blob: 37d645593caff66aeff9fec738049e8f9d1fe7d9 [file] [log] [blame]
Stephen Smalley6d10ca82014-01-13 09:45:45 -05001# recovery console (used in recovery init.rc for /sbin/recovery)
2type recovery, domain;
3allow recovery rootfs:file entrypoint;
4unconfined_domain(recovery)
5relabelto_domain(recovery)
6
Stephen Smalley04ee5df2014-01-30 13:23:08 -05007allow recovery self:capability2 mac_admin;
8
Stephen Smalley6d10ca82014-01-13 09:45:45 -05009allow recovery {fs_type dev_type -kmem_device file_type}:dir_file_class_set relabelto;
10allow recovery unlabeled:filesystem mount;
Stephen Smalleyb081cc12014-02-10 13:29:38 -050011allow recovery fs_type:filesystem *;
Stephen Smalley6d10ca82014-01-13 09:45:45 -050012
13allow recovery self:process execmem;
Stephen Smalley9fe4e7b2014-01-13 15:32:11 -050014allow recovery ashmem_device:chr_file execute;
Stephen Smalley9a407022014-01-13 14:03:47 -050015allow recovery tmpfs:file rx_file_perms;