Linux Services AIDL
Binder API for MDMs and BootSight to provision and control Linux Services jobs.
Who may call it
A caller is allowed if it is one of these:
- the system uid;
- a holder of
org.ax86.linuxservices.permission.MANAGE_JOBS(signature|privileged); - the device owner;
- a package listed by certificate SHA-256 in
/system/etc/linux-services-callers.xml.
Any other caller gets a SecurityException.
Methods
Zero-touch example
A provisioning client typically:
- Binds, checks
apiVersion() >= 2, and registers a callback. - Calls
environment(). IfinstalledordisplaySessionis false, callsinstallEnvironment()and waits for anonEnvironmentupdate with both true. - Calls
importJson(document, true)with the fleet's job set. - Watches
onJobStateor pollsstatus().
Jobs marked atBoot then start on every boot without the client being present.