xref: /aosp_15_r20/system/sepolicy/prebuilts/api/202404/202404_plat_sepolicy.cil (revision e4a36f4174b17bbab9dc043f4a65dc8d87377290)
1(role object_r)
2(role auditadm_r)
3(role secadm_r)
4(typeattribute cil_gen_require)
5(roleattribute cil_gen_require)
6(handleunknown deny)
7(mls true)
8(policycap network_peer_controls)
9(policycap open_perms)
10(policycap extended_socket_class)
11(policycap nnp_nosuid_transition)
12(sid devnull)
13(sidcontext devnull (u object_r null_device ((s0) (s0))))
14(sid scmp_packet)
15(sidcontext scmp_packet (u object_r unlabeled ((s0) (s0))))
16(sid policy)
17(sidcontext policy (u object_r unlabeled ((s0) (s0))))
18(sid kmod)
19(sidcontext kmod (u object_r unlabeled ((s0) (s0))))
20(sid sysctl_dev)
21(sidcontext sysctl_dev (u object_r unlabeled ((s0) (s0))))
22(sid sysctl_vm)
23(sidcontext sysctl_vm (u object_r unlabeled ((s0) (s0))))
24(sid sysctl_net_unix)
25(sidcontext sysctl_net_unix (u object_r unlabeled ((s0) (s0))))
26(sid sysctl_net)
27(sidcontext sysctl_net (u object_r unlabeled ((s0) (s0))))
28(sid sysctl_kernel)
29(sidcontext sysctl_kernel (u object_r unlabeled ((s0) (s0))))
30(sid sysctl_fs)
31(sidcontext sysctl_fs (u object_r unlabeled ((s0) (s0))))
32(sid sysctl)
33(sidcontext sysctl (u object_r proc ((s0) (s0))))
34(sid sysctl_modprobe)
35(sidcontext sysctl_modprobe (u object_r unlabeled ((s0) (s0))))
36(sid tcp_socket)
37(sidcontext tcp_socket (u object_r unlabeled ((s0) (s0))))
38(sid icmp_socket)
39(sidcontext icmp_socket (u object_r unlabeled ((s0) (s0))))
40(sid igmp_packet)
41(sidcontext igmp_packet (u object_r unlabeled ((s0) (s0))))
42(sid node)
43(sidcontext node (u object_r node ((s0) (s0))))
44(sid netmsg)
45(sidcontext netmsg (u object_r unlabeled ((s0) (s0))))
46(sid netif)
47(sidcontext netif (u object_r netif ((s0) (s0))))
48(sid port)
49(sidcontext port (u object_r port ((s0) (s0))))
50(sid any_socket)
51(sidcontext any_socket (u object_r unlabeled ((s0) (s0))))
52(sid init)
53(sidcontext init (u object_r unlabeled ((s0) (s0))))
54(sid file_labels)
55(sidcontext file_labels (u object_r unlabeled ((s0) (s0))))
56(sid file)
57(sidcontext file (u object_r unlabeled ((s0) (s0))))
58(sid fs)
59(sidcontext fs (u object_r labeledfs ((s0) (s0))))
60(sid unlabeled)
61(sidcontext unlabeled (u object_r unlabeled ((s0) (s0))))
62(sid security)
63(sidcontext security (u object_r kernel ((s0) (s0))))
64(sid kernel)
65(sidcontext kernel (u r kernel ((s0) (s0))))
66(sidorder (kernel security unlabeled fs file file_labels init any_socket port netif netmsg node igmp_packet icmp_socket tcp_socket sysctl_modprobe sysctl sysctl_fs sysctl_kernel sysctl_net sysctl_net_unix sysctl_vm sysctl_dev kmod policy scmp_packet devnull ))
67(fsuse trans mqueue (u object_r mqueue ((s0) (s0))))
68(fsuse trans shm (u object_r shm ((s0) (s0))))
69(fsuse trans devtmpfs (u object_r device ((s0) (s0))))
70(fsuse trans tmpfs (u object_r tmpfs ((s0) (s0))))
71(fsuse trans devpts (u object_r devpts ((s0) (s0))))
72(fsuse task sockfs (u object_r sockfs ((s0) (s0))))
73(fsuse task pipefs (u object_r pipefs ((s0) (s0))))
74(fsuse xattr virtiofs (u object_r labeledfs ((s0) (s0))))
75(fsuse xattr incremental-fs (u object_r labeledfs ((s0) (s0))))
76(fsuse xattr erofs (u object_r labeledfs ((s0) (s0))))
77(fsuse xattr overlay (u object_r labeledfs ((s0) (s0))))
78(fsuse xattr squashfs (u object_r labeledfs ((s0) (s0))))
79(fsuse xattr f2fs (u object_r labeledfs ((s0) (s0))))
80(fsuse xattr btrfs (u object_r labeledfs ((s0) (s0))))
81(fsuse xattr xfs (u object_r labeledfs ((s0) (s0))))
82(fsuse xattr ext4 (u object_r labeledfs ((s0) (s0))))
83(fsuse xattr ext3 (u object_r labeledfs ((s0) (s0))))
84(fsuse xattr ext2 (u object_r labeledfs ((s0) (s0))))
85(fsuse xattr jffs2 (u object_r labeledfs ((s0) (s0))))
86(fsuse xattr yaffs2 (u object_r labeledfs ((s0) (s0))))
87(genfscon binder "/binder_logs/stats" (u object_r binderfs_logs_stats ((s0) (s0))))
88(genfscon binder "/binder_logs/proc" (u object_r binderfs_logs_proc ((s0) (s0))))
89(genfscon binder "/binder_logs" (u object_r binderfs_logs ((s0) (s0))))
90(genfscon binder "/vndbinder" (u object_r vndbinder_device ((s0) (s0))))
91(genfscon binder "/hwbinder" (u object_r hwbinder_device ((s0) (s0))))
92(genfscon binder "/features" (u object_r binderfs_features ((s0) (s0))))
93(genfscon binder "/binder" (u object_r binder_device ((s0) (s0))))
94(genfscon binder "/" (u object_r binderfs ((s0) (s0))))
95(genfscon binfmt_misc "/" (u object_r binfmt_miscfs ((s0) (s0))))
96(genfscon bpf "/netd_readonly" (u object_r fs_bpf_netd_readonly ((s0) (s0))))
97(genfscon bpf "/net_private" (u object_r fs_bpf_net_private ((s0) (s0))))
98(genfscon bpf "/netd_shared" (u object_r fs_bpf_netd_shared ((s0) (s0))))
99(genfscon bpf "/uprobestats" (u object_r fs_bpf_uprobestats ((s0) (s0))))
100(genfscon bpf "/net_shared" (u object_r fs_bpf_net_shared ((s0) (s0))))
101(genfscon bpf "/tethering" (u object_r fs_bpf_tethering ((s0) (s0))))
102(genfscon bpf "/loader" (u object_r fs_bpf_loader ((s0) (s0))))
103(genfscon bpf "/vendor" (u object_r fs_bpf_vendor ((s0) (s0))))
104(genfscon bpf "/" (u object_r fs_bpf ((s0) (s0))))
105(genfscon cgroup "/" (u object_r cgroup ((s0) (s0))))
106(genfscon cgroup2 "/" (u object_r cgroup_v2 ((s0) (s0))))
107(genfscon configfs "/" (u object_r configfs ((s0) (s0))))
108(genfscon debugfs "/tracing/events/filemap/mm_filemap_delete_from_page_cache/" (u object_r debugfs_tracing ((s0) (s0))))
109(genfscon debugfs "/tracing/events/vmscan/mm_vmscan_direct_reclaim_begin/" (u object_r debugfs_tracing ((s0) (s0))))
110(genfscon debugfs "/tracing/events/filemap/mm_filemap_add_to_page_cache/" (u object_r debugfs_tracing ((s0) (s0))))
111(genfscon debugfs "/tracing/events/vmscan/mm_vmscan_direct_reclaim_end/" (u object_r debugfs_tracing ((s0) (s0))))
112(genfscon debugfs "/tracing/events/binder/binder_transaction_alloc_buf/" (u object_r debugfs_tracing ((s0) (s0))))
113(genfscon debugfs "/tracing/events/binder/binder_transaction_received/" (u object_r debugfs_tracing ((s0) (s0))))
114(genfscon debugfs "/tracing/events/ext4/ext4_es_lookup_extent_enter/" (u object_r debugfs_tracing ((s0) (s0))))
115(genfscon debugfs "/tracing/events/ext4/ext4_es_lookup_extent_exit/" (u object_r debugfs_tracing ((s0) (s0))))
116(genfscon debugfs "/tracing/events/synthetic/suspend_resume_minimal" (u object_r debugfs_tracing ((s0) (s0))))
117(genfscon debugfs "/tracing/events/vmscan/mm_vmscan_kswapd_sleep/" (u object_r debugfs_tracing ((s0) (s0))))
118(genfscon debugfs "/tracing/events/vmscan/mm_vmscan_kswapd_wake/" (u object_r debugfs_tracing ((s0) (s0))))
119(genfscon debugfs "/tracing/events/synthetic/rss_stat_throttled" (u object_r debugfs_tracing ((s0) (s0))))
120(genfscon debugfs "/tracing/events/thermal/thermal_temperature/" (u object_r debugfs_tracing ((s0) (s0))))
121(genfscon debugfs "/tracing/events/sched/sched_blocked_reason/" (u object_r debugfs_tracing ((s0) (s0))))
122(genfscon debugfs "/tracing/events/power/cpu_frequency_limits/" (u object_r debugfs_tracing ((s0) (s0))))
123(genfscon debugfs "/tracing/events/binder/binder_set_priority/" (u object_r debugfs_tracing ((s0) (s0))))
124(genfscon debugfs "/tracing/events/f2fs/f2fs_sync_file_enter/" (u object_r debugfs_tracing ((s0) (s0))))
125(genfscon debugfs "/tracing/events/ext4/ext4_sync_file_enter/" (u object_r debugfs_tracing ((s0) (s0))))
126(genfscon debugfs "/tracing/events/binder/binder_transaction/" (u object_r debugfs_tracing ((s0) (s0))))
127(genfscon debugfs "/tracing/events/f2fs/f2fs_get_data_block/" (u object_r debugfs_tracing ((s0) (s0))))
128(genfscon debugfs "/tracing/events/f2fs/f2fs_sync_file_exit/" (u object_r debugfs_tracing ((s0) (s0))))
129(genfscon debugfs "/tracing/events/ext4/ext4_da_write_begin/" (u object_r debugfs_tracing ((s0) (s0))))
130(genfscon debugfs "/tracing/events/ext4/ext4_sync_file_exit/" (u object_r debugfs_tracing ((s0) (s0))))
131(genfscon debugfs "/tracing/events/sched/sched_process_exit/" (u object_r debugfs_tracing ((s0) (s0))))
132(genfscon debugfs "/tracing/events/sched/sched_process_free/" (u object_r debugfs_tracing ((s0) (s0))))
133(genfscon debugfs "/tracing/events/mm_event/mm_event_record/" (u object_r debugfs_tracing ((s0) (s0))))
134(genfscon debugfs "/tracing/events/oom/oom_score_adj_update/" (u object_r debugfs_tracing ((s0) (s0))))
135(genfscon debugfs "/tracing/events/block/block_rq_complete/" (u object_r debugfs_tracing ((s0) (s0))))
136(genfscon debugfs "/tracing/events/sched/sched_cpu_hotplug/" (u object_r debugfs_tracing ((s0) (s0))))
137(genfscon debugfs "/tracing/events/ext4/ext4_da_write_end/" (u object_r debugfs_tracing ((s0) (s0))))
138(genfscon debugfs "/tracing/events/sched/sched_wakeup_new/" (u object_r debugfs_tracing ((s0) (s0))))
139(genfscon debugfs "/tracing/events/sched/sched_pi_setprio/" (u object_r debugfs_tracing ((s0) (s0))))
140(genfscon debugfs "/tracing/events/f2fs/f2fs_write_begin/" (u object_r debugfs_tracing ((s0) (s0))))
141(genfscon debugfs "/tracing/events/power/gpu_work_period/" (u object_r debugfs_tracing ((s0) (s0))))
142(genfscon debugfs "/tracing/events/binder/binder_command/" (u object_r debugfs_tracing ((s0) (s0))))
143(genfscon debugfs "/tracing/events/ext4/ext4_load_inode/" (u object_r debugfs_tracing ((s0) (s0))))
144(genfscon debugfs "/tracing/events/block/block_rq_issue/" (u object_r debugfs_tracing ((s0) (s0))))
145(genfscon debugfs "/tracing/events/power/clock_set_rate/" (u object_r debugfs_tracing ((s0) (s0))))
146(genfscon debugfs "/tracing/events/power/suspend_resume/" (u object_r debugfs_tracing ((s0) (s0))))
147(genfscon debugfs "/tracing/events/binder/binder_locked/" (u object_r debugfs_tracing ((s0) (s0))))
148(genfscon debugfs "/tracing/events/binder/binder_unlock/" (u object_r debugfs_tracing ((s0) (s0))))
149(genfscon debugfs "/tracing/events/binder/binder_return/" (u object_r debugfs_tracing ((s0) (s0))))
150(genfscon debugfs "/tracing/events/kmem/ion_heap_shrink/" (u object_r debugfs_tracing ((s0) (s0))))
151(genfscon debugfs "/tracing/events/gpu_mem/gpu_mem_total" (u object_r debugfs_tracing ((s0) (s0))))
152(genfscon debugfs "/tracing/events/f2fs/f2fs_write_end/" (u object_r debugfs_tracing ((s0) (s0))))
153(genfscon debugfs "/tracing/events/power/cpu_frequency/" (u object_r debugfs_tracing ((s0) (s0))))
154(genfscon debugfs "/tracing/events/power/clock_disable/" (u object_r debugfs_tracing ((s0) (s0))))
155(genfscon debugfs "/tracing/events/power/gpu_frequency/" (u object_r debugfs_tracing ((s0) (s0))))
156(genfscon debugfs "/tracing/events/cpufreq_interactive/" (u object_r debugfs_tracing ((s0) (s0))))
157(genfscon debugfs "/tracing/events/thermal/cdev_update/" (u object_r debugfs_tracing ((s0) (s0))))
158(genfscon debugfs "/tracing/events/sched/sched_switch/" (u object_r debugfs_tracing ((s0) (s0))))
159(genfscon debugfs "/tracing/events/sched/sched_wakeup/" (u object_r debugfs_tracing ((s0) (s0))))
160(genfscon debugfs "/tracing/events/sched/sched_waking/" (u object_r debugfs_tracing ((s0) (s0))))
161(genfscon debugfs "/tracing/events/power/clock_enable/" (u object_r debugfs_tracing ((s0) (s0))))
162(genfscon debugfs "/tracing/events/binder/binder_lock/" (u object_r debugfs_tracing ((s0) (s0))))
163(genfscon debugfs "/tracing/events/kmem/ion_heap_grow/" (u object_r debugfs_tracing ((s0) (s0))))
164(genfscon debugfs "/tracing/events/task/task_newtask/" (u object_r debugfs_tracing ((s0) (s0))))
165(genfscon debugfs "/tracing/events/cpuhp/cpuhp_enter/" (u object_r debugfs_tracing ((s0) (s0))))
166(genfscon debugfs "/tracing/events/task/task_rename/" (u object_r debugfs_tracing ((s0) (s0))))
167(genfscon debugfs "/tracing/events/cpuhp/cpuhp_exit/" (u object_r debugfs_tracing ((s0) (s0))))
168(genfscon debugfs "/tracing/events/clk/clk_set_rate/" (u object_r debugfs_tracing ((s0) (s0))))
169(genfscon debugfs "/tracing/events/lowmemorykiller/" (u object_r debugfs_tracing ((s0) (s0))))
170(genfscon debugfs "/tracing/events/oom/mark_victim/" (u object_r debugfs_tracing ((s0) (s0))))
171(genfscon debugfs "/tracing/events/clk/clk_disable/" (u object_r debugfs_tracing ((s0) (s0))))
172(genfscon debugfs "/tracing/instances/bootreceiver" (u object_r debugfs_bootreceiver_tracing ((s0) (s0))))
173(genfscon debugfs "/tracing/events/f2fs/f2fs_iget/" (u object_r debugfs_tracing ((s0) (s0))))
174(genfscon debugfs "/tracing/events/power/cpu_idle/" (u object_r debugfs_tracing ((s0) (s0))))
175(genfscon debugfs "/tracing/events/clk/clk_enable/" (u object_r debugfs_tracing ((s0) (s0))))
176(genfscon debugfs "/tracing/events/kmem/rss_stat/" (u object_r debugfs_tracing ((s0) (s0))))
177(genfscon debugfs "/tracing/events/ion/ion_stat/" (u object_r debugfs_tracing ((s0) (s0))))
178(genfscon debugfs "/tracing/events/ftrace/print/" (u object_r debugfs_tracing ((s0) (s0))))
179(genfscon debugfs "/tracing/instances/mm_events" (u object_r debugfs_mm_events_tracing ((s0) (s0))))
180(genfscon debugfs "/tracing/options/record-tgid" (u object_r debugfs_tracing ((s0) (s0))))
181(genfscon debugfs "/tracing/saved_cmdlines_size" (u object_r debugfs_tracing ((s0) (s0))))
182(genfscon debugfs "/tracing/events/header_page" (u object_r debugfs_tracing ((s0) (s0))))
183(genfscon debugfs "/tracing/options/print-tgid" (u object_r debugfs_tracing ((s0) (s0))))
184(genfscon debugfs "/tracing/options/overwrite" (u object_r debugfs_tracing ((s0) (s0))))
185(genfscon debugfs "/tracing/events/dma_fence/" (u object_r debugfs_tracing ((s0) (s0))))
186(genfscon debugfs "/tracing/synthetic_events" (u object_r debugfs_tracing ((s0) (s0))))
187(genfscon debugfs "/tracing/instances/wifi" (u object_r debugfs_wifi_tracing ((s0) (s0))))
188(genfscon debugfs "/tracing/printk_formats" (u object_r debugfs_tracing_printk_formats ((s0) (s0))))
189(genfscon debugfs "/tracing/buffer_size_kb" (u object_r debugfs_tracing ((s0) (s0))))
190(genfscon debugfs "/tracing/events/cgroup/" (u object_r debugfs_tracing ((s0) (s0))))
191(genfscon debugfs "/tracing/events/fence/" (u object_r debugfs_tracing ((s0) (s0))))
192(genfscon debugfs "/tracing/trace_marker" (u object_r debugfs_trace_marker ((s0) (s0))))
193(genfscon debugfs "/tracing/events/sync/" (u object_r debugfs_tracing ((s0) (s0))))
194(genfscon debugfs "/tracing/per_cpu/cpu" (u object_r debugfs_tracing ((s0) (s0))))
195(genfscon debugfs "/tracing/trace_clock" (u object_r debugfs_tracing ((s0) (s0))))
196(genfscon debugfs "/tracing/events/ipi/" (u object_r debugfs_tracing ((s0) (s0))))
197(genfscon debugfs "/tracing/events/irq/" (u object_r debugfs_tracing ((s0) (s0))))
198(genfscon debugfs "/tracing/tracing_on" (u object_r debugfs_tracing ((s0) (s0))))
199(genfscon debugfs "/tracing/instances" (u object_r debugfs_tracing_instances ((s0) (s0))))
200(genfscon debugfs "/wakeup_sources" (u object_r debugfs_wakeup_sources ((s0) (s0))))
201(genfscon debugfs "/tracing/trace" (u object_r debugfs_tracing ((s0) (s0))))
202(genfscon debugfs "/tracing/hyp" (u object_r debugfs_tracing ((s0) (s0))))
203(genfscon debugfs "/kprobes" (u object_r debugfs_kprobes ((s0) (s0))))
204(genfscon debugfs "/tracing" (u object_r debugfs_tracing_debug ((s0) (s0))))
205(genfscon debugfs "/mmc0" (u object_r debugfs_mmc ((s0) (s0))))
206(genfscon debugfs "/kcov" (u object_r debugfs_kcov ((s0) (s0))))
207(genfscon debugfs "/" (u object_r debugfs ((s0) (s0))))
208(genfscon esdfs "/" (u object_r sdcardfs ((s0) (s0))))
209(genfscon exfat "/" (u object_r exfat ((s0) (s0))))
210(genfscon functionfs "/" (u object_r functionfs ((s0) (s0))))
211(genfscon fuse "/" (u object_r fuse ((s0) (s0))))
212(genfscon fuseblk "/" (u object_r fuseblk ((s0) (s0))))
213(genfscon fusectl "/" (u object_r fusectlfs ((s0) (s0))))
214(genfscon inotifyfs "/" (u object_r inotify ((s0) (s0))))
215(genfscon proc "/sys/kernel/sched_util_clamp_min_rt_default" (u object_r proc_sched ((s0) (s0))))
216(genfscon proc "/sys/kernel/sched_wakeup_granularity_ns" (u object_r proc_sched ((s0) (s0))))
217(genfscon proc "/sys/kernel/perf_event_max_sample_rate" (u object_r proc_perf ((s0) (s0))))
218(genfscon proc "/sys/kernel/perf_cpu_time_max_percent" (u object_r proc_perf ((s0) (s0))))
219(genfscon proc "/sys/vm/percpu_pagelist_high_fraction" (u object_r proc_percpu_pagelist_high_fraction ((s0) (s0))))
220(genfscon proc "/sys/kernel/sched_child_runs_first" (u object_r proc_sched ((s0) (s0))))
221(genfscon proc "/sys/kernel/sched_tunable_scaling" (u object_r proc_sched ((s0) (s0))))
222(genfscon proc "/sys/kernel/sched_util_clamp_max" (u object_r proc_sched ((s0) (s0))))
223(genfscon proc "/sys/kernel/sched_util_clamp_min" (u object_r proc_sched ((s0) (s0))))
224(genfscon proc "/sys/kernel/perf_event_paranoid" (u object_r proc_perf ((s0) (s0))))
225(genfscon proc "/sys/kernel/perf_event_mlock_kb" (u object_r proc_perf ((s0) (s0))))
226(genfscon proc "/sys/kernel/sched_rt_runtime_us" (u object_r proc_sched ((s0) (s0))))
227(genfscon proc "/sys/kernel/randomize_va_space" (u object_r proc_security ((s0) (s0))))
228(genfscon proc "/sys/kernel/sched_rt_period_us" (u object_r proc_sched ((s0) (s0))))
229(genfscon proc "/sys/vm/dirty_background_ratio" (u object_r proc_dirty ((s0) (s0))))
230(genfscon proc "/sys/vm/dirty_expire_centisecs" (u object_r proc_dirty ((s0) (s0))))
231(genfscon proc "/sys/vm/watermark_boost_factor" (u object_r proc_watermark_boost_factor ((s0) (s0))))
232(genfscon proc "/sys/vm/watermark_scale_factor" (u object_r proc_watermark_scale_factor ((s0) (s0))))
233(genfscon proc "/sys/kernel/unprivileged_bpf_" (u object_r proc_bpf ((s0) (s0))))
234(genfscon proc "/uid_cputime/remove_uid_range" (u object_r proc_uid_cputime_removeuid ((s0) (s0))))
235(genfscon proc "/sys/kernel/modules_disabled" (u object_r proc_security ((s0) (s0))))
236(genfscon proc "/sys/kernel/sched_latency_ns" (u object_r proc_sched ((s0) (s0))))
237(genfscon proc "/sys/kernel/sched_schedstats" (u object_r proc_sched ((s0) (s0))))
238(genfscon proc "/sys/vm/mmap_rnd_compat_bits" (u object_r proc_security ((s0) (s0))))
239(genfscon proc "/sys/vm/min_free_order_shift" (u object_r proc_min_free_order_shift ((s0) (s0))))
240(genfscon proc "/sys/fs/protected_hardlinks" (u object_r proc_security ((s0) (s0))))
241(genfscon proc "/sys/kernel/core_pipe_limit" (u object_r usermodehelper ((s0) (s0))))
242(genfscon proc "/uid_concurrent_active_time" (u object_r proc_uid_concurrent_active_time ((s0) (s0))))
243(genfscon proc "/uid_concurrent_policy_time" (u object_r proc_uid_concurrent_policy_time ((s0) (s0))))
244(genfscon proc "/sys/fs/protected_symlinks" (u object_r proc_security ((s0) (s0))))
245(genfscon proc "/sys/kernel/dmesg_restrict" (u object_r proc_security ((s0) (s0))))
246(genfscon proc "/sys/kernel/usermodehelper" (u object_r usermodehelper ((s0) (s0))))
247(genfscon proc "/uid_cputime/show_uid_stat" (u object_r proc_uid_cputime_showstat ((s0) (s0))))
248(genfscon proc "/sys/kernel/kptr_restrict" (u object_r proc_security ((s0) (s0))))
249(genfscon proc "/sys/kernel/panic_on_oops" (u object_r proc_panic ((s0) (s0))))
250(genfscon proc "/sys/vm/extra_free_kbytes" (u object_r proc_extra_free_kbytes ((s0) (s0))))
251(genfscon proc "/sys/vm/overcommit_memory" (u object_r proc_overcommit_memory ((s0) (s0))))
252(genfscon proc "/sys/kernel/core_pattern" (u object_r usermodehelper ((s0) (s0))))
253(genfscon proc "/sys/kernel/poweroff_cmd" (u object_r usermodehelper ((s0) (s0))))
254(genfscon proc "/sys/kernel/domainname" (u object_r proc_hostname ((s0) (s0))))
255(genfscon proc "/sys/kernel/hung_task_" (u object_r proc_hung_task ((s0) (s0))))
256(genfscon proc "/sys/fs/pipe-max-size" (u object_r proc_pipe_conf ((s0) (s0))))
257(genfscon proc "/sys/fs/suid_dumpable" (u object_r proc_security ((s0) (s0))))
258(genfscon proc "/sys/vm/max_map_count" (u object_r proc_max_map_count ((s0) (s0))))
259(genfscon proc "/sys/vm/mmap_min_addr" (u object_r proc_security ((s0) (s0))))
260(genfscon proc "/sys/vm/mmap_rnd_bits" (u object_r proc_security ((s0) (s0))))
261(genfscon proc "/net/xt_qtaguid/ctrl" (u object_r proc_qtaguid_ctrl ((s0) (s0))))
262(genfscon proc "/sys/kernel/hostname" (u object_r proc_hostname ((s0) (s0))))
263(genfscon proc "/sys/kernel/modprobe" (u object_r usermodehelper ((s0) (s0))))
264(genfscon proc "/sys/vm/page-cluster" (u object_r proc_page_cluster ((s0) (s0))))
265(genfscon proc "/sys/kernel/hotplug" (u object_r usermodehelper ((s0) (s0))))
266(genfscon proc "/sys/kernel/pid_max" (u object_r proc_pid_max ((s0) (s0))))
267(genfscon proc "/sys/vm/drop_caches" (u object_r proc_drop_caches ((s0) (s0))))
268(genfscon proc "/sys/kernel/random" (u object_r proc_random ((s0) (s0))))
269(genfscon proc "/sys/net/core/bpf_" (u object_r proc_bpf ((s0) (s0))))
270(genfscon proc "/uid_time_in_state" (u object_r proc_uid_time_in_state ((s0) (s0))))
271(genfscon proc "/sys/kernel/sysrq" (u object_r proc_sysrq ((s0) (s0))))
272(genfscon proc "/uid_procstat/set" (u object_r proc_uid_procstat_set ((s0) (s0))))
273(genfscon proc "/device-tree/avf" (u object_r proc_dt_avf ((s0) (s0))))
274(genfscon proc "/lowmemorykiller" (u object_r proc_lowmemorykiller ((s0) (s0))))
275(genfscon proc "/net/xt_qtaguid/" (u object_r proc_qtaguid_stat ((s0) (s0))))
276(genfscon proc "/pressure/memory" (u object_r proc_pressure_mem ((s0) (s0))))
277(genfscon proc "/sys/kernel/bpf_" (u object_r proc_bpf ((s0) (s0))))
278(genfscon proc "/cpu/alignment" (u object_r proc_cpu_alignment ((s0) (s0))))
279(genfscon proc "/sysrq-trigger" (u object_r proc_sysrq ((s0) (s0))))
280(genfscon proc "/uid_cpupower/" (u object_r proc_uid_cpupower ((s0) (s0))))
281(genfscon proc "/pagetypeinfo" (u object_r proc_pagetypeinfo ((s0) (s0))))
282(genfscon proc "/pressure/cpu" (u object_r proc_pressure_cpu ((s0) (s0))))
283(genfscon proc "/uid_io/stats" (u object_r proc_uid_io_stats ((s0) (s0))))
284(genfscon proc "/vendor_sched" (u object_r proc_vendor_sched ((s0) (s0))))
285(genfscon proc "/filesystems" (u object_r proc_filesystems ((s0) (s0))))
286(genfscon proc "/pressure/io" (u object_r proc_pressure_io ((s0) (s0))))
287(genfscon proc "/sys/abi/swp" (u object_r proc_abi ((s0) (s0))))
288(genfscon proc "/timer_stats" (u object_r proc_timer ((s0) (s0))))
289(genfscon proc "/tty/drivers" (u object_r proc_tty_drivers ((s0) (s0))))
290(genfscon proc "/vmallocinfo" (u object_r proc_vmallocinfo ((s0) (s0))))
291(genfscon proc "/bootconfig" (u object_r proc_bootconfig ((s0) (s0))))
292(genfscon proc "/interrupts" (u object_r proc_interrupts ((s0) (s0))))
293(genfscon proc "/kpageflags" (u object_r proc_kpageflags ((s0) (s0))))
294(genfscon proc "/timer_list" (u object_r proc_timer ((s0) (s0))))
295(genfscon proc "/buddyinfo" (u object_r proc_buddyinfo ((s0) (s0))))
296(genfscon proc "/config.gz" (u object_r config_gz ((s0) (s0))))
297(genfscon proc "/diskstats" (u object_r proc_diskstats ((s0) (s0))))
298(genfscon proc "/kallsyms" (u object_r proc_kallsyms ((s0) (s0))))
299(genfscon proc "/slabinfo" (u object_r proc_slabinfo ((s0) (s0))))
300(genfscon proc "/softirqs" (u object_r proc_timer ((s0) (s0))))
301(genfscon proc "/zoneinfo" (u object_r proc_zoneinfo ((s0) (s0))))
302(genfscon proc "/cmdline" (u object_r proc_cmdline ((s0) (s0))))
303(genfscon proc "/loadavg" (u object_r proc_loadavg ((s0) (s0))))
304(genfscon proc "/meminfo" (u object_r proc_meminfo ((s0) (s0))))
305(genfscon proc "/modules" (u object_r proc_modules ((s0) (s0))))
306(genfscon proc "/net/tcp" (u object_r proc_net_tcp_udp ((s0) (s0))))
307(genfscon proc "/net/udp" (u object_r proc_net_tcp_udp ((s0) (s0))))
308(genfscon proc "/cpuinfo" (u object_r proc_cpuinfo ((s0) (s0))))
309(genfscon proc "/sys/net" (u object_r proc_net ((s0) (s0))))
310(genfscon proc "/version" (u object_r proc_version ((s0) (s0))))
311(genfscon proc "/asound" (u object_r proc_asound ((s0) (s0))))
312(genfscon proc "/mounts" (u object_r proc_mounts ((s0) (s0))))
313(genfscon proc "/uptime" (u object_r proc_uptime ((s0) (s0))))
314(genfscon proc "/vmstat" (u object_r proc_vmstat ((s0) (s0))))
315(genfscon proc "/iomem" (u object_r proc_iomem ((s0) (s0))))
316(genfscon proc "/locks" (u object_r proc_locks ((s0) (s0))))
317(genfscon proc "/swaps" (u object_r proc_swaps ((s0) (s0))))
318(genfscon proc "/keys" (u object_r proc_keys ((s0) (s0))))
319(genfscon proc "/kmsg" (u object_r proc_kmsg ((s0) (s0))))
320(genfscon proc "/misc" (u object_r proc_misc ((s0) (s0))))
321(genfscon proc "/stat" (u object_r proc_stat ((s0) (s0))))
322(genfscon proc "/uid/" (u object_r proc_uid_time_in_state ((s0) (s0))))
323(genfscon proc "/net" (u object_r proc_net ((s0) (s0))))
324(genfscon proc "/" (u object_r proc ((s0) (s0))))
325(genfscon pstore "/" (u object_r pstorefs ((s0) (s0))))
326(genfscon rootfs "/" (u object_r rootfs ((s0) (s0))))
327(genfscon sdcardfs "/" (u object_r sdcardfs ((s0) (s0))))
328(genfscon securityfs "/" (u object_r securityfs ((s0) (s0))))
329(genfscon selinuxfs "/" (u object_r selinuxfs ((s0) (s0))))
330(genfscon sysfs "/module/dm_verity/parameters/prefetch_cluster" (u object_r sysfs_dm_verity ((s0) (s0))))
331(genfscon sysfs "/devices/virtual/timed_output/vibrator/enable" (u object_r sysfs_vibrator ((s0) (s0))))
332(genfscon sysfs "/firmware/devicetree/base/firmware/android" (u object_r sysfs_dt_firmware_android ((s0) (s0))))
333(genfscon sysfs "/devices/platform/nfc-power/nfc_power" (u object_r sysfs_nfc_power_writable ((s0) (s0))))
334(genfscon sysfs "/devices/virtual/block/zram0/uevent" (u object_r sysfs_zram_uevent ((s0) (s0))))
335(genfscon sysfs "/devices/virtual/block/zram1/uevent" (u object_r sysfs_zram_uevent ((s0) (s0))))
336(genfscon sysfs "/devices/virtual/misc/hw_random" (u object_r sysfs_hwrandom ((s0) (s0))))
337(genfscon sysfs "/kernel/mm/transparent_hugepage" (u object_r sysfs_transparent_hugepage ((s0) (s0))))
338(genfscon sysfs "/module/wlan/parameters/fwpath" (u object_r sysfs_wlan_fwpath ((s0) (s0))))
339(genfscon sysfs "/firmware/devicetree/base/avf" (u object_r sysfs_dt_avf ((s0) (s0))))
340(genfscon sysfs "/devices/virtual/android_usb" (u object_r sysfs_android_usb ((s0) (s0))))
341(genfscon sysfs "/devices/virtual/block/zram0" (u object_r sysfs_zram ((s0) (s0))))
342(genfscon sysfs "/devices/virtual/block/zram1" (u object_r sysfs_zram ((s0) (s0))))
343(genfscon sysfs "/fs/incremental-fs/instances" (u object_r sysfs_fs_incfs_metrics ((s0) (s0))))
344(genfscon sysfs "/module/tcp_cubic/parameters" (u object_r sysfs_net ((s0) (s0))))
345(genfscon sysfs "/class/rfkill/rfkill0/state" (u object_r sysfs_bluetooth_writable ((s0) (s0))))
346(genfscon sysfs "/class/rfkill/rfkill1/state" (u object_r sysfs_bluetooth_writable ((s0) (s0))))
347(genfscon sysfs "/class/rfkill/rfkill2/state" (u object_r sysfs_bluetooth_writable ((s0) (s0))))
348(genfscon sysfs "/class/rfkill/rfkill3/state" (u object_r sysfs_bluetooth_writable ((s0) (s0))))
349(genfscon sysfs "/devices/virtual/block/loop" (u object_r sysfs_loop ((s0) (s0))))
350(genfscon sysfs "/fs/fuse/bpf_prog_type_fuse" (u object_r sysfs_fs_fuse_bpf ((s0) (s0))))
351(genfscon sysfs "/fs/incremental-fs/features" (u object_r sysfs_fs_incfs_features ((s0) (s0))))
352(genfscon sysfs "/devices/virtual/block/dm-" (u object_r sysfs_dm ((s0) (s0))))
353(genfscon sysfs "/kernel/mm/lru_gen/enabled" (u object_r sysfs_lru_gen_enabled ((s0) (s0))))
354(genfscon sysfs "/devices/virtual/misc/uhid" (u object_r sysfs_uhid ((s0) (s0))))
355(genfscon sysfs "/kernel/memory_state_time" (u object_r sysfs_power ((s0) (s0))))
356(genfscon sysfs "/devices/virtual/block/" (u object_r sysfs_devices_block ((s0) (s0))))
357(genfscon sysfs "/devices/virtual/switch" (u object_r sysfs_switch ((s0) (s0))))
358(genfscon sysfs "/devices/virtual/wakeup" (u object_r sysfs_wakeup ((s0) (s0))))
359(genfscon sysfs "/module/lowmemorykiller" (u object_r sysfs_lowmemorykiller ((s0) (s0))))
360(genfscon sysfs "/power/sync_on_suspend" (u object_r sysfs_sync_on_suspend ((s0) (s0))))
361(genfscon sysfs "/kernel/wakeup_reasons" (u object_r sysfs_wakeup_reasons ((s0) (s0))))
362(genfscon sysfs "/kernel/dmabuf/buffers" (u object_r sysfs_dmabuf_stats ((s0) (s0))))
363(genfscon sysfs "/kernel/uevent_helper" (u object_r sysfs_usermodehelper ((s0) (s0))))
364(genfscon sysfs "/devices/virtual/net" (u object_r sysfs_net ((s0) (s0))))
365(genfscon sysfs "/power/suspend_stats" (u object_r sysfs_suspend_stats ((s0) (s0))))
366(genfscon sysfs "/kernel/vendor_sched" (u object_r sysfs_vendor_sched ((s0) (s0))))
367(genfscon sysfs "/devices/system/cpu" (u object_r sysfs_devices_system_cpu ((s0) (s0))))
368(genfscon sysfs "/power/wakeup_count" (u object_r sysfs_power ((s0) (s0))))
369(genfscon sysfs "/class/android_usb" (u object_r sysfs_android_usb ((s0) (s0))))
370(genfscon sysfs "/power/wake_unlock" (u object_r sysfs_wake_lock ((s0) (s0))))
371(genfscon sysfs "/fs/ext4/features" (u object_r sysfs_fs_ext4_features ((s0) (s0))))
372(genfscon sysfs "/fs/fuse/features" (u object_r sysfs_fs_fuse_features ((s0) (s0))))
373(genfscon sysfs "/power/autosleep" (u object_r sysfs_power ((s0) (s0))))
374(genfscon sysfs "/power/wake_lock" (u object_r sysfs_wake_lock ((s0) (s0))))
375(genfscon sysfs "/kernel/dma_heap" (u object_r sysfs_dma_heap ((s0) (s0))))
376(genfscon sysfs "/devices/cs_etm" (u object_r sysfs_devices_cs_etm ((s0) (s0))))
377(genfscon sysfs "/devices/uprobe" (u object_r sysfs_uprobe ((s0) (s0))))
378(genfscon sysfs "/class/extcon" (u object_r sysfs_extcon ((s0) (s0))))
379(genfscon sysfs "/class/switch" (u object_r sysfs_switch ((s0) (s0))))
380(genfscon sysfs "/class/wakeup" (u object_r sysfs_wakeup ((s0) (s0))))
381(genfscon sysfs "/kernel/notes" (u object_r sysfs_kernel_notes ((s0) (s0))))
382(genfscon sysfs "/power/state" (u object_r sysfs_power ((s0) (s0))))
383(genfscon sysfs "/kernel/ipv4" (u object_r sysfs_ipv4 ((s0) (s0))))
384(genfscon sysfs "/class/leds" (u object_r sysfs_leds ((s0) (s0))))
385(genfscon sysfs "/kernel/ion" (u object_r sysfs_ion ((s0) (s0))))
386(genfscon sysfs "/class/gpu" (u object_r sysfs_gpu ((s0) (s0))))
387(genfscon sysfs "/class/net" (u object_r sysfs_net ((s0) (s0))))
388(genfscon sysfs "/class/rtc" (u object_r sysfs_rtc ((s0) (s0))))
389(genfscon sysfs "/fs/f2fs" (u object_r sysfs_fs_f2fs ((s0) (s0))))
390(genfscon sysfs "/" (u object_r sysfs ((s0) (s0))))
391(genfscon tracefs "/events/filemap/mm_filemap_delete_from_page_cache/" (u object_r debugfs_tracing ((s0) (s0))))
392(genfscon tracefs "/events/vmscan/mm_vmscan_direct_reclaim_begin/" (u object_r debugfs_tracing ((s0) (s0))))
393(genfscon tracefs "/events/filemap/mm_filemap_add_to_page_cache/" (u object_r debugfs_tracing ((s0) (s0))))
394(genfscon tracefs "/events/vmscan/mm_vmscan_direct_reclaim_end/" (u object_r debugfs_tracing ((s0) (s0))))
395(genfscon tracefs "/events/binder/binder_transaction_alloc_buf/" (u object_r debugfs_tracing ((s0) (s0))))
396(genfscon tracefs "/events/binder/binder_transaction_received/" (u object_r debugfs_tracing ((s0) (s0))))
397(genfscon tracefs "/events/ext4/ext4_es_lookup_extent_enter/" (u object_r debugfs_tracing ((s0) (s0))))
398(genfscon tracefs "/events/ext4/ext4_es_lookup_extent_exit/" (u object_r debugfs_tracing ((s0) (s0))))
399(genfscon tracefs "/events/synthetic/suspend_resume_minimal" (u object_r debugfs_tracing ((s0) (s0))))
400(genfscon tracefs "/events/vmscan/mm_vmscan_kswapd_sleep/" (u object_r debugfs_tracing ((s0) (s0))))
401(genfscon tracefs "/events/vmscan/mm_vmscan_kswapd_wake/" (u object_r debugfs_tracing ((s0) (s0))))
402(genfscon tracefs "/events/synthetic/rss_stat_throttled" (u object_r debugfs_tracing ((s0) (s0))))
403(genfscon tracefs "/events/thermal/thermal_temperature/" (u object_r debugfs_tracing ((s0) (s0))))
404(genfscon tracefs "/events/sched/sched_blocked_reason/" (u object_r debugfs_tracing ((s0) (s0))))
405(genfscon tracefs "/events/power/cpu_frequency_limits/" (u object_r debugfs_tracing ((s0) (s0))))
406(genfscon tracefs "/events/binder/binder_set_priority/" (u object_r debugfs_tracing ((s0) (s0))))
407(genfscon tracefs "/events/f2fs/f2fs_sync_file_enter/" (u object_r debugfs_tracing ((s0) (s0))))
408(genfscon tracefs "/events/ext4/ext4_sync_file_enter/" (u object_r debugfs_tracing ((s0) (s0))))
409(genfscon tracefs "/events/binder/binder_transaction/" (u object_r debugfs_tracing ((s0) (s0))))
410(genfscon tracefs "/events/f2fs/f2fs_get_data_block/" (u object_r debugfs_tracing ((s0) (s0))))
411(genfscon tracefs "/events/f2fs/f2fs_sync_file_exit/" (u object_r debugfs_tracing ((s0) (s0))))
412(genfscon tracefs "/events/ext4/ext4_da_write_begin/" (u object_r debugfs_tracing ((s0) (s0))))
413(genfscon tracefs "/events/ext4/ext4_sync_file_exit/" (u object_r debugfs_tracing ((s0) (s0))))
414(genfscon tracefs "/events/sched/sched_process_exit/" (u object_r debugfs_tracing ((s0) (s0))))
415(genfscon tracefs "/events/sched/sched_process_free/" (u object_r debugfs_tracing ((s0) (s0))))
416(genfscon tracefs "/events/mm_event/mm_event_record/" (u object_r debugfs_tracing ((s0) (s0))))
417(genfscon tracefs "/events/oom/oom_score_adj_update/" (u object_r debugfs_tracing ((s0) (s0))))
418(genfscon tracefs "/events/block/block_rq_complete/" (u object_r debugfs_tracing ((s0) (s0))))
419(genfscon tracefs "/events/sched/sched_cpu_hotplug/" (u object_r debugfs_tracing ((s0) (s0))))
420(genfscon tracefs "/events/ext4/ext4_da_write_end/" (u object_r debugfs_tracing ((s0) (s0))))
421(genfscon tracefs "/events/sched/sched_wakeup_new/" (u object_r debugfs_tracing ((s0) (s0))))
422(genfscon tracefs "/events/sched/sched_pi_setprio/" (u object_r debugfs_tracing ((s0) (s0))))
423(genfscon tracefs "/events/f2fs/f2fs_write_begin/" (u object_r debugfs_tracing ((s0) (s0))))
424(genfscon tracefs "/events/power/gpu_work_period/" (u object_r debugfs_tracing ((s0) (s0))))
425(genfscon tracefs "/events/binder/binder_command/" (u object_r debugfs_tracing ((s0) (s0))))
426(genfscon tracefs "/events/ext4/ext4_load_inode/" (u object_r debugfs_tracing ((s0) (s0))))
427(genfscon tracefs "/events/block/block_rq_issue/" (u object_r debugfs_tracing ((s0) (s0))))
428(genfscon tracefs "/events/power/clock_set_rate/" (u object_r debugfs_tracing ((s0) (s0))))
429(genfscon tracefs "/events/power/suspend_resume/" (u object_r debugfs_tracing ((s0) (s0))))
430(genfscon tracefs "/events/binder/binder_locked/" (u object_r debugfs_tracing ((s0) (s0))))
431(genfscon tracefs "/events/binder/binder_unlock/" (u object_r debugfs_tracing ((s0) (s0))))
432(genfscon tracefs "/events/binder/binder_return/" (u object_r debugfs_tracing ((s0) (s0))))
433(genfscon tracefs "/events/kmem/ion_heap_shrink/" (u object_r debugfs_tracing ((s0) (s0))))
434(genfscon tracefs "/events/gpu_mem/gpu_mem_total" (u object_r debugfs_tracing ((s0) (s0))))
435(genfscon tracefs "/events/f2fs/f2fs_write_end/" (u object_r debugfs_tracing ((s0) (s0))))
436(genfscon tracefs "/events/power/cpu_frequency/" (u object_r debugfs_tracing ((s0) (s0))))
437(genfscon tracefs "/events/power/clock_disable/" (u object_r debugfs_tracing ((s0) (s0))))
438(genfscon tracefs "/events/power/gpu_frequency/" (u object_r debugfs_tracing ((s0) (s0))))
439(genfscon tracefs "/events/cpufreq_interactive/" (u object_r debugfs_tracing ((s0) (s0))))
440(genfscon tracefs "/events/thermal/cdev_update/" (u object_r debugfs_tracing ((s0) (s0))))
441(genfscon tracefs "/events/sched/sched_switch/" (u object_r debugfs_tracing ((s0) (s0))))
442(genfscon tracefs "/events/sched/sched_wakeup/" (u object_r debugfs_tracing ((s0) (s0))))
443(genfscon tracefs "/events/sched/sched_waking/" (u object_r debugfs_tracing ((s0) (s0))))
444(genfscon tracefs "/events/power/clock_enable/" (u object_r debugfs_tracing ((s0) (s0))))
445(genfscon tracefs "/events/binder/binder_lock/" (u object_r debugfs_tracing ((s0) (s0))))
446(genfscon tracefs "/events/kmem/ion_heap_grow/" (u object_r debugfs_tracing ((s0) (s0))))
447(genfscon tracefs "/events/task/task_newtask/" (u object_r debugfs_tracing ((s0) (s0))))
448(genfscon tracefs "/events/cpuhp/cpuhp_enter/" (u object_r debugfs_tracing ((s0) (s0))))
449(genfscon tracefs "/events/cpuhp/cpuhp_pause/" (u object_r debugfs_tracing ((s0) (s0))))
450(genfscon tracefs "/events/task/task_rename/" (u object_r debugfs_tracing ((s0) (s0))))
451(genfscon tracefs "/events/cpuhp/cpuhp_exit/" (u object_r debugfs_tracing ((s0) (s0))))
452(genfscon tracefs "/events/clk/clk_set_rate/" (u object_r debugfs_tracing ((s0) (s0))))
453(genfscon tracefs "/events/lowmemorykiller/" (u object_r debugfs_tracing ((s0) (s0))))
454(genfscon tracefs "/events/oom/mark_victim/" (u object_r debugfs_tracing ((s0) (s0))))
455(genfscon tracefs "/events/clk/clk_disable/" (u object_r debugfs_tracing ((s0) (s0))))
456(genfscon tracefs "/instances/bootreceiver" (u object_r debugfs_bootreceiver_tracing ((s0) (s0))))
457(genfscon tracefs "/events/f2fs/f2fs_iget/" (u object_r debugfs_tracing ((s0) (s0))))
458(genfscon tracefs "/events/power/cpu_idle/" (u object_r debugfs_tracing ((s0) (s0))))
459(genfscon tracefs "/events/clk/clk_enable/" (u object_r debugfs_tracing ((s0) (s0))))
460(genfscon tracefs "/events/kmem/rss_stat/" (u object_r debugfs_tracing ((s0) (s0))))
461(genfscon tracefs "/events/ion/ion_stat/" (u object_r debugfs_tracing ((s0) (s0))))
462(genfscon tracefs "/events/ftrace/print/" (u object_r debugfs_tracing ((s0) (s0))))
463(genfscon tracefs "/instances/mm_events" (u object_r debugfs_mm_events_tracing ((s0) (s0))))
464(genfscon tracefs "/options/record-tgid" (u object_r debugfs_tracing ((s0) (s0))))
465(genfscon tracefs "/saved_cmdlines_size" (u object_r debugfs_tracing ((s0) (s0))))
466(genfscon tracefs "/events/header_page" (u object_r debugfs_tracing ((s0) (s0))))
467(genfscon tracefs "/options/print-tgid" (u object_r debugfs_tracing ((s0) (s0))))
468(genfscon tracefs "/options/overwrite" (u object_r debugfs_tracing ((s0) (s0))))
469(genfscon tracefs "/events/dma_fence/" (u object_r debugfs_tracing ((s0) (s0))))
470(genfscon tracefs "/synthetic_events" (u object_r debugfs_tracing ((s0) (s0))))
471(genfscon tracefs "/instances/wifi" (u object_r debugfs_wifi_tracing ((s0) (s0))))
472(genfscon tracefs "/printk_formats" (u object_r debugfs_tracing_printk_formats ((s0) (s0))))
473(genfscon tracefs "/buffer_size_kb" (u object_r debugfs_tracing ((s0) (s0))))
474(genfscon tracefs "/events/cgroup/" (u object_r debugfs_tracing ((s0) (s0))))
475(genfscon tracefs "/events/fence/" (u object_r debugfs_tracing ((s0) (s0))))
476(genfscon tracefs "/trace_marker" (u object_r debugfs_trace_marker ((s0) (s0))))
477(genfscon tracefs "/events/sync/" (u object_r debugfs_tracing ((s0) (s0))))
478(genfscon tracefs "/per_cpu/cpu" (u object_r debugfs_tracing ((s0) (s0))))
479(genfscon tracefs "/trace_clock" (u object_r debugfs_tracing ((s0) (s0))))
480(genfscon tracefs "/events/ipi/" (u object_r debugfs_tracing ((s0) (s0))))
481(genfscon tracefs "/events/irq/" (u object_r debugfs_tracing ((s0) (s0))))
482(genfscon tracefs "/tracing_on" (u object_r debugfs_tracing ((s0) (s0))))
483(genfscon tracefs "/instances" (u object_r debugfs_tracing_instances ((s0) (s0))))
484(genfscon tracefs "/trace" (u object_r debugfs_tracing ((s0) (s0))))
485(genfscon tracefs "/hyp" (u object_r debugfs_tracing ((s0) (s0))))
486(genfscon tracefs "/" (u object_r debugfs_tracing_debug ((s0) (s0))))
487(genfscon usbfs "/" (u object_r usbfs ((s0) (s0))))
488(genfscon vfat "/" (u object_r vfat ((s0) (s0))))
489(common cap (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap ))
490(common cap2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon ))
491(common ipc (create destroy getattr setattr read write associate unix_read unix_write ))
492(common socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind ))
493(common file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads ))
494(typealias rs_data_file)
495(typealiasactual rs_data_file app_exec_data_file)
496(class security (compute_av compute_create compute_member check_context load_policy compute_relabel compute_user setenforce setbool setsecparam setcheckreqprot read_policy validate_trans ))
497(class process (fork transition sigchld sigkill sigstop signull signal ptrace getsched setsched getsession getpgid setpgid getcap setcap share getattr setexec setfscreate noatsecure siginh setrlimit rlimitinh dyntransition setcurrent execmem execstack execheap setkeycreate setsockcreate getrlimit ))
498(mlsconstrain (process (sigkill sigstop signal ptrace setsched setpgid setcap share setrlimit)) (or (eq l1 l2) (eq t1 mlstrustedsubject)))
499(mlsconstrain (process (ptrace getsched getsession getpgid getcap share getattr)) (or (dom l1 l2) (eq t1 mlstrustedsubject)))
500(mlsconstrain (process (transition dyntransition)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
501(class system (ipc_info syslog_read syslog_mod syslog_console module_request module_load ))
502(class capability ())
503(classcommon capability cap)
504(class filesystem (mount remount unmount getattr relabelfrom relabelto associate quotamod quotaget watch ))
505(class file (execute_no_trans entrypoint ))
506(classcommon file file)
507(mlsconstrain (file (write setattr append unlink link rename)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
508(mlsconstrain (file (read getattr execute)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
509(mlsconstrain (file (setattr unlink link rename open)) (or (or (and (neq t2 app_data_file_type) (neq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)))
510(mlsconstrain (file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
511(class anon_inode ())
512(classcommon anon_inode file)
513(mlsconstrain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute open execmod)) (eq l1 l2))
514(class dir (add_name remove_name reparent search rmdir ))
515(classcommon dir file)
516(mlsconstrain (dir (write setattr rename add_name remove_name reparent rmdir)) (or (or (or (eq t2 app_data_file_type) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
517(mlsconstrain (dir (read getattr search)) (or (or (or (or (eq t2 app_data_file_type) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)) (and (eq t1 mlsvendorcompat) (or (eq t2 system_data_file) (eq t2 user_profile_root_file)))))
518(mlsconstrain (dir (getattr setattr rename open add_name remove_name reparent search rmdir)) (or (or (neq t2 app_data_file_type) (dom l1 l2)) (eq t1 mlstrustedsubject)))
519(mlsconstrain (dir (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
520(class fd (use ))
521(class lnk_file ())
522(classcommon lnk_file file)
523(mlsconstrain (lnk_file (write setattr append unlink link rename)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
524(mlsconstrain (lnk_file (read getattr execute)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
525(mlsconstrain (lnk_file (read setattr unlink link rename open)) (or (or (and (neq t2 privapp_data_file) (neq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)))
526(mlsconstrain (lnk_file (read setattr unlink link rename open)) (or (or (or (neq t2 app_data_file_type) (eq t2 privapp_data_file)) (eq l1 l2)) (eq t1 mlstrustedsubject)))
527(mlsconstrain (lnk_file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
528(class chr_file (execute_no_trans entrypoint ))
529(classcommon chr_file file)
530(mlsconstrain (chr_file (write setattr append unlink link rename)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
531(mlsconstrain (chr_file (read getattr execute)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
532(mlsconstrain (chr_file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
533(class blk_file ())
534(classcommon blk_file file)
535(mlsconstrain (blk_file (write setattr append unlink link rename)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
536(mlsconstrain (blk_file (read getattr execute)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
537(mlsconstrain (blk_file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
538(class sock_file ())
539(classcommon sock_file file)
540(mlsconstrain (sock_file (write setattr append unlink link rename)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (eq l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
541(mlsconstrain (sock_file (read getattr execute)) (or (or (or (or (eq t2 app_data_file_type) (eq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)))
542(mlsconstrain (sock_file (setattr unlink link rename open)) (or (or (and (neq t2 app_data_file_type) (neq t2 appdomain_tmpfs)) (dom l1 l2)) (eq t1 mlstrustedsubject)))
543(mlsconstrain (sock_file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
544(class fifo_file ())
545(classcommon fifo_file file)
546(mlsconstrain (fifo_file (write setattr append unlink link rename)) (or (or (or (eq l1 l2) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)) (eq t2 domain)))
547(mlsconstrain (fifo_file (read getattr)) (or (or (or (dom l1 l2) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedobject)) (eq t2 domain)))
548(mlsconstrain (fifo_file (create relabelfrom relabelto)) (and (eq l2 h2) (or (eq l1 l2) (eq t1 mlstrustedsubject))))
549(class socket ())
550(classcommon socket socket)
551(mlsconstrain (socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
552(class tcp_socket (node_bind name_connect ))
553(classcommon tcp_socket socket)
554(mlsconstrain (tcp_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
555(class udp_socket (node_bind ))
556(classcommon udp_socket socket)
557(mlsconstrain (udp_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
558(class rawip_socket (node_bind ))
559(classcommon rawip_socket socket)
560(mlsconstrain (rawip_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
561(class node (recvfrom sendto ))
562(class netif (ingress egress ))
563(class netlink_socket ())
564(classcommon netlink_socket socket)
565(mlsconstrain (netlink_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
566(class packet_socket ())
567(classcommon packet_socket socket)
568(mlsconstrain (packet_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
569(class key_socket ())
570(classcommon key_socket socket)
571(mlsconstrain (key_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
572(class unix_stream_socket (connectto ))
573(classcommon unix_stream_socket socket)
574(mlsconstrain (unix_stream_socket (connectto)) (or (or (eq l1 l2) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedsubject)))
575(mlsconstrain (unix_stream_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
576(class unix_dgram_socket ())
577(classcommon unix_dgram_socket socket)
578(mlsconstrain (unix_dgram_socket (sendto)) (or (or (eq l1 l2) (eq t1 mlstrustedsubject)) (eq t2 mlstrustedsubject)))
579(mlsconstrain (unix_dgram_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
580(class sem ())
581(classcommon sem ipc)
582(class msg (send receive ))
583(class msgq (enqueue ))
584(classcommon msgq ipc)
585(class shm (lock ))
586(classcommon shm ipc)
587(class ipc ())
588(classcommon ipc ipc)
589(class netlink_route_socket (nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh ))
590(classcommon netlink_route_socket socket)
591(mlsconstrain (netlink_route_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
592(class netlink_tcpdiag_socket (nlmsg_read nlmsg_write ))
593(classcommon netlink_tcpdiag_socket socket)
594(mlsconstrain (netlink_tcpdiag_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
595(class netlink_nflog_socket ())
596(classcommon netlink_nflog_socket socket)
597(mlsconstrain (netlink_nflog_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
598(class netlink_xfrm_socket (nlmsg_read nlmsg_write ))
599(classcommon netlink_xfrm_socket socket)
600(mlsconstrain (netlink_xfrm_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
601(class netlink_selinux_socket ())
602(classcommon netlink_selinux_socket socket)
603(mlsconstrain (netlink_selinux_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
604(class netlink_audit_socket (nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit ))
605(classcommon netlink_audit_socket socket)
606(mlsconstrain (netlink_audit_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
607(class netlink_dnrt_socket ())
608(classcommon netlink_dnrt_socket socket)
609(mlsconstrain (netlink_dnrt_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
610(class association (sendto recvfrom setcontext polmatch ))
611(class netlink_kobject_uevent_socket ())
612(classcommon netlink_kobject_uevent_socket socket)
613(mlsconstrain (netlink_kobject_uevent_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
614(class appletalk_socket ())
615(classcommon appletalk_socket socket)
616(mlsconstrain (appletalk_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
617(class packet (send recv relabelto forward_in forward_out ))
618(class key (view read write search link setattr create ))
619(class dccp_socket (node_bind name_connect ))
620(classcommon dccp_socket socket)
621(class memprotect (mmap_zero ))
622(class peer (recv ))
623(class capability2 ())
624(classcommon capability2 cap2)
625(class kernel_service (use_as_override create_files_as ))
626(class tun_socket (attach_queue ))
627(classcommon tun_socket socket)
628(mlsconstrain (tun_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
629(class binder (impersonate call set_context_mgr transfer ))
630(class netlink_iscsi_socket ())
631(classcommon netlink_iscsi_socket socket)
632(mlsconstrain (netlink_iscsi_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
633(class netlink_fib_lookup_socket ())
634(classcommon netlink_fib_lookup_socket socket)
635(mlsconstrain (netlink_fib_lookup_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
636(class netlink_connector_socket ())
637(classcommon netlink_connector_socket socket)
638(mlsconstrain (netlink_connector_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
639(class netlink_netfilter_socket ())
640(classcommon netlink_netfilter_socket socket)
641(mlsconstrain (netlink_netfilter_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
642(class netlink_generic_socket ())
643(classcommon netlink_generic_socket socket)
644(mlsconstrain (netlink_generic_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
645(class netlink_scsitransport_socket ())
646(classcommon netlink_scsitransport_socket socket)
647(mlsconstrain (netlink_scsitransport_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
648(class netlink_rdma_socket ())
649(classcommon netlink_rdma_socket socket)
650(mlsconstrain (netlink_rdma_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
651(class netlink_crypto_socket ())
652(classcommon netlink_crypto_socket socket)
653(mlsconstrain (netlink_crypto_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
654(class infiniband_pkey (access ))
655(class infiniband_endport (manage_subnet ))
656(class cap_userns ())
657(classcommon cap_userns cap)
658(class cap2_userns ())
659(classcommon cap2_userns cap2)
660(class sctp_socket (node_bind name_connect association ))
661(classcommon sctp_socket socket)
662(mlsconstrain (sctp_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
663(class icmp_socket (node_bind ))
664(classcommon icmp_socket socket)
665(mlsconstrain (icmp_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
666(class ax25_socket ())
667(classcommon ax25_socket socket)
668(mlsconstrain (ax25_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
669(class ipx_socket ())
670(classcommon ipx_socket socket)
671(mlsconstrain (ipx_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
672(class netrom_socket ())
673(classcommon netrom_socket socket)
674(mlsconstrain (netrom_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
675(class atmpvc_socket ())
676(classcommon atmpvc_socket socket)
677(mlsconstrain (atmpvc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
678(class x25_socket ())
679(classcommon x25_socket socket)
680(mlsconstrain (x25_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
681(class rose_socket ())
682(classcommon rose_socket socket)
683(mlsconstrain (rose_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
684(class decnet_socket ())
685(classcommon decnet_socket socket)
686(mlsconstrain (decnet_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
687(class atmsvc_socket ())
688(classcommon atmsvc_socket socket)
689(mlsconstrain (atmsvc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
690(class rds_socket ())
691(classcommon rds_socket socket)
692(mlsconstrain (rds_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
693(class irda_socket ())
694(classcommon irda_socket socket)
695(mlsconstrain (irda_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
696(class pppox_socket ())
697(classcommon pppox_socket socket)
698(mlsconstrain (pppox_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
699(class llc_socket ())
700(classcommon llc_socket socket)
701(mlsconstrain (llc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
702(class can_socket ())
703(classcommon can_socket socket)
704(mlsconstrain (can_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
705(class tipc_socket ())
706(classcommon tipc_socket socket)
707(mlsconstrain (tipc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
708(class bluetooth_socket ())
709(classcommon bluetooth_socket socket)
710(mlsconstrain (bluetooth_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
711(class iucv_socket ())
712(classcommon iucv_socket socket)
713(mlsconstrain (iucv_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
714(class rxrpc_socket ())
715(classcommon rxrpc_socket socket)
716(mlsconstrain (rxrpc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
717(class isdn_socket ())
718(classcommon isdn_socket socket)
719(mlsconstrain (isdn_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
720(class phonet_socket ())
721(classcommon phonet_socket socket)
722(mlsconstrain (phonet_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
723(class ieee802154_socket ())
724(classcommon ieee802154_socket socket)
725(mlsconstrain (ieee802154_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
726(class caif_socket ())
727(classcommon caif_socket socket)
728(mlsconstrain (caif_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
729(class alg_socket ())
730(classcommon alg_socket socket)
731(mlsconstrain (alg_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
732(class nfc_socket ())
733(classcommon nfc_socket socket)
734(mlsconstrain (nfc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
735(class vsock_socket ())
736(classcommon vsock_socket socket)
737(mlsconstrain (vsock_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
738(class kcm_socket ())
739(classcommon kcm_socket socket)
740(mlsconstrain (kcm_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
741(class qipcrtr_socket ())
742(classcommon qipcrtr_socket socket)
743(mlsconstrain (qipcrtr_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
744(class smc_socket ())
745(classcommon smc_socket socket)
746(mlsconstrain (smc_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
747(class process2 (nnp_transition nosuid_transition ))
748(class bpf (map_create map_read map_write prog_load prog_run ))
749(class xdp_socket ())
750(classcommon xdp_socket socket)
751(mlsconstrain (xdp_socket (create relabelfrom relabelto)) (or (and (eq h1 h2) (eq l1 l2)) (eq t1 mlstrustedsubject)))
752(class perf_event (open cpu kernel tracepoint read write ))
753(class io_uring (override_creds sqpoll cmd ))
754(class lockdown (integrity confidentiality ))
755(class property_service (set ))
756(class service_manager (add find list ))
757(class hwservice_manager (add find list ))
758(class keystore_key (get_state get insert delete exist list reset password lock unlock is_empty sign verify grant duplicate clear_uid add_auth user_changed gen_unique_id ))
759(class keystore2 (add_auth change_password change_user clear_ns clear_uid delete_all_keys early_boot_ended get_attestation_key get_auth_token get_last_auth_time get_state list lock pull_metrics report_off_body reset unlock ))
760(class keystore2_key (convert_storage_key_to_ephemeral delete gen_unique_id get_info grant manage_blob rebind req_forced_op update use use_dev_id ))
761(class diced (demote demote_self derive get_attestation_chain use_seal use_sign ))
762(class drmservice (consumeRights setPlaybackStatus openDecryptSession closeDecryptSession initializeDecryptUnit decrypt finalizeDecryptUnit pread ))
763(classorder (security process system capability filesystem file anon_inode dir fd lnk_file chr_file blk_file sock_file fifo_file socket tcp_socket udp_socket rawip_socket node netif netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket sem msg msgq shm ipc netlink_route_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_dnrt_socket association netlink_kobject_uevent_socket appletalk_socket packet key dccp_socket memprotect peer capability2 kernel_service tun_socket binder netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket infiniband_pkey infiniband_endport cap_userns cap2_userns sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket smc_socket process2 bpf xdp_socket perf_event io_uring lockdown property_service service_manager hwservice_manager keystore_key keystore2 keystore2_key diced drmservice ))
764(role r)
765(roletype r domain)
766(typeattribute dev_type)
767(typeattributeset dev_type (device ashmem_device ashmem_libcutils_device audio_device binder_device hwbinder_device vndbinder_device block_device bt_device camera_device dm_device ublk_block_device dm_user_device ublk_control_device keychord_device loop_control_device loop_device pmsg_device radio_device ram_device rtc_device vd_device vold_device console_device fscklogs gpu_device graphics_device hw_random_device input_device port_device lowpan_device mtp_device nfc_device ptmx_device kmsg_device kmsg_debug_device null_device random_device secure_element_device sensors_device serial_device socket_device owntty_device tty_device video_device zero_device fuse_device iio_device ion_device dmabuf_heap_device dmabuf_system_heap_device dmabuf_system_secure_heap_device qtaguid_device watchdog_device uhid_device uio_device tun_device usbaccessory_device usb_device usb_serial_device gnss_device properties_device properties_serial property_info hidraw_device hci_attach_dev rpmsg_device root_block_device frp_block_device system_block_device recovery_block_device boot_block_device dtbo_block_device userdata_block_device zoned_block_device cache_block_device swap_block_device metadata_block_device misc_block_device super_block_device sdcard_block_device userdata_sysdev rootdisk_sysdev vfio_device tee_device kvm_device ))
768(typeattribute bpffs_type)
769(typeattributeset bpffs_type (fs_bpf fs_bpf_tethering fs_bpf_vendor fs_bpf_net_private fs_bpf_net_shared fs_bpf_netd_readonly fs_bpf_netd_shared fs_bpf_loader fs_bpf_uprobestats ))
770(typeattribute domain)
771(typeattributeset domain (adbd aidl_lazy_test_server apexd app_zygote artd atrace audioserver blkid blkid_untrusted bluetooth bootanim bootstat bpfloader bufferhubd cameraserver charger charger_vendor crash_dump credstore dhcp dnsmasq drmserver dumpstate e2fs ephemeral_app evsmanagerd extra_free_kbytes fastbootd fingerprintd flags_health_check fsck fsck_untrusted gatekeeperd gmscore_app gpuservice healthd heapprofd hwservicemanager idmap incident incident_helper incidentd init inputflinger installd isolated_app isolated_compute_app kernel keystore llkd lmkd logd logpersist mdnsd mediadrmserver mediaextractor mediametrics mediaprovider mediaserver mediaswcodec mediatranscoding modprobe mtp netd netutils_wrapper network_stack nfc otapreopt_chroot perfetto performanced platform_app postinstall ppp priv_app prng_seeder profman radio recovery recovery_persist recovery_refresh rkpdapp rs rss_hwm_reset runas runas_app sdcardd secure_element servicemanager sgdisk shared_relro shell simpleperf simpleperf_app_runner slideshow statsd su surfaceflinger system_app system_server tee tombstoned toolbox traced traced_perf traced_probes traceur_app ueventd uncrypt untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 update_engine update_verifier usbd vdc vendor_init vendor_misc_writer vendor_modprobe vendor_shell virtual_touchpad vndservicemanager vold vold_prepare_subdirs watchdogd webview_zygote wificond zygote aconfigd apex_test_prepostinstall apexd_derive_classpath art_boot auditctl automotive_display_service blank_screen boringssl_self_test vendor_boringssl_self_test canhalconfigurator clatd compos_fd_server compos_verify composd cppreopts crosvm derive_classpath derive_sdk device_as_webcam dex2oat dexopt_chroot_setup dexoptanalyzer dmesgd fsverity_init fuseblkd fuseblkd_untrusted fwk_bufferhub gki_apex_prepostinstall gsid hal_allocator_default hidl_lazy_test_server iw linkerconfig lpdumpd mediaprovider_app mediatuner migrate_legacy_obb_data misctrl mm_events mtectrl odrefresh odsign ot_daemon otapreopt_slot permissioncontroller_app postinstall_dexopt preloads_copy preopt2cachename profcollectd remount rkpd sdk_sandbox_34 sdk_sandbox_audit sdk_sandbox_next simpleperf_boot snapshotctl snapuserd stats storaged system_server_startup system_suspend uprobestats vehicle_binding_util viewcompiler virtual_camera virtualizationmanager virtualizationservice vzwomatrigger_app wait_for_keymaster ))
772(typeattribute fs_type)
773(typeattributeset fs_type (device labeledfs pipefs sockfs rootfs proc binderfs binderfs_logs binderfs_logs_proc binderfs_logs_stats binderfs_features proc_security proc_drop_caches proc_overcommit_memory proc_min_free_order_shift proc_kpageflags proc_watermark_boost_factor proc_percpu_pagelist_high_fraction usermodehelper sysfs_usermodehelper proc_qtaguid_ctrl proc_qtaguid_stat proc_bluetooth_writable proc_abi proc_asound proc_bootconfig proc_bpf proc_buddyinfo proc_cmdline proc_cpu_alignment proc_cpuinfo proc_dirty proc_diskstats proc_extra_free_kbytes proc_filesystems proc_fs_verity proc_hostname proc_hung_task proc_interrupts proc_iomem proc_kallsyms proc_keys proc_kmsg proc_loadavg proc_locks proc_lowmemorykiller proc_max_map_count proc_meminfo proc_misc proc_modules proc_mounts proc_net proc_net_tcp_udp proc_page_cluster proc_pagetypeinfo proc_panic proc_perf proc_pid_max proc_pipe_conf proc_pressure_cpu proc_pressure_io proc_pressure_mem proc_random proc_sched proc_slabinfo proc_stat proc_swaps proc_sysrq proc_timer proc_tty_drivers proc_uid_cputime_showstat proc_uid_cputime_removeuid proc_uid_io_stats proc_uid_procstat_set proc_uid_time_in_state proc_uid_concurrent_active_time proc_uid_concurrent_policy_time proc_uid_cpupower proc_uptime proc_version proc_vmallocinfo proc_vmstat proc_watermark_scale_factor proc_zoneinfo proc_vendor_sched selinuxfs fusectlfs cgroup cgroup_v2 sysfs sysfs_android_usb sysfs_uio sysfs_batteryinfo sysfs_bluetooth_writable sysfs_devfreq_cur sysfs_devfreq_dir sysfs_devices_block sysfs_dm sysfs_dm_verity sysfs_dma_heap sysfs_dmabuf_stats sysfs_dt_firmware_android sysfs_extcon sysfs_ion sysfs_ipv4 sysfs_kernel_notes sysfs_leds sysfs_loop sysfs_gpu sysfs_hwrandom sysfs_nfc_power_writable sysfs_wake_lock sysfs_net sysfs_power sysfs_rtc sysfs_suspend_stats sysfs_switch sysfs_sync_on_suspend sysfs_transparent_hugepage sysfs_lru_gen_enabled sysfs_usb sysfs_wakeup sysfs_wakeup_reasons sysfs_fs_ext4_features sysfs_fs_f2fs sysfs_fs_fuse_bpf sysfs_fs_fuse_features sysfs_fs_incfs_features sysfs_fs_incfs_metrics sysfs_vendor_sched fs_bpf fs_bpf_tethering fs_bpf_vendor configfs sysfs_devices_cs_etm sysfs_devices_system_cpu sysfs_lowmemorykiller sysfs_wlan_fwpath sysfs_vibrator sysfs_uhid sysfs_thermal sysfs_zram sysfs_zram_uevent inotify devpts tmpfs shm mqueue fuse fuseblk sdcardfs vfat exfat debugfs debugfs_kprobes debugfs_mmc debugfs_mm_events_tracing debugfs_trace_marker debugfs_tracing debugfs_tracing_debug debugfs_tracing_instances debugfs_tracing_printk_formats debugfs_wakeup_sources debugfs_wifi_tracing securityfs pstorefs functionfs oemfs usbfs binfmt_miscfs app_fusefs debugfs_bootreceiver_tracing apexd_devpts config_gz fs_bpf_net_private fs_bpf_net_shared fs_bpf_netd_readonly fs_bpf_netd_shared fs_bpf_loader fs_bpf_uprobestats debugfs_kcov sysfs_dt_avf proc_dt_avf sysfs_uprobe odsign_devpts priv_app_devpts untrusted_app_all_devpts ))
774(typeattribute contextmount_type)
775(typeattributeset contextmount_type (oemfs app_fusefs ))
776(typeattribute fusefs_type)
777(typeattributeset fusefs_type (fuse fuseblk app_fusefs ))
778(typeattribute file_type)
779(typeattributeset file_type (adbd_exec aidl_lazy_test_server_exec apexd_exec appdomain_tmpfs app_zygote_tmpfs audioserver_tmpfs bootanim_exec bootstat_exec bufferhubd_exec cameraserver_exec cameraserver_tmpfs charger_exec crash_dump_exec credstore_exec dhcp_exec dnsmasq_exec drmserver_exec drmserver_socket dumpstate_exec e2fs_exec extra_free_kbytes_exec unlabeled system_file system_asan_options_file system_event_log_tags_file system_lib_file system_bootstrap_lib_file system_group_file system_linker_exec system_linker_config_file system_passwd_file system_seccomp_policy_file system_security_cacerts_file tcpdump_exec system_zoneinfo_file cgroup_desc_file cgroup_desc_api_file vendor_cgroup_desc_file task_profiles_file task_profiles_api_file vendor_task_profiles_file art_apex_dir linkerconfig_file incremental_control_file bootanim_oem_file vendor_hal_file vendor_file vendor_app_file vendor_configs_file same_process_hal_file vndk_sp_file vendor_framework_file vendor_overlay_file vendor_public_lib_file vendor_public_framework_file vendor_microdroid_file vendor_keylayout_file vendor_keychars_file vendor_idc_file vendor_uuid_mapping_config_file vendor_vm_file vendor_vm_data_file metadata_file vold_metadata_file gsi_metadata_file gsi_public_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file metadata_bootstat_file userspace_reboot_metadata_file staged_install_file watchdog_metadata_file repair_mode_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file dev_cpu_variant runtime_event_log_tags_file logcat_exec cgroup_rc_file coredump_file system_data_root_file system_data_file system_userdir_file packages_list_file game_mode_intervention_list_file vendor_data_file vendor_userdir_file unencrypted_data_file install_data_file drm_data_file adb_data_file anr_data_file tombstone_data_file tombstone_wifi_data_file apex_data_file apk_data_file apk_tmp_file apk_private_data_file apk_private_tmp_file dalvikcache_data_file ota_data_file ota_package_file user_profile_root_file user_profile_data_file profman_dump_data_file prereboot_data_file resourcecache_data_file shell_data_file property_data_file bootchart_data_file dropbox_data_file heapdump_data_file nativetest_data_file shell_test_data_file ringtone_file preloads_data_file preloads_media_file dhcp_data_file server_configurable_flags_data_file staging_data_file vendor_apex_file vendor_apex_metadata_file shutdown_checkpoints_system_data_file mnt_media_rw_file mnt_user_file mnt_pass_through_file mnt_expand_file mnt_sdcard_file storage_file mnt_media_rw_stub_file storage_stub_file mnt_vendor_file mnt_product_file apex_mnt_dir apex_info_file postinstall_mnt_dir postinstall_file postinstall_apex_mnt_dir mirror_data_file adb_keys_file apex_system_server_data_file apex_module_data_file apex_ota_reserved_file apex_rollback_data_file appcompat_data_file audio_data_file audioserver_data_file bluetooth_data_file bluetooth_logs_data_file bootstat_data_file boottrace_data_file camera_data_file credstore_data_file gatekeeper_data_file incident_data_file keychain_data_file keystore_data_file media_data_file media_rw_data_file media_userdir_file misc_user_data_file net_data_file network_watchlist_data_file nfc_data_file nfc_logs_data_file radio_data_file recovery_data_file shared_relro_file snapshotctl_log_data_file stats_config_data_file stats_data_file systemkeys_data_file textclassifier_data_file trace_data_file vpn_data_file wifi_data_file vold_data_file tee_data_file update_engine_data_file update_engine_log_data_file snapuserd_log_data_file method_trace_data_file gsi_data_file radio_core_data_file app_data_file privapp_data_file system_app_data_file cache_file overlayfs_file cache_backup_file cache_private_backup_file cache_recovery_file efs_file wallpaper_file shortcut_manager_icons icon_file asec_apk_file asec_public_file asec_image_file backup_data_file bluetooth_efs_file fingerprintd_data_file fingerprint_vendor_data_file app_fuse_file face_vendor_data_file iris_vendor_data_file adbd_socket bluetooth_socket dnsproxyd_socket dumpstate_socket fwmarkd_socket lmkd_socket logd_socket logdr_socket logdw_socket mdns_socket mdnsd_socket misc_logd_file mtpd_socket ot_daemon_socket property_socket racoon_socket recovery_socket rild_socket rild_debug_socket snapuserd_socket snapuserd_proxy_socket statsdw_socket system_wpa_socket system_ndebug_socket system_unsolzygote_socket tombstoned_crash_socket tombstoned_java_trace_socket tombstoned_intercept_socket traced_consumer_socket traced_perf_socket traced_producer_socket uncrypt_socket wpa_socket zygote_socket heapprofd_socket gps_control pdx_display_dir pdx_performance_dir pdx_bufferhub_dir pdx_display_client_endpoint_socket pdx_display_manager_endpoint_socket pdx_display_screenshot_endpoint_socket pdx_display_vsync_endpoint_socket pdx_performance_client_endpoint_socket pdx_bufferhub_client_endpoint_socket file_contexts_file mac_perms_file property_contexts_file seapp_contexts_file sepolicy_file service_contexts_file keystore2_key_contexts_file vendor_service_contexts_file hwservice_contexts_file vndservice_contexts_file vendor_kernel_modules system_dlkm_file audiohal_data_file fingerprintd_exec flags_health_check_exec fsck_exec gatekeeperd_exec hal_graphics_composer_server_tmpfs hwservicemanager_exec idmap_exec init_exec init_tmpfs inputflinger_exec installd_exec keystore_exec llkd_exec lmkd_exec logd_exec mediadrmserver_exec mediaextractor_exec mediaextractor_tmpfs mediametrics_exec mediaserver_exec mediaserver_tmpfs mediaswcodec_exec netd_exec netutils_wrapper_exec performanced_exec profman_exec recovery_persist_exec recovery_refresh_exec rs_exec runas_exec sdcardd_exec servicemanager_exec sgdisk_exec shell_exec simpleperf_app_runner_exec statsd_exec su_exec surfaceflinger_tmpfs system_server_tmpfs tombstoned_exec toolbox_exec traced_tmpfs ueventd_tmpfs uncrypt_exec update_engine_exec update_verifier_exec usbd_exec vdc_exec vendor_misc_writer_exec vendor_shell_exec vendor_toolbox_exec virtual_touchpad_exec vold_exec vold_prepare_subdirs_exec watchdogd_exec webview_zygote_exec webview_zygote_tmpfs wificond_exec zygote_tmpfs zygote_exec aconfigd_exec apex_test_prepostinstall_exec art_boot_exec artd_exec artd_tmpfs atrace_exec audioserver_exec auditctl_exec automotive_display_service_exec blank_screen_exec blkid_exec boringssl_self_test_exec vendor_boringssl_self_test_exec boringssl_self_test_marker bpfloader_exec canhalconfigurator_exec clatd_exec compos_verify_exec composd_exec cppreopts_exec crosvm_exec crosvm_tmpfs derive_classpath_exec derive_sdk_exec dex2oat_exec dexopt_chroot_setup_exec dexopt_chroot_setup_tmpfs dexoptanalyzer_exec dexoptanalyzer_tmpfs dmesgd_exec dumpstate_tmpfs evsmanagerd_exec storaged_data_file wm_trace_data_file accessibility_trace_data_file perfetto_traces_data_file perfetto_traces_bugreport_data_file perfetto_traces_profiling_data_file perfetto_configs_data_file uprobestats_configs_data_file oatdump_exec sdk_sandbox_system_data_file sdk_sandbox_data_file app_exec_data_file rollback_data_file checkin_data_file ota_image_data_file gsi_persistent_data_file emergency_data_file profcollectd_data_file apex_art_data_file apex_art_staging_data_file apex_compos_data_file apex_virt_data_file apex_tethering_data_file apex_appsearch_data_file apex_permission_data_file apex_scheduling_data_file apex_wifi_data_file font_data_file dmesgd_data_file odrefresh_data_file odsign_data_file odsign_metrics_file virtualizationservice_data_file environ_system_data_file bootanim_data_file fd_server_exec compos_exec compos_key_helper_exec art_exec_exec prng_seeder_socket system_font_fallback_file aconfigd_socket system_aconfig_storage_file vendor_aconfig_storage_file fsverity_init_exec fuseblkd_exec fuseblkd_untrusted_exec fwk_bufferhub_exec gki_apex_prepostinstall_exec gpuservice_exec gsid_exec hal_allocator_default_exec heapprofd_exec heapprofd_tmpfs hidl_lazy_test_server_exec incident_exec incident_helper_exec incidentd_exec iw_exec linkerconfig_exec lpdumpd_exec mdnsd_exec mediatranscoding_exec mediatranscoding_tmpfs mediatuner_exec migrate_legacy_obb_data_exec misctrl_exec mm_events_exec mtectrl_exec odrefresh_exec odsign_exec ot_daemon_exec otapreopt_chroot_exec otapreopt_slot_exec perfetto_exec perfetto_tmpfs postinstall_exec postinstall_dexopt_exec postinstall_dexopt_tmpfs preloads_copy_exec preopt2cachename_exec prng_seeder_exec profcollectd_exec remount_exec rkpd_exec rss_hwm_reset_exec simpleperf_exec simpleperf_boot_data_file snapshotctl_exec snapuserd_exec stats_exec storaged_exec surfaceflinger_exec system_server_startup_tmpfs system_suspend_exec traced_exec traced_perf_exec traced_probes_exec traced_probes_tmpfs uprobestats_exec vehicle_binding_util_exec viewcompiler_exec viewcompiler_tmpfs virtual_camera_exec virtualizationmanager_exec virtualizationservice_exec wait_for_keymaster_exec ))
780(typeattribute exec_type)
781(typeattributeset exec_type (adbd_exec aidl_lazy_test_server_exec apexd_exec bootanim_exec bootstat_exec bufferhubd_exec cameraserver_exec charger_exec crash_dump_exec credstore_exec dhcp_exec dnsmasq_exec drmserver_exec dumpstate_exec e2fs_exec extra_free_kbytes_exec tcpdump_exec logcat_exec fingerprintd_exec flags_health_check_exec fsck_exec gatekeeperd_exec hwservicemanager_exec idmap_exec init_exec inputflinger_exec installd_exec keystore_exec llkd_exec lmkd_exec logd_exec mediadrmserver_exec mediaextractor_exec mediametrics_exec mediaserver_exec mediaswcodec_exec netd_exec netutils_wrapper_exec performanced_exec profman_exec recovery_persist_exec recovery_refresh_exec rs_exec runas_exec sdcardd_exec servicemanager_exec sgdisk_exec shell_exec simpleperf_app_runner_exec statsd_exec su_exec tombstoned_exec toolbox_exec uncrypt_exec update_engine_exec update_verifier_exec usbd_exec vdc_exec vendor_misc_writer_exec vendor_shell_exec vendor_toolbox_exec virtual_touchpad_exec vold_exec vold_prepare_subdirs_exec watchdogd_exec webview_zygote_exec wificond_exec zygote_exec aconfigd_exec apex_test_prepostinstall_exec art_boot_exec artd_exec atrace_exec audioserver_exec auditctl_exec automotive_display_service_exec blank_screen_exec blkid_exec boringssl_self_test_exec vendor_boringssl_self_test_exec bpfloader_exec canhalconfigurator_exec clatd_exec compos_verify_exec composd_exec cppreopts_exec crosvm_exec derive_classpath_exec derive_sdk_exec dex2oat_exec dexopt_chroot_setup_exec dexoptanalyzer_exec dmesgd_exec evsmanagerd_exec oatdump_exec fd_server_exec compos_exec compos_key_helper_exec art_exec_exec fsverity_init_exec fuseblkd_exec fuseblkd_untrusted_exec fwk_bufferhub_exec gki_apex_prepostinstall_exec gpuservice_exec gsid_exec hal_allocator_default_exec heapprofd_exec hidl_lazy_test_server_exec incident_exec incident_helper_exec incidentd_exec iw_exec linkerconfig_exec lpdumpd_exec mdnsd_exec mediatranscoding_exec mediatuner_exec migrate_legacy_obb_data_exec misctrl_exec mm_events_exec mtectrl_exec odrefresh_exec odsign_exec ot_daemon_exec otapreopt_chroot_exec otapreopt_slot_exec perfetto_exec postinstall_exec postinstall_dexopt_exec preloads_copy_exec preopt2cachename_exec prng_seeder_exec profcollectd_exec remount_exec rkpd_exec rss_hwm_reset_exec simpleperf_exec snapshotctl_exec snapuserd_exec stats_exec storaged_exec surfaceflinger_exec system_suspend_exec traced_exec traced_perf_exec traced_probes_exec uprobestats_exec vehicle_binding_util_exec viewcompiler_exec virtual_camera_exec virtualizationmanager_exec virtualizationservice_exec wait_for_keymaster_exec ))
782(typeattribute data_file_type)
783(expandtypeattribute (data_file_type) false)
784(typeattributeset data_file_type (incremental_control_file system_data_root_file system_data_file system_userdir_file packages_list_file game_mode_intervention_list_file vendor_data_file vendor_userdir_file unencrypted_data_file install_data_file drm_data_file adb_data_file anr_data_file tombstone_data_file tombstone_wifi_data_file apex_data_file apk_data_file apk_tmp_file apk_private_data_file apk_private_tmp_file dalvikcache_data_file ota_data_file ota_package_file user_profile_root_file user_profile_data_file profman_dump_data_file prereboot_data_file resourcecache_data_file shell_data_file property_data_file bootchart_data_file dropbox_data_file heapdump_data_file nativetest_data_file shell_test_data_file ringtone_file preloads_data_file preloads_media_file dhcp_data_file server_configurable_flags_data_file staging_data_file shutdown_checkpoints_system_data_file adb_keys_file apex_system_server_data_file apex_module_data_file apex_ota_reserved_file apex_rollback_data_file appcompat_data_file audio_data_file audioserver_data_file bluetooth_data_file bluetooth_logs_data_file bootstat_data_file boottrace_data_file camera_data_file credstore_data_file gatekeeper_data_file incident_data_file keychain_data_file keystore_data_file media_data_file media_rw_data_file media_userdir_file misc_user_data_file net_data_file network_watchlist_data_file nfc_data_file nfc_logs_data_file radio_data_file recovery_data_file shared_relro_file snapshotctl_log_data_file stats_config_data_file stats_data_file systemkeys_data_file textclassifier_data_file trace_data_file vpn_data_file wifi_data_file vold_data_file tee_data_file update_engine_data_file update_engine_log_data_file snapuserd_log_data_file method_trace_data_file gsi_data_file radio_core_data_file app_data_file privapp_data_file system_app_data_file cache_file overlayfs_file cache_backup_file cache_private_backup_file cache_recovery_file wallpaper_file shortcut_manager_icons icon_file asec_apk_file asec_public_file asec_image_file backup_data_file fingerprintd_data_file fingerprint_vendor_data_file app_fuse_file face_vendor_data_file iris_vendor_data_file bluetooth_socket misc_logd_file system_wpa_socket system_ndebug_socket system_unsolzygote_socket wpa_socket audiohal_data_file storaged_data_file wm_trace_data_file accessibility_trace_data_file perfetto_traces_data_file perfetto_traces_bugreport_data_file perfetto_traces_profiling_data_file perfetto_configs_data_file uprobestats_configs_data_file sdk_sandbox_system_data_file sdk_sandbox_data_file app_exec_data_file rollback_data_file checkin_data_file ota_image_data_file gsi_persistent_data_file emergency_data_file profcollectd_data_file apex_art_data_file apex_art_staging_data_file apex_compos_data_file apex_virt_data_file apex_tethering_data_file apex_appsearch_data_file apex_permission_data_file apex_scheduling_data_file apex_wifi_data_file font_data_file dmesgd_data_file odrefresh_data_file odsign_data_file odsign_metrics_file virtualizationservice_data_file environ_system_data_file bootanim_data_file ))
785(typeattribute core_data_file_type)
786(expandtypeattribute (core_data_file_type) false)
787(typeattributeset core_data_file_type (incremental_control_file system_data_root_file system_data_file system_userdir_file packages_list_file game_mode_intervention_list_file vendor_userdir_file unencrypted_data_file install_data_file drm_data_file adb_data_file anr_data_file tombstone_data_file apex_data_file apk_data_file apk_tmp_file apk_private_data_file apk_private_tmp_file dalvikcache_data_file ota_data_file ota_package_file user_profile_root_file user_profile_data_file profman_dump_data_file prereboot_data_file resourcecache_data_file shell_data_file property_data_file bootchart_data_file dropbox_data_file heapdump_data_file nativetest_data_file shell_test_data_file ringtone_file preloads_data_file preloads_media_file dhcp_data_file server_configurable_flags_data_file staging_data_file shutdown_checkpoints_system_data_file mirror_data_file adb_keys_file apex_system_server_data_file apex_module_data_file apex_ota_reserved_file apex_rollback_data_file appcompat_data_file audio_data_file audioserver_data_file bluetooth_data_file bluetooth_logs_data_file bootstat_data_file boottrace_data_file camera_data_file credstore_data_file gatekeeper_data_file incident_data_file keychain_data_file keystore_data_file media_data_file media_rw_data_file media_userdir_file misc_user_data_file net_data_file network_watchlist_data_file nfc_data_file nfc_logs_data_file radio_data_file recovery_data_file shared_relro_file snapshotctl_log_data_file stats_config_data_file stats_data_file systemkeys_data_file textclassifier_data_file trace_data_file vpn_data_file wifi_data_file vold_data_file update_engine_data_file update_engine_log_data_file snapuserd_log_data_file method_trace_data_file gsi_data_file radio_core_data_file app_data_file privapp_data_file system_app_data_file cache_file overlayfs_file cache_backup_file cache_private_backup_file cache_recovery_file wallpaper_file shortcut_manager_icons icon_file asec_apk_file asec_public_file asec_image_file backup_data_file fingerprintd_data_file app_fuse_file bluetooth_socket misc_logd_file system_wpa_socket system_ndebug_socket system_unsolzygote_socket wpa_socket audiohal_data_file storaged_data_file wm_trace_data_file accessibility_trace_data_file perfetto_traces_data_file perfetto_traces_bugreport_data_file perfetto_traces_profiling_data_file perfetto_configs_data_file uprobestats_configs_data_file sdk_sandbox_system_data_file sdk_sandbox_data_file app_exec_data_file rollback_data_file checkin_data_file ota_image_data_file gsi_persistent_data_file emergency_data_file profcollectd_data_file apex_art_data_file apex_art_staging_data_file apex_compos_data_file apex_virt_data_file apex_tethering_data_file apex_appsearch_data_file apex_permission_data_file apex_scheduling_data_file apex_wifi_data_file font_data_file dmesgd_data_file odrefresh_data_file odsign_data_file odsign_metrics_file virtualizationservice_data_file environ_system_data_file bootanim_data_file ))
788(typeattribute app_data_file_type)
789(expandtypeattribute (app_data_file_type) false)
790(typeattributeset app_data_file_type (shell_data_file bluetooth_data_file nfc_data_file radio_data_file app_data_file privapp_data_file system_app_data_file sdk_sandbox_data_file ))
791(typeattribute system_file_type)
792(typeattributeset system_file_type (adbd_exec aidl_lazy_test_server_exec apexd_exec bootanim_exec bootstat_exec bufferhubd_exec cameraserver_exec charger_exec crash_dump_exec credstore_exec dhcp_exec dnsmasq_exec drmserver_exec dumpstate_exec e2fs_exec extra_free_kbytes_exec system_file system_asan_options_file system_event_log_tags_file system_lib_file system_bootstrap_lib_file system_group_file system_linker_exec system_linker_config_file system_passwd_file system_seccomp_policy_file system_security_cacerts_file tcpdump_exec system_zoneinfo_file cgroup_desc_file cgroup_desc_api_file task_profiles_file task_profiles_api_file art_apex_dir bootanim_oem_file logcat_exec file_contexts_file mac_perms_file property_contexts_file seapp_contexts_file sepolicy_file service_contexts_file keystore2_key_contexts_file hwservice_contexts_file fingerprintd_exec flags_health_check_exec fsck_exec gatekeeperd_exec hwservicemanager_exec idmap_exec init_exec inputflinger_exec installd_exec keystore_exec llkd_exec lmkd_exec logd_exec mediadrmserver_exec mediaextractor_exec mediametrics_exec mediaserver_exec mediaswcodec_exec netd_exec netutils_wrapper_exec performanced_exec profman_exec recovery_persist_exec recovery_refresh_exec rs_exec runas_exec sdcardd_exec servicemanager_exec sgdisk_exec shell_exec simpleperf_app_runner_exec statsd_exec su_exec tombstoned_exec toolbox_exec uncrypt_exec update_engine_exec update_verifier_exec usbd_exec vdc_exec virtual_touchpad_exec vold_exec vold_prepare_subdirs_exec watchdogd_exec wificond_exec zygote_exec aconfigd_exec apex_test_prepostinstall_exec art_boot_exec artd_exec atrace_exec audioserver_exec auditctl_exec automotive_display_service_exec blank_screen_exec blkid_exec boringssl_self_test_exec bpfloader_exec canhalconfigurator_exec clatd_exec compos_verify_exec composd_exec cppreopts_exec crosvm_exec derive_classpath_exec derive_sdk_exec dex2oat_exec dexopt_chroot_setup_exec dexoptanalyzer_exec dmesgd_exec evsmanagerd_exec oatdump_exec fd_server_exec compos_exec compos_key_helper_exec art_exec_exec system_font_fallback_file system_aconfig_storage_file fsverity_init_exec fuseblkd_exec fuseblkd_untrusted_exec fwk_bufferhub_exec gki_apex_prepostinstall_exec gpuservice_exec gsid_exec hal_allocator_default_exec heapprofd_exec hidl_lazy_test_server_exec incident_exec incident_helper_exec incidentd_exec iw_exec linkerconfig_exec lpdumpd_exec mdnsd_exec mediatranscoding_exec mediatuner_exec migrate_legacy_obb_data_exec misctrl_exec mm_events_exec mtectrl_exec odrefresh_exec odsign_exec ot_daemon_exec otapreopt_chroot_exec otapreopt_slot_exec perfetto_exec postinstall_exec postinstall_dexopt_exec preloads_copy_exec preopt2cachename_exec prng_seeder_exec profcollectd_exec remount_exec rkpd_exec rss_hwm_reset_exec simpleperf_exec snapshotctl_exec snapuserd_exec stats_exec storaged_exec surfaceflinger_exec system_suspend_exec traced_exec traced_perf_exec traced_probes_exec uprobestats_exec vehicle_binding_util_exec viewcompiler_exec virtual_camera_exec virtualizationmanager_exec virtualizationservice_exec wait_for_keymaster_exec ))
793(typeattribute system_dlkm_file_type)
794(typeattributeset system_dlkm_file_type (system_dlkm_file ))
795(typeattribute vendor_file_type)
796(typeattributeset vendor_file_type (vendor_cgroup_desc_file vendor_task_profiles_file vendor_hal_file vendor_file vendor_app_file vendor_configs_file same_process_hal_file vndk_sp_file vendor_framework_file vendor_overlay_file vendor_public_lib_file vendor_public_framework_file vendor_microdroid_file vendor_keylayout_file vendor_keychars_file vendor_idc_file vendor_uuid_mapping_config_file vendor_vm_file vendor_vm_data_file vendor_apex_file vendor_apex_metadata_file vendor_service_contexts_file vendor_kernel_modules vendor_misc_writer_exec vendor_shell_exec vendor_toolbox_exec vendor_boringssl_self_test_exec vendor_aconfig_storage_file ))
797(typeattribute proc_type)
798(expandtypeattribute (proc_type) false)
799(typeattributeset proc_type (proc proc_security proc_drop_caches proc_overcommit_memory proc_min_free_order_shift proc_kpageflags proc_watermark_boost_factor proc_percpu_pagelist_high_fraction usermodehelper proc_qtaguid_ctrl proc_qtaguid_stat proc_bluetooth_writable proc_abi proc_asound proc_bootconfig proc_bpf proc_buddyinfo proc_cmdline proc_cpu_alignment proc_cpuinfo proc_dirty proc_diskstats proc_extra_free_kbytes proc_filesystems proc_fs_verity proc_hostname proc_hung_task proc_interrupts proc_iomem proc_kallsyms proc_keys proc_kmsg proc_loadavg proc_locks proc_lowmemorykiller proc_max_map_count proc_meminfo proc_misc proc_modules proc_mounts proc_net proc_net_tcp_udp proc_page_cluster proc_pagetypeinfo proc_panic proc_perf proc_pid_max proc_pipe_conf proc_pressure_cpu proc_pressure_io proc_pressure_mem proc_random proc_sched proc_slabinfo proc_stat proc_swaps proc_sysrq proc_timer proc_tty_drivers proc_uid_cputime_showstat proc_uid_cputime_removeuid proc_uid_io_stats proc_uid_procstat_set proc_uid_time_in_state proc_uid_concurrent_active_time proc_uid_concurrent_policy_time proc_uid_cpupower proc_uptime proc_version proc_vmallocinfo proc_vmstat proc_watermark_scale_factor proc_zoneinfo proc_vendor_sched config_gz proc_dt_avf ))
800(typeattribute proc_net_type)
801(expandtypeattribute (proc_net_type) true)
802(typeattributeset proc_net_type (proc_net ))
803(typeattribute sysfs_type)
804(typeattributeset sysfs_type (sysfs_usermodehelper sysfs sysfs_android_usb sysfs_uio sysfs_batteryinfo sysfs_bluetooth_writable sysfs_devfreq_cur sysfs_devfreq_dir sysfs_devices_block sysfs_dm sysfs_dm_verity sysfs_dma_heap sysfs_dmabuf_stats sysfs_dt_firmware_android sysfs_extcon sysfs_ion sysfs_ipv4 sysfs_kernel_notes sysfs_leds sysfs_loop sysfs_gpu sysfs_hwrandom sysfs_nfc_power_writable sysfs_wake_lock sysfs_net sysfs_power sysfs_rtc sysfs_suspend_stats sysfs_switch sysfs_sync_on_suspend sysfs_transparent_hugepage sysfs_lru_gen_enabled sysfs_usb sysfs_wakeup sysfs_wakeup_reasons sysfs_fs_ext4_features sysfs_fs_f2fs sysfs_fs_fuse_bpf sysfs_fs_fuse_features sysfs_fs_incfs_features sysfs_fs_incfs_metrics sysfs_vendor_sched sysfs_devices_cs_etm sysfs_devices_system_cpu sysfs_lowmemorykiller sysfs_wlan_fwpath sysfs_vibrator sysfs_uhid sysfs_thermal sysfs_zram sysfs_zram_uevent sysfs_dt_avf sysfs_uprobe ))
805(typeattribute debugfs_type)
806(typeattributeset debugfs_type (debugfs debugfs_kprobes debugfs_mmc debugfs_mm_events_tracing debugfs_trace_marker debugfs_tracing debugfs_tracing_debug debugfs_tracing_instances debugfs_tracing_printk_formats debugfs_wakeup_sources debugfs_wifi_tracing debugfs_bootreceiver_tracing debugfs_kcov ))
807(typeattribute tracefs_type)
808(typeattributeset tracefs_type (debugfs_mm_events_tracing debugfs_trace_marker debugfs_tracing debugfs_tracing_debug debugfs_tracing_instances debugfs_tracing_printk_formats debugfs_wifi_tracing debugfs_bootreceiver_tracing ))
809(typeattribute sdcard_type)
810(typeattributeset sdcard_type (fuseblk sdcardfs vfat exfat ))
811(typeattribute node_type)
812(typeattributeset node_type (node ))
813(typeattribute netif_type)
814(typeattributeset netif_type (netif ))
815(typeattribute port_type)
816(typeattributeset port_type (port ))
817(typeattribute property_type)
818(typeattributeset property_type (apexd_prop bootloader_boot_reason_prop device_config_activity_manager_native_boot_prop device_config_boot_count_prop device_config_input_native_boot_prop device_config_netd_native_prop device_config_reset_performed_prop firstboot_prop boottime_prop charger_prop cold_boot_done_prop ctl_adbd_prop ctl_apexd_prop ctl_bootanim_prop ctl_bugreport_prop ctl_console_prop ctl_dumpstate_prop ctl_fuse_prop ctl_gsid_prop ctl_interface_restart_prop ctl_interface_stop_prop ctl_mdnsd_prop ctl_restart_prop ctl_rildaemon_prop ctl_sigstop_prop dynamic_system_prop heapprofd_enabled_prop llkd_prop lpdumpd_prop mmc_prop mock_ota_prop net_dns_prop overlay_prop persistent_properties_ready_prop safemode_prop system_lmk_prop system_trace_prop test_boot_reason_prop time_prop traced_enabled_prop traced_lazy_prop aac_drc_prop adaptive_haptics_prop apex_ready_prop arm64_memtag_prop binder_cache_bluetooth_server_prop binder_cache_system_server_prop binder_cache_telephony_server_prop boot_status_prop bootanim_system_prop bootloader_prop boottime_public_prop bq_config_prop build_bootimage_prop build_prop composd_vm_art_prop device_config_aconfig_flags_prop device_config_camera_native_prop device_config_edgetpu_native_prop device_config_media_native_prop device_config_nnapi_native_prop device_config_runtime_native_boot_prop device_config_runtime_native_prop device_config_surface_flinger_native_boot_prop device_config_vendor_system_native_prop device_config_vendor_system_native_boot_prop drm_forcel3_prop fingerprint_prop gwp_asan_prop hal_instrumentation_prop userdebug_or_eng_prop init_service_status_prop libc_debug_prop module_sdkextensions_prop nnapi_ext_deny_product_prop persist_wm_debug_prop power_debug_prop property_service_version_prop provisioned_prop restorecon_prop retaildemo_prop servicemanager_prop smart_idle_maint_enabled_prop socket_hook_prop sqlite_log_prop surfaceflinger_display_prop system_boot_reason_prop system_jvmti_agent_prop traced_oome_heap_session_count_prop ab_update_gki_prop usb_prop userspace_reboot_exported_prop vold_status_prop vts_status_prop config_prop cppreopt_prop dalvik_prop debuggerd_prop device_logging_prop dhcp_prop dumpstate_prop exported3_system_prop exported_dumpstate_prop exported_secure_prop heapprofd_prop net_radio_prop pan_result_prop persist_debug_prop shell_prop test_harness_prop theme_prop use_memfd_prop vold_prop apexd_config_prop apexd_select_prop aaudio_config_prop apk_verity_prop audio_config_prop bootanim_config_prop bluetooth_config_prop build_attestation_prop build_config_prop build_odm_prop build_vendor_prop camera_calibration_prop camera_config_prop camera2_extensions_prop camerax_extensions_prop charger_config_prop codec2_config_prop composd_vm_vendor_prop cpu_variant_prop debugfs_restriction_prop drm_service_config_prop exported_camera_prop exported_config_prop exported_default_prop ffs_config_prop framework_watchdog_config_prop graphics_config_prop hdmi_config_prop hw_timeout_multiplier_prop hypervisor_prop hypervisor_restricted_prop incremental_prop input_device_config_prop keyguard_config_prop keystore_config_prop lmkd_config_prop media_config_prop media_variant_prop mediadrm_config_prop mm_events_config_prop oem_unlock_prop ota_build_prop packagemanager_config_prop quick_start_prop recovery_config_prop recovery_usb_config_prop sendbug_config_prop soc_prop storage_config_prop storagemanager_config_prop surfaceflinger_prop suspend_prop systemsound_config_prop telephony_config_prop threadnetwork_config_prop tombstone_config_prop usb_config_prop userspace_reboot_config_prop vehicle_hal_prop vendor_security_patch_level_prop vendor_socket_hook_prop virtual_ab_prop vndk_prop vts_config_prop vold_config_prop wifi_config_prop zram_config_prop zygote_config_prop dck_prop tuner_config_prop usb_uvc_enabled_prop setupwizard_mode_prop pm_archiving_enabled_prop adbd_config_prop audio_prop bluetooth_a2dp_offload_prop bluetooth_audio_hal_prop bluetooth_prop bpf_progs_loaded_prop charger_status_prop ctl_default_prop ctl_interface_start_prop ctl_start_prop ctl_stop_prop dalvik_config_prop dalvik_dynamic_config_prop dalvik_runtime_prop debug_prop device_config_memory_safety_native_boot_prop device_config_memory_safety_native_prop dumpstate_options_prop exported_system_prop exported_bluetooth_prop exported_overlay_prop exported_pm_prop future_pm_prop ffs_control_prop framework_status_prop gesture_prop graphics_config_writable_prop hal_dumpstate_config_prop sota_prop hwservicemanager_prop lmkd_prop locale_prop logd_prop logpersistd_logging_prop log_prop log_tag_prop lowpan_prop nfc_prop ota_prop permissive_mte_prop powerctl_prop qemu_hw_prop qemu_sf_lcd_density_prop radio_control_prop radio_prop serialno_prop surfaceflinger_color_prop system_prop system_user_mode_emulation_prop telephony_status_prop timezone_prop usb_control_prop vold_post_fs_data_prop wifi_hal_prop wifi_log_prop wifi_prop zram_control_prop default_prop rebootescrow_hal_prop virtual_face_hal_prop virtual_fingerprint_hal_prop persist_vendor_debug_wifi_prop vendor_default_prop adbd_prop apexd_payload_metadata_prop ctl_snapuserd_prop crashrecovery_prop device_config_core_experiments_team_internal_prop device_config_lmkd_native_prop device_config_mglru_native_prop device_config_profcollect_native_boot_prop device_config_remote_key_provisioning_native_prop device_config_statsd_native_prop device_config_statsd_native_boot_prop device_config_storage_native_boot_prop device_config_sys_traced_prop device_config_window_manager_native_boot_prop device_config_configuration_prop device_config_connectivity_prop device_config_swcodec_native_prop device_config_tethering_u_or_later_native_prop dmesgd_start_prop fastbootd_protocol_prop gsid_prop init_perf_lsm_hooks_prop init_service_status_private_prop init_storage_prop init_svc_debug_prop keystore_crash_prop keystore_listen_prop last_boot_reason_prop localization_prop logd_auditrate_prop lower_kptr_restrict_prop net_464xlat_fromvendor_prop net_connectivity_prop netd_stable_secret_prop next_boot_prop odsign_prop misctrl_prop perf_drop_caches_prop pm_prop profcollectd_node_id_prop radio_cdma_ecm_prop remote_prov_prop rollback_test_prop setupwizard_prop snapuserd_prop system_adbd_prop system_audio_config_prop timezone_metadata_prop traced_perf_enabled_prop uprobestats_start_with_config_prop tuner_server_ctl_prop userspace_reboot_log_prop userspace_reboot_test_prop verity_status_prop zygote_wrap_prop ctl_mediatranscoding_prop ctl_odsign_prop virtualizationservice_prop ctl_apex_load_prop enable_16k_pages_prop sensors_config_prop hypervisor_pvmfw_prop hypervisor_virtualizationmanager_prop game_manager_config_prop hidl_memory_prop suspend_debug_prop device_config_virtualization_framework_native_prop log_file_logger_prop persist_sysui_builder_extras_prop persist_sysui_ranking_update_prop ))
819(typeattribute core_property_type)
820(typeattributeset core_property_type (restorecon_prop usb_prop config_prop cppreopt_prop dalvik_prop debuggerd_prop dhcp_prop dumpstate_prop net_radio_prop pan_result_prop persist_debug_prop shell_prop vold_prop audio_prop debug_prop logd_prop nfc_prop ota_prop powerctl_prop radio_prop system_prop ))
821(typeattribute log_property_type)
822(typeattributeset log_property_type (log_prop log_tag_prop wifi_log_prop ))
823(typeattribute extended_core_property_type)
824(typeattribute system_property_type)
825(expandtypeattribute (system_property_type) false)
826(typeattributeset system_property_type (apexd_prop bootloader_boot_reason_prop device_config_activity_manager_native_boot_prop device_config_boot_count_prop device_config_input_native_boot_prop device_config_netd_native_prop device_config_reset_performed_prop firstboot_prop boottime_prop charger_prop cold_boot_done_prop ctl_adbd_prop ctl_apexd_prop ctl_bootanim_prop ctl_bugreport_prop ctl_console_prop ctl_dumpstate_prop ctl_fuse_prop ctl_gsid_prop ctl_interface_restart_prop ctl_interface_stop_prop ctl_mdnsd_prop ctl_restart_prop ctl_rildaemon_prop ctl_sigstop_prop dynamic_system_prop heapprofd_enabled_prop llkd_prop lpdumpd_prop mmc_prop mock_ota_prop net_dns_prop overlay_prop persistent_properties_ready_prop safemode_prop system_lmk_prop system_trace_prop test_boot_reason_prop time_prop traced_enabled_prop traced_lazy_prop aac_drc_prop adaptive_haptics_prop apex_ready_prop arm64_memtag_prop binder_cache_bluetooth_server_prop binder_cache_system_server_prop binder_cache_telephony_server_prop boot_status_prop bootanim_system_prop bootloader_prop boottime_public_prop bq_config_prop build_bootimage_prop build_prop composd_vm_art_prop device_config_aconfig_flags_prop device_config_camera_native_prop device_config_edgetpu_native_prop device_config_media_native_prop device_config_nnapi_native_prop device_config_runtime_native_boot_prop device_config_runtime_native_prop device_config_surface_flinger_native_boot_prop device_config_vendor_system_native_prop device_config_vendor_system_native_boot_prop drm_forcel3_prop fingerprint_prop gwp_asan_prop hal_instrumentation_prop userdebug_or_eng_prop init_service_status_prop libc_debug_prop module_sdkextensions_prop nnapi_ext_deny_product_prop persist_wm_debug_prop power_debug_prop property_service_version_prop provisioned_prop restorecon_prop retaildemo_prop servicemanager_prop smart_idle_maint_enabled_prop socket_hook_prop sqlite_log_prop surfaceflinger_display_prop system_boot_reason_prop system_jvmti_agent_prop traced_oome_heap_session_count_prop ab_update_gki_prop usb_prop userspace_reboot_exported_prop vold_status_prop vts_status_prop config_prop cppreopt_prop dalvik_prop debuggerd_prop device_logging_prop dhcp_prop dumpstate_prop exported3_system_prop exported_dumpstate_prop exported_secure_prop heapprofd_prop net_radio_prop pan_result_prop persist_debug_prop shell_prop test_harness_prop theme_prop use_memfd_prop vold_prop apexd_config_prop apexd_select_prop aaudio_config_prop apk_verity_prop audio_config_prop bootanim_config_prop bluetooth_config_prop build_attestation_prop build_config_prop build_odm_prop build_vendor_prop camera_calibration_prop camera_config_prop camera2_extensions_prop camerax_extensions_prop charger_config_prop codec2_config_prop composd_vm_vendor_prop cpu_variant_prop debugfs_restriction_prop drm_service_config_prop exported_camera_prop exported_config_prop exported_default_prop ffs_config_prop framework_watchdog_config_prop graphics_config_prop hdmi_config_prop hw_timeout_multiplier_prop hypervisor_prop hypervisor_restricted_prop incremental_prop input_device_config_prop keyguard_config_prop keystore_config_prop lmkd_config_prop media_config_prop media_variant_prop mediadrm_config_prop mm_events_config_prop oem_unlock_prop ota_build_prop packagemanager_config_prop quick_start_prop recovery_config_prop recovery_usb_config_prop sendbug_config_prop soc_prop storage_config_prop storagemanager_config_prop surfaceflinger_prop suspend_prop systemsound_config_prop telephony_config_prop threadnetwork_config_prop tombstone_config_prop usb_config_prop userspace_reboot_config_prop vehicle_hal_prop vendor_security_patch_level_prop vendor_socket_hook_prop virtual_ab_prop vndk_prop vts_config_prop vold_config_prop wifi_config_prop zram_config_prop zygote_config_prop dck_prop tuner_config_prop usb_uvc_enabled_prop setupwizard_mode_prop pm_archiving_enabled_prop adbd_config_prop audio_prop bluetooth_a2dp_offload_prop bluetooth_audio_hal_prop bluetooth_prop bpf_progs_loaded_prop charger_status_prop ctl_default_prop ctl_interface_start_prop ctl_start_prop ctl_stop_prop dalvik_config_prop dalvik_dynamic_config_prop dalvik_runtime_prop debug_prop device_config_memory_safety_native_boot_prop device_config_memory_safety_native_prop dumpstate_options_prop exported_system_prop exported_bluetooth_prop exported_overlay_prop exported_pm_prop future_pm_prop ffs_control_prop framework_status_prop gesture_prop graphics_config_writable_prop hal_dumpstate_config_prop sota_prop hwservicemanager_prop lmkd_prop locale_prop logd_prop logpersistd_logging_prop log_prop log_tag_prop lowpan_prop nfc_prop ota_prop permissive_mte_prop powerctl_prop qemu_hw_prop qemu_sf_lcd_density_prop radio_control_prop radio_prop serialno_prop surfaceflinger_color_prop system_prop system_user_mode_emulation_prop telephony_status_prop timezone_prop usb_control_prop vold_post_fs_data_prop wifi_hal_prop wifi_log_prop wifi_prop zram_control_prop default_prop adbd_prop apexd_payload_metadata_prop ctl_snapuserd_prop crashrecovery_prop device_config_core_experiments_team_internal_prop device_config_lmkd_native_prop device_config_mglru_native_prop device_config_profcollect_native_boot_prop device_config_remote_key_provisioning_native_prop device_config_statsd_native_prop device_config_statsd_native_boot_prop device_config_storage_native_boot_prop device_config_sys_traced_prop device_config_window_manager_native_boot_prop device_config_configuration_prop device_config_connectivity_prop device_config_swcodec_native_prop device_config_tethering_u_or_later_native_prop dmesgd_start_prop fastbootd_protocol_prop gsid_prop init_perf_lsm_hooks_prop init_service_status_private_prop init_storage_prop init_svc_debug_prop keystore_crash_prop keystore_listen_prop last_boot_reason_prop localization_prop logd_auditrate_prop lower_kptr_restrict_prop net_464xlat_fromvendor_prop net_connectivity_prop netd_stable_secret_prop next_boot_prop odsign_prop misctrl_prop perf_drop_caches_prop pm_prop profcollectd_node_id_prop radio_cdma_ecm_prop remote_prov_prop rollback_test_prop setupwizard_prop snapuserd_prop system_adbd_prop system_audio_config_prop timezone_metadata_prop traced_perf_enabled_prop uprobestats_start_with_config_prop tuner_server_ctl_prop userspace_reboot_log_prop userspace_reboot_test_prop verity_status_prop zygote_wrap_prop ctl_mediatranscoding_prop ctl_odsign_prop virtualizationservice_prop ctl_apex_load_prop enable_16k_pages_prop sensors_config_prop hypervisor_pvmfw_prop hypervisor_virtualizationmanager_prop game_manager_config_prop hidl_memory_prop suspend_debug_prop device_config_virtualization_framework_native_prop log_file_logger_prop persist_sysui_builder_extras_prop persist_sysui_ranking_update_prop ))
827(typeattribute system_internal_property_type)
828(expandtypeattribute (system_internal_property_type) false)
829(typeattributeset system_internal_property_type (apexd_prop bootloader_boot_reason_prop device_config_activity_manager_native_boot_prop device_config_boot_count_prop device_config_input_native_boot_prop device_config_netd_native_prop device_config_reset_performed_prop firstboot_prop boottime_prop charger_prop cold_boot_done_prop ctl_adbd_prop ctl_apexd_prop ctl_bootanim_prop ctl_bugreport_prop ctl_console_prop ctl_dumpstate_prop ctl_fuse_prop ctl_gsid_prop ctl_interface_restart_prop ctl_interface_stop_prop ctl_mdnsd_prop ctl_restart_prop ctl_rildaemon_prop ctl_sigstop_prop dynamic_system_prop heapprofd_enabled_prop llkd_prop lpdumpd_prop mmc_prop mock_ota_prop net_dns_prop overlay_prop persistent_properties_ready_prop safemode_prop system_lmk_prop system_trace_prop test_boot_reason_prop time_prop traced_enabled_prop traced_lazy_prop default_prop adbd_prop apexd_payload_metadata_prop ctl_snapuserd_prop crashrecovery_prop device_config_core_experiments_team_internal_prop device_config_lmkd_native_prop device_config_mglru_native_prop device_config_profcollect_native_boot_prop device_config_remote_key_provisioning_native_prop device_config_statsd_native_prop device_config_statsd_native_boot_prop device_config_storage_native_boot_prop device_config_sys_traced_prop device_config_window_manager_native_boot_prop device_config_configuration_prop device_config_connectivity_prop device_config_swcodec_native_prop device_config_tethering_u_or_later_native_prop dmesgd_start_prop fastbootd_protocol_prop gsid_prop init_perf_lsm_hooks_prop init_service_status_private_prop init_storage_prop init_svc_debug_prop keystore_crash_prop keystore_listen_prop last_boot_reason_prop localization_prop logd_auditrate_prop lower_kptr_restrict_prop net_464xlat_fromvendor_prop net_connectivity_prop netd_stable_secret_prop next_boot_prop odsign_prop misctrl_prop perf_drop_caches_prop pm_prop profcollectd_node_id_prop radio_cdma_ecm_prop remote_prov_prop rollback_test_prop setupwizard_prop snapuserd_prop system_adbd_prop system_audio_config_prop timezone_metadata_prop traced_perf_enabled_prop uprobestats_start_with_config_prop tuner_server_ctl_prop userspace_reboot_log_prop userspace_reboot_test_prop verity_status_prop zygote_wrap_prop ctl_mediatranscoding_prop ctl_odsign_prop virtualizationservice_prop ctl_apex_load_prop enable_16k_pages_prop sensors_config_prop hypervisor_pvmfw_prop hypervisor_virtualizationmanager_prop game_manager_config_prop hidl_memory_prop suspend_debug_prop ))
830(typeattribute system_restricted_property_type)
831(expandtypeattribute (system_restricted_property_type) false)
832(typeattributeset system_restricted_property_type (aac_drc_prop adaptive_haptics_prop apex_ready_prop arm64_memtag_prop binder_cache_bluetooth_server_prop binder_cache_system_server_prop binder_cache_telephony_server_prop boot_status_prop bootanim_system_prop bootloader_prop boottime_public_prop bq_config_prop build_bootimage_prop build_prop composd_vm_art_prop device_config_aconfig_flags_prop device_config_camera_native_prop device_config_edgetpu_native_prop device_config_media_native_prop device_config_nnapi_native_prop device_config_runtime_native_boot_prop device_config_runtime_native_prop device_config_surface_flinger_native_boot_prop device_config_vendor_system_native_prop device_config_vendor_system_native_boot_prop drm_forcel3_prop fingerprint_prop gwp_asan_prop hal_instrumentation_prop userdebug_or_eng_prop init_service_status_prop libc_debug_prop module_sdkextensions_prop nnapi_ext_deny_product_prop persist_wm_debug_prop power_debug_prop property_service_version_prop provisioned_prop restorecon_prop retaildemo_prop servicemanager_prop smart_idle_maint_enabled_prop socket_hook_prop sqlite_log_prop surfaceflinger_display_prop system_boot_reason_prop system_jvmti_agent_prop traced_oome_heap_session_count_prop ab_update_gki_prop usb_prop userspace_reboot_exported_prop vold_status_prop vts_status_prop config_prop cppreopt_prop dalvik_prop debuggerd_prop device_logging_prop dhcp_prop dumpstate_prop exported3_system_prop exported_dumpstate_prop exported_secure_prop heapprofd_prop net_radio_prop pan_result_prop persist_debug_prop shell_prop test_harness_prop theme_prop use_memfd_prop vold_prop device_config_virtualization_framework_native_prop log_file_logger_prop persist_sysui_builder_extras_prop persist_sysui_ranking_update_prop ))
833(typeattribute system_public_property_type)
834(expandtypeattribute (system_public_property_type) false)
835(typeattributeset system_public_property_type (apexd_config_prop apexd_select_prop aaudio_config_prop apk_verity_prop audio_config_prop bootanim_config_prop bluetooth_config_prop build_attestation_prop build_config_prop build_odm_prop build_vendor_prop camera_calibration_prop camera_config_prop camera2_extensions_prop camerax_extensions_prop charger_config_prop codec2_config_prop composd_vm_vendor_prop cpu_variant_prop debugfs_restriction_prop drm_service_config_prop exported_camera_prop exported_config_prop exported_default_prop ffs_config_prop framework_watchdog_config_prop graphics_config_prop hdmi_config_prop hw_timeout_multiplier_prop hypervisor_prop hypervisor_restricted_prop incremental_prop input_device_config_prop keyguard_config_prop keystore_config_prop lmkd_config_prop media_config_prop media_variant_prop mediadrm_config_prop mm_events_config_prop oem_unlock_prop ota_build_prop packagemanager_config_prop quick_start_prop recovery_config_prop recovery_usb_config_prop sendbug_config_prop soc_prop storage_config_prop storagemanager_config_prop surfaceflinger_prop suspend_prop systemsound_config_prop telephony_config_prop threadnetwork_config_prop tombstone_config_prop usb_config_prop userspace_reboot_config_prop vehicle_hal_prop vendor_security_patch_level_prop vendor_socket_hook_prop virtual_ab_prop vndk_prop vts_config_prop vold_config_prop wifi_config_prop zram_config_prop zygote_config_prop dck_prop tuner_config_prop usb_uvc_enabled_prop setupwizard_mode_prop pm_archiving_enabled_prop adbd_config_prop audio_prop bluetooth_a2dp_offload_prop bluetooth_audio_hal_prop bluetooth_prop bpf_progs_loaded_prop charger_status_prop ctl_default_prop ctl_interface_start_prop ctl_start_prop ctl_stop_prop dalvik_config_prop dalvik_dynamic_config_prop dalvik_runtime_prop debug_prop device_config_memory_safety_native_boot_prop device_config_memory_safety_native_prop dumpstate_options_prop exported_system_prop exported_bluetooth_prop exported_overlay_prop exported_pm_prop future_pm_prop ffs_control_prop framework_status_prop gesture_prop graphics_config_writable_prop hal_dumpstate_config_prop sota_prop hwservicemanager_prop lmkd_prop locale_prop logd_prop logpersistd_logging_prop log_prop log_tag_prop lowpan_prop nfc_prop ota_prop permissive_mte_prop powerctl_prop qemu_hw_prop qemu_sf_lcd_density_prop radio_control_prop radio_prop serialno_prop surfaceflinger_color_prop system_prop system_user_mode_emulation_prop telephony_status_prop timezone_prop usb_control_prop vold_post_fs_data_prop wifi_hal_prop wifi_log_prop wifi_prop zram_control_prop ))
836(typeattribute keystore2_key_type)
837(typeattributeset keystore2_key_type (keystore wifi_key shell_key su_key vold_key odsign_key locksettings_key resume_on_reboot_key ))
838(typeattribute vendor_property_type)
839(expandtypeattribute (vendor_property_type) false)
840(typeattributeset vendor_property_type (rebootescrow_hal_prop virtual_face_hal_prop virtual_fingerprint_hal_prop persist_vendor_debug_wifi_prop vendor_default_prop ))
841(typeattribute vendor_internal_property_type)
842(expandtypeattribute (vendor_internal_property_type) false)
843(typeattributeset vendor_internal_property_type (rebootescrow_hal_prop virtual_face_hal_prop virtual_fingerprint_hal_prop vendor_default_prop ))
844(typeattribute vendor_restricted_property_type)
845(expandtypeattribute (vendor_restricted_property_type) false)
846(typeattribute vendor_public_property_type)
847(expandtypeattribute (vendor_public_property_type) false)
848(typeattributeset vendor_public_property_type (persist_vendor_debug_wifi_prop ))
849(typeattribute system_server_service)
850(typeattributeset system_server_service (device_config_updatable_service ondevicepersonalization_system_service profiling_service accessibility_service account_service activity_service activity_task_service adb_service adservices_manager_service alarm_service app_binding_service app_hibernation_service app_integrity_service app_prediction_service app_search_service appops_service appwidget_service archive_service assetatlas_service attestation_verification_service audio_service auth_service autofill_service backup_service batterystats_service battery_service binder_calls_stats_service blob_store_service bluetooth_manager_service broadcastradio_service cacheinfo_service cameraproxy_service clipboard_service cloudsearch_service contexthub_service contextual_search_service crossprofileapps_service IProxyService_service companion_device_service connectivity_native_service connectivity_service connmetrics_service consumer_ir_service content_capture_service content_suggestions_service content_service country_detector_service coverage_service cpuinfo_service cpu_monitor_service credential_service dataloader_manager_service dbinfo_service device_config_service device_policy_service device_state_service deviceidle_service device_identifiers_service devicestoragemonitor_service diskstats_service display_service domain_verification_service color_display_service ecm_enhanced_confirmation_service external_vibrator_service file_integrity_service font_service netd_listener_service network_watchlist_service devicelock_service DockObserver_service dreams_service dropbox_service ethernet_service biometric_service bugreport_service platform_compat_service face_service fingerprint_service fwk_altitude_service fwk_stats_service fwk_sensor_service fwk_vibrator_control_service game_service gfxinfo_service gnss_time_update_service grammatical_inflection_service graphicsstats_service hardware_service hardware_properties_service hdmi_control_service healthconnect_service hint_service imms_service incremental_service input_method_service input_service ipsec_service iris_service jobscheduler_service launcherapps_service legacy_permission_service light_service locale_service location_service location_time_zone_manager_service lock_settings_service looper_stats_service media_communication_service media_metrics_service media_projection_service media_router_service media_session_service meminfo_service memtrackproxy_service midi_service mount_service music_recognition_service nearby_service netpolicy_service netstats_service network_management_service network_score_service network_stack_service network_time_update_service notification_service oem_lock_service otadexopt_service overlay_service pac_proxy_service package_service package_native_service people_service permission_service permissionmgr_service permission_checker_service persistent_data_block_service pinner_service powerstats_service power_service print_service processinfo_service procstats_service reboot_readiness_service recovery_service registry_service remote_auth_service remote_provisioning_service resources_manager_service restrictions_service role_service rollback_service runtime_service rttmanager_service samplingprofiler_service scheduling_policy_service search_service search_ui_service sec_key_att_app_id_provider_service security_state_service selection_toolbar_service sensitive_content_protection_service sensorservice_service sensor_privacy_service serial_service servicediscovery_service settings_service shortcut_service slice_service smartspace_service statusbar_service storagestats_service sdk_sandbox_service system_config_service system_server_dumper_service system_update_service soundtrigger_middleware_service speech_recognition_service tare_service task_service testharness_service textclassification_service textservices_service texttospeech_service telecom_service thermal_service threadnetwork_service timedetector_service timezonedetector_service translation_service trust_service tv_ad_service tv_iapp_service tv_input_service tv_tuner_resource_mgr_service uimode_service updatelock_service uri_grants_service usagestats_service usb_service user_service uwb_service vcn_management_service vibrator_service vibrator_manager_service virtual_device_service virtual_device_native_service voiceinteraction_service vpn_management_service vr_manager_service wallpaper_service wallpaper_effects_generation_service webviewupdate_service wifip2p_service wifiscanner_service wifi_service wifiaware_service window_service inputflinger_service tethering_service emergency_affordance_service adaptive_auth_service ambient_context_service attention_service bg_install_control_service communal_service dynamic_system_service feature_flags_service incidentcompanion_service logcat_service resolver_service safety_center_service statsbootstrap_service statscompanion_service statsmanager_service tracingproxy_service transparency_service wearable_sensing_service ))
851(typeattribute app_api_service)
852(typeattributeset app_api_service (batteryproperties_service gatekeeper_service gpu_service credstore_service mediatranscoding_service profiling_service surfaceflinger_service accessibility_service account_service activity_service activity_task_service alarm_service app_hibernation_service app_prediction_service app_search_service appops_service appwidget_service archive_service assetatlas_service attestation_verification_service audio_service auth_service autofill_service backup_service batterystats_service blob_store_service bluetooth_manager_service broadcastradio_service clipboard_service cloudsearch_service contexthub_service contextual_search_service crossprofileapps_service IProxyService_service companion_device_service connectivity_native_service connectivity_service connmetrics_service consumer_ir_service content_capture_service content_suggestions_service content_service country_detector_service credential_service device_policy_service device_state_service deviceidle_service device_identifiers_service display_service domain_verification_service color_display_service ecm_enhanced_confirmation_service file_integrity_service font_service devicelock_service dreams_service dropbox_service ethernet_service biometric_service bugreport_service platform_compat_service face_service fingerprint_service fwk_stats_service game_service grammatical_inflection_service graphicsstats_service hardware_properties_service hdmi_control_service healthconnect_service hint_service imms_service input_method_service input_service ipsec_service iris_service jobscheduler_service launcherapps_service legacy_permission_service light_service locale_service location_service lock_settings_service media_communication_service media_metrics_service media_projection_service media_router_service media_session_service memtrackproxy_service midi_service mount_service music_recognition_service nearby_service netpolicy_service netstats_service network_management_service notification_service pac_proxy_service package_service package_native_service people_service permission_service permissionmgr_service permission_checker_service powerstats_service power_service print_service procstats_service reboot_readiness_service registry_service remote_auth_service restrictions_service role_service rollback_service rttmanager_service search_service search_ui_service sec_key_att_app_id_provider_service security_state_service selection_toolbar_service sensitive_content_protection_service sensorservice_service sensor_privacy_service servicediscovery_service settings_service shortcut_service slice_service smartspace_service statusbar_service storagestats_service sdk_sandbox_service speech_recognition_service tare_service textclassification_service textservices_service texttospeech_service telecom_service thermal_service threadnetwork_service timedetector_service timezonedetector_service translation_service trust_service tv_ad_service tv_iapp_service tv_input_service tv_tuner_resource_mgr_service uimode_service uri_grants_service usagestats_service usb_service user_service uwb_service vcn_management_service vibrator_service vibrator_manager_service virtual_device_service virtual_device_native_service voiceinteraction_service vpn_management_service wallpaper_service wallpaper_effects_generation_service webviewupdate_service wifip2p_service wifi_service wifiaware_service tethering_service ambient_context_service communal_service feature_flags_service incidentcompanion_service mediatuner_service safety_center_service wearable_sensing_service ))
853(typeattribute ephemeral_app_api_service)
854(typeattributeset ephemeral_app_api_service (batteryproperties_service gpu_service surfaceflinger_service accessibility_service account_service activity_service activity_task_service alarm_service app_search_service appops_service appwidget_service assetatlas_service audio_service autofill_service backup_service batterystats_service bluetooth_manager_service clipboard_service IProxyService_service companion_device_service connectivity_native_service connectivity_service connmetrics_service consumer_ir_service content_capture_service content_suggestions_service content_service country_detector_service credential_service deviceidle_service device_identifiers_service display_service font_service devicelock_service dreams_service dropbox_service platform_compat_service game_service grammatical_inflection_service graphicsstats_service hardware_properties_service hint_service imms_service input_method_service input_service ipsec_service jobscheduler_service launcherapps_service legacy_permission_service light_service locale_service location_service media_communication_service media_metrics_service media_projection_service media_router_service media_session_service memtrackproxy_service midi_service mount_service music_recognition_service netpolicy_service netstats_service network_management_service notification_service package_service package_native_service permission_service permissionmgr_service permission_checker_service power_service print_service procstats_service registry_service restrictions_service rttmanager_service search_service security_state_service selection_toolbar_service sensorservice_service sensor_privacy_service servicediscovery_service settings_service statusbar_service storagestats_service speech_recognition_service textclassification_service textservices_service texttospeech_service telecom_service thermal_service timedetector_service translation_service tv_ad_service tv_iapp_service tv_input_service uimode_service uri_grants_service usagestats_service user_service vcn_management_service vibrator_service vibrator_manager_service virtual_device_native_service voiceinteraction_service webviewupdate_service tethering_service ))
855(typeattribute system_api_service)
856(typeattributeset system_api_service (device_config_updatable_service ondevicepersonalization_system_service adb_service adservices_manager_service app_hibernation_service app_integrity_service cacheinfo_service cpuinfo_service credential_service dbinfo_service device_state_service diskstats_service color_display_service gfxinfo_service lock_settings_service meminfo_service network_score_service oem_lock_service overlay_service persistent_data_block_service resources_manager_service serial_service system_config_service system_server_dumper_service updatelock_service wifiscanner_service window_service inputflinger_service bg_install_control_service dynamic_system_service incidentcompanion_service safety_center_service statsmanager_service ))
857(typeattribute protected_service)
858(typeattributeset protected_service (hal_audio_service hal_authgraph_service hal_authsecret_service hal_bluetooth_service hal_bootctl_service hal_broadcastradio_service hal_camera_service hal_can_controller_service hal_confirmationui_service hal_contexthub_service hal_dumpstate_service hal_evs_service hal_face_service hal_fastboot_service hal_fingerprint_service hal_gnss_service hal_graphics_composer_service hal_health_service hal_health_storage_service hal_identity_service hal_input_processor_service hal_ir_service hal_ivn_service hal_keymint_service hal_light_service hal_macsec_service hal_memtrack_service hal_nfc_service hal_oemlock_service hal_power_service hal_power_stats_service hal_radio_service hal_rebootescrow_service hal_remoteaccess_service hal_remotelyprovisionedcomponent_avf_service hal_remotelyprovisionedcomponent_service hal_sensors_service hal_secretkeeper_service hal_secureclock_service hal_secure_element_service hal_sharedsecret_service hal_system_suspend_service hal_tetheroffload_service hal_thermal_service hal_tv_hdmi_cec_service hal_tv_hdmi_connection_service hal_tv_hdmi_earc_service hal_tv_input_service hal_threadnetwork_service hal_tv_tuner_service hal_usb_service hal_usb_gadget_service hal_uwb_service hal_vehicle_service hal_vibrator_service hal_weaver_service hal_nlinterceptor_service hal_wifi_service hal_wifi_hostapd_service hal_wifi_supplicant_service hal_gatekeeper_service ))
859(typeattribute service_manager_type)
860(typeattributeset service_manager_type (aidl_lazy_test_service apc_service apex_service artd_service artd_pre_reboot_service audioserver_service authorization_service batteryproperties_service bluetooth_service cameraserver_service fwk_camera_service default_android_service device_config_updatable_service dexopt_chroot_setup_service dnsresolver_service drmserver_service dumpstate_service evsmanagerd_service fingerprintd_service fwk_automotive_display_service gatekeeper_service gpu_service idmap_service incident_service installd_service credstore_service keystore_compat_hal_service keystore_maintenance_service keystore_metrics_service keystore_service legacykeystore_service lpdump_service mdns_service mediaserver_service mediametrics_service mediaextractor_service mediadrmserver_service mediatranscoding_service netd_service nfc_service ondevicepersonalization_system_service ot_daemon_service profiling_service radio_service secure_element_service service_manager_service storaged_service surfaceflinger_service system_app_service system_net_netd_service system_suspend_control_internal_service system_suspend_control_service update_engine_service update_engine_stable_service virtualization_service virtual_camera_service virtual_touchpad_service vold_service vr_hwc_service vrflinger_vsync_service accessibility_service account_service activity_service activity_task_service adb_service adservices_manager_service alarm_service app_binding_service app_hibernation_service app_integrity_service app_prediction_service app_search_service appops_service appwidget_service archive_service assetatlas_service attestation_verification_service audio_service auth_service autofill_service backup_service batterystats_service battery_service binder_calls_stats_service blob_store_service bluetooth_manager_service broadcastradio_service cacheinfo_service cameraproxy_service clipboard_service cloudsearch_service contexthub_service contextual_search_service crossprofileapps_service IProxyService_service companion_device_service connectivity_native_service connectivity_service connmetrics_service consumer_ir_service content_capture_service content_suggestions_service content_service country_detector_service coverage_service cpuinfo_service cpu_monitor_service credential_service dataloader_manager_service dbinfo_service device_config_service device_policy_service device_state_service deviceidle_service device_identifiers_service devicestoragemonitor_service diskstats_service display_service domain_verification_service color_display_service ecm_enhanced_confirmation_service external_vibrator_service file_integrity_service font_service netd_listener_service network_watchlist_service devicelock_service DockObserver_service dreams_service dropbox_service ethernet_service biometric_service bugreport_service platform_compat_service face_service fingerprint_service fwk_altitude_service fwk_stats_service fwk_sensor_service fwk_vibrator_control_service game_service gfxinfo_service gnss_time_update_service grammatical_inflection_service graphicsstats_service hardware_service hardware_properties_service hdmi_control_service healthconnect_service hint_service imms_service incremental_service input_method_service input_service ipsec_service iris_service jobscheduler_service launcherapps_service legacy_permission_service light_service locale_service location_service location_time_zone_manager_service lock_settings_service looper_stats_service media_communication_service media_metrics_service media_projection_service media_router_service media_session_service meminfo_service memtrackproxy_service midi_service mount_service music_recognition_service nearby_service netpolicy_service netstats_service network_management_service network_score_service network_stack_service network_time_update_service notification_service oem_lock_service otadexopt_service overlay_service pac_proxy_service package_service package_native_service people_service permission_service permissionmgr_service permission_checker_service persistent_data_block_service pinner_service powerstats_service power_service print_service processinfo_service procstats_service reboot_readiness_service recovery_service registry_service remote_auth_service remote_provisioning_service resources_manager_service restrictions_service role_service rollback_service runtime_service rttmanager_service samplingprofiler_service scheduling_policy_service search_service search_ui_service sec_key_att_app_id_provider_service security_state_service selection_toolbar_service sensitive_content_protection_service sensorservice_service sensor_privacy_service serial_service servicediscovery_service settings_service shortcut_service slice_service smartspace_service statusbar_service storagestats_service sdk_sandbox_service system_config_service system_server_dumper_service system_update_service soundtrigger_middleware_service speech_recognition_service tare_service task_service testharness_service textclassification_service textservices_service texttospeech_service telecom_service thermal_service threadnetwork_service timedetector_service timezonedetector_service translation_service trust_service tv_ad_service tv_iapp_service tv_input_service tv_tuner_resource_mgr_service uimode_service updatelock_service uri_grants_service usagestats_service usb_service user_service uwb_service vcn_management_service vibrator_service vibrator_manager_service virtual_device_service virtual_device_native_service voiceinteraction_service vpn_management_service vr_manager_service wallpaper_service wallpaper_effects_generation_service webviewupdate_service wifip2p_service wifiscanner_service wifi_service wifinl80211_service wifiaware_service window_service inputflinger_service tethering_service emergency_affordance_service hal_audio_service hal_audiocontrol_service hal_authgraph_service hal_authsecret_service hal_bluetooth_service hal_bootctl_service hal_broadcastradio_service hal_camera_service hal_can_controller_service hal_cas_service hal_codec2_service hal_confirmationui_service hal_contexthub_service hal_drm_service hal_dumpstate_service hal_evs_service hal_face_service hal_fastboot_service hal_fingerprint_service hal_gnss_service hal_graphics_allocator_service hal_graphics_composer_service hal_graphics_mapper_service hal_health_service hal_health_storage_service hal_identity_service hal_input_processor_service hal_ir_service hal_ivn_service hal_keymint_service hal_light_service hal_macsec_service hal_memtrack_service hal_neuralnetworks_service hal_nfc_service hal_oemlock_service hal_power_service hal_power_stats_service hal_radio_service hal_rebootescrow_service hal_remoteaccess_service hal_remotelyprovisionedcomponent_avf_service hal_remotelyprovisionedcomponent_service hal_sensors_service hal_secretkeeper_service hal_secureclock_service hal_secure_element_service hal_sharedsecret_service hal_system_suspend_service hal_tetheroffload_service hal_thermal_service hal_tv_hdmi_cec_service hal_tv_hdmi_connection_service hal_tv_hdmi_earc_service hal_tv_input_service hal_threadnetwork_service hal_tv_tuner_service hal_usb_service hal_usb_gadget_service hal_uwb_service hal_vehicle_service hal_vibrator_service hal_weaver_service hal_nlinterceptor_service hal_wifi_service hal_wifi_hostapd_service hal_wifi_supplicant_service hal_gatekeeper_service adaptive_auth_service ambient_context_service attention_service bg_install_control_service compos_service communal_service dynamic_system_service feature_flags_service gsi_service incidentcompanion_service logcat_service logd_service mediatuner_service profcollectd_service resolver_service rkpd_registrar_service rkpd_refresh_service safety_center_service stats_service statsbootstrap_service statscompanion_service statsmanager_service tracingproxy_service transparency_service uce_service wearable_sensing_service ))
861(typeattribute hwservice_manager_type)
862(typeattributeset hwservice_manager_type (default_android_hwservice fwk_camera_hwservice fwk_display_hwservice fwk_scheduler_hwservice fwk_sensor_hwservice fwk_stats_hwservice fwk_automotive_display_hwservice hal_atrace_hwservice hal_audio_hwservice hal_audiocontrol_hwservice hal_authsecret_hwservice hal_bluetooth_hwservice hal_bootctl_hwservice hal_broadcastradio_hwservice hal_camera_hwservice hal_can_bus_hwservice hal_can_controller_hwservice hal_confirmationui_hwservice hal_contexthub_hwservice hal_dumpstate_hwservice hal_evs_hwservice hal_face_hwservice hal_fingerprint_hwservice hal_gatekeeper_hwservice hal_gnss_hwservice hal_graphics_composer_hwservice hal_health_hwservice hal_health_storage_hwservice hal_input_classifier_hwservice hal_ir_hwservice hal_keymaster_hwservice hal_light_hwservice hal_lowpan_hwservice hal_memtrack_hwservice hal_nfc_hwservice hal_oemlock_hwservice hal_power_hwservice hal_power_stats_hwservice hal_secure_element_hwservice hal_sensors_hwservice hal_telephony_hwservice hal_tetheroffload_hwservice hal_thermal_hwservice hal_tv_cec_hwservice hal_tv_input_hwservice hal_tv_tuner_hwservice hal_usb_gadget_hwservice hal_usb_hwservice hal_vehicle_hwservice hal_vibrator_hwservice hal_vr_hwservice hal_weaver_hwservice hal_wifi_hostapd_hwservice hal_wifi_hwservice hal_wifi_supplicant_hwservice system_net_netd_hwservice system_suspend_hwservice system_wifi_keystore_hwservice fwk_bufferhub_hwservice hal_cas_hwservice hal_codec2_hwservice hal_configstore_ISurfaceFlingerConfigs hal_drm_hwservice hal_graphics_allocator_hwservice hal_graphics_mapper_hwservice hal_neuralnetworks_hwservice hal_omx_hwservice hal_renderscript_hwservice hidl_allocator_hwservice hidl_base_hwservice hidl_manager_hwservice hidl_memory_hwservice hidl_token_hwservice hal_lazy_test_hwservice ))
863(typeattribute same_process_hwservice)
864(typeattributeset same_process_hwservice (hal_graphics_mapper_hwservice hal_renderscript_hwservice ))
865(typeattribute coredomain_hwservice)
866(typeattributeset coredomain_hwservice (fwk_camera_hwservice fwk_display_hwservice fwk_scheduler_hwservice fwk_sensor_hwservice fwk_stats_hwservice fwk_automotive_display_hwservice system_net_netd_hwservice system_suspend_hwservice system_wifi_keystore_hwservice fwk_bufferhub_hwservice hidl_allocator_hwservice hidl_manager_hwservice hidl_memory_hwservice hidl_token_hwservice ))
867(typeattribute protected_hwservice)
868(typeattributeset protected_hwservice (default_android_hwservice fwk_camera_hwservice fwk_display_hwservice fwk_scheduler_hwservice fwk_sensor_hwservice fwk_stats_hwservice fwk_automotive_display_hwservice hal_atrace_hwservice hal_audio_hwservice hal_audiocontrol_hwservice hal_authsecret_hwservice hal_bluetooth_hwservice hal_bootctl_hwservice hal_broadcastradio_hwservice hal_camera_hwservice hal_can_bus_hwservice hal_can_controller_hwservice hal_confirmationui_hwservice hal_contexthub_hwservice hal_dumpstate_hwservice hal_evs_hwservice hal_face_hwservice hal_fingerprint_hwservice hal_gatekeeper_hwservice hal_gnss_hwservice hal_graphics_composer_hwservice hal_health_hwservice hal_health_storage_hwservice hal_input_classifier_hwservice hal_ir_hwservice hal_keymaster_hwservice hal_light_hwservice hal_lowpan_hwservice hal_memtrack_hwservice hal_nfc_hwservice hal_oemlock_hwservice hal_power_hwservice hal_power_stats_hwservice hal_secure_element_hwservice hal_sensors_hwservice hal_telephony_hwservice hal_tetheroffload_hwservice hal_thermal_hwservice hal_tv_cec_hwservice hal_tv_input_hwservice hal_tv_tuner_hwservice hal_usb_gadget_hwservice hal_usb_hwservice hal_vehicle_hwservice hal_vibrator_hwservice hal_vr_hwservice hal_weaver_hwservice hal_wifi_hostapd_hwservice hal_wifi_hwservice hal_wifi_supplicant_hwservice system_net_netd_hwservice system_suspend_hwservice system_wifi_keystore_hwservice hal_lazy_test_hwservice ))
869(typeattribute vndservice_manager_type)
870(typeattributeset vndservice_manager_type (service_manager_vndservice default_android_vndservice ))
871(typeattribute hal_service_type)
872(typeattributeset hal_service_type (hal_audio_service hal_audiocontrol_service hal_authgraph_service hal_authsecret_service hal_bluetooth_service hal_bootctl_service hal_broadcastradio_service hal_camera_service hal_can_controller_service hal_cas_service hal_codec2_service hal_confirmationui_service hal_contexthub_service hal_drm_service hal_dumpstate_service hal_evs_service hal_face_service hal_fastboot_service hal_fingerprint_service hal_gnss_service hal_graphics_allocator_service hal_graphics_composer_service hal_graphics_mapper_service hal_health_service hal_health_storage_service hal_identity_service hal_input_processor_service hal_ir_service hal_ivn_service hal_keymint_service hal_light_service hal_macsec_service hal_memtrack_service hal_neuralnetworks_service hal_nfc_service hal_oemlock_service hal_power_service hal_power_stats_service hal_radio_service hal_rebootescrow_service hal_remoteaccess_service hal_remotelyprovisionedcomponent_avf_service hal_remotelyprovisionedcomponent_service hal_sensors_service hal_secretkeeper_service hal_secureclock_service hal_secure_element_service hal_sharedsecret_service hal_system_suspend_service hal_tetheroffload_service hal_thermal_service hal_tv_hdmi_cec_service hal_tv_hdmi_connection_service hal_tv_hdmi_earc_service hal_tv_input_service hal_threadnetwork_service hal_tv_tuner_service hal_usb_service hal_usb_gadget_service hal_uwb_service hal_vehicle_service hal_vibrator_service hal_weaver_service hal_nlinterceptor_service hal_wifi_service hal_wifi_hostapd_service hal_wifi_supplicant_service hal_gatekeeper_service ))
873(typeattribute mlstrustedsubject)
874(typeattributeset mlstrustedsubject (adbd artd bluetooth bufferhubd drmserver dumpstate pdx_display_client_endpoint_socket pdx_display_manager_endpoint_socket pdx_display_screenshot_endpoint_socket pdx_display_vsync_endpoint_socket pdx_performance_client_endpoint_socket pdx_bufferhub_client_endpoint_socket heapprofd hwservicemanager incidentd init installd kernel keystore llkd lmkd logd mdnsd mediadrmserver mediaextractor mediaserver netd network_stack nfc performanced prng_seeder radio rss_hwm_reset runas servicemanager shell simpleperf_app_runner statsd surfaceflinger system_app system_server tombstoned traced traced_perf traced_probes uncrypt vendor_init vold vold_prepare_subdirs webview_zygote zygote cppreopts device_as_webcam dexoptanalyzer otapreopt_slot postinstall_dexopt profcollectd simpleperf_boot storaged viewcompiler virtualizationservice ))
875(typeattribute mlstrustedobject)
876(typeattributeset mlstrustedobject (ashmem_device ashmem_libcutils_device binder_device hwbinder_device pmsg_device gpu_device mtp_device ptmx_device kmsg_device null_device random_device owntty_device zero_device fuse_device ion_device dmabuf_heap_device dmabuf_system_heap_device dmabuf_system_secure_heap_device uhid_device tun_device usbaccessory_device usb_device proc_qtaguid_ctrl proc_qtaguid_stat selinuxfs cgroup sysfs sysfs_bluetooth_writable sysfs_kernel_notes sysfs_nfc_power_writable inotify devpts fuse fuseblk sdcardfs vfat exfat debugfs_trace_marker debugfs_tracing debugfs_tracing_debug functionfs anr_data_file tombstone_data_file apk_tmp_file apk_private_tmp_file ota_package_file user_profile_data_file shell_data_file heapdump_data_file ringtone_file media_rw_data_file radio_data_file shared_relro_file trace_data_file method_trace_data_file system_app_data_file cache_file cache_backup_file cache_recovery_file wallpaper_file shortcut_manager_icons asec_apk_file backup_data_file app_fuse_file dnsproxyd_socket fwmarkd_socket logd_socket logdr_socket logdw_socket mdnsd_socket property_socket statsdw_socket system_ndebug_socket system_unsolzygote_socket tombstoned_crash_socket tombstoned_java_trace_socket traced_consumer_socket traced_perf_socket traced_producer_socket heapprofd_socket pdx_display_client_endpoint_socket pdx_display_manager_endpoint_socket pdx_display_screenshot_endpoint_socket pdx_display_vsync_endpoint_socket pdx_performance_client_endpoint_socket pdx_bufferhub_client_endpoint_socket system_server_tmpfs traced_tmpfs wm_trace_data_file virtualizationservice_data_file kvm_device prng_seeder_socket heapprofd_tmpfs ))
877(typeattribute appdomain)
878(typeattributeset appdomain (bluetooth ephemeral_app gmscore_app isolated_app isolated_compute_app mediaprovider network_stack nfc platform_app priv_app radio rkpdapp runas_app secure_element shared_relro shell simpleperf system_app traceur_app untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 device_as_webcam mediaprovider_app permissioncontroller_app sdk_sandbox_34 sdk_sandbox_audit sdk_sandbox_next vzwomatrigger_app ))
879(typeattribute untrusted_app_all)
880(typeattributeset untrusted_app_all (runas_app simpleperf untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 ))
881(typeattribute isolated_app_all)
882(typeattributeset isolated_app_all (isolated_app isolated_compute_app ))
883(typeattribute isolated_compute_allowed_service)
884(typeattributeset isolated_compute_allowed_service (audioserver_service cameraserver_service mediaserver_service content_capture_service device_state_service speech_recognition_service hal_codec2_service ))
885(typeattribute isolated_compute_allowed_device)
886(typeattributeset isolated_compute_allowed_device (hwbinder_device ion_device dmabuf_system_heap_device ))
887(typeattribute netdomain)
888(typeattributeset netdomain (adbd bluetooth dhcp dnsmasq drmserver dumpstate ephemeral_app gmscore_app mdnsd mediadrmserver mediaprovider mediaserver netd network_stack nfc platform_app priv_app radio rkpdapp runas_app shell system_app system_server untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 update_engine clatd ot_daemon sdk_sandbox_34 sdk_sandbox_audit sdk_sandbox_next ))
889(typeattribute bluetoothdomain)
890(typeattributeset bluetoothdomain (platform_app priv_app radio runas_app system_server untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 ))
891(typeattribute binderservicedomain)
892(typeattributeset binderservicedomain (audioserver cameraserver credstore drmserver evsmanagerd gatekeeperd idmap inputflinger keystore logd mediadrmserver mediaextractor mediametrics mediaserver mediatranscoding nfc radio secure_element surfaceflinger system_app system_server virtual_touchpad gsid mediatuner rkpd ))
893(typeattribute bpfdomain)
894(expandtypeattribute (bpfdomain) false)
895(typeattributeset bpfdomain (bpfloader charger_vendor gpuservice lmkd netd netutils_wrapper network_stack system_server mediaprovider_app uprobestats ))
896(typeattribute update_engine_common)
897(typeattributeset update_engine_common (update_engine ))
898(typeattribute coredomain)
899(typeattributeset coredomain (adbd apexd app_zygote artd atrace audioserver blkid blkid_untrusted bluetooth bootanim bootstat bpfloader bufferhubd cameraserver charger crash_dump credstore dhcp dnsmasq drmserver dumpstate e2fs ephemeral_app evsmanagerd extra_free_kbytes fastbootd fingerprintd flags_health_check fsck fsck_untrusted gatekeeperd gmscore_app gpuservice healthd heapprofd hwservicemanager idmap incident incident_helper incidentd init inputflinger installd isolated_app isolated_compute_app kernel keystore llkd lmkd logd logpersist mdnsd mediadrmserver mediaextractor mediametrics mediaprovider mediaserver mediaswcodec mediatranscoding modprobe netd netutils_wrapper network_stack nfc otapreopt_chroot perfetto performanced platform_app postinstall priv_app prng_seeder profman radio recovery recovery_persist recovery_refresh rkpdapp rs rss_hwm_reset runas runas_app sdcardd secure_element servicemanager sgdisk shared_relro shell simpleperf simpleperf_app_runner slideshow statsd surfaceflinger system_app system_server tombstoned toolbox traced traced_perf traced_probes traceur_app ueventd uncrypt untrusted_app untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 update_engine update_verifier usbd vdc virtual_touchpad vold vold_prepare_subdirs watchdogd webview_zygote wificond zygote aconfigd apex_test_prepostinstall apexd_derive_classpath art_boot auditctl automotive_display_service blank_screen boringssl_self_test canhalconfigurator clatd compos_fd_server compos_verify composd cppreopts crosvm derive_classpath derive_sdk device_as_webcam dex2oat dexopt_chroot_setup dexoptanalyzer dmesgd fsverity_init fuseblkd fuseblkd_untrusted fwk_bufferhub gki_apex_prepostinstall gsid hal_allocator_default iw linkerconfig lpdumpd mediaprovider_app mediatuner migrate_legacy_obb_data misctrl mm_events mtectrl odrefresh odsign ot_daemon otapreopt_slot permissioncontroller_app postinstall_dexopt preloads_copy preopt2cachename profcollectd remount rkpd sdk_sandbox_34 sdk_sandbox_audit sdk_sandbox_next simpleperf_boot snapshotctl snapuserd stats storaged system_server_startup system_suspend uprobestats vehicle_binding_util viewcompiler virtual_camera virtualizationmanager virtualizationservice wait_for_keymaster ))
900(typeattribute vendor_hwservice_type)
901(typeattribute coredomain_socket)
902(expandtypeattribute (coredomain_socket) false)
903(typeattributeset coredomain_socket (drmserver_socket adbd_socket bluetooth_socket dnsproxyd_socket dumpstate_socket fwmarkd_socket lmkd_socket logd_socket logdr_socket logdw_socket mdns_socket mdnsd_socket misc_logd_file mtpd_socket ot_daemon_socket property_socket racoon_socket recovery_socket snapuserd_socket snapuserd_proxy_socket statsdw_socket system_wpa_socket system_ndebug_socket system_unsolzygote_socket tombstoned_crash_socket tombstoned_intercept_socket traced_consumer_socket traced_perf_socket traced_producer_socket uncrypt_socket zygote_socket heapprofd_socket pdx_display_client_endpoint_socket pdx_display_client_channel_socket pdx_display_manager_endpoint_socket pdx_display_manager_channel_socket pdx_display_screenshot_endpoint_socket pdx_display_screenshot_channel_socket pdx_display_vsync_endpoint_socket pdx_display_vsync_channel_socket pdx_performance_client_endpoint_socket pdx_performance_client_channel_socket pdx_bufferhub_client_endpoint_socket pdx_bufferhub_client_channel_socket prng_seeder_socket aconfigd_socket ))
904(typeattribute socket_between_core_and_vendor_violators)
905(expandtypeattribute (socket_between_core_and_vendor_violators) false)
906(typeattribute vendor_executes_system_violators)
907(expandtypeattribute (vendor_executes_system_violators) false)
908(typeattribute data_between_core_and_vendor_violators)
909(expandtypeattribute (data_between_core_and_vendor_violators) false)
910(typeattribute system_executes_vendor_violators)
911(expandtypeattribute (system_executes_vendor_violators) false)
912(typeattribute system_writes_vendor_properties_violators)
913(expandtypeattribute (system_writes_vendor_properties_violators) false)
914(typeattribute system_writes_mnt_vendor_violators)
915(expandtypeattribute (system_writes_mnt_vendor_violators) false)
916(typeattribute untrusted_app_visible_hwservice_violators)
917(expandtypeattribute (untrusted_app_visible_hwservice_violators) false)
918(typeattribute untrusted_app_visible_halserver_violators)
919(expandtypeattribute (untrusted_app_visible_halserver_violators) false)
920(typeattribute pdx_endpoint_dir_type)
921(typeattributeset pdx_endpoint_dir_type (pdx_display_dir pdx_performance_dir pdx_bufferhub_dir ))
922(typeattribute pdx_endpoint_socket_type)
923(expandtypeattribute (pdx_endpoint_socket_type) false)
924(typeattributeset pdx_endpoint_socket_type (pdx_display_client_endpoint_socket pdx_display_manager_endpoint_socket pdx_display_screenshot_endpoint_socket pdx_display_vsync_endpoint_socket pdx_performance_client_endpoint_socket pdx_bufferhub_client_endpoint_socket ))
925(typeattribute pdx_channel_socket_type)
926(expandtypeattribute (pdx_channel_socket_type) false)
927(typeattributeset pdx_channel_socket_type (pdx_display_client_channel_socket pdx_display_manager_channel_socket pdx_display_screenshot_channel_socket pdx_display_vsync_channel_socket pdx_performance_client_channel_socket pdx_bufferhub_client_channel_socket ))
928(typeattribute pdx_display_client_endpoint_dir_type)
929(typeattributeset pdx_display_client_endpoint_dir_type (pdx_display_dir ))
930(typeattribute pdx_display_client_endpoint_socket_type)
931(typeattributeset pdx_display_client_endpoint_socket_type (pdx_display_client_endpoint_socket ))
932(typeattribute pdx_display_client_channel_socket_type)
933(typeattributeset pdx_display_client_channel_socket_type (pdx_display_client_channel_socket ))
934(typeattribute pdx_display_client_server_type)
935(typeattributeset pdx_display_client_server_type (surfaceflinger ))
936(typeattribute pdx_display_manager_endpoint_dir_type)
937(typeattributeset pdx_display_manager_endpoint_dir_type (pdx_display_dir ))
938(typeattribute pdx_display_manager_endpoint_socket_type)
939(typeattributeset pdx_display_manager_endpoint_socket_type (pdx_display_manager_endpoint_socket ))
940(typeattribute pdx_display_manager_channel_socket_type)
941(typeattributeset pdx_display_manager_channel_socket_type (pdx_display_manager_channel_socket ))
942(typeattribute pdx_display_manager_server_type)
943(typeattributeset pdx_display_manager_server_type (surfaceflinger ))
944(typeattribute pdx_display_screenshot_endpoint_dir_type)
945(typeattributeset pdx_display_screenshot_endpoint_dir_type (pdx_display_dir ))
946(typeattribute pdx_display_screenshot_endpoint_socket_type)
947(typeattributeset pdx_display_screenshot_endpoint_socket_type (pdx_display_screenshot_endpoint_socket ))
948(typeattribute pdx_display_screenshot_channel_socket_type)
949(typeattributeset pdx_display_screenshot_channel_socket_type (pdx_display_screenshot_channel_socket ))
950(typeattribute pdx_display_screenshot_server_type)
951(typeattributeset pdx_display_screenshot_server_type (surfaceflinger ))
952(typeattribute pdx_display_vsync_endpoint_dir_type)
953(typeattributeset pdx_display_vsync_endpoint_dir_type (pdx_display_dir ))
954(typeattribute pdx_display_vsync_endpoint_socket_type)
955(typeattributeset pdx_display_vsync_endpoint_socket_type (pdx_display_vsync_endpoint_socket ))
956(typeattribute pdx_display_vsync_channel_socket_type)
957(typeattributeset pdx_display_vsync_channel_socket_type (pdx_display_vsync_channel_socket ))
958(typeattribute pdx_display_vsync_server_type)
959(typeattributeset pdx_display_vsync_server_type (surfaceflinger ))
960(typeattribute pdx_performance_client_endpoint_dir_type)
961(typeattributeset pdx_performance_client_endpoint_dir_type (pdx_performance_dir ))
962(typeattribute pdx_performance_client_endpoint_socket_type)
963(typeattributeset pdx_performance_client_endpoint_socket_type (pdx_performance_client_endpoint_socket ))
964(typeattribute pdx_performance_client_channel_socket_type)
965(typeattributeset pdx_performance_client_channel_socket_type (pdx_performance_client_channel_socket ))
966(typeattribute pdx_performance_client_server_type)
967(typeattributeset pdx_performance_client_server_type (performanced ))
968(typeattribute pdx_bufferhub_client_endpoint_dir_type)
969(typeattributeset pdx_bufferhub_client_endpoint_dir_type (pdx_bufferhub_dir ))
970(typeattribute pdx_bufferhub_client_endpoint_socket_type)
971(typeattributeset pdx_bufferhub_client_endpoint_socket_type (pdx_bufferhub_client_endpoint_socket ))
972(typeattribute pdx_bufferhub_client_channel_socket_type)
973(typeattributeset pdx_bufferhub_client_channel_socket_type (pdx_bufferhub_client_channel_socket ))
974(typeattribute pdx_bufferhub_client_server_type)
975(typeattributeset pdx_bufferhub_client_server_type (bufferhubd ))
976(typeattribute halserverdomain)
977(typeattributeset halserverdomain (charger_vendor mediaswcodec hal_allocator_default virtualizationservice ))
978(typeattribute halclientdomain)
979(expandtypeattribute (halclientdomain) true)
980(typeattributeset halclientdomain (adbd atrace audioserver bluetooth bootanim bufferhubd cameraserver charger credstore dumpstate evsmanagerd gatekeeperd isolated_compute_app keystore mediadrmserver mediaextractor mediaserver mediaswcodec mediatranscoding network_stack nfc radio rkpdapp secure_element shell statsd surfaceflinger system_app system_server traced_probes traceur_app update_engine update_verifier usbd vold wificond automotive_display_service blank_screen canhalconfigurator fwk_bufferhub mediatuner odsign ot_daemon snapshotctl storaged vehicle_binding_util virtual_camera virtualizationmanager virtualizationservice ))
981(typeattribute hal_automotive_socket_exemption)
982(typeattribute hal_allocator)
983(expandtypeattribute (hal_allocator) true)
984(typeattributeset hal_allocator (hal_allocator_default ))
985(typeattribute hal_allocator_client)
986(expandtypeattribute (hal_allocator_client) true)
987(typeattributeset hal_allocator_client (audioserver cameraserver isolated_compute_app mediaextractor mediaserver mediaswcodec mediatranscoding system_server ))
988(typeattribute hal_allocator_server)
989(expandtypeattribute (hal_allocator_server) false)
990(typeattributeset hal_allocator_server (hal_allocator_default ))
991(typeattribute hal_atrace)
992(expandtypeattribute (hal_atrace) true)
993(typeattribute hal_atrace_client)
994(expandtypeattribute (hal_atrace_client) true)
995(typeattributeset hal_atrace_client (atrace shell traced_probes traceur_app ))
996(typeattribute hal_atrace_server)
997(expandtypeattribute (hal_atrace_server) false)
998(typeattribute hal_audio)
999(expandtypeattribute (hal_audio) true)
1000(typeattribute hal_audio_client)
1001(expandtypeattribute (hal_audio_client) true)
1002(typeattributeset hal_audio_client (audioserver bluetooth dumpstate system_server ))
1003(typeattribute hal_audio_server)
1004(expandtypeattribute (hal_audio_server) false)
1005(typeattribute hal_audiocontrol)
1006(expandtypeattribute (hal_audiocontrol) true)
1007(typeattribute hal_audiocontrol_client)
1008(expandtypeattribute (hal_audiocontrol_client) true)
1009(typeattributeset hal_audiocontrol_client (dumpstate ))
1010(typeattribute hal_audiocontrol_server)
1011(expandtypeattribute (hal_audiocontrol_server) false)
1012(typeattribute hal_authgraph)
1013(expandtypeattribute (hal_authgraph) true)
1014(typeattribute hal_authgraph_client)
1015(expandtypeattribute (hal_authgraph_client) true)
1016(typeattributeset hal_authgraph_client (dumpstate system_server ))
1017(typeattribute hal_authgraph_server)
1018(expandtypeattribute (hal_authgraph_server) false)
1019(typeattribute hal_authsecret)
1020(expandtypeattribute (hal_authsecret) true)
1021(typeattribute hal_authsecret_client)
1022(expandtypeattribute (hal_authsecret_client) true)
1023(typeattributeset hal_authsecret_client (dumpstate system_server ))
1024(typeattribute hal_authsecret_server)
1025(expandtypeattribute (hal_authsecret_server) false)
1026(typeattribute hal_bluetooth)
1027(expandtypeattribute (hal_bluetooth) true)
1028(typeattribute hal_bluetooth_client)
1029(expandtypeattribute (hal_bluetooth_client) true)
1030(typeattributeset hal_bluetooth_client (bluetooth dumpstate system_server ))
1031(typeattribute hal_bluetooth_server)
1032(expandtypeattribute (hal_bluetooth_server) false)
1033(typeattribute hal_bootctl)
1034(expandtypeattribute (hal_bootctl) true)
1035(typeattribute hal_bootctl_client)
1036(expandtypeattribute (hal_bootctl_client) true)
1037(typeattributeset hal_bootctl_client (system_server update_engine update_verifier vold snapshotctl ))
1038(typeattribute hal_bootctl_server)
1039(expandtypeattribute (hal_bootctl_server) false)
1040(typeattribute hal_broadcastradio)
1041(expandtypeattribute (hal_broadcastradio) true)
1042(typeattribute hal_broadcastradio_client)
1043(expandtypeattribute (hal_broadcastradio_client) true)
1044(typeattributeset hal_broadcastradio_client (dumpstate system_server ))
1045(typeattribute hal_broadcastradio_server)
1046(expandtypeattribute (hal_broadcastradio_server) false)
1047(typeattribute hal_camera)
1048(expandtypeattribute (hal_camera) true)
1049(typeattribute hal_camera_client)
1050(expandtypeattribute (hal_camera_client) true)
1051(typeattributeset hal_camera_client (cameraserver dumpstate ))
1052(typeattribute hal_camera_server)
1053(expandtypeattribute (hal_camera_server) false)
1054(typeattribute hal_can_bus)
1055(expandtypeattribute (hal_can_bus) true)
1056(typeattribute hal_can_bus_client)
1057(expandtypeattribute (hal_can_bus_client) true)
1058(typeattribute hal_can_bus_server)
1059(expandtypeattribute (hal_can_bus_server) false)
1060(typeattribute hal_can_controller)
1061(expandtypeattribute (hal_can_controller) true)
1062(typeattribute hal_can_controller_client)
1063(expandtypeattribute (hal_can_controller_client) true)
1064(typeattributeset hal_can_controller_client (canhalconfigurator ))
1065(typeattribute hal_can_controller_server)
1066(expandtypeattribute (hal_can_controller_server) false)
1067(typeattribute hal_cas)
1068(expandtypeattribute (hal_cas) true)
1069(typeattribute hal_cas_client)
1070(expandtypeattribute (hal_cas_client) true)
1071(typeattributeset hal_cas_client (mediaextractor ))
1072(typeattribute hal_cas_server)
1073(expandtypeattribute (hal_cas_server) false)
1074(typeattribute hal_codec2)
1075(expandtypeattribute (hal_codec2) true)
1076(typeattributeset hal_codec2 (mediaswcodec ))
1077(typeattribute hal_codec2_client)
1078(expandtypeattribute (hal_codec2_client) true)
1079(typeattributeset hal_codec2_client (cameraserver dumpstate isolated_compute_app mediaserver mediaswcodec mediatranscoding surfaceflinger system_server virtual_camera ))
1080(typeattribute hal_codec2_server)
1081(expandtypeattribute (hal_codec2_server) false)
1082(typeattributeset hal_codec2_server (mediaswcodec ))
1083(typeattribute hal_configstore)
1084(expandtypeattribute (hal_configstore) true)
1085(typeattribute hal_configstore_client)
1086(expandtypeattribute (hal_configstore_client) true)
1087(typeattributeset hal_configstore_client (bootanim mediaserver mediatranscoding surfaceflinger system_server ))
1088(typeattribute hal_configstore_server)
1089(expandtypeattribute (hal_configstore_server) false)
1090(typeattribute hal_confirmationui)
1091(expandtypeattribute (hal_confirmationui) true)
1092(typeattribute hal_confirmationui_client)
1093(expandtypeattribute (hal_confirmationui_client) true)
1094(typeattributeset hal_confirmationui_client (keystore ))
1095(typeattribute hal_confirmationui_server)
1096(expandtypeattribute (hal_confirmationui_server) false)
1097(typeattribute hal_contexthub)
1098(expandtypeattribute (hal_contexthub) true)
1099(typeattribute hal_contexthub_client)
1100(expandtypeattribute (hal_contexthub_client) true)
1101(typeattributeset hal_contexthub_client (dumpstate system_server ))
1102(typeattribute hal_contexthub_server)
1103(expandtypeattribute (hal_contexthub_server) false)
1104(typeattribute hal_drm)
1105(expandtypeattribute (hal_drm) true)
1106(typeattribute hal_drm_client)
1107(expandtypeattribute (hal_drm_client) true)
1108(typeattributeset hal_drm_client (dumpstate mediadrmserver mediaserver ))
1109(typeattribute hal_drm_server)
1110(expandtypeattribute (hal_drm_server) false)
1111(typeattribute hal_dumpstate)
1112(expandtypeattribute (hal_dumpstate) true)
1113(typeattribute hal_dumpstate_client)
