Lines Matching refs:gsid

1 # gsid - Manager for GSI Installation
3 type gsid, domain;
5 typeattribute gsid coredomain;
7 init_daemon_domain(gsid)
9 binder_use(gsid)
10 binder_service(gsid)
11 add_service(gsid, gsi_service)
12 set_prop(gsid, gsid_prop)
15 allow gsid dm_device:chr_file rw_file_perms;
16 allow gsid dm_device:blk_file rw_file_perms;
17 allow gsid self:global_capability_class_set sys_admin;
18 dontaudit gsid self:global_capability_class_set dac_override;
23 allow gsid sysfs_dm:dir r_dir_perms;
28 allow gsid proc_cmdline:file r_file_perms;
29 allow gsid sysfs_dt_firmware_android:dir r_dir_perms;
30 allow gsid sysfs_dt_firmware_android:file r_file_perms;
33 allow gsid block_device:dir r_dir_perms;
36 allowxperm gsid { userdata_block_device sdcard_block_device }:blk_file ioctl {
41 # When installing images to an sdcard, gsid needs to be able to stat() the
42 # block device. gsid also calls realpath() to remove symlinks.
43 allow gsid mnt_media_rw_file:dir r_dir_perms;
45 # When installing images to an sdcard, gsid must bypass sdcardfs and install
47 allow gsid vfat:dir rw_dir_perms;
48 allow gsid vfat:file create_file_perms;
49 allow gsid sdcard_block_device:blk_file r_file_perms;
52 allow gsid self:global_capability_class_set sys_rawio;
55 allow gsid adbd:fd use;
57 allow gsid adbd:unix_stream_socket rw_socket_perms;
59 neverallow { domain -gsid -init } gsid_prop:property_service set;
61 # gsid needs to store images on /data, but cannot use file I/O. If it did, the
73 allow gsid userdata_block_device:blk_file r_file_perms;
75 # gsid uses /metadata/gsi to communicate GSI boot information to first-stage
79 # gsid uses /metadata/gsi to store three files:
86 allow gsid metadata_file:dir search;
87 allow gsid gsi_metadata_file:dir rw_dir_perms;
88 allow gsid gsi_metadata_file:file create_file_perms;
90 allow gsid gsi_data_file:dir rw_dir_perms;
91 allow gsid gsi_data_file:file create_file_perms;
92 allowxperm gsid gsi_data_file:file ioctl FS_IOC_FIEMAP;
97 -gsid
105 -gsid
113 -gsid
120 -gsid
126 -gsid
131 -gsid