# Start the keystore2 service.
# Keystore 2.0 changes its working directory to the first positional
# command line option, i.e., /data/misc/keystore, where it stores its
# database.
# Keystore shall run as user keystore and groups keystore, readproc, and log.
#
# See system/core/init/README.md for information on the init.rc language.

service keystore2 /system/bin/keystore2 /data/misc/keystore
    class early_hal
    user keystore
    group keystore readproc log
    task_profiles ProcessCapacityHigh
    # The default memlock limit of 65536 bytes is too low for keystore.
    rlimit memlock unlimited unlimited
    # Reboot to bootloader if Keystore crashes more than 4 times before `sys.boot_completed`.
    critical window=0