1114(expandtypeattribute (hal_dumpstate_client) true)
1115(typeattributeset hal_dumpstate_client (dumpstate system_app ))
1116(typeattribute hal_dumpstate_server)
1117(expandtypeattribute (hal_dumpstate_server) false)
1118(typeattribute hal_evs)
1119(expandtypeattribute (hal_evs) true)
1120(typeattribute hal_evs_client)
1121(expandtypeattribute (hal_evs_client) true)
1122(typeattributeset hal_evs_client (dumpstate evsmanagerd ))
1123(typeattribute hal_evs_server)
1124(expandtypeattribute (hal_evs_server) false)
1125(typeattribute hal_face)
1126(expandtypeattribute (hal_face) true)
1127(typeattribute hal_face_client)
1128(expandtypeattribute (hal_face_client) true)
1129(typeattributeset hal_face_client (dumpstate system_server ))
1130(typeattribute hal_face_server)
1131(expandtypeattribute (hal_face_server) false)
1132(typeattribute hal_fastboot)
1133(expandtypeattribute (hal_fastboot) true)
1134(typeattribute hal_fastboot_client)
1135(expandtypeattribute (hal_fastboot_client) true)
1136(typeattribute hal_fastboot_server)
1137(expandtypeattribute (hal_fastboot_server) false)
1138(typeattribute hal_fingerprint)
1139(expandtypeattribute (hal_fingerprint) true)
1140(typeattribute hal_fingerprint_client)
1141(expandtypeattribute (hal_fingerprint_client) true)
1142(typeattributeset hal_fingerprint_client (dumpstate system_server ))
1143(typeattribute hal_fingerprint_server)
1144(expandtypeattribute (hal_fingerprint_server) false)
1145(typeattribute hal_gatekeeper)
1146(expandtypeattribute (hal_gatekeeper) true)
1147(typeattribute hal_gatekeeper_client)
1148(expandtypeattribute (hal_gatekeeper_client) true)
1149(typeattributeset hal_gatekeeper_client (gatekeeperd ))
1150(typeattribute hal_gatekeeper_server)
1151(expandtypeattribute (hal_gatekeeper_server) false)
1152(typeattribute hal_gnss)
1153(expandtypeattribute (hal_gnss) true)
1154(typeattribute hal_gnss_client)
1155(expandtypeattribute (hal_gnss_client) true)
1156(typeattributeset hal_gnss_client (dumpstate system_server ))
1157(typeattribute hal_gnss_server)
1158(expandtypeattribute (hal_gnss_server) false)
1159(typeattribute hal_graphics_allocator)
1160(expandtypeattribute (hal_graphics_allocator) true)
1161(typeattribute hal_graphics_allocator_client)
1162(expandtypeattribute (hal_graphics_allocator_client) true)
1163(typeattributeset hal_graphics_allocator_client (adbd bootanim bufferhubd cameraserver dumpstate mediadrmserver mediaserver mediaswcodec mediatranscoding surfaceflinger system_server automotive_display_service fwk_bufferhub virtual_camera ))
1164(typeattribute hal_graphics_allocator_server)
1165(expandtypeattribute (hal_graphics_allocator_server) false)
1166(typeattribute hal_graphics_composer)
1167(expandtypeattribute (hal_graphics_composer) true)
1168(typeattribute hal_graphics_composer_client)
1169(expandtypeattribute (hal_graphics_composer_client) true)
1170(typeattributeset hal_graphics_composer_client (bootanim dumpstate surfaceflinger automotive_display_service ))
1171(typeattribute hal_graphics_composer_server)
1172(expandtypeattribute (hal_graphics_composer_server) false)
1173(typeattribute hal_health)
1174(expandtypeattribute (hal_health) true)
1175(typeattributeset hal_health (charger_vendor ))
1176(typeattribute hal_health_client)
1177(expandtypeattribute (hal_health_client) true)
1178(typeattributeset hal_health_client (charger dumpstate statsd system_server traced_probes storaged ))
1179(typeattribute hal_health_server)
1180(expandtypeattribute (hal_health_server) false)
1181(typeattributeset hal_health_server (charger_vendor ))
1182(typeattribute hal_health_storage)
1183(expandtypeattribute (hal_health_storage) true)
1184(typeattribute hal_health_storage_client)
1185(expandtypeattribute (hal_health_storage_client) true)
1186(typeattributeset hal_health_storage_client (vold ))
1187(typeattribute hal_health_storage_server)
1188(expandtypeattribute (hal_health_storage_server) false)
1189(typeattribute hal_identity)
1190(expandtypeattribute (hal_identity) true)
1191(typeattribute hal_identity_client)
1192(expandtypeattribute (hal_identity_client) true)
1193(typeattributeset hal_identity_client (credstore dumpstate ))
1194(typeattribute hal_identity_server)
1195(expandtypeattribute (hal_identity_server) false)
1196(typeattribute hal_input_classifier)
1197(expandtypeattribute (hal_input_classifier) true)
1198(typeattribute hal_input_classifier_client)
1199(expandtypeattribute (hal_input_classifier_client) true)
1200(typeattributeset hal_input_classifier_client (system_server ))
1201(typeattribute hal_input_classifier_server)
1202(expandtypeattribute (hal_input_classifier_server) false)
1203(typeattribute hal_input_processor)
1204(expandtypeattribute (hal_input_processor) true)
1205(typeattribute hal_input_processor_client)
1206(expandtypeattribute (hal_input_processor_client) true)
1207(typeattributeset hal_input_processor_client (dumpstate system_server ))
1208(typeattribute hal_input_processor_server)
1209(expandtypeattribute (hal_input_processor_server) false)
1210(typeattribute hal_ir)
1211(expandtypeattribute (hal_ir) true)
1212(typeattribute hal_ir_client)
1213(expandtypeattribute (hal_ir_client) true)
1214(typeattributeset hal_ir_client (system_server ))
1215(typeattribute hal_ir_server)
1216(expandtypeattribute (hal_ir_server) false)
1217(typeattribute hal_ivn)
1218(expandtypeattribute (hal_ivn) true)
1219(typeattribute hal_ivn_client)
1220(expandtypeattribute (hal_ivn_client) true)
1221(typeattribute hal_ivn_server)
1222(expandtypeattribute (hal_ivn_server) false)
1223(typeattribute hal_keymaster)
1224(expandtypeattribute (hal_keymaster) true)
1225(typeattribute hal_keymaster_client)
1226(expandtypeattribute (hal_keymaster_client) true)
1227(typeattributeset hal_keymaster_client (keystore odsign ))
1228(typeattribute hal_keymaster_server)
1229(expandtypeattribute (hal_keymaster_server) false)
1230(typeattribute hal_keymint)
1231(expandtypeattribute (hal_keymint) true)
1232(typeattribute hal_keymint_client)
1233(expandtypeattribute (hal_keymint_client) true)
1234(typeattributeset hal_keymint_client (credstore dumpstate keystore rkpdapp system_server ))
1235(typeattribute hal_keymint_server)
1236(expandtypeattribute (hal_keymint_server) false)
1237(typeattribute hal_light)
1238(expandtypeattribute (hal_light) true)
1239(typeattribute hal_light_client)
1240(expandtypeattribute (hal_light_client) true)
1241(typeattributeset hal_light_client (dumpstate system_server blank_screen ))
1242(typeattribute hal_light_server)
1243(expandtypeattribute (hal_light_server) false)
1244(typeattribute hal_lowpan)
1245(expandtypeattribute (hal_lowpan) true)
1246(typeattribute hal_lowpan_client)
1247(expandtypeattribute (hal_lowpan_client) true)
1248(typeattribute hal_lowpan_server)
1249(expandtypeattribute (hal_lowpan_server) false)
1250(typeattribute hal_macsec)
1251(expandtypeattribute (hal_macsec) true)
1252(typeattribute hal_macsec_client)
1253(expandtypeattribute (hal_macsec_client) true)
1254(typeattribute hal_macsec_server)
1255(expandtypeattribute (hal_macsec_server) false)
1256(typeattribute hal_memtrack)
1257(expandtypeattribute (hal_memtrack) true)
1258(typeattribute hal_memtrack_client)
1259(expandtypeattribute (hal_memtrack_client) true)
1260(typeattributeset hal_memtrack_client (dumpstate system_server ))
1261(typeattribute hal_memtrack_server)
1262(expandtypeattribute (hal_memtrack_server) false)
1263(typeattribute hal_neuralnetworks)
1264(expandtypeattribute (hal_neuralnetworks) true)
1265(typeattribute hal_neuralnetworks_client)
1266(expandtypeattribute (hal_neuralnetworks_client) true)
1267(typeattributeset hal_neuralnetworks_client (dumpstate system_server ))
1268(typeattribute hal_neuralnetworks_server)
1269(expandtypeattribute (hal_neuralnetworks_server) false)
1270(typeattribute hal_nfc)
1271(expandtypeattribute (hal_nfc) true)
1272(typeattribute hal_nfc_client)
1273(expandtypeattribute (hal_nfc_client) true)
1274(typeattributeset hal_nfc_client (dumpstate nfc ))
1275(typeattribute hal_nfc_server)
1276(expandtypeattribute (hal_nfc_server) false)
1277(typeattribute hal_nlinterceptor)
1278(expandtypeattribute (hal_nlinterceptor) true)
1279(typeattribute hal_nlinterceptor_client)
1280(expandtypeattribute (hal_nlinterceptor_client) true)
1281(typeattributeset hal_nlinterceptor_client (wificond ))
1282(typeattribute hal_nlinterceptor_server)
1283(expandtypeattribute (hal_nlinterceptor_server) false)
1284(typeattribute hal_oemlock)
1285(expandtypeattribute (hal_oemlock) true)
1286(typeattribute hal_oemlock_client)
1287(expandtypeattribute (hal_oemlock_client) true)
1288(typeattributeset hal_oemlock_client (dumpstate system_server ))
1289(typeattribute hal_oemlock_server)
1290(expandtypeattribute (hal_oemlock_server) false)
1291(typeattribute hal_omx)
1292(expandtypeattribute (hal_omx) true)
1293(typeattribute hal_omx_client)
1294(expandtypeattribute (hal_omx_client) true)
1295(typeattributeset hal_omx_client (cameraserver mediaserver mediaswcodec mediatranscoding surfaceflinger system_server virtual_camera ))
1296(typeattribute hal_omx_server)
1297(expandtypeattribute (hal_omx_server) false)
1298(typeattribute hal_power)
1299(expandtypeattribute (hal_power) true)
1300(typeattribute hal_power_client)
1301(expandtypeattribute (hal_power_client) true)
1302(typeattributeset hal_power_client (dumpstate statsd surfaceflinger system_server ))
1303(typeattribute hal_power_server)
1304(expandtypeattribute (hal_power_server) false)
1305(typeattribute hal_power_stats)
1306(expandtypeattribute (hal_power_stats) true)
1307(typeattribute hal_power_stats_client)
1308(expandtypeattribute (hal_power_stats_client) true)
1309(typeattributeset hal_power_stats_client (dumpstate statsd system_server traced_probes ))
1310(typeattribute hal_power_stats_server)
1311(expandtypeattribute (hal_power_stats_server) false)
1312(typeattribute hal_rebootescrow)
1313(expandtypeattribute (hal_rebootescrow) true)
1314(typeattribute hal_rebootescrow_client)
1315(expandtypeattribute (hal_rebootescrow_client) true)
1316(typeattributeset hal_rebootescrow_client (dumpstate system_server ))
1317(typeattribute hal_rebootescrow_server)
1318(expandtypeattribute (hal_rebootescrow_server) false)
1319(typeattribute hal_remoteaccess)
1320(expandtypeattribute (hal_remoteaccess) true)
1321(typeattribute hal_remoteaccess_client)
1322(expandtypeattribute (hal_remoteaccess_client) true)
1323(typeattribute hal_remoteaccess_server)
1324(expandtypeattribute (hal_remoteaccess_server) false)
1325(typeattribute hal_secretkeeper)
1326(expandtypeattribute (hal_secretkeeper) true)
1327(typeattribute hal_secretkeeper_client)
1328(expandtypeattribute (hal_secretkeeper_client) true)
1329(typeattributeset hal_secretkeeper_client (dumpstate virtualizationmanager virtualizationservice ))
1330(typeattribute hal_secretkeeper_server)
1331(expandtypeattribute (hal_secretkeeper_server) false)
1332(typeattribute hal_remotelyprovisionedcomponent_avf)
1333(expandtypeattribute (hal_remotelyprovisionedcomponent_avf) true)
1334(typeattributeset hal_remotelyprovisionedcomponent_avf (virtualizationservice ))
1335(typeattribute hal_remotelyprovisionedcomponent_avf_client)
1336(expandtypeattribute (hal_remotelyprovisionedcomponent_avf_client) true)
1337(typeattributeset hal_remotelyprovisionedcomponent_avf_client (rkpdapp system_server ))
1338(typeattribute hal_remotelyprovisionedcomponent_avf_server)
1339(expandtypeattribute (hal_remotelyprovisionedcomponent_avf_server) false)
1340(typeattributeset hal_remotelyprovisionedcomponent_avf_server (virtualizationservice ))
1341(typeattribute hal_secure_element)
1342(expandtypeattribute (hal_secure_element) true)
1343(typeattribute hal_secure_element_client)
1344(expandtypeattribute (hal_secure_element_client) true)
1345(typeattributeset hal_secure_element_client (secure_element ))
1346(typeattribute hal_secure_element_server)
1347(expandtypeattribute (hal_secure_element_server) false)
1348(typeattribute hal_sensors)
1349(expandtypeattribute (hal_sensors) true)
1350(typeattribute hal_sensors_client)
1351(expandtypeattribute (hal_sensors_client) true)
1352(typeattributeset hal_sensors_client (dumpstate system_server ))
1353(typeattribute hal_sensors_server)
1354(expandtypeattribute (hal_sensors_server) false)
1355(typeattribute hal_telephony)
1356(expandtypeattribute (hal_telephony) true)
1357(typeattribute hal_telephony_client)
1358(expandtypeattribute (hal_telephony_client) true)
1359(typeattributeset hal_telephony_client (bluetooth radio ))
1360(typeattribute hal_telephony_server)
1361(expandtypeattribute (hal_telephony_server) false)
1362(typeattribute hal_tetheroffload)
1363(expandtypeattribute (hal_tetheroffload) true)
1364(typeattribute hal_tetheroffload_client)
1365(expandtypeattribute (hal_tetheroffload_client) true)
1366(typeattributeset hal_tetheroffload_client (network_stack system_server ))
1367(typeattribute hal_tetheroffload_server)
1368(expandtypeattribute (hal_tetheroffload_server) false)
1369(typeattribute hal_thermal)
1370(expandtypeattribute (hal_thermal) true)
1371(typeattribute hal_thermal_client)
1372(expandtypeattribute (hal_thermal_client) true)
1373(typeattributeset hal_thermal_client (dumpstate statsd system_server ))
1374(typeattribute hal_thermal_server)
1375(expandtypeattribute (hal_thermal_server) false)
1376(typeattribute hal_threadnetwork)
1377(expandtypeattribute (hal_threadnetwork) true)
1378(typeattribute hal_threadnetwork_client)
1379(expandtypeattribute (hal_threadnetwork_client) true)
1380(typeattributeset hal_threadnetwork_client (system_server ot_daemon ))
1381(typeattribute hal_threadnetwork_server)
1382(expandtypeattribute (hal_threadnetwork_server) false)
1383(typeattribute hal_tv_cec)
1384(expandtypeattribute (hal_tv_cec) true)
1385(typeattribute hal_tv_cec_client)
1386(expandtypeattribute (hal_tv_cec_client) true)
1387(typeattributeset hal_tv_cec_client (system_server ))
1388(typeattribute hal_tv_cec_server)
1389(expandtypeattribute (hal_tv_cec_server) false)
1390(typeattribute hal_tv_hdmi_cec)
1391(expandtypeattribute (hal_tv_hdmi_cec) true)
1392(typeattribute hal_tv_hdmi_cec_client)
1393(expandtypeattribute (hal_tv_hdmi_cec_client) true)
1394(typeattributeset hal_tv_hdmi_cec_client (system_server ))
1395(typeattribute hal_tv_hdmi_cec_server)
1396(expandtypeattribute (hal_tv_hdmi_cec_server) false)
1397(typeattribute hal_tv_hdmi_connection)
1398(expandtypeattribute (hal_tv_hdmi_connection) true)
1399(typeattribute hal_tv_hdmi_connection_client)
1400(expandtypeattribute (hal_tv_hdmi_connection_client) true)
1401(typeattributeset hal_tv_hdmi_connection_client (system_server ))
1402(typeattribute hal_tv_hdmi_connection_server)
1403(expandtypeattribute (hal_tv_hdmi_connection_server) false)
1404(typeattribute hal_tv_hdmi_earc)
1405(expandtypeattribute (hal_tv_hdmi_earc) true)
1406(typeattribute hal_tv_hdmi_earc_client)
1407(expandtypeattribute (hal_tv_hdmi_earc_client) true)
1408(typeattributeset hal_tv_hdmi_earc_client (system_server ))
1409(typeattribute hal_tv_hdmi_earc_server)
1410(expandtypeattribute (hal_tv_hdmi_earc_server) false)
1411(typeattribute hal_tv_input)
1412(expandtypeattribute (hal_tv_input) true)
1413(typeattribute hal_tv_input_client)
1414(expandtypeattribute (hal_tv_input_client) true)
1415(typeattributeset hal_tv_input_client (system_server ))
1416(typeattribute hal_tv_input_server)
1417(expandtypeattribute (hal_tv_input_server) false)
1418(typeattribute hal_tv_tuner)
1419(expandtypeattribute (hal_tv_tuner) true)
1420(typeattribute hal_tv_tuner_client)
1421(expandtypeattribute (hal_tv_tuner_client) true)
1422(typeattributeset hal_tv_tuner_client (mediatuner ))
1423(typeattribute hal_tv_tuner_server)
1424(expandtypeattribute (hal_tv_tuner_server) false)
1425(typeattribute hal_usb)
1426(expandtypeattribute (hal_usb) true)
1427(typeattribute hal_usb_client)
1428(expandtypeattribute (hal_usb_client) true)
1429(typeattributeset hal_usb_client (system_server ))
1430(typeattribute hal_usb_server)
1431(expandtypeattribute (hal_usb_server) false)
1432(typeattribute hal_usb_gadget)
1433(expandtypeattribute (hal_usb_gadget) true)
1434(typeattribute hal_usb_gadget_client)
1435(expandtypeattribute (hal_usb_gadget_client) true)
1436(typeattributeset hal_usb_gadget_client (system_server usbd ))
1437(typeattribute hal_usb_gadget_server)
1438(expandtypeattribute (hal_usb_gadget_server) false)
1439(typeattribute hal_uwb)
1440(expandtypeattribute (hal_uwb) true)
1441(typeattribute hal_uwb_client)
1442(expandtypeattribute (hal_uwb_client) true)
1443(typeattributeset hal_uwb_client (system_server ))
1444(typeattribute hal_uwb_server)
1445(expandtypeattribute (hal_uwb_server) false)
1446(typeattribute hal_uwb_vendor)
1447(expandtypeattribute (hal_uwb_vendor) true)
1448(typeattribute hal_uwb_vendor_client)
1449(expandtypeattribute (hal_uwb_vendor_client) true)
1450(typeattribute hal_uwb_vendor_server)
1451(expandtypeattribute (hal_uwb_vendor_server) false)
1452(typeattribute hal_vehicle)
1453(expandtypeattribute (hal_vehicle) true)
1454(typeattribute hal_vehicle_client)
1455(expandtypeattribute (hal_vehicle_client) true)
1456(typeattributeset hal_vehicle_client (dumpstate vehicle_binding_util ))
1457(typeattribute hal_vehicle_server)
1458(expandtypeattribute (hal_vehicle_server) false)
1459(typeattribute hal_vibrator)
1460(expandtypeattribute (hal_vibrator) true)
1461(typeattribute hal_vibrator_client)
1462(expandtypeattribute (hal_vibrator_client) true)
1463(typeattributeset hal_vibrator_client (dumpstate system_server ))
1464(typeattribute hal_vibrator_server)
1465(expandtypeattribute (hal_vibrator_server) false)
1466(typeattribute hal_vr)
1467(expandtypeattribute (hal_vr) true)
1468(typeattribute hal_vr_client)
1469(expandtypeattribute (hal_vr_client) true)
1470(typeattributeset hal_vr_client (system_server ))
1471(typeattribute hal_vr_server)
1472(expandtypeattribute (hal_vr_server) false)
1473(typeattribute hal_weaver)
1474(expandtypeattribute (hal_weaver) true)
1475(typeattribute hal_weaver_client)
1476(expandtypeattribute (hal_weaver_client) true)
1477(typeattributeset hal_weaver_client (dumpstate system_server ))
1478(typeattribute hal_weaver_server)
1479(expandtypeattribute (hal_weaver_server) false)
1480(typeattribute hal_wifi)
1481(expandtypeattribute (hal_wifi) true)
1482(typeattribute hal_wifi_client)
1483(expandtypeattribute (hal_wifi_client) true)
1484(typeattributeset hal_wifi_client (dumpstate system_server ))
1485(typeattribute hal_wifi_server)
1486(expandtypeattribute (hal_wifi_server) false)
1487(typeattribute hal_wifi_hostapd)
1488(expandtypeattribute (hal_wifi_hostapd) true)
1489(typeattribute hal_wifi_hostapd_client)
1490(expandtypeattribute (hal_wifi_hostapd_client) true)
1491(typeattributeset hal_wifi_hostapd_client (system_server ))
1492(typeattribute hal_wifi_hostapd_server)
1493(expandtypeattribute (hal_wifi_hostapd_server) false)
1494(typeattribute hal_wifi_supplicant)
1495(expandtypeattribute (hal_wifi_supplicant) true)
1496(typeattribute hal_wifi_supplicant_client)
1497(expandtypeattribute (hal_wifi_supplicant_client) true)
1498(typeattributeset hal_wifi_supplicant_client (system_server ))
1499(typeattribute hal_wifi_supplicant_server)
1500(expandtypeattribute (hal_wifi_supplicant_server) false)
1501(typeattribute automotive_display_service_server)
1502(typeattributeset automotive_display_service_server (automotive_display_service ))
1503(typeattribute camera_service_server)
1504(typeattributeset camera_service_server (cameraserver ))
1505(typeattribute display_service_server)
1506(typeattributeset display_service_server (surfaceflinger ))
1507(typeattribute evsmanager_service_server)
1508(typeattributeset evsmanager_service_server (evsmanagerd ))
1509(typeattribute remote_provisioning_service_server)
1510(typeattributeset remote_provisioning_service_server (system_server ))
1511(typeattribute scheduler_service_server)
1512(typeattributeset scheduler_service_server (system_server ))
1513(typeattribute sensor_service_server)
1514(typeattributeset sensor_service_server (system_server ))
1515(typeattribute stats_service_server)
1516(typeattributeset stats_service_server (system_server ))
1517(typeattribute system_suspend_internal_server)
1518(typeattributeset system_suspend_internal_server (system_suspend ))
1519(typeattribute system_suspend_server)
1520(typeattributeset system_suspend_server (system_suspend ))
1521(typeattribute wifi_keystore_service_server)
1522(typeattributeset wifi_keystore_service_server (wificond ))
1523(typeattribute super_block_device_type)
1524(typeattributeset super_block_device_type (super_block_device ))
1525(typeattribute dmabuf_heap_device_type)
1526(expandtypeattribute (dmabuf_heap_device_type) false)
1527(typeattributeset dmabuf_heap_device_type (dmabuf_heap_device dmabuf_system_heap_device dmabuf_system_secure_heap_device ))
1528(typeattribute vm_manager_device_type)
1529(typeattributeset vm_manager_device_type (kvm_device ))
1530(typeattribute gsi_metadata_file_type)
1531(typeattributeset gsi_metadata_file_type (gsi_metadata_file gsi_public_metadata_file ))
1532(typeattribute apex_data_file_type)
1533(typeattributeset apex_data_file_type (apex_system_server_data_file apex_art_data_file apex_compos_data_file apex_virt_data_file apex_tethering_data_file apex_appsearch_data_file apex_permission_data_file apex_scheduling_data_file apex_wifi_data_file ))
1534(typeattribute charger_type)
1535(typeattributeset charger_type (charger charger_vendor ))
1536(typeattribute dalvik_config_prop_type)
1537(typeattributeset dalvik_config_prop_type (dalvik_config_prop dalvik_dynamic_config_prop ))
1538(type adbd)
1539(roletype object_r adbd)
1540(type adbd_exec)
1541(roletype object_r adbd_exec)
1542(type aidl_lazy_test_server)
1543(roletype object_r aidl_lazy_test_server)
1544(type aidl_lazy_test_server_exec)
1545(roletype object_r aidl_lazy_test_server_exec)
1546(type apexd)
1547(roletype object_r apexd)
1548(type apexd_exec)
1549(roletype object_r apexd_exec)
1550(type appdomain_tmpfs)
1551(roletype object_r appdomain_tmpfs)
1552(type app_zygote)
1553(roletype object_r app_zygote)
1554(type app_zygote_tmpfs)
1555(roletype object_r app_zygote_tmpfs)
1556(type artd)
1557(roletype object_r artd)
1558(type atrace)
1559(roletype object_r atrace)
1560(type audioserver)
1561(roletype object_r audioserver)
1562(type audioserver_tmpfs)
1563(roletype object_r audioserver_tmpfs)
1564(type blkid)
1565(roletype object_r blkid)
1566(type blkid_untrusted)
1567(roletype object_r blkid_untrusted)
1568(type bluetooth)
1569(roletype object_r bluetooth)
1570(type bootanim)
1571(roletype object_r bootanim)
1572(type bootanim_exec)
1573(roletype object_r bootanim_exec)
1574(type bootstat)
1575(roletype object_r bootstat)
1576(type bootstat_exec)
1577(roletype object_r bootstat_exec)
1578(type bpfloader)
1579(roletype object_r bpfloader)
1580(type bufferhubd)
1581(roletype object_r bufferhubd)
1582(type bufferhubd_exec)
1583(roletype object_r bufferhubd_exec)
1584(type cameraserver)
1585(roletype object_r cameraserver)
1586(type cameraserver_exec)
1587(roletype object_r cameraserver_exec)
1588(type cameraserver_tmpfs)
1589(roletype object_r cameraserver_tmpfs)
1590(type charger)
1591(roletype object_r charger)
1592(type charger_exec)
1593(roletype object_r charger_exec)
1594(type charger_vendor)
1595(roletype object_r charger_vendor)
1596(type crash_dump)
1597(roletype object_r crash_dump)
1598(type crash_dump_exec)
1599(roletype object_r crash_dump_exec)
1600(type credstore)
1601(roletype object_r credstore)
1602(type credstore_exec)
1603(roletype object_r credstore_exec)
1604(type device)
1605(roletype object_r device)
1606(type ashmem_device)
1607(roletype object_r ashmem_device)
1608(type ashmem_libcutils_device)
1609(roletype object_r ashmem_libcutils_device)
1610(type audio_device)
1611(roletype object_r audio_device)
1612(type binder_device)
1613(roletype object_r binder_device)
1614(type hwbinder_device)
1615(roletype object_r hwbinder_device)
1616(type vndbinder_device)
1617(roletype object_r vndbinder_device)
1618(type block_device)
1619(roletype object_r block_device)
1620(type bt_device)
1621(roletype object_r bt_device)
1622(type camera_device)
1623(roletype object_r camera_device)
1624(type dm_device)
1625(roletype object_r dm_device)
1626(type ublk_block_device)
1627(roletype object_r ublk_block_device)
1628(type dm_user_device)
1629(roletype object_r dm_user_device)
1630(type ublk_control_device)
1631(roletype object_r ublk_control_device)
1632(type keychord_device)
1633(roletype object_r keychord_device)
1634(type loop_control_device)
1635(roletype object_r loop_control_device)
1636(type loop_device)
1637(roletype object_r loop_device)
1638(type pmsg_device)
1639(roletype object_r pmsg_device)
1640(type radio_device)
1641(roletype object_r radio_device)
1642(type ram_device)
1643(roletype object_r ram_device)
1644(type rtc_device)
1645(roletype object_r rtc_device)
1646(type vd_device)
1647(roletype object_r vd_device)
1648(type vold_device)
1649(roletype object_r vold_device)
1650(type console_device)
1651(roletype object_r console_device)
1652(type fscklogs)
1653(roletype object_r fscklogs)
1654(type gpu_device)
1655(roletype object_r gpu_device)
1656(type graphics_device)
1657(roletype object_r graphics_device)
1658(type hw_random_device)
1659(roletype object_r hw_random_device)
1660(type input_device)
1661(roletype object_r input_device)
1662(type port_device)
1663(roletype object_r port_device)
1664(type lowpan_device)
1665(roletype object_r lowpan_device)
1666(type mtp_device)
1667(roletype object_r mtp_device)
1668(type nfc_device)
1669(roletype object_r nfc_device)
1670(type ptmx_device)
1671(roletype object_r ptmx_device)
1672(type kmsg_device)
1673(roletype object_r kmsg_device)
1674(type kmsg_debug_device)
1675(roletype object_r kmsg_debug_device)
1676(type null_device)
1677(roletype object_r null_device)
1678(type random_device)
1679(roletype object_r random_device)
1680(type secure_element_device)
1681(roletype object_r secure_element_device)
1682(type sensors_device)
1683(roletype object_r sensors_device)
1684(type serial_device)
1685(roletype object_r serial_device)
1686(type socket_device)
1687(roletype object_r socket_device)
1688(type owntty_device)
1689(roletype object_r owntty_device)
1690(type tty_device)
1691(roletype object_r tty_device)
1692(type video_device)
1693(roletype object_r video_device)
1694(type zero_device)
1695(roletype object_r zero_device)
1696(type fuse_device)
1697(roletype object_r fuse_device)
1698(type iio_device)
1699(roletype object_r iio_device)
1700(type ion_device)
1701(roletype object_r ion_device)
1702(type dmabuf_heap_device)
1703(roletype object_r dmabuf_heap_device)
1704(type dmabuf_system_heap_device)
1705(roletype object_r dmabuf_system_heap_device)
1706(type dmabuf_system_secure_heap_device)
1707(roletype object_r dmabuf_system_secure_heap_device)
1708(type qtaguid_device)
1709(roletype object_r qtaguid_device)
1710(type watchdog_device)
1711(roletype object_r watchdog_device)
1712(type uhid_device)
1713(roletype object_r uhid_device)
1714(type uio_device)
1715(roletype object_r uio_device)
1716(type tun_device)
1717(roletype object_r tun_device)
1718(type usbaccessory_device)
1719(roletype object_r usbaccessory_device)
1720(type usb_device)
1721(roletype object_r usb_device)
1722(type usb_serial_device)
1723(roletype object_r usb_serial_device)
1724(type gnss_device)
1725(roletype object_r gnss_device)
1726(type properties_device)
1727(roletype object_r properties_device)
1728(type properties_serial)
1729(roletype object_r properties_serial)
1730(type property_info)
1731(roletype object_r property_info)
1732(type hidraw_device)
1733(roletype object_r hidraw_device)
1734(type hci_attach_dev)
1735(roletype object_r hci_attach_dev)
1736(type rpmsg_device)
1737(roletype object_r rpmsg_device)
1738(type root_block_device)
1739(roletype object_r root_block_device)
1740(type frp_block_device)
1741(roletype object_r frp_block_device)
1742(type system_block_device)
1743(roletype object_r system_block_device)
1744(type recovery_block_device)
1745(roletype object_r recovery_block_device)
1746(type boot_block_device)
1747(roletype object_r boot_block_device)
1748(type dtbo_block_device)
1749(roletype object_r dtbo_block_device)
1750(type userdata_block_device)
1751(roletype object_r userdata_block_device)
1752(type zoned_block_device)
1753(roletype object_r zoned_block_device)
1754(type cache_block_device)
1755(roletype object_r cache_block_device)
1756(type swap_block_device)
1757(roletype object_r swap_block_device)
1758(type metadata_block_device)
1759(roletype object_r metadata_block_device)
1760(type misc_block_device)
1761(roletype object_r misc_block_device)
1762(type super_block_device)
1763(roletype object_r super_block_device)
1764(type sdcard_block_device)
1765(roletype object_r sdcard_block_device)
1766(type userdata_sysdev)
1767(roletype object_r userdata_sysdev)
1768(type rootdisk_sysdev)
1769(roletype object_r rootdisk_sysdev)
1770(type vfio_device)
1771(roletype object_r vfio_device)
1772(type dhcp)
1773(roletype object_r dhcp)
1774(type dhcp_exec)
1775(roletype object_r dhcp_exec)
1776(type dnsmasq)
1777(roletype object_r dnsmasq)
1778(type dnsmasq_exec)
1779(roletype object_r dnsmasq_exec)
1780(type drmserver)
1781(roletype object_r drmserver)
1782(type drmserver_exec)
1783(roletype object_r drmserver_exec)
1784(type drmserver_socket)
1785(roletype object_r drmserver_socket)
1786(type dumpstate)
1787(roletype object_r dumpstate)
1788(type dumpstate_exec)
1789(roletype object_r dumpstate_exec)
1790(type e2fs)
1791(roletype object_r e2fs)
1792(type e2fs_exec)
1793(roletype object_r e2fs_exec)
1794(type ephemeral_app)
1795(roletype object_r ephemeral_app)
1796(type evsmanagerd)
1797(roletype object_r evsmanagerd)
1798(type extra_free_kbytes)
1799(roletype object_r extra_free_kbytes)
1800(type extra_free_kbytes_exec)
1801(roletype object_r extra_free_kbytes_exec)
1802(type fastbootd)
1803(roletype object_r fastbootd)
1804(type labeledfs)
1805(roletype object_r labeledfs)
1806(type pipefs)
1807(roletype object_r pipefs)
1808(type sockfs)
1809(roletype object_r sockfs)
1810(type rootfs)
1811(roletype object_r rootfs)
1812(type proc)
1813(roletype object_r proc)
1814(type binderfs)
1815(roletype object_r binderfs)
1816(type binderfs_logs)
1817(roletype object_r binderfs_logs)
1818(type binderfs_logs_proc)
1819(roletype object_r binderfs_logs_proc)
1820(type binderfs_logs_stats)
1821(roletype object_r binderfs_logs_stats)
1822(type binderfs_features)
1823(roletype object_r binderfs_features)
1824(type proc_security)
1825(roletype object_r proc_security)
1826(type proc_drop_caches)
1827(roletype object_r proc_drop_caches)
1828(type proc_overcommit_memory)
1829(roletype object_r proc_overcommit_memory)
1830(type proc_min_free_order_shift)
1831(roletype object_r proc_min_free_order_shift)
1832(type proc_kpageflags)
1833(roletype object_r proc_kpageflags)
1834(type proc_watermark_boost_factor)
1835(roletype object_r proc_watermark_boost_factor)
1836(type proc_percpu_pagelist_high_fraction)
1837(roletype object_r proc_percpu_pagelist_high_fraction)
1838(type usermodehelper)
1839(roletype object_r usermodehelper)
1840(type sysfs_usermodehelper)
1841(roletype object_r sysfs_usermodehelper)
1842(type proc_qtaguid_ctrl)
1843(roletype object_r proc_qtaguid_ctrl)
1844(type proc_qtaguid_stat)
1845(roletype object_r proc_qtaguid_stat)
1846(type proc_bluetooth_writable)
1847(roletype object_r proc_bluetooth_writable)
1848(type proc_abi)
1849(roletype object_r proc_abi)
1850(type proc_asound)
1851(roletype object_r proc_asound)
1852(type proc_bootconfig)
1853(roletype object_r proc_bootconfig)
1854(type proc_bpf)
1855(roletype object_r proc_bpf)
1856(type proc_buddyinfo)
1857(roletype object_r proc_buddyinfo)
1858(type proc_cmdline)
1859(roletype object_r proc_cmdline)
1860(type proc_cpu_alignment)
1861(roletype object_r proc_cpu_alignment)
1862(type proc_cpuinfo)
1863(roletype object_r proc_cpuinfo)
1864(type proc_dirty)
1865(roletype object_r proc_dirty)
1866(type proc_diskstats)
1867(roletype object_r proc_diskstats)
1868(type proc_extra_free_kbytes)
1869(roletype object_r proc_extra_free_kbytes)
1870(type proc_filesystems)
1871(roletype object_r proc_filesystems)
1872(type proc_fs_verity)
1873(roletype object_r proc_fs_verity)
1874(type proc_hostname)
1875(roletype object_r proc_hostname)
1876(type proc_hung_task)
1877(roletype object_r proc_hung_task)
1878(type proc_interrupts)
1879(roletype object_r proc_interrupts)
1880(type proc_iomem)
1881(roletype object_r proc_iomem)
1882(type proc_kallsyms)
1883(roletype object_r proc_kallsyms)
1884(type proc_keys)
1885(roletype object_r proc_keys)
1886(type proc_kmsg)
1887(roletype object_r proc_kmsg)
1888(type proc_loadavg)
1889(roletype object_r proc_loadavg)
1890(type proc_locks)
1891(roletype object_r proc_locks)
1892(type proc_lowmemorykiller)
1893(roletype object_r proc_lowmemorykiller)
1894(type proc_max_map_count)
1895(roletype object_r proc_max_map_count)
1896(type proc_meminfo)
1897(roletype object_r proc_meminfo)
1898(type proc_misc)
1899(roletype object_r proc_misc)
1900(type proc_modules)
1901(roletype object_r proc_modules)
1902(type proc_mounts)
1903(roletype object_r proc_mounts)
1904(type proc_net)
1905(roletype object_r proc_net)
1906(type proc_net_tcp_udp)
1907(roletype object_r proc_net_tcp_udp)
1908(type proc_page_cluster)
1909(roletype object_r proc_page_cluster)
1910(type proc_pagetypeinfo)
1911(roletype object_r proc_pagetypeinfo)
1912(type proc_panic)
1913(roletype object_r proc_panic)
1914(type proc_perf)
1915(roletype object_r proc_perf)
1916(type proc_pid_max)
1917(roletype object_r proc_pid_max)
1918(type proc_pipe_conf)
1919(roletype object_r proc_pipe_conf)
1920(type proc_pressure_cpu)
1921(roletype object_r proc_pressure_cpu)
1922(type proc_pressure_io)
1923(roletype object_r proc_pressure_io)
1924(type proc_pressure_mem)
1925(roletype object_r proc_pressure_mem)
1926(type proc_random)
1927(roletype object_r proc_random)
1928(type proc_sched)
1929(roletype object_r proc_sched)
1930(type proc_slabinfo)
1931(roletype object_r proc_slabinfo)
1932(type proc_stat)
1933(roletype object_r proc_stat)
1934(type proc_swaps)
1935(roletype object_r proc_swaps)
1936(type proc_sysrq)
1937(roletype object_r proc_sysrq)
1938(type proc_timer)
1939(roletype object_r proc_timer)
1940(type proc_tty_drivers)
1941(roletype object_r proc_tty_drivers)
1942(type proc_uid_cputime_showstat)
1943(roletype object_r proc_uid_cputime_showstat)
1944(type proc_uid_cputime_removeuid)
1945(roletype object_r proc_uid_cputime_removeuid)
1946(type proc_uid_io_stats)
1947(roletype object_r proc_uid_io_stats)
1948(type proc_uid_procstat_set)
1949(roletype object_r proc_uid_procstat_set)
1950(type proc_uid_time_in_state)
1951(roletype object_r proc_uid_time_in_state)
1952(type proc_uid_concurrent_active_time)
1953(roletype object_r proc_uid_concurrent_active_time)
1954(type proc_uid_concurrent_policy_time)
1955(roletype object_r proc_uid_concurrent_policy_time)
1956(type proc_uid_cpupower)
1957(roletype object_r proc_uid_cpupower)
1958(type proc_uptime)
1959(roletype object_r proc_uptime)
1960(type proc_version)
1961(roletype object_r proc_version)
1962(type proc_vmallocinfo)
1963(roletype object_r proc_vmallocinfo)
1964(type proc_vmstat)
1965(roletype object_r proc_vmstat)
1966(type proc_watermark_scale_factor)
1967(roletype object_r proc_watermark_scale_factor)
1968(type proc_zoneinfo)
1969(roletype object_r proc_zoneinfo)
1970(type proc_vendor_sched)
1971(roletype object_r proc_vendor_sched)
1972(type selinuxfs)
1973(roletype object_r selinuxfs)
1974(type fusectlfs)
1975(roletype object_r fusectlfs)
1976(type cgroup)
1977(roletype object_r cgroup)
1978(type cgroup_v2)
1979(roletype object_r cgroup_v2)
1980(type sysfs)
1981(roletype object_r sysfs)
1982(type sysfs_android_usb)
1983(roletype object_r sysfs_android_usb)
1984(type sysfs_uio)
1985(roletype object_r sysfs_uio)
1986(type sysfs_batteryinfo)
1987(roletype object_r sysfs_batteryinfo)
1988(type sysfs_bluetooth_writable)
1989(roletype object_r sysfs_bluetooth_writable)
1990(type sysfs_devfreq_cur)
1991(roletype object_r sysfs_devfreq_cur)
1992(type sysfs_devfreq_dir)
1993(roletype object_r sysfs_devfreq_dir)
1994(type sysfs_devices_block)
1995(roletype object_r sysfs_devices_block)
1996(type sysfs_dm)
1997(roletype object_r sysfs_dm)
1998(type sysfs_dm_verity)
1999(roletype object_r sysfs_dm_verity)
2000(type sysfs_dma_heap)
2001(roletype object_r sysfs_dma_heap)
2002(type sysfs_dmabuf_stats)
2003(roletype object_r sysfs_dmabuf_stats)
2004(type sysfs_dt_firmware_android)
2005(roletype object_r sysfs_dt_firmware_android)
2006(type sysfs_extcon)
2007(roletype object_r sysfs_extcon)
2008(type sysfs_ion)
2009(roletype object_r sysfs_ion)
2010(type sysfs_ipv4)
2011(roletype object_r sysfs_ipv4)
2012(type sysfs_kernel_notes)
2013(roletype object_r sysfs_kernel_notes)
2014(type sysfs_leds)
2015(roletype object_r sysfs_leds)
2016(type sysfs_loop)
2017(roletype object_r sysfs_loop)
2018(type sysfs_gpu)
2019(roletype object_r sysfs_gpu)
2020(type sysfs_hwrandom)
2021(roletype object_r sysfs_hwrandom)
2022(type sysfs_nfc_power_writable)
2023(roletype object_r sysfs_nfc_power_writable)
2024(type sysfs_wake_lock)
2025(roletype object_r sysfs_wake_lock)
2026(type sysfs_net)
2027(roletype object_r sysfs_net)
2028(type sysfs_power)
2029(roletype object_r sysfs_power)
2030(type sysfs_rtc)
2031(roletype object_r sysfs_rtc)
2032(type sysfs_suspend_stats)
2033(roletype object_r sysfs_suspend_stats)
2034(type sysfs_switch)
2035(roletype object_r sysfs_switch)
2036(type sysfs_sync_on_suspend)
2037(roletype object_r sysfs_sync_on_suspend)
2038(type sysfs_transparent_hugepage)
2039(roletype object_r sysfs_transparent_hugepage)
2040(type sysfs_lru_gen_enabled)
2041(roletype object_r sysfs_lru_gen_enabled)
2042(type sysfs_usb)
2043(roletype object_r sysfs_usb)
2044(type sysfs_wakeup)
2045(roletype object_r sysfs_wakeup)
2046(type sysfs_wakeup_reasons)
2047(roletype object_r sysfs_wakeup_reasons)
2048(type sysfs_fs_ext4_features)
2049(roletype object_r sysfs_fs_ext4_features)
2050(type sysfs_fs_f2fs)
2051(roletype object_r sysfs_fs_f2fs)
2052(type sysfs_fs_fuse_bpf)
2053(roletype object_r sysfs_fs_fuse_bpf)
2054(type sysfs_fs_fuse_features)
2055(roletype object_r sysfs_fs_fuse_features)
2056(type sysfs_fs_incfs_features)
2057(roletype object_r sysfs_fs_incfs_features)
2058(type sysfs_fs_incfs_metrics)
2059(roletype object_r sysfs_fs_incfs_metrics)
2060(type sysfs_vendor_sched)
2061(roletype object_r sysfs_vendor_sched)
2062(type fs_bpf)
2063(roletype object_r fs_bpf)
2064(type fs_bpf_tethering)
2065(roletype object_r fs_bpf_tethering)
2066(type fs_bpf_vendor)
2067(roletype object_r fs_bpf_vendor)
2068(type configfs)
2069(roletype object_r configfs)
2070(type sysfs_devices_cs_etm)
2071(roletype object_r sysfs_devices_cs_etm)
2072(type sysfs_devices_system_cpu)
2073(roletype object_r sysfs_devices_system_cpu)
2074(type sysfs_lowmemorykiller)
2075(roletype object_r sysfs_lowmemorykiller)
2076(type sysfs_wlan_fwpath)
2077(roletype object_r sysfs_wlan_fwpath)
2078(type sysfs_vibrator)
2079(roletype object_r sysfs_vibrator)
2080(type sysfs_uhid)
2081(roletype object_r sysfs_uhid)
2082(type sysfs_thermal)
2083(roletype object_r sysfs_thermal)
2084(type sysfs_zram)
2085(roletype object_r sysfs_zram)
2086(type sysfs_zram_uevent)
2087(roletype object_r sysfs_zram_uevent)
2088(type inotify)
2089(roletype object_r inotify)
2090(type devpts)
2091(roletype object_r devpts)
2092(type tmpfs)
2093(roletype object_r tmpfs)
2094(type shm)
2095(roletype object_r shm)
2096(type mqueue)
2097(roletype object_r mqueue)
2098(type fuse)
2099(roletype object_r fuse)
2100(type fuseblk)
2101(roletype object_r fuseblk)
2102(type sdcardfs)
2103(roletype object_r sdcardfs)
2104(type vfat)
2105(roletype object_r vfat)
2106(type exfat)
2107(roletype object_r exfat)
2108(type debugfs)
2109(roletype object_r debugfs)
2110(type debugfs_kprobes)
2111(roletype object_r debugfs_kprobes)
2112(type debugfs_mmc)
2113(roletype object_r debugfs_mmc)
2114(type debugfs_mm_events_tracing)
2115(roletype object_r debugfs_mm_events_tracing)
2116(type debugfs_trace_marker)
2117(roletype object_r debugfs_trace_marker)
2118(type debugfs_tracing)
2119(roletype object_r debugfs_tracing)
2120(type debugfs_tracing_debug)
2121(roletype object_r debugfs_tracing_debug)
2122(type debugfs_tracing_instances)
2123(roletype object_r debugfs_tracing_instances)
2124(type debugfs_tracing_printk_formats)
2125(roletype object_r debugfs_tracing_printk_formats)
2126(type debugfs_wakeup_sources)
2127(roletype object_r debugfs_wakeup_sources)
2128(type debugfs_wifi_tracing)
2129(roletype object_r debugfs_wifi_tracing)
2130(type securityfs)
2131(roletype object_r securityfs)
2132(type pstorefs)
2133(roletype object_r pstorefs)
2134(type functionfs)
2135(roletype object_r functionfs)
2136(type oemfs)
2137(roletype object_r oemfs)
2138(type usbfs)
2139(roletype object_r usbfs)
2140(type binfmt_miscfs)
2141(roletype object_r binfmt_miscfs)
2142(type app_fusefs)
2143(roletype object_r app_fusefs)
2144(type unlabeled)
2145(roletype object_r unlabeled)
2146(type system_file)
2147(roletype object_r system_file)
2148(type system_asan_options_file)
2149(roletype object_r system_asan_options_file)
2150(type system_event_log_tags_file)
2151(roletype object_r system_event_log_tags_file)
2152(type system_lib_file)
2153(roletype object_r system_lib_file)
2154(type system_bootstrap_lib_file)
2155(roletype object_r system_bootstrap_lib_file)
2156(type system_group_file)
2157(roletype object_r system_group_file)
2158(type system_linker_exec)
2159(roletype object_r system_linker_exec)
2160(type system_linker_config_file)
2161(roletype object_r system_linker_config_file)
2162(type system_passwd_file)
2163(roletype object_r system_passwd_file)
2164(type system_seccomp_policy_file)
2165(roletype object_r system_seccomp_policy_file)
2166(type system_security_cacerts_file)
2167(roletype object_r system_security_cacerts_file)
2168(type tcpdump_exec)
2169(roletype object_r tcpdump_exec)
2170(type system_zoneinfo_file)
2171(roletype object_r system_zoneinfo_file)
2172(type cgroup_desc_file)
2173(roletype object_r cgroup_desc_file)
2174(type cgroup_desc_api_file)
2175(roletype object_r cgroup_desc_api_file)
2176(type vendor_cgroup_desc_file)
2177(roletype object_r vendor_cgroup_desc_file)
2178(type task_profiles_file)
2179(roletype object_r task_profiles_file)
2180(type task_profiles_api_file)
2181(roletype object_r task_profiles_api_file)
2182(type vendor_task_profiles_file)
2183(roletype object_r vendor_task_profiles_file)
2184(type art_apex_dir)
2185(roletype object_r art_apex_dir)
2186(type linkerconfig_file)
2187(roletype object_r linkerconfig_file)
2188(type incremental_control_file)
2189(roletype object_r incremental_control_file)
2190(type bootanim_oem_file)
2191(roletype object_r bootanim_oem_file)
2192(type vendor_hal_file)
2193(roletype object_r vendor_hal_file)
2194(type vendor_file)
2195(roletype object_r vendor_file)
2196(type vendor_app_file)
2197(roletype object_r vendor_app_file)
2198(type vendor_configs_file)
2199(roletype object_r vendor_configs_file)
2200(type same_process_hal_file)
2201(roletype object_r same_process_hal_file)
2202(type vndk_sp_file)
2203(roletype object_r vndk_sp_file)
2204(type vendor_framework_file)
2205(roletype object_r vendor_framework_file)
2206(type vendor_overlay_file)
2207(roletype object_r vendor_overlay_file)
2208(type vendor_public_lib_file)
2209(roletype object_r vendor_public_lib_file)
2210(type vendor_public_framework_file)
2211(roletype object_r vendor_public_framework_file)
2212(type vendor_microdroid_file)
2213(roletype object_r vendor_microdroid_file)
2214(type vendor_keylayout_file)
2215(roletype object_r vendor_keylayout_file)
2216(type vendor_keychars_file)
2217(roletype object_r vendor_keychars_file)
2218(type vendor_idc_file)
2219(roletype object_r vendor_idc_file)
2220(type vendor_uuid_mapping_config_file)
2221(roletype object_r vendor_uuid_mapping_config_file)
2222(type vendor_vm_file)
2223(roletype object_r vendor_vm_file)
2224(type vendor_vm_data_file)
2225(roletype object_r vendor_vm_data_file)
2226(type metadata_file)
2227(roletype object_r metadata_file)
2228(type vold_metadata_file)
2229(roletype object_r vold_metadata_file)
2230(type gsi_metadata_file)
2231(roletype object_r gsi_metadata_file)
2232(type gsi_public_metadata_file)
2233(roletype object_r gsi_public_metadata_file)
2234(type password_slot_metadata_file)
2235(roletype object_r password_slot_metadata_file)
2236(type apex_metadata_file)
2237(roletype object_r apex_metadata_file)
2238(type ota_metadata_file)
2239(roletype object_r ota_metadata_file)
2240(type metadata_bootstat_file)
2241(roletype object_r metadata_bootstat_file)
2242(type userspace_reboot_metadata_file)
2243(roletype object_r userspace_reboot_metadata_file)
2244(type staged_install_file)
2245(roletype object_r staged_install_file)
2246(type watchdog_metadata_file)
2247(roletype object_r watchdog_metadata_file)
2248(type repair_mode_metadata_file)
2249(roletype object_r repair_mode_metadata_file)
2250(type aconfig_storage_metadata_file)
2251(roletype object_r aconfig_storage_metadata_file)
2252(type aconfig_storage_flags_metadata_file)
2253(roletype object_r aconfig_storage_flags_metadata_file)
2254(type dev_cpu_variant)
2255(roletype object_r dev_cpu_variant)
2256(type runtime_event_log_tags_file)
2257(roletype object_r runtime_event_log_tags_file)
2258(type logcat_exec)
2259(roletype object_r logcat_exec)
2260(type cgroup_rc_file)
2261(roletype object_r cgroup_rc_file)
2262(type coredump_file)
2263(roletype object_r coredump_file)
2264(type system_data_root_file)
2265(roletype object_r system_data_root_file)
2266(type system_data_file)
2267(roletype object_r system_data_file)
2268(type system_userdir_file)
2269(roletype object_r system_userdir_file)
2270(type packages_list_file)
2271(roletype object_r packages_list_file)
2272(type game_mode_intervention_list_file)
2273(roletype object_r game_mode_intervention_list_file)
2274(type vendor_data_file)
2275(roletype object_r vendor_data_file)
2276(type vendor_userdir_file)
2277(roletype object_r vendor_userdir_file)
2278(type unencrypted_data_file)
2279(roletype object_r unencrypted_data_file)
2280(type install_data_file)
2281(roletype object_r install_data_file)
2282(type drm_data_file)
2283(roletype object_r drm_data_file)
2284(type adb_data_file)
2285(roletype object_r adb_data_file)
2286(type anr_data_file)
2287(roletype object_r anr_data_file)
2288(type tombstone_data_file)
2289(roletype object_r tombstone_data_file)
2290(type tombstone_wifi_data_file)
2291(roletype object_r tombstone_wifi_data_file)
2292(type apex_data_file)
2293(roletype object_r apex_data_file)
2294(type apk_data_file)
2295(roletype object_r apk_data_file)
2296(type apk_tmp_file)
2297(roletype object_r apk_tmp_file)
2298(type apk_private_data_file)
2299(roletype object_r apk_private_data_file)
2300(type apk_private_tmp_file)
2301(roletype object_r apk_private_tmp_file)
2302(type dalvikcache_data_file)
2303(roletype object_r dalvikcache_data_file)
2304(type ota_data_file)
2305(roletype object_r ota_data_file)
2306(type ota_package_file)
2307(roletype object_r ota_package_file)
2308(type user_profile_root_file)
2309(roletype object_r user_profile_root_file)
2310(type user_profile_data_file)
2311(roletype object_r user_profile_data_file)
2312(type profman_dump_data_file)
2313(roletype object_r profman_dump_data_file)
2314(type prereboot_data_file)
2315(roletype object_r prereboot_data_file)
2316(type resourcecache_data_file)
2317(roletype object_r resourcecache_data_file)
2318(type shell_data_file)
2319(roletype object_r shell_data_file)
2320(type property_data_file)
2321(roletype object_r property_data_file)
2322(type bootchart_data_file)
2323(roletype object_r bootchart_data_file)
2324(type dropbox_data_file)
2325(roletype object_r dropbox_data_file)
2326(type heapdump_data_file)
2327(roletype object_r heapdump_data_file)
2328(type nativetest_data_file)
2329(roletype object_r nativetest_data_file)
2330(type shell_test_data_file)
2331(roletype object_r shell_test_data_file)
2332(type ringtone_file)
2333(roletype object_r ringtone_file)
2334(type preloads_data_file)
2335(roletype object_r preloads_data_file)
2336(type preloads_media_file)
2337(roletype object_r preloads_media_file)
2338(type dhcp_data_file)
2339(roletype object_r dhcp_data_file)
2340(type server_configurable_flags_data_file)
2341(roletype object_r server_configurable_flags_data_file)
2342(type staging_data_file)
2343(roletype object_r staging_data_file)
2344(type vendor_apex_file)
2345(roletype object_r vendor_apex_file)
2346(type vendor_apex_metadata_file)
2347(roletype object_r vendor_apex_metadata_file)
2348(type shutdown_checkpoints_system_data_file)
2349(roletype object_r shutdown_checkpoints_system_data_file)
2350(type mnt_media_rw_file)
2351(roletype object_r mnt_media_rw_file)
2352(type mnt_user_file)
2353(roletype object_r mnt_user_file)
2354(type mnt_pass_through_file)
2355(roletype object_r mnt_pass_through_file)
2356(type mnt_expand_file)
2357(roletype object_r mnt_expand_file)
2358(type mnt_sdcard_file)
2359(roletype object_r mnt_sdcard_file)
2360(type storage_file)
2361(roletype object_r storage_file)
2362(type mnt_media_rw_stub_file)
2363(roletype object_r mnt_media_rw_stub_file)
2364(type storage_stub_file)
2365(roletype object_r storage_stub_file)
2366(type mnt_vendor_file)
2367(roletype object_r mnt_vendor_file)
2368(type mnt_product_file)
2369(roletype object_r mnt_product_file)
2370(type apex_mnt_dir)
2371(roletype object_r apex_mnt_dir)
2372(type apex_info_file)
2373(roletype object_r apex_info_file)
2374(type postinstall_mnt_dir)
2375(roletype object_r postinstall_mnt_dir)
2376(type postinstall_file)
2377(roletype object_r postinstall_file)
2378(type postinstall_apex_mnt_dir)
2379(roletype object_r postinstall_apex_mnt_dir)
2380(type mirror_data_file)
2381(roletype object_r mirror_data_file)
2382(type adb_keys_file)
2383(roletype object_r adb_keys_file)
2384(type apex_system_server_data_file)
2385(roletype object_r apex_system_server_data_file)
2386(type apex_module_data_file)
2387(roletype object_r apex_module_data_file)
2388(type apex_ota_reserved_file)
2389(roletype object_r apex_ota_reserved_file)
2390(type apex_rollback_data_file)
2391(roletype object_r apex_rollback_data_file)
2392(type appcompat_data_file)
2393(roletype object_r appcompat_data_file)
2394(type audio_data_file)
2395(roletype object_r audio_data_file)
2396(type audioserver_data_file)
2397(roletype object_r audioserver_data_file)
2398(type bluetooth_data_file)
2399(roletype object_r bluetooth_data_file)
2400(type bluetooth_logs_data_file)
2401(roletype object_r bluetooth_logs_data_file)
2402(type bootstat_data_file)
2403(roletype object_r bootstat_data_file)
2404(type boottrace_data_file)
2405(roletype object_r boottrace_data_file)
2406(type camera_data_file)
2407(roletype object_r camera_data_file)
2408(type credstore_data_file)
2409(roletype object_r credstore_data_file)
2410(type gatekeeper_data_file)
2411(roletype object_r gatekeeper_data_file)
2412(type incident_data_file)
2413(roletype object_r incident_data_file)
2414(type keychain_data_file)
2415(roletype object_r keychain_data_file)
2416(type keystore_data_file)
2417(roletype object_r keystore_data_file)
2418(type media_data_file)
2419(roletype object_r media_data_file)
2420(type media_rw_data_file)
2421(roletype object_r media_rw_data_file)
2422(type media_userdir_file)
2423(roletype object_r media_userdir_file)
2424(type misc_user_data_file)
2425(roletype object_r misc_user_data_file)
2426(type net_data_file)
2427(roletype object_r net_data_file)
2428(type network_watchlist_data_file)
2429(roletype object_r network_watchlist_data_file)
2430(type nfc_data_file)
2431(roletype object_r nfc_data_file)
2432(type nfc_logs_data_file)
2433(roletype object_r nfc_logs_data_file)
2434(type radio_data_file)
2435(roletype object_r radio_data_file)
2436(type recovery_data_file)
2437(roletype object_r recovery_data_file)
2438(type shared_relro_file)
2439(roletype object_r shared_relro_file)
2440(type snapshotctl_log_data_file)
2441(roletype object_r snapshotctl_log_data_file)
2442(type stats_config_data_file)
2443(roletype object_r stats_config_data_file)
2444(type stats_data_file)
2445(roletype object_r stats_data_file)
2446(type systemkeys_data_file)
2447(roletype object_r systemkeys_data_file)
2448(type textclassifier_data_file)
2449(roletype object_r textclassifier_data_file)
2450(type trace_data_file)
2451(roletype object_r trace_data_file)
2452(type vpn_data_file)
2453(roletype object_r vpn_data_file)
2454(type wifi_data_file)
2455(roletype object_r wifi_data_file)
2456(type vold_data_file)
2457(roletype object_r vold_data_file)
2458(type tee_data_file)
2459(roletype object_r tee_data_file)
2460(type update_engine_data_file)
2461(roletype object_r update_engine_data_file)
2462(type update_engine_log_data_file)
2463(roletype object_r update_engine_log_data_file)
2464(type snapuserd_log_data_file)
2465(roletype object_r snapuserd_log_data_file)
2466(type method_trace_data_file)
2467(roletype object_r method_trace_data_file)
2468(type gsi_data_file)
2469(roletype object_r gsi_data_file)
2470(type radio_core_data_file)
2471(roletype object_r radio_core_data_file)
2472(type app_data_file)
2473(roletype object_r app_data_file)
2474(type privapp_data_file)
2475(roletype object_r privapp_data_file)
2476(type system_app_data_file)
2477(roletype object_r system_app_data_file)
2478(type cache_file)
2479(roletype object_r cache_file)
2480(type overlayfs_file)
2481(roletype object_r overlayfs_file)
2482(type cache_backup_file)
2483(roletype object_r cache_backup_file)
2484(type cache_private_backup_file)
2485(roletype object_r cache_private_backup_file)
2486(type cache_recovery_file)
2487(roletype object_r cache_recovery_file)
2488(type efs_file)
2489(roletype object_r efs_file)
2490(type wallpaper_file)
2491(roletype object_r wallpaper_file)
2492(type shortcut_manager_icons)
2493(roletype object_r shortcut_manager_icons)
2494(type icon_file)
2495(roletype object_r icon_file)
2496(type asec_apk_file)
2497(roletype object_r asec_apk_file)
2498(type asec_public_file)
2499(roletype object_r asec_public_file)
2500(type asec_image_file)
2501(roletype object_r asec_image_file)
2502(type backup_data_file)
2503(roletype object_r backup_data_file)
2504(type bluetooth_efs_file)
2505(roletype object_r bluetooth_efs_file)
2506(type fingerprintd_data_file)
2507(roletype object_r fingerprintd_data_file)
2508(type fingerprint_vendor_data_file)
2509(roletype object_r fingerprint_vendor_data_file)
2510(type app_fuse_file)
2511(roletype object_r app_fuse_file)
2512(type face_vendor_data_file)
2513(roletype object_r face_vendor_data_file)
2514(type iris_vendor_data_file)
2515(roletype object_r iris_vendor_data_file)
2516(type adbd_socket)
2517(roletype object_r adbd_socket)
2518(type bluetooth_socket)
2519(roletype object_r bluetooth_socket)
2520(type dnsproxyd_socket)
2521(roletype object_r dnsproxyd_socket)
2522(type dumpstate_socket)
2523(roletype object_r dumpstate_socket)
2524(type fwmarkd_socket)
2525(roletype object_r fwmarkd_socket)
2526(type lmkd_socket)
2527(roletype object_r lmkd_socket)
2528(type logd_socket)
2529(roletype object_r logd_socket)
2530(type logdr_socket)
2531(roletype object_r logdr_socket)
2532(type logdw_socket)
2533(roletype object_r logdw_socket)
2534(type mdns_socket)
2535(roletype object_r mdns_socket)
2536(type mdnsd_socket)
2537(roletype object_r mdnsd_socket)
2538(type misc_logd_file)
2539(roletype object_r misc_logd_file)
2540(type mtpd_socket)
2541(roletype object_r mtpd_socket)
2542(type ot_daemon_socket)
2543(roletype object_r ot_daemon_socket)
2544(type property_socket)
2545(roletype object_r property_socket)
2546(type racoon_socket)
2547(roletype object_r racoon_socket)
2548(type recovery_socket)
2549(roletype object_r recovery_socket)
2550(type rild_socket)
2551(roletype object_r rild_socket)
2552(type rild_debug_socket)
2553(roletype object_r rild_debug_socket)
2554(type snapuserd_socket)
2555(roletype object_r snapuserd_socket)
2556(type snapuserd_proxy_socket)
2557(roletype object_r snapuserd_proxy_socket)
2558(type statsdw_socket)
2559(roletype object_r statsdw_socket)
2560(type system_wpa_socket)
2561(roletype object_r system_wpa_socket)
2562(type system_ndebug_socket)
2563(roletype object_r system_ndebug_socket)
2564(type system_unsolzygote_socket)
2565(roletype object_r system_unsolzygote_socket)
2566(type tombstoned_crash_socket)
2567(roletype object_r tombstoned_crash_socket)
2568(type tombstoned_java_trace_socket)
2569(roletype object_r tombstoned_java_trace_socket)
2570(type tombstoned_intercept_socket)
2571(roletype object_r tombstoned_intercept_socket)
2572(type traced_consumer_socket)
2573(roletype object_r traced_consumer_socket)
2574(type traced_perf_socket)
2575(roletype object_r traced_perf_socket)
2576(type traced_producer_socket)
2577(roletype object_r traced_producer_socket)
2578(type uncrypt_socket)
2579(roletype object_r uncrypt_socket)
2580(type wpa_socket)
2581(roletype object_r wpa_socket)
2582(type zygote_socket)
2583(roletype object_r zygote_socket)
2584(type heapprofd_socket)
2585(roletype object_r heapprofd_socket)
2586(type gps_control)
2587(roletype object_r gps_control)
2588(type pdx_display_dir)
2589(roletype object_r pdx_display_dir)
2590(type pdx_performance_dir)
2591(roletype object_r pdx_performance_dir)
2592(type pdx_bufferhub_dir)
2593(roletype object_r pdx_bufferhub_dir)
2594(type pdx_display_client_endpoint_socket)
2595(roletype object_r pdx_display_client_endpoint_socket)
2596(type pdx_display_client_channel_socket)
2597(roletype object_r pdx_display_client_channel_socket)
2598(type pdx_display_manager_endpoint_socket)
2599(roletype object_r pdx_display_manager_endpoint_socket)
2600(type pdx_display_manager_channel_socket)
2601(roletype object_r pdx_display_manager_channel_socket)
2602(type pdx_display_screenshot_endpoint_socket)
2603(roletype object_r pdx_display_screenshot_endpoint_socket)
2604(type pdx_display_screenshot_channel_socket)
2605(roletype object_r pdx_display_screenshot_channel_socket)
2606(type pdx_display_vsync_endpoint_socket)
2607(roletype object_r pdx_display_vsync_endpoint_socket)
2608(type pdx_display_vsync_channel_socket)
2609(roletype object_r pdx_display_vsync_channel_socket)
2610(type pdx_performance_client_endpoint_socket)
2611(roletype object_r pdx_performance_client_endpoint_socket)
2612(type pdx_performance_client_channel_socket)
2613(roletype object_r pdx_performance_client_channel_socket)
2614(type pdx_bufferhub_client_endpoint_socket)
2615(roletype object_r pdx_bufferhub_client_endpoint_socket)
2616(type pdx_bufferhub_client_channel_socket)
2617(roletype object_r pdx_bufferhub_client_channel_socket)
2618(type file_contexts_file)
2619(roletype object_r file_contexts_file)
2620(type mac_perms_file)
2621(roletype object_r mac_perms_file)
2622(type property_contexts_file)
2623(roletype object_r property_contexts_file)
2624(type seapp_contexts_file)
2625(roletype object_r seapp_contexts_file)
2626(type sepolicy_file)
2627(roletype object_r sepolicy_file)
2628(type service_contexts_file)
2629(roletype object_r service_contexts_file)
2630(type keystore2_key_contexts_file)
2631(roletype object_r keystore2_key_contexts_file)
2632(type vendor_service_contexts_file)
2633(roletype object_r vendor_service_contexts_file)
2634(type hwservice_contexts_file)
2635(roletype object_r hwservice_contexts_file)
2636(type vndservice_contexts_file)
2637(roletype object_r vndservice_contexts_file)
2638(type debugfs_bootreceiver_tracing)
2639(roletype object_r debugfs_bootreceiver_tracing)
2640(type vendor_kernel_modules)
2641(roletype object_r vendor_kernel_modules)
2642(type system_dlkm_file)
2643(roletype object_r system_dlkm_file)
2644(type audiohal_data_file)
2645(roletype object_r audiohal_data_file)
2646(type fingerprintd)
2647(roletype object_r fingerprintd)
2648(type fingerprintd_exec)
2649(roletype object_r fingerprintd_exec)
2650(type flags_health_check)
2651(roletype object_r flags_health_check)
2652(type flags_health_check_exec)
2653(roletype object_r flags_health_check_exec)
2654(type fsck)
2655(roletype object_r fsck)
2656(type fsck_exec)
2657(roletype object_r fsck_exec)
2658(type fsck_untrusted)
2659(roletype object_r fsck_untrusted)
2660(type gatekeeperd)
2661(roletype object_r gatekeeperd)
2662(type gatekeeperd_exec)
2663(roletype object_r gatekeeperd_exec)
2664(type gmscore_app)
2665(roletype object_r gmscore_app)
2666(type gpuservice)
2667(roletype object_r gpuservice)
2668(type hal_graphics_composer_server_tmpfs)
2669(roletype object_r hal_graphics_composer_server_tmpfs)
2670(typeattribute hal_graphics_composer_client_tmpfs)
2671(expandtypeattribute (hal_graphics_composer_client_tmpfs) true)
2672(typeattributeset hal_graphics_composer_client_tmpfs (surfaceflinger_tmpfs ))
2673(type healthd)
2674(roletype object_r healthd)
2675(type heapprofd)
2676(roletype object_r heapprofd)
2677(type default_android_hwservice)
2678(roletype object_r default_android_hwservice)
2679(type fwk_camera_hwservice)
2680(roletype object_r fwk_camera_hwservice)
2681(type fwk_display_hwservice)
2682(roletype object_r fwk_display_hwservice)
2683(type fwk_scheduler_hwservice)
2684(roletype object_r fwk_scheduler_hwservice)
2685(type fwk_sensor_hwservice)
2686(roletype object_r fwk_sensor_hwservice)
2687(type fwk_stats_hwservice)
2688(roletype object_r fwk_stats_hwservice)
2689(type fwk_automotive_display_hwservice)
2690(roletype object_r fwk_automotive_display_hwservice)
2691(type hal_atrace_hwservice)
2692(roletype object_r hal_atrace_hwservice)
2693(type hal_audio_hwservice)
2694(roletype object_r hal_audio_hwservice)
2695(type hal_audiocontrol_hwservice)
2696(roletype object_r hal_audiocontrol_hwservice)
2697(type hal_authsecret_hwservice)
2698(roletype object_r hal_authsecret_hwservice)
2699(type hal_bluetooth_hwservice)
2700(roletype object_r hal_bluetooth_hwservice)
2701(type hal_bootctl_hwservice)
2702(roletype object_r hal_bootctl_hwservice)
2703(type hal_broadcastradio_hwservice)
2704(roletype object_r hal_broadcastradio_hwservice)
2705(type hal_camera_hwservice)
2706(roletype object_r hal_camera_hwservice)
2707(type hal_can_bus_hwservice)
2708(roletype object_r hal_can_bus_hwservice)
2709(type hal_can_controller_hwservice)
2710(roletype object_r hal_can_controller_hwservice)
2711(type hal_confirmationui_hwservice)
2712(roletype object_r hal_confirmationui_hwservice)
2713(type hal_contexthub_hwservice)
2714(roletype object_r hal_contexthub_hwservice)
2715(type hal_dumpstate_hwservice)
2716(roletype object_r hal_dumpstate_hwservice)
2717(type hal_evs_hwservice)
2718(roletype object_r hal_evs_hwservice)
2719(type hal_face_hwservice)
2720(roletype object_r hal_face_hwservice)
2721(type hal_fingerprint_hwservice)
2722(roletype object_r hal_fingerprint_hwservice)
2723(type hal_gatekeeper_hwservice)
2724(roletype object_r hal_gatekeeper_hwservice)
2725(type hal_gnss_hwservice)
2726(roletype object_r hal_gnss_hwservice)
2727(type hal_graphics_composer_hwservice)
2728(roletype object_r hal_graphics_composer_hwservice)
2729(type hal_health_hwservice)
2730(roletype object_r hal_health_hwservice)
2731(type hal_health_storage_hwservice)
2732(roletype object_r hal_health_storage_hwservice)
2733(type hal_input_classifier_hwservice)
2734(roletype object_r hal_input_classifier_hwservice)
2735(type hal_ir_hwservice)
2736(roletype object_r hal_ir_hwservice)
2737(type hal_keymaster_hwservice)
2738(roletype object_r hal_keymaster_hwservice)
2739(type hal_light_hwservice)
2740(roletype object_r hal_light_hwservice)
2741(type hal_lowpan_hwservice)
2742(roletype object_r hal_lowpan_hwservice)
2743(type hal_memtrack_hwservice)
2744(roletype object_r hal_memtrack_hwservice)
2745(type hal_nfc_hwservice)
2746(roletype object_r hal_nfc_hwservice)
2747(type hal_oemlock_hwservice)
2748(roletype object_r hal_oemlock_hwservice)
2749(type hal_power_hwservice)
2750(roletype object_r hal_power_hwservice)
2751(type hal_power_stats_hwservice)
2752(roletype object_r hal_power_stats_hwservice)
2753(type hal_secure_element_hwservice)
2754(roletype object_r hal_secure_element_hwservice)
2755(type hal_sensors_hwservice)
2756(roletype object_r hal_sensors_hwservice)
2757(type hal_telephony_hwservice)
2758(roletype object_r hal_telephony_hwservice)
2759(type hal_tetheroffload_hwservice)
2760(roletype object_r hal_tetheroffload_hwservice)
2761(type hal_thermal_hwservice)
2762(roletype object_r hal_thermal_hwservice)
2763(type hal_tv_cec_hwservice)
2764(roletype object_r hal_tv_cec_hwservice)
2765(type hal_tv_input_hwservice)
2766(roletype object_r hal_tv_input_hwservice)
2767(type hal_tv_tuner_hwservice)
2768(roletype object_r hal_tv_tuner_hwservice)
2769(type hal_usb_gadget_hwservice)
2770(roletype object_r hal_usb_gadget_hwservice)
2771(type hal_usb_hwservice)
2772(roletype object_r hal_usb_hwservice)
2773(type hal_vehicle_hwservice)
2774(roletype object_r hal_vehicle_hwservice)
2775(type hal_vibrator_hwservice)
2776(roletype object_r hal_vibrator_hwservice)
2777(type hal_vr_hwservice)
2778(roletype object_r hal_vr_hwservice)
2779(type hal_weaver_hwservice)
2780(roletype object_r hal_weaver_hwservice)
2781(type hal_wifi_hostapd_hwservice)
2782(roletype object_r hal_wifi_hostapd_hwservice)
2783(type hal_wifi_hwservice)
2784(roletype object_r hal_wifi_hwservice)
2785(type hal_wifi_supplicant_hwservice)
2786(roletype object_r hal_wifi_supplicant_hwservice)
2787(type system_net_netd_hwservice)
2788(roletype object_r system_net_netd_hwservice)
2789(type system_suspend_hwservice)
2790(roletype object_r system_suspend_hwservice)
2791(type system_wifi_keystore_hwservice)
2792(roletype object_r system_wifi_keystore_hwservice)
2793(type fwk_bufferhub_hwservice)
2794(roletype object_r fwk_bufferhub_hwservice)
2795(type hal_cas_hwservice)
2796(roletype object_r hal_cas_hwservice)
2797(type hal_codec2_hwservice)
2798(roletype object_r hal_codec2_hwservice)
2799(type hal_configstore_ISurfaceFlingerConfigs)
2800(roletype object_r hal_configstore_ISurfaceFlingerConfigs)
2801(type hal_drm_hwservice)
2802(roletype object_r hal_drm_hwservice)
2803(type hal_graphics_allocator_hwservice)
2804(roletype object_r hal_graphics_allocator_hwservice)
2805(type hal_graphics_mapper_hwservice)
2806(roletype object_r hal_graphics_mapper_hwservice)
2807(type hal_neuralnetworks_hwservice)
2808(roletype object_r hal_neuralnetworks_hwservice)
2809(type hal_omx_hwservice)
2810(roletype object_r hal_omx_hwservice)
2811(type hal_renderscript_hwservice)
2812(roletype object_r hal_renderscript_hwservice)
2813(type hidl_allocator_hwservice)
2814(roletype object_r hidl_allocator_hwservice)
2815(type hidl_base_hwservice)
2816(roletype object_r hidl_base_hwservice)
2817(type hidl_manager_hwservice)
2818(roletype object_r hidl_manager_hwservice)
2819(type hidl_memory_hwservice)
2820(roletype object_r hidl_memory_hwservice)
2821(type hidl_token_hwservice)
2822(roletype object_r hidl_token_hwservice)
2823(type hwservicemanager)
2824(roletype object_r hwservicemanager)
2825(type hwservicemanager_exec)
2826(roletype object_r hwservicemanager_exec)
2827(type idmap)
2828(roletype object_r idmap)
2829(type idmap_exec)
2830(roletype object_r idmap_exec)
2831(type incident)
2832(roletype object_r incident)
2833(type incident_helper)
2834(roletype object_r incident_helper)
2835(type incidentd)
2836(roletype object_r incidentd)
2837(type init)
2838(roletype object_r init)
2839(type init_exec)
2840(roletype object_r init_exec)
2841(type init_tmpfs)
2842(roletype object_r init_tmpfs)
2843(type inputflinger)
2844(roletype object_r inputflinger)
2845(type inputflinger_exec)
2846(roletype object_r inputflinger_exec)
2847(type installd)
2848(roletype object_r installd)
2849(type installd_exec)
2850(roletype object_r installd_exec)
2851(type isolated_app)
2852(roletype object_r isolated_app)
2853(type isolated_compute_app)
2854(roletype object_r isolated_compute_app)
2855(type kernel)
2856(roletype object_r kernel)
2857(type keystore)
2858(roletype object_r keystore)
2859(type keystore_exec)
2860(roletype object_r keystore_exec)
2861(type wifi_key)
2862(roletype object_r wifi_key)
2863(type llkd)
2864(roletype object_r llkd)
2865(type llkd_exec)
2866(roletype object_r llkd_exec)
2867(type lmkd)
2868(roletype object_r lmkd)
2869(type lmkd_exec)
2870(roletype object_r lmkd_exec)
2871(type logd)
2872(roletype object_r logd)
2873(type logd_exec)
2874(roletype object_r logd_exec)
2875(type logpersist)
2876(roletype object_r logpersist)
2877(type mdnsd)
2878(roletype object_r mdnsd)
2879(type mediadrmserver)
2880(roletype object_r mediadrmserver)
2881(type mediadrmserver_exec)
2882(roletype object_r mediadrmserver_exec)
2883(type mediaextractor)
2884(roletype object_r mediaextractor)
2885(type mediaextractor_exec)
2886(roletype object_r mediaextractor_exec)
2887(type mediaextractor_tmpfs)
2888(roletype object_r mediaextractor_tmpfs)
2889(type mediametrics)
2890(roletype object_r mediametrics)
2891(type mediametrics_exec)
2892(roletype object_r mediametrics_exec)
2893(type mediaprovider)
2894(roletype object_r mediaprovider)
2895(type mediaserver)
2896(roletype object_r mediaserver)
2897(type mediaserver_exec)
2898(roletype object_r mediaserver_exec)
2899(type mediaserver_tmpfs)
2900(roletype object_r mediaserver_tmpfs)
2901(type mediaswcodec)
2902(roletype object_r mediaswcodec)
2903(type mediaswcodec_exec)
2904(roletype object_r mediaswcodec_exec)
2905(type mediatranscoding)
2906(roletype object_r mediatranscoding)
2907(type modprobe)
2908(roletype object_r modprobe)
2909(type mtp)
2910(roletype object_r mtp)
2911(type node)
2912(roletype object_r node)
2913(type netif)
2914(roletype object_r netif)
2915(type port)
2916(roletype object_r port)
2917(type netd)
2918(roletype object_r netd)
2919(type netd_exec)
2920(roletype object_r netd_exec)
2921(type netutils_wrapper)
2922(roletype object_r netutils_wrapper)
2923(type netutils_wrapper_exec)
2924(roletype object_r netutils_wrapper_exec)
2925(type network_stack)
2926(roletype object_r network_stack)
2927(type nfc)
2928(roletype object_r nfc)
2929(type otapreopt_chroot)
2930(roletype object_r otapreopt_chroot)
2931(type perfetto)
2932(roletype object_r perfetto)
2933(type performanced)
2934(roletype object_r performanced)
2935(type performanced_exec)
2936(roletype object_r performanced_exec)
2937(type platform_app)
2938(roletype object_r platform_app)
2939(type postinstall)
2940(roletype object_r postinstall)
2941(type ppp)
2942(roletype object_r ppp)
2943(type priv_app)
2944(roletype object_r priv_app)
2945(type prng_seeder)
2946(roletype object_r prng_seeder)
2947(type profman)
2948(roletype object_r profman)
2949(type profman_exec)
2950(roletype object_r profman_exec)
2951(type apexd_prop)
2952(roletype object_r apexd_prop)
2953(type bootloader_boot_reason_prop)
2954(roletype object_r bootloader_boot_reason_prop)
2955(type device_config_activity_manager_native_boot_prop)
2956(roletype object_r device_config_activity_manager_native_boot_prop)
2957(type device_config_boot_count_prop)
2958(roletype object_r device_config_boot_count_prop)
2959(type device_config_input_native_boot_prop)
2960(roletype object_r device_config_input_native_boot_prop)
2961(type device_config_netd_native_prop)
2962(roletype object_r device_config_netd_native_prop)
2963(type device_config_reset_performed_prop)
2964(roletype object_r device_config_reset_performed_prop)
2965(type firstboot_prop)
2966(roletype object_r firstboot_prop)
2967(type boottime_prop)
2968(roletype object_r boottime_prop)
2969(type charger_prop)
2970(roletype object_r charger_prop)
2971(type cold_boot_done_prop)
2972(roletype object_r cold_boot_done_prop)
2973(type ctl_adbd_prop)
2974(roletype object_r ctl_adbd_prop)
2975(type ctl_apexd_prop)
2976(roletype object_r ctl_apexd_prop)
2977(type ctl_bootanim_prop)
2978(roletype object_r ctl_bootanim_prop)
2979(type ctl_bugreport_prop)
2980(roletype object_r ctl_bugreport_prop)
2981(type ctl_console_prop)
2982(roletype object_r ctl_console_prop)
2983(type ctl_dumpstate_prop)
2984(roletype object_r ctl_dumpstate_prop)
2985(type ctl_fuse_prop)
2986(roletype object_r ctl_fuse_prop)
2987(type ctl_gsid_prop)
2988(roletype object_r ctl_gsid_prop)
2989(type ctl_interface_restart_prop)
2990(roletype object_r ctl_interface_restart_prop)
2991(type ctl_interface_stop_prop)
2992(roletype object_r ctl_interface_stop_prop)
2993(type ctl_mdnsd_prop)
2994(roletype object_r ctl_mdnsd_prop)
2995(type ctl_restart_prop)
2996(roletype object_r ctl_restart_prop)
2997(type ctl_rildaemon_prop)
2998(roletype object_r ctl_rildaemon_prop)
2999(type ctl_sigstop_prop)
3000(roletype object_r ctl_sigstop_prop)
3001(type dynamic_system_prop)
3002(roletype object_r dynamic_system_prop)
3003(type heapprofd_enabled_prop)
3004(roletype object_r heapprofd_enabled_prop)
3005(type llkd_prop)
3006(roletype object_r llkd_prop)
3007(type lpdumpd_prop)
3008(roletype object_r lpdumpd_prop)
3009(type mmc_prop)
3010(roletype object_r mmc_prop)
3011(type mock_ota_prop)
3012(roletype object_r mock_ota_prop)
3013(type net_dns_prop)
3014(roletype object_r net_dns_prop)
3015(type overlay_prop)
3016(roletype object_r overlay_prop)
3017(type persistent_properties_ready_prop)
3018(roletype object_r persistent_properties_ready_prop)
3019(type safemode_prop)
3020(roletype object_r safemode_prop)
3021(type system_lmk_prop)
3022(roletype object_r system_lmk_prop)
3023(type system_trace_prop)
3024(roletype object_r system_trace_prop)
3025(type test_boot_reason_prop)
3026(roletype object_r test_boot_reason_prop)
3027(type time_prop)
3028(roletype object_r time_prop)
3029(type traced_enabled_prop)
3030(roletype object_r traced_enabled_prop)
3031(type traced_lazy_prop)
3032(roletype object_r traced_lazy_prop)
3033(type aac_drc_prop)
3034(roletype object_r aac_drc_prop)
3035(type adaptive_haptics_prop)
3036(roletype object_r adaptive_haptics_prop)
3037(type apex_ready_prop)
3038(roletype object_r apex_ready_prop)
3039(type arm64_memtag_prop)
3040(roletype object_r arm64_memtag_prop)
3041(type binder_cache_bluetooth_server_prop)
3042(roletype object_r binder_cache_bluetooth_server_prop)
3043(type binder_cache_system_server_prop)
3044(roletype object_r binder_cache_system_server_prop)
3045(type binder_cache_telephony_server_prop)
3046(roletype object_r binder_cache_telephony_server_prop)
3047(type boot_status_prop)
3048(roletype object_r boot_status_prop)
3049(type bootanim_system_prop)
3050(roletype object_r bootanim_system_prop)
3051(type bootloader_prop)
3052(roletype object_r bootloader_prop)
3053(type boottime_public_prop)
3054(roletype object_r boottime_public_prop)
3055(type bq_config_prop)
3056(roletype object_r bq_config_prop)
3057(type build_bootimage_prop)
3058(roletype object_r build_bootimage_prop)
3059(type build_prop)
3060(roletype object_r build_prop)
3061(type composd_vm_art_prop)
3062(roletype object_r composd_vm_art_prop)
3063(type device_config_aconfig_flags_prop)
3064(roletype object_r device_config_aconfig_flags_prop)
3065(type device_config_camera_native_prop)
3066(roletype object_r device_config_camera_native_prop)
3067(type device_config_edgetpu_native_prop)
3068(roletype object_r device_config_edgetpu_native_prop)
3069(type device_config_media_native_prop)
3070(roletype object_r device_config_media_native_prop)
3071(type device_config_nnapi_native_prop)
3072(roletype object_r device_config_nnapi_native_prop)
3073(type device_config_runtime_native_boot_prop)
3074(roletype object_r device_config_runtime_native_boot_prop)
3075(type device_config_runtime_native_prop)
3076(roletype object_r device_config_runtime_native_prop)
3077(type device_config_surface_flinger_native_boot_prop)
3078(roletype object_r device_config_surface_flinger_native_boot_prop)
3079(type device_config_vendor_system_native_prop)
3080(roletype object_r device_config_vendor_system_native_prop)
3081(type device_config_vendor_system_native_boot_prop)
3082(roletype object_r device_config_vendor_system_native_boot_prop)
3083(type drm_forcel3_prop)
3084(roletype object_r drm_forcel3_prop)
3085(type fingerprint_prop)
3086(roletype object_r fingerprint_prop)
3087(type gwp_asan_prop)
3088(roletype object_r gwp_asan_prop)
3089(type hal_instrumentation_prop)
3090(roletype object_r hal_instrumentation_prop)
3091(type userdebug_or_eng_prop)
3092(roletype object_r userdebug_or_eng_prop)
3093(type init_service_status_prop)
3094(roletype object_r init_service_status_prop)
3095(type libc_debug_prop)
3096(roletype object_r libc_debug_prop)
3097(type module_sdkextensions_prop)
3098(roletype object_r module_sdkextensions_prop)
3099(type nnapi_ext_deny_product_prop)
3100(roletype object_r nnapi_ext_deny_product_prop)
3101(type persist_wm_debug_prop)
3102(roletype object_r persist_wm_debug_prop)
3103(type power_debug_prop)
3104(roletype object_r power_debug_prop)
3105(type property_service_version_prop)
3106(roletype object_r property_service_version_prop)
3107(type provisioned_prop)
3108(roletype object_r provisioned_prop)
3109(type restorecon_prop)
3110(roletype object_r restorecon_prop)
3111(type retaildemo_prop)
3112(roletype object_r retaildemo_prop)
3113(type servicemanager_prop)
3114(roletype object_r servicemanager_prop)
3115(type smart_idle_maint_enabled_prop)
3116(roletype object_r smart_idle_maint_enabled_prop)
3117(type socket_hook_prop)
3118(roletype object_r socket_hook_prop)
3119(type sqlite_log_prop)
3120(roletype object_r sqlite_log_prop)
3121(type surfaceflinger_display_prop)
3122(roletype object_r surfaceflinger_display_prop)
3123(type system_boot_reason_prop)
3124(roletype object_r system_boot_reason_prop)
3125(type system_jvmti_agent_prop)
3126(roletype object_r system_jvmti_agent_prop)
3127(type traced_oome_heap_session_count_prop)
3128(roletype object_r traced_oome_heap_session_count_prop)
3129(type ab_update_gki_prop)
3130(roletype object_r ab_update_gki_prop)
3131(type usb_prop)
3132(roletype object_r usb_prop)
3133(type userspace_reboot_exported_prop)
3134(roletype object_r userspace_reboot_exported_prop)
3135(type vold_status_prop)
3136(roletype object_r vold_status_prop)
3137(type vts_status_prop)
3138(roletype object_r vts_status_prop)
3139(type config_prop)
3140(roletype object_r config_prop)
3141(type cppreopt_prop)
3142(roletype object_r cppreopt_prop)
3143(type dalvik_prop)
3144(roletype object_r dalvik_prop)
3145(type debuggerd_prop)
3146(roletype object_r debuggerd_prop)
3147(type device_logging_prop)
3148(roletype object_r device_logging_prop)
3149(type dhcp_prop)
3150(roletype object_r dhcp_prop)
3151(type dumpstate_prop)
3152(roletype object_r dumpstate_prop)
3153(type exported3_system_prop)
3154(roletype object_r exported3_system_prop)
3155(type exported_dumpstate_prop)
3156(roletype object_r exported_dumpstate_prop)
3157(type exported_secure_prop)
3158(roletype object_r exported_secure_prop)
3159(type heapprofd_prop)
3160(roletype object_r heapprofd_prop)
3161(type net_radio_prop)
3162(roletype object_r net_radio_prop)
3163(type pan_result_prop)
3164(roletype object_r pan_result_prop)
3165(type persist_debug_prop)
3166(roletype object_r persist_debug_prop)
3167(type shell_prop)
3168(roletype object_r shell_prop)
3169(type test_harness_prop)
3170(roletype object_r test_harness_prop)
3171(type theme_prop)
3172(roletype object_r theme_prop)
3173(type use_memfd_prop)
3174(roletype object_r use_memfd_prop)
3175(type vold_prop)
3176(roletype object_r vold_prop)
3177(type apexd_config_prop)
3178(roletype object_r apexd_config_prop)
3179(type apexd_select_prop)
3180(roletype object_r apexd_select_prop)
3181(type aaudio_config_prop)
3182(roletype object_r aaudio_config_prop)
3183(type apk_verity_prop)
3184(roletype object_r apk_verity_prop)
3185(type audio_config_prop)
3186(roletype object_r audio_config_prop)
3187(type bootanim_config_prop)
3188(roletype object_r bootanim_config_prop)
3189(type bluetooth_config_prop)
3190(roletype object_r bluetooth_config_prop)
3191(type build_attestation_prop)
3192(roletype object_r build_attestation_prop)
3193(type build_config_prop)
3194(roletype object_r build_config_prop)
3195(type build_odm_prop)
3196(roletype object_r build_odm_prop)
3197(type build_vendor_prop)
3198(roletype object_r build_vendor_prop)
3199(type camera_calibration_prop)
3200(roletype object_r camera_calibration_prop)
3201(type camera_config_prop)
3202(roletype object_r camera_config_prop)
3203(type camera2_extensions_prop)
3204(roletype object_r camera2_extensions_prop)
3205(type camerax_extensions_prop)
3206(roletype object_r camerax_extensions_prop)
3207(type charger_config_prop)
3208(roletype object_r charger_config_prop)
3209(type codec2_config_prop)
3210(roletype object_r codec2_config_prop)
3211(type composd_vm_vendor_prop)
3212(roletype object_r composd_vm_vendor_prop)
3213(type cpu_variant_prop)
3214(roletype object_r cpu_variant_prop)
3215(type debugfs_restriction_prop)
3216(roletype object_r debugfs_restriction_prop)
3217(type drm_service_config_prop)
3218(roletype object_r drm_service_config_prop)
3219(type exported_camera_prop)
3220(roletype object_r exported_camera_prop)
3221(type exported_config_prop)
3222(roletype object_r exported_config_prop)
3223(type exported_default_prop)
3224(roletype object_r exported_default_prop)
3225(type ffs_config_prop)
3226(roletype object_r ffs_config_prop)
3227(type framework_watchdog_config_prop)
3228(roletype object_r framework_watchdog_config_prop)
3229(type graphics_config_prop)
3230(roletype object_r graphics_config_prop)
3231(type hdmi_config_prop)
3232(roletype object_r hdmi_config_prop)
3233(type hw_timeout_multiplier_prop)
3234(roletype object_r hw_timeout_multiplier_prop)
3235(type hypervisor_prop)
3236(roletype object_r hypervisor_prop)
3237(type hypervisor_restricted_prop)
3238(roletype object_r hypervisor_restricted_prop)
3239(type incremental_prop)
3240(roletype object_r incremental_prop)
3241(type input_device_config_prop)
3242(roletype object_r input_device_config_prop)
3243(type keyguard_config_prop)
3244(roletype object_r keyguard_config_prop)
3245(type keystore_config_prop)
3246(roletype object_r keystore_config_prop)
3247(type lmkd_config_prop)
3248(roletype object_r lmkd_config_prop)
3249(type media_config_prop)
3250(roletype object_r media_config_prop)
3251(type media_variant_prop)
3252(roletype object_r media_variant_prop)
3253(type mediadrm_config_prop)
3254(roletype object_r mediadrm_config_prop)
3255(type mm_events_config_prop)
3256(roletype object_r mm_events_config_prop)
3257(type oem_unlock_prop)
3258(roletype object_r oem_unlock_prop)
3259(type ota_build_prop)
3260(roletype object_r ota_build_prop)
3261(type packagemanager_config_prop)
3262(roletype object_r packagemanager_config_prop)
3263(type quick_start_prop)
3264(roletype object_r quick_start_prop)
3265(type recovery_config_prop)
3266(roletype object_r recovery_config_prop)
3267(type recovery_usb_config_prop)
3268(roletype object_r recovery_usb_config_prop)
3269(type sendbug_config_prop)
3270(roletype object_r sendbug_config_prop)
3271(type soc_prop)
3272(roletype object_r soc_prop)
3273(type storage_config_prop)
3274(roletype object_r storage_config_prop)
3275(type storagemanager_config_prop)
3276(roletype object_r storagemanager_config_prop)
3277(type surfaceflinger_prop)
3278(roletype object_r surfaceflinger_prop)
3279(type suspend_prop)
3280(roletype object_r suspend_prop)
3281(type systemsound_config_prop)
3282(roletype object_r systemsound_config_prop)
3283(type telephony_config_prop)
3284(roletype object_r telephony_config_prop)
3285(type threadnetwork_config_prop)
3286(roletype object_r threadnetwork_config_prop)
3287(type tombstone_config_prop)
3288(roletype object_r tombstone_config_prop)
3289(type usb_config_prop)
3290(roletype object_r usb_config_prop)
3291(type userspace_reboot_config_prop)
3292(roletype object_r userspace_reboot_config_prop)
3293(type vehicle_hal_prop)
3294(roletype object_r vehicle_hal_prop)
3295(type vendor_security_patch_level_prop)
3296(roletype object_r vendor_security_patch_level_prop)
3297(type vendor_socket_hook_prop)
3298(roletype object_r vendor_socket_hook_prop)
3299(type virtual_ab_prop)
3300(roletype object_r virtual_ab_prop)
3301(type vndk_prop)
3302(roletype object_r vndk_prop)
3303(type vts_config_prop)
3304(roletype object_r vts_config_prop)
3305(type vold_config_prop)
3306(roletype object_r vold_config_prop)
3307(type wifi_config_prop)
3308(roletype object_r wifi_config_prop)
3309(type zram_config_prop)
3310(roletype object_r zram_config_prop)
3311(type zygote_config_prop)
3312(roletype object_r zygote_config_prop)
3313(type dck_prop)
3314(roletype object_r dck_prop)
3315(type tuner_config_prop)
3316(roletype object_r tuner_config_prop)
3317(type usb_uvc_enabled_prop)
3318(roletype object_r usb_uvc_enabled_prop)
3319(type setupwizard_mode_prop)
3320(roletype object_r setupwizard_mode_prop)
3321(type pm_archiving_enabled_prop)
3322(roletype object_r pm_archiving_enabled_prop)
3323(type adbd_config_prop)
3324(roletype object_r adbd_config_prop)
3325(type audio_prop)
3326(roletype object_r audio_prop)
3327(type bluetooth_a2dp_offload_prop)
3328(roletype object_r bluetooth_a2dp_offload_prop)
3329(type bluetooth_audio_hal_prop)
3330(roletype object_r bluetooth_audio_hal_prop)
3331(type bluetooth_prop)
3332(roletype object_r bluetooth_prop)
3333(type bpf_progs_loaded_prop)
3334(roletype object_r bpf_progs_loaded_prop)
3335(type charger_status_prop)
3336(roletype object_r charger_status_prop)
3337(type ctl_default_prop)
3338(roletype object_r ctl_default_prop)
3339(type ctl_interface_start_prop)
3340(roletype object_r ctl_interface_start_prop)
3341(type ctl_start_prop)
3342(roletype object_r ctl_start_prop)
3343(type ctl_stop_prop)
3344(roletype object_r ctl_stop_prop)
3345(type dalvik_config_prop)
3346(roletype object_r dalvik_config_prop)
3347(type dalvik_dynamic_config_prop)
3348(roletype object_r dalvik_dynamic_config_prop)
3349(type dalvik_runtime_prop)
3350(roletype object_r dalvik_runtime_prop)
3351(type debug_prop)
3352(roletype object_r debug_prop)
3353(type device_config_memory_safety_native_boot_prop)
3354(roletype object_r device_config_memory_safety_native_boot_prop)
3355(type device_config_memory_safety_native_prop)
3356(roletype object_r device_config_memory_safety_native_prop)
3357(type dumpstate_options_prop)
3358(roletype object_r dumpstate_options_prop)
3359(type exported_system_prop)
3360(roletype object_r exported_system_prop)
3361(type exported_bluetooth_prop)
3362(roletype object_r exported_bluetooth_prop)
3363(type exported_overlay_prop)
3364(roletype object_r exported_overlay_prop)
3365(type exported_pm_prop)
3366(roletype object_r exported_pm_prop)
3367(type future_pm_prop)
3368(roletype object_r future_pm_prop)
3369(type ffs_control_prop)
3370(roletype object_r ffs_control_prop)
3371(type framework_status_prop)
3372(roletype object_r framework_status_prop)
3373(type gesture_prop)
3374(roletype object_r gesture_prop)
3375(type graphics_config_writable_prop)
3376(roletype object_r graphics_config_writable_prop)
3377(type hal_dumpstate_config_prop)
3378(roletype object_r hal_dumpstate_config_prop)
3379(type sota_prop)
3380(roletype object_r sota_prop)
3381(type hwservicemanager_prop)
3382(roletype object_r hwservicemanager_prop)
3383(type lmkd_prop)
3384(roletype object_r lmkd_prop)
3385(type locale_prop)
3386(roletype object_r locale_prop)
3387(type logd_prop)
3388(roletype object_r logd_prop)
3389(type logpersistd_logging_prop)
3390(roletype object_r logpersistd_logging_prop)
3391(type log_prop)
3392(roletype object_r log_prop)
3393(type log_tag_prop)
3394(roletype object_r log_tag_prop)
3395(type lowpan_prop)
3396(roletype object_r lowpan_prop)
3397(type nfc_prop)
3398(roletype object_r nfc_prop)
3399(type ota_prop)
3400(roletype object_r ota_prop)
3401(type permissive_mte_prop)
3402(roletype object_r permissive_mte_prop)
3403(type powerctl_prop)
3404(roletype object_r powerctl_prop)
3405(type qemu_hw_prop)
3406(roletype object_r qemu_hw_prop)
3407(type qemu_sf_lcd_density_prop)
3408(roletype object_r qemu_sf_lcd_density_prop)
3409(type radio_control_prop)
3410(roletype object_r radio_control_prop)
3411(type radio_prop)
3412(roletype object_r radio_prop)
3413(type serialno_prop)
3414(roletype object_r serialno_prop)
3415(type surfaceflinger_color_prop)
3416(roletype object_r surfaceflinger_color_prop)
3417(type system_prop)
3418(roletype object_r system_prop)
3419(type system_user_mode_emulation_prop)
3420(roletype object_r system_user_mode_emulation_prop)
3421(type telephony_status_prop)
3422(roletype object_r telephony_status_prop)
3423(type timezone_prop)
3424(roletype object_r timezone_prop)
3425(type usb_control_prop)
3426(roletype object_r usb_control_prop)
3427(type vold_post_fs_data_prop)
3428(roletype object_r vold_post_fs_data_prop)
3429(type wifi_hal_prop)
3430(roletype object_r wifi_hal_prop)
3431(type wifi_log_prop)
3432(roletype object_r wifi_log_prop)
3433(type wifi_prop)
3434(roletype object_r wifi_prop)
3435(type zram_control_prop)
3436(roletype object_r zram_control_prop)
3437(type default_prop)
3438(roletype object_r default_prop)
3439(type rebootescrow_hal_prop)
3440(roletype object_r rebootescrow_hal_prop)
3441(type virtual_face_hal_prop)
3442(roletype object_r virtual_face_hal_prop)
3443(type virtual_fingerprint_hal_prop)
3444(roletype object_r virtual_fingerprint_hal_prop)
3445(type persist_vendor_debug_wifi_prop)
3446(roletype object_r persist_vendor_debug_wifi_prop)
3447(type vendor_default_prop)
3448(roletype object_r vendor_default_prop)
3449(type radio)
3450(roletype object_r radio)
3451(type recovery)
3452(roletype object_r recovery)
3453(type recovery_persist)
3454(roletype object_r recovery_persist)
3455(type recovery_persist_exec)
3456(roletype object_r recovery_persist_exec)
3457(type recovery_refresh)
3458(roletype object_r recovery_refresh)
3459(type recovery_refresh_exec)
3460(roletype object_r recovery_refresh_exec)
3461(type rkpdapp)
3462(roletype object_r rkpdapp)
3463(type rs)
3464(roletype object_r rs)
3465(type rs_exec)
3466(roletype object_r rs_exec)
3467(type rss_hwm_reset)
3468(roletype object_r rss_hwm_reset)
3469(type runas)
3470(roletype object_r runas)
3471(type runas_exec)
3472(roletype object_r runas_exec)
3473(type runas_app)
3474(roletype object_r runas_app)
3475(type sdcardd)
3476(roletype object_r sdcardd)
3477(type sdcardd_exec)
3478(roletype object_r sdcardd_exec)
3479(type secure_element)
3480(roletype object_r secure_element)
3481(type aidl_lazy_test_service)
3482(roletype object_r aidl_lazy_test_service)
3483(type apc_service)
3484(roletype object_r apc_service)
3485(type apex_service)
3486(roletype object_r apex_service)
3487(type artd_service)
3488(roletype object_r artd_service)
3489(type artd_pre_reboot_service)
3490(roletype object_r artd_pre_reboot_service)
3491(type audioserver_service)
3492(roletype object_r audioserver_service)
3493(type authorization_service)
3494(roletype object_r authorization_service)
3495(type batteryproperties_service)
3496(roletype object_r batteryproperties_service)
3497(type bluetooth_service)
3498(roletype object_r bluetooth_service)
3499(type cameraserver_service)
3500(roletype object_r cameraserver_service)
3501(type fwk_camera_service)
3502(roletype object_r fwk_camera_service)
3503(type default_android_service)
3504(roletype object_r default_android_service)
3505(type device_config_updatable_service)
3506(roletype object_r device_config_updatable_service)
3507(type dexopt_chroot_setup_service)
3508(roletype object_r dexopt_chroot_setup_service)
3509(type dnsresolver_service)
3510(roletype object_r dnsresolver_service)
3511(type drmserver_service)
3512(roletype object_r drmserver_service)
3513(type dumpstate_service)
3514(roletype object_r dumpstate_service)
3515(type evsmanagerd_service)
3516(roletype object_r evsmanagerd_service)
3517(type fingerprintd_service)
3518(roletype object_r fingerprintd_service)
3519(type fwk_automotive_display_service)
3520(roletype object_r fwk_automotive_display_service)
3521(type gatekeeper_service)
3522(roletype object_r gatekeeper_service)
3523(type gpu_service)
3524(roletype object_r gpu_service)
3525(type idmap_service)
3526(roletype object_r idmap_service)
3527(type incident_service)
3528(roletype object_r incident_service)
3529(type installd_service)
3530(roletype object_r installd_service)
3531(type credstore_service)
3532(roletype object_r credstore_service)
3533(type keystore_compat_hal_service)
3534(roletype object_r keystore_compat_hal_service)
3535(type keystore_maintenance_service)
3536(roletype object_r keystore_maintenance_service)
3537(type keystore_metrics_service)
3538(roletype object_r keystore_metrics_service)
3539(type keystore_service)
3540(roletype object_r keystore_service)
3541(type legacykeystore_service)
3542(roletype object_r legacykeystore_service)
3543(type lpdump_service)
3544(roletype object_r lpdump_service)
3545(type mdns_service)
3546(roletype object_r mdns_service)
3547(type mediaserver_service)
3548(roletype object_r mediaserver_service)
3549(type mediametrics_service)
3550(roletype object_r mediametrics_service)
3551(type mediaextractor_service)
3552(roletype object_r mediaextractor_service)
3553(type mediadrmserver_service)
3554(roletype object_r mediadrmserver_service)
3555(type mediatranscoding_service)
3556(roletype object_r mediatranscoding_service)
3557(type netd_service)
3558(roletype object_r netd_service)
3559(type nfc_service)
3560(roletype object_r nfc_service)
3561(type ondevicepersonalization_system_service)
3562(roletype object_r ondevicepersonalization_system_service)
3563(type ot_daemon_service)
3564(roletype object_r ot_daemon_service)
3565(type profiling_service)
3566(roletype object_r profiling_service)
3567(type radio_service)
3568(roletype object_r radio_service)
3569(type secure_element_service)
3570(roletype object_r secure_element_service)
3571(type service_manager_service)
3572(roletype object_r service_manager_service)
3573(type storaged_service)
3574(roletype object_r storaged_service)
3575(type surfaceflinger_service)
3576(roletype object_r surfaceflinger_service)
3577(type system_app_service)
3578(roletype object_r system_app_service)
3579(type system_net_netd_service)
3580(roletype object_r system_net_netd_service)
3581(type system_suspend_control_internal_service)
3582(roletype object_r system_suspend_control_internal_service)
3583(type system_suspend_control_service)
3584(roletype object_r system_suspend_control_service)
3585(type update_engine_service)
3586(roletype object_r update_engine_service)
3587(type update_engine_stable_service)
3588(roletype object_r update_engine_stable_service)
3589(type virtualization_service)
3590(roletype object_r virtualization_service)
3591(type virtual_camera_service)
3592(roletype object_r virtual_camera_service)
3593(type virtual_touchpad_service)
3594(roletype object_r virtual_touchpad_service)
3595(type vold_service)
3596(roletype object_r vold_service)
3597(type vr_hwc_service)
3598(roletype object_r vr_hwc_service)
3599(type vrflinger_vsync_service)
3600(roletype object_r vrflinger_vsync_service)
3601(type accessibility_service)
3602(roletype object_r accessibility_service)
3603(type account_service)
3604(roletype object_r account_service)
3605(type activity_service)
3606(roletype object_r activity_service)
3607(type activity_task_service)
3608(roletype object_r activity_task_service)
3609(type adb_service)
3610(roletype object_r adb_service)
3611(type adservices_manager_service)
3612(roletype object_r adservices_manager_service)
3613(type alarm_service)
3614(roletype object_r alarm_service)
3615(type app_binding_service)
3616(roletype object_r app_binding_service)
3617(type app_hibernation_service)
3618(roletype object_r app_hibernation_service)
3619(type app_integrity_service)
3620(roletype object_r app_integrity_service)
3621(type app_prediction_service)
3622(roletype object_r app_prediction_service)
3623(type app_search_service)
3624(roletype object_r app_search_service)
3625(type appops_service)
3626(roletype object_r appops_service)
3627(type appwidget_service)
3628(roletype object_r appwidget_service)
3629(type archive_service)
3630(roletype object_r archive_service)
3631(type assetatlas_service)
3632(roletype object_r assetatlas_service)
3633(type attestation_verification_service)
3634(roletype object_r attestation_verification_service)
3635(type audio_service)
3636(roletype object_r audio_service)
3637(type auth_service)
3638(roletype object_r auth_service)
3639(type autofill_service)
3640(roletype object_r autofill_service)
3641(type backup_service)
3642(roletype object_r backup_service)
3643(type batterystats_service)
3644(roletype object_r batterystats_service)
3645(type battery_service)
3646(roletype object_r battery_service)
3647(type binder_calls_stats_service)
3648(roletype object_r binder_calls_stats_service)
3649(type blob_store_service)
3650(roletype object_r blob_store_service)
3651(type bluetooth_manager_service)
3652(roletype object_r bluetooth_manager_service)
3653(type broadcastradio_service)
3654(roletype object_r broadcastradio_service)
3655(type cacheinfo_service)
3656(roletype object_r cacheinfo_service)
3657(type cameraproxy_service)
3658(roletype object_r cameraproxy_service)
3659(type clipboard_service)
3660(roletype object_r clipboard_service)
3661(type cloudsearch_service)
3662(roletype object_r cloudsearch_service)
3663(type contexthub_service)
3664(roletype object_r contexthub_service)
3665(type contextual_search_service)
3666(roletype object_r contextual_search_service)
3667(type crossprofileapps_service)
3668(roletype object_r crossprofileapps_service)
3669(type IProxyService_service)
3670(roletype object_r IProxyService_service)
3671(type companion_device_service)
3672(roletype object_r companion_device_service)
3673(type connectivity_native_service)
3674(roletype object_r connectivity_native_service)
3675(type connectivity_service)
3676(roletype object_r connectivity_service)
3677(type connmetrics_service)
3678(roletype object_r connmetrics_service)
3679(type consumer_ir_service)
3680(roletype object_r consumer_ir_service)
3681(type content_capture_service)
3682(roletype object_r content_capture_service)
3683(type content_suggestions_service)
3684(roletype object_r content_suggestions_service)
3685(type content_service)
3686(roletype object_r content_service)
3687(type country_detector_service)
3688(roletype object_r country_detector_service)
3689(type coverage_service)
3690(roletype object_r coverage_service)
3691(type cpuinfo_service)
3692(roletype object_r cpuinfo_service)
3693(type cpu_monitor_service)
3694(roletype object_r cpu_monitor_service)
3695(type credential_service)
3696(roletype object_r credential_service)
3697(type dataloader_manager_service)
3698(roletype object_r dataloader_manager_service)
3699(type dbinfo_service)
3700(roletype object_r dbinfo_service)
3701(type device_config_service)
3702(roletype object_r device_config_service)
3703(type device_policy_service)
3704(roletype object_r device_policy_service)
3705(type device_state_service)
3706(roletype object_r device_state_service)
3707(type deviceidle_service)
3708(roletype object_r deviceidle_service)
3709(type device_identifiers_service)
3710(roletype object_r device_identifiers_service)
3711(type devicestoragemonitor_service)
3712(roletype object_r devicestoragemonitor_service)
3713(type diskstats_service)
3714(roletype object_r diskstats_service)
3715(type display_service)
3716(roletype object_r display_service)
3717(type domain_verification_service)
3718(roletype object_r domain_verification_service)
3719(type color_display_service)
3720(roletype object_r color_display_service)
3721(type ecm_enhanced_confirmation_service)
3722(roletype object_r ecm_enhanced_confirmation_service)
3723(type external_vibrator_service)
3724(roletype object_r external_vibrator_service)
3725(type file_integrity_service)
3726(roletype object_r file_integrity_service)
3727(type font_service)
3728(roletype object_r font_service)
3729(type netd_listener_service)
3730(roletype object_r netd_listener_service)
3731(type network_watchlist_service)
3732(roletype object_r network_watchlist_service)
3733(type devicelock_service)
3734(roletype object_r devicelock_service)
3735(type DockObserver_service)
3736(roletype object_r DockObserver_service)
3737(type dreams_service)
3738(roletype object_r dreams_service)
3739(type dropbox_service)
3740(roletype object_r dropbox_service)
3741(type ethernet_service)
3742(roletype object_r ethernet_service)
3743(type biometric_service)
3744(roletype object_r biometric_service)
3745(type bugreport_service)
3746(roletype object_r bugreport_service)
3747(type platform_compat_service)
3748(roletype object_r platform_compat_service)
3749(type face_service)
3750(roletype object_r face_service)
3751(type fingerprint_service)
3752(roletype object_r fingerprint_service)
3753(type fwk_altitude_service)
3754(roletype object_r fwk_altitude_service)
3755(type fwk_stats_service)
3756(roletype object_r fwk_stats_service)
3757(type fwk_sensor_service)
3758(roletype object_r fwk_sensor_service)
3759(type fwk_vibrator_control_service)
3760(roletype object_r fwk_vibrator_control_service)
3761(type game_service)
3762(roletype object_r game_service)
3763(type gfxinfo_service)
3764(roletype object_r gfxinfo_service)
3765(type gnss_time_update_service)
3766(roletype object_r gnss_time_update_service)
3767(type grammatical_inflection_service)
3768(roletype object_r grammatical_inflection_service)
3769(type graphicsstats_service)
3770(roletype object_r graphicsstats_service)
3771(type hardware_service)
3772(roletype object_r hardware_service)
3773(type hardware_properties_service)
3774(roletype object_r hardware_properties_service)
3775(type hdmi_control_service)
3776(roletype object_r hdmi_control_service)
3777(type healthconnect_service)
3778(roletype object_r healthconnect_service)
3779(type hint_service)
3780(roletype object_r hint_service)
3781(type imms_service)
3782(roletype object_r imms_service)
3783(type incremental_service)
3784(roletype object_r incremental_service)
3785(type input_method_service)
3786(roletype object_r input_method_service)
3787(type input_service)
3788(roletype object_r input_service)
3789(type ipsec_service)
3790(roletype object_r ipsec_service)
3791(type iris_service)
3792(roletype object_r iris_service)
3793(type jobscheduler_service)
3794(roletype object_r jobscheduler_service)
3795(type launcherapps_service)
3796(roletype object_r launcherapps_service)
3797(type legacy_permission_service)
3798(roletype object_r legacy_permission_service)
3799(type light_service)
3800(roletype object_r light_service)
3801(type locale_service)
3802(roletype object_r locale_service)
3803(type location_service)
3804(roletype object_r location_service)
3805(type location_time_zone_manager_service)
3806(roletype object_r location_time_zone_manager_service)
3807(type lock_settings_service)
3808(roletype object_r lock_settings_service)
3809(type looper_stats_service)
3810(roletype object_r looper_stats_service)
3811(type media_communication_service)
3812(roletype object_r media_communication_service)
3813(type media_metrics_service)
3814(roletype object_r media_metrics_service)
3815(type media_projection_service)
3816(roletype object_r media_projection_service)
3817(type media_router_service)
3818(roletype object_r media_router_service)
3819(type media_session_service)
3820(roletype object_r media_session_service)
3821(type meminfo_service)
3822(roletype object_r meminfo_service)
3823(type memtrackproxy_service)
3824(roletype object_r memtrackproxy_service)
3825(type midi_service)
3826(roletype object_r midi_service)
3827(type mount_service)
3828(roletype object_r mount_service)
3829(type music_recognition_service)
3830(roletype object_r music_recognition_service)
3831(type nearby_service)
3832(roletype object_r nearby_service)
3833(type netpolicy_service)
3834(roletype object_r netpolicy_service)
3835(type netstats_service)
3836(roletype object_r netstats_service)
3837(type network_management_service)
3838(roletype object_r network_management_service)
3839(type network_score_service)
3840(roletype object_r network_score_service)
3841(type network_stack_service)
3842(roletype object_r network_stack_service)
3843(type network_time_update_service)
3844(roletype object_r network_time_update_service)
3845(type notification_service)
3846(roletype object_r notification_service)
3847(type oem_lock_service)
3848(roletype object_r oem_lock_service)
3849(type otadexopt_service)
3850(roletype object_r otadexopt_service)
3851(type overlay_service)
3852(roletype object_r overlay_service)
3853(type pac_proxy_service)
3854(roletype object_r pac_proxy_service)
3855(type package_service)
3856(roletype object_r package_service)
3857(type package_native_service)
3858(roletype object_r package_native_service)
3859(type people_service)
3860(roletype object_r people_service)
3861(type permission_service)
3862(roletype object_r permission_service)
3863(type permissionmgr_service)
3864(roletype object_r permissionmgr_service)
3865(type permission_checker_service)
3866(roletype object_r permission_checker_service)
3867(type persistent_data_block_service)
3868(roletype object_r persistent_data_block_service)
3869(type pinner_service)
3870(roletype object_r pinner_service)
3871(type powerstats_service)
3872(roletype object_r powerstats_service)
3873(type power_service)
3874(roletype object_r power_service)
3875(type print_service)
3876(roletype object_r print_service)
3877(type processinfo_service)
3878(roletype object_r processinfo_service)
3879(type procstats_service)
3880(roletype object_r procstats_service)
3881(type reboot_readiness_service)
3882(roletype object_r reboot_readiness_service)
3883(type recovery_service)
3884(roletype object_r recovery_service)
3885(type registry_service)
3886(roletype object_r registry_service)
3887(type remote_auth_service)
3888(roletype object_r remote_auth_service)
3889(type remote_provisioning_service)
3890(roletype object_r remote_provisioning_service)
3891(type resources_manager_service)
3892(roletype object_r resources_manager_service)
3893(type restrictions_service)
3894(roletype object_r restrictions_service)
3895(type role_service)
3896(roletype object_r role_service)
3897(type rollback_service)
3898(roletype object_r rollback_service)
3899(type runtime_service)
3900(roletype object_r runtime_service)
3901(type rttmanager_service)
3902(roletype object_r rttmanager_service)
3903(type samplingprofiler_service)
3904(roletype object_r samplingprofiler_service)
3905(type scheduling_policy_service)
3906(roletype object_r scheduling_policy_service)
3907(type search_service)
3908(roletype object_r search_service)
3909(type search_ui_service)
3910(roletype object_r search_ui_service)
3911(type sec_key_att_app_id_provider_service)
3912(roletype object_r sec_key_att_app_id_provider_service)
3913(type security_state_service)
3914(roletype object_r security_state_service)
3915(type selection_toolbar_service)
3916(roletype object_r selection_toolbar_service)
3917(type sensitive_content_protection_service)
3918(roletype object_r sensitive_content_protection_service)
3919(type sensorservice_service)
3920(roletype object_r sensorservice_service)
3921(type sensor_privacy_service)
3922(roletype object_r sensor_privacy_service)
3923(type serial_service)
3924(roletype object_r serial_service)
3925(type servicediscovery_service)
3926(roletype object_r servicediscovery_service)
3927(type settings_service)
3928(roletype object_r settings_service)
3929(type shortcut_service)
3930(roletype object_r shortcut_service)
3931(type slice_service)
3932(roletype object_r slice_service)
3933(type smartspace_service)
3934(roletype object_r smartspace_service)
3935(type statusbar_service)
3936(roletype object_r statusbar_service)
3937(type storagestats_service)
3938(roletype object_r storagestats_service)
3939(type sdk_sandbox_service)
3940(roletype object_r sdk_sandbox_service)
3941(type system_config_service)
3942(roletype object_r system_config_service)
3943(type system_server_dumper_service)
3944(roletype object_r system_server_dumper_service)
3945(type system_update_service)
3946(roletype object_r system_update_service)
3947(type soundtrigger_middleware_service)
3948(roletype object_r soundtrigger_middleware_service)
3949(type speech_recognition_service)
3950(roletype object_r speech_recognition_service)
3951(type tare_service)
3952(roletype object_r tare_service)
3953(type task_service)
3954(roletype object_r task_service)
3955(type testharness_service)
3956(roletype object_r testharness_service)
3957(type textclassification_service)
3958(roletype object_r textclassification_service)
3959(type textservices_service)
3960(roletype object_r textservices_service)
3961(type texttospeech_service)
3962(roletype object_r texttospeech_service)
3963(type telecom_service)
3964(roletype object_r telecom_service)
3965(type thermal_service)
3966(roletype object_r thermal_service)
3967(type threadnetwork_service)
3968(roletype object_r threadnetwork_service)
3969(type timedetector_service)
3970(roletype object_r timedetector_service)
3971(type timezonedetector_service)
3972(roletype object_r timezonedetector_service)
3973(type translation_service)
3974(roletype object_r translation_service)
3975(type trust_service)
3976(roletype object_r trust_service)
3977(type tv_ad_service)
3978(roletype object_r tv_ad_service)
3979(type tv_iapp_service)
3980(roletype object_r tv_iapp_service)
3981(type tv_input_service)
3982(roletype object_r tv_input_service)
3983(type tv_tuner_resource_mgr_service)
3984(roletype object_r tv_tuner_resource_mgr_service)
3985(type uimode_service)
3986(roletype object_r uimode_service)
3987(type updatelock_service)
3988(roletype object_r updatelock_service)
3989(type uri_grants_service)
3990(roletype object_r uri_grants_service)
3991(type usagestats_service)
3992(roletype object_r usagestats_service)
3993(type usb_service)
3994(roletype object_r usb_service)
3995(type user_service)
3996(roletype object_r user_service)
3997(type uwb_service)
3998(roletype object_r uwb_service)
3999(type vcn_management_service)
4000(roletype object_r vcn_management_service)
4001(type vibrator_service)
4002(roletype object_r vibrator_service)
4003(type vibrator_manager_service)
4004(roletype object_r vibrator_manager_service)
4005(type virtual_device_service)
4006(roletype object_r virtual_device_service)
4007(type virtual_device_native_service)
4008(roletype object_r virtual_device_native_service)
4009(type voiceinteraction_service)
4010(roletype object_r voiceinteraction_service)
4011(type vpn_management_service)
4012(roletype object_r vpn_management_service)
4013(type vr_manager_service)
4014(roletype object_r vr_manager_service)
4015(type wallpaper_service)
4016(roletype object_r wallpaper_service)
4017(type wallpaper_effects_generation_service)
4018(roletype object_r wallpaper_effects_generation_service)
4019(type webviewupdate_service)
4020(roletype object_r webviewupdate_service)
4021(type wifip2p_service)
4022(roletype object_r wifip2p_service)
4023(type wifiscanner_service)
4024(roletype object_r wifiscanner_service)
4025(type wifi_service)
4026(roletype object_r wifi_service)
4027(type wifinl80211_service)
4028(roletype object_r wifinl80211_service)
4029(type wifiaware_service)
4030(roletype object_r wifiaware_service)
4031(type window_service)
4032(roletype object_r window_service)
4033(type inputflinger_service)
4034(roletype object_r inputflinger_service)
4035(type tethering_service)
4036(roletype object_r tethering_service)
4037(type emergency_affordance_service)
4038(roletype object_r emergency_affordance_service)
4039(type hal_audio_service)
4040(roletype object_r hal_audio_service)
4041(type hal_audiocontrol_service)
4042(roletype object_r hal_audiocontrol_service)
4043(type hal_authgraph_service)
4044(roletype object_r hal_authgraph_service)
4045(type hal_authsecret_service)
4046(roletype object_r hal_authsecret_service)
4047(type hal_bluetooth_service)
4048(roletype object_r hal_bluetooth_service)
4049(type hal_bootctl_service)
4050(roletype object_r hal_bootctl_service)
4051(type hal_broadcastradio_service)
4052(roletype object_r hal_broadcastradio_service)
4053(type hal_camera_service)
4054(roletype object_r hal_camera_service)
4055(type hal_can_controller_service)
4056(roletype object_r hal_can_controller_service)
4057(type hal_cas_service)
4058(roletype object_r hal_cas_service)
4059(type hal_codec2_service)
4060(roletype object_r hal_codec2_service)
4061(type hal_confirmationui_service)
4062(roletype object_r hal_confirmationui_service)
4063(type hal_contexthub_service)
4064(roletype object_r hal_contexthub_service)
4065(type hal_drm_service)
4066(roletype object_r hal_drm_service)
4067(type hal_dumpstate_service)
4068(roletype object_r hal_dumpstate_service)
4069(type hal_evs_service)
4070(roletype object_r hal_evs_service)
4071(type hal_face_service)
4072(roletype object_r hal_face_service)
4073(type hal_fastboot_service)
4074(roletype object_r hal_fastboot_service)
4075(type hal_fingerprint_service)
4076(roletype object_r hal_fingerprint_service)
4077(type hal_gnss_service)
4078(roletype object_r hal_gnss_service)
4079(type hal_graphics_allocator_service)
4080(roletype object_r hal_graphics_allocator_service)
4081(type hal_graphics_composer_service)
4082(roletype object_r hal_graphics_composer_service)
4083(type hal_graphics_mapper_service)
4084(roletype object_r hal_graphics_mapper_service)
4085(type hal_health_service)
4086(roletype object_r hal_health_service)
4087(type hal_health_storage_service)
4088(roletype object_r hal_health_storage_service)
4089(type hal_identity_service)
4090(roletype object_r hal_identity_service)
4091(type hal_input_processor_service)
4092(roletype object_r hal_input_processor_service)
4093(type hal_ir_service)
4094(roletype object_r hal_ir_service)
4095(type hal_ivn_service)
4096(roletype object_r hal_ivn_service)
4097(type hal_keymint_service)
4098(roletype object_r hal_keymint_service)
4099(type hal_light_service)
4100(roletype object_r hal_light_service)
4101(type hal_macsec_service)
4102(roletype object_r hal_macsec_service)
4103(type hal_memtrack_service)
4104(roletype object_r hal_memtrack_service)
4105(type hal_neuralnetworks_service)
4106(roletype object_r hal_neuralnetworks_service)
4107(type hal_nfc_service)
4108(roletype object_r hal_nfc_service)
4109(type hal_oemlock_service)
4110(roletype object_r hal_oemlock_service)
4111(type hal_power_service)
4112(roletype object_r hal_power_service)
4113(type hal_power_stats_service)
4114(roletype object_r hal_power_stats_service)
4115(type hal_radio_service)
4116(roletype object_r hal_radio_service)
4117(type hal_rebootescrow_service)
4118(roletype object_r hal_rebootescrow_service)
4119(type hal_remoteaccess_service)
4120(roletype object_r hal_remoteaccess_service)
4121(type hal_remotelyprovisionedcomponent_avf_service)
4122(roletype object_r hal_remotelyprovisionedcomponent_avf_service)
4123(type hal_remotelyprovisionedcomponent_service)
4124(roletype object_r hal_remotelyprovisionedcomponent_service)
4125(type hal_sensors_service)
4126(roletype object_r hal_sensors_service)
4127(type hal_secretkeeper_service)
4128(roletype object_r hal_secretkeeper_service)
4129(type hal_secureclock_service)
4130(roletype object_r hal_secureclock_service)
4131(type hal_secure_element_service)
4132(roletype object_r hal_secure_element_service)
4133(type hal_sharedsecret_service)
4134(roletype object_r hal_sharedsecret_service)
4135(type hal_system_suspend_service)
4136(roletype object_r hal_system_suspend_service)
4137(type hal_tetheroffload_service)
4138(roletype object_r hal_tetheroffload_service)
4139(type hal_thermal_service)
4140(roletype object_r hal_thermal_service)
4141(type hal_tv_hdmi_cec_service)
4142(roletype object_r hal_tv_hdmi_cec_service)
4143(type hal_tv_hdmi_connection_service)
4144(roletype object_r hal_tv_hdmi_connection_service)
4145(type hal_tv_hdmi_earc_service)
4146(roletype object_r hal_tv_hdmi_earc_service)
4147(type hal_tv_input_service)
4148(roletype object_r hal_tv_input_service)
4149(type hal_threadnetwork_service)
4150(roletype object_r hal_threadnetwork_service)
4151(type hal_tv_tuner_service)
4152(roletype object_r hal_tv_tuner_service)
4153(type hal_usb_service)
4154(roletype object_r hal_usb_service)
4155(type hal_usb_gadget_service)
4156(roletype object_r hal_usb_gadget_service)
4157(type hal_uwb_service)
4158(roletype object_r hal_uwb_service)
4159(type hal_vehicle_service)
4160(roletype object_r hal_vehicle_service)
4161(type hal_vibrator_service)
4162(roletype object_r hal_vibrator_service)
4163(type hal_weaver_service)
4164(roletype object_r hal_weaver_service)
4165(type hal_nlinterceptor_service)
4166(roletype object_r hal_nlinterceptor_service)
4167(type hal_wifi_service)
4168(roletype object_r hal_wifi_service)
4169(type hal_wifi_hostapd_service)
4170(roletype object_r hal_wifi_hostapd_service)
4171(type hal_wifi_supplicant_service)
4172(roletype object_r hal_wifi_supplicant_service)
4173(type hal_gatekeeper_service)
4174(roletype object_r hal_gatekeeper_service)
4175(type servicemanager)
4176(roletype object_r servicemanager)
4177(type servicemanager_exec)
4178(roletype object_r servicemanager_exec)
4179(type sgdisk)
4180(roletype object_r sgdisk)
4181(type sgdisk_exec)
4182(roletype object_r sgdisk_exec)
4183(type shared_relro)
4184(roletype object_r shared_relro)
4185(type shell)
4186(roletype object_r shell)
4187(type shell_exec)
4188(roletype object_r shell_exec)
4189(type simpleperf)
4190(roletype object_r simpleperf)
4191(type simpleperf_app_runner)
4192(roletype object_r simpleperf_app_runner)
4193(type simpleperf_app_runner_exec)
4194(roletype object_r simpleperf_app_runner_exec)
4195(type slideshow)
4196(roletype object_r slideshow)
4197(type statsd)
4198(roletype object_r statsd)
4199(type statsd_exec)
4200(roletype object_r statsd_exec)
4201(type su)
4202(roletype object_r su)
4203(type su_exec)
4204(roletype object_r su_exec)
4205(type surfaceflinger)
4206(roletype object_r surfaceflinger)
4207(type surfaceflinger_tmpfs)
4208(roletype object_r surfaceflinger_tmpfs)
4209(type system_app)
4210(roletype object_r system_app)
4211(type system_server)
4212(roletype object_r system_server)
4213(type system_server_tmpfs)
4214(roletype object_r system_server_tmpfs)
4215(type tee)
4216(roletype object_r tee)
4217(type tee_device)
4218(roletype object_r tee_device)
4219(type tombstoned)
4220(roletype object_r tombstoned)
4221(type tombstoned_exec)
4222(roletype object_r tombstoned_exec)
4223(type toolbox)
4224(roletype object_r toolbox)
4225(type toolbox_exec)
4226(roletype object_r toolbox_exec)
4227(type traced)
4228(roletype object_r traced)
4229(type traced_tmpfs)
4230(roletype object_r traced_tmpfs)
4231(type traced_perf)
4232(roletype object_r traced_perf)
4233(type traced_probes)
4234(roletype object_r traced_probes)
4235(type traceur_app)
4236(roletype object_r traceur_app)
4237(type ueventd)
4238(roletype object_r ueventd)
4239(type ueventd_tmpfs)
4240(roletype object_r ueventd_tmpfs)
4241(type uncrypt)
4242(roletype object_r uncrypt)
4243(type uncrypt_exec)
4244(roletype object_r uncrypt_exec)
4245(type untrusted_app)
4246(roletype object_r untrusted_app)
4247(type untrusted_app_32)
4248(roletype object_r untrusted_app_32)
4249(type untrusted_app_30)
4250(roletype object_r untrusted_app_30)
4251(type untrusted_app_29)
4252(roletype object_r untrusted_app_29)
4253(type untrusted_app_27)
4254(roletype object_r untrusted_app_27)
4255(type untrusted_app_25)
4256(roletype object_r untrusted_app_25)
4257(type update_engine)
4258(roletype object_r update_engine)
4259(type update_engine_exec)
4260(roletype object_r update_engine_exec)
4261(type update_verifier)
4262(roletype object_r update_verifier)
4263(type update_verifier_exec)
4264(roletype object_r update_verifier_exec)
4265(type usbd)
4266(roletype object_r usbd)
4267(type usbd_exec)
4268(roletype object_r usbd_exec)
4269(type vdc)
4270(roletype object_r vdc)
4271(type vdc_exec)
4272(roletype object_r vdc_exec)
4273(type vendor_init)
4274(roletype object_r vendor_init)
4275(type vendor_misc_writer)
4276(roletype object_r vendor_misc_writer)
4277(type vendor_misc_writer_exec)
4278(roletype object_r vendor_misc_writer_exec)
4279(type vendor_modprobe)
4280(roletype object_r vendor_modprobe)
4281(type vendor_shell)
4282(roletype object_r vendor_shell)
4283(type vendor_shell_exec)
4284(roletype object_r vendor_shell_exec)
4285(type vendor_toolbox_exec)
4286(roletype object_r vendor_toolbox_exec)
4287(type virtual_touchpad)
4288(roletype object_r virtual_touchpad)
4289(type virtual_touchpad_exec)
4290(roletype object_r virtual_touchpad_exec)
4291(type service_manager_vndservice)
4292(roletype object_r service_manager_vndservice)
4293(type default_android_vndservice)
4294(roletype object_r default_android_vndservice)
4295(type vndservicemanager)
4296(roletype object_r vndservicemanager)
4297(type vold)
4298(roletype object_r vold)
4299(type vold_exec)
4300(roletype object_r vold_exec)
4301(type vold_prepare_subdirs)
4302(roletype object_r vold_prepare_subdirs)
4303(type vold_prepare_subdirs_exec)
4304(roletype object_r vold_prepare_subdirs_exec)
4305(type watchdogd)
4306(roletype object_r watchdogd)
4307(type watchdogd_exec)
4308(roletype object_r watchdogd_exec)
4309(type webview_zygote)
4310(roletype object_r webview_zygote)
4311(type webview_zygote_exec)
4312(roletype object_r webview_zygote_exec)
4313(type webview_zygote_tmpfs)
4314(roletype object_r webview_zygote_tmpfs)
4315(type wificond)
4316(roletype object_r wificond)
4317(type wificond_exec)
4318(roletype object_r wificond_exec)
4319(type zygote)
4320(roletype object_r zygote)
4321(type zygote_tmpfs)
4322(roletype object_r zygote_tmpfs)
4323(type zygote_exec)
4324(roletype object_r zygote_exec)
4325(typeattribute hal_lazy_test)
4326(expandtypeattribute (hal_lazy_test) true)
4327(typeattribute hal_lazy_test_client)
4328(expandtypeattribute (hal_lazy_test_client) true)
4329(typeattribute hal_lazy_test_server)
4330(expandtypeattribute (hal_lazy_test_server) false)
4331(typeattribute mlsvendorcompat)
4332(typeattribute system_and_vendor_property_type)
4333(expandtypeattribute (system_and_vendor_property_type) false)
4334(typeattribute sdk_sandbox_all)
4335(typeattributeset sdk_sandbox_all (sdk_sandbox_34 sdk_sandbox_audit sdk_sandbox_next ))
4336(typeattribute sdk_sandbox_current)
4337(typeattributeset sdk_sandbox_current (sdk_sandbox_34 sdk_sandbox_audit ))
4338(type aconfigd)
4339(roletype object_r aconfigd)
4340(type aconfigd_exec)
4341(roletype object_r aconfigd_exec)
4342(type apex_test_prepostinstall)
4343(roletype object_r apex_test_prepostinstall)
4344(type apex_test_prepostinstall_exec)
4345(roletype object_r apex_test_prepostinstall_exec)
4346(type apexd_devpts)
4347(roletype object_r apexd_devpts)
4348(type apexd_derive_classpath)
4349(roletype object_r apexd_derive_classpath)
4350(type app_zygote_userfaultfd)
4351(roletype object_r app_zygote_userfaultfd)
4352(type art_boot)
4353(roletype object_r art_boot)
4354(type art_boot_exec)
4355(roletype object_r art_boot_exec)
4356(type artd_exec)
4357(roletype object_r artd_exec)
4358(type artd_tmpfs)
4359(roletype object_r artd_tmpfs)
4360(type artd_userfaultfd)
4361(roletype object_r artd_userfaultfd)
4362(type atrace_exec)
4363(roletype object_r atrace_exec)
4364(type audioserver_exec)
4365(roletype object_r audioserver_exec)
4366(type auditctl)
4367(roletype object_r auditctl)
4368(type auditctl_exec)
4369(roletype object_r auditctl_exec)
4370(type automotive_display_service)
4371(roletype object_r automotive_display_service)
4372(type automotive_display_service_exec)
4373(roletype object_r automotive_display_service_exec)
4374(type blank_screen)
4375(roletype object_r blank_screen)
4376(type blank_screen_exec)
4377(roletype object_r blank_screen_exec)
4378(type blkid_exec)
4379(roletype object_r blkid_exec)
4380(type bluetooth_userfaultfd)
4381(roletype object_r bluetooth_userfaultfd)
4382(type boringssl_self_test)
4383(roletype object_r boringssl_self_test)
4384(type boringssl_self_test_exec)
4385(roletype object_r boringssl_self_test_exec)
4386(type vendor_boringssl_self_test)
4387(roletype object_r vendor_boringssl_self_test)
4388(type vendor_boringssl_self_test_exec)
4389(roletype object_r vendor_boringssl_self_test_exec)
4390(type boringssl_self_test_marker)
4391(roletype object_r boringssl_self_test_marker)
4392(type bpfloader_exec)
4393(roletype object_r bpfloader_exec)
4394(type canhalconfigurator)
4395(roletype object_r canhalconfigurator)
4396(type canhalconfigurator_exec)
4397(roletype object_r canhalconfigurator_exec)
4398(type clatd)
4399(roletype object_r clatd)
4400(type clatd_exec)
4401(roletype object_r clatd_exec)
4402(type compos_fd_server)
4403(roletype object_r compos_fd_server)
4404(type compos_verify)
4405(roletype object_r compos_verify)
4406(type compos_verify_exec)
4407(roletype object_r compos_verify_exec)
4408(type composd)
4409(roletype object_r composd)
4410(type composd_exec)
4411(roletype object_r composd_exec)
4412(type cppreopts)
4413(roletype object_r cppreopts)
4414(type cppreopts_exec)
4415(roletype object_r cppreopts_exec)
4416(type crosvm)
4417(roletype object_r crosvm)
4418(type crosvm_exec)
4419(roletype object_r crosvm_exec)
4420(type crosvm_tmpfs)
4421(roletype object_r crosvm_tmpfs)
4422(type derive_classpath)
4423(roletype object_r derive_classpath)
4424(type derive_classpath_exec)
4425(roletype object_r derive_classpath_exec)
4426(type derive_sdk)
4427(roletype object_r derive_sdk)
4428(type derive_sdk_exec)
4429(roletype object_r derive_sdk_exec)
4430(type device_as_webcam)
4431(roletype object_r device_as_webcam)
4432(type device_as_webcam_userfaultfd)
4433(roletype object_r device_as_webcam_userfaultfd)
4434(type dex2oat)
4435(roletype object_r dex2oat)
4436(type dex2oat_exec)
4437(roletype object_r dex2oat_exec)
4438(type dex2oat_userfaultfd)
4439(roletype object_r dex2oat_userfaultfd)
4440(type dexopt_chroot_setup)
4441(roletype object_r dexopt_chroot_setup)
4442(type dexopt_chroot_setup_exec)
4443(roletype object_r dexopt_chroot_setup_exec)
4444(type dexopt_chroot_setup_tmpfs)
4445(roletype object_r dexopt_chroot_setup_tmpfs)
4446(type dexopt_chroot_setup_userfaultfd)
4447(roletype object_r dexopt_chroot_setup_userfaultfd)
4448(type dexoptanalyzer)
4449(roletype object_r dexoptanalyzer)
4450(type dexoptanalyzer_exec)
4451(roletype object_r dexoptanalyzer_exec)
4452(type dexoptanalyzer_tmpfs)
4453(roletype object_r dexoptanalyzer_tmpfs)
4454(type dexoptanalyzer_userfaultfd)
4455(roletype object_r dexoptanalyzer_userfaultfd)
4456(type dmesgd)
4457(roletype object_r dmesgd)
4458(type dmesgd_exec)
4459(roletype object_r dmesgd_exec)
4460(type dumpstate_tmpfs)
4461(roletype object_r dumpstate_tmpfs)
4462(type ephemeral_app_userfaultfd)
4463(roletype object_r ephemeral_app_userfaultfd)
4464(type evsmanagerd_exec)
4465(roletype object_r evsmanagerd_exec)
4466(type fastbootd_iouring)
4467(roletype object_r fastbootd_iouring)
4468(type config_gz)
4469(roletype object_r config_gz)
4470(type fs_bpf_net_private)
4471(roletype object_r fs_bpf_net_private)
4472(type fs_bpf_net_shared)
4473(roletype object_r fs_bpf_net_shared)
4474(type fs_bpf_netd_readonly)
4475(roletype object_r fs_bpf_netd_readonly)
4476(type fs_bpf_netd_shared)
4477(roletype object_r fs_bpf_netd_shared)
4478(type fs_bpf_loader)
4479(roletype object_r fs_bpf_loader)
4480(type fs_bpf_uprobestats)
4481(roletype object_r fs_bpf_uprobestats)
4482(type storaged_data_file)
4483(roletype object_r storaged_data_file)
4484(type wm_trace_data_file)
4485(roletype object_r wm_trace_data_file)
4486(type accessibility_trace_data_file)
4487(roletype object_r accessibility_trace_data_file)
4488(type perfetto_traces_data_file)
4489(roletype object_r perfetto_traces_data_file)
4490(type perfetto_traces_bugreport_data_file)
4491(roletype object_r perfetto_traces_bugreport_data_file)
4492(type perfetto_traces_profiling_data_file)
4493(roletype object_r perfetto_traces_profiling_data_file)
4494(type perfetto_configs_data_file)
4495(roletype object_r perfetto_configs_data_file)
4496(type uprobestats_configs_data_file)
4497(roletype object_r uprobestats_configs_data_file)
4498(type oatdump_exec)
4499(roletype object_r oatdump_exec)
4500(type sdk_sandbox_system_data_file)
4501(roletype object_r sdk_sandbox_system_data_file)
4502(type sdk_sandbox_data_file)
4503(roletype object_r sdk_sandbox_data_file)
4504(type debugfs_kcov)
4505(roletype object_r debugfs_kcov)
4506(type app_exec_data_file)
4507(roletype object_r app_exec_data_file)
4508(type rollback_data_file)
4509(roletype object_r rollback_data_file)
4510(type checkin_data_file)
4511(roletype object_r checkin_data_file)
4512(type ota_image_data_file)
4513(roletype object_r ota_image_data_file)
4514(type gsi_persistent_data_file)
4515(roletype object_r gsi_persistent_data_file)
4516(type emergency_data_file)
4517(roletype object_r emergency_data_file)
4518(type profcollectd_data_file)
4519(roletype object_r profcollectd_data_file)
4520(type apex_art_data_file)
4521(roletype object_r apex_art_data_file)
4522(type apex_art_staging_data_file)
4523(roletype object_r apex_art_staging_data_file)
4524(type apex_compos_data_file)
4525(roletype object_r apex_compos_data_file)
4526(type apex_virt_data_file)
4527(roletype object_r apex_virt_data_file)
4528(type apex_tethering_data_file)
4529(roletype object_r apex_tethering_data_file)
4530(type apex_appsearch_data_file)
4531(roletype object_r apex_appsearch_data_file)
4532(type apex_permission_data_file)
4533(roletype object_r apex_permission_data_file)
4534(type apex_scheduling_data_file)
4535(roletype object_r apex_scheduling_data_file)
4536(type apex_wifi_data_file)
4537(roletype object_r apex_wifi_data_file)
4538(type font_data_file)
4539(roletype object_r font_data_file)
4540(type dmesgd_data_file)
4541(roletype object_r dmesgd_data_file)
4542(type odrefresh_data_file)
4543(roletype object_r odrefresh_data_file)
4544(type odsign_data_file)
4545(roletype object_r odsign_data_file)
4546(type odsign_metrics_file)
4547(roletype object_r odsign_metrics_file)
4548(type virtualizationservice_data_file)
4549(roletype object_r virtualizationservice_data_file)
4550(type environ_system_data_file)
4551(roletype object_r environ_system_data_file)
4552(type bootanim_data_file)
4553(roletype object_r bootanim_data_file)
4554(type kvm_device)
4555(roletype object_r kvm_device)
4556(type fd_server_exec)
4557(roletype object_r fd_server_exec)
4558(type compos_exec)
4559(roletype object_r compos_exec)
4560(type compos_key_helper_exec)
4561(roletype object_r compos_key_helper_exec)
4562(type art_exec_exec)
4563(roletype object_r art_exec_exec)
4564(type prng_seeder_socket)
4565(roletype object_r prng_seeder_socket)
4566(type sysfs_dt_avf)
4567(roletype object_r sysfs_dt_avf)
4568(type proc_dt_avf)
4569(roletype object_r proc_dt_avf)
4570(type system_font_fallback_file)
4571(roletype object_r system_font_fallback_file)
4572(type sysfs_uprobe)
4573(roletype object_r sysfs_uprobe)
4574(type aconfigd_socket)
4575(roletype object_r aconfigd_socket)
4576(type system_aconfig_storage_file)
4577(roletype object_r system_aconfig_storage_file)
4578(type vendor_aconfig_storage_file)
4579(roletype object_r vendor_aconfig_storage_file)
4580(type fsverity_init)
4581(roletype object_r fsverity_init)
4582(type fsverity_init_exec)
4583(roletype object_r fsverity_init_exec)
4584(type fuseblkd_exec)
4585(roletype object_r fuseblkd_exec)
4586(type fuseblkd)
4587(roletype object_r fuseblkd)
4588(type fuseblkd_untrusted_exec)
4589(roletype object_r fuseblkd_untrusted_exec)
4590(type fuseblkd_untrusted)
4591(roletype object_r fuseblkd_untrusted)
4592(type fwk_bufferhub)
4593(roletype object_r fwk_bufferhub)
4594(type fwk_bufferhub_exec)
4595(roletype object_r fwk_bufferhub_exec)
4596(type gki_apex_prepostinstall)
4597(roletype object_r gki_apex_prepostinstall)
4598(type gki_apex_prepostinstall_exec)
4599(roletype object_r gki_apex_prepostinstall_exec)
4600(type gmscore_app_userfaultfd)
4601(roletype object_r gmscore_app_userfaultfd)
4602(type gpuservice_exec)
4603(roletype object_r gpuservice_exec)
4604(type gsid)
4605(roletype object_r gsid)
4606(type gsid_exec)
4607(roletype object_r gsid_exec)
4608(type hal_allocator_default)
4609(roletype object_r hal_allocator_default)
4610(type hal_allocator_default_exec)
4611(roletype object_r hal_allocator_default_exec)
4612(type heapprofd_exec)
4613(roletype object_r heapprofd_exec)
4614(type heapprofd_tmpfs)
4615(roletype object_r heapprofd_tmpfs)
4616(type hidl_lazy_test_server)
4617(roletype object_r hidl_lazy_test_server)
4618(type hidl_lazy_test_server_exec)
4619(roletype object_r hidl_lazy_test_server_exec)
4620(type hal_lazy_test_hwservice)
4621(roletype object_r hal_lazy_test_hwservice)
4622(type incident_exec)
4623(roletype object_r incident_exec)
4624(type incident_helper_exec)
4625(roletype object_r incident_helper_exec)
4626(type incidentd_exec)
4627(roletype object_r incidentd_exec)
4628(type isolated_app_userfaultfd)
4629(roletype object_r isolated_app_userfaultfd)
4630(type isolated_compute_app_userfaultfd)
4631(roletype object_r isolated_compute_app_userfaultfd)
4632(type iw)
4633(roletype object_r iw)
4634(type iw_exec)
4635(roletype object_r iw_exec)
4636(type shell_key)
4637(roletype object_r shell_key)
4638(type su_key)
4639(roletype object_r su_key)
4640(type vold_key)
4641(roletype object_r vold_key)
4642(type odsign_key)
4643(roletype object_r odsign_key)
4644(type locksettings_key)
4645(roletype object_r locksettings_key)
4646(type resume_on_reboot_key)
4647(roletype object_r resume_on_reboot_key)
4648(type linkerconfig)
4649(roletype object_r linkerconfig)
4650(type linkerconfig_exec)
4651(roletype object_r linkerconfig_exec)
4652(type lpdumpd)
4653(roletype object_r lpdumpd)
4654(type lpdumpd_exec)
4655(roletype object_r lpdumpd_exec)
4656(type mdnsd_exec)
4657(roletype object_r mdnsd_exec)
4658(type mediaprovider_userfaultfd)
4659(roletype object_r mediaprovider_userfaultfd)
4660(type mediaprovider_app)
4661(roletype object_r mediaprovider_app)
4662(type mediaprovider_app_userfaultfd)
4663(roletype object_r mediaprovider_app_userfaultfd)
4664(type mediatranscoding_exec)
4665(roletype object_r mediatranscoding_exec)
4666(type mediatranscoding_tmpfs)
4667(roletype object_r mediatranscoding_tmpfs)
4668(type mediatuner)
4669(roletype object_r mediatuner)
4670(type mediatuner_exec)
4671(roletype object_r mediatuner_exec)
4672(type migrate_legacy_obb_data)
4673(roletype object_r migrate_legacy_obb_data)
4674(type migrate_legacy_obb_data_exec)
4675(roletype object_r migrate_legacy_obb_data_exec)
4676(type misctrl)
4677(roletype object_r misctrl)
4678(type misctrl_exec)
4679(roletype object_r misctrl_exec)
4680(type mm_events)
4681(roletype object_r mm_events)
4682(type mm_events_exec)
4683(roletype object_r mm_events_exec)
4684(type mtectrl)
4685(roletype object_r mtectrl)
4686(type mtectrl_exec)
4687(roletype object_r mtectrl_exec)
4688(type network_stack_userfaultfd)
4689(roletype object_r network_stack_userfaultfd)
4690(type nfc_userfaultfd)
4691(roletype object_r nfc_userfaultfd)
4692(type odrefresh)
4693(roletype object_r odrefresh)
4694(type odrefresh_exec)
4695(roletype object_r odrefresh_exec)
4696(type odrefresh_userfaultfd)
4697(roletype object_r odrefresh_userfaultfd)
4698(type odsign)
4699(roletype object_r odsign)
4700(type odsign_exec)
4701(roletype object_r odsign_exec)
4702(type odsign_devpts)
4703(roletype object_r odsign_devpts)
4704(type ot_daemon)
4705(roletype object_r ot_daemon)
4706(type ot_daemon_exec)
4707(roletype object_r ot_daemon_exec)
4708(type otapreopt_chroot_exec)
4709(roletype object_r otapreopt_chroot_exec)
4710(type otapreopt_slot)
4711(roletype object_r otapreopt_slot)
4712(type otapreopt_slot_exec)
4713(roletype object_r otapreopt_slot_exec)
4714(type perfetto_exec)
4715(roletype object_r perfetto_exec)
4716(type perfetto_tmpfs)
4717(roletype object_r perfetto_tmpfs)
4718(type permissioncontroller_app)
4719(roletype object_r permissioncontroller_app)
4720(type permissioncontroller_app_userfaultfd)
4721(roletype object_r permissioncontroller_app_userfaultfd)
4722(type platform_app_userfaultfd)
4723(roletype object_r platform_app_userfaultfd)
4724(type postinstall_exec)
4725(roletype object_r postinstall_exec)
4726(type postinstall_dexopt)
4727(roletype object_r postinstall_dexopt)
4728(type postinstall_dexopt_exec)
4729(roletype object_r postinstall_dexopt_exec)
4730(type postinstall_dexopt_tmpfs)
4731(roletype object_r postinstall_dexopt_tmpfs)
4732(type preloads_copy)
4733(roletype object_r preloads_copy)
4734(type preloads_copy_exec)
4735(roletype object_r preloads_copy_exec)
4736(type preopt2cachename)
4737(roletype object_r preopt2cachename)
4738(type preopt2cachename_exec)
4739(roletype object_r preopt2cachename_exec)
4740(type priv_app_userfaultfd)
4741(roletype object_r priv_app_userfaultfd)
4742(type priv_app_devpts)
4743(roletype object_r priv_app_devpts)
4744(type prng_seeder_exec)
4745(roletype object_r prng_seeder_exec)
4746(type profcollectd)
4747(roletype object_r profcollectd)
4748(type profcollectd_exec)
4749(roletype object_r profcollectd_exec)
4750(type adbd_prop)
4751(roletype object_r adbd_prop)
4752(type apexd_payload_metadata_prop)
4753(roletype object_r apexd_payload_metadata_prop)
4754(type ctl_snapuserd_prop)
4755(roletype object_r ctl_snapuserd_prop)
4756(type crashrecovery_prop)
4757(roletype object_r crashrecovery_prop)
4758(type device_config_core_experiments_team_internal_prop)
4759(roletype object_r device_config_core_experiments_team_internal_prop)
4760(type device_config_lmkd_native_prop)
4761(roletype object_r device_config_lmkd_native_prop)
4762(type device_config_mglru_native_prop)
4763(roletype object_r device_config_mglru_native_prop)
4764(type device_config_profcollect_native_boot_prop)
4765(roletype object_r device_config_profcollect_native_boot_prop)
4766(type device_config_remote_key_provisioning_native_prop)
4767(roletype object_r device_config_remote_key_provisioning_native_prop)
4768(type device_config_statsd_native_prop)
4769(roletype object_r device_config_statsd_native_prop)
4770(type device_config_statsd_native_boot_prop)
4771(roletype object_r device_config_statsd_native_boot_prop)
4772(type device_config_storage_native_boot_prop)
4773(roletype object_r device_config_storage_native_boot_prop)
4774(type device_config_sys_traced_prop)
4775(roletype object_r device_config_sys_traced_prop)
4776(type device_config_window_manager_native_boot_prop)
4777(roletype object_r device_config_window_manager_native_boot_prop)
4778(type device_config_configuration_prop)
4779(roletype object_r device_config_configuration_prop)
4780(type device_config_connectivity_prop)
4781(roletype object_r device_config_connectivity_prop)
4782(type device_config_swcodec_native_prop)
4783(roletype object_r device_config_swcodec_native_prop)
4784(type device_config_tethering_u_or_later_native_prop)
4785(roletype object_r device_config_tethering_u_or_later_native_prop)
4786(type dmesgd_start_prop)
4787(roletype object_r dmesgd_start_prop)
4788(type fastbootd_protocol_prop)
4789(roletype object_r fastbootd_protocol_prop)
4790(type gsid_prop)
4791(roletype object_r gsid_prop)
4792(type init_perf_lsm_hooks_prop)
4793(roletype object_r init_perf_lsm_hooks_prop)
4794(type init_service_status_private_prop)
4795(roletype object_r init_service_status_private_prop)
4796(type init_storage_prop)
4797(roletype object_r init_storage_prop)
4798(type init_svc_debug_prop)
4799(roletype object_r init_svc_debug_prop)
4800(type keystore_crash_prop)
4801(roletype object_r keystore_crash_prop)
4802(type keystore_listen_prop)
4803(roletype object_r keystore_listen_prop)
4804(type last_boot_reason_prop)
4805(roletype object_r last_boot_reason_prop)
4806(type localization_prop)
4807(roletype object_r localization_prop)
4808(type logd_auditrate_prop)
4809(roletype object_r logd_auditrate_prop)
4810(type lower_kptr_restrict_prop)
4811(roletype object_r lower_kptr_restrict_prop)
4812(type net_464xlat_fromvendor_prop)
4813(roletype object_r net_464xlat_fromvendor_prop)
4814(type net_connectivity_prop)
4815(roletype object_r net_connectivity_prop)
4816(type netd_stable_secret_prop)
4817(roletype object_r netd_stable_secret_prop)
4818(type next_boot_prop)
4819(roletype object_r next_boot_prop)
4820(type odsign_prop)
4821(roletype object_r odsign_prop)
4822(type misctrl_prop)
4823(roletype object_r misctrl_prop)
4824(type perf_drop_caches_prop)
4825(roletype object_r perf_drop_caches_prop)
4826(type pm_prop)
4827(roletype object_r pm_prop)
4828(type profcollectd_node_id_prop)
4829(roletype object_r profcollectd_node_id_prop)
4830(type radio_cdma_ecm_prop)
4831(roletype object_r radio_cdma_ecm_prop)
4832(type remote_prov_prop)
4833(roletype object_r remote_prov_prop)
4834(type rollback_test_prop)
4835(roletype object_r rollback_test_prop)
4836(type setupwizard_prop)
4837(roletype object_r setupwizard_prop)
4838(type snapuserd_prop)
4839(roletype object_r snapuserd_prop)
4840(type system_adbd_prop)
4841(roletype object_r system_adbd_prop)
4842(type system_audio_config_prop)
4843(roletype object_r system_audio_config_prop)
4844(type timezone_metadata_prop)
4845(roletype object_r timezone_metadata_prop)
4846(type traced_perf_enabled_prop)
4847(roletype object_r traced_perf_enabled_prop)
4848(type uprobestats_start_with_config_prop)
4849(roletype object_r uprobestats_start_with_config_prop)
4850(type tuner_server_ctl_prop)
4851(roletype object_r tuner_server_ctl_prop)
4852(type userspace_reboot_log_prop)
4853(roletype object_r userspace_reboot_log_prop)
4854(type userspace_reboot_test_prop)
4855(roletype object_r userspace_reboot_test_prop)
4856(type verity_status_prop)
4857(roletype object_r verity_status_prop)
4858(type zygote_wrap_prop)
4859(roletype object_r zygote_wrap_prop)
4860(type ctl_mediatranscoding_prop)
4861(roletype object_r ctl_mediatranscoding_prop)
4862(type ctl_odsign_prop)
4863(roletype object_r ctl_odsign_prop)
4864(type virtualizationservice_prop)
4865(roletype object_r virtualizationservice_prop)
4866(type ctl_apex_load_prop)
4867(roletype object_r ctl_apex_load_prop)
4868(type enable_16k_pages_prop)
4869(roletype object_r enable_16k_pages_prop)
4870(type sensors_config_prop)
4871(roletype object_r sensors_config_prop)
4872(type hypervisor_pvmfw_prop)
4873(roletype object_r hypervisor_pvmfw_prop)
4874(type hypervisor_virtualizationmanager_prop)
4875(roletype object_r hypervisor_virtualizationmanager_prop)
4876(type game_manager_config_prop)
4877(roletype object_r game_manager_config_prop)
4878(type hidl_memory_prop)
4879(roletype object_r hidl_memory_prop)
4880(type suspend_debug_prop)
4881(roletype object_r suspend_debug_prop)
4882(type device_config_virtualization_framework_native_prop)
4883(roletype object_r device_config_virtualization_framework_native_prop)
4884(type log_file_logger_prop)
4885(roletype object_r log_file_logger_prop)
4886(type persist_sysui_builder_extras_prop)
4887(roletype object_r persist_sysui_builder_extras_prop)
4888(type persist_sysui_ranking_update_prop)
4889(roletype object_r persist_sysui_ranking_update_prop)
4890(type radio_userfaultfd)
4891(roletype object_r radio_userfaultfd)
4892(type remount)
4893(roletype object_r remount)
4894(type remount_exec)
4895(roletype object_r remount_exec)
4896(type rkpd)
4897(roletype object_r rkpd)
4898(type rkpd_exec)
4899(roletype object_r rkpd_exec)
4900(type rkpdapp_userfaultfd)
4901(roletype object_r rkpdapp_userfaultfd)
4902(type rss_hwm_reset_exec)
4903(roletype object_r rss_hwm_reset_exec)
4904(type runas_app_userfaultfd)
4905(roletype object_r runas_app_userfaultfd)
4906(type sdk_sandbox_34)
4907(roletype object_r sdk_sandbox_34)
4908(type sdk_sandbox_34_userfaultfd)
4909(roletype object_r sdk_sandbox_34_userfaultfd)
4910(type sdk_sandbox_audit)
4911(roletype object_r sdk_sandbox_audit)
4912(type sdk_sandbox_audit_userfaultfd)
4913(roletype object_r sdk_sandbox_audit_userfaultfd)
4914(type sdk_sandbox_next)
4915(roletype object_r sdk_sandbox_next)
4916(type sdk_sandbox_next_userfaultfd)
4917(roletype object_r sdk_sandbox_next_userfaultfd)
4918(type secure_element_userfaultfd)
4919(roletype object_r secure_element_userfaultfd)
4920(type adaptive_auth_service)
4921(roletype object_r adaptive_auth_service)
4922(type ambient_context_service)
4923(roletype object_r ambient_context_service)
4924(type attention_service)
4925(roletype object_r attention_service)
4926(type bg_install_control_service)
4927(roletype object_r bg_install_control_service)
4928(type compos_service)
4929(roletype object_r compos_service)
4930(type communal_service)
4931(roletype object_r communal_service)
4932(type dynamic_system_service)
4933(roletype object_r dynamic_system_service)
4934(type feature_flags_service)
4935(roletype object_r feature_flags_service)
4936(type gsi_service)
4937(roletype object_r gsi_service)
4938(type incidentcompanion_service)
4939(roletype object_r incidentcompanion_service)
4940(type logcat_service)
4941(roletype object_r logcat_service)
4942(type logd_service)
4943(roletype object_r logd_service)
4944(type mediatuner_service)
4945(roletype object_r mediatuner_service)
4946(type profcollectd_service)
4947(roletype object_r profcollectd_service)
4948(type resolver_service)
4949(roletype object_r resolver_service)
4950(type rkpd_registrar_service)
4951(roletype object_r rkpd_registrar_service)
4952(type rkpd_refresh_service)
4953(roletype object_r rkpd_refresh_service)
4954(type safety_center_service)
4955(roletype object_r safety_center_service)
4956(type stats_service)
4957(roletype object_r stats_service)
4958(type statsbootstrap_service)
4959(roletype object_r statsbootstrap_service)
4960(type statscompanion_service)
4961(roletype object_r statscompanion_service)
4962(type statsmanager_service)
4963(roletype object_r statsmanager_service)
4964(type tracingproxy_service)
4965(roletype object_r tracingproxy_service)
4966(type transparency_service)
4967(roletype object_r transparency_service)
4968(type uce_service)
4969(roletype object_r uce_service)
4970(type wearable_sensing_service)
4971(roletype object_r wearable_sensing_service)
4972(type shared_relro_userfaultfd)
4973(roletype object_r shared_relro_userfaultfd)
4974(type shell_userfaultfd)
4975(roletype object_r shell_userfaultfd)
4976(type simpleperf_exec)
4977(roletype object_r simpleperf_exec)
4978(type simpleperf_userfaultfd)
4979(roletype object_r simpleperf_userfaultfd)
4980(type simpleperf_boot)
4981(roletype object_r simpleperf_boot)
4982(type simpleperf_boot_data_file)
4983(roletype object_r simpleperf_boot_data_file)
4984(type snapshotctl)
4985(roletype object_r snapshotctl)
4986(type snapshotctl_exec)
4987(roletype object_r snapshotctl_exec)
4988(type snapuserd)
4989(roletype object_r snapuserd)
4990(type snapuserd_exec)
4991(roletype object_r snapuserd_exec)
4992(type snapuserd_iouring)
4993(roletype object_r snapuserd_iouring)
4994(type stats)
4995(roletype object_r stats)
4996(type stats_exec)
4997(roletype object_r stats_exec)
4998(type storaged)
4999(roletype object_r storaged)
5000(type storaged_exec)
5001(roletype object_r storaged_exec)
5002(type surfaceflinger_exec)
5003(roletype object_r surfaceflinger_exec)
5004(type system_app_userfaultfd)
5005(roletype object_r system_app_userfaultfd)
5006(type system_server_userfaultfd)
5007(roletype object_r system_server_userfaultfd)
5008(type system_server_startup)
5009(roletype object_r system_server_startup)
5010(type system_server_startup_tmpfs)
5011(roletype object_r system_server_startup_tmpfs)
5012(type system_suspend)
5013(roletype object_r system_suspend)
5014(type system_suspend_exec)
5015(roletype object_r system_suspend_exec)
5016(type traced_exec)
5017(roletype object_r traced_exec)
5018(type traced_perf_exec)
5019(roletype object_r traced_perf_exec)
5020(type traced_probes_exec)
5021(roletype object_r traced_probes_exec)
5022(type traced_probes_tmpfs)
5023(roletype object_r traced_probes_tmpfs)
5024(type traceur_app_userfaultfd)
5025(roletype object_r traceur_app_userfaultfd)
5026(type untrusted_app_userfaultfd)
5027(roletype object_r untrusted_app_userfaultfd)
5028(type untrusted_app_25_userfaultfd)
5029(roletype object_r untrusted_app_25_userfaultfd)
5030(type untrusted_app_27_userfaultfd)
5031(roletype object_r untrusted_app_27_userfaultfd)
5032(type untrusted_app_29_userfaultfd)
5033(roletype object_r untrusted_app_29_userfaultfd)
5034(type untrusted_app_30_userfaultfd)
5035(roletype object_r untrusted_app_30_userfaultfd)
5036(type untrusted_app_32_userfaultfd)
5037(roletype object_r untrusted_app_32_userfaultfd)
5038(type untrusted_app_all_devpts)
5039(roletype object_r untrusted_app_all_devpts)
5040(type uprobestats)
5041(roletype object_r uprobestats)
5042(type uprobestats_exec)
5043(roletype object_r uprobestats_exec)
5044(type vehicle_binding_util)
5045(roletype object_r vehicle_binding_util)
5046(type vehicle_binding_util_exec)
5047(roletype object_r vehicle_binding_util_exec)
5048(type viewcompiler)
5049(roletype object_r viewcompiler)
5050(type viewcompiler_exec)
5051(roletype object_r viewcompiler_exec)
5052(type viewcompiler_tmpfs)
5053(roletype object_r viewcompiler_tmpfs)
5054(type virtual_camera)
5055(roletype object_r virtual_camera)
5056(type virtual_camera_exec)
5057(roletype object_r virtual_camera_exec)
5058(type virtualizationmanager)
5059(roletype object_r virtualizationmanager)
5060(type virtualizationmanager_exec)
5061(roletype object_r virtualizationmanager_exec)
5062(type virtualizationservice)
5063(roletype object_r virtualizationservice)
5064(type virtualizationservice_exec)
5065(roletype object_r virtualizationservice_exec)
5066(type vzwomatrigger_app)
5067(roletype object_r vzwomatrigger_app)
5068(type vzwomatrigger_app_userfaultfd)
5069(roletype object_r vzwomatrigger_app_userfaultfd)
5070(type wait_for_keymaster)
5071(roletype object_r wait_for_keymaster)
5072(type wait_for_keymaster_exec)
5073(roletype object_r wait_for_keymaster_exec)
5074(type webview_zygote_userfaultfd)
5075(roletype object_r webview_zygote_userfaultfd)
5076(type zygote_userfaultfd)
5077(roletype object_r zygote_userfaultfd)
5078(user u)
5079(userrole u object_r)
5080(userrole u r)
5081(userlevel u (s0 ))
5082(userrange u ((s0 ) (s0 (range c0 c1023))))
5083(sensitivity s0)
5084(sensitivitycategory s0 (c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 c10 c11 c12 c13 c14 c15 c16 c17 c18 c19 c20 c21 c22 c23 c24 c25 c26 c27 c28 c29 c30 c31 c32 c33 c34 c35 c36 c37 c38 c39 c40 c41 c42 c43 c44 c45 c46 c47 c48 c49 c50 c51 c52 c53 c54 c55 c56 c57 c58 c59 c60 c61 c62 c63 c64 c65 c66 c67 c68 c69 c70 c71 c72 c73 c74 c75 c76 c77 c78 c79 c80 c81 c82 c83 c84 c85 c86 c87 c88 c89 c90 c91 c92 c93 c94 c95 c96 c97 c98 c99 c100 c101 c102 c103 c104 c105 c106 c107 c108 c109 c110 c111 c112 c113 c114 c115 c116 c117 c118 c119 c120 c121 c122 c123 c124 c125 c126 c127 c128 c129 c130 c131 c132 c133 c134 c135 c136 c137 c138 c139 c140 c141 c142 c143 c144 c145 c146 c147 c148 c149 c150 c151 c152 c153 c154 c155 c156 c157 c158 c159 c160 c161 c162 c163 c164 c165 c166 c167 c168 c169 c170 c171 c172 c173 c174 c175 c176 c177 c178 c179 c180 c181 c182 c183 c184 c185 c186 c187 c188 c189 c190 c191 c192 c193 c194 c195 c196 c197 c198 c199 c200 c201 c202 c203 c204 c205 c206 c207 c208 c209 c210 c211 c212 c213 c214 c215 c216 c217 c218 c219 c220 c221 c222 c223 c224 c225 c226 c227 c228 c229 c230 c231 c232 c233 c234 c235 c236 c237 c238 c239 c240 c241 c242 c243 c244 c245 c246 c247 c248 c249 c250 c251 c252 c253 c254 c255 c256 c257 c258 c259 c260 c261 c262 c263 c264 c265 c266 c267 c268 c269 c270 c271 c272 c273 c274 c275 c276 c277 c278 c279 c280 c281 c282 c283 c284 c285 c286 c287 c288 c289 c290 c291 c292 c293 c294 c295 c296 c297 c298 c299 c300 c301 c302 c303 c304 c305 c306 c307 c308 c309 c310 c311 c312 c313 c314 c315 c316 c317 c318 c319 c320 c321 c322 c323 c324 c325 c326 c327 c328 c329 c330 c331 c332 c333 c334 c335 c336 c337 c338 c339 c340 c341 c342 c343 c344 c345 c346 c347 c348 c349 c350 c351 c352 c353 c354 c355 c356 c357 c358 c359 c360 c361 c362 c363 c364 c365 c366 c367 c368 c369 c370 c371 c372 c373 c374 c375 c376 c377 c378 c379 c380 c381 c382 c383 c384 c385 c386 c387 c388 c389 c390 c391 c392 c393 c394 c395 c396 c397 c398 c399 c400 c401 c402 c403 c404 c405 c406 c407 c408 c409 c410 c411 c412 c413 c414 c415 c416 c417 c418 c419 c420 c421 c422 c423 c424 c425 c426 c427 c428 c429 c430 c431 c432 c433 c434 c435 c436 c437 c438 c439 c440 c441 c442 c443 c444 c445 c446 c447 c448 c449 c450 c451 c452 c453 c454 c455 c456 c457 c458 c459 c460 c461 c462 c463 c464 c465 c466 c467 c468 c469 c470 c471 c472 c473 c474 c475 c476 c477 c478 c479 c480 c481 c482 c483 c484 c485 c486 c487 c488 c489 c490 c491 c492 c493 c494 c495 c496 c497 c498 c499 c500 c501 c502 c503 c504 c505 c506 c507 c508 c509 c510 c511 c512 c513 c514 c515 c516 c517 c518 c519 c520 c521 c522 c523 c524 c525 c526 c527 c528 c529 c530 c531 c532 c533 c534 c535 c536 c537 c538 c539 c540 c541 c542 c543 c544 c545 c546 c547 c548 c549 c550 c551 c552 c553 c554 c555 c556 c557 c558 c559 c560 c561 c562 c563 c564 c565 c566 c567 c568 c569 c570 c571 c572 c573 c574 c575 c576 c577 c578 c579 c580 c581 c582 c583 c584 c585 c586 c587 c588 c589 c590 c591 c592 c593 c594 c595 c596 c597 c598 c599 c600 c601 c602 c603 c604 c605 c606 c607 c608 c609 c610 c611 c612 c613 c614 c615 c616 c617 c618 c619 c620 c621 c622 c623 c624 c625 c626 c627 c628 c629 c630 c631 c632 c633 c634 c635 c636 c637 c638 c639 c640 c641 c642 c643 c644 c645 c646 c647 c648 c649 c650 c651 c652 c653 c654 c655 c656 c657 c658 c659 c660 c661 c662 c663 c664 c665 c666 c667 c668 c669 c670 c671 c672 c673 c674 c675 c676 c677 c678 c679 c680 c681 c682 c683 c684 c685 c686 c687 c688 c689 c690 c691 c692 c693 c694 c695 c696 c697 c698 c699 c700 c701 c702 c703 c704 c705 c706 c707 c708 c709 c710 c711 c712 c713 c714 c715 c716 c717 c718 c719 c720 c721 c722 c723 c724 c725 c726 c727 c728 c729 c730 c731 c732 c733 c734 c735 c736 c737 c738 c739 c740 c741 c742 c743 c744 c745 c746 c747 c748 c749 c750 c751 c752 c753 c754 c755 c756 c757 c758 c759 c760 c761 c762 c763 c764 c765 c766 c767 c768 c769 c770 c771 c772 c773 c774 c775 c776 c777 c778 c779 c780 c781 c782 c783 c784 c785 c786 c787 c788 c789 c790 c791 c792 c793 c794 c795 c796 c797 c798 c799 c800 c801 c802 c803 c804 c805 c806 c807 c808 c809 c810 c811 c812 c813 c814 c815 c816 c817 c818 c819 c820 c821 c822 c823 c824 c825 c826 c827 c828 c829 c830 c831 c832 c833 c834 c835 c836 c837 c838 c839 c840 c841 c842 c843 c844 c845 c846 c847 c848 c849 c850 c851 c852 c853 c854 c855 c856 c857 c858 c859 c860 c861 c862 c863 c864 c865 c866 c867 c868 c869 c870 c871 c872 c873 c874 c875 c876 c877 c878 c879 c880 c881 c882 c883 c884 c885 c886 c887 c888 c889 c890 c891 c892 c893 c894 c895 c896 c897 c898 c899 c900 c901 c902 c903 c904 c905 c906 c907 c908 c909 c910 c911 c912 c913 c914 c915 c916 c917 c918 c919 c920 c921 c922 c923 c924 c925 c926 c927 c928 c929 c930 c931 c932 c933 c934 c935 c936 c937 c938 c939 c940 c941 c942 c943 c944 c945 c946 c947 c948 c949 c950 c951 c952 c953 c954 c955 c956 c957 c958 c959 c960 c961 c962 c963 c964 c965 c966 c967 c968 c969 c970 c971 c972 c973 c974 c975 c976 c977 c978 c979 c980 c981 c982 c983 c984 c985 c986 c987 c988 c989 c990 c991 c992 c993 c994 c995 c996 c997 c998 c999 c1000 c1001 c1002 c1003 c1004 c1005 c1006 c1007 c1008 c1009 c1010 c1011 c1012 c1013 c1014 c1015 c1016 c1017 c1018 c1019 c1020 c1021 c1022 c1023 ))
5085(sensitivityorder (s0 ))
5086(category c0)
5087(category c1)
5088(category c2)
5089(category c3)
5090(category c4)
5091(category c5)
5092(category c6)
5093(category c7)
5094(category c8)
5095(category c9)
5096(category c10)
5097(category c11)
5098(category c12)
5099(category c13)
5100(category c14)
5101(category c15)
5102(category c16)
5103(category c17)
5104(category c18)
5105(category c19)
5106(category c20)
5107(category c21)
5108(category c22)
5109(category c23)
5110(category c24)
5111(category c25)
5112(category c26)
5113(category c27)
5114(category c28)
5115(category c29)
5116(category c30)
5117(category c31)
5118(category c32)
5119(category c33)
5120(category c34)
5121(category c35)
5122(category c36)
5123(category c37)
5124(category c38)
5125(category c39)
5126(category c40)
5127(category c41)
5128(category c42)
5129(category c43)
5130(category c44)
5131(category c45)
5132(category c46)
5133(category c47)
5134(category c48)
5135(category c49)
5136(category c50)
5137(category c51)
5138(category c52)
5139(category c53)
5140(category c54)
5141(category c55)
5142(category c56)
5143(category c57)
5144(category c58)
5145(category c59)
5146(category c60)
5147(category c61)
5148(category c62)
5149(category c63)
5150(category c64)
5151(category c65)
5152(category c66)
5153(category c67)
5154(category c68)
5155(category c69)
5156(category c70)
5157(category c71)
5158(category c72)
5159(category c73)
5160(category c74)
5161(category c75)
5162(category c76)
5163(category c77)
5164(category c78)
5165(category c79)
5166(category c80)
5167(category c81)
5168(category c82)
5169(category c83)
5170(category c84)
5171(category c85)
5172(category c86)
5173(category c87)
5174(category c88)
5175(category c89)
5176(category c90)
5177(category c91)
5178(category c92)
5179(category c93)
5180(category c94)
5181(category c95)
5182(category c96)
5183(category c97)
5184(category c98)
5185(category c99)
5186(category c100)
5187(category c101)
5188(category c102)
5189(category c103)
5190(category c104)
5191(category c105)
5192(category c106)
5193(category c107)
5194(category c108)
5195(category c109)
5196(category c110)
5197(category c111)
5198(category c112)
5199(category c113)
5200(category c114)
5201(category c115)
5202(category c116)
5203(category c117)
5204(category c118)
5205(category c119)
5206(category c120)
5207(category c121)
5208(category c122)
5209(category c123)
5210(category c124)
5211(category c125)
5212(category c126)
5213(category c127)
5214(category c128)
5215(category c129)
5216(category c130)
5217(category c131)
5218(category c132)
5219(category c133)
5220(category c134)
5221(category c135)
5222(category c136)
5223(category c137)
5224(category c138)
5225(category c139)
5226(category c140)
5227(category c141)
5228(category c142)
5229(category c143)
5230(category c144)
5231(category c145)
5232(category c146)
5233(category c147)
5234(category c148)
5235(category c149)
5236(category c150)
5237(category c151)
5238(category c152)
5239(category c153)
5240(category c154)
5241(category c155)
5242(category c156)
5243(category c157)
5244(category c158)
5245(category c159)
5246(category c160)
5247(category c161)
5248(category c162)
5249(category c163)
5250(category c164)
5251(category c165)
5252(category c166)
5253(category c167)
5254(category c168)
5255(category c169)
5256(category c170)
5257(category c171)
5258(category c172)
5259(category c173)
5260(category c174)
5261(category c175)
5262(category c176)
5263(category c177)
5264(category c178)
5265(category c179)
5266(category c180)
5267(category c181)
5268(category c182)
5269(category c183)
5270(category c184)
5271(category c185)
5272(category c186)
5273(category c187)
5274(category c188)
5275(category c189)
5276(category c190)
5277(category c191)
5278(category c192)
5279(category c193)
5280(category c194)
5281(category c195)
5282(category c196)
5283(category c197)
5284(category c198)
5285(category c199)
5286(category c200)
5287(category c201)
5288(category c202)
5289(category c203)
5290(category c204)
5291(category c205)
5292(category c206)
5293(category c207)
5294(category c208)
