2013-07-12 16:33:29 -07:00
|
|
|
###
|
|
|
|
### Apps signed with the platform key.
|
|
|
|
###
|
|
|
|
|
|
|
|
type platform_app, domain;
|
2014-01-11 01:31:03 -08:00
|
|
|
permissive_or_unconfined(platform_app)
|
2013-07-12 16:33:29 -07:00
|
|
|
app_domain(platform_app)
|
|
|
|
platform_app_domain(platform_app)
|
|
|
|
# Access the network.
|
|
|
|
net_domain(platform_app)
|
|
|
|
# Access bluetooth.
|
|
|
|
bluetooth_domain(platform_app)
|
2014-03-06 13:03:48 -08:00
|
|
|
# Read from /data/local/tmp or /data/data/com.android.shell.
|
2013-10-23 10:12:55 -07:00
|
|
|
allow platform_app shell_data_file:dir search;
|
|
|
|
allow platform_app shell_data_file:file { open getattr read };
|
|
|
|
allow platform_app shell_data_file:lnk_file read;
|
|
|
|
# Populate /data/app/vmdl*.tmp, /data/app-private/vmdl*.tmp files
|
|
|
|
# created by system server.
|
|
|
|
allow platform_app { apk_tmp_file apk_private_tmp_file }:file rw_file_perms;
|
|
|
|
allow platform_app apk_private_data_file:dir search;
|
|
|
|
# ASEC
|
|
|
|
allow platform_app asec_apk_file:dir create_dir_perms;
|
|
|
|
allow platform_app asec_apk_file:file create_file_perms;
|
|
|
|
|
2014-03-06 13:03:48 -08:00
|
|
|
# inherits from platformappdomain.te
|