123456789101112131415161718192021222324252627282930313233343536373839 |
- allow rs app_data_file:dir ra_dir_perms;
- allow rs app_exec_data_file:file create_file_perms;
- type_transition rs app_data_file:file app_exec_data_file;
- allow rs system_data_file:lnk_file read;
- allow rs app_data_file:file r_file_perms;
- allow rs app_data_file:dir r_dir_perms;
- allow rs app_data_file:dir remove_name;
- allow rs vendor_file:dir r_dir_perms;
- r_dir_file(rs, vendor_overlay_file)
- r_dir_file(rs, vendor_app_file)
- r_dir_file(rs, apk_data_file)
- allow rs gpu_device:chr_file rw_file_perms;
- allow rs ion_device:chr_file r_file_perms;
- allow rs same_process_hal_file:file { r_file_perms execute };
- allow rs { untrusted_app_all ephemeral_app }:fd use;
- neverallow rs rs:capability_class_set *;
- neverallow { domain -appdomain } rs:process { dyntransition transition };
- neverallow rs { domain -crash_dump }:process { dyntransition transition };
- neverallow rs app_data_file:file_class_set ~r_file_perms;
- neverallow rs *:network_socket_class_set *;
|