5295(category c209)
5296(category c210)
5297(category c211)
5298(category c212)
5299(category c213)
5300(category c214)
5301(category c215)
5302(category c216)
5303(category c217)
5304(category c218)
5305(category c219)
5306(category c220)
5307(category c221)
5308(category c222)
5309(category c223)
5310(category c224)
5311(category c225)
5312(category c226)
5313(category c227)
5314(category c228)
5315(category c229)
5316(category c230)
5317(category c231)
5318(category c232)
5319(category c233)
5320(category c234)
5321(category c235)
5322(category c236)
5323(category c237)
5324(category c238)
5325(category c239)
5326(category c240)
5327(category c241)
5328(category c242)
5329(category c243)
5330(category c244)
5331(category c245)
5332(category c246)
5333(category c247)
5334(category c248)
5335(category c249)
5336(category c250)
5337(category c251)
5338(category c252)
5339(category c253)
5340(category c254)
5341(category c255)
5342(category c256)
5343(category c257)
5344(category c258)
5345(category c259)
5346(category c260)
5347(category c261)
5348(category c262)
5349(category c263)
5350(category c264)
5351(category c265)
5352(category c266)
5353(category c267)
5354(category c268)
5355(category c269)
5356(category c270)
5357(category c271)
5358(category c272)
5359(category c273)
5360(category c274)
5361(category c275)
5362(category c276)
5363(category c277)
5364(category c278)
5365(category c279)
5366(category c280)
5367(category c281)
5368(category c282)
5369(category c283)
5370(category c284)
5371(category c285)
5372(category c286)
5373(category c287)
5374(category c288)
5375(category c289)
5376(category c290)
5377(category c291)
5378(category c292)
5379(category c293)
5380(category c294)
5381(category c295)
5382(category c296)
5383(category c297)
5384(category c298)
5385(category c299)
5386(category c300)
5387(category c301)
5388(category c302)
5389(category c303)
5390(category c304)
5391(category c305)
5392(category c306)
5393(category c307)
5394(category c308)
5395(category c309)
5396(category c310)
5397(category c311)
5398(category c312)
5399(category c313)
5400(category c314)
5401(category c315)
5402(category c316)
5403(category c317)
5404(category c318)
5405(category c319)
5406(category c320)
5407(category c321)
5408(category c322)
5409(category c323)
5410(category c324)
5411(category c325)
5412(category c326)
5413(category c327)
5414(category c328)
5415(category c329)
5416(category c330)
5417(category c331)
5418(category c332)
5419(category c333)
5420(category c334)
5421(category c335)
5422(category c336)
5423(category c337)
5424(category c338)
5425(category c339)
5426(category c340)
5427(category c341)
5428(category c342)
5429(category c343)
5430(category c344)
5431(category c345)
5432(category c346)
5433(category c347)
5434(category c348)
5435(category c349)
5436(category c350)
5437(category c351)
5438(category c352)
5439(category c353)
5440(category c354)
5441(category c355)
5442(category c356)
5443(category c357)
5444(category c358)
5445(category c359)
5446(category c360)
5447(category c361)
5448(category c362)
5449(category c363)
5450(category c364)
5451(category c365)
5452(category c366)
5453(category c367)
5454(category c368)
5455(category c369)
5456(category c370)
5457(category c371)
5458(category c372)
5459(category c373)
5460(category c374)
5461(category c375)
5462(category c376)
5463(category c377)
5464(category c378)
5465(category c379)
5466(category c380)
5467(category c381)
5468(category c382)
5469(category c383)
5470(category c384)
5471(category c385)
5472(category c386)
5473(category c387)
5474(category c388)
5475(category c389)
5476(category c390)
5477(category c391)
5478(category c392)
5479(category c393)
5480(category c394)
5481(category c395)
5482(category c396)
5483(category c397)
5484(category c398)
5485(category c399)
5486(category c400)
5487(category c401)
5488(category c402)
5489(category c403)
5490(category c404)
5491(category c405)
5492(category c406)
5493(category c407)
5494(category c408)
5495(category c409)
5496(category c410)
5497(category c411)
5498(category c412)
5499(category c413)
5500(category c414)
5501(category c415)
5502(category c416)
5503(category c417)
5504(category c418)
5505(category c419)
5506(category c420)
5507(category c421)
5508(category c422)
5509(category c423)
5510(category c424)
5511(category c425)
5512(category c426)
5513(category c427)
5514(category c428)
5515(category c429)
5516(category c430)
5517(category c431)
5518(category c432)
5519(category c433)
5520(category c434)
5521(category c435)
5522(category c436)
5523(category c437)
5524(category c438)
5525(category c439)
5526(category c440)
5527(category c441)
5528(category c442)
5529(category c443)
5530(category c444)
5531(category c445)
5532(category c446)
5533(category c447)
5534(category c448)
5535(category c449)
5536(category c450)
5537(category c451)
5538(category c452)
5539(category c453)
5540(category c454)
5541(category c455)
5542(category c456)
5543(category c457)
5544(category c458)
5545(category c459)
5546(category c460)
5547(category c461)
5548(category c462)
5549(category c463)
5550(category c464)
5551(category c465)
5552(category c466)
5553(category c467)
5554(category c468)
5555(category c469)
5556(category c470)
5557(category c471)
5558(category c472)
5559(category c473)
5560(category c474)
5561(category c475)
5562(category c476)
5563(category c477)
5564(category c478)
5565(category c479)
5566(category c480)
5567(category c481)
5568(category c482)
5569(category c483)
5570(category c484)
5571(category c485)
5572(category c486)
5573(category c487)
5574(category c488)
5575(category c489)
5576(category c490)
5577(category c491)
5578(category c492)
5579(category c493)
5580(category c494)
5581(category c495)
5582(category c496)
5583(category c497)
5584(category c498)
5585(category c499)
5586(category c500)
5587(category c501)
5588(category c502)
5589(category c503)
5590(category c504)
5591(category c505)
5592(category c506)
5593(category c507)
5594(category c508)
5595(category c509)
5596(category c510)
5597(category c511)
5598(category c512)
5599(category c513)
5600(category c514)
5601(category c515)
5602(category c516)
5603(category c517)
5604(category c518)
5605(category c519)
5606(category c520)
5607(category c521)
5608(category c522)
5609(category c523)
5610(category c524)
5611(category c525)
5612(category c526)
5613(category c527)
5614(category c528)
5615(category c529)
5616(category c530)
5617(category c531)
5618(category c532)
5619(category c533)
5620(category c534)
5621(category c535)
5622(category c536)
5623(category c537)
5624(category c538)
5625(category c539)
5626(category c540)
5627(category c541)
5628(category c542)
5629(category c543)
5630(category c544)
5631(category c545)
5632(category c546)
5633(category c547)
5634(category c548)
5635(category c549)
5636(category c550)
5637(category c551)
5638(category c552)
5639(category c553)
5640(category c554)
5641(category c555)
5642(category c556)
5643(category c557)
5644(category c558)
5645(category c559)
5646(category c560)
5647(category c561)
5648(category c562)
5649(category c563)
5650(category c564)
5651(category c565)
5652(category c566)
5653(category c567)
5654(category c568)
5655(category c569)
5656(category c570)
5657(category c571)
5658(category c572)
5659(category c573)
5660(category c574)
5661(category c575)
5662(category c576)
5663(category c577)
5664(category c578)
5665(category c579)
5666(category c580)
5667(category c581)
5668(category c582)
5669(category c583)
5670(category c584)
5671(category c585)
5672(category c586)
5673(category c587)
5674(category c588)
5675(category c589)
5676(category c590)
5677(category c591)
5678(category c592)
5679(category c593)
5680(category c594)
5681(category c595)
5682(category c596)
5683(category c597)
5684(category c598)
5685(category c599)
5686(category c600)
5687(category c601)
5688(category c602)
5689(category c603)
5690(category c604)
5691(category c605)
5692(category c606)
5693(category c607)
5694(category c608)
5695(category c609)
5696(category c610)
5697(category c611)
5698(category c612)
5699(category c613)
5700(category c614)
5701(category c615)
5702(category c616)
5703(category c617)
5704(category c618)
5705(category c619)
5706(category c620)
5707(category c621)
5708(category c622)
5709(category c623)
5710(category c624)
5711(category c625)
5712(category c626)
5713(category c627)
5714(category c628)
5715(category c629)
5716(category c630)
5717(category c631)
5718(category c632)
5719(category c633)
5720(category c634)
5721(category c635)
5722(category c636)
5723(category c637)
5724(category c638)
5725(category c639)
5726(category c640)
5727(category c641)
5728(category c642)
5729(category c643)
5730(category c644)
5731(category c645)
5732(category c646)
5733(category c647)
5734(category c648)
5735(category c649)
5736(category c650)
5737(category c651)
5738(category c652)
5739(category c653)
5740(category c654)
5741(category c655)
5742(category c656)
5743(category c657)
5744(category c658)
5745(category c659)
5746(category c660)
5747(category c661)
5748(category c662)
5749(category c663)
5750(category c664)
5751(category c665)
5752(category c666)
5753(category c667)
5754(category c668)
5755(category c669)
5756(category c670)
5757(category c671)
5758(category c672)
5759(category c673)
5760(category c674)
5761(category c675)
5762(category c676)
5763(category c677)
5764(category c678)
5765(category c679)
5766(category c680)
5767(category c681)
5768(category c682)
5769(category c683)
5770(category c684)
5771(category c685)
5772(category c686)
5773(category c687)
5774(category c688)
5775(category c689)
5776(category c690)
5777(category c691)
5778(category c692)
5779(category c693)
5780(category c694)
5781(category c695)
5782(category c696)
5783(category c697)
5784(category c698)
5785(category c699)
5786(category c700)
5787(category c701)
5788(category c702)
5789(category c703)
5790(category c704)
5791(category c705)
5792(category c706)
5793(category c707)
5794(category c708)
5795(category c709)
5796(category c710)
5797(category c711)
5798(category c712)
5799(category c713)
5800(category c714)
5801(category c715)
5802(category c716)
5803(category c717)
5804(category c718)
5805(category c719)
5806(category c720)
5807(category c721)
5808(category c722)
5809(category c723)
5810(category c724)
5811(category c725)
5812(category c726)
5813(category c727)
5814(category c728)
5815(category c729)
5816(category c730)
5817(category c731)
5818(category c732)
5819(category c733)
5820(category c734)
5821(category c735)
5822(category c736)
5823(category c737)
5824(category c738)
5825(category c739)
5826(category c740)
5827(category c741)
5828(category c742)
5829(category c743)
5830(category c744)
5831(category c745)
5832(category c746)
5833(category c747)
5834(category c748)
5835(category c749)
5836(category c750)
5837(category c751)
5838(category c752)
5839(category c753)
5840(category c754)
5841(category c755)
5842(category c756)
5843(category c757)
5844(category c758)
5845(category c759)
5846(category c760)
5847(category c761)
5848(category c762)
5849(category c763)
5850(category c764)
5851(category c765)
5852(category c766)
5853(category c767)
5854(category c768)
5855(category c769)
5856(category c770)
5857(category c771)
5858(category c772)
5859(category c773)
5860(category c774)
5861(category c775)
5862(category c776)
5863(category c777)
5864(category c778)
5865(category c779)
5866(category c780)
5867(category c781)
5868(category c782)
5869(category c783)
5870(category c784)
5871(category c785)
5872(category c786)
5873(category c787)
5874(category c788)
5875(category c789)
5876(category c790)
5877(category c791)
5878(category c792)
5879(category c793)
5880(category c794)
5881(category c795)
5882(category c796)
5883(category c797)
5884(category c798)
5885(category c799)
5886(category c800)
5887(category c801)
5888(category c802)
5889(category c803)
5890(category c804)
5891(category c805)
5892(category c806)
5893(category c807)
5894(category c808)
5895(category c809)
5896(category c810)
5897(category c811)
5898(category c812)
5899(category c813)
5900(category c814)
5901(category c815)
5902(category c816)
5903(category c817)
5904(category c818)
5905(category c819)
5906(category c820)
5907(category c821)
5908(category c822)
5909(category c823)
5910(category c824)
5911(category c825)
5912(category c826)
5913(category c827)
5914(category c828)
5915(category c829)
5916(category c830)
5917(category c831)
5918(category c832)
5919(category c833)
5920(category c834)
5921(category c835)
5922(category c836)
5923(category c837)
5924(category c838)
5925(category c839)
5926(category c840)
5927(category c841)
5928(category c842)
5929(category c843)
5930(category c844)
5931(category c845)
5932(category c846)
5933(category c847)
5934(category c848)
5935(category c849)
5936(category c850)
5937(category c851)
5938(category c852)
5939(category c853)
5940(category c854)
5941(category c855)
5942(category c856)
5943(category c857)
5944(category c858)
5945(category c859)
5946(category c860)
5947(category c861)
5948(category c862)
5949(category c863)
5950(category c864)
5951(category c865)
5952(category c866)
5953(category c867)
5954(category c868)
5955(category c869)
5956(category c870)
5957(category c871)
5958(category c872)
5959(category c873)
5960(category c874)
5961(category c875)
5962(category c876)
5963(category c877)
5964(category c878)
5965(category c879)
5966(category c880)
5967(category c881)
5968(category c882)
5969(category c883)
5970(category c884)
5971(category c885)
5972(category c886)
5973(category c887)
5974(category c888)
5975(category c889)
5976(category c890)
5977(category c891)
5978(category c892)
5979(category c893)
5980(category c894)
5981(category c895)
5982(category c896)
5983(category c897)
5984(category c898)
5985(category c899)
5986(category c900)
5987(category c901)
5988(category c902)
5989(category c903)
5990(category c904)
5991(category c905)
5992(category c906)
5993(category c907)
5994(category c908)
5995(category c909)
5996(category c910)
5997(category c911)
5998(category c912)
5999(category c913)
6000(category c914)
6001(category c915)
6002(category c916)
6003(category c917)
6004(category c918)
6005(category c919)
6006(category c920)
6007(category c921)
6008(category c922)
6009(category c923)
6010(category c924)
6011(category c925)
6012(category c926)
6013(category c927)
6014(category c928)
6015(category c929)
6016(category c930)
6017(category c931)
6018(category c932)
6019(category c933)
6020(category c934)
6021(category c935)
6022(category c936)
6023(category c937)
6024(category c938)
6025(category c939)
6026(category c940)
6027(category c941)
6028(category c942)
6029(category c943)
6030(category c944)
6031(category c945)
6032(category c946)
6033(category c947)
6034(category c948)
6035(category c949)
6036(category c950)
6037(category c951)
6038(category c952)
6039(category c953)
6040(category c954)
6041(category c955)
6042(category c956)
6043(category c957)
6044(category c958)
6045(category c959)
6046(category c960)
6047(category c961)
6048(category c962)
6049(category c963)
6050(category c964)
6051(category c965)
6052(category c966)
6053(category c967)
6054(category c968)
6055(category c969)
6056(category c970)
6057(category c971)
6058(category c972)
6059(category c973)
6060(category c974)
6061(category c975)
6062(category c976)
6063(category c977)
6064(category c978)
6065(category c979)
6066(category c980)
6067(category c981)
6068(category c982)
6069(category c983)
6070(category c984)
6071(category c985)
6072(category c986)
6073(category c987)
6074(category c988)
6075(category c989)
6076(category c990)
6077(category c991)
6078(category c992)
6079(category c993)
6080(category c994)
6081(category c995)
6082(category c996)
6083(category c997)
6084(category c998)
6085(category c999)
6086(category c1000)
6087(category c1001)
6088(category c1002)
6089(category c1003)
6090(category c1004)
6091(category c1005)
6092(category c1006)
6093(category c1007)
6094(category c1008)
6095(category c1009)
6096(category c1010)
6097(category c1011)
6098(category c1012)
6099(category c1013)
6100(category c1014)
6101(category c1015)
6102(category c1016)
6103(category c1017)
6104(category c1018)
6105(category c1019)
6106(category c1020)
6107(category c1021)
6108(category c1022)
6109(category c1023)
6110(categoryorder (c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 c10 c11 c12 c13 c14 c15 c16 c17 c18 c19 c20 c21 c22 c23 c24 c25 c26 c27 c28 c29 c30 c31 c32 c33 c34 c35 c36 c37 c38 c39 c40 c41 c42 c43 c44 c45 c46 c47 c48 c49 c50 c51 c52 c53 c54 c55 c56 c57 c58 c59 c60 c61 c62 c63 c64 c65 c66 c67 c68 c69 c70 c71 c72 c73 c74 c75 c76 c77 c78 c79 c80 c81 c82 c83 c84 c85 c86 c87 c88 c89 c90 c91 c92 c93 c94 c95 c96 c97 c98 c99 c100 c101 c102 c103 c104 c105 c106 c107 c108 c109 c110 c111 c112 c113 c114 c115 c116 c117 c118 c119 c120 c121 c122 c123 c124 c125 c126 c127 c128 c129 c130 c131 c132 c133 c134 c135 c136 c137 c138 c139 c140 c141 c142 c143 c144 c145 c146 c147 c148 c149 c150 c151 c152 c153 c154 c155 c156 c157 c158 c159 c160 c161 c162 c163 c164 c165 c166 c167 c168 c169 c170 c171 c172 c173 c174 c175 c176 c177 c178 c179 c180 c181 c182 c183 c184 c185 c186 c187 c188 c189 c190 c191 c192 c193 c194 c195 c196 c197 c198 c199 c200 c201 c202 c203 c204 c205 c206 c207 c208 c209 c210 c211 c212 c213 c214 c215 c216 c217 c218 c219 c220 c221 c222 c223 c224 c225 c226 c227 c228 c229 c230 c231 c232 c233 c234 c235 c236 c237 c238 c239 c240 c241 c242 c243 c244 c245 c246 c247 c248 c249 c250 c251 c252 c253 c254 c255 c256 c257 c258 c259 c260 c261 c262 c263 c264 c265 c266 c267 c268 c269 c270 c271 c272 c273 c274 c275 c276 c277 c278 c279 c280 c281 c282 c283 c284 c285 c286 c287 c288 c289 c290 c291 c292 c293 c294 c295 c296 c297 c298 c299 c300 c301 c302 c303 c304 c305 c306 c307 c308 c309 c310 c311 c312 c313 c314 c315 c316 c317 c318 c319 c320 c321 c322 c323 c324 c325 c326 c327 c328 c329 c330 c331 c332 c333 c334 c335 c336 c337 c338 c339 c340 c341 c342 c343 c344 c345 c346 c347 c348 c349 c350 c351 c352 c353 c354 c355 c356 c357 c358 c359 c360 c361 c362 c363 c364 c365 c366 c367 c368 c369 c370 c371 c372 c373 c374 c375 c376 c377 c378 c379 c380 c381 c382 c383 c384 c385 c386 c387 c388 c389 c390 c391 c392 c393 c394 c395 c396 c397 c398 c399 c400 c401 c402 c403 c404 c405 c406 c407 c408 c409 c410 c411 c412 c413 c414 c415 c416 c417 c418 c419 c420 c421 c422 c423 c424 c425 c426 c427 c428 c429 c430 c431 c432 c433 c434 c435 c436 c437 c438 c439 c440 c441 c442 c443 c444 c445 c446 c447 c448 c449 c450 c451 c452 c453 c454 c455 c456 c457 c458 c459 c460 c461 c462 c463 c464 c465 c466 c467 c468 c469 c470 c471 c472 c473 c474 c475 c476 c477 c478 c479 c480 c481 c482 c483 c484 c485 c486 c487 c488 c489 c490 c491 c492 c493 c494 c495 c496 c497 c498 c499 c500 c501 c502 c503 c504 c505 c506 c507 c508 c509 c510 c511 c512 c513 c514 c515 c516 c517 c518 c519 c520 c521 c522 c523 c524 c525 c526 c527 c528 c529 c530 c531 c532 c533 c534 c535 c536 c537 c538 c539 c540 c541 c542 c543 c544 c545 c546 c547 c548 c549 c550 c551 c552 c553 c554 c555 c556 c557 c558 c559 c560 c561 c562 c563 c564 c565 c566 c567 c568 c569 c570 c571 c572 c573 c574 c575 c576 c577 c578 c579 c580 c581 c582 c583 c584 c585 c586 c587 c588 c589 c590 c591 c592 c593 c594 c595 c596 c597 c598 c599 c600 c601 c602 c603 c604 c605 c606 c607 c608 c609 c610 c611 c612 c613 c614 c615 c616 c617 c618 c619 c620 c621 c622 c623 c624 c625 c626 c627 c628 c629 c630 c631 c632 c633 c634 c635 c636 c637 c638 c639 c640 c641 c642 c643 c644 c645 c646 c647 c648 c649 c650 c651 c652 c653 c654 c655 c656 c657 c658 c659 c660 c661 c662 c663 c664 c665 c666 c667 c668 c669 c670 c671 c672 c673 c674 c675 c676 c677 c678 c679 c680 c681 c682 c683 c684 c685 c686 c687 c688 c689 c690 c691 c692 c693 c694 c695 c696 c697 c698 c699 c700 c701 c702 c703 c704 c705 c706 c707 c708 c709 c710 c711 c712 c713 c714 c715 c716 c717 c718 c719 c720 c721 c722 c723 c724 c725 c726 c727 c728 c729 c730 c731 c732 c733 c734 c735 c736 c737 c738 c739 c740 c741 c742 c743 c744 c745 c746 c747 c748 c749 c750 c751 c752 c753 c754 c755 c756 c757 c758 c759 c760 c761 c762 c763 c764 c765 c766 c767 c768 c769 c770 c771 c772 c773 c774 c775 c776 c777 c778 c779 c780 c781 c782 c783 c784 c785 c786 c787 c788 c789 c790 c791 c792 c793 c794 c795 c796 c797 c798 c799 c800 c801 c802 c803 c804 c805 c806 c807 c808 c809 c810 c811 c812 c813 c814 c815 c816 c817 c818 c819 c820 c821 c822 c823 c824 c825 c826 c827 c828 c829 c830 c831 c832 c833 c834 c835 c836 c837 c838 c839 c840 c841 c842 c843 c844 c845 c846 c847 c848 c849 c850 c851 c852 c853 c854 c855 c856 c857 c858 c859 c860 c861 c862 c863 c864 c865 c866 c867 c868 c869 c870 c871 c872 c873 c874 c875 c876 c877 c878 c879 c880 c881 c882 c883 c884 c885 c886 c887 c888 c889 c890 c891 c892 c893 c894 c895 c896 c897 c898 c899 c900 c901 c902 c903 c904 c905 c906 c907 c908 c909 c910 c911 c912 c913 c914 c915 c916 c917 c918 c919 c920 c921 c922 c923 c924 c925 c926 c927 c928 c929 c930 c931 c932 c933 c934 c935 c936 c937 c938 c939 c940 c941 c942 c943 c944 c945 c946 c947 c948 c949 c950 c951 c952 c953 c954 c955 c956 c957 c958 c959 c960 c961 c962 c963 c964 c965 c966 c967 c968 c969 c970 c971 c972 c973 c974 c975 c976 c977 c978 c979 c980 c981 c982 c983 c984 c985 c986 c987 c988 c989 c990 c991 c992 c993 c994 c995 c996 c997 c998 c999 c1000 c1001 c1002 c1003 c1004 c1005 c1006 c1007 c1008 c1009 c1010 c1011 c1012 c1013 c1014 c1015 c1016 c1017 c1018 c1019 c1020 c1021 c1022 c1023 ))
6111;;* lmx 330 system/sepolicy/public/attributes
6112
6113(neverallow base_typeattr_1 domain (process (fork)))
6114;;* lme
6115
6116;;* lmx 330 system/sepolicy/public/attributes
6117
6118(neverallow base_typeattr_2 domain (process (fork)))
6119;;* lme
6120
6121;;* lmx 330 system/sepolicy/public/attributes
6122
6123(neverallow base_typeattr_3 domain (process (fork)))
6124;;* lme
6125
6126;;* lmx 331 system/sepolicy/public/attributes
6127
6128(neverallow base_typeattr_4 domain (process (fork)))
6129;;* lme
6130
6131;;* lmx 331 system/sepolicy/public/attributes
6132
6133(neverallow base_typeattr_5 domain (process (fork)))
6134;;* lme
6135
6136;;* lmx 331 system/sepolicy/public/attributes
6137
6138(neverallow base_typeattr_6 domain (process (fork)))
6139;;* lme
6140
6141;;* lmx 332 system/sepolicy/public/attributes
6142
6143(neverallow base_typeattr_7 domain (process (fork)))
6144;;* lme
6145
6146;;* lmx 332 system/sepolicy/public/attributes
6147
6148(neverallow base_typeattr_8 domain (process (fork)))
6149;;* lme
6150
6151;;* lmx 332 system/sepolicy/public/attributes
6152
6153(neverallow base_typeattr_9 domain (process (fork)))
6154;;* lme
6155
6156;;* lmx 333 system/sepolicy/public/attributes
6157
6158(neverallow base_typeattr_10 domain (process (fork)))
6159;;* lme
6160
6161;;* lmx 333 system/sepolicy/public/attributes
6162
6163(neverallow base_typeattr_11 domain (process (fork)))
6164;;* lme
6165
6166;;* lmx 333 system/sepolicy/public/attributes
6167
6168(neverallow base_typeattr_12 domain (process (fork)))
6169;;* lme
6170
6171;;* lmx 334 system/sepolicy/public/attributes
6172
6173(neverallow base_typeattr_13 domain (process (fork)))
6174;;* lme
6175
6176;;* lmx 334 system/sepolicy/public/attributes
6177
6178(neverallow base_typeattr_14 domain (process (fork)))
6179;;* lme
6180
6181;;* lmx 334 system/sepolicy/public/attributes
6182
6183(neverallow base_typeattr_15 domain (process (fork)))
6184;;* lme
6185
6186;;* lmx 335 system/sepolicy/public/attributes
6187
6188(neverallow base_typeattr_16 domain (process (fork)))
6189;;* lme
6190
6191;;* lmx 335 system/sepolicy/public/attributes
6192
6193(neverallow base_typeattr_17 domain (process (fork)))
6194;;* lme
6195
6196;;* lmx 335 system/sepolicy/public/attributes
6197
6198(neverallow base_typeattr_18 domain (process (fork)))
6199;;* lme
6200
6201;;* lmx 336 system/sepolicy/public/attributes
6202
6203(neverallow base_typeattr_19 domain (process (fork)))
6204;;* lme
6205
6206;;* lmx 336 system/sepolicy/public/attributes
6207
6208(neverallow base_typeattr_20 domain (process (fork)))
6209;;* lme
6210
6211;;* lmx 336 system/sepolicy/public/attributes
6212
6213(neverallow base_typeattr_21 domain (process (fork)))
6214;;* lme
6215
6216;;* lmx 337 system/sepolicy/public/attributes
6217
6218(neverallow base_typeattr_22 domain (process (fork)))
6219;;* lme
6220
6221;;* lmx 337 system/sepolicy/public/attributes
6222
6223(neverallow base_typeattr_23 domain (process (fork)))
6224;;* lme
6225
6226;;* lmx 337 system/sepolicy/public/attributes
6227
6228(neverallow base_typeattr_24 domain (process (fork)))
6229;;* lme
6230
6231;;* lmx 338 system/sepolicy/public/attributes
6232
6233(neverallow base_typeattr_25 domain (process (fork)))
6234;;* lme
6235
6236;;* lmx 338 system/sepolicy/public/attributes
6237
6238(neverallow base_typeattr_26 domain (process (fork)))
6239;;* lme
6240
6241;;* lmx 338 system/sepolicy/public/attributes
6242
6243(neverallow base_typeattr_27 domain (process (fork)))
6244;;* lme
6245
6246;;* lmx 339 system/sepolicy/public/attributes
6247
6248(neverallow base_typeattr_28 domain (process (fork)))
6249;;* lme
6250
6251;;* lmx 339 system/sepolicy/public/attributes
6252
6253(neverallow base_typeattr_29 domain (process (fork)))
6254;;* lme
6255
6256;;* lmx 339 system/sepolicy/public/attributes
6257
6258(neverallow base_typeattr_30 domain (process (fork)))
6259;;* lme
6260
6261;;* lmx 340 system/sepolicy/public/attributes
6262
6263(neverallow base_typeattr_31 domain (process (fork)))
6264;;* lme
6265
6266;;* lmx 340 system/sepolicy/public/attributes
6267
6268(neverallow base_typeattr_32 domain (process (fork)))
6269;;* lme
6270
6271;;* lmx 340 system/sepolicy/public/attributes
6272
6273(neverallow base_typeattr_33 domain (process (fork)))
6274;;* lme
6275
6276;;* lmx 341 system/sepolicy/public/attributes
6277
6278(neverallow base_typeattr_34 domain (process (fork)))
6279;;* lme
6280
6281;;* lmx 341 system/sepolicy/public/attributes
6282
6283(neverallow base_typeattr_35 domain (process (fork)))
6284;;* lme
6285
6286;;* lmx 341 system/sepolicy/public/attributes
6287
6288(neverallow base_typeattr_36 domain (process (fork)))
6289;;* lme
6290
6291;;* lmx 342 system/sepolicy/public/attributes
6292
6293(neverallow base_typeattr_37 domain (process (fork)))
6294;;* lme
6295
6296;;* lmx 342 system/sepolicy/public/attributes
6297
6298(neverallow base_typeattr_38 domain (process (fork)))
6299;;* lme
6300
6301;;* lmx 342 system/sepolicy/public/attributes
6302
6303(neverallow base_typeattr_39 domain (process (fork)))
6304;;* lme
6305
6306;;* lmx 343 system/sepolicy/public/attributes
6307
6308(neverallow base_typeattr_40 domain (process (fork)))
6309;;* lme
6310
6311;;* lmx 343 system/sepolicy/public/attributes
6312
6313(neverallow base_typeattr_41 domain (process (fork)))
6314;;* lme
6315
6316;;* lmx 343 system/sepolicy/public/attributes
6317
6318(neverallow base_typeattr_42 domain (process (fork)))
6319;;* lme
6320
6321;;* lmx 344 system/sepolicy/public/attributes
6322
6323(neverallow base_typeattr_43 domain (process (fork)))
6324;;* lme
6325
6326;;* lmx 344 system/sepolicy/public/attributes
6327
6328(neverallow base_typeattr_44 domain (process (fork)))
6329;;* lme
6330
6331;;* lmx 344 system/sepolicy/public/attributes
6332
6333(neverallow base_typeattr_45 domain (process (fork)))
6334;;* lme
6335
6336;;* lmx 345 system/sepolicy/public/attributes
6337
6338(neverallow base_typeattr_46 domain (process (fork)))
6339;;* lme
6340
6341;;* lmx 345 system/sepolicy/public/attributes
6342
6343(neverallow base_typeattr_47 domain (process (fork)))
6344;;* lme
6345
6346;;* lmx 345 system/sepolicy/public/attributes
6347
6348(neverallow base_typeattr_48 domain (process (fork)))
6349;;* lme
6350
6351;;* lmx 346 system/sepolicy/public/attributes
6352
6353(neverallow base_typeattr_49 domain (process (fork)))
6354;;* lme
6355
6356;;* lmx 346 system/sepolicy/public/attributes
6357
6358(neverallow base_typeattr_50 domain (process (fork)))
6359;;* lme
6360
6361;;* lmx 346 system/sepolicy/public/attributes
6362
6363(neverallow base_typeattr_51 domain (process (fork)))
6364;;* lme
6365
6366;;* lmx 347 system/sepolicy/public/attributes
6367
6368(neverallow base_typeattr_52 domain (process (fork)))
6369;;* lme
6370
6371;;* lmx 347 system/sepolicy/public/attributes
6372
6373(neverallow base_typeattr_53 domain (process (fork)))
6374;;* lme
6375
6376;;* lmx 347 system/sepolicy/public/attributes
6377
6378(neverallow base_typeattr_54 domain (process (fork)))
6379;;* lme
6380
6381;;* lmx 348 system/sepolicy/public/attributes
6382
6383(neverallow base_typeattr_55 domain (process (fork)))
6384;;* lme
6385
6386;;* lmx 348 system/sepolicy/public/attributes
6387
6388(neverallow base_typeattr_56 domain (process (fork)))
6389;;* lme
6390
6391;;* lmx 348 system/sepolicy/public/attributes
6392
6393(neverallow base_typeattr_57 domain (process (fork)))
6394;;* lme
6395
6396;;* lmx 349 system/sepolicy/public/attributes
6397
6398(neverallow base_typeattr_58 domain (process (fork)))
6399;;* lme
6400
6401;;* lmx 349 system/sepolicy/public/attributes
6402
6403(neverallow base_typeattr_59 domain (process (fork)))
6404;;* lme
6405
6406;;* lmx 349 system/sepolicy/public/attributes
6407
6408(neverallow base_typeattr_60 domain (process (fork)))
6409;;* lme
6410
6411;;* lmx 350 system/sepolicy/public/attributes
6412
6413(neverallow base_typeattr_61 domain (process (fork)))
6414;;* lme
6415
6416;;* lmx 350 system/sepolicy/public/attributes
6417
6418(neverallow base_typeattr_62 domain (process (fork)))
6419;;* lme
6420
6421;;* lmx 350 system/sepolicy/public/attributes
6422
6423(neverallow base_typeattr_63 domain (process (fork)))
6424;;* lme
6425
6426;;* lmx 351 system/sepolicy/public/attributes
6427
6428(neverallow base_typeattr_64 domain (process (fork)))
6429;;* lme
6430
6431;;* lmx 351 system/sepolicy/public/attributes
6432
6433(neverallow base_typeattr_65 domain (process (fork)))
6434;;* lme
6435
6436;;* lmx 351 system/sepolicy/public/attributes
6437
6438(neverallow base_typeattr_66 domain (process (fork)))
6439;;* lme
6440
6441;;* lmx 352 system/sepolicy/public/attributes
6442
6443(neverallow base_typeattr_67 domain (process (fork)))
6444;;* lme
6445
6446;;* lmx 352 system/sepolicy/public/attributes
6447
6448(neverallow base_typeattr_68 domain (process (fork)))
6449;;* lme
6450
6451;;* lmx 352 system/sepolicy/public/attributes
6452
6453(neverallow base_typeattr_69 domain (process (fork)))
6454;;* lme
6455
6456;;* lmx 353 system/sepolicy/public/attributes
6457
6458(neverallow base_typeattr_70 domain (process (fork)))
6459;;* lme
6460
6461;;* lmx 353 system/sepolicy/public/attributes
6462
6463(neverallow base_typeattr_71 domain (process (fork)))
6464;;* lme
6465
6466;;* lmx 353 system/sepolicy/public/attributes
6467
6468(neverallow base_typeattr_72 domain (process (fork)))
6469;;* lme
6470
6471;;* lmx 354 system/sepolicy/public/attributes
6472
6473(neverallow base_typeattr_73 domain (process (fork)))
6474;;* lme
6475
6476;;* lmx 354 system/sepolicy/public/attributes
6477
6478(neverallow base_typeattr_74 domain (process (fork)))
6479;;* lme
6480
6481;;* lmx 354 system/sepolicy/public/attributes
6482
6483(neverallow base_typeattr_75 domain (process (fork)))
6484;;* lme
6485
6486;;* lmx 355 system/sepolicy/public/attributes
6487
6488(neverallow base_typeattr_76 domain (process (fork)))
6489;;* lme
6490
6491;;* lmx 355 system/sepolicy/public/attributes
6492
6493(neverallow base_typeattr_77 domain (process (fork)))
6494;;* lme
6495
6496;;* lmx 355 system/sepolicy/public/attributes
6497
6498(neverallow base_typeattr_78 domain (process (fork)))
6499;;* lme
6500
6501;;* lmx 356 system/sepolicy/public/attributes
6502
6503(neverallow base_typeattr_79 domain (process (fork)))
6504;;* lme
6505
6506;;* lmx 356 system/sepolicy/public/attributes
6507
6508(neverallow base_typeattr_80 domain (process (fork)))
6509;;* lme
6510
6511;;* lmx 356 system/sepolicy/public/attributes
6512
6513(neverallow base_typeattr_81 domain (process (fork)))
6514;;* lme
6515
6516;;* lmx 357 system/sepolicy/public/attributes
6517
6518(neverallow base_typeattr_82 domain (process (fork)))
6519;;* lme
6520
6521;;* lmx 357 system/sepolicy/public/attributes
6522
6523(neverallow base_typeattr_83 domain (process (fork)))
6524;;* lme
6525
6526;;* lmx 357 system/sepolicy/public/attributes
6527
6528(neverallow base_typeattr_84 domain (process (fork)))
6529;;* lme
6530
6531;;* lmx 358 system/sepolicy/public/attributes
6532
6533(neverallow base_typeattr_85 domain (process (fork)))
6534;;* lme
6535
6536;;* lmx 358 system/sepolicy/public/attributes
6537
6538(neverallow base_typeattr_86 domain (process (fork)))
6539;;* lme
6540
6541;;* lmx 358 system/sepolicy/public/attributes
6542
6543(neverallow base_typeattr_87 domain (process (fork)))
6544;;* lme
6545
6546;;* lmx 359 system/sepolicy/public/attributes
6547
6548(neverallow base_typeattr_88 domain (process (fork)))
6549;;* lme
6550
6551;;* lmx 359 system/sepolicy/public/attributes
6552
6553(neverallow base_typeattr_89 domain (process (fork)))
6554;;* lme
6555
6556;;* lmx 359 system/sepolicy/public/attributes
6557
6558(neverallow base_typeattr_90 domain (process (fork)))
6559;;* lme
6560
6561;;* lmx 360 system/sepolicy/public/attributes
6562
6563(neverallow base_typeattr_91 domain (process (fork)))
6564;;* lme
6565
6566;;* lmx 360 system/sepolicy/public/attributes
6567
6568(neverallow base_typeattr_92 domain (process (fork)))
6569;;* lme
6570
6571;;* lmx 360 system/sepolicy/public/attributes
6572
6573(neverallow base_typeattr_93 domain (process (fork)))
6574;;* lme
6575
6576;;* lmx 361 system/sepolicy/public/attributes
6577
6578(neverallow base_typeattr_94 domain (process (fork)))
6579;;* lme
6580
6581;;* lmx 361 system/sepolicy/public/attributes
6582
6583(neverallow base_typeattr_95 domain (process (fork)))
6584;;* lme
6585
6586;;* lmx 361 system/sepolicy/public/attributes
6587
6588(neverallow base_typeattr_96 domain (process (fork)))
6589;;* lme
6590
6591;;* lmx 362 system/sepolicy/public/attributes
6592
6593(neverallow base_typeattr_97 domain (process (fork)))
6594;;* lme
6595
6596;;* lmx 362 system/sepolicy/public/attributes
6597
6598(neverallow base_typeattr_98 domain (process (fork)))
6599;;* lme
6600
6601;;* lmx 362 system/sepolicy/public/attributes
6602
6603(neverallow base_typeattr_99 domain (process (fork)))
6604;;* lme
6605
6606;;* lmx 363 system/sepolicy/public/attributes
6607
6608(neverallow base_typeattr_100 domain (process (fork)))
6609;;* lme
6610
6611;;* lmx 363 system/sepolicy/public/attributes
6612
6613(neverallow base_typeattr_101 domain (process (fork)))
6614;;* lme
6615
6616;;* lmx 363 system/sepolicy/public/attributes
6617
6618(neverallow base_typeattr_102 domain (process (fork)))
6619;;* lme
6620
6621;;* lmx 364 system/sepolicy/public/attributes
6622
6623(neverallow base_typeattr_103 domain (process (fork)))
6624;;* lme
6625
6626;;* lmx 364 system/sepolicy/public/attributes
6627
6628(neverallow base_typeattr_104 domain (process (fork)))
6629;;* lme
6630
6631;;* lmx 364 system/sepolicy/public/attributes
6632
6633(neverallow base_typeattr_105 domain (process (fork)))
6634;;* lme
6635
6636;;* lmx 365 system/sepolicy/public/attributes
6637
6638(neverallow base_typeattr_106 domain (process (fork)))
6639;;* lme
6640
6641;;* lmx 365 system/sepolicy/public/attributes
6642
6643(neverallow base_typeattr_107 domain (process (fork)))
6644;;* lme
6645
6646;;* lmx 365 system/sepolicy/public/attributes
6647
6648(neverallow base_typeattr_108 domain (process (fork)))
6649;;* lme
6650
6651;;* lmx 366 system/sepolicy/public/attributes
6652
6653(neverallow base_typeattr_109 domain (process (fork)))
6654;;* lme
6655
6656;;* lmx 366 system/sepolicy/public/attributes
6657
6658(neverallow base_typeattr_110 domain (process (fork)))
6659;;* lme
6660
6661;;* lmx 366 system/sepolicy/public/attributes
6662
6663(neverallow base_typeattr_111 domain (process (fork)))
6664;;* lme
6665
6666;;* lmx 367 system/sepolicy/public/attributes
6667
6668(neverallow base_typeattr_112 domain (process (fork)))
6669;;* lme
6670
6671;;* lmx 367 system/sepolicy/public/attributes
6672
6673(neverallow base_typeattr_113 domain (process (fork)))
6674;;* lme
6675
6676;;* lmx 367 system/sepolicy/public/attributes
6677
6678(neverallow base_typeattr_114 domain (process (fork)))
6679;;* lme
6680
6681;;* lmx 368 system/sepolicy/public/attributes
6682
6683(neverallow base_typeattr_115 domain (process (fork)))
6684;;* lme
6685
6686;;* lmx 368 system/sepolicy/public/attributes
6687
6688(neverallow base_typeattr_116 domain (process (fork)))
6689;;* lme
6690
6691;;* lmx 368 system/sepolicy/public/attributes
6692
6693(neverallow base_typeattr_117 domain (process (fork)))
6694;;* lme
6695
6696;;* lmx 369 system/sepolicy/public/attributes
6697
6698(neverallow base_typeattr_118 domain (process (fork)))
6699;;* lme
6700
6701;;* lmx 369 system/sepolicy/public/attributes
6702
6703(neverallow base_typeattr_119 domain (process (fork)))
6704;;* lme
6705
6706;;* lmx 369 system/sepolicy/public/attributes
6707
6708(neverallow base_typeattr_120 domain (process (fork)))
6709;;* lme
6710
6711;;* lmx 370 system/sepolicy/public/attributes
6712
6713(neverallow base_typeattr_121 domain (process (fork)))
6714;;* lme
6715
6716;;* lmx 370 system/sepolicy/public/attributes
6717
6718(neverallow base_typeattr_122 domain (process (fork)))
6719;;* lme
6720
6721;;* lmx 370 system/sepolicy/public/attributes
6722
6723(neverallow base_typeattr_123 domain (process (fork)))
6724;;* lme
6725
6726;;* lmx 371 system/sepolicy/public/attributes
6727
6728(neverallow base_typeattr_124 domain (process (fork)))
6729;;* lme
6730
6731;;* lmx 371 system/sepolicy/public/attributes
6732
6733(neverallow base_typeattr_125 domain (process (fork)))
6734;;* lme
6735
6736;;* lmx 371 system/sepolicy/public/attributes
6737
6738(neverallow base_typeattr_126 domain (process (fork)))
6739;;* lme
6740
6741;;* lmx 372 system/sepolicy/public/attributes
6742
6743(neverallow base_typeattr_127 domain (process (fork)))
6744;;* lme
6745
6746;;* lmx 372 system/sepolicy/public/attributes
6747
6748(neverallow base_typeattr_128 domain (process (fork)))
6749;;* lme
6750
6751;;* lmx 372 system/sepolicy/public/attributes
6752
6753(neverallow base_typeattr_129 domain (process (fork)))
6754;;* lme
6755
6756;;* lmx 373 system/sepolicy/public/attributes
6757
6758(neverallow base_typeattr_130 domain (process (fork)))
6759;;* lme
6760
6761;;* lmx 373 system/sepolicy/public/attributes
6762
6763(neverallow base_typeattr_131 domain (process (fork)))
6764;;* lme
6765
6766;;* lmx 373 system/sepolicy/public/attributes
6767
6768(neverallow base_typeattr_132 domain (process (fork)))
6769;;* lme
6770
6771;;* lmx 374 system/sepolicy/public/attributes
6772
6773(neverallow base_typeattr_133 domain (process (fork)))
6774;;* lme
6775
6776;;* lmx 374 system/sepolicy/public/attributes
6777
6778(neverallow base_typeattr_134 domain (process (fork)))
6779;;* lme
6780
6781;;* lmx 374 system/sepolicy/public/attributes
6782
6783(neverallow base_typeattr_135 domain (process (fork)))
6784;;* lme
6785
6786;;* lmx 375 system/sepolicy/public/attributes
6787
6788(neverallow base_typeattr_136 domain (process (fork)))
6789;;* lme
6790
6791;;* lmx 375 system/sepolicy/public/attributes
6792
6793(neverallow base_typeattr_137 domain (process (fork)))
6794;;* lme
6795
6796;;* lmx 375 system/sepolicy/public/attributes
6797
6798(neverallow base_typeattr_138 domain (process (fork)))
6799;;* lme
6800
6801;;* lmx 376 system/sepolicy/public/attributes
6802
6803(neverallow base_typeattr_139 domain (process (fork)))
6804;;* lme
6805
6806;;* lmx 376 system/sepolicy/public/attributes
6807
6808(neverallow base_typeattr_140 domain (process (fork)))
6809;;* lme
6810
6811;;* lmx 376 system/sepolicy/public/attributes
6812
6813(neverallow base_typeattr_141 domain (process (fork)))
6814;;* lme
6815
6816;;* lmx 377 system/sepolicy/public/attributes
6817
6818(neverallow base_typeattr_142 domain (process (fork)))
6819;;* lme
6820
6821;;* lmx 377 system/sepolicy/public/attributes
6822
6823(neverallow base_typeattr_143 domain (process (fork)))
6824;;* lme
6825
6826;;* lmx 377 system/sepolicy/public/attributes
6827
6828(neverallow base_typeattr_144 domain (process (fork)))
6829;;* lme
6830
6831;;* lmx 378 system/sepolicy/public/attributes
6832
6833(neverallow base_typeattr_145 domain (process (fork)))
6834;;* lme
6835
6836;;* lmx 378 system/sepolicy/public/attributes
6837
6838(neverallow base_typeattr_146 domain (process (fork)))
6839;;* lme
6840
6841;;* lmx 378 system/sepolicy/public/attributes
6842
6843(neverallow base_typeattr_147 domain (process (fork)))
6844;;* lme
6845
6846;;* lmx 379 system/sepolicy/public/attributes
6847
6848(neverallow base_typeattr_148 domain (process (fork)))
6849;;* lme
6850
6851;;* lmx 379 system/sepolicy/public/attributes
6852
6853(neverallow base_typeattr_149 domain (process (fork)))
6854;;* lme
6855
6856;;* lmx 379 system/sepolicy/public/attributes
6857
6858(neverallow base_typeattr_150 domain (process (fork)))
6859;;* lme
6860
6861;;* lmx 380 system/sepolicy/public/attributes
6862
6863(neverallow base_typeattr_151 domain (process (fork)))
6864;;* lme
6865
6866;;* lmx 380 system/sepolicy/public/attributes
6867
6868(neverallow base_typeattr_152 domain (process (fork)))
6869;;* lme
6870
6871;;* lmx 380 system/sepolicy/public/attributes
6872
6873(neverallow base_typeattr_153 domain (process (fork)))
6874;;* lme
6875
6876;;* lmx 381 system/sepolicy/public/attributes
6877
6878(neverallow base_typeattr_154 domain (process (fork)))
6879;;* lme
6880
6881;;* lmx 381 system/sepolicy/public/attributes
6882
6883(neverallow base_typeattr_155 domain (process (fork)))
6884;;* lme
6885
6886;;* lmx 381 system/sepolicy/public/attributes
6887
6888(neverallow base_typeattr_156 domain (process (fork)))
6889;;* lme
6890
6891;;* lmx 382 system/sepolicy/public/attributes
6892
6893(neverallow base_typeattr_157 domain (process (fork)))
6894;;* lme
6895
6896;;* lmx 382 system/sepolicy/public/attributes
6897
6898(neverallow base_typeattr_158 domain (process (fork)))
6899;;* lme
6900
6901;;* lmx 382 system/sepolicy/public/attributes
6902
6903(neverallow base_typeattr_159 domain (process (fork)))
6904;;* lme
6905
6906;;* lmx 383 system/sepolicy/public/attributes
6907
6908(neverallow base_typeattr_160 domain (process (fork)))
6909;;* lme
6910
6911;;* lmx 383 system/sepolicy/public/attributes
6912
6913(neverallow base_typeattr_161 domain (process (fork)))
6914;;* lme
6915
6916;;* lmx 383 system/sepolicy/public/attributes
6917
6918(neverallow base_typeattr_162 domain (process (fork)))
6919;;* lme
6920
6921;;* lmx 384 system/sepolicy/public/attributes
6922
6923(neverallow base_typeattr_163 domain (process (fork)))
6924;;* lme
6925
6926;;* lmx 384 system/sepolicy/public/attributes
6927
6928(neverallow base_typeattr_164 domain (process (fork)))
6929;;* lme
6930
6931;;* lmx 384 system/sepolicy/public/attributes
6932
6933(neverallow base_typeattr_165 domain (process (fork)))
6934;;* lme
6935
6936;;* lmx 385 system/sepolicy/public/attributes
6937
6938(neverallow base_typeattr_166 domain (process (fork)))
6939;;* lme
6940
6941;;* lmx 385 system/sepolicy/public/attributes
6942
6943(neverallow base_typeattr_167 domain (process (fork)))
6944;;* lme
6945
6946;;* lmx 385 system/sepolicy/public/attributes
6947
6948(neverallow base_typeattr_168 domain (process (fork)))
6949;;* lme
6950
6951;;* lmx 386 system/sepolicy/public/attributes
6952
6953(neverallow base_typeattr_169 domain (process (fork)))
6954;;* lme
6955
6956;;* lmx 386 system/sepolicy/public/attributes
6957
6958(neverallow base_typeattr_170 domain (process (fork)))
6959;;* lme
6960
6961;;* lmx 386 system/sepolicy/public/attributes
6962
6963(neverallow base_typeattr_171 domain (process (fork)))
6964;;* lme
6965
6966;;* lmx 387 system/sepolicy/public/attributes
6967
6968(neverallow base_typeattr_172 domain (process (fork)))
6969;;* lme
6970
6971;;* lmx 387 system/sepolicy/public/attributes
6972
6973(neverallow base_typeattr_173 domain (process (fork)))
6974;;* lme
6975
6976;;* lmx 387 system/sepolicy/public/attributes
6977
6978(neverallow base_typeattr_174 domain (process (fork)))
6979;;* lme
6980
6981;;* lmx 388 system/sepolicy/public/attributes
6982
6983(neverallow base_typeattr_175 domain (process (fork)))
6984;;* lme
6985
6986;;* lmx 388 system/sepolicy/public/attributes
6987
6988(neverallow base_typeattr_176 domain (process (fork)))
6989;;* lme
6990
6991;;* lmx 388 system/sepolicy/public/attributes
6992
6993(neverallow base_typeattr_177 domain (process (fork)))
6994;;* lme
6995
6996;;* lmx 389 system/sepolicy/public/attributes
6997
6998(neverallow base_typeattr_178 domain (process (fork)))
6999;;* lme
7000
7001;;* lmx 389 system/sepolicy/public/attributes
7002
7003(neverallow base_typeattr_179 domain (process (fork)))
7004;;* lme
7005
7006;;* lmx 389 system/sepolicy/public/attributes
7007
7008(neverallow base_typeattr_180 domain (process (fork)))
7009;;* lme
7010
7011;;* lmx 390 system/sepolicy/public/attributes
7012
7013(neverallow base_typeattr_181 domain (process (fork)))
7014;;* lme
7015
7016;;* lmx 390 system/sepolicy/public/attributes
7017
7018(neverallow base_typeattr_182 domain (process (fork)))
7019;;* lme
7020
7021;;* lmx 390 system/sepolicy/public/attributes
7022
7023(neverallow base_typeattr_183 domain (process (fork)))
7024;;* lme
7025
7026;;* lmx 391 system/sepolicy/public/attributes
7027
7028(neverallow base_typeattr_184 domain (process (fork)))
7029;;* lme
7030
7031;;* lmx 391 system/sepolicy/public/attributes
7032
7033(neverallow base_typeattr_185 domain (process (fork)))
7034;;* lme
7035
7036;;* lmx 391 system/sepolicy/public/attributes
7037
7038(neverallow base_typeattr_186 domain (process (fork)))
7039;;* lme
7040
7041;;* lmx 392 system/sepolicy/public/attributes
7042
7043(neverallow base_typeattr_187 domain (process (fork)))
7044;;* lme
7045
7046;;* lmx 392 system/sepolicy/public/attributes
7047
7048(neverallow base_typeattr_188 domain (process (fork)))
7049;;* lme
7050
7051;;* lmx 392 system/sepolicy/public/attributes
7052
7053(neverallow base_typeattr_189 domain (process (fork)))
7054;;* lme
7055
7056;;* lmx 393 system/sepolicy/public/attributes
7057
7058(neverallow base_typeattr_190 domain (process (fork)))
7059;;* lme
7060
7061;;* lmx 393 system/sepolicy/public/attributes
7062
7063(neverallow base_typeattr_191 domain (process (fork)))
7064;;* lme
7065
7066;;* lmx 393 system/sepolicy/public/attributes
7067
7068(neverallow base_typeattr_192 domain (process (fork)))
7069;;* lme
7070
7071;;* lmx 394 system/sepolicy/public/attributes
7072
7073(neverallow base_typeattr_193 domain (process (fork)))
7074;;* lme
7075
7076;;* lmx 394 system/sepolicy/public/attributes
7077
7078(neverallow base_typeattr_194 domain (process (fork)))
7079;;* lme
7080
7081;;* lmx 394 system/sepolicy/public/attributes
7082
7083(neverallow base_typeattr_195 domain (process (fork)))
7084;;* lme
7085
7086;;* lmx 395 system/sepolicy/public/attributes
7087
7088(neverallow base_typeattr_196 domain (process (fork)))
7089;;* lme
7090
7091;;* lmx 395 system/sepolicy/public/attributes
7092
7093(neverallow base_typeattr_197 domain (process (fork)))
7094;;* lme
7095
7096;;* lmx 395 system/sepolicy/public/attributes
7097
7098(neverallow base_typeattr_198 domain (process (fork)))
7099;;* lme
7100
7101;;* lmx 398 system/sepolicy/public/attributes
7102
7103(neverallow base_typeattr_199 domain (process (fork)))
7104;;* lme
7105
7106;;* lmx 398 system/sepolicy/public/attributes
7107
7108(neverallow base_typeattr_200 domain (process (fork)))
7109;;* lme
7110
7111;;* lmx 398 system/sepolicy/public/attributes
7112
7113(neverallow base_typeattr_201 domain (process (fork)))
7114;;* lme
7115
7116;;* lmx 399 system/sepolicy/public/attributes
7117
7118(neverallow base_typeattr_202 domain (process (fork)))
7119;;* lme
7120
7121;;* lmx 399 system/sepolicy/public/attributes
7122
7123(neverallow base_typeattr_203 domain (process (fork)))
7124;;* lme
7125
7126;;* lmx 399 system/sepolicy/public/attributes
7127
7128(neverallow base_typeattr_204 domain (process (fork)))
7129;;* lme
7130
7131;;* lmx 400 system/sepolicy/public/attributes
7132
7133(neverallow base_typeattr_205 domain (process (fork)))
7134;;* lme
7135
7136;;* lmx 400 system/sepolicy/public/attributes
7137
7138(neverallow base_typeattr_206 domain (process (fork)))
7139;;* lme
7140
7141;;* lmx 400 system/sepolicy/public/attributes
7142
7143(neverallow base_typeattr_207 domain (process (fork)))
7144;;* lme
7145
7146;;* lmx 401 system/sepolicy/public/attributes
7147
7148(neverallow base_typeattr_208 domain (process (fork)))
7149;;* lme
7150
7151;;* lmx 401 system/sepolicy/public/attributes
7152
7153(neverallow base_typeattr_209 domain (process (fork)))
7154;;* lme
7155
7156;;* lmx 401 system/sepolicy/public/attributes
7157
7158(neverallow base_typeattr_210 domain (process (fork)))
7159;;* lme
7160
7161;;* lmx 402 system/sepolicy/public/attributes
7162
7163(neverallow base_typeattr_211 domain (process (fork)))
7164;;* lme
7165
7166;;* lmx 402 system/sepolicy/public/attributes
7167
7168(neverallow base_typeattr_212 domain (process (fork)))
7169;;* lme
7170
7171;;* lmx 402 system/sepolicy/public/attributes
7172
7173(neverallow base_typeattr_213 domain (process (fork)))
7174;;* lme
7175
7176;;* lmx 403 system/sepolicy/public/attributes
7177
7178(neverallow base_typeattr_214 domain (process (fork)))
7179;;* lme
7180
7181;;* lmx 403 system/sepolicy/public/attributes
7182
7183(neverallow base_typeattr_215 domain (process (fork)))
7184;;* lme
7185
7186;;* lmx 403 system/sepolicy/public/attributes
7187
7188(neverallow base_typeattr_216 domain (process (fork)))
7189;;* lme
7190
7191;;* lmx 404 system/sepolicy/public/attributes
7192
7193(neverallow base_typeattr_217 domain (process (fork)))
7194;;* lme
7195
7196;;* lmx 404 system/sepolicy/public/attributes
7197
7198(neverallow base_typeattr_218 domain (process (fork)))
7199;;* lme
7200
7201;;* lmx 404 system/sepolicy/public/attributes
7202
7203(neverallow base_typeattr_219 domain (process (fork)))
7204;;* lme
7205
7206;;* lmx 405 system/sepolicy/public/attributes
7207
7208(neverallow base_typeattr_220 domain (process (fork)))
7209;;* lme
7210
7211;;* lmx 405 system/sepolicy/public/attributes
7212
7213(neverallow base_typeattr_221 domain (process (fork)))
7214;;* lme
7215
7216;;* lmx 405 system/sepolicy/public/attributes
7217
7218(neverallow base_typeattr_222 domain (process (fork)))
7219;;* lme
7220
7221;;* lmx 8 system/sepolicy/public/adbd.te
7222
7223(neverallow base_typeattr_223 adbd (process (transition)))
7224;;* lme
7225
7226;;* lmx 9 system/sepolicy/public/adbd.te
7227
7228(neverallow base_typeattr_224 adbd (process (dyntransition)))
7229;;* lme
7230
7231(allow adbd shell_test_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
7232(allow adbd shell_test_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7233(allow adbd shell_test_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7234(allow apexd servicemanager (binder (call transfer)))
7235(allow servicemanager apexd (binder (call transfer)))
7236(allow servicemanager apexd (dir (search)))
7237(allow servicemanager apexd (file (read open)))
7238(allow servicemanager apexd (process (getattr)))
7239(allow apexd apex_service (service_manager (add find)))
7240;;* lmx 6 system/sepolicy/public/apexd.te
7241
7242(neverallow base_typeattr_225 apex_service (service_manager (add)))
7243;;* lme
7244
7245;;* lmx 8 system/sepolicy/public/apexd.te
7246
7247(neverallow base_typeattr_226 apex_service (service_manager (find)))
7248;;* lme
7249
7250;;* lmx 9 system/sepolicy/public/apexd.te
7251
7252(neverallow base_typeattr_227 apexd (binder (call)))
7253;;* lme
7254
7255;;* lmx 11 system/sepolicy/public/apexd.te
7256
7257(neverallow domain apexd (process (ptrace)))
7258;;* lme
7259
7260;;* lmx 20 system/sepolicy/public/app.te
7261
7262(neverallow base_typeattr_228 self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
7263(neverallow base_typeattr_228 self (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
7264(neverallow base_typeattr_228 self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
7265(neverallow base_typeattr_228 self (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
7266;;* lme
7267
7268;;* lmx 23 system/sepolicy/public/app.te
7269
7270(neverallow appdomain dev_type (blk_file (read write)))
7271;;* lme
7272
7273;;* lmx 26 system/sepolicy/public/app.te
7274
7275(neverallow isolated_app graphics_device (chr_file (read write)))
7276(neverallow shell graphics_device (chr_file (read write)))
7277(neverallow untrusted_app graphics_device (chr_file (read write)))
7278;;* lme
7279
7280;;* lmx 29 system/sepolicy/public/app.te
7281
7282(neverallow base_typeattr_229 nfc_device (chr_file (read write)))
7283;;* lme
7284
7285;;* lmx 31 system/sepolicy/public/app.te
7286
7287(neverallow base_typeattr_230 hci_attach_dev (chr_file (read write)))
7288;;* lme
7289
7290;;* lmx 32 system/sepolicy/public/app.te
7291
7292(neverallow appdomain tee_device (chr_file (read write)))
7293;;* lme
7294
7295;;* lmx 42 system/sepolicy/public/app.te
7296
7297(neverallow base_typeattr_231 domain (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
7298(neverallow base_typeattr_231 domain (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
7299(neverallow base_typeattr_231 domain (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
7300(neverallow base_typeattr_231 domain (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
7301(neverallow base_typeattr_231 domain (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
7302;;* lme
7303
7304;;* lmx 48 system/sepolicy/public/app.te
7305
7306(neverallow base_typeattr_231 domain (netlink_kobject_uevent_socket (write append)))
7307;;* lme
7308
7309;;* lmx 51 system/sepolicy/public/app.te
7310
7311(neverallow appdomain socket_device (sock_file (write)))
7312;;* lme
7313
7314;;* lmx 54 system/sepolicy/public/app.te
7315
7316(neverallow appdomain adbd_socket (sock_file (write)))
7317;;* lme
7318
7319;;* lmx 55 system/sepolicy/public/app.te
7320
7321(neverallow base_typeattr_232 rild_socket (sock_file (write)))
7322;;* lme
7323
7324;;* lmx 58 system/sepolicy/public/app.te
7325
7326(neverallow appdomain base_typeattr_233 (process (ptrace)))
7327;;* lme
7328
7329;;* lmx 72 system/sepolicy/public/app.te
7330
7331(neverallow base_typeattr_234 appdomain (process (ptrace)))
7332;;* lme
7333
7334;;* lmx 76 system/sepolicy/public/app.te
7335
7336(neverallow appdomain base_typeattr_233 (file (write create setattr relabelfrom append unlink link rename)))
7337;;* lme
7338
7339;;* lmx 77 system/sepolicy/public/app.te
7340
7341(neverallow base_typeattr_235 base_typeattr_233 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
7342;;* lme
7343
7344;;* lmx 86 system/sepolicy/public/app.te
7345
7346(neverallow appdomain base_typeattr_236 (process (sigkill sigstop signal)))
7347;;* lme
7348
7349;;* lmx 90 system/sepolicy/public/app.te
7350
7351(neverallow appdomain rootfs (file (write create setattr relabelfrom relabelto append unlink link rename)))
7352(neverallow appdomain rootfs (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7353(neverallow appdomain rootfs (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7354(neverallow appdomain rootfs (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7355(neverallow appdomain rootfs (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7356(neverallow appdomain rootfs (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7357(neverallow appdomain rootfs (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7358;;* lme
7359
7360;;* lmx 94 system/sepolicy/public/app.te
7361
7362(neverallow appdomain system_file_type (file (write create setattr relabelfrom relabelto append unlink link rename)))
7363(neverallow appdomain system_file_type (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7364(neverallow appdomain system_file_type (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7365(neverallow appdomain system_file_type (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7366(neverallow appdomain system_file_type (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7367(neverallow appdomain system_file_type (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7368(neverallow appdomain system_file_type (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7369;;* lme
7370
7371;;* lmx 98 system/sepolicy/public/app.te
7372
7373(neverallow appdomain exec_type (file (write create setattr relabelfrom relabelto append unlink link rename)))
7374;;* lme
7375
7376;;* lmx 105 system/sepolicy/public/app.te
7377
7378(neverallow appdomain system_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7379(neverallow appdomain system_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7380(neverallow appdomain system_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7381(neverallow appdomain system_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7382(neverallow appdomain system_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7383(neverallow appdomain system_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7384(neverallow appdomain system_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7385;;* lme
7386
7387;;* lmx 109 system/sepolicy/public/app.te
7388
7389(neverallow appdomain drm_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7390(neverallow appdomain drm_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7391(neverallow appdomain drm_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7392(neverallow appdomain drm_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7393(neverallow appdomain drm_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7394(neverallow appdomain drm_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7395(neverallow appdomain drm_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7396;;* lme
7397
7398;;* lmx 112 system/sepolicy/public/app.te
7399
7400(neverallow base_typeattr_237 apk_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7401(neverallow base_typeattr_237 apk_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7402(neverallow base_typeattr_237 apk_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7403(neverallow base_typeattr_237 apk_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7404(neverallow base_typeattr_237 apk_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7405(neverallow base_typeattr_237 apk_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7406(neverallow base_typeattr_237 apk_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7407;;* lme
7408
7409;;* lmx 115 system/sepolicy/public/app.te
7410
7411(neverallow base_typeattr_237 apk_private_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7412(neverallow base_typeattr_237 apk_private_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7413(neverallow base_typeattr_237 apk_private_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7414(neverallow base_typeattr_237 apk_private_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7415(neverallow base_typeattr_237 apk_private_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7416(neverallow base_typeattr_237 apk_private_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7417(neverallow base_typeattr_237 apk_private_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7418;;* lme
7419
7420;;* lmx 118 system/sepolicy/public/app.te
7421
7422(neverallow base_typeattr_237 apk_private_tmp_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7423(neverallow base_typeattr_237 apk_private_tmp_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7424(neverallow base_typeattr_237 apk_private_tmp_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7425(neverallow base_typeattr_237 apk_private_tmp_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7426(neverallow base_typeattr_237 apk_private_tmp_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7427(neverallow base_typeattr_237 apk_private_tmp_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7428(neverallow base_typeattr_237 apk_private_tmp_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7429;;* lme
7430
7431;;* lmx 121 system/sepolicy/public/app.te
7432
7433(neverallow base_typeattr_235 shell_data_file (file (create setattr relabelfrom relabelto append unlink link rename)))
7434(neverallow base_typeattr_235 shell_data_file (dir (create setattr relabelfrom relabelto append unlink link rename)))
7435(neverallow base_typeattr_235 shell_data_file (lnk_file (create setattr relabelfrom relabelto append unlink link rename)))
7436(neverallow base_typeattr_235 shell_data_file (chr_file (create setattr relabelfrom relabelto append unlink link rename)))
7437(neverallow base_typeattr_235 shell_data_file (blk_file (create setattr relabelfrom relabelto append unlink link rename)))
7438(neverallow base_typeattr_235 shell_data_file (sock_file (create setattr relabelfrom relabelto append unlink link rename)))
7439(neverallow base_typeattr_235 shell_data_file (fifo_file (create setattr relabelfrom relabelto append unlink link rename)))
7440;;* lme
7441
7442;;* lmx 124 system/sepolicy/public/app.te
7443
7444(neverallow base_typeattr_230 bluetooth_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7445(neverallow base_typeattr_230 bluetooth_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7446(neverallow base_typeattr_230 bluetooth_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7447(neverallow base_typeattr_230 bluetooth_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7448(neverallow base_typeattr_230 bluetooth_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7449(neverallow base_typeattr_230 bluetooth_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7450(neverallow base_typeattr_230 bluetooth_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7451;;* lme
7452
7453;;* lmx 125 system/sepolicy/public/app.te
7454
7455(neverallow base_typeattr_238 credstore_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7456(neverallow base_typeattr_238 credstore_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7457(neverallow base_typeattr_238 credstore_data_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7458(neverallow base_typeattr_238 credstore_data_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7459(neverallow base_typeattr_238 credstore_data_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7460(neverallow base_typeattr_238 credstore_data_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7461(neverallow base_typeattr_238 credstore_data_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7462;;* lme
7463
7464;;* lmx 128 system/sepolicy/public/app.te
7465
7466(neverallow appdomain keystore_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7467(neverallow appdomain keystore_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7468(neverallow appdomain keystore_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7469(neverallow appdomain keystore_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7470(neverallow appdomain keystore_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7471(neverallow appdomain keystore_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7472(neverallow appdomain keystore_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7473;;* lme
7474
7475;;* lmx 131 system/sepolicy/public/app.te
7476
7477(neverallow appdomain systemkeys_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7478(neverallow appdomain systemkeys_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7479(neverallow appdomain systemkeys_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7480(neverallow appdomain systemkeys_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7481(neverallow appdomain systemkeys_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7482(neverallow appdomain systemkeys_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7483(neverallow appdomain systemkeys_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7484;;* lme
7485
7486;;* lmx 134 system/sepolicy/public/app.te
7487
7488(neverallow appdomain wifi_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7489(neverallow appdomain wifi_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7490(neverallow appdomain wifi_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7491(neverallow appdomain wifi_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7492(neverallow appdomain wifi_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7493(neverallow appdomain wifi_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7494(neverallow appdomain wifi_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7495;;* lme
7496
7497;;* lmx 137 system/sepolicy/public/app.te
7498
7499(neverallow appdomain dhcp_data_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7500(neverallow appdomain dhcp_data_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7501(neverallow appdomain dhcp_data_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7502(neverallow appdomain dhcp_data_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7503(neverallow appdomain dhcp_data_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7504(neverallow appdomain dhcp_data_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7505(neverallow appdomain dhcp_data_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7506;;* lme
7507
7508;;* lmx 142 system/sepolicy/public/app.te
7509
7510(neverallow base_typeattr_237 apk_tmp_file (file (write create setattr relabelfrom relabelto append unlink link rename)))
7511(neverallow base_typeattr_237 apk_tmp_file (dir (write create setattr relabelfrom relabelto append unlink link rename)))
7512(neverallow base_typeattr_237 apk_tmp_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7513(neverallow base_typeattr_237 apk_tmp_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename)))
7514(neverallow base_typeattr_237 apk_tmp_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename)))
7515(neverallow base_typeattr_237 apk_tmp_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename)))
7516(neverallow base_typeattr_237 apk_tmp_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename)))
7517;;* lme
7518
7519;;* lmx 145 system/sepolicy/public/app.te
7520
7521(neverallow base_typeattr_239 apk_tmp_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7522(neverallow base_typeattr_239 apk_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7523(neverallow base_typeattr_239 apk_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7524(neverallow base_typeattr_239 apk_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7525(neverallow base_typeattr_239 apk_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7526(neverallow base_typeattr_239 apk_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7527(neverallow base_typeattr_239 apk_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7528(neverallow base_typeattr_239 apk_private_tmp_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7529(neverallow base_typeattr_239 apk_private_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7530(neverallow base_typeattr_239 apk_private_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7531(neverallow base_typeattr_239 apk_private_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7532(neverallow base_typeattr_239 apk_private_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7533(neverallow base_typeattr_239 apk_private_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7534(neverallow base_typeattr_239 apk_private_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7535;;* lme
7536
7537;;* lmx 147 system/sepolicy/public/app.te
7538
7539(neverallow untrusted_app_all apk_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7540(neverallow untrusted_app_all apk_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7541(neverallow untrusted_app_all apk_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7542(neverallow untrusted_app_all apk_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7543(neverallow untrusted_app_all apk_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7544(neverallow untrusted_app_all apk_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7545(neverallow untrusted_app_all apk_private_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7546(neverallow untrusted_app_all apk_private_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7547(neverallow untrusted_app_all apk_private_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7548(neverallow untrusted_app_all apk_private_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7549(neverallow untrusted_app_all apk_private_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7550(neverallow untrusted_app_all apk_private_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7551(neverallow isolated_app_all apk_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7552(neverallow isolated_app_all apk_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7553(neverallow isolated_app_all apk_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7554(neverallow isolated_app_all apk_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7555(neverallow isolated_app_all apk_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7556(neverallow isolated_app_all apk_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7557(neverallow isolated_app_all apk_private_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
7558(neverallow isolated_app_all apk_private_tmp_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7559(neverallow isolated_app_all apk_private_tmp_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7560(neverallow isolated_app_all apk_private_tmp_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7561(neverallow isolated_app_all apk_private_tmp_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7562(neverallow isolated_app_all apk_private_tmp_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
7563;;* lme
7564
7565;;* lmx 148 system/sepolicy/public/app.te
7566
7567(neverallow untrusted_app_all apk_tmp_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7568(neverallow untrusted_app_all apk_private_tmp_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7569(neverallow isolated_app_all apk_tmp_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7570(neverallow isolated_app_all apk_private_tmp_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7571;;* lme
7572
7573;;* lmx 151 system/sepolicy/public/app.te
7574
7575(neverallow appdomain efs_file (file (write)))
7576(neverallow appdomain efs_file (dir (write)))
7577(neverallow appdomain efs_file (lnk_file (write)))
7578(neverallow appdomain efs_file (chr_file (write)))
7579(neverallow appdomain efs_file (blk_file (write)))
7580(neverallow appdomain efs_file (sock_file (write)))
7581(neverallow appdomain efs_file (fifo_file (write)))
7582;;* lme
7583
7584;;* lmx 152 system/sepolicy/public/app.te
7585
7586(neverallow base_typeattr_235 efs_file (file (read)))
7587(neverallow base_typeattr_235 efs_file (dir (read)))
7588(neverallow base_typeattr_235 efs_file (lnk_file (read)))
7589(neverallow base_typeattr_235 efs_file (chr_file (read)))
7590(neverallow base_typeattr_235 efs_file (blk_file (read)))
7591(neverallow base_typeattr_235 efs_file (sock_file (read)))
7592(neverallow base_typeattr_235 efs_file (fifo_file (read)))
7593;;* lme
7594
7595;;* lmx 156 system/sepolicy/public/app.te
7596
7597(neverallow base_typeattr_240 sysfs (file (write)))
7598(neverallow base_typeattr_240 sysfs (dir (write)))
7599(neverallow base_typeattr_240 sysfs (lnk_file (write)))
7600(neverallow base_typeattr_240 sysfs (chr_file (write)))
7601(neverallow base_typeattr_240 sysfs (blk_file (write)))
7602(neverallow base_typeattr_240 sysfs (sock_file (write)))
7603(neverallow base_typeattr_240 sysfs (fifo_file (write)))
7604;;* lme
7605
7606;;* lmx 158 system/sepolicy/public/app.te
7607
7608(neverallow appdomain proc (file (write)))
7609(neverallow appdomain proc (dir (write)))
7610(neverallow appdomain proc (lnk_file (write)))
7611(neverallow appdomain proc (chr_file (write)))
7612(neverallow appdomain proc (blk_file (write)))
7613(neverallow appdomain proc (sock_file (write)))
7614(neverallow appdomain proc (fifo_file (write)))
7615;;* lme
7616
7617;;* lmx 161 system/sepolicy/public/app.te
7618
7619(neverallow appdomain kernel (system (syslog_read syslog_mod syslog_console)))
7620;;* lme
7621
7622;;* lmx 164 system/sepolicy/public/app.te
7623
7624(neverallow base_typeattr_235 base_typeattr_224 (security (compute_av check_context)))
7625;;* lme
7626
7627;;* lmx 165 system/sepolicy/public/app.te
7628
7629(neverallow base_typeattr_235 base_typeattr_224 (netlink_selinux_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
7630;;* lme
7631
7632;;* lmx 169 system/sepolicy/public/app.te
7633
7634(neverallow appdomain fs_type (filesystem (mount remount unmount relabelfrom relabelto associate quotamod quotaget watch)))
7635;;* lme
7636
7637;;* lmx 180 system/sepolicy/public/app.te
7638
7639(neverallow appdomain dev_type (lnk_file (write create setattr relabelfrom append unlink link rename)))
7640(neverallow appdomain rootfs (lnk_file (write create setattr relabelfrom append unlink link rename)))
7641(neverallow appdomain tmpfs (lnk_file (write create setattr relabelfrom append unlink link rename)))
7642(neverallow appdomain system_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
7643(neverallow appdomain apk_data_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
7644(neverallow appdomain cache_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
7645(neverallow appdomain cache_recovery_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
7646;;* lme
7647
7648;;* lmx 186 system/sepolicy/public/app.te
7649
7650(neverallow base_typeattr_235 input_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7651;;* lme
7652
7653;;* lmx 194 system/sepolicy/public/app.te
7654
7655(neverallow base_typeattr_241 bluetooth_a2dp_offload_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7656(neverallow base_typeattr_241 bluetooth_audio_hal_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7657(neverallow base_typeattr_241 bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7658(neverallow base_typeattr_241 exported_bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7659;;* lme
7660
7661(allow system_app property_socket (sock_file (write)))
7662(allow system_app init (unix_stream_socket (connectto)))
7663(allow system_app nfc_prop (property_service (set)))
7664(allow system_app nfc_prop (file (read getattr map open)))
7665(allow system_app property_socket (sock_file (write)))
7666(allow system_app init (unix_stream_socket (connectto)))
7667(allow system_app radio_control_prop (property_service (set)))
7668(allow system_app radio_control_prop (file (read getattr map open)))
7669;;* lmx 202 system/sepolicy/public/app.te
7670
7671(neverallow appdomain proc_uid_time_in_state (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7672;;* lme
7673
7674;;* lmx 205 system/sepolicy/public/app.te
7675
7676(neverallow appdomain proc_uid_concurrent_active_time (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7677;;* lme
7678
7679;;* lmx 208 system/sepolicy/public/app.te
7680
7681(neverallow appdomain proc_uid_concurrent_policy_time (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7682;;* lme
7683
7684;;* lmx 211 system/sepolicy/public/app.te
7685
7686(neverallow appdomain proc_uid_cpupower (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7687;;* lme
7688
7689;;* lmx 216 system/sepolicy/public/app.te
7690
7691(neverallow base_typeattr_235 proc_net_tcp_udp (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
7692;;* lme
7693
7694;;* lmx 224 system/sepolicy/public/app.te
7695
7696(neverallow appdomain system_bootstrap_lib_file (file (read write append map execute open execute_no_trans)))
7697;;* lme
7698
7699;;* lmx 226 system/sepolicy/public/app.te
7700
7701(neverallow appdomain system_bootstrap_lib_file (dir (read getattr open search)))
7702;;* lme
7703
7704(allow audioserver hal_audio_server (process (signal)))
7705(allow audioserver sensorservice_service (service_manager (find)))
7706(allow audioserver system_server (unix_stream_socket (read write)))
7707(allow bootanim servicemanager (binder (call transfer)))
7708(allow servicemanager bootanim (binder (call transfer)))
7709(allow servicemanager bootanim (dir (search)))
7710(allow servicemanager bootanim (file (read open)))
7711(allow servicemanager bootanim (process (getattr)))
7712(allow bootanim surfaceflinger (binder (call transfer)))
7713(allow surfaceflinger bootanim (binder (transfer)))
7714(allow bootanim surfaceflinger (fd (use)))
7715(allow bootanim audioserver (binder (call transfer)))
7716(allow audioserver bootanim (binder (transfer)))
7717(allow bootanim audioserver (fd (use)))
7718(allow bootanim hwservicemanager (binder (call transfer)))
7719(allow hwservicemanager bootanim (binder (call transfer)))
7720(allow hwservicemanager bootanim (dir (search)))
7721(allow hwservicemanager bootanim (file (read map open)))
7722(allow hwservicemanager bootanim (process (getattr)))
7723(allow bootanim gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7724(allow bootanim gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
7725(allow bootanim sysfs_gpu (file (ioctl read getattr lock map open watch watch_reads)))
7726(allow bootanim oemfs (dir (ioctl read getattr lock open watch watch_reads search)))
7727(allow bootanim bootanim_oem_file (file (ioctl read getattr lock map open watch watch_reads)))
7728(allow bootanim audio_device (dir (ioctl read getattr lock open watch watch_reads search)))
7729(allow bootanim audio_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7730(allow bootanim audioserver_service (service_manager (find)))
7731(allow bootanim surfaceflinger_service (service_manager (find)))
7732(allow bootanim surfaceflinger (unix_stream_socket (read write)))
7733(allow bootanim ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7734(allow bootanim dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
7735(allow bootanim hal_graphics_allocator (fd (use)))
7736(allow bootanim hal_graphics_composer (fd (use)))
7737(allow bootanim proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
7738(allow bootanim system_file (dir (ioctl read getattr lock open watch watch_reads search)))
7739(allow bootstat runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
7740(allow bootstat bootstat_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
7741(allow bootstat bootstat_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7742(allow bootstat metadata_file (dir (search)))
7743(allow bootstat metadata_bootstat_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
7744(allow bootstat metadata_bootstat_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7745(allow bootstat pstorefs (dir (search)))
7746(allow bootstat pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
7747(allow bootstat kernel (system (syslog_read)))
7748(allow bootstat logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
7749(allow bootstat logdr_socket (sock_file (write)))
7750(allow bootstat logd (unix_stream_socket (connectto)))
7751(allow bootstat statsdw_socket (sock_file (write)))
7752(allow bootstat statsd (unix_dgram_socket (sendto)))
7753;;* lmx 32 system/sepolicy/public/bootstat.te
7754
7755(neverallow base_typeattr_242 system_boot_reason_prop (property_service (set)))
7756;;* lme
7757
7758(allow init pdx_bufferhub_client_endpoint_socket_type (unix_stream_socket (create bind)))
7759(allow bufferhubd pdx_bufferhub_client_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
7760(allow bufferhubd self (process (setsockcreate)))
7761(allow bufferhubd pdx_bufferhub_client_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
7762;;* lmx 8 system/sepolicy/public/bufferhubd.te
7763
7764(neverallow base_typeattr_243 pdx_bufferhub_client_endpoint_socket_type (unix_stream_socket (listen accept)))
7765;;* lme
7766
7767(allow bufferhubd pdx_performance_client_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
7768(allow bufferhubd pdx_performance_client_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
7769(allow bufferhubd pdx_performance_client_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
7770(allow bufferhubd pdx_performance_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
7771(allow bufferhubd pdx_performance_client_server_type (fd (use)))
7772(allow pdx_performance_client_server_type bufferhubd (fd (use)))
7773(allow bufferhubd gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7774(allow bufferhubd ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
7775(allow bufferhubd hal_omx_server (fd (use)))
7776(allow bufferhubd hal_codec2_server (fd (use)))
7777(allow camera_service_server fwk_camera_hwservice (hwservice_manager (add find)))
7778(allow camera_service_server hidl_base_hwservice (hwservice_manager (add)))
7779;;* lmx 1 system/sepolicy/public/camera_service_server.te
7780
7781(neverallow base_typeattr_244 fwk_camera_hwservice (hwservice_manager (add)))
7782;;* lme
7783
7784(allow cameraserver servicemanager (binder (call transfer)))
7785(allow servicemanager cameraserver (binder (call transfer)))
7786(allow servicemanager cameraserver (dir (search)))
7787(allow servicemanager cameraserver (file (read open)))
7788(allow servicemanager cameraserver (process (getattr)))
7789(allow cameraserver binderservicedomain (binder (call transfer)))
7790(allow binderservicedomain cameraserver (binder (transfer)))
7791(allow cameraserver binderservicedomain (fd (use)))
7792(allow cameraserver appdomain (binder (call transfer)))
7793(allow appdomain cameraserver (binder (transfer)))
7794(allow cameraserver appdomain (fd (use)))
7795(allow cameraserver ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7796(allow cameraserver dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
7797(allow cameraserver hal_graphics_composer (fd (use)))
7798(allow cameraserver cameraserver_service (service_manager (add find)))
7799;;* lmx 21 system/sepolicy/public/cameraserver.te
7800
7801(neverallow base_typeattr_245 cameraserver_service (service_manager (add)))
7802;;* lme
7803
7804(allow cameraserver fwk_camera_service (service_manager (add find)))
7805;;* lmx 22 system/sepolicy/public/cameraserver.te
7806
7807(neverallow base_typeattr_245 fwk_camera_service (service_manager (add)))
7808;;* lme
7809
7810(allow cameraserver fwk_camera_hwservice (hwservice_manager (add find)))
7811(allow cameraserver hidl_base_hwservice (hwservice_manager (add)))
7812;;* lmx 23 system/sepolicy/public/cameraserver.te
7813
7814(neverallow base_typeattr_245 fwk_camera_hwservice (hwservice_manager (add)))
7815;;* lme
7816
7817(allow cameraserver activity_service (service_manager (find)))
7818(allow cameraserver appops_service (service_manager (find)))
7819(allow cameraserver audioserver_service (service_manager (find)))
7820(allow cameraserver batterystats_service (service_manager (find)))
7821(allow cameraserver cameraproxy_service (service_manager (find)))
7822(allow cameraserver mediaserver_service (service_manager (find)))
7823(allow cameraserver package_native_service (service_manager (find)))
7824(allow cameraserver permission_checker_service (service_manager (find)))
7825(allow cameraserver processinfo_service (service_manager (find)))
7826(allow cameraserver scheduling_policy_service (service_manager (find)))
7827(allow cameraserver sensor_privacy_service (service_manager (find)))
7828(allow cameraserver surfaceflinger_service (service_manager (find)))
7829(allow cameraserver hidl_token_hwservice (hwservice_manager (find)))
7830(allow cameraserver hal_camera_service (service_manager (find)))
7831(allow cameraserver virtual_camera_service (service_manager (find)))
7832(allow cameraserver surfaceflinger (unix_stream_socket (read write)))
7833;;* lmx 51 system/sepolicy/public/cameraserver.te
7834
7835(neverallow cameraserver fs_type (file (execute_no_trans)))
7836(neverallow cameraserver file_type (file (execute_no_trans)))
7837;;* lme
7838
7839;;* lmx 63 system/sepolicy/public/cameraserver.te
7840
7841(neverallow cameraserver domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
7842(neverallow cameraserver domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
7843;;* lme
7844
7845;;* lmx 64 system/sepolicy/public/cameraserver.te
7846
7847(neverallow cameraserver domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
7848;;* lme
7849
7850(allow cameraserver adbd (fd (use)))
7851(allow cameraserver adbd (unix_stream_socket (read write)))
7852(allow cameraserver shell (fd (use)))
7853(allow cameraserver shell (unix_stream_socket (read write)))
7854(allow cameraserver shell (fifo_file (read write)))
7855(allow cameraserver mediametrics_service (service_manager (find)))
7856(allow charger_type kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7857(allow charger_type rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
7858(allow charger_type rootfs (file (ioctl read getattr lock map open watch watch_reads)))
7859(allow charger_type rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7860(allow charger_type cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
7861(allow charger_type cgroup (file (ioctl read getattr lock map open watch watch_reads)))
7862(allow charger_type cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7863(allow charger_type cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
7864(allow charger_type cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
7865(allow charger_type cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7866(allow charger_type sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
7867(allow charger_type self (capability (sys_boot sys_tty_config)))
7868(allow charger_type self (cap_userns (sys_boot sys_tty_config)))
7869(allow charger_type sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
7870(allow charger_type self (capability2 (block_suspend)))
7871(allow charger_type self (cap2_userns (block_suspend)))
7872(allow charger_type system_suspend_server (binder (call transfer)))
7873(allow system_suspend_server charger_type (binder (transfer)))
7874(allow charger_type system_suspend_server (fd (use)))
7875(allow charger_type system_suspend_hwservice (hwservice_manager (find)))
7876(allow charger_type hwservicemanager (binder (call transfer)))
7877(allow hwservicemanager charger_type (binder (call transfer)))
7878(allow hwservicemanager charger_type (dir (search)))
7879(allow hwservicemanager charger_type (file (read map open)))
7880(allow hwservicemanager charger_type (process (getattr)))
7881(allow charger_type hwservicemanager_prop (file (read getattr map open)))
7882(allow charger_type hidl_manager_hwservice (hwservice_manager (find)))
7883(allow charger_type hal_system_suspend_service (service_manager (find)))
7884(allow charger_type servicemanager (binder (call transfer)))
7885(allow servicemanager charger_type (binder (call transfer)))
7886(allow servicemanager charger_type (dir (search)))
7887(allow servicemanager charger_type (file (read open)))
7888(allow servicemanager charger_type (process (getattr)))
7889(allow charger_type self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
7890(allow charger_type sysfs_power (file (ioctl read write getattr lock append map open watch watch_reads)))
7891(allow charger_type sysfs_batteryinfo (dir (ioctl read getattr lock open watch watch_reads search)))
7892(allow charger_type sysfs_batteryinfo (file (ioctl read getattr lock map open watch watch_reads)))
7893(allow charger_type sysfs_batteryinfo (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7894(allow charger_type pstorefs (dir (ioctl read getattr lock open watch watch_reads search)))
7895(allow charger_type pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
7896(allow charger_type graphics_device (dir (ioctl read getattr lock open watch watch_reads search)))
7897(allow charger_type graphics_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7898(allow charger_type input_device (dir (ioctl read getattr lock open watch watch_reads search)))
7899(allow charger_type input_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
7900(allow charger_type tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
7901(allow charger_type proc_sysrq (file (ioctl read write getattr lock append map open watch watch_reads)))
7902(dontaudit crash_dump self (capability (sys_ptrace)))
7903(dontaudit crash_dump self (cap_userns (sys_ptrace)))
7904(allow crash_dump domain (fd (use)))
7905(allow crash_dump domain (fifo_file (read write)))
7906(allow crash_dump domain (fifo_file (append)))
7907(allow crash_dump domain (process (getattr)))
7908(allow crash_dump domain (dir (ioctl read getattr lock open watch watch_reads search)))
7909(allow crash_dump domain (file (ioctl read getattr lock map open watch watch_reads)))
7910(allow crash_dump domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7911(allow crash_dump exec_type (file (ioctl read getattr lock map open watch watch_reads)))
7912(allow crash_dump dalvikcache_data_file (dir (getattr search)))
7913(allow crash_dump dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
7914(allow crash_dump apex_module_data_file (dir (getattr search)))
7915(allow crash_dump proc_uptime (file (ioctl read getattr lock map open watch watch_reads)))
7916(allow crash_dump apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
7917(allow crash_dump apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
7918(allow crash_dump apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7919(allow crash_dump vendor_file (dir (ioctl read getattr lock open watch watch_reads search)))
7920(allow crash_dump same_process_hal_file (dir (ioctl read getattr lock open watch watch_reads search)))
7921(allow crash_dump vendor_file (file (ioctl read getattr lock map open watch watch_reads)))
7922(allow crash_dump vendor_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7923(allow crash_dump same_process_hal_file (file (ioctl read getattr lock map open watch watch_reads)))
7924(allow crash_dump same_process_hal_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7925(allow crash_dump shell_test_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
7926(allow crash_dump shell_test_data_file (file (ioctl read getattr lock map open watch watch_reads)))
7927(allow crash_dump shell_test_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7928(allow crash_dump tombstoned_crash_socket (sock_file (write)))
7929(allow crash_dump tombstoned (unix_stream_socket (connectto)))
7930(allow crash_dump system_ndebug_socket (sock_file (write)))
7931(allow crash_dump system_server (unix_stream_socket (connectto)))
7932(allow crash_dump anr_data_file (file (getattr append)))
7933(allow crash_dump tombstone_data_file (file (getattr append)))
7934(allow crash_dump logdr_socket (sock_file (write)))
7935(allow crash_dump logd (unix_stream_socket (connectto)))
7936(dontaudit crash_dump core_data_file_type (dir (search)))
7937(dontaudit crash_dump vendor_file_type (dir (search)))
7938(dontaudit crash_dump system_data_file (file (read)))
7939(dontaudit crash_dump system_data_file (lnk_file (read)))
7940(dontaudit crash_dump property_type (file (read)))
7941;;* lmx 80 system/sepolicy/public/crash_dump.te
7942
7943(neverallow domain crash_dump_exec (file (execute_no_trans)))
7944;;* lme
7945
7946(allow credstore servicemanager (binder (call transfer)))
7947(allow servicemanager credstore (binder (call transfer)))
7948(allow servicemanager credstore (dir (search)))
7949(allow servicemanager credstore (file (read open)))
7950(allow servicemanager credstore (process (getattr)))
7951(allow credstore system_server (binder (call transfer)))
7952(allow system_server credstore (binder (transfer)))
7953(allow credstore system_server (fd (use)))
7954(allow credstore credstore_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
7955(allow credstore credstore_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7956(allow credstore credstore_service (service_manager (add find)))
7957;;* lmx 12 system/sepolicy/public/credstore.te
7958
7959(neverallow base_typeattr_246 credstore_service (service_manager (add)))
7960;;* lme
7961
7962(allow credstore sec_key_att_app_id_provider_service (service_manager (find)))
7963(allow credstore dropbox_service (service_manager (find)))
7964(allow credstore authorization_service (service_manager (find)))
7965(allow credstore keystore (keystore2 (get_auth_token)))
7966(allow credstore cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
7967(allow credstore cgroup (file (ioctl read getattr lock map open watch watch_reads)))
7968(allow credstore cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7969(allow credstore cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
7970(allow credstore cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
7971(allow credstore cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
7972(allow dhcp cgroup (dir (write create add_name)))
7973(allow dhcp cgroup_v2 (dir (write create add_name)))
7974(allow dhcp self (capability (setgid setuid net_bind_service net_admin net_raw)))
7975(allow dhcp self (cap_userns (setgid setuid net_bind_service net_admin net_raw)))
7976(allow dhcp self (packet_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
7977(allow dhcp self (netlink_route_socket (nlmsg_write)))
7978(allow dhcp shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
7979(allow dhcp system_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
7980(allow dhcp toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
7981(allow dhcp proc_net_type (file (write)))
7982(allow dhcp dhcp_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
7983(allow dhcp dhcp_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
7984(allow dhcp netd (fd (use)))
7985(allow dhcp netd (fifo_file (ioctl read write getattr lock append map open watch watch_reads)))
7986(allow dhcp netd (udp_socket (read write)))
7987(allow dhcp netd (unix_stream_socket (read write)))
7988(allow dhcp netd (unix_dgram_socket (read write)))
7989(allow dhcp netd (netlink_route_socket (read write)))
7990(allow dhcp netd (netlink_nflog_socket (read write)))
7991(allow dhcp netd (netlink_kobject_uevent_socket (read write)))
7992(allow display_service_server fwk_display_hwservice (hwservice_manager (add find)))
7993(allow display_service_server hidl_base_hwservice (hwservice_manager (add)))
7994;;* lmx 1 system/sepolicy/public/display_service_server.te
7995
7996(neverallow base_typeattr_247 fwk_display_hwservice (hwservice_manager (add)))
7997;;* lme
7998
7999(allowx dnsmasq self (ioctl udp_socket (0x6900 0x6902)))
8000(allowx dnsmasq self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
8001(allowx dnsmasq self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
8002(allow dnsmasq self (capability (dac_override dac_read_search)))
8003(allow dnsmasq self (cap_userns (dac_override dac_read_search)))
8004(allow dnsmasq self (capability (setgid setuid net_bind_service net_admin net_raw)))
8005(allow dnsmasq self (cap_userns (setgid setuid net_bind_service net_admin net_raw)))
8006(allow dnsmasq dhcp_data_file (dir (write lock open add_name remove_name search)))
8007(allow dnsmasq dhcp_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
8008(allow dnsmasq netd (fd (use)))
8009(allow dnsmasq netd (fifo_file (read write getattr)))
8010(allow dnsmasq netd (netlink_kobject_uevent_socket (read write)))
8011(allow dnsmasq netd (netlink_nflog_socket (read write)))
8012(allow dnsmasq netd (netlink_route_socket (read write)))
8013(allow dnsmasq netd (unix_stream_socket (read write getattr)))
8014(allow dnsmasq netd (unix_dgram_socket (read write)))
8015(allow dnsmasq netd (udp_socket (read write)))
8016(allow domain init (process (sigchld)))
8017(allow domain self (process (fork sigchld sigkill sigstop signull signal getsched setsched getsession getpgid setpgid getcap setcap getattr setrlimit)))
8018(allow domain self (fd (use)))
8019(allow domain proc (dir (ioctl read getattr lock open watch watch_reads search)))
8020(allow domain proc_net_type (dir (search)))
8021(allow domain self (dir (ioctl read getattr lock open watch watch_reads search)))
8022(allow domain self (file (ioctl read getattr lock map open watch watch_reads)))
8023(allow domain self (lnk_file (ioctl read getattr lock map open watch watch_reads)))
8024(allow domain self (file (ioctl read write getattr lock append map open watch watch_reads)))
8025(allow domain self (fifo_file (ioctl read write getattr lock append map open watch watch_reads)))
8026(allow domain self (unix_dgram_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown sendto)))
8027(allow domain self (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown connectto)))
8028(allow domain init (fd (use)))
8029(allow domain device_config_aconfig_flags_prop (file (read getattr map open)))
8030(allow domain tmpfs (dir (getattr search)))
8031(allow domain rootfs (dir (search)))
8032(allow domain rootfs (lnk_file (read getattr)))
8033(allow domain device (dir (search)))
8034(allow domain dev_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
8035(allow domain devpts (dir (search)))
8036(allow domain dmabuf_heap_device (dir (ioctl read getattr lock open watch watch_reads search)))
8037(allow domain socket_device (dir (ioctl read getattr lock open watch watch_reads search)))
8038(allow domain owntty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8039(allow domain null_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8040(allow domain zero_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8041(allow domain ashmem_device (chr_file (ioctl read write getattr lock append map)))
8042(allow domain ashmem_libcutils_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8043(allow base_typeattr_248 binder_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8044(allow base_typeattr_248 servicemanager_prop (file (read getattr map open)))
8045(allowx domain binder_device (ioctl chr_file (0x6201 0x6203 (range 0x6205 0x6209) (range 0x620b 0x620d) (range 0x6210 0x6211))))
8046(allow domain binderfs (dir (getattr search)))
8047(allow domain binderfs_logs_proc (dir (search)))
8048(allow domain binderfs_features (dir (search)))
8049(allow domain binderfs_features (file (ioctl read getattr lock map open watch watch_reads)))
8050(allow base_typeattr_249 hwbinder_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8051(allow domain ptmx_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8052(allow domain random_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8053(allow domain proc_random (dir (ioctl read getattr lock open watch watch_reads search)))
8054(allow domain proc_random (file (ioctl read getattr lock map open watch watch_reads)))
8055(allow domain properties_device (dir (getattr search)))
8056(allow domain properties_serial (file (ioctl read getattr lock map open watch watch_reads)))
8057(allow domain property_info (file (ioctl read getattr lock map open watch watch_reads)))
8058(allow domain log_property_type (file (read getattr map open)))
8059(dontaudit domain property_type (file (audit_access)))
8060(allow domain property_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
8061(allow domain init (key (search)))
8062(allow domain vold (key (search)))
8063(allow domain logdw_socket (sock_file (write)))
8064(allow domain logd (unix_dgram_socket (sendto)))
8065(allow domain pmsg_device (chr_file (write lock append map open)))
8066(allow domain system_file (dir (ioctl read getattr lock open watch watch_reads search)))
8067(allow domain system_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
8068(allow domain system_seccomp_policy_file (dir (ioctl read getattr lock open watch watch_reads search)))
8069(allow domain system_security_cacerts_file (dir (ioctl read getattr lock open watch watch_reads search)))
8070(allow domain system_file (lnk_file (read getattr)))
8071(allow domain system_seccomp_policy_file (file (ioctl read getattr lock map open watch watch_reads)))
8072(allow domain system_security_cacerts_file (file (ioctl read getattr lock map open watch watch_reads)))
8073(allow domain system_group_file (file (ioctl read getattr lock map open watch watch_reads)))
8074(allow domain system_passwd_file (file (ioctl read getattr lock map open watch watch_reads)))
8075(allow domain system_linker_exec (file (read getattr map execute open)))
8076(allow domain system_linker_config_file (file (ioctl read getattr lock map open watch watch_reads)))
8077(allow domain system_lib_file (file (read getattr map execute open)))
8078(allow domain system_linker_exec (lnk_file (read getattr open)))
8079(allow domain system_lib_file (lnk_file (read getattr open)))
8080(allow domain system_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
8081(allow appdomain system_file (file (read getattr map execute open)))
8082(allow coredomain system_file (file (read getattr map execute open)))
8083(allow domain vendor_hal_file (dir (ioctl read getattr lock open watch watch_reads search)))
8084(allow domain same_process_hal_file (dir (ioctl read getattr lock open watch watch_reads search)))
8085(allow base_typeattr_250 same_process_hal_file (file (read getattr map execute open)))
8086(allow domain vndk_sp_file (dir (ioctl read getattr lock open watch watch_reads search)))
8087(allow domain vndk_sp_file (file (read getattr map execute open)))
8088(allow domain vendor_configs_file (dir (ioctl read getattr lock open watch watch_reads search)))
8089(allow domain vendor_configs_file (file (read getattr map open)))
8090(allow domain vendor_file_type (lnk_file (read getattr open)))
8091(allow domain vendor_file (dir (getattr search)))
8092(allow base_typeattr_250 vendor_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
8093(allow base_typeattr_250 vendor_file_type (file (read getattr map execute open)))
8094(allow base_typeattr_250 vendor_file_type (lnk_file (read getattr)))
8095(allow domain sysfs (lnk_file (read getattr)))
8096(allow domain system_zoneinfo_file (file (ioctl read getattr lock map open watch watch_reads)))
8097(allow domain system_zoneinfo_file (dir (ioctl read getattr lock open watch watch_reads search)))
8098(allow domain sysfs_devices_system_cpu (dir (ioctl read getattr lock open watch watch_reads search)))
8099(allow domain sysfs_devices_system_cpu (file (ioctl read getattr lock map open watch watch_reads)))
8100(allow domain sysfs_devices_system_cpu (lnk_file (ioctl read getattr lock map open watch watch_reads)))
8101(allow domain sysfs_usb (dir (ioctl read getattr lock open watch watch_reads search)))
8102(allow domain sysfs_usb (file (ioctl read getattr lock map open watch watch_reads)))
8103(allow domain sysfs_usb (lnk_file (ioctl read getattr lock map open watch watch_reads)))
8104(allow domain sysfs_transparent_hugepage (dir (search)))
8105(allow domain sysfs_transparent_hugepage (file (ioctl read getattr lock map open watch watch_reads)))
8106(allow appdomain system_data_file (dir (getattr)))
8107(allow coredomain system_data_file (dir (getattr)))
8108(allow domain system_data_root_file (dir (getattr search)))
8109(allow domain system_data_file (dir (search)))
8110(allow appdomain system_userdir_file (dir (getattr search)))
8111(allow coredomain system_userdir_file (dir (getattr search)))
8112(allow appdomain media_userdir_file (dir (search)))
8113(allow coredomain media_userdir_file (dir (search)))
8114(allow domain vendor_userdir_file (dir (getattr search)))
8115(allow domain vendor_data_file (dir (getattr search)))
8116(allow domain proc (lnk_file (read getattr)))
8117(allow domain proc_cpuinfo (file (ioctl read getattr lock map open watch watch_reads)))
8118(allow domain dev_cpu_variant (file (ioctl read getattr lock map open watch watch_reads)))
8119(allow domain proc_perf (file (ioctl read getattr lock map open watch watch_reads)))
8120(allow domain selinuxfs (dir (search)))
8121(allow domain selinuxfs (file (getattr)))
8122(allow domain sysfs (dir (search)))
8123(allow domain selinuxfs (filesystem (getattr)))
8124(allow domain debugfs (dir (search)))
8125(allow domain debugfs_tracing (dir (search)))
8126(allow domain debugfs_tracing_debug (dir (search)))
8127(allow domain debugfs_trace_marker (file (write lock append map open)))
8128(allow domain self (lockdown (integrity confidentiality)))
8129(allow domain fs_type (filesystem (getattr)))
8130(allow domain fs_type (dir (getattr)))
8131(allowx domain domain (ioctl tcp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
8132(allowx domain domain (ioctl udp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
8133(allowx domain domain (ioctl rawip_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
8134(allowx domain domain (ioctl icmp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
8135(allowx domain domain (ioctl tcp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
8136(allowx domain domain (ioctl udp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
8137(allowx domain domain (ioctl rawip_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
8138(allowx domain domain (ioctl icmp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
8139(allowx domain domain (ioctl tcp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
8140(allowx domain domain (ioctl udp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
8141(allowx domain domain (ioctl rawip_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
8142(allowx domain domain (ioctl icmp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
8143(allowx domain domain (ioctl unix_stream_socket (0x5401 0x5411 (range 0x5413 0x5414) 0x541b (range 0x5450 0x5451))))
8144(allowx domain domain (ioctl unix_dgram_socket (0x5401 0x5411 (range 0x5413 0x5414) 0x541b (range 0x5450 0x5451))))
8145(allowx domain pdx_channel_socket_type (ioctl unix_stream_socket (0x5401 0x5411 (range 0x5413 0x5414) 0x541b (range 0x5450 0x5451))))
8146(allowx domain pdx_channel_socket_type (ioctl unix_dgram_socket (0x5401 0x5411 (range 0x5413 0x5414) 0x541b (range 0x5450 0x5451))))
8147(allowx domain devpts (ioctl chr_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
8148(allowx domain dev_type (ioctl file ((range 0x5450 0x5451))))
8149(allowx domain dev_type (ioctl dir ((range 0x5450 0x5451))))
8150(allowx domain dev_type (ioctl lnk_file ((range 0x5450 0x5451))))
8151(allowx domain dev_type (ioctl blk_file ((range 0x5450 0x5451))))
8152(allowx domain dev_type (ioctl sock_file ((range 0x5450 0x5451))))
8153(allowx domain dev_type (ioctl fifo_file ((range 0x5450 0x5451))))
8154(allowx domain domain (ioctl file ((range 0x5450 0x5451))))
8155(allowx domain domain (ioctl dir ((range 0x5450 0x5451))))
8156(allowx domain domain (ioctl lnk_file ((range 0x5450 0x5451))))
8157(allowx domain domain (ioctl blk_file ((range 0x5450 0x5451))))
8158(allowx domain domain (ioctl sock_file ((range 0x5450 0x5451))))
8159(allowx domain domain (ioctl fifo_file ((range 0x5450 0x5451))))
8160(allowx domain fs_type (ioctl file ((range 0x5450 0x5451))))
8161(allowx domain fs_type (ioctl dir ((range 0x5450 0x5451))))
8162(allowx domain fs_type (ioctl lnk_file ((range 0x5450 0x5451))))
8163(allowx domain fs_type (ioctl blk_file ((range 0x5450 0x5451))))
8164(allowx domain fs_type (ioctl sock_file ((range 0x5450 0x5451))))
8165(allowx domain fs_type (ioctl fifo_file ((range 0x5450 0x5451))))
8166(allowx domain file_type (ioctl file ((range 0x5450 0x5451))))
8167(allowx domain file_type (ioctl dir ((range 0x5450 0x5451))))
8168(allowx domain file_type (ioctl lnk_file ((range 0x5450 0x5451))))
8169(allowx domain file_type (ioctl blk_file ((range 0x5450 0x5451))))
8170(allowx domain file_type (ioctl sock_file ((range 0x5450 0x5451))))
8171(allowx domain file_type (ioctl fifo_file ((range 0x5450 0x5451))))
8172(allowx domain tun_device (ioctl chr_file ((range 0x5450 0x5451))))
8173(allowx domain fs_type (ioctl file (0x5401)))
8174(allowx domain file_type (ioctl file (0x5401)))
8175(allowx domain domain (ioctl fifo_file (0x5401)))
8176(allowx domain dev_type (ioctl blk_file (0x1268 0x1272)))
8177(allowx domain file_type (ioctl file ((range 0xf501 0xf502) 0xf505 (range 0xf50c 0xf50e))))
8178(allowx domain sdcard_type (ioctl file ((range 0xf501 0xf502) 0xf505 (range 0xf50c 0xf50e))))
8179(allow base_typeattr_251 hwservice_manager_type (hwservice_manager (add find)))
8180(allow base_typeattr_251 vndservice_manager_type (service_manager (add find)))
8181(allow domain apex_mnt_dir (dir (getattr search)))
8182(allow domain apex_mnt_dir (lnk_file (ioctl read getattr lock map open watch watch_reads)))
8183(allow domain device_config_media_native_prop (file (read getattr map open)))
8184(allow domain aconfig_storage_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
8185;;* lmx 357 system/sepolicy/public/domain.te
8186
8187(neverallowx base_typeattr_224 base_typeattr_224 (ioctl file (0x0)))
8188(neverallowx base_typeattr_224 base_typeattr_224 (ioctl dir (0x0)))
8189(neverallowx base_typeattr_224 base_typeattr_224 (ioctl lnk_file (0x0)))
8190(neverallowx base_typeattr_224 base_typeattr_224 (ioctl blk_file (0x0)))
8191(neverallowx base_typeattr_224 base_typeattr_224 (ioctl sock_file (0x0)))
8192(neverallowx base_typeattr_224 base_typeattr_224 (ioctl fifo_file (0x0)))
8193(neverallowx base_typeattr_224 base_typeattr_224 (ioctl socket (0x0)))
8194(neverallowx base_typeattr_224 base_typeattr_224 (ioctl tcp_socket (0x0)))
8195(neverallowx base_typeattr_224 base_typeattr_224 (ioctl udp_socket (0x0)))
8196(neverallowx base_typeattr_224 base_typeattr_224 (ioctl rawip_socket (0x0)))
8197(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_socket (0x0)))
8198(neverallowx base_typeattr_224 base_typeattr_224 (ioctl packet_socket (0x0)))
8199(neverallowx base_typeattr_224 base_typeattr_224 (ioctl key_socket (0x0)))
8200(neverallowx base_typeattr_224 base_typeattr_224 (ioctl unix_stream_socket (0x0)))
8201(neverallowx base_typeattr_224 base_typeattr_224 (ioctl unix_dgram_socket (0x0)))
8202(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_route_socket (0x0)))
8203(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_tcpdiag_socket (0x0)))
8204(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_nflog_socket (0x0)))
8205(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_xfrm_socket (0x0)))
8206(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_selinux_socket (0x0)))
8207(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_audit_socket (0x0)))
8208(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_dnrt_socket (0x0)))
8209(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_kobject_uevent_socket (0x0)))
8210(neverallowx base_typeattr_224 base_typeattr_224 (ioctl appletalk_socket (0x0)))
8211(neverallowx base_typeattr_224 base_typeattr_224 (ioctl tun_socket (0x0)))
8212(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_iscsi_socket (0x0)))
8213(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_fib_lookup_socket (0x0)))
8214(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_connector_socket (0x0)))
8215(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_netfilter_socket (0x0)))
8216(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_generic_socket (0x0)))
8217(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_scsitransport_socket (0x0)))
8218(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_rdma_socket (0x0)))
8219(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netlink_crypto_socket (0x0)))
8220(neverallowx base_typeattr_224 base_typeattr_224 (ioctl sctp_socket (0x0)))
8221(neverallowx base_typeattr_224 base_typeattr_224 (ioctl icmp_socket (0x0)))
8222(neverallowx base_typeattr_224 base_typeattr_224 (ioctl ax25_socket (0x0)))
8223(neverallowx base_typeattr_224 base_typeattr_224 (ioctl ipx_socket (0x0)))
8224(neverallowx base_typeattr_224 base_typeattr_224 (ioctl netrom_socket (0x0)))
8225(neverallowx base_typeattr_224 base_typeattr_224 (ioctl atmpvc_socket (0x0)))
8226(neverallowx base_typeattr_224 base_typeattr_224 (ioctl x25_socket (0x0)))
8227(neverallowx base_typeattr_224 base_typeattr_224 (ioctl rose_socket (0x0)))
8228(neverallowx base_typeattr_224 base_typeattr_224 (ioctl decnet_socket (0x0)))
8229(neverallowx base_typeattr_224 base_typeattr_224 (ioctl atmsvc_socket (0x0)))
8230(neverallowx base_typeattr_224 base_typeattr_224 (ioctl rds_socket (0x0)))
8231(neverallowx base_typeattr_224 base_typeattr_224 (ioctl irda_socket (0x0)))
8232(neverallowx base_typeattr_224 base_typeattr_224 (ioctl pppox_socket (0x0)))
8233(neverallowx base_typeattr_224 base_typeattr_224 (ioctl llc_socket (0x0)))
8234(neverallowx base_typeattr_224 base_typeattr_224 (ioctl can_socket (0x0)))
8235(neverallowx base_typeattr_224 base_typeattr_224 (ioctl tipc_socket (0x0)))
8236(neverallowx base_typeattr_224 base_typeattr_224 (ioctl bluetooth_socket (0x0)))
8237(neverallowx base_typeattr_224 base_typeattr_224 (ioctl iucv_socket (0x0)))
8238(neverallowx base_typeattr_224 base_typeattr_224 (ioctl rxrpc_socket (0x0)))
8239(neverallowx base_typeattr_224 base_typeattr_224 (ioctl isdn_socket (0x0)))
8240(neverallowx base_typeattr_224 base_typeattr_224 (ioctl phonet_socket (0x0)))
8241(neverallowx base_typeattr_224 base_typeattr_224 (ioctl ieee802154_socket (0x0)))
8242(neverallowx base_typeattr_224 base_typeattr_224 (ioctl caif_socket (0x0)))
8243(neverallowx base_typeattr_224 base_typeattr_224 (ioctl alg_socket (0x0)))
8244(neverallowx base_typeattr_224 base_typeattr_224 (ioctl nfc_socket (0x0)))
8245(neverallowx base_typeattr_224 base_typeattr_224 (ioctl vsock_socket (0x0)))
8246(neverallowx base_typeattr_224 base_typeattr_224 (ioctl kcm_socket (0x0)))
8247(neverallowx base_typeattr_224 base_typeattr_224 (ioctl qipcrtr_socket (0x0)))
8248(neverallowx base_typeattr_224 base_typeattr_224 (ioctl smc_socket (0x0)))
8249(neverallowx base_typeattr_224 base_typeattr_224 (ioctl xdp_socket (0x0)))
8250;;* lme
8251
8252;;* lmx 361 system/sepolicy/public/domain.te
8253
8254(neverallowx domain domain (ioctl socket (0x8905)))
8255(neverallowx domain domain (ioctl tcp_socket (0x8905)))
8256(neverallowx domain domain (ioctl udp_socket (0x8905)))
8257(neverallowx domain domain (ioctl rawip_socket (0x8905)))
8258(neverallowx domain domain (ioctl netlink_socket (0x8905)))
8259(neverallowx domain domain (ioctl packet_socket (0x8905)))
8260(neverallowx domain domain (ioctl key_socket (0x8905)))
8261(neverallowx domain domain (ioctl unix_stream_socket (0x8905)))
8262(neverallowx domain domain (ioctl unix_dgram_socket (0x8905)))
8263(neverallowx domain domain (ioctl netlink_route_socket (0x8905)))
8264(neverallowx domain domain (ioctl netlink_tcpdiag_socket (0x8905)))
8265(neverallowx domain domain (ioctl netlink_nflog_socket (0x8905)))
8266(neverallowx domain domain (ioctl netlink_xfrm_socket (0x8905)))
8267(neverallowx domain domain (ioctl netlink_selinux_socket (0x8905)))
8268(neverallowx domain domain (ioctl netlink_audit_socket (0x8905)))
8269(neverallowx domain domain (ioctl netlink_dnrt_socket (0x8905)))
8270(neverallowx domain domain (ioctl netlink_kobject_uevent_socket (0x8905)))
8271(neverallowx domain domain (ioctl appletalk_socket (0x8905)))
8272(neverallowx domain domain (ioctl tun_socket (0x8905)))
8273(neverallowx domain domain (ioctl netlink_iscsi_socket (0x8905)))
8274(neverallowx domain domain (ioctl netlink_fib_lookup_socket (0x8905)))
8275(neverallowx domain domain (ioctl netlink_connector_socket (0x8905)))
8276(neverallowx domain domain (ioctl netlink_netfilter_socket (0x8905)))
8277(neverallowx domain domain (ioctl netlink_generic_socket (0x8905)))
8278(neverallowx domain domain (ioctl netlink_scsitransport_socket (0x8905)))
8279(neverallowx domain domain (ioctl netlink_rdma_socket (0x8905)))
8280(neverallowx domain domain (ioctl netlink_crypto_socket (0x8905)))
8281(neverallowx domain domain (ioctl sctp_socket (0x8905)))
8282(neverallowx domain domain (ioctl icmp_socket (0x8905)))
8283(neverallowx domain domain (ioctl ax25_socket (0x8905)))
8284(neverallowx domain domain (ioctl ipx_socket (0x8905)))
8285(neverallowx domain domain (ioctl netrom_socket (0x8905)))
8286(neverallowx domain domain (ioctl atmpvc_socket (0x8905)))
8287(neverallowx domain domain (ioctl x25_socket (0x8905)))
8288(neverallowx domain domain (ioctl rose_socket (0x8905)))
8289(neverallowx domain domain (ioctl decnet_socket (0x8905)))
8290(neverallowx domain domain (ioctl atmsvc_socket (0x8905)))
8291(neverallowx domain domain (ioctl rds_socket (0x8905)))
8292(neverallowx domain domain (ioctl irda_socket (0x8905)))
8293(neverallowx domain domain (ioctl pppox_socket (0x8905)))
8294(neverallowx domain domain (ioctl llc_socket (0x8905)))
8295(neverallowx domain domain (ioctl can_socket (0x8905)))
8296(neverallowx domain domain (ioctl tipc_socket (0x8905)))
8297(neverallowx domain domain (ioctl bluetooth_socket (0x8905)))
8298(neverallowx domain domain (ioctl iucv_socket (0x8905)))
8299(neverallowx domain domain (ioctl rxrpc_socket (0x8905)))
8300(neverallowx domain domain (ioctl isdn_socket (0x8905)))
8301(neverallowx domain domain (ioctl phonet_socket (0x8905)))
8302(neverallowx domain domain (ioctl ieee802154_socket (0x8905)))
8303(neverallowx domain domain (ioctl caif_socket (0x8905)))
8304(neverallowx domain domain (ioctl alg_socket (0x8905)))
8305(neverallowx domain domain (ioctl nfc_socket (0x8905)))
8306(neverallowx domain domain (ioctl vsock_socket (0x8905)))
8307(neverallowx domain domain (ioctl kcm_socket (0x8905)))
8308(neverallowx domain domain (ioctl qipcrtr_socket (0x8905)))
8309(neverallowx domain domain (ioctl smc_socket (0x8905)))
8310(neverallowx domain domain (ioctl xdp_socket (0x8905)))
8311;;* lme
8312
8313;;* lmx 366 system/sepolicy/public/domain.te
8314
8315(neverallowx base_typeattr_224 devpts (ioctl chr_file (0x5412)))
8316;;* lme
8317
8318;;* lmx 369 system/sepolicy/public/domain.te
8319
8320(neverallow base_typeattr_252 unlabeled (file (create)))
8321(neverallow base_typeattr_252 unlabeled (dir (create)))
8322(neverallow base_typeattr_252 unlabeled (lnk_file (create)))
8323(neverallow base_typeattr_252 unlabeled (chr_file (create)))
8324(neverallow base_typeattr_252 unlabeled (blk_file (create)))
8325(neverallow base_typeattr_252 unlabeled (sock_file (create)))
8326(neverallow base_typeattr_252 unlabeled (fifo_file (create)))
8327;;* lme
8328
8329;;* lmx 378 system/sepolicy/public/domain.te
8330
8331(neverallow base_typeattr_253 self (capability (mknod)))
8332(neverallow base_typeattr_253 self (cap_userns (mknod)))
8333;;* lme
8334
8335;;* lmx 381 system/sepolicy/public/domain.te
8336
8337(neverallow base_typeattr_224 self (memprotect (mmap_zero)))
8338;;* lme
8339
8340;;* lmx 384 system/sepolicy/public/domain.te
8341
8342(neverallow base_typeattr_224 self (capability2 (mac_override)))
8343(neverallow base_typeattr_224 self (cap2_userns (mac_override)))
8344;;* lme
8345
8346;;* lmx 389 system/sepolicy/public/domain.te
8347
8348(neverallow base_typeattr_224 self (capability2 (mac_admin)))
8349(neverallow base_typeattr_224 self (cap2_userns (mac_admin)))
8350;;* lme
8351
8352;;* lmx 393 system/sepolicy/public/domain.te
8353
8354(neverallow base_typeattr_224 kernel (security (load_policy)))
8355;;* lme
8356
8357;;* lmx 399 system/sepolicy/public/domain.te
8358
8359(neverallow base_typeattr_224 kernel (security (setenforce)))
8360;;* lme
8361
8362;;* lmx 400 system/sepolicy/public/domain.te
8363
8364(neverallow base_typeattr_254 kernel (security (setcheckreqprot)))
8365;;* lme
8366
8367;;* lmx 403 system/sepolicy/public/domain.te
8368
8369(neverallow base_typeattr_224 kernel (security (setbool)))
8370;;* lme
8371
8372;;* lmx 408 system/sepolicy/public/domain.te
8373
8374(neverallow base_typeattr_223 kernel (security (setsecparam)))
8375;;* lme
8376
8377;;* lmx 416 system/sepolicy/public/domain.te
8378
8379(neverallow base_typeattr_255 hw_random_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8380;;* lme
8381
8382;;* lmx 422 system/sepolicy/public/domain.te
8383
8384(neverallow base_typeattr_256 keychord_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8385;;* lme
8386
8387;;* lmx 425 system/sepolicy/public/domain.te
8388
8389(neverallow base_typeattr_224 base_typeattr_257 (file (entrypoint)))
8390;;* lme
8391
8392(dontaudit domain postinstall_mnt_dir (dir (audit_access)))
8393;;* lmx 437 system/sepolicy/public/domain.te
8394
8395(neverallow base_typeattr_256 port_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8396;;* lme
8397
8398;;* lmx 438 system/sepolicy/public/domain.te
8399
8400(neverallow base_typeattr_224 port_device (chr_file (ioctl read write lock relabelfrom append map link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8401;;* lme
8402
8403;;* lmx 441 system/sepolicy/public/domain.te
8404
8405(neverallow base_typeattr_223 usermodehelper (file (write append)))
8406;;* lme
8407
8408;;* lmx 442 system/sepolicy/public/domain.te
8409
8410(neverallow base_typeattr_258 sysfs_usermodehelper (file (write append)))
8411;;* lme
8412
8413;;* lmx 443 system/sepolicy/public/domain.te
8414
8415(neverallow base_typeattr_259 proc_security (file (read write append open)))
8416;;* lme
8417
8418;;* lmx 447 system/sepolicy/public/domain.te
8419
8420(neverallow base_typeattr_224 init (binder (impersonate call set_context_mgr transfer)))
8421;;* lme
8422
8423;;* lmx 448 system/sepolicy/public/domain.te
8424
8425(neverallow base_typeattr_224 vendor_init (binder (impersonate call set_context_mgr transfer)))
8426;;* lme
8427
8428;;* lmx 451 system/sepolicy/public/domain.te
8429
8430(neverallow base_typeattr_260 binderfs_logs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8431(neverallow base_typeattr_260 binderfs_logs_proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8432;;* lme
8433
8434;;* lmx 452 system/sepolicy/public/domain.te
8435
8436(neverallow base_typeattr_261 binderfs_logs_stats (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8437;;* lme
8438
8439;;* lmx 456 system/sepolicy/public/domain.te
8440
8441(neverallow base_typeattr_262 block_device (blk_file (read write open)))
8442;;* lme
8443
8444;;* lmx 461 system/sepolicy/public/domain.te
8445
8446(neverallow base_typeattr_224 base_typeattr_224 (chr_file (rename)))
8447(neverallow base_typeattr_224 base_typeattr_224 (blk_file (rename)))
8448;;* lme
8449
8450;;* lmx 465 system/sepolicy/public/domain.te
8451
8452(neverallow domain device (chr_file (read write open)))
8453;;* lme
8454
8455;;* lmx 468 system/sepolicy/public/domain.te
8456
8457(neverallow domain cache_file (file (execute)))
8458(neverallow domain cache_backup_file (file (execute)))
8459(neverallow domain cache_private_backup_file (file (execute)))
8460(neverallow domain cache_recovery_file (file (execute)))
8461;;* lme
8462
8463;;* lmx 471 system/sepolicy/public/domain.te
8464
8465(neverallow domain nativetest_data_file (file (write create setattr relabelfrom append unlink link rename)))
8466(neverallow domain nativetest_data_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
8467(neverallow domain nativetest_data_file (chr_file (write create setattr relabelfrom append unlink link rename)))
8468(neverallow domain nativetest_data_file (blk_file (write create setattr relabelfrom append unlink link rename)))
8469(neverallow domain nativetest_data_file (sock_file (write create setattr relabelfrom append unlink link rename)))
8470(neverallow domain nativetest_data_file (fifo_file (write create setattr relabelfrom append unlink link rename)))
8471;;* lme
8472
8473;;* lmx 472 system/sepolicy/public/domain.te
8474
8475(neverallow domain nativetest_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
8476;;* lme
8477
8478;;* lmx 473 system/sepolicy/public/domain.te
8479
8480(neverallow domain nativetest_data_file (file (execute execute_no_trans)))
8481;;* lme
8482
8483;;* lmx 475 system/sepolicy/public/domain.te
8484
8485(neverallow base_typeattr_263 shell_test_data_file (file (write create setattr relabelfrom append unlink link rename)))
8486(neverallow base_typeattr_263 shell_test_data_file (lnk_file (write create setattr relabelfrom append unlink link rename)))
8487(neverallow base_typeattr_263 shell_test_data_file (chr_file (write create setattr relabelfrom append unlink link rename)))
8488(neverallow base_typeattr_263 shell_test_data_file (blk_file (write create setattr relabelfrom append unlink link rename)))
8489(neverallow base_typeattr_263 shell_test_data_file (sock_file (write create setattr relabelfrom append unlink link rename)))
8490(neverallow base_typeattr_263 shell_test_data_file (fifo_file (write create setattr relabelfrom append unlink link rename)))
8491;;* lme
8492
8493;;* lmx 476 system/sepolicy/public/domain.te
8494
8495(neverallow base_typeattr_263 shell_test_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
8496;;* lme
8497
8498;;* lmx 477 system/sepolicy/public/domain.te
8499
8500(neverallow base_typeattr_264 shell_test_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8501;;* lme
8502
8503;;* lmx 478 system/sepolicy/public/domain.te
8504
8505(neverallow heapprofd shell_test_data_file (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
8506;;* lme
8507
8508;;* lmx 479 system/sepolicy/public/domain.te
8509
8510(neverallow base_typeattr_263 shell_test_data_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8511;;* lme
8512
8513;;* lmx 482 system/sepolicy/public/domain.te
8514
8515(neverallow base_typeattr_223 property_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
8516;;* lme
8517
8518;;* lmx 483 system/sepolicy/public/domain.te
8519
8520(neverallow base_typeattr_223 property_data_file (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
8521;;* lme
8522
8523;;* lmx 484 system/sepolicy/public/domain.te
8524
8525(neverallow base_typeattr_223 property_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
8526;;* lme
8527
8528;;* lmx 485 system/sepolicy/public/domain.te
8529
8530(neverallow base_typeattr_223 properties_device (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
8531;;* lme
8532
8533;;* lmx 486 system/sepolicy/public/domain.te
8534
8535(neverallow base_typeattr_223 properties_serial (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
8536;;* lme
8537
8538;;* lmx 500 system/sepolicy/public/domain.te
8539
8540(neverallow domain exec_type (file (write create setattr relabelfrom append unlink link rename)))
8541(neverallow domain exec_type (dir (write create setattr relabelfrom append unlink link rename)))
8542(neverallow domain exec_type (lnk_file (write create setattr relabelfrom append unlink link rename)))
8543(neverallow domain exec_type (chr_file (write create setattr relabelfrom append unlink link rename)))
8544(neverallow domain exec_type (blk_file (write create setattr relabelfrom append unlink link rename)))
8545(neverallow domain exec_type (sock_file (write create setattr relabelfrom append unlink link rename)))
8546(neverallow domain exec_type (fifo_file (write create setattr relabelfrom append unlink link rename)))
8547(neverallow domain system_file_type (file (write create setattr relabelfrom append unlink link rename)))
8548(neverallow domain system_file_type (dir (write create setattr relabelfrom append unlink link rename)))
8549(neverallow domain system_file_type (lnk_file (write create setattr relabelfrom append unlink link rename)))
8550(neverallow domain system_file_type (chr_file (write create setattr relabelfrom append unlink link rename)))
8551(neverallow domain system_file_type (blk_file (write create setattr relabelfrom append unlink link rename)))
8552(neverallow domain system_file_type (sock_file (write create setattr relabelfrom append unlink link rename)))
8553(neverallow domain system_file_type (fifo_file (write create setattr relabelfrom append unlink link rename)))
8554(neverallow domain vendor_file_type (file (write create setattr relabelfrom append unlink link rename)))
8555(neverallow domain vendor_file_type (dir (write create setattr relabelfrom append unlink link rename)))
8556(neverallow domain vendor_file_type (lnk_file (write create setattr relabelfrom append unlink link rename)))
8557(neverallow domain vendor_file_type (chr_file (write create setattr relabelfrom append unlink link rename)))
8558(neverallow domain vendor_file_type (blk_file (write create setattr relabelfrom append unlink link rename)))
8559(neverallow domain vendor_file_type (sock_file (write create setattr relabelfrom append unlink link rename)))
8560(neverallow domain vendor_file_type (fifo_file (write create setattr relabelfrom append unlink link rename)))
8561;;* lme
8562
8563;;* lmx 502 system/sepolicy/public/domain.te
8564
8565(neverallow base_typeattr_254 exec_type (file (relabelto)))
8566(neverallow base_typeattr_254 exec_type (dir (relabelto)))
8567(neverallow base_typeattr_254 exec_type (lnk_file (relabelto)))
8568(neverallow base_typeattr_254 exec_type (chr_file (relabelto)))
8569(neverallow base_typeattr_254 exec_type (blk_file (relabelto)))
8570(neverallow base_typeattr_254 exec_type (sock_file (relabelto)))
8571(neverallow base_typeattr_254 exec_type (fifo_file (relabelto)))
8572(neverallow base_typeattr_254 system_file_type (file (relabelto)))
8573(neverallow base_typeattr_254 system_file_type (dir (relabelto)))
8574(neverallow base_typeattr_254 system_file_type (lnk_file (relabelto)))
8575(neverallow base_typeattr_254 system_file_type (chr_file (relabelto)))
8576(neverallow base_typeattr_254 system_file_type (blk_file (relabelto)))
8577(neverallow base_typeattr_254 system_file_type (sock_file (relabelto)))
8578(neverallow base_typeattr_254 system_file_type (fifo_file (relabelto)))
8579(neverallow base_typeattr_254 vendor_file_type (file (relabelto)))
8580(neverallow base_typeattr_254 vendor_file_type (dir (relabelto)))
8581(neverallow base_typeattr_254 vendor_file_type (lnk_file (relabelto)))
8582(neverallow base_typeattr_254 vendor_file_type (chr_file (relabelto)))
8583(neverallow base_typeattr_254 vendor_file_type (blk_file (relabelto)))
8584(neverallow base_typeattr_254 vendor_file_type (sock_file (relabelto)))
8585(neverallow base_typeattr_254 vendor_file_type (fifo_file (relabelto)))
8586;;* lme
8587
8588;;* lmx 505 system/sepolicy/public/domain.te
8589
8590(neverallow base_typeattr_224 exec_type (file (mounton)))
8591(neverallow base_typeattr_224 exec_type (dir (mounton)))
8592(neverallow base_typeattr_224 exec_type (lnk_file (mounton)))
8593(neverallow base_typeattr_224 exec_type (chr_file (mounton)))
8594(neverallow base_typeattr_224 exec_type (blk_file (mounton)))
8595(neverallow base_typeattr_224 exec_type (sock_file (mounton)))
8596(neverallow base_typeattr_224 exec_type (fifo_file (mounton)))
8597;;* lme
8598
8599;;* lmx 508 system/sepolicy/public/domain.te
8600
8601(neverallow base_typeattr_224 rootfs (file (write create setattr relabelto append unlink link rename)))
8602;;* lme
8603
8604;;* lmx 512 system/sepolicy/public/domain.te
8605
8606(neverallow base_typeattr_224 base_typeattr_265 (filesystem (relabelto)))
8607;;* lme
8608
8609;;* lmx 518 system/sepolicy/public/domain.te
8610
8611(neverallow base_typeattr_224 contextmount_type (file (create setattr relabelfrom relabelto append link rename)))
8612(neverallow base_typeattr_224 contextmount_type (dir (create setattr relabelfrom relabelto append link rename)))
8613(neverallow base_typeattr_224 contextmount_type (lnk_file (create setattr relabelfrom relabelto append link rename)))
8614(neverallow base_typeattr_224 contextmount_type (chr_file (create setattr relabelfrom relabelto append link rename)))
8615(neverallow base_typeattr_224 contextmount_type (blk_file (create setattr relabelfrom relabelto append link rename)))
8616(neverallow base_typeattr_224 contextmount_type (sock_file (create setattr relabelfrom relabelto append link rename)))
8617(neverallow base_typeattr_224 contextmount_type (fifo_file (create setattr relabelfrom relabelto append link rename)))
8618;;* lme
8619
8620;;* lmx 519 system/sepolicy/public/domain.te
8621
8622(neverallow domain contextmount_type (file (write unlink)))
8623(neverallow domain contextmount_type (dir (write unlink)))
8624(neverallow domain contextmount_type (lnk_file (write unlink)))
8625(neverallow domain contextmount_type (chr_file (write unlink)))
8626(neverallow domain contextmount_type (blk_file (write unlink)))
8627(neverallow domain contextmount_type (sock_file (write unlink)))
8628(neverallow domain contextmount_type (fifo_file (write unlink)))
8629;;* lme
8630
8631;;* lmx 526 system/sepolicy/public/domain.te
8632
8633(neverallow base_typeattr_224 default_android_service (service_manager (add find list)))
8634;;* lme
8635
8636;;* lmx 527 system/sepolicy/public/domain.te
8637
8638(neverallow base_typeattr_224 default_android_vndservice (service_manager (add find list)))
8639;;* lme
8640
8641;;* lmx 528 system/sepolicy/public/domain.te
8642
8643(neverallow base_typeattr_224 default_android_hwservice (hwservice_manager (add find list)))
8644;;* lme
8645
8646;;* lmx 537 system/sepolicy/public/domain.te
8647
8648(neverallow base_typeattr_224 hidl_base_hwservice (hwservice_manager (find)))
8649;;* lme
8650
8651;;* lmx 541 system/sepolicy/public/domain.te
8652
8653(neverallow base_typeattr_259 mmc_prop (property_service (set)))
8654;;* lme
8655
8656;;* lmx 542 system/sepolicy/public/domain.te
8657
8658(neverallow base_typeattr_259 vndk_prop (property_service (set)))
8659;;* lme
8660
8661;;* lmx 544 system/sepolicy/public/domain.te
8662
8663(neverallow base_typeattr_223 mmc_prop (property_service (set)))
8664;;* lme
8665
8666;;* lmx 544 system/sepolicy/public/domain.te
8667
8668(neverallow base_typeattr_259 exported_default_prop (property_service (set)))
8669;;* lme
8670
8671;;* lmx 544 system/sepolicy/public/domain.te
8672
8673(neverallow base_typeattr_223 exported_secure_prop (property_service (set)))
8674;;* lme
8675
8676;;* lmx 544 system/sepolicy/public/domain.te
8677
8678(neverallow base_typeattr_259 vendor_default_prop (property_service (set)))
8679;;* lme
8680
8681;;* lmx 544 system/sepolicy/public/domain.te
8682
8683(neverallow base_typeattr_259 storage_config_prop (property_service (set)))
8684;;* lme
8685
8686;;* lmx 544 system/sepolicy/public/domain.te
8687
8688(neverallow base_typeattr_259 hw_timeout_multiplier_prop (property_service (set)))
8689;;* lme
8690
8691;;* lmx 553 system/sepolicy/public/domain.te
8692
8693(neverallow base_typeattr_266 exported_pm_prop (property_service (set)))
8694;;* lme
8695
8696;;* lmx 553 system/sepolicy/public/domain.te
8697
8698(neverallow base_typeattr_267 exported_pm_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8699;;* lme
8700
8701;;* lmx 559 system/sepolicy/public/domain.te
8702
8703(neverallow base_typeattr_260 future_pm_prop (property_service (set)))
8704;;* lme
8705
8706;;* lmx 560 system/sepolicy/public/domain.te
8707
8708(neverallow base_typeattr_260 future_pm_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8709;;* lme
8710
8711(dontaudit domain future_pm_prop (file (read)))
8712;;* lmx 566 system/sepolicy/public/domain.te
8713
8714(neverallow base_typeattr_223 aac_drc_prop (property_service (set)))
8715;;* lme
8716
8717;;* lmx 567 system/sepolicy/public/domain.te
8718
8719(neverallow base_typeattr_223 build_prop (property_service (set)))
8720;;* lme
8721
8722;;* lmx 568 system/sepolicy/public/domain.te
8723
8724(neverallow base_typeattr_223 userdebug_or_eng_prop (property_service (set)))
8725;;* lme
8726
8727;;* lmx 589 system/sepolicy/public/domain.te
8728
8729(neverallow base_typeattr_268 serialno_prop (file (ioctl read getattr lock map open watch watch_reads)))
8730;;* lme
8731
8732;;* lmx 597 system/sepolicy/public/domain.te
8733
8734(neverallow base_typeattr_269 frp_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8735;;* lme
8736
8737;;* lmx 611 system/sepolicy/public/domain.te
8738
8739(neverallow base_typeattr_270 metadata_block_device (blk_file (ioctl read write lock append link rename open)))
8740;;* lme
8741
8742;;* lmx 621 system/sepolicy/public/domain.te
8743
8744(neverallow base_typeattr_271 system_block_device (blk_file (write append)))
8745;;* lme
8746
8747;;* lmx 624 system/sepolicy/public/domain.te
8748
8749(neverallow base_typeattr_272 base_typeattr_224 (binder (set_context_mgr)))
8750;;* lme
8751
8752;;* lmx 626 system/sepolicy/public/domain.te
8753
8754(neverallow servicemanager hwbinder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8755;;* lme
8756
8757;;* lmx 627 system/sepolicy/public/domain.te
8758
8759(neverallow servicemanager vndbinder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8760;;* lme
8761
8762;;* lmx 628 system/sepolicy/public/domain.te
8763
8764(neverallow hwservicemanager binder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8765;;* lme
8766
8767;;* lmx 629 system/sepolicy/public/domain.te
8768
8769(neverallow hwservicemanager vndbinder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8770;;* lme
8771
8772;;* lmx 630 system/sepolicy/public/domain.te
8773
8774(neverallow vndservicemanager binder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8775;;* lme
8776
8777;;* lmx 631 system/sepolicy/public/domain.te
8778
8779(neverallow vndservicemanager hwbinder_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
8780;;* lme
8781
8782;;* lmx 633 system/sepolicy/public/domain.te
8783
8784(neverallow base_typeattr_273 base_typeattr_274 (service_manager (find)))
8785;;* lme
8786
8787;;* lmx 670 system/sepolicy/public/domain.te
8788
8789(neverallow base_typeattr_275 vndbinder_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
8790;;* lme
8791
8792;;* lmx 678 system/sepolicy/public/domain.te
8793
8794(neverallow ueventd vndbinder_device (chr_file (ioctl read write append)))
8795;;* lme
8796
8797;;* lmx 681 system/sepolicy/public/domain.te
8798
8799(neverallow base_typeattr_276 vndservice_manager_type (service_manager (add find list)))
8800;;* lme
8801
8802;;* lmx 688 system/sepolicy/public/domain.te
8803
8804(neverallow base_typeattr_276 vndservicemanager (binder (impersonate call set_context_mgr transfer)))
8805;;* lme
8806
8807;;* lmx 705 system/sepolicy/public/domain.te
8808
8809(neverallow base_typeattr_277 base_typeattr_278 (socket (connect sendto)))
8810(neverallow base_typeattr_277 base_typeattr_278 (tcp_socket (connect sendto)))
8811(neverallow base_typeattr_277 base_typeattr_278 (udp_socket (connect sendto)))
8812(neverallow base_typeattr_277 base_typeattr_278 (rawip_socket (connect sendto)))
8813(neverallow base_typeattr_277 base_typeattr_278 (netlink_socket (connect sendto)))
8814(neverallow base_typeattr_277 base_typeattr_278 (packet_socket (connect sendto)))
8815(neverallow base_typeattr_277 base_typeattr_278 (key_socket (connect sendto)))
8816(neverallow base_typeattr_277 base_typeattr_278 (unix_stream_socket (connect sendto)))
8817(neverallow base_typeattr_277 base_typeattr_278 (unix_dgram_socket (connect sendto)))
8818(neverallow base_typeattr_277 base_typeattr_278 (netlink_route_socket (connect sendto)))
8819(neverallow base_typeattr_277 base_typeattr_278 (netlink_tcpdiag_socket (connect sendto)))
8820(neverallow base_typeattr_277 base_typeattr_278 (netlink_nflog_socket (connect sendto)))
8821(neverallow base_typeattr_277 base_typeattr_278 (netlink_xfrm_socket (connect sendto)))
8822(neverallow base_typeattr_277 base_typeattr_278 (netlink_selinux_socket (connect sendto)))
8823(neverallow base_typeattr_277 base_typeattr_278 (netlink_audit_socket (connect sendto)))
8824(neverallow base_typeattr_277 base_typeattr_278 (netlink_dnrt_socket (connect sendto)))
8825(neverallow base_typeattr_277 base_typeattr_278 (netlink_kobject_uevent_socket (connect sendto)))
8826(neverallow base_typeattr_277 base_typeattr_278 (appletalk_socket (connect sendto)))
8827(neverallow base_typeattr_277 base_typeattr_278 (tun_socket (connect sendto)))
8828(neverallow base_typeattr_277 base_typeattr_278 (netlink_iscsi_socket (connect sendto)))
8829(neverallow base_typeattr_277 base_typeattr_278 (netlink_fib_lookup_socket (connect sendto)))
8830(neverallow base_typeattr_277 base_typeattr_278 (netlink_connector_socket (connect sendto)))
8831(neverallow base_typeattr_277 base_typeattr_278 (netlink_netfilter_socket (connect sendto)))
8832(neverallow base_typeattr_277 base_typeattr_278 (netlink_generic_socket (connect sendto)))
8833(neverallow base_typeattr_277 base_typeattr_278 (netlink_scsitransport_socket (connect sendto)))
8834(neverallow base_typeattr_277 base_typeattr_278 (netlink_rdma_socket (connect sendto)))
8835(neverallow base_typeattr_277 base_typeattr_278 (netlink_crypto_socket (connect sendto)))
8836(neverallow base_typeattr_277 base_typeattr_278 (sctp_socket (connect sendto)))
8837(neverallow base_typeattr_277 base_typeattr_278 (icmp_socket (connect sendto)))
8838(neverallow base_typeattr_277 base_typeattr_278 (ax25_socket (connect sendto)))
8839(neverallow base_typeattr_277 base_typeattr_278 (ipx_socket (connect sendto)))
8840(neverallow base_typeattr_277 base_typeattr_278 (netrom_socket (connect sendto)))
8841(neverallow base_typeattr_277 base_typeattr_278 (atmpvc_socket (connect sendto)))
8842(neverallow base_typeattr_277 base_typeattr_278 (x25_socket (connect sendto)))
8843(neverallow base_typeattr_277 base_typeattr_278 (rose_socket (connect sendto)))
8844(neverallow base_typeattr_277 base_typeattr_278 (decnet_socket (connect sendto)))
8845(neverallow base_typeattr_277 base_typeattr_278 (atmsvc_socket (connect sendto)))
8846(neverallow base_typeattr_277 base_typeattr_278 (rds_socket (connect sendto)))
8847(neverallow base_typeattr_277 base_typeattr_278 (irda_socket (connect sendto)))
8848(neverallow base_typeattr_277 base_typeattr_278 (pppox_socket (connect sendto)))
8849(neverallow base_typeattr_277 base_typeattr_278 (llc_socket (connect sendto)))
8850(neverallow base_typeattr_277 base_typeattr_278 (can_socket (connect sendto)))
8851(neverallow base_typeattr_277 base_typeattr_278 (tipc_socket (connect sendto)))
8852(neverallow base_typeattr_277 base_typeattr_278 (bluetooth_socket (connect sendto)))
8853(neverallow base_typeattr_277 base_typeattr_278 (iucv_socket (connect sendto)))
8854(neverallow base_typeattr_277 base_typeattr_278 (rxrpc_socket (connect sendto)))
8855(neverallow base_typeattr_277 base_typeattr_278 (isdn_socket (connect sendto)))
8856(neverallow base_typeattr_277 base_typeattr_278 (phonet_socket (connect sendto)))
8857(neverallow base_typeattr_277 base_typeattr_278 (ieee802154_socket (connect sendto)))
8858(neverallow base_typeattr_277 base_typeattr_278 (caif_socket (connect sendto)))
8859(neverallow base_typeattr_277 base_typeattr_278 (alg_socket (connect sendto)))
8860(neverallow base_typeattr_277 base_typeattr_278 (nfc_socket (connect sendto)))
8861(neverallow base_typeattr_277 base_typeattr_278 (vsock_socket (connect sendto)))
8862(neverallow base_typeattr_277 base_typeattr_278 (kcm_socket (connect sendto)))
8863(neverallow base_typeattr_277 base_typeattr_278 (qipcrtr_socket (connect sendto)))
8864(neverallow base_typeattr_277 base_typeattr_278 (smc_socket (connect sendto)))
8865(neverallow base_typeattr_277 base_typeattr_278 (xdp_socket (connect sendto)))
8866;;* lme
8867
8868;;* lmx 705 system/sepolicy/public/domain.te
8869
8870(neverallow base_typeattr_277 base_typeattr_278 (unix_stream_socket (connectto)))
8871;;* lme
8872
8873;;* lmx 718 system/sepolicy/public/domain.te
8874
8875(neverallow base_typeattr_279 core_data_file_type (sock_file (create setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8876(neverallow base_typeattr_279 coredomain_socket (sock_file (create setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8877(neverallow base_typeattr_279 unlabeled (sock_file (create setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8878;;* lme
8879
8880;;* lmx 732 system/sepolicy/public/domain.te
8881
8882(neverallow base_typeattr_273 base_typeattr_280 (sock_file (create setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8883;;* lme
8884
8885;;* lmx 748 system/sepolicy/public/domain.te
8886
8887(neverallow base_typeattr_281 base_typeattr_282 (sock_file (create setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8888;;* lme
8889
8890;;* lmx 772 system/sepolicy/public/domain.te
8891
8892(neverallow base_typeattr_283 base_typeattr_284 (file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8893(neverallow base_typeattr_283 base_typeattr_284 (lnk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8894(neverallow base_typeattr_283 base_typeattr_284 (chr_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8895(neverallow base_typeattr_283 base_typeattr_284 (blk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8896(neverallow base_typeattr_283 base_typeattr_284 (sock_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8897(neverallow base_typeattr_283 base_typeattr_284 (fifo_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8898;;* lme
8899
8900;;* lmx 787 system/sepolicy/public/domain.te
8901
8902(neverallow base_typeattr_283 base_typeattr_285 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
8903;;* lme
8904
8905;;* lmx 804 system/sepolicy/public/domain.te
8906
8907(neverallow base_typeattr_286 core_data_file_type (file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8908(neverallow base_typeattr_286 core_data_file_type (lnk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8909(neverallow base_typeattr_286 core_data_file_type (chr_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8910(neverallow base_typeattr_286 core_data_file_type (blk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8911(neverallow base_typeattr_286 core_data_file_type (sock_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8912(neverallow base_typeattr_286 core_data_file_type (fifo_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8913;;* lme
8914
8915;;* lmx 804 system/sepolicy/public/domain.te
8916
8917(neverallow base_typeattr_287 base_typeattr_288 (file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8918(neverallow base_typeattr_287 base_typeattr_288 (lnk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8919(neverallow base_typeattr_287 base_typeattr_288 (chr_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8920(neverallow base_typeattr_287 base_typeattr_288 (blk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8921(neverallow base_typeattr_287 base_typeattr_288 (sock_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8922(neverallow base_typeattr_287 base_typeattr_288 (fifo_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8923;;* lme
8924
8925;;* lmx 804 system/sepolicy/public/domain.te
8926
8927(neverallow vendor_init unencrypted_data_file (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
8928;;* lme
8929
8930;;* lmx 828 system/sepolicy/public/domain.te
8931
8932(neverallow base_typeattr_286 base_typeattr_289 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
8933;;* lme
8934
8935;;* lmx 828 system/sepolicy/public/domain.te
8936
8937(neverallow base_typeattr_287 base_typeattr_290 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
8938;;* lme
8939
8940;;* lmx 828 system/sepolicy/public/domain.te
8941
8942(neverallow vendor_init unencrypted_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
8943;;* lme
8944
8945;;* lmx 860 system/sepolicy/public/domain.te
8946
8947(neverallow base_typeattr_291 system_data_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
8948;;* lme
8949
8950;;* lmx 872 system/sepolicy/public/domain.te
8951
8952(neverallow base_typeattr_292 vendor_data_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
8953;;* lme
8954
8955;;* lmx 885 system/sepolicy/public/domain.te
8956
8957(neverallow base_typeattr_293 vendor_data_file (file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8958(neverallow base_typeattr_293 vendor_data_file (lnk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8959(neverallow base_typeattr_293 vendor_data_file (chr_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8960(neverallow base_typeattr_293 vendor_data_file (blk_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8961(neverallow base_typeattr_293 vendor_data_file (sock_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8962(neverallow base_typeattr_293 vendor_data_file (fifo_file (create setattr lock relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
8963;;* lme
8964
8965;;* lmx 896 system/sepolicy/public/domain.te
8966
8967(neverallow base_typeattr_294 vendor_shell_exec (file (execute execute_no_trans)))
8968;;* lme
8969
8970;;* lmx 907 system/sepolicy/public/domain.te
8971
8972(neverallow base_typeattr_295 base_typeattr_296 (file (execute execute_no_trans entrypoint)))
8973;;* lme
8974
8975;;* lmx 929 system/sepolicy/public/domain.te
8976
8977(neverallow coredomain base_typeattr_297 (file (entrypoint)))
8978;;* lme
8979
8980;;* lmx 929 system/sepolicy/public/domain.te
8981
8982(neverallow base_typeattr_250 base_typeattr_298 (file (entrypoint)))
8983;;* lme
8984
8985;;* lmx 946 system/sepolicy/public/domain.te
8986
8987(neverallow base_typeattr_299 base_typeattr_300 (file (execute)))
8988;;* lme
8989
8990;;* lmx 965 system/sepolicy/public/domain.te
8991
8992(neverallow base_typeattr_301 base_typeattr_302 (file (execute_no_trans)))
8993;;* lme
8994
8995;;* lmx 976 system/sepolicy/public/domain.te
8996
8997(neverallow base_typeattr_295 base_typeattr_303 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
8998;;* lme
8999
9000;;* lmx 1013 system/sepolicy/public/domain.te
9001
9002(neverallow base_typeattr_304 zygote (unix_stream_socket (connectto)))
9003;;* lme
9004
9005;;* lmx 1014 system/sepolicy/public/domain.te
9006
9007(neverallow base_typeattr_305 zygote_socket (sock_file (write)))
9008;;* lme
9009
9010;;* lmx 1016 system/sepolicy/public/domain.te
9011
9012(neverallow base_typeattr_306 webview_zygote (unix_stream_socket (connectto)))
9013;;* lme
9014
9015;;* lmx 1017 system/sepolicy/public/domain.te
9016
9017(neverallow base_typeattr_305 webview_zygote (sock_file (write)))
9018;;* lme
9019
9020;;* lmx 1018 system/sepolicy/public/domain.te
9021
9022(neverallow base_typeattr_305 app_zygote (sock_file (write)))
9023;;* lme
9024
9025;;* lmx 1020 system/sepolicy/public/domain.te
9026
9027(neverallow domain tombstoned_crash_socket (unix_stream_socket (connectto)))
9028;;* lme
9029
9030;;* lmx 1024 system/sepolicy/public/domain.te
9031
9032(neverallow base_typeattr_307 tombstoned_intercept_socket (sock_file (write)))
9033;;* lme
9034
9035;;* lmx 1025 system/sepolicy/public/domain.te
9036
9037(neverallow base_typeattr_307 tombstoned_intercept_socket (unix_stream_socket (connectto)))
9038;;* lme
9039
9040;;* lmx 1028 system/sepolicy/public/domain.te
9041
9042(neverallow base_typeattr_308 heapdump_data_file (file (read)))
9043;;* lme
9044
9045;;* lmx 1046 system/sepolicy/public/domain.te
9046
9047(neverallow base_typeattr_224 base_typeattr_224 (sem (create destroy getattr setattr read write associate unix_read unix_write)))
9048(neverallow base_typeattr_224 base_typeattr_224 (msg (send receive)))
9049(neverallow base_typeattr_224 base_typeattr_224 (msgq (create destroy getattr setattr read write associate unix_read unix_write enqueue)))
9050(neverallow base_typeattr_224 base_typeattr_224 (shm (create destroy getattr setattr read write associate unix_read unix_write lock)))
9051;;* lme
9052
9053;;* lmx 1050 system/sepolicy/public/domain.te
9054
9055(neverallow base_typeattr_224 dev_type (lnk_file (mounton)))
9056(neverallow base_typeattr_224 dev_type (sock_file (mounton)))
9057(neverallow base_typeattr_224 dev_type (fifo_file (mounton)))
9058(neverallow base_typeattr_224 fs_type (lnk_file (mounton)))
9059(neverallow base_typeattr_224 fs_type (sock_file (mounton)))
9060(neverallow base_typeattr_224 fs_type (fifo_file (mounton)))
9061(neverallow base_typeattr_224 file_type (lnk_file (mounton)))
9062(neverallow base_typeattr_224 file_type (sock_file (mounton)))
9063(neverallow base_typeattr_224 file_type (fifo_file (mounton)))
9064;;* lme
9065
9066;;* lmx 1055 system/sepolicy/public/domain.te
9067
9068(neverallow domain su_exec (file (execute execute_no_trans)))
9069;;* lme
9070
9071;;* lmx 1067 system/sepolicy/public/domain.te
9072
9073(neverallow base_typeattr_224 base_typeattr_309 (file (execmod)))
9074;;* lme
9075
9076;;* lmx 1072 system/sepolicy/public/domain.te
9077
9078(neverallow base_typeattr_224 self (process (execstack execheap)))
9079;;* lme
9080
9081;;* lmx 1076 system/sepolicy/public/domain.te
9082
9083(neverallow base_typeattr_310 file_type (file (execmod)))
9084;;* lme
9085
9086;;* lmx 1078 system/sepolicy/public/domain.te
9087
9088(neverallow base_typeattr_223 proc (file (mounton)))
9089(neverallow base_typeattr_223 proc (dir (mounton)))
9090;;* lme
9091
9092;;* lmx 1079 system/sepolicy/public/domain.te
9093
9094(neverallow base_typeattr_311 proc_type (file (mounton)))
9095(neverallow base_typeattr_311 proc_type (dir (mounton)))
9096;;* lme
9097
9098;;* lmx 1087 system/sepolicy/public/domain.te
9099
9100(neverallow base_typeattr_312 domain (process (transition dyntransition)))
9101;;* lme
9102
9103;;* lmx 1106 system/sepolicy/public/domain.te
9104
9105(neverallow base_typeattr_313 system_data_file (file (write create setattr relabelfrom append unlink link rename)))
9106;;* lme
9107
9108;;* lmx 1109 system/sepolicy/public/domain.te
9109
9110(neverallow installd system_data_file (file (write create setattr relabelto append link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
9111;;* lme
9112
9113;;* lmx 1122 system/sepolicy/public/domain.te
9114
9115(neverallow base_typeattr_314 shell (process (transition dyntransition)))
9116;;* lme
9117
9118;;* lmx 1129 system/sepolicy/public/domain.te
9119
9120(neverallow base_typeattr_315 base_typeattr_316 (process (transition dyntransition)))
9121;;* lme
9122
9123;;* lmx 1138 system/sepolicy/public/domain.te
9124
9125(neverallow base_typeattr_317 app_data_file (lnk_file (read)))
9126(neverallow base_typeattr_317 privapp_data_file (lnk_file (read)))
9127;;* lme
9128
9129;;* lmx 1145 system/sepolicy/public/domain.te
9130
9131(neverallow base_typeattr_318 shell_data_file (lnk_file (read)))
9132;;* lme
9133
9134;;* lmx 1152 system/sepolicy/public/domain.te
9135
9136(neverallow base_typeattr_224 base_typeattr_319 (service_manager (list)))
9137;;* lme
9138
9139;;* lmx 1157 system/sepolicy/public/domain.te
9140
9141(neverallow base_typeattr_224 base_typeattr_320 (hwservice_manager (list)))
9142;;* lme
9143
9144;;* lmx 1176 system/sepolicy/public/domain.te
9145
9146(neverallow base_typeattr_224 domain (file (execute execute_no_trans entrypoint)))
9147;;* lme
9148
9149;;* lmx 1182 system/sepolicy/public/domain.te
9150
9151(neverallow base_typeattr_260 debugfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9152(neverallow base_typeattr_260 debugfs (lnk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9153;;* lme
9154
9155;;* lmx 1185 system/sepolicy/public/domain.te
9156
9157(neverallow domain debugfs_type (file (execute execute_no_trans)))
9158;;* lme
9159
9160;;* lmx 1188 system/sepolicy/public/domain.te
9161
9162(neverallow base_typeattr_321 fusectlfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9163;;* lme
9164
9165;;* lmx 1197 system/sepolicy/public/domain.te
9166
9167(neverallow base_typeattr_322 profman_exec (file (execute execute_no_trans)))
9168;;* lme
9169
9170;;* lmx 1203 system/sepolicy/public/domain.te
9171
9172(neverallow base_typeattr_224 base_typeattr_323 (system (module_load)))
9173;;* lme
9174
9175;;* lmx 1207 system/sepolicy/public/domain.te
9176
9177(neverallow base_typeattr_224 self (capability (setfcap)))
9178(neverallow base_typeattr_224 self (cap_userns (setfcap)))
9179;;* lme
9180
9181;;* lmx 1210 system/sepolicy/public/domain.te
9182
9183(neverallow domain crash_dump (process (noatsecure)))
9184;;* lme
9185
9186;;* lmx 1214 system/sepolicy/public/domain.te
9187
9188(neverallow base_typeattr_324 coredomain_hwservice (hwservice_manager (add)))
9189;;* lme
9190
9191;;* lmx 1219 system/sepolicy/public/domain.te
9192
9193(neverallow base_typeattr_224 same_process_hwservice (hwservice_manager (add)))
9194;;* lme
9195
9196;;* lmx 1230 system/sepolicy/public/domain.te
9197
9198(neverallow domain proc_type (dir (write create link rename add_name remove_name reparent rmdir)))
9199(neverallow domain sysfs_type (dir (write create link rename add_name remove_name reparent rmdir)))
9200;;* lme
9201
9202;;* lmx 1233 system/sepolicy/public/domain.te
9203
9204(neverallow domain cgroup (file (create)))
9205;;* lme
9206
9207;;* lmx 1234 system/sepolicy/public/domain.te
9208
9209(neverallow domain cgroup_v2 (file (create)))
9210;;* lme
9211
9212(dontaudit domain proc_type (dir (write)))
9213(dontaudit domain sysfs_type (dir (write)))
9214(dontaudit domain cgroup (file (create)))
9215(dontaudit domain cgroup_v2 (file (create)))
9216;;* lmx 1257 system/sepolicy/public/domain.te
9217
9218(neverallow base_typeattr_325 mnt_vendor_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
9219;;* lme
9220
9221;;* lmx 1260 system/sepolicy/public/domain.te
9222
9223(neverallow base_typeattr_326 vendor_public_lib_file (file (execute execute_no_trans)))
9224(neverallow base_typeattr_326 vendor_public_framework_file (file (execute execute_no_trans)))
9225;;* lme
9226
9227;;* lmx 1271 system/sepolicy/public/domain.te
9228
9229(neverallow base_typeattr_250 mnt_product_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
9230;;* lme
9231
9232;;* lmx 1274 system/sepolicy/public/domain.te
9233
9234(neverallow base_typeattr_327 sysfs_batteryinfo (file (read open)))
9235;;* lme
9236
9237;;* lmx 1297 system/sepolicy/public/domain.te
9238
9239(neverallow base_typeattr_328 hal_codec2_hwservice (hwservice_manager (add)))
9240;;* lme
9241
9242;;* lmx 1306 system/sepolicy/public/domain.te
9243
9244(neverallow base_typeattr_329 ashmem_device (chr_file (open)))
9245;;* lme
9246
9247;;* lmx 1308 system/sepolicy/public/domain.te
9248
9249(neverallow base_typeattr_330 debugfs_tracing_printk_formats (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
9250;;* lme
9251
9252(allow drmserver servicemanager (binder (call transfer)))
9253(allow servicemanager drmserver (binder (call transfer)))
9254(allow servicemanager drmserver (dir (search)))
9255(allow servicemanager drmserver (file (read open)))
9256(allow servicemanager drmserver (process (getattr)))
9257(allow drmserver system_server (binder (call transfer)))
9258(allow system_server drmserver (binder (transfer)))
9259(allow drmserver system_server (fd (use)))
9260(allow drmserver appdomain (binder (call transfer)))
9261(allow appdomain drmserver (binder (transfer)))
9262(allow drmserver appdomain (fd (use)))
9263(allow drmserver mediametrics (binder (call transfer)))
9264(allow mediametrics drmserver (binder (transfer)))
9265(allow drmserver mediametrics (fd (use)))
9266(allow drmserver system_server (fd (use)))
9267(allow drmserver mediaserver (binder (call transfer)))
9268(allow mediaserver drmserver (binder (transfer)))
9269(allow drmserver mediaserver (fd (use)))
9270(allow drmserver sdcard_type (dir (search)))
9271(allow drmserver fuse (dir (search)))
9272(allow drmserver drm_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
9273(allow drmserver drm_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9274(allow drmserver app_data_file (file (read write getattr map)))
9275(allow drmserver privapp_data_file (file (read write getattr map)))
9276(allow drmserver sdcard_type (file (read write getattr map)))
9277(allow drmserver fuse (file (read write getattr map)))
9278(allow drmserver efs_file (dir (ioctl read getattr lock open watch watch_reads search)))
9279(allow drmserver efs_file (file (ioctl read getattr lock map open watch watch_reads)))
9280(allow drmserver efs_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9281(allow drmserver apk_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
9282(auditallow drmserver apk_data_file (dir (write add_name)))
9283(allow drmserver drmserver_socket (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9284(auditallow drmserver drmserver_socket (sock_file (create)))
9285(allow drmserver apk_data_file (sock_file (unlink)))
