file.te 4.2 KB
Newer Older
Stephen Smalley's avatar
Stephen Smalley committed
1 2 3 4 5 6
# Filesystem types
type labeledfs, fs_type;
type pipefs, fs_type;
type sockfs, fs_type;
type rootfs, fs_type;
type proc, fs_type;
7
type qtaguid_proc, fs_type, mlstrustedobject;
Robert Craig's avatar
Robert Craig committed
8
type proc_bluetooth_writable, fs_type;
Stephen Smalley's avatar
Stephen Smalley committed
9 10 11 12
type selinuxfs, fs_type;
type cgroup, fs_type, mlstrustedobject;
type sysfs, fs_type, mlstrustedobject;
type sysfs_writable, fs_type, sysfs_type, mlstrustedobject;
13
type sysfs_bluetooth_writable, fs_type, sysfs_type, mlstrustedobject;
14
type sysfs_nfc_power_writable, fs_type, sysfs_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
15
type inotify, fs_type, mlstrustedobject;
16
type devpts, fs_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
17 18 19
type tmpfs, fs_type;
type shm, fs_type;
type mqueue, fs_type;
20 21
type sdcard_internal, sdcard_type, fs_type, mlstrustedobject;
type sdcard_external, sdcard_type, fs_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
22 23 24 25 26 27 28 29
type debugfs, fs_type, mlstrustedobject;

# File types
type unlabeled, file_type;
# Default type for anything under /system.
type system_file, file_type;
# Default type for anything under /data.
type system_data_file, file_type, data_file_type;
30 31
# /data/drm - DRM plugin data
type drm_data_file, file_type, data_file_type;
Stephen Smalley's avatar
Stephen Smalley committed
32
# /data/anr - ANR traces
33
type anr_data_file, file_type, data_file_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
34 35 36
# /data/tombstones - core dumps
type tombstone_data_file, file_type, data_file_type;
# /data/app - user-installed apps
37 38
type apk_data_file, file_type, data_file_type;
type apk_tmp_file, file_type, data_file_type, mlstrustedobject;
39 40 41
# /data/app-private - forward-locked apps
type apk_private_data_file, file_type, data_file_type;
type apk_private_tmp_file, file_type, data_file_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
42 43 44 45 46 47 48 49 50 51 52 53 54 55 56
# /data/dalvik-cache
type dalvikcache_data_file, file_type, data_file_type;
# /data/local - writable by shell
type shell_data_file, file_type, data_file_type;
# /data/gps
type gps_data_file, file_type, data_file_type;
# /data/misc subdirectories
type bluetoothd_data_file, file_type, data_file_type;
type bluetooth_data_file, file_type, data_file_type;
type keystore_data_file, file_type, data_file_type;
type vpn_data_file, file_type, data_file_type;
type systemkeys_data_file, file_type, data_file_type;
type wifi_data_file, file_type, data_file_type;
type radio_data_file, file_type, data_file_type;
type nfc_data_file, file_type, data_file_type;
hqjiang's avatar
hqjiang committed
57
type camera_calibration_file, file_type, data_file_type;
Stephen Smalley's avatar
Stephen Smalley committed
58 59
# /data/data subdirectories - app sandboxes
type app_data_file, file_type, data_file_type;
60
type platform_app_data_file, file_type, data_file_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
61 62
# Default type for anything under /cache
type cache_file, file_type, mlstrustedobject;
rpcraig's avatar
rpcraig committed
63 64 65
# Type for /cache/.*\.{data|restore} and default
# type for anything under /cache/backup
type cache_backup_file, file_type, mlstrustedobject;
Stephen Smalley's avatar
Stephen Smalley committed
66 67
# Default type for anything under /efs
type efs_file, file_type;
68
# Type for wallpaper file.
69
type wallpaper_file, file_type, mlstrustedobject;
70 71 72 73
# /mnt/asec
type asec_apk_file, file_type, data_file_type;
# /data/app-asec
type asec_image_file, file_type, data_file_type;
rpcraig's avatar
rpcraig committed
74 75
# /data/backup and /data/secure/backup
type backup_data_file, file_type, data_file_type, mlstrustedobject;
William Roberts's avatar
William Roberts committed
76 77
# For /data/security
type security_file, file_type;
78 79
# All devices have bluetooth efs files. But they
# vary per device, so this type is used in per
William Roberts's avatar
William Roberts committed
80
# device policy
81
type bluetooth_efs_file, file_type;
Geremy Condra's avatar
Geremy Condra committed
82 83
# Downloaded files
type download_file, file_type;
84 85
# /sys/devices/system/cpu
type sysfs_devices_system_cpu, file_type;
86

Stephen Smalley's avatar
Stephen Smalley committed
87
# Socket types
88
type adbd_socket, file_type;
Stephen Smalley's avatar
Stephen Smalley committed
89 90 91 92 93 94 95 96 97
type bluetooth_socket, file_type;
type dbus_socket, file_type;
type dnsproxyd_socket, file_type, mlstrustedobject;
type gps_socket, file_type;
type installd_socket, file_type;
type keystore_socket, file_type;
type netd_socket, file_type;
type property_socket, file_type;
type qemud_socket, file_type;
Robert Craig's avatar
Robert Craig committed
98
type racoon_socket, file_type;
Stephen Smalley's avatar
Stephen Smalley committed
99 100 101 102 103 104 105
type rild_socket, file_type;
type rild_debug_socket, file_type;
type system_wpa_socket, file_type;
type vold_socket, file_type;
type wpa_socket, file_type;
type zygote_socket, file_type;

106 107 108
# UART (for GPS) control proc file
type gps_control, file_type;

Stephen Smalley's avatar
Stephen Smalley committed
109 110 111 112 113 114
# Allow files to be created in their appropriate filesystems.
allow fs_type self:filesystem associate;
allow sysfs_type sysfs:filesystem associate;
allow file_type labeledfs:filesystem associate;
allow file_type tmpfs:filesystem associate;
allow dev_type tmpfs:filesystem associate;