1# volume manager
2type vold, domain;
3type vold_exec, exec_type, file_type, system_file_type;
4
5# Read already opened /cache files.
6allow vold cache_file:dir r_dir_perms;
7allow vold cache_file:file { getattr read };
8allow vold cache_file:lnk_file r_file_perms;
9
10r_dir_file(vold, { sysfs_type -sysfs_batteryinfo })
11# XXX Label sysfs files with a specific type?
12allow vold {
13  sysfs # writing to /sys/*/uevent during coldboot.
14  sysfs_devices_block
15  sysfs_dm
16  sysfs_loop # writing to /sys/block/loop*/uevent during coldboot.
17  sysfs_usb
18  sysfs_zram_uevent
19  sysfs_fs_f2fs
20}:file w_file_perms;
21
22r_dir_file(vold, rootfs)
23r_dir_file(vold, metadata_file)
24allow vold {
25  proc # b/67049235 processes /proc/<pid>/* files are mislabeled.
26  proc_cmdline
27  proc_drop_caches
28  proc_filesystems
29  proc_meminfo
30  proc_mounts
31}:file r_file_perms;
32
33#Get file contexts
34allow vold file_contexts_file:file r_file_perms;
35
36# Allow us to jump into execution domains of above tools
37allow vold self:process setexec;
38
39# For formatting adoptable storage devices
40allow vold e2fs_exec:file rx_file_perms;
41
42# Run fstrim on mounted partitions
43# allowxperm still requires the ioctl permission for the individual type
44allowxperm vold { fs_type file_type }:dir ioctl FITRIM;
45
46# Get encryption policy for dirs in /data
47allowxperm vold data_file_type:dir ioctl {
48  FS_IOC_GET_ENCRYPTION_POLICY
49  FS_IOC_SET_ENCRYPTION_POLICY
50};
51
52# Find the location on the raw block device where the
53# crypto key is stored so it can be destroyed
54allowxperm vold vold_data_file:file ioctl {
55  FS_IOC_FIEMAP
56};
57
58typeattribute vold mlstrustedsubject;
59allow vold self:process setfscreate;
60allow vold system_file:file x_file_perms;
61not_full_treble(`allow vold vendor_file:file x_file_perms;')
62allow vold block_device:dir create_dir_perms;
63allow vold device:dir write;
64allow vold devpts:chr_file rw_file_perms;
65allow vold rootfs:dir mounton;
66allow vold sdcard_type:dir mounton; # TODO: deprecated in M
67allow vold sdcard_type:filesystem { mount remount unmount }; # TODO: deprecated in M
68allow vold sdcard_type:dir create_dir_perms; # TODO: deprecated in M
69allow vold sdcard_type:file create_file_perms; # TODO: deprecated in M
70
71# Manage locations where storage is mounted
72allow vold { mnt_media_rw_file storage_file sdcard_type }:dir create_dir_perms;
73allow vold { mnt_media_rw_file storage_file sdcard_type }:file create_file_perms;
74
75# Access to storage that backs emulated FUSE daemons for migration optimization
76allow vold media_rw_data_file:dir create_dir_perms;
77allow vold media_rw_data_file:file create_file_perms;
78
79# Allow mounting of storage devices
80allow vold { mnt_media_rw_stub_file storage_stub_file }:dir { mounton create rmdir getattr setattr };
81
82# Manage per-user primary symlinks
83allow vold mnt_user_file:dir { create_dir_perms mounton };
84allow vold mnt_user_file:lnk_file create_file_perms;
85allow vold mnt_user_file:file create_file_perms;
86
87# Allow to create and mount expanded storage
88allow vold mnt_expand_file:dir { create_dir_perms mounton };
89allow vold apk_data_file:dir { create getattr setattr };
90allow vold shell_data_file:dir { create getattr setattr };
91
92allow vold tmpfs:filesystem { mount unmount };
93allow vold tmpfs:dir create_dir_perms;
94allow vold tmpfs:dir mounton;
95allow vold self:global_capability_class_set { net_admin dac_override dac_read_search mknod sys_admin chown fowner fsetid };
96allow vold self:netlink_kobject_uevent_socket create_socket_perms_no_ioctl;
97allow vold loop_control_device:chr_file rw_file_perms;
98allow vold loop_device:blk_file { create setattr unlink rw_file_perms };
99allowxperm vold loop_device:blk_file ioctl {
100  LOOP_CLR_FD
101  LOOP_CTL_GET_FREE
102  LOOP_GET_STATUS64
103  LOOP_SET_FD
104  LOOP_SET_STATUS64
105};
106allow vold vold_device:blk_file { create setattr unlink rw_file_perms };
107allowxperm vold vold_device:blk_file ioctl { BLKDISCARD BLKGETSIZE };
108allow vold dm_device:chr_file rw_file_perms;
109allow vold dm_device:blk_file rw_file_perms;
110allowxperm vold dm_device:blk_file ioctl BLKSECDISCARD;
111# For vold Process::killProcessesWithOpenFiles function.