9286(allow drmserver media_rw_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9287(allow drmserver media_rw_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9288(allow drmserver media_rw_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9289(allow drmserver apk_data_file (file (read getattr map)))
9290(allow drmserver asec_apk_file (file (read getattr map)))
9291(allow drmserver ringtone_file (file (read getattr map)))
9292(allow drmserver radio_data_file (file (read getattr map)))
9293(allow drmserver oemfs (dir (search)))
9294(allow drmserver oemfs (file (ioctl read getattr lock map open watch watch_reads)))
9295(allow drmserver vendor_overlay_file (file (read map)))
9296(allow drmserver drmserver_service (service_manager (add find)))
9297;;* lmx 57 system/sepolicy/public/drmserver.te
9298
9299(neverallow base_typeattr_331 drmserver_service (service_manager (add)))
9300;;* lme
9301
9302(allow drmserver permission_service (service_manager (find)))
9303(allow drmserver mediametrics_service (service_manager (find)))
9304(allow drmserver selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
9305(allow drmserver selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
9306(allow drmserver selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9307(allow drmserver selinuxfs (file (write lock append map open)))
9308(allow drmserver kernel (security (compute_av)))
9309(allow drmserver self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
9310(allow drmserver cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
9311(allow drmserver cgroup (file (ioctl read getattr lock map open watch watch_reads)))
9312(allow drmserver cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9313(allow drmserver cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
9314(allow drmserver cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
9315(allow drmserver cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9316(allow drmserver system_file (dir (ioctl read getattr lock open watch watch_reads search)))
9317(allow drmserver system_file (file (ioctl read getattr lock map open watch watch_reads)))
9318(allow drmserver system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9319(allow dumpstate servicemanager (binder (call transfer)))
9320(allow servicemanager dumpstate (binder (call transfer)))
9321(allow servicemanager dumpstate (dir (search)))
9322(allow servicemanager dumpstate (file (read open)))
9323(allow servicemanager dumpstate (process (getattr)))
9324(allow dumpstate sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
9325(allow dumpstate self (capability2 (block_suspend)))
9326(allow dumpstate self (cap2_userns (block_suspend)))
9327(allow dumpstate system_suspend_server (binder (call transfer)))
9328(allow system_suspend_server dumpstate (binder (transfer)))
9329(allow dumpstate system_suspend_server (fd (use)))
9330(allow dumpstate system_suspend_hwservice (hwservice_manager (find)))
9331(allow dumpstate hwservicemanager (binder (call transfer)))
9332(allow hwservicemanager dumpstate (binder (call transfer)))
9333(allow hwservicemanager dumpstate (dir (search)))
9334(allow hwservicemanager dumpstate (file (read map open)))
9335(allow hwservicemanager dumpstate (process (getattr)))
9336(allow dumpstate hwservicemanager_prop (file (read getattr map open)))
9337(allow dumpstate hidl_manager_hwservice (hwservice_manager (find)))
9338(allow dumpstate hal_system_suspend_service (service_manager (find)))
9339(allow dumpstate servicemanager (binder (call transfer)))
9340(allow servicemanager dumpstate (binder (call transfer)))
9341(allow servicemanager dumpstate (dir (search)))
9342(allow servicemanager dumpstate (file (read open)))
9343(allow servicemanager dumpstate (process (getattr)))
9344(allow dumpstate self (capability (setgid setuid sys_resource)))
9345(allow dumpstate self (cap_userns (setgid setuid sys_resource)))
9346(allow dumpstate domain (dir (ioctl read getattr lock open watch watch_reads search)))
9347(allow dumpstate domain (file (ioctl read getattr lock map open watch watch_reads)))
9348(allow dumpstate domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9349(allow dumpstate self (capability (kill net_admin net_raw)))
9350(allow dumpstate self (cap_userns (kill net_admin net_raw)))
9351(allow dumpstate system_file (file (execute_no_trans)))
9352(allow dumpstate toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9353(allow dumpstate system_file (dir (ioctl read getattr lock open watch watch_reads search)))
9354(allow dumpstate self (capability (chown dac_override dac_read_search fowner fsetid)))
9355(allow dumpstate self (cap_userns (chown dac_override dac_read_search fowner fsetid)))
9356(allow dumpstate anr_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
9357(allow dumpstate anr_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9358(allow dumpstate system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9359(allow dumpstate app_data_file (file (append)))
9360(allow dumpstate privapp_data_file (file (append)))
9361(allow dumpstate self (capability2 (syslog)))
9362(allow dumpstate self (cap2_userns (syslog)))
9363(allow dumpstate kernel (system (syslog_read)))
9364(allow dumpstate pstorefs (dir (ioctl read getattr lock open watch watch_reads search)))
9365(allow dumpstate pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
9366(allow dumpstate domain (process (getattr)))
9367(allow dumpstate appdomain (process (signal)))
9368(allow dumpstate app_zygote (process (signal)))
9369(allow dumpstate system_server (process (signal)))
9370(allow dumpstate zygote (process (signal)))
9371(allow dumpstate hal_audio_server (process (signal)))
9372(allow dumpstate hal_audiocontrol_server (process (signal)))
9373(allow dumpstate hal_bluetooth_server (process (signal)))
9374(allow dumpstate hal_broadcastradio_server (process (signal)))
9375(allow dumpstate hal_camera_server (process (signal)))
9376(allow dumpstate hal_codec2_server (process (signal)))
9377(allow dumpstate hal_drm_server (process (signal)))
9378(allow dumpstate hal_evs_server (process (signal)))
9379(allow dumpstate hal_face_server (process (signal)))
9380(allow dumpstate hal_fingerprint_server (process (signal)))
9381(allow dumpstate hal_graphics_allocator_server (process (signal)))
9382(allow dumpstate hal_graphics_composer_server (process (signal)))
9383(allow dumpstate hal_health_server (process (signal)))
9384(allow dumpstate hal_input_processor_server (process (signal)))
9385(allow dumpstate hal_neuralnetworks_server (process (signal)))
9386(allow dumpstate hal_omx_server (process (signal)))
9387(allow dumpstate hal_power_server (process (signal)))
9388(allow dumpstate hal_power_stats_server (process (signal)))
9389(allow dumpstate hal_sensors_server (process (signal)))
9390(allow dumpstate hal_thermal_server (process (signal)))
9391(allow dumpstate hal_vehicle_server (process (signal)))
9392(allow dumpstate hal_vr_server (process (signal)))
9393(allow dumpstate system_suspend_server (process (signal)))
9394(allow dumpstate audioserver (process (signal)))
9395(allow dumpstate cameraserver (process (signal)))
9396(allow dumpstate drmserver (process (signal)))
9397(allow dumpstate evsmanagerd (process (signal)))
9398(allow dumpstate inputflinger (process (signal)))
9399(allow dumpstate mediadrmserver (process (signal)))
9400(allow dumpstate mediaextractor (process (signal)))
9401(allow dumpstate mediametrics (process (signal)))
9402(allow dumpstate mediaserver (process (signal)))
9403(allow dumpstate mediaswcodec (process (signal)))
9404(allow dumpstate sdcardd (process (signal)))
9405(allow dumpstate surfaceflinger (process (signal)))
9406(allow dumpstate vold (process (signal)))
9407(allow dumpstate tombstoned_intercept_socket (sock_file (write)))
9408(allow dumpstate tombstoned (unix_stream_socket (connectto)))
9409(allow dumpstate sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
9410(allow dumpstate sysfs_devices_block (file (ioctl read getattr lock map open watch watch_reads)))
9411(allow dumpstate sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
9412(allow dumpstate sysfs_loop (file (ioctl read getattr lock map open watch watch_reads)))
9413(allow dumpstate sysfs_usb (file (ioctl read getattr lock map open watch watch_reads)))
9414(allow dumpstate sysfs_zram (file (ioctl read getattr lock map open watch watch_reads)))
9415(dontaudit dumpstate sysfs (file (ioctl read getattr lock map open watch watch_reads)))
9416(allow dumpstate block_device (dir (getattr search)))
9417(allow dumpstate rootfs (dir (getattr search)))
9418(allow dumpstate selinuxfs (dir (getattr search)))
9419(allow dumpstate tmpfs (dir (getattr search)))
9420(allow dumpstate metadata_file (dir (getattr search)))
9421(allow dumpstate storage_file (dir (getattr search)))
9422(allow dumpstate cache_file (dir (getattr search)))
9423(allow dumpstate fuse_device (chr_file (getattr)))
9424(allow dumpstate dm_device (blk_file (getattr)))
9425(allow dumpstate cache_block_device (blk_file (getattr)))
9426(allow dumpstate rootfs (lnk_file (read getattr)))
9427(allow dumpstate cache_file (lnk_file (read getattr)))
9428(allow dumpstate cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
9429(allow dumpstate cgroup (file (ioctl read getattr lock map open watch watch_reads)))
9430(allow dumpstate cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9431(allow dumpstate cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
9432(allow dumpstate cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
9433(allow dumpstate cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9434(allow dumpstate binderservicedomain (binder (call transfer)))
9435(allow binderservicedomain dumpstate (binder (transfer)))
9436(allow dumpstate binderservicedomain (fd (use)))
9437(allow dumpstate appdomain (binder (call transfer)))
9438(allow dumpstate artd (binder (call transfer)))
9439(allow dumpstate netd (binder (call transfer)))
9440(allow dumpstate wificond (binder (call transfer)))
9441(allow appdomain dumpstate (binder (transfer)))
9442(allow artd dumpstate (binder (transfer)))
9443(allow netd dumpstate (binder (transfer)))
9444(allow wificond dumpstate (binder (transfer)))
9445(allow dumpstate appdomain (fd (use)))
9446(allow dumpstate artd (fd (use)))
9447(allow dumpstate netd (fd (use)))
9448(allow dumpstate wificond (fd (use)))
9449(allow hal_audio_server dumpstate (fifo_file (write)))
9450(allow hal_audio_server dumpstate (fd (use)))
9451(allow hal_audiocontrol_server dumpstate (fifo_file (write)))
9452(allow hal_audiocontrol_server dumpstate (fd (use)))
9453(allow hal_authgraph_server dumpstate (fifo_file (write)))
9454(allow hal_authgraph_server dumpstate (fd (use)))
9455(allow hal_authsecret_server dumpstate (fifo_file (write)))
9456(allow hal_authsecret_server dumpstate (fd (use)))
9457(allow hal_bluetooth_server dumpstate (fifo_file (write)))
9458(allow hal_bluetooth_server dumpstate (fd (use)))
9459(allow hal_broadcastradio_server dumpstate (fifo_file (write)))
9460(allow hal_broadcastradio_server dumpstate (fd (use)))
9461(allow hal_camera_server dumpstate (fifo_file (write)))
9462(allow hal_camera_server dumpstate (fd (use)))
9463(allow hal_codec2_server dumpstate (fifo_file (write)))
9464(allow hal_codec2_server dumpstate (fd (use)))
9465(allow hal_contexthub_server dumpstate (fifo_file (write)))
9466(allow hal_contexthub_server dumpstate (fd (use)))
9467(allow hal_drm_server dumpstate (fifo_file (write)))
9468(allow hal_drm_server dumpstate (fd (use)))
9469(allow hal_dumpstate_server dumpstate (fifo_file (write)))
9470(allow hal_dumpstate_server dumpstate (fd (use)))
9471(allow hal_evs_server dumpstate (fifo_file (write)))
9472(allow hal_evs_server dumpstate (fd (use)))
9473(allow hal_face_server dumpstate (fifo_file (write)))
9474(allow hal_face_server dumpstate (fd (use)))
9475(allow hal_fingerprint_server dumpstate (fifo_file (write)))
9476(allow hal_fingerprint_server dumpstate (fd (use)))
9477(allow hal_gnss_server dumpstate (fifo_file (write)))
9478(allow hal_gnss_server dumpstate (fd (use)))
9479(allow hal_graphics_allocator_server dumpstate (fifo_file (write)))
9480(allow hal_graphics_allocator_server dumpstate (fd (use)))
9481(allow hal_graphics_composer_server dumpstate (fifo_file (write)))
9482(allow hal_graphics_composer_server dumpstate (fd (use)))
9483(allow hal_health_server dumpstate (fifo_file (write)))
9484(allow hal_health_server dumpstate (fd (use)))
9485(allow hal_identity_server dumpstate (fifo_file (write)))
9486(allow hal_identity_server dumpstate (fd (use)))
9487(allow hal_input_processor_server dumpstate (fifo_file (write)))
9488(allow hal_input_processor_server dumpstate (fd (use)))
9489(allow hal_keymint_server dumpstate (fifo_file (write)))
9490(allow hal_keymint_server dumpstate (fd (use)))
9491(allow hal_light_server dumpstate (fifo_file (write)))
9492(allow hal_light_server dumpstate (fd (use)))
9493(allow hal_memtrack_server dumpstate (fifo_file (write)))
9494(allow hal_memtrack_server dumpstate (fd (use)))
9495(allow hal_neuralnetworks_server dumpstate (fifo_file (write)))
9496(allow hal_neuralnetworks_server dumpstate (fd (use)))
9497(allow hal_nfc_server dumpstate (fifo_file (write)))
9498(allow hal_nfc_server dumpstate (fd (use)))
9499(allow hal_oemlock_server dumpstate (fifo_file (write)))
9500(allow hal_oemlock_server dumpstate (fd (use)))
9501(allow hal_power_server dumpstate (fifo_file (write)))
9502(allow hal_power_server dumpstate (fd (use)))
9503(allow hal_power_stats_server dumpstate (fifo_file (write)))
9504(allow hal_power_stats_server dumpstate (fd (use)))
9505(allow hal_rebootescrow_server dumpstate (fifo_file (write)))
9506(allow hal_rebootescrow_server dumpstate (fd (use)))
9507(allow hal_secretkeeper_server dumpstate (fifo_file (write)))
9508(allow hal_secretkeeper_server dumpstate (fd (use)))
9509(allow hal_sensors_server dumpstate (fifo_file (write)))
9510(allow hal_sensors_server dumpstate (fd (use)))
9511(allow hal_thermal_server dumpstate (fifo_file (write)))
9512(allow hal_thermal_server dumpstate (fd (use)))
9513(allow hal_vehicle_server dumpstate (fifo_file (write)))
9514(allow hal_vehicle_server dumpstate (fd (use)))
9515(allow hal_weaver_server dumpstate (fifo_file (write)))
9516(allow hal_weaver_server dumpstate (fd (use)))
9517(allow hal_wifi_server dumpstate (fifo_file (write)))
9518(allow hal_wifi_server dumpstate (fd (use)))
9519(allow dumpstate self (capability (sys_ptrace)))
9520(allow dumpstate self (cap_userns (sys_ptrace)))
9521(allow dumpstate shell_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
9522(allow dumpstate shell_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9523(allow dumpstate shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9524(allow dumpstate zygote_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9525(allow dumpstate bluetooth_data_file (dir (search)))
9526(allow dumpstate bluetooth_logs_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9527(allow dumpstate bluetooth_logs_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9528(allow dumpstate nfc_logs_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9529(allow dumpstate nfc_logs_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9530(allow dumpstate gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
9531(allow dumpstate gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
9532(allow dumpstate logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9533(allow dumpstate logdr_socket (sock_file (write)))
9534(allow dumpstate logd (unix_stream_socket (connectto)))
9535(allow dumpstate logd_socket (sock_file (write)))
9536(allow dumpstate logd (unix_stream_socket (connectto)))
9537(allow dumpstate runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
9538(allow dumpstate proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
9539(allow dumpstate proc_qtaguid_ctrl (file (ioctl read getattr lock map open watch watch_reads)))
9540(allow dumpstate proc_qtaguid_stat (file (ioctl read getattr lock map open watch watch_reads)))
9541(allow dumpstate proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
9542(allow dumpstate proc_buddyinfo (file (ioctl read getattr lock map open watch watch_reads)))
9543(allow dumpstate proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
9544(allow dumpstate proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
9545(allow dumpstate proc_modules (file (ioctl read getattr lock map open watch watch_reads)))
9546(allow dumpstate proc_pagetypeinfo (file (ioctl read getattr lock map open watch watch_reads)))
9547(allow dumpstate proc_pipe_conf (file (ioctl read getattr lock map open watch watch_reads)))
9548(allow dumpstate proc_slabinfo (file (ioctl read getattr lock map open watch watch_reads)))
9549(allow dumpstate proc_version (file (ioctl read getattr lock map open watch watch_reads)))
9550(allow dumpstate proc_vmallocinfo (file (ioctl read getattr lock map open watch watch_reads)))
9551(allow dumpstate proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
9552(allow dumpstate net_data_file (dir (search)))
9553(allow dumpstate net_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9554(allow dumpstate self (netlink_tcpdiag_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read)))
9555(allow dumpstate tombstone_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9556(allow dumpstate tombstone_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9557(allow dumpstate cache_recovery_file (dir (ioctl read getattr lock open watch watch_reads search)))
9558(allow dumpstate cache_recovery_file (file (ioctl read getattr lock map open watch watch_reads)))
9559(allow dumpstate recovery_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9560(allow dumpstate recovery_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9561(allow dumpstate update_engine_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9562(allow dumpstate update_engine_log_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9563(allow dumpstate update_engine_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9564(allow dumpstate update_engine_log_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9565(allow dumpstate snapuserd_log_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9566(allow dumpstate snapuserd_log_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9567(allow dumpstate misc_logd_file (dir (ioctl read getattr lock open watch watch_reads search)))
9568(allow dumpstate misc_logd_file (file (ioctl read getattr lock map open watch watch_reads)))
9569(allow dumpstate prereboot_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9570(allow dumpstate prereboot_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9571(allow dumpstate app_fuse_file (dir (ioctl read getattr lock open watch watch_reads search)))
9572(allow dumpstate overlayfs_file (dir (ioctl read getattr lock open watch watch_reads search)))
9573(allow dumpstate base_typeattr_332 (service_manager (find)))
9574(dontaudit dumpstate hal_service_type (service_manager (find)))
9575(dontaudit dumpstate apex_service (service_manager (find)))
9576(dontaudit dumpstate dumpstate_service (service_manager (find)))
9577(dontaudit dumpstate gatekeeper_service (service_manager (find)))
9578(dontaudit dumpstate virtual_touchpad_service (service_manager (find)))
9579(dontaudit dumpstate vold_service (service_manager (find)))
9580(dontaudit dumpstate hwservice_manager_type (hwservice_manager (find)))
9581(allow dumpstate servicemanager (service_manager (list)))
9582(allow dumpstate hwservicemanager (hwservice_manager (list)))
9583(allow dumpstate devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
9584(allow dumpstate property_type (file (read getattr map open)))
9585(allow dumpstate media_rw_data_file (dir (getattr)))
9586(allow dumpstate proc_interrupts (file (ioctl read getattr lock map open watch watch_reads)))
9587(allow dumpstate proc_zoneinfo (file (ioctl read getattr lock map open watch watch_reads)))
9588(allow dumpstate dumpstate_service (service_manager (add find)))
9589;;* lmx 324 system/sepolicy/public/dumpstate.te
9590
9591(neverallow base_typeattr_333 dumpstate_service (service_manager (add)))
9592;;* lme
9593
9594(allow dumpstate ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
9595(allow dumpstate proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
9596(allow dumpstate proc_pressure_cpu (file (ioctl read getattr lock map open watch watch_reads)))
9597(allow dumpstate proc_pressure_mem (file (ioctl read getattr lock map open watch watch_reads)))
9598(allow dumpstate proc_pressure_io (file (ioctl read getattr lock map open watch watch_reads)))
9599(allow dumpstate proc_pid_max (file (ioctl read getattr lock map open watch watch_reads)))
9600(allow dumpstate installd (binder (call transfer)))
9601(allow installd dumpstate (binder (transfer)))
9602(allow dumpstate installd (fd (use)))
9603(allow dumpstate self (netlink_xfrm_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read)))
9604(allow dumpstate self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
9605(allow dumpstate self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
9606(allow dumpstate domain (socket (getattr)))
9607(allow dumpstate domain (tcp_socket (getattr)))
9608(allow dumpstate domain (udp_socket (getattr)))
9609(allow dumpstate domain (rawip_socket (getattr)))
9610(allow dumpstate domain (netlink_socket (getattr)))
9611(allow dumpstate domain (packet_socket (getattr)))
9612(allow dumpstate domain (key_socket (getattr)))
9613(allow dumpstate domain (unix_stream_socket (getattr)))
9614(allow dumpstate domain (unix_dgram_socket (getattr)))
9615(allow dumpstate domain (netlink_route_socket (getattr)))
9616(allow dumpstate domain (netlink_tcpdiag_socket (getattr)))
9617(allow dumpstate domain (netlink_nflog_socket (getattr)))
9618(allow dumpstate domain (netlink_xfrm_socket (getattr)))
9619(allow dumpstate domain (netlink_selinux_socket (getattr)))
9620(allow dumpstate domain (netlink_audit_socket (getattr)))
9621(allow dumpstate domain (netlink_dnrt_socket (getattr)))
9622(allow dumpstate domain (netlink_kobject_uevent_socket (getattr)))
9623(allow dumpstate domain (appletalk_socket (getattr)))
9624(allow dumpstate domain (tun_socket (getattr)))
9625(allow dumpstate domain (netlink_iscsi_socket (getattr)))
9626(allow dumpstate domain (netlink_fib_lookup_socket (getattr)))
9627(allow dumpstate domain (netlink_connector_socket (getattr)))
9628(allow dumpstate domain (netlink_netfilter_socket (getattr)))
9629(allow dumpstate domain (netlink_generic_socket (getattr)))
9630(allow dumpstate domain (netlink_scsitransport_socket (getattr)))
9631(allow dumpstate domain (netlink_rdma_socket (getattr)))
9632(allow dumpstate domain (netlink_crypto_socket (getattr)))
9633(allow dumpstate domain (sctp_socket (getattr)))
9634(allow dumpstate domain (icmp_socket (getattr)))
9635(allow dumpstate domain (ax25_socket (getattr)))
9636(allow dumpstate domain (ipx_socket (getattr)))
9637(allow dumpstate domain (netrom_socket (getattr)))
9638(allow dumpstate domain (atmpvc_socket (getattr)))
9639(allow dumpstate domain (x25_socket (getattr)))
9640(allow dumpstate domain (rose_socket (getattr)))
9641(allow dumpstate domain (decnet_socket (getattr)))
9642(allow dumpstate domain (atmsvc_socket (getattr)))
9643(allow dumpstate domain (rds_socket (getattr)))
9644(allow dumpstate domain (irda_socket (getattr)))
9645(allow dumpstate domain (pppox_socket (getattr)))
9646(allow dumpstate domain (llc_socket (getattr)))
9647(allow dumpstate domain (can_socket (getattr)))
9648(allow dumpstate domain (tipc_socket (getattr)))
9649(allow dumpstate domain (bluetooth_socket (getattr)))
9650(allow dumpstate domain (iucv_socket (getattr)))
9651(allow dumpstate domain (rxrpc_socket (getattr)))
9652(allow dumpstate domain (isdn_socket (getattr)))
9653(allow dumpstate domain (phonet_socket (getattr)))
9654(allow dumpstate domain (ieee802154_socket (getattr)))
9655(allow dumpstate domain (caif_socket (getattr)))
9656(allow dumpstate domain (alg_socket (getattr)))
9657(allow dumpstate domain (nfc_socket (getattr)))
9658(allow dumpstate domain (vsock_socket (getattr)))
9659(allow dumpstate domain (kcm_socket (getattr)))
9660(allow dumpstate domain (qipcrtr_socket (getattr)))
9661(allow dumpstate domain (smc_socket (getattr)))
9662(allow dumpstate domain (xdp_socket (getattr)))
9663(allow dumpstate pdx_endpoint_socket_type (socket (getattr)))
9664(allow dumpstate pdx_endpoint_socket_type (tcp_socket (getattr)))
9665(allow dumpstate pdx_endpoint_socket_type (udp_socket (getattr)))
9666(allow dumpstate pdx_endpoint_socket_type (rawip_socket (getattr)))
9667(allow dumpstate pdx_endpoint_socket_type (netlink_socket (getattr)))
9668(allow dumpstate pdx_endpoint_socket_type (packet_socket (getattr)))
9669(allow dumpstate pdx_endpoint_socket_type (key_socket (getattr)))
9670(allow dumpstate pdx_endpoint_socket_type (unix_stream_socket (getattr)))
9671(allow dumpstate pdx_endpoint_socket_type (unix_dgram_socket (getattr)))
9672(allow dumpstate pdx_endpoint_socket_type (netlink_route_socket (getattr)))
9673(allow dumpstate pdx_endpoint_socket_type (netlink_tcpdiag_socket (getattr)))
9674(allow dumpstate pdx_endpoint_socket_type (netlink_nflog_socket (getattr)))
9675(allow dumpstate pdx_endpoint_socket_type (netlink_xfrm_socket (getattr)))
9676(allow dumpstate pdx_endpoint_socket_type (netlink_selinux_socket (getattr)))
9677(allow dumpstate pdx_endpoint_socket_type (netlink_audit_socket (getattr)))
9678(allow dumpstate pdx_endpoint_socket_type (netlink_dnrt_socket (getattr)))
9679(allow dumpstate pdx_endpoint_socket_type (netlink_kobject_uevent_socket (getattr)))
9680(allow dumpstate pdx_endpoint_socket_type (appletalk_socket (getattr)))
9681(allow dumpstate pdx_endpoint_socket_type (tun_socket (getattr)))
9682(allow dumpstate pdx_endpoint_socket_type (netlink_iscsi_socket (getattr)))
9683(allow dumpstate pdx_endpoint_socket_type (netlink_fib_lookup_socket (getattr)))
9684(allow dumpstate pdx_endpoint_socket_type (netlink_connector_socket (getattr)))
9685(allow dumpstate pdx_endpoint_socket_type (netlink_netfilter_socket (getattr)))
9686(allow dumpstate pdx_endpoint_socket_type (netlink_generic_socket (getattr)))
9687(allow dumpstate pdx_endpoint_socket_type (netlink_scsitransport_socket (getattr)))
9688(allow dumpstate pdx_endpoint_socket_type (netlink_rdma_socket (getattr)))
9689(allow dumpstate pdx_endpoint_socket_type (netlink_crypto_socket (getattr)))
9690(allow dumpstate pdx_endpoint_socket_type (sctp_socket (getattr)))
9691(allow dumpstate pdx_endpoint_socket_type (icmp_socket (getattr)))
9692(allow dumpstate pdx_endpoint_socket_type (ax25_socket (getattr)))
9693(allow dumpstate pdx_endpoint_socket_type (ipx_socket (getattr)))
9694(allow dumpstate pdx_endpoint_socket_type (netrom_socket (getattr)))
9695(allow dumpstate pdx_endpoint_socket_type (atmpvc_socket (getattr)))
9696(allow dumpstate pdx_endpoint_socket_type (x25_socket (getattr)))
9697(allow dumpstate pdx_endpoint_socket_type (rose_socket (getattr)))
9698(allow dumpstate pdx_endpoint_socket_type (decnet_socket (getattr)))
9699(allow dumpstate pdx_endpoint_socket_type (atmsvc_socket (getattr)))
9700(allow dumpstate pdx_endpoint_socket_type (rds_socket (getattr)))
9701(allow dumpstate pdx_endpoint_socket_type (irda_socket (getattr)))
9702(allow dumpstate pdx_endpoint_socket_type (pppox_socket (getattr)))
9703(allow dumpstate pdx_endpoint_socket_type (llc_socket (getattr)))
9704(allow dumpstate pdx_endpoint_socket_type (can_socket (getattr)))
9705(allow dumpstate pdx_endpoint_socket_type (tipc_socket (getattr)))
9706(allow dumpstate pdx_endpoint_socket_type (bluetooth_socket (getattr)))
9707(allow dumpstate pdx_endpoint_socket_type (iucv_socket (getattr)))
9708(allow dumpstate pdx_endpoint_socket_type (rxrpc_socket (getattr)))
9709(allow dumpstate pdx_endpoint_socket_type (isdn_socket (getattr)))
9710(allow dumpstate pdx_endpoint_socket_type (phonet_socket (getattr)))
9711(allow dumpstate pdx_endpoint_socket_type (ieee802154_socket (getattr)))
9712(allow dumpstate pdx_endpoint_socket_type (caif_socket (getattr)))
9713(allow dumpstate pdx_endpoint_socket_type (alg_socket (getattr)))
9714(allow dumpstate pdx_endpoint_socket_type (nfc_socket (getattr)))
9715(allow dumpstate pdx_endpoint_socket_type (vsock_socket (getattr)))
9716(allow dumpstate pdx_endpoint_socket_type (kcm_socket (getattr)))
9717(allow dumpstate pdx_endpoint_socket_type (qipcrtr_socket (getattr)))
9718(allow dumpstate pdx_endpoint_socket_type (smc_socket (getattr)))
9719(allow dumpstate pdx_endpoint_socket_type (xdp_socket (getattr)))
9720(allow dumpstate pdx_channel_socket_type (socket (getattr)))
9721(allow dumpstate pdx_channel_socket_type (tcp_socket (getattr)))
9722(allow dumpstate pdx_channel_socket_type (udp_socket (getattr)))
9723(allow dumpstate pdx_channel_socket_type (rawip_socket (getattr)))
9724(allow dumpstate pdx_channel_socket_type (netlink_socket (getattr)))
9725(allow dumpstate pdx_channel_socket_type (packet_socket (getattr)))
9726(allow dumpstate pdx_channel_socket_type (key_socket (getattr)))
9727(allow dumpstate pdx_channel_socket_type (unix_stream_socket (getattr)))
9728(allow dumpstate pdx_channel_socket_type (unix_dgram_socket (getattr)))
9729(allow dumpstate pdx_channel_socket_type (netlink_route_socket (getattr)))
9730(allow dumpstate pdx_channel_socket_type (netlink_tcpdiag_socket (getattr)))
9731(allow dumpstate pdx_channel_socket_type (netlink_nflog_socket (getattr)))
9732(allow dumpstate pdx_channel_socket_type (netlink_xfrm_socket (getattr)))
9733(allow dumpstate pdx_channel_socket_type (netlink_selinux_socket (getattr)))
9734(allow dumpstate pdx_channel_socket_type (netlink_audit_socket (getattr)))
9735(allow dumpstate pdx_channel_socket_type (netlink_dnrt_socket (getattr)))
9736(allow dumpstate pdx_channel_socket_type (netlink_kobject_uevent_socket (getattr)))
9737(allow dumpstate pdx_channel_socket_type (appletalk_socket (getattr)))
9738(allow dumpstate pdx_channel_socket_type (tun_socket (getattr)))
9739(allow dumpstate pdx_channel_socket_type (netlink_iscsi_socket (getattr)))
9740(allow dumpstate pdx_channel_socket_type (netlink_fib_lookup_socket (getattr)))
9741(allow dumpstate pdx_channel_socket_type (netlink_connector_socket (getattr)))
9742(allow dumpstate pdx_channel_socket_type (netlink_netfilter_socket (getattr)))
9743(allow dumpstate pdx_channel_socket_type (netlink_generic_socket (getattr)))
9744(allow dumpstate pdx_channel_socket_type (netlink_scsitransport_socket (getattr)))
9745(allow dumpstate pdx_channel_socket_type (netlink_rdma_socket (getattr)))
9746(allow dumpstate pdx_channel_socket_type (netlink_crypto_socket (getattr)))
9747(allow dumpstate pdx_channel_socket_type (sctp_socket (getattr)))
9748(allow dumpstate pdx_channel_socket_type (icmp_socket (getattr)))
9749(allow dumpstate pdx_channel_socket_type (ax25_socket (getattr)))
9750(allow dumpstate pdx_channel_socket_type (ipx_socket (getattr)))
9751(allow dumpstate pdx_channel_socket_type (netrom_socket (getattr)))
9752(allow dumpstate pdx_channel_socket_type (atmpvc_socket (getattr)))
9753(allow dumpstate pdx_channel_socket_type (x25_socket (getattr)))
9754(allow dumpstate pdx_channel_socket_type (rose_socket (getattr)))
9755(allow dumpstate pdx_channel_socket_type (decnet_socket (getattr)))
9756(allow dumpstate pdx_channel_socket_type (atmsvc_socket (getattr)))
9757(allow dumpstate pdx_channel_socket_type (rds_socket (getattr)))
9758(allow dumpstate pdx_channel_socket_type (irda_socket (getattr)))
9759(allow dumpstate pdx_channel_socket_type (pppox_socket (getattr)))
9760(allow dumpstate pdx_channel_socket_type (llc_socket (getattr)))
9761(allow dumpstate pdx_channel_socket_type (can_socket (getattr)))
9762(allow dumpstate pdx_channel_socket_type (tipc_socket (getattr)))
9763(allow dumpstate pdx_channel_socket_type (bluetooth_socket (getattr)))
9764(allow dumpstate pdx_channel_socket_type (iucv_socket (getattr)))
9765(allow dumpstate pdx_channel_socket_type (rxrpc_socket (getattr)))
9766(allow dumpstate pdx_channel_socket_type (isdn_socket (getattr)))
9767(allow dumpstate pdx_channel_socket_type (phonet_socket (getattr)))
9768(allow dumpstate pdx_channel_socket_type (ieee802154_socket (getattr)))
9769(allow dumpstate pdx_channel_socket_type (caif_socket (getattr)))
9770(allow dumpstate pdx_channel_socket_type (alg_socket (getattr)))
9771(allow dumpstate pdx_channel_socket_type (nfc_socket (getattr)))
9772(allow dumpstate pdx_channel_socket_type (vsock_socket (getattr)))
9773(allow dumpstate pdx_channel_socket_type (kcm_socket (getattr)))
9774(allow dumpstate pdx_channel_socket_type (qipcrtr_socket (getattr)))
9775(allow dumpstate pdx_channel_socket_type (smc_socket (getattr)))
9776(allow dumpstate pdx_channel_socket_type (xdp_socket (getattr)))
9777(allow dumpstate linkerconfig_file (dir (read open)))
9778(dontaudit dumpstate mnt_user_file (dir (search)))
9779(dontaudit dumpstate mnt_vendor_file (dir (search)))
9780(dontaudit dumpstate mnt_product_file (dir (search)))
9781(dontaudit dumpstate mirror_data_file (dir (search)))
9782(dontaudit dumpstate linkerconfig_file (dir (getattr)))
9783(dontaudit dumpstate mnt_user_file (dir (getattr)))
9784(dontaudit dumpstate apex_mnt_dir (dir (getattr)))
9785(dontaudit dumpstate mirror_data_file (dir (getattr)))
9786(allow dumpstate bufferhubd (binder (call transfer)))
9787(allow bufferhubd dumpstate (binder (transfer)))
9788(allow dumpstate bufferhubd (fd (use)))
9789(allow dumpstate mediaswcodec (binder (call transfer)))
9790(allow mediaswcodec dumpstate (binder (transfer)))
9791(allow dumpstate mediaswcodec (fd (use)))
9792(allow dumpstate snapshotctl_log_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9793(allow dumpstate snapshotctl_log_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9794(allow dumpstate binderfs_logs (dir (ioctl read getattr lock open watch watch_reads search)))
9795(allow dumpstate binderfs_logs (file (ioctl read getattr lock map open watch watch_reads)))
9796(allow dumpstate binderfs_logs_proc (file (ioctl read getattr lock map open watch watch_reads)))
9797(allow dumpstate binderfs_logs_stats (file (ioctl read getattr lock map open watch watch_reads)))
9798(allow dumpstate apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
9799(allow dumpstate apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
9800(allow dumpstate vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
9801(allow dumpstate vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
9802(allow dumpstate vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
9803(allow dumpstate shutdown_checkpoints_system_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
9804(allow dumpstate shutdown_checkpoints_system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
9805;;* lmx 398 system/sepolicy/public/dumpstate.te
9806
9807(neverallow dumpstate base_typeattr_224 (process (ptrace)))
9808;;* lme
9809
9810;;* lmx 407 system/sepolicy/public/dumpstate.te
9811
9812(neverallow base_typeattr_334 dumpstate_service (service_manager (find)))
9813;;* lme
9814
9815(allow e2fs devpts (chr_file (ioctl read write getattr)))
9816(allow e2fs dev_type (blk_file (getattr)))
9817(allow e2fs block_device (dir (search)))
9818(allow e2fs userdata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9819(allow e2fs metadata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9820(allow e2fs dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9821(allow e2fs zoned_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9822(allow e2fs vold (fd (use)))
9823(allow e2fs sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
9824(allow e2fs sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
9825(allowx e2fs dm_device (ioctl blk_file (0x125e 0x1277 (range 0x127b 0x127d) (range 0x1282 0x1283))))
9826(allowx e2fs userdata_block_device (ioctl blk_file (0x125e 0x1277 (range 0x127b 0x127d) (range 0x1282 0x1283))))
9827(allowx e2fs zoned_block_device (ioctl blk_file (0x125e 0x1277 (range 0x127b 0x127d) (range 0x1282 0x1283))))
9828(allowx e2fs metadata_block_device (ioctl blk_file (0x125e 0x1277 (range 0x127b 0x127d) (range 0x1282 0x1283))))
9829(allow e2fs proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
9830(allow e2fs proc_mounts (file (ioctl read getattr lock map open watch watch_reads)))
9831(allow e2fs proc_swaps (file (ioctl read getattr lock map open watch watch_reads)))
9832(allow e2fs sysfs_fs_ext4_features (dir (search)))
9833(allow e2fs sysfs_fs_ext4_features (file (ioctl read getattr lock map open watch watch_reads)))
9834(allow e2fs file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
9835(allow extra_free_kbytes shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9836(allow extra_free_kbytes system_file (file (getattr map execute execute_no_trans)))
9837(allow extra_free_kbytes toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
9838(allow extra_free_kbytes proc_extra_free_kbytes (file (ioctl read write getattr lock append map open watch watch_reads)))
9839(allow extra_free_kbytes proc_watermark_scale_factor (file (ioctl read write getattr lock append map open watch watch_reads)))
9840(allow extra_free_kbytes proc_zoneinfo (file (ioctl read getattr lock map open watch watch_reads)))
9841;;* lmx 129 system/sepolicy/public/fastbootd.te
9842
9843(neverallow fastbootd data_file_type (file (execute execute_no_trans)))
9844;;* lme
9845
9846(allow fs_type self (filesystem (associate)))
9847(allow cgroup tmpfs (filesystem (associate)))
9848(allow cgroup_v2 tmpfs (filesystem (associate)))
9849(allow cgroup_rc_file tmpfs (filesystem (associate)))
9850(allow sysfs_type sysfs (filesystem (associate)))
9851(allow debugfs_type debugfs (filesystem (associate)))
9852(allow debugfs_type debugfs_tracing (filesystem (associate)))
9853(allow debugfs_type debugfs_tracing_debug (filesystem (associate)))
9854(allow file_type labeledfs (filesystem (associate)))
9855(allow file_type tmpfs (filesystem (associate)))
9856(allow file_type rootfs (filesystem (associate)))
9857(allow dev_type tmpfs (filesystem (associate)))
9858(allow app_fuse_file app_fusefs (filesystem (associate)))
9859(allow postinstall_file self (filesystem (associate)))
9860(allow proc_net proc (filesystem (associate)))
9861;;* lmx 651 system/sepolicy/public/file.te
9862
9863(neverallow fs_type file_type (filesystem (associate)))
9864;;* lme
9865
9866(allow fingerprintd servicemanager (binder (call transfer)))
9867(allow servicemanager fingerprintd (binder (call transfer)))
9868(allow servicemanager fingerprintd (dir (search)))
9869(allow servicemanager fingerprintd (file (read open)))
9870(allow servicemanager fingerprintd (process (getattr)))
9871(allow fingerprintd system_file (dir (ioctl read getattr lock open watch watch_reads search)))
9872(allow fingerprintd fingerprintd_service (service_manager (add find)))
9873;;* lmx 10 system/sepolicy/public/fingerprintd.te
9874
9875(neverallow base_typeattr_335 fingerprintd_service (service_manager (add)))
9876;;* lme
9877
9878(allow fingerprintd fingerprintd_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9879(allow fingerprintd fingerprintd_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
9880(allow keystore fingerprintd (dir (search)))
9881(allow keystore fingerprintd (file (read open)))
9882(allow keystore fingerprintd (process (getattr)))
9883(allow fingerprintd apc_service (service_manager (find)))
9884(allow fingerprintd keystore_service (service_manager (find)))
9885(allow fingerprintd legacykeystore_service (service_manager (find)))
9886(allow fingerprintd keystore (binder (call transfer)))
9887(allow keystore fingerprintd (binder (transfer)))
9888(allow fingerprintd keystore (fd (use)))
9889(allow keystore fingerprintd (binder (call transfer)))
9890(allow fingerprintd keystore (binder (transfer)))
9891(allow keystore fingerprintd (fd (use)))
9892(allow fingerprintd keystore (keystore2 (add_auth)))
9893(allow fingerprintd system_server (binder (call transfer)))
9894(allow system_server fingerprintd (binder (transfer)))
9895(allow fingerprintd system_server (fd (use)))
9896(allow fingerprintd permission_service (service_manager (find)))
9897(allow fingerprintd ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
9898(allow flags_health_check server_configurable_flags_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
9899(allow flags_health_check server_configurable_flags_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
9900;;* lmx 12 system/sepolicy/public/flags_health_check.te
9901
9902(neverallow base_typeattr_336 server_configurable_flags_data_file (file (write create setattr relabelfrom append unlink link rename)))
9903;;* lme
9904
9905(allow fsck tmpfs (chr_file (ioctl read write)))
9906(allow fsck devpts (chr_file (ioctl read write getattr)))
9907(allow fsck vold (fd (use)))
9908(allow fsck vold (fifo_file (read write getattr)))
9909(allow fsck userdata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9910(allow fsck cache_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9911(allow fsck dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9912(allow fsck zoned_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9913(allow fsck metadata_file (dir (getattr)))
9914(allow fsck block_device (dir (search)))
9915(allow fsck mirror_data_file (dir (search)))
9916(allowx fsck dev_type (ioctl blk_file (0x125e 0x127c 0x1282)))
9917(allow fsck dev_type (blk_file (getattr)))
9918(allow fsck proc_mounts (file (ioctl read getattr lock map open watch watch_reads)))
9919(allow fsck proc_swaps (file (ioctl read getattr lock map open watch watch_reads)))
9920(allow fsck sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
9921(allow fsck rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
9922(allow fsck sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
9923;;* lmx 72 system/sepolicy/public/fsck.te
9924
9925(neverallow fsck vold_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9926(neverallow fsck root_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9927(neverallow fsck frp_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9928(neverallow fsck system_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9929(neverallow fsck recovery_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9930(neverallow fsck boot_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9931(neverallow fsck swap_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9932;;* lme
9933
9934;;* lmx 75 system/sepolicy/public/fsck.te
9935
9936(neverallow base_typeattr_337 fsck (process (transition)))
9937;;* lme
9938
9939;;* lmx 76 system/sepolicy/public/fsck.te
9940
9941(neverallow base_typeattr_224 fsck (process (dyntransition)))
9942;;* lme
9943
9944;;* lmx 77 system/sepolicy/public/fsck.te
9945
9946(neverallow fsck base_typeattr_338 (file (entrypoint)))
9947;;* lme
9948
9949(allow fsck_untrusted devpts (chr_file (ioctl read write getattr)))
9950(allow fsck_untrusted vold (fd (use)))
9951(allow fsck_untrusted vold (fifo_file (read write getattr)))
9952(allow fsck_untrusted block_device (dir (search)))
9953(allow fsck_untrusted vold_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
9954(allow fsck_untrusted proc_mounts (file (ioctl read getattr lock map open watch watch_reads)))
9955(allow fsck_untrusted dev_type (blk_file (getattr)))
9956;;* lmx 45 system/sepolicy/public/fsck_untrusted.te
9957
9958(neverallow fsck_untrusted dm_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9959(neverallow fsck_untrusted root_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9960(neverallow fsck_untrusted frp_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9961(neverallow fsck_untrusted system_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9962(neverallow fsck_untrusted recovery_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9963(neverallow fsck_untrusted boot_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9964(neverallow fsck_untrusted userdata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9965(neverallow fsck_untrusted cache_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9966(neverallow fsck_untrusted swap_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9967(neverallow fsck_untrusted metadata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
9968;;* lme
9969
9970;;* lmx 48 system/sepolicy/public/fsck_untrusted.te
9971
9972(neverallow base_typeattr_339 fsck_untrusted (process (transition)))
9973;;* lme
9974
9975;;* lmx 49 system/sepolicy/public/fsck_untrusted.te
9976
9977(neverallow base_typeattr_224 fsck_untrusted (process (dyntransition)))
9978;;* lme
9979
9980;;* lmx 50 system/sepolicy/public/fsck_untrusted.te
9981
9982(neverallow fsck_untrusted base_typeattr_338 (file (entrypoint)))
9983;;* lme
9984
9985;;* lmx 55 system/sepolicy/public/fsck_untrusted.te
9986
9987(neverallow fsck_untrusted self (capability (setgid setuid sys_admin)))
9988(neverallow fsck_untrusted self (cap_userns (setgid setuid sys_admin)))
9989;;* lme
9990
9991(dontaudit fsck_untrusted sysfs (file (ioctl read write getattr lock append map open watch watch_reads)))
9992(dontaudit fsck_untrusted sysfs_dm (file (ioctl read write getattr lock append map open watch watch_reads)))
9993(dontaudit fsck_untrusted sysfs_dm (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
9994(dontaudit fsck_untrusted tmpfs (lnk_file (read)))
9995(allow gatekeeperd servicemanager (binder (call transfer)))
9996(allow servicemanager gatekeeperd (binder (call transfer)))
9997(allow servicemanager gatekeeperd (dir (search)))
9998(allow servicemanager gatekeeperd (file (read open)))
9999(allow servicemanager gatekeeperd (process (getattr)))
10000(allow gatekeeperd ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10001(allow gatekeeperd system_file (dir (ioctl read getattr lock open watch watch_reads search)))
10002(allow gatekeeperd gatekeeper_service (service_manager (add find)))
10003;;* lmx 21 system/sepolicy/public/gatekeeperd.te
10004
10005(neverallow base_typeattr_340 gatekeeper_service (service_manager (add)))
10006;;* lme
10007
10008(allow keystore gatekeeperd (dir (search)))
10009(allow keystore gatekeeperd (file (read open)))
10010(allow keystore gatekeeperd (process (getattr)))
10011(allow gatekeeperd apc_service (service_manager (find)))
10012(allow gatekeeperd keystore_service (service_manager (find)))
10013(allow gatekeeperd legacykeystore_service (service_manager (find)))
10014(allow gatekeeperd keystore (binder (call transfer)))
10015(allow keystore gatekeeperd (binder (transfer)))
10016(allow gatekeeperd keystore (fd (use)))
10017(allow keystore gatekeeperd (binder (call transfer)))
10018(allow gatekeeperd keystore (binder (transfer)))
10019(allow keystore gatekeeperd (fd (use)))
10020(allow gatekeeperd keystore (keystore2 (add_auth)))
10021(allow gatekeeperd authorization_service (service_manager (find)))
10022(allow gatekeeperd system_server (binder (call)))
10023(allow gatekeeperd permission_service (service_manager (find)))
10024(allow gatekeeperd gatekeeper_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
10025(allow gatekeeperd gatekeeper_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
10026(allow gatekeeperd hardware_properties_service (service_manager (find)))
10027(allow gatekeeperd cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
10028(allow gatekeeperd cgroup (file (ioctl read getattr lock map open watch watch_reads)))
10029(allow gatekeeperd cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10030(allow gatekeeperd cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
10031(allow gatekeeperd cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
10032(allow gatekeeperd cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10033(allow hal_allocator_client hal_allocator_server (binder (call transfer)))
10034(allow hal_allocator_server hal_allocator_client (binder (transfer)))
10035(allow hal_allocator_client hal_allocator_server (fd (use)))
10036(allow hal_allocator_client hidl_allocator_hwservice (hwservice_manager (find)))
10037(allow hal_allocator_server hidl_allocator_hwservice (hwservice_manager (add find)))
10038(allow hal_allocator_server hidl_base_hwservice (hwservice_manager (add)))
10039;;* lmx 4 system/sepolicy/public/hal_allocator.te
10040
10041(neverallow base_typeattr_341 hidl_allocator_hwservice (hwservice_manager (add)))
10042;;* lme
10043
10044;;* lmx 4 system/sepolicy/public/hal_allocator.te
10045
10046(neverallow base_typeattr_342 hidl_allocator_hwservice (hwservice_manager (find)))
10047;;* lme
10048
10049(allow hal_allocator_client hidl_memory_hwservice (hwservice_manager (find)))
10050(allow hal_allocator_client same_process_hal_file (file (read getattr map execute open)))
10051(allow hal_atrace_client hal_atrace_server (binder (call transfer)))
10052(allow hal_atrace_server hal_atrace_client (binder (transfer)))
10053(allow hal_atrace_client hal_atrace_server (fd (use)))
10054(allow hal_atrace_client hal_atrace_hwservice (hwservice_manager (find)))
10055(allow hal_atrace_server hal_atrace_hwservice (hwservice_manager (add find)))
10056(allow hal_atrace_server hidl_base_hwservice (hwservice_manager (add)))
10057;;* lmx 4 system/sepolicy/public/hal_atrace.te
10058
10059(neverallow base_typeattr_343 hal_atrace_hwservice (hwservice_manager (add)))
10060;;* lme
10061
10062;;* lmx 4 system/sepolicy/public/hal_atrace.te
10063
10064(neverallow base_typeattr_344 hal_atrace_hwservice (hwservice_manager (find)))
10065;;* lme
10066
10067(allow hal_audio_client hal_audio_server (binder (call transfer)))
10068(allow hal_audio_server hal_audio_client (binder (transfer)))
10069(allow hal_audio_client hal_audio_server (fd (use)))
10070(allow hal_audio_server hal_audio_client (binder (call transfer)))
10071(allow hal_audio_client hal_audio_server (binder (transfer)))
10072(allow hal_audio_server hal_audio_client (fd (use)))
10073(allow hal_audio_client hal_audio_hwservice (hwservice_manager (find)))
10074(allow hal_audio_server hal_audio_hwservice (hwservice_manager (add find)))
10075(allow hal_audio_server hidl_base_hwservice (hwservice_manager (add)))
10076;;* lmx 5 system/sepolicy/public/hal_audio.te
10077
10078(neverallow base_typeattr_345 hal_audio_hwservice (hwservice_manager (add)))
10079;;* lme
10080
10081;;* lmx 5 system/sepolicy/public/hal_audio.te
10082
10083(neverallow base_typeattr_346 hal_audio_hwservice (hwservice_manager (find)))
10084;;* lme
10085
10086(allow hal_audio_client hal_audio_service (service_manager (find)))
10087(allow hal_audio_server hal_audio_service (service_manager (add find)))
10088;;* lmx 6 system/sepolicy/public/hal_audio.te
10089
10090(neverallow base_typeattr_345 hal_audio_service (service_manager (add)))
10091;;* lme
10092
10093;;* lmx 6 system/sepolicy/public/hal_audio.te
10094
10095(neverallow base_typeattr_347 hal_audio_service (service_manager (find)))
10096;;* lme
10097
10098(allow hal_audio ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10099(allow hal_audio_server servicemanager (binder (call transfer)))
10100(allow servicemanager hal_audio_server (binder (transfer)))
10101(allow hal_audio_server servicemanager (fd (use)))
10102(allow hal_audio proc (dir (ioctl read getattr lock open watch watch_reads search)))
10103(allow hal_audio proc (file (ioctl read getattr lock map open watch watch_reads)))
10104(allow hal_audio proc (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10105(allow hal_audio proc_asound (dir (ioctl read getattr lock open watch watch_reads search)))
10106(allow hal_audio proc_asound (file (ioctl read getattr lock map open watch watch_reads)))
10107(allow hal_audio proc_asound (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10108(allow hal_audio_server audio_device (dir (ioctl read getattr lock open watch watch_reads search)))
10109(allow hal_audio_server audio_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10110(allow hal_audio shell (fd (use)))
10111(allow hal_audio shell (fifo_file (write)))
10112(allow hal_audio dumpstate (fd (use)))
10113(allow hal_audio dumpstate (fifo_file (write)))
10114(allow hal_audio_server appdomain (fd (use)))
10115(allow hal_audio_server system_server_tmpfs (file (read getattr map)))
10116(allow hal_audio_server self (capability (sys_nice)))
10117(allow hal_audio_server self (cap_userns (sys_nice)))
10118(allow hal_audio vndbinder_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10119(allow hal_audio vndservicemanager (binder (call transfer)))
10120(allow vndservicemanager hal_audio (dir (search)))
10121(allow vndservicemanager hal_audio (file (read map open)))
10122(allow vndservicemanager hal_audio (process (getattr)))
10123;;* lmx 39 system/sepolicy/public/hal_audio.te
10124
10125(neverallow hal_audio_server fs_type (file (execute_no_trans)))
10126(neverallow hal_audio_server file_type (file (execute_no_trans)))
10127;;* lme
10128
10129;;* lmx 42 system/sepolicy/public/hal_audio.te
10130
10131(neverallow base_typeattr_348 audio_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10132;;* lme
10133
10134(allow hal_audio audio_config_prop (file (read getattr map open)))
10135(allow hal_audio bluetooth_a2dp_offload_prop (file (read getattr map open)))
10136(allow hal_audio bluetooth_audio_hal_prop (file (read getattr map open)))
10137(allow hal_audiocontrol_client hal_audiocontrol_server (binder (call transfer)))
10138(allow hal_audiocontrol_server hal_audiocontrol_client (binder (transfer)))
10139(allow hal_audiocontrol_client hal_audiocontrol_server (fd (use)))
10140(allow hal_audiocontrol_server hal_audiocontrol_client (binder (call transfer)))
10141(allow hal_audiocontrol_client hal_audiocontrol_server (binder (transfer)))
10142(allow hal_audiocontrol_server hal_audiocontrol_client (fd (use)))
10143(allow hal_audiocontrol_client hal_audiocontrol_hwservice (hwservice_manager (find)))
10144(allow hal_audiocontrol_server hal_audiocontrol_hwservice (hwservice_manager (add find)))
10145(allow hal_audiocontrol_server hidl_base_hwservice (hwservice_manager (add)))
10146;;* lmx 5 system/sepolicy/public/hal_audiocontrol.te
10147
10148(neverallow base_typeattr_349 hal_audiocontrol_hwservice (hwservice_manager (add)))
10149;;* lme
10150
10151;;* lmx 5 system/sepolicy/public/hal_audiocontrol.te
10152
10153(neverallow base_typeattr_350 hal_audiocontrol_hwservice (hwservice_manager (find)))
10154;;* lme
10155
10156(allow hal_audiocontrol_client hal_audiocontrol_service (service_manager (find)))
10157(allow hal_audiocontrol_server hal_audiocontrol_service (service_manager (add find)))
10158;;* lmx 6 system/sepolicy/public/hal_audiocontrol.te
10159
10160(neverallow base_typeattr_349 hal_audiocontrol_service (service_manager (add)))
10161;;* lme
10162
10163;;* lmx 6 system/sepolicy/public/hal_audiocontrol.te
10164
10165(neverallow base_typeattr_351 hal_audiocontrol_service (service_manager (find)))
10166;;* lme
10167
10168(allow hal_audiocontrol_server servicemanager (binder (call transfer)))
10169(allow servicemanager hal_audiocontrol_server (binder (transfer)))
10170(allow hal_audiocontrol_server servicemanager (fd (use)))
10171(allow hal_authgraph_client hal_authgraph_server (binder (call transfer)))
10172(allow hal_authgraph_server hal_authgraph_client (binder (transfer)))
10173(allow hal_authgraph_client hal_authgraph_server (fd (use)))
10174(allow hal_authgraph_client hal_authgraph_service (service_manager (find)))
10175(allow hal_authgraph_server hal_authgraph_service (service_manager (add find)))
10176;;* lmx 3 system/sepolicy/public/hal_authgraph.te
10177
10178(neverallow base_typeattr_352 hal_authgraph_service (service_manager (add)))
10179;;* lme
10180
10181;;* lmx 3 system/sepolicy/public/hal_authgraph.te
10182
10183(neverallow base_typeattr_353 hal_authgraph_service (service_manager (find)))
10184;;* lme
10185
10186(allow hal_authgraph_server servicemanager (binder (call transfer)))
10187(allow servicemanager hal_authgraph_server (binder (transfer)))
10188(allow hal_authgraph_server servicemanager (fd (use)))
10189(allow hal_authgraph_server tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10190(allow hal_authgraph_server ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10191(allow hal_authsecret_client hal_authsecret_server (binder (call transfer)))
10192(allow hal_authsecret_server hal_authsecret_client (binder (transfer)))
10193(allow hal_authsecret_client hal_authsecret_server (fd (use)))
10194(allow hal_authsecret_client hal_authsecret_hwservice (hwservice_manager (find)))
10195(allow hal_authsecret_server hal_authsecret_hwservice (hwservice_manager (add find)))
10196(allow hal_authsecret_server hidl_base_hwservice (hwservice_manager (add)))
10197;;* lmx 4 system/sepolicy/public/hal_authsecret.te
10198
10199(neverallow base_typeattr_354 hal_authsecret_hwservice (hwservice_manager (add)))
10200;;* lme
10201
10202;;* lmx 4 system/sepolicy/public/hal_authsecret.te
10203
10204(neverallow base_typeattr_355 hal_authsecret_hwservice (hwservice_manager (find)))
10205;;* lme
10206
10207(allow hal_authsecret_client hal_authsecret_service (service_manager (find)))
10208(allow hal_authsecret_server hal_authsecret_service (service_manager (add find)))
10209;;* lmx 5 system/sepolicy/public/hal_authsecret.te
10210
10211(neverallow base_typeattr_354 hal_authsecret_service (service_manager (add)))
10212;;* lme
10213
10214;;* lmx 5 system/sepolicy/public/hal_authsecret.te
10215
10216(neverallow base_typeattr_356 hal_authsecret_service (service_manager (find)))
10217;;* lme
10218
10219(allow hal_authsecret_server servicemanager (binder (call transfer)))
10220(allow servicemanager hal_authsecret_server (binder (transfer)))
10221(allow hal_authsecret_server servicemanager (fd (use)))
10222(allow hal_bluetooth_client hal_bluetooth_server (binder (call transfer)))
10223(allow hal_bluetooth_server hal_bluetooth_client (binder (transfer)))
10224(allow hal_bluetooth_client hal_bluetooth_server (fd (use)))
10225(allow hal_bluetooth_server hal_bluetooth_client (binder (call transfer)))
10226(allow hal_bluetooth_client hal_bluetooth_server (binder (transfer)))
10227(allow hal_bluetooth_server hal_bluetooth_client (fd (use)))
10228(allow hal_bluetooth_server servicemanager (binder (call transfer)))
10229(allow servicemanager hal_bluetooth_server (binder (transfer)))
10230(allow hal_bluetooth_server servicemanager (fd (use)))
10231(allow hal_bluetooth_client hal_bluetooth_hwservice (hwservice_manager (find)))
10232(allow hal_bluetooth_server hal_bluetooth_hwservice (hwservice_manager (add find)))
10233(allow hal_bluetooth_server hidl_base_hwservice (hwservice_manager (add)))
10234;;* lmx 6 system/sepolicy/public/hal_bluetooth.te
10235
10236(neverallow base_typeattr_357 hal_bluetooth_hwservice (hwservice_manager (add)))
10237;;* lme
10238
10239;;* lmx 6 system/sepolicy/public/hal_bluetooth.te
10240
10241(neverallow base_typeattr_358 hal_bluetooth_hwservice (hwservice_manager (find)))
10242;;* lme
10243
10244(allow hal_bluetooth_client hal_bluetooth_service (service_manager (find)))
10245(allow hal_bluetooth_server hal_bluetooth_service (service_manager (add find)))
10246;;* lmx 7 system/sepolicy/public/hal_bluetooth.te
10247
10248(neverallow base_typeattr_357 hal_bluetooth_service (service_manager (add)))
10249;;* lme
10250
10251;;* lmx 7 system/sepolicy/public/hal_bluetooth.te
10252
10253(neverallow base_typeattr_359 hal_bluetooth_service (service_manager (find)))
10254;;* lme
10255
10256(allow hal_bluetooth sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
10257(allow hal_bluetooth self (capability2 (block_suspend)))
10258(allow hal_bluetooth self (cap2_userns (block_suspend)))
10259(allow hal_bluetooth system_suspend_server (binder (call transfer)))
10260(allow system_suspend_server hal_bluetooth (binder (transfer)))
10261(allow hal_bluetooth system_suspend_server (fd (use)))
10262(allow hal_bluetooth system_suspend_hwservice (hwservice_manager (find)))
10263(allow hal_bluetooth hwservicemanager (binder (call transfer)))
10264(allow hwservicemanager hal_bluetooth (binder (call transfer)))
10265(allow hwservicemanager hal_bluetooth (dir (search)))
10266(allow hwservicemanager hal_bluetooth (file (read map open)))
10267(allow hwservicemanager hal_bluetooth (process (getattr)))
10268(allow hal_bluetooth hwservicemanager_prop (file (read getattr map open)))
10269(allow hal_bluetooth hidl_manager_hwservice (hwservice_manager (find)))
10270(allow hal_bluetooth hal_system_suspend_service (service_manager (find)))
10271(allow hal_bluetooth servicemanager (binder (call transfer)))
10272(allow servicemanager hal_bluetooth (binder (call transfer)))
10273(allow servicemanager hal_bluetooth (dir (search)))
10274(allow servicemanager hal_bluetooth (file (read open)))
10275(allow servicemanager hal_bluetooth (process (getattr)))
10276(allow hal_bluetooth self (capability (net_admin)))
10277(allow hal_bluetooth self (cap_userns (net_admin)))
10278(allow hal_bluetooth bluetooth_efs_file (dir (ioctl read getattr lock open watch watch_reads search)))
10279(allow hal_bluetooth bluetooth_efs_file (file (ioctl read getattr lock map open watch watch_reads)))
10280(allow hal_bluetooth bluetooth_efs_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10281(allow hal_bluetooth uhid_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10282(allow hal_bluetooth hci_attach_dev (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10283(allow hal_bluetooth sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
10284(allow hal_bluetooth sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
10285(allow hal_bluetooth sysfs_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10286(allow hal_bluetooth sysfs_bluetooth_writable (file (ioctl read write getattr lock append map open watch watch_reads)))
10287(allow hal_bluetooth self (capability2 (wake_alarm)))
10288(allow hal_bluetooth self (cap2_userns (wake_alarm)))
10289(allow hal_bluetooth property_socket (sock_file (write)))
10290(allow hal_bluetooth init (unix_stream_socket (connectto)))
10291(allow hal_bluetooth bluetooth_a2dp_offload_prop (property_service (set)))
10292(allow hal_bluetooth bluetooth_a2dp_offload_prop (file (read getattr map open)))
10293(allow hal_bluetooth property_socket (sock_file (write)))
10294(allow hal_bluetooth init (unix_stream_socket (connectto)))
10295(allow hal_bluetooth bluetooth_audio_hal_prop (property_service (set)))
10296(allow hal_bluetooth bluetooth_audio_hal_prop (file (read getattr map open)))
10297(allow hal_bluetooth property_socket (sock_file (write)))
10298(allow hal_bluetooth init (unix_stream_socket (connectto)))
10299(allow hal_bluetooth bluetooth_prop (property_service (set)))
10300(allow hal_bluetooth bluetooth_prop (file (read getattr map open)))
10301(allow hal_bluetooth property_socket (sock_file (write)))
10302(allow hal_bluetooth init (unix_stream_socket (connectto)))
10303(allow hal_bluetooth exported_bluetooth_prop (property_service (set)))
10304(allow hal_bluetooth exported_bluetooth_prop (file (read getattr map open)))
10305(allow hal_bluetooth proc_bluetooth_writable (file (ioctl read write getattr lock append map open watch watch_reads)))
10306(allow hal_bluetooth self (capability (sys_nice)))
10307(allow hal_bluetooth self (cap_userns (sys_nice)))
10308(allow hal_bootctl_client hal_bootctl_server (binder (call transfer)))
10309(allow hal_bootctl_server hal_bootctl_client (binder (transfer)))
10310(allow hal_bootctl_client hal_bootctl_server (fd (use)))
10311(allow hal_bootctl_server hal_bootctl_client (binder (call transfer)))
10312(allow hal_bootctl_client hal_bootctl_server (binder (transfer)))
10313(allow hal_bootctl_server hal_bootctl_client (fd (use)))
10314(allow hal_bootctl_server servicemanager (binder (call transfer)))
10315(allow servicemanager hal_bootctl_server (binder (call transfer)))
10316(allow servicemanager hal_bootctl_server (dir (search)))
10317(allow servicemanager hal_bootctl_server (file (read open)))
10318(allow servicemanager hal_bootctl_server (process (getattr)))
10319(allow hal_bootctl_client hal_bootctl_hwservice (hwservice_manager (find)))
10320(allow hal_bootctl_server hal_bootctl_hwservice (hwservice_manager (add find)))
10321(allow hal_bootctl_server hidl_base_hwservice (hwservice_manager (add)))
10322;;* lmx 6 system/sepolicy/public/hal_bootctl.te
10323
10324(neverallow base_typeattr_360 hal_bootctl_hwservice (hwservice_manager (add)))
10325;;* lme
10326
10327;;* lmx 6 system/sepolicy/public/hal_bootctl.te
10328
10329(neverallow base_typeattr_361 hal_bootctl_hwservice (hwservice_manager (find)))
10330;;* lme
10331
10332(allow hal_bootctl_server proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
10333(allow hal_bootctl_client hal_bootctl_service (service_manager (find)))
10334(allow hal_bootctl_server hal_bootctl_service (service_manager (add find)))
10335;;* lmx 10 system/sepolicy/public/hal_bootctl.te
10336
10337(neverallow base_typeattr_360 hal_bootctl_service (service_manager (add)))
10338;;* lme
10339
10340;;* lmx 10 system/sepolicy/public/hal_bootctl.te
10341
10342(neverallow base_typeattr_362 hal_bootctl_service (service_manager (find)))
10343;;* lme
10344
10345(allow hal_broadcastradio_client hal_broadcastradio_server (binder (call transfer)))
10346(allow hal_broadcastradio_server hal_broadcastradio_client (binder (transfer)))
10347(allow hal_broadcastradio_client hal_broadcastradio_server (fd (use)))
10348(allow hal_broadcastradio_server hal_broadcastradio_client (binder (call transfer)))
10349(allow hal_broadcastradio_client hal_broadcastradio_server (binder (transfer)))
10350(allow hal_broadcastradio_server hal_broadcastradio_client (fd (use)))
10351(allow hal_broadcastradio_client hal_broadcastradio_hwservice (hwservice_manager (find)))
10352(allow hal_broadcastradio_server hal_broadcastradio_hwservice (hwservice_manager (add find)))
10353(allow hal_broadcastradio_server hidl_base_hwservice (hwservice_manager (add)))
10354;;* lmx 4 system/sepolicy/public/hal_broadcastradio.te
10355
10356(neverallow base_typeattr_363 hal_broadcastradio_hwservice (hwservice_manager (add)))
10357;;* lme
10358
10359;;* lmx 4 system/sepolicy/public/hal_broadcastradio.te
10360
10361(neverallow base_typeattr_364 hal_broadcastradio_hwservice (hwservice_manager (find)))
10362;;* lme
10363
10364(allow hal_broadcastradio_client hal_broadcastradio_service (service_manager (find)))
10365(allow hal_broadcastradio_server hal_broadcastradio_service (service_manager (add find)))
10366;;* lmx 5 system/sepolicy/public/hal_broadcastradio.te
10367
10368(neverallow base_typeattr_363 hal_broadcastradio_service (service_manager (add)))
10369;;* lme
10370
10371;;* lmx 5 system/sepolicy/public/hal_broadcastradio.te
10372
10373(neverallow base_typeattr_365 hal_broadcastradio_service (service_manager (find)))
10374;;* lme
10375
10376(allow hal_broadcastradio_server servicemanager (binder (call transfer)))
10377(allow servicemanager hal_broadcastradio_server (binder (transfer)))
10378(allow hal_broadcastradio_server servicemanager (fd (use)))
10379(allow hal_camera_client hal_camera_server (binder (call transfer)))
10380(allow hal_camera_server hal_camera_client (binder (transfer)))
10381(allow hal_camera_client hal_camera_server (fd (use)))
10382(allow hal_camera_server hal_camera_client (binder (call transfer)))
10383(allow hal_camera_client hal_camera_server (binder (transfer)))
10384(allow hal_camera_server hal_camera_client (fd (use)))
10385(allow hal_camera_server servicemanager (binder (call transfer)))
10386(allow servicemanager hal_camera_server (binder (call transfer)))
10387(allow servicemanager hal_camera_server (dir (search)))
10388(allow servicemanager hal_camera_server (file (read open)))
10389(allow servicemanager hal_camera_server (process (getattr)))
10390(allow hal_camera_client hal_camera_hwservice (hwservice_manager (find)))
10391(allow hal_camera_server hal_camera_hwservice (hwservice_manager (add find)))
10392(allow hal_camera_server hidl_base_hwservice (hwservice_manager (add)))
10393;;* lmx 8 system/sepolicy/public/hal_camera.te
10394
10395(neverallow base_typeattr_366 hal_camera_hwservice (hwservice_manager (add)))
10396;;* lme
10397
10398;;* lmx 8 system/sepolicy/public/hal_camera.te
10399
10400(neverallow base_typeattr_367 hal_camera_hwservice (hwservice_manager (find)))
10401;;* lme
10402
10403(allow hal_camera_client hal_camera_service (service_manager (find)))
10404(allow hal_camera_server hal_camera_service (service_manager (add find)))
10405;;* lmx 9 system/sepolicy/public/hal_camera.te
10406
10407(neverallow base_typeattr_366 hal_camera_service (service_manager (add)))
10408;;* lme
10409
10410;;* lmx 9 system/sepolicy/public/hal_camera.te
10411
10412(neverallow base_typeattr_368 hal_camera_service (service_manager (find)))
10413;;* lme
10414
10415(allow hal_camera device (dir (ioctl read getattr lock open watch watch_reads search)))
10416(allow hal_camera video_device (dir (ioctl read getattr lock open watch watch_reads search)))
10417(allow hal_camera video_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10418(allow hal_camera camera_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10419(allow hal_camera ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10420(allow hal_camera dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10421(allow hal_camera_client hal_graphics_allocator (fd (use)))
10422(allow hal_camera_server hal_graphics_allocator (fd (use)))
10423(allow hal_camera base_typeattr_369 (fd (use)))
10424(allow hal_camera surfaceflinger (fd (use)))
10425(allow hal_camera hal_allocator_server (fd (use)))
10426(allow hal_camera shell (fd (use)))
10427(allow hal_camera shell (fifo_file (write)))
10428;;* lmx 36 system/sepolicy/public/hal_camera.te
10429
10430(neverallow hal_camera_server fs_type (file (execute_no_trans)))
10431(neverallow hal_camera_server file_type (file (execute_no_trans)))
10432;;* lme
10433
10434;;* lmx 39 system/sepolicy/public/hal_camera.te
10435
10436(neverallow hal_camera_server domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
10437(neverallow hal_camera_server domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
10438(neverallow hal_camera_server domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
10439;;* lme
10440
10441;;* lmx 42 system/sepolicy/public/hal_camera.te
10442
10443(neverallow base_typeattr_370 camera_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10444;;* lme
10445
10446(allow hal_can_controller_client hal_can_controller_server (binder (call transfer)))
10447(allow hal_can_controller_server hal_can_controller_client (binder (transfer)))
10448(allow hal_can_controller_client hal_can_controller_server (fd (use)))
10449(allow hal_can_controller_server hal_can_controller_client (binder (call transfer)))
10450(allow hal_can_controller_client hal_can_controller_server (binder (transfer)))
10451(allow hal_can_controller_server hal_can_controller_client (fd (use)))
10452(allow hal_can_controller_client hal_can_controller_hwservice (hwservice_manager (find)))
10453(allow hal_can_controller_server hal_can_controller_hwservice (hwservice_manager (add find)))
10454(allow hal_can_controller_server hidl_base_hwservice (hwservice_manager (add)))
10455;;* lmx 4 system/sepolicy/public/hal_can.te
10456
10457(neverallow base_typeattr_371 hal_can_controller_hwservice (hwservice_manager (add)))
10458;;* lme
10459
10460;;* lmx 4 system/sepolicy/public/hal_can.te
10461
10462(neverallow base_typeattr_372 hal_can_controller_hwservice (hwservice_manager (find)))
10463;;* lme
10464
10465(allow hal_can_bus_client hal_can_bus_server (binder (call transfer)))
10466(allow hal_can_bus_server hal_can_bus_client (binder (transfer)))
10467(allow hal_can_bus_client hal_can_bus_server (fd (use)))
10468(allow hal_can_bus_server hal_can_bus_client (binder (call transfer)))
10469(allow hal_can_bus_client hal_can_bus_server (binder (transfer)))
10470(allow hal_can_bus_server hal_can_bus_client (fd (use)))
10471(allow hal_can_bus_client hal_can_bus_hwservice (hwservice_manager (find)))
10472(allow hal_can_bus_server hal_can_bus_hwservice (hwservice_manager (add find)))
10473(allow hal_can_bus_server hidl_base_hwservice (hwservice_manager (add)))
10474;;* lmx 9 system/sepolicy/public/hal_can.te
10475
10476(neverallow base_typeattr_373 hal_can_bus_hwservice (hwservice_manager (add)))
10477;;* lme
10478
10479;;* lmx 9 system/sepolicy/public/hal_can.te
10480
10481(neverallow base_typeattr_374 hal_can_bus_hwservice (hwservice_manager (find)))
10482;;* lme
10483
10484(allow hal_can_controller_client hal_can_controller_service (service_manager (find)))
10485(allow hal_can_controller_server hal_can_controller_service (service_manager (add find)))
10486;;* lmx 12 system/sepolicy/public/hal_can.te
10487
10488(neverallow base_typeattr_371 hal_can_controller_service (service_manager (add)))
10489;;* lme
10490
10491;;* lmx 12 system/sepolicy/public/hal_can.te
10492
10493(neverallow base_typeattr_375 hal_can_controller_service (service_manager (find)))
10494;;* lme
10495
10496(allow hal_can_controller servicemanager (binder (call transfer)))
10497(allow servicemanager hal_can_controller (binder (call transfer)))
10498(allow servicemanager hal_can_controller (dir (search)))
10499(allow servicemanager hal_can_controller (file (read open)))
10500(allow servicemanager hal_can_controller (process (getattr)))
10501(allow hal_cas_client hal_cas_server (binder (call transfer)))
10502(allow hal_cas_server hal_cas_client (binder (transfer)))
10503(allow hal_cas_client hal_cas_server (fd (use)))
10504(allow hal_cas_server hal_cas_client (binder (call transfer)))
10505(allow hal_cas_client hal_cas_server (binder (transfer)))
10506(allow hal_cas_server hal_cas_client (fd (use)))
10507(allow hal_cas_client hal_cas_hwservice (hwservice_manager (find)))
10508(allow hal_cas_server hal_cas_hwservice (hwservice_manager (add find)))
10509(allow hal_cas_server hidl_base_hwservice (hwservice_manager (add)))
10510;;* lmx 5 system/sepolicy/public/hal_cas.te
10511
10512(neverallow base_typeattr_376 hal_cas_hwservice (hwservice_manager (add)))
10513;;* lme
10514
10515;;* lmx 5 system/sepolicy/public/hal_cas.te
10516
10517(neverallow base_typeattr_377 hal_cas_hwservice (hwservice_manager (find)))
10518;;* lme
10519
10520(allow hal_cas_server hidl_memory_hwservice (hwservice_manager (find)))
10521(allow hal_cas_client hal_cas_service (service_manager (find)))
10522(allow hal_cas_server hal_cas_service (service_manager (add find)))
10523;;* lmx 8 system/sepolicy/public/hal_cas.te
10524
10525(neverallow base_typeattr_376 hal_cas_service (service_manager (add)))
10526;;* lme
10527
10528;;* lmx 8 system/sepolicy/public/hal_cas.te
10529
10530(neverallow base_typeattr_378 hal_cas_service (service_manager (find)))
10531;;* lme
10532
10533(allow hal_cas_server servicemanager (binder (call transfer)))
10534(allow servicemanager hal_cas_server (binder (transfer)))
10535(allow hal_cas_server servicemanager (fd (use)))
10536(allow hal_cas_client servicemanager (binder (call transfer)))
10537(allow servicemanager hal_cas_client (binder (transfer)))
10538(allow hal_cas_client servicemanager (fd (use)))
10539(allow hal_cas_server serialno_prop (file (read getattr map open)))
10540(allow hal_cas system_data_file (file (read getattr)))
10541(allow hal_cas cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
10542(allow hal_cas cgroup (file (ioctl read getattr lock map open watch watch_reads)))
10543(allow hal_cas cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10544(allow hal_cas cgroup (dir (write search)))
10545(allow hal_cas cgroup (file (write lock append map open)))
10546(allow hal_cas cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
10547(allow hal_cas cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
10548(allow hal_cas cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10549(allow hal_cas cgroup_v2 (dir (write search)))
10550(allow hal_cas cgroup_v2 (file (write lock append map open)))
10551(allow hal_cas ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10552(allow hal_cas hal_graphics_allocator (fd (use)))
10553(allow hal_cas tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10554;;* lmx 40 system/sepolicy/public/hal_cas.te
10555
10556(neverallow hal_cas_server fs_type (file (execute_no_trans)))
10557(neverallow hal_cas_server file_type (file (execute_no_trans)))
10558;;* lme
10559
10560;;* lmx 43 system/sepolicy/public/hal_cas.te
10561
10562(neverallowx hal_cas_server domain (ioctl tcp_socket (0x6900 0x6902)))
10563(neverallowx hal_cas_server domain (ioctl udp_socket (0x6900 0x6902)))
10564(neverallowx hal_cas_server domain (ioctl rawip_socket (0x6900 0x6902)))
10565;;* lme
10566
10567;;* lmx 43 system/sepolicy/public/hal_cas.te
10568
10569(neverallowx hal_cas_server domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10570(neverallowx hal_cas_server domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10571(neverallowx hal_cas_server domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10572;;* lme
10573
10574;;* lmx 43 system/sepolicy/public/hal_cas.te
10575
10576(neverallowx hal_cas_server domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10577(neverallowx hal_cas_server domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10578(neverallowx hal_cas_server domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10579;;* lme
10580
10581(allow hal_codec2_client media_variant_prop (file (read getattr map open)))
10582(allow hal_codec2_server media_variant_prop (file (read getattr map open)))
10583(allow hal_codec2_client codec2_config_prop (file (read getattr map open)))
10584(allow hal_codec2_server codec2_config_prop (file (read getattr map open)))
10585(allow hal_codec2_client hal_codec2_server (binder (call transfer)))
10586(allow hal_codec2_server hal_codec2_client (binder (transfer)))
10587(allow hal_codec2_client hal_codec2_server (fd (use)))
10588(allow hal_codec2_server hal_codec2_client (binder (call transfer)))
10589(allow hal_codec2_client hal_codec2_server (binder (transfer)))
10590(allow hal_codec2_server hal_codec2_client (fd (use)))
10591(allow hal_codec2_client hal_codec2_hwservice (hwservice_manager (find)))
10592(allow hal_codec2_server hal_codec2_hwservice (hwservice_manager (add find)))
10593(allow hal_codec2_server hidl_base_hwservice (hwservice_manager (add)))
10594;;* lmx 9 system/sepolicy/public/hal_codec2.te
10595
10596(neverallow base_typeattr_379 hal_codec2_hwservice (hwservice_manager (add)))
10597;;* lme
10598
10599;;* lmx 9 system/sepolicy/public/hal_codec2.te
10600
10601(neverallow base_typeattr_380 hal_codec2_hwservice (hwservice_manager (find)))
10602;;* lme
10603
10604(allow hal_codec2_client hal_codec2_service (service_manager (find)))
10605(allow hal_codec2_server hal_codec2_service (service_manager (add find)))
10606;;* lmx 10 system/sepolicy/public/hal_codec2.te
10607
10608(neverallow base_typeattr_379 hal_codec2_service (service_manager (add)))
10609;;* lme
10610
10611;;* lmx 10 system/sepolicy/public/hal_codec2.te
10612
10613(neverallow base_typeattr_381 hal_codec2_service (service_manager (find)))
10614;;* lme
10615
10616(allow hal_codec2_server hal_graphics_composer (fd (use)))
10617(allow hal_codec2_server ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10618(allow hal_codec2_server hal_camera (fd (use)))
10619(allow hal_codec2_server bufferhubd (fd (use)))
10620(allow hal_codec2_client ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
10621(allow hal_codec2_server su (fifo_file (read)))
10622(allow hal_codec2_server mediaserver (fifo_file (read)))
10623(allow hal_codec2_server base_typeattr_382 (fifo_file (read)))
10624(allow hal_configstore_client hal_configstore_server (binder (call transfer)))
10625(allow hal_configstore_server hal_configstore_client (binder (transfer)))
10626(allow hal_configstore_client hal_configstore_server (fd (use)))
10627(allow hal_configstore_client hal_configstore_ISurfaceFlingerConfigs (hwservice_manager (find)))
10628(allow hal_configstore_server hal_configstore_ISurfaceFlingerConfigs (hwservice_manager (add find)))
10629(allow hal_configstore_server hidl_base_hwservice (hwservice_manager (add)))
10630;;* lmx 4 system/sepolicy/public/hal_configstore.te
10631
10632(neverallow base_typeattr_383 hal_configstore_ISurfaceFlingerConfigs (hwservice_manager (add)))
10633;;* lme
10634
10635;;* lmx 4 system/sepolicy/public/hal_configstore.te
10636
10637(neverallow base_typeattr_384 hal_configstore_ISurfaceFlingerConfigs (hwservice_manager (find)))
10638;;* lme
10639
10640(allow hal_configstore_server anr_data_file (file (append)))
10641(allow hal_configstore_server dumpstate (fd (use)))
10642(allow hal_configstore_server incidentd (fd (use)))
10643(allow hal_configstore_server dumpstate (fifo_file (write append)))
10644(allow hal_configstore_server incidentd (fifo_file (write append)))
10645(allow hal_configstore_server system_server (fifo_file (write append)))
10646(allow hal_configstore_server tombstoned (unix_stream_socket (connectto)))
10647(allow hal_configstore_server tombstoned (fd (use)))
10648(allow hal_configstore_server tombstoned_crash_socket (sock_file (write)))
10649(allow hal_configstore_server tombstone_data_file (file (append)))
10650;;* lmx 15 system/sepolicy/public/hal_configstore.te
10651
10652(neverallow hal_configstore_server fs_type (file (execute_no_trans)))
10653(neverallow hal_configstore_server file_type (file (execute_no_trans)))
10654;;* lme
10655
10656;;* lmx 29 system/sepolicy/public/hal_configstore.te
10657
10658(neverallow hal_configstore_server domain (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10659(neverallow hal_configstore_server domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
10660(neverallow hal_configstore_server domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
10661(neverallow hal_configstore_server domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
10662(neverallow hal_configstore_server domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10663(neverallow hal_configstore_server domain (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10664(neverallow hal_configstore_server domain (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10665(neverallow hal_configstore_server domain (netlink_route_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh)))
10666(neverallow hal_configstore_server domain (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
10667(neverallow hal_configstore_server domain (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10668(neverallow hal_configstore_server domain (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
10669(neverallow hal_configstore_server domain (netlink_selinux_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10670(neverallow hal_configstore_server domain (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
10671(neverallow hal_configstore_server domain (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10672(neverallow hal_configstore_server domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10673(neverallow hal_configstore_server domain (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10674(neverallow hal_configstore_server domain (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
10675(neverallow hal_configstore_server domain (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10676(neverallow hal_configstore_server domain (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10677(neverallow hal_configstore_server domain (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10678(neverallow hal_configstore_server domain (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10679(neverallow hal_configstore_server domain (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10680(neverallow hal_configstore_server domain (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10681(neverallow hal_configstore_server domain (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10682(neverallow hal_configstore_server domain (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10683;;* lme
10684
10685;;* lmx 37 system/sepolicy/public/hal_configstore.te
10686
10687(neverallow hal_configstore_server base_typeattr_385 (unix_stream_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind connectto)))
10688(neverallow hal_configstore_server base_typeattr_385 (unix_dgram_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
10689;;* lme
10690
10691;;* lmx 45 system/sepolicy/public/hal_configstore.te
10692
10693(neverallow hal_configstore_server base_typeattr_386 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10694(neverallow hal_configstore_server base_typeattr_386 (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
10695(neverallow hal_configstore_server base_typeattr_386 (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
10696;;* lme
10697
10698;;* lmx 51 system/sepolicy/public/hal_configstore.te
10699
10700(neverallow hal_configstore_server sdcard_type (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10701(neverallow hal_configstore_server fuse (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10702(neverallow hal_configstore_server fuseblk (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10703(neverallow hal_configstore_server sdcardfs (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10704(neverallow hal_configstore_server vfat (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10705(neverallow hal_configstore_server exfat (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
10706;;* lme
10707
10708;;* lmx 55 system/sepolicy/public/hal_configstore.te
10709
10710(neverallow hal_configstore_server sdcard_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10711(neverallow hal_configstore_server fuse (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10712(neverallow hal_configstore_server fuseblk (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10713(neverallow hal_configstore_server sdcardfs (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10714(neverallow hal_configstore_server vfat (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10715(neverallow hal_configstore_server exfat (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
10716;;* lme
10717
10718;;* lmx 58 system/sepolicy/public/hal_configstore.te
10719
10720(neverallow hal_configstore_server base_typeattr_224 (service_manager (add find list)))
10721;;* lme
10722
10723;;* lmx 61 system/sepolicy/public/hal_configstore.te
10724
10725(neverallow hal_configstore_server self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
10726(neverallow hal_configstore_server self (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
10727(neverallow hal_configstore_server self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
10728(neverallow hal_configstore_server self (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
10729;;* lme
10730
10731;;* lmx 64 system/sepolicy/public/hal_configstore.te
10732
10733(neverallow hal_configstore_server base_typeattr_224 (process (ptrace)))
10734;;* lme
10735
10736;;* lmx 67 system/sepolicy/public/hal_configstore.te
10737
10738(neverallow hal_configstore_server base_typeattr_224 (file (relabelfrom relabelto)))
10739(neverallow hal_configstore_server base_typeattr_224 (dir (relabelfrom relabelto)))
10740(neverallow hal_configstore_server base_typeattr_224 (lnk_file (relabelfrom relabelto)))
10741(neverallow hal_configstore_server base_typeattr_224 (chr_file (relabelfrom relabelto)))
10742(neverallow hal_configstore_server base_typeattr_224 (blk_file (relabelfrom relabelto)))
10743(neverallow hal_configstore_server base_typeattr_224 (sock_file (relabelfrom relabelto)))
10744(neverallow hal_configstore_server base_typeattr_224 (fifo_file (relabelfrom relabelto)))
10745;;* lme
10746
10747(allow hal_confirmationui_client hal_confirmationui_server (binder (call transfer)))
10748(allow hal_confirmationui_server hal_confirmationui_client (binder (transfer)))
10749(allow hal_confirmationui_client hal_confirmationui_server (fd (use)))
10750(allow hal_confirmationui_client hal_confirmationui_hwservice (hwservice_manager (find)))
10751(allow hal_confirmationui_server hal_confirmationui_hwservice (hwservice_manager (add find)))
10752(allow hal_confirmationui_server hidl_base_hwservice (hwservice_manager (add)))
10753;;* lmx 4 system/sepolicy/public/hal_confirmationui.te
10754
10755(neverallow base_typeattr_387 hal_confirmationui_hwservice (hwservice_manager (add)))
10756;;* lme
10757
10758;;* lmx 4 system/sepolicy/public/hal_confirmationui.te
10759
10760(neverallow base_typeattr_388 hal_confirmationui_hwservice (hwservice_manager (find)))
10761;;* lme
10762
10763(allow hal_confirmationui_client hal_confirmationui_service (service_manager (find)))
10764(allow hal_confirmationui_server hal_confirmationui_service (service_manager (add find)))
10765;;* lmx 5 system/sepolicy/public/hal_confirmationui.te
10766
10767(neverallow base_typeattr_387 hal_confirmationui_service (service_manager (add)))
10768;;* lme
10769
10770;;* lmx 5 system/sepolicy/public/hal_confirmationui.te
10771
10772(neverallow base_typeattr_389 hal_confirmationui_service (service_manager (find)))
10773;;* lme
10774
10775(allow hal_confirmationui_server servicemanager (binder (call transfer)))
10776(allow servicemanager hal_confirmationui_server (binder (transfer)))
10777(allow hal_confirmationui_server servicemanager (fd (use)))
10778(allow hal_contexthub_client hal_contexthub_server (binder (call transfer)))
10779(allow hal_contexthub_server hal_contexthub_client (binder (transfer)))
10780(allow hal_contexthub_client hal_contexthub_server (fd (use)))
10781(allow hal_contexthub_server hal_contexthub_client (binder (call transfer)))
10782(allow hal_contexthub_client hal_contexthub_server (binder (transfer)))
10783(allow hal_contexthub_server hal_contexthub_client (fd (use)))
10784(allow hal_contexthub_server hal_contexthub_service (service_manager (add find)))
10785;;* lmx 5 system/sepolicy/public/hal_contexthub.te
10786
10787(neverallow base_typeattr_390 hal_contexthub_service (service_manager (add)))
10788;;* lme
10789
10790(allow hal_contexthub_server servicemanager (binder (call transfer)))
10791(allow servicemanager hal_contexthub_server (binder (transfer)))
10792(allow hal_contexthub_server servicemanager (fd (use)))
10793(allow hal_contexthub_client hal_contexthub_service (service_manager (find)))
10794(allow hal_contexthub_client hal_contexthub_hwservice (hwservice_manager (find)))
10795(allow hal_contexthub_server hal_contexthub_hwservice (hwservice_manager (add find)))
10796(allow hal_contexthub_server hidl_base_hwservice (hwservice_manager (add)))
10797;;* lmx 10 system/sepolicy/public/hal_contexthub.te
10798
10799(neverallow base_typeattr_390 hal_contexthub_hwservice (hwservice_manager (add)))
10800;;* lme
10801
10802;;* lmx 10 system/sepolicy/public/hal_contexthub.te
10803
10804(neverallow base_typeattr_391 hal_contexthub_hwservice (hwservice_manager (find)))
10805;;* lme
10806
10807(allow hal_drm_server servicemanager (binder (call transfer)))
10808(allow servicemanager hal_drm_server (binder (call transfer)))
10809(allow servicemanager hal_drm_server (dir (search)))
10810(allow servicemanager hal_drm_server (file (read open)))
10811(allow servicemanager hal_drm_server (process (getattr)))
10812(allow hal_drm_client hal_drm_server (binder (call transfer)))
10813(allow hal_drm_server hal_drm_client (binder (transfer)))
10814(allow hal_drm_client hal_drm_server (fd (use)))
10815(allow hal_drm_server hal_drm_client (binder (call transfer)))
10816(allow hal_drm_client hal_drm_server (binder (transfer)))
10817(allow hal_drm_server hal_drm_client (fd (use)))
10818(allow hal_drm_client hal_drm_hwservice (hwservice_manager (find)))
10819(allow hal_drm_server hal_drm_hwservice (hwservice_manager (add find)))
10820(allow hal_drm_server hidl_base_hwservice (hwservice_manager (add)))
10821;;* lmx 6 system/sepolicy/public/hal_drm.te
10822
10823(neverallow base_typeattr_392 hal_drm_hwservice (hwservice_manager (add)))
10824;;* lme
10825
10826;;* lmx 6 system/sepolicy/public/hal_drm.te
10827
10828(neverallow base_typeattr_393 hal_drm_hwservice (hwservice_manager (find)))
10829;;* lme
10830
10831(allow hal_drm_client hal_drm_service (service_manager (find)))
10832(allow hal_drm_server hal_drm_service (service_manager (add find)))
10833;;* lmx 7 system/sepolicy/public/hal_drm.te
10834
10835(neverallow base_typeattr_392 hal_drm_service (service_manager (add)))
10836;;* lme
10837
10838;;* lmx 7 system/sepolicy/public/hal_drm.te
10839
10840(neverallow base_typeattr_394 hal_drm_service (service_manager (find)))
10841;;* lme
10842
10843(allow hal_drm hidl_memory_hwservice (hwservice_manager (find)))
10844(allow hal_drm self (process (execmem)))
10845(allow hal_drm_server serialno_prop (file (read getattr map open)))
10846(allow hal_drm_server drm_forcel3_prop (file (read getattr map open)))
10847(allow hal_drm system_data_file (file (read getattr)))
10848(allow hal_drm cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
10849(allow hal_drm cgroup (file (ioctl read getattr lock map open watch watch_reads)))
10850(allow hal_drm cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10851(allow hal_drm cgroup (dir (write search)))
10852(allow hal_drm cgroup (file (write lock append map open)))
10853(allow hal_drm cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
10854(allow hal_drm cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
10855(allow hal_drm cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10856(allow hal_drm cgroup_v2 (dir (write search)))
10857(allow hal_drm cgroup_v2 (file (write lock append map open)))
10858(allow hal_drm ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10859(allow hal_drm hal_graphics_allocator (fd (use)))
10860(allow hal_drm hal_allocator_server (fd (use)))
10861(allow hal_drm mediaserver (fd (use)))
10862(allow hal_drm sysfs (file (ioctl read getattr lock map open watch watch_reads)))
10863(allow hal_drm tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
10864(allow hal_drm_server base_typeattr_369 (fd (use)))
10865(allowx hal_drm self (ioctl tcp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
10866(allowx hal_drm self (ioctl udp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
10867(allowx hal_drm self (ioctl rawip_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
10868(allowx hal_drm self (ioctl tcp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
10869(allowx hal_drm self (ioctl udp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
10870(allowx hal_drm self (ioctl rawip_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
10871(allowx hal_drm self (ioctl tcp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
10872(allowx hal_drm self (ioctl udp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
10873(allowx hal_drm self (ioctl rawip_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
10874;;* lmx 63 system/sepolicy/public/hal_drm.te
10875
10876(neverallow hal_drm_server fs_type (file (execute_no_trans)))
10877(neverallow hal_drm_server file_type (file (execute_no_trans)))
10878;;* lme
10879
10880;;* lmx 66 system/sepolicy/public/hal_drm.te
10881
10882(neverallowx hal_drm_server domain (ioctl tcp_socket (0x6900 0x6902)))
10883(neverallowx hal_drm_server domain (ioctl udp_socket (0x6900 0x6902)))
10884(neverallowx hal_drm_server domain (ioctl rawip_socket (0x6900 0x6902)))
10885;;* lme
10886
10887;;* lmx 66 system/sepolicy/public/hal_drm.te
10888
10889(neverallowx hal_drm_server domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10890(neverallowx hal_drm_server domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10891(neverallowx hal_drm_server domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
10892;;* lme
10893
10894;;* lmx 66 system/sepolicy/public/hal_drm.te
10895
10896(neverallowx hal_drm_server domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10897(neverallowx hal_drm_server domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10898(neverallowx hal_drm_server domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
10899;;* lme
10900
10901(allow hal_dumpstate_client hal_dumpstate_server (binder (call transfer)))
10902(allow hal_dumpstate_server hal_dumpstate_client (binder (transfer)))
10903(allow hal_dumpstate_client hal_dumpstate_server (fd (use)))
10904(allow hal_dumpstate_server hal_dumpstate_client (binder (call transfer)))
10905(allow hal_dumpstate_client hal_dumpstate_server (binder (transfer)))
10906(allow hal_dumpstate_server hal_dumpstate_client (fd (use)))
10907(allow hal_dumpstate_server property_socket (sock_file (write)))
10908(allow hal_dumpstate_server init (unix_stream_socket (connectto)))
10909(allow hal_dumpstate_server hal_dumpstate_config_prop (property_service (set)))
10910(allow hal_dumpstate_server hal_dumpstate_config_prop (file (read getattr map open)))
10911(allow hal_dumpstate_client hal_dumpstate_hwservice (hwservice_manager (find)))
10912(allow hal_dumpstate_server hal_dumpstate_hwservice (hwservice_manager (add find)))
10913(allow hal_dumpstate_server hidl_base_hwservice (hwservice_manager (add)))
10914;;* lmx 7 system/sepolicy/public/hal_dumpstate.te
10915
10916(neverallow base_typeattr_395 hal_dumpstate_hwservice (hwservice_manager (add)))
10917;;* lme
10918
10919;;* lmx 7 system/sepolicy/public/hal_dumpstate.te
10920
10921(neverallow base_typeattr_396 hal_dumpstate_hwservice (hwservice_manager (find)))
10922;;* lme
10923
10924(allow hal_dumpstate_client hal_dumpstate_service (service_manager (find)))
10925(allow hal_dumpstate_server hal_dumpstate_service (service_manager (add find)))
10926;;* lmx 8 system/sepolicy/public/hal_dumpstate.te
10927
10928(neverallow base_typeattr_395 hal_dumpstate_service (service_manager (add)))
10929;;* lme
10930
10931;;* lmx 8 system/sepolicy/public/hal_dumpstate.te
10932
10933(neverallow base_typeattr_397 hal_dumpstate_service (service_manager (find)))
10934;;* lme
10935
10936(allow hal_dumpstate_server servicemanager (binder (call transfer)))
10937(allow servicemanager hal_dumpstate_server (binder (transfer)))
10938(allow hal_dumpstate_server servicemanager (fd (use)))
10939(allow hal_dumpstate_server servicemanager (binder (call transfer)))
10940(allow servicemanager hal_dumpstate_server (binder (call transfer)))
10941(allow servicemanager hal_dumpstate_server (dir (search)))
10942(allow servicemanager hal_dumpstate_server (file (read open)))
10943(allow servicemanager hal_dumpstate_server (process (getattr)))
10944(allow hal_dumpstate shell_data_file (file (write)))
10945(allow hal_dumpstate proc_interrupts (file (ioctl read getattr lock map open watch watch_reads)))
10946(allow hal_dumpstate fscklogs (dir (ioctl read getattr lock open watch watch_reads search)))
10947(allow hal_dumpstate fscklogs (file (ioctl read getattr lock map open watch watch_reads)))
10948(allow hal_dumpstate fscklogs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
10949(allow hal_evs_client hwservicemanager (binder (call transfer)))
10950(allow hwservicemanager hal_evs_client (binder (call transfer)))
10951(allow hwservicemanager hal_evs_client (dir (search)))
10952(allow hwservicemanager hal_evs_client (file (read map open)))
10953(allow hwservicemanager hal_evs_client (process (getattr)))
10954(allow hal_evs_server hwservicemanager (binder (call transfer)))
10955(allow hwservicemanager hal_evs_server (binder (call transfer)))
10956(allow hwservicemanager hal_evs_server (dir (search)))
10957(allow hwservicemanager hal_evs_server (file (read map open)))
10958(allow hwservicemanager hal_evs_server (process (getattr)))
10959(allow hal_evs_client hal_evs_server (binder (call transfer)))
10960(allow hal_evs_server hal_evs_client (binder (transfer)))
10961(allow hal_evs_client hal_evs_server (fd (use)))
10962(allow hal_evs_server hal_evs_client (binder (call transfer)))
10963(allow hal_evs_client hal_evs_server (binder (transfer)))
10964(allow hal_evs_server hal_evs_client (fd (use)))
10965(allow hal_evs_client hal_evs_hwservice (hwservice_manager (find)))
10966(allow hal_evs_server hal_evs_hwservice (hwservice_manager (add find)))
10967(allow hal_evs_server hidl_base_hwservice (hwservice_manager (add)))
10968;;* lmx 12 system/sepolicy/public/hal_evs.te
10969
10970(neverallow base_typeattr_398 hal_evs_hwservice (hwservice_manager (add)))
10971;;* lme
10972
10973(allow hal_evs_client hal_evs_service (service_manager (find)))
10974(allow hal_evs_server hal_evs_service (service_manager (add find)))
10975;;* lmx 15 system/sepolicy/public/hal_evs.te
10976
10977(neverallow base_typeattr_399 hal_evs_service (service_manager (add)))
10978;;* lme
10979
10980;;* lmx 15 system/sepolicy/public/hal_evs.te
10981
10982(neverallow base_typeattr_400 hal_evs_service (service_manager (find)))
10983;;* lme
10984
10985(allow hal_face_client hal_face_server (binder (call transfer)))
10986(allow hal_face_server hal_face_client (binder (transfer)))
10987(allow hal_face_client hal_face_server (fd (use)))
10988(allow hal_face_server hal_face_client (binder (call transfer)))
10989(allow hal_face_client hal_face_server (binder (transfer)))
10990(allow hal_face_server hal_face_client (fd (use)))
10991(allow hal_face_client hal_face_hwservice (hwservice_manager (find)))
10992(allow hal_face_server hal_face_hwservice (hwservice_manager (add find)))
10993(allow hal_face_server hidl_base_hwservice (hwservice_manager (add)))
10994;;* lmx 5 system/sepolicy/public/hal_face.te
10995
10996(neverallow base_typeattr_401 hal_face_hwservice (hwservice_manager (add)))
10997;;* lme
10998
10999;;* lmx 5 system/sepolicy/public/hal_face.te
11000
11001(neverallow base_typeattr_402 hal_face_hwservice (hwservice_manager (find)))
11002;;* lme
11003
11004(allow hal_face_client hal_face_service (service_manager (find)))
11005(allow hal_face_server hal_face_service (service_manager (add find)))
11006;;* lmx 6 system/sepolicy/public/hal_face.te
11007
11008(neverallow base_typeattr_401 hal_face_service (service_manager (add)))
11009;;* lme
11010
11011;;* lmx 6 system/sepolicy/public/hal_face.te
11012
11013(neverallow base_typeattr_403 hal_face_service (service_manager (find)))
11014;;* lme
11015
11016(allow hal_face_server servicemanager (binder (call transfer)))
11017(allow servicemanager hal_face_server (binder (call transfer)))
11018(allow servicemanager hal_face_server (dir (search)))
11019(allow servicemanager hal_face_server (file (read open)))
11020(allow servicemanager hal_face_server (process (getattr)))
11021(allow hal_face ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11022(allow hal_face face_vendor_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
11023(allow hal_face face_vendor_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
11024(allow hal_fastboot_client hal_fastboot_server (binder (call transfer)))
11025(allow hal_fastboot_server hal_fastboot_client (binder (transfer)))
11026(allow hal_fastboot_client hal_fastboot_server (fd (use)))
11027(allow hal_fastboot_client hal_fastboot_service (service_manager (find)))
11028(allow hal_fastboot_server hal_fastboot_service (service_manager (add find)))
11029;;* lmx 4 system/sepolicy/public/hal_fastboot.te
11030
11031(neverallow base_typeattr_404 hal_fastboot_service (service_manager (add)))
11032;;* lme
11033
11034;;* lmx 4 system/sepolicy/public/hal_fastboot.te
11035
11036(neverallow base_typeattr_405 hal_fastboot_service (service_manager (find)))
11037;;* lme
11038
11039(allow hal_fastboot_server servicemanager (binder (call transfer)))
11040(allow servicemanager hal_fastboot_server (binder (transfer)))
11041(allow hal_fastboot_server servicemanager (fd (use)))
11042(allow hal_fingerprint_client hal_fingerprint_server (binder (call transfer)))
11043(allow hal_fingerprint_server hal_fingerprint_client (binder (transfer)))
11044(allow hal_fingerprint_client hal_fingerprint_server (fd (use)))
11045(allow hal_fingerprint_server hal_fingerprint_client (binder (call transfer)))
11046(allow hal_fingerprint_client hal_fingerprint_server (binder (transfer)))
11047(allow hal_fingerprint_server hal_fingerprint_client (fd (use)))
11048(allow hal_fingerprint_client hal_fingerprint_hwservice (hwservice_manager (find)))
11049(allow hal_fingerprint_server hal_fingerprint_hwservice (hwservice_manager (add find)))
11050(allow hal_fingerprint_server hidl_base_hwservice (hwservice_manager (add)))
11051;;* lmx 5 system/sepolicy/public/hal_fingerprint.te
11052
11053(neverallow base_typeattr_406 hal_fingerprint_hwservice (hwservice_manager (add)))
11054;;* lme
11055
11056;;* lmx 5 system/sepolicy/public/hal_fingerprint.te
11057
11058(neverallow base_typeattr_407 hal_fingerprint_hwservice (hwservice_manager (find)))
11059;;* lme
11060
11061(allow hal_fingerprint_client hal_fingerprint_service (service_manager (find)))
11062(allow hal_fingerprint_server hal_fingerprint_service (service_manager (add find)))
11063;;* lmx 6 system/sepolicy/public/hal_fingerprint.te
11064
11065(neverallow base_typeattr_406 hal_fingerprint_service (service_manager (add)))
11066;;* lme
11067
11068;;* lmx 6 system/sepolicy/public/hal_fingerprint.te
11069
11070(neverallow base_typeattr_408 hal_fingerprint_service (service_manager (find)))
11071;;* lme
11072
11073(allow hal_fingerprint_server servicemanager (binder (call transfer)))
11074(allow servicemanager hal_fingerprint_server (binder (call transfer)))
11075(allow servicemanager hal_fingerprint_server (dir (search)))
11076(allow servicemanager hal_fingerprint_server (file (read open)))
11077(allow servicemanager hal_fingerprint_server (process (getattr)))
11078(allow hal_fingerprint ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11079(allow hal_fingerprint fingerprint_vendor_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
11080(allow hal_fingerprint fingerprint_vendor_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
11081(allow hal_fingerprint cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
11082(allow hal_fingerprint cgroup (file (ioctl read getattr lock map open watch watch_reads)))
11083(allow hal_fingerprint cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
11084(allow hal_fingerprint cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
11085(allow hal_fingerprint cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
11086(allow hal_fingerprint cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
11087(allow hal_fingerprint sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
11088(allow hal_fingerprint sysfs (file (ioctl read getattr lock map open watch watch_reads)))
11089(allow hal_fingerprint sysfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
11090(allow hal_gatekeeper_client hal_gatekeeper_server (binder (call transfer)))
11091(allow hal_gatekeeper_server hal_gatekeeper_client (binder (transfer)))
11092(allow hal_gatekeeper_client hal_gatekeeper_server (fd (use)))
11093(allow hal_gatekeeper_client hal_gatekeeper_hwservice (hwservice_manager (find)))
11094(allow hal_gatekeeper_server hal_gatekeeper_hwservice (hwservice_manager (add find)))
11095(allow hal_gatekeeper_server hidl_base_hwservice (hwservice_manager (add)))
11096;;* lmx 3 system/sepolicy/public/hal_gatekeeper.te
11097
11098(neverallow base_typeattr_409 hal_gatekeeper_hwservice (hwservice_manager (add)))
11099;;* lme
11100
11101;;* lmx 3 system/sepolicy/public/hal_gatekeeper.te
11102
11103(neverallow base_typeattr_410 hal_gatekeeper_hwservice (hwservice_manager (find)))
11104;;* lme
11105
11106(allow hal_gatekeeper_client hal_gatekeeper_service (service_manager (find)))
11107(allow hal_gatekeeper_server hal_gatekeeper_service (service_manager (add find)))
11108;;* lmx 4 system/sepolicy/public/hal_gatekeeper.te
11109
11110(neverallow base_typeattr_409 hal_gatekeeper_service (service_manager (add)))
11111;;* lme
11112
11113;;* lmx 4 system/sepolicy/public/hal_gatekeeper.te
11114
11115(neverallow base_typeattr_411 hal_gatekeeper_service (service_manager (find)))
11116;;* lme
11117
11118(allow hal_gatekeeper_server servicemanager (binder (call transfer)))
11119(allow servicemanager hal_gatekeeper_server (binder (transfer)))
11120(allow hal_gatekeeper_server servicemanager (fd (use)))
11121(allow hal_gatekeeper tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11122(allow hal_gatekeeper ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11123(allow hal_gnss_client hal_gnss_server (binder (call transfer)))
11124(allow hal_gnss_server hal_gnss_client (binder (transfer)))
11125(allow hal_gnss_client hal_gnss_server (fd (use)))
11126(allow hal_gnss_server hal_gnss_client (binder (call transfer)))
11127(allow hal_gnss_client hal_gnss_server (binder (transfer)))
11128(allow hal_gnss_server hal_gnss_client (fd (use)))
11129(allow hal_gnss_client hal_gnss_hwservice (hwservice_manager (find)))
11130(allow hal_gnss_server hal_gnss_hwservice (hwservice_manager (add find)))
11131(allow hal_gnss_server hidl_base_hwservice (hwservice_manager (add)))
11132;;* lmx 5 system/sepolicy/public/hal_gnss.te
11133
11134(neverallow base_typeattr_412 hal_gnss_hwservice (hwservice_manager (add)))
11135;;* lme
11136
11137;;* lmx 5 system/sepolicy/public/hal_gnss.te
11138
11139(neverallow base_typeattr_413 hal_gnss_hwservice (hwservice_manager (find)))
11140;;* lme
11141
11142(allow hal_gnss_client hal_gnss_service (service_manager (find)))
11143(allow hal_gnss_server hal_gnss_service (service_manager (add find)))
11144;;* lmx 6 system/sepolicy/public/hal_gnss.te
11145
11146(neverallow base_typeattr_412 hal_gnss_service (service_manager (add)))
11147;;* lme
11148
11149;;* lmx 6 system/sepolicy/public/hal_gnss.te
11150
11151(neverallow base_typeattr_414 hal_gnss_service (service_manager (find)))
11152;;* lme
11153
11154(allow hal_gnss_server servicemanager (binder (call transfer)))
11155(allow servicemanager hal_gnss_server (binder (call transfer)))
11156(allow servicemanager hal_gnss_server (dir (search)))
11157(allow servicemanager hal_gnss_server (file (read open)))
11158(allow servicemanager hal_gnss_server (process (getattr)))
11159(allow hal_gnss_client servicemanager (binder (call transfer)))
11160(allow servicemanager hal_gnss_client (binder (call transfer)))
11161(allow servicemanager hal_gnss_client (dir (search)))
11162(allow servicemanager hal_gnss_client (file (read open)))
11163(allow servicemanager hal_gnss_client (process (getattr)))
11164(allow hal_graphics_allocator_client hal_graphics_allocator_server (binder (call transfer)))
11165(allow hal_graphics_allocator_server hal_graphics_allocator_client (binder (transfer)))
11166(allow hal_graphics_allocator_client hal_graphics_allocator_server (fd (use)))
11167(allow hal_graphics_allocator_client hal_graphics_allocator_hwservice (hwservice_manager (find)))
11168(allow hal_graphics_allocator_server hal_graphics_allocator_hwservice (hwservice_manager (add find)))
11169(allow hal_graphics_allocator_server hidl_base_hwservice (hwservice_manager (add)))
11170;;* lmx 4 system/sepolicy/public/hal_graphics_allocator.te
11171
11172(neverallow base_typeattr_415 hal_graphics_allocator_hwservice (hwservice_manager (add)))
11173;;* lme
11174
11175;;* lmx 4 system/sepolicy/public/hal_graphics_allocator.te
11176
11177(neverallow base_typeattr_416 hal_graphics_allocator_hwservice (hwservice_manager (find)))
11178;;* lme
11179
11180(allow hal_graphics_allocator_client hal_graphics_mapper_hwservice (hwservice_manager (find)))
11181(allow hal_graphics_allocator_client hal_graphics_mapper_service (service_manager (find)))
11182(allow hal_graphics_allocator_client same_process_hal_file (file (read getattr map execute open)))
11183(allow hal_graphics_allocator gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11184(allow hal_graphics_allocator gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
11185(allow hal_graphics_allocator ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11186(allow hal_graphics_allocator dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11187(allow hal_graphics_allocator dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11188(allow hal_graphics_allocator self (capability (sys_nice)))
11189(allow hal_graphics_allocator self (cap_userns (sys_nice)))
11190(allow hal_graphics_allocator_client hal_graphics_allocator_service (service_manager (find)))
11191(allow hal_graphics_allocator_server hal_graphics_allocator_service (service_manager (add find)))
11192;;* lmx 22 system/sepolicy/public/hal_graphics_allocator.te
11193
11194(neverallow base_typeattr_415 hal_graphics_allocator_service (service_manager (add)))
11195;;* lme
11196
11197;;* lmx 22 system/sepolicy/public/hal_graphics_allocator.te
11198
11199(neverallow base_typeattr_417 hal_graphics_allocator_service (service_manager (find)))
11200;;* lme
11201
11202(allow hal_graphics_allocator_server servicemanager (binder (call transfer)))
11203(allow servicemanager hal_graphics_allocator_server (binder (transfer)))
11204(allow hal_graphics_allocator_server servicemanager (fd (use)))
11205(allow hal_graphics_allocator_client servicemanager (binder (call transfer)))
11206(allow servicemanager hal_graphics_allocator_client (binder (transfer)))
11207(allow hal_graphics_allocator_client servicemanager (fd (use)))
11208(allow hal_graphics_composer_client hal_graphics_composer_server (binder (call transfer)))
11209(allow hal_graphics_composer_server hal_graphics_composer_client (binder (transfer)))
11210(allow hal_graphics_composer_client hal_graphics_composer_server (fd (use)))
11211(allow hal_graphics_composer_server hal_graphics_composer_client (binder (call transfer)))
11212(allow hal_graphics_composer_client hal_graphics_composer_server (binder (transfer)))
11213(allow hal_graphics_composer_server hal_graphics_composer_client (fd (use)))
11214(allow hal_graphics_composer_client hal_graphics_composer_server_tmpfs (file (read write getattr map)))
11215(allow hal_graphics_composer_server hal_graphics_composer_client_tmpfs (file (read write getattr map)))
11216(allow hal_graphics_composer_client hal_graphics_composer_hwservice (hwservice_manager (find)))
11217(allow hal_graphics_composer_server hal_graphics_composer_hwservice (hwservice_manager (add find)))
11218(allow hal_graphics_composer_server hidl_base_hwservice (hwservice_manager (add)))
11219;;* lmx 11 system/sepolicy/public/hal_graphics_composer.te
11220
11221(neverallow base_typeattr_418 hal_graphics_composer_hwservice (hwservice_manager (add)))
11222;;* lme
11223
11224;;* lmx 11 system/sepolicy/public/hal_graphics_composer.te
11225
11226(neverallow base_typeattr_419 hal_graphics_composer_hwservice (hwservice_manager (find)))
11227;;* lme
11228
11229(allow hal_graphics_composer_server hal_graphics_mapper_hwservice (hwservice_manager (find)))
11230(allow hal_graphics_composer gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11231(allow hal_graphics_composer gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
11232(allow hal_graphics_composer ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11233(allow hal_graphics_composer dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11234(allow hal_graphics_composer hal_graphics_allocator (fd (use)))
11235(allow hal_graphics_composer graphics_device (dir (search)))
11236(allow hal_graphics_composer graphics_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11237(allow hal_graphics_composer system_server (fd (use)))
11238(allow hal_graphics_composer bootanim (fd (use)))
11239(allow hal_graphics_composer appdomain (fd (use)))
11240(allow hal_graphics_composer self (capability (sys_nice)))
11241(allow hal_graphics_composer self (cap_userns (sys_nice)))
11242(allow hal_graphics_composer_server hal_graphics_composer_client (fifo_file (write)))
11243(allow hal_graphics_composer_client servicemanager (binder (call transfer)))
11244(allow servicemanager hal_graphics_composer_client (binder (transfer)))
11245(allow hal_graphics_composer_client servicemanager (fd (use)))
11246(allow hal_graphics_composer_server servicemanager (binder (call transfer)))
11247(allow servicemanager hal_graphics_composer_server (binder (transfer)))
11248(allow hal_graphics_composer_server servicemanager (fd (use)))
11249(allow hal_graphics_composer_client hal_graphics_composer_service (service_manager (find)))
11250(allow hal_graphics_composer_server hal_graphics_composer_service (service_manager (add find)))
11251;;* lmx 42 system/sepolicy/public/hal_graphics_composer.te
11252
11253(neverallow base_typeattr_418 hal_graphics_composer_service (service_manager (add)))
11254;;* lme
11255
11256;;* lmx 42 system/sepolicy/public/hal_graphics_composer.te
11257
11258(neverallow base_typeattr_420 hal_graphics_composer_service (service_manager (find)))
11259;;* lme
11260
11261(allow hal_health_client hal_health_server (binder (call transfer)))
11262(allow hal_health_server hal_health_client (binder (transfer)))
11263(allow hal_health_client hal_health_server (fd (use)))
11264(allow hal_health_server hal_health_client (binder (call transfer)))
11265(allow hal_health_client hal_health_server (binder (transfer)))
11266(allow hal_health_server hal_health_client (fd (use)))
11267(allow hal_health_client hal_health_hwservice (hwservice_manager (find)))
11268(allow hal_health_server hal_health_hwservice (hwservice_manager (add find)))
11269(allow hal_health_server hidl_base_hwservice (hwservice_manager (add)))
11270;;* lmx 5 system/sepolicy/public/hal_health.te
11271
11272(neverallow base_typeattr_421 hal_health_hwservice (hwservice_manager (add)))
11273;;* lme
11274
11275;;* lmx 5 system/sepolicy/public/hal_health.te
11276
11277(neverallow base_typeattr_422 hal_health_hwservice (hwservice_manager (find)))
11278;;* lme
11279
11280(allow hal_health_client hal_health_service (service_manager (find)))
11281(allow hal_health_server hal_health_service (service_manager (add find)))
11282;;* lmx 6 system/sepolicy/public/hal_health.te
11283
11284(neverallow base_typeattr_421 hal_health_service (service_manager (add)))
11285;;* lme
11286
11287;;* lmx 6 system/sepolicy/public/hal_health.te
11288
11289(neverallow base_typeattr_423 hal_health_service (service_manager (find)))
11290;;* lme
11291
11292(allow hal_health_server self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
11293(allow hal_health_server sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
11294(allow hal_health_server sysfs_batteryinfo (dir (ioctl read getattr lock open watch watch_reads search)))
11295(allow hal_health_server sysfs_batteryinfo (file (ioctl read getattr lock map open watch watch_reads)))
11296(allow hal_health_server sysfs_batteryinfo (lnk_file (ioctl read getattr lock map open watch watch_reads)))
11297(allow hal_health_server sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
11298(allow hal_health_server self (capability2 (block_suspend)))
11299(allow hal_health_server self (cap2_userns (block_suspend)))
11300(allow hal_health_server system_suspend_server (binder (call transfer)))
11301(allow system_suspend_server hal_health_server (binder (transfer)))
11302(allow hal_health_server system_suspend_server (fd (use)))
11303(allow hal_health_server system_suspend_hwservice (hwservice_manager (find)))
11304(allow hal_health_server hwservicemanager (binder (call transfer)))
11305(allow hwservicemanager hal_health_server (binder (call transfer)))
11306(allow hwservicemanager hal_health_server (dir (search)))
11307(allow hwservicemanager hal_health_server (file (read map open)))
11308(allow hwservicemanager hal_health_server (process (getattr)))
11309(allow hal_health_server hwservicemanager_prop (file (read getattr map open)))
11310(allow hal_health_server hidl_manager_hwservice (hwservice_manager (find)))
11311(allow hal_health_server hal_system_suspend_service (service_manager (find)))
11312(allow hal_health_server servicemanager (binder (call transfer)))
11313(allow servicemanager hal_health_server (binder (call transfer)))
11314(allow servicemanager hal_health_server (dir (search)))
11315(allow servicemanager hal_health_server (file (read open)))
11316(allow servicemanager hal_health_server (process (getattr)))
11317(allow hal_health_server kmsg_device (chr_file (write getattr lock append map open)))
11318(allow hal_health_server self (capability2 (wake_alarm)))
11319(allow hal_health_server fs_bpf_vendor (dir (search)))
11320(allow hal_health_server fs_bpf_vendor (file (read)))
11321(allow hal_health_server bpfloader (bpf (prog_run)))
11322(allow hal_health_storage_client hal_health_storage_server (binder (call transfer)))
11323(allow hal_health_storage_server hal_health_storage_client (binder (transfer)))
11324(allow hal_health_storage_client hal_health_storage_server (fd (use)))
11325(allow hal_health_storage_server hal_health_storage_client (binder (call transfer)))
11326(allow hal_health_storage_client hal_health_storage_server (binder (transfer)))
11327(allow hal_health_storage_server hal_health_storage_client (fd (use)))
11328(allow hal_health_storage_server servicemanager (binder (call transfer)))
11329(allow servicemanager hal_health_storage_server (binder (call transfer)))
11330(allow servicemanager hal_health_storage_server (dir (search)))
11331(allow servicemanager hal_health_storage_server (file (read open)))
11332(allow servicemanager hal_health_storage_server (process (getattr)))
11333(allow hal_health_storage_client hal_health_storage_hwservice (hwservice_manager (find)))
11334(allow hal_health_storage_server hal_health_storage_hwservice (hwservice_manager (add find)))
11335(allow hal_health_storage_server hidl_base_hwservice (hwservice_manager (add)))
11336;;* lmx 7 system/sepolicy/public/hal_health_storage.te
11337
11338(neverallow base_typeattr_424 hal_health_storage_hwservice (hwservice_manager (add)))
11339;;* lme
11340
11341;;* lmx 7 system/sepolicy/public/hal_health_storage.te
11342
11343(neverallow base_typeattr_425 hal_health_storage_hwservice (hwservice_manager (find)))
11344;;* lme
11345
11346(allow hal_health_storage_client hal_health_storage_service (service_manager (find)))
11347(allow hal_health_storage_server hal_health_storage_service (service_manager (add find)))
11348;;* lmx 8 system/sepolicy/public/hal_health_storage.te
11349
11350(neverallow base_typeattr_424 hal_health_storage_service (service_manager (add)))
11351;;* lme
11352
11353;;* lmx 8 system/sepolicy/public/hal_health_storage.te
11354
11355(neverallow base_typeattr_426 hal_health_storage_service (service_manager (find)))
11356;;* lme
11357
11358(allow hal_health_storage_server gsi_metadata_file_type (dir (search)))
11359(allow hal_health_storage_server metadata_file (dir (search)))
11360(allow hal_health_storage_server gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
11361(allow hal_health_storage_server proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
11362(allow hal_health_storage_server proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
11363(allow hal_identity_client hal_identity_server (binder (call transfer)))
11364(allow hal_identity_server hal_identity_client (binder (transfer)))
11365(allow hal_identity_client hal_identity_server (fd (use)))
11366(allow hal_identity_client hal_identity_service (service_manager (find)))
11367(allow hal_identity_server hal_identity_service (service_manager (add find)))
11368;;* lmx 4 system/sepolicy/public/hal_identity.te
11369
11370(neverallow base_typeattr_427 hal_identity_service (service_manager (add)))
11371;;* lme
11372
11373;;* lmx 4 system/sepolicy/public/hal_identity.te
11374
11375(neverallow base_typeattr_428 hal_identity_service (service_manager (find)))
11376;;* lme
11377
11378(allow hal_identity_server servicemanager (binder (call transfer)))
11379(allow servicemanager hal_identity_server (binder (transfer)))
11380(allow hal_identity_server servicemanager (fd (use)))
11381(allow hal_input_classifier_client hal_input_classifier_server (binder (call transfer)))
11382(allow hal_input_classifier_server hal_input_classifier_client (binder (transfer)))
11383(allow hal_input_classifier_client hal_input_classifier_server (fd (use)))
11384(allow hal_input_classifier_client hal_input_classifier_hwservice (hwservice_manager (find)))
11385(allow hal_input_classifier_server hal_input_classifier_hwservice (hwservice_manager (add find)))
11386(allow hal_input_classifier_server hidl_base_hwservice (hwservice_manager (add)))
11387;;* lmx 4 system/sepolicy/public/hal_input_classifier.te
11388
11389(neverallow base_typeattr_429 hal_input_classifier_hwservice (hwservice_manager (add)))
11390;;* lme
11391
11392;;* lmx 4 system/sepolicy/public/hal_input_classifier.te
11393
11394(neverallow base_typeattr_430 hal_input_classifier_hwservice (hwservice_manager (find)))
11395;;* lme
11396
11397(allow hal_input_processor_client hal_input_processor_server (binder (call transfer)))
11398(allow hal_input_processor_server hal_input_processor_client (binder (transfer)))
11399(allow hal_input_processor_client hal_input_processor_server (fd (use)))
11400(allow hal_input_processor_server servicemanager (binder (call transfer)))
11401(allow servicemanager hal_input_processor_server (binder (transfer)))
11402(allow hal_input_processor_server servicemanager (fd (use)))
11403(allow hal_input_processor_client hal_input_processor_service (service_manager (find)))
11404(allow hal_input_processor_server hal_input_processor_service (service_manager (add find)))
11405;;* lmx 5 system/sepolicy/public/hal_input_processor.te
11406
11407(neverallow base_typeattr_431 hal_input_processor_service (service_manager (add)))
11408;;* lme
11409
11410;;* lmx 5 system/sepolicy/public/hal_input_processor.te
11411
11412(neverallow base_typeattr_432 hal_input_processor_service (service_manager (find)))
11413;;* lme
11414
11415(allow hal_input_processor_server dumpstate (fifo_file (write)))
11416(allow hal_ir_client hal_ir_server (binder (call transfer)))
11417(allow hal_ir_server hal_ir_client (binder (transfer)))
11418(allow hal_ir_client hal_ir_server (fd (use)))
11419(allow hal_ir_server hal_ir_client (binder (call transfer)))
11420(allow hal_ir_client hal_ir_server (binder (transfer)))
11421(allow hal_ir_server hal_ir_client (fd (use)))
11422(allow hal_ir_client hal_ir_service (service_manager (find)))
11423(allow hal_ir_server hal_ir_service (service_manager (add find)))
11424;;* lmx 5 system/sepolicy/public/hal_ir.te
11425
11426(neverallow base_typeattr_433 hal_ir_service (service_manager (add)))
11427;;* lme
11428
11429;;* lmx 5 system/sepolicy/public/hal_ir.te
11430
11431(neverallow base_typeattr_434 hal_ir_service (service_manager (find)))
11432;;* lme
11433
11434(allow hal_ir_server servicemanager (binder (call transfer)))
11435(allow servicemanager hal_ir_server (binder (transfer)))
11436(allow hal_ir_server servicemanager (fd (use)))
11437(allow hal_ir_client hal_ir_hwservice (hwservice_manager (find)))
11438(allow hal_ir_server hal_ir_hwservice (hwservice_manager (add find)))
11439(allow hal_ir_server hidl_base_hwservice (hwservice_manager (add)))
11440;;* lmx 8 system/sepolicy/public/hal_ir.te
11441
11442(neverallow base_typeattr_433 hal_ir_hwservice (hwservice_manager (add)))
11443;;* lme
11444
11445;;* lmx 8 system/sepolicy/public/hal_ir.te
11446
11447(neverallow base_typeattr_435 hal_ir_hwservice (hwservice_manager (find)))
11448;;* lme
11449
11450(allow hal_ivn_client hal_ivn_server (binder (call transfer)))
11451(allow hal_ivn_server hal_ivn_client (binder (transfer)))
11452(allow hal_ivn_client hal_ivn_server (fd (use)))
11453(allow hal_ivn_client hal_ivn_service (service_manager (find)))
11454(allow hal_ivn_server hal_ivn_service (service_manager (add find)))
11455;;* lmx 4 system/sepolicy/public/hal_ivn.te
11456
11457(neverallow base_typeattr_436 hal_ivn_service (service_manager (add)))
11458;;* lme
11459
11460;;* lmx 4 system/sepolicy/public/hal_ivn.te
11461
11462(neverallow base_typeattr_437 hal_ivn_service (service_manager (find)))
11463;;* lme
11464
11465(allow hal_keymaster_client hal_keymaster_server (binder (call transfer)))
11466(allow hal_keymaster_server hal_keymaster_client (binder (transfer)))
11467(allow hal_keymaster_client hal_keymaster_server (fd (use)))
11468(allow hal_keymaster_client hal_keymaster_hwservice (hwservice_manager (find)))
11469(allow hal_keymaster_server hal_keymaster_hwservice (hwservice_manager (add find)))
11470(allow hal_keymaster_server hidl_base_hwservice (hwservice_manager (add)))
11471;;* lmx 4 system/sepolicy/public/hal_keymaster.te
11472
11473(neverallow base_typeattr_438 hal_keymaster_hwservice (hwservice_manager (add)))
11474;;* lme
11475
11476;;* lmx 4 system/sepolicy/public/hal_keymaster.te
11477
11478(neverallow base_typeattr_439 hal_keymaster_hwservice (hwservice_manager (find)))
11479;;* lme
11480
11481(allow hal_keymaster tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11482(allow hal_keymaster ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11483(allow hal_keymint_client hal_keymint_server (binder (call transfer)))
11484(allow hal_keymint_server hal_keymint_client (binder (transfer)))
11485(allow hal_keymint_client hal_keymint_server (fd (use)))
11486(allow hal_keymint_client hal_keymint_service (service_manager (find)))
11487(allow hal_keymint_server hal_keymint_service (service_manager (add find)))
11488;;* lmx 3 system/sepolicy/public/hal_keymint.te
11489
11490(neverallow base_typeattr_440 hal_keymint_service (service_manager (add)))
11491;;* lme
11492
11493;;* lmx 3 system/sepolicy/public/hal_keymint.te
11494
11495(neverallow base_typeattr_441 hal_keymint_service (service_manager (find)))
11496;;* lme
11497
11498(allow hal_keymint_client hal_remotelyprovisionedcomponent_service (service_manager (find)))
11499(allow hal_keymint_server hal_remotelyprovisionedcomponent_service (service_manager (add find)))
11500;;* lmx 4 system/sepolicy/public/hal_keymint.te
11501
11502(neverallow base_typeattr_440 hal_remotelyprovisionedcomponent_service (service_manager (add)))
11503;;* lme
11504
11505;;* lmx 4 system/sepolicy/public/hal_keymint.te
11506
11507(neverallow base_typeattr_441 hal_remotelyprovisionedcomponent_service (service_manager (find)))
11508;;* lme
11509
11510(allow hal_keymint_server servicemanager (binder (call transfer)))
11511(allow servicemanager hal_keymint_server (binder (transfer)))
11512(allow hal_keymint_server servicemanager (fd (use)))
11513(allow hal_keymint_server tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11514(allow hal_keymint_server ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11515(allow hal_light_client hal_light_server (binder (call transfer)))
11516(allow hal_light_server hal_light_client (binder (transfer)))
11517(allow hal_light_client hal_light_server (fd (use)))
11518(allow hal_light_server hal_light_client (binder (call transfer)))
11519(allow hal_light_client hal_light_server (binder (transfer)))
11520(allow hal_light_server hal_light_client (fd (use)))
11521(allow hal_light_client hal_light_hwservice (hwservice_manager (find)))
11522(allow hal_light_server hal_light_hwservice (hwservice_manager (add find)))
11523(allow hal_light_server hidl_base_hwservice (hwservice_manager (add)))
11524;;* lmx 5 system/sepolicy/public/hal_light.te
11525
11526(neverallow base_typeattr_442 hal_light_hwservice (hwservice_manager (add)))
11527;;* lme
11528
11529;;* lmx 5 system/sepolicy/public/hal_light.te
11530
11531(neverallow base_typeattr_443 hal_light_hwservice (hwservice_manager (find)))
11532;;* lme
11533
11534(allow hal_light_client hal_light_service (service_manager (find)))
11535(allow hal_light_server hal_light_service (service_manager (add find)))
11536;;* lmx 6 system/sepolicy/public/hal_light.te
11537
11538(neverallow base_typeattr_442 hal_light_service (service_manager (add)))
11539;;* lme
11540
11541;;* lmx 6 system/sepolicy/public/hal_light.te
11542
11543(neverallow base_typeattr_444 hal_light_service (service_manager (find)))
11544;;* lme
11545
11546(allow hal_light_server servicemanager (binder (call transfer)))
11547(allow servicemanager hal_light_server (binder (transfer)))
11548(allow hal_light_server servicemanager (fd (use)))
11549(allow hal_light_client servicemanager (binder (call transfer)))
11550(allow servicemanager hal_light_client (binder (call transfer)))
11551(allow servicemanager hal_light_client (dir (search)))
11552(allow servicemanager hal_light_client (file (read open)))
11553(allow servicemanager hal_light_client (process (getattr)))
11554(allow hal_light_server dumpstate (fifo_file (write)))
11555(allow hal_light sysfs_leds (lnk_file (read)))
11556(allow hal_light sysfs_leds (file (ioctl read write getattr lock append map open watch watch_reads)))
11557(allow hal_light sysfs_leds (dir (ioctl read getattr lock open watch watch_reads search)))
11558(allow hal_lowpan_client hal_lowpan_server (binder (call transfer)))
11559(allow hal_lowpan_server hal_lowpan_client (binder (transfer)))
11560(allow hal_lowpan_client hal_lowpan_server (fd (use)))
11561(allow hal_lowpan_server hal_lowpan_client (binder (call transfer)))
11562(allow hal_lowpan_client hal_lowpan_server (binder (transfer)))
11563(allow hal_lowpan_server hal_lowpan_client (fd (use)))
11564(allow hal_lowpan_client hal_lowpan_hwservice (hwservice_manager (find)))
11565(allow hal_lowpan_server hal_lowpan_hwservice (hwservice_manager (add find)))
11566(allow hal_lowpan_server hidl_base_hwservice (hwservice_manager (add)))
11567;;* lmx 7 system/sepolicy/public/hal_lowpan.te
11568
11569(neverallow base_typeattr_445 hal_lowpan_hwservice (hwservice_manager (add)))
11570;;* lme
11571
11572;;* lmx 7 system/sepolicy/public/hal_lowpan.te
11573
11574(neverallow base_typeattr_446 hal_lowpan_hwservice (hwservice_manager (find)))
11575;;* lme
11576
11577(allow hal_lowpan_server property_socket (sock_file (write)))
11578(allow hal_lowpan_server init (unix_stream_socket (connectto)))
11579(allow hal_lowpan_server lowpan_prop (property_service (set)))
11580(allow hal_lowpan_server lowpan_prop (file (read getattr map open)))
11581(allow hal_lowpan_server lowpan_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11582;;* lmx 20 system/sepolicy/public/hal_lowpan.te
11583
11584(neverallow base_typeattr_447 lowpan_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
11585;;* lme
11586
11587(allow hal_macsec_client hal_macsec_server (binder (call transfer)))
11588(allow hal_macsec_server hal_macsec_client (binder (transfer)))
11589(allow hal_macsec_client hal_macsec_server (fd (use)))
11590(allow hal_macsec_server hal_macsec_client (binder (call transfer)))
11591(allow hal_macsec_client hal_macsec_server (binder (transfer)))
11592(allow hal_macsec_server hal_macsec_client (fd (use)))
11593(allow hal_macsec_client hal_macsec_service (service_manager (find)))
11594(allow hal_macsec_server hal_macsec_service (service_manager (add find)))
11595;;* lmx 5 system/sepolicy/public/hal_macsec.te
11596
11597(neverallow base_typeattr_448 hal_macsec_service (service_manager (add)))
11598;;* lme
11599
11600;;* lmx 5 system/sepolicy/public/hal_macsec.te
11601
11602(neverallow base_typeattr_449 hal_macsec_service (service_manager (find)))
11603;;* lme
11604
11605(allow hal_macsec_server servicemanager (binder (call transfer)))
11606(allow servicemanager hal_macsec_server (binder (call transfer)))
11607(allow servicemanager hal_macsec_server (dir (search)))
11608(allow servicemanager hal_macsec_server (file (read open)))
11609(allow servicemanager hal_macsec_server (process (getattr)))
11610(allow hal_memtrack_client hal_memtrack_server (binder (call transfer)))
11611(allow hal_memtrack_server hal_memtrack_client (binder (transfer)))
11612(allow hal_memtrack_client hal_memtrack_server (fd (use)))
11613(allow hal_memtrack_client hal_memtrack_hwservice (hwservice_manager (find)))
11614(allow hal_memtrack_server hal_memtrack_hwservice (hwservice_manager (add find)))
11615(allow hal_memtrack_server hidl_base_hwservice (hwservice_manager (add)))
11616;;* lmx 4 system/sepolicy/public/hal_memtrack.te
11617
11618(neverallow base_typeattr_450 hal_memtrack_hwservice (hwservice_manager (add)))
11619;;* lme
11620
11621;;* lmx 4 system/sepolicy/public/hal_memtrack.te
11622
11623(neverallow base_typeattr_451 hal_memtrack_hwservice (hwservice_manager (find)))
11624;;* lme
11625
11626(allow hal_memtrack_client hal_memtrack_service (service_manager (find)))
11627(allow hal_memtrack_server hal_memtrack_service (service_manager (add find)))
11628;;* lmx 6 system/sepolicy/public/hal_memtrack.te
11629
11630(neverallow base_typeattr_450 hal_memtrack_service (service_manager (add)))
11631;;* lme
11632
11633;;* lmx 6 system/sepolicy/public/hal_memtrack.te
11634
11635(neverallow base_typeattr_452 hal_memtrack_service (service_manager (find)))
11636;;* lme
11637
11638(allow hal_memtrack_server servicemanager (binder (call transfer)))
11639(allow servicemanager hal_memtrack_server (binder (transfer)))
11640(allow hal_memtrack_server servicemanager (fd (use)))
11641(allow hal_neuralnetworks_client hal_neuralnetworks_server (binder (call transfer)))
11642(allow hal_neuralnetworks_server hal_neuralnetworks_client (binder (transfer)))
11643(allow hal_neuralnetworks_client hal_neuralnetworks_server (fd (use)))
11644(allow hal_neuralnetworks_server hal_neuralnetworks_client (binder (call transfer)))
11645(allow hal_neuralnetworks_client hal_neuralnetworks_server (binder (transfer)))
11646(allow hal_neuralnetworks_server hal_neuralnetworks_client (fd (use)))
11647(allow hal_neuralnetworks_client hal_neuralnetworks_hwservice (hwservice_manager (find)))
11648(allow hal_neuralnetworks_server hal_neuralnetworks_hwservice (hwservice_manager (add find)))
11649(allow hal_neuralnetworks_server hidl_base_hwservice (hwservice_manager (add)))
11650;;* lmx 5 system/sepolicy/public/hal_neuralnetworks.te
11651
11652(neverallow base_typeattr_453 hal_neuralnetworks_hwservice (hwservice_manager (add)))
11653;;* lme
11654
11655;;* lmx 5 system/sepolicy/public/hal_neuralnetworks.te
11656
11657(neverallow base_typeattr_454 hal_neuralnetworks_hwservice (hwservice_manager (find)))
11658;;* lme
11659
11660(allow hal_neuralnetworks hidl_memory_hwservice (hwservice_manager (find)))
11661(allow hal_neuralnetworks hal_allocator (fd (use)))
11662(allow hal_neuralnetworks hal_graphics_mapper_hwservice (hwservice_manager (find)))
11663(allow hal_neuralnetworks hal_graphics_allocator (fd (use)))
11664(allow hal_neuralnetworks gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11665(allow hal_neuralnetworks gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
11666(allow hal_neuralnetworks_server app_data_file (file (read write getattr map)))
11667(allow hal_neuralnetworks_server privapp_data_file (file (read write getattr map)))
11668(allow hal_neuralnetworks_server shell_data_file (file (read write getattr map)))
11669(allow hal_neuralnetworks_server ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
11670(allow hal_neuralnetworks_server storage_file (file (read getattr map)))
11671(allow hal_neuralnetworks_server apk_data_file (file (read getattr map)))
11672(allow hal_neuralnetworks_client nnapi_ext_deny_product_prop (file (read getattr map open)))
11673(allow hal_neuralnetworks_client device_config_nnapi_native_prop (file (read getattr map open)))
11674;;* lmx 39 system/sepolicy/public/hal_neuralnetworks.te
11675
11676(neverallow base_typeattr_223 nnapi_ext_deny_product_prop (property_service (set)))
11677;;* lme
11678
11679(allow hal_neuralnetworks_client hal_neuralnetworks_service (service_manager (find)))
11680(allow hal_neuralnetworks_server hal_neuralnetworks_service (service_manager (add find)))
11681;;* lmx 42 system/sepolicy/public/hal_neuralnetworks.te
11682
11683(neverallow base_typeattr_453 hal_neuralnetworks_service (service_manager (add)))
11684;;* lme
11685
11686;;* lmx 42 system/sepolicy/public/hal_neuralnetworks.te
11687
11688(neverallow base_typeattr_455 hal_neuralnetworks_service (service_manager (find)))
11689;;* lme
11690
11691(allow hal_neuralnetworks_server servicemanager (binder (call transfer)))
11692(allow servicemanager hal_neuralnetworks_server (binder (transfer)))
11693(allow hal_neuralnetworks_server servicemanager (fd (use)))
11694(allow hal_neuralnetworks_server servicemanager (binder (call transfer)))
11695(allow servicemanager hal_neuralnetworks_server (binder (call transfer)))
11696(allow servicemanager hal_neuralnetworks_server (dir (search)))
11697(allow servicemanager hal_neuralnetworks_server (file (read open)))
11698(allow servicemanager hal_neuralnetworks_server (process (getattr)))
11699(allow hal_neuralnetworks_server dumpstate (fifo_file (write)))
11700;;* lmx 16 system/sepolicy/public/hal_neverallows.te
11701
11702(neverallow base_typeattr_456 self (capability (net_admin net_raw)))
11703(neverallow base_typeattr_456 self (cap_userns (net_admin net_raw)))
11704;;* lme
11705
11706;;* lmx 38 system/sepolicy/public/hal_neverallows.te
11707
11708(neverallow base_typeattr_457 domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
11709(neverallow base_typeattr_457 domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
11710;;* lme
11711
11712;;* lmx 54 system/sepolicy/public/hal_neverallows.te
11713
11714(neverallow base_typeattr_458 domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
11715;;* lme
11716
11717;;* lmx 58 system/sepolicy/public/hal_neverallows.te
11718
11719(neverallow hal_uwb_vendor_server self (capability (net_raw)))
11720(neverallow hal_uwb_vendor_server self (cap_userns (net_raw)))
11721;;* lme
11722
11723;;* lmx 62 system/sepolicy/public/hal_neverallows.te
11724
11725(neverallow hal_uwb_vendor_server domain (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11726(neverallow hal_uwb_vendor_server domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
11727(neverallow hal_uwb_vendor_server domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11728(neverallow hal_uwb_vendor_server domain (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11729(neverallow hal_uwb_vendor_server domain (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11730(neverallow hal_uwb_vendor_server domain (netlink_route_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh)))
11731(neverallow hal_uwb_vendor_server domain (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
11732(neverallow hal_uwb_vendor_server domain (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11733(neverallow hal_uwb_vendor_server domain (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
11734(neverallow hal_uwb_vendor_server domain (netlink_selinux_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11735(neverallow hal_uwb_vendor_server domain (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
11736(neverallow hal_uwb_vendor_server domain (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11737(neverallow hal_uwb_vendor_server domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11738(neverallow hal_uwb_vendor_server domain (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
11739(neverallow hal_uwb_vendor_server domain (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11740(neverallow hal_uwb_vendor_server domain (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11741(neverallow hal_uwb_vendor_server domain (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11742(neverallow hal_uwb_vendor_server domain (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11743(neverallow hal_uwb_vendor_server domain (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11744(neverallow hal_uwb_vendor_server domain (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11745(neverallow hal_uwb_vendor_server domain (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11746(neverallow hal_uwb_vendor_server domain (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11747(neverallow hal_uwb_vendor_server domain (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
11748;;* lme
11749
11750;;* lmx 95 system/sepolicy/public/hal_neverallows.te
11751
11752(neverallow base_typeattr_459 base_typeattr_460 (file (execute_no_trans)))
11753;;* lme
11754
11755;;* lmx 97 system/sepolicy/public/hal_neverallows.te
11756
11757(neverallow base_typeattr_223 halserverdomain (process (transition)))
11758;;* lme
11759
11760;;* lmx 101 system/sepolicy/public/hal_neverallows.te
11761
11762(neverallow base_typeattr_224 halserverdomain (process (dyntransition)))
11763;;* lme
11764
11765(allow hal_nfc_client hal_nfc_server (binder (call transfer)))
11766(allow hal_nfc_server hal_nfc_client (binder (transfer)))
11767(allow hal_nfc_client hal_nfc_server (fd (use)))
11768(allow hal_nfc_server hal_nfc_client (binder (call transfer)))
11769(allow hal_nfc_client hal_nfc_server (binder (transfer)))
11770(allow hal_nfc_server hal_nfc_client (fd (use)))
11771(allow hal_nfc_server servicemanager (binder (call transfer)))
11772(allow servicemanager hal_nfc_server (binder (transfer)))
11773(allow hal_nfc_server servicemanager (fd (use)))
11774(allow hal_nfc_client hal_nfc_hwservice (hwservice_manager (find)))
11775(allow hal_nfc_server hal_nfc_hwservice (hwservice_manager (add find)))
11776(allow hal_nfc_server hidl_base_hwservice (hwservice_manager (add)))
11777;;* lmx 6 system/sepolicy/public/hal_nfc.te
11778
11779(neverallow base_typeattr_461 hal_nfc_hwservice (hwservice_manager (add)))
11780;;* lme
11781
11782;;* lmx 6 system/sepolicy/public/hal_nfc.te
11783
11784(neverallow base_typeattr_462 hal_nfc_hwservice (hwservice_manager (find)))
11785;;* lme
11786
11787(allow hal_nfc_client hal_nfc_service (service_manager (find)))
11788(allow hal_nfc_server hal_nfc_service (service_manager (add find)))
11789;;* lmx 7 system/sepolicy/public/hal_nfc.te
11790
11791(neverallow base_typeattr_461 hal_nfc_service (service_manager (add)))
11792;;* lme
11793
11794;;* lmx 7 system/sepolicy/public/hal_nfc.te
11795
11796(neverallow base_typeattr_463 hal_nfc_service (service_manager (find)))
11797;;* lme
11798
11799(allow hal_nfc property_socket (sock_file (write)))
11800(allow hal_nfc init (unix_stream_socket (connectto)))
11801(allow hal_nfc nfc_prop (property_service (set)))
11802(allow hal_nfc nfc_prop (file (read getattr map open)))
11803(allow hal_nfc nfc_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11804(allow hal_nlinterceptor_client hal_nlinterceptor_server (binder (call transfer)))
11805(allow hal_nlinterceptor_server hal_nlinterceptor_client (binder (transfer)))
11806(allow hal_nlinterceptor_client hal_nlinterceptor_server (fd (use)))
11807(allow hal_nlinterceptor_client hal_nlinterceptor_service (service_manager (find)))
11808(allow hal_nlinterceptor_server hal_nlinterceptor_service (service_manager (add find)))
11809;;* lmx 3 system/sepolicy/public/hal_nlinterceptor.te
11810
11811(neverallow base_typeattr_464 hal_nlinterceptor_service (service_manager (add)))
11812;;* lme
11813
11814;;* lmx 3 system/sepolicy/public/hal_nlinterceptor.te
11815
11816(neverallow base_typeattr_465 hal_nlinterceptor_service (service_manager (find)))
11817;;* lme
11818
11819(allow hal_nlinterceptor servicemanager (binder (call transfer)))
11820(allow servicemanager hal_nlinterceptor (binder (transfer)))
11821(allow hal_nlinterceptor servicemanager (fd (use)))
11822(allow hal_nlinterceptor self (capability (net_admin)))
11823(allow hal_nlinterceptor self (cap_userns (net_admin)))
11824(allow hal_nlinterceptor self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
11825(allow hal_nlinterceptor self (netlink_route_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_write nlmsg_readpriv)))
11826(allow hal_oemlock_client hal_oemlock_server (binder (call transfer)))
11827(allow hal_oemlock_server hal_oemlock_client (binder (transfer)))
11828(allow hal_oemlock_client hal_oemlock_server (fd (use)))
11829(allow hal_oemlock_client hal_oemlock_hwservice (hwservice_manager (find)))
11830(allow hal_oemlock_server hal_oemlock_hwservice (hwservice_manager (add find)))
11831(allow hal_oemlock_server hidl_base_hwservice (hwservice_manager (add)))
11832;;* lmx 4 system/sepolicy/public/hal_oemlock.te
11833
11834(neverallow base_typeattr_466 hal_oemlock_hwservice (hwservice_manager (add)))
11835;;* lme
11836
11837;;* lmx 4 system/sepolicy/public/hal_oemlock.te
11838
11839(neverallow base_typeattr_467 hal_oemlock_hwservice (hwservice_manager (find)))
11840;;* lme
11841
11842(allow hal_oemlock_client hal_oemlock_service (service_manager (find)))
11843(allow hal_oemlock_server hal_oemlock_service (service_manager (add find)))
11844;;* lmx 5 system/sepolicy/public/hal_oemlock.te
11845
11846(neverallow base_typeattr_466 hal_oemlock_service (service_manager (add)))
11847;;* lme
11848
11849;;* lmx 5 system/sepolicy/public/hal_oemlock.te
11850
11851(neverallow base_typeattr_468 hal_oemlock_service (service_manager (find)))
11852;;* lme
11853
11854(allow hal_oemlock_server servicemanager (binder (call transfer)))
11855(allow servicemanager hal_oemlock_server (binder (transfer)))
11856(allow hal_oemlock_server servicemanager (fd (use)))
11857(allow hal_omx_server binderservicedomain (binder (call transfer)))
11858(allow binderservicedomain hal_omx_server (binder (transfer)))
11859(allow hal_omx_server binderservicedomain (fd (use)))
11860(allow hal_omx_server base_typeattr_369 (binder (call transfer)))
11861(allow base_typeattr_369 hal_omx_server (binder (transfer)))
11862(allow hal_omx_server base_typeattr_369 (fd (use)))
11863(allow hal_omx_server hal_graphics_composer (fd (use)))
11864(allow hal_omx_server ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
11865(allow hal_omx_server hal_camera (fd (use)))
11866(allow hal_omx_server anr_data_file (file (append)))
11867(allow hal_omx_server dumpstate (fd (use)))
11868(allow hal_omx_server incidentd (fd (use)))
11869(allow hal_omx_server dumpstate (fifo_file (write append)))
11870(allow hal_omx_server incidentd (fifo_file (write append)))
11871(allow hal_omx_server system_server (fifo_file (write append)))
11872(allow hal_omx_server tombstoned (unix_stream_socket (connectto)))
11873(allow hal_omx_server tombstoned (fd (use)))
11874(allow hal_omx_server tombstoned_crash_socket (sock_file (write)))
11875(allow hal_omx_server tombstone_data_file (file (append)))
11876(allow hal_omx_server bufferhubd (fd (use)))
11877(allow hal_omx_client hal_omx_hwservice (hwservice_manager (find)))
11878(allow hal_omx_server hal_omx_hwservice (hwservice_manager (add find)))
11879(allow hal_omx_server hidl_base_hwservice (hwservice_manager (add)))
11880;;* lmx 21 system/sepolicy/public/hal_omx.te
11881
11882(neverallow base_typeattr_469 hal_omx_hwservice (hwservice_manager (add)))
11883;;* lme
11884
11885;;* lmx 21 system/sepolicy/public/hal_omx.te
11886
11887(neverallow base_typeattr_470 hal_omx_hwservice (hwservice_manager (find)))
11888;;* lme
11889
11890(allow hal_omx_client hidl_token_hwservice (hwservice_manager (find)))
11891(allow hal_omx_client media_variant_prop (file (read getattr map open)))
11892(allow hal_omx_server media_variant_prop (file (read getattr map open)))
11893(allow hal_omx_client hal_omx_server (binder (call transfer)))
11894(allow hal_omx_server hal_omx_client (binder (transfer)))
11895(allow hal_omx_client hal_omx_server (fd (use)))
11896(allow hal_omx_server hal_omx_client (binder (call transfer)))
11897(allow hal_omx_client hal_omx_server (binder (transfer)))
11898(allow hal_omx_server hal_omx_client (fd (use)))
11899;;* lmx 37 system/sepolicy/public/hal_omx.te
11900
11901(neverallow hal_omx_server fs_type (file (execute_no_trans)))
11902(neverallow hal_omx_server file_type (file (execute_no_trans)))
11903;;* lme
11904
11905;;* lmx 49 system/sepolicy/public/hal_omx.te
11906
11907(neverallow hal_omx_server domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
11908(neverallow hal_omx_server domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
11909;;* lme
11910
11911;;* lmx 50 system/sepolicy/public/hal_omx.te
11912
11913(neverallow hal_omx_server domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
11914;;* lme
11915
11916(allow hal_power_client hal_power_server (binder (call transfer)))
11917(allow hal_power_server hal_power_client (binder (transfer)))
11918(allow hal_power_client hal_power_server (fd (use)))
11919(allow hal_power_server hal_power_client (binder (call transfer)))
11920(allow hal_power_client hal_power_server (binder (transfer)))
11921(allow hal_power_server hal_power_client (fd (use)))
11922(allow hal_power_client hal_power_hwservice (hwservice_manager (find)))
11923(allow hal_power_server hal_power_hwservice (hwservice_manager (add find)))
11924(allow hal_power_server hidl_base_hwservice (hwservice_manager (add)))
11925;;* lmx 5 system/sepolicy/public/hal_power.te
11926
11927(neverallow base_typeattr_471 hal_power_hwservice (hwservice_manager (add)))
11928;;* lme
11929
11930;;* lmx 5 system/sepolicy/public/hal_power.te
11931
11932(neverallow base_typeattr_472 hal_power_hwservice (hwservice_manager (find)))
11933;;* lme
11934
11935(allow hal_power_client hal_power_service (service_manager (find)))
11936(allow hal_power_server hal_power_service (service_manager (add find)))
11937;;* lmx 6 system/sepolicy/public/hal_power.te
11938
11939(neverallow base_typeattr_471 hal_power_service (service_manager (add)))
11940;;* lme
11941
11942;;* lmx 6 system/sepolicy/public/hal_power.te
11943
11944(neverallow base_typeattr_473 hal_power_service (service_manager (find)))
11945;;* lme
11946
11947(allow hal_power_server servicemanager (binder (call transfer)))
11948(allow servicemanager hal_power_server (binder (transfer)))
11949(allow hal_power_server servicemanager (fd (use)))
11950(allow hal_power_client servicemanager (binder (call transfer)))
11951(allow servicemanager hal_power_client (binder (transfer)))
11952(allow hal_power_client servicemanager (fd (use)))
11953(allow hal_power_stats_client hal_power_stats_server (binder (call transfer)))
11954(allow hal_power_stats_server hal_power_stats_client (binder (transfer)))
11955(allow hal_power_stats_client hal_power_stats_server (fd (use)))
11956(allow hal_power_stats_server hal_power_stats_client (binder (call transfer)))
11957(allow hal_power_stats_client hal_power_stats_server (binder (transfer)))
11958(allow hal_power_stats_server hal_power_stats_client (fd (use)))
11959(allow hal_power_stats_client hal_power_stats_hwservice (hwservice_manager (find)))
11960(allow hal_power_stats_server hal_power_stats_hwservice (hwservice_manager (add find)))
11961(allow hal_power_stats_server hidl_base_hwservice (hwservice_manager (add)))
11962;;* lmx 5 system/sepolicy/public/hal_power_stats.te
11963
11964(neverallow base_typeattr_474 hal_power_stats_hwservice (hwservice_manager (add)))
11965;;* lme
11966
11967;;* lmx 5 system/sepolicy/public/hal_power_stats.te
11968
11969(neverallow base_typeattr_475 hal_power_stats_hwservice (hwservice_manager (find)))
11970;;* lme
11971
11972(allow hal_power_stats_client hal_power_stats_service (service_manager (find)))
11973(allow hal_power_stats_server hal_power_stats_service (service_manager (add find)))
11974;;* lmx 6 system/sepolicy/public/hal_power_stats.te
11975
11976(neverallow base_typeattr_474 hal_power_stats_service (service_manager (add)))
11977;;* lme
11978
11979;;* lmx 6 system/sepolicy/public/hal_power_stats.te
11980
11981(neverallow base_typeattr_476 hal_power_stats_service (service_manager (find)))
11982;;* lme
11983
11984(allow hal_power_stats_server servicemanager (binder (call transfer)))
11985(allow servicemanager hal_power_stats_server (binder (transfer)))
11986(allow hal_power_stats_server servicemanager (fd (use)))
11987(allow hal_power_stats_client servicemanager (binder (call transfer)))
11988(allow servicemanager hal_power_stats_client (binder (transfer)))
11989(allow hal_power_stats_client servicemanager (fd (use)))
11990(allow hal_rebootescrow_client hal_rebootescrow_server (binder (call transfer)))
11991(allow hal_rebootescrow_server hal_rebootescrow_client (binder (transfer)))
11992(allow hal_rebootescrow_client hal_rebootescrow_server (fd (use)))
11993(allow hal_rebootescrow_client hal_rebootescrow_service (service_manager (find)))
11994(allow hal_rebootescrow_server hal_rebootescrow_service (service_manager (add find)))
11995;;* lmx 4 system/sepolicy/public/hal_rebootescrow.te
11996
11997(neverallow base_typeattr_477 hal_rebootescrow_service (service_manager (add)))
11998;;* lme
11999
12000;;* lmx 4 system/sepolicy/public/hal_rebootescrow.te
12001
12002(neverallow base_typeattr_478 hal_rebootescrow_service (service_manager (find)))
12003;;* lme
12004
12005(allow hal_rebootescrow_server servicemanager (binder (call transfer)))
12006(allow servicemanager hal_rebootescrow_server (binder (call transfer)))
12007(allow servicemanager hal_rebootescrow_server (dir (search)))
12008(allow servicemanager hal_rebootescrow_server (file (read open)))
12009(allow servicemanager hal_rebootescrow_server (process (getattr)))
12010(allow hal_remoteaccess_client hal_remoteaccess_server (binder (call transfer)))
12011(allow hal_remoteaccess_server hal_remoteaccess_client (binder (transfer)))
12012(allow hal_remoteaccess_client hal_remoteaccess_server (fd (use)))
12013(allow hal_remoteaccess_server hal_remoteaccess_client (binder (call transfer)))
12014(allow hal_remoteaccess_client hal_remoteaccess_server (binder (transfer)))
12015(allow hal_remoteaccess_server hal_remoteaccess_client (fd (use)))
12016(allow hal_remoteaccess_client hal_remoteaccess_service (service_manager (find)))
12017(allow hal_remoteaccess_server hal_remoteaccess_service (service_manager (add find)))
12018;;* lmx 5 system/sepolicy/public/hal_remoteaccess.te
12019
12020(neverallow base_typeattr_479 hal_remoteaccess_service (service_manager (add)))
12021;;* lme
12022
12023;;* lmx 5 system/sepolicy/public/hal_remoteaccess.te
12024
12025(neverallow base_typeattr_480 hal_remoteaccess_service (service_manager (find)))
12026;;* lme
12027
12028(allow hal_remotelyprovisionedcomponent_avf_client hal_remotelyprovisionedcomponent_avf_server (binder (call transfer)))
12029(allow hal_remotelyprovisionedcomponent_avf_server hal_remotelyprovisionedcomponent_avf_client (binder (transfer)))
12030(allow hal_remotelyprovisionedcomponent_avf_client hal_remotelyprovisionedcomponent_avf_server (fd (use)))
12031(allow hal_remotelyprovisionedcomponent_avf_client hal_remotelyprovisionedcomponent_avf_service (service_manager (find)))
12032(allow hal_remotelyprovisionedcomponent_avf_server hal_remotelyprovisionedcomponent_avf_service (service_manager (add find)))
12033;;* lmx 5 system/sepolicy/public/hal_remotelyprovisionedcomponent_avf.te
12034
12035(neverallow base_typeattr_481 hal_remotelyprovisionedcomponent_avf_service (service_manager (add)))
12036;;* lme
12037
12038;;* lmx 5 system/sepolicy/public/hal_remotelyprovisionedcomponent_avf.te
12039
12040(neverallow base_typeattr_482 hal_remotelyprovisionedcomponent_avf_service (service_manager (find)))
12041;;* lme
12042
12043(allow hal_remotelyprovisionedcomponent_avf_server servicemanager (binder (call transfer)))
12044(allow servicemanager hal_remotelyprovisionedcomponent_avf_server (binder (call transfer)))
12045(allow servicemanager hal_remotelyprovisionedcomponent_avf_server (dir (search)))
12046(allow servicemanager hal_remotelyprovisionedcomponent_avf_server (file (read open)))
12047(allow servicemanager hal_remotelyprovisionedcomponent_avf_server (process (getattr)))
12048(allow hal_secretkeeper_client hal_secretkeeper_server (binder (call transfer)))
12049(allow hal_secretkeeper_server hal_secretkeeper_client (binder (transfer)))
12050(allow hal_secretkeeper_client hal_secretkeeper_server (fd (use)))
12051(allow hal_secretkeeper_client hal_secretkeeper_service (service_manager (find)))
12052(allow hal_secretkeeper_server hal_secretkeeper_service (service_manager (add find)))
12053;;* lmx 5 system/sepolicy/public/hal_secretkeeper.te
12054
12055(neverallow base_typeattr_483 hal_secretkeeper_service (service_manager (add)))
12056;;* lme
12057
12058;;* lmx 5 system/sepolicy/public/hal_secretkeeper.te
12059
12060(neverallow base_typeattr_484 hal_secretkeeper_service (service_manager (find)))
12061;;* lme
12062
12063(allow hal_secretkeeper_server servicemanager (binder (call transfer)))
12064(allow servicemanager hal_secretkeeper_server (binder (call transfer)))
12065(allow servicemanager hal_secretkeeper_server (dir (search)))
12066(allow servicemanager hal_secretkeeper_server (file (read open)))
12067(allow servicemanager hal_secretkeeper_server (process (getattr)))
12068(allow hal_secretkeeper_client servicemanager (binder (call transfer)))
12069(allow servicemanager hal_secretkeeper_client (binder (call transfer)))
12070(allow servicemanager hal_secretkeeper_client (dir (search)))
12071(allow servicemanager hal_secretkeeper_client (file (read open)))
12072(allow servicemanager hal_secretkeeper_client (process (getattr)))
12073(allow hal_secretkeeper_server tee_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
12074(allow hal_secure_element_client hal_secure_element_server (binder (call transfer)))
12075(allow hal_secure_element_server hal_secure_element_client (binder (transfer)))
12076(allow hal_secure_element_client hal_secure_element_server (fd (use)))
12077(allow hal_secure_element_server hal_secure_element_client (binder (call transfer)))
12078(allow hal_secure_element_client hal_secure_element_server (binder (transfer)))
12079(allow hal_secure_element_server hal_secure_element_client (fd (use)))
12080(allow hal_secure_element_client hal_secure_element_hwservice (hwservice_manager (find)))
12081(allow hal_secure_element_server hal_secure_element_hwservice (hwservice_manager (add find)))
12082(allow hal_secure_element_server hidl_base_hwservice (hwservice_manager (add)))
12083;;* lmx 5 system/sepolicy/public/hal_secure_element.te
12084
12085(neverallow base_typeattr_485 hal_secure_element_hwservice (hwservice_manager (add)))
12086;;* lme
12087
12088;;* lmx 5 system/sepolicy/public/hal_secure_element.te
12089
12090(neverallow base_typeattr_486 hal_secure_element_hwservice (hwservice_manager (find)))
12091;;* lme
12092
12093(allow hal_secure_element_client hal_secure_element_service (service_manager (find)))
12094(allow hal_secure_element_server hal_secure_element_service (service_manager (add find)))
12095;;* lmx 6 system/sepolicy/public/hal_secure_element.te
12096
12097(neverallow base_typeattr_485 hal_secure_element_service (service_manager (add)))
12098;;* lme
12099
12100;;* lmx 6 system/sepolicy/public/hal_secure_element.te
12101
12102(neverallow base_typeattr_487 hal_secure_element_service (service_manager (find)))
12103;;* lme
12104
12105(allow hal_secure_element_server servicemanager (binder (call transfer)))
12106(allow servicemanager hal_secure_element_server (binder (call transfer)))
12107(allow servicemanager hal_secure_element_server (dir (search)))
12108(allow servicemanager hal_secure_element_server (file (read open)))
12109(allow servicemanager hal_secure_element_server (process (getattr)))
12110(allow hal_secure_element_client hal_secure_element_service (service_manager (find)))
12111(allow hal_sensors_client hal_sensors_server (binder (call transfer)))
12112(allow hal_sensors_server hal_sensors_client (binder (transfer)))
12113(allow hal_sensors_client hal_sensors_server (fd (use)))
12114(allow hal_sensors_client hal_sensors_hwservice (hwservice_manager (find)))
12115(allow hal_sensors_server hal_sensors_hwservice (hwservice_manager (add find)))
12116(allow hal_sensors_server hidl_base_hwservice (hwservice_manager (add)))
12117;;* lmx 4 system/sepolicy/public/hal_sensors.te
12118
12119(neverallow base_typeattr_488 hal_sensors_hwservice (hwservice_manager (add)))
12120;;* lme
12121
12122;;* lmx 4 system/sepolicy/public/hal_sensors.te
12123
12124(neverallow base_typeattr_489 hal_sensors_hwservice (hwservice_manager (find)))
12125;;* lme
12126
12127(allow hal_sensors base_typeattr_369 (fd (use)))
12128(allow hal_sensors hal_allocator (fd (use)))
12129(allow hal_sensors self (capability (sys_nice)))
12130(allow hal_sensors self (cap_userns (sys_nice)))
12131(allow hal_sensors_server hal_sensors_service (service_manager (add find)))
12132;;* lmx 16 system/sepolicy/public/hal_sensors.te
12133
12134(neverallow base_typeattr_488 hal_sensors_service (service_manager (add)))
12135;;* lme
12136
12137(allow hal_sensors_server servicemanager (binder (call transfer)))
12138(allow servicemanager hal_sensors_server (binder (transfer)))
12139(allow hal_sensors_server servicemanager (fd (use)))
12140(allow hal_sensors_client hal_sensors_service (service_manager (find)))
12141(allow hal_telephony_client hal_telephony_server (binder (call transfer)))
12142(allow hal_telephony_server hal_telephony_client (binder (transfer)))
12143(allow hal_telephony_client hal_telephony_server (fd (use)))
12144(allow hal_telephony_server hal_telephony_client (binder (call transfer)))
12145(allow hal_telephony_client hal_telephony_server (binder (transfer)))
12146(allow hal_telephony_server hal_telephony_client (fd (use)))
12147(allow hal_telephony_client hal_telephony_hwservice (hwservice_manager (find)))
12148(allow hal_telephony_server hal_telephony_hwservice (hwservice_manager (add find)))
12149(allow hal_telephony_server hidl_base_hwservice (hwservice_manager (add)))
12150;;* lmx 5 system/sepolicy/public/hal_telephony.te
12151
12152(neverallow base_typeattr_490 hal_telephony_hwservice (hwservice_manager (add)))
12153;;* lme
12154
12155;;* lmx 5 system/sepolicy/public/hal_telephony.te
12156
12157(neverallow base_typeattr_491 hal_telephony_hwservice (hwservice_manager (find)))
12158;;* lme
12159
12160(allow hal_telephony_client hal_radio_service (service_manager (find)))
12161(allow hal_telephony_server hal_radio_service (service_manager (add find)))
12162;;* lmx 6 system/sepolicy/public/hal_telephony.te
12163
12164(neverallow base_typeattr_490 hal_radio_service (service_manager (add)))
12165;;* lme
12166
12167;;* lmx 6 system/sepolicy/public/hal_telephony.te
12168
12169(neverallow base_typeattr_492 hal_radio_service (service_manager (find)))
12170;;* lme
12171
12172(allowx hal_telephony_server self (ioctl udp_socket (0x6900 0x6902)))
12173(allowx hal_telephony_server self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
12174(allowx hal_telephony_server self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
12175(allow hal_telephony_server self (netlink_route_socket (nlmsg_write)))
12176(allow hal_telephony_server self (capability (setgid setuid setpcap net_admin net_raw)))
12177(allow hal_telephony_server self (cap_userns (setgid setuid setpcap net_admin net_raw)))
12178(allow hal_telephony_server cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
12179(allow hal_telephony_server cgroup (file (ioctl read getattr lock map open watch watch_reads)))
12180(allow hal_telephony_server cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12181(allow hal_telephony_server cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
12182(allow hal_telephony_server cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
12183(allow hal_telephony_server cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12184(allow hal_telephony_server radio_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
12185(allow hal_telephony_server radio_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
12186(allow hal_telephony_server efs_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
12187(allow hal_telephony_server efs_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
12188(allow hal_telephony_server vendor_shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
12189(allow hal_telephony_server bluetooth_efs_file (file (ioctl read getattr lock map open watch watch_reads)))
12190(allow hal_telephony_server bluetooth_efs_file (dir (ioctl read getattr lock open watch watch_reads search)))
12191(allow hal_telephony_server telephony_config_prop (file (read getattr map open)))
12192(allow hal_telephony_server property_socket (sock_file (write)))
12193(allow hal_telephony_server init (unix_stream_socket (connectto)))
12194(allow hal_telephony_server radio_control_prop (property_service (set)))
12195(allow hal_telephony_server radio_control_prop (file (read getattr map open)))
12196(allow hal_telephony_server property_socket (sock_file (write)))
12197(allow hal_telephony_server init (unix_stream_socket (connectto)))
12198(allow hal_telephony_server radio_prop (property_service (set)))
12199(allow hal_telephony_server radio_prop (file (read getattr map open)))
12200(allow hal_telephony_server property_socket (sock_file (write)))
12201(allow hal_telephony_server init (unix_stream_socket (connectto)))
12202(allow hal_telephony_server telephony_status_prop (property_service (set)))
12203(allow hal_telephony_server telephony_status_prop (file (read getattr map open)))
12204(allow hal_telephony_server tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
12205(allow hal_telephony_server self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12206(allow hal_telephony_server self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12207(allow hal_telephony_server self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12208(allow hal_telephony_server sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
12209(allow hal_telephony_server self (capability2 (block_suspend)))
12210(allow hal_telephony_server self (cap2_userns (block_suspend)))
12211(allow hal_telephony_server system_suspend_server (binder (call transfer)))
12212(allow system_suspend_server hal_telephony_server (binder (transfer)))
12213(allow hal_telephony_server system_suspend_server (fd (use)))
12214(allow hal_telephony_server system_suspend_hwservice (hwservice_manager (find)))
12215(allow hal_telephony_server hwservicemanager (binder (call transfer)))
12216(allow hwservicemanager hal_telephony_server (binder (call transfer)))
12217(allow hwservicemanager hal_telephony_server (dir (search)))
12218(allow hwservicemanager hal_telephony_server (file (read map open)))
12219(allow hwservicemanager hal_telephony_server (process (getattr)))
12220(allow hal_telephony_server hwservicemanager_prop (file (read getattr map open)))
12221(allow hal_telephony_server hidl_manager_hwservice (hwservice_manager (find)))
12222(allow hal_telephony_server hal_system_suspend_service (service_manager (find)))
12223(allow hal_telephony_server servicemanager (binder (call transfer)))
12224(allow servicemanager hal_telephony_server (binder (call transfer)))
12225(allow servicemanager hal_telephony_server (dir (search)))
12226(allow servicemanager hal_telephony_server (file (read open)))
12227(allow servicemanager hal_telephony_server (process (getattr)))
12228(allow hal_telephony_server proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
12229(allow hal_telephony_server proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
12230(allow hal_telephony_server proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12231(allow hal_telephony_server sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
12232(allow hal_telephony_server sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
12233(allow hal_telephony_server sysfs_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12234(allow hal_telephony_server self (socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12235(allow hal_telephony_server hal_telephony_server (binder (call transfer)))
12236(allow hal_telephony_server hal_telephony_server (binder (transfer)))
12237(allow hal_telephony_server hal_telephony_server (fd (use)))
12238(allow hal_tetheroffload_client hal_tetheroffload_server (binder (call transfer)))
12239(allow hal_tetheroffload_server hal_tetheroffload_client (binder (transfer)))
12240(allow hal_tetheroffload_client hal_tetheroffload_server (fd (use)))
12241(allow hal_tetheroffload_server hal_tetheroffload_client (binder (call transfer)))
12242(allow hal_tetheroffload_client hal_tetheroffload_server (binder (transfer)))
12243(allow hal_tetheroffload_server hal_tetheroffload_client (fd (use)))
12244(allow hal_tetheroffload_client hal_tetheroffload_hwservice (hwservice_manager (find)))
12245(allow hal_tetheroffload_server hal_tetheroffload_hwservice (hwservice_manager (add find)))
12246(allow hal_tetheroffload_server hidl_base_hwservice (hwservice_manager (add)))
12247;;* lmx 5 system/sepolicy/public/hal_tetheroffload.te
12248
12249(neverallow base_typeattr_493 hal_tetheroffload_hwservice (hwservice_manager (add)))
12250;;* lme
12251
12252;;* lmx 5 system/sepolicy/public/hal_tetheroffload.te
12253
12254(neverallow base_typeattr_494 hal_tetheroffload_hwservice (hwservice_manager (find)))
12255;;* lme
12256
12257(allow hal_tetheroffload_client hal_tetheroffload_service (service_manager (find)))
12258(allow hal_tetheroffload_server hal_tetheroffload_service (service_manager (add find)))
12259;;* lmx 6 system/sepolicy/public/hal_tetheroffload.te
12260
12261(neverallow base_typeattr_493 hal_tetheroffload_service (service_manager (add)))
12262;;* lme
12263
12264;;* lmx 6 system/sepolicy/public/hal_tetheroffload.te
12265
12266(neverallow base_typeattr_495 hal_tetheroffload_service (service_manager (find)))
12267;;* lme
12268
12269(allow hal_tetheroffload_server servicemanager (binder (call transfer)))
12270(allow servicemanager hal_tetheroffload_server (binder (call transfer)))
12271(allow servicemanager hal_tetheroffload_server (dir (search)))
12272(allow servicemanager hal_tetheroffload_server (file (read open)))
12273(allow servicemanager hal_tetheroffload_server (process (getattr)))
12274(allow hal_tetheroffload_server hal_tetheroffload_client (netlink_netfilter_socket (read write getattr setopt)))
12275(allow hal_thermal_client hal_thermal_server (binder (call transfer)))
12276(allow hal_thermal_server hal_thermal_client (binder (transfer)))
12277(allow hal_thermal_client hal_thermal_server (fd (use)))
12278(allow hal_thermal_server hal_thermal_client (binder (call transfer)))
12279(allow hal_thermal_client hal_thermal_server (binder (transfer)))
12280(allow hal_thermal_server hal_thermal_client (fd (use)))
12281(allow hal_thermal_client hal_thermal_hwservice (hwservice_manager (find)))
12282(allow hal_thermal_server hal_thermal_hwservice (hwservice_manager (add find)))
12283(allow hal_thermal_server hidl_base_hwservice (hwservice_manager (add)))
12284;;* lmx 5 system/sepolicy/public/hal_thermal.te
12285
12286(neverallow base_typeattr_496 hal_thermal_hwservice (hwservice_manager (add)))
12287;;* lme
12288
12289;;* lmx 5 system/sepolicy/public/hal_thermal.te
12290
12291(neverallow base_typeattr_497 hal_thermal_hwservice (hwservice_manager (find)))
12292;;* lme
12293
12294(allow hal_thermal_client hal_thermal_service (service_manager (find)))
12295(allow hal_thermal_server hal_thermal_service (service_manager (add find)))
12296;;* lmx 6 system/sepolicy/public/hal_thermal.te
12297
12298(neverallow base_typeattr_496 hal_thermal_service (service_manager (add)))
12299;;* lme
12300
12301;;* lmx 6 system/sepolicy/public/hal_thermal.te
12302
12303(neverallow base_typeattr_498 hal_thermal_service (service_manager (find)))
12304;;* lme
12305
12306(allow hal_thermal_server hal_thermal_service (service_manager (add find)))
12307;;* lmx 8 system/sepolicy/public/hal_thermal.te
12308
12309(neverallow base_typeattr_496 hal_thermal_service (service_manager (add)))
12310;;* lme
12311
12312(allow hal_thermal_server servicemanager (binder (call transfer)))
12313(allow servicemanager hal_thermal_server (binder (transfer)))
12314(allow hal_thermal_server servicemanager (fd (use)))
12315(allow hal_thermal_client servicemanager (binder (call transfer)))
12316(allow servicemanager hal_thermal_client (binder (transfer)))
12317(allow hal_thermal_client servicemanager (fd (use)))
12318(allow hal_threadnetwork_client hal_threadnetwork_server (binder (call transfer)))
12319(allow hal_threadnetwork_server hal_threadnetwork_client (binder (transfer)))
12320(allow hal_threadnetwork_client hal_threadnetwork_server (fd (use)))
12321(allow hal_threadnetwork_server hal_threadnetwork_client (binder (call transfer)))
12322(allow hal_threadnetwork_client hal_threadnetwork_server (binder (transfer)))
12323(allow hal_threadnetwork_server hal_threadnetwork_client (fd (use)))
12324(allow hal_threadnetwork_client hal_threadnetwork_service (service_manager (find)))
12325(allow hal_threadnetwork_server hal_threadnetwork_service (service_manager (add find)))
12326;;* lmx 4 system/sepolicy/public/hal_threadnetwork.te
12327
12328(neverallow base_typeattr_499 hal_threadnetwork_service (service_manager (add)))
12329;;* lme
12330
12331;;* lmx 4 system/sepolicy/public/hal_threadnetwork.te
12332
12333(neverallow base_typeattr_500 hal_threadnetwork_service (service_manager (find)))
12334;;* lme
12335
12336(allow hal_threadnetwork_server servicemanager (binder (call transfer)))
12337(allow servicemanager hal_threadnetwork_server (binder (transfer)))
12338(allow hal_threadnetwork_server servicemanager (fd (use)))
12339(allow hal_threadnetwork_client servicemanager (binder (call transfer)))
12340(allow servicemanager hal_threadnetwork_client (binder (transfer)))
12341(allow hal_threadnetwork_client servicemanager (fd (use)))
12342(allow hal_tv_cec_client hal_tv_cec_server (binder (call transfer)))
12343(allow hal_tv_cec_server hal_tv_cec_client (binder (transfer)))
12344(allow hal_tv_cec_client hal_tv_cec_server (fd (use)))
12345(allow hal_tv_cec_server hal_tv_cec_client (binder (call transfer)))
12346(allow hal_tv_cec_client hal_tv_cec_server (binder (transfer)))
12347(allow hal_tv_cec_server hal_tv_cec_client (fd (use)))
12348(allow hal_tv_cec_client hal_tv_cec_hwservice (hwservice_manager (find)))
12349(allow hal_tv_cec_server hal_tv_cec_hwservice (hwservice_manager (add find)))
12350(allow hal_tv_cec_server hidl_base_hwservice (hwservice_manager (add)))
12351;;* lmx 5 system/sepolicy/public/hal_tv_cec.te
12352
12353(neverallow base_typeattr_501 hal_tv_cec_hwservice (hwservice_manager (add)))
12354;;* lme
12355
12356;;* lmx 5 system/sepolicy/public/hal_tv_cec.te
12357
12358(neverallow base_typeattr_502 hal_tv_cec_hwservice (hwservice_manager (find)))
12359;;* lme
12360
12361(allow hal_tv_hdmi_cec_client hal_tv_hdmi_cec_server (binder (call transfer)))
12362(allow hal_tv_hdmi_cec_server hal_tv_hdmi_cec_client (binder (transfer)))
12363(allow hal_tv_hdmi_cec_client hal_tv_hdmi_cec_server (fd (use)))
12364(allow hal_tv_hdmi_cec_server hal_tv_hdmi_cec_client (binder (call transfer)))
12365(allow hal_tv_hdmi_cec_client hal_tv_hdmi_cec_server (binder (transfer)))
12366(allow hal_tv_hdmi_cec_server hal_tv_hdmi_cec_client (fd (use)))
12367(allow hal_tv_hdmi_cec_client servicemanager (binder (call transfer)))
12368(allow servicemanager hal_tv_hdmi_cec_client (binder (call transfer)))
12369(allow servicemanager hal_tv_hdmi_cec_client (dir (search)))
12370(allow servicemanager hal_tv_hdmi_cec_client (file (read open)))
12371(allow servicemanager hal_tv_hdmi_cec_client (process (getattr)))
12372(allow hal_tv_hdmi_cec_server servicemanager (binder (call transfer)))
12373(allow servicemanager hal_tv_hdmi_cec_server (binder (call transfer)))
12374(allow servicemanager hal_tv_hdmi_cec_server (dir (search)))
12375(allow servicemanager hal_tv_hdmi_cec_server (file (read open)))
12376(allow servicemanager hal_tv_hdmi_cec_server (process (getattr)))
12377(allow hal_tv_hdmi_cec_client hal_tv_hdmi_cec_service (service_manager (find)))
12378(allow hal_tv_hdmi_cec_server hal_tv_hdmi_cec_service (service_manager (add find)))
12379;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_cec.te
12380
12381(neverallow base_typeattr_503 hal_tv_hdmi_cec_service (service_manager (add)))
12382;;* lme
12383
12384;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_cec.te
12385
12386(neverallow base_typeattr_504 hal_tv_hdmi_cec_service (service_manager (find)))
12387;;* lme
12388
12389(allow hal_tv_hdmi_connection_client hal_tv_hdmi_connection_server (binder (call transfer)))
12390(allow hal_tv_hdmi_connection_server hal_tv_hdmi_connection_client (binder (transfer)))
12391(allow hal_tv_hdmi_connection_client hal_tv_hdmi_connection_server (fd (use)))
12392(allow hal_tv_hdmi_connection_server hal_tv_hdmi_connection_client (binder (call transfer)))
12393(allow hal_tv_hdmi_connection_client hal_tv_hdmi_connection_server (binder (transfer)))
12394(allow hal_tv_hdmi_connection_server hal_tv_hdmi_connection_client (fd (use)))
12395(allow hal_tv_hdmi_connection_client servicemanager (binder (call transfer)))
12396(allow servicemanager hal_tv_hdmi_connection_client (binder (call transfer)))
12397(allow servicemanager hal_tv_hdmi_connection_client (dir (search)))
12398(allow servicemanager hal_tv_hdmi_connection_client (file (read open)))
12399(allow servicemanager hal_tv_hdmi_connection_client (process (getattr)))
12400(allow hal_tv_hdmi_connection_server servicemanager (binder (call transfer)))
12401(allow servicemanager hal_tv_hdmi_connection_server (binder (call transfer)))
12402(allow servicemanager hal_tv_hdmi_connection_server (dir (search)))
12403(allow servicemanager hal_tv_hdmi_connection_server (file (read open)))
12404(allow servicemanager hal_tv_hdmi_connection_server (process (getattr)))
12405(allow hal_tv_hdmi_connection_client hal_tv_hdmi_connection_service (service_manager (find)))
12406(allow hal_tv_hdmi_connection_server hal_tv_hdmi_connection_service (service_manager (add find)))
12407;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_connection.te
12408
12409(neverallow base_typeattr_505 hal_tv_hdmi_connection_service (service_manager (add)))
12410;;* lme
12411
12412;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_connection.te
12413
12414(neverallow base_typeattr_506 hal_tv_hdmi_connection_service (service_manager (find)))
12415;;* lme
12416
12417(allow hal_tv_hdmi_earc_client hal_tv_hdmi_earc_server (binder (call transfer)))
12418(allow hal_tv_hdmi_earc_server hal_tv_hdmi_earc_client (binder (transfer)))
12419(allow hal_tv_hdmi_earc_client hal_tv_hdmi_earc_server (fd (use)))
12420(allow hal_tv_hdmi_earc_server hal_tv_hdmi_earc_client (binder (call transfer)))
12421(allow hal_tv_hdmi_earc_client hal_tv_hdmi_earc_server (binder (transfer)))
12422(allow hal_tv_hdmi_earc_server hal_tv_hdmi_earc_client (fd (use)))
12423(allow hal_tv_hdmi_earc_client servicemanager (binder (call transfer)))
12424(allow servicemanager hal_tv_hdmi_earc_client (binder (call transfer)))
12425(allow servicemanager hal_tv_hdmi_earc_client (dir (search)))
12426(allow servicemanager hal_tv_hdmi_earc_client (file (read open)))
12427(allow servicemanager hal_tv_hdmi_earc_client (process (getattr)))
12428(allow hal_tv_hdmi_earc_server servicemanager (binder (call transfer)))
12429(allow servicemanager hal_tv_hdmi_earc_server (binder (call transfer)))
12430(allow servicemanager hal_tv_hdmi_earc_server (dir (search)))
12431(allow servicemanager hal_tv_hdmi_earc_server (file (read open)))
12432(allow servicemanager hal_tv_hdmi_earc_server (process (getattr)))
12433(allow hal_tv_hdmi_earc_client hal_tv_hdmi_earc_service (service_manager (find)))
12434(allow hal_tv_hdmi_earc_server hal_tv_hdmi_earc_service (service_manager (add find)))
12435;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_earc.te
12436
12437(neverallow base_typeattr_507 hal_tv_hdmi_earc_service (service_manager (add)))
12438;;* lme
12439
12440;;* lmx 7 system/sepolicy/public/hal_tv_hdmi_earc.te
12441
12442(neverallow base_typeattr_508 hal_tv_hdmi_earc_service (service_manager (find)))
12443;;* lme
12444
12445(allow hal_tv_input_client hal_tv_input_server (binder (call transfer)))
12446(allow hal_tv_input_server hal_tv_input_client (binder (transfer)))
12447(allow hal_tv_input_client hal_tv_input_server (fd (use)))
12448(allow hal_tv_input_server hal_tv_input_client (binder (call transfer)))
12449(allow hal_tv_input_client hal_tv_input_server (binder (transfer)))
12450(allow hal_tv_input_server hal_tv_input_client (fd (use)))
12451(allow hal_tv_input_client hal_tv_input_hwservice (hwservice_manager (find)))
12452(allow hal_tv_input_server hal_tv_input_hwservice (hwservice_manager (add find)))
12453(allow hal_tv_input_server hidl_base_hwservice (hwservice_manager (add)))
12454;;* lmx 5 system/sepolicy/public/hal_tv_input.te
12455
12456(neverallow base_typeattr_509 hal_tv_input_hwservice (hwservice_manager (add)))
12457;;* lme
12458
12459;;* lmx 5 system/sepolicy/public/hal_tv_input.te
12460
12461(neverallow base_typeattr_510 hal_tv_input_hwservice (hwservice_manager (find)))
12462;;* lme
12463
12464(allow hal_tv_input_client hal_tv_input_service (service_manager (find)))
12465(allow hal_tv_input_server hal_tv_input_service (service_manager (add find)))
12466;;* lmx 6 system/sepolicy/public/hal_tv_input.te
12467
12468(neverallow base_typeattr_509 hal_tv_input_service (service_manager (add)))
12469;;* lme
12470
12471;;* lmx 6 system/sepolicy/public/hal_tv_input.te
12472
12473(neverallow base_typeattr_511 hal_tv_input_service (service_manager (find)))
12474;;* lme
12475
12476(allow hal_tv_input_server servicemanager (binder (call transfer)))
12477(allow servicemanager hal_tv_input_server (binder (transfer)))
12478(allow hal_tv_input_server servicemanager (fd (use)))
12479(allow hal_tv_input_client servicemanager (binder (call transfer)))
12480(allow servicemanager hal_tv_input_client (binder (transfer)))
12481(allow hal_tv_input_client servicemanager (fd (use)))
12482(allow hal_tv_tuner_client hal_tv_tuner_server (binder (call transfer)))
12483(allow hal_tv_tuner_server hal_tv_tuner_client (binder (transfer)))
12484(allow hal_tv_tuner_client hal_tv_tuner_server (fd (use)))
12485(allow hal_tv_tuner_server hal_tv_tuner_client (binder (call transfer)))
12486(allow hal_tv_tuner_client hal_tv_tuner_server (binder (transfer)))
12487(allow hal_tv_tuner_server hal_tv_tuner_client (fd (use)))
12488(allow hal_tv_tuner_client hal_tv_tuner_hwservice (hwservice_manager (find)))
12489(allow hal_tv_tuner_server hal_tv_tuner_hwservice (hwservice_manager (add find)))
12490(allow hal_tv_tuner_server hidl_base_hwservice (hwservice_manager (add)))
12491;;* lmx 4 system/sepolicy/public/hal_tv_tuner.te
12492
12493(neverallow base_typeattr_512 hal_tv_tuner_hwservice (hwservice_manager (add)))
12494;;* lme
12495
12496;;* lmx 4 system/sepolicy/public/hal_tv_tuner.te
12497
12498(neverallow base_typeattr_513 hal_tv_tuner_hwservice (hwservice_manager (find)))
12499;;* lme
12500
12501(allow hal_tv_tuner_client hal_tv_tuner_service (service_manager (find)))
12502(allow hal_tv_tuner_server hal_tv_tuner_service (service_manager (add find)))
12503;;* lmx 5 system/sepolicy/public/hal_tv_tuner.te
12504
12505(neverallow base_typeattr_512 hal_tv_tuner_service (service_manager (add)))
12506;;* lme
12507
12508;;* lmx 5 system/sepolicy/public/hal_tv_tuner.te
12509
12510(neverallow base_typeattr_514 hal_tv_tuner_service (service_manager (find)))
12511;;* lme
12512
12513(allow hal_tv_tuner_server servicemanager (binder (call transfer)))
12514(allow servicemanager hal_tv_tuner_server (binder (transfer)))
12515(allow hal_tv_tuner_server servicemanager (fd (use)))
12516(allow hal_tv_tuner_client servicemanager (binder (call transfer)))
12517(allow servicemanager hal_tv_tuner_client (binder (transfer)))
12518(allow hal_tv_tuner_client servicemanager (fd (use)))
12519(allow hal_usb_client hal_usb_server (binder (call transfer)))
12520(allow hal_usb_server hal_usb_client (binder (transfer)))
12521(allow hal_usb_client hal_usb_server (fd (use)))
12522(allow hal_usb_server hal_usb_client (binder (call transfer)))
12523(allow hal_usb_client hal_usb_server (binder (transfer)))
12524(allow hal_usb_server hal_usb_client (fd (use)))
12525(allow hal_usb_client hal_usb_service (service_manager (find)))
12526(allow hal_usb_server hal_usb_service (service_manager (add find)))
12527;;* lmx 5 system/sepolicy/public/hal_usb.te
12528
12529(neverallow base_typeattr_515 hal_usb_service (service_manager (add)))
12530;;* lme
12531
12532;;* lmx 5 system/sepolicy/public/hal_usb.te
12533
12534(neverallow base_typeattr_516 hal_usb_service (service_manager (find)))
12535;;* lme
12536
12537(allow hal_usb_server servicemanager (binder (call transfer)))
12538(allow servicemanager hal_usb_server (binder (transfer)))
12539(allow hal_usb_server servicemanager (fd (use)))
12540(allow hal_usb_client hal_usb_hwservice (hwservice_manager (find)))
12541(allow hal_usb_server hal_usb_hwservice (hwservice_manager (add find)))
12542(allow hal_usb_server hidl_base_hwservice (hwservice_manager (add)))
12543;;* lmx 8 system/sepolicy/public/hal_usb.te
12544
12545(neverallow base_typeattr_515 hal_usb_hwservice (hwservice_manager (add)))
12546;;* lme
12547
12548;;* lmx 8 system/sepolicy/public/hal_usb.te
12549
12550(neverallow base_typeattr_517 hal_usb_hwservice (hwservice_manager (find)))
12551;;* lme
12552
12553(allow hal_usb self (netlink_kobject_uevent_socket (create)))
12554(allow hal_usb self (netlink_kobject_uevent_socket (setopt)))
12555(allow hal_usb self (netlink_kobject_uevent_socket (getopt)))
12556(allow hal_usb self (netlink_kobject_uevent_socket (bind)))
12557(allow hal_usb self (netlink_kobject_uevent_socket (read)))
12558(allow hal_usb sysfs (dir (open)))
12559(allow hal_usb sysfs (dir (read)))
12560(allow hal_usb sysfs (file (read)))
12561(allow hal_usb sysfs (file (open)))
12562(allow hal_usb sysfs (file (write)))
12563(allow hal_usb sysfs (file (getattr)))
12564(allow hal_usb_gadget_client hal_usb_gadget_server (binder (call transfer)))
12565(allow hal_usb_gadget_server hal_usb_gadget_client (binder (transfer)))
12566(allow hal_usb_gadget_client hal_usb_gadget_server (fd (use)))
12567(allow hal_usb_gadget_server hal_usb_gadget_client (binder (call transfer)))
12568(allow hal_usb_gadget_client hal_usb_gadget_server (binder (transfer)))
12569(allow hal_usb_gadget_server hal_usb_gadget_client (fd (use)))
12570(allow hal_usb_gadget_client hal_usb_gadget_service (service_manager (find)))
12571(allow hal_usb_gadget_server hal_usb_gadget_service (service_manager (add find)))
12572;;* lmx 5 system/sepolicy/public/hal_usb_gadget.te
12573
12574(neverallow base_typeattr_518 hal_usb_gadget_service (service_manager (add)))
12575;;* lme
12576
12577;;* lmx 5 system/sepolicy/public/hal_usb_gadget.te
12578
12579(neverallow base_typeattr_519 hal_usb_gadget_service (service_manager (find)))
12580;;* lme
12581
12582(allow hal_usb_gadget_server servicemanager (binder (call transfer)))
12583(allow servicemanager hal_usb_gadget_server (binder (transfer)))
12584(allow hal_usb_gadget_server servicemanager (fd (use)))
12585(allow hal_usb_gadget_client hal_usb_gadget_hwservice (hwservice_manager (find)))
12586(allow hal_usb_gadget_server hal_usb_gadget_hwservice (hwservice_manager (add find)))
12587(allow hal_usb_gadget_server hidl_base_hwservice (hwservice_manager (add)))
12588;;* lmx 8 system/sepolicy/public/hal_usb_gadget.te
12589
12590(neverallow base_typeattr_518 hal_usb_gadget_hwservice (hwservice_manager (add)))
12591;;* lme
12592
12593;;* lmx 8 system/sepolicy/public/hal_usb_gadget.te
12594
12595(neverallow base_typeattr_520 hal_usb_gadget_hwservice (hwservice_manager (find)))
12596;;* lme
12597
12598(allow hal_usb_gadget_server configfs (lnk_file (read create unlink)))
12599(allow hal_usb_gadget_server configfs (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
12600(allow hal_usb_gadget_server configfs (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
12601(allow hal_usb_gadget_server functionfs (dir (read search)))
12602(allow hal_usb_gadget_server functionfs (file (read)))
12603(allow hal_usb_gadget_server proc_interrupts (file (ioctl read getattr lock map open watch watch_reads)))
12604(allow hal_usb_gadget_server usb_uvc_enabled_prop (file (read getattr map open)))
12605(allow hal_uwb_client hal_uwb_server (binder (call transfer)))
12606(allow hal_uwb_server hal_uwb_client (binder (transfer)))
12607(allow hal_uwb_client hal_uwb_server (fd (use)))
12608(allow hal_uwb_server hal_uwb_client (binder (call transfer)))
12609(allow hal_uwb_client hal_uwb_server (binder (transfer)))
12610(allow hal_uwb_server hal_uwb_client (fd (use)))
12611(allow hal_uwb_client hal_uwb_service (service_manager (find)))
12612(allow hal_uwb_server hal_uwb_service (service_manager (add find)))
12613;;* lmx 5 system/sepolicy/public/hal_uwb.te
12614
12615(neverallow base_typeattr_521 hal_uwb_service (service_manager (add)))
12616;;* lme
12617
12618;;* lmx 5 system/sepolicy/public/hal_uwb.te
12619
12620(neverallow base_typeattr_522 hal_uwb_service (service_manager (find)))
12621;;* lme
12622
12623(allow hal_uwb_server servicemanager (binder (call transfer)))
12624(allow servicemanager hal_uwb_server (binder (transfer)))
12625(allow hal_uwb_server servicemanager (fd (use)))
12626(allow hal_uwb_client servicemanager (binder (call transfer)))
12627(allow servicemanager hal_uwb_client (binder (transfer)))
12628(allow hal_uwb_client servicemanager (fd (use)))
12629(allow hal_vehicle_client hal_vehicle_server (binder (call transfer)))
12630(allow hal_vehicle_server hal_vehicle_client (binder (transfer)))
12631(allow hal_vehicle_client hal_vehicle_server (fd (use)))
12632(allow hal_vehicle_server hal_vehicle_client (binder (call transfer)))
12633(allow hal_vehicle_client hal_vehicle_server (binder (transfer)))
12634(allow hal_vehicle_server hal_vehicle_client (fd (use)))
12635(allow hal_vehicle_client hal_vehicle_hwservice (hwservice_manager (find)))
12636(allow hal_vehicle_server hal_vehicle_hwservice (hwservice_manager (add find)))
12637(allow hal_vehicle_server hidl_base_hwservice (hwservice_manager (add)))
12638;;* lmx 6 system/sepolicy/public/hal_vehicle.te
12639
12640(neverallow base_typeattr_523 hal_vehicle_hwservice (hwservice_manager (add)))
12641;;* lme
12642
12643;;* lmx 6 system/sepolicy/public/hal_vehicle.te
12644
12645(neverallow base_typeattr_524 hal_vehicle_hwservice (hwservice_manager (find)))
12646;;* lme
12647
12648(allow hal_vehicle_client hal_vehicle_service (service_manager (find)))
12649(allow hal_vehicle_server hal_vehicle_service (service_manager (add find)))
12650;;* lmx 7 system/sepolicy/public/hal_vehicle.te
12651
12652(neverallow base_typeattr_523 hal_vehicle_service (service_manager (add)))
12653;;* lme
12654
12655;;* lmx 7 system/sepolicy/public/hal_vehicle.te
12656
12657(neverallow base_typeattr_525 hal_vehicle_service (service_manager (find)))
12658;;* lme
12659
12660(allow hal_vibrator_client hal_vibrator_server (binder (call transfer)))
12661(allow hal_vibrator_server hal_vibrator_client (binder (transfer)))
12662(allow hal_vibrator_client hal_vibrator_server (fd (use)))
12663(allow hal_vibrator_server hal_vibrator_client (binder (call transfer)))
12664(allow hal_vibrator_client hal_vibrator_server (binder (transfer)))
12665(allow hal_vibrator_server hal_vibrator_client (fd (use)))
12666(allow hal_vibrator_client hal_vibrator_hwservice (hwservice_manager (find)))
12667(allow hal_vibrator_server hal_vibrator_hwservice (hwservice_manager (add find)))
12668(allow hal_vibrator_server hidl_base_hwservice (hwservice_manager (add)))
12669;;* lmx 5 system/sepolicy/public/hal_vibrator.te
12670
12671(neverallow base_typeattr_526 hal_vibrator_hwservice (hwservice_manager (add)))
12672;;* lme
12673
12674;;* lmx 5 system/sepolicy/public/hal_vibrator.te
12675
12676(neverallow base_typeattr_527 hal_vibrator_hwservice (hwservice_manager (find)))
12677;;* lme
12678
12679(allow hal_vibrator_client hal_vibrator_service (service_manager (find)))
12680(allow hal_vibrator_server hal_vibrator_service (service_manager (add find)))
12681;;* lmx 6 system/sepolicy/public/hal_vibrator.te
12682
12683(neverallow base_typeattr_526 hal_vibrator_service (service_manager (add)))
12684;;* lme
12685
12686;;* lmx 6 system/sepolicy/public/hal_vibrator.te
12687
12688(neverallow base_typeattr_528 hal_vibrator_service (service_manager (find)))
12689;;* lme
12690
12691(allow hal_vibrator_server servicemanager (binder (call transfer)))
12692(allow servicemanager hal_vibrator_server (binder (transfer)))
12693(allow hal_vibrator_server servicemanager (fd (use)))
12694(allow hal_vibrator_server dumpstate (fifo_file (write)))
12695(allow hal_vibrator sysfs_vibrator (file (ioctl read write getattr lock append map open watch watch_reads)))
12696(allow hal_vibrator sysfs_vibrator (dir (search)))
12697(allow hal_vibrator fwk_vibrator_control_service (service_manager (find)))
12698(allow hal_vr_client hal_vr_server (binder (call transfer)))
12699(allow hal_vr_server hal_vr_client (binder (transfer)))
12700(allow hal_vr_client hal_vr_server (fd (use)))
12701(allow hal_vr_server hal_vr_client (binder (call transfer)))
12702(allow hal_vr_client hal_vr_server (binder (transfer)))
12703(allow hal_vr_server hal_vr_client (fd (use)))
12704(allow hal_vr_client hal_vr_hwservice (hwservice_manager (find)))
12705(allow hal_vr_server hal_vr_hwservice (hwservice_manager (add find)))
12706(allow hal_vr_server hidl_base_hwservice (hwservice_manager (add)))
12707;;* lmx 5 system/sepolicy/public/hal_vr.te
12708
12709(neverallow base_typeattr_529 hal_vr_hwservice (hwservice_manager (add)))
12710;;* lme
12711
12712;;* lmx 5 system/sepolicy/public/hal_vr.te
12713
12714(neverallow base_typeattr_530 hal_vr_hwservice (hwservice_manager (find)))
12715;;* lme
12716
12717(allow hal_weaver_client hal_weaver_server (binder (call transfer)))
12718(allow hal_weaver_server hal_weaver_client (binder (transfer)))
12719(allow hal_weaver_client hal_weaver_server (fd (use)))
12720(allow hal_weaver_client hal_weaver_hwservice (hwservice_manager (find)))
12721(allow hal_weaver_server hal_weaver_hwservice (hwservice_manager (add find)))
12722(allow hal_weaver_server hidl_base_hwservice (hwservice_manager (add)))
12723;;* lmx 4 system/sepolicy/public/hal_weaver.te
12724
12725(neverallow base_typeattr_531 hal_weaver_hwservice (hwservice_manager (add)))
12726;;* lme
12727
12728;;* lmx 4 system/sepolicy/public/hal_weaver.te
12729
12730(neverallow base_typeattr_532 hal_weaver_hwservice (hwservice_manager (find)))
12731;;* lme
12732
12733(allow hal_weaver_client hal_weaver_service (service_manager (find)))
12734(allow hal_weaver_server hal_weaver_service (service_manager (add find)))
12735;;* lmx 5 system/sepolicy/public/hal_weaver.te
12736
12737(neverallow base_typeattr_531 hal_weaver_service (service_manager (add)))
12738;;* lme
12739
12740;;* lmx 5 system/sepolicy/public/hal_weaver.te
12741
12742(neverallow base_typeattr_533 hal_weaver_service (service_manager (find)))
12743;;* lme
12744
12745(allow hal_weaver_server servicemanager (binder (call transfer)))
12746(allow servicemanager hal_weaver_server (binder (transfer)))
12747(allow hal_weaver_server servicemanager (fd (use)))
12748(allow hal_wifi_client hal_wifi_server (binder (call transfer)))
12749(allow hal_wifi_server hal_wifi_client (binder (transfer)))
12750(allow hal_wifi_client hal_wifi_server (fd (use)))
12751(allow hal_wifi_server hal_wifi_client (binder (call transfer)))
12752(allow hal_wifi_client hal_wifi_server (binder (transfer)))
12753(allow hal_wifi_server hal_wifi_client (fd (use)))
12754(allow hal_wifi_client hal_wifi_hwservice (hwservice_manager (find)))
12755(allow hal_wifi_server hal_wifi_hwservice (hwservice_manager (add find)))
12756(allow hal_wifi_server hidl_base_hwservice (hwservice_manager (add)))
12757;;* lmx 5 system/sepolicy/public/hal_wifi.te
12758
12759(neverallow base_typeattr_534 hal_wifi_hwservice (hwservice_manager (add)))
12760;;* lme
12761
12762;;* lmx 5 system/sepolicy/public/hal_wifi.te
12763
12764(neverallow base_typeattr_535 hal_wifi_hwservice (hwservice_manager (find)))
12765;;* lme
12766
12767(allow hal_wifi_client hal_wifi_service (service_manager (find)))
12768(allow hal_wifi_server hal_wifi_service (service_manager (add find)))
12769;;* lmx 6 system/sepolicy/public/hal_wifi.te
12770
12771(neverallow base_typeattr_534 hal_wifi_service (service_manager (add)))
12772;;* lme
12773
12774;;* lmx 6 system/sepolicy/public/hal_wifi.te
12775
12776(neverallow base_typeattr_536 hal_wifi_service (service_manager (find)))
12777;;* lme
12778
12779(allow hal_wifi_server servicemanager (binder (call transfer)))
12780(allow servicemanager hal_wifi_server (binder (call transfer)))
12781(allow servicemanager hal_wifi_server (dir (search)))
12782(allow servicemanager hal_wifi_server (file (read open)))
12783(allow servicemanager hal_wifi_server (process (getattr)))
12784(allow hal_wifi proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
12785(allow hal_wifi proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
12786(allow hal_wifi proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12787(allow hal_wifi sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
12788(allow hal_wifi sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
12789(allow hal_wifi sysfs_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12790(allow hal_wifi_server property_socket (sock_file (write)))
12791(allow hal_wifi_server init (unix_stream_socket (connectto)))
12792(allow hal_wifi_server wifi_hal_prop (property_service (set)))
12793(allow hal_wifi_server wifi_hal_prop (file (read getattr map open)))
12794(allow hal_wifi property_socket (sock_file (write)))
12795(allow hal_wifi init (unix_stream_socket (connectto)))
12796(allow hal_wifi wifi_prop (property_service (set)))
12797(allow hal_wifi wifi_prop (file (read getattr map open)))
12798(allow hal_wifi self (udp_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12799(allowx hal_wifi self (ioctl udp_socket (0x8914 0x8924 0x8946)))
12800(allow hal_wifi self (capability (net_admin net_raw)))
12801(allow hal_wifi self (cap_userns (net_admin net_raw)))
12802(allow hal_wifi self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12803(allow hal_wifi self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12804(allow hal_wifi sysfs_wlan_fwpath (file (write lock append map open)))
12805(allow hal_wifi proc_modules (file (read getattr open)))
12806(allow hal_wifi dumpstate (fifo_file (write)))
12807(allow hal_wifi_server tombstone_wifi_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
12808(allow hal_wifi_server tombstone_wifi_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
12809(allow hal_wifi_hostapd_client hal_wifi_hostapd_server (binder (call transfer)))
12810(allow hal_wifi_hostapd_server hal_wifi_hostapd_client (binder (transfer)))
12811(allow hal_wifi_hostapd_client hal_wifi_hostapd_server (fd (use)))
12812(allow hal_wifi_hostapd_server hal_wifi_hostapd_client (binder (call transfer)))
12813(allow hal_wifi_hostapd_client hal_wifi_hostapd_server (binder (transfer)))
12814(allow hal_wifi_hostapd_server hal_wifi_hostapd_client (fd (use)))
12815(allow hal_wifi_hostapd_client hal_wifi_hostapd_hwservice (hwservice_manager (find)))
12816(allow hal_wifi_hostapd_server hal_wifi_hostapd_hwservice (hwservice_manager (add find)))
12817(allow hal_wifi_hostapd_server hidl_base_hwservice (hwservice_manager (add)))
12818;;* lmx 5 system/sepolicy/public/hal_wifi_hostapd.te
12819
12820(neverallow base_typeattr_537 hal_wifi_hostapd_hwservice (hwservice_manager (add)))
12821;;* lme
12822
12823;;* lmx 5 system/sepolicy/public/hal_wifi_hostapd.te
12824
12825(neverallow base_typeattr_538 hal_wifi_hostapd_hwservice (hwservice_manager (find)))
12826;;* lme
12827
12828(allow hal_wifi_hostapd_client hal_wifi_hostapd_service (service_manager (find)))
12829(allow hal_wifi_hostapd_server hal_wifi_hostapd_service (service_manager (add find)))
12830;;* lmx 6 system/sepolicy/public/hal_wifi_hostapd.te
12831
12832(neverallow base_typeattr_537 hal_wifi_hostapd_service (service_manager (add)))
12833;;* lme
12834
12835;;* lmx 6 system/sepolicy/public/hal_wifi_hostapd.te
12836
12837(neverallow base_typeattr_539 hal_wifi_hostapd_service (service_manager (find)))
12838;;* lme
12839
12840(allow hal_wifi_hostapd_server servicemanager (binder (call transfer)))
12841(allow servicemanager hal_wifi_hostapd_server (binder (call transfer)))
12842(allow servicemanager hal_wifi_hostapd_server (dir (search)))
12843(allow servicemanager hal_wifi_hostapd_server (file (read open)))
12844(allow servicemanager hal_wifi_hostapd_server (process (getattr)))
12845(allow hal_wifi_hostapd_server dumpstate (fifo_file (write)))
12846(allow hal_wifi_hostapd_server self (capability (net_admin net_raw)))
12847(allow hal_wifi_hostapd_server self (cap_userns (net_admin net_raw)))
12848(allow hal_wifi_hostapd_server sysfs_net (dir (search)))
12849(allow hal_wifi_hostapd_server proc_net_type (file (read getattr open)))
12850(allowx hal_wifi_hostapd_server self (ioctl udp_socket (0x6900 0x6902)))
12851(allowx hal_wifi_hostapd_server self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
12852(allowx hal_wifi_hostapd_server self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
12853(allow hal_wifi_hostapd_server self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12854(allow hal_wifi_hostapd_server self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12855(allow hal_wifi_hostapd_server self (packet_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12856(allow hal_wifi_hostapd_server self (netlink_route_socket (nlmsg_write)))
12857;;* lmx 31 system/sepolicy/public/hal_wifi_hostapd.te
12858
12859(neverallow hal_wifi_hostapd_server sdcard_type (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
12860(neverallow hal_wifi_hostapd_server fuse (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
12861;;* lme
12862
12863;;* lmx 32 system/sepolicy/public/hal_wifi_hostapd.te
12864
12865(neverallow hal_wifi_hostapd_server sdcard_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
12866(neverallow hal_wifi_hostapd_server fuse (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
12867;;* lme
12868
12869(allow hal_wifi_supplicant_client hal_wifi_supplicant_server (binder (call transfer)))
12870(allow hal_wifi_supplicant_server hal_wifi_supplicant_client (binder (transfer)))
12871(allow hal_wifi_supplicant_client hal_wifi_supplicant_server (fd (use)))
12872(allow hal_wifi_supplicant_server hal_wifi_supplicant_client (binder (call transfer)))
12873(allow hal_wifi_supplicant_client hal_wifi_supplicant_server (binder (transfer)))
12874(allow hal_wifi_supplicant_server hal_wifi_supplicant_client (fd (use)))
12875(allow hal_wifi_supplicant_client hal_wifi_supplicant_hwservice (hwservice_manager (find)))
12876(allow hal_wifi_supplicant_server hal_wifi_supplicant_hwservice (hwservice_manager (add find)))
12877(allow hal_wifi_supplicant_server hidl_base_hwservice (hwservice_manager (add)))
12878;;* lmx 5 system/sepolicy/public/hal_wifi_supplicant.te
12879
12880(neverallow base_typeattr_540 hal_wifi_supplicant_hwservice (hwservice_manager (add)))
12881;;* lme
12882
12883;;* lmx 5 system/sepolicy/public/hal_wifi_supplicant.te
12884
12885(neverallow base_typeattr_541 hal_wifi_supplicant_hwservice (hwservice_manager (find)))
12886;;* lme
12887
12888(allow hal_wifi_supplicant_client hal_wifi_supplicant_service (service_manager (find)))
12889(allow hal_wifi_supplicant_server hal_wifi_supplicant_service (service_manager (add find)))
12890;;* lmx 6 system/sepolicy/public/hal_wifi_supplicant.te
12891
12892(neverallow base_typeattr_540 hal_wifi_supplicant_service (service_manager (add)))
12893;;* lme
12894
12895;;* lmx 6 system/sepolicy/public/hal_wifi_supplicant.te
12896
12897(neverallow base_typeattr_542 hal_wifi_supplicant_service (service_manager (find)))
12898;;* lme
12899
12900(allowx hal_wifi_supplicant self (ioctl udp_socket (0x6900 0x6902)))
12901(allowx hal_wifi_supplicant self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
12902(allowx hal_wifi_supplicant self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
12903(allow hal_wifi_supplicant sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
12904(allow hal_wifi_supplicant sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
12905(allow hal_wifi_supplicant sysfs_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12906(allow hal_wifi_supplicant proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
12907(allow hal_wifi_supplicant proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
12908(allow hal_wifi_supplicant proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12909(allow hal_wifi_supplicant self (capability (setgid setuid net_admin net_raw)))
12910(allow hal_wifi_supplicant self (cap_userns (setgid setuid net_admin net_raw)))
12911(allow hal_wifi_supplicant cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
12912(allow hal_wifi_supplicant cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
12913(allow hal_wifi_supplicant self (netlink_route_socket (nlmsg_write)))
12914(allow hal_wifi_supplicant self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12915(allow hal_wifi_supplicant self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12916(allow hal_wifi_supplicant self (packet_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
12917(allowx hal_wifi_supplicant self (ioctl packet_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
12918(allowx hal_wifi_supplicant self (ioctl packet_socket (0x6900 0x6902)))
12919(allowx hal_wifi_supplicant self (ioctl packet_socket ((range 0x8906 0x8907) (range 0x890b 0x890d) (range 0x8910 0x8927) 0x8929 (range 0x8930 0x8939) (range 0x8940 0x8943) (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
12920(allowx hal_wifi_supplicant self (ioctl packet_socket ((range 0x8b00 0x8b02) (range 0x8b04 0x8b1d) (range 0x8b20 0x8b2d) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
12921(allow keystore hal_wifi_supplicant (dir (search)))
12922(allow keystore hal_wifi_supplicant (file (read open)))
12923(allow keystore hal_wifi_supplicant (process (getattr)))
12924(allow hal_wifi_supplicant apc_service (service_manager (find)))
12925(allow hal_wifi_supplicant keystore_service (service_manager (find)))
12926(allow hal_wifi_supplicant legacykeystore_service (service_manager (find)))
12927(allow hal_wifi_supplicant keystore (binder (call transfer)))
12928(allow keystore hal_wifi_supplicant (binder (transfer)))
12929(allow hal_wifi_supplicant keystore (fd (use)))
12930(allow keystore hal_wifi_supplicant (binder (call transfer)))
12931(allow hal_wifi_supplicant keystore (binder (transfer)))
12932(allow keystore hal_wifi_supplicant (fd (use)))
12933(allow hal_wifi_supplicant_server servicemanager (binder (call transfer)))
12934(allow servicemanager hal_wifi_supplicant_server (binder (call transfer)))
12935(allow servicemanager hal_wifi_supplicant_server (dir (search)))
12936(allow servicemanager hal_wifi_supplicant_server (file (read open)))
12937(allow servicemanager hal_wifi_supplicant_server (process (getattr)))
12938(allow hal_wifi_supplicant wifi_key (keystore2_key (get_info use)))
12939;;* lmx 37 system/sepolicy/public/hal_wifi_supplicant.te
12940
12941(neverallow hal_wifi_supplicant_server sdcard_type (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
12942(neverallow hal_wifi_supplicant_server fuse (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
12943;;* lme
12944
12945;;* lmx 38 system/sepolicy/public/hal_wifi_supplicant.te
12946
12947(neverallow hal_wifi_supplicant_server sdcard_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
12948(neverallow hal_wifi_supplicant_server fuse (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
12949;;* lme
12950
12951;;* lmx 102 system/sepolicy/public/hwservice.te
12952
12953(neverallow domain base_typeattr_543 (hwservice_manager (add find)))
12954;;* lme
12955
12956(allow hwservicemanager self (binder (set_context_mgr)))
12957(allow hwservicemanager system_file (dir (ioctl read getattr lock open watch watch_reads search)))
12958(allow hwservicemanager hwservice_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
12959(allow hwservicemanager selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
12960(allow hwservicemanager selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
12961(allow hwservicemanager selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12962(allow hwservicemanager selinuxfs (file (write lock append map open)))
12963(allow hwservicemanager kernel (security (compute_av)))
12964(allow hwservicemanager self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
12965(allow idmap resourcecache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
12966(allow idmap resourcecache_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
12967(allow idmap apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
12968(allow idmap apk_data_file (dir (search)))
12969(allow idmap apk_tmp_file (file (ioctl read getattr lock map open watch watch_reads)))
12970(allow idmap apk_private_tmp_file (file (ioctl read getattr lock map open watch watch_reads)))
12971(allow idmap apk_tmp_file (dir (search)))
12972(allow idmap apk_private_tmp_file (dir (search)))
12973(allow idmap vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
12974(allow idmap vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
12975(allow idmap vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12976(allow idmap vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
12977(allow idmap vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
12978(allow idmap vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
12979(allow idmap servicemanager (binder (call transfer)))
12980(allow servicemanager idmap (binder (call transfer)))
12981(allow servicemanager idmap (dir (search)))
12982(allow servicemanager idmap (file (read open)))
12983(allow servicemanager idmap (process (getattr)))
12984(allow idmap idmap_service (service_manager (add find)))
12985;;* lmx 26 system/sepolicy/public/idmap.te
12986
12987(neverallow base_typeattr_544 idmap_service (service_manager (add)))
12988;;* lme
12989
12990(allow init tmpfs (chr_file (ioctl read write create getattr setattr lock append map unlink open watch watch_reads)))
12991(allow init tmpfs (chr_file (relabelfrom)))
12992(allow init kmsg_device (chr_file (write getattr relabelto)))
12993(allow init properties_device (dir (relabelto)))
12994(allow init properties_serial (file (write relabelto)))
12995(allow init property_type (file (read write create getattr setattr relabelto append map unlink rename open)))
12996(allow init properties_device (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
12997(allow init property_info (file (relabelto)))
12998(allow init device (file (relabelfrom)))
12999(allow init runtime_event_log_tags_file (file (write create setattr relabelto open)))
13000(allow init device (dir (relabelto)))
13001(allow init dm_user_device (dir (relabelto)))
13002(allow init socket_device (dir (relabelto)))
13003(allow init lmkd_socket (sock_file (write)))
13004(allow init lmkd (unix_stream_socket (connectto)))
13005(allow init console_device (chr_file (relabelto)))
13006(allow init ptmx_device (chr_file (relabelto)))
13007(allow init null_device (chr_file (relabelto)))
13008(allow init random_device (chr_file (relabelto)))
13009(allow init tmpfs (chr_file (relabelfrom)))
13010(allow init tmpfs (blk_file (relabelfrom)))
13011(allow init tmpfs (blk_file (getattr)))
13012(allow init block_device (dir (relabelto)))
13013(allow init block_device (lnk_file (relabelto)))
13014(allow init block_device (blk_file (relabelto)))
13015(allow init dm_device (chr_file (relabelto)))
13016(allow init dm_device (blk_file (relabelto)))
13017(allow init dm_user_device (chr_file (relabelto)))
13018(allow init kernel (fd (use)))
13019(allow init tmpfs (lnk_file (read getattr relabelfrom)))
13020(allow init system_block_device (lnk_file (relabelto)))
13021(allow init system_block_device (blk_file (relabelto)))
13022(allow init recovery_block_device (lnk_file (relabelto)))
13023(allow init recovery_block_device (blk_file (relabelto)))
13024(allow init userdata_block_device (lnk_file (relabelto)))
13025(allow init userdata_block_device (blk_file (relabelto)))
13026(allow init metadata_block_device (lnk_file (relabelto)))
13027(allow init metadata_block_device (blk_file (relabelto)))
13028(allow init misc_block_device (lnk_file (relabelto)))
13029(allow init misc_block_device (blk_file (relabelto)))
13030(allow init dtbo_block_device (lnk_file (relabelto)))
13031(allow init super_block_device (lnk_file (relabelto)))
13032(allow init mnt_sdcard_file (lnk_file (create)))
13033(allow init self (capability (sys_resource)))
13034(allow init self (cap_userns (sys_resource)))
13035(allow init tmpfs (file (getattr unlink)))
13036(allow init devpts (chr_file (read write open)))
13037(allow init fscklogs (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13038(allow init tmpfs (chr_file (write)))
13039(allow init console_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13040(allow init tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13041(allow init self (capability (sys_admin)))
13042(allow init self (cap_userns (sys_admin)))
13043(allow init self (capability (sys_chroot)))
13044(allow init self (cap_userns (sys_chroot)))
13045(allow init rootfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13046(allow init rootfs (dir (mounton)))
13047(allow init cgroup (dir (mounton)))
13048(allow init system_file (dir (mounton)))
13049(allow init linkerconfig_file (dir (mounton)))
13050(allow init vendor_file (dir (mounton)))
13051(allow init system_data_root_file (dir (mounton)))
13052(allow init system_data_file (dir (mounton)))
13053(allow init shell_data_file (dir (mounton)))
13054(allow init mnt_user_file (dir (mounton)))
13055(allow init storage_file (dir (mounton)))
13056(allow init postinstall_mnt_dir (dir (mounton)))
13057(allow init mirror_data_file (dir (mounton)))
13058(allow init cache_file (dir (mounton)))
13059(allow init system_dlkm_file (dir (mounton)))
13060(allow init fs_bpf (dir (mounton)))
13061(allow init device (dir (mounton)))
13062(allow init apex_mnt_dir (dir (mounton)))
13063(allow init art_apex_dir (dir (mounton)))
13064(allow init rootfs (lnk_file (create unlink)))
13065(allow init sysfs (dir (mounton)))
13066(allow init tmpfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13067(allow init tmpfs (dir (mounton)))
13068(allow init cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13069(allow init cgroup (file (ioctl read write getattr lock append map open watch watch_reads)))
13070(allow init cgroup_rc_file (file (ioctl read write getattr lock append map open watch watch_reads)))
13071(allow init cgroup_desc_file (file (ioctl read getattr lock map open watch watch_reads)))
13072(allow init cgroup_desc_api_file (file (ioctl read getattr lock map open watch watch_reads)))
13073(allow init vendor_cgroup_desc_file (file (ioctl read getattr lock map open watch watch_reads)))
13074(allow init cgroup_v2 (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
13075(allow init cgroup_v2 (file (ioctl read write getattr lock append map open watch watch_reads)))
13076(allow init configfs (dir (mounton)))
13077(allow init configfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13078(allow init configfs (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13079(allow init configfs (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13080(allow init metadata_file (dir (mounton)))
13081(allow init tmpfs (dir (relabelfrom)))
13082(allow init self (capability (dac_override dac_read_search)))
13083(allow init self (cap_userns (dac_override dac_read_search)))
13084(allow init self (capability (sys_time)))
13085(allow init self (cap_userns (sys_time)))
13086(allow init self (capability (sys_rawio mknod)))
13087(allow init self (cap_userns (sys_rawio mknod)))
13088(allow init dev_type (blk_file (ioctl read getattr lock map open watch watch_reads)))
13089(allowx init dev_type (ioctl blk_file (0x125d)))
13090(allowx init system_data_root_file (ioctl dir (0x587d)))
13091(allow init base_typeattr_545 (filesystem (mount remount unmount getattr relabelfrom associate quotamod quotaget watch)))
13092(allow init debugfs_tracing_debug (filesystem (mount)))
13093(allow init unlabeled (filesystem (mount remount unmount getattr relabelfrom associate quotamod quotaget watch)))
13094(allow init contextmount_type (filesystem (relabelto)))
13095(allow init contextmount_type (dir (ioctl read getattr lock open watch watch_reads search)))
13096(allow init contextmount_type (file (ioctl read getattr lock map open watch watch_reads)))
13097(allow init contextmount_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13098(allow init contextmount_type (sock_file (ioctl read getattr lock map open watch watch_reads)))
13099(allow init contextmount_type (fifo_file (ioctl read getattr lock map open watch watch_reads)))
13100(allow init rootfs (file (relabelfrom)))
13101(allow init rootfs (dir (relabelfrom)))
13102(allow init self (capability (chown fowner fsetid)))
13103(allow init self (cap_userns (chown fowner fsetid)))
13104(allow init base_typeattr_546 (dir (ioctl read create getattr setattr open search)))
13105(allow init base_typeattr_547 (dir (write relabelfrom add_name remove_name rmdir)))
13106(allow init base_typeattr_548 (file (read write create getattr setattr relabelfrom map unlink open)))
13107(allow init tracefs_type (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
13108(allow init apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
13109(allow init base_typeattr_549 (sock_file (read create getattr setattr relabelfrom unlink open)))
13110(allow init base_typeattr_549 (fifo_file (read create getattr setattr relabelfrom unlink open)))
13111(allow init base_typeattr_550 (lnk_file (create getattr setattr relabelfrom unlink)))
13112(allow init cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13113(allow init base_typeattr_551 (file (relabelto)))
13114(allow init base_typeattr_551 (dir (relabelto)))
13115(allow init base_typeattr_551 (lnk_file (relabelto)))
13116(allow init base_typeattr_551 (chr_file (relabelto)))
13117(allow init base_typeattr_551 (blk_file (relabelto)))
13118(allow init base_typeattr_551 (sock_file (relabelto)))
13119(allow init base_typeattr_551 (fifo_file (relabelto)))
13120(allow init sysfs (file (getattr relabelfrom)))
13121(allow init sysfs (dir (getattr relabelfrom)))
13122(allow init sysfs (lnk_file (getattr relabelfrom)))
13123(allow init debugfs_tracing (file (getattr relabelfrom)))
13124(allow init debugfs_tracing (dir (getattr relabelfrom)))
13125(allow init debugfs_tracing (lnk_file (getattr relabelfrom)))
13126(allow init debugfs_tracing_debug (file (getattr relabelfrom)))
13127(allow init debugfs_tracing_debug (dir (getattr relabelfrom)))
13128(allow init debugfs_tracing_debug (lnk_file (getattr relabelfrom)))
13129(allow init sysfs_type (file (getattr relabelto)))
13130(allow init sysfs_type (dir (getattr relabelto)))
13131(allow init sysfs_type (lnk_file (getattr relabelto)))
13132(allow init tracefs_type (file (getattr relabelto)))
13133(allow init tracefs_type (dir (getattr relabelto)))
13134(allow init tracefs_type (lnk_file (getattr relabelto)))
13135(allow init dev_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13136(allow init dev_type (lnk_file (create)))
13137(allow init debugfs_tracing (file (write lock append map open)))
13138(allow init debugfs_tracing_instances (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13139(allow init debugfs_tracing_instances (file (write lock append map open)))
13140(allow init debugfs_wifi_tracing (file (write lock append map open)))
13141(allow init base_typeattr_552 (file (read setattr open)))
13142(allow init base_typeattr_553 (dir (read setattr open search)))
13143(allow init binder_device (chr_file (read open)))
13144(allow init hwbinder_device (chr_file (read open)))
13145(allow init dm_device (chr_file (read open)))
13146(allow init pmsg_device (chr_file (read open)))
13147(allow init console_device (chr_file (read open)))
13148(allow init input_device (chr_file (read open)))
13149(allow init ptmx_device (chr_file (read open)))
13150(allow init kmsg_device (chr_file (read open)))
13151(allow init null_device (chr_file (read open)))
13152(allow init random_device (chr_file (read open)))
13153(allow init owntty_device (chr_file (read open)))
13154(allow init tty_device (chr_file (read open)))
13155(allow init zero_device (chr_file (read open)))
13156(allow init devpts (chr_file (read open)))
13157(allow init unlabeled (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
13158(allow init unlabeled (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
13159(allow init unlabeled (lnk_file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
13160(allow init unlabeled (sock_file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
13161(allow init unlabeled (fifo_file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
13162(allow init kernel (system (syslog_mod)))
13163(allow init self (capability2 (syslog)))
13164(allow init self (cap2_userns (syslog)))
13165(allow init proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
13166(allow init proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
13167(allow init proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13168(allow init proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
13169(allow init proc (file (ioctl read getattr lock map open watch watch_reads)))
13170(allow init proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
13171(allow init proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
13172(allow init proc_diskstats (file (ioctl read getattr lock map open watch watch_reads)))
13173(allow init proc_kmsg (file (ioctl read getattr lock map open watch watch_reads)))
13174(allow init proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
13175(allow init proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
13176(allow init proc_uptime (file (ioctl read getattr lock map open watch watch_reads)))
13177(allow init proc_version (file (ioctl read getattr lock map open watch watch_reads)))
13178(allow init proc_net_type (file (write lock append map open)))
13179(allow init proc_overcommit_memory (file (write lock append map open)))
13180(allow init proc_min_free_order_shift (file (write lock append map open)))
13181(allow init proc_watermark_boost_factor (file (write lock append map open)))
13182(allow init proc_abi (file (write lock append map open)))
13183(allow init proc_cpu_alignment (file (write lock append map open)))
13184(allow init proc_dirty (file (write lock append map open)))
13185(allow init proc_extra_free_kbytes (file (write lock append map open)))
13186(allow init proc_hostname (file (write lock append map open)))
13187(allow init proc_hung_task (file (write lock append map open)))
13188(allow init proc_max_map_count (file (write lock append map open)))
13189(allow init proc_page_cluster (file (write lock append map open)))
13190(allow init proc_panic (file (write lock append map open)))
13191(allow init proc_perf (file (write lock append map open)))
13192(allow init proc_sched (file (write lock append map open)))
13193(allow init proc_sysrq (file (write lock append map open)))
13194(allow init proc_security (file (ioctl read write getattr lock append map open watch watch_reads)))
13195(allow init proc_qtaguid_ctrl (file (setattr)))
13196(allow init proc_qtaguid_stat (file (setattr)))
13197(allow init proc_bootconfig (file (setattr)))
13198(allow init proc_cmdline (file (setattr)))
13199(allow init proc_kmsg (file (setattr)))
13200(allow init proc_net (file (setattr)))
13201(allow init proc_pagetypeinfo (file (setattr)))
13202(allow init proc_slabinfo (file (setattr)))
13203(allow init proc_sysrq (file (setattr)))
13204(allow init proc_vmallocinfo (file (setattr)))
13205(allow init sysfs_android_usb (file (write lock append map open)))
13206(allow init sysfs_dm (file (write lock append map open)))
13207(allow init sysfs_dm_verity (file (write lock append map open)))
13208(allow init sysfs_leds (file (write lock append map open)))
13209(allow init sysfs_power (file (write lock append map open)))
13210(allow init sysfs_lru_gen_enabled (file (write lock append map open)))
13211(allow init sysfs_fs_f2fs (file (write lock append map open)))
13212(allow init sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
13213(allow init sysfs_fs_ext4_features (file (ioctl read getattr lock map open watch watch_reads)))
13214(allow init sysfs_zram (file (ioctl read write getattr lock append map open watch watch_reads)))
13215(allow init loop_control_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13216(allow init loop_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
13217(allowx init loop_device (ioctl blk_file ((range 0x4c00 0x4c01) (range 0x4c03 0x4c04) (range 0x4c08 0x4c09) 0x4c82)))
13218(allow init sysfs_vibrator (file (write lock append map open)))
13219(allow init sysfs_android_usb (file (setattr)))
13220(allow init sysfs_ipv4 (file (setattr)))
13221(allow init sysfs_leds (file (setattr)))
13222(allow init sysfs_wake_lock (file (setattr)))
13223(allow init sysfs_power (file (setattr)))
13224(allow init sysfs_devices_system_cpu (file (setattr)))
13225(allow init sysfs_lowmemorykiller (file (setattr)))
13226(allow init sysfs_vibrator (file (setattr)))
13227(allow init sysfs_zram (file (setattr)))
13228(allow init usermodehelper (file (ioctl read write getattr lock append map open watch watch_reads)))
13229(allow init sysfs_usermodehelper (file (ioctl read write getattr lock append map open watch watch_reads)))
13230(allow init self (capability (net_admin)))
13231(allow init self (cap_userns (net_admin)))
13232(allow init self (capability (sys_boot)))
13233(allow init self (cap_userns (sys_boot)))
13234(allow init misc_logd_file (dir (read write create getattr setattr open add_name search)))
13235(allow init misc_logd_file (file (write create getattr setattr open)))
13236(allow init self (capability (kill)))
13237(allow init self (cap_userns (kill)))
13238(allow init domain (process (sigkill signal getpgid)))
13239(allow init credstore_data_file (dir (read create getattr setattr open search)))
13240(allow init credstore_data_file (file (getattr)))
13241(allow init keystore_data_file (dir (read create getattr setattr open search)))
13242(allow init keystore_data_file (file (getattr)))
13243(allow init vold_data_file (dir (read create getattr setattr open search)))
13244(allow init vold_data_file (file (getattr)))
13245(allow init shell_data_file (dir (read create getattr setattr open search)))
13246(allow init shell_data_file (file (getattr)))
13247(allow init self (capability (setgid setuid setpcap)))
13248(allow init self (cap_userns (setgid setuid setpcap)))
13249(allow init domain (dir (ioctl read getattr lock open watch watch_reads search)))
13250(allow init domain (file (ioctl read getattr lock map open watch watch_reads)))
13251(allow init domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13252(allow init self (process (setexec setfscreate setsockcreate)))
13253(allow init file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
13254(allow init sepolicy_file (file (ioctl read getattr lock map open watch watch_reads)))
13255(allow init selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
13256(allow init selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
13257(allow init selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13258(allow init selinuxfs (file (write lock append map open)))
13259(allow init kernel (security (compute_av)))
13260(allow init self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
13261(allow init kernel (security (compute_create)))
13262(allow init domain (unix_stream_socket (create bind setopt)))
13263(allow init domain (unix_dgram_socket (create bind setopt)))
13264(allow init property_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13265(allow init property_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13266(allow init property_type (property_service (set)))
13267(allow init self (netlink_audit_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_relay)))
13268(allow init self (capability (audit_write)))
13269(allow init self (cap_userns (audit_write)))
13270(allow init self (udp_socket (ioctl create)))
13271(allowx init self (ioctl udp_socket (0x8914)))
13272(allow init self (capability (net_raw)))
13273(allow init self (cap_userns (net_raw)))
13274(allow init kernel (process (getsched setsched)))
13275(allow init swap_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
13276(allow init device (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13277(allow init input_device (dir (ioctl read getattr lock open watch watch_reads search)))
13278(allow init input_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13279(allow init dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13280(allow init dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
13281(allow init dm_user_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13282(allow init metadata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
13283(allow init pstorefs (dir (search)))
13284(allow init pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
13285(allow init kernel (system (syslog_read)))
13286(allow init init (key (write search setattr)))
13287(allow init unencrypted_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13288(allowx init data_file_type (ioctl dir (0x6613 0x6615)))
13289(allowx init unlabeled (ioctl dir (0x6613 0x6615)))
13290(allow init misc_block_device (blk_file (write lock append map open)))
13291(allow init system_file (dir (ioctl read getattr lock open watch watch_reads search)))
13292(allow init system_file (file (ioctl read getattr lock map open watch watch_reads)))
13293(allow init system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13294(allow init system_dlkm_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
13295(allow init system_dlkm_file_type (file (ioctl read getattr lock map open watch watch_reads)))
13296(allow init system_dlkm_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13297(allow init vendor_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
13298(allow init vendor_file_type (file (ioctl read getattr lock map open watch watch_reads)))
13299(allow init vendor_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13300(allow init system_data_file (file (read getattr)))
13301(allow init system_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13302(allow init vendor_shell_exec (file (execute)))
13303(allow init vold_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13304(allow init vold_metadata_file (file (getattr)))
13305(allow init metadata_bootstat_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13306(allow init metadata_bootstat_file (file (write lock append map open)))
13307(allow init userspace_reboot_metadata_file (file (write lock append map open)))
13308(allow init proc_pressure_mem (file (ioctl read write getattr setattr lock append map open watch watch_reads)))
13309(allow init system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
13310(allow init system_bootstrap_lib_file (file (read getattr map execute open)))
13311(allow init fuse (dir (getattr search)))
13312(allow init userdata_sysdev (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13313(allow init rootdisk_sysdev (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13314;;* lmx 659 system/sepolicy/public/init.te
13315
13316(neverallow domain init (process (dyntransition)))
13317;;* lme
13318
13319;;* lmx 660 system/sepolicy/public/init.te
13320
13321(neverallow base_typeattr_254 init (process (transition)))
13322;;* lme
13323
13324;;* lmx 661 system/sepolicy/public/init.te
13325
13326(neverallow init base_typeattr_554 (file (entrypoint)))
13327;;* lme
13328
13329;;* lmx 664 system/sepolicy/public/init.te
13330
13331(neverallow init shell_data_file (lnk_file (read)))
13332;;* lme
13333
13334;;* lmx 665 system/sepolicy/public/init.te
13335
13336(neverallow init app_data_file_type (lnk_file (read)))
13337;;* lme
13338
13339;;* lmx 668 system/sepolicy/public/init.te
13340
13341(neverallow init fs_type (file (execute_no_trans)))
13342(neverallow init file_type (file (execute_no_trans)))
13343;;* lme
13344
13345;;* lmx 677 system/sepolicy/public/init.te
13346
13347(neverallow init base_typeattr_224 (process (noatsecure)))
13348;;* lme
13349
13350;;* lmx 680 system/sepolicy/public/init.te
13351
13352(neverallow init service_manager_type (service_manager (add find)))
13353;;* lme
13354
13355;;* lmx 682 system/sepolicy/public/init.te
13356
13357(neverallow init servicemanager (service_manager (list)))
13358;;* lme
13359
13360;;* lmx 685 system/sepolicy/public/init.te
13361
13362(neverallow init shell_data_file (dir (write add_name remove_name)))
13363;;* lme
13364
13365;;* lmx 688 system/sepolicy/public/init.te
13366
13367(neverallow init sysfs (file (write open)))
13368;;* lme
13369
13370;;* lmx 691 system/sepolicy/public/init.te
13371
13372(neverallow base_typeattr_224 init (process (ptrace)))
13373;;* lme
13374
13375;;* lmx 696 system/sepolicy/public/init.te
13376
13377(neverallow base_typeattr_555 system_data_root_file (dir (write add_name remove_name)))
13378;;* lme
13379
13380(allow inputflinger servicemanager (binder (call transfer)))
13381(allow servicemanager inputflinger (binder (call transfer)))
13382(allow servicemanager inputflinger (dir (search)))
13383(allow servicemanager inputflinger (file (read open)))
13384(allow servicemanager inputflinger (process (getattr)))
13385(allow inputflinger system_server (binder (call transfer)))
13386(allow system_server inputflinger (binder (transfer)))
13387(allow inputflinger system_server (fd (use)))
13388(allow inputflinger sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
13389(allow inputflinger self (capability2 (block_suspend)))
13390(allow inputflinger self (cap2_userns (block_suspend)))
13391(allow inputflinger system_suspend_server (binder (call transfer)))
13392(allow system_suspend_server inputflinger (binder (transfer)))
13393(allow inputflinger system_suspend_server (fd (use)))
13394(allow inputflinger system_suspend_hwservice (hwservice_manager (find)))
13395(allow inputflinger hwservicemanager (binder (call transfer)))
13396(allow hwservicemanager inputflinger (binder (call transfer)))
13397(allow hwservicemanager inputflinger (dir (search)))
13398(allow hwservicemanager inputflinger (file (read map open)))
13399(allow hwservicemanager inputflinger (process (getattr)))
13400(allow inputflinger hwservicemanager_prop (file (read getattr map open)))
13401(allow inputflinger hidl_manager_hwservice (hwservice_manager (find)))
13402(allow inputflinger hal_system_suspend_service (service_manager (find)))
13403(allow inputflinger servicemanager (binder (call transfer)))
13404(allow servicemanager inputflinger (binder (call transfer)))
13405(allow servicemanager inputflinger (dir (search)))
13406(allow servicemanager inputflinger (file (read open)))
13407(allow servicemanager inputflinger (process (getattr)))
13408(allow inputflinger input_device (dir (ioctl read getattr lock open watch watch_reads search)))
13409(allow inputflinger input_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13410(allow inputflinger cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
13411(allow inputflinger cgroup (file (ioctl read getattr lock map open watch watch_reads)))
13412(allow inputflinger cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13413(allow inputflinger cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
13414(allow inputflinger cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
13415(allow inputflinger cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13416(allow installd self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid sys_admin)))
13417(allow installd self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid sys_admin)))
13418(allow installd dalvikcache_data_file (dir (relabelto)))
13419(allow installd dalvikcache_data_file (file (relabelto link)))
13420(allow installd apk_data_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
13421(allow installd apk_data_file (file (ioctl read write create getattr setattr lock relabelfrom append map unlink link rename open watch watch_reads)))
13422(allow installd apk_data_file (lnk_file (ioctl read create getattr lock map unlink open watch watch_reads)))
13423(allow installd asec_apk_file (file (ioctl read getattr lock map open watch watch_reads)))
13424(allow installd apk_tmp_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
13425(allow installd apk_tmp_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
13426(allow installd oemfs (dir (ioctl read getattr lock open watch watch_reads search)))
13427(allow installd oemfs (file (ioctl read getattr lock map open watch watch_reads)))
13428(allow installd cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13429(allow installd cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13430(allow installd mnt_expand_file (dir (getattr search)))
13431(allow installd selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
13432(allow installd selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
13433(allow installd selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13434(allow installd selinuxfs (file (write lock append map open)))
13435(allow installd kernel (security (check_context)))
13436(allow installd rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
13437(allow installd rootfs (file (ioctl read getattr lock map open watch watch_reads)))
13438(allow installd rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13439(allow installd system_file (dir (ioctl read getattr lock open watch watch_reads search)))
13440(allow installd system_file (file (ioctl read getattr lock map open watch watch_reads)))
13441(allow installd system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13442(allow installd vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
13443(allow installd vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
13444(allow installd vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13445(allow installd vendor_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
13446(allow installd vendor_framework_file (file (ioctl read getattr lock map open watch watch_reads)))
13447(allow installd vendor_framework_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13448(allow installd vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
13449(allow installd vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
13450(allow installd vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13451(allow installd vendor_apex_metadata_file (dir (getattr search)))
13452(allow installd file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
13453(allow installd seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
13454(allow installd asec_image_file (dir (search)))
13455(allow installd asec_image_file (file (getattr)))
13456(allow installd system_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13457(allow installd system_data_file (lnk_file (read create getattr setattr unlink)))
13458(allow installd mnt_pass_through_file (dir (ioctl read getattr lock open watch watch_reads search)))
13459(allow installd media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13460(allow installd media_rw_data_file (file (getattr unlink)))
13461(allow installd system_data_file (dir (relabelfrom)))
13462(allow installd media_rw_data_file (dir (relabelto)))
13463(allow installd media_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
13464(allow installd tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
13465(allow installd storage_file (dir (search)))
13466(allow installd sdcard_type (dir (read write getattr open remove_name search rmdir)))
13467(allow installd fuse (dir (read write getattr open remove_name search rmdir)))
13468(allow installd sdcard_type (file (getattr unlink)))
13469(allow installd fuse (file (getattr unlink)))
13470(allow installd mirror_data_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
13471(allow installd system_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
13472(allow installd misc_user_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13473(allow installd misc_user_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13474(allow installd keychain_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13475(allow installd keychain_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
13476(allow installd install_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13477(allow installd install_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
13478(allow installd dalvikcache_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13479(allow installd dalvikcache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13480(allow installd dalvikcache_data_file (lnk_file (getattr)))
13481(allow installd resourcecache_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
13482(allow installd resourcecache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13483(allow installd unlabeled (dir (ioctl read write getattr lock relabelfrom open watch watch_reads add_name remove_name search rmdir)))
13484(allow installd unlabeled (file (getattr setattr relabelfrom unlink rename)))
13485(allow installd unlabeled (lnk_file (getattr setattr relabelfrom unlink rename)))
13486(allow installd unlabeled (sock_file (getattr setattr relabelfrom unlink rename)))
13487(allow installd unlabeled (fifo_file (getattr setattr relabelfrom unlink rename)))
13488(allow installd unlabeled (file (ioctl read getattr lock map open watch watch_reads)))
13489(allow installd system_data_file (file (getattr relabelfrom unlink)))
13490(allow installd system_data_file (lnk_file (getattr relabelfrom unlink)))
13491(allow installd system_data_file (sock_file (getattr relabelfrom unlink)))
13492(allow installd system_data_file (fifo_file (getattr relabelfrom unlink)))
13493(allow installd app_data_file_type (dir (ioctl read write create getattr setattr lock relabelfrom relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
13494(allow installd app_data_file_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink rename open watch watch_reads)))
13495(allow installd app_data_file_type (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink rename open watch watch_reads)))
13496(allow installd app_data_file_type (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink rename open watch watch_reads)))
13497(allow installd app_data_file_type (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink rename open watch watch_reads)))
13498(allowx installd app_data_file_type (ioctl file ((range 0x581f 0x5820))))
13499(allowx installd app_data_file_type (ioctl dir ((range 0x581f 0x5820))))
13500(allowx installd system_data_file (ioctl file ((range 0x581f 0x5820))))
13501(allowx installd system_data_file (ioctl dir ((range 0x581f 0x5820))))
13502(allowx installd install_data_file (ioctl file ((range 0x581f 0x5820))))
13503(allowx installd install_data_file (ioctl dir ((range 0x581f 0x5820))))
13504(allowx installd app_data_file_type (ioctl file ((range 0x6601 0x6602))))
13505(allowx installd app_data_file_type (ioctl dir ((range 0x6601 0x6602))))
13506(allowx installd system_data_file (ioctl file ((range 0x6601 0x6602))))
13507(allowx installd system_data_file (ioctl dir ((range 0x6601 0x6602))))
13508(allowx installd install_data_file (ioctl file ((range 0x6601 0x6602))))
13509(allowx installd install_data_file (ioctl dir ((range 0x6601 0x6602))))
13510(allow installd user_profile_root_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
13511(allow installd user_profile_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
13512(allow installd user_profile_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13513(allow installd user_profile_data_file (file (unlink)))
13514(allow installd labeledfs (filesystem (unmount)))
13515(allow installd profman_dump_data_file (dir (write add_name search)))
13516(allow installd profman_dump_data_file (file (write create setattr open)))
13517(allow installd devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
13518(allow installd toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
13519(allow installd servicemanager (binder (call transfer)))
13520(allow servicemanager installd (binder (call transfer)))
13521(allow servicemanager installd (dir (search)))
13522(allow servicemanager installd (file (read open)))
13523(allow servicemanager installd (process (getattr)))
13524(allow installd installd_service (service_manager (add find)))
13525;;* lmx 145 system/sepolicy/public/installd.te
13526
13527(neverallow base_typeattr_556 installd_service (service_manager (add)))
13528;;* lme
13529
13530(allow installd dumpstate (fifo_file (write getattr)))
13531(allow installd system_server (binder (call transfer)))
13532(allow system_server installd (binder (transfer)))
13533(allow installd system_server (fd (use)))
13534(allow installd permission_service (service_manager (find)))
13535(allow installd block_device (dir (search)))
13536(allow installd labeledfs (filesystem (quotamod quotaget)))
13537(allow installd preloads_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
13538(allow installd preloads_data_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search rmdir)))
13539(allow installd preloads_media_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
13540(allow installd preloads_media_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search rmdir)))
13541(allow installd proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
13542(allow installd storage_config_prop (file (read getattr map open)))
13543(allow installd vold (fd (use)))
13544;;* lmx 178 system/sepolicy/public/installd.te
13545
13546(neverallow base_typeattr_557 installd_service (service_manager (find)))
13547;;* lme
13548
13549;;* lmx 179 system/sepolicy/public/installd.te
13550
13551(neverallow base_typeattr_558 installd (binder (call)))
13552;;* lme
13553
13554;;* lmx 185 system/sepolicy/public/installd.te
13555
13556(neverallow installd base_typeattr_559 (binder (call)))
13557;;* lme
13558
13559(allow kernel self (capability (sys_nice)))
13560(allow kernel self (cap_userns (sys_nice)))
13561(allow kernel rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
13562(allow kernel rootfs (file (ioctl read getattr lock map open watch watch_reads)))
13563(allow kernel rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13564(allow kernel proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
13565(allow kernel proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
13566(allow kernel selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
13567(allow kernel selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
13568(allow kernel file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
13569(allow kernel rootfs (file (relabelfrom)))
13570(allow kernel init_exec (file (relabelto)))
13571(allow kernel init (process (share)))
13572(allow kernel unlabeled (dir (search)))
13573(allow kernel usbfs (filesystem (mount)))
13574(allow kernel usbfs (dir (search)))
13575(dontaudit kernel self (security (setenforce)))
13576(allow kernel self (capability (sys_resource)))
13577(allow kernel self (cap_userns (sys_resource)))
13578(allow kernel self (capability (sys_boot)))
13579(allow kernel self (cap_userns (sys_boot)))
13580(allow kernel proc_sysrq (file (write lock append map open)))
13581(allow kernel tmpfs (chr_file (write)))
13582(allow kernel selinuxfs (file (write)))
13583(allow kernel self (security (setcheckreqprot)))
13584(allow kernel sdcard_type (file (read write)))
13585(allow kernel fuse (file (read write)))
13586(allow kernel mediaprovider (fd (use)))
13587(allow kernel vold (fd (use)))
13588(allow kernel app_data_file (file (read)))
13589(allow kernel privapp_data_file (file (read)))
13590(allow kernel asec_image_file (file (read)))
13591(allow kernel media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13592(allow kernel media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13593(allow kernel vold_data_file (file (read write)))
13594(allow kernel apexd (fd (use)))
13595(allow kernel apex_data_file (file (read)))
13596(allow kernel staging_data_file (file (read)))
13597(allow kernel vendor_apex_file (file (read)))
13598(allow kernel system_file (file (execute)))
13599(allow kernel appdomain_tmpfs (file (read write)))
13600;;* lmx 128 system/sepolicy/public/kernel.te
13601
13602(neverallow base_typeattr_224 kernel (process (transition dyntransition)))
13603;;* lme
13604
13605;;* lmx 138 system/sepolicy/public/kernel.te
13606
13607(neverallow kernel base_typeattr_224 (file (execute_no_trans entrypoint)))
13608;;* lme
13609
13610;;* lmx 143 system/sepolicy/public/kernel.te
13611
13612(neverallow kernel self (capability (dac_override dac_read_search)))
13613(neverallow kernel self (cap_userns (dac_override dac_read_search)))
13614;;* lme
13615
13616;;* lmx 146 system/sepolicy/public/kernel.te
13617
13618(neverallow base_typeattr_224 kernel (process (ptrace)))
13619;;* lme
13620
13621(allow keystore servicemanager (binder (call transfer)))
13622(allow servicemanager keystore (binder (call transfer)))
13623(allow servicemanager keystore (dir (search)))
13624(allow servicemanager keystore (file (read open)))
13625(allow servicemanager keystore (process (getattr)))
13626(allow keystore remote_provisioning_service_server (binder (call transfer)))
13627(allow remote_provisioning_service_server keystore (binder (transfer)))
13628(allow keystore remote_provisioning_service_server (fd (use)))
13629(allow keystore system_server (binder (call transfer)))
13630(allow system_server keystore (binder (transfer)))
13631(allow keystore system_server (fd (use)))
13632(allow keystore wificond (binder (call transfer)))
13633(allow wificond keystore (binder (transfer)))
13634(allow keystore wificond (fd (use)))
13635(allow keystore keystore_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
13636(allow keystore keystore_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13637(allow keystore keystore_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13638(allow keystore keystore_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13639(allow keystore keystore_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
13640(allow keystore keystore_exec (file (getattr)))
13641(allow keystore keystore_service (service_manager (add find)))
13642;;* lmx 16 system/sepolicy/public/keystore.te
13643
13644(neverallow base_typeattr_560 keystore_service (service_manager (add)))
13645;;* lme
13646
13647(allow keystore sec_key_att_app_id_provider_service (service_manager (find)))
13648(allow keystore dropbox_service (service_manager (find)))
13649(allow keystore remote_provisioning_service (service_manager (find)))
13650(allow keystore apc_service (service_manager (add find)))
13651;;* lmx 20 system/sepolicy/public/keystore.te
13652
13653(neverallow base_typeattr_560 apc_service (service_manager (add)))
13654;;* lme
13655
13656(allow keystore keystore_compat_hal_service (service_manager (add find)))
13657;;* lmx 21 system/sepolicy/public/keystore.te
13658
13659(neverallow base_typeattr_560 keystore_compat_hal_service (service_manager (add)))
13660;;* lme
13661
13662(allow keystore authorization_service (service_manager (add find)))
13663;;* lmx 22 system/sepolicy/public/keystore.te
13664
13665(neverallow base_typeattr_560 authorization_service (service_manager (add)))
13666;;* lme
13667
13668(allow keystore keystore_maintenance_service (service_manager (add find)))
13669;;* lmx 23 system/sepolicy/public/keystore.te
13670
13671(neverallow base_typeattr_560 keystore_maintenance_service (service_manager (add)))
13672;;* lme
13673
13674(allow keystore keystore_metrics_service (service_manager (add find)))
13675;;* lmx 24 system/sepolicy/public/keystore.te
13676
13677(neverallow base_typeattr_560 keystore_metrics_service (service_manager (add)))
13678;;* lme
13679
13680(allow keystore legacykeystore_service (service_manager (add find)))
13681;;* lmx 25 system/sepolicy/public/keystore.te
13682
13683(neverallow base_typeattr_560 legacykeystore_service (service_manager (add)))
13684;;* lme
13685
13686(allow keystore selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
13687(allow keystore selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
13688(allow keystore selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13689(allow keystore selinuxfs (file (write lock append map open)))
13690(allow keystore kernel (security (compute_av)))
13691(allow keystore self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
13692(allow keystore cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
13693(allow keystore cgroup (file (ioctl read getattr lock map open watch watch_reads)))
13694(allow keystore cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13695(allow keystore cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
13696(allow keystore cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
13697(allow keystore cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13698;;* lmx 39 system/sepolicy/public/keystore.te
13699
13700(neverallow base_typeattr_560 keystore_data_file (dir (write lock relabelfrom append map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
13701;;* lme
13702
13703;;* lmx 40 system/sepolicy/public/keystore.te
13704
13705(neverallow base_typeattr_560 keystore_data_file (file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
13706(neverallow base_typeattr_560 keystore_data_file (lnk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13707(neverallow base_typeattr_560 keystore_data_file (sock_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13708(neverallow base_typeattr_560 keystore_data_file (fifo_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13709;;* lme
13710
13711;;* lmx 42 system/sepolicy/public/keystore.te
13712
13713(neverallow base_typeattr_561 keystore_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
13714;;* lme
13715
13716;;* lmx 43 system/sepolicy/public/keystore.te
13717
13718(neverallow base_typeattr_561 keystore_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
13719(neverallow base_typeattr_561 keystore_data_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13720(neverallow base_typeattr_561 keystore_data_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13721(neverallow base_typeattr_561 keystore_data_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
13722;;* lme
13723
13724;;* lmx 46 system/sepolicy/public/keystore.te
13725
13726(neverallow domain keystore (process (ptrace)))
13727;;* lme
13728
13729(allow keystore vendor_security_patch_level_prop (file (read getattr map open)))
13730(allow keystore keystore_config_prop (file (read getattr map open)))
13731(allow lmkd self (capability (dac_override dac_read_search kill sys_resource)))
13732(allow lmkd self (cap_userns (dac_override dac_read_search kill sys_resource)))
13733(allow lmkd self (capability (ipc_lock)))
13734(allow lmkd self (cap_userns (ipc_lock)))
13735(allow lmkd domain (dir (ioctl read getattr lock open watch watch_reads search)))
13736(allow lmkd domain (file (ioctl read getattr lock map open watch watch_reads)))
13737(allow lmkd domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13738(allow lmkd domain (file (write)))
13739(allow lmkd sysfs_lowmemorykiller (dir (ioctl read getattr lock open watch watch_reads search)))
13740(allow lmkd sysfs_lowmemorykiller (file (ioctl read getattr lock map open watch watch_reads)))
13741(allow lmkd sysfs_lowmemorykiller (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13742(allow lmkd sysfs_lowmemorykiller (file (write lock append map open)))
13743(allow lmkd domain (process (sigkill setsched)))
13744(allow lmkd kernel (process (setsched)))
13745(allow lmkd cgroup (dir (remove_name rmdir)))
13746(allow lmkd cgroup_v2 (dir (remove_name rmdir)))
13747(allow lmkd cgroup (file (ioctl read getattr lock map open watch watch_reads)))
13748(allow lmkd cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
13749(allow lmkd self (capability (sys_nice)))
13750(allow lmkd self (cap_userns (sys_nice)))
13751(allow lmkd proc_zoneinfo (file (ioctl read getattr lock map open watch watch_reads)))
13752(allow lmkd proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
13753(allow lmkd domain (dir (read open search)))
13754(allow lmkd domain (file (read open)))
13755(allow lmkd proc_sysrq (file (ioctl read write getattr lock append map open watch watch_reads)))
13756(allow lmkd proc_lowmemorykiller (file (ioctl read getattr lock map open watch watch_reads)))
13757(allow lmkd proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
13758(allow lmkd proc_pressure_cpu (file (ioctl read getattr lock map open watch watch_reads)))
13759(allow lmkd proc_pressure_io (file (ioctl read getattr lock map open watch watch_reads)))
13760(allow lmkd proc_pressure_mem (file (ioctl read write getattr lock append map open watch watch_reads)))
13761(allow lmkd lmkd_socket (sock_file (write)))
13762(allow lmkd statsdw_socket (sock_file (write)))
13763(allow lmkd statsd (unix_dgram_socket (sendto)))
13764;;* lmx 71 system/sepolicy/public/lmkd.te
13765
13766(neverallow base_typeattr_224 lmkd (process (noatsecure)))
13767;;* lme
13768
13769;;* lmx 72 system/sepolicy/public/lmkd.te
13770
13771(neverallow lmkd self (capability (sys_ptrace)))
13772(neverallow lmkd self (cap_userns (sys_ptrace)))
13773;;* lme
13774
13775(allow logd cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
13776(allow logd cgroup (file (ioctl read getattr lock map open watch watch_reads)))
13777(allow logd cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13778(allow logd cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
13779(allow logd cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
13780(allow logd cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13781(allow logd proc_kmsg (dir (ioctl read getattr lock open watch watch_reads search)))
13782(allow logd proc_kmsg (file (ioctl read getattr lock map open watch watch_reads)))
13783(allow logd proc_kmsg (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13784(allow logd proc_meminfo (dir (ioctl read getattr lock open watch watch_reads search)))
13785(allow logd proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
13786(allow logd proc_meminfo (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13787(allow logd self (capability (setgid setuid setpcap sys_nice audit_control)))
13788(allow logd self (cap_userns (setgid setuid setpcap sys_nice audit_control)))
13789(allow logd self (capability2 (syslog)))
13790(allow logd self (cap2_userns (syslog)))
13791(allow logd self (netlink_audit_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_write)))
13792(allow logd kernel (system (syslog_read)))
13793(allow logd kmsg_device (chr_file (write getattr lock append map open)))
13794(allow logd system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
13795(allow logd system_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13796(allow logd packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
13797(allow logd pstorefs (dir (search)))
13798(allow logd pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
13799(allow logd runtime_event_log_tags_file (file (ioctl read write getattr lock append map open watch watch_reads)))
13800(allow logd domain (dir (ioctl read getattr lock open watch watch_reads search)))
13801(allow logd domain (file (ioctl read getattr lock map open watch watch_reads)))
13802(allow logd domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13803(allow logd kernel (system (syslog_mod)))
13804(allow logd logd_socket (sock_file (write)))
13805(allow logd logd (unix_stream_socket (connectto)))
13806(allow logd runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
13807(allow runtime_event_log_tags_file tmpfs (filesystem (associate)))
13808(dontaudit domain runtime_event_log_tags_file (file (read map open)))
13809(allow logd property_socket (sock_file (write)))
13810(allow logd init (unix_stream_socket (connectto)))
13811(allow logd logd_prop (property_service (set)))
13812(allow logd logd_prop (file (read getattr map open)))
13813;;* lmx 51 system/sepolicy/public/logd.te
13814
13815(neverallow logd dev_type (blk_file (read write)))
13816;;* lme
13817
13818;;* lmx 54 system/sepolicy/public/logd.te
13819
13820(neverallow logd domain (process (ptrace)))
13821;;* lme
13822
13823;;* lmx 57 system/sepolicy/public/logd.te
13824
13825(neverallow domain logd (process (ptrace)))
13826;;* lme
13827
13828;;* lmx 60 system/sepolicy/public/logd.te
13829
13830(neverallow logd system_file_type (file (write)))
13831(neverallow logd system_file_type (dir (write)))
13832(neverallow logd system_file_type (lnk_file (write)))
13833(neverallow logd system_file_type (chr_file (write)))
13834(neverallow logd system_file_type (blk_file (write)))
13835(neverallow logd system_file_type (sock_file (write)))
13836(neverallow logd system_file_type (fifo_file (write)))
13837;;* lme
13838
13839;;* lmx 68 system/sepolicy/public/logd.te
13840
13841(neverallow logd base_typeattr_562 (file (write)))
13842(neverallow logd base_typeattr_562 (dir (write)))
13843(neverallow logd base_typeattr_562 (lnk_file (write)))
13844(neverallow logd base_typeattr_562 (chr_file (write)))
13845(neverallow logd base_typeattr_562 (blk_file (write)))
13846(neverallow logd base_typeattr_562 (sock_file (write)))
13847(neverallow logd base_typeattr_562 (fifo_file (write)))
13848;;* lme
13849
13850;;* lmx 71 system/sepolicy/public/logd.te
13851
13852(neverallow base_typeattr_223 logd (process (transition)))
13853;;* lme
13854
13855;;* lmx 72 system/sepolicy/public/logd.te
13856
13857(neverallow base_typeattr_224 logd (process (dyntransition)))
13858;;* lme
13859
13860;;* lmx 79 system/sepolicy/public/logd.te
13861
13862(neverallow base_typeattr_563 runtime_event_log_tags_file (file (write create setattr relabelfrom append unlink link rename)))
13863;;* lme
13864
13865(allow logpersist shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
13866(allow logpersist logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
13867;;* lmx 15 system/sepolicy/public/logpersist.te
13868
13869(neverallow logpersist dev_type (blk_file (read write)))
13870;;* lme
13871
13872;;* lmx 18 system/sepolicy/public/logpersist.te
13873
13874(neverallow logpersist domain (process (ptrace)))
13875;;* lme
13876
13877;;* lmx 21 system/sepolicy/public/logpersist.te
13878
13879(neverallow logpersist app_data_file_type (file (write)))
13880(neverallow logpersist app_data_file_type (dir (write)))
13881(neverallow logpersist app_data_file_type (lnk_file (write)))
13882(neverallow logpersist app_data_file_type (chr_file (write)))
13883(neverallow logpersist app_data_file_type (blk_file (write)))
13884(neverallow logpersist app_data_file_type (sock_file (write)))
13885(neverallow logpersist app_data_file_type (fifo_file (write)))
13886(neverallow logpersist system_data_file (file (write)))
13887(neverallow logpersist system_data_file (dir (write)))
13888(neverallow logpersist system_data_file (lnk_file (write)))
13889(neverallow logpersist system_data_file (chr_file (write)))
13890(neverallow logpersist system_data_file (blk_file (write)))
13891(neverallow logpersist system_data_file (sock_file (write)))
13892(neverallow logpersist system_data_file (fifo_file (write)))
13893;;* lme
13894
13895;;* lmx 31 system/sepolicy/public/logpersist.te
13896
13897(neverallow base_typeattr_224 logpersist (process (dyntransition)))
13898;;* lme
13899
13900(allowx logpersist misc_logd_file (ioctl file (0x6602)))
13901(allowx logpersist misc_logd_file (ioctl file (0xf512)))
13902(allow mediadrmserver servicemanager (binder (call transfer)))
13903(allow servicemanager mediadrmserver (binder (call transfer)))
13904(allow servicemanager mediadrmserver (dir (search)))
13905(allow servicemanager mediadrmserver (file (read open)))
13906(allow servicemanager mediadrmserver (process (getattr)))
13907(allow mediadrmserver binderservicedomain (binder (call transfer)))
13908(allow binderservicedomain mediadrmserver (binder (transfer)))
13909(allow mediadrmserver binderservicedomain (fd (use)))
13910(allow mediadrmserver appdomain (binder (call transfer)))
13911(allow appdomain mediadrmserver (binder (transfer)))
13912(allow mediadrmserver appdomain (fd (use)))
13913(allow mediadrmserver mediadrmserver_service (service_manager (add find)))
13914;;* lmx 14 system/sepolicy/public/mediadrmserver.te
13915
13916(neverallow base_typeattr_564 mediadrmserver_service (service_manager (add)))
13917;;* lme
13918
13919(allow mediadrmserver mediaserver_service (service_manager (find)))
13920(allow mediadrmserver mediametrics_service (service_manager (find)))
13921(allow mediadrmserver processinfo_service (service_manager (find)))
13922(allow mediadrmserver surfaceflinger_service (service_manager (find)))
13923(allow mediadrmserver system_file (dir (ioctl read getattr lock open watch watch_reads search)))
13924(allow mediadrmserver hal_omx_server (binder (call transfer)))
13925(allow hal_omx_server mediadrmserver (binder (transfer)))
13926(allow mediadrmserver hal_omx_server (fd (use)))
13927;;* lmx 30 system/sepolicy/public/mediadrmserver.te
13928
13929(neverallow mediadrmserver fs_type (file (execute_no_trans)))
13930(neverallow mediadrmserver file_type (file (execute_no_trans)))
13931;;* lme
13932
13933;;* lmx 33 system/sepolicy/public/mediadrmserver.te
13934
13935(neverallowx mediadrmserver domain (ioctl tcp_socket (0x6900 0x6902)))
13936(neverallowx mediadrmserver domain (ioctl udp_socket (0x6900 0x6902)))
13937(neverallowx mediadrmserver domain (ioctl rawip_socket (0x6900 0x6902)))
13938;;* lme
13939
13940;;* lmx 33 system/sepolicy/public/mediadrmserver.te
13941
13942(neverallowx mediadrmserver domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
13943(neverallowx mediadrmserver domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
13944(neverallowx mediadrmserver domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
13945;;* lme
13946
13947;;* lmx 33 system/sepolicy/public/mediadrmserver.te
13948
13949(neverallowx mediadrmserver domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
13950(neverallowx mediadrmserver domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
13951(neverallowx mediadrmserver domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
13952;;* lme
13953
13954(allow mediaextractor servicemanager (binder (call transfer)))
13955(allow servicemanager mediaextractor (binder (call transfer)))
13956(allow servicemanager mediaextractor (dir (search)))
13957(allow servicemanager mediaextractor (file (read open)))
13958(allow servicemanager mediaextractor (process (getattr)))
13959(allow mediaextractor binderservicedomain (binder (call transfer)))
13960(allow binderservicedomain mediaextractor (binder (transfer)))
13961(allow mediaextractor binderservicedomain (fd (use)))
13962(allow mediaextractor appdomain (binder (call transfer)))
13963(allow appdomain mediaextractor (binder (transfer)))
13964(allow mediaextractor appdomain (fd (use)))
13965(allow mediaextractor mediaextractor_service (service_manager (add find)))
13966;;* lmx 13 system/sepolicy/public/mediaextractor.te
13967
13968(neverallow base_typeattr_565 mediaextractor_service (service_manager (add)))
13969;;* lme
13970
13971(allow mediaextractor mediametrics_service (service_manager (find)))
13972(allow mediaextractor hidl_token_hwservice (hwservice_manager (find)))
13973(allow mediaextractor system_server (fd (use)))
13974(allow mediaextractor cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
13975(allow mediaextractor cgroup (file (ioctl read getattr lock map open watch watch_reads)))
13976(allow mediaextractor cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13977(allow mediaextractor cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
13978(allow mediaextractor cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
13979(allow mediaextractor cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
13980(allow mediaextractor proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
13981(allow mediaextractor anr_data_file (file (append)))
13982(allow mediaextractor dumpstate (fd (use)))
13983(allow mediaextractor incidentd (fd (use)))
13984(allow mediaextractor dumpstate (fifo_file (write append)))
13985(allow mediaextractor incidentd (fifo_file (write append)))
13986(allow mediaextractor system_server (fifo_file (write append)))
13987(allow mediaextractor tombstoned (unix_stream_socket (connectto)))
13988(allow mediaextractor tombstoned (fd (use)))
13989(allow mediaextractor tombstoned_crash_socket (sock_file (write)))
13990(allow mediaextractor tombstone_data_file (file (append)))
13991(allow mediaextractor sdcard_type (file (read getattr)))
13992(allow mediaextractor fuse (file (read getattr)))
13993(allow mediaextractor media_rw_data_file (file (read getattr)))
13994(allow mediaextractor app_data_file (file (read getattr)))
13995(allow mediaextractor privapp_data_file (file (read getattr)))
13996(allow mediaextractor apk_data_file (file (read getattr)))
13997(allow mediaextractor asec_apk_file (file (read getattr)))
13998(allow mediaextractor ringtone_file (file (read getattr)))
13999(allow mediaextractor vendor_overlay_file (file (read map)))
14000(allow mediaextractor system_file (dir (read open)))
14001;;* lmx 50 system/sepolicy/public/mediaextractor.te
14002
14003(neverallow mediaextractor fs_type (file (execute_no_trans)))
14004(neverallow mediaextractor file_type (file (execute_no_trans)))
14005;;* lme
14006
14007;;* lmx 62 system/sepolicy/public/mediaextractor.te
14008
14009(neverallow mediaextractor domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14010(neverallow mediaextractor domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14011;;* lme
14012
14013;;* lmx 63 system/sepolicy/public/mediaextractor.te
14014
14015(neverallow mediaextractor domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
14016;;* lme
14017
14018;;* lmx 72 system/sepolicy/public/mediaextractor.te
14019
14020(neverallow mediaextractor data_file_type (file (open)))
14021;;* lme
14022
14023(allow mediametrics servicemanager (binder (call transfer)))
14024(allow servicemanager mediametrics (binder (call transfer)))
14025(allow servicemanager mediametrics (dir (search)))
14026(allow servicemanager mediametrics (file (read open)))
14027(allow servicemanager mediametrics (process (getattr)))
14028(allow mediametrics binderservicedomain (binder (call transfer)))
14029(allow binderservicedomain mediametrics (binder (transfer)))
14030(allow mediametrics binderservicedomain (fd (use)))
14031(allow mediametrics mediametrics_service (service_manager (add find)))
14032;;* lmx 10 system/sepolicy/public/mediametrics.te
14033
14034(neverallow base_typeattr_566 mediametrics_service (service_manager (add)))
14035;;* lme
14036
14037(allow mediametrics system_server (fd (use)))
14038(allow mediametrics cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
14039(allow mediametrics cgroup (file (ioctl read getattr lock map open watch watch_reads)))
14040(allow mediametrics cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14041(allow mediametrics cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
14042(allow mediametrics cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
14043(allow mediametrics cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14044(allow mediametrics proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
14045(allow mediametrics app_data_file (file (write)))
14046(allow mediametrics privapp_data_file (file (write)))
14047(allow mediametrics package_native_service (service_manager (find)))
14048(allow mediametrics statsdw_socket (sock_file (write)))
14049(allow mediametrics statsd (unix_dgram_socket (sendto)))
14050;;* lmx 33 system/sepolicy/public/mediametrics.te
14051
14052(neverallow mediametrics fs_type (file (execute_no_trans)))
14053(neverallow mediametrics file_type (file (execute_no_trans)))
14054;;* lme
14055
14056;;* lmx 45 system/sepolicy/public/mediametrics.te
14057
14058(neverallow mediametrics domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14059(neverallow mediametrics domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14060;;* lme
14061
14062;;* lmx 46 system/sepolicy/public/mediametrics.te
14063
14064(neverallow mediametrics domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
14065;;* lme
14066
14067(allow mediaserver sdcard_type (dir (ioctl read getattr lock open watch watch_reads search)))
14068(allow mediaserver sdcard_type (file (ioctl read getattr lock map open watch watch_reads)))
14069(allow mediaserver sdcard_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14070(allow mediaserver fuse (dir (ioctl read getattr lock open watch watch_reads search)))
14071(allow mediaserver fuse (file (ioctl read getattr lock map open watch watch_reads)))
14072(allow mediaserver fuse (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14073(allow mediaserver cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
14074(allow mediaserver cgroup (file (ioctl read getattr lock map open watch watch_reads)))
14075(allow mediaserver cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14076(allow mediaserver cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
14077(allow mediaserver cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
14078(allow mediaserver cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14079(allow mediaserver proc (lnk_file (getattr)))
14080(allow mediaserver system_file (dir (ioctl read getattr lock open watch watch_reads search)))
14081(allow mediaserver servicemanager (binder (call transfer)))
14082(allow servicemanager mediaserver (binder (call transfer)))
14083(allow servicemanager mediaserver (dir (search)))
14084(allow servicemanager mediaserver (file (read open)))
14085(allow servicemanager mediaserver (process (getattr)))
14086(allow mediaserver binderservicedomain (binder (call transfer)))
14087(allow binderservicedomain mediaserver (binder (transfer)))
14088(allow mediaserver binderservicedomain (fd (use)))
14089(allow mediaserver appdomain (binder (call transfer)))
14090(allow appdomain mediaserver (binder (transfer)))
14091(allow mediaserver appdomain (fd (use)))
14092(allow mediaserver media_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
14093(allow mediaserver media_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
14094(allow mediaserver app_data_file (file (ioctl read write getattr lock append map)))
14095(allow mediaserver privapp_data_file (file (ioctl read write getattr lock append map)))
14096(allow mediaserver sdcard_type (file (write)))
14097(allow mediaserver fuse (file (write)))
14098(allow mediaserver gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14099(allow mediaserver gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
14100(allow mediaserver video_device (dir (ioctl read getattr lock open watch watch_reads search)))
14101(allow mediaserver video_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14102(allow mediaserver apk_data_file (file (read getattr)))
14103(allow mediaserver asec_apk_file (file (read getattr)))
14104(allow mediaserver ringtone_file (file (read getattr)))
14105(allow mediaserver radio_data_file (file (read getattr)))
14106(allow mediaserver appdomain (fifo_file (read write getattr)))
14107(allow mediaserver rpmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14108(allow mediaserver system_server (fifo_file (ioctl read getattr lock map open watch watch_reads)))
14109(allow mediaserver media_rw_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
14110(allow mediaserver media_rw_data_file (file (ioctl read getattr lock map open watch watch_reads)))
14111(allow mediaserver media_rw_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14112(allow mediaserver app_fuse_file (file (read getattr)))
14113(allow mediaserver drmserver_socket (sock_file (write)))
14114(allow mediaserver drmserver (unix_stream_socket (connectto)))
14115(allow mediaserver bluetooth_socket (sock_file (write)))
14116(allow mediaserver bluetooth (unix_stream_socket (connectto)))
14117(allow mediaserver statsdw_socket (sock_file (write)))
14118(allow mediaserver statsd (unix_dgram_socket (sendto)))
14119(allow mediaserver mediaserver_service (service_manager (add find)))
14120;;* lmx 72 system/sepolicy/public/mediaserver.te
14121
14122(neverallow base_typeattr_567 mediaserver_service (service_manager (add)))
14123;;* lme
14124
14125(allow mediaserver activity_service (service_manager (find)))
14126(allow mediaserver appops_service (service_manager (find)))
14127(allow mediaserver audio_service (service_manager (find)))
14128(allow mediaserver audioserver_service (service_manager (find)))
14129(allow mediaserver cameraserver_service (service_manager (find)))
14130(allow mediaserver batterystats_service (service_manager (find)))
14131(allow mediaserver drmserver_service (service_manager (find)))
14132(allow mediaserver mediaextractor_service (service_manager (find)))
14133(allow mediaserver mediametrics_service (service_manager (find)))
14134(allow mediaserver media_session_service (service_manager (find)))
14135(allow mediaserver package_native_service (service_manager (find)))
14136(allow mediaserver permission_service (service_manager (find)))
14137(allow mediaserver permission_checker_service (service_manager (find)))
14138(allow mediaserver power_service (service_manager (find)))
14139(allow mediaserver processinfo_service (service_manager (find)))
14140(allow mediaserver scheduling_policy_service (service_manager (find)))
14141(allow mediaserver surfaceflinger_service (service_manager (find)))
14142(allow mediaserver mediadrmserver_service (service_manager (find)))
14143(allow mediaserver hidl_token_hwservice (hwservice_manager (find)))
14144(allow mediaserver oemfs (dir (search)))
14145(allow mediaserver oemfs (file (ioctl read getattr lock map open watch watch_reads)))
14146(allow mediaserver bootanim_oem_file (file (ioctl read getattr lock map open watch watch_reads)))
14147(allow mediaserver vendor_app_file (file (read getattr map)))
14148(allow drmserver mediaserver (dir (search)))
14149(allow drmserver mediaserver (file (read open)))
14150(allow drmserver mediaserver (process (getattr)))
14151(allow mediaserver drmserver (drmservice (consumeRights setPlaybackStatus openDecryptSession closeDecryptSession initializeDecryptUnit decrypt finalizeDecryptUnit pread)))
14152(allowx mediaserver self (ioctl tcp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
14153(allowx mediaserver self (ioctl udp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
14154(allowx mediaserver self (ioctl rawip_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
14155(allowx mediaserver self (ioctl tcp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
14156(allowx mediaserver self (ioctl udp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
14157(allowx mediaserver self (ioctl rawip_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
14158(allowx mediaserver self (ioctl tcp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
14159(allowx mediaserver self (ioctl udp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
14160(allowx mediaserver self (ioctl rawip_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
14161(allow mediaserver media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
14162(allow mediaserver media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
14163(allow mediaserver preloads_media_file (file (ioctl read getattr)))
14164(allow mediaserver ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14165(allow mediaserver dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14166(allow mediaserver dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14167(allow mediaserver hal_graphics_allocator (fd (use)))
14168(allow mediaserver hal_graphics_composer (fd (use)))
14169(allow mediaserver hal_camera (fd (use)))
14170(allow mediaserver system_server (fd (use)))
14171(allow mediaserver vold (fd (use)))
14172(allow mediaserver vendor_overlay_file (file (read getattr map)))
14173;;* lmx 155 system/sepolicy/public/mediaserver.te
14174
14175(neverallow mediaserver fs_type (file (execute_no_trans)))
14176(neverallow mediaserver file_type (file (execute_no_trans)))
14177;;* lme
14178
14179;;* lmx 158 system/sepolicy/public/mediaserver.te
14180
14181(neverallowx mediaserver domain (ioctl tcp_socket (0x6900 0x6902)))
14182(neverallowx mediaserver domain (ioctl udp_socket (0x6900 0x6902)))
14183(neverallowx mediaserver domain (ioctl rawip_socket (0x6900 0x6902)))
14184;;* lme
14185
14186;;* lmx 158 system/sepolicy/public/mediaserver.te
14187
14188(neverallowx mediaserver domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
14189(neverallowx mediaserver domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
14190(neverallowx mediaserver domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
14191;;* lme
14192
14193;;* lmx 158 system/sepolicy/public/mediaserver.te
14194
14195(neverallowx mediaserver domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
14196(neverallowx mediaserver domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
14197(neverallowx mediaserver domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
14198;;* lme
14199
14200(allow mediaswcodec aac_drc_prop (file (read getattr map open)))
14201(allow mediaswcodec anr_data_file (file (append)))
14202(allow mediaswcodec dumpstate (fd (use)))
14203(allow mediaswcodec incidentd (fd (use)))
14204(allow mediaswcodec dumpstate (fifo_file (write append)))
14205(allow mediaswcodec incidentd (fifo_file (write append)))
14206(allow mediaswcodec system_server (fifo_file (write append)))
14207(allow mediaswcodec tombstoned (unix_stream_socket (connectto)))
14208(allow mediaswcodec tombstoned (fd (use)))
14209(allow mediaswcodec tombstoned_crash_socket (sock_file (write)))
14210(allow mediaswcodec tombstone_data_file (file (append)))
14211;;* lmx 21 system/sepolicy/public/mediaswcodec.te
14212
14213(neverallow mediaswcodec fs_type (file (execute_no_trans)))
14214(neverallow mediaswcodec file_type (file (execute_no_trans)))
14215;;* lme
14216
14217;;* lmx 27 system/sepolicy/public/mediaswcodec.te
14218
14219(neverallow mediaswcodec domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14220(neverallow mediaswcodec domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
14221;;* lme
14222
14223;;* lmx 28 system/sepolicy/public/mediaswcodec.te
14224
14225(neverallow mediaswcodec domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
14226;;* lme
14227
14228(allow mediaswcodec dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14229(allow mediaswcodec dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14230(allow mediaswcodec gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14231(allow mediaswcodec gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
14232(allow modprobe proc_modules (file (ioctl read getattr lock map open watch watch_reads)))
14233(allow modprobe proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
14234(allow modprobe self (capability (sys_module)))
14235(allow modprobe self (cap_userns (sys_module)))
14236(allow modprobe kernel (key (search)))
14237(allow modprobe system_dlkm_file (dir (search)))
14238(allow modprobe system_dlkm_file (file (ioctl read getattr lock map open watch watch_reads)))
14239(allow modprobe system_dlkm_file (system (module_load)))
14240(allow netdomain self (tcp_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
14241(allow netdomain self (udp_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14242(allow netdomain self (rawip_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14243(allow netdomain self (icmp_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14244(allow netdomain port_type (tcp_socket (name_connect)))
14245(allow netdomain self (netlink_route_socket (read write create getattr setattr lock append connect getopt setopt shutdown nlmsg_read)))
14246(allow netdomain dnsproxyd_socket (sock_file (write)))
14247(allow netdomain netd (unix_stream_socket (connectto)))
14248(allow netdomain fwmarkd_socket (sock_file (write)))
14249(allow netdomain netd (unix_stream_socket (connectto)))
14250(allow netd mdnsd_socket (sock_file (write)))
14251(allow netd mdnsd (unix_stream_socket (connectto)))
14252(allowx netd self (ioctl udp_socket (0x6900 0x6902)))
14253(allowx netd self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
14254(allowx netd self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
14255(allow netd cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
14256(allow netd cgroup (file (ioctl read getattr lock map open watch watch_reads)))
14257(allow netd cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14258(allow netd system_server (fd (use)))
14259(allow netd self (capability (kill net_admin net_raw)))
14260(allow netd self (cap_userns (kill net_admin net_raw)))
14261(dontaudit netd self (capability (fsetid)))
14262(dontaudit netd self (cap_userns (fsetid)))
14263(allow netd tun_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14264(allowx netd tun_device (ioctl chr_file (0x54ca 0x54d2)))
14265(allow netd self (tun_socket (create)))
14266(allow netd self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14267(allow netd self (netlink_route_socket (nlmsg_write)))
14268(allow netd self (netlink_nflog_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14269(allow netd self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14270(allow netd self (netlink_tcpdiag_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
14271(allow netd self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14272(allow netd self (netlink_netfilter_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
14273(allow netd shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
14274(allow netd system_file (file (getattr map execute execute_no_trans)))
14275(allow netd devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
14276(allow netd system_file (file (lock)))
14277(dontaudit netd system_file (dir (write)))
14278(allow netd proc_qtaguid_ctrl (file (ioctl read write getattr lock append map open watch watch_reads)))
14279(allow netd qtaguid_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
14280(allow netd proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
14281(allow netd proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
14282(allow netd proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14283(allow netd proc_net_type (file (ioctl read write getattr lock append map open watch watch_reads)))
14284(allow netd sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
14285(allow netd sysfs_net (dir (ioctl read getattr lock open watch watch_reads search)))
14286(allow netd sysfs_net (file (ioctl read getattr lock map open watch watch_reads)))
14287(allow netd sysfs_net (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14288(allow netd sysfs_net (file (write lock append map open)))
14289(allow netd sysfs_usb (file (write)))
14290(allow netd cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
14291(allow netd cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
14292(allow netd cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14293(allow netd self (capability (chown dac_override dac_read_search)))
14294(allow netd self (cap_userns (chown dac_override dac_read_search)))
14295(allow netd net_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
14296(allow netd net_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
14297(allow netd self (capability (fowner)))
14298(allow netd self (cap_userns (fowner)))
14299(allow netd system_file (file (lock)))
14300(allow netd dnsmasq (process (sigkill signal)))
14301(allow netd servicemanager (binder (call transfer)))
14302(allow servicemanager netd (binder (call transfer)))
14303(allow servicemanager netd (dir (search)))
14304(allow servicemanager netd (file (read open)))
14305(allow servicemanager netd (process (getattr)))
14306(allow netd netd_service (service_manager (add find)))
14307;;* lmx 87 system/sepolicy/public/netd.te
14308
14309(neverallow base_typeattr_568 netd_service (service_manager (add)))
14310;;* lme
14311
14312(allow netd dnsresolver_service (service_manager (add find)))
14313;;* lmx 88 system/sepolicy/public/netd.te
14314
14315(neverallow base_typeattr_568 dnsresolver_service (service_manager (add)))
14316;;* lme
14317
14318(allow netd mdns_service (service_manager (add find)))
14319;;* lmx 89 system/sepolicy/public/netd.te
14320
14321(neverallow base_typeattr_568 mdns_service (service_manager (add)))
14322;;* lme
14323
14324(allow netd dumpstate (fifo_file (write getattr)))
14325(allow netd system_server (binder (call)))
14326(allow netd permission_service (service_manager (find)))
14327(allow netd netd_listener_service (service_manager (find)))
14328(allow netd netdomain (tcp_socket (read write getattr setattr getopt setopt)))
14329(allow netd netdomain (udp_socket (read write getattr setattr getopt setopt)))
14330(allow netd netdomain (rawip_socket (read write getattr setattr getopt setopt)))
14331(allow netd netdomain (tun_socket (read write getattr setattr getopt setopt)))
14332(allow netd netdomain (icmp_socket (read write getattr setattr getopt setopt)))
14333(allow netd netdomain (fd (use)))
14334(allow netd self (netlink_xfrm_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
14335(allow netd system_net_netd_hwservice (hwservice_manager (add find)))
14336(allow netd hidl_base_hwservice (hwservice_manager (add)))
14337;;* lmx 113 system/sepolicy/public/netd.te
14338
14339(neverallow base_typeattr_568 system_net_netd_hwservice (hwservice_manager (add)))
14340;;* lme
14341
14342(allow netd hwservicemanager (binder (call transfer)))
14343(allow hwservicemanager netd (binder (call transfer)))
14344(allow hwservicemanager netd (dir (search)))
14345(allow hwservicemanager netd (file (read map open)))
14346(allow hwservicemanager netd (process (getattr)))
14347(allow system_net_netd_service servicemanager (binder (call transfer)))
14348(allow servicemanager system_net_netd_service (binder (transfer)))
14349(allow system_net_netd_service servicemanager (fd (use)))
14350(allow netd system_net_netd_service (service_manager (add find)))
14351;;* lmx 118 system/sepolicy/public/netd.te
14352
14353(neverallow base_typeattr_568 system_net_netd_service (service_manager (add)))
14354;;* lme
14355
14356;;* lmx 126 system/sepolicy/public/netd.te
14357
14358(neverallow netd dev_type (blk_file (read write)))
14359;;* lme
14360
14361;;* lmx 129 system/sepolicy/public/netd.te
14362
14363(neverallow netd domain (process (ptrace)))
14364;;* lme
14365
14366;;* lmx 132 system/sepolicy/public/netd.te
14367
14368(neverallow netd system_file_type (file (write)))
14369(neverallow netd system_file_type (dir (write)))
14370(neverallow netd system_file_type (lnk_file (write)))
14371(neverallow netd system_file_type (chr_file (write)))
14372(neverallow netd system_file_type (blk_file (write)))
14373(neverallow netd system_file_type (sock_file (write)))
14374(neverallow netd system_file_type (fifo_file (write)))
14375;;* lme
14376
14377;;* lmx 135 system/sepolicy/public/netd.te
14378
14379(neverallow netd app_data_file_type (file (write)))
14380(neverallow netd app_data_file_type (dir (write)))
14381(neverallow netd app_data_file_type (lnk_file (write)))
14382(neverallow netd app_data_file_type (chr_file (write)))
14383(neverallow netd app_data_file_type (blk_file (write)))
14384(neverallow netd app_data_file_type (sock_file (write)))
14385(neverallow netd app_data_file_type (fifo_file (write)))
14386(neverallow netd system_data_file (file (write)))
14387(neverallow netd system_data_file (dir (write)))
14388(neverallow netd system_data_file (lnk_file (write)))
14389(neverallow netd system_data_file (chr_file (write)))
14390(neverallow netd system_data_file (blk_file (write)))
14391(neverallow netd system_data_file (sock_file (write)))
14392(neverallow netd system_data_file (fifo_file (write)))
14393;;* lme
14394
14395;;* lmx 145 system/sepolicy/public/netd.te
14396
14397(neverallow base_typeattr_569 netd_service (service_manager (find)))
14398;;* lme
14399
14400;;* lmx 155 system/sepolicy/public/netd.te
14401
14402(neverallow base_typeattr_569 dnsresolver_service (service_manager (find)))
14403;;* lme
14404
14405;;* lmx 165 system/sepolicy/public/netd.te
14406
14407(neverallow base_typeattr_569 mdns_service (service_manager (find)))
14408;;* lme
14409
14410;;* lmx 168 system/sepolicy/public/netd.te
14411
14412(neverallow base_typeattr_231 netd (binder (call)))
14413;;* lme
14414
14415;;* lmx 169 system/sepolicy/public/netd.te
14416
14417(neverallow netd base_typeattr_231 (binder (call)))
14418;;* lme
14419
14420;;* lmx 174 system/sepolicy/public/netd.te
14421
14422(neverallow netd proc_net (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
14423;;* lme
14424
14425(dontaudit netd proc_net (dir (write)))
14426;;* lmx 177 system/sepolicy/public/netd.te
14427
14428(neverallow netd sysfs_net (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
14429;;* lme
14430
14431(dontaudit netd sysfs_net (dir (write)))
14432;;* lmx 181 system/sepolicy/public/netd.te
14433
14434(neverallow netd self (capability (sys_admin)))
14435;;* lme
14436
14437(dontaudit netd self (capability (sys_admin)))
14438(dontaudit netd self (capability (sys_module)))
14439(dontaudit netd appdomain (unix_stream_socket (read write)))
14440;;* lmx 5 system/sepolicy/public/netutils_wrapper.te
14441
14442(neverallow domain netutils_wrapper_exec (file (execute_no_trans)))
14443;;* lme
14444
14445(allow performanced servicemanager (binder (call transfer)))
14446(allow servicemanager performanced (binder (call transfer)))
14447(allow servicemanager performanced (dir (search)))
14448(allow servicemanager performanced (file (read open)))
14449(allow servicemanager performanced (process (getattr)))
14450(allow performanced system_server (binder (call transfer)))
14451(allow system_server performanced (binder (transfer)))
14452(allow performanced system_server (fd (use)))
14453(allow performanced permission_service (service_manager (find)))
14454(allow init pdx_performance_client_endpoint_socket_type (unix_stream_socket (create bind)))
14455(allow performanced pdx_performance_client_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
14456(allow performanced self (process (setsockcreate)))
14457(allow performanced pdx_performance_client_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
14458;;* lmx 10 system/sepolicy/public/performanced.te
14459
14460(neverallow base_typeattr_570 pdx_performance_client_endpoint_socket_type (unix_stream_socket (listen accept)))
14461;;* lme
14462
14463(allow performanced self (capability (setgid setuid sys_nice)))
14464(allow performanced self (cap_userns (setgid setuid sys_nice)))
14465(allow performanced appdomain (dir (ioctl read getattr lock open watch watch_reads search)))
14466(allow performanced bufferhubd (dir (ioctl read getattr lock open watch watch_reads search)))
14467(allow performanced kernel (dir (ioctl read getattr lock open watch watch_reads search)))
14468(allow performanced surfaceflinger (dir (ioctl read getattr lock open watch watch_reads search)))
14469(allow performanced appdomain (file (ioctl read getattr lock map open watch watch_reads)))
14470(allow performanced appdomain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14471(allow performanced bufferhubd (file (ioctl read getattr lock map open watch watch_reads)))
14472(allow performanced bufferhubd (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14473(allow performanced kernel (file (ioctl read getattr lock map open watch watch_reads)))
14474(allow performanced kernel (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14475(allow performanced surfaceflinger (file (ioctl read getattr lock map open watch watch_reads)))
14476(allow performanced surfaceflinger (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14477(dontaudit performanced domain (dir (read)))
14478(allow performanced appdomain (process (setsched)))
14479(allow performanced bufferhubd (process (setsched)))
14480(allow performanced kernel (process (setsched)))
14481(allow performanced surfaceflinger (process (setsched)))
14482(allow performanced cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
14483(allow performanced cgroup (file (ioctl read getattr lock map open watch watch_reads)))
14484(allow performanced cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14485(allow performanced cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
14486(allow performanced cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
14487(allow performanced cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14488(allow postinstall update_engine_common (fd (use)))
14489(allow postinstall update_engine_common (fifo_file (ioctl read write getattr lock append map open watch watch_reads)))
14490(allow postinstall postinstall_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
14491(allow postinstall postinstall_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
14492(allow postinstall postinstall_file (dir (ioctl read getattr lock open watch watch_reads search)))
14493(allow postinstall shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
14494(allow postinstall system_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
14495(allow postinstall toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
14496(allow postinstall servicemanager (binder (call transfer)))
14497(allow servicemanager postinstall (binder (call transfer)))
14498(allow servicemanager postinstall (dir (search)))
14499(allow servicemanager postinstall (file (read open)))
14500(allow servicemanager postinstall (process (getattr)))
14501(allow postinstall system_server (binder (call transfer)))
14502(allow system_server postinstall (binder (transfer)))
14503(allow postinstall system_server (fd (use)))
14504(allow postinstall otadexopt_service (service_manager (find)))
14505(allow postinstall sysfs_fs_f2fs (file (ioctl read write getattr lock append map open watch watch_reads)))
14506(allow postinstall sysfs_fs_f2fs (dir (ioctl read getattr lock open watch watch_reads search)))
14507;;* lmx 45 system/sepolicy/public/postinstall.te
14508
14509(neverallow base_typeattr_571 postinstall (process (transition dyntransition)))
14510;;* lme
14511
14512(allow profman user_profile_data_file (file (read write getattr lock map)))
14513(allow profman asec_apk_file (file (read map)))
14514(allow profman apk_data_file (file (read getattr map)))
14515(allow profman apk_data_file (dir (read getattr search)))
14516(allow profman oemfs (file (read map)))
14517(allow profman tmpfs (file (read map)))
14518(allow profman profman_dump_data_file (file (write map)))
14519(allow profman app_data_file (file (read write getattr lock map)))
14520(allow profman privapp_data_file (file (read write getattr lock map)))
14521(allow profman app_data_file (dir (read getattr search)))
14522(allow profman privapp_data_file (dir (read getattr search)))
14523(allow profman device_config_runtime_native_prop (file (read getattr map open)))
14524(allow profman device_config_runtime_native_boot_prop (file (read getattr map open)))
14525;;* lmx 31 system/sepolicy/public/profman.te
14526
14527(neverallow profman app_data_file_type (file (open)))
14528(neverallow profman app_data_file_type (lnk_file (open)))
14529(neverallow profman app_data_file_type (sock_file (open)))
14530(neverallow profman app_data_file_type (fifo_file (open)))
14531;;* lme
14532
14533;;* lmx 6 system/sepolicy/public/property.te
14534
14535(neverallow base_typeattr_250 apexd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14536;;* lme
14537
14538;;* lmx 7 system/sepolicy/public/property.te
14539
14540(neverallow base_typeattr_250 bootloader_boot_reason_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14541;;* lme
14542
14543;;* lmx 8 system/sepolicy/public/property.te
14544
14545(neverallow base_typeattr_250 device_config_activity_manager_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14546;;* lme
14547
14548;;* lmx 9 system/sepolicy/public/property.te
14549
14550(neverallow base_typeattr_250 device_config_boot_count_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14551;;* lme
14552
14553;;* lmx 10 system/sepolicy/public/property.te
14554
14555(neverallow base_typeattr_250 device_config_input_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14556;;* lme
14557
14558;;* lmx 11 system/sepolicy/public/property.te
14559
14560(neverallow base_typeattr_250 device_config_netd_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14561;;* lme
14562
14563;;* lmx 12 system/sepolicy/public/property.te
14564
14565(neverallow base_typeattr_250 device_config_reset_performed_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14566;;* lme
14567
14568;;* lmx 13 system/sepolicy/public/property.te
14569
14570(neverallow base_typeattr_250 firstboot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14571;;* lme
14572
14573;;* lmx 15 system/sepolicy/public/property.te
14574
14575(neverallow base_typeattr_250 boottime_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14576;;* lme
14577
14578;;* lmx 15 system/sepolicy/public/property.te
14579
14580(neverallow base_typeattr_250 charger_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14581;;* lme
14582
14583;;* lmx 15 system/sepolicy/public/property.te
14584
14585(neverallow base_typeattr_250 cold_boot_done_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14586;;* lme
14587
14588;;* lmx 15 system/sepolicy/public/property.te
14589
14590(neverallow base_typeattr_250 ctl_adbd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14591;;* lme
14592
14593;;* lmx 15 system/sepolicy/public/property.te
14594
14595(neverallow base_typeattr_250 ctl_apexd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14596;;* lme
14597
14598;;* lmx 15 system/sepolicy/public/property.te
14599
14600(neverallow base_typeattr_250 ctl_bootanim_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14601;;* lme
14602
14603;;* lmx 15 system/sepolicy/public/property.te
14604
14605(neverallow base_typeattr_250 ctl_bugreport_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14606;;* lme
14607
14608;;* lmx 15 system/sepolicy/public/property.te
14609
14610(neverallow base_typeattr_250 ctl_console_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14611;;* lme
14612
14613;;* lmx 15 system/sepolicy/public/property.te
14614
14615(neverallow base_typeattr_250 ctl_dumpstate_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14616;;* lme
14617
14618;;* lmx 15 system/sepolicy/public/property.te
14619
14620(neverallow base_typeattr_250 ctl_fuse_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14621;;* lme
14622
14623;;* lmx 15 system/sepolicy/public/property.te
14624
14625(neverallow base_typeattr_250 ctl_gsid_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14626;;* lme
14627
14628;;* lmx 15 system/sepolicy/public/property.te
14629
14630(neverallow base_typeattr_250 ctl_interface_restart_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14631;;* lme
14632
14633;;* lmx 15 system/sepolicy/public/property.te
14634
14635(neverallow base_typeattr_250 ctl_interface_stop_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14636;;* lme
14637
14638;;* lmx 15 system/sepolicy/public/property.te
14639
14640(neverallow base_typeattr_250 ctl_mdnsd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14641;;* lme
14642
14643;;* lmx 15 system/sepolicy/public/property.te
14644
14645(neverallow base_typeattr_250 ctl_restart_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14646;;* lme
14647
14648;;* lmx 15 system/sepolicy/public/property.te
14649
14650(neverallow base_typeattr_250 ctl_rildaemon_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14651;;* lme
14652
14653;;* lmx 15 system/sepolicy/public/property.te
14654
14655(neverallow base_typeattr_250 ctl_sigstop_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14656;;* lme
14657
14658;;* lmx 15 system/sepolicy/public/property.te
14659
14660(neverallow base_typeattr_250 dynamic_system_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14661;;* lme
14662
14663;;* lmx 15 system/sepolicy/public/property.te
14664
14665(neverallow base_typeattr_250 heapprofd_enabled_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14666;;* lme
14667
14668;;* lmx 15 system/sepolicy/public/property.te
14669
14670(neverallow base_typeattr_250 llkd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14671;;* lme
14672
14673;;* lmx 15 system/sepolicy/public/property.te
14674
14675(neverallow base_typeattr_250 lpdumpd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14676;;* lme
14677
14678;;* lmx 15 system/sepolicy/public/property.te
14679
14680(neverallow base_typeattr_250 mmc_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14681;;* lme
14682
14683;;* lmx 15 system/sepolicy/public/property.te
14684
14685(neverallow base_typeattr_250 mock_ota_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14686;;* lme
14687
14688;;* lmx 15 system/sepolicy/public/property.te
14689
14690(neverallow base_typeattr_250 net_dns_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14691;;* lme
14692
14693;;* lmx 15 system/sepolicy/public/property.te
14694
14695(neverallow base_typeattr_250 overlay_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14696;;* lme
14697
14698;;* lmx 15 system/sepolicy/public/property.te
14699
14700(neverallow base_typeattr_250 persistent_properties_ready_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14701;;* lme
14702
14703;;* lmx 15 system/sepolicy/public/property.te
14704
14705(neverallow base_typeattr_250 safemode_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14706;;* lme
14707
14708;;* lmx 15 system/sepolicy/public/property.te
14709
14710(neverallow base_typeattr_250 system_lmk_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14711;;* lme
14712
14713;;* lmx 15 system/sepolicy/public/property.te
14714
14715(neverallow base_typeattr_250 system_trace_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14716;;* lme
14717
14718;;* lmx 15 system/sepolicy/public/property.te
14719
14720(neverallow base_typeattr_250 test_boot_reason_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14721;;* lme
14722
14723;;* lmx 15 system/sepolicy/public/property.te
14724
14725(neverallow base_typeattr_250 time_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14726;;* lme
14727
14728;;* lmx 15 system/sepolicy/public/property.te
14729
14730(neverallow base_typeattr_250 traced_enabled_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14731;;* lme
14732
14733;;* lmx 15 system/sepolicy/public/property.te
14734
14735(neverallow base_typeattr_250 traced_lazy_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
14736;;* lme
14737
14738;;* lmx 53 system/sepolicy/public/property.te
14739
14740(neverallow base_typeattr_250 aac_drc_prop (property_service (set)))
14741;;* lme
14742
14743;;* lmx 54 system/sepolicy/public/property.te
14744
14745(neverallow base_typeattr_250 adaptive_haptics_prop (property_service (set)))
14746;;* lme
14747
14748;;* lmx 55 system/sepolicy/public/property.te
14749
14750(neverallow base_typeattr_250 apex_ready_prop (property_service (set)))
14751;;* lme
14752
14753;;* lmx 56 system/sepolicy/public/property.te
14754
14755(neverallow base_typeattr_250 arm64_memtag_prop (property_service (set)))
14756;;* lme
14757
14758;;* lmx 57 system/sepolicy/public/property.te
14759
14760(neverallow base_typeattr_250 binder_cache_bluetooth_server_prop (property_service (set)))
14761;;* lme
14762
14763;;* lmx 58 system/sepolicy/public/property.te
14764
14765(neverallow base_typeattr_250 binder_cache_system_server_prop (property_service (set)))
14766;;* lme
14767
14768;;* lmx 59 system/sepolicy/public/property.te
14769
14770(neverallow base_typeattr_250 binder_cache_telephony_server_prop (property_service (set)))
14771;;* lme
14772
14773;;* lmx 60 system/sepolicy/public/property.te
14774
14775(neverallow base_typeattr_250 boot_status_prop (property_service (set)))
14776;;* lme
14777
14778;;* lmx 61 system/sepolicy/public/property.te
14779
14780(neverallow base_typeattr_250 bootanim_system_prop (property_service (set)))
14781;;* lme
14782
14783;;* lmx 62 system/sepolicy/public/property.te
14784
14785(neverallow base_typeattr_250 bootloader_prop (property_service (set)))
14786;;* lme
14787
14788;;* lmx 63 system/sepolicy/public/property.te
14789
14790(neverallow base_typeattr_250 boottime_public_prop (property_service (set)))
14791;;* lme
14792
14793;;* lmx 64 system/sepolicy/public/property.te
14794
14795(neverallow base_typeattr_250 bq_config_prop (property_service (set)))
14796;;* lme
14797
14798;;* lmx 65 system/sepolicy/public/property.te
14799
14800(neverallow base_typeattr_250 build_bootimage_prop (property_service (set)))
14801;;* lme
14802
14803;;* lmx 66 system/sepolicy/public/property.te
14804
14805(neverallow base_typeattr_250 build_prop (property_service (set)))
14806;;* lme
14807
14808;;* lmx 67 system/sepolicy/public/property.te
14809
14810(neverallow base_typeattr_250 composd_vm_art_prop (property_service (set)))
14811;;* lme
14812
14813;;* lmx 68 system/sepolicy/public/property.te
14814
14815(neverallow base_typeattr_250 device_config_aconfig_flags_prop (property_service (set)))
14816;;* lme
14817
14818;;* lmx 69 system/sepolicy/public/property.te
14819
14820(neverallow base_typeattr_250 device_config_camera_native_prop (property_service (set)))
14821;;* lme
14822
14823;;* lmx 70 system/sepolicy/public/property.te
14824
14825(neverallow base_typeattr_250 device_config_edgetpu_native_prop (property_service (set)))
14826;;* lme
14827
14828;;* lmx 71 system/sepolicy/public/property.te
14829
14830(neverallow base_typeattr_250 device_config_media_native_prop (property_service (set)))
14831;;* lme
14832
14833;;* lmx 72 system/sepolicy/public/property.te
14834
14835(neverallow base_typeattr_250 device_config_nnapi_native_prop (property_service (set)))
14836;;* lme
14837
14838;;* lmx 73 system/sepolicy/public/property.te
14839
14840(neverallow base_typeattr_250 device_config_runtime_native_boot_prop (property_service (set)))
14841;;* lme
14842
14843;;* lmx 74 system/sepolicy/public/property.te
14844
14845(neverallow base_typeattr_250 device_config_runtime_native_prop (property_service (set)))
14846;;* lme
14847
14848;;* lmx 75 system/sepolicy/public/property.te
14849
14850(neverallow base_typeattr_250 device_config_surface_flinger_native_boot_prop (property_service (set)))
14851;;* lme
14852
14853;;* lmx 76 system/sepolicy/public/property.te
14854
14855(neverallow base_typeattr_250 device_config_vendor_system_native_prop (property_service (set)))
14856;;* lme
14857
14858;;* lmx 77 system/sepolicy/public/property.te
14859
14860(neverallow base_typeattr_250 device_config_vendor_system_native_boot_prop (property_service (set)))
14861;;* lme
14862
14863;;* lmx 78 system/sepolicy/public/property.te
14864
14865(neverallow base_typeattr_250 drm_forcel3_prop (property_service (set)))
14866;;* lme
14867
14868;;* lmx 79 system/sepolicy/public/property.te
14869
14870(neverallow base_typeattr_250 fingerprint_prop (property_service (set)))
14871;;* lme
14872
14873;;* lmx 80 system/sepolicy/public/property.te
14874
14875(neverallow base_typeattr_250 gwp_asan_prop (property_service (set)))
14876;;* lme
14877
14878;;* lmx 81 system/sepolicy/public/property.te
14879
14880(neverallow base_typeattr_250 hal_instrumentation_prop (property_service (set)))
14881;;* lme
14882
14883;;* lmx 82 system/sepolicy/public/property.te
14884
14885(neverallow base_typeattr_250 userdebug_or_eng_prop (property_service (set)))
14886;;* lme
14887
14888;;* lmx 83 system/sepolicy/public/property.te
14889
14890(neverallow base_typeattr_250 init_service_status_prop (property_service (set)))
14891;;* lme
14892
14893;;* lmx 84 system/sepolicy/public/property.te
14894
14895(neverallow base_typeattr_250 libc_debug_prop (property_service (set)))
14896;;* lme
14897
14898;;* lmx 85 system/sepolicy/public/property.te
14899
14900(neverallow base_typeattr_250 module_sdkextensions_prop (property_service (set)))
14901;;* lme
14902
14903;;* lmx 86 system/sepolicy/public/property.te
14904
14905(neverallow base_typeattr_250 nnapi_ext_deny_product_prop (property_service (set)))
14906;;* lme
14907
14908;;* lmx 87 system/sepolicy/public/property.te
14909
14910(neverallow base_typeattr_250 persist_wm_debug_prop (property_service (set)))
14911;;* lme
14912
14913;;* lmx 88 system/sepolicy/public/property.te
14914
14915(neverallow base_typeattr_250 power_debug_prop (property_service (set)))
14916;;* lme
14917
14918;;* lmx 89 system/sepolicy/public/property.te
14919
14920(neverallow base_typeattr_250 property_service_version_prop (property_service (set)))
14921;;* lme
14922
14923;;* lmx 90 system/sepolicy/public/property.te
14924
14925(neverallow base_typeattr_250 provisioned_prop (property_service (set)))
14926;;* lme
14927
14928;;* lmx 91 system/sepolicy/public/property.te
14929
14930(neverallow base_typeattr_250 restorecon_prop (property_service (set)))
14931;;* lme
14932
14933;;* lmx 92 system/sepolicy/public/property.te
14934
14935(neverallow base_typeattr_250 retaildemo_prop (property_service (set)))
14936;;* lme
14937
14938;;* lmx 93 system/sepolicy/public/property.te
14939
14940(neverallow base_typeattr_250 servicemanager_prop (property_service (set)))
14941;;* lme
14942
14943;;* lmx 94 system/sepolicy/public/property.te
14944
14945(neverallow base_typeattr_250 smart_idle_maint_enabled_prop (property_service (set)))
14946;;* lme
14947
14948;;* lmx 95 system/sepolicy/public/property.te
14949
14950(neverallow base_typeattr_250 socket_hook_prop (property_service (set)))
14951;;* lme
14952
14953;;* lmx 96 system/sepolicy/public/property.te
14954
14955(neverallow base_typeattr_250 sqlite_log_prop (property_service (set)))
14956;;* lme
14957
14958;;* lmx 97 system/sepolicy/public/property.te
14959
14960(neverallow base_typeattr_250 surfaceflinger_display_prop (property_service (set)))
14961;;* lme
14962
14963;;* lmx 98 system/sepolicy/public/property.te
14964
14965(neverallow base_typeattr_250 system_boot_reason_prop (property_service (set)))
14966;;* lme
14967
14968;;* lmx 99 system/sepolicy/public/property.te
14969
14970(neverallow base_typeattr_250 system_jvmti_agent_prop (property_service (set)))
14971;;* lme
14972
14973;;* lmx 100 system/sepolicy/public/property.te
14974
14975(neverallow base_typeattr_250 traced_oome_heap_session_count_prop (property_service (set)))
14976;;* lme
14977
14978;;* lmx 101 system/sepolicy/public/property.te
14979
14980(neverallow base_typeattr_250 ab_update_gki_prop (property_service (set)))
14981;;* lme
14982
14983;;* lmx 102 system/sepolicy/public/property.te
14984
14985(neverallow base_typeattr_250 usb_prop (property_service (set)))
14986;;* lme
14987
14988;;* lmx 103 system/sepolicy/public/property.te
14989
14990(neverallow base_typeattr_250 userspace_reboot_exported_prop (property_service (set)))
14991;;* lme
14992
14993;;* lmx 104 system/sepolicy/public/property.te
14994
14995(neverallow base_typeattr_250 vold_status_prop (property_service (set)))
14996;;* lme
14997
14998;;* lmx 105 system/sepolicy/public/property.te
14999
15000(neverallow base_typeattr_250 vts_status_prop (property_service (set)))
15001;;* lme
15002
15003;;* lmx 107 system/sepolicy/public/property.te
15004
15005(neverallow base_typeattr_250 config_prop (property_service (set)))
15006;;* lme
15007
15008;;* lmx 107 system/sepolicy/public/property.te
15009
15010(neverallow base_typeattr_250 cppreopt_prop (property_service (set)))
15011;;* lme
15012
15013;;* lmx 107 system/sepolicy/public/property.te
15014
15015(neverallow base_typeattr_250 dalvik_prop (property_service (set)))
15016;;* lme
15017
15018;;* lmx 107 system/sepolicy/public/property.te
15019
15020(neverallow base_typeattr_250 debuggerd_prop (property_service (set)))
15021;;* lme
15022
15023;;* lmx 107 system/sepolicy/public/property.te
15024
15025(neverallow base_typeattr_250 device_logging_prop (property_service (set)))
15026;;* lme
15027
15028;;* lmx 107 system/sepolicy/public/property.te
15029
15030(neverallow base_typeattr_250 dhcp_prop (property_service (set)))
15031;;* lme
15032
15033;;* lmx 107 system/sepolicy/public/property.te
15034
15035(neverallow base_typeattr_250 dumpstate_prop (property_service (set)))
15036;;* lme
15037
15038;;* lmx 107 system/sepolicy/public/property.te
15039
15040(neverallow base_typeattr_250 exported3_system_prop (property_service (set)))
15041;;* lme
15042
15043;;* lmx 107 system/sepolicy/public/property.te
15044
15045(neverallow base_typeattr_250 exported_dumpstate_prop (property_service (set)))
15046;;* lme
15047
15048;;* lmx 107 system/sepolicy/public/property.te
15049
15050(neverallow base_typeattr_250 exported_secure_prop (property_service (set)))
15051;;* lme
15052
15053;;* lmx 107 system/sepolicy/public/property.te
15054
15055(neverallow base_typeattr_250 heapprofd_prop (property_service (set)))
15056;;* lme
15057
15058;;* lmx 107 system/sepolicy/public/property.te
15059
15060(neverallow base_typeattr_250 net_radio_prop (property_service (set)))
15061;;* lme
15062
15063;;* lmx 107 system/sepolicy/public/property.te
15064
15065(neverallow base_typeattr_250 pan_result_prop (property_service (set)))
15066;;* lme
15067
15068;;* lmx 107 system/sepolicy/public/property.te
15069
15070(neverallow base_typeattr_250 persist_debug_prop (property_service (set)))
15071;;* lme
15072
15073;;* lmx 107 system/sepolicy/public/property.te
15074
15075(neverallow base_typeattr_250 shell_prop (property_service (set)))
15076;;* lme
15077
15078;;* lmx 107 system/sepolicy/public/property.te
15079
15080(neverallow base_typeattr_250 test_harness_prop (property_service (set)))
15081;;* lme
15082
15083;;* lmx 107 system/sepolicy/public/property.te
15084
15085(neverallow base_typeattr_250 theme_prop (property_service (set)))
15086;;* lme
15087
15088;;* lmx 107 system/sepolicy/public/property.te
15089
15090(neverallow base_typeattr_250 use_memfd_prop (property_service (set)))
15091;;* lme
15092
15093;;* lmx 107 system/sepolicy/public/property.te
15094
15095(neverallow base_typeattr_250 vold_prop (property_service (set)))
15096;;* lme
15097
15098(allow vendor_init property_socket (sock_file (write)))
15099(allow vendor_init init (unix_stream_socket (connectto)))
15100(allow vendor_init apexd_config_prop (property_service (set)))
15101(allow vendor_init apexd_config_prop (file (read getattr map open)))
15102;;* lmx 131 system/sepolicy/public/property.te
15103
15104(neverallow base_typeattr_259 apexd_config_prop (property_service (set)))
15105;;* lme
15106
15107(allow vendor_init property_socket (sock_file (write)))
15108(allow vendor_init init (unix_stream_socket (connectto)))
15109(allow vendor_init apexd_select_prop (property_service (set)))
15110(allow vendor_init apexd_select_prop (file (read getattr map open)))
15111;;* lmx 132 system/sepolicy/public/property.te
15112
15113(neverallow base_typeattr_259 apexd_select_prop (property_service (set)))
15114;;* lme
15115
15116(allow vendor_init property_socket (sock_file (write)))
15117(allow vendor_init init (unix_stream_socket (connectto)))
15118(allow vendor_init aaudio_config_prop (property_service (set)))
15119(allow vendor_init aaudio_config_prop (file (read getattr map open)))
15120;;* lmx 133 system/sepolicy/public/property.te
15121
15122(neverallow base_typeattr_259 aaudio_config_prop (property_service (set)))
15123;;* lme
15124
15125(allow vendor_init property_socket (sock_file (write)))
15126(allow vendor_init init (unix_stream_socket (connectto)))
15127(allow vendor_init apk_verity_prop (property_service (set)))
15128(allow vendor_init apk_verity_prop (file (read getattr map open)))
15129;;* lmx 134 system/sepolicy/public/property.te
15130
15131(neverallow base_typeattr_259 apk_verity_prop (property_service (set)))
15132;;* lme
15133
15134(allow vendor_init property_socket (sock_file (write)))
15135(allow vendor_init init (unix_stream_socket (connectto)))
15136(allow vendor_init audio_config_prop (property_service (set)))
15137(allow vendor_init audio_config_prop (file (read getattr map open)))
15138;;* lmx 135 system/sepolicy/public/property.te
15139
15140(neverallow base_typeattr_259 audio_config_prop (property_service (set)))
15141;;* lme
15142
15143(allow vendor_init property_socket (sock_file (write)))
15144(allow vendor_init init (unix_stream_socket (connectto)))
15145(allow vendor_init bootanim_config_prop (property_service (set)))
15146(allow vendor_init bootanim_config_prop (file (read getattr map open)))
15147;;* lmx 136 system/sepolicy/public/property.te
15148
15149(neverallow base_typeattr_259 bootanim_config_prop (property_service (set)))
15150;;* lme
15151
15152(allow vendor_init property_socket (sock_file (write)))
15153(allow vendor_init init (unix_stream_socket (connectto)))
15154(allow vendor_init bluetooth_config_prop (property_service (set)))
15155(allow vendor_init bluetooth_config_prop (file (read getattr map open)))
15156;;* lmx 137 system/sepolicy/public/property.te
15157
15158(neverallow base_typeattr_259 bluetooth_config_prop (property_service (set)))
15159;;* lme
15160
15161(allow vendor_init property_socket (sock_file (write)))
15162(allow vendor_init init (unix_stream_socket (connectto)))
15163(allow vendor_init build_attestation_prop (property_service (set)))
15164(allow vendor_init build_attestation_prop (file (read getattr map open)))
15165;;* lmx 138 system/sepolicy/public/property.te
15166
15167(neverallow base_typeattr_259 build_attestation_prop (property_service (set)))
15168;;* lme
15169
15170(allow vendor_init property_socket (sock_file (write)))
15171(allow vendor_init init (unix_stream_socket (connectto)))
15172(allow vendor_init build_config_prop (property_service (set)))
15173(allow vendor_init build_config_prop (file (read getattr map open)))
15174;;* lmx 139 system/sepolicy/public/property.te
15175
15176(neverallow base_typeattr_259 build_config_prop (property_service (set)))
15177;;* lme
15178
15179(allow vendor_init property_socket (sock_file (write)))
15180(allow vendor_init init (unix_stream_socket (connectto)))
15181(allow vendor_init build_odm_prop (property_service (set)))
15182(allow vendor_init build_odm_prop (file (read getattr map open)))
15183;;* lmx 140 system/sepolicy/public/property.te
15184
15185(neverallow base_typeattr_259 build_odm_prop (property_service (set)))
15186;;* lme
15187
15188(allow vendor_init property_socket (sock_file (write)))
15189(allow vendor_init init (unix_stream_socket (connectto)))
15190(allow vendor_init build_vendor_prop (property_service (set)))
15191(allow vendor_init build_vendor_prop (file (read getattr map open)))
15192;;* lmx 141 system/sepolicy/public/property.te
15193
15194(neverallow base_typeattr_259 build_vendor_prop (property_service (set)))
15195;;* lme
15196
15197(allow vendor_init property_socket (sock_file (write)))
15198(allow vendor_init init (unix_stream_socket (connectto)))
15199(allow vendor_init camera_calibration_prop (property_service (set)))
15200(allow vendor_init camera_calibration_prop (file (read getattr map open)))
15201;;* lmx 142 system/sepolicy/public/property.te
15202
15203(neverallow base_typeattr_259 camera_calibration_prop (property_service (set)))
15204;;* lme
15205
15206(allow vendor_init property_socket (sock_file (write)))
15207(allow vendor_init init (unix_stream_socket (connectto)))
15208(allow vendor_init camera_config_prop (property_service (set)))
15209(allow vendor_init camera_config_prop (file (read getattr map open)))
15210;;* lmx 143 system/sepolicy/public/property.te
15211
15212(neverallow base_typeattr_259 camera_config_prop (property_service (set)))
15213;;* lme
15214
15215(allow vendor_init property_socket (sock_file (write)))
15216(allow vendor_init init (unix_stream_socket (connectto)))
15217(allow vendor_init camera2_extensions_prop (property_service (set)))
15218(allow vendor_init camera2_extensions_prop (file (read getattr map open)))
15219;;* lmx 144 system/sepolicy/public/property.te
15220
15221(neverallow base_typeattr_259 camera2_extensions_prop (property_service (set)))
15222;;* lme
15223
15224(allow vendor_init property_socket (sock_file (write)))
15225(allow vendor_init init (unix_stream_socket (connectto)))
15226(allow vendor_init camerax_extensions_prop (property_service (set)))
15227(allow vendor_init camerax_extensions_prop (file (read getattr map open)))
15228;;* lmx 145 system/sepolicy/public/property.te
15229
15230(neverallow base_typeattr_259 camerax_extensions_prop (property_service (set)))
15231;;* lme
15232
15233(allow vendor_init property_socket (sock_file (write)))
15234(allow vendor_init init (unix_stream_socket (connectto)))
15235(allow vendor_init charger_config_prop (property_service (set)))
15236(allow vendor_init charger_config_prop (file (read getattr map open)))
15237;;* lmx 146 system/sepolicy/public/property.te
15238
15239(neverallow base_typeattr_259 charger_config_prop (property_service (set)))
15240;;* lme
15241
15242(allow vendor_init property_socket (sock_file (write)))
15243(allow vendor_init init (unix_stream_socket (connectto)))
15244(allow vendor_init codec2_config_prop (property_service (set)))
15245(allow vendor_init codec2_config_prop (file (read getattr map open)))
15246;;* lmx 147 system/sepolicy/public/property.te
15247
15248(neverallow base_typeattr_259 codec2_config_prop (property_service (set)))
15249;;* lme
15250
15251(allow vendor_init property_socket (sock_file (write)))
15252(allow vendor_init init (unix_stream_socket (connectto)))
15253(allow vendor_init composd_vm_vendor_prop (property_service (set)))
15254(allow vendor_init composd_vm_vendor_prop (file (read getattr map open)))
15255;;* lmx 148 system/sepolicy/public/property.te
15256
15257(neverallow base_typeattr_259 composd_vm_vendor_prop (property_service (set)))
15258;;* lme
15259
15260(allow vendor_init property_socket (sock_file (write)))
15261(allow vendor_init init (unix_stream_socket (connectto)))
15262(allow vendor_init cpu_variant_prop (property_service (set)))
15263(allow vendor_init cpu_variant_prop (file (read getattr map open)))
15264;;* lmx 149 system/sepolicy/public/property.te
15265
15266(neverallow base_typeattr_259 cpu_variant_prop (property_service (set)))
15267;;* lme
15268
15269(allow vendor_init property_socket (sock_file (write)))
15270(allow vendor_init init (unix_stream_socket (connectto)))
15271(allow vendor_init debugfs_restriction_prop (property_service (set)))
15272(allow vendor_init debugfs_restriction_prop (file (read getattr map open)))
15273;;* lmx 150 system/sepolicy/public/property.te
15274
15275(neverallow base_typeattr_259 debugfs_restriction_prop (property_service (set)))
15276;;* lme
15277
15278(allow vendor_init property_socket (sock_file (write)))
15279(allow vendor_init init (unix_stream_socket (connectto)))
15280(allow vendor_init drm_service_config_prop (property_service (set)))
15281(allow vendor_init drm_service_config_prop (file (read getattr map open)))
15282;;* lmx 151 system/sepolicy/public/property.te
15283
15284(neverallow base_typeattr_259 drm_service_config_prop (property_service (set)))
15285;;* lme
15286
15287(allow vendor_init property_socket (sock_file (write)))
15288(allow vendor_init init (unix_stream_socket (connectto)))
15289(allow vendor_init exported_camera_prop (property_service (set)))
15290(allow vendor_init exported_camera_prop (file (read getattr map open)))
15291;;* lmx 152 system/sepolicy/public/property.te
15292
15293(neverallow base_typeattr_259 exported_camera_prop (property_service (set)))
15294;;* lme
15295
15296(allow vendor_init property_socket (sock_file (write)))
15297(allow vendor_init init (unix_stream_socket (connectto)))
15298(allow vendor_init exported_config_prop (property_service (set)))
15299(allow vendor_init exported_config_prop (file (read getattr map open)))
15300;;* lmx 153 system/sepolicy/public/property.te
15301
15302(neverallow base_typeattr_259 exported_config_prop (property_service (set)))
15303;;* lme
15304
15305(allow vendor_init property_socket (sock_file (write)))
15306(allow vendor_init init (unix_stream_socket (connectto)))
15307(allow vendor_init exported_default_prop (property_service (set)))
15308(allow vendor_init exported_default_prop (file (read getattr map open)))
15309;;* lmx 154 system/sepolicy/public/property.te
15310
15311(neverallow base_typeattr_259 exported_default_prop (property_service (set)))
15312;;* lme
15313
15314(allow vendor_init property_socket (sock_file (write)))
15315(allow vendor_init init (unix_stream_socket (connectto)))
15316(allow vendor_init ffs_config_prop (property_service (set)))
15317(allow vendor_init ffs_config_prop (file (read getattr map open)))
15318;;* lmx 155 system/sepolicy/public/property.te
15319
15320(neverallow base_typeattr_259 ffs_config_prop (property_service (set)))
15321;;* lme
15322
15323(allow vendor_init property_socket (sock_file (write)))
15324(allow vendor_init init (unix_stream_socket (connectto)))
15325(allow vendor_init framework_watchdog_config_prop (property_service (set)))
15326(allow vendor_init framework_watchdog_config_prop (file (read getattr map open)))
15327;;* lmx 156 system/sepolicy/public/property.te
15328
15329(neverallow base_typeattr_259 framework_watchdog_config_prop (property_service (set)))
15330;;* lme
15331
15332(allow vendor_init property_socket (sock_file (write)))
15333(allow vendor_init init (unix_stream_socket (connectto)))
15334(allow vendor_init graphics_config_prop (property_service (set)))
15335(allow vendor_init graphics_config_prop (file (read getattr map open)))
15336;;* lmx 157 system/sepolicy/public/property.te
15337
15338(neverallow base_typeattr_259 graphics_config_prop (property_service (set)))
15339;;* lme
15340
15341(allow vendor_init property_socket (sock_file (write)))
15342(allow vendor_init init (unix_stream_socket (connectto)))
15343(allow vendor_init hdmi_config_prop (property_service (set)))
15344(allow vendor_init hdmi_config_prop (file (read getattr map open)))
15345;;* lmx 158 system/sepolicy/public/property.te
15346
15347(neverallow base_typeattr_259 hdmi_config_prop (property_service (set)))
15348;;* lme
15349
15350(allow vendor_init property_socket (sock_file (write)))
15351(allow vendor_init init (unix_stream_socket (connectto)))
15352(allow vendor_init hw_timeout_multiplier_prop (property_service (set)))
15353(allow vendor_init hw_timeout_multiplier_prop (file (read getattr map open)))
15354;;* lmx 159 system/sepolicy/public/property.te
15355
15356(neverallow base_typeattr_259 hw_timeout_multiplier_prop (property_service (set)))
15357;;* lme
15358
15359(allow vendor_init property_socket (sock_file (write)))
15360(allow vendor_init init (unix_stream_socket (connectto)))
15361(allow vendor_init hypervisor_prop (property_service (set)))
15362(allow vendor_init hypervisor_prop (file (read getattr map open)))
15363;;* lmx 160 system/sepolicy/public/property.te
15364
15365(neverallow base_typeattr_259 hypervisor_prop (property_service (set)))
15366;;* lme
15367
15368(allow vendor_init property_socket (sock_file (write)))
15369(allow vendor_init init (unix_stream_socket (connectto)))
15370(allow vendor_init hypervisor_restricted_prop (property_service (set)))
15371(allow vendor_init hypervisor_restricted_prop (file (read getattr map open)))
15372;;* lmx 161 system/sepolicy/public/property.te
15373
15374(neverallow base_typeattr_259 hypervisor_restricted_prop (property_service (set)))
15375;;* lme
15376
15377(allow vendor_init property_socket (sock_file (write)))
15378(allow vendor_init init (unix_stream_socket (connectto)))
15379(allow vendor_init incremental_prop (property_service (set)))
15380(allow vendor_init incremental_prop (file (read getattr map open)))
15381;;* lmx 162 system/sepolicy/public/property.te
15382
15383(neverallow base_typeattr_259 incremental_prop (property_service (set)))
15384;;* lme
15385
15386(allow vendor_init property_socket (sock_file (write)))
15387(allow vendor_init init (unix_stream_socket (connectto)))
15388(allow vendor_init input_device_config_prop (property_service (set)))
15389(allow vendor_init input_device_config_prop (file (read getattr map open)))
15390;;* lmx 163 system/sepolicy/public/property.te
15391
15392(neverallow base_typeattr_259 input_device_config_prop (property_service (set)))
15393;;* lme
15394
15395(allow vendor_init property_socket (sock_file (write)))
15396(allow vendor_init init (unix_stream_socket (connectto)))
15397(allow vendor_init keyguard_config_prop (property_service (set)))
15398(allow vendor_init keyguard_config_prop (file (read getattr map open)))
15399;;* lmx 164 system/sepolicy/public/property.te
15400
15401(neverallow base_typeattr_259 keyguard_config_prop (property_service (set)))
15402;;* lme
15403
15404(allow vendor_init property_socket (sock_file (write)))
15405(allow vendor_init init (unix_stream_socket (connectto)))
15406(allow vendor_init keystore_config_prop (property_service (set)))
15407(allow vendor_init keystore_config_prop (file (read getattr map open)))
15408;;* lmx 165 system/sepolicy/public/property.te
15409
15410(neverallow base_typeattr_259 keystore_config_prop (property_service (set)))
15411;;* lme
15412
15413(allow vendor_init property_socket (sock_file (write)))
15414(allow vendor_init init (unix_stream_socket (connectto)))
15415(allow vendor_init lmkd_config_prop (property_service (set)))
15416(allow vendor_init lmkd_config_prop (file (read getattr map open)))
15417;;* lmx 166 system/sepolicy/public/property.te
15418
15419(neverallow base_typeattr_259 lmkd_config_prop (property_service (set)))
15420;;* lme
15421
15422(allow vendor_init property_socket (sock_file (write)))
15423(allow vendor_init init (unix_stream_socket (connectto)))
15424(allow vendor_init media_config_prop (property_service (set)))
15425(allow vendor_init media_config_prop (file (read getattr map open)))
15426;;* lmx 167 system/sepolicy/public/property.te
15427
15428(neverallow base_typeattr_259 media_config_prop (property_service (set)))
15429;;* lme
15430
15431(allow vendor_init property_socket (sock_file (write)))
15432(allow vendor_init init (unix_stream_socket (connectto)))
15433(allow vendor_init media_variant_prop (property_service (set)))
15434(allow vendor_init media_variant_prop (file (read getattr map open)))
15435;;* lmx 168 system/sepolicy/public/property.te
15436
15437(neverallow base_typeattr_259 media_variant_prop (property_service (set)))
15438;;* lme
15439
15440(allow vendor_init property_socket (sock_file (write)))
15441(allow vendor_init init (unix_stream_socket (connectto)))
15442(allow vendor_init mediadrm_config_prop (property_service (set)))
15443(allow vendor_init mediadrm_config_prop (file (read getattr map open)))
15444;;* lmx 169 system/sepolicy/public/property.te
15445
15446(neverallow base_typeattr_259 mediadrm_config_prop (property_service (set)))
15447;;* lme
15448
15449(allow vendor_init property_socket (sock_file (write)))
15450(allow vendor_init init (unix_stream_socket (connectto)))
15451(allow vendor_init mm_events_config_prop (property_service (set)))
15452(allow vendor_init mm_events_config_prop (file (read getattr map open)))
15453;;* lmx 170 system/sepolicy/public/property.te
15454
15455(neverallow base_typeattr_259 mm_events_config_prop (property_service (set)))
15456;;* lme
15457
15458(allow vendor_init property_socket (sock_file (write)))
15459(allow vendor_init init (unix_stream_socket (connectto)))
15460(allow vendor_init oem_unlock_prop (property_service (set)))
15461(allow vendor_init oem_unlock_prop (file (read getattr map open)))
15462;;* lmx 171 system/sepolicy/public/property.te
15463
15464(neverallow base_typeattr_259 oem_unlock_prop (property_service (set)))
15465;;* lme
15466
15467(allow vendor_init property_socket (sock_file (write)))
15468(allow vendor_init init (unix_stream_socket (connectto)))
15469(allow vendor_init ota_build_prop (property_service (set)))
15470(allow vendor_init ota_build_prop (file (read getattr map open)))
15471;;* lmx 172 system/sepolicy/public/property.te
15472
15473(neverallow base_typeattr_259 ota_build_prop (property_service (set)))
15474;;* lme
15475
15476(allow vendor_init property_socket (sock_file (write)))
15477(allow vendor_init init (unix_stream_socket (connectto)))
15478(allow vendor_init packagemanager_config_prop (property_service (set)))
15479(allow vendor_init packagemanager_config_prop (file (read getattr map open)))
15480;;* lmx 173 system/sepolicy/public/property.te
15481
15482(neverallow base_typeattr_259 packagemanager_config_prop (property_service (set)))
15483;;* lme
15484
15485(allow vendor_init property_socket (sock_file (write)))
15486(allow vendor_init init (unix_stream_socket (connectto)))
15487(allow vendor_init quick_start_prop (property_service (set)))
15488(allow vendor_init quick_start_prop (file (read getattr map open)))
15489;;* lmx 174 system/sepolicy/public/property.te
15490
15491(neverallow base_typeattr_259 quick_start_prop (property_service (set)))
15492;;* lme
15493
15494(allow vendor_init property_socket (sock_file (write)))
15495(allow vendor_init init (unix_stream_socket (connectto)))
15496(allow vendor_init recovery_config_prop (property_service (set)))
15497(allow vendor_init recovery_config_prop (file (read getattr map open)))
15498;;* lmx 175 system/sepolicy/public/property.te
15499
15500(neverallow base_typeattr_259 recovery_config_prop (property_service (set)))
15501;;* lme
15502
15503(allow vendor_init property_socket (sock_file (write)))
15504(allow vendor_init init (unix_stream_socket (connectto)))
15505(allow vendor_init recovery_usb_config_prop (property_service (set)))
15506(allow vendor_init recovery_usb_config_prop (file (read getattr map open)))
15507;;* lmx 176 system/sepolicy/public/property.te
15508
15509(neverallow base_typeattr_259 recovery_usb_config_prop (property_service (set)))
15510;;* lme
15511
15512(allow vendor_init property_socket (sock_file (write)))
15513(allow vendor_init init (unix_stream_socket (connectto)))
15514(allow vendor_init sendbug_config_prop (property_service (set)))
15515(allow vendor_init sendbug_config_prop (file (read getattr map open)))
15516;;* lmx 177 system/sepolicy/public/property.te
15517
15518(neverallow base_typeattr_259 sendbug_config_prop (property_service (set)))
15519;;* lme
15520
15521(allow vendor_init property_socket (sock_file (write)))
15522(allow vendor_init init (unix_stream_socket (connectto)))
15523(allow vendor_init soc_prop (property_service (set)))
15524(allow vendor_init soc_prop (file (read getattr map open)))
15525;;* lmx 178 system/sepolicy/public/property.te
15526
15527(neverallow base_typeattr_259 soc_prop (property_service (set)))
15528;;* lme
15529
15530(allow vendor_init property_socket (sock_file (write)))
15531(allow vendor_init init (unix_stream_socket (connectto)))
15532(allow vendor_init storage_config_prop (property_service (set)))
15533(allow vendor_init storage_config_prop (file (read getattr map open)))
15534;;* lmx 179 system/sepolicy/public/property.te
15535
15536(neverallow base_typeattr_259 storage_config_prop (property_service (set)))
15537;;* lme
15538
15539(allow vendor_init property_socket (sock_file (write)))
15540(allow vendor_init init (unix_stream_socket (connectto)))
15541(allow vendor_init storagemanager_config_prop (property_service (set)))
15542(allow vendor_init storagemanager_config_prop (file (read getattr map open)))
15543;;* lmx 180 system/sepolicy/public/property.te
15544
15545(neverallow base_typeattr_259 storagemanager_config_prop (property_service (set)))
15546;;* lme
15547
15548(allow vendor_init property_socket (sock_file (write)))
15549(allow vendor_init init (unix_stream_socket (connectto)))
15550(allow vendor_init surfaceflinger_prop (property_service (set)))
15551(allow vendor_init surfaceflinger_prop (file (read getattr map open)))
15552;;* lmx 181 system/sepolicy/public/property.te
15553
15554(neverallow base_typeattr_259 surfaceflinger_prop (property_service (set)))
15555;;* lme
15556
15557(allow vendor_init property_socket (sock_file (write)))
15558(allow vendor_init init (unix_stream_socket (connectto)))
15559(allow vendor_init suspend_prop (property_service (set)))
15560(allow vendor_init suspend_prop (file (read getattr map open)))
15561;;* lmx 182 system/sepolicy/public/property.te
15562
15563(neverallow base_typeattr_259 suspend_prop (property_service (set)))
15564;;* lme
15565
15566(allow vendor_init property_socket (sock_file (write)))
15567(allow vendor_init init (unix_stream_socket (connectto)))
15568(allow vendor_init systemsound_config_prop (property_service (set)))
15569(allow vendor_init systemsound_config_prop (file (read getattr map open)))
15570;;* lmx 183 system/sepolicy/public/property.te
15571
15572(neverallow base_typeattr_259 systemsound_config_prop (property_service (set)))
15573;;* lme
15574
15575(allow vendor_init property_socket (sock_file (write)))
15576(allow vendor_init init (unix_stream_socket (connectto)))
15577(allow vendor_init telephony_config_prop (property_service (set)))
15578(allow vendor_init telephony_config_prop (file (read getattr map open)))
15579;;* lmx 184 system/sepolicy/public/property.te
15580
15581(neverallow base_typeattr_259 telephony_config_prop (property_service (set)))
15582;;* lme
15583
15584(allow vendor_init property_socket (sock_file (write)))
15585(allow vendor_init init (unix_stream_socket (connectto)))
15586(allow vendor_init threadnetwork_config_prop (property_service (set)))
15587(allow vendor_init threadnetwork_config_prop (file (read getattr map open)))
15588;;* lmx 185 system/sepolicy/public/property.te
15589
15590(neverallow base_typeattr_259 threadnetwork_config_prop (property_service (set)))
15591;;* lme
15592
15593(allow vendor_init property_socket (sock_file (write)))
15594(allow vendor_init init (unix_stream_socket (connectto)))
15595(allow vendor_init tombstone_config_prop (property_service (set)))
15596(allow vendor_init tombstone_config_prop (file (read getattr map open)))
15597;;* lmx 186 system/sepolicy/public/property.te
15598
15599(neverallow base_typeattr_259 tombstone_config_prop (property_service (set)))
15600;;* lme
15601
15602(allow vendor_init property_socket (sock_file (write)))
15603(allow vendor_init init (unix_stream_socket (connectto)))
15604(allow vendor_init usb_config_prop (property_service (set)))
15605(allow vendor_init usb_config_prop (file (read getattr map open)))
15606;;* lmx 187 system/sepolicy/public/property.te
15607
15608(neverallow base_typeattr_259 usb_config_prop (property_service (set)))
15609;;* lme
15610
15611(allow vendor_init property_socket (sock_file (write)))
15612(allow vendor_init init (unix_stream_socket (connectto)))
15613(allow vendor_init userspace_reboot_config_prop (property_service (set)))
15614(allow vendor_init userspace_reboot_config_prop (file (read getattr map open)))
15615;;* lmx 188 system/sepolicy/public/property.te
15616
15617(neverallow base_typeattr_259 userspace_reboot_config_prop (property_service (set)))
15618;;* lme
15619
15620(allow vendor_init property_socket (sock_file (write)))
15621(allow vendor_init init (unix_stream_socket (connectto)))
15622(allow vendor_init vehicle_hal_prop (property_service (set)))
15623(allow vendor_init vehicle_hal_prop (file (read getattr map open)))
15624;;* lmx 189 system/sepolicy/public/property.te
15625
15626(neverallow base_typeattr_259 vehicle_hal_prop (property_service (set)))
15627;;* lme
15628
15629(allow vendor_init property_socket (sock_file (write)))
15630(allow vendor_init init (unix_stream_socket (connectto)))
15631(allow vendor_init vendor_security_patch_level_prop (property_service (set)))
15632(allow vendor_init vendor_security_patch_level_prop (file (read getattr map open)))
15633;;* lmx 190 system/sepolicy/public/property.te
15634
15635(neverallow base_typeattr_259 vendor_security_patch_level_prop (property_service (set)))
15636;;* lme
15637
15638(allow vendor_init property_socket (sock_file (write)))
15639(allow vendor_init init (unix_stream_socket (connectto)))
15640(allow vendor_init vendor_socket_hook_prop (property_service (set)))
15641(allow vendor_init vendor_socket_hook_prop (file (read getattr map open)))
15642;;* lmx 191 system/sepolicy/public/property.te
15643
15644(neverallow base_typeattr_259 vendor_socket_hook_prop (property_service (set)))
15645;;* lme
15646
15647(allow vendor_init property_socket (sock_file (write)))
15648(allow vendor_init init (unix_stream_socket (connectto)))
15649(allow vendor_init virtual_ab_prop (property_service (set)))
15650(allow vendor_init virtual_ab_prop (file (read getattr map open)))
15651;;* lmx 192 system/sepolicy/public/property.te
15652
15653(neverallow base_typeattr_259 virtual_ab_prop (property_service (set)))
15654;;* lme
15655
15656(allow vendor_init property_socket (sock_file (write)))
15657(allow vendor_init init (unix_stream_socket (connectto)))
15658(allow vendor_init vndk_prop (property_service (set)))
15659(allow vendor_init vndk_prop (file (read getattr map open)))
15660;;* lmx 193 system/sepolicy/public/property.te
15661
15662(neverallow base_typeattr_259 vndk_prop (property_service (set)))
15663;;* lme
15664
15665(allow vendor_init property_socket (sock_file (write)))
15666(allow vendor_init init (unix_stream_socket (connectto)))
15667(allow vendor_init vts_config_prop (property_service (set)))
15668(allow vendor_init vts_config_prop (file (read getattr map open)))
15669;;* lmx 194 system/sepolicy/public/property.te
15670
15671(neverallow base_typeattr_259 vts_config_prop (property_service (set)))
15672;;* lme
15673
15674(allow vendor_init property_socket (sock_file (write)))
15675(allow vendor_init init (unix_stream_socket (connectto)))
15676(allow vendor_init vold_config_prop (property_service (set)))
15677(allow vendor_init vold_config_prop (file (read getattr map open)))
15678;;* lmx 195 system/sepolicy/public/property.te
15679
15680(neverallow base_typeattr_259 vold_config_prop (property_service (set)))
15681;;* lme
15682
15683(allow vendor_init property_socket (sock_file (write)))
15684(allow vendor_init init (unix_stream_socket (connectto)))
15685(allow vendor_init wifi_config_prop (property_service (set)))
15686(allow vendor_init wifi_config_prop (file (read getattr map open)))
15687;;* lmx 196 system/sepolicy/public/property.te
15688
15689(neverallow base_typeattr_259 wifi_config_prop (property_service (set)))
15690;;* lme
15691
15692(allow vendor_init property_socket (sock_file (write)))
15693(allow vendor_init init (unix_stream_socket (connectto)))
15694(allow vendor_init zram_config_prop (property_service (set)))
15695(allow vendor_init zram_config_prop (file (read getattr map open)))
15696;;* lmx 197 system/sepolicy/public/property.te
15697
15698(neverallow base_typeattr_259 zram_config_prop (property_service (set)))
15699;;* lme
15700
15701(allow vendor_init property_socket (sock_file (write)))
15702(allow vendor_init init (unix_stream_socket (connectto)))
15703(allow vendor_init zygote_config_prop (property_service (set)))
15704(allow vendor_init zygote_config_prop (file (read getattr map open)))
15705;;* lmx 198 system/sepolicy/public/property.te
15706
15707(neverallow base_typeattr_259 zygote_config_prop (property_service (set)))
15708;;* lme
15709
15710(allow vendor_init property_socket (sock_file (write)))
15711(allow vendor_init init (unix_stream_socket (connectto)))
15712(allow vendor_init dck_prop (property_service (set)))
15713(allow vendor_init dck_prop (file (read getattr map open)))
15714;;* lmx 199 system/sepolicy/public/property.te
15715
15716(neverallow base_typeattr_259 dck_prop (property_service (set)))
15717;;* lme
15718
15719(allow vendor_init property_socket (sock_file (write)))
15720(allow vendor_init init (unix_stream_socket (connectto)))
15721(allow vendor_init tuner_config_prop (property_service (set)))
15722(allow vendor_init tuner_config_prop (file (read getattr map open)))
15723;;* lmx 200 system/sepolicy/public/property.te
15724
15725(neverallow base_typeattr_259 tuner_config_prop (property_service (set)))
15726;;* lme
15727
15728(allow vendor_init property_socket (sock_file (write)))
15729(allow vendor_init init (unix_stream_socket (connectto)))
15730(allow vendor_init usb_uvc_enabled_prop (property_service (set)))
15731(allow vendor_init usb_uvc_enabled_prop (file (read getattr map open)))
15732;;* lmx 201 system/sepolicy/public/property.te
15733
15734(neverallow base_typeattr_259 usb_uvc_enabled_prop (property_service (set)))
15735;;* lme
15736
15737(allow vendor_init property_socket (sock_file (write)))
15738(allow vendor_init init (unix_stream_socket (connectto)))
15739(allow vendor_init setupwizard_mode_prop (property_service (set)))
15740(allow vendor_init setupwizard_mode_prop (file (read getattr map open)))
15741;;* lmx 202 system/sepolicy/public/property.te
15742
15743(neverallow base_typeattr_259 setupwizard_mode_prop (property_service (set)))
15744;;* lme
15745
15746(allow vendor_init property_socket (sock_file (write)))
15747(allow vendor_init init (unix_stream_socket (connectto)))
15748(allow vendor_init pm_archiving_enabled_prop (property_service (set)))
15749(allow vendor_init pm_archiving_enabled_prop (file (read getattr map open)))
15750;;* lmx 203 system/sepolicy/public/property.te
15751
15752(neverallow base_typeattr_259 pm_archiving_enabled_prop (property_service (set)))
15753;;* lme
15754
15755;;* lmx 265 system/sepolicy/public/property.te
15756
15757(neverallow base_typeattr_250 default_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
15758;;* lme
15759
15760;;* lmx 268 system/sepolicy/public/property.te
15761
15762(neverallow base_typeattr_572 rebootescrow_hal_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
15763;;* lme
15764
15765;;* lmx 271 system/sepolicy/public/property.te
15766
15767(neverallow base_typeattr_572 virtual_face_hal_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
15768;;* lme
15769
15770;;* lmx 274 system/sepolicy/public/property.te
15771
15772(neverallow base_typeattr_572 virtual_fingerprint_hal_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
15773;;* lme
15774
15775;;* lmx 341 system/sepolicy/public/property.te
15776
15777(neverallow base_typeattr_572 vendor_default_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
15778;;* lme
15779
15780(allow property_type tmpfs (filesystem (associate)))
15781(allow radio radio_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15782(allow radio radio_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15783(allow radio radio_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15784(allow radio radio_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15785(allow radio radio_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15786(allow radio radio_core_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
15787(allow radio radio_core_data_file (file (ioctl read getattr lock map open watch watch_reads)))
15788(allow radio net_data_file (dir (search)))
15789(allow radio net_data_file (file (ioctl read getattr lock map open watch watch_reads)))
15790(allow radio radio_service (service_manager (add find)))
15791;;* lmx 20 system/sepolicy/public/radio.te
15792
15793(neverallow base_typeattr_573 radio_service (service_manager (add)))
15794;;* lme
15795
15796(allow radio audioserver_service (service_manager (find)))
15797(allow radio cameraserver_service (service_manager (find)))
15798(allow radio drmserver_service (service_manager (find)))
15799(allow radio mediaserver_service (service_manager (find)))
15800(allow radio nfc_service (service_manager (find)))
15801(allow radio app_api_service (service_manager (find)))
15802(allow radio system_api_service (service_manager (find)))
15803(allow radio timedetector_service (service_manager (find)))
15804(allow radio timezonedetector_service (service_manager (find)))
15805(allow radio hwservicemanager (binder (call transfer)))
15806(allow hwservicemanager radio (binder (call transfer)))
15807(allow hwservicemanager radio (dir (search)))
15808(allow hwservicemanager radio (file (read map open)))
15809(allow hwservicemanager radio (process (getattr)))
15810(allow radio proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
15811;;* lmx 165 system/sepolicy/public/recovery.te
15812
15813(neverallow recovery base_typeattr_574 (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
15814;;* lme
15815
15816;;* lmx 171 system/sepolicy/public/recovery.te
15817
15818(neverallow recovery base_typeattr_574 (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
15819;;* lme
15820
15821(allow recovery_persist pstorefs (dir (search)))
15822(allow recovery_persist pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
15823(allow recovery_persist recovery_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15824(allow recovery_persist recovery_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15825(allow recovery_persist cache_file (dir (search)))
15826(allow recovery_persist cache_file (lnk_file (read)))
15827(allow recovery_persist cache_recovery_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
15828(allow recovery_persist cache_recovery_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
15829;;* lmx 23 system/sepolicy/public/recovery_persist.te
15830
15831(neverallow recovery_persist dev_type (blk_file (read write)))
15832;;* lme
15833
15834;;* lmx 26 system/sepolicy/public/recovery_persist.te
15835
15836(neverallow recovery_persist domain (process (ptrace)))
15837;;* lme
15838
15839;;* lmx 29 system/sepolicy/public/recovery_persist.te
15840
15841(neverallow recovery_persist system_file_type (file (write)))
15842(neverallow recovery_persist system_file_type (dir (write)))
15843(neverallow recovery_persist system_file_type (lnk_file (write)))
15844(neverallow recovery_persist system_file_type (chr_file (write)))
15845(neverallow recovery_persist system_file_type (blk_file (write)))
15846(neverallow recovery_persist system_file_type (sock_file (write)))
15847(neverallow recovery_persist system_file_type (fifo_file (write)))
15848;;* lme
15849
15850;;* lmx 32 system/sepolicy/public/recovery_persist.te
15851
15852(neverallow recovery_persist app_data_file_type (file (write)))
15853(neverallow recovery_persist app_data_file_type (dir (write)))
15854(neverallow recovery_persist app_data_file_type (lnk_file (write)))
15855(neverallow recovery_persist app_data_file_type (chr_file (write)))
15856(neverallow recovery_persist app_data_file_type (blk_file (write)))
15857(neverallow recovery_persist app_data_file_type (sock_file (write)))
15858(neverallow recovery_persist app_data_file_type (fifo_file (write)))
15859(neverallow recovery_persist system_data_file (file (write)))
15860(neverallow recovery_persist system_data_file (dir (write)))
15861(neverallow recovery_persist system_data_file (lnk_file (write)))
15862(neverallow recovery_persist system_data_file (chr_file (write)))
15863(neverallow recovery_persist system_data_file (blk_file (write)))
15864(neverallow recovery_persist system_data_file (sock_file (write)))
15865(neverallow recovery_persist system_data_file (fifo_file (write)))
15866;;* lme
15867
15868(allow recovery_refresh pstorefs (dir (search)))
15869(allow recovery_refresh pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
15870;;* lmx 16 system/sepolicy/public/recovery_refresh.te
15871
15872(neverallow recovery_refresh dev_type (blk_file (read write)))
15873;;* lme
15874
15875;;* lmx 19 system/sepolicy/public/recovery_refresh.te
15876
15877(neverallow recovery_refresh domain (process (ptrace)))
15878;;* lme
15879
15880;;* lmx 22 system/sepolicy/public/recovery_refresh.te
15881
15882(neverallow recovery_refresh system_file_type (file (write)))
15883(neverallow recovery_refresh system_file_type (dir (write)))
15884(neverallow recovery_refresh system_file_type (lnk_file (write)))
15885(neverallow recovery_refresh system_file_type (chr_file (write)))
15886(neverallow recovery_refresh system_file_type (blk_file (write)))
15887(neverallow recovery_refresh system_file_type (sock_file (write)))
15888(neverallow recovery_refresh system_file_type (fifo_file (write)))
15889;;* lme
15890
15891;;* lmx 25 system/sepolicy/public/recovery_refresh.te
15892
15893(neverallow recovery_refresh app_data_file_type (file (write)))
15894(neverallow recovery_refresh app_data_file_type (dir (write)))
15895(neverallow recovery_refresh app_data_file_type (lnk_file (write)))
15896(neverallow recovery_refresh app_data_file_type (chr_file (write)))
15897(neverallow recovery_refresh app_data_file_type (blk_file (write)))
15898(neverallow recovery_refresh app_data_file_type (sock_file (write)))
15899(neverallow recovery_refresh app_data_file_type (fifo_file (write)))
15900(neverallow recovery_refresh system_data_file (file (write)))
15901(neverallow recovery_refresh system_data_file (dir (write)))
15902(neverallow recovery_refresh system_data_file (lnk_file (write)))
15903(neverallow recovery_refresh system_data_file (chr_file (write)))
15904(neverallow recovery_refresh system_data_file (blk_file (write)))
15905(neverallow recovery_refresh system_data_file (sock_file (write)))
15906(neverallow recovery_refresh system_data_file (fifo_file (write)))
15907;;* lme
15908
15909(allow remote_provisioning_service_server remote_provisioning_service (service_manager (add find)))
15910;;* lmx 3 system/sepolicy/public/remote_provisioning_service_server.te
15911
15912(neverallow base_typeattr_575 remote_provisioning_service (service_manager (add)))
15913;;* lme
15914
15915(allow remote_provisioning_service_server servicemanager (binder (call transfer)))
15916(allow servicemanager remote_provisioning_service_server (binder (call transfer)))
15917(allow servicemanager remote_provisioning_service_server (dir (search)))
15918(allow servicemanager remote_provisioning_service_server (file (read open)))
15919(allow servicemanager remote_provisioning_service_server (process (getattr)))
15920(allow rootdisk_sysdev sysfs (filesystem (associate)))
15921(allow runas adbd (fd (use)))
15922(allow runas adbd (process (sigchld)))
15923(allow runas adbd (unix_stream_socket (read write)))
15924(allow runas shell (fd (use)))
15925(allow runas shell (fifo_file (read write)))
15926(allow runas shell (unix_stream_socket (read write)))
15927(allow runas devpts (chr_file (ioctl read write)))
15928(allow runas shell_data_file (file (read write)))
15929(allow runas system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
15930(allow runas system_data_file (lnk_file (getattr)))
15931(allow runas packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
15932(allow runas system_data_file (lnk_file (read)))
15933(dontaudit runas self (capability (dac_override dac_read_search)))
15934(dontaudit runas self (cap_userns (dac_override dac_read_search)))
15935(allow runas app_data_file (dir (getattr search)))
15936(allow runas self (capability (setgid setuid)))
15937(allow runas self (cap_userns (setgid setuid)))
15938(allow runas selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
15939(allow runas selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
15940(allow runas selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
15941(allow runas selinuxfs (file (write lock append map open)))
15942(allow runas kernel (security (check_context)))
15943(allow runas self (process (setcurrent)))
15944(allow runas base_typeattr_576 (process (dyntransition)))
15945(allow runas seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
15946;;* lmx 42 system/sepolicy/public/runas.te
15947
15948(neverallow runas self (capability (chown dac_override dac_read_search fowner fsetid kill setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
15949(neverallow runas self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
15950;;* lme
15951
15952;;* lmx 43 system/sepolicy/public/runas.te
15953
15954(neverallow runas self (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
15955(neverallow runas self (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
15956;;* lme
15957
15958(allow scheduler_service_server fwk_scheduler_hwservice (hwservice_manager (add find)))
15959(allow scheduler_service_server hidl_base_hwservice (hwservice_manager (add)))
15960;;* lmx 1 system/sepolicy/public/scheduler_service_server.te
15961
15962(neverallow base_typeattr_577 fwk_scheduler_hwservice (hwservice_manager (add)))
15963;;* lme
15964
15965(allow sdcardd cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15966(allow sdcardd cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15967(allow sdcardd fuse_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
15968(allow sdcardd rootfs (dir (mounton)))
15969(allow sdcardd sdcardfs (filesystem (remount)))
15970(allow sdcardd tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
15971(allow sdcardd mnt_media_rw_file (dir (ioctl read getattr lock open watch watch_reads search)))
15972(allow sdcardd storage_file (dir (search)))
15973(allow sdcardd storage_stub_file (dir (mounton search)))
15974(allow sdcardd sdcard_type (filesystem (mount unmount)))
15975(allow sdcardd fuse (filesystem (mount unmount)))
15976(allow sdcardd self (capability (dac_override dac_read_search setgid setuid sys_admin sys_resource)))
15977(allow sdcardd self (cap_userns (dac_override dac_read_search setgid setuid sys_admin sys_resource)))
15978(allow sdcardd sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15979(allow sdcardd fuse (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15980(allow sdcardd sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15981(allow sdcardd fuse (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15982(allow sdcardd media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
15983(allow sdcardd media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
15984(allow sdcardd system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
15985(allow sdcardd packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
15986(allow sdcardd install_data_file (file (ioctl read getattr lock map open watch watch_reads)))
15987(allow sdcardd install_data_file (dir (search)))
15988(allow sdcardd vold (fd (use)))
15989(allow sdcardd vold (fifo_file (read write getattr)))
15990(allow sdcardd mnt_expand_file (dir (search)))
15991(allow sdcardd proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
15992;;* lmx 46 system/sepolicy/public/sdcardd.te
15993
15994(neverallow init sdcardd_exec (file (execute)))
15995;;* lme
15996
15997;;* lmx 47 system/sepolicy/public/sdcardd.te
15998
15999(neverallow init sdcardd (process (transition dyntransition)))
16000;;* lme
16001
16002(allow sensor_service_server fwk_sensor_hwservice (hwservice_manager (add find)))
16003(allow sensor_service_server hidl_base_hwservice (hwservice_manager (add)))
16004;;* lmx 1 system/sepolicy/public/sensor_service_server.te
16005
16006(neverallow base_typeattr_578 fwk_sensor_hwservice (hwservice_manager (add)))
16007;;* lme
16008
16009;;* lmx 366 system/sepolicy/public/service.te
16010
16011(neverallow domain base_typeattr_579 (service_manager (add find)))
16012;;* lme
16013
16014(allow servicemanager self (binder (set_context_mgr)))
16015(allow servicemanager base_typeattr_580 (binder (transfer)))
16016(allow servicemanager service_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16017(allow servicemanager vendor_service_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16018(allow servicemanager service_manager_service (service_manager (add find)))
16019;;* lmx 27 system/sepolicy/public/servicemanager.te
16020
16021(neverallow base_typeattr_581 service_manager_service (service_manager (add)))
16022;;* lme
16023
16024(allow servicemanager dumpstate (fd (use)))
16025(allow servicemanager dumpstate (fifo_file (write)))
16026(allow servicemanager selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
16027(allow servicemanager selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
16028(allow servicemanager selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16029(allow servicemanager selinuxfs (file (write lock append map open)))
16030(allow servicemanager kernel (security (compute_av)))
16031(allow servicemanager self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
16032(allow servicemanager kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16033(allow sgdisk block_device (dir (search)))
16034(allow sgdisk vold_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16035(allowx sgdisk vold_device (ioctl blk_file (0x301)))
16036(allowx sgdisk vold_device (ioctl blk_file (0x1260)))
16037(allowx sgdisk vold_device (ioctl blk_file (0x125f)))
16038(allowx sgdisk vold_device (ioctl blk_file (0x127b)))
16039(allow sgdisk devpts (chr_file (ioctl read write getattr)))
16040(allow sgdisk vold (fd (use)))
16041(allow sgdisk vold (fifo_file (read write getattr)))
16042(allow sgdisk self (capability (sys_admin)))
16043(allow sgdisk self (cap_userns (sys_admin)))
16044;;* lmx 35 system/sepolicy/public/sgdisk.te
16045
16046(neverallow base_typeattr_339 sgdisk (process (transition)))
16047;;* lme
16048
16049;;* lmx 36 system/sepolicy/public/sgdisk.te
16050
16051(neverallow base_typeattr_224 sgdisk (process (dyntransition)))
16052;;* lme
16053
16054;;* lmx 37 system/sepolicy/public/sgdisk.te
16055
16056(neverallow sgdisk base_typeattr_582 (file (entrypoint)))
16057;;* lme
16058
16059(allow shell logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16060(allow shell logdr_socket (sock_file (write)))
16061(allow shell logd (unix_stream_socket (connectto)))
16062(allow shell logd_socket (sock_file (write)))
16063(allow shell logd (unix_stream_socket (connectto)))
16064(allow shell logd_prop (file (read getattr map open)))
16065(allow shell pstorefs (dir (search)))
16066(allow shell pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
16067(allow shell rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
16068(allow shell anr_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
16069(allow shell anr_data_file (file (ioctl read getattr lock map open watch watch_reads)))
16070(allow shell shell_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16071(allow shell shell_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16072(allow shell shell_data_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16073(allow shell shell_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16074(allow shell shell_test_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16075(allow shell shell_test_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16076(allow shell shell_test_data_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16077(allow shell shell_test_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16078(allow shell shell_test_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16079(allow shell trace_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
16080(allow shell trace_data_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search)))
16081(allow shell profman_dump_data_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search)))
16082(allow shell profman_dump_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
16083(allow shell dumpstate_socket (sock_file (write)))
16084(allow shell dumpstate (unix_stream_socket (connectto)))
16085(allow shell devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16086(allow shell tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16087(allow shell console_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16088(allow shell input_device (dir (ioctl read getattr lock open watch watch_reads search)))
16089(allow shell input_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
16090(allow shell system_file (dir (ioctl read getattr lock open watch watch_reads search)))
16091(allow shell system_file (file (ioctl read getattr lock map open watch watch_reads)))
16092(allow shell system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16093(allow shell system_file (file (getattr map execute execute_no_trans)))
16094(allow shell toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16095(allow shell shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16096(allow shell zygote_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16097(allow shell servicemanager (service_manager (list)))
16098(allow shell base_typeattr_583 (service_manager (find)))
16099(allow shell dumpstate (binder (call)))
16100(allow shell hwservicemanager (binder (call transfer)))
16101(allow hwservicemanager shell (binder (call transfer)))
16102(allow hwservicemanager shell (dir (search)))
16103(allow hwservicemanager shell (file (read map open)))
16104(allow hwservicemanager shell (process (getattr)))
16105(allow shell hwservicemanager (hwservice_manager (list)))
16106(allow shell proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
16107(allow shell proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
16108(allow shell proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16109(allow shell proc_asound (file (ioctl read getattr lock map open watch watch_reads)))
16110(allow shell proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
16111(allow shell proc_interrupts (file (ioctl read getattr lock map open watch watch_reads)))
16112(allow shell proc_loadavg (file (ioctl read getattr lock map open watch watch_reads)))
16113(allow shell proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
16114(allow shell proc_modules (file (ioctl read getattr lock map open watch watch_reads)))
16115(allow shell proc_pid_max (file (ioctl read getattr lock map open watch watch_reads)))
16116(allow shell proc_slabinfo (file (ioctl read getattr lock map open watch watch_reads)))
16117(allow shell proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
16118(allow shell proc_timer (file (ioctl read getattr lock map open watch watch_reads)))
16119(allow shell proc_uptime (file (ioctl read getattr lock map open watch watch_reads)))
16120(allow shell proc_version (file (ioctl read getattr lock map open watch watch_reads)))
16121(allow shell proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
16122(allow shell proc_zoneinfo (file (ioctl read getattr lock map open watch watch_reads)))
16123(allow shell sysfs_net (dir (ioctl read getattr lock open watch watch_reads search)))
16124(allow shell cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
16125(allow shell cgroup (file (ioctl read getattr lock map open watch watch_reads)))
16126(allow shell cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16127(allow shell cgroup_desc_file (file (ioctl read getattr lock map open watch watch_reads)))
16128(allow shell cgroup_desc_api_file (file (ioctl read getattr lock map open watch watch_reads)))
16129(allow shell vendor_cgroup_desc_file (file (ioctl read getattr lock map open watch watch_reads)))
16130(allow shell cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
16131(allow shell cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
16132(allow shell cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16133(allow shell domain (dir (read getattr open search)))
16134(allow shell domain (file (read getattr open)))
16135(allow shell domain (lnk_file (read getattr open)))
16136(allow shell labeledfs (filesystem (getattr)))
16137(allow shell proc (filesystem (getattr)))
16138(allow shell device (dir (getattr)))
16139(allow shell domain (process (getattr)))
16140(allow shell selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
16141(allow shell selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
16142(allow shell bootchart_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16143(allow shell bootchart_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16144(allow shell self (process (ptrace)))
16145(allow shell sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
16146(allow shell sysfs_batteryinfo (dir (ioctl read getattr lock open watch watch_reads search)))
16147(allow shell sysfs_batteryinfo (file (ioctl read getattr lock map open watch watch_reads)))
16148(allow shell ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16149(allow shell dev_type (dir (ioctl read getattr lock open watch watch_reads search)))
16150(allow shell dev_type (chr_file (getattr)))
16151(allow shell proc (lnk_file (getattr)))
16152(allow shell dev_type (blk_file (getattr)))
16153(allow shell file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16154(allow shell property_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16155(allow shell seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16156(allow shell service_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16157(allow shell sepolicy_file (file (ioctl read getattr lock map open watch watch_reads)))
16158(allow shell vendor_shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16159;;* lmx 206 system/sepolicy/public/shell.te
16160
16161(neverallow shell hal_keymint_service (service_manager (find)))
16162(neverallow shell hal_secureclock_service (service_manager (find)))
16163(neverallow shell hal_sharedsecret_service (service_manager (find)))
16164;;* lme
16165
16166;;* lmx 214 system/sepolicy/public/shell.te
16167
16168(neverallow shell file_type (file (link)))
16169;;* lme
16170
16171;;* lmx 217 system/sepolicy/public/shell.te
16172
16173(neverallowx shell domain (ioctl tcp_socket (0x6900 0x6902)))
16174(neverallowx shell domain (ioctl udp_socket (0x6900 0x6902)))
16175(neverallowx shell domain (ioctl rawip_socket (0x6900 0x6902)))
16176;;* lme
16177
16178;;* lmx 217 system/sepolicy/public/shell.te
16179
16180(neverallowx shell domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
16181(neverallowx shell domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
16182(neverallowx shell domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
16183;;* lme
16184
16185;;* lmx 217 system/sepolicy/public/shell.te
16186
16187(neverallowx shell domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
16188(neverallowx shell domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
16189(neverallowx shell domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
16190;;* lme
16191
16192;;* lmx 225 system/sepolicy/public/shell.te
16193
16194(neverallow shell hw_random_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16195(neverallow shell port_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16196(neverallow shell fuse_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16197;;* lme
16198
16199;;* lmx 228 system/sepolicy/public/shell.te
16200
16201(neverallow shell dev_type (blk_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
16202;;* lme
16203
16204;;* lmx 237 system/sepolicy/public/shell.te
16205
16206(neverallow shell input_device (chr_file (write create setattr relabelfrom append unlink link rename)))
16207;;* lme
16208
16209(allow slideshow kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16210(allow slideshow sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
16211(allow slideshow self (capability2 (block_suspend)))
16212(allow slideshow self (cap2_userns (block_suspend)))
16213(allow slideshow system_suspend_server (binder (call transfer)))
16214(allow system_suspend_server slideshow (binder (transfer)))
16215(allow slideshow system_suspend_server (fd (use)))
16216(allow slideshow system_suspend_hwservice (hwservice_manager (find)))
16217(allow slideshow hwservicemanager (binder (call transfer)))
16218(allow hwservicemanager slideshow (binder (call transfer)))
16219(allow hwservicemanager slideshow (dir (search)))
16220(allow hwservicemanager slideshow (file (read map open)))
16221(allow hwservicemanager slideshow (process (getattr)))
16222(allow slideshow hwservicemanager_prop (file (read getattr map open)))
16223(allow slideshow hidl_manager_hwservice (hwservice_manager (find)))
16224(allow slideshow hal_system_suspend_service (service_manager (find)))
16225(allow slideshow servicemanager (binder (call transfer)))
16226(allow servicemanager slideshow (binder (call transfer)))
16227(allow servicemanager slideshow (dir (search)))
16228(allow servicemanager slideshow (file (read open)))
16229(allow servicemanager slideshow (process (getattr)))
16230(allow slideshow device (dir (ioctl read getattr lock open watch watch_reads search)))
16231(allow slideshow self (capability (sys_tty_config)))
16232(allow slideshow self (cap_userns (sys_tty_config)))
16233(allow slideshow graphics_device (dir (ioctl read getattr lock open watch watch_reads search)))
16234(allow slideshow graphics_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16235(allow slideshow input_device (dir (ioctl read getattr lock open watch watch_reads search)))
16236(allow slideshow input_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
16237(allow slideshow tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16238(allow stats_service_server fwk_stats_hwservice (hwservice_manager (add find)))
16239(allow stats_service_server hidl_base_hwservice (hwservice_manager (add)))
16240;;* lmx 1 system/sepolicy/public/stats_service_server.te
16241
16242(neverallow base_typeattr_584 fwk_stats_hwservice (hwservice_manager (add)))
16243;;* lme
16244
16245(allow stats_service_server fwk_stats_service (service_manager (add find)))
16246;;* lmx 2 system/sepolicy/public/stats_service_server.te
16247
16248(neverallow base_typeattr_584 fwk_stats_service (service_manager (add)))
16249;;* lme
16250
16251(allow stats_service_server servicemanager (binder (call transfer)))
16252(allow servicemanager stats_service_server (binder (call transfer)))
16253(allow servicemanager stats_service_server (dir (search)))
16254(allow servicemanager stats_service_server (file (read open)))
16255(allow servicemanager stats_service_server (process (getattr)))
16256(allow statsd servicemanager (binder (call transfer)))
16257(allow servicemanager statsd (binder (call transfer)))
16258(allow servicemanager statsd (dir (search)))
16259(allow servicemanager statsd (file (read open)))
16260(allow servicemanager statsd (process (getattr)))
16261(allow statsd domain (dir (ioctl read getattr lock open watch watch_reads search)))
16262(allow statsd domain (file (ioctl read getattr lock map open watch watch_reads)))
16263(allow statsd domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16264(allow statsd devpts (chr_file (ioctl read write getattr)))
16265(allow statsd shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16266(allow statsd system_file (file (execute_no_trans)))
16267(allow statsd toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16268(allow statsd stats_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16269(allow statsd stats_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16270(allow statsd stats_config_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16271(allow statsd stats_config_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16272(allow statsd appdomain (binder (call transfer)))
16273(allow appdomain statsd (binder (transfer)))
16274(allow statsd appdomain (fd (use)))
16275(allow statsd incidentd (binder (call transfer)))
16276(allow incidentd statsd (binder (transfer)))
16277(allow statsd incidentd (fd (use)))
16278(allow statsd system_server (binder (call transfer)))
16279(allow system_server statsd (binder (transfer)))
16280(allow statsd system_server (fd (use)))
16281(allow statsd traced_probes (binder (call transfer)))
16282(allow traced_probes statsd (binder (transfer)))
16283(allow statsd traced_probes (fd (use)))
16284(allow statsd gpu_service (service_manager (find)))
16285(allow statsd gpuservice (binder (call transfer)))
16286(allow gpuservice statsd (binder (transfer)))
16287(allow statsd gpuservice (fd (use)))
16288(allow statsd keystore_service (service_manager (find)))
16289(allow statsd keystore (binder (call transfer)))
16290(allow keystore statsd (binder (transfer)))
16291(allow statsd keystore (fd (use)))
16292(allow statsd mediametrics_service (service_manager (find)))
16293(allow statsd mediametrics (binder (call transfer)))
16294(allow mediametrics statsd (binder (transfer)))
16295(allow statsd mediametrics (fd (use)))
16296(allow statsd mediaserver_service (service_manager (find)))
16297(allow statsd mediaserver (binder (call transfer)))
16298(allow mediaserver statsd (binder (transfer)))
16299(allow statsd mediaserver (fd (use)))
16300(allow statsd logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16301(allow statsd logdr_socket (sock_file (write)))
16302(allow statsd logd (unix_stream_socket (connectto)))
16303(allow statsd logd_socket (sock_file (write)))
16304(allow statsd logd (unix_stream_socket (connectto)))
16305(allow statsd app_api_service (service_manager (find)))
16306(allow statsd system_api_service (service_manager (find)))
16307(allow statsd incident_service (service_manager (find)))
16308(allow statsd hal_health_hwservice (hwservice_manager (find)))
16309(allow statsd dumpstate (fd (use)))
16310(allow statsd dumpstate (fifo_file (write getattr)))
16311(allow statsd proc_uid_cputime_showstat (file (read getattr open)))
16312(allow statsd adbd (fd (use)))
16313(allow statsd adbd (unix_stream_socket (read write getattr)))
16314(allow statsd shell (fifo_file (read write getattr)))
16315(allow statsd statsdw_socket (sock_file (write)))
16316(allow statsd statsd (unix_dgram_socket (sendto)))
16317;;* lmx 94 system/sepolicy/public/statsd.te
16318
16319(neverallow base_typeattr_585 stats_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16320;;* lme
16321
16322;;* lmx 95 system/sepolicy/public/statsd.te
16323
16324(neverallow base_typeattr_586 stats_config_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16325;;* lme
16326
16327;;* lmx 99 system/sepolicy/public/statsd.te
16328
16329(neverallow base_typeattr_585 stats_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
16330;;* lme
16331
16332;;* lmx 100 system/sepolicy/public/statsd.te
16333
16334(neverallow base_typeattr_586 stats_config_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
16335;;* lme
16336
16337(allow system_server power_debug_prop (file (read getattr map open)))
16338(allow system_server property_socket (sock_file (write)))
16339(allow system_server init (unix_stream_socket (connectto)))
16340(allow system_server power_debug_prop (property_service (set)))
16341(allow system_server power_debug_prop (file (read getattr map open)))
16342;;* lmx 18 system/sepolicy/public/system_server.te
16343
16344(neverallow base_typeattr_587 power_debug_prop (property_service (set)))
16345;;* lme
16346
16347(allow system_suspend_internal_server system_suspend_control_internal_service (service_manager (add find)))
16348;;* lmx 2 system/sepolicy/public/system_suspend_internal_server.te
16349
16350(neverallow base_typeattr_588 system_suspend_control_internal_service (service_manager (add)))
16351;;* lme
16352
16353;;* lmx 11 system/sepolicy/public/system_suspend_internal_server.te
16354
16355(neverallow base_typeattr_589 system_suspend_control_internal_service (service_manager (find)))
16356;;* lme
16357
16358(allow system_suspend_server hwservicemanager (binder (call transfer)))
16359(allow hwservicemanager system_suspend_server (binder (call transfer)))
16360(allow hwservicemanager system_suspend_server (dir (search)))
16361(allow hwservicemanager system_suspend_server (file (read map open)))
16362(allow hwservicemanager system_suspend_server (process (getattr)))
16363(allow system_suspend_server hwservicemanager_prop (file (read getattr map open)))
16364(allow system_suspend_server system_suspend_hwservice (hwservice_manager (add find)))
16365(allow system_suspend_server hidl_base_hwservice (hwservice_manager (add)))
16366;;* lmx 6 system/sepolicy/public/system_suspend_server.te
16367
16368(neverallow base_typeattr_590 system_suspend_hwservice (hwservice_manager (add)))
16369;;* lme
16370
16371(allow tee fingerprint_vendor_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16372(allow tee fingerprint_vendor_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16373(allow tombstoned domain (fd (use)))
16374(allow tombstoned domain (fifo_file (write)))
16375(allow tombstoned domain (dir (ioctl read getattr lock open watch watch_reads search)))
16376(allow tombstoned domain (file (ioctl read getattr lock map open watch watch_reads)))
16377(allow tombstoned tombstone_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16378(allow tombstoned tombstone_data_file (file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
16379(allow tombstoned anr_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16380(allow tombstoned anr_data_file (file (create getattr append unlink link open)))
16381(allow toolbox tmpfs (chr_file (ioctl read write)))
16382(allow toolbox devpts (chr_file (ioctl read write getattr)))
16383(allow toolbox block_device (dir (search)))
16384(allow toolbox swap_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16385;;* lmx 22 system/sepolicy/public/toolbox.te
16386
16387(neverallow base_typeattr_223 toolbox (process (transition)))
16388;;* lme
16389
16390;;* lmx 23 system/sepolicy/public/toolbox.te
16391
16392(neverallow base_typeattr_224 toolbox (process (dyntransition)))
16393;;* lme
16394
16395;;* lmx 24 system/sepolicy/public/toolbox.te
16396
16397(neverallow toolbox base_typeattr_591 (file (entrypoint)))
16398;;* lme
16399
16400(allow toolbox system_data_root_file (dir (write remove_name)))
16401(allow toolbox system_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search rmdir)))
16402(allow toolbox system_data_file (file (getattr unlink)))
16403(allow toolbox media_userdir_file (dir (ioctl read getattr setattr lock open watch watch_reads search)))
16404(allowx toolbox media_userdir_file (ioctl dir ((range 0x6601 0x6602))))
16405(allow traceur_app servicemanager (service_manager (list)))
16406(allow traceur_app hwservicemanager (hwservice_manager (list)))
16407(allow traceur_app base_typeattr_592 (service_manager (find)))
16408(dontaudit traceur_app service_manager_type (service_manager (find)))
16409(dontaudit traceur_app hwservice_manager_type (hwservice_manager (find)))
16410(dontaudit traceur_app domain (binder (call)))
16411(allow ueventd kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16412(allow ueventd self (capability (chown dac_override dac_read_search fowner fsetid setgid setuid net_admin sys_rawio mknod)))
16413(allow ueventd self (cap_userns (chown dac_override dac_read_search fowner fsetid setgid setuid net_admin sys_rawio mknod)))
16414(allow ueventd device (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16415(allow ueventd rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
16416(allow ueventd rootfs (file (ioctl read getattr lock map open watch watch_reads)))
16417(allow ueventd rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16418(allow ueventd sysfs_type (file (write lock append map open)))
16419(allow ueventd sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
16420(allow ueventd sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
16421(allow ueventd sysfs_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16422(allow ueventd sysfs_type (file (setattr relabelfrom relabelto)))
16423(allow ueventd sysfs_type (lnk_file (setattr relabelfrom relabelto)))
16424(allow ueventd sysfs_type (dir (setattr relabelfrom relabelto)))
16425(allow ueventd tmpfs (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16426(allow ueventd dev_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16427(allow ueventd dev_type (lnk_file (create unlink)))
16428(allow ueventd dev_type (chr_file (create getattr setattr unlink)))
16429(allow ueventd dev_type (blk_file (create getattr setattr relabelfrom relabelto unlink)))
16430(allow ueventd self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
16431(allow ueventd efs_file (dir (search)))
16432(allow ueventd efs_file (file (ioctl read getattr lock map open watch watch_reads)))
16433(allow ueventd selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
16434(allow ueventd selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
16435(allow ueventd selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16436(allow ueventd base_typeattr_593 (dir (ioctl read getattr lock open watch watch_reads search)))
16437(allow ueventd base_typeattr_593 (file (ioctl read getattr lock map open watch watch_reads)))
16438(allow ueventd base_typeattr_593 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16439(allow ueventd apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
16440(allow ueventd file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16441(allow ueventd self (process (setfscreate)))
16442(allow ueventd proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
16443(allow ueventd proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
16444(dontaudit ueventd postinstall_mnt_dir (dir (getattr)))
16445(allow ueventd self (capability (sys_module)))
16446(allow ueventd self (cap_userns (sys_module)))
16447(allow ueventd vendor_file (system (module_load)))
16448(allow ueventd kernel (key (search)))
16449(allow ueventd system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
16450(allow ueventd system_bootstrap_lib_file (file (read getattr map execute open)))
16451(allow ueventd vendor_shell_exec (file (execute)))
16452(allow ueventd dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16453(allow ueventd self (capability (sys_admin)))
16454(allow ueventd apexd_prop (file (read getattr map open)))
16455;;* lmx 80 system/sepolicy/public/ueventd.te
16456
16457(neverallow ueventd dev_type (blk_file (ioctl read write lock append map link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
16458;;* lme
16459
16460;;* lmx 83 system/sepolicy/public/ueventd.te
16461
16462(neverallow ueventd port_device (chr_file (ioctl read write lock relabelfrom append map link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
16463;;* lme
16464
16465;;* lmx 86 system/sepolicy/public/ueventd.te
16466
16467(neverallow base_typeattr_224 ueventd (process (ptrace)))
16468;;* lme
16469
16470;;* lmx 89 system/sepolicy/public/ueventd.te
16471
16472(neverallow ueventd fs_type (file (execute_no_trans)))
16473(neverallow ueventd file_type (file (execute_no_trans)))
16474;;* lme
16475
16476(allow uncrypt self (capability (dac_override dac_read_search)))
16477(allow uncrypt self (cap_userns (dac_override dac_read_search)))
16478(allow uncrypt cache_file (dir (search)))
16479(allow uncrypt cache_recovery_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16480(allow uncrypt cache_recovery_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16481(allow uncrypt ota_package_file (dir (ioctl read getattr lock open watch watch_reads search)))
16482(allow uncrypt ota_package_file (file (ioctl read write getattr lock append map open watch watch_reads)))
16483(allow uncrypt uncrypt_socket (sock_file (write)))
16484(allow uncrypt uncrypt (unix_stream_socket (connectto)))
16485(allow uncrypt self (capability (sys_rawio)))
16486(allow uncrypt self (cap_userns (sys_rawio)))
16487(allow uncrypt misc_block_device (blk_file (write lock append map open)))
16488(allow uncrypt block_device (dir (ioctl read getattr lock open watch watch_reads search)))
16489(allow uncrypt userdata_block_device (blk_file (write lock append map open)))
16490(allow uncrypt rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
16491(allow uncrypt rootfs (file (ioctl read getattr lock map open watch watch_reads)))
16492(allow uncrypt rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16493(allow uncrypt proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
16494(allow uncrypt proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
16495(allow uncrypt sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
16496(allow uncrypt sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
16497(allow uncrypt sysfs_dt_firmware_android (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16498(allow uncrypt gsi_metadata_file_type (dir (search)))
16499(allow uncrypt metadata_file (dir (search)))
16500(allow uncrypt gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
16501(allow uncrypt proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
16502(allow uncrypt proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
16503(allow update_engine self (process (setsched)))
16504(allow update_engine self (capability (fowner sys_admin)))
16505(allow update_engine self (cap_userns (fowner sys_admin)))
16506(dontaudit update_engine self (capability (fsetid)))
16507(dontaudit update_engine self (cap_userns (fsetid)))
16508(allow update_engine kmsg_device (chr_file (write getattr lock append map open)))
16509(allow update_engine update_engine_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16510(allow update_engine sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
16511(allow update_engine self (capability2 (block_suspend)))
16512(allow update_engine self (cap2_userns (block_suspend)))
16513(allow update_engine system_suspend_server (binder (call transfer)))
16514(allow system_suspend_server update_engine (binder (transfer)))
16515(allow update_engine system_suspend_server (fd (use)))
16516(allow update_engine system_suspend_hwservice (hwservice_manager (find)))
16517(allow update_engine hwservicemanager (binder (call transfer)))
16518(allow hwservicemanager update_engine (binder (call transfer)))
16519(allow hwservicemanager update_engine (dir (search)))
16520(allow hwservicemanager update_engine (file (read map open)))
16521(allow hwservicemanager update_engine (process (getattr)))
16522(allow update_engine hwservicemanager_prop (file (read getattr map open)))
16523(allow update_engine hidl_manager_hwservice (hwservice_manager (find)))
16524(allow update_engine hal_system_suspend_service (service_manager (find)))
16525(allow update_engine servicemanager (binder (call transfer)))
16526(allow servicemanager update_engine (binder (call transfer)))
16527(allow servicemanager update_engine (dir (search)))
16528(allow servicemanager update_engine (file (read open)))
16529(allow servicemanager update_engine (process (getattr)))
16530(dontaudit update_engine kernel (process (setsched)))
16531(dontaudit update_engine self (capability (sys_rawio)))
16532(dontaudit update_engine self (cap_userns (sys_rawio)))
16533(allow update_engine update_engine_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16534(allow update_engine update_engine_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16535(allow update_engine update_engine_log_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16536(allow update_engine update_engine_log_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16537(allow update_engine servicemanager (binder (call transfer)))
16538(allow servicemanager update_engine (binder (call transfer)))
16539(allow servicemanager update_engine (dir (search)))
16540(allow servicemanager update_engine (file (read open)))
16541(allow servicemanager update_engine (process (getattr)))
16542(allow update_engine update_engine_service (service_manager (add find)))
16543;;* lmx 34 system/sepolicy/public/update_engine.te
16544
16545(neverallow base_typeattr_594 update_engine_service (service_manager (add)))
16546;;* lme
16547
16548(allow update_engine update_engine_stable_service (service_manager (add find)))
16549;;* lmx 35 system/sepolicy/public/update_engine.te
16550
16551(neverallow base_typeattr_594 update_engine_stable_service (service_manager (add)))
16552;;* lme
16553
16554(allow update_engine priv_app (binder (call transfer)))
16555(allow priv_app update_engine (binder (transfer)))
16556(allow update_engine priv_app (fd (use)))
16557(allow update_engine gmscore_app (binder (call transfer)))
16558(allow gmscore_app update_engine (binder (transfer)))
16559(allow update_engine gmscore_app (fd (use)))
16560(allow update_engine system_server (binder (call transfer)))
16561(allow system_server update_engine (binder (transfer)))
16562(allow update_engine system_server (fd (use)))
16563(allow update_engine ota_package_file (file (ioctl read getattr lock map open watch watch_reads)))
16564(allow update_engine ota_package_file (dir (ioctl read getattr lock open watch watch_reads search)))
16565(allow update_engine proc_misc (file (ioctl read getattr lock map open watch watch_reads)))
16566(allow update_engine system_file (dir (ioctl read getattr lock open watch watch_reads search)))
16567(allow update_engine gsi_metadata_file_type (dir (search)))
16568(allow update_engine metadata_file (dir (search)))
16569(allow update_engine gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
16570(allow update_engine proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
16571(allow update_engine proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
16572(allow update_engine proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
16573(allow update_engine_common block_device (dir (search)))
16574(allow update_engine_common boot_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16575(allow update_engine_common system_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16576(allowx update_engine_common dev_type (ioctl blk_file ((range 0x125d 0x125e) 0x1277 (range 0x127c 0x127d) 0x127f)))
16577(allow update_engine_common misc_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16578(allow update_engine_common rootfs (dir (getattr)))
16579(allow update_engine_common rootfs (file (ioctl read getattr lock map open watch watch_reads)))
16580(allow update_engine_common postinstall_mnt_dir (dir (getattr mounton search)))
16581(allow update_engine_common postinstall_file (filesystem (mount unmount relabelfrom relabelto)))
16582(allow update_engine_common labeledfs (filesystem (mount unmount relabelfrom)))
16583(allow update_engine_common postinstall_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16584(allow update_engine_common postinstall_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16585(allow update_engine_common postinstall_file (dir (ioctl read getattr lock open watch watch_reads search)))
16586(allow update_engine_common cache_file (dir (ioctl read getattr lock open watch watch_reads search)))
16587(allow update_engine_common cache_file (file (ioctl read getattr lock map open watch watch_reads)))
16588(allow update_engine_common cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16589(allow update_engine_common shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
16590(allow update_engine_common postinstall (process (sigkill sigstop signal)))
16591(allow update_engine_common proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
16592(allow update_engine_common sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
16593(allow update_engine_common sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
16594(allow update_engine_common sysfs_dt_firmware_android (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16595(allow update_engine_common sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
16596(allow update_engine_common sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
16597(allow update_engine_common sysfs_dm (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16598(allow update_engine_common sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
16599(allow update_engine_common sysfs_fs_f2fs (dir (ioctl read getattr lock open watch watch_reads search)))
16600(allow update_engine_common dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16601(allow update_engine_common dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16602(allow update_engine dm_user_device (dir (ioctl read getattr lock open watch watch_reads search)))
16603(allow update_engine dm_user_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
16604(allow update_engine_common super_block_device_type (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
16605(allowx update_engine_common super_block_device_type (ioctl blk_file (0x1278 0x127a)))
16606(allow update_engine_common block_device (dir (ioctl read getattr lock open watch watch_reads search)))
16607(allow update_engine_common statsdw_socket (sock_file (write)))
16608(allow update_engine_common statsd (unix_dgram_socket (sendto)))
16609(allow update_engine_common virtual_ab_prop (file (read getattr map open)))
16610(allow update_engine_common ab_update_gki_prop (file (read getattr map open)))
16611(allow update_engine_common build_bootimage_prop (file (read getattr map open)))
16612(allow update_engine_common metadata_file (dir (search)))
16613(allow update_engine_common ota_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
16614(allow update_engine_common ota_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16615(allow update_verifier block_device (dir (search)))
16616(allow update_verifier ota_package_file (dir (ioctl read getattr lock open watch watch_reads search)))
16617(allow update_verifier ota_package_file (file (ioctl read getattr lock map open watch watch_reads)))
16618(allow update_verifier sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
16619(allow update_verifier sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
16620(allow update_verifier sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
16621(allow update_verifier dm_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
16622(allow update_verifier kmsg_device (chr_file (write getattr lock append map open)))
16623(allow update_verifier vold_service (service_manager (find)))
16624(allow update_verifier servicemanager (binder (call transfer)))
16625(allow servicemanager update_verifier (binder (transfer)))
16626(allow update_verifier servicemanager (fd (use)))
16627(allow update_verifier vold (binder (call transfer)))
16628(allow vold update_verifier (binder (transfer)))
16629(allow update_verifier vold (fd (use)))
16630(allow usbd servicemanager (binder (call transfer)))
16631(allow servicemanager usbd (binder (transfer)))
16632(allow usbd servicemanager (fd (use)))
16633(allow userdata_sysdev sysfs (filesystem (associate)))
16634(allow vdc devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
16635(allow vdc kmsg_device (chr_file (write getattr lock append map open)))
16636(allow vdc servicemanager (binder (call transfer)))
16637(allow servicemanager vdc (binder (call transfer)))
16638(allow servicemanager vdc (dir (search)))
16639(allow servicemanager vdc (file (read open)))
16640(allow servicemanager vdc (process (getattr)))
16641(allow vdc vold (binder (call transfer)))
16642(allow vold vdc (binder (transfer)))
16643(allow vdc vold (fd (use)))
16644(allow vdc vold_service (service_manager (find)))
16645(allow vendor_init init (unix_stream_socket (read write)))
16646(allow vendor_init kmsg_device (chr_file (write getattr open)))
16647(allow vendor_init device (dir (mounton)))
16648(allow vendor_init rootfs (lnk_file (create unlink)))
16649(allow vendor_init cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16650(allow vendor_init cgroup (file (write lock append map open)))
16651(allow vendor_init cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16652(allow vendor_init cgroup_v2 (file (write lock append map open)))
16653(allow vendor_init configfs (dir (mounton)))
16654(allow vendor_init configfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16655(allow vendor_init configfs (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16656(allow vendor_init configfs (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16657(allow vendor_init self (capability (dac_override dac_read_search)))
16658(allow vendor_init self (cap_userns (dac_override dac_read_search)))
16659(allow vendor_init self (capability (chown fowner fsetid)))
16660(allow vendor_init self (cap_userns (chown fowner fsetid)))
16661(allow vendor_init unencrypted_data_file (dir (search)))
16662(allow vendor_init unencrypted_data_file (file (ioctl read getattr lock map open watch watch_reads)))
16663(allowx vendor_init data_file_type (ioctl dir (0x6613 0x6615)))
16664(allow vendor_init system_data_file (dir (getattr)))
16665(allow vendor_init base_typeattr_595 (dir (ioctl read write create getattr setattr relabelfrom open add_name remove_name search rmdir)))
16666(allow vendor_init unlabeled (file (getattr relabelfrom)))
16667(allow vendor_init unlabeled (dir (getattr relabelfrom)))
16668(allow vendor_init unlabeled (lnk_file (getattr relabelfrom)))
16669(allow vendor_init unlabeled (sock_file (getattr relabelfrom)))
16670(allow vendor_init unlabeled (fifo_file (getattr relabelfrom)))
16671(allow vendor_init base_typeattr_596 (file (read write create getattr setattr relabelfrom map unlink open)))
16672(allow vendor_init base_typeattr_597 (sock_file (read create getattr setattr relabelfrom unlink open)))
16673(allow vendor_init base_typeattr_597 (fifo_file (read create getattr setattr relabelfrom unlink open)))
16674(allow vendor_init base_typeattr_598 (lnk_file (create getattr setattr relabelfrom unlink)))
16675(allow vendor_init base_typeattr_599 (file (relabelto)))
16676(allow vendor_init base_typeattr_599 (dir (relabelto)))
16677(allow vendor_init base_typeattr_599 (lnk_file (relabelto)))
16678(allow vendor_init base_typeattr_599 (chr_file (relabelto)))
16679(allow vendor_init base_typeattr_599 (blk_file (relabelto)))
16680(allow vendor_init base_typeattr_599 (sock_file (relabelto)))
16681(allow vendor_init base_typeattr_599 (fifo_file (relabelto)))
16682(allow vendor_init dev_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
16683(allow vendor_init dev_type (lnk_file (create)))
16684(allow vendor_init debugfs_tracing (file (write lock append map open)))
16685(allow vendor_init base_typeattr_600 (file (read setattr map open)))
16686(allow vendor_init tracefs_type (file (read setattr map open)))
16687(allow vendor_init base_typeattr_601 (dir (read setattr open search)))
16688(allow vendor_init dev_type (blk_file (getattr)))
16689(allow vendor_init proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
16690(allow vendor_init proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
16691(allow vendor_init proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16692(allow vendor_init proc_net_type (file (write lock append map open)))
16693(allow vendor_init self (capability (net_admin)))
16694(allow vendor_init self (cap_userns (net_admin)))
16695(allow vendor_init proc_page_cluster (file (write lock append map open)))
16696(allow vendor_init sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
16697(allow vendor_init sysfs_type (lnk_file (read)))
16698(allow vendor_init base_typeattr_602 (file (ioctl read write getattr lock append map open watch watch_reads)))
16699(allow vendor_init self (process (setfscreate)))
16700(allow vendor_init vendor_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
16701(allow vendor_init vendor_file_type (file (ioctl read getattr lock map open watch watch_reads)))
16702(allow vendor_init vendor_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
16703(allow vendor_init serialno_prop (file (read getattr map open)))
16704(allow vendor_init self (capability (sys_admin)))
16705(allow vendor_init self (cap_userns (sys_admin)))
16706(allow vendor_init misc_block_device (blk_file (write lock append map open)))
16707(allow vendor_init system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
16708(allow vendor_init system_bootstrap_lib_file (file (read getattr map execute open)))
16709(allow vendor_init userdata_sysdev (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
16710(allow vendor_init file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
16711(allow vendor_init self (capability (sys_nice)))
16712(allow vendor_init property_socket (sock_file (write)))
16713(allow vendor_init init (unix_stream_socket (connectto)))
16714(allow vendor_init apk_verity_prop (property_service (set)))
16715(allow vendor_init apk_verity_prop (file (read getattr map open)))
16716(allow vendor_init property_socket (sock_file (write)))
16717(allow vendor_init init (unix_stream_socket (connectto)))
16718(allow vendor_init bluetooth_a2dp_offload_prop (property_service (set)))
16719(allow vendor_init bluetooth_a2dp_offload_prop (file (read getattr map open)))
16720(allow vendor_init property_socket (sock_file (write)))
16721(allow vendor_init init (unix_stream_socket (connectto)))
16722(allow vendor_init bluetooth_audio_hal_prop (property_service (set)))
16723(allow vendor_init bluetooth_audio_hal_prop (file (read getattr map open)))
16724(allow vendor_init property_socket (sock_file (write)))
16725(allow vendor_init init (unix_stream_socket (connectto)))
16726(allow vendor_init bluetooth_config_prop (property_service (set)))
16727(allow vendor_init bluetooth_config_prop (file (read getattr map open)))
16728(allow vendor_init property_socket (sock_file (write)))
16729(allow vendor_init init (unix_stream_socket (connectto)))
16730(allow vendor_init camera2_extensions_prop (property_service (set)))
16731(allow vendor_init camera2_extensions_prop (file (read getattr map open)))
16732(allow vendor_init property_socket (sock_file (write)))
16733(allow vendor_init init (unix_stream_socket (connectto)))
16734(allow vendor_init camerax_extensions_prop (property_service (set)))
16735(allow vendor_init camerax_extensions_prop (file (read getattr map open)))
16736(allow vendor_init property_socket (sock_file (write)))
16737(allow vendor_init init (unix_stream_socket (connectto)))
16738(allow vendor_init cpu_variant_prop (property_service (set)))
16739(allow vendor_init cpu_variant_prop (file (read getattr map open)))
16740(allow vendor_init property_socket (sock_file (write)))
16741(allow vendor_init init (unix_stream_socket (connectto)))
16742(allow vendor_init dalvik_config_prop (property_service (set)))
16743(allow vendor_init dalvik_config_prop (file (read getattr map open)))
16744(allow vendor_init property_socket (sock_file (write)))
16745(allow vendor_init init (unix_stream_socket (connectto)))
16746(allow vendor_init dalvik_dynamic_config_prop (property_service (set)))
16747(allow vendor_init dalvik_dynamic_config_prop (file (read getattr map open)))
16748(allow vendor_init property_socket (sock_file (write)))
16749(allow vendor_init init (unix_stream_socket (connectto)))
16750(allow vendor_init dalvik_runtime_prop (property_service (set)))
16751(allow vendor_init dalvik_runtime_prop (file (read getattr map open)))
16752(allow vendor_init property_socket (sock_file (write)))
16753(allow vendor_init init (unix_stream_socket (connectto)))
16754(allow vendor_init debug_prop (property_service (set)))
16755(allow vendor_init debug_prop (file (read getattr map open)))
16756(allow vendor_init property_socket (sock_file (write)))
16757(allow vendor_init init (unix_stream_socket (connectto)))
16758(allow vendor_init exported_bluetooth_prop (property_service (set)))
16759(allow vendor_init exported_bluetooth_prop (file (read getattr map open)))
16760(allow vendor_init property_socket (sock_file (write)))
16761(allow vendor_init init (unix_stream_socket (connectto)))
16762(allow vendor_init exported_camera_prop (property_service (set)))
16763(allow vendor_init exported_camera_prop (file (read getattr map open)))
16764(allow vendor_init property_socket (sock_file (write)))
16765(allow vendor_init init (unix_stream_socket (connectto)))
16766(allow vendor_init exported_config_prop (property_service (set)))
16767(allow vendor_init exported_config_prop (file (read getattr map open)))
16768(allow vendor_init property_socket (sock_file (write)))
16769(allow vendor_init init (unix_stream_socket (connectto)))
16770(allow vendor_init exported_default_prop (property_service (set)))
16771(allow vendor_init exported_default_prop (file (read getattr map open)))
16772(allow vendor_init property_socket (sock_file (write)))
16773(allow vendor_init init (unix_stream_socket (connectto)))
16774(allow vendor_init exported_overlay_prop (property_service (set)))
16775(allow vendor_init exported_overlay_prop (file (read getattr map open)))
16776(allow vendor_init property_socket (sock_file (write)))
16777(allow vendor_init init (unix_stream_socket (connectto)))
16778(allow vendor_init exported_pm_prop (property_service (set)))
16779(allow vendor_init exported_pm_prop (file (read getattr map open)))
16780(allow vendor_init property_socket (sock_file (write)))
16781(allow vendor_init init (unix_stream_socket (connectto)))
16782(allow vendor_init ffs_control_prop (property_service (set)))
16783(allow vendor_init ffs_control_prop (file (read getattr map open)))
16784(allow vendor_init property_socket (sock_file (write)))
16785(allow vendor_init init (unix_stream_socket (connectto)))
16786(allow vendor_init hw_timeout_multiplier_prop (property_service (set)))
16787(allow vendor_init hw_timeout_multiplier_prop (file (read getattr map open)))
16788(allow vendor_init property_socket (sock_file (write)))
16789(allow vendor_init init (unix_stream_socket (connectto)))
16790(allow vendor_init incremental_prop (property_service (set)))
16791(allow vendor_init incremental_prop (file (read getattr map open)))
16792(allow vendor_init property_socket (sock_file (write)))
16793(allow vendor_init init (unix_stream_socket (connectto)))
16794(allow vendor_init lmkd_prop (property_service (set)))
16795(allow vendor_init lmkd_prop (file (read getattr map open)))
16796(allow vendor_init property_socket (sock_file (write)))
16797(allow vendor_init init (unix_stream_socket (connectto)))
16798(allow vendor_init logd_prop (property_service (set)))
16799(allow vendor_init logd_prop (file (read getattr map open)))
16800(allow vendor_init property_socket (sock_file (write)))
16801(allow vendor_init init (unix_stream_socket (connectto)))
16802(allow vendor_init log_tag_prop (property_service (set)))
16803(allow vendor_init log_tag_prop (file (read getattr map open)))
16804(allow vendor_init property_socket (sock_file (write)))
16805(allow vendor_init init (unix_stream_socket (connectto)))
16806(allow vendor_init log_prop (property_service (set)))
16807(allow vendor_init log_prop (file (read getattr map open)))
16808(allow vendor_init property_socket (sock_file (write)))
16809(allow vendor_init init (unix_stream_socket (connectto)))
16810(allow vendor_init graphics_config_writable_prop (property_service (set)))
16811(allow vendor_init graphics_config_writable_prop (file (read getattr map open)))
16812(allow vendor_init property_socket (sock_file (write)))
16813(allow vendor_init init (unix_stream_socket (connectto)))
16814(allow vendor_init qemu_hw_prop (property_service (set)))
16815(allow vendor_init qemu_hw_prop (file (read getattr map open)))
16816(allow vendor_init property_socket (sock_file (write)))
16817(allow vendor_init init (unix_stream_socket (connectto)))
16818(allow vendor_init radio_control_prop (property_service (set)))
16819(allow vendor_init radio_control_prop (file (read getattr map open)))
16820(allow vendor_init property_socket (sock_file (write)))
16821(allow vendor_init init (unix_stream_socket (connectto)))
16822(allow vendor_init rebootescrow_hal_prop (property_service (set)))
16823(allow vendor_init rebootescrow_hal_prop (file (read getattr map open)))
16824(allow vendor_init property_socket (sock_file (write)))
16825(allow vendor_init init (unix_stream_socket (connectto)))
16826(allow vendor_init serialno_prop (property_service (set)))
16827(allow vendor_init serialno_prop (file (read getattr map open)))
16828(allow vendor_init property_socket (sock_file (write)))
16829(allow vendor_init init (unix_stream_socket (connectto)))
16830(allow vendor_init soc_prop (property_service (set)))
16831(allow vendor_init soc_prop (file (read getattr map open)))
16832(allow vendor_init property_socket (sock_file (write)))
16833(allow vendor_init init (unix_stream_socket (connectto)))
16834(allow vendor_init surfaceflinger_color_prop (property_service (set)))
16835(allow vendor_init surfaceflinger_color_prop (file (read getattr map open)))
16836(allow vendor_init property_socket (sock_file (write)))
16837(allow vendor_init init (unix_stream_socket (connectto)))
16838(allow vendor_init usb_control_prop (property_service (set)))
16839(allow vendor_init usb_control_prop (file (read getattr map open)))
16840(allow vendor_init property_socket (sock_file (write)))
16841(allow vendor_init init (unix_stream_socket (connectto)))
16842(allow vendor_init userspace_reboot_config_prop (property_service (set)))
16843(allow vendor_init userspace_reboot_config_prop (file (read getattr map open)))
16844(allow vendor_init property_socket (sock_file (write)))
16845(allow vendor_init init (unix_stream_socket (connectto)))
16846(allow vendor_init vehicle_hal_prop (property_service (set)))
16847(allow vendor_init vehicle_hal_prop (file (read getattr map open)))
16848(allow vendor_init property_socket (sock_file (write)))
16849(allow vendor_init init (unix_stream_socket (connectto)))
16850(allow vendor_init vendor_default_prop (property_service (set)))
16851(allow vendor_init vendor_default_prop (file (read getattr map open)))
16852(allow vendor_init property_socket (sock_file (write)))
16853(allow vendor_init init (unix_stream_socket (connectto)))
16854(allow vendor_init keystore_config_prop (property_service (set)))
16855(allow vendor_init keystore_config_prop (file (read getattr map open)))
16856(allow vendor_init property_socket (sock_file (write)))
16857(allow vendor_init init (unix_stream_socket (connectto)))
16858(allow vendor_init vendor_security_patch_level_prop (property_service (set)))
16859(allow vendor_init vendor_security_patch_level_prop (file (read getattr map open)))
16860(allow vendor_init property_socket (sock_file (write)))
16861(allow vendor_init init (unix_stream_socket (connectto)))
16862(allow vendor_init vndk_prop (property_service (set)))
16863(allow vendor_init vndk_prop (file (read getattr map open)))
16864(allow vendor_init property_socket (sock_file (write)))
16865(allow vendor_init init (unix_stream_socket (connectto)))
16866(allow vendor_init virtual_ab_prop (property_service (set)))
16867(allow vendor_init virtual_ab_prop (file (read getattr map open)))
16868(allow vendor_init property_socket (sock_file (write)))
16869(allow vendor_init init (unix_stream_socket (connectto)))
16870(allow vendor_init vold_post_fs_data_prop (property_service (set)))
16871(allow vendor_init vold_post_fs_data_prop (file (read getattr map open)))
16872(allow vendor_init property_socket (sock_file (write)))
16873(allow vendor_init init (unix_stream_socket (connectto)))
16874(allow vendor_init wifi_hal_prop (property_service (set)))
16875(allow vendor_init wifi_hal_prop (file (read getattr map open)))
16876(allow vendor_init property_socket (sock_file (write)))
16877(allow vendor_init init (unix_stream_socket (connectto)))
16878(allow vendor_init wifi_log_prop (property_service (set)))
16879(allow vendor_init wifi_log_prop (file (read getattr map open)))
16880(allow vendor_init property_socket (sock_file (write)))
16881(allow vendor_init init (unix_stream_socket (connectto)))
16882(allow vendor_init zram_control_prop (property_service (set)))
16883(allow vendor_init zram_control_prop (file (read getattr map open)))
16884(allow vendor_init boot_status_prop (file (read getattr map open)))
16885(allow vendor_init exported3_system_prop (file (read getattr map open)))
16886(allow vendor_init ota_prop (file (read getattr map open)))
16887(allow vendor_init power_debug_prop (file (read getattr map open)))
16888(allow vendor_init provisioned_prop (file (read getattr map open)))
16889(allow vendor_init retaildemo_prop (file (read getattr map open)))
16890(allow vendor_init surfaceflinger_display_prop (file (read getattr map open)))
16891(allow vendor_init test_harness_prop (file (read getattr map open)))
16892(allow vendor_init theme_prop (file (read getattr map open)))
16893(allow vendor_init property_socket (sock_file (write)))
16894(allow vendor_init init (unix_stream_socket (connectto)))
16895(allow vendor_init dck_prop (property_service (set)))
16896(allow vendor_init dck_prop (file (read getattr map open)))
16897(allow vendor_init device_config_vendor_system_native_prop (file (read getattr map open)))
16898(allow vendor_init device_config_vendor_system_native_boot_prop (file (read getattr map open)))
16899;;* lmx 305 system/sepolicy/public/vendor_init.te
16900
16901(neverallow vendor_init base_typeattr_603 (socket (connect sendto)))
16902(neverallow vendor_init base_typeattr_603 (tcp_socket (connect sendto)))
16903(neverallow vendor_init base_typeattr_603 (udp_socket (connect sendto)))
16904(neverallow vendor_init base_typeattr_603 (rawip_socket (connect sendto)))
16905(neverallow vendor_init base_typeattr_603 (netlink_socket (connect sendto)))
16906(neverallow vendor_init base_typeattr_603 (packet_socket (connect sendto)))
16907(neverallow vendor_init base_typeattr_603 (key_socket (connect sendto)))
16908(neverallow vendor_init base_typeattr_603 (unix_stream_socket (connect sendto)))
16909(neverallow vendor_init base_typeattr_603 (unix_dgram_socket (connect sendto)))
16910(neverallow vendor_init base_typeattr_603 (netlink_route_socket (connect sendto)))
16911(neverallow vendor_init base_typeattr_603 (netlink_tcpdiag_socket (connect sendto)))
16912(neverallow vendor_init base_typeattr_603 (netlink_nflog_socket (connect sendto)))
16913(neverallow vendor_init base_typeattr_603 (netlink_xfrm_socket (connect sendto)))
16914(neverallow vendor_init base_typeattr_603 (netlink_selinux_socket (connect sendto)))
16915(neverallow vendor_init base_typeattr_603 (netlink_audit_socket (connect sendto)))
16916(neverallow vendor_init base_typeattr_603 (netlink_dnrt_socket (connect sendto)))
16917(neverallow vendor_init base_typeattr_603 (netlink_kobject_uevent_socket (connect sendto)))
16918(neverallow vendor_init base_typeattr_603 (appletalk_socket (connect sendto)))
16919(neverallow vendor_init base_typeattr_603 (tun_socket (connect sendto)))
16920(neverallow vendor_init base_typeattr_603 (netlink_iscsi_socket (connect sendto)))
16921(neverallow vendor_init base_typeattr_603 (netlink_fib_lookup_socket (connect sendto)))
16922(neverallow vendor_init base_typeattr_603 (netlink_connector_socket (connect sendto)))
16923(neverallow vendor_init base_typeattr_603 (netlink_netfilter_socket (connect sendto)))
16924(neverallow vendor_init base_typeattr_603 (netlink_generic_socket (connect sendto)))
16925(neverallow vendor_init base_typeattr_603 (netlink_scsitransport_socket (connect sendto)))
16926(neverallow vendor_init base_typeattr_603 (netlink_rdma_socket (connect sendto)))
16927(neverallow vendor_init base_typeattr_603 (netlink_crypto_socket (connect sendto)))
16928(neverallow vendor_init base_typeattr_603 (sctp_socket (connect sendto)))
16929(neverallow vendor_init base_typeattr_603 (icmp_socket (connect sendto)))
16930(neverallow vendor_init base_typeattr_603 (ax25_socket (connect sendto)))
16931(neverallow vendor_init base_typeattr_603 (ipx_socket (connect sendto)))
16932(neverallow vendor_init base_typeattr_603 (netrom_socket (connect sendto)))
16933(neverallow vendor_init base_typeattr_603 (atmpvc_socket (connect sendto)))
16934(neverallow vendor_init base_typeattr_603 (x25_socket (connect sendto)))
16935(neverallow vendor_init base_typeattr_603 (rose_socket (connect sendto)))
16936(neverallow vendor_init base_typeattr_603 (decnet_socket (connect sendto)))
16937(neverallow vendor_init base_typeattr_603 (atmsvc_socket (connect sendto)))
16938(neverallow vendor_init base_typeattr_603 (rds_socket (connect sendto)))
16939(neverallow vendor_init base_typeattr_603 (irda_socket (connect sendto)))
16940(neverallow vendor_init base_typeattr_603 (pppox_socket (connect sendto)))
16941(neverallow vendor_init base_typeattr_603 (llc_socket (connect sendto)))
16942(neverallow vendor_init base_typeattr_603 (can_socket (connect sendto)))
16943(neverallow vendor_init base_typeattr_603 (tipc_socket (connect sendto)))
16944(neverallow vendor_init base_typeattr_603 (bluetooth_socket (connect sendto)))
16945(neverallow vendor_init base_typeattr_603 (iucv_socket (connect sendto)))
16946(neverallow vendor_init base_typeattr_603 (rxrpc_socket (connect sendto)))
16947(neverallow vendor_init base_typeattr_603 (isdn_socket (connect sendto)))
16948(neverallow vendor_init base_typeattr_603 (phonet_socket (connect sendto)))
16949(neverallow vendor_init base_typeattr_603 (ieee802154_socket (connect sendto)))
16950(neverallow vendor_init base_typeattr_603 (caif_socket (connect sendto)))
16951(neverallow vendor_init base_typeattr_603 (alg_socket (connect sendto)))
16952(neverallow vendor_init base_typeattr_603 (nfc_socket (connect sendto)))
16953(neverallow vendor_init base_typeattr_603 (vsock_socket (connect sendto)))
16954(neverallow vendor_init base_typeattr_603 (kcm_socket (connect sendto)))
16955(neverallow vendor_init base_typeattr_603 (qipcrtr_socket (connect sendto)))
16956(neverallow vendor_init base_typeattr_603 (smc_socket (connect sendto)))
16957(neverallow vendor_init base_typeattr_603 (xdp_socket (connect sendto)))
16958;;* lme
16959
16960;;* lmx 305 system/sepolicy/public/vendor_init.te
16961
16962(neverallow vendor_init base_typeattr_603 (unix_stream_socket (connectto)))
16963;;* lme
16964
16965;;* lmx 310 system/sepolicy/public/vendor_init.te
16966
16967(neverallow domain vendor_init (process (dyntransition)))
16968;;* lme
16969
16970;;* lmx 311 system/sepolicy/public/vendor_init.te
16971
16972(neverallow base_typeattr_223 vendor_init (process (transition)))
16973;;* lme
16974
16975;;* lmx 312 system/sepolicy/public/vendor_init.te
16976
16977(neverallow vendor_init base_typeattr_554 (file (entrypoint)))
16978;;* lme
16979
16980;;* lmx 315 system/sepolicy/public/vendor_init.te
16981
16982(neverallow vendor_init app_data_file_type (lnk_file (read)))
16983;;* lme
16984
16985;;* lmx 316 system/sepolicy/public/vendor_init.te
16986
16987(neverallow vendor_init shell_data_file (lnk_file (read)))
16988;;* lme
16989
16990;;* lmx 318 system/sepolicy/public/vendor_init.te
16991
16992(neverallow vendor_init shell_data_file (dir (write add_name remove_name)))
16993;;* lme
16994
16995;;* lmx 321 system/sepolicy/public/vendor_init.te
16996
16997(neverallow vendor_init fs_type (file (execute_no_trans)))
16998(neverallow vendor_init file_type (file (execute_no_trans)))
16999;;* lme
17000
17001;;* lmx 324 system/sepolicy/public/vendor_init.te
17002
17003(neverallow vendor_init service_manager_type (service_manager (add find)))
17004;;* lme
17005
17006;;* lmx 325 system/sepolicy/public/vendor_init.te
17007
17008(neverallow vendor_init servicemanager (service_manager (list)))
17009;;* lme
17010
17011;;* lmx 328 system/sepolicy/public/vendor_init.te
17012
17013(neverallow base_typeattr_224 vendor_init (process (ptrace)))
17014;;* lme
17015
17016(allow vendor_misc_writer misc_block_device (blk_file (write lock append map open)))
17017(allow vendor_misc_writer block_device (dir (ioctl read getattr lock open watch watch_reads search)))
17018(dontaudit vendor_misc_writer proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
17019(dontaudit vendor_misc_writer sysfs_dt_firmware_android (dir (search)))
17020(dontaudit vendor_misc_writer proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
17021(allow vendor_misc_writer gsi_metadata_file_type (dir (search)))
17022(allow vendor_misc_writer metadata_file (dir (search)))
17023(allow vendor_misc_writer gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
17024(allow vendor_misc_writer proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
17025(allow vendor_misc_writer proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
17026(allow vendor_shell vendor_shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17027(allow vendor_shell vendor_toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17028(allow vendor_shell shell (fd (use)))
17029(allow vendor_shell adbd (fd (use)))
17030(allow vendor_shell adbd (process (sigchld)))
17031(allow vendor_shell adbd (unix_stream_socket (ioctl read write getattr)))
17032(allow vendor_shell devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17033(allow vendor_shell tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17034(allow vendor_shell console_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17035(allow vendor_shell input_device (dir (ioctl read getattr lock open watch watch_reads search)))
17036(allow vendor_shell input_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17037;;* lmx 8 system/sepolicy/public/vendor_toolbox.te
17038
17039(neverallow base_typeattr_604 vendor_toolbox_exec (file (execute execute_no_trans entrypoint)))
17040;;* lme
17041
17042(allow virtual_touchpad servicemanager (binder (call transfer)))
17043(allow servicemanager virtual_touchpad (binder (call transfer)))
17044(allow servicemanager virtual_touchpad (dir (search)))
17045(allow servicemanager virtual_touchpad (file (read open)))
17046(allow servicemanager virtual_touchpad (process (getattr)))
17047(allow virtual_touchpad virtual_touchpad_service (service_manager (add find)))
17048;;* lmx 6 system/sepolicy/public/virtual_touchpad.te
17049
17050(neverallow base_typeattr_605 virtual_touchpad_service (service_manager (add)))
17051;;* lme
17052
17053(allow virtual_touchpad system_server (binder (call transfer)))
17054(allow system_server virtual_touchpad (binder (transfer)))
17055(allow virtual_touchpad system_server (fd (use)))
17056(allow virtual_touchpad uhid_device (chr_file (ioctl write lock append map open)))
17057(allow virtual_touchpad permission_service (service_manager (find)))
17058(allow vold cache_file (dir (ioctl read getattr lock open watch watch_reads search)))
17059(allow vold cache_file (file (read getattr)))
17060(allow vold cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17061(allow vold base_typeattr_606 (dir (ioctl read getattr lock open watch watch_reads search)))
17062(allow vold base_typeattr_606 (file (ioctl read getattr lock map open watch watch_reads)))
17063(allow vold base_typeattr_606 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17064(allow vold sysfs (file (write lock append map open)))
17065(allow vold sysfs_devices_block (file (write lock append map open)))
17066(allow vold sysfs_dm (file (write lock append map open)))
17067(allow vold sysfs_loop (file (write lock append map open)))
17068(allow vold sysfs_usb (file (write lock append map open)))
17069(allow vold sysfs_fs_f2fs (file (write lock append map open)))
17070(allow vold sysfs_zram_uevent (file (write lock append map open)))
17071(allow vold rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
17072(allow vold rootfs (file (ioctl read getattr lock map open watch watch_reads)))
17073(allow vold rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17074(allow vold metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
17075(allow vold metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
17076(allow vold metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17077(allow vold proc (file (ioctl read getattr lock map open watch watch_reads)))
17078(allow vold proc_drop_caches (file (ioctl read getattr lock map open watch watch_reads)))
17079(allow vold proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
17080(allow vold proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
17081(allow vold proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
17082(allow vold proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
17083(allow vold proc_mounts (file (ioctl read getattr lock map open watch watch_reads)))
17084(allow vold file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17085(allow vold self (process (setexec)))
17086(allow vold e2fs_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17087(allowx vold fs_type (ioctl dir (0x5879)))
17088(allowx vold file_type (ioctl dir (0x5879)))
17089(allowx vold data_file_type (ioctl dir (0x6613 0x6615 (range 0x6617 0x6618) 0x661a)))
17090;;* lmx 63 system/sepolicy/public/vold.te
17091
17092(neverallowx base_typeattr_321 data_file_type (ioctl dir (0x6613)))
17093;;* lme
17094
17095;;* lmx 69 system/sepolicy/public/vold.te
17096
17097(neverallowx base_typeattr_339 data_file_type (ioctl dir ((range 0x6617 0x6618) 0x661a)))
17098;;* lme
17099
17100(allowx vold vold_metadata_file (ioctl file (0x660b)))
17101(allowx vold vold_data_file (ioctl file (0x660b)))
17102(allowx vold vold_metadata_file (ioctl file (0xf514)))
17103(allowx vold vold_data_file (ioctl file (0xf514)))
17104(allow vold self (process (setfscreate)))
17105(allow vold system_file (file (getattr map execute execute_no_trans)))
17106(allow vold block_device (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17107(allow vold device (dir (write)))
17108(allow vold devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17109(allow vold rootfs (dir (mounton)))
17110(allow vold sdcard_type (dir (mounton)))
17111(allow vold fuse (dir (mounton)))
17112(allow vold sdcard_type (filesystem (mount remount unmount)))
17113(allow vold fuse (filesystem (mount remount unmount)))
17114(allow vold sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17115(allow vold fuse (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17116(allow vold mnt_media_rw_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17117(allow vold storage_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17118(allow vold sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17119(allow vold fuse (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17120(allow vold mnt_media_rw_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17121(allow vold storage_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17122(allow vold media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17123(allow vold media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17124(allow vold media_rw_data_file (dir (mounton)))
17125(allowx vold media_rw_data_file (ioctl file ((range 0x581f 0x5820))))
17126(allowx vold media_rw_data_file (ioctl dir ((range 0x581f 0x5820))))
17127(allowx vold media_rw_data_file (ioctl file ((range 0x6601 0x6602))))
17128(allowx vold media_rw_data_file (ioctl dir ((range 0x6601 0x6602))))
17129(allow vold mnt_media_rw_stub_file (dir (create getattr setattr mounton rmdir)))
17130(allow vold storage_stub_file (dir (create getattr setattr mounton rmdir)))
17131(allow vold mnt_user_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17132(allow vold mnt_user_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17133(allow vold mnt_user_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17134(allow vold mnt_pass_through_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17135(allow vold mnt_pass_through_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17136(allow vold mnt_expand_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17137(allow vold apk_data_file (dir (create getattr setattr)))
17138(allow vold shell_data_file (dir (create getattr setattr)))
17139(allow vold system_userdir_file (dir (create getattr setattr)))
17140(allow vold media_userdir_file (dir (ioctl read create getattr setattr open)))
17141(allowx vold media_userdir_file (ioctl dir ((range 0x6601 0x6602))))
17142(allow vold apk_data_file (dir (ioctl read write getattr lock mounton open watch watch_reads add_name remove_name search)))
17143(allow vold apk_data_file (file (ioctl read write getattr lock append map unlink open watch watch_reads)))
17144(allow vold apk_tmp_file (dir (ioctl read getattr lock mounton open watch watch_reads search)))
17145(allow vold incremental_control_file (file (ioctl read getattr lock relabelto map open watch watch_reads)))
17146(allow vold tmpfs (filesystem (mount unmount)))
17147(allow vold tmpfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17148(allow vold tmpfs (dir (mounton)))
17149(allow vold self (capability (chown dac_override dac_read_search fowner fsetid net_admin sys_admin mknod)))
17150(allow vold self (cap_userns (chown dac_override dac_read_search fowner fsetid net_admin sys_admin mknod)))
17151(allow vold self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
17152(allow vold loop_control_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17153(allow vold loop_device (blk_file (ioctl read write create getattr setattr lock append map unlink open watch watch_reads)))
17154(allowx vold loop_device (ioctl blk_file ((range 0x4c00 0x4c01) (range 0x4c04 0x4c05) 0x4c82)))
17155(allow vold vold_device (blk_file (ioctl read write create getattr setattr lock append map unlink open watch watch_reads)))
17156(allowx vold vold_device (ioctl blk_file (0x1260 0x1277)))
17157(allow vold dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17158(allow vold dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17159(allowx vold dm_device (ioctl blk_file (0x1277 0x127d (range 0x1282 0x1283))))
17160(allow vold domain (dir (ioctl read getattr lock open watch watch_reads search)))
17161(allow vold domain (file (ioctl read getattr lock map open watch watch_reads)))
17162(allow vold domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17163(allow vold domain (process (sigkill signal)))
17164(allow vold self (capability (kill sys_ptrace)))
17165(allow vold self (cap_userns (kill sys_ptrace)))
17166(allow vold kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17167(allow vold fsck_exec (file (ioctl read getattr lock map execute open watch watch_reads)))
17168(allow vold fscklogs (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
17169(allow vold fscklogs (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17170(allow vold labeledfs (filesystem (mount remount unmount)))
17171(allow vold system_data_root_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17172(allow vold system_data_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17173(allow vold system_data_file (lnk_file (getattr)))
17174(allow vold vendor_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17175(allow vold system_data_file (file (read)))
17176(allow vold kernel (process (setsched)))
17177(allow vold asec_image_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17178(allow vold asec_image_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
17179(allow vold asec_apk_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17180(allow vold asec_public_file (dir (setattr relabelto)))
17181(allow vold asec_apk_file (file (ioctl read getattr setattr lock relabelfrom relabelto map open watch watch_reads)))
17182(allow vold asec_public_file (file (setattr relabelto)))
17183(allow vold unlabeled (dir (ioctl read getattr setattr lock relabelfrom open watch watch_reads search)))
17184(allow vold unlabeled (file (ioctl read getattr setattr lock relabelfrom map open watch watch_reads)))
17185(allow vold fusectlfs (file (ioctl read write getattr lock append map open watch watch_reads)))
17186(allow vold fusectlfs (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
17187(allow vold sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
17188(allow vold self (capability2 (block_suspend)))
17189(allow vold self (cap2_userns (block_suspend)))
17190(allow vold system_suspend_server (binder (call transfer)))
17191(allow system_suspend_server vold (binder (transfer)))
17192(allow vold system_suspend_server (fd (use)))
17193(allow vold system_suspend_hwservice (hwservice_manager (find)))
17194(allow vold hwservicemanager (binder (call transfer)))
17195(allow hwservicemanager vold (binder (call transfer)))
17196(allow hwservicemanager vold (dir (search)))
17197(allow hwservicemanager vold (file (read map open)))
17198(allow hwservicemanager vold (process (getattr)))
17199(allow vold hwservicemanager_prop (file (read getattr map open)))
17200(allow vold hidl_manager_hwservice (hwservice_manager (find)))
17201(allow vold hal_system_suspend_service (service_manager (find)))
17202(allow vold servicemanager (binder (call transfer)))
17203(allow servicemanager vold (binder (call transfer)))
17204(allow servicemanager vold (dir (search)))
17205(allow servicemanager vold (file (read open)))
17206(allow servicemanager vold (process (getattr)))
17207(allow vold servicemanager (binder (call transfer)))
17208(allow servicemanager vold (binder (call transfer)))
17209(allow servicemanager vold (dir (search)))
17210(allow servicemanager vold (file (read open)))
17211(allow servicemanager vold (process (getattr)))
17212(allow vold vold_service (service_manager (add find)))
17213;;* lmx 218 system/sepolicy/public/vold.te
17214
17215(neverallow base_typeattr_339 vold_service (service_manager (add)))
17216;;* lme
17217
17218(allow vold system_server (binder (call transfer)))
17219(allow system_server vold (binder (transfer)))
17220(allow vold system_server (fd (use)))
17221(allow vold permission_service (service_manager (find)))
17222(allow vold userdata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17223(allowx vold userdata_block_device (ioctl blk_file (0x127d)))
17224(allow vold zoned_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17225(allow vold metadata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17226(allowx vold metadata_block_device (ioctl blk_file (0x127d)))
17227(allow vold unencrypted_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17228(allow vold unencrypted_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17229(allow vold proc_drop_caches (file (write lock append map open)))
17230(allow vold vold_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17231(allow vold vold_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17232(allow vold vold_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17233(allow vold vold_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17234(allow vold init (key (write search setattr)))
17235(allow vold vold (key (write search setattr)))
17236(allow vold self (capability (sys_nice)))
17237(allow vold self (cap_userns (sys_nice)))
17238(allow vold self (capability (sys_chroot)))
17239(allow vold self (cap_userns (sys_chroot)))
17240(allow vold storage_file (dir (mounton)))
17241(allow vold fuse_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17242(allow vold fuse (filesystem (relabelfrom)))
17243(allow vold app_fusefs (filesystem (relabelfrom relabelto)))
17244(allow vold app_fusefs (filesystem (mount unmount)))
17245(allow vold app_fuse_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
17246(allow vold app_fuse_file (file (read write getattr append open)))
17247(allow vold toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17248(allow vold user_profile_root_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17249(allow vold user_profile_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17250(allow vold misc_block_device (blk_file (write lock append map open)))
17251(allow vold mnt_vendor_file (dir (search)))
17252(dontaudit vold self (capability (sys_resource)))
17253(dontaudit vold self (cap_userns (sys_resource)))
17254(allow vold gsi_metadata_file_type (dir (search)))
17255(allow vold metadata_file (dir (search)))
17256(allow vold gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
17257(allow vold proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
17258(allow vold proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
17259(allow vold vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
17260;;* lmx 299 system/sepolicy/public/vold.te
17261
17262(neverallow base_typeattr_607 vold_data_file (dir (write lock append map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
17263;;* lme
17264
17265;;* lmx 306 system/sepolicy/public/vold.te
17266
17267(neverallow base_typeattr_608 vold_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
17268;;* lme
17269
17270;;* lmx 312 system/sepolicy/public/vold.te
17271
17272(neverallow base_typeattr_337 vold_metadata_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
17273;;* lme
17274
17275;;* lmx 319 system/sepolicy/public/vold.te
17276
17277(neverallow base_typeattr_609 vold_data_file (file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
17278(neverallow base_typeattr_609 vold_data_file (lnk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17279(neverallow base_typeattr_609 vold_data_file (sock_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17280(neverallow base_typeattr_609 vold_data_file (fifo_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17281;;* lme
17282
17283;;* lmx 326 system/sepolicy/public/vold.te
17284
17285(neverallow base_typeattr_608 vold_metadata_file (file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
17286(neverallow base_typeattr_608 vold_metadata_file (lnk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17287(neverallow base_typeattr_608 vold_metadata_file (sock_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17288(neverallow base_typeattr_608 vold_metadata_file (fifo_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17289;;* lme
17290
17291;;* lmx 334 system/sepolicy/public/vold.te
17292
17293(neverallow base_typeattr_610 vold_metadata_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
17294(neverallow base_typeattr_610 vold_metadata_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17295(neverallow base_typeattr_610 vold_metadata_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17296(neverallow base_typeattr_610 vold_metadata_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17297(neverallow base_typeattr_610 vold_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
17298(neverallow base_typeattr_610 vold_data_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17299(neverallow base_typeattr_610 vold_data_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17300(neverallow base_typeattr_610 vold_data_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
17301;;* lme
17302
17303;;* lmx 336 system/sepolicy/public/vold.te
17304
17305(neverallow base_typeattr_337 restorecon_prop (property_service (set)))
17306;;* lme
17307
17308;;* lmx 349 system/sepolicy/public/vold.te
17309
17310(neverallow vold base_typeattr_611 (binder (call)))
17311;;* lme
17312
17313;;* lmx 351 system/sepolicy/public/vold.te
17314
17315(neverallow vold fsck_exec (file (execute_no_trans)))
17316;;* lme
17317
17318;;* lmx 352 system/sepolicy/public/vold.te
17319
17320(neverallow base_typeattr_223 vold (process (transition dyntransition)))
17321;;* lme
17322
17323;;* lmx 353 system/sepolicy/public/vold.te
17324
17325(neverallow vold base_typeattr_224 (process (ptrace)))
17326;;* lme
17327
17328;;* lmx 354 system/sepolicy/public/vold.te
17329
17330(neverallow vold base_typeattr_224 (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
17331;;* lme
17332
17333(allow watchdogd watchdog_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17334(allow watchdogd kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17335(allow wificond servicemanager (binder (call transfer)))
17336(allow servicemanager wificond (binder (call transfer)))
17337(allow servicemanager wificond (dir (search)))
17338(allow servicemanager wificond (file (read open)))
17339(allow servicemanager wificond (process (getattr)))
17340(allow wificond system_server (binder (call transfer)))
17341(allow system_server wificond (binder (transfer)))
17342(allow wificond system_server (fd (use)))
17343(allow wificond keystore (binder (call transfer)))
17344(allow keystore wificond (binder (transfer)))
17345(allow wificond keystore (fd (use)))
17346(allow wificond wifinl80211_service (service_manager (add find)))
17347;;* lmx 9 system/sepolicy/public/wificond.te
17348
17349(neverallow base_typeattr_612 wifinl80211_service (service_manager (add)))
17350;;* lme
17351
17352(allow wificond self (udp_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
17353(allowx wificond self (ioctl udp_socket (0x8914 0x8924)))
17354(allow wificond self (capability (net_admin net_raw)))
17355(allow wificond self (cap_userns (net_admin net_raw)))
17356(allow wificond self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
17357(allow wificond self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
17358(allow wificond proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
17359(allow wificond proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
17360(allow wificond proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17361(allow wificond permission_service (service_manager (find)))
17362(allow wificond dumpstate (fd (use)))
17363(allow wificond dumpstate (fifo_file (write)))
17364(allow wificond hwservicemanager (binder (call transfer)))
17365(allow hwservicemanager wificond (binder (call transfer)))
17366(allow hwservicemanager wificond (dir (search)))
17367(allow hwservicemanager wificond (file (read map open)))
17368(allow hwservicemanager wificond (process (getattr)))
17369(allow wificond system_wifi_keystore_hwservice (hwservice_manager (add find)))
17370(allow wificond hidl_base_hwservice (hwservice_manager (add)))
17371;;* lmx 34 system/sepolicy/public/wificond.te
17372
17373(neverallow base_typeattr_612 system_wifi_keystore_hwservice (hwservice_manager (add)))
17374;;* lme
17375
17376(allow wificond keystore_service (service_manager (find)))
17377(allow wificond wifi_key (keystore2_key (get_info use)))
17378;;* lmx 1 system/sepolicy/private/attributes
17379
17380(neverallow base_typeattr_613 domain (process (fork)))
17381;;* lme
17382
17383;;* lmx 1 system/sepolicy/private/attributes
17384
17385(neverallow base_typeattr_614 domain (process (fork)))
17386;;* lme
17387
17388;;* lmx 1 system/sepolicy/private/attributes
17389
17390(neverallow base_typeattr_615 domain (process (fork)))
17391;;* lme
17392
17393(allow init aconfigd_exec (file (read getattr map execute open)))
17394(allow init aconfigd (process (transition)))
17395(allow aconfigd aconfigd_exec (file (read getattr map execute open entrypoint)))
17396(dontaudit init aconfigd (process (noatsecure)))
17397(allow init aconfigd (process (siginh rlimitinh)))
17398(typetransition init aconfigd_exec process aconfigd)
17399;;* lmx 10 system/sepolicy/private/aconfigd.te
17400
17401(neverallow base_typeattr_223 aconfigd (process (transition)))
17402;;* lme
17403
17404;;* lmx 11 system/sepolicy/private/aconfigd.te
17405
17406(neverallow base_typeattr_224 aconfigd (process (dyntransition)))
17407;;* lme
17408
17409(allow aconfigd metadata_file (dir (search)))
17410(allow aconfigd aconfig_storage_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17411(allow aconfigd aconfig_storage_flags_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17412(allow aconfigd aconfig_storage_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17413(allow aconfigd aconfig_storage_flags_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17414(allow aconfigd aconfigd_socket (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
17415(allow aconfigd kmsg_device (chr_file (write lock append map open)))
17416(allow aconfigd system_aconfig_storage_file (file (ioctl read getattr lock map open watch watch_reads)))
17417(allow aconfigd system_aconfig_storage_file (dir (ioctl read getattr lock open watch watch_reads search)))
17418(allow aconfigd vendor_aconfig_storage_file (file (ioctl read getattr lock map open watch watch_reads)))
17419(allow aconfigd vendor_aconfig_storage_file (dir (ioctl read getattr lock open watch watch_reads search)))
17420(allow init adbd_exec (file (read getattr map execute open)))
17421(allow init adbd (process (transition)))
17422(allow adbd adbd_exec (file (read getattr map execute open entrypoint)))
17423(dontaudit init adbd (process (noatsecure)))
17424(allow init adbd (process (siginh rlimitinh)))
17425(typetransition init adbd_exec process adbd)
17426(allow adbd shell_exec (file (read getattr map execute open)))
17427(allow adbd shell (process (transition)))
17428(allow shell shell_exec (file (read getattr map execute open entrypoint)))
17429(allow shell adbd (process (sigchld)))
17430(dontaudit adbd shell (process (noatsecure)))
17431(allow adbd shell (process (siginh rlimitinh)))
17432(typetransition adbd shell_exec process shell)
17433(allow adbd traced_consumer_socket (sock_file (write)))
17434(allow adbd traced (unix_stream_socket (connectto)))
17435(allow adbd shell (process (signal noatsecure)))
17436(allow adbd self (capability (setgid setuid)))
17437(allow adbd self (cap_userns (setgid setuid)))
17438(allow adbd self (capability (setpcap)))
17439(allow adbd self (cap_userns (setpcap)))
17440(dontaudit adbd self (capability (sys_resource)))
17441(dontaudit adbd self (cap_userns (sys_resource)))
17442(dontaudit adbd self (socket (create)))
17443(dontaudit adbd self (vsock_socket (create)))
17444(allow adbd self (vsock_socket (read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
17445(allow adbd mdnsd_socket (sock_file (write)))
17446(allow adbd mdnsd (unix_stream_socket (connectto)))
17447(allow adbd functionfs (dir (search)))
17448(allow adbd functionfs (file (ioctl read write getattr lock append map open watch watch_reads)))
17449(allowx adbd functionfs (ioctl file (0x6703 0x6782)))
17450(allow adbd devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17451(allow adbd shell_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17452(allow adbd shell_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17453(allow adbd trace_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17454(allow adbd trace_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17455(allow adbd profman_dump_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17456(allow adbd profman_dump_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17457(allow adbd tmpfs (dir (search)))
17458(allow adbd rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17459(allow adbd tmpfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17460(allow adbd sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17461(allow adbd fuse (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17462(allow adbd sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17463(allow adbd fuse (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17464(allow adbd anr_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17465(allow adbd anr_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17466(allow adbd vendor_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
17467(allow adbd vendor_framework_file (file (ioctl read getattr lock map open watch watch_reads)))
17468(allow adbd property_socket (sock_file (write)))
17469(allow adbd init (unix_stream_socket (connectto)))
17470(allow adbd shell_prop (property_service (set)))
17471(allow adbd shell_prop (file (read getattr map open)))
17472(allow adbd property_socket (sock_file (write)))
17473(allow adbd init (unix_stream_socket (connectto)))
17474(allow adbd powerctl_prop (property_service (set)))
17475(allow adbd powerctl_prop (file (read getattr map open)))
17476(allow adbd ffs_config_prop (file (read getattr map open)))
17477(allow adbd property_socket (sock_file (write)))
17478(allow adbd init (unix_stream_socket (connectto)))
17479(allow adbd ffs_control_prop (property_service (set)))
17480(allow adbd ffs_control_prop (file (read getattr map open)))
17481(allow adbd property_socket (sock_file (write)))
17482(allow adbd init (unix_stream_socket (connectto)))
17483(allow adbd adbd_prop (property_service (set)))
17484(allow adbd adbd_prop (file (read getattr map open)))
17485(allow adbd property_socket (sock_file (write)))
17486(allow adbd init (unix_stream_socket (connectto)))
17487(allow adbd adbd_config_prop (property_service (set)))
17488(allow adbd adbd_config_prop (file (read getattr map open)))
17489(allow adbd property_socket (sock_file (write)))
17490(allow adbd init (unix_stream_socket (connectto)))
17491(allow adbd ctl_mdnsd_prop (property_service (set)))
17492(allow adbd ctl_mdnsd_prop (file (read getattr map open)))
17493(allow adbd device_logging_prop (file (read getattr map open)))
17494(allow adbd serialno_prop (file (read getattr map open)))
17495(allow adbd test_harness_prop (file (read getattr map open)))
17496(allow adbd system_adbd_prop (file (read getattr map open)))
17497(allow adbd system_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17498(allow adbd servicemanager (binder (call transfer)))
17499(allow servicemanager adbd (binder (call transfer)))
17500(allow servicemanager adbd (dir (search)))
17501(allow servicemanager adbd (file (read open)))
17502(allow servicemanager adbd (process (getattr)))
17503(allow adbd surfaceflinger (binder (call transfer)))
17504(allow surfaceflinger adbd (binder (transfer)))
17505(allow adbd surfaceflinger (fd (use)))
17506(allow adbd gpuservice (binder (call transfer)))
17507(allow gpuservice adbd (binder (transfer)))
17508(allow adbd gpuservice (fd (use)))
17509(allow adbd gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17510(allow adbd gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
17511(allow adbd ion_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17512(allow adbd system_file (dir (ioctl read getattr lock open watch watch_reads search)))
17513(allow adbd system_file (file (ioctl read getattr lock map open watch watch_reads)))
17514(allow adbd system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17515(allow adbd adb_keys_file (dir (search)))
17516(allow adbd adb_keys_file (file (ioctl read getattr lock map open watch watch_reads)))
17517(allow adbd app_data_file (dir (search)))
17518(allow adbd app_data_file (sock_file (write)))
17519(allow adbd appdomain (unix_stream_socket (connectto)))
17520(allow adbd zygote_exec (file (ioctl read getattr lock map open watch watch_reads)))
17521(allow adbd system_file (file (ioctl read getattr lock map open watch watch_reads)))
17522(allow adbd selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
17523(allow adbd selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
17524(allow adbd kernel (security (read_policy)))
17525(allow adbd service_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17526(allow adbd file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17527(allow adbd seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17528(allow adbd property_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17529(allow adbd sepolicy_file (file (ioctl read getattr lock map open watch watch_reads)))
17530(allow adbd config_gz (file (ioctl read getattr lock map open watch watch_reads)))
17531(allow adbd proc_net_tcp_udp (file (ioctl read getattr lock map open watch watch_reads)))
17532(allow adbd gpu_service (service_manager (find)))
17533(allow adbd surfaceflinger_service (service_manager (find)))
17534(allow adbd bootchart_data_file (dir (search)))
17535(allow adbd bootchart_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17536(allow adbd storage_file (dir (ioctl read getattr lock open watch watch_reads search)))
17537(allow adbd storage_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17538(allow adbd mnt_user_file (dir (ioctl read getattr lock open watch watch_reads search)))
17539(allow adbd mnt_user_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17540(allow adbd media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17541(allow adbd media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17542(allow adbd apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17543(allow adbd apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17544(allow adbd apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17545(allow adbd rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
17546(allow adbd perfetto (process (signal)))
17547(allow adbd perfetto_traces_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17548(allow adbd perfetto_traces_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17549(allow adbd perfetto_configs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
17550(allow adbd perfetto_configs_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17551(allow adbd shell (unix_stream_socket (read write shutdown)))
17552(allow adbd shell (fd (use)))
17553(allow adbd vendor_apex_file (dir (search)))
17554(allow adbd vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
17555(allow adbd apex_data_file (dir (search)))
17556(allow adbd staging_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17557(allow adbd apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
17558(allow adbd tombstone_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17559(allow adbd tombstone_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17560;;* lmx 240 system/sepolicy/private/adbd.te
17561
17562(neverallow adbd base_typeattr_616 (process (transition)))
17563;;* lme
17564
17565;;* lmx 241 system/sepolicy/private/adbd.te
17566
17567(neverallow adbd domain (process (dyntransition)))
17568;;* lme
17569
17570(allow init apexd_exec (file (read getattr map execute open)))
17571(allow init apexd (process (transition)))
17572(allow apexd apexd_exec (file (read getattr map execute open entrypoint)))
17573(dontaudit init apexd (process (noatsecure)))
17574(allow init apexd (process (siginh rlimitinh)))
17575(typetransition init apexd_exec process apexd)
17576(allow apexd apex_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17577(allow apexd apex_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17578(allow apexd apex_data_file (file (relabelfrom)))
17579(allow apexd metadata_file (dir (search)))
17580(allow apexd apex_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17581(allow apexd apex_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17582(allow apexd apex_ota_reserved_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17583(allow apexd apex_ota_reserved_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17584(allow apexd apex_data_file_type (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
17585(allow apexd apex_data_file_type (file (ioctl read write create getattr setattr lock relabelto append map unlink rename open watch watch_reads)))
17586(allow apexd apex_module_data_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
17587(allow apexd apex_module_data_file (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
17588(allow apexd apex_rollback_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17589(allow apexd apex_rollback_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17590(allow apexd system_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17591(allow apexd system_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
17592(allow apexd loop_control_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17593(allow apexd loop_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17594(allowx apexd loop_device (ioctl blk_file (0x1261)))
17595(allowx apexd loop_device (ioctl blk_file ((range 0x4c00 0x4c01) (range 0x4c04 0x4c05) (range 0x4c08 0x4c0a))))
17596(allow apexd dev_type (dir (ioctl read getattr lock open watch watch_reads search)))
17597(allow apexd dev_type (blk_file (getattr)))
17598(allow apexd vd_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
17599(allow apexd dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17600(allow apexd dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
17601(allow apexd self (capability (chown dac_override dac_read_search fowner sys_admin)))
17602(allow apexd self (cap_userns (chown dac_override dac_read_search fowner sys_admin)))
17603(dontaudit apexd self (capability (fsetid)))
17604(dontaudit apexd self (cap_userns (fsetid)))
17605(allow apexd apex_mnt_dir (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17606(allow apexd apex_mnt_dir (filesystem (mount unmount)))
17607(allow apexd apex_mnt_dir (dir (mounton)))
17608(allow apexd apex_mnt_dir (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17609(allow apexd apex_mnt_dir (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename mounton open watch watch_reads)))
17610(allow apexd apex_info_file (file (relabelto)))
17611(allow apexd apex_info_file (file (ioctl read write getattr lock append map open watch watch_reads)))
17612(allow apexd staging_data_file (file (unlink)))
17613(allow apexd staging_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17614(allow apexd staging_data_file (file (ioctl read getattr lock map link open watch watch_reads)))
17615(allow apexd staging_data_file (file (relabelto)))
17616(allow apexd vendor_apex_file (dir (ioctl read getattr lock open watch watch_reads search)))
17617(allow apexd vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
17618(allow apexd vendor_apex_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17619(allow apexd vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
17620(allow apexd vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
17621(allow apexd vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17622(allow apexd labeledfs (filesystem (mount unmount)))
17623(allow apexd sysfs_type (dir (search)))
17624(allow apexd sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
17625(allow apexd sysfs_type (file (ioctl read getattr lock map open watch watch_reads)))
17626(allow apexd sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
17627(allow apexd sysfs_dm (file (ioctl read write getattr lock append map open watch watch_reads)))
17628(allow apexd sysfs_loop (dir (ioctl read getattr lock open watch watch_reads search)))
17629(allow apexd sysfs_loop (file (ioctl read write getattr lock append map open watch watch_reads)))
17630(allow apexd kmsg_device (chr_file (write lock append map open)))
17631(allow apexd property_socket (sock_file (write)))
17632(allow apexd init (unix_stream_socket (connectto)))
17633(allow apexd powerctl_prop (property_service (set)))
17634(allow apexd powerctl_prop (file (read getattr map open)))
17635(allow apexd property_socket (sock_file (write)))
17636(allow apexd init (unix_stream_socket (connectto)))
17637(allow apexd ctl_apexd_prop (property_service (set)))
17638(allow apexd ctl_apexd_prop (file (read getattr map open)))
17639(allow apexd property_socket (sock_file (write)))
17640(allow apexd init (unix_stream_socket (connectto)))
17641(allow apexd ctl_apex_load_prop (property_service (set)))
17642(allow apexd ctl_apex_load_prop (file (read getattr map open)))
17643(allow apexd vold_service (service_manager (find)))
17644(allow apexd vold (binder (call transfer)))
17645(allow vold apexd (binder (transfer)))
17646(allow apexd vold (fd (use)))
17647(allow apexd system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
17648(allow apexd system_bootstrap_lib_file (file (read getattr map execute open)))
17649(allow apexd devpts (chr_file (read write)))
17650(typetransition apexd devpts chr_file apexd_devpts)
17651(allow apexd apexd_devpts (chr_file (ioctl read write getattr open)))
17652(allowx apexd apexd_devpts (ioctl chr_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
17653;;* lmx 141 system/sepolicy/private/apexd.te
17654
17655(neverallowx base_typeattr_224 apexd_devpts (ioctl chr_file (0x5412)))
17656;;* lme
17657
17658(allow apexd file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
17659(allow apexd toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17660(allowx apexd staging_data_file (ioctl file (0x6601)))
17661(allowx apexd staging_data_file (ioctl file (0xf512)))
17662(allow apexd cold_boot_done_prop (file (read getattr map open)))
17663(allow apexd apexd_config_prop (file (read getattr map open)))
17664(allow apexd apexd_select_prop (file (read getattr map open)))
17665(allow apexd apexd_payload_metadata_prop (file (read getattr map open)))
17666;;* lmx 169 system/sepolicy/private/apexd.te
17667
17668(neverallow base_typeattr_617 apex_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
17669;;* lme
17670
17671;;* lmx 170 system/sepolicy/private/apexd.te
17672
17673(neverallow base_typeattr_617 apex_metadata_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
17674;;* lme
17675
17676;;* lmx 171 system/sepolicy/private/apexd.te
17677
17678(neverallow base_typeattr_618 apex_data_file (file (write create setattr relabelfrom append unlink link rename)))
17679;;* lme
17680
17681;;* lmx 172 system/sepolicy/private/apexd.te
17682
17683(neverallow base_typeattr_618 apex_metadata_file (file (write create setattr relabelfrom append unlink link rename)))
17684;;* lme
17685
17686;;* lmx 173 system/sepolicy/private/apexd.te
17687
17688(neverallow base_typeattr_225 apex_mnt_dir (lnk_file (write create setattr relabelfrom append unlink link rename)))
17689;;* lme
17690
17691;;* lmx 175 system/sepolicy/private/apexd.te
17692
17693(neverallow base_typeattr_619 apex_module_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
17694;;* lme
17695
17696;;* lmx 176 system/sepolicy/private/apexd.te
17697
17698(neverallow base_typeattr_619 apex_module_data_file (file (write create setattr relabelfrom append unlink link rename)))
17699;;* lme
17700
17701;;* lmx 178 system/sepolicy/private/apexd.te
17702
17703(neverallow base_typeattr_619 apex_rollback_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
17704;;* lme
17705
17706;;* lmx 179 system/sepolicy/private/apexd.te
17707
17708(neverallow base_typeattr_619 apex_rollback_data_file (file (write create setattr relabelfrom append unlink link rename)))
17709;;* lme
17710
17711(allow apexd property_socket (sock_file (write)))
17712(allow apexd init (unix_stream_socket (connectto)))
17713(allow apexd apexd_prop (property_service (set)))
17714(allow apexd apexd_prop (file (read getattr map open)))
17715;;* lmx 183 system/sepolicy/private/apexd.te
17716
17717(neverallow base_typeattr_617 apexd_prop (property_service (set)))
17718;;* lme
17719
17720;;* lmx 186 system/sepolicy/private/apexd.te
17721
17722(neverallow base_typeattr_225 apex_info_file (file (write create setattr relabelfrom append unlink link rename)))
17723;;* lme
17724
17725;;* lmx 192 system/sepolicy/private/apexd.te
17726
17727(neverallow base_typeattr_620 apex_mnt_dir (filesystem (mount unmount)))
17728;;* lme
17729
17730;;* lmx 193 system/sepolicy/private/apexd.te
17731
17732(neverallow base_typeattr_620 apex_mnt_dir (dir (mounton)))
17733;;* lme
17734
17735(allow apexd otapreopt_chroot (fd (use)))
17736(allow apexd postinstall_apex_mnt_dir (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
17737(allow apexd postinstall_apex_mnt_dir (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
17738(allow apexd postinstall_apex_mnt_dir (lnk_file (create)))
17739(allow apexd proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
17740(allow apexd derive_classpath_exec (file (read getattr map execute open)))
17741(allow apexd apexd_derive_classpath (process (transition)))
17742(allow apexd_derive_classpath derive_classpath_exec (file (read getattr map execute open entrypoint)))
17743(allow apexd_derive_classpath apexd (process (sigchld)))
17744(dontaudit apexd apexd_derive_classpath (process (noatsecure)))
17745(allow apexd apexd_derive_classpath (process (siginh rlimitinh)))
17746(typetransition apexd derive_classpath_exec process apexd_derive_classpath)
17747(allow apexd property_socket (sock_file (write)))
17748(allow apexd init (unix_stream_socket (connectto)))
17749(allow apexd apex_ready_prop (property_service (set)))
17750(allow apexd apex_ready_prop (file (read getattr map open)))
17751(allow apexd_derive_classpath apexd (fd (use)))
17752(allow apexd_derive_classpath apex_mnt_dir (file (write open)))
17753(allow apexd_derive_classpath apexd_devpts (chr_file (read write)))
17754(allow base_typeattr_621 proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
17755(allow base_typeattr_621 proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
17756(allow base_typeattr_621 proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17757(allow appdomain test_harness_prop (file (read getattr map open)))
17758(allow appdomain boot_status_prop (file (read getattr map open)))
17759(allow appdomain dalvik_config_prop_type (file (read getattr map open)))
17760(allow appdomain media_config_prop (file (read getattr map open)))
17761(allow appdomain packagemanager_config_prop (file (read getattr map open)))
17762(allow appdomain radio_control_prop (file (read getattr map open)))
17763(allow appdomain surfaceflinger_color_prop (file (read getattr map open)))
17764(allow appdomain systemsound_config_prop (file (read getattr map open)))
17765(allow appdomain telephony_config_prop (file (read getattr map open)))
17766(allow appdomain userspace_reboot_config_prop (file (read getattr map open)))
17767(allow appdomain vold_config_prop (file (read getattr map open)))
17768(allow appdomain adbd_config_prop (file (read getattr map open)))
17769(allow appdomain dck_prop (file (read getattr map open)))
17770(allow appdomain persist_wm_debug_prop (file (read getattr map open)))
17771(allow appdomain persist_sysui_builder_extras_prop (file (read getattr map open)))
17772(allow appdomain persist_sysui_ranking_update_prop (file (read getattr map open)))
17773(allow appdomain traced_oome_heap_session_count_prop (file (read getattr map open)))
17774(allow appdomain camera2_extensions_prop (file (read getattr map open)))
17775(allow appdomain camerax_extensions_prop (file (read getattr map open)))
17776(dontaudit appdomain storage_stub_file (dir (getattr)))
17777(dontaudit appdomain system_data_file (dir (write)))
17778(dontaudit appdomain vendor_default_prop (file (read)))
17779(allow base_typeattr_622 mnt_media_rw_file (dir (search)))
17780(allow appdomain system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
17781;;* lmx 89 system/sepolicy/private/app.te
17782
17783(neverallow appdomain system_server (udp_socket (ioctl create setattr lock relabelfrom relabelto append bind listen accept shutdown name_bind)))
17784;;* lme
17785
17786;;* lmx 98 system/sepolicy/private/app.te
17787
17788(neverallow base_typeattr_235 base_typeattr_623 (process (transition)))
17789;;* lme
17790
17791;;* lmx 100 system/sepolicy/private/app.te
17792
17793(neverallow base_typeattr_235 base_typeattr_233 (process (dyntransition)))
17794;;* lme
17795
17796;;* lmx 103 system/sepolicy/private/app.te
17797
17798(neverallow base_typeattr_624 storage_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
17799;;* lme
17800
17801(dontaudit appdomain system_font_fallback_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
17802;;* lmx 107 system/sepolicy/private/app.te
17803
17804(neverallow appdomain system_font_fallback_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
17805;;* lme
17806
17807(allow appdomain sendbug_config_prop (file (read getattr map open)))
17808(allow appdomain graphics_config_prop (file (read getattr map open)))
17809(allow appdomain camera_calibration_prop (file (read getattr map open)))
17810(allow appdomain sqlite_log_prop (file (read getattr map open)))
17811(allow appdomain font_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17812(allow appdomain font_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17813(allow appdomain apex_module_data_file (dir (search)))
17814(allow appdomain apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17815(allow appdomain apex_art_data_file (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17816(allow appdomain tombstone_data_file (file (read getattr)))
17817;;* lmx 137 system/sepolicy/private/app.te
17818
17819(neverallow base_typeattr_235 tombstone_data_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
17820;;* lme
17821
17822(allow base_typeattr_625 shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17823(allow base_typeattr_625 toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17824(allow base_typeattr_625 vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
17825(allow base_typeattr_625 vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
17826(allow base_typeattr_625 vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17827(allow base_typeattr_625 vendor_app_file (file (execute)))
17828(allow base_typeattr_626 vendor_microdroid_file (dir (ioctl read getattr lock open watch watch_reads search)))
17829(allow base_typeattr_626 vendor_microdroid_file (file (ioctl read getattr lock map open watch watch_reads)))
17830(allow base_typeattr_626 vendor_microdroid_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17831(allow appdomain sdk_sandbox_all (binder (call transfer)))
17832(allow sdk_sandbox_all appdomain (binder (transfer)))
17833(allow appdomain sdk_sandbox_all (fd (use)))
17834(allow appdomain virtual_camera (binder (call transfer)))
17835(allow virtual_camera appdomain (binder (transfer)))
17836(allow appdomain virtual_camera (fd (use)))
17837(allow base_typeattr_626 storage_file (dir (ioctl read getattr lock open watch watch_reads search)))
17838(allow base_typeattr_626 storage_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17839(allow base_typeattr_626 mnt_user_file (dir (ioctl read getattr lock open watch watch_reads search)))
17840(allow base_typeattr_626 mnt_user_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17841(allow base_typeattr_626 sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17842(allow base_typeattr_626 fuse (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17843(allow base_typeattr_626 sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17844(allow base_typeattr_626 fuse (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17845(allow base_typeattr_626 media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17846(allow base_typeattr_626 media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17847(allow base_typeattr_626 usb_device (chr_file (ioctl read write getattr)))
17848(allow base_typeattr_626 usbaccessory_device (chr_file (read write getattr)))
17849(allow base_typeattr_625 logd_socket (sock_file (write)))
17850(allow base_typeattr_625 logd (unix_stream_socket (connectto)))
17851(allow base_typeattr_626 keystore (keystore2_key (delete get_info rebind update use)))
17852(allow base_typeattr_626 keystore_maintenance_service (service_manager (find)))
17853(allow keystore base_typeattr_626 (dir (search)))
17854(allow keystore base_typeattr_626 (file (read open)))
17855(allow keystore base_typeattr_626 (process (getattr)))
17856(allow base_typeattr_626 apc_service (service_manager (find)))
17857(allow base_typeattr_626 keystore_service (service_manager (find)))
17858(allow base_typeattr_626 legacykeystore_service (service_manager (find)))
17859(allow base_typeattr_626 keystore (binder (call transfer)))
17860(allow keystore base_typeattr_626 (binder (transfer)))
17861(allow base_typeattr_626 keystore (fd (use)))
17862(allow keystore base_typeattr_626 (binder (call transfer)))
17863(allow base_typeattr_626 keystore (binder (transfer)))
17864(allow keystore base_typeattr_626 (fd (use)))
17865(allow credstore base_typeattr_626 (dir (search)))
17866(allow credstore base_typeattr_626 (file (read open)))
17867(allow credstore base_typeattr_626 (process (getattr)))
17868(allow base_typeattr_626 credstore_service (service_manager (find)))
17869(allow base_typeattr_626 credstore (binder (call transfer)))
17870(allow credstore base_typeattr_626 (binder (transfer)))
17871(allow base_typeattr_626 credstore (fd (use)))
17872(allow credstore base_typeattr_626 (binder (call transfer)))
17873(allow base_typeattr_626 credstore (binder (transfer)))
17874(allow credstore base_typeattr_626 (fd (use)))
17875(allow base_typeattr_626 pdx_display_client_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
17876(allow base_typeattr_626 pdx_display_client_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
17877(allow base_typeattr_626 pdx_display_client_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
17878(allow base_typeattr_626 pdx_display_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
17879(allow base_typeattr_626 pdx_display_client_server_type (fd (use)))
17880(allow pdx_display_client_server_type base_typeattr_626 (fd (use)))
17881(allow base_typeattr_626 pdx_display_manager_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
17882(allow base_typeattr_626 pdx_display_manager_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
17883(allow base_typeattr_626 pdx_display_manager_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
17884(allow base_typeattr_626 pdx_display_manager_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
17885(allow base_typeattr_626 pdx_display_manager_server_type (fd (use)))
17886(allow pdx_display_manager_server_type base_typeattr_626 (fd (use)))
17887(allow base_typeattr_626 pdx_display_vsync_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
17888(allow base_typeattr_626 pdx_display_vsync_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
17889(allow base_typeattr_626 pdx_display_vsync_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
17890(allow base_typeattr_626 pdx_display_vsync_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
17891(allow base_typeattr_626 pdx_display_vsync_server_type (fd (use)))
17892(allow pdx_display_vsync_server_type base_typeattr_626 (fd (use)))
17893(allow base_typeattr_626 pdx_performance_client_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
17894(allow base_typeattr_626 pdx_performance_client_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
17895(allow base_typeattr_626 pdx_performance_client_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
17896(allow base_typeattr_626 pdx_performance_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
17897(allow base_typeattr_626 pdx_performance_client_server_type (fd (use)))
17898(allow pdx_performance_client_server_type base_typeattr_626 (fd (use)))
17899(allow base_typeattr_626 pdx_bufferhub_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
17900(allow base_typeattr_626 pdx_bufferhub_client_server_type (fd (use)))
17901(allow pdx_bufferhub_client_server_type base_typeattr_626 (fd (use)))
17902(allow base_typeattr_626 tun_device (chr_file (ioctl read write getattr append)))
17903(allowx base_typeattr_626 tun_device (ioctl chr_file (0x54d2)))
17904(allow appdomain self (process (execmem)))
17905(allow appdomain ashmem_device (chr_file (execute)))
17906(allow appdomain ashmem_libcutils_device (chr_file (execute)))
17907(allow appdomain zygote (fd (use)))
17908(allow appdomain app_zygote (fd (use)))
17909(allow appdomain zygote_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17910(allow appdomain zygote (process (sigchld)))
17911(allow appdomain dalvikcache_data_file (dir (getattr search)))
17912(allow appdomain dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17913(allow base_typeattr_627 rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17914(allow base_typeattr_627 tmpfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17915(allow base_typeattr_622 tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
17916(allow appdomain zygote (fifo_file (write)))
17917(allow appdomain shell (process (sigchld)))
17918(allow appdomain adbd (process (sigchld)))
17919(allow appdomain devpts (chr_file (ioctl read write getattr)))
17920(allow appdomain system_server (fd (use)))
17921(allow appdomain system_server (fifo_file (ioctl read write getattr lock append map open watch watch_reads)))
17922(allow appdomain system_server (unix_stream_socket (read write getattr getopt setopt shutdown)))
17923(allow appdomain system_server (tcp_socket (read write getattr getopt shutdown)))
17924(allow appdomain vold (fd (use)))
17925(allow appdomain appdomain (fifo_file (ioctl read write getattr lock append map open watch watch_reads)))
17926(allow appdomain surfaceflinger (unix_stream_socket (read write getattr getopt setopt shutdown)))
17927(allow base_typeattr_628 app_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17928(allow base_typeattr_628 privapp_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
17929(allow base_typeattr_628 app_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17930(allow base_typeattr_628 privapp_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17931(allowx base_typeattr_628 app_data_file (ioctl file (0x6686)))
17932(allowx base_typeattr_628 privapp_data_file (ioctl file (0x6686)))
17933(allow base_typeattr_627 app_data_file (file (read write getattr map)))
17934(allow base_typeattr_627 privapp_data_file (file (read write getattr map)))
17935(allow base_typeattr_627 system_app_data_file (file (read write getattr map)))
17936(allow appdomain sdk_sandbox_data_file (file (read getattr)))
17937(allow appdomain mnt_expand_file (dir (ioctl read getattr lock open watch watch_reads search)))
17938(allow appdomain keychain_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17939(allow appdomain keychain_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17940(allow appdomain keychain_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17941(allow appdomain misc_user_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17942(allow appdomain misc_user_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17943(allow base_typeattr_382 textclassifier_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
17944(allow base_typeattr_382 textclassifier_data_file (file (ioctl read getattr lock map open watch watch_reads)))
17945(allow base_typeattr_382 textclassifier_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17946(allow appdomain oemfs (dir (ioctl read getattr lock open watch watch_reads search)))
17947(allow appdomain oemfs (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
17948(allow appdomain system_file (file (getattr map execute execute_no_trans)))
17949(allow appdomain system_file (dir (ioctl read getattr lock open watch watch_reads search)))
17950(allow appdomain system_file (lnk_file (read getattr open)))
17951(allow base_typeattr_382 vendor_file (dir (read open)))
17952(allow appdomain vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
17953(allow appdomain vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
17954(allow appdomain vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17955(allow appdomain vendor_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
17956(allow appdomain vendor_framework_file (file (ioctl read getattr lock map open watch watch_reads)))
17957(allow appdomain vendor_framework_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
17958(allow appdomain vendor_public_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
17959(allow appdomain vendor_public_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
17960(allow appdomain vendor_public_lib_file (file (read getattr map execute open)))
17961(allow appdomain vendor_public_framework_file (file (read getattr map execute open)))
17962(allow appdomain wallpaper_file (file (read write getattr map)))
17963(allow appdomain ringtone_file (file (read write getattr map)))
17964(allow appdomain shortcut_manager_icons (file (read getattr map)))
17965(allow appdomain icon_file (file (read getattr map)))
17966(allow appdomain anr_data_file (dir (search)))
17967(allow appdomain anr_data_file (file (append open)))
17968(allow appdomain tombstoned_java_trace_socket (sock_file (write)))
17969(allow appdomain tombstoned (unix_stream_socket (connectto)))
17970(allow appdomain tombstoned (fd (use)))
17971(allow appdomain dumpstate (fifo_file (append)))
17972(allow appdomain incidentd (fifo_file (append)))
17973(allow appdomain dumpstate (fd (use)))
17974(allow appdomain dumpstate (unix_stream_socket (read write getattr getopt shutdown)))
17975(allow appdomain dumpstate (fifo_file (write getattr)))
17976(allow appdomain shell_data_file (file (write getattr)))
17977(allow appdomain incidentd (fd (use)))
17978(allow appdomain incidentd (fifo_file (write getattr)))
17979(allow appdomain statsdw_socket (sock_file (write)))
17980(allow appdomain statsd (unix_dgram_socket (sendto)))
17981(allow appdomain user_profile_root_file (dir (search)))
17982(allow appdomain user_profile_data_file (dir (write lock open add_name remove_name search)))
17983(allow appdomain user_profile_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
17984(allow appdomain traced (fd (use)))
17985(allow appdomain traced_tmpfs (file (read write getattr map)))
17986(allow appdomain traced_producer_socket (sock_file (write)))
17987(allow appdomain traced (unix_stream_socket (connectto)))
17988(allow traced appdomain (fd (use)))
17989(allow base_typeattr_382 gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
17990(allow base_typeattr_382 gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
17991(allow base_typeattr_382 sysfs_gpu (file (ioctl read getattr lock map open watch watch_reads)))
17992(allow appdomain servicemanager (binder (call transfer)))
17993(allow servicemanager appdomain (binder (call transfer)))
17994(allow servicemanager appdomain (dir (search)))
17995(allow servicemanager appdomain (file (read open)))
17996(allow servicemanager appdomain (process (getattr)))
17997(allow appdomain binderservicedomain (binder (call transfer)))
17998(allow binderservicedomain appdomain (binder (transfer)))
17999(allow appdomain binderservicedomain (fd (use)))
18000(allow appdomain appdomain (binder (call transfer)))
18001(allow appdomain appdomain (binder (transfer)))
18002(allow appdomain appdomain (fd (use)))
18003(allow appdomain ephemeral_app (binder (call transfer)))
18004(allow ephemeral_app appdomain (binder (transfer)))
18005(allow appdomain ephemeral_app (fd (use)))
18006(allow base_typeattr_382 gpuservice (binder (call transfer)))
18007(allow gpuservice base_typeattr_382 (binder (transfer)))
18008(allow base_typeattr_382 gpuservice (fd (use)))
18009(allow appdomain hal_graphics_composer (fd (use)))
18010(allow appdomain appdomain (unix_stream_socket (read write getattr getopt shutdown)))
18011(allow appdomain backup_data_file (file (read write getattr map)))
18012(allow appdomain cache_backup_file (file (read write getattr map)))
18013(allow appdomain cache_backup_file (dir (getattr)))
18014(allow appdomain system_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
18015(allow appdomain system_data_file (file (read getattr map)))
18016(allow base_typeattr_627 media_rw_data_file (file (read getattr)))
18017(allow base_typeattr_382 radio_data_file (file (read write getattr)))
18018(allow appdomain dalvikcache_data_file (file (execute)))
18019(allow appdomain dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
18020(allow appdomain shared_relro_file (dir (search)))
18021(allow appdomain shared_relro_file (file (ioctl read getattr lock map open watch watch_reads)))
18022(allow appdomain apk_data_file (dir (ioctl read getattr lock open search)))
18023(allow appdomain apk_data_file (file (ioctl read getattr lock map execute open execute_no_trans)))
18024(allow appdomain resourcecache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
18025(allow appdomain resourcecache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
18026(allow appdomain logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
18027(allow appdomain logdr_socket (sock_file (write)))
18028(allow appdomain logd (unix_stream_socket (connectto)))
18029(allow appdomain zygote (unix_dgram_socket (write)))
18030(allow appdomain console_device (chr_file (read write)))
18031(allowx base_typeattr_230 self (ioctl tcp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
18032(allowx base_typeattr_230 self (ioctl udp_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
18033(allowx base_typeattr_230 self (ioctl rawip_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
18034(allowx base_typeattr_230 self (ioctl tcp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
18035(allowx base_typeattr_230 self (ioctl udp_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
18036(allowx base_typeattr_230 self (ioctl rawip_socket ((range 0x8906 0x8907) 0x8910 (range 0x8912 0x8913) 0x8915 0x8917 0x8919 0x891b 0x8921 0x8933 0x8938 0x8942)))
18037(allowx base_typeattr_230 self (ioctl tcp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
18038(allowx base_typeattr_230 self (ioctl udp_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
18039(allowx base_typeattr_230 self (ioctl rawip_socket (0x8b01 0x8b05 0x8b07 0x8b09 0x8b0b 0x8b0d 0x8b0f (range 0x8b11 0x8b13) 0x8b21 0x8b23 0x8b25 0x8b27 0x8b29 0x8b2d)))
18040(allow base_typeattr_382 ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
18041(allow base_typeattr_382 dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
18042(allow base_typeattr_382 dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
18043(allow base_typeattr_382 hal_audio (fd (use)))
18044(allow base_typeattr_382 hal_camera (fd (use)))
18045(allow base_typeattr_382 hal_tv_tuner_server (fd (use)))
18046(allow base_typeattr_382 hal_renderscript_hwservice (hwservice_manager (find)))
18047(allow appdomain same_process_hal_file (file (read getattr map execute open)))
18048(allow appdomain proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
18049(allow appdomain app_fuse_file (file (read write getattr append map)))
18050(allow appdomain runas_exec (file (getattr)))
18051(allow appdomain adbd (unix_stream_socket (connectto)))
18052(allow appdomain adbd (fd (use)))
18053(allow appdomain adbd (unix_stream_socket (ioctl read write getattr getopt shutdown)))
18054(allow appdomain cache_file (dir (getattr)))
18055(allow appdomain dropbox_data_file (file (read getattr)))
18056(allow appdomain audioserver_tmpfs (file (read write getattr map)))
18057(allow appdomain system_server_tmpfs (file (read write getattr map)))
18058(allow appdomain zygote_tmpfs (file (read map)))
18059;;* lmx 522 system/sepolicy/private/app.te
18060
18061(neverallow isolated_app_all base_typeattr_629 (file (execute execute_no_trans)))
18062(neverallow bluetooth base_typeattr_629 (file (execute execute_no_trans)))
18063(neverallow nfc base_typeattr_629 (file (execute execute_no_trans)))
18064(neverallow radio base_typeattr_629 (file (execute execute_no_trans)))
18065(neverallow shared_relro base_typeattr_629 (file (execute execute_no_trans)))
18066(neverallow system_app base_typeattr_629 (file (execute execute_no_trans)))
18067(neverallow sdk_sandbox_all base_typeattr_629 (file (execute execute_no_trans)))
18068;;* lme
18069
18070;;* lmx 531 system/sepolicy/private/app.te
18071
18072(neverallow appdomain audio_device (chr_file (read write)))
18073(neverallow appdomain camera_device (chr_file (read write)))
18074(neverallow appdomain dm_device (chr_file (read write)))
18075(neverallow appdomain radio_device (chr_file (read write)))
18076(neverallow appdomain rpmsg_device (chr_file (read write)))
18077;;* lme
18078
18079;;* lmx 538 system/sepolicy/private/app.te
18080
18081(neverallow base_typeattr_630 video_device (chr_file (read write)))
18082;;* lme
18083
18084;;* lmx 550 system/sepolicy/private/app.te
18085
18086(neverallow base_typeattr_631 apk_data_file (dir (watch watch_reads)))
18087;;* lme
18088
18089;;* lmx 558 system/sepolicy/private/app.te
18090
18091(neverallow base_typeattr_631 apk_data_file (file (watch watch_reads)))
18092;;* lme
18093
18094;;* lmx 20 system/sepolicy/private/app_neverallows.te
18095
18096(neverallow untrusted_app_all domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18097(neverallow isolated_app_all domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18098(neverallow ephemeral_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18099(neverallow isolated_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18100(neverallow isolated_compute_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18101(neverallow mediaprovider domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18102(neverallow untrusted_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18103(neverallow untrusted_app_30 domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18104(neverallow untrusted_app_29 domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18105(neverallow untrusted_app_27 domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18106(neverallow untrusted_app_25 domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18107(neverallow mediaprovider_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18108;;* lme
18109
18110;;* lmx 23 system/sepolicy/private/app_neverallows.te
18111
18112(neverallow untrusted_app_all domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18113(neverallow isolated_app_all domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18114(neverallow ephemeral_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18115(neverallow isolated_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18116(neverallow isolated_compute_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18117(neverallow mediaprovider domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18118(neverallow untrusted_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18119(neverallow untrusted_app_30 domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18120(neverallow untrusted_app_29 domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18121(neverallow untrusted_app_27 domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18122(neverallow untrusted_app_25 domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18123(neverallow mediaprovider_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18124;;* lme
18125
18126;;* lmx 26 system/sepolicy/private/app_neverallows.te
18127
18128(neverallow untrusted_app_all kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18129(neverallow isolated_app_all kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18130(neverallow ephemeral_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18131(neverallow isolated_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18132(neverallow isolated_compute_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18133(neverallow mediaprovider kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18134(neverallow untrusted_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18135(neverallow untrusted_app_30 kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18136(neverallow untrusted_app_29 kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18137(neverallow untrusted_app_27 kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18138(neverallow untrusted_app_25 kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18139(neverallow mediaprovider_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18140;;* lme
18141
18142;;* lmx 30 system/sepolicy/private/app_neverallows.te
18143
18144(neverallow untrusted_app_all base_typeattr_632 (file (read)))
18145(neverallow isolated_app_all base_typeattr_632 (file (read)))
18146(neverallow ephemeral_app base_typeattr_632 (file (read)))
18147(neverallow isolated_app base_typeattr_632 (file (read)))
18148(neverallow isolated_compute_app base_typeattr_632 (file (read)))
18149(neverallow mediaprovider base_typeattr_632 (file (read)))
18150(neverallow untrusted_app base_typeattr_632 (file (read)))
18151(neverallow untrusted_app_30 base_typeattr_632 (file (read)))
18152(neverallow untrusted_app_29 base_typeattr_632 (file (read)))
18153(neverallow untrusted_app_27 base_typeattr_632 (file (read)))
18154(neverallow untrusted_app_25 base_typeattr_632 (file (read)))
18155(neverallow mediaprovider_app base_typeattr_632 (file (read)))
18156;;* lme
18157
18158;;* lmx 31 system/sepolicy/private/app_neverallows.te
18159
18160(neverallow untrusted_app_all debugfs_type (file (read)))
18161(neverallow untrusted_app_all debugfs_type (lnk_file (read)))
18162(neverallow isolated_app_all debugfs_type (file (read)))
18163(neverallow isolated_app_all debugfs_type (lnk_file (read)))
18164(neverallow ephemeral_app debugfs_type (file (read)))
18165(neverallow ephemeral_app debugfs_type (lnk_file (read)))
18166(neverallow isolated_app debugfs_type (file (read)))
18167(neverallow isolated_app debugfs_type (lnk_file (read)))
18168(neverallow isolated_compute_app debugfs_type (file (read)))
18169(neverallow isolated_compute_app debugfs_type (lnk_file (read)))
18170(neverallow mediaprovider debugfs_type (file (read)))
18171(neverallow mediaprovider debugfs_type (lnk_file (read)))
18172(neverallow untrusted_app debugfs_type (file (read)))
18173(neverallow untrusted_app debugfs_type (lnk_file (read)))
18174(neverallow untrusted_app_30 debugfs_type (file (read)))
18175(neverallow untrusted_app_30 debugfs_type (lnk_file (read)))
18176(neverallow untrusted_app_29 debugfs_type (file (read)))
18177(neverallow untrusted_app_29 debugfs_type (lnk_file (read)))
18178(neverallow untrusted_app_27 debugfs_type (file (read)))
18179(neverallow untrusted_app_27 debugfs_type (lnk_file (read)))
18180(neverallow untrusted_app_25 debugfs_type (file (read)))
18181(neverallow untrusted_app_25 debugfs_type (lnk_file (read)))
18182(neverallow mediaprovider_app debugfs_type (file (read)))
18183(neverallow mediaprovider_app debugfs_type (lnk_file (read)))
18184;;* lme
18185
18186;;* lmx 36 system/sepolicy/private/app_neverallows.te
18187
18188(neverallow untrusted_app_all service_manager_type (service_manager (add)))
18189(neverallow isolated_app_all service_manager_type (service_manager (add)))
18190(neverallow ephemeral_app service_manager_type (service_manager (add)))
18191(neverallow isolated_app service_manager_type (service_manager (add)))
18192(neverallow isolated_compute_app service_manager_type (service_manager (add)))
18193(neverallow mediaprovider service_manager_type (service_manager (add)))
18194(neverallow untrusted_app service_manager_type (service_manager (add)))
18195(neverallow untrusted_app_30 service_manager_type (service_manager (add)))
18196(neverallow untrusted_app_29 service_manager_type (service_manager (add)))
18197(neverallow untrusted_app_27 service_manager_type (service_manager (add)))
18198(neverallow untrusted_app_25 service_manager_type (service_manager (add)))
18199(neverallow mediaprovider_app service_manager_type (service_manager (add)))
18200;;* lme
18201
18202;;* lmx 39 system/sepolicy/private/app_neverallows.te
18203
18204(neverallow untrusted_app_all vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18205(neverallow isolated_app_all vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18206(neverallow ephemeral_app vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18207(neverallow isolated_app vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18208(neverallow isolated_compute_app vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18209(neverallow mediaprovider vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18210(neverallow untrusted_app vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18211(neverallow untrusted_app_30 vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18212(neverallow untrusted_app_29 vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18213(neverallow untrusted_app_27 vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18214(neverallow untrusted_app_25 vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18215(neverallow mediaprovider_app vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
18216;;* lme
18217
18218;;* lmx 40 system/sepolicy/private/app_neverallows.te
18219
18220(neverallow untrusted_app_all vndservice_manager_type (service_manager (add find list)))
18221(neverallow isolated_app_all vndservice_manager_type (service_manager (add find list)))
18222(neverallow ephemeral_app vndservice_manager_type (service_manager (add find list)))
18223(neverallow isolated_app vndservice_manager_type (service_manager (add find list)))
18224(neverallow isolated_compute_app vndservice_manager_type (service_manager (add find list)))
18225(neverallow mediaprovider vndservice_manager_type (service_manager (add find list)))
18226(neverallow untrusted_app vndservice_manager_type (service_manager (add find list)))
18227(neverallow untrusted_app_30 vndservice_manager_type (service_manager (add find list)))
18228(neverallow untrusted_app_29 vndservice_manager_type (service_manager (add find list)))
18229(neverallow untrusted_app_27 vndservice_manager_type (service_manager (add find list)))
18230(neverallow untrusted_app_25 vndservice_manager_type (service_manager (add find list)))
18231(neverallow mediaprovider_app vndservice_manager_type (service_manager (add find list)))
18232;;* lme
18233
18234;;* lmx 44 system/sepolicy/private/app_neverallows.te
18235
18236(neverallow base_typeattr_633 property_socket (sock_file (write)))
18237;;* lme
18238
18239;;* lmx 45 system/sepolicy/private/app_neverallows.te
18240
18241(neverallow base_typeattr_633 init (unix_stream_socket (connectto)))
18242;;* lme
18243
18244;;* lmx 46 system/sepolicy/private/app_neverallows.te
18245
18246(neverallow base_typeattr_633 property_type (property_service (set)))
18247;;* lme
18248
18249;;* lmx 49 system/sepolicy/private/app_neverallows.te
18250
18251(neverallow untrusted_app_all net_dns_prop (file (read)))
18252(neverallow isolated_app_all net_dns_prop (file (read)))
18253(neverallow ephemeral_app net_dns_prop (file (read)))
18254(neverallow isolated_app net_dns_prop (file (read)))
18255(neverallow isolated_compute_app net_dns_prop (file (read)))
18256(neverallow mediaprovider net_dns_prop (file (read)))
18257(neverallow untrusted_app net_dns_prop (file (read)))
18258(neverallow untrusted_app_30 net_dns_prop (file (read)))
18259(neverallow untrusted_app_29 net_dns_prop (file (read)))
18260(neverallow untrusted_app_27 net_dns_prop (file (read)))
18261(neverallow untrusted_app_25 net_dns_prop (file (read)))
18262(neverallow mediaprovider_app net_dns_prop (file (read)))
18263;;* lme
18264
18265;;* lmx 52 system/sepolicy/private/app_neverallows.te
18266
18267(neverallow untrusted_app_all radio_cdma_ecm_prop (file (read)))
18268(neverallow isolated_app_all radio_cdma_ecm_prop (file (read)))
18269(neverallow ephemeral_app radio_cdma_ecm_prop (file (read)))
18270(neverallow isolated_app radio_cdma_ecm_prop (file (read)))
18271(neverallow isolated_compute_app radio_cdma_ecm_prop (file (read)))
18272(neverallow mediaprovider radio_cdma_ecm_prop (file (read)))
18273(neverallow untrusted_app radio_cdma_ecm_prop (file (read)))
18274(neverallow untrusted_app_30 radio_cdma_ecm_prop (file (read)))
18275(neverallow untrusted_app_29 radio_cdma_ecm_prop (file (read)))
18276(neverallow untrusted_app_27 radio_cdma_ecm_prop (file (read)))
18277(neverallow untrusted_app_25 radio_cdma_ecm_prop (file (read)))
18278(neverallow mediaprovider_app radio_cdma_ecm_prop (file (read)))
18279;;* lme
18280
18281;;* lmx 58 system/sepolicy/private/app_neverallows.te
18282
18283(neverallow untrusted_app_all app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18284(neverallow isolated_app_all app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18285(neverallow ephemeral_app app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18286(neverallow isolated_app app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18287(neverallow isolated_compute_app app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18288(neverallow mediaprovider app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18289(neverallow untrusted_app app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18290(neverallow untrusted_app_30 app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18291(neverallow untrusted_app_29 app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18292(neverallow untrusted_app_27 app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18293(neverallow untrusted_app_25 app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18294(neverallow mediaprovider_app app_exec_data_file (file (write create setattr relabelfrom relabelto append link rename)))
18295;;* lme
18296
18297;;* lmx 69 system/sepolicy/private/app_neverallows.te
18298
18299(neverallow base_typeattr_634 app_data_file (file (execute_no_trans)))
18300(neverallow base_typeattr_634 privapp_data_file (file (execute_no_trans)))
18301;;* lme
18302
18303;;* lmx 78 system/sepolicy/private/app_neverallows.te
18304
18305(neverallow base_typeattr_635 dex2oat_exec (file (execute execute_no_trans)))
18306;;* lme
18307
18308;;* lmx 88 system/sepolicy/private/app_neverallows.te
18309
18310(neverallow untrusted_app_all mlstrustedsubject (process (fork)))
18311(neverallow isolated_app_all mlstrustedsubject (process (fork)))
18312(neverallow ephemeral_app mlstrustedsubject (process (fork)))
18313(neverallow isolated_app mlstrustedsubject (process (fork)))
18314(neverallow isolated_compute_app mlstrustedsubject (process (fork)))
18315(neverallow mediaprovider mlstrustedsubject (process (fork)))
18316(neverallow untrusted_app mlstrustedsubject (process (fork)))
18317(neverallow untrusted_app_30 mlstrustedsubject (process (fork)))
18318(neverallow untrusted_app_29 mlstrustedsubject (process (fork)))
18319(neverallow untrusted_app_27 mlstrustedsubject (process (fork)))
18320(neverallow untrusted_app_25 mlstrustedsubject (process (fork)))
18321(neverallow mediaprovider_app mlstrustedsubject (process (fork)))
18322;;* lme
18323
18324;;* lmx 96 system/sepolicy/private/app_neverallows.te
18325
18326(neverallow untrusted_app_all file_type (file (link)))
18327(neverallow isolated_app_all file_type (file (link)))
18328(neverallow ephemeral_app file_type (file (link)))
18329(neverallow isolated_app file_type (file (link)))
18330(neverallow isolated_compute_app file_type (file (link)))
18331(neverallow mediaprovider file_type (file (link)))
18332(neverallow untrusted_app file_type (file (link)))
18333(neverallow untrusted_app_30 file_type (file (link)))
18334(neverallow untrusted_app_29 file_type (file (link)))
18335(neverallow untrusted_app_27 file_type (file (link)))
18336(neverallow untrusted_app_25 file_type (file (link)))
18337(neverallow mediaprovider_app file_type (file (link)))
18338;;* lme
18339
18340;;* lmx 99 system/sepolicy/private/app_neverallows.te
18341
18342(neverallow untrusted_app_all sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18343(neverallow isolated_app_all sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18344(neverallow ephemeral_app sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18345(neverallow isolated_app sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18346(neverallow isolated_compute_app sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18347(neverallow mediaprovider sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18348(neverallow untrusted_app sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18349(neverallow untrusted_app_30 sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18350(neverallow untrusted_app_29 sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18351(neverallow untrusted_app_27 sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18352(neverallow untrusted_app_25 sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18353(neverallow mediaprovider_app sysfs_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18354;;* lme
18355
18356;;* lmx 102 system/sepolicy/private/app_neverallows.te
18357
18358(neverallow untrusted_app_all sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18359(neverallow isolated_app_all sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18360(neverallow ephemeral_app sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18361(neverallow isolated_app sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18362(neverallow isolated_compute_app sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18363(neverallow mediaprovider sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18364(neverallow untrusted_app sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18365(neverallow untrusted_app_30 sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18366(neverallow untrusted_app_29 sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18367(neverallow untrusted_app_27 sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18368(neverallow untrusted_app_25 sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18369(neverallow mediaprovider_app sysfs_type (file (write create setattr relabelfrom append unlink link rename execute execute_no_trans)))
18370;;* lme
18371
18372;;* lmx 105 system/sepolicy/private/app_neverallows.te
18373
18374(neverallow untrusted_app_all sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18375(neverallow isolated_app_all sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18376(neverallow ephemeral_app sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18377(neverallow isolated_app sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18378(neverallow isolated_compute_app sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18379(neverallow mediaprovider sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18380(neverallow untrusted_app sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18381(neverallow untrusted_app_30 sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18382(neverallow untrusted_app_29 sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18383(neverallow untrusted_app_27 sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18384(neverallow untrusted_app_25 sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18385(neverallow mediaprovider_app sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
18386;;* lme
18387
18388;;* lmx 109 system/sepolicy/private/app_neverallows.te
18389
18390(neverallowx untrusted_app_all domain (ioctl tcp_socket (0x6900 0x6902)))
18391(neverallowx untrusted_app_all domain (ioctl udp_socket (0x6900 0x6902)))
18392(neverallowx untrusted_app_all domain (ioctl rawip_socket (0x6900 0x6902)))
18393(neverallowx untrusted_app_all domain (ioctl icmp_socket (0x6900 0x6902)))
18394(neverallowx isolated_app_all domain (ioctl tcp_socket (0x6900 0x6902)))
18395(neverallowx isolated_app_all domain (ioctl udp_socket (0x6900 0x6902)))
18396(neverallowx isolated_app_all domain (ioctl rawip_socket (0x6900 0x6902)))
18397(neverallowx isolated_app_all domain (ioctl icmp_socket (0x6900 0x6902)))
18398(neverallowx ephemeral_app domain (ioctl tcp_socket (0x6900 0x6902)))
18399(neverallowx ephemeral_app domain (ioctl udp_socket (0x6900 0x6902)))
18400(neverallowx ephemeral_app domain (ioctl rawip_socket (0x6900 0x6902)))
18401(neverallowx ephemeral_app domain (ioctl icmp_socket (0x6900 0x6902)))
18402(neverallowx isolated_app domain (ioctl tcp_socket (0x6900 0x6902)))
18403(neverallowx isolated_app domain (ioctl udp_socket (0x6900 0x6902)))
18404(neverallowx isolated_app domain (ioctl rawip_socket (0x6900 0x6902)))
18405(neverallowx isolated_app domain (ioctl icmp_socket (0x6900 0x6902)))
18406(neverallowx isolated_compute_app domain (ioctl tcp_socket (0x6900 0x6902)))
18407(neverallowx isolated_compute_app domain (ioctl udp_socket (0x6900 0x6902)))
18408(neverallowx isolated_compute_app domain (ioctl rawip_socket (0x6900 0x6902)))
18409(neverallowx isolated_compute_app domain (ioctl icmp_socket (0x6900 0x6902)))
18410(neverallowx mediaprovider domain (ioctl tcp_socket (0x6900 0x6902)))
18411(neverallowx mediaprovider domain (ioctl udp_socket (0x6900 0x6902)))
18412(neverallowx mediaprovider domain (ioctl rawip_socket (0x6900 0x6902)))
18413(neverallowx mediaprovider domain (ioctl icmp_socket (0x6900 0x6902)))
18414(neverallowx untrusted_app domain (ioctl tcp_socket (0x6900 0x6902)))
18415(neverallowx untrusted_app domain (ioctl udp_socket (0x6900 0x6902)))
18416(neverallowx untrusted_app domain (ioctl rawip_socket (0x6900 0x6902)))
18417(neverallowx untrusted_app domain (ioctl icmp_socket (0x6900 0x6902)))
18418(neverallowx untrusted_app_30 domain (ioctl tcp_socket (0x6900 0x6902)))
18419(neverallowx untrusted_app_30 domain (ioctl udp_socket (0x6900 0x6902)))
18420(neverallowx untrusted_app_30 domain (ioctl rawip_socket (0x6900 0x6902)))
18421(neverallowx untrusted_app_30 domain (ioctl icmp_socket (0x6900 0x6902)))
18422(neverallowx untrusted_app_29 domain (ioctl tcp_socket (0x6900 0x6902)))
18423(neverallowx untrusted_app_29 domain (ioctl udp_socket (0x6900 0x6902)))
18424(neverallowx untrusted_app_29 domain (ioctl rawip_socket (0x6900 0x6902)))
18425(neverallowx untrusted_app_29 domain (ioctl icmp_socket (0x6900 0x6902)))
18426(neverallowx untrusted_app_27 domain (ioctl tcp_socket (0x6900 0x6902)))
18427(neverallowx untrusted_app_27 domain (ioctl udp_socket (0x6900 0x6902)))
18428(neverallowx untrusted_app_27 domain (ioctl rawip_socket (0x6900 0x6902)))
18429(neverallowx untrusted_app_27 domain (ioctl icmp_socket (0x6900 0x6902)))
18430(neverallowx untrusted_app_25 domain (ioctl tcp_socket (0x6900 0x6902)))
18431(neverallowx untrusted_app_25 domain (ioctl udp_socket (0x6900 0x6902)))
18432(neverallowx untrusted_app_25 domain (ioctl rawip_socket (0x6900 0x6902)))
18433(neverallowx untrusted_app_25 domain (ioctl icmp_socket (0x6900 0x6902)))
18434(neverallowx mediaprovider_app domain (ioctl tcp_socket (0x6900 0x6902)))
18435(neverallowx mediaprovider_app domain (ioctl udp_socket (0x6900 0x6902)))
18436(neverallowx mediaprovider_app domain (ioctl rawip_socket (0x6900 0x6902)))
18437(neverallowx mediaprovider_app domain (ioctl icmp_socket (0x6900 0x6902)))
18438;;* lme
18439
18440;;* lmx 109 system/sepolicy/private/app_neverallows.te
18441
18442(neverallowx untrusted_app_all domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18443(neverallowx untrusted_app_all domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18444(neverallowx untrusted_app_all domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18445(neverallowx untrusted_app_all domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18446(neverallowx isolated_app_all domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18447(neverallowx isolated_app_all domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18448(neverallowx isolated_app_all domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18449(neverallowx isolated_app_all domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18450(neverallowx ephemeral_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18451(neverallowx ephemeral_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18452(neverallowx ephemeral_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18453(neverallowx ephemeral_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18454(neverallowx isolated_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18455(neverallowx isolated_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18456(neverallowx isolated_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18457(neverallowx isolated_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18458(neverallowx isolated_compute_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18459(neverallowx isolated_compute_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18460(neverallowx isolated_compute_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18461(neverallowx isolated_compute_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18462(neverallowx mediaprovider domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18463(neverallowx mediaprovider domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18464(neverallowx mediaprovider domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18465(neverallowx mediaprovider domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18466(neverallowx untrusted_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18467(neverallowx untrusted_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18468(neverallowx untrusted_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18469(neverallowx untrusted_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18470(neverallowx untrusted_app_30 domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18471(neverallowx untrusted_app_30 domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18472(neverallowx untrusted_app_30 domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18473(neverallowx untrusted_app_30 domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18474(neverallowx untrusted_app_29 domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18475(neverallowx untrusted_app_29 domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18476(neverallowx untrusted_app_29 domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18477(neverallowx untrusted_app_29 domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18478(neverallowx untrusted_app_27 domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18479(neverallowx untrusted_app_27 domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18480(neverallowx untrusted_app_27 domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18481(neverallowx untrusted_app_27 domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18482(neverallowx untrusted_app_25 domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18483(neverallowx untrusted_app_25 domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18484(neverallowx untrusted_app_25 domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18485(neverallowx untrusted_app_25 domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18486(neverallowx mediaprovider_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18487(neverallowx mediaprovider_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18488(neverallowx mediaprovider_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18489(neverallowx mediaprovider_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
18490;;* lme
18491
18492;;* lmx 109 system/sepolicy/private/app_neverallows.te
18493
18494(neverallowx untrusted_app_all domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18495(neverallowx untrusted_app_all domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18496(neverallowx untrusted_app_all domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18497(neverallowx untrusted_app_all domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18498(neverallowx isolated_app_all domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18499(neverallowx isolated_app_all domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18500(neverallowx isolated_app_all domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18501(neverallowx isolated_app_all domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18502(neverallowx ephemeral_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18503(neverallowx ephemeral_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18504(neverallowx ephemeral_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18505(neverallowx ephemeral_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18506(neverallowx isolated_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18507(neverallowx isolated_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18508(neverallowx isolated_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18509(neverallowx isolated_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18510(neverallowx isolated_compute_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18511(neverallowx isolated_compute_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18512(neverallowx isolated_compute_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18513(neverallowx isolated_compute_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18514(neverallowx mediaprovider domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18515(neverallowx mediaprovider domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18516(neverallowx mediaprovider domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18517(neverallowx mediaprovider domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18518(neverallowx untrusted_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18519(neverallowx untrusted_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18520(neverallowx untrusted_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18521(neverallowx untrusted_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18522(neverallowx untrusted_app_30 domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18523(neverallowx untrusted_app_30 domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18524(neverallowx untrusted_app_30 domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18525(neverallowx untrusted_app_30 domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18526(neverallowx untrusted_app_29 domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18527(neverallowx untrusted_app_29 domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18528(neverallowx untrusted_app_29 domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18529(neverallowx untrusted_app_29 domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18530(neverallowx untrusted_app_27 domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18531(neverallowx untrusted_app_27 domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18532(neverallowx untrusted_app_27 domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18533(neverallowx untrusted_app_27 domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18534(neverallowx untrusted_app_25 domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18535(neverallowx untrusted_app_25 domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18536(neverallowx untrusted_app_25 domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18537(neverallowx untrusted_app_25 domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18538(neverallowx mediaprovider_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18539(neverallowx mediaprovider_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18540(neverallowx mediaprovider_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18541(neverallowx mediaprovider_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
18542;;* lme
18543
18544;;* lmx 110 system/sepolicy/private/app_neverallows.te
18545
18546(neverallow untrusted_app_all base_typeattr_224 (netlink_route_socket (ioctl)))
18547(neverallow untrusted_app_all base_typeattr_224 (netlink_selinux_socket (ioctl)))
18548(neverallow isolated_app_all base_typeattr_224 (netlink_route_socket (ioctl)))
18549(neverallow isolated_app_all base_typeattr_224 (netlink_selinux_socket (ioctl)))
18550(neverallow ephemeral_app base_typeattr_224 (netlink_route_socket (ioctl)))
18551(neverallow ephemeral_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
18552(neverallow isolated_app base_typeattr_224 (netlink_route_socket (ioctl)))
18553(neverallow isolated_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
18554(neverallow isolated_compute_app base_typeattr_224 (netlink_route_socket (ioctl)))
18555(neverallow isolated_compute_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
18556(neverallow mediaprovider base_typeattr_224 (netlink_route_socket (ioctl)))
18557(neverallow mediaprovider base_typeattr_224 (netlink_selinux_socket (ioctl)))
18558(neverallow untrusted_app base_typeattr_224 (netlink_route_socket (ioctl)))
18559(neverallow untrusted_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
18560(neverallow untrusted_app_30 base_typeattr_224 (netlink_route_socket (ioctl)))
18561(neverallow untrusted_app_30 base_typeattr_224 (netlink_selinux_socket (ioctl)))
18562(neverallow untrusted_app_29 base_typeattr_224 (netlink_route_socket (ioctl)))
18563(neverallow untrusted_app_29 base_typeattr_224 (netlink_selinux_socket (ioctl)))
18564(neverallow untrusted_app_27 base_typeattr_224 (netlink_route_socket (ioctl)))
18565(neverallow untrusted_app_27 base_typeattr_224 (netlink_selinux_socket (ioctl)))
18566(neverallow untrusted_app_25 base_typeattr_224 (netlink_route_socket (ioctl)))
18567(neverallow untrusted_app_25 base_typeattr_224 (netlink_selinux_socket (ioctl)))
18568(neverallow mediaprovider_app base_typeattr_224 (netlink_route_socket (ioctl)))
18569(neverallow mediaprovider_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
18570;;* lme
18571
18572;;* lmx 123 system/sepolicy/private/app_neverallows.te
18573
18574(neverallow untrusted_app_all base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18575(neverallow untrusted_app_all base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18576(neverallow untrusted_app_all base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18577(neverallow untrusted_app_all base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18578(neverallow untrusted_app_all base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18579(neverallow untrusted_app_all base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18580(neverallow untrusted_app_all base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18581(neverallow untrusted_app_all base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18582(neverallow untrusted_app_all base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18583(neverallow untrusted_app_all base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18584(neverallow untrusted_app_all base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18585(neverallow untrusted_app_all base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18586(neverallow untrusted_app_all base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18587(neverallow untrusted_app_all base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18588(neverallow untrusted_app_all base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18589(neverallow untrusted_app_all base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18590(neverallow untrusted_app_all base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18591(neverallow untrusted_app_all base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18592(neverallow untrusted_app_all base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18593(neverallow untrusted_app_all base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18594(neverallow untrusted_app_all base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18595(neverallow untrusted_app_all base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18596(neverallow untrusted_app_all base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18597(neverallow untrusted_app_all base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18598(neverallow untrusted_app_all base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18599(neverallow untrusted_app_all base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18600(neverallow untrusted_app_all base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18601(neverallow untrusted_app_all base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18602(neverallow untrusted_app_all base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18603(neverallow untrusted_app_all base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18604(neverallow untrusted_app_all base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18605(neverallow untrusted_app_all base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18606(neverallow untrusted_app_all base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18607(neverallow untrusted_app_all base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18608(neverallow untrusted_app_all base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18609(neverallow untrusted_app_all base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18610(neverallow untrusted_app_all base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18611(neverallow untrusted_app_all base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18612(neverallow untrusted_app_all base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18613(neverallow untrusted_app_all base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18614(neverallow untrusted_app_all base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18615(neverallow untrusted_app_all base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18616(neverallow untrusted_app_all base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18617(neverallow untrusted_app_all base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18618(neverallow untrusted_app_all base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18619(neverallow untrusted_app_all base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18620(neverallow untrusted_app_all base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18621(neverallow untrusted_app_all base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18622(neverallow isolated_app_all base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18623(neverallow isolated_app_all base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18624(neverallow isolated_app_all base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18625(neverallow isolated_app_all base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18626(neverallow isolated_app_all base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18627(neverallow isolated_app_all base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18628(neverallow isolated_app_all base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18629(neverallow isolated_app_all base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18630(neverallow isolated_app_all base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18631(neverallow isolated_app_all base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18632(neverallow isolated_app_all base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18633(neverallow isolated_app_all base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18634(neverallow isolated_app_all base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18635(neverallow isolated_app_all base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18636(neverallow isolated_app_all base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18637(neverallow isolated_app_all base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18638(neverallow isolated_app_all base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18639(neverallow isolated_app_all base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18640(neverallow isolated_app_all base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18641(neverallow isolated_app_all base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18642(neverallow isolated_app_all base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18643(neverallow isolated_app_all base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18644(neverallow isolated_app_all base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18645(neverallow isolated_app_all base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18646(neverallow isolated_app_all base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18647(neverallow isolated_app_all base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18648(neverallow isolated_app_all base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18649(neverallow isolated_app_all base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18650(neverallow isolated_app_all base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18651(neverallow isolated_app_all base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18652(neverallow isolated_app_all base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18653(neverallow isolated_app_all base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18654(neverallow isolated_app_all base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18655(neverallow isolated_app_all base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18656(neverallow isolated_app_all base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18657(neverallow isolated_app_all base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18658(neverallow isolated_app_all base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18659(neverallow isolated_app_all base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18660(neverallow isolated_app_all base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18661(neverallow isolated_app_all base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18662(neverallow isolated_app_all base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18663(neverallow isolated_app_all base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18664(neverallow isolated_app_all base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18665(neverallow isolated_app_all base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18666(neverallow isolated_app_all base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18667(neverallow isolated_app_all base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18668(neverallow isolated_app_all base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18669(neverallow isolated_app_all base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18670(neverallow ephemeral_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18671(neverallow ephemeral_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18672(neverallow ephemeral_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18673(neverallow ephemeral_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18674(neverallow ephemeral_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18675(neverallow ephemeral_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18676(neverallow ephemeral_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18677(neverallow ephemeral_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18678(neverallow ephemeral_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18679(neverallow ephemeral_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18680(neverallow ephemeral_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18681(neverallow ephemeral_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18682(neverallow ephemeral_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18683(neverallow ephemeral_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18684(neverallow ephemeral_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18685(neverallow ephemeral_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18686(neverallow ephemeral_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18687(neverallow ephemeral_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18688(neverallow ephemeral_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18689(neverallow ephemeral_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18690(neverallow ephemeral_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18691(neverallow ephemeral_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18692(neverallow ephemeral_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18693(neverallow ephemeral_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18694(neverallow ephemeral_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18695(neverallow ephemeral_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18696(neverallow ephemeral_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18697(neverallow ephemeral_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18698(neverallow ephemeral_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18699(neverallow ephemeral_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18700(neverallow ephemeral_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18701(neverallow ephemeral_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18702(neverallow ephemeral_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18703(neverallow ephemeral_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18704(neverallow ephemeral_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18705(neverallow ephemeral_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18706(neverallow ephemeral_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18707(neverallow ephemeral_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18708(neverallow ephemeral_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18709(neverallow ephemeral_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18710(neverallow ephemeral_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18711(neverallow ephemeral_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18712(neverallow ephemeral_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18713(neverallow ephemeral_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18714(neverallow ephemeral_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18715(neverallow ephemeral_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18716(neverallow ephemeral_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18717(neverallow ephemeral_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18718(neverallow isolated_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18719(neverallow isolated_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18720(neverallow isolated_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18721(neverallow isolated_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18722(neverallow isolated_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18723(neverallow isolated_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18724(neverallow isolated_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18725(neverallow isolated_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18726(neverallow isolated_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18727(neverallow isolated_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18728(neverallow isolated_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18729(neverallow isolated_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18730(neverallow isolated_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18731(neverallow isolated_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18732(neverallow isolated_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18733(neverallow isolated_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18734(neverallow isolated_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18735(neverallow isolated_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18736(neverallow isolated_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18737(neverallow isolated_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18738(neverallow isolated_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18739(neverallow isolated_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18740(neverallow isolated_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18741(neverallow isolated_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18742(neverallow isolated_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18743(neverallow isolated_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18744(neverallow isolated_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18745(neverallow isolated_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18746(neverallow isolated_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18747(neverallow isolated_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18748(neverallow isolated_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18749(neverallow isolated_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18750(neverallow isolated_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18751(neverallow isolated_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18752(neverallow isolated_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18753(neverallow isolated_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18754(neverallow isolated_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18755(neverallow isolated_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18756(neverallow isolated_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18757(neverallow isolated_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18758(neverallow isolated_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18759(neverallow isolated_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18760(neverallow isolated_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18761(neverallow isolated_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18762(neverallow isolated_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18763(neverallow isolated_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18764(neverallow isolated_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18765(neverallow isolated_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18766(neverallow isolated_compute_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18767(neverallow isolated_compute_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18768(neverallow isolated_compute_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18769(neverallow isolated_compute_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18770(neverallow isolated_compute_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18771(neverallow isolated_compute_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18772(neverallow isolated_compute_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18773(neverallow isolated_compute_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18774(neverallow isolated_compute_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18775(neverallow isolated_compute_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18776(neverallow isolated_compute_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18777(neverallow isolated_compute_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18778(neverallow isolated_compute_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18779(neverallow isolated_compute_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18780(neverallow isolated_compute_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18781(neverallow isolated_compute_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18782(neverallow isolated_compute_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18783(neverallow isolated_compute_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18784(neverallow isolated_compute_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18785(neverallow isolated_compute_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18786(neverallow isolated_compute_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18787(neverallow isolated_compute_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18788(neverallow isolated_compute_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18789(neverallow isolated_compute_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18790(neverallow isolated_compute_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18791(neverallow isolated_compute_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18792(neverallow isolated_compute_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18793(neverallow isolated_compute_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18794(neverallow isolated_compute_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18795(neverallow isolated_compute_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18796(neverallow isolated_compute_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18797(neverallow isolated_compute_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18798(neverallow isolated_compute_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18799(neverallow isolated_compute_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18800(neverallow isolated_compute_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18801(neverallow isolated_compute_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18802(neverallow isolated_compute_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18803(neverallow isolated_compute_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18804(neverallow isolated_compute_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18805(neverallow isolated_compute_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18806(neverallow isolated_compute_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18807(neverallow isolated_compute_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18808(neverallow isolated_compute_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18809(neverallow isolated_compute_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18810(neverallow isolated_compute_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18811(neverallow isolated_compute_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18812(neverallow isolated_compute_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18813(neverallow isolated_compute_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18814(neverallow mediaprovider base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18815(neverallow mediaprovider base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18816(neverallow mediaprovider base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18817(neverallow mediaprovider base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18818(neverallow mediaprovider base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18819(neverallow mediaprovider base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18820(neverallow mediaprovider base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18821(neverallow mediaprovider base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18822(neverallow mediaprovider base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18823(neverallow mediaprovider base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18824(neverallow mediaprovider base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18825(neverallow mediaprovider base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18826(neverallow mediaprovider base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18827(neverallow mediaprovider base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18828(neverallow mediaprovider base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18829(neverallow mediaprovider base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18830(neverallow mediaprovider base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18831(neverallow mediaprovider base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18832(neverallow mediaprovider base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18833(neverallow mediaprovider base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18834(neverallow mediaprovider base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18835(neverallow mediaprovider base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18836(neverallow mediaprovider base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18837(neverallow mediaprovider base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18838(neverallow mediaprovider base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18839(neverallow mediaprovider base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18840(neverallow mediaprovider base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18841(neverallow mediaprovider base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18842(neverallow mediaprovider base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18843(neverallow mediaprovider base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18844(neverallow mediaprovider base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18845(neverallow mediaprovider base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18846(neverallow mediaprovider base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18847(neverallow mediaprovider base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18848(neverallow mediaprovider base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18849(neverallow mediaprovider base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18850(neverallow mediaprovider base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18851(neverallow mediaprovider base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18852(neverallow mediaprovider base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18853(neverallow mediaprovider base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18854(neverallow mediaprovider base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18855(neverallow mediaprovider base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18856(neverallow mediaprovider base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18857(neverallow mediaprovider base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18858(neverallow mediaprovider base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18859(neverallow mediaprovider base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18860(neverallow mediaprovider base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18861(neverallow mediaprovider base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18862(neverallow untrusted_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18863(neverallow untrusted_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18864(neverallow untrusted_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18865(neverallow untrusted_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18866(neverallow untrusted_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18867(neverallow untrusted_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18868(neverallow untrusted_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18869(neverallow untrusted_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18870(neverallow untrusted_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18871(neverallow untrusted_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18872(neverallow untrusted_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18873(neverallow untrusted_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18874(neverallow untrusted_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18875(neverallow untrusted_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18876(neverallow untrusted_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18877(neverallow untrusted_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18878(neverallow untrusted_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18879(neverallow untrusted_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18880(neverallow untrusted_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18881(neverallow untrusted_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18882(neverallow untrusted_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18883(neverallow untrusted_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18884(neverallow untrusted_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18885(neverallow untrusted_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18886(neverallow untrusted_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18887(neverallow untrusted_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18888(neverallow untrusted_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18889(neverallow untrusted_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18890(neverallow untrusted_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18891(neverallow untrusted_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18892(neverallow untrusted_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18893(neverallow untrusted_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18894(neverallow untrusted_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18895(neverallow untrusted_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18896(neverallow untrusted_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18897(neverallow untrusted_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18898(neverallow untrusted_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18899(neverallow untrusted_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18900(neverallow untrusted_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18901(neverallow untrusted_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18902(neverallow untrusted_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18903(neverallow untrusted_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18904(neverallow untrusted_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18905(neverallow untrusted_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18906(neverallow untrusted_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18907(neverallow untrusted_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18908(neverallow untrusted_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18909(neverallow untrusted_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18910(neverallow untrusted_app_30 base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18911(neverallow untrusted_app_30 base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18912(neverallow untrusted_app_30 base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18913(neverallow untrusted_app_30 base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18914(neverallow untrusted_app_30 base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18915(neverallow untrusted_app_30 base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18916(neverallow untrusted_app_30 base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18917(neverallow untrusted_app_30 base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18918(neverallow untrusted_app_30 base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18919(neverallow untrusted_app_30 base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18920(neverallow untrusted_app_30 base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18921(neverallow untrusted_app_30 base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18922(neverallow untrusted_app_30 base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18923(neverallow untrusted_app_30 base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18924(neverallow untrusted_app_30 base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18925(neverallow untrusted_app_30 base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18926(neverallow untrusted_app_30 base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18927(neverallow untrusted_app_30 base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18928(neverallow untrusted_app_30 base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18929(neverallow untrusted_app_30 base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18930(neverallow untrusted_app_30 base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18931(neverallow untrusted_app_30 base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18932(neverallow untrusted_app_30 base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18933(neverallow untrusted_app_30 base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18934(neverallow untrusted_app_30 base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18935(neverallow untrusted_app_30 base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18936(neverallow untrusted_app_30 base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18937(neverallow untrusted_app_30 base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18938(neverallow untrusted_app_30 base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18939(neverallow untrusted_app_30 base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18940(neverallow untrusted_app_30 base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18941(neverallow untrusted_app_30 base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18942(neverallow untrusted_app_30 base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18943(neverallow untrusted_app_30 base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18944(neverallow untrusted_app_30 base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18945(neverallow untrusted_app_30 base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18946(neverallow untrusted_app_30 base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18947(neverallow untrusted_app_30 base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18948(neverallow untrusted_app_30 base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18949(neverallow untrusted_app_30 base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18950(neverallow untrusted_app_30 base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18951(neverallow untrusted_app_30 base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18952(neverallow untrusted_app_30 base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18953(neverallow untrusted_app_30 base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18954(neverallow untrusted_app_30 base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18955(neverallow untrusted_app_30 base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18956(neverallow untrusted_app_30 base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18957(neverallow untrusted_app_30 base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18958(neverallow untrusted_app_29 base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18959(neverallow untrusted_app_29 base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18960(neverallow untrusted_app_29 base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18961(neverallow untrusted_app_29 base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18962(neverallow untrusted_app_29 base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18963(neverallow untrusted_app_29 base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18964(neverallow untrusted_app_29 base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
18965(neverallow untrusted_app_29 base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
18966(neverallow untrusted_app_29 base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18967(neverallow untrusted_app_29 base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18968(neverallow untrusted_app_29 base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18969(neverallow untrusted_app_29 base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
18970(neverallow untrusted_app_29 base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18971(neverallow untrusted_app_29 base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18972(neverallow untrusted_app_29 base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18973(neverallow untrusted_app_29 base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18974(neverallow untrusted_app_29 base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18975(neverallow untrusted_app_29 base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18976(neverallow untrusted_app_29 base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18977(neverallow untrusted_app_29 base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18978(neverallow untrusted_app_29 base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
18979(neverallow untrusted_app_29 base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18980(neverallow untrusted_app_29 base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18981(neverallow untrusted_app_29 base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18982(neverallow untrusted_app_29 base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18983(neverallow untrusted_app_29 base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18984(neverallow untrusted_app_29 base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18985(neverallow untrusted_app_29 base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18986(neverallow untrusted_app_29 base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18987(neverallow untrusted_app_29 base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18988(neverallow untrusted_app_29 base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18989(neverallow untrusted_app_29 base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18990(neverallow untrusted_app_29 base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18991(neverallow untrusted_app_29 base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18992(neverallow untrusted_app_29 base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18993(neverallow untrusted_app_29 base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18994(neverallow untrusted_app_29 base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18995(neverallow untrusted_app_29 base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18996(neverallow untrusted_app_29 base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18997(neverallow untrusted_app_29 base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18998(neverallow untrusted_app_29 base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
18999(neverallow untrusted_app_29 base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19000(neverallow untrusted_app_29 base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19001(neverallow untrusted_app_29 base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19002(neverallow untrusted_app_29 base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19003(neverallow untrusted_app_29 base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19004(neverallow untrusted_app_29 base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19005(neverallow untrusted_app_29 base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19006(neverallow untrusted_app_27 base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19007(neverallow untrusted_app_27 base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19008(neverallow untrusted_app_27 base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19009(neverallow untrusted_app_27 base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19010(neverallow untrusted_app_27 base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19011(neverallow untrusted_app_27 base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19012(neverallow untrusted_app_27 base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19013(neverallow untrusted_app_27 base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
19014(neverallow untrusted_app_27 base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19015(neverallow untrusted_app_27 base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19016(neverallow untrusted_app_27 base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19017(neverallow untrusted_app_27 base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
19018(neverallow untrusted_app_27 base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19019(neverallow untrusted_app_27 base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19020(neverallow untrusted_app_27 base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19021(neverallow untrusted_app_27 base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19022(neverallow untrusted_app_27 base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19023(neverallow untrusted_app_27 base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19024(neverallow untrusted_app_27 base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19025(neverallow untrusted_app_27 base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19026(neverallow untrusted_app_27 base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
19027(neverallow untrusted_app_27 base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19028(neverallow untrusted_app_27 base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19029(neverallow untrusted_app_27 base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19030(neverallow untrusted_app_27 base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19031(neverallow untrusted_app_27 base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19032(neverallow untrusted_app_27 base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19033(neverallow untrusted_app_27 base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19034(neverallow untrusted_app_27 base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19035(neverallow untrusted_app_27 base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19036(neverallow untrusted_app_27 base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19037(neverallow untrusted_app_27 base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19038(neverallow untrusted_app_27 base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19039(neverallow untrusted_app_27 base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19040(neverallow untrusted_app_27 base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19041(neverallow untrusted_app_27 base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19042(neverallow untrusted_app_27 base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19043(neverallow untrusted_app_27 base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19044(neverallow untrusted_app_27 base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19045(neverallow untrusted_app_27 base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19046(neverallow untrusted_app_27 base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19047(neverallow untrusted_app_27 base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19048(neverallow untrusted_app_27 base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19049(neverallow untrusted_app_27 base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19050(neverallow untrusted_app_27 base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19051(neverallow untrusted_app_27 base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19052(neverallow untrusted_app_27 base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19053(neverallow untrusted_app_27 base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19054(neverallow untrusted_app_25 base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19055(neverallow untrusted_app_25 base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19056(neverallow untrusted_app_25 base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19057(neverallow untrusted_app_25 base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19058(neverallow untrusted_app_25 base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19059(neverallow untrusted_app_25 base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19060(neverallow untrusted_app_25 base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19061(neverallow untrusted_app_25 base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
19062(neverallow untrusted_app_25 base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19063(neverallow untrusted_app_25 base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19064(neverallow untrusted_app_25 base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19065(neverallow untrusted_app_25 base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
19066(neverallow untrusted_app_25 base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19067(neverallow untrusted_app_25 base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19068(neverallow untrusted_app_25 base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19069(neverallow untrusted_app_25 base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19070(neverallow untrusted_app_25 base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19071(neverallow untrusted_app_25 base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19072(neverallow untrusted_app_25 base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19073(neverallow untrusted_app_25 base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19074(neverallow untrusted_app_25 base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
19075(neverallow untrusted_app_25 base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19076(neverallow untrusted_app_25 base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19077(neverallow untrusted_app_25 base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19078(neverallow untrusted_app_25 base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19079(neverallow untrusted_app_25 base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19080(neverallow untrusted_app_25 base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19081(neverallow untrusted_app_25 base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19082(neverallow untrusted_app_25 base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19083(neverallow untrusted_app_25 base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19084(neverallow untrusted_app_25 base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19085(neverallow untrusted_app_25 base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19086(neverallow untrusted_app_25 base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19087(neverallow untrusted_app_25 base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19088(neverallow untrusted_app_25 base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19089(neverallow untrusted_app_25 base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19090(neverallow untrusted_app_25 base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19091(neverallow untrusted_app_25 base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19092(neverallow untrusted_app_25 base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19093(neverallow untrusted_app_25 base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19094(neverallow untrusted_app_25 base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19095(neverallow untrusted_app_25 base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19096(neverallow untrusted_app_25 base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19097(neverallow untrusted_app_25 base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19098(neverallow untrusted_app_25 base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19099(neverallow untrusted_app_25 base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19100(neverallow untrusted_app_25 base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19101(neverallow untrusted_app_25 base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19102(neverallow mediaprovider_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19103(neverallow mediaprovider_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19104(neverallow mediaprovider_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19105(neverallow mediaprovider_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19106(neverallow mediaprovider_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19107(neverallow mediaprovider_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19108(neverallow mediaprovider_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19109(neverallow mediaprovider_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
19110(neverallow mediaprovider_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19111(neverallow mediaprovider_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19112(neverallow mediaprovider_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19113(neverallow mediaprovider_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
19114(neverallow mediaprovider_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19115(neverallow mediaprovider_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19116(neverallow mediaprovider_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19117(neverallow mediaprovider_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19118(neverallow mediaprovider_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19119(neverallow mediaprovider_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19120(neverallow mediaprovider_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19121(neverallow mediaprovider_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19122(neverallow mediaprovider_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
19123(neverallow mediaprovider_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19124(neverallow mediaprovider_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19125(neverallow mediaprovider_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19126(neverallow mediaprovider_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19127(neverallow mediaprovider_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19128(neverallow mediaprovider_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19129(neverallow mediaprovider_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19130(neverallow mediaprovider_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19131(neverallow mediaprovider_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19132(neverallow mediaprovider_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19133(neverallow mediaprovider_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19134(neverallow mediaprovider_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19135(neverallow mediaprovider_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19136(neverallow mediaprovider_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19137(neverallow mediaprovider_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19138(neverallow mediaprovider_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19139(neverallow mediaprovider_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19140(neverallow mediaprovider_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19141(neverallow mediaprovider_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19142(neverallow mediaprovider_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19143(neverallow mediaprovider_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19144(neverallow mediaprovider_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19145(neverallow mediaprovider_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19146(neverallow mediaprovider_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19147(neverallow mediaprovider_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19148(neverallow mediaprovider_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19149(neverallow mediaprovider_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19150;;* lme
19151
19152;;* lmx 128 system/sepolicy/private/app_neverallows.te
19153
19154(neverallow untrusted_app_all base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19155(neverallow isolated_app_all base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19156(neverallow ephemeral_app base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19157(neverallow isolated_app base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19158(neverallow isolated_compute_app base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19159(neverallow mediaprovider base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19160(neverallow untrusted_app base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19161(neverallow untrusted_app_30 base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19162(neverallow untrusted_app_29 base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19163(neverallow untrusted_app_27 base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19164(neverallow untrusted_app_25 base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19165(neverallow mediaprovider_app base_typeattr_224 (vsock_socket (ioctl create setattr lock relabelfrom relabelto append map bind connect listen accept setopt shutdown recvfrom sendto name_bind)))
19166;;* lme
19167
19168;;* lmx 131 system/sepolicy/private/app_neverallows.te
19169
19170(neverallow untrusted_app_all domain (netlink_route_socket (bind nlmsg_readpriv)))
19171(neverallow isolated_app_all domain (netlink_route_socket (bind nlmsg_readpriv)))
19172(neverallow ephemeral_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19173(neverallow isolated_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19174(neverallow isolated_compute_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19175(neverallow mediaprovider domain (netlink_route_socket (bind nlmsg_readpriv)))
19176(neverallow untrusted_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19177(neverallow untrusted_app_30 domain (netlink_route_socket (bind nlmsg_readpriv)))
19178(neverallow untrusted_app_29 domain (netlink_route_socket (bind nlmsg_readpriv)))
19179(neverallow untrusted_app_27 domain (netlink_route_socket (bind nlmsg_readpriv)))
19180(neverallow untrusted_app_25 domain (netlink_route_socket (bind nlmsg_readpriv)))
19181(neverallow mediaprovider_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19182;;* lme
19183
19184;;* lmx 132 system/sepolicy/private/app_neverallows.te
19185
19186(neverallow priv_app domain (netlink_route_socket (bind nlmsg_readpriv)))
19187;;* lme
19188
19189;;* lmx 141 system/sepolicy/private/app_neverallows.te
19190
19191(neverallow base_typeattr_636 domain (netlink_route_socket (nlmsg_getneigh)))
19192;;* lme
19193
19194;;* lmx 144 system/sepolicy/private/app_neverallows.te
19195
19196(neverallow base_typeattr_633 cache_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
19197(neverallow base_typeattr_633 cache_recovery_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
19198;;* lme
19199
19200;;* lmx 145 system/sepolicy/private/app_neverallows.te
19201
19202(neverallow base_typeattr_633 cache_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19203(neverallow base_typeattr_633 cache_recovery_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19204;;* lme
19205
19206;;* lmx 167 system/sepolicy/private/app_neverallows.te
19207
19208(neverallow base_typeattr_633 base_typeattr_637 (file (create unlink)))
19209(neverallow base_typeattr_633 base_typeattr_637 (dir (create unlink)))
19210(neverallow base_typeattr_633 base_typeattr_637 (lnk_file (create unlink)))
19211(neverallow base_typeattr_633 base_typeattr_637 (chr_file (create unlink)))
19212(neverallow base_typeattr_633 base_typeattr_637 (blk_file (create unlink)))
19213(neverallow base_typeattr_633 base_typeattr_637 (sock_file (create unlink)))
19214(neverallow base_typeattr_633 base_typeattr_637 (fifo_file (create unlink)))
19215;;* lme
19216
19217;;* lmx 170 system/sepolicy/private/app_neverallows.te
19218
19219(neverallow base_typeattr_638 fuse_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19220;;* lme
19221
19222;;* lmx 173 system/sepolicy/private/app_neverallows.te
19223
19224(neverallow untrusted_app_all tun_device (chr_file (open)))
19225(neverallow isolated_app_all tun_device (chr_file (open)))
19226(neverallow ephemeral_app tun_device (chr_file (open)))
19227(neverallow isolated_app tun_device (chr_file (open)))
19228(neverallow isolated_compute_app tun_device (chr_file (open)))
19229(neverallow mediaprovider tun_device (chr_file (open)))
19230(neverallow untrusted_app tun_device (chr_file (open)))
19231(neverallow untrusted_app_30 tun_device (chr_file (open)))
19232(neverallow untrusted_app_29 tun_device (chr_file (open)))
19233(neverallow untrusted_app_27 tun_device (chr_file (open)))
19234(neverallow untrusted_app_25 tun_device (chr_file (open)))
19235(neverallow mediaprovider_app tun_device (chr_file (open)))
19236;;* lme
19237
19238;;* lmx 177 system/sepolicy/private/app_neverallows.te
19239
19240(neverallowx untrusted_app_all tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19241(neverallowx isolated_app_all tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19242(neverallowx ephemeral_app tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19243(neverallowx isolated_app tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19244(neverallowx isolated_compute_app tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19245(neverallowx mediaprovider tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19246(neverallowx untrusted_app tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19247(neverallowx untrusted_app_30 tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19248(neverallowx untrusted_app_29 tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19249(neverallowx untrusted_app_27 tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19250(neverallowx untrusted_app_25 tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19251(neverallowx mediaprovider_app tun_device (ioctl chr_file ((range 0x0 0x53ff) (range 0x5500 0xffff))))
19252;;* lme
19253
19254;;* lmx 177 system/sepolicy/private/app_neverallows.te
19255
19256(neverallowx untrusted_app_all tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19257(neverallowx isolated_app_all tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19258(neverallowx ephemeral_app tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19259(neverallowx isolated_app tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19260(neverallowx isolated_compute_app tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19261(neverallowx mediaprovider tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19262(neverallowx untrusted_app tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19263(neverallowx untrusted_app_30 tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19264(neverallowx untrusted_app_29 tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19265(neverallowx untrusted_app_27 tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19266(neverallowx untrusted_app_25 tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19267(neverallowx mediaprovider_app tun_device (ioctl chr_file ((range 0x5400 0x544f) (range 0x5452 0x54d1) (range 0x54d3 0x54ff))))
19268;;* lme
19269
19270;;* lmx 180 system/sepolicy/private/app_neverallows.te
19271
19272(neverallow untrusted_app_all anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19273(neverallow isolated_app_all anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19274(neverallow ephemeral_app anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19275(neverallow isolated_app anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19276(neverallow isolated_compute_app anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19277(neverallow mediaprovider anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19278(neverallow untrusted_app anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19279(neverallow untrusted_app_30 anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19280(neverallow untrusted_app_29 anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19281(neverallow untrusted_app_27 anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19282(neverallow untrusted_app_25 anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19283(neverallow mediaprovider_app anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19284;;* lme
19285
19286;;* lmx 181 system/sepolicy/private/app_neverallows.te
19287
19288(neverallow untrusted_app_all anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19289(neverallow isolated_app_all anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19290(neverallow ephemeral_app anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19291(neverallow isolated_app anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19292(neverallow isolated_compute_app anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19293(neverallow mediaprovider anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19294(neverallow untrusted_app anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19295(neverallow untrusted_app_30 anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19296(neverallow untrusted_app_29 anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19297(neverallow untrusted_app_27 anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19298(neverallow untrusted_app_25 anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19299(neverallow mediaprovider_app anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
19300;;* lme
19301
19302;;* lmx 199 system/sepolicy/private/app_neverallows.te
19303
19304(neverallow untrusted_app_all proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19305(neverallow untrusted_app_all proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19306(neverallow untrusted_app_all proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19307(neverallow untrusted_app_all proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19308(neverallow untrusted_app_all proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19309(neverallow untrusted_app_all proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19310(neverallow untrusted_app_all proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19311(neverallow untrusted_app_all proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19312(neverallow untrusted_app_all proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19313(neverallow untrusted_app_all proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19314(neverallow untrusted_app_all proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19315(neverallow untrusted_app_all proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19316(neverallow untrusted_app_all proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19317(neverallow isolated_app_all proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19318(neverallow isolated_app_all proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19319(neverallow isolated_app_all proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19320(neverallow isolated_app_all proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19321(neverallow isolated_app_all proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19322(neverallow isolated_app_all proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19323(neverallow isolated_app_all proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19324(neverallow isolated_app_all proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19325(neverallow isolated_app_all proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19326(neverallow isolated_app_all proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19327(neverallow isolated_app_all proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19328(neverallow isolated_app_all proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19329(neverallow isolated_app_all proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19330(neverallow ephemeral_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19331(neverallow ephemeral_app proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19332(neverallow ephemeral_app proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19333(neverallow ephemeral_app proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19334(neverallow ephemeral_app proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19335(neverallow ephemeral_app proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19336(neverallow ephemeral_app proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19337(neverallow ephemeral_app proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19338(neverallow ephemeral_app proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19339(neverallow ephemeral_app proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19340(neverallow ephemeral_app proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19341(neverallow ephemeral_app proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19342(neverallow ephemeral_app proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19343(neverallow isolated_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19344(neverallow isolated_app proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19345(neverallow isolated_app proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19346(neverallow isolated_app proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19347(neverallow isolated_app proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19348(neverallow isolated_app proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19349(neverallow isolated_app proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19350(neverallow isolated_app proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19351(neverallow isolated_app proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19352(neverallow isolated_app proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19353(neverallow isolated_app proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19354(neverallow isolated_app proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19355(neverallow isolated_app proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19356(neverallow isolated_compute_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19357(neverallow isolated_compute_app proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19358(neverallow isolated_compute_app proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19359(neverallow isolated_compute_app proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19360(neverallow isolated_compute_app proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19361(neverallow isolated_compute_app proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19362(neverallow isolated_compute_app proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19363(neverallow isolated_compute_app proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19364(neverallow isolated_compute_app proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19365(neverallow isolated_compute_app proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19366(neverallow isolated_compute_app proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19367(neverallow isolated_compute_app proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19368(neverallow isolated_compute_app proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19369(neverallow mediaprovider proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19370(neverallow mediaprovider proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19371(neverallow mediaprovider proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19372(neverallow mediaprovider proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19373(neverallow mediaprovider proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19374(neverallow mediaprovider proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19375(neverallow mediaprovider proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19376(neverallow mediaprovider proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19377(neverallow mediaprovider proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19378(neverallow mediaprovider proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19379(neverallow mediaprovider proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19380(neverallow mediaprovider proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19381(neverallow mediaprovider proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19382(neverallow untrusted_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19383(neverallow untrusted_app proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19384(neverallow untrusted_app proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19385(neverallow untrusted_app proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19386(neverallow untrusted_app proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19387(neverallow untrusted_app proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19388(neverallow untrusted_app proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19389(neverallow untrusted_app proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19390(neverallow untrusted_app proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19391(neverallow untrusted_app proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19392(neverallow untrusted_app proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19393(neverallow untrusted_app proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19394(neverallow untrusted_app proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19395(neverallow untrusted_app_30 proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19396(neverallow untrusted_app_30 proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19397(neverallow untrusted_app_30 proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19398(neverallow untrusted_app_30 proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19399(neverallow untrusted_app_30 proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19400(neverallow untrusted_app_30 proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19401(neverallow untrusted_app_30 proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19402(neverallow untrusted_app_30 proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19403(neverallow untrusted_app_30 proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19404(neverallow untrusted_app_30 proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19405(neverallow untrusted_app_30 proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19406(neverallow untrusted_app_30 proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19407(neverallow untrusted_app_30 proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19408(neverallow untrusted_app_29 proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19409(neverallow untrusted_app_29 proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19410(neverallow untrusted_app_29 proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19411(neverallow untrusted_app_29 proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19412(neverallow untrusted_app_29 proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19413(neverallow untrusted_app_29 proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19414(neverallow untrusted_app_29 proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19415(neverallow untrusted_app_29 proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19416(neverallow untrusted_app_29 proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19417(neverallow untrusted_app_29 proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19418(neverallow untrusted_app_29 proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19419(neverallow untrusted_app_29 proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19420(neverallow untrusted_app_29 proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19421(neverallow untrusted_app_27 proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19422(neverallow untrusted_app_27 proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19423(neverallow untrusted_app_27 proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19424(neverallow untrusted_app_27 proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19425(neverallow untrusted_app_27 proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19426(neverallow untrusted_app_27 proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19427(neverallow untrusted_app_27 proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19428(neverallow untrusted_app_27 proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19429(neverallow untrusted_app_27 proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19430(neverallow untrusted_app_27 proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19431(neverallow untrusted_app_27 proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19432(neverallow untrusted_app_27 proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19433(neverallow untrusted_app_27 proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19434(neverallow untrusted_app_25 proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19435(neverallow untrusted_app_25 proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19436(neverallow untrusted_app_25 proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19437(neverallow untrusted_app_25 proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19438(neverallow untrusted_app_25 proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19439(neverallow untrusted_app_25 proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19440(neverallow untrusted_app_25 proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19441(neverallow untrusted_app_25 proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19442(neverallow untrusted_app_25 proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19443(neverallow untrusted_app_25 proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19444(neverallow untrusted_app_25 proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19445(neverallow untrusted_app_25 proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19446(neverallow untrusted_app_25 proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19447(neverallow mediaprovider_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19448(neverallow mediaprovider_app proc_asound (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19449(neverallow mediaprovider_app proc_kmsg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19450(neverallow mediaprovider_app proc_loadavg (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19451(neverallow mediaprovider_app proc_mounts (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19452(neverallow mediaprovider_app proc_pagetypeinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19453(neverallow mediaprovider_app proc_slabinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19454(neverallow mediaprovider_app proc_stat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19455(neverallow mediaprovider_app proc_swaps (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19456(neverallow mediaprovider_app proc_uptime (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19457(neverallow mediaprovider_app proc_version (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19458(neverallow mediaprovider_app proc_vmallocinfo (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19459(neverallow mediaprovider_app proc_vmstat (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19460;;* lme
19461
19462;;* lmx 203 system/sepolicy/private/app_neverallows.te
19463
19464(neverallow base_typeattr_638 proc_filesystems (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19465;;* lme
19466
19467;;* lmx 206 system/sepolicy/private/app_neverallows.te
19468
19469(neverallow untrusted_app_all config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19470(neverallow isolated_app_all config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19471(neverallow ephemeral_app config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19472(neverallow isolated_app config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19473(neverallow isolated_compute_app config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19474(neverallow mediaprovider config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19475(neverallow untrusted_app config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19476(neverallow untrusted_app_30 config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19477(neverallow untrusted_app_29 config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19478(neverallow untrusted_app_27 config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19479(neverallow untrusted_app_25 config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19480(neverallow mediaprovider_app config_gz (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
19481;;* lme
19482
19483;;* lmx 209 system/sepolicy/private/app_neverallows.te
19484
19485(neverallow untrusted_app_all preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19486(neverallow isolated_app_all preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19487(neverallow ephemeral_app preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19488(neverallow isolated_app preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19489(neverallow isolated_compute_app preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19490(neverallow mediaprovider preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19491(neverallow untrusted_app preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19492(neverallow untrusted_app_30 preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19493(neverallow untrusted_app_29 preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19494(neverallow untrusted_app_27 preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19495(neverallow untrusted_app_25 preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19496(neverallow mediaprovider_app preloads_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19497;;* lme
19498
19499;;* lmx 213 system/sepolicy/private/app_neverallows.te
19500
19501(neverallow untrusted_app_all system_file (file (lock)))
19502(neverallow isolated_app_all system_file (file (lock)))
19503(neverallow ephemeral_app system_file (file (lock)))
19504(neverallow isolated_app system_file (file (lock)))
19505(neverallow isolated_compute_app system_file (file (lock)))
19506(neverallow mediaprovider system_file (file (lock)))
19507(neverallow untrusted_app system_file (file (lock)))
19508(neverallow untrusted_app_30 system_file (file (lock)))
19509(neverallow untrusted_app_29 system_file (file (lock)))
19510(neverallow untrusted_app_27 system_file (file (lock)))
19511(neverallow untrusted_app_25 system_file (file (lock)))
19512(neverallow mediaprovider_app system_file (file (lock)))
19513;;* lme
19514
19515;;* lmx 217 system/sepolicy/private/app_neverallows.te
19516
19517(neverallow untrusted_app_all base_typeattr_224 (hwservice_manager (add list)))
19518(neverallow isolated_app_all base_typeattr_224 (hwservice_manager (add list)))
19519(neverallow ephemeral_app base_typeattr_224 (hwservice_manager (add list)))
19520(neverallow isolated_app base_typeattr_224 (hwservice_manager (add list)))
19521(neverallow isolated_compute_app base_typeattr_224 (hwservice_manager (add list)))
19522(neverallow mediaprovider base_typeattr_224 (hwservice_manager (add list)))
19523(neverallow untrusted_app base_typeattr_224 (hwservice_manager (add list)))
19524(neverallow untrusted_app_30 base_typeattr_224 (hwservice_manager (add list)))
19525(neverallow untrusted_app_29 base_typeattr_224 (hwservice_manager (add list)))
19526(neverallow untrusted_app_27 base_typeattr_224 (hwservice_manager (add list)))
19527(neverallow untrusted_app_25 base_typeattr_224 (hwservice_manager (add list)))
19528(neverallow mediaprovider_app base_typeattr_224 (hwservice_manager (add list)))
19529;;* lme
19530
19531;;* lmx 232 system/sepolicy/private/app_neverallows.te
19532
19533(neverallow untrusted_app_all protected_hwservice (hwservice_manager (find)))
19534(neverallow isolated_app_all protected_hwservice (hwservice_manager (find)))
19535(neverallow ephemeral_app protected_hwservice (hwservice_manager (find)))
19536(neverallow isolated_app protected_hwservice (hwservice_manager (find)))
19537(neverallow isolated_compute_app protected_hwservice (hwservice_manager (find)))
19538(neverallow mediaprovider protected_hwservice (hwservice_manager (find)))
19539(neverallow untrusted_app protected_hwservice (hwservice_manager (find)))
19540(neverallow untrusted_app_30 protected_hwservice (hwservice_manager (find)))
19541(neverallow untrusted_app_29 protected_hwservice (hwservice_manager (find)))
19542(neverallow untrusted_app_27 protected_hwservice (hwservice_manager (find)))
19543(neverallow untrusted_app_25 protected_hwservice (hwservice_manager (find)))
19544(neverallow mediaprovider_app protected_hwservice (hwservice_manager (find)))
19545;;* lme
19546
19547;;* lmx 233 system/sepolicy/private/app_neverallows.te
19548
19549(neverallow untrusted_app_all protected_service (service_manager (find)))
19550(neverallow isolated_app_all protected_service (service_manager (find)))
19551(neverallow ephemeral_app protected_service (service_manager (find)))
19552(neverallow isolated_app protected_service (service_manager (find)))
19553(neverallow isolated_compute_app protected_service (service_manager (find)))
19554(neverallow mediaprovider protected_service (service_manager (find)))
19555(neverallow untrusted_app protected_service (service_manager (find)))
19556(neverallow untrusted_app_30 protected_service (service_manager (find)))
19557(neverallow untrusted_app_29 protected_service (service_manager (find)))
19558(neverallow untrusted_app_27 protected_service (service_manager (find)))
19559(neverallow untrusted_app_25 protected_service (service_manager (find)))
19560(neverallow mediaprovider_app protected_service (service_manager (find)))
19561;;* lme
19562
19563;;* lmx 236 system/sepolicy/private/app_neverallows.te
19564
19565(neverallow untrusted_app_all selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19566(neverallow isolated_app_all selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19567(neverallow ephemeral_app selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19568(neverallow isolated_app selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19569(neverallow isolated_compute_app selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19570(neverallow mediaprovider selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19571(neverallow untrusted_app selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19572(neverallow untrusted_app_30 selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19573(neverallow untrusted_app_29 selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19574(neverallow untrusted_app_27 selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19575(neverallow untrusted_app_25 selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19576(neverallow mediaprovider_app selinuxfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
19577;;* lme
19578
19579;;* lmx 243 system/sepolicy/private/app_neverallows.te
19580
19581(neverallow base_typeattr_639 proc_tty_drivers (file (ioctl read getattr lock map open watch watch_reads)))
19582;;* lme
19583
19584;;* lmx 244 system/sepolicy/private/app_neverallows.te
19585
19586(neverallow untrusted_app_all proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19587(neverallow isolated_app_all proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19588(neverallow ephemeral_app proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19589(neverallow isolated_app proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19590(neverallow isolated_compute_app proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19591(neverallow mediaprovider proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19592(neverallow untrusted_app proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19593(neverallow untrusted_app_30 proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19594(neverallow untrusted_app_29 proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19595(neverallow untrusted_app_27 proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19596(neverallow untrusted_app_25 proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19597(neverallow mediaprovider_app proc_tty_drivers (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
19598;;* lme
19599
19600;;* lmx 247 system/sepolicy/private/app_neverallows.te
19601
19602(neverallow untrusted_app_all cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19603(neverallow isolated_app_all cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19604(neverallow ephemeral_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19605(neverallow isolated_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19606(neverallow isolated_compute_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19607(neverallow mediaprovider cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19608(neverallow untrusted_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19609(neverallow untrusted_app_30 cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19610(neverallow untrusted_app_29 cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19611(neverallow untrusted_app_27 cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19612(neverallow untrusted_app_25 cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19613(neverallow mediaprovider_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19614;;* lme
19615
19616;;* lmx 248 system/sepolicy/private/app_neverallows.te
19617
19618(neverallow untrusted_app_all cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19619(neverallow isolated_app_all cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19620(neverallow ephemeral_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19621(neverallow isolated_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19622(neverallow isolated_compute_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19623(neverallow mediaprovider cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19624(neverallow untrusted_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19625(neverallow untrusted_app_30 cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19626(neverallow untrusted_app_29 cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19627(neverallow untrusted_app_27 cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19628(neverallow untrusted_app_25 cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19629(neverallow mediaprovider_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19630;;* lme
19631
19632;;* lmx 256 system/sepolicy/private/app_neverallows.te
19633
19634(neverallow base_typeattr_635 mnt_sdcard_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19635;;* lme
19636
19637;;* lmx 259 system/sepolicy/private/app_neverallows.te
19638
19639(neverallow untrusted_app_all incident_service (service_manager (find)))
19640(neverallow isolated_app_all incident_service (service_manager (find)))
19641(neverallow ephemeral_app incident_service (service_manager (find)))
19642(neverallow isolated_app incident_service (service_manager (find)))
19643(neverallow isolated_compute_app incident_service (service_manager (find)))
19644(neverallow mediaprovider incident_service (service_manager (find)))
19645(neverallow untrusted_app incident_service (service_manager (find)))
19646(neverallow untrusted_app_30 incident_service (service_manager (find)))
19647(neverallow untrusted_app_29 incident_service (service_manager (find)))
19648(neverallow untrusted_app_27 incident_service (service_manager (find)))
19649(neverallow untrusted_app_25 incident_service (service_manager (find)))
19650(neverallow mediaprovider_app incident_service (service_manager (find)))
19651;;* lme
19652
19653;;* lmx 262 system/sepolicy/private/app_neverallows.te
19654
19655(neverallow untrusted_app_all stats_service (service_manager (find)))
19656(neverallow isolated_app_all stats_service (service_manager (find)))
19657(neverallow ephemeral_app stats_service (service_manager (find)))
19658(neverallow isolated_app stats_service (service_manager (find)))
19659(neverallow isolated_compute_app stats_service (service_manager (find)))
19660(neverallow mediaprovider stats_service (service_manager (find)))
19661(neverallow untrusted_app stats_service (service_manager (find)))
19662(neverallow untrusted_app_30 stats_service (service_manager (find)))
19663(neverallow untrusted_app_29 stats_service (service_manager (find)))
19664(neverallow untrusted_app_27 stats_service (service_manager (find)))
19665(neverallow untrusted_app_25 stats_service (service_manager (find)))
19666(neverallow mediaprovider_app stats_service (service_manager (find)))
19667;;* lme
19668
19669;;* lmx 272 system/sepolicy/private/app_neverallows.te
19670
19671(neverallow base_typeattr_640 userdebug_or_eng_prop (file (read)))
19672;;* lme
19673
19674;;* lmx 286 system/sepolicy/private/app_neverallows.te
19675
19676(neverallow base_typeattr_641 mdnsd_socket (sock_file (write)))
19677;;* lme
19678
19679;;* lmx 294 system/sepolicy/private/app_neverallows.te
19680
19681(neverallow base_typeattr_641 mdnsd (unix_stream_socket (connectto)))
19682;;* lme
19683
19684;;* lmx 300 system/sepolicy/private/app_neverallows.te
19685
19686(neverallow untrusted_app_all domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19687(neverallow isolated_app_all domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19688(neverallow ephemeral_app domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19689(neverallow isolated_app domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19690(neverallow isolated_compute_app domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19691(neverallow mediaprovider domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19692(neverallow untrusted_app domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19693(neverallow untrusted_app_30 domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19694(neverallow untrusted_app_29 domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19695(neverallow untrusted_app_27 domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19696(neverallow untrusted_app_25 domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19697(neverallow mediaprovider_app domain (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19698;;* lme
19699
19700;;* lmx 303 system/sepolicy/private/app_neverallows.te
19701
19702(neverallow untrusted_app_all hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19703(neverallow isolated_app_all hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19704(neverallow ephemeral_app hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19705(neverallow isolated_app hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19706(neverallow isolated_compute_app hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19707(neverallow mediaprovider hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19708(neverallow untrusted_app hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19709(neverallow untrusted_app_30 hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19710(neverallow untrusted_app_29 hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19711(neverallow untrusted_app_27 hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19712(neverallow untrusted_app_25 hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19713(neverallow mediaprovider_app hidraw_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19714;;* lme
19715
19716(typetransition app_zygote tmpfs file app_zygote_tmpfs)
19717(allow app_zygote app_zygote_tmpfs (file (read write getattr map)))
19718(allow app_zygote self (capability (setgid setuid)))
19719(allow app_zygote self (cap_userns (setgid setuid)))
19720(allow app_zygote self (capability (setpcap)))
19721(allow app_zygote self (cap_userns (setpcap)))
19722(allow app_zygote self (process (setcurrent)))
19723(allow app_zygote isolated_app (process (dyntransition)))
19724(allow app_zygote self (process (execmem)))
19725(allow app_zygote app_zygote_tmpfs (file (execute)))
19726(allow app_zygote debugfs_trace_marker (file (getattr)))
19727(allow app_zygote system_server (process (getpgid)))
19728(allow app_zygote isolated_app (process (setpgid)))
19729(dontaudit app_zygote mnt_expand_file (dir (getattr)))
19730(allow app_zygote seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
19731(allow app_zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
19732(allow app_zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
19733(allow app_zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19734(allow app_zygote selinuxfs (file (write lock append map open)))
19735(allow app_zygote kernel (security (check_context)))
19736(allow app_zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
19737(allow app_zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
19738(allow app_zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19739(allow app_zygote selinuxfs (file (write lock append map open)))
19740(allow app_zygote kernel (security (compute_av)))
19741(allow app_zygote self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19742(allow app_zygote zygote_tmpfs (file (read getattr)))
19743(allow app_zygote zygote (fd (use)))
19744(allow app_zygote zygote (process (sigchld)))
19745(allow app_zygote dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
19746(allow app_zygote dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
19747(allow app_zygote dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19748(allow app_zygote dalvikcache_data_file (file (execute)))
19749(allow app_zygote app_zygote_userfaultfd (anon_inode (ioctl read create)))
19750(dontaudit su app_zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19751;;* lmx 63 system/sepolicy/private/app_zygote.te
19752
19753(neverallow base_typeattr_642 app_zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19754;;* lme
19755
19756(allow app_zygote apex_module_data_file (dir (search)))
19757(allow app_zygote apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
19758(allow app_zygote apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
19759(allow app_zygote apex_art_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19760(allow app_zygote apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
19761(allow app_zygote apk_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
19762(allow app_zygote oemfs (dir (search)))
19763(allow app_zygote vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
19764(allow app_zygote vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
19765(allow app_zygote vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19766(allow app_zygote vendor_apex_metadata_file (dir (getattr search)))
19767(allow app_zygote system_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19768(allow app_zygote system_data_file (file (read getattr map)))
19769(allow app_zygote system_unsolzygote_socket (sock_file (write)))
19770(allow app_zygote system_server (unix_dgram_socket (sendto)))
19771(allow app_zygote device_config_runtime_native_prop (file (read getattr map open)))
19772(allow app_zygote device_config_runtime_native_boot_prop (file (read getattr map open)))
19773(allow app_zygote odsign_prop (file (read getattr map open)))
19774(allow app_zygote resourcecache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
19775(allow app_zygote resourcecache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
19776;;* lmx 105 system/sepolicy/private/app_zygote.te
19777
19778(neverallow app_zygote base_typeattr_643 (process (dyntransition)))
19779;;* lme
19780
19781;;* lmx 108 system/sepolicy/private/app_zygote.te
19782
19783(neverallow app_zygote base_typeattr_644 (process (transition)))
19784;;* lme
19785
19786;;* lmx 112 system/sepolicy/private/app_zygote.te
19787
19788(neverallow app_zygote base_typeattr_224 (file (execute_no_trans)))
19789;;* lme
19790
19791;;* lmx 116 system/sepolicy/private/app_zygote.te
19792
19793(neverallow base_typeattr_645 app_zygote (process (dyntransition)))
19794;;* lme
19795
19796;;* lmx 119 system/sepolicy/private/app_zygote.te
19797
19798(neverallow app_zygote property_socket (sock_file (write)))
19799;;* lme
19800
19801;;* lmx 120 system/sepolicy/private/app_zygote.te
19802
19803(neverallow app_zygote property_type (property_service (set)))
19804;;* lme
19805
19806;;* lmx 123 system/sepolicy/private/app_zygote.te
19807
19808(neverallow app_zygote app_data_file_type (file (ioctl read write getattr lock append map execute open watch watch_reads execute_no_trans)))
19809;;* lme
19810
19811;;* lmx 129 system/sepolicy/private/app_zygote.te
19812
19813(neverallow app_zygote base_typeattr_646 (service_manager (find)))
19814;;* lme
19815
19816;;* lmx 132 system/sepolicy/private/app_zygote.te
19817
19818(neverallow app_zygote gpu_device (chr_file (ioctl read write getattr lock append map execute open watch watch_reads execute_no_trans)))
19819;;* lme
19820
19821;;* lmx 135 system/sepolicy/private/app_zygote.te
19822
19823(neverallow app_zygote cache_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
19824;;* lme
19825
19826;;* lmx 136 system/sepolicy/private/app_zygote.te
19827
19828(neverallow app_zygote cache_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
19829;;* lme
19830
19831;;* lmx 152 system/sepolicy/private/app_zygote.te
19832
19833(neverallow app_zygote domain (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19834(neverallow app_zygote domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
19835(neverallow app_zygote domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
19836(neverallow app_zygote domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
19837(neverallow app_zygote domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19838(neverallow app_zygote domain (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19839(neverallow app_zygote domain (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19840(neverallow app_zygote domain (netlink_route_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh)))
19841(neverallow app_zygote domain (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19842(neverallow app_zygote domain (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19843(neverallow app_zygote domain (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
19844(neverallow app_zygote domain (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
19845(neverallow app_zygote domain (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19846(neverallow app_zygote domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19847(neverallow app_zygote domain (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19848(neverallow app_zygote domain (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
19849(neverallow app_zygote domain (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19850(neverallow app_zygote domain (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19851(neverallow app_zygote domain (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19852(neverallow app_zygote domain (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19853(neverallow app_zygote domain (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19854(neverallow app_zygote domain (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19855(neverallow app_zygote domain (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19856(neverallow app_zygote domain (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19857(neverallow app_zygote domain (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
19858(neverallow app_zygote domain (icmp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
19859(neverallow app_zygote domain (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19860(neverallow app_zygote domain (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19861(neverallow app_zygote domain (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19862(neverallow app_zygote domain (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19863(neverallow app_zygote domain (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19864(neverallow app_zygote domain (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19865(neverallow app_zygote domain (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19866(neverallow app_zygote domain (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19867(neverallow app_zygote domain (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19868(neverallow app_zygote domain (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19869(neverallow app_zygote domain (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19870(neverallow app_zygote domain (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19871(neverallow app_zygote domain (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19872(neverallow app_zygote domain (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19873(neverallow app_zygote domain (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19874(neverallow app_zygote domain (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19875(neverallow app_zygote domain (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19876(neverallow app_zygote domain (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19877(neverallow app_zygote domain (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19878(neverallow app_zygote domain (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19879(neverallow app_zygote domain (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19880(neverallow app_zygote domain (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19881(neverallow app_zygote domain (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19882(neverallow app_zygote domain (vsock_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19883(neverallow app_zygote domain (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19884(neverallow app_zygote domain (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19885(neverallow app_zygote domain (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19886;;* lme
19887
19888;;* lmx 163 system/sepolicy/private/app_zygote.te
19889
19890(neverallow app_zygote base_typeattr_647 (unix_dgram_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
19891;;* lme
19892
19893;;* lmx 170 system/sepolicy/private/app_zygote.te
19894
19895(neverallow app_zygote base_typeattr_648 (unix_stream_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind connectto)))
19896;;* lme
19897
19898;;* lmx 173 system/sepolicy/private/app_zygote.te
19899
19900(neverallow app_zygote base_typeattr_224 (process (ptrace)))
19901;;* lme
19902
19903;;* lmx 182 system/sepolicy/private/app_zygote.te
19904
19905(neverallow app_zygote bluetooth_a2dp_offload_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
19906(neverallow app_zygote bluetooth_audio_hal_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
19907(neverallow app_zygote bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
19908(neverallow app_zygote exported_bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
19909;;* lme
19910
19911(allow init art_boot_exec (file (read getattr map execute open)))
19912(allow init art_boot (process (transition)))
19913(allow art_boot art_boot_exec (file (read getattr map execute open entrypoint)))
19914(dontaudit init art_boot (process (noatsecure)))
19915(allow init art_boot (process (siginh rlimitinh)))
19916(typetransition init art_boot_exec process art_boot)
19917(allow art_boot device_config_runtime_native_boot_prop (file (read getattr map open)))
19918(allow art_boot device_config_runtime_native_prop (file (read getattr map open)))
19919(allow art_boot property_socket (sock_file (write)))
19920(allow art_boot init (unix_stream_socket (connectto)))
19921(allow art_boot dalvik_config_prop_type (property_service (set)))
19922(allow art_boot dalvik_config_prop_type (file (read getattr map open)))
19923(allow artd servicemanager (binder (call transfer)))
19924(allow servicemanager artd (binder (call transfer)))
19925(allow servicemanager artd (dir (search)))
19926(allow servicemanager artd (file (read open)))
19927(allow servicemanager artd (process (getattr)))
19928(allow artd artd_service (service_manager (add find)))
19929;;* lmx 9 system/sepolicy/private/artd.te
19930
19931(neverallow base_typeattr_649 artd_service (service_manager (add)))
19932;;* lme
19933
19934(allow artd artd_pre_reboot_service (service_manager (add find)))
19935;;* lmx 10 system/sepolicy/private/artd.te
19936
19937(neverallow base_typeattr_649 artd_pre_reboot_service (service_manager (add)))
19938;;* lme
19939
19940(allow artd dumpstate (fifo_file (write getattr)))
19941(allow artd dumpstate (fd (use)))
19942(allow init artd_exec (file (read getattr map execute open)))
19943(allow init artd (process (transition)))
19944(allow artd artd_exec (file (read getattr map execute open entrypoint)))
19945(dontaudit init artd (process (noatsecure)))
19946(allow init artd (process (siginh rlimitinh)))
19947(typetransition init artd_exec process artd)
19948(allow artd device_config_runtime_native_prop (file (read getattr map open)))
19949(allow artd device_config_runtime_native_boot_prop (file (read getattr map open)))
19950(allow artd odsign_prop (file (read getattr map open)))
19951(typetransition artd tmpfs file artd_tmpfs)
19952(allow artd artd_tmpfs (file (read write getattr map)))
19953(allow artd artd_userfaultfd (anon_inode (ioctl read create)))
19954(dontaudit su artd_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19955;;* lmx 32 system/sepolicy/private/artd.te
19956
19957(neverallow base_typeattr_649 artd_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
19958;;* lme
19959
19960(allow artd mnt_expand_file (dir (getattr search)))
19961(allow artd apk_data_file (dir (ioctl read write create getattr setattr lock relabelfrom open watch watch_reads add_name remove_name search)))
19962(allow artd apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
19963(allow artd vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
19964(allow artd vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
19965(allow artd vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19966(allow artd oemfs (dir (getattr search)))
19967(allow artd vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
19968(allow artd vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
19969(allow artd vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19970(allow artd vendor_apex_metadata_file (dir (getattr search)))
19971(allow artd vendor_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
19972(allow artd vendor_framework_file (file (ioctl read getattr lock map open watch watch_reads)))
19973(allow artd vendor_framework_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19974(allow artd dalvikcache_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
19975(allow artd dalvikcache_data_file (file (ioctl read write create getattr setattr lock relabelto append map unlink rename open watch watch_reads)))
19976(allow artd apex_module_data_file (dir (getattr search)))
19977(allow artd apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
19978(allow artd apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
19979(allow artd apex_art_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19980(allow artd apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
19981(allow artd self (capability (chown dac_override dac_read_search fowner)))
19982(allow artd self (cap_userns (chown dac_override dac_read_search fowner)))
19983(allow artd user_profile_root_file (dir (ioctl read getattr lock open watch watch_reads search)))
19984(allow artd user_profile_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
19985(allow artd user_profile_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
19986(allow artd app_data_file_type (dir (ioctl read write create getattr setattr lock relabelfrom relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
19987(allow artd app_data_file_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink rename open watch watch_reads)))
19988(allow artd privapp_data_file (lnk_file (read getattr)))
19989(allow artd file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
19990(allow artd seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
19991(allow artd selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
19992(allow artd selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
19993(allow artd selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
19994(allow artd selinuxfs (file (write lock append map open)))
19995(allow artd kernel (security (check_context)))
19996(allow artd rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
19997(allow artd system_data_root_file (dir (ioctl read getattr lock open watch watch_reads search)))
19998(allow artd tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
19999(allow artd mnt_expand_file (dir (ioctl read getattr lock open watch watch_reads search)))
20000(allow artd system_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
20001(allow artd system_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
20002;;* lmx 127 system/sepolicy/private/artd.te
20003
20004(neverallow artd base_typeattr_650 (file (execute_no_trans)))
20005;;* lme
20006
20007(allow artd art_exec_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
20008(allow artd profman_exec (file (read getattr map execute open)))
20009(allow artd profman (process (transition)))
20010(allow profman profman_exec (file (read getattr map execute open entrypoint)))
20011(allow profman artd (process (sigchld)))
20012(dontaudit artd profman (process (noatsecure)))
20013(allow artd profman (process (siginh rlimitinh)))
20014(typetransition artd profman_exec process profman)
20015(allow artd dex2oat_exec (file (read getattr map execute open)))
20016(allow artd dex2oat (process (transition)))
20017(allow dex2oat dex2oat_exec (file (read getattr map execute open entrypoint)))
20018(allow dex2oat artd (process (sigchld)))
20019(dontaudit artd dex2oat (process (noatsecure)))
20020(allow artd dex2oat (process (siginh rlimitinh)))
20021(typetransition artd dex2oat_exec process dex2oat)
20022(allow artd profman (process (sigkill)))
20023(allow artd dex2oat (process (sigkill)))
20024(allow artd profman (dir (ioctl read getattr lock open watch watch_reads search)))
20025(allow artd profman (file (ioctl read getattr lock map open watch watch_reads)))
20026(allow artd profman (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20027(allow artd dex2oat (dir (ioctl read getattr lock open watch watch_reads search)))
20028(allow artd dex2oat (file (ioctl read getattr lock map open watch watch_reads)))
20029(allow artd dex2oat (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20030(allow artd artd_tmpfs (file (open)))
20031(allow atrace boottrace_data_file (dir (search)))
20032(allow atrace boottrace_data_file (file (ioctl read getattr lock map open watch watch_reads)))
20033(allow atrace debugfs_tracing (dir (ioctl read getattr lock open watch watch_reads search)))
20034(allow atrace debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
20035(allow atrace debugfs_trace_marker (file (getattr)))
20036(allow atrace traced_probes (fd (use)))
20037(allow atrace traced_probes (fifo_file (write getattr)))
20038(allow atrace property_socket (sock_file (write)))
20039(allow atrace init (unix_stream_socket (connectto)))
20040(allow atrace debug_prop (property_service (set)))
20041(allow atrace debug_prop (file (read getattr map open)))
20042(allow atrace base_typeattr_651 (service_manager (find)))
20043(allow atrace servicemanager (service_manager (list)))
20044(allow atrace servicemanager (binder (call transfer)))
20045(allow servicemanager atrace (binder (call transfer)))
20046(allow servicemanager atrace (dir (search)))
20047(allow servicemanager atrace (file (read open)))
20048(allow servicemanager atrace (process (getattr)))
20049(allow atrace surfaceflinger (binder (call)))
20050(allow atrace system_server (binder (call)))
20051(allow atrace cameraserver (binder (call)))
20052(dontaudit atrace hwservice_manager_type (hwservice_manager (find)))
20053(dontaudit atrace service_manager_type (service_manager (find)))
20054(dontaudit atrace domain (binder (call)))
20055(allow atrace hwservicemanager_prop (file (read getattr map open)))
20056(dontaudit atrace debugfs_tracing_debug (file (audit_access)))
20057(allow init audioserver_exec (file (read getattr map execute open)))
20058(allow init audioserver (process (transition)))
20059(allow audioserver audioserver_exec (file (read getattr map execute open entrypoint)))
20060(dontaudit init audioserver (process (noatsecure)))
20061(allow init audioserver (process (siginh rlimitinh)))
20062(typetransition init audioserver_exec process audioserver)
20063(typetransition audioserver tmpfs file audioserver_tmpfs)
20064(allow audioserver audioserver_tmpfs (file (read write getattr map)))
20065(allow audioserver sdcard_type (dir (ioctl read getattr lock open watch watch_reads search)))
20066(allow audioserver sdcard_type (file (ioctl read getattr lock map open watch watch_reads)))
20067(allow audioserver sdcard_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20068(allow audioserver fuse (dir (ioctl read getattr lock open watch watch_reads search)))
20069(allow audioserver fuse (file (ioctl read getattr lock map open watch watch_reads)))
20070(allow audioserver fuse (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20071(allow audioserver servicemanager (binder (call transfer)))
20072(allow servicemanager audioserver (binder (call transfer)))
20073(allow servicemanager audioserver (dir (search)))
20074(allow servicemanager audioserver (file (read open)))
20075(allow servicemanager audioserver (process (getattr)))
20076(allow audioserver binderservicedomain (binder (call transfer)))
20077(allow binderservicedomain audioserver (binder (transfer)))
20078(allow audioserver binderservicedomain (fd (use)))
20079(allow audioserver appdomain (binder (call transfer)))
20080(allow appdomain audioserver (binder (transfer)))
20081(allow audioserver appdomain (fd (use)))
20082(allow audioserver system_file (dir (ioctl read getattr lock open watch watch_reads search)))
20083(allow audioserver system_file (file (ioctl read getattr lock map open watch watch_reads)))
20084(allow audioserver system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20085(allow audioserver audioserver_service (service_manager (add find)))
20086;;* lmx 33 system/sepolicy/private/audioserver.te
20087
20088(neverallow base_typeattr_652 audioserver_service (service_manager (add)))
20089;;* lme
20090
20091(allow audioserver activity_service (service_manager (find)))
20092(allow audioserver appops_service (service_manager (find)))
20093(allow audioserver batterystats_service (service_manager (find)))
20094(allow audioserver external_vibrator_service (service_manager (find)))
20095(allow audioserver package_native_service (service_manager (find)))
20096(allow audioserver permission_service (service_manager (find)))
20097(allow audioserver permission_checker_service (service_manager (find)))
20098(allow audioserver power_service (service_manager (find)))
20099(allow audioserver scheduling_policy_service (service_manager (find)))
20100(allow audioserver mediametrics_service (service_manager (find)))
20101(allow audioserver sensor_privacy_service (service_manager (find)))
20102(allow audioserver soundtrigger_middleware_service (service_manager (find)))
20103(allow audioserver audio_service (service_manager (find)))
20104(allow audioserver property_socket (sock_file (write)))
20105(allow audioserver init (unix_stream_socket (connectto)))
20106(allow audioserver bluetooth_a2dp_offload_prop (property_service (set)))
20107(allow audioserver bluetooth_a2dp_offload_prop (file (read getattr map open)))
20108(allow audioserver property_socket (sock_file (write)))
20109(allow audioserver init (unix_stream_socket (connectto)))
20110(allow audioserver bluetooth_audio_hal_prop (property_service (set)))
20111(allow audioserver bluetooth_audio_hal_prop (file (read getattr map open)))
20112(allow audioserver property_socket (sock_file (write)))
20113(allow audioserver init (unix_stream_socket (connectto)))
20114(allow audioserver bluetooth_prop (property_service (set)))
20115(allow audioserver bluetooth_prop (file (read getattr map open)))
20116(allow audioserver property_socket (sock_file (write)))
20117(allow audioserver init (unix_stream_socket (connectto)))
20118(allow audioserver exported_bluetooth_prop (property_service (set)))
20119(allow audioserver exported_bluetooth_prop (file (read getattr map open)))
20120(allow audioserver audio_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
20121(allow audioserver audio_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20122(allow audioserver audio_device (chr_file (read write)))
20123(allow audioserver bluetooth_socket (sock_file (write)))
20124(allow audioserver bluetooth (unix_stream_socket (connectto)))
20125(allow audioserver adbd (fd (use)))
20126(allow audioserver adbd (unix_stream_socket (read write)))
20127(allow audioserver shell (fifo_file (read write)))
20128(allow audioserver property_socket (sock_file (write)))
20129(allow audioserver init (unix_stream_socket (connectto)))
20130(allow audioserver log_tag_prop (property_service (set)))
20131(allow audioserver log_tag_prop (file (read getattr map open)))
20132;;* lmx 88 system/sepolicy/private/audioserver.te
20133
20134(neverallow audioserver fs_type (file (execute_no_trans)))
20135(neverallow audioserver file_type (file (execute_no_trans)))
20136;;* lme
20137
20138;;* lmx 100 system/sepolicy/private/audioserver.te
20139
20140(neverallow audioserver domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
20141(neverallow audioserver domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
20142;;* lme
20143
20144;;* lmx 101 system/sepolicy/private/audioserver.te
20145
20146(neverallow audioserver domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
20147;;* lme
20148
20149(allow audioserver sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
20150(allow audioserver self (capability2 (block_suspend)))
20151(allow audioserver self (cap2_userns (block_suspend)))
20152(allow audioserver system_suspend_server (binder (call transfer)))
20153(allow system_suspend_server audioserver (binder (transfer)))
20154(allow audioserver system_suspend_server (fd (use)))
20155(allow audioserver system_suspend_hwservice (hwservice_manager (find)))
20156(allow audioserver hwservicemanager (binder (call transfer)))
20157(allow hwservicemanager audioserver (binder (call transfer)))
20158(allow hwservicemanager audioserver (dir (search)))
20159(allow hwservicemanager audioserver (file (read map open)))
20160(allow hwservicemanager audioserver (process (getattr)))
20161(allow audioserver hwservicemanager_prop (file (read getattr map open)))
20162(allow audioserver hidl_manager_hwservice (hwservice_manager (find)))
20163(allow audioserver hal_system_suspend_service (service_manager (find)))
20164(allow audioserver servicemanager (binder (call transfer)))
20165(allow servicemanager audioserver (binder (call transfer)))
20166(allow servicemanager audioserver (dir (search)))
20167(allow servicemanager audioserver (file (read open)))
20168(allow servicemanager audioserver (process (getattr)))
20169(allow audioserver audio_config_prop (file (read getattr map open)))
20170(allow audioserver system_audio_config_prop (file (read getattr map open)))
20171(allow init auditctl_exec (file (read getattr map execute open)))
20172(allow init auditctl (process (transition)))
20173(allow auditctl auditctl_exec (file (read getattr map execute open entrypoint)))
20174(dontaudit init auditctl (process (noatsecure)))
20175(allow init auditctl (process (siginh rlimitinh)))
20176(typetransition init auditctl_exec process auditctl)
20177(allow auditctl self (capability (audit_control)))
20178(allow auditctl self (cap_userns (audit_control)))
20179(allow auditctl self (netlink_audit_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_write)))
20180(allow automotive_display_service fwk_automotive_display_hwservice (hwservice_manager (add find)))
20181(allow automotive_display_service hidl_base_hwservice (hwservice_manager (add)))
20182;;* lmx 8 system/sepolicy/private/automotive_display_service.te
20183
20184(neverallow base_typeattr_653 fwk_automotive_display_hwservice (hwservice_manager (add)))
20185;;* lme
20186
20187(allow init automotive_display_service_exec (file (read getattr map execute open)))
20188(allow init automotive_display_service (process (transition)))
20189(allow automotive_display_service automotive_display_service_exec (file (read getattr map execute open entrypoint)))
20190(dontaudit init automotive_display_service (process (noatsecure)))
20191(allow init automotive_display_service (process (siginh rlimitinh)))
20192(typetransition init automotive_display_service_exec process automotive_display_service)
20193(allow automotive_display_service servicemanager (binder (call transfer)))
20194(allow servicemanager automotive_display_service (binder (call transfer)))
20195(allow servicemanager automotive_display_service (dir (search)))
20196(allow servicemanager automotive_display_service (file (read open)))
20197(allow servicemanager automotive_display_service (process (getattr)))
20198(allow automotive_display_service hwservicemanager (binder (call transfer)))
20199(allow hwservicemanager automotive_display_service (binder (call transfer)))
20200(allow hwservicemanager automotive_display_service (dir (search)))
20201(allow hwservicemanager automotive_display_service (file (read map open)))
20202(allow hwservicemanager automotive_display_service (process (getattr)))
20203(allow automotive_display_service hwservicemanager_prop (file (read getattr map open)))
20204(allow automotive_display_service surfaceflinger_service (service_manager (find)))
20205(allow automotive_display_service surfaceflinger (binder (call transfer)))
20206(allow surfaceflinger automotive_display_service (binder (transfer)))
20207(allow automotive_display_service surfaceflinger (fd (use)))
20208(allow automotive_display_service hal_graphics_mapper_hwservice (hwservice_manager (find)))
20209(allow automotive_display_service hidl_token_hwservice (hwservice_manager (find)))
20210(allow automotive_display_service gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20211(allow automotive_display_service gpu_device (dir (search)))
20212(allow automotive_display_service fwk_automotive_display_service (service_manager (add find)))
20213;;* lmx 41 system/sepolicy/private/automotive_display_service.te
20214
20215(neverallow base_typeattr_653 fwk_automotive_display_service (service_manager (add)))
20216;;* lme
20217
20218(allow automotive_display_service hal_evs (binder (call transfer)))
20219(allow hal_evs automotive_display_service (binder (transfer)))
20220(allow automotive_display_service hal_evs (fd (use)))
20221(allow binderservicedomain dumpstate (fd (use)))
20222(allow binderservicedomain incidentd (fd (use)))
20223(allow binderservicedomain dumpstate (unix_stream_socket (read write getattr getopt)))
20224(allow binderservicedomain incidentd (unix_stream_socket (read write getattr getopt)))
20225(allow binderservicedomain dumpstate (fifo_file (write getattr)))
20226(allow binderservicedomain incidentd (fifo_file (write getattr)))
20227(allow binderservicedomain shell_data_file (file (write getattr)))
20228(allow binderservicedomain devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20229(allow binderservicedomain console_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20230(allow binderservicedomain appdomain (fd (use)))
20231(allow binderservicedomain appdomain (fifo_file (write)))
20232(allow binderservicedomain permission_service (service_manager (find)))
20233(allow binderservicedomain keystore (keystore2_key (delete get_info rebind use)))
20234(allow keystore binderservicedomain (dir (search)))
20235(allow keystore binderservicedomain (file (read open)))
20236(allow keystore binderservicedomain (process (getattr)))
20237(allow binderservicedomain apc_service (service_manager (find)))
20238(allow binderservicedomain keystore_service (service_manager (find)))
20239(allow binderservicedomain legacykeystore_service (service_manager (find)))
20240(allow binderservicedomain keystore (binder (call transfer)))
20241(allow keystore binderservicedomain (binder (transfer)))
20242(allow binderservicedomain keystore (fd (use)))
20243(allow keystore binderservicedomain (binder (call transfer)))
20244(allow binderservicedomain keystore (binder (transfer)))
20245(allow keystore binderservicedomain (fd (use)))
20246(allow binderservicedomain apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
20247(allow binderservicedomain apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
20248(allow binderservicedomain vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
20249(allow binderservicedomain vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
20250(allow binderservicedomain vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20251(allow init blank_screen_exec (file (read getattr map execute open)))
20252(allow init blank_screen (process (transition)))
20253(allow blank_screen blank_screen_exec (file (read getattr map execute open entrypoint)))
20254(dontaudit init blank_screen (process (noatsecure)))
20255(allow init blank_screen (process (siginh rlimitinh)))
20256(typetransition init blank_screen_exec process blank_screen)
20257(allow blkid block_device (dir (search)))
20258(allow blkid userdata_block_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
20259(allow blkid dm_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
20260(allow blkid vold (fd (use)))
20261(allow blkid vold (fifo_file (read write getattr)))
20262(allow blkid blkid_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
20263;;* lmx 21 system/sepolicy/private/blkid.te
20264
20265(neverallow base_typeattr_339 blkid (process (transition)))
20266;;* lme
20267
20268;;* lmx 22 system/sepolicy/private/blkid.te
20269
20270(neverallow base_typeattr_224 blkid (process (dyntransition)))
20271;;* lme
20272
20273;;* lmx 23 system/sepolicy/private/blkid.te
20274
20275(neverallow blkid base_typeattr_654 (file (entrypoint)))
20276;;* lme
20277
20278(allow blkid_untrusted block_device (dir (search)))
20279(allow blkid_untrusted vold_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
20280(allow blkid_untrusted vold (fd (use)))
20281(allow blkid_untrusted vold (fifo_file (read write getattr)))
20282(allow blkid_untrusted blkid_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
20283;;* lmx 33 system/sepolicy/private/blkid_untrusted.te
20284
20285(neverallow blkid_untrusted dm_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20286(neverallow blkid_untrusted root_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20287(neverallow blkid_untrusted frp_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20288(neverallow blkid_untrusted system_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20289(neverallow blkid_untrusted recovery_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20290(neverallow blkid_untrusted boot_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20291(neverallow blkid_untrusted userdata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20292(neverallow blkid_untrusted cache_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20293(neverallow blkid_untrusted swap_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20294(neverallow blkid_untrusted metadata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20295;;* lme
20296
20297;;* lmx 36 system/sepolicy/private/blkid_untrusted.te
20298
20299(neverallow base_typeattr_339 blkid_untrusted (process (transition)))
20300;;* lme
20301
20302;;* lmx 37 system/sepolicy/private/blkid_untrusted.te
20303
20304(neverallow base_typeattr_224 blkid_untrusted (process (dyntransition)))
20305;;* lme
20306
20307;;* lmx 38 system/sepolicy/private/blkid_untrusted.te
20308
20309(neverallow blkid_untrusted base_typeattr_654 (file (entrypoint)))
20310;;* lme
20311
20312(typetransition bluetooth tmpfs file appdomain_tmpfs)
20313(allow bluetooth bluetooth_userfaultfd (anon_inode (ioctl read create)))
20314(dontaudit su bluetooth_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
20315;;* lmx 5 system/sepolicy/private/bluetooth.te
20316
20317(neverallow base_typeattr_655 bluetooth_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
20318;;* lme
20319
20320(allow bluetooth appdomain_tmpfs (file (read write getattr map execute)))
20321;;* lmx 5 system/sepolicy/private/bluetooth.te
20322
20323(neverallow base_typeattr_656 base_typeattr_655 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20324;;* lme
20325
20326;;* lmx 5 system/sepolicy/private/bluetooth.te
20327
20328(neverallow base_typeattr_657 bluetooth (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20329;;* lme
20330
20331;;* lmx 5 system/sepolicy/private/bluetooth.te
20332
20333(neverallow base_typeattr_658 bluetooth (process (ptrace)))
20334;;* lme
20335
20336(typetransition bluetooth bluetooth_data_file sock_file bluetooth_socket)
20337(allowx bluetooth self (ioctl udp_socket (0x6900 0x6902)))
20338(allowx bluetooth self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
20339(allowx bluetooth self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
20340(allow bluetooth sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
20341(allow bluetooth self (capability2 (block_suspend)))
20342(allow bluetooth self (cap2_userns (block_suspend)))
20343(allow bluetooth system_suspend_server (binder (call transfer)))
20344(allow system_suspend_server bluetooth (binder (transfer)))
20345(allow bluetooth system_suspend_server (fd (use)))
20346(allow bluetooth system_suspend_hwservice (hwservice_manager (find)))
20347(allow bluetooth hwservicemanager (binder (call transfer)))
20348(allow hwservicemanager bluetooth (binder (call transfer)))
20349(allow hwservicemanager bluetooth (dir (search)))
20350(allow hwservicemanager bluetooth (file (read map open)))
20351(allow hwservicemanager bluetooth (process (getattr)))
20352(allow bluetooth hwservicemanager_prop (file (read getattr map open)))
20353(allow bluetooth hidl_manager_hwservice (hwservice_manager (find)))
20354(allow bluetooth hal_system_suspend_service (service_manager (find)))
20355(allow bluetooth servicemanager (binder (call transfer)))
20356(allow servicemanager bluetooth (binder (call transfer)))
20357(allow servicemanager bluetooth (dir (search)))
20358(allow servicemanager bluetooth (file (read open)))
20359(allow servicemanager bluetooth (process (getattr)))
20360(allow bluetooth bluetooth_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
20361(allow bluetooth bluetooth_data_file (file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
20362(allow bluetooth bluetooth_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
20363(allow bluetooth bluetooth_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
20364(allow bluetooth bluetooth_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
20365(allow bluetooth bluetooth_logs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
20366(allow bluetooth bluetooth_logs_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20367(allow bluetooth bluetooth_socket (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20368(allow bluetooth self (capability (net_admin)))
20369(allow bluetooth self (cap_userns (net_admin)))
20370(allow bluetooth self (capability2 (wake_alarm)))
20371(allow bluetooth self (cap2_userns (wake_alarm)))
20372(allow bluetooth self (packet_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
20373(allow bluetooth self (capability (net_bind_service net_admin net_raw)))
20374(allow bluetooth self (cap_userns (net_bind_service net_admin net_raw)))
20375(allow bluetooth self (tun_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
20376(allow bluetooth tun_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20377(allowx bluetooth tun_device (ioctl chr_file (0x54ca 0x54d2)))
20378(allow bluetooth efs_file (dir (search)))
20379(allow bluetooth uhid_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20380(allow bluetooth gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20381(allow bluetooth gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
20382(allow bluetooth proc_bluetooth_writable (file (ioctl read write getattr lock append map open watch watch_reads)))
20383(allow bluetooth proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
20384(allow bluetooth incremental_prop (file (read getattr map open)))
20385(allow bluetooth device_logging_prop (file (read getattr map open)))
20386(allow bluetooth property_socket (sock_file (write)))
20387(allow bluetooth init (unix_stream_socket (connectto)))
20388(allow bluetooth binder_cache_bluetooth_server_prop (property_service (set)))
20389(allow bluetooth binder_cache_bluetooth_server_prop (file (read getattr map open)))
20390;;* lmx 55 system/sepolicy/private/bluetooth.te
20391
20392(neverallow base_typeattr_659 binder_cache_bluetooth_server_prop (property_service (set)))
20393;;* lme
20394
20395(allow bluetooth property_socket (sock_file (write)))
20396(allow bluetooth init (unix_stream_socket (connectto)))
20397(allow bluetooth bluetooth_a2dp_offload_prop (property_service (set)))
20398(allow bluetooth bluetooth_a2dp_offload_prop (file (read getattr map open)))
20399(allow bluetooth property_socket (sock_file (write)))
20400(allow bluetooth init (unix_stream_socket (connectto)))
20401(allow bluetooth bluetooth_audio_hal_prop (property_service (set)))
20402(allow bluetooth bluetooth_audio_hal_prop (file (read getattr map open)))
20403(allow bluetooth property_socket (sock_file (write)))
20404(allow bluetooth init (unix_stream_socket (connectto)))
20405(allow bluetooth bluetooth_prop (property_service (set)))
20406(allow bluetooth bluetooth_prop (file (read getattr map open)))
20407(allow bluetooth property_socket (sock_file (write)))
20408(allow bluetooth init (unix_stream_socket (connectto)))
20409(allow bluetooth exported_bluetooth_prop (property_service (set)))
20410(allow bluetooth exported_bluetooth_prop (file (read getattr map open)))
20411(allow bluetooth property_socket (sock_file (write)))
20412(allow bluetooth init (unix_stream_socket (connectto)))
20413(allow bluetooth pan_result_prop (property_service (set)))
20414(allow bluetooth pan_result_prop (file (read getattr map open)))
20415(allow bluetooth audioserver_service (service_manager (find)))
20416(allow bluetooth bluetooth_service (service_manager (find)))
20417(allow bluetooth drmserver_service (service_manager (find)))
20418(allow bluetooth mediaserver_service (service_manager (find)))
20419(allow bluetooth radio_service (service_manager (find)))
20420(allow bluetooth app_api_service (service_manager (find)))
20421(allow bluetooth system_api_service (service_manager (find)))
20422(allow bluetooth network_stack_service (service_manager (find)))
20423(allow bluetooth system_suspend_control_service (service_manager (find)))
20424(allow bluetooth hal_audio_service (service_manager (find)))
20425(allow bluetooth shell_data_file (file (read)))
20426(allow bluetooth self (capability (sys_nice)))
20427(allow bluetooth self (cap_userns (sys_nice)))
20428(allow bluetooth runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
20429;;* lmx 97 system/sepolicy/private/bluetooth.te
20430
20431(neverallow bluetooth self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_broadcast ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
20432(neverallow bluetooth self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_broadcast ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
20433;;* lme
20434
20435;;* lmx 98 system/sepolicy/private/bluetooth.te
20436
20437(neverallow bluetooth self (capability2 (mac_override mac_admin syslog audit_read perfmon)))
20438(neverallow bluetooth self (cap2_userns (mac_override mac_admin syslog audit_read perfmon)))
20439;;* lme
20440
20441(allow bluetoothdomain bluetooth (unix_stream_socket (ioctl read write getattr getopt setopt shutdown)))
20442(allow init bootanim_exec (file (read getattr map execute open)))
20443(allow init bootanim (process (transition)))
20444(allow bootanim bootanim_exec (file (read getattr map execute open entrypoint)))
20445(dontaudit init bootanim (process (noatsecure)))
20446(allow init bootanim (process (siginh rlimitinh)))
20447(typetransition init bootanim_exec process bootanim)
20448(dontaudit bootanim unlabeled (dir (search)))
20449(dontaudit bootanim vendor_default_prop (file (read)))
20450(allow bootanim bootloader_boot_reason_prop (file (read getattr map open)))
20451(allow bootanim bootanim_config_prop (file (read getattr map open)))
20452(allow bootanim property_socket (sock_file (write)))
20453(allow bootanim init (unix_stream_socket (connectto)))
20454(allow bootanim bootanim_system_prop (property_service (set)))
20455(allow bootanim bootanim_system_prop (file (read getattr map open)))
20456(allow bootanim bootanim_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
20457(allow bootanim bootanim_data_file (file (ioctl read getattr lock map open watch watch_reads)))
20458(allow bootanim bootanim_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
20459(allow bootanim vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
20460(allow init bootstat_exec (file (read getattr map execute open)))
20461(allow init bootstat (process (transition)))
20462(allow bootstat bootstat_exec (file (read getattr map execute open entrypoint)))
20463(dontaudit init bootstat (process (noatsecure)))
20464(allow init bootstat (process (siginh rlimitinh)))
20465(typetransition init bootstat_exec process bootstat)
20466(allow bootstat boottime_prop (file (read getattr map open)))
20467(allow bootstat property_socket (sock_file (write)))
20468(allow bootstat init (unix_stream_socket (connectto)))
20469(allow bootstat bootloader_boot_reason_prop (property_service (set)))
20470(allow bootstat bootloader_boot_reason_prop (file (read getattr map open)))
20471(allow bootstat property_socket (sock_file (write)))
20472(allow bootstat init (unix_stream_socket (connectto)))
20473(allow bootstat system_boot_reason_prop (property_service (set)))
20474(allow bootstat system_boot_reason_prop (file (read getattr map open)))
20475(allow bootstat property_socket (sock_file (write)))
20476(allow bootstat init (unix_stream_socket (connectto)))
20477(allow bootstat last_boot_reason_prop (property_service (set)))
20478(allow bootstat last_boot_reason_prop (file (read getattr map open)))
20479;;* lmx 24 system/sepolicy/private/bootstat.te
20480
20481(neverallow base_typeattr_660 bootloader_boot_reason_prop (file (ioctl read getattr lock map open watch watch_reads)))
20482(neverallow base_typeattr_660 last_boot_reason_prop (file (ioctl read getattr lock map open watch watch_reads)))
20483;;* lme
20484
20485;;* lmx 26 system/sepolicy/private/bootstat.te
20486
20487(neverallow bootanim last_boot_reason_prop (file (ioctl read getattr lock map open watch watch_reads)))
20488(neverallow recovery last_boot_reason_prop (file (ioctl read getattr lock map open watch watch_reads)))
20489;;* lme
20490
20491;;* lmx 33 system/sepolicy/private/bootstat.te
20492
20493(neverallow base_typeattr_661 bootloader_boot_reason_prop (property_service (set)))
20494(neverallow base_typeattr_661 last_boot_reason_prop (property_service (set)))
20495;;* lme
20496
20497;;* lmx 35 system/sepolicy/private/bootstat.te
20498
20499(neverallow system_server bootloader_boot_reason_prop (property_service (set)))
20500;;* lme
20501
20502(allow init boringssl_self_test_exec (file (read getattr map execute open)))
20503(allow init boringssl_self_test (process (transition)))
20504(allow boringssl_self_test boringssl_self_test_exec (file (read getattr map execute open entrypoint)))
20505(dontaudit init boringssl_self_test (process (noatsecure)))
20506(allow init boringssl_self_test (process (siginh rlimitinh)))
20507(typetransition init boringssl_self_test_exec process boringssl_self_test)
20508(allow init vendor_boringssl_self_test_exec (file (read getattr map execute open)))
20509(allow init vendor_boringssl_self_test (process (transition)))
20510(allow vendor_boringssl_self_test vendor_boringssl_self_test_exec (file (read getattr map execute open entrypoint)))
20511(dontaudit init vendor_boringssl_self_test (process (noatsecure)))
20512(allow init vendor_boringssl_self_test (process (siginh rlimitinh)))
20513(typetransition init vendor_boringssl_self_test_exec process vendor_boringssl_self_test)
20514(allow boringssl_self_test boringssl_self_test_marker (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20515(allow vendor_boringssl_self_test boringssl_self_test_marker (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20516(allow boringssl_self_test boringssl_self_test_marker (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
20517(allow vendor_boringssl_self_test boringssl_self_test_marker (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
20518(allow boringssl_self_test kmsg_debug_device (chr_file (ioctl write getattr lock append map open)))
20519(allow vendor_boringssl_self_test kmsg_debug_device (chr_file (ioctl write getattr lock append map open)))
20520;;* lmx 66 system/sepolicy/private/boringssl_self_test.te
20521
20522(neverallow base_typeattr_662 boringssl_self_test_marker (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20523;;* lme
20524
20525;;* lmx 74 system/sepolicy/private/boringssl_self_test.te
20526
20527(neverallow base_typeattr_662 boringssl_self_test_marker (dir (write)))
20528;;* lme
20529
20530;;* lmx 10 system/sepolicy/private/bpfdomain.te
20531
20532(neverallow base_typeattr_663 self (capability (net_admin net_raw)))
20533(neverallow base_typeattr_663 self (cap_userns (net_admin net_raw)))
20534;;* lme
20535
20536;;* lmx 13 system/sepolicy/private/bpfdomain.te
20537
20538(neverallow base_typeattr_664 base_typeattr_224 (bpf (map_create map_read map_write prog_load prog_run)))
20539;;* lme
20540
20541(allow bpfdomain fs_bpf (dir (search)))
20542(allow bpfdomain bpffs_type (lnk_file (read)))
20543(allow bpfdomain bpf_progs_loaded_prop (file (read getattr map open)))
20544(allow bpfloader kmsg_device (chr_file (write lock append map open)))
20545(allow bpfloader bpffs_type (dir (write create add_name remove_name search)))
20546(allow bpfloader bpffs_type (file (read create getattr setattr rename)))
20547(allow bpfloader bpffs_type (lnk_file (read create getattr)))
20548(allow base_typeattr_665 fs_bpf (filesystem (associate)))
20549(allow bpfloader self (bpf (map_create map_read map_write prog_load prog_run)))
20550(allow bpfloader self (capability (chown net_admin sys_admin)))
20551(allow bpfloader sysfs_fs_fuse_bpf (file (ioctl read getattr lock map open watch watch_reads)))
20552(allow bpfloader proc_bpf (file (write lock append map open)))
20553(allow bpfloader property_socket (sock_file (write)))
20554(allow bpfloader init (unix_stream_socket (connectto)))
20555(allow bpfloader bpf_progs_loaded_prop (property_service (set)))
20556(allow bpfloader bpf_progs_loaded_prop (file (read getattr map open)))
20557(allow bpfloader bpfloader_exec (file (execute_no_trans)))
20558;;* lmx 32 system/sepolicy/private/bpfloader.te
20559
20560(neverallow domain bpffs_type (dir (ioctl read setattr lock relabelfrom relabelto append map unlink link rename execute quotaon audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads reparent rmdir)))
20561;;* lme
20562
20563;;* lmx 33 system/sepolicy/private/bpfloader.te
20564
20565(neverallow base_typeattr_666 bpffs_type (dir (write create add_name remove_name)))
20566;;* lme
20567
20568;;* lmx 35 system/sepolicy/private/bpfloader.te
20569
20570(neverallow domain bpffs_type (file (ioctl lock relabelfrom relabelto append unlink link execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
20571;;* lme
20572
20573;;* lmx 36 system/sepolicy/private/bpfloader.te
20574
20575(neverallow base_typeattr_666 bpffs_type (file (create setattr map rename open)))
20576;;* lme
20577
20578;;* lmx 37 system/sepolicy/private/bpfloader.te
20579
20580(neverallow base_typeattr_667 fs_bpf (file (read getattr)))
20581;;* lme
20582
20583;;* lmx 38 system/sepolicy/private/bpfloader.te
20584
20585(neverallow base_typeattr_666 fs_bpf_loader (file (read getattr)))
20586;;* lme
20587
20588;;* lmx 39 system/sepolicy/private/bpfloader.te
20589
20590(neverallow base_typeattr_668 fs_bpf_net_private (file (read getattr)))
20591;;* lme
20592
20593;;* lmx 40 system/sepolicy/private/bpfloader.te
20594
20595(neverallow base_typeattr_669 fs_bpf_net_shared (file (read getattr)))
20596;;* lme
20597
20598;;* lmx 41 system/sepolicy/private/bpfloader.te
20599
20600(neverallow base_typeattr_670 fs_bpf_netd_readonly (file (read getattr)))
20601;;* lme
20602
20603;;* lmx 42 system/sepolicy/private/bpfloader.te
20604
20605(neverallow base_typeattr_671 fs_bpf_netd_shared (file (read getattr)))
20606;;* lme
20607
20608;;* lmx 43 system/sepolicy/private/bpfloader.te
20609
20610(neverallow base_typeattr_668 fs_bpf_tethering (file (read getattr)))
20611;;* lme
20612
20613;;* lmx 44 system/sepolicy/private/bpfloader.te
20614
20615(neverallow base_typeattr_672 fs_bpf_uprobestats (file (read getattr)))
20616;;* lme
20617
20618;;* lmx 45 system/sepolicy/private/bpfloader.te
20619
20620(neverallow base_typeattr_673 base_typeattr_674 (file (write)))
20621;;* lme
20622
20623;;* lmx 47 system/sepolicy/private/bpfloader.te
20624
20625(neverallow base_typeattr_666 bpffs_type (lnk_file (ioctl write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
20626;;* lme
20627
20628;;* lmx 48 system/sepolicy/private/bpfloader.te
20629
20630(neverallow base_typeattr_664 bpffs_type (lnk_file (read)))
20631;;* lme
20632
20633;;* lmx 50 system/sepolicy/private/bpfloader.te
20634
20635(neverallow base_typeattr_666 base_typeattr_224 (bpf (map_create prog_load)))
20636;;* lme
20637
20638;;* lmx 53 system/sepolicy/private/bpfloader.te
20639
20640(neverallow base_typeattr_666 fs_bpf_loader (bpf (map_create map_read map_write prog_load prog_run)))
20641;;* lme
20642
20643;;* lmx 54 system/sepolicy/private/bpfloader.te
20644
20645(neverallow base_typeattr_666 fs_bpf_loader (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
20646;;* lme
20647
20648;;* lmx 67 system/sepolicy/private/bpfloader.te
20649
20650(neverallow base_typeattr_675 base_typeattr_224 (bpf (prog_run)))
20651;;* lme
20652
20653;;* lmx 68 system/sepolicy/private/bpfloader.te
20654
20655(neverallow base_typeattr_676 base_typeattr_224 (bpf (map_read map_write)))
20656;;* lme
20657
20658;;* lmx 69 system/sepolicy/private/bpfloader.te
20659
20660(neverallow base_typeattr_677 bpfloader_exec (file (execute execute_no_trans)))
20661;;* lme
20662
20663;;* lmx 71 system/sepolicy/private/bpfloader.te
20664
20665(neverallow base_typeattr_678 fs_bpf_vendor (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
20666;;* lme
20667
20668;;* lmx 73 system/sepolicy/private/bpfloader.te
20669
20670(neverallow bpfloader base_typeattr_224 (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
20671(neverallow bpfloader base_typeattr_224 (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
20672(neverallow bpfloader base_typeattr_224 (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
20673;;* lme
20674
20675;;* lmx 76 system/sepolicy/private/bpfloader.te
20676
20677(neverallow domain bpfloader (process (ptrace)))
20678;;* lme
20679
20680;;* lmx 78 system/sepolicy/private/bpfloader.te
20681
20682(neverallow base_typeattr_666 proc_bpf (file (write)))
20683;;* lme
20684
20685(allow init bufferhubd_exec (file (read getattr map execute open)))
20686(allow init bufferhubd (process (transition)))
20687(allow bufferhubd bufferhubd_exec (file (read getattr map execute open entrypoint)))
20688(dontaudit init bufferhubd (process (noatsecure)))
20689(allow init bufferhubd (process (siginh rlimitinh)))
20690(typetransition init bufferhubd_exec process bufferhubd)
20691(allow init cameraserver_exec (file (read getattr map execute open)))
20692(allow init cameraserver (process (transition)))
20693(allow cameraserver cameraserver_exec (file (read getattr map execute open entrypoint)))
20694(dontaudit init cameraserver (process (noatsecure)))
20695(allow init cameraserver (process (siginh rlimitinh)))
20696(typetransition init cameraserver_exec process cameraserver)
20697(typetransition cameraserver tmpfs file cameraserver_tmpfs)
20698(allow cameraserver cameraserver_tmpfs (file (read write getattr map)))
20699(allow cameraserver gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20700(allow cameraserver gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
20701(allow cameraserver virtual_camera (binder (call)))
20702(allow init canhalconfigurator_exec (file (read getattr map execute open)))
20703(allow init canhalconfigurator (process (transition)))
20704(allow canhalconfigurator canhalconfigurator_exec (file (read getattr map execute open entrypoint)))
20705(dontaudit init canhalconfigurator (process (noatsecure)))
20706(allow init canhalconfigurator (process (siginh rlimitinh)))
20707(typetransition init canhalconfigurator_exec process canhalconfigurator)
20708(allow canhalconfigurator servicemanager (binder (call transfer)))
20709(allow servicemanager canhalconfigurator (binder (call transfer)))
20710(allow servicemanager canhalconfigurator (dir (search)))
20711(allow servicemanager canhalconfigurator (file (read open)))
20712(allow servicemanager canhalconfigurator (process (getattr)))
20713(allow hal_can_controller canhalconfigurator (binder (call transfer)))
20714(allow canhalconfigurator hal_can_controller (binder (transfer)))
20715(allow hal_can_controller canhalconfigurator (fd (use)))
20716(allow charger property_socket (sock_file (write)))
20717(allow charger init (unix_stream_socket (connectto)))
20718(allow charger system_prop (property_service (set)))
20719(allow charger system_prop (file (read getattr map open)))
20720(allow charger property_socket (sock_file (write)))
20721(allow charger init (unix_stream_socket (connectto)))
20722(allow charger exported_system_prop (property_service (set)))
20723(allow charger exported_system_prop (file (read getattr map open)))
20724(allow charger property_socket (sock_file (write)))
20725(allow charger init (unix_stream_socket (connectto)))
20726(allow charger exported3_system_prop (property_service (set)))
20727(allow charger exported3_system_prop (file (read getattr map open)))
20728(allow charger charger_prop (file (read getattr map open)))
20729;;* lmx 13 system/sepolicy/private/charger.te
20730
20731(neverallow base_typeattr_679 charger_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20732;;* lme
20733
20734(allow charger_type property_socket (sock_file (write)))
20735(allow charger_type init (unix_stream_socket (connectto)))
20736(allow charger_type charger_status_prop (property_service (set)))
20737(allow charger_type charger_status_prop (file (read getattr map open)))
20738(allow charger_type charger_config_prop (file (read getattr map open)))
20739(allow charger_type recovery_config_prop (file (read getattr map open)))
20740;;* lmx 16 system/sepolicy/private/charger_type.te
20741
20742(neverallow base_typeattr_259 charger_config_prop (property_service (set)))
20743;;* lme
20744
20745;;* lmx 26 system/sepolicy/private/charger_type.te
20746
20747(neverallow base_typeattr_680 charger_status_prop (property_service (set)))
20748;;* lme
20749
20750;;* lmx 38 system/sepolicy/private/charger_type.te
20751
20752(neverallow base_typeattr_681 charger_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20753(neverallow base_typeattr_681 charger_status_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20754;;* lme
20755
20756(allow clatd system_server (fd (use)))
20757(allow clatd system_server (packet_socket (read write)))
20758(allow clatd system_server (rawip_socket (read write)))
20759(allow clatd tun_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
20760(allow compos_fd_server composd (fd (use)))
20761(allow compos_fd_server apex_art_staging_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
20762(allow compos_fd_server apex_art_staging_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20763(allow compos_fd_server apex_art_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
20764(allow compos_fd_server apex_art_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20765(allow compos_fd_server composd (fifo_file (write)))
20766(allow compos_fd_server composd (fifo_file (read)))
20767(allow compos_fd_server self (vsock_socket (read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
20768;;* lmx 26 system/sepolicy/private/compos_fd_server.te
20769
20770(neverallow base_typeattr_682 compos_fd_server (process (transition)))
20771;;* lme
20772
20773;;* lmx 27 system/sepolicy/private/compos_fd_server.te
20774
20775(neverallow base_typeattr_224 compos_fd_server (process (dyntransition)))
20776;;* lme
20777
20778(allow compos_verify servicemanager (binder (call transfer)))
20779(allow servicemanager compos_verify (binder (call transfer)))
20780(allow servicemanager compos_verify (dir (search)))
20781(allow servicemanager compos_verify (file (read open)))
20782(allow servicemanager compos_verify (process (getattr)))
20783(allow compos_verify virtualizationmanager_exec (file (read getattr map execute open)))
20784(allow compos_verify virtualizationmanager (process (transition)))
20785(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
20786(allow virtualizationmanager compos_verify (process (sigchld)))
20787(dontaudit compos_verify virtualizationmanager (process (noatsecure)))
20788(allow compos_verify virtualizationmanager (process (siginh rlimitinh)))
20789(typetransition compos_verify virtualizationmanager_exec process virtualizationmanager)
20790(allow crosvm compos_verify (unix_stream_socket (ioctl read write getattr)))
20791(allow virtualizationmanager compos_verify (unix_stream_socket (ioctl read write getattr)))
20792(allow crosvm compos_verify (fd (use)))
20793(allow virtualizationmanager compos_verify (fd (use)))
20794(allow compos_verify virtualizationmanager (fd (use)))
20795(allow crosvm compos_verify (fifo_file (ioctl read write getattr)))
20796(allow virtualizationmanager compos_verify (fifo_file (ioctl read write getattr)))
20797(allow compos_verify virtualizationmanager (vsock_socket (read write getattr getopt)))
20798(allow compos_verify hypervisor_prop (file (read getattr map open)))
20799(allow compos_verify virtualizationservice_data_file (file (read getattr)))
20800(allow compos_verify apex_module_data_file (dir (search)))
20801(allow compos_verify apex_compos_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
20802(allow compos_verify apex_compos_data_file (file (ioctl read write create getattr lock append map open watch watch_reads)))
20803(allow compos_verify apex_art_data_file (dir (search)))
20804(allow compos_verify apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
20805(allow compos_verify odsign (fd (use)))
20806(allow compos_verify odsign_devpts (chr_file (read write)))
20807;;* lmx 23 system/sepolicy/private/compos_verify.te
20808
20809(neverallow base_typeattr_683 compos_verify (process (transition)))
20810;;* lme
20811
20812;;* lmx 24 system/sepolicy/private/compos_verify.te
20813
20814(neverallow base_typeattr_224 compos_verify (process (dyntransition)))
20815;;* lme
20816
20817(allow init composd_exec (file (read getattr map execute open)))
20818(allow init composd (process (transition)))
20819(allow composd composd_exec (file (read getattr map execute open entrypoint)))
20820(dontaudit init composd (process (noatsecure)))
20821(allow init composd (process (siginh rlimitinh)))
20822(typetransition init composd_exec process composd)
20823(allow composd servicemanager (binder (call transfer)))
20824(allow servicemanager composd (binder (call transfer)))
20825(allow servicemanager composd (dir (search)))
20826(allow servicemanager composd (file (read open)))
20827(allow servicemanager composd (process (getattr)))
20828(allow composd compos_service (service_manager (add find)))
20829;;* lmx 7 system/sepolicy/private/composd.te
20830
20831(neverallow base_typeattr_682 compos_service (service_manager (add)))
20832;;* lme
20833
20834(allow composd system_server (binder (call transfer)))
20835(allow system_server composd (binder (transfer)))
20836(allow composd system_server (fd (use)))
20837(allow composd virtualizationmanager_exec (file (read getattr map execute open)))
20838(allow composd virtualizationmanager (process (transition)))
20839(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
20840(allow virtualizationmanager composd (process (sigchld)))
20841(dontaudit composd virtualizationmanager (process (noatsecure)))
20842(allow composd virtualizationmanager (process (siginh rlimitinh)))
20843(typetransition composd virtualizationmanager_exec process virtualizationmanager)
20844(allow crosvm composd (unix_stream_socket (ioctl read write getattr)))
20845(allow virtualizationmanager composd (unix_stream_socket (ioctl read write getattr)))
20846(allow crosvm composd (fd (use)))
20847(allow virtualizationmanager composd (fd (use)))
20848(allow composd virtualizationmanager (fd (use)))
20849(allow crosvm composd (fifo_file (ioctl read write getattr)))
20850(allow virtualizationmanager composd (fifo_file (ioctl read write getattr)))
20851(allow composd virtualizationmanager (vsock_socket (read write getattr getopt)))
20852(allow composd hypervisor_prop (file (read getattr map open)))
20853(allow composd virtualizationservice_data_file (file (read getattr)))
20854(allow composd apex_art_data_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
20855(allow composd apex_art_staging_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
20856(allow composd apex_art_staging_data_file (file (getattr unlink)))
20857(allow composd apex_art_data_file (file (ioctl read write unlink open)))
20858(allowx composd apex_art_data_file (ioctl file (0x6685)))
20859(allow composd apex_module_data_file (dir (search)))
20860(allow composd apex_compos_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
20861(allow composd apex_compos_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
20862(allow composd fd_server_exec (file (read getattr map execute open)))
20863(allow composd compos_fd_server (process (transition)))
20864(allow compos_fd_server fd_server_exec (file (read getattr map execute open entrypoint)))
20865(allow compos_fd_server composd (process (sigchld)))
20866(dontaudit composd compos_fd_server (process (noatsecure)))
20867(allow composd compos_fd_server (process (siginh rlimitinh)))
20868(typetransition composd fd_server_exec process compos_fd_server)
20869(allow composd compos_fd_server (process (signal)))
20870(allow composd composd_vm_art_prop (file (read getattr map open)))
20871(allow composd composd_vm_vendor_prop (file (read getattr map open)))
20872(allow composd dalvik_config_prop_type (file (read getattr map open)))
20873(allow composd device_config_runtime_native_boot_prop (file (read getattr map open)))
20874;;* lmx 42 system/sepolicy/private/composd.te
20875
20876(neverallow composd apex_art_data_file (file (create)))
20877;;* lme
20878
20879;;* lmx 45 system/sepolicy/private/composd.te
20880
20881(neverallow base_typeattr_223 composd_vm_art_prop (property_service (set)))
20882;;* lme
20883
20884(allow coredomain apex_ready_prop (file (read getattr map open)))
20885(allow coredomain boot_status_prop (file (read getattr map open)))
20886(allow coredomain camera_config_prop (file (read getattr map open)))
20887(allow coredomain dalvik_config_prop_type (file (read getattr map open)))
20888(allow coredomain dalvik_runtime_prop (file (read getattr map open)))
20889(allow coredomain exported_pm_prop (file (read getattr map open)))
20890(allow coredomain ffs_config_prop (file (read getattr map open)))
20891(allow coredomain graphics_config_prop (file (read getattr map open)))
20892(allow coredomain graphics_config_writable_prop (file (read getattr map open)))
20893(allow coredomain hdmi_config_prop (file (read getattr map open)))
20894(allow coredomain init_service_status_private_prop (file (read getattr map open)))
20895(allow coredomain lmkd_config_prop (file (read getattr map open)))
20896(allow coredomain localization_prop (file (read getattr map open)))
20897(allow coredomain pm_prop (file (read getattr map open)))
20898(allow coredomain radio_control_prop (file (read getattr map open)))
20899(allow coredomain rollback_test_prop (file (read getattr map open)))
20900(allow coredomain setupwizard_prop (file (read getattr map open)))
20901(allow coredomain setupwizard_mode_prop (file (read getattr map open)))
20902(allow coredomain sqlite_log_prop (file (read getattr map open)))
20903(allow coredomain storagemanager_config_prop (file (read getattr map open)))
20904(allow coredomain surfaceflinger_color_prop (file (read getattr map open)))
20905(allow coredomain systemsound_config_prop (file (read getattr map open)))
20906(allow coredomain telephony_config_prop (file (read getattr map open)))
20907(allow coredomain usb_config_prop (file (read getattr map open)))
20908(allow coredomain usb_control_prop (file (read getattr map open)))
20909(allow coredomain userspace_reboot_config_prop (file (read getattr map open)))
20910(allow coredomain vold_config_prop (file (read getattr map open)))
20911(allow coredomain vts_status_prop (file (read getattr map open)))
20912(allow coredomain zygote_config_prop (file (read getattr map open)))
20913(allow coredomain zygote_wrap_prop (file (read getattr map open)))
20914(allow coredomain default_prop (file (read getattr map open)))
20915;;* lmx 35 system/sepolicy/private/coredomain.te
20916
20917(neverallow base_typeattr_684 sysfs_leds (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
20918;;* lme
20919
20920;;* lmx 51 system/sepolicy/private/coredomain.te
20921
20922(neverallow base_typeattr_685 vendor_app_file (dir (read getattr open search)))
20923;;* lme
20924
20925;;* lmx 70 system/sepolicy/private/coredomain.te
20926
20927(neverallow base_typeattr_686 vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
20928;;* lme
20929
20930;;* lmx 92 system/sepolicy/private/coredomain.te
20931
20932(neverallow base_typeattr_687 vendor_overlay_file (dir (read getattr open search)))
20933;;* lme
20934
20935;;* lmx 114 system/sepolicy/private/coredomain.te
20936
20937(neverallow base_typeattr_687 vendor_overlay_file (file (open)))
20938;;* lme
20939
20940;;* lmx 140 system/sepolicy/private/coredomain.te
20941
20942(neverallow base_typeattr_688 proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20943;;* lme
20944
20945;;* lmx 140 system/sepolicy/private/coredomain.te
20946
20947(neverallow base_typeattr_684 sysfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20948;;* lme
20949
20950;;* lmx 140 system/sepolicy/private/coredomain.te
20951
20952(neverallow base_typeattr_689 device (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20953(neverallow base_typeattr_689 device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20954;;* lme
20955
20956;;* lmx 140 system/sepolicy/private/coredomain.te
20957
20958(neverallow coredomain debugfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20959;;* lme
20960
20961;;* lmx 140 system/sepolicy/private/coredomain.te
20962
20963(neverallow base_typeattr_690 debugfs_tracing (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20964;;* lme
20965
20966;;* lmx 140 system/sepolicy/private/coredomain.te
20967
20968(neverallow base_typeattr_691 inotify (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20969;;* lme
20970
20971;;* lmx 140 system/sepolicy/private/coredomain.te
20972
20973(neverallow base_typeattr_692 pstorefs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20974;;* lme
20975
20976;;* lmx 140 system/sepolicy/private/coredomain.te
20977
20978(neverallow base_typeattr_693 configfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20979;;* lme
20980
20981;;* lmx 140 system/sepolicy/private/coredomain.te
20982
20983(neverallow base_typeattr_694 functionfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20984;;* lme
20985
20986;;* lmx 140 system/sepolicy/private/coredomain.te
20987
20988(neverallow base_typeattr_691 usbfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20989(neverallow base_typeattr_691 binfmt_miscfs (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20990;;* lme
20991
20992;;* lmx 140 system/sepolicy/private/coredomain.te
20993
20994(neverallow base_typeattr_695 base_typeattr_696 (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
20995;;* lme
20996
20997;;* lmx 254 system/sepolicy/private/coredomain.te
20998
20999(neverallow coredomain radio_device (chr_file (ioctl read write append open)))
21000(neverallow coredomain iio_device (chr_file (ioctl read write append open)))
21001;;* lme
21002
21003;;* lmx 258 system/sepolicy/private/coredomain.te
21004
21005(neverallow coredomain tee_device (chr_file (ioctl read write append open)))
21006;;* lme
21007
21008(allow init cppreopts_exec (file (read getattr map execute open)))
21009(allow init cppreopts (process (transition)))
21010(allow cppreopts cppreopts_exec (file (read getattr map execute open entrypoint)))
21011(dontaudit init cppreopts (process (noatsecure)))
21012(allow init cppreopts (process (siginh rlimitinh)))
21013(typetransition init cppreopts_exec process cppreopts)
21014(allow cppreopts preopt2cachename_exec (file (read getattr map execute open)))
21015(allow cppreopts preopt2cachename (process (transition)))
21016(allow preopt2cachename preopt2cachename_exec (file (read getattr map execute open entrypoint)))
21017(allow preopt2cachename cppreopts (process (sigchld)))
21018(dontaudit cppreopts preopt2cachename (process (noatsecure)))
21019(allow cppreopts preopt2cachename (process (siginh rlimitinh)))
21020(typetransition cppreopts preopt2cachename_exec process preopt2cachename)
21021(allow cppreopts dalvikcache_data_file (dir (write add_name remove_name search)))
21022(allow cppreopts dalvikcache_data_file (file (read write create getattr unlink rename open)))
21023(allow cppreopts shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21024(allow cppreopts system_file (dir (read open)))
21025(allow cppreopts toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21026(dontaudit cppreopts postinstall_mnt_dir (dir (search)))
21027(dontaudit crash_dump dev_type (chr_file (read write)))
21028(dontaudit crash_dump devpts (chr_file (read write)))
21029(allow crash_dump base_typeattr_697 (process (sigchld sigkill sigstop signal ptrace)))
21030(allow crash_dump apex_art_data_file (dir (getattr search)))
21031(allow crash_dump apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21032(allow crash_dump system_bootstrap_lib_file (dir (getattr search)))
21033(allow crash_dump system_bootstrap_lib_file (file (ioctl read getattr lock map open watch watch_reads)))
21034(allow crash_dump vendor_apex_metadata_file (dir (getattr search)))
21035;;* lmx 64 system/sepolicy/private/crash_dump.te
21036
21037(neverallow crash_dump apexd (process (sigkill sigstop signal ptrace)))
21038(neverallow crash_dump bpfloader (process (sigkill sigstop signal ptrace)))
21039(neverallow crash_dump init (process (sigkill sigstop signal ptrace)))
21040(neverallow crash_dump kernel (process (sigkill sigstop signal ptrace)))
21041(neverallow crash_dump keystore (process (sigkill sigstop signal ptrace)))
21042(neverallow crash_dump llkd (process (sigkill sigstop signal ptrace)))
21043(neverallow crash_dump logd (process (sigkill sigstop signal ptrace)))
21044(neverallow crash_dump ueventd (process (sigkill sigstop signal ptrace)))
21045(neverallow crash_dump vendor_init (process (sigkill sigstop signal ptrace)))
21046(neverallow crash_dump vold (process (sigkill sigstop signal ptrace)))
21047;;* lme
21048
21049;;* lmx 66 system/sepolicy/private/crash_dump.te
21050
21051(neverallow crash_dump self (process (ptrace)))
21052;;* lme
21053
21054;;* lmx 67 system/sepolicy/private/crash_dump.te
21055
21056(neverallow crash_dump gpu_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21057;;* lme
21058
21059(allow init credstore_exec (file (read getattr map execute open)))
21060(allow init credstore (process (transition)))
21061(allow credstore credstore_exec (file (read getattr map execute open entrypoint)))
21062(dontaudit init credstore (process (noatsecure)))
21063(allow init credstore (process (siginh rlimitinh)))
21064(typetransition init credstore_exec process credstore)
21065(allow credstore remote_prov_prop (file (read getattr map open)))
21066(allow credstore remote_provisioning_service (service_manager (find)))
21067(allow crosvm vm_manager_device_type (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
21068;;* lmx 10 system/sepolicy/private/crosvm.te
21069
21070(neverallow base_typeattr_698 kvm_device (chr_file (getattr)))
21071;;* lme
21072
21073;;* lmx 11 system/sepolicy/private/crosvm.te
21074
21075(neverallow base_typeattr_699 kvm_device (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21076;;* lme
21077
21078;;* lmx 12 system/sepolicy/private/crosvm.te
21079
21080(neverallowx base_typeattr_700 kvm_device (ioctl chr_file ((range 0x0 0xadff) (range 0xaf00 0xffff))))
21081;;* lme
21082
21083;;* lmx 12 system/sepolicy/private/crosvm.te
21084
21085(neverallowx base_typeattr_700 kvm_device (ioctl chr_file ((range 0xae00 0xae02) (range 0xae04 0xaeff))))
21086;;* lme
21087
21088;;* lmx 17 system/sepolicy/private/crosvm.te
21089
21090(neverallow base_typeattr_701 vm_manager_device_type (chr_file (getattr)))
21091;;* lme
21092
21093;;* lmx 18 system/sepolicy/private/crosvm.te
21094
21095(neverallow base_typeattr_702 vm_manager_device_type (chr_file (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21096;;* lme
21097
21098(typetransition crosvm tmpfs file crosvm_tmpfs)
21099(allow crosvm crosvm_tmpfs (file (read write getattr map)))
21100(allow crosvm virtualizationmanager (fd (use)))
21101(allow crosvm virtualizationmanager (fifo_file (write)))
21102(allow crosvm vendor_microdroid_file (file (ioctl read getattr lock)))
21103(allow crosvm apk_data_file (file (ioctl read getattr lock)))
21104(allow crosvm shell_data_file (file (ioctl read getattr lock)))
21105(allow crosvm staging_data_file (file (ioctl read getattr lock)))
21106(allow crosvm app_data_file (file (ioctl read getattr lock)))
21107(allow crosvm privapp_data_file (file (ioctl read getattr lock)))
21108(allow crosvm apex_compos_data_file (file (ioctl read getattr lock)))
21109(allow crosvm apex_virt_data_file (file (ioctl read getattr lock)))
21110(allow crosvm virtualizationservice_data_file (file (ioctl read getattr lock)))
21111(allow crosvm virtualizationservice_data_file (dir (search)))
21112(allow crosvm self (capability (sys_nice)))
21113(allow crosvm self (cap_userns (sys_nice)))
21114(allow crosvm virtualizationmanager (unix_stream_socket (read write getattr accept getopt)))
21115(allow crosvm app_data_file (file (write)))
21116(allow crosvm privapp_data_file (file (write)))
21117(allow crosvm apex_compos_data_file (file (write)))
21118(allow crosvm apex_virt_data_file (file (write)))
21119(allow crosvm virtualizationservice_data_file (file (write)))
21120(allow crosvm adbd (fd (use)))
21121(allow crosvm adbd (unix_stream_socket (read write)))
21122(allow crosvm devpts (chr_file (ioctl read write getattr)))
21123(dontaudit crosvm self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
21124(allow crosvm shell_data_file (file (write)))
21125(dontaudit crosvm virtualizationmanager (fifo_file (read getattr)))
21126(allow crosvm self (tcp_socket (read write create bind listen accept setopt)))
21127(allow crosvm port (tcp_socket (name_bind)))
21128(allow crosvm adbd (unix_stream_socket (ioctl)))
21129(allow crosvm node (tcp_socket (node_bind)))
21130(allow crosvm vfio_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
21131(allow crosvm vfio_device (dir (ioctl read getattr lock open watch watch_reads search)))
21132(allow crosvm virtualizationmanager (fd (use)))
21133(allow crosvm virtualizationservice_data_file (file (read)))
21134;;* lmx 125 system/sepolicy/private/crosvm.te
21135
21136(neverallow crosvm apk_data_file (file (open)))
21137(neverallow crosvm staging_data_file (file (open)))
21138(neverallow crosvm app_data_file (file (open)))
21139(neverallow crosvm privapp_data_file (file (open)))
21140(neverallow crosvm virtualizationservice_data_file (file (open)))
21141;;* lme
21142
21143;;* lmx 128 system/sepolicy/private/crosvm.te
21144
21145(neverallow crosvm base_typeattr_703 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21146;;* lme
21147
21148;;* lmx 151 system/sepolicy/private/crosvm.te
21149
21150(neverallow crosvm base_typeattr_704 (file (read)))
21151;;* lme
21152
21153;;* lmx 158 system/sepolicy/private/crosvm.te
21154
21155(neverallow base_typeattr_705 crosvm_exec (file (execute execute_no_trans)))
21156;;* lme
21157
21158(allow init derive_classpath_exec (file (read getattr map execute open)))
21159(allow init derive_classpath (process (transition)))
21160(allow derive_classpath derive_classpath_exec (file (read getattr map execute open entrypoint)))
21161(dontaudit init derive_classpath (process (noatsecure)))
21162(allow init derive_classpath (process (siginh rlimitinh)))
21163(typetransition init derive_classpath_exec process derive_classpath)
21164(allow derive_classpath apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
21165(allow derive_classpath vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
21166(allow derive_classpath environ_system_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
21167(allow derive_classpath environ_system_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
21168(allow derive_classpath unlabeled (dir (search)))
21169(allow derive_classpath postinstall_apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
21170(allow derive_classpath postinstall_dexopt (dir (search)))
21171(allow derive_classpath postinstall_dexopt (fd (use)))
21172(allow derive_classpath postinstall_dexopt (file (read)))
21173(allow derive_classpath postinstall_dexopt (lnk_file (read)))
21174(allow derive_classpath postinstall_dexopt_tmpfs (file (ioctl read write getattr lock append map open watch watch_reads)))
21175(allow init derive_sdk_exec (file (read getattr map execute open)))
21176(allow init derive_sdk (process (transition)))
21177(allow derive_sdk derive_sdk_exec (file (read getattr map execute open entrypoint)))
21178(dontaudit init derive_sdk (process (noatsecure)))
21179(allow init derive_sdk (process (siginh rlimitinh)))
21180(typetransition init derive_sdk_exec process derive_sdk)
21181(allow derive_sdk apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
21182(allow derive_sdk vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
21183(allow derive_sdk property_socket (sock_file (write)))
21184(allow derive_sdk init (unix_stream_socket (connectto)))
21185(allow derive_sdk module_sdkextensions_prop (property_service (set)))
21186(allow derive_sdk module_sdkextensions_prop (file (read getattr map open)))
21187;;* lmx 13 system/sepolicy/private/derive_sdk.te
21188
21189(neverallow base_typeattr_706 module_sdkextensions_prop (property_service (set)))
21190;;* lme
21191
21192(allow derive_sdk dumpstate (fd (use)))
21193(allow derive_sdk dumpstate (unix_stream_socket (read write)))
21194(allow derive_sdk shell_data_file (file (read write getattr append)))
21195(typetransition device_as_webcam tmpfs file appdomain_tmpfs)
21196(allow device_as_webcam device_as_webcam_userfaultfd (anon_inode (ioctl read create)))
21197(dontaudit su device_as_webcam_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21198;;* lmx 4 system/sepolicy/private/device_as_webcam.te
21199
21200(neverallow base_typeattr_707 device_as_webcam_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21201;;* lme
21202
21203(allow device_as_webcam appdomain_tmpfs (file (read write getattr map execute)))
21204;;* lmx 4 system/sepolicy/private/device_as_webcam.te
21205
21206(neverallow base_typeattr_708 base_typeattr_707 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21207;;* lme
21208
21209;;* lmx 4 system/sepolicy/private/device_as_webcam.te
21210
21211(neverallow base_typeattr_709 device_as_webcam (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21212;;* lme
21213
21214;;* lmx 4 system/sepolicy/private/device_as_webcam.te
21215
21216(neverallow base_typeattr_710 device_as_webcam (process (ptrace)))
21217;;* lme
21218
21219(allow device_as_webcam system_app_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
21220(allow device_as_webcam system_app_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
21221(allow device_as_webcam app_api_service (service_manager (find)))
21222(allow device_as_webcam cameraserver_service (service_manager (find)))
21223(allow device_as_webcam usb_uvc_enabled_prop (file (read getattr map open)))
21224(allow device_as_webcam device (dir (ioctl read getattr lock open watch watch_reads search)))
21225(allow device_as_webcam video_device (dir (ioctl read getattr lock open watch watch_reads search)))
21226(allow device_as_webcam video_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
21227(allow dex2oat dex2oat_userfaultfd (anon_inode (ioctl read create)))
21228(dontaudit su dex2oat_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21229;;* lmx 5 system/sepolicy/private/dex2oat.te
21230
21231(neverallow base_typeattr_711 dex2oat_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21232;;* lme
21233
21234(allow dex2oat apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21235(allow dex2oat apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21236(allow dex2oat apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21237(allow dex2oat vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
21238(allow dex2oat vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
21239(allow dex2oat vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21240(allow dex2oat vendor_framework_file (dir (getattr search)))
21241(allow dex2oat vendor_framework_file (file (read getattr map open)))
21242(allow dex2oat vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
21243(allow dex2oat vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
21244(allow dex2oat vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21245(allow dex2oat vendor_apex_metadata_file (dir (getattr search)))
21246(allow dex2oat tmpfs (file (read getattr map)))
21247(allow dex2oat dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21248(allow dex2oat dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21249(allow dex2oat dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21250(allow dex2oat dalvikcache_data_file (file (write)))
21251(allow dex2oat system_file (file (lock)))
21252(allow dex2oat postinstall_file (file (lock)))
21253(allow dex2oat asec_apk_file (file (read map)))
21254(allow dex2oat unlabeled (file (read map)))
21255(allow dex2oat oemfs (file (read map)))
21256(allow dex2oat apk_tmp_file (dir (search)))
21257(allow dex2oat apk_tmp_file (file (ioctl read getattr lock map open watch watch_reads)))
21258(allow dex2oat user_profile_data_file (file (read getattr lock map)))
21259(allow dex2oat app_data_file (file (read write getattr lock map)))
21260(allow dex2oat privapp_data_file (file (read write getattr lock map)))
21261(allow dex2oat apex_module_data_file (dir (search)))
21262(allow dex2oat odsign_devpts (chr_file (read write)))
21263(allow dex2oat apex_art_staging_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21264(allow dex2oat apex_art_staging_data_file (file (read write getattr map unlink)))
21265(allow dex2oat apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21266(allow dex2oat apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21267(allow dex2oat device_config_runtime_native_prop (file (read getattr map open)))
21268(allow dex2oat device_config_runtime_native_boot_prop (file (read getattr map open)))
21269(allow dex2oat apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
21270(allow dex2oat artd (fd (use)))
21271(allow dex2oat installd (fd (use)))
21272(allow dex2oat odrefresh (fd (use)))
21273(allow dex2oat odsign (fd (use)))
21274(allow dex2oat proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
21275(allow dex2oat postinstall_dexopt (fd (use)))
21276(allow dex2oat postinstall_file (dir (ioctl read getattr lock open watch watch_reads search)))
21277(allow dex2oat postinstall_file (filesystem (getattr)))
21278(allow dex2oat postinstall_file (lnk_file (read getattr)))
21279(allow dex2oat postinstall_file (file (read)))
21280(allow dex2oat postinstall_file (file (getattr execute open)))
21281(allow dex2oat postinstall_apex_mnt_dir (dir (getattr search)))
21282(allow dex2oat postinstall_apex_mnt_dir (file (ioctl read getattr lock map open watch watch_reads)))
21283(allow dex2oat postinstall_apex_mnt_dir (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21284(allow dex2oat ota_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
21285(allow dex2oat ota_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21286(allow dex2oat ota_data_file (lnk_file (read create)))
21287(allow dex2oat ota_data_file (file (write create setattr lock append map open)))
21288(allow dex2oat apexd (fd (use)))
21289;;* lmx 115 system/sepolicy/private/dex2oat.te
21290
21291(neverallow dex2oat app_data_file_type (file (open)))
21292(neverallow dex2oat app_data_file_type (lnk_file (open)))
21293(neverallow dex2oat app_data_file_type (sock_file (open)))
21294(neverallow dex2oat app_data_file_type (fifo_file (open)))
21295;;* lme
21296
21297(allow dexopt_chroot_setup servicemanager (binder (call transfer)))
21298(allow servicemanager dexopt_chroot_setup (binder (call transfer)))
21299(allow servicemanager dexopt_chroot_setup (dir (search)))
21300(allow servicemanager dexopt_chroot_setup (file (read open)))
21301(allow servicemanager dexopt_chroot_setup (process (getattr)))
21302(allow dexopt_chroot_setup dexopt_chroot_setup_service (service_manager (add find)))
21303;;* lmx 7 system/sepolicy/private/dexopt_chroot_setup.te
21304
21305(neverallow base_typeattr_712 dexopt_chroot_setup_service (service_manager (add)))
21306;;* lme
21307
21308(allow dexopt_chroot_setup dumpstate (fifo_file (write getattr)))
21309(allow dexopt_chroot_setup dumpstate (fd (use)))
21310(allow init dexopt_chroot_setup_exec (file (read getattr map execute open)))
21311(allow init dexopt_chroot_setup (process (transition)))
21312(allow dexopt_chroot_setup dexopt_chroot_setup_exec (file (read getattr map execute open entrypoint)))
21313(dontaudit init dexopt_chroot_setup (process (noatsecure)))
21314(allow init dexopt_chroot_setup (process (siginh rlimitinh)))
21315(typetransition init dexopt_chroot_setup_exec process dexopt_chroot_setup)
21316(typetransition dexopt_chroot_setup tmpfs file dexopt_chroot_setup_tmpfs)
21317(allow dexopt_chroot_setup dexopt_chroot_setup_tmpfs (file (read write getattr map)))
21318(allow dexopt_chroot_setup apex_module_data_file (dir (getattr search)))
21319(allow dexopt_chroot_setup apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21320(allow dexopt_chroot_setup apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21321(allow dexopt_chroot_setup apex_art_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21322(allow dexopt_chroot_setup dexopt_chroot_setup_userfaultfd (anon_inode (ioctl read create)))
21323(dontaudit su dexopt_chroot_setup_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21324;;* lmx 23 system/sepolicy/private/dexopt_chroot_setup.te
21325
21326(neverallow base_typeattr_712 dexopt_chroot_setup_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21327;;* lme
21328
21329(allow dexoptanalyzer apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
21330(allow dexoptanalyzer apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21331(allow dexoptanalyzer apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21332(allow dexoptanalyzer vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
21333(allow dexoptanalyzer vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
21334(allow dexoptanalyzer vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21335(typetransition dexoptanalyzer tmpfs file dexoptanalyzer_tmpfs)
21336(allow dexoptanalyzer dexoptanalyzer_tmpfs (file (read write getattr map)))
21337(allow dexoptanalyzer dexoptanalyzer_userfaultfd (anon_inode (ioctl read create)))
21338(dontaudit su dexoptanalyzer_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21339;;* lmx 17 system/sepolicy/private/dexoptanalyzer.te
21340
21341(neverallow base_typeattr_713 dexoptanalyzer_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
21342;;* lme
21343
21344(allow dexoptanalyzer dalvikcache_data_file (dir (getattr search)))
21345(allow dexoptanalyzer dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21346(allow dexoptanalyzer dalvikcache_data_file (lnk_file (read)))
21347(allow dexoptanalyzer apex_module_data_file (dir (getattr search)))
21348(allow dexoptanalyzer apex_art_data_file (dir (getattr search)))
21349(allow dexoptanalyzer apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
21350(allow dexoptanalyzer odrefresh (fd (use)))
21351(allow dexoptanalyzer odsign (fd (use)))
21352(allow dexoptanalyzer odsign_devpts (chr_file (read write)))
21353(allow dexoptanalyzer installd (fd (use)))
21354(allow dexoptanalyzer installd (fifo_file (write getattr)))
21355(allow dexoptanalyzer system_file (file (lock)))
21356(allow dexoptanalyzer app_data_file (file (read getattr map)))
21357(allow dexoptanalyzer privapp_data_file (file (read getattr map)))
21358(dontaudit dexoptanalyzer app_data_file (dir (search)))
21359(dontaudit dexoptanalyzer privapp_data_file (dir (search)))
21360(allow dexoptanalyzer system_data_file (lnk_file (getattr)))
21361(allow dexoptanalyzer device_config_runtime_native_prop (file (read getattr map open)))
21362(allow dexoptanalyzer device_config_runtime_native_boot_prop (file (read getattr map open)))
21363(allow dexoptanalyzer apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
21364(allow init dhcp_exec (file (read getattr map execute open)))
21365(allow init dhcp (process (transition)))
21366(allow dhcp dhcp_exec (file (read getattr map execute open entrypoint)))
21367(dontaudit init dhcp (process (noatsecure)))
21368(allow init dhcp (process (siginh rlimitinh)))
21369(typetransition init dhcp_exec process dhcp)
21370(typetransition dhcp system_data_file dir dhcp_data_file)
21371(typetransition dhcp system_data_file file dhcp_data_file)
21372(allow dhcp property_socket (sock_file (write)))
21373(allow dhcp init (unix_stream_socket (connectto)))
21374(allow dhcp dhcp_prop (property_service (set)))
21375(allow dhcp dhcp_prop (file (read getattr map open)))
21376(allow dhcp property_socket (sock_file (write)))
21377(allow dhcp init (unix_stream_socket (connectto)))
21378(allow dhcp pan_result_prop (property_service (set)))
21379(allow dhcp pan_result_prop (file (read getattr map open)))
21380(allow init dmesgd_exec (file (read getattr map execute open)))
21381(allow init dmesgd (process (transition)))
21382(allow dmesgd dmesgd_exec (file (read getattr map execute open entrypoint)))
21383(dontaudit init dmesgd (process (noatsecure)))
21384(allow init dmesgd (process (siginh rlimitinh)))
21385(typetransition init dmesgd_exec process dmesgd)
21386(allow dmesgd dmesgd_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
21387(allow dmesgd dmesgd_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
21388(allow dmesgd kernel (system (syslog_read)))
21389(allow dmesgd shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21390(allow dmesgd toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21391(allow dmesgd servicemanager (binder (call transfer)))
21392(allow servicemanager dmesgd (binder (call transfer)))
21393(allow servicemanager dmesgd (dir (search)))
21394(allow servicemanager dmesgd (file (read open)))
21395(allow servicemanager dmesgd (process (getattr)))
21396(allow dmesgd system_server (binder (call transfer)))
21397(allow system_server dmesgd (binder (transfer)))
21398(allow dmesgd system_server (fd (use)))
21399(allow dmesgd dropbox_service (service_manager (find)))
21400(allow dmesgd proc_version (file (ioctl read getattr lock map open watch watch_reads)))
21401(allow domain crash_dump_exec (file (read getattr map execute open)))
21402(allow domain crash_dump (process (transition)))
21403(allow crash_dump crash_dump_exec (file (read getattr map execute open entrypoint)))
21404(allow crash_dump domain (process (sigchld)))
21405(dontaudit domain crash_dump (process (noatsecure)))
21406(allow domain crash_dump (process (siginh rlimitinh)))
21407(typetransition domain crash_dump_exec process crash_dump)
21408(allow domain crash_dump (process (sigchld)))
21409(allow domain heapprofd_prop (file (read getattr map open)))
21410(allow heapprofd base_typeattr_714 (process (signal)))
21411(allow base_typeattr_714 heapprofd_socket (sock_file (write)))
21412(allow base_typeattr_714 heapprofd (unix_stream_socket (connectto)))
21413(allow heapprofd base_typeattr_714 (fd (use)))
21414(allow base_typeattr_714 heapprofd_tmpfs (file (read write getattr map)))
21415(allow base_typeattr_714 heapprofd (fd (use)))
21416(allow heapprofd base_typeattr_714 (file (ioctl read write getattr lock append map open watch watch_reads)))
21417(allow heapprofd base_typeattr_714 (dir (ioctl read getattr lock open watch watch_reads search)))
21418(allow traced_perf base_typeattr_715 (file (ioctl read getattr lock map open watch watch_reads)))
21419(allow traced_perf base_typeattr_715 (dir (ioctl read getattr lock open watch watch_reads search)))
21420(allow traced_perf base_typeattr_715 (process (signal)))
21421(allow base_typeattr_715 traced_perf_socket (sock_file (write)))
21422(allow base_typeattr_715 traced_perf (unix_stream_socket (connectto)))
21423(allow traced_perf base_typeattr_715 (fd (use)))
21424(allow domain sysfs_fs_incfs_features (dir (ioctl read getattr lock open watch watch_reads search)))
21425(allow domain sysfs_fs_incfs_features (file (ioctl read getattr lock map open watch watch_reads)))
21426(allow domain sysfs_fs_incfs_features (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21427(allow domain sysfs_fs_fuse_features (dir (ioctl read getattr lock open watch watch_reads search)))
21428(allow domain sysfs_fs_fuse_features (file (ioctl read getattr lock map open watch watch_reads)))
21429(allow domain sysfs_fs_fuse_features (lnk_file (ioctl read getattr lock map open watch watch_reads)))
21430(allow domain cgroup (dir (search)))
21431(allow base_typeattr_716 cgroup (dir (write lock open add_name remove_name search)))
21432(allow base_typeattr_716 cgroup (file (write lock append map open)))
21433(allow domain cgroup_v2 (dir (search)))
21434(allow base_typeattr_716 cgroup_v2 (dir (write lock open add_name remove_name search)))
21435(allow base_typeattr_716 cgroup_v2 (file (write lock append map open)))
21436(allow domain cgroup_rc_file (dir (search)))
21437(allow domain cgroup_rc_file (file (ioctl read getattr lock map open watch watch_reads)))
21438(allow domain task_profiles_file (file (ioctl read getattr lock map open watch watch_reads)))
21439(allow domain task_profiles_api_file (file (ioctl read getattr lock map open watch watch_reads)))
21440(allow domain vendor_task_profiles_file (file (ioctl read getattr lock map open watch watch_reads)))
21441(allow domain use_memfd_prop (file (read getattr map open)))
21442(allow domain module_sdkextensions_prop (file (read getattr map open)))
21443(allow domain bq_config_prop (file (read getattr map open)))
21444(allow domain permissive_mte_prop (file (read getattr map open)))
21445(allow domain device_config_memory_safety_native_boot_prop (file (read getattr map open)))
21446(allow domain device_config_memory_safety_native_prop (file (read getattr map open)))
21447(allow domain device_config_runtime_native_boot_prop (file (read getattr map open)))
21448(allow domain device_config_runtime_native_prop (file (read getattr map open)))
21449(allow appdomain core_property_type (file (read getattr map open)))
21450(allow coredomain core_property_type (file (read getattr map open)))
21451(allow shell core_property_type (file (read getattr map open)))
21452(allow appdomain exported3_system_prop (file (read getattr map open)))
21453(allow coredomain exported3_system_prop (file (read getattr map open)))
21454(allow shell exported3_system_prop (file (read getattr map open)))
21455(allow appdomain exported_camera_prop (file (read getattr map open)))
21456(allow coredomain exported_camera_prop (file (read getattr map open)))
21457(allow shell exported_camera_prop (file (read getattr map open)))
21458(allow coredomain userspace_reboot_exported_prop (file (read getattr map open)))
21459(allow shell userspace_reboot_exported_prop (file (read getattr map open)))
21460(allow coredomain userspace_reboot_log_prop (file (read getattr map open)))
21461(allow shell userspace_reboot_log_prop (file (read getattr map open)))
21462(allow coredomain userspace_reboot_test_prop (file (read getattr map open)))
21463(allow shell userspace_reboot_test_prop (file (read getattr map open)))
21464(allow base_typeattr_717 vendor_default_prop (file (read getattr map open)))
21465(allow domain aaudio_config_prop (file (read getattr map open)))
21466(allow domain apexd_select_prop (file (read getattr map open)))
21467(allow domain arm64_memtag_prop (file (read getattr map open)))
21468(allow domain bluetooth_config_prop (file (read getattr map open)))
21469(allow domain bootloader_prop (file (read getattr map open)))
21470(allow domain build_odm_prop (file (read getattr map open)))
21471(allow domain build_prop (file (read getattr map open)))
21472(allow domain build_vendor_prop (file (read getattr map open)))
21473(allow domain debug_prop (file (read getattr map open)))
21474(allow domain exported_config_prop (file (read getattr map open)))
21475(allow domain exported_default_prop (file (read getattr map open)))
21476(allow domain exported_dumpstate_prop (file (read getattr map open)))
21477(allow domain exported_secure_prop (file (read getattr map open)))
21478(allow domain exported_system_prop (file (read getattr map open)))
21479(allow domain fingerprint_prop (file (read getattr map open)))
21480(allow domain framework_status_prop (file (read getattr map open)))
21481(allow domain gwp_asan_prop (file (read getattr map open)))
21482(allow domain hal_instrumentation_prop (file (read getattr map open)))
21483(allow domain hw_timeout_multiplier_prop (file (read getattr map open)))
21484(allow domain init_service_status_prop (file (read getattr map open)))
21485(allow domain libc_debug_prop (file (read getattr map open)))
21486(allow domain locale_prop (file (read getattr map open)))
21487(allow domain logd_prop (file (read getattr map open)))
21488(allow domain mediadrm_config_prop (file (read getattr map open)))
21489(allow domain property_service_version_prop (file (read getattr map open)))
21490(allow domain soc_prop (file (read getattr map open)))
21491(allow domain socket_hook_prop (file (read getattr map open)))
21492(allow domain surfaceflinger_prop (file (read getattr map open)))
21493(allow domain telephony_status_prop (file (read getattr map open)))
21494(allow domain timezone_prop (file (read getattr map open)))
21495(allow base_typeattr_718 userdebug_or_eng_prop (file (read getattr map open)))
21496(allow domain vendor_socket_hook_prop (file (read getattr map open)))
21497(allow domain vndk_prop (file (read getattr map open)))
21498(allow domain vold_status_prop (file (read getattr map open)))
21499(allow domain vts_config_prop (file (read getattr map open)))
21500(allow domain binder_cache_bluetooth_server_prop (file (read getattr map open)))
21501(allow domain binder_cache_system_server_prop (file (read getattr map open)))
21502(allow domain binder_cache_telephony_server_prop (file (read getattr map open)))
21503(allow domain kernel (key (search)))
21504(allow domain fsverity_init (key (search)))
21505(allow domain linkerconfig_file (dir (search)))
21506(allow domain linkerconfig_file (file (ioctl read getattr lock map open watch watch_reads)))
21507(allow domain boringssl_self_test_marker (dir (search)))
21508(allow domain log_file_logger_prop (file (read getattr map open)))
21509(allow domain prng_seeder_socket (sock_file (write)))
21510(allow domain prng_seeder (unix_stream_socket (connectto)))
21511(allow base_typeattr_719 shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21512(allow base_typeattr_719 toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
21513;;* lmx 230 system/sepolicy/private/domain.te
21514
21515(neverallow base_typeattr_720 misc_block_device (blk_file (ioctl read write lock relabelfrom append link rename open)))
21516;;* lme
21517
21518;;* lmx 244 system/sepolicy/private/domain.te
21519
21520(neverallow base_typeattr_721 self (capability (sys_ptrace)))
21521(neverallow base_typeattr_721 self (cap_userns (sys_ptrace)))
21522;;* lme
21523
21524;;* lmx 247 system/sepolicy/private/domain.te
21525
21526(neverallow base_typeattr_722 base_typeattr_224 (keystore2_key (gen_unique_id)))
21527;;* lme
21528
21529;;* lmx 248 system/sepolicy/private/domain.te
21530
21531(neverallow base_typeattr_305 base_typeattr_224 (keystore2_key (use_dev_id)))
21532;;* lme
21533
21534;;* lmx 249 system/sepolicy/private/domain.te
21535
21536(neverallow base_typeattr_305 keystore (keystore2 (clear_ns lock reset unlock)))
21537;;* lme
21538
21539;;* lmx 256 system/sepolicy/private/domain.te
21540
21541(neverallow base_typeattr_259 debugfs_tracing_debug (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21542;;* lme
21543
21544;;* lmx 265 system/sepolicy/private/domain.te
21545
21546(neverallow base_typeattr_308 dropbox_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21547;;* lme
21548
21549;;* lmx 271 system/sepolicy/private/domain.te
21550
21551(neverallow base_typeattr_308 dropbox_data_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21552;;* lme
21553
21554;;* lmx 280 system/sepolicy/private/domain.te
21555
21556(neverallow base_typeattr_317 app_data_file (file (create unlink)))
21557(neverallow base_typeattr_317 app_data_file (dir (create unlink)))
21558(neverallow base_typeattr_317 app_data_file (lnk_file (create unlink)))
21559(neverallow base_typeattr_317 app_data_file (chr_file (create unlink)))
21560(neverallow base_typeattr_317 app_data_file (blk_file (create unlink)))
21561(neverallow base_typeattr_317 app_data_file (sock_file (create unlink)))
21562(neverallow base_typeattr_317 app_data_file (fifo_file (create unlink)))
21563(neverallow base_typeattr_317 privapp_data_file (file (create unlink)))
21564(neverallow base_typeattr_317 privapp_data_file (dir (create unlink)))
21565(neverallow base_typeattr_317 privapp_data_file (lnk_file (create unlink)))
21566(neverallow base_typeattr_317 privapp_data_file (chr_file (create unlink)))
21567(neverallow base_typeattr_317 privapp_data_file (blk_file (create unlink)))
21568(neverallow base_typeattr_317 privapp_data_file (sock_file (create unlink)))
21569(neverallow base_typeattr_317 privapp_data_file (fifo_file (create unlink)))
21570;;* lme
21571
21572;;* lmx 298 system/sepolicy/private/domain.te
21573
21574(neverallow base_typeattr_723 app_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21575(neverallow base_typeattr_723 privapp_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21576;;* lme
21577
21578;;* lmx 308 system/sepolicy/private/domain.te
21579
21580(neverallow base_typeattr_724 app_data_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
21581(neverallow base_typeattr_724 privapp_data_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
21582;;* lme
21583
21584;;* lmx 317 system/sepolicy/private/domain.te
21585
21586(neverallow base_typeattr_725 app_data_file (file (open)))
21587(neverallow base_typeattr_725 app_data_file (lnk_file (open)))
21588(neverallow base_typeattr_725 app_data_file (chr_file (open)))
21589(neverallow base_typeattr_725 app_data_file (blk_file (open)))
21590(neverallow base_typeattr_725 app_data_file (sock_file (open)))
21591(neverallow base_typeattr_725 app_data_file (fifo_file (open)))
21592(neverallow base_typeattr_725 privapp_data_file (file (open)))
21593(neverallow base_typeattr_725 privapp_data_file (lnk_file (open)))
21594(neverallow base_typeattr_725 privapp_data_file (chr_file (open)))
21595(neverallow base_typeattr_725 privapp_data_file (blk_file (open)))
21596(neverallow base_typeattr_725 privapp_data_file (sock_file (open)))
21597(neverallow base_typeattr_725 privapp_data_file (fifo_file (open)))
21598;;* lme
21599
21600;;* lmx 324 system/sepolicy/private/domain.te
21601
21602(neverallow base_typeattr_317 app_data_file (file (create unlink)))
21603(neverallow base_typeattr_317 app_data_file (dir (create unlink)))
21604(neverallow base_typeattr_317 app_data_file (lnk_file (create unlink)))
21605(neverallow base_typeattr_317 app_data_file (chr_file (create unlink)))
21606(neverallow base_typeattr_317 app_data_file (blk_file (create unlink)))
21607(neverallow base_typeattr_317 app_data_file (sock_file (create unlink)))
21608(neverallow base_typeattr_317 app_data_file (fifo_file (create unlink)))
21609(neverallow base_typeattr_317 privapp_data_file (file (create unlink)))
21610(neverallow base_typeattr_317 privapp_data_file (dir (create unlink)))
21611(neverallow base_typeattr_317 privapp_data_file (lnk_file (create unlink)))
21612(neverallow base_typeattr_317 privapp_data_file (chr_file (create unlink)))
21613(neverallow base_typeattr_317 privapp_data_file (blk_file (create unlink)))
21614(neverallow base_typeattr_317 privapp_data_file (sock_file (create unlink)))
21615(neverallow base_typeattr_317 privapp_data_file (fifo_file (create unlink)))
21616;;* lme
21617
21618;;* lmx 330 system/sepolicy/private/domain.te
21619
21620(neverallow base_typeattr_726 app_data_file (file (relabelfrom relabelto)))
21621(neverallow base_typeattr_726 app_data_file (dir (relabelfrom relabelto)))
21622(neverallow base_typeattr_726 app_data_file (lnk_file (relabelfrom relabelto)))
21623(neverallow base_typeattr_726 app_data_file (chr_file (relabelfrom relabelto)))
21624(neverallow base_typeattr_726 app_data_file (blk_file (relabelfrom relabelto)))
21625(neverallow base_typeattr_726 app_data_file (sock_file (relabelfrom relabelto)))
21626(neverallow base_typeattr_726 app_data_file (fifo_file (relabelfrom relabelto)))
21627(neverallow base_typeattr_726 privapp_data_file (file (relabelfrom relabelto)))
21628(neverallow base_typeattr_726 privapp_data_file (dir (relabelfrom relabelto)))
21629(neverallow base_typeattr_726 privapp_data_file (lnk_file (relabelfrom relabelto)))
21630(neverallow base_typeattr_726 privapp_data_file (chr_file (relabelfrom relabelto)))
21631(neverallow base_typeattr_726 privapp_data_file (blk_file (relabelfrom relabelto)))
21632(neverallow base_typeattr_726 privapp_data_file (sock_file (relabelfrom relabelto)))
21633(neverallow base_typeattr_726 privapp_data_file (fifo_file (relabelfrom relabelto)))
21634;;* lme
21635
21636;;* lmx 344 system/sepolicy/private/domain.te
21637
21638(neverallow base_typeattr_727 staging_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21639;;* lme
21640
21641;;* lmx 358 system/sepolicy/private/domain.te
21642
21643(neverallow base_typeattr_728 staging_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21644;;* lme
21645
21646;;* lmx 359 system/sepolicy/private/domain.te
21647
21648(neverallow base_typeattr_729 staging_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
21649;;* lme
21650
21651;;* lmx 363 system/sepolicy/private/domain.te
21652
21653(neverallow base_typeattr_308 staging_data_file (file (write create setattr relabelfrom append rename execute execute_no_trans)))
21654;;* lme
21655
21656;;* lmx 370 system/sepolicy/private/domain.te
21657
21658(neverallow base_typeattr_730 base_typeattr_731 (file (execute)))
21659;;* lme
21660
21661;;* lmx 399 system/sepolicy/private/domain.te
21662
21663(neverallow base_typeattr_732 base_typeattr_733 (file (execute)))
21664;;* lme
21665
21666;;* lmx 406 system/sepolicy/private/domain.te
21667
21668(neverallow base_typeattr_259 cgroup_rc_file (file (write create setattr relabelfrom append unlink link rename)))
21669;;* lme
21670
21671;;* lmx 419 system/sepolicy/private/domain.te
21672
21673(neverallow base_typeattr_734 dalvikcache_data_file (file (write create setattr relabelfrom append unlink link rename)))
21674;;* lme
21675
21676;;* lmx 431 system/sepolicy/private/domain.te
21677
21678(neverallow base_typeattr_734 dalvikcache_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
21679;;* lme
21680
21681;;* lmx 446 system/sepolicy/private/domain.te
21682
21683(neverallow base_typeattr_735 apex_art_data_file (file (write create setattr relabelfrom append unlink link rename)))
21684;;* lme
21685
21686;;* lmx 459 system/sepolicy/private/domain.te
21687
21688(neverallow base_typeattr_735 apex_art_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
21689;;* lme
21690
21691;;* lmx 471 system/sepolicy/private/domain.te
21692
21693(neverallow base_typeattr_233 base_typeattr_629 (file (execute execute_no_trans)))
21694;;* lme
21695
21696;;* lmx 499 system/sepolicy/private/domain.te
21697
21698(neverallow base_typeattr_736 self (capability (dac_override)))
21699(neverallow base_typeattr_736 self (cap_userns (dac_override)))
21700;;* lme
21701
21702;;* lmx 509 system/sepolicy/private/domain.te
21703
21704(neverallow base_typeattr_737 self (capability (dac_read_search)))
21705(neverallow base_typeattr_737 self (cap_userns (dac_read_search)))
21706;;* lme
21707
21708;;* lmx 528 system/sepolicy/private/domain.te
21709
21710(neverallow base_typeattr_738 base_typeattr_739 (filesystem (mount remount relabelfrom relabelto)))
21711;;* lme
21712
21713;;* lmx 530 system/sepolicy/private/domain.te
21714
21715(neverallow domain base_typeattr_740 (filesystem (mount remount relabelfrom relabelto)))
21716;;* lme
21717
21718;;* lmx 549 system/sepolicy/private/domain.te
21719
21720(neverallow base_typeattr_741 self (capability (sys_rawio)))
21721(neverallow base_typeattr_741 self (cap_userns (sys_rawio)))
21722;;* lme
21723
21724;;* lmx 558 system/sepolicy/private/domain.te
21725
21726(neverallow base_typeattr_742 mirror_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21727;;* lme
21728
21729;;* lmx 561 system/sepolicy/private/domain.te
21730
21731(neverallow base_typeattr_266 net_dns_prop (property_service (set)))
21732;;* lme
21733
21734;;* lmx 562 system/sepolicy/private/domain.te
21735
21736(neverallow base_typeattr_261 net_dns_prop (file (read)))
21737;;* lme
21738
21739;;* lmx 565 system/sepolicy/private/domain.te
21740
21741(neverallow base_typeattr_308 pm_prop (property_service (set)))
21742;;* lme
21743
21744;;* lmx 566 system/sepolicy/private/domain.te
21745
21746(neverallow base_typeattr_250 pm_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21747;;* lme
21748
21749;;* lmx 569 system/sepolicy/private/domain.te
21750
21751(neverallow base_typeattr_743 firstboot_prop (file (ioctl read getattr lock map open watch watch_reads)))
21752;;* lme
21753
21754;;* lmx 573 system/sepolicy/private/domain.te
21755
21756(neverallow base_typeattr_744 dalvik_config_prop (property_service (set)))
21757;;* lme
21758
21759;;* lmx 576 system/sepolicy/private/domain.te
21760
21761(neverallow base_typeattr_259 debugfs_kprobes (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21762;;* lme
21763
21764;;* lmx 580 system/sepolicy/private/domain.te
21765
21766(neverallow base_typeattr_745 vendor_file (file (write create setattr relabelfrom append unlink link rename execute open execute_no_trans)))
21767;;* lme
21768
21769;;* lmx 597 system/sepolicy/private/domain.te
21770
21771(neverallow base_typeattr_746 base_typeattr_747 (socket (connect sendto)))
21772(neverallow base_typeattr_746 base_typeattr_747 (tcp_socket (connect sendto)))
21773(neverallow base_typeattr_746 base_typeattr_747 (udp_socket (connect sendto)))
21774(neverallow base_typeattr_746 base_typeattr_747 (rawip_socket (connect sendto)))
21775(neverallow base_typeattr_746 base_typeattr_747 (netlink_socket (connect sendto)))
21776(neverallow base_typeattr_746 base_typeattr_747 (packet_socket (connect sendto)))
21777(neverallow base_typeattr_746 base_typeattr_747 (key_socket (connect sendto)))
21778(neverallow base_typeattr_746 base_typeattr_747 (unix_stream_socket (connect sendto)))
21779(neverallow base_typeattr_746 base_typeattr_747 (unix_dgram_socket (connect sendto)))
21780(neverallow base_typeattr_746 base_typeattr_747 (netlink_route_socket (connect sendto)))
21781(neverallow base_typeattr_746 base_typeattr_747 (netlink_tcpdiag_socket (connect sendto)))
21782(neverallow base_typeattr_746 base_typeattr_747 (netlink_nflog_socket (connect sendto)))
21783(neverallow base_typeattr_746 base_typeattr_747 (netlink_xfrm_socket (connect sendto)))
21784(neverallow base_typeattr_746 base_typeattr_747 (netlink_selinux_socket (connect sendto)))
21785(neverallow base_typeattr_746 base_typeattr_747 (netlink_audit_socket (connect sendto)))
21786(neverallow base_typeattr_746 base_typeattr_747 (netlink_dnrt_socket (connect sendto)))
21787(neverallow base_typeattr_746 base_typeattr_747 (netlink_kobject_uevent_socket (connect sendto)))
21788(neverallow base_typeattr_746 base_typeattr_747 (appletalk_socket (connect sendto)))
21789(neverallow base_typeattr_746 base_typeattr_747 (tun_socket (connect sendto)))
21790(neverallow base_typeattr_746 base_typeattr_747 (netlink_iscsi_socket (connect sendto)))
21791(neverallow base_typeattr_746 base_typeattr_747 (netlink_fib_lookup_socket (connect sendto)))
21792(neverallow base_typeattr_746 base_typeattr_747 (netlink_connector_socket (connect sendto)))
21793(neverallow base_typeattr_746 base_typeattr_747 (netlink_netfilter_socket (connect sendto)))
21794(neverallow base_typeattr_746 base_typeattr_747 (netlink_generic_socket (connect sendto)))
21795(neverallow base_typeattr_746 base_typeattr_747 (netlink_scsitransport_socket (connect sendto)))
21796(neverallow base_typeattr_746 base_typeattr_747 (netlink_rdma_socket (connect sendto)))
21797(neverallow base_typeattr_746 base_typeattr_747 (netlink_crypto_socket (connect sendto)))
21798(neverallow base_typeattr_746 base_typeattr_747 (sctp_socket (connect sendto)))
21799(neverallow base_typeattr_746 base_typeattr_747 (icmp_socket (connect sendto)))
21800(neverallow base_typeattr_746 base_typeattr_747 (ax25_socket (connect sendto)))
21801(neverallow base_typeattr_746 base_typeattr_747 (ipx_socket (connect sendto)))
21802(neverallow base_typeattr_746 base_typeattr_747 (netrom_socket (connect sendto)))
21803(neverallow base_typeattr_746 base_typeattr_747 (atmpvc_socket (connect sendto)))
21804(neverallow base_typeattr_746 base_typeattr_747 (x25_socket (connect sendto)))
21805(neverallow base_typeattr_746 base_typeattr_747 (rose_socket (connect sendto)))
21806(neverallow base_typeattr_746 base_typeattr_747 (decnet_socket (connect sendto)))
21807(neverallow base_typeattr_746 base_typeattr_747 (atmsvc_socket (connect sendto)))
21808(neverallow base_typeattr_746 base_typeattr_747 (rds_socket (connect sendto)))
21809(neverallow base_typeattr_746 base_typeattr_747 (irda_socket (connect sendto)))
21810(neverallow base_typeattr_746 base_typeattr_747 (pppox_socket (connect sendto)))
21811(neverallow base_typeattr_746 base_typeattr_747 (llc_socket (connect sendto)))
21812(neverallow base_typeattr_746 base_typeattr_747 (can_socket (connect sendto)))
21813(neverallow base_typeattr_746 base_typeattr_747 (tipc_socket (connect sendto)))
21814(neverallow base_typeattr_746 base_typeattr_747 (bluetooth_socket (connect sendto)))
21815(neverallow base_typeattr_746 base_typeattr_747 (iucv_socket (connect sendto)))
21816(neverallow base_typeattr_746 base_typeattr_747 (rxrpc_socket (connect sendto)))
21817(neverallow base_typeattr_746 base_typeattr_747 (isdn_socket (connect sendto)))
21818(neverallow base_typeattr_746 base_typeattr_747 (phonet_socket (connect sendto)))
21819(neverallow base_typeattr_746 base_typeattr_747 (ieee802154_socket (connect sendto)))
21820(neverallow base_typeattr_746 base_typeattr_747 (caif_socket (connect sendto)))
21821(neverallow base_typeattr_746 base_typeattr_747 (alg_socket (connect sendto)))
21822(neverallow base_typeattr_746 base_typeattr_747 (nfc_socket (connect sendto)))
21823(neverallow base_typeattr_746 base_typeattr_747 (vsock_socket (connect sendto)))
21824(neverallow base_typeattr_746 base_typeattr_747 (kcm_socket (connect sendto)))
21825(neverallow base_typeattr_746 base_typeattr_747 (qipcrtr_socket (connect sendto)))
21826(neverallow base_typeattr_746 base_typeattr_747 (smc_socket (connect sendto)))
21827(neverallow base_typeattr_746 base_typeattr_747 (xdp_socket (connect sendto)))
21828;;* lme
21829
21830;;* lmx 597 system/sepolicy/private/domain.te
21831
21832(neverallow base_typeattr_746 base_typeattr_747 (unix_stream_socket (connectto)))
21833;;* lme
21834
21835;;* lmx 618 system/sepolicy/private/domain.te
21836
21837(neverallow base_typeattr_748 base_typeattr_749 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21838;;* lme
21839
21840;;* lmx 663 system/sepolicy/private/domain.te
21841
21842(neverallow domain mlsvendorcompat (process (fork)))
21843;;* lme
21844
21845;;* lmx 667 system/sepolicy/private/domain.te
21846
21847(neverallow base_typeattr_750 system_file_type (file (mounton)))
21848(neverallow base_typeattr_750 system_file_type (dir (mounton)))
21849(neverallow base_typeattr_750 system_file_type (lnk_file (mounton)))
21850(neverallow base_typeattr_750 system_file_type (chr_file (mounton)))
21851(neverallow base_typeattr_750 system_file_type (blk_file (mounton)))
21852(neverallow base_typeattr_750 system_file_type (sock_file (mounton)))
21853(neverallow base_typeattr_750 system_file_type (fifo_file (mounton)))
21854(neverallow base_typeattr_750 vendor_file_type (file (mounton)))
21855(neverallow base_typeattr_750 vendor_file_type (dir (mounton)))
21856(neverallow base_typeattr_750 vendor_file_type (lnk_file (mounton)))
21857(neverallow base_typeattr_750 vendor_file_type (chr_file (mounton)))
21858(neverallow base_typeattr_750 vendor_file_type (blk_file (mounton)))
21859(neverallow base_typeattr_750 vendor_file_type (sock_file (mounton)))
21860(neverallow base_typeattr_750 vendor_file_type (fifo_file (mounton)))
21861;;* lme
21862
21863;;* lmx 676 system/sepolicy/private/domain.te
21864
21865(neverallow base_typeattr_260 mm_events_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21866;;* lme
21867
21868;;* lmx 689 system/sepolicy/private/domain.te
21869
21870(neverallow base_typeattr_751 proc_kallsyms (file (read open)))
21871;;* lme
21872
21873;;* lmx 695 system/sepolicy/private/domain.te
21874
21875(neverallow base_typeattr_752 base_typeattr_753 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
21876;;* lme
21877
21878;;* lmx 711 system/sepolicy/private/domain.te
21879
21880(neverallow base_typeattr_754 sysfs_devices_cs_etm (file (write create setattr relabelfrom append unlink link rename)))
21881;;* lme
21882
21883;;* lmx 721 system/sepolicy/private/domain.te
21884
21885(neverallow base_typeattr_755 self (capability2 (perfmon)))
21886;;* lme
21887
21888;;* lmx 741 system/sepolicy/private/domain.te
21889
21890(neverallow base_typeattr_756 shell_data_file (file (open)))
21891;;* lme
21892
21893;;* lmx 759 system/sepolicy/private/domain.te
21894
21895(neverallow base_typeattr_757 shell_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
21896;;* lme
21897
21898;;* lmx 772 system/sepolicy/private/domain.te
21899
21900(neverallow base_typeattr_758 shell_data_file (dir (open)))
21901;;* lme
21902
21903;;* lmx 787 system/sepolicy/private/domain.te
21904
21905(neverallow base_typeattr_758 shell_data_file (dir (search)))
21906;;* lme
21907
21908;;* lmx 799 system/sepolicy/private/domain.te
21909
21910(neverallow base_typeattr_759 system_app_data_file (file (create unlink open)))
21911(neverallow base_typeattr_759 system_app_data_file (dir (create unlink open)))
21912(neverallow base_typeattr_759 system_app_data_file (lnk_file (create unlink open)))
21913(neverallow base_typeattr_759 system_app_data_file (chr_file (create unlink open)))
21914(neverallow base_typeattr_759 system_app_data_file (blk_file (create unlink open)))
21915(neverallow base_typeattr_759 system_app_data_file (sock_file (create unlink open)))
21916(neverallow base_typeattr_759 system_app_data_file (fifo_file (create unlink open)))
21917;;* lme
21918
21919;;* lmx 806 system/sepolicy/private/domain.te
21920
21921(neverallow untrusted_app_all system_app_data_file (file (create unlink open)))
21922(neverallow untrusted_app_all system_app_data_file (dir (create unlink open)))
21923(neverallow untrusted_app_all system_app_data_file (lnk_file (create unlink open)))
21924(neverallow untrusted_app_all system_app_data_file (chr_file (create unlink open)))
21925(neverallow untrusted_app_all system_app_data_file (blk_file (create unlink open)))
21926(neverallow untrusted_app_all system_app_data_file (sock_file (create unlink open)))
21927(neverallow untrusted_app_all system_app_data_file (fifo_file (create unlink open)))
21928(neverallow isolated_app_all system_app_data_file (file (create unlink open)))
21929(neverallow isolated_app_all system_app_data_file (dir (create unlink open)))
21930(neverallow isolated_app_all system_app_data_file (lnk_file (create unlink open)))
21931(neverallow isolated_app_all system_app_data_file (chr_file (create unlink open)))
21932(neverallow isolated_app_all system_app_data_file (blk_file (create unlink open)))
21933(neverallow isolated_app_all system_app_data_file (sock_file (create unlink open)))
21934(neverallow isolated_app_all system_app_data_file (fifo_file (create unlink open)))
21935(neverallow ephemeral_app system_app_data_file (file (create unlink open)))
21936(neverallow ephemeral_app system_app_data_file (dir (create unlink open)))
21937(neverallow ephemeral_app system_app_data_file (lnk_file (create unlink open)))
21938(neverallow ephemeral_app system_app_data_file (chr_file (create unlink open)))
21939(neverallow ephemeral_app system_app_data_file (blk_file (create unlink open)))
21940(neverallow ephemeral_app system_app_data_file (sock_file (create unlink open)))
21941(neverallow ephemeral_app system_app_data_file (fifo_file (create unlink open)))
21942(neverallow priv_app system_app_data_file (file (create unlink open)))
21943(neverallow priv_app system_app_data_file (dir (create unlink open)))
21944(neverallow priv_app system_app_data_file (lnk_file (create unlink open)))
21945(neverallow priv_app system_app_data_file (chr_file (create unlink open)))
21946(neverallow priv_app system_app_data_file (blk_file (create unlink open)))
21947(neverallow priv_app system_app_data_file (sock_file (create unlink open)))
21948(neverallow priv_app system_app_data_file (fifo_file (create unlink open)))
21949(neverallow sdk_sandbox_all system_app_data_file (file (create unlink open)))
21950(neverallow sdk_sandbox_all system_app_data_file (dir (create unlink open)))
21951(neverallow sdk_sandbox_all system_app_data_file (lnk_file (create unlink open)))
21952(neverallow sdk_sandbox_all system_app_data_file (chr_file (create unlink open)))
21953(neverallow sdk_sandbox_all system_app_data_file (blk_file (create unlink open)))
21954(neverallow sdk_sandbox_all system_app_data_file (sock_file (create unlink open)))
21955(neverallow sdk_sandbox_all system_app_data_file (fifo_file (create unlink open)))
21956;;* lme
21957
21958;;* lmx 808 system/sepolicy/private/domain.te
21959
21960(neverallow base_typeattr_223 mtectrl (process (transition dyntransition)))
21961;;* lme
21962
21963;;* lmx 811 system/sepolicy/private/domain.te
21964
21965(neverallow base_typeattr_760 checkin_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
21966(neverallow base_typeattr_760 checkin_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21967;;* lme
21968
21969;;* lmx 814 system/sepolicy/private/domain.te
21970
21971(neverallow base_typeattr_761 aconfig_storage_metadata_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
21972;;* lme
21973
21974;;* lmx 815 system/sepolicy/private/domain.te
21975
21976(neverallow base_typeattr_761 aconfig_storage_metadata_file (file (write create setattr relabelfrom append unlink link rename)))
21977;;* lme
21978
21979(allow init drmserver_exec (file (read getattr map execute open)))
21980(allow init drmserver (process (transition)))
21981(allow drmserver drmserver_exec (file (read getattr map execute open entrypoint)))
21982(dontaudit init drmserver (process (noatsecure)))
21983(allow init drmserver (process (siginh rlimitinh)))
21984(typetransition init drmserver_exec process drmserver)
21985(typetransition drmserver apk_data_file sock_file drmserver_socket)
21986(allow drmserver drm_service_config_prop (file (read getattr map open)))
21987(allow init dumpstate_exec (file (read getattr map execute open)))
21988(allow init dumpstate (process (transition)))
21989(allow dumpstate dumpstate_exec (file (read getattr map execute open entrypoint)))
21990(dontaudit init dumpstate (process (noatsecure)))
21991(allow init dumpstate (process (siginh rlimitinh)))
21992(typetransition init dumpstate_exec process dumpstate)
21993(allow dumpstate vdc_exec (file (read getattr map execute open)))
21994(allow dumpstate vdc (process (transition)))
21995(allow vdc vdc_exec (file (read getattr map execute open entrypoint)))
21996(allow vdc dumpstate (process (sigchld)))
21997(dontaudit dumpstate vdc (process (noatsecure)))
21998(allow dumpstate vdc (process (siginh rlimitinh)))
21999(typetransition dumpstate vdc_exec process vdc)
22000(typetransition dumpstate tmpfs file dumpstate_tmpfs)
22001(allow dumpstate dumpstate_tmpfs (file (read write getattr map)))
22002(allow dumpstate system_file (file (lock)))
22003(allow dumpstate storaged_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
22004(allow dumpstate incidentd (binder (call transfer)))
22005(allow incidentd dumpstate (binder (transfer)))
22006(allow dumpstate incidentd (fd (use)))
22007(allow dumpstate incident (process (sigkill signal)))
22008(allow dumpstate storaged (binder (call transfer)))
22009(allow storaged dumpstate (binder (transfer)))
22010(allow dumpstate storaged (fd (use)))
22011(allow dumpstate statsd (binder (call transfer)))
22012(allow statsd dumpstate (binder (transfer)))
22013(allow dumpstate statsd (fd (use)))
22014(allow dumpstate gpuservice (binder (call transfer)))
22015(allow gpuservice dumpstate (binder (transfer)))
22016(allow dumpstate gpuservice (fd (use)))
22017(allow dumpstate idmap (binder (call transfer)))
22018(allow idmap dumpstate (binder (transfer)))
22019(allow dumpstate idmap (fd (use)))
22020(allow dumpstate automotive_display_service (binder (call transfer)))
22021(allow automotive_display_service dumpstate (binder (transfer)))
22022(allow dumpstate automotive_display_service (fd (use)))
22023(allow dumpstate virtual_camera (binder (call transfer)))
22024(allow virtual_camera dumpstate (binder (transfer)))
22025(allow dumpstate virtual_camera (fd (use)))
22026(allow dumpstate ot_daemon (binder (call transfer)))
22027(allow ot_daemon dumpstate (binder (transfer)))
22028(allow dumpstate ot_daemon (fd (use)))
22029(allow dumpstate boottime_prop (file (read getattr map open)))
22030(allow dumpstate misctrl_prop (file (read getattr map open)))
22031(allow dumpstate mediatranscoding (process (signal)))
22032(allow dumpstate netd (process (signal)))
22033(allow dumpstate statsd (process (signal)))
22034(allow dumpstate ot_daemon (process (signal)))
22035(allow dumpstate virtual_camera (process (signal)))
22036(dontaudit dumpstate keystore (process (signal)))
22037(allow dumpstate dev_type (blk_file (getattr)))
22038(allow dumpstate webview_zygote (process (signal)))
22039(allow dumpstate sysfs_dmabuf_stats (file (ioctl read getattr lock map open watch watch_reads)))
22040(dontaudit dumpstate update_engine (binder (call)))
22041(allow dumpstate proc_net_tcp_udp (file (ioctl read getattr lock map open watch watch_reads)))
22042(allow dumpstate proc_pid_max (file (ioctl read getattr lock map open watch watch_reads)))
22043(allow dumpstate config_gz (file (ioctl read getattr lock map open watch watch_reads)))
22044(allow dumpstate incidentcompanion_service (binder (call transfer)))
22045(allow incidentcompanion_service dumpstate (binder (transfer)))
22046(allow dumpstate incidentcompanion_service (fd (use)))
22047(allow dumpstate property_socket (sock_file (write)))
22048(allow dumpstate init (unix_stream_socket (connectto)))
22049(allow dumpstate dumpstate_prop (property_service (set)))
22050(allow dumpstate dumpstate_prop (file (read getattr map open)))
22051(allow dumpstate property_socket (sock_file (write)))
22052(allow dumpstate init (unix_stream_socket (connectto)))
22053(allow dumpstate exported_dumpstate_prop (property_service (set)))
22054(allow dumpstate exported_dumpstate_prop (file (read getattr map open)))
22055(allow dumpstate property_socket (sock_file (write)))
22056(allow dumpstate init (unix_stream_socket (connectto)))
22057(allow dumpstate dumpstate_options_prop (property_service (set)))
22058(allow dumpstate dumpstate_options_prop (file (read getattr map open)))
22059(allow dumpstate property_socket (sock_file (write)))
22060(allow dumpstate init (unix_stream_socket (connectto)))
22061(allow dumpstate ctl_dumpstate_prop (property_service (set)))
22062(allow dumpstate ctl_dumpstate_prop (file (read getattr map open)))
22063(allow dumpstate property_socket (sock_file (write)))
22064(allow dumpstate init (unix_stream_socket (connectto)))
22065(allow dumpstate lpdumpd_prop (property_service (set)))
22066(allow dumpstate lpdumpd_prop (file (read getattr map open)))
22067(allow dumpstate lpdumpd (binder (call transfer)))
22068(allow lpdumpd dumpstate (binder (transfer)))
22069(allow dumpstate lpdumpd (fd (use)))
22070(allow dumpstate hypervisor_prop (file (read getattr map open)))
22071(allow dumpstate gsid_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
22072(allow dumpstate property_socket (sock_file (write)))
22073(allow dumpstate init (unix_stream_socket (connectto)))
22074(allow dumpstate ctl_gsid_prop (property_service (set)))
22075(allow dumpstate ctl_gsid_prop (file (read getattr map open)))
22076(allow dumpstate gsid (binder (call transfer)))
22077(allow gsid dumpstate (binder (transfer)))
22078(allow dumpstate gsid (fd (use)))
22079(allow dumpstate ota_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
22080(allow dumpstate ota_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
22081(allow dumpstate ota_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22082(allow dumpstate perfetto_exec (file (read getattr map execute open)))
22083(allow dumpstate perfetto (process (transition)))
22084(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
22085(allow perfetto dumpstate (process (sigchld)))
22086(dontaudit dumpstate perfetto (process (noatsecure)))
22087(allow dumpstate perfetto (process (siginh rlimitinh)))
22088(typetransition dumpstate perfetto_exec process perfetto)
22089(allow dumpstate perfetto (process (signal)))
22090(allow dumpstate perfetto_traces_data_file (dir (search)))
22091(allow dumpstate perfetto_traces_bugreport_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
22092(allow dumpstate perfetto_traces_bugreport_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
22093(allow perfetto dumpstate_tmpfs (file (ioctl read write getattr lock append map open watch watch_reads)))
22094(allow perfetto dumpstate (fd (use)))
22095(allow dumpstate system_dlkm_file (dir (getattr)))
22096(allow dumpstate derive_sdk_exec (file (read getattr map execute open)))
22097(allow dumpstate derive_sdk (process (transition)))
22098(allow derive_sdk derive_sdk_exec (file (read getattr map execute open entrypoint)))
22099(allow derive_sdk dumpstate (process (sigchld)))
22100(dontaudit dumpstate derive_sdk (process (noatsecure)))
22101(allow dumpstate derive_sdk (process (siginh rlimitinh)))
22102(typetransition dumpstate derive_sdk_exec process derive_sdk)
22103(typetransition ephemeral_app tmpfs file appdomain_tmpfs)
22104(allow ephemeral_app ephemeral_app_userfaultfd (anon_inode (ioctl read create)))
22105(dontaudit su ephemeral_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22106;;* lmx 17 system/sepolicy/private/ephemeral_app.te
22107
22108(neverallow base_typeattr_762 ephemeral_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22109;;* lme
22110
22111(allow ephemeral_app appdomain_tmpfs (file (read write getattr map execute)))
22112;;* lmx 17 system/sepolicy/private/ephemeral_app.te
22113
22114(neverallow base_typeattr_763 base_typeattr_762 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22115;;* lme
22116
22117;;* lmx 17 system/sepolicy/private/ephemeral_app.te
22118
22119(neverallow base_typeattr_764 ephemeral_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22120;;* lme
22121
22122;;* lmx 17 system/sepolicy/private/ephemeral_app.te
22123
22124(neverallow base_typeattr_765 ephemeral_app (process (ptrace)))
22125;;* lme
22126
22127(allow ephemeral_app sdcard_type (file (ioctl read write getattr lock append)))
22128(allow ephemeral_app fuse (file (ioctl read write getattr lock append)))
22129(allow ephemeral_app media_rw_data_file (file (ioctl read write getattr lock append)))
22130(allow ephemeral_app privapp_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
22131(allow ephemeral_app app_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
22132(allow ephemeral_app privapp_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22133(allow ephemeral_app rs_exec (file (read getattr map execute open)))
22134(allow ephemeral_app rs (process (transition)))
22135(allow rs rs_exec (file (read getattr map execute open entrypoint)))
22136(allow rs ephemeral_app (process (sigchld)))
22137(dontaudit ephemeral_app rs (process (noatsecure)))
22138(allow ephemeral_app rs (process (siginh rlimitinh)))
22139(typetransition ephemeral_app rs_exec process rs)
22140(allow ephemeral_app app_exec_data_file (file (ioctl read getattr lock map unlink execute open watch watch_reads)))
22141(allow ephemeral_app audioserver_service (service_manager (find)))
22142(allow ephemeral_app cameraserver_service (service_manager (find)))
22143(allow ephemeral_app mediaserver_service (service_manager (find)))
22144(allow ephemeral_app mediaextractor_service (service_manager (find)))
22145(allow ephemeral_app mediametrics_service (service_manager (find)))
22146(allow ephemeral_app mediadrmserver_service (service_manager (find)))
22147(allow ephemeral_app drmserver_service (service_manager (find)))
22148(allow ephemeral_app radio_service (service_manager (find)))
22149(allow ephemeral_app ephemeral_app_api_service (service_manager (find)))
22150(allow ephemeral_app system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
22151(allow ephemeral_app ashmem_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22152;;* lmx 59 system/sepolicy/private/ephemeral_app.te
22153
22154(neverallow ephemeral_app app_data_file_type (file (execute_no_trans)))
22155;;* lme
22156
22157;;* lmx 62 system/sepolicy/private/ephemeral_app.te
22158
22159(neverallow ephemeral_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22160;;* lme
22161
22162;;* lmx 65 system/sepolicy/private/ephemeral_app.te
22163
22164(neverallow ephemeral_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22165;;* lme
22166
22167;;* lmx 69 system/sepolicy/private/ephemeral_app.te
22168
22169(neverallow ephemeral_app debugfs_type (file (read)))
22170;;* lme
22171
22172;;* lmx 72 system/sepolicy/private/ephemeral_app.te
22173
22174(neverallow ephemeral_app gpu_device (chr_file (execute)))
22175;;* lme
22176
22177;;* lmx 75 system/sepolicy/private/ephemeral_app.te
22178
22179(neverallow ephemeral_app sysfs (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22180;;* lme
22181
22182;;* lmx 79 system/sepolicy/private/ephemeral_app.te
22183
22184(neverallow ephemeral_app proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
22185;;* lme
22186
22187;;* lmx 82 system/sepolicy/private/ephemeral_app.te
22188
22189(neverallow ephemeral_app sdcard_type (file (create open)))
22190(neverallow ephemeral_app fuse (file (create open)))
22191(neverallow ephemeral_app media_rw_data_file (file (create open)))
22192;;* lme
22193
22194;;* lmx 83 system/sepolicy/private/ephemeral_app.te
22195
22196(neverallow ephemeral_app sdcard_type (dir (search)))
22197(neverallow ephemeral_app fuse (dir (search)))
22198(neverallow ephemeral_app media_rw_data_file (dir (search)))
22199;;* lme
22200
22201;;* lmx 87 system/sepolicy/private/ephemeral_app.te
22202
22203(neverallow ephemeral_app proc_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22204;;* lme
22205
22206(allow init evsmanagerd_exec (file (read getattr map execute open)))
22207(allow init evsmanagerd (process (transition)))
22208(allow evsmanagerd evsmanagerd_exec (file (read getattr map execute open entrypoint)))
22209(dontaudit init evsmanagerd (process (noatsecure)))
22210(allow init evsmanagerd (process (siginh rlimitinh)))
22211(typetransition init evsmanagerd_exec process evsmanagerd)
22212(allow evsmanagerd evsmanagerd_service (service_manager (add find)))
22213;;* lmx 13 system/sepolicy/private/evsmanagerd.te
22214
22215(neverallow base_typeattr_766 evsmanagerd_service (service_manager (add)))
22216;;* lme
22217
22218(allow evsmanagerd servicemanager (binder (call transfer)))
22219(allow servicemanager evsmanagerd (binder (call transfer)))
22220(allow servicemanager evsmanagerd (dir (search)))
22221(allow servicemanager evsmanagerd (file (read open)))
22222(allow servicemanager evsmanagerd (process (getattr)))
22223(allow evsmanagerd system_server (binder (call transfer)))
22224(allow system_server evsmanagerd (binder (transfer)))
22225(allow evsmanagerd system_server (fd (use)))
22226(allow evsmanagerd shell (fd (use)))
22227(allow evsmanagerd shell (fifo_file (write)))
22228(allow evsmanagerd hal_graphics_allocator (fd (use)))
22229(allow evsmanagerd statsbootstrap_service (service_manager (find)))
22230(allow evsmanagerd appdomain (binder (call transfer)))
22231(allow appdomain evsmanagerd (binder (transfer)))
22232(allow evsmanagerd appdomain (fd (use)))
22233(allow evsmanagerd hal_evs_hwservice (hwservice_manager (add)))
22234(allow evsmanagerd hidl_base_hwservice (hwservice_manager (add)))
22235(allow init extra_free_kbytes_exec (file (read getattr map execute open)))
22236(allow init extra_free_kbytes (process (transition)))
22237(allow extra_free_kbytes extra_free_kbytes_exec (file (read getattr map execute open entrypoint)))
22238(dontaudit init extra_free_kbytes (process (noatsecure)))
22239(allow init extra_free_kbytes (process (siginh rlimitinh)))
22240(typetransition init extra_free_kbytes_exec process extra_free_kbytes)
22241(allow extra_free_kbytes property_socket (sock_file (write)))
22242(allow extra_free_kbytes init (unix_stream_socket (connectto)))
22243(allow extra_free_kbytes init_storage_prop (property_service (set)))
22244(allow extra_free_kbytes init_storage_prop (file (read getattr map open)))
22245(allow fastbootd self (capability (ipc_lock)))
22246(allow fastbootd fastbootd_iouring (anon_inode (read write create map)))
22247(allow fastbootd self (io_uring (sqpoll)))
22248;;* lmx 57 system/sepolicy/private/fastbootd.te
22249
22250(neverallow base_typeattr_767 fastbootd_iouring (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22251;;* lme
22252
22253(dontaudit fastbootd self (capability (ipc_lock)))
22254(dontaudit fastbootd self (cap_userns (ipc_lock)))
22255(allow init fingerprintd_exec (file (read getattr map execute open)))
22256(allow init fingerprintd (process (transition)))
22257(allow fingerprintd fingerprintd_exec (file (read getattr map execute open entrypoint)))
22258(dontaudit init fingerprintd (process (noatsecure)))
22259(allow init fingerprintd (process (siginh rlimitinh)))
22260(typetransition init fingerprintd_exec process fingerprintd)
22261(allow init flags_health_check_exec (file (read getattr map execute open)))
22262(allow init flags_health_check (process (transition)))
22263(allow flags_health_check flags_health_check_exec (file (read getattr map execute open entrypoint)))
22264(dontaudit init flags_health_check (process (noatsecure)))
22265(allow init flags_health_check (process (siginh rlimitinh)))
22266(typetransition init flags_health_check_exec process flags_health_check)
22267(allow flags_health_check property_socket (sock_file (write)))
22268(allow flags_health_check init (unix_stream_socket (connectto)))
22269(allow flags_health_check device_config_boot_count_prop (property_service (set)))
22270(allow flags_health_check device_config_boot_count_prop (file (read getattr map open)))
22271(allow flags_health_check property_socket (sock_file (write)))
22272(allow flags_health_check init (unix_stream_socket (connectto)))
22273(allow flags_health_check device_config_core_experiments_team_internal_prop (property_service (set)))
22274(allow flags_health_check device_config_core_experiments_team_internal_prop (file (read getattr map open)))
22275(allow flags_health_check property_socket (sock_file (write)))
22276(allow flags_health_check init (unix_stream_socket (connectto)))
22277(allow flags_health_check device_config_edgetpu_native_prop (property_service (set)))
22278(allow flags_health_check device_config_edgetpu_native_prop (file (read getattr map open)))
22279(allow flags_health_check property_socket (sock_file (write)))
22280(allow flags_health_check init (unix_stream_socket (connectto)))
22281(allow flags_health_check device_config_reset_performed_prop (property_service (set)))
22282(allow flags_health_check device_config_reset_performed_prop (file (read getattr map open)))
22283(allow flags_health_check property_socket (sock_file (write)))
22284(allow flags_health_check init (unix_stream_socket (connectto)))
22285(allow flags_health_check device_config_runtime_native_boot_prop (property_service (set)))
22286(allow flags_health_check device_config_runtime_native_boot_prop (file (read getattr map open)))
22287(allow flags_health_check property_socket (sock_file (write)))
22288(allow flags_health_check init (unix_stream_socket (connectto)))
22289(allow flags_health_check device_config_runtime_native_prop (property_service (set)))
22290(allow flags_health_check device_config_runtime_native_prop (file (read getattr map open)))
22291(allow flags_health_check property_socket (sock_file (write)))
22292(allow flags_health_check init (unix_stream_socket (connectto)))
22293(allow flags_health_check device_config_input_native_boot_prop (property_service (set)))
22294(allow flags_health_check device_config_input_native_boot_prop (file (read getattr map open)))
22295(allow flags_health_check property_socket (sock_file (write)))
22296(allow flags_health_check init (unix_stream_socket (connectto)))
22297(allow flags_health_check device_config_lmkd_native_prop (property_service (set)))
22298(allow flags_health_check device_config_lmkd_native_prop (file (read getattr map open)))
22299(allow flags_health_check property_socket (sock_file (write)))
22300(allow flags_health_check init (unix_stream_socket (connectto)))
22301(allow flags_health_check device_config_netd_native_prop (property_service (set)))
22302(allow flags_health_check device_config_netd_native_prop (file (read getattr map open)))
22303(allow flags_health_check property_socket (sock_file (write)))
22304(allow flags_health_check init (unix_stream_socket (connectto)))
22305(allow flags_health_check device_config_nnapi_native_prop (property_service (set)))
22306(allow flags_health_check device_config_nnapi_native_prop (file (read getattr map open)))
22307(allow flags_health_check property_socket (sock_file (write)))
22308(allow flags_health_check init (unix_stream_socket (connectto)))
22309(allow flags_health_check device_config_activity_manager_native_boot_prop (property_service (set)))
22310(allow flags_health_check device_config_activity_manager_native_boot_prop (file (read getattr map open)))
22311(allow flags_health_check property_socket (sock_file (write)))
22312(allow flags_health_check init (unix_stream_socket (connectto)))
22313(allow flags_health_check device_config_media_native_prop (property_service (set)))
22314(allow flags_health_check device_config_media_native_prop (file (read getattr map open)))
22315(allow flags_health_check property_socket (sock_file (write)))
22316(allow flags_health_check init (unix_stream_socket (connectto)))
22317(allow flags_health_check device_config_mglru_native_prop (property_service (set)))
22318(allow flags_health_check device_config_mglru_native_prop (file (read getattr map open)))
22319(allow flags_health_check property_socket (sock_file (write)))
22320(allow flags_health_check init (unix_stream_socket (connectto)))
22321(allow flags_health_check device_config_profcollect_native_boot_prop (property_service (set)))
22322(allow flags_health_check device_config_profcollect_native_boot_prop (file (read getattr map open)))
22323(allow flags_health_check property_socket (sock_file (write)))
22324(allow flags_health_check init (unix_stream_socket (connectto)))
22325(allow flags_health_check device_config_statsd_native_prop (property_service (set)))
22326(allow flags_health_check device_config_statsd_native_prop (file (read getattr map open)))
22327(allow flags_health_check property_socket (sock_file (write)))
22328(allow flags_health_check init (unix_stream_socket (connectto)))
22329(allow flags_health_check device_config_statsd_native_boot_prop (property_service (set)))
22330(allow flags_health_check device_config_statsd_native_boot_prop (file (read getattr map open)))
22331(allow flags_health_check property_socket (sock_file (write)))
22332(allow flags_health_check init (unix_stream_socket (connectto)))
22333(allow flags_health_check device_config_storage_native_boot_prop (property_service (set)))
22334(allow flags_health_check device_config_storage_native_boot_prop (file (read getattr map open)))
22335(allow flags_health_check property_socket (sock_file (write)))
22336(allow flags_health_check init (unix_stream_socket (connectto)))
22337(allow flags_health_check device_config_swcodec_native_prop (property_service (set)))
22338(allow flags_health_check device_config_swcodec_native_prop (file (read getattr map open)))
22339(allow flags_health_check property_socket (sock_file (write)))
22340(allow flags_health_check init (unix_stream_socket (connectto)))
22341(allow flags_health_check device_config_sys_traced_prop (property_service (set)))
22342(allow flags_health_check device_config_sys_traced_prop (file (read getattr map open)))
22343(allow flags_health_check property_socket (sock_file (write)))
22344(allow flags_health_check init (unix_stream_socket (connectto)))
22345(allow flags_health_check device_config_window_manager_native_boot_prop (property_service (set)))
22346(allow flags_health_check device_config_window_manager_native_boot_prop (file (read getattr map open)))
22347(allow flags_health_check property_socket (sock_file (write)))
22348(allow flags_health_check init (unix_stream_socket (connectto)))
22349(allow flags_health_check device_config_configuration_prop (property_service (set)))
22350(allow flags_health_check device_config_configuration_prop (file (read getattr map open)))
22351(allow flags_health_check property_socket (sock_file (write)))
22352(allow flags_health_check init (unix_stream_socket (connectto)))
22353(allow flags_health_check device_config_connectivity_prop (property_service (set)))
22354(allow flags_health_check device_config_connectivity_prop (file (read getattr map open)))
22355(allow flags_health_check property_socket (sock_file (write)))
22356(allow flags_health_check init (unix_stream_socket (connectto)))
22357(allow flags_health_check device_config_surface_flinger_native_boot_prop (property_service (set)))
22358(allow flags_health_check device_config_surface_flinger_native_boot_prop (file (read getattr map open)))
22359(allow flags_health_check property_socket (sock_file (write)))
22360(allow flags_health_check init (unix_stream_socket (connectto)))
22361(allow flags_health_check device_config_aconfig_flags_prop (property_service (set)))
22362(allow flags_health_check device_config_aconfig_flags_prop (file (read getattr map open)))
22363(allow flags_health_check property_socket (sock_file (write)))
22364(allow flags_health_check init (unix_stream_socket (connectto)))
22365(allow flags_health_check device_config_vendor_system_native_prop (property_service (set)))
22366(allow flags_health_check device_config_vendor_system_native_prop (file (read getattr map open)))
22367(allow flags_health_check property_socket (sock_file (write)))
22368(allow flags_health_check init (unix_stream_socket (connectto)))
22369(allow flags_health_check device_config_vendor_system_native_boot_prop (property_service (set)))
22370(allow flags_health_check device_config_vendor_system_native_boot_prop (file (read getattr map open)))
22371(allow flags_health_check property_socket (sock_file (write)))
22372(allow flags_health_check init (unix_stream_socket (connectto)))
22373(allow flags_health_check device_config_virtualization_framework_native_prop (property_service (set)))
22374(allow flags_health_check device_config_virtualization_framework_native_prop (file (read getattr map open)))
22375(allow flags_health_check property_socket (sock_file (write)))
22376(allow flags_health_check init (unix_stream_socket (connectto)))
22377(allow flags_health_check device_config_memory_safety_native_boot_prop (property_service (set)))
22378(allow flags_health_check device_config_memory_safety_native_boot_prop (file (read getattr map open)))
22379(allow flags_health_check property_socket (sock_file (write)))
22380(allow flags_health_check init (unix_stream_socket (connectto)))
22381(allow flags_health_check device_config_memory_safety_native_prop (property_service (set)))
22382(allow flags_health_check device_config_memory_safety_native_prop (file (read getattr map open)))
22383(allow flags_health_check property_socket (sock_file (write)))
22384(allow flags_health_check init (unix_stream_socket (connectto)))
22385(allow flags_health_check device_config_remote_key_provisioning_native_prop (property_service (set)))
22386(allow flags_health_check device_config_remote_key_provisioning_native_prop (file (read getattr map open)))
22387(allow flags_health_check property_socket (sock_file (write)))
22388(allow flags_health_check init (unix_stream_socket (connectto)))
22389(allow flags_health_check device_config_camera_native_prop (property_service (set)))
22390(allow flags_health_check device_config_camera_native_prop (file (read getattr map open)))
22391(allow flags_health_check property_socket (sock_file (write)))
22392(allow flags_health_check init (unix_stream_socket (connectto)))
22393(allow flags_health_check device_config_tethering_u_or_later_native_prop (property_service (set)))
22394(allow flags_health_check device_config_tethering_u_or_later_native_prop (file (read getattr map open)))
22395(allow flags_health_check property_socket (sock_file (write)))
22396(allow flags_health_check init (unix_stream_socket (connectto)))
22397(allow flags_health_check next_boot_prop (property_service (set)))
22398(allow flags_health_check next_boot_prop (file (read getattr map open)))
22399;;* lmx 43 system/sepolicy/private/flags_health_check.te
22400
22401(neverallow base_typeattr_336 device_config_boot_count_prop (property_service (set)))
22402;;* lme
22403
22404;;* lmx 48 system/sepolicy/private/flags_health_check.te
22405
22406(neverallow base_typeattr_336 device_config_reset_performed_prop (property_service (set)))
22407;;* lme
22408
22409(allow init fsck_exec (file (read getattr map execute open)))
22410(allow init fsck (process (transition)))
22411(allow fsck fsck_exec (file (read getattr map execute open entrypoint)))
22412(dontaudit init fsck (process (noatsecure)))
22413(allow init fsck (process (siginh rlimitinh)))
22414(typetransition init fsck_exec process fsck)
22415(allow fsck metadata_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
22416(allow init fsverity_init_exec (file (read getattr map execute open)))
22417(allow init fsverity_init (process (transition)))
22418(allow fsverity_init fsverity_init_exec (file (read getattr map execute open entrypoint)))
22419(dontaudit init fsverity_init (process (noatsecure)))
22420(allow init fsverity_init (process (siginh rlimitinh)))
22421(typetransition init fsverity_init_exec process fsverity_init)
22422(allow fsverity_init proc_keys (file (ioctl read getattr lock map open watch watch_reads)))
22423(dontaudit fsverity_init domain (key (view)))
22424(allow fsverity_init kernel (key (view write search setattr)))
22425(allow fsverity_init fsverity_init (key (view write search)))
22426(allow fsverity_init odsign (fd (use)))
22427(allow fsverity_init odsign_data_file (file (read getattr)))
22428(allow fuseblkd self (capability (sys_admin)))
22429(allow fuseblkd self (cap_userns (sys_admin)))
22430(allow fuseblkd fuse_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22431(allow fuseblkd fuseblk (filesystem (mount unmount)))
22432(allow fuseblkd fuseblkd_untrusted (fd (use)))
22433(allow fuseblkd block_device (dir (search)))
22434(allow fuseblkd mnt_media_rw_file (dir (search)))
22435(allow fuseblkd mnt_media_rw_stub_file (dir (mounton)))
22436;;* lmx 30 system/sepolicy/private/fuseblkd.te
22437
22438(neverallow base_typeattr_768 fuseblkd (process (transition)))
22439;;* lme
22440
22441;;* lmx 31 system/sepolicy/private/fuseblkd.te
22442
22443(neverallow base_typeattr_224 fuseblkd (process (dyntransition)))
22444;;* lme
22445
22446;;* lmx 32 system/sepolicy/private/fuseblkd.te
22447
22448(neverallow fuseblkd base_typeattr_769 (file (entrypoint)))
22449;;* lme
22450
22451(allow fuseblkd_untrusted fuseblkd_exec (file (read getattr map execute open)))
22452(allow fuseblkd_untrusted fuseblkd (process (transition)))
22453(allow fuseblkd fuseblkd_exec (file (read getattr map execute open entrypoint)))
22454(allow fuseblkd fuseblkd_untrusted (process (sigchld)))
22455(dontaudit fuseblkd_untrusted fuseblkd (process (noatsecure)))
22456(allow fuseblkd_untrusted fuseblkd (process (siginh rlimitinh)))
22457(typetransition fuseblkd_untrusted fuseblkd_exec process fuseblkd)
22458(allow fuseblkd_untrusted vold (fd (use)))
22459(allow fuseblkd_untrusted block_device (dir (search)))
22460(allow fuseblkd_untrusted super_block_device (blk_file (getattr)))
22461(allow fuseblkd_untrusted fuse_device (chr_file (read write getattr open)))
22462(allow fuseblkd_untrusted mnt_media_rw_file (dir (getattr search)))
22463(allow fuseblkd_untrusted mnt_media_rw_stub_file (dir (getattr)))
22464(allow fuseblkd_untrusted sysfs_dm (dir (search)))
22465(allow fuseblkd_untrusted sysfs_dm (file (read getattr open)))
22466(allow fuseblkd_untrusted dm_device (blk_file (getattr)))
22467(allow fuseblkd_untrusted tmpfs (lnk_file (read)))
22468(allow fuseblkd_untrusted loop_device (blk_file (getattr)))
22469(allow fuseblkd_untrusted proc_filesystems (file (read getattr open)))
22470(dontaudit fuseblkd_untrusted self (capability (sys_admin)))
22471;;* lmx 65 system/sepolicy/private/fuseblkd_untrusted.te
22472
22473(neverallow fuseblkd_untrusted dm_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22474(neverallow fuseblkd_untrusted root_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22475(neverallow fuseblkd_untrusted frp_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22476(neverallow fuseblkd_untrusted system_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22477(neverallow fuseblkd_untrusted recovery_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22478(neverallow fuseblkd_untrusted boot_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22479(neverallow fuseblkd_untrusted userdata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22480(neverallow fuseblkd_untrusted cache_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22481(neverallow fuseblkd_untrusted swap_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22482(neverallow fuseblkd_untrusted metadata_block_device (blk_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22483;;* lme
22484
22485;;* lmx 68 system/sepolicy/private/fuseblkd_untrusted.te
22486
22487(neverallow base_typeattr_339 fuseblkd_untrusted (process (transition)))
22488;;* lme
22489
22490;;* lmx 69 system/sepolicy/private/fuseblkd_untrusted.te
22491
22492(neverallow base_typeattr_224 fuseblkd_untrusted (process (dyntransition)))
22493;;* lme
22494
22495;;* lmx 70 system/sepolicy/private/fuseblkd_untrusted.te
22496
22497(neverallow fuseblkd_untrusted base_typeattr_770 (file (entrypoint)))
22498;;* lme
22499
22500;;* lmx 77 system/sepolicy/private/fuseblkd_untrusted.te
22501
22502(neverallow fuseblkd_untrusted self (capability (setgid setuid sys_admin)))
22503;;* lme
22504
22505;;* lmx 78 system/sepolicy/private/fuseblkd_untrusted.te
22506
22507(neverallow fuseblkd_untrusted self (capability (setgid setuid sys_admin)))
22508(neverallow fuseblkd_untrusted self (cap_userns (setgid setuid sys_admin)))
22509;;* lme
22510
22511;;* lmx 82 system/sepolicy/private/fuseblkd_untrusted.te
22512
22513(neverallow fuseblkd_untrusted fuseblk (filesystem (mount unmount relabelfrom relabelto)))
22514;;* lme
22515
22516(allow fwk_bufferhub ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
22517(allow init fwk_bufferhub_exec (file (read getattr map execute open)))
22518(allow init fwk_bufferhub (process (transition)))
22519(allow fwk_bufferhub fwk_bufferhub_exec (file (read getattr map execute open entrypoint)))
22520(dontaudit init fwk_bufferhub (process (noatsecure)))
22521(allow init fwk_bufferhub (process (siginh rlimitinh)))
22522(typetransition init fwk_bufferhub_exec process fwk_bufferhub)
22523(allow init gatekeeperd_exec (file (read getattr map execute open)))
22524(allow init gatekeeperd (process (transition)))
22525(allow gatekeeperd gatekeeperd_exec (file (read getattr map execute open entrypoint)))
22526(dontaudit init gatekeeperd (process (noatsecure)))
22527(allow init gatekeeperd (process (siginh rlimitinh)))
22528(typetransition init gatekeeperd_exec process gatekeeperd)
22529(allow gatekeeperd gsid_prop (file (read getattr map open)))
22530(allow gki_apex_prepostinstall shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
22531(allow gki_apex_prepostinstall toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
22532(allow gki_apex_prepostinstall gki_apex_prepostinstall_exec (file (execute_no_trans)))
22533(allow gki_apex_prepostinstall servicemanager (binder (call transfer)))
22534(allow servicemanager gki_apex_prepostinstall (binder (call transfer)))
22535(allow servicemanager gki_apex_prepostinstall (dir (search)))
22536(allow servicemanager gki_apex_prepostinstall (file (read open)))
22537(allow servicemanager gki_apex_prepostinstall (process (getattr)))
22538(allow gki_apex_prepostinstall update_engine_stable_service (service_manager (find)))
22539(allow gki_apex_prepostinstall update_engine (binder (call transfer)))
22540(allow update_engine gki_apex_prepostinstall (binder (transfer)))
22541(allow gki_apex_prepostinstall update_engine (fd (use)))
22542(allow gki_apex_prepostinstall apexd (fd (use)))
22543(typetransition gmscore_app tmpfs file appdomain_tmpfs)
22544(allow gmscore_app gmscore_app_userfaultfd (anon_inode (ioctl read create)))
22545(dontaudit su gmscore_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22546;;* lmx 6 system/sepolicy/private/gmscore_app.te
22547
22548(neverallow base_typeattr_771 gmscore_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22549;;* lme
22550
22551(allow gmscore_app appdomain_tmpfs (file (read write getattr map execute)))
22552;;* lmx 6 system/sepolicy/private/gmscore_app.te
22553
22554(neverallow base_typeattr_772 base_typeattr_771 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22555;;* lme
22556
22557;;* lmx 6 system/sepolicy/private/gmscore_app.te
22558
22559(neverallow base_typeattr_773 gmscore_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22560;;* lme
22561
22562;;* lmx 6 system/sepolicy/private/gmscore_app.te
22563
22564(neverallow base_typeattr_774 gmscore_app (process (ptrace)))
22565;;* lme
22566
22567(allow gmscore_app sysfs_type (dir (search)))
22568(allow gmscore_app sysfs_zram (dir (ioctl read getattr lock open watch watch_reads search)))
22569(allow gmscore_app sysfs_zram (file (ioctl read getattr lock map open watch watch_reads)))
22570(allow gmscore_app sysfs_zram (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22571(allow gmscore_app rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
22572(allow gmscore_app rootfs (file (ioctl read getattr lock map open watch watch_reads)))
22573(allow gmscore_app rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22574(allow gmscore_app config_gz (file (read getattr open)))
22575(allow gmscore_app update_engine (binder (call transfer)))
22576(allow update_engine gmscore_app (binder (transfer)))
22577(allow gmscore_app update_engine (fd (use)))
22578(allow gmscore_app update_engine_service (service_manager (find)))
22579(allow gmscore_app storaged (binder (call transfer)))
22580(allow storaged gmscore_app (binder (transfer)))
22581(allow gmscore_app storaged (fd (use)))
22582(allow gmscore_app storaged_service (service_manager (find)))
22583(allow gmscore_app system_update_service (service_manager (find)))
22584(allow gmscore_app statsd (binder (call transfer)))
22585(allow statsd gmscore_app (binder (transfer)))
22586(allow gmscore_app statsd (fd (use)))
22587(allow gmscore_app perfetto (fd (use)))
22588(allow gmscore_app perfetto_traces_data_file (file (read getattr)))
22589(allow gmscore_app keystore (keystore2_key (gen_unique_id)))
22590(allow gmscore_app selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
22591(dontaudit gmscore_app exec_type (file (ioctl read getattr lock map open watch watch_reads)))
22592(dontaudit gmscore_app device (dir (ioctl read getattr lock open watch watch_reads search)))
22593(dontaudit gmscore_app fs_bpf (dir (ioctl read getattr lock open watch watch_reads search)))
22594(dontaudit gmscore_app kernel (security (compute_av compute_create compute_member check_context load_policy compute_relabel compute_user setenforce setbool setsecparam setcheckreqprot read_policy validate_trans)))
22595(dontaudit gmscore_app net_dns_prop (file (ioctl read getattr lock map open watch watch_reads)))
22596(dontaudit gmscore_app proc (file (ioctl read getattr lock map open watch watch_reads)))
22597(dontaudit gmscore_app proc_interrupts (file (ioctl read getattr lock map open watch watch_reads)))
22598(dontaudit gmscore_app proc_modules (file (ioctl read getattr lock map open watch watch_reads)))
22599(dontaudit gmscore_app proc_net (file (ioctl read getattr lock map open watch watch_reads)))
22600(dontaudit gmscore_app proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
22601(dontaudit gmscore_app proc_version (file (ioctl read getattr lock map open watch watch_reads)))
22602(dontaudit gmscore_app sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
22603(dontaudit gmscore_app sysfs (file (ioctl read getattr lock map open watch watch_reads)))
22604(dontaudit gmscore_app sysfs_android_usb (file (ioctl read getattr lock map open watch watch_reads)))
22605(dontaudit gmscore_app sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
22606(dontaudit gmscore_app sysfs_loop (file (ioctl read getattr lock map open watch watch_reads)))
22607(dontaudit gmscore_app sysfs_net (file (ioctl read getattr lock map open watch watch_reads)))
22608(dontaudit gmscore_app sysfs_net (dir (ioctl read getattr lock open watch watch_reads search)))
22609(dontaudit gmscore_app wifi_hal_prop (file (ioctl read getattr lock map open watch watch_reads)))
22610(dontaudit gmscore_app wifi_prop (file (ioctl read getattr lock map open watch watch_reads)))
22611(dontaudit gmscore_app mirror_data_file (dir (search)))
22612(dontaudit gmscore_app mnt_vendor_file (dir (search)))
22613(allow gmscore_app self (process (ptrace)))
22614(allow gmscore_app privapp_data_file (file (execute)))
22615(allow gmscore_app system_linker_exec (file (execute_no_trans)))
22616(allow gmscore_app privapp_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22617(allow gmscore_app proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
22618(allow gmscore_app gpuservice (binder (call transfer)))
22619(allow gpuservice gmscore_app (binder (transfer)))
22620(allow gmscore_app gpuservice (fd (use)))
22621(allow gmscore_app gpu_service (service_manager (find)))
22622(allow gmscore_app app_api_service (service_manager (find)))
22623(allow gmscore_app system_api_service (service_manager (find)))
22624(allow gmscore_app audioserver_service (service_manager (find)))
22625(allow gmscore_app cameraserver_service (service_manager (find)))
22626(allow gmscore_app drmserver_service (service_manager (find)))
22627(allow gmscore_app mediadrmserver_service (service_manager (find)))
22628(allow gmscore_app mediaextractor_service (service_manager (find)))
22629(allow gmscore_app mediametrics_service (service_manager (find)))
22630(allow gmscore_app mediaserver_service (service_manager (find)))
22631(allow gmscore_app network_watchlist_service (service_manager (find)))
22632(allow gmscore_app nfc_service (service_manager (find)))
22633(allow gmscore_app oem_lock_service (service_manager (find)))
22634(allow gmscore_app persistent_data_block_service (service_manager (find)))
22635(allow gmscore_app radio_service (service_manager (find)))
22636(allow gmscore_app recovery_service (service_manager (find)))
22637(allow gmscore_app stats_service (service_manager (find)))
22638(allow gmscore_app shell_data_file (file (ioctl read getattr lock map open watch watch_reads)))
22639(allow gmscore_app shell_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
22640(allow gmscore_app cache_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22641(allow gmscore_app cache_recovery_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22642(allow gmscore_app cache_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22643(allow gmscore_app cache_recovery_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22644(allow gmscore_app cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22645(allow gmscore_app ota_package_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22646(allow gmscore_app ota_package_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22647(allow gmscore_app checkin_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
22648(allow gmscore_app checkin_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22649(allow gmscore_app shell_data_file (file (ioctl read getattr lock map open watch watch_reads)))
22650(allow gmscore_app shell_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
22651(allow gmscore_app anr_data_file (file (ioctl read getattr lock map open watch watch_reads)))
22652(allow gmscore_app priv_app (tcp_socket (read write)))
22653(allow gmscore_app virtual_ab_prop (file (read getattr map open)))
22654(allow gmscore_app dck_prop (file (read getattr map open)))
22655(allow gmscore_app remote_prov_prop (file (read getattr map open)))
22656(allow gmscore_app quick_start_prop (file (read getattr map open)))
22657;;* lmx 158 system/sepolicy/private/gmscore_app.te
22658
22659(neverallow base_typeattr_775 quick_start_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
22660;;* lme
22661
22662;;* lmx 161 system/sepolicy/private/gmscore_app.te
22663
22664(neverallow gmscore_app sysfs_net (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22665;;* lme
22666
22667;;* lmx 165 system/sepolicy/private/gmscore_app.te
22668
22669(neverallowx gmscore_app domain (ioctl tcp_socket (0x6900 0x6902)))
22670(neverallowx gmscore_app domain (ioctl udp_socket (0x6900 0x6902)))
22671(neverallowx gmscore_app domain (ioctl rawip_socket (0x6900 0x6902)))
22672(neverallowx gmscore_app domain (ioctl icmp_socket (0x6900 0x6902)))
22673;;* lme
22674
22675;;* lmx 165 system/sepolicy/private/gmscore_app.te
22676
22677(neverallowx gmscore_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
22678(neverallowx gmscore_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
22679(neverallowx gmscore_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
22680(neverallowx gmscore_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
22681;;* lme
22682
22683;;* lmx 165 system/sepolicy/private/gmscore_app.te
22684
22685(neverallowx gmscore_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
22686(neverallowx gmscore_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
22687(neverallowx gmscore_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
22688(neverallowx gmscore_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
22689;;* lme
22690
22691;;* lmx 166 system/sepolicy/private/gmscore_app.te
22692
22693(neverallow gmscore_app base_typeattr_224 (netlink_route_socket (ioctl)))
22694(neverallow gmscore_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
22695;;* lme
22696
22697;;* lmx 179 system/sepolicy/private/gmscore_app.te
22698
22699(neverallow gmscore_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22700(neverallow gmscore_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22701(neverallow gmscore_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22702(neverallow gmscore_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22703(neverallow gmscore_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
22704(neverallow gmscore_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22705(neverallow gmscore_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
22706(neverallow gmscore_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
22707(neverallow gmscore_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22708(neverallow gmscore_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22709(neverallow gmscore_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22710(neverallow gmscore_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
22711(neverallow gmscore_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22712(neverallow gmscore_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22713(neverallow gmscore_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22714(neverallow gmscore_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22715(neverallow gmscore_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22716(neverallow gmscore_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22717(neverallow gmscore_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22718(neverallow gmscore_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22719(neverallow gmscore_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
22720(neverallow gmscore_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22721(neverallow gmscore_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22722(neverallow gmscore_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22723(neverallow gmscore_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22724(neverallow gmscore_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22725(neverallow gmscore_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22726(neverallow gmscore_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22727(neverallow gmscore_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22728(neverallow gmscore_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22729(neverallow gmscore_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22730(neverallow gmscore_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22731(neverallow gmscore_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22732(neverallow gmscore_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22733(neverallow gmscore_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22734(neverallow gmscore_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22735(neverallow gmscore_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22736(neverallow gmscore_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22737(neverallow gmscore_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22738(neverallow gmscore_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22739(neverallow gmscore_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22740(neverallow gmscore_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22741(neverallow gmscore_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22742(neverallow gmscore_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22743(neverallow gmscore_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22744(neverallow gmscore_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22745(neverallow gmscore_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22746(neverallow gmscore_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
22747;;* lme
22748
22749(allow init gpuservice_exec (file (read getattr map execute open)))
22750(allow init gpuservice (process (transition)))
22751(allow gpuservice gpuservice_exec (file (read getattr map execute open entrypