vendor_shell.te 796 B

12345678910111213141516171819
  1. type vendor_shell, domain;
  2. type vendor_shell_exec, exec_type, vendor_file_type, file_type;
  3. allow vendor_shell vendor_shell_exec:file rx_file_perms;
  4. allow vendor_shell vendor_toolbox_exec:file rx_file_perms;
  5. # Use fd from shell when vendor_shell is started from shell
  6. allow vendor_shell shell:fd use;
  7. # adbd: allow `adb shell /vendor/bin/sh` and `adb shell` then `/vendor/bin/sh`
  8. allow vendor_shell adbd:fd use;
  9. allow vendor_shell adbd:process sigchld;
  10. allow vendor_shell adbd:unix_stream_socket { getattr ioctl read write };
  11. allow vendor_shell devpts:chr_file rw_file_perms;
  12. allow vendor_shell tty_device:chr_file rw_file_perms;
  13. allow vendor_shell console_device:chr_file rw_file_perms;
  14. allow vendor_shell input_device:dir r_dir_perms;
  15. allow vendor_shell input_device:chr_file rw_file_perms;