Skip to content
Snippets Groups Projects
profman.te 583 B
Newer Older
  • Learn to ignore specific revisions
  • # profman
    type profman, domain;
    type profman_exec, exec_type, file_type;
    
    
    allow profman user_profile_data_file:file { getattr read write lock };
    
    # Dumping profile info opens the application APK file for pretty printing.
    allow profman asec_apk_file:file { read };
    allow profman apk_data_file:file { read };
    allow profman oemfs:file { read };
    # Reading an APK opens a ZipArchive, which unpack to tmpfs.
    allow profman tmpfs:file { read };
    
    allow profman profman_dump_data_file:file { write };
    
    
    allow profman installd:fd use;
    
    neverallow profman app_data_file:notdevfile_class_set open;