112allow vold domain:dir r_dir_perms;
113allow vold domain:{ file lnk_file } r_file_perms;
114allow vold domain:process { signal sigkill };
115allow vold self:global_capability_class_set { sys_ptrace kill };
116
117allow vold kmsg_device:chr_file rw_file_perms;
118
119# Run fsck in the fsck domain.
120allow vold fsck_exec:file { r_file_perms execute };
121
122# Log fsck results
123allow vold fscklogs:dir rw_dir_perms;
124allow vold fscklogs:file create_file_perms;
125
126#
127# Rules to support encrypted fs support.
128#
129
130# Unmount and mount the fs.
131allow vold labeledfs:filesystem { mount unmount remount };
132
133# Access /efs/userdata_footer.
134# XXX Split into a separate type?
135allow vold efs_file:file rw_file_perms;
136
137# Create and mount on /data/tmp_mnt and management of expansion mounts
138allow vold system_data_file:dir { create rw_dir_perms mounton setattr rmdir };
139allow vold system_data_file:lnk_file getattr;
140
141# Vold create users in /data/vendor_{ce,de}/[0-9]+
142allow vold vendor_data_file:dir create_dir_perms;
143
144# for secdiscard
145allow vold system_data_file:file read;
146
147# Set scheduling policy of kernel processes
148allow vold kernel:process setsched;
149
150# Property Service
151set_prop(vold, vold_prop)
152set_prop(vold, exported_vold_prop)
153set_prop(vold, exported2_vold_prop)
154set_prop(vold, powerctl_prop)
155set_prop(vold, ctl_fuse_prop)
156set_prop(vold, restorecon_prop)
157
158# ASEC
159allow vold asec_image_file:file create_file_perms;
160allow vold asec_image_file:dir rw_dir_perms;
161allow vold asec_apk_file:dir { create_dir_perms mounton relabelfrom relabelto };
162allow vold asec_public_file:dir { relabelto setattr };
163allow vold asec_apk_file:file { r_file_perms setattr relabelfrom relabelto };
164allow vold asec_public_file:file { relabelto setattr };
165# restorecon files in asec containers created on 4.2 or earlier.
166allow vold unlabeled:dir { r_dir_perms setattr relabelfrom };
167allow vold unlabeled:file { r_file_perms setattr relabelfrom };
168
169# Handle wake locks (used for device encryption)
170wakelock_use(vold)
171
172# Allow vold to publish a binder service and make binder calls.
173binder_use(vold)
174add_service(vold, vold_service)
175
176# Allow vold to call into the system server so it can check permissions.
177binder_call(vold, system_server)
178allow vold permission_service:service_manager find;
179
180# talk to batteryservice
181binder_call(vold, healthd)
182
183# talk to keymaster
184hal_client_domain(vold, hal_keymaster)
185
186# talk to health storage HAL
187hal_client_domain(vold, hal_health_storage)
188
189# talk to bootloader HAL
190full_treble_only(`hal_client_domain(vold, hal_bootctl)')
191
192# Access userdata block device.
193allow vold userdata_block_device:blk_file rw_file_perms;
194allowxperm vold userdata_block_device:blk_file ioctl BLKSECDISCARD;
195
196# Access metadata block device used for encryption meta-data.
197allow vold metadata_block_device:blk_file rw_file_perms;
198
199# Allow vold to manipulate /data/unencrypted
200allow vold unencrypted_data_file:{ file } create_file_perms;
201allow vold unencrypted_data_file:dir create_dir_perms;
202
203# Write to /proc/sys/vm/drop_caches
204allow vold proc_drop_caches:file w_file_perms;
205
206# Give vold a place where only vold can store files; everyone else is off limits
207allow vold vold_data_file:dir create_dir_perms;
208allow vold vold_data_file:file create_file_perms;
209
210# And a similar place in the metadata partition
211allow vold vold_metadata_file:dir create_dir_perms;
212allow vold vold_metadata_file:file create_file_perms;
213
214# linux keyring configuration
215allow vold init:key { write search setattr };
216allow vold vold:key { write search setattr };
217
218# vold temporarily changes its priority when running benchmarks
219allow vold self:global_capability_class_set sys_nice;
220
221# vold needs to chroot into app namespaces to remount when runtime permissions change
222allow vold self:global_capability_class_set sys_chroot;
223allow vold storage_file:dir mounton;
224
225# For AppFuse.
226allow vold fuse_device:chr_file rw_file_perms;
227allow vold fuse:filesystem { relabelfrom };
228allow vold app_fusefs:filesystem { relabelfrom relabelto };
229allow vold app_fusefs:filesystem { mount unmount };
230allow vold app_fuse_file:dir rw_dir_perms;
231allow vold app_fuse_file:file { read write open getattr append };
232
233# MoveTask.cpp executes cp and rm
234allow vold toolbox_exec:file rx_file_perms;
235
236# Prepare profile dir for users.
237allow vold user_profile_data_file:dir create_dir_perms;
238
239# Raw writes to misc block device
240allow vold misc_block_device:blk_file w_file_perms;
241
242# vold might need to search or mount /mnt/vendor/*
243allow vold mnt_vendor_file:dir search;
244
245dontaudit vold self:global_capability_class_set sys_resource;
246
247# vold needs to know whether we're running a GSI.
248allow vold gsi_metadata_file:dir r_dir_perms;
249allow vold gsi_metadata_file:file r_file_perms;
250
251neverallow {
252    domain
253    -vold
254    -vold_prepare_subdirs
255} vold_data_file:dir ~{ open create read getattr setattr search relabelfrom relabelto ioctl };
256
257neverallow {
258    domain
259    -init
260    -vold
261    -vold_prepare_subdirs
262} vold_data_file:dir *;
263
264neverallow {
265    domain
266    -init
267    -vold
268} vold_metadata_file:dir *;
269
270neverallow {
271    domain
272    -kernel
273    -vold
274    -vold_prepare_subdirs
275} vold_data_file:notdevfile_class_set ~{ relabelto getattr };
276
277neverallow {
278    domain
279    -init
280    -vold
281    -vold_prepare_subdirs
282} vold_metadata_file:notdevfile_class_set ~{ relabelto getattr };
283
284neverallow {
285    domain
286    -init
287    -kernel
288    -vold
289    -vold_prepare_subdirs
290} { vold_data_file vold_metadata_file }:notdevfile_class_set *;
291
292neverallow { domain -vold -init } restorecon_prop:property_service set;
293
294neverallow {
295    domain
296    -system_server
297    -vdc
298    -vold
299    -update_verifier
300    -apexd
301} vold_service:service_manager find;
302
303neverallow vold {
304  domain
305  -ashmemd
306  -hal_health_storage_server
307  -hal_keymaster_server
308  -system_suspend_server
309  -hal_bootctl_server
310  -healthd
311  -hwservicemanager
312  -iorapd_service
313  -servicemanager
314  -system_server
315  userdebug_or_eng(`-su')
316}:binder call;
317
318neverallow vold fsck_exec:file execute_no_trans;
319neverallow { domain -init } vold:process { transition dyntransition };
320neverallow vold *:process ptrace;
321neverallow vold *:rawip_socket *;
322