xref: /aosp_15_r20/system/sepolicy/private/microfuchsiad.te (revision e4a36f4174b17bbab9dc043f4a65dc8d87377290)
1is_flag_enabled(RELEASE_AVF_ENABLE_MICROFUCHSIA, `
2    type microfuchsiad, domain, coredomain;
3    type microfuchsiad_exec, system_file_type, exec_type, file_type;
4
5    # Host dynamic AIDL services
6    init_daemon_domain(microfuchsiad)
7    binder_use(microfuchsiad)
8    add_service(microfuchsiad, microfuchsia_service)
9
10    # Call back into system server
11    binder_call(microfuchsiad, system_server)
12
13    # Start a VM
14    virtualizationservice_use(microfuchsiad)
15
16    # Create pty devices
17    allow microfuchsiad devpts:chr_file { read write open getattr ioctl };
18')
19