diff --git a/profman.te b/profman.te index 9897069622d5ac72d1afbdbf5f159b2f47c3a3aa..fa3df94a6526d52e6174959b41d7f94a9de15cd3 100644 --- a/profman.te +++ b/profman.te @@ -4,6 +4,12 @@ type profman_exec, exec_type, file_type; allow profman user_profile_data_file:file { getattr read write lock }; +# Dumping profile info opens the application APK file for pretty printing. +allow profman asec_apk_file:file { read }; +allow profman apk_data_file:file { read }; +allow profman oemfs:file { read }; +# Reading an APK opens a ZipArchive, which unpack to tmpfs. +allow profman tmpfs:file { read }; allow profman profman_dump_data_file:file { write }; allow profman installd:fd use;