Files
oxmc ae9e830f7f Initial commit: PawletCache, device-side LAN content-cache resolver
Bound service BgUpd consults before downloading component assets:
discovers a trusted cache server (mDNS and/or central lookup, policy-
configurable), verifies its signed CacheToken against a pinned root key,
and hands back a rewritten URL + TLS pin. Three-tier discovery policy
(runtime MDM override -> vendor-baked default -> compiled default).

Pairs with pawletcache-server (the LAN daemon) and BgUpd (the caller).
2026-07-25 00:06:51 -07:00
..

Vendor/OEM content-cache policy

A device builder shipping a PawletOS build can ship a standing default discovery policy on the read-only vendor partition — no MDM enrollment or post-boot profile push required. PawletCacheService reads it automatically; see PolicyOverride.kt for the full three-tier resolution (/data/misc/pawletcache/policy.json runtime override → this vendor file → compiled-in default).

This directory is not itself installed anywherePawletCache's own build doesn't ship an opinionated default. It's a template for your device tree.


File contract

Same shape as the runtime/MDM override — see policy.json.example:

{
  "mode": "both",
  "pinnedServer": { "host": "cache.local.lan", "port": 8443, "token": "<base64 CacheToken>" }
}

mode — one of central, lan, both (default if the file is malformed or missing this key), disabled.

pinnedServer — optional. If present, PawletCacheService skips discovery entirely and uses this server directly (its token is still signature-verified against the pinned root key — see Constants.kt's CACHE_TRUST_ROOT_PUBKEY_BASE64 — a vendor config can point at a server, not bypass the trust chain).


Installing it from a device tree

Drop your own policy.json somewhere in your device tree, then either of:

Soong (Android.bp):

prebuilt_etc {
    name: "pawletcache_vendor_policy",
    src: "policy.json",              // your file, relative to this Android.bp
    sub_dir: "pawletcache",          // -> /vendor/etc/pawletcache/policy.json
    vendor: true,
}

Then add pawletcache_vendor_policy to your device's PRODUCT_PACKAGES.

Make (device.mk), if your tree still uses it:

PRODUCT_COPY_FILES += \
    device/yourvendor/yourdevice/pawletcache_policy.json:$(TARGET_COPY_OUT_VENDOR)/etc/pawletcache/policy.json

sepolicy

android_packages_apps_PawletCache/sepolicy/file_contexts already labels /vendor/etc/pawletcache(/.*)? and pawlet_cache.te already grants the app read access — nothing extra needed in your device tree's own policy unless you've customized pawlet_cache's domain.