision e4a36f4174b17bbab9dc043f4a65dc8d87377290)
1*e4a36f41SAndroid Build Coastguard Workeris_flag_enabled(RELEASE_AVF_ENABLE_EARLY_VM, `
2*e4a36f41SAndroid Build Coastguard Worker    # Domain for a child process that manages early VMs available before /data mount, on behalf of
3*e4a36f41SAndroid Build Coastguard Worker    # its parent.
4*e4a36f41SAndroid Build Coastguard Worker    type early_virtmgr, domain, coredomain;
5*e4a36f41SAndroid Build Coastguard Worker    type early_virtmgr_exec, system_file_type, exec_type, file_type;
6*e4a36f41SAndroid Build Coastguard Worker
7*e4a36f41SAndroid Build Coastguard Worker    use_bootstrap_libs(early_virtmgr)
8*e4a36f41SAndroid Build Coastguard Worker
9*e4a36f41SAndroid Build Coastguard Worker    # Let early_virtmgr create files and directories inside /mnt/vm/early.
10*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr vm_data_file:dir create_dir_perms;
11*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr vm_data_file:file create_file_perms;
12*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr vm_data_file:sock_file create_file_perms;
13*e4a36f41SAndroid Build Coastguard Worker
14*e4a36f41SAndroid Build Coastguard Worker    # Allow early_virtmgr to communicate use, read and write over the adb connection.
15*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr adbd:fd use;
16*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr adbd:unix_stream_socket { getattr read write };
17*e4a36f41SAndroid Build Coastguard Worker
18*e4a36f41SAndroid Build Coastguard Worker    # Allow writing VM logs to the shell console
19*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr devpts:chr_file { read write getattr ioctl };
20*e4a36f41SAndroid Build Coastguard Worker
21*e4a36f41SAndroid Build Coastguard Worker    # Let the early_virtmgr domain use Binder.
22*e4a36f41SAndroid Build Coastguard Worker    binder_use(early_virtmgr)
23*e4a36f41SAndroid Build Coastguard Worker
24*e4a36f41SAndroid Build Coastguard Worker    # When early_virtmgr execs a file with the crosvm_exec label, run it in the crosvm domain.
25*e4a36f41SAndroid Build Coastguard Worker    domain_auto_trans(early_virtmgr, crosvm_exec, crosvm)
26*e4a36f41SAndroid Build Coastguard Worker
27*e4a36f41SAndroid Build Coastguard Worker    # Let early_virtmgr kill crosvm.
28*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr crosvm:process sigkill;
29*e4a36f41SAndroid Build Coastguard Worker
30*e4a36f41SAndroid Build Coastguard Worker    # Allow early_virtmgr to read apex-info-list.xml and access the APEX files listed there.
31*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr apex_info_file:file r_file_perms;
32*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr apex_data_file:dir search;
33*e4a36f41SAndroid Build Coastguard Worker
34*e4a36f41SAndroid Build Coastguard Worker    # Ignore harmless denials on /proc/self/fd
35*e4a36f41SAndroid Build Coastguard Worker    dontaudit early_virtmgr self:dir write;
36*e4a36f41SAndroid Build Coastguard Worker
37*e4a36f41SAndroid Build Coastguard Worker    # Let early_virtmgr to accept vsock connection from the guest VMs
38*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr self:vsock_socket { create_socket_perms_no_ioctl listen accept };
39*e4a36f41SAndroid Build Coastguard Worker
40*e4a36f41SAndroid Build Coastguard Worker    # Allow early_virtmgr to inspect all hypervisor capabilities.
41*e4a36f41SAndroid Build Coastguard Worker    get_prop(early_virtmgr, hypervisor_prop)
42*e4a36f41SAndroid Build Coastguard Worker    get_prop(early_virtmgr, hypervisor_pvmfw_prop)
43*e4a36f41SAndroid Build Coastguard Worker    get_prop(early_virtmgr, hypervisor_restricted_prop)
44*e4a36f41SAndroid Build Coastguard Worker    get_prop(early_virtmgr, hypervisor_virtualizationmanager_prop)
45*e4a36f41SAndroid Build Coastguard Worker
46*e4a36f41SAndroid Build Coastguard Worker    # Allow early_virtmgr to read file system DT for VM reference DT and AVF debug policy
47*e4a36f41SAndroid Build Coastguard Worker    r_dir_file(early_virtmgr, proc_dt_avf)
48*e4a36f41SAndroid Build Coastguard Worker    r_dir_file(early_virtmgr, sysfs_dt_avf)
49*e4a36f41SAndroid Build Coastguard Worker
50*e4a36f41SAndroid Build Coastguard Worker    # early_virtmgr to be client of secretkeeper HAL. It ferries SecretManagement messages from pVM
51*e4a36f41SAndroid Build Coastguard Worker    # to HAL.
52*e4a36f41SAndroid Build Coastguard Worker    hal_client_domain(early_virtmgr, hal_secretkeeper);
53*e4a36f41SAndroid Build Coastguard Worker
54*e4a36f41SAndroid Build Coastguard Worker    # Allow reading files under /proc/[crosvm pid]/, for collecting CPU & memory usage inside VM.
55*e4a36f41SAndroid Build Coastguard Worker    r_dir_file(early_virtmgr, crosvm);
56*e4a36f41SAndroid Build Coastguard Worker
57*e4a36f41SAndroid Build Coastguard Worker    # Allow early_virtmgr to:
58*e4a36f41SAndroid Build Coastguard Worker    # 1) bind to a vsock port less than 1024, because early VMs use static CIDs less than 1024
59*e4a36f41SAndroid Build Coastguard Worker    # 2) call RLIMIT_MEMLOCK for itself
60*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr self:global_capability_class_set { net_bind_service ipc_lock sys_resource };
61*e4a36f41SAndroid Build Coastguard Worker
62*e4a36f41SAndroid Build Coastguard Worker    # early_virtmgr may print messages to kmsg_debug_device.
63*e4a36f41SAndroid Build Coastguard Worker    allow early_virtmgr kmsg_debug_device:chr_file w_file_perms;
64*e4a36f41SAndroid Build Coastguard Worker
65*e4a36f41SAndroid Build Coastguard Worker    ###
66*e4a36f41SAndroid Build Coastguard Worker    ### Neverallow rules
67*e4a36f41SAndroid Build Coastguard Worker    ###
68*e4a36f41SAndroid Build Coastguard Worker
69*e4a36f41SAndroid Build Coastguard Worker    # Only crosvm and early_virtmgr can access vm_data_file
70*e4a36f41SAndroid Build Coastguard Worker    neverallow { domain -crosvm -early_virtmgr -init } vm_data_file:dir no_w_dir_perms;
71*e4a36f41SAndroid Build Coastguard Worker    neverallow { domain -crosvm -early_virtmgr } vm_data_file:file no_rw_file_perms;
72*e4a36f41SAndroid Build Coastguard Worker
73*e4a36f41SAndroid Build Coastguard Worker    # No other domains can accept vsock connection from the guest VMs
74*e4a36f41SAndroid Build Coastguard Worker    neverallow { domain -early_virtmgr } early_virtmgr:vsock_socket { accept bind create connect listen };
75*e4a36f41SAndroid Build Coastguard Worker')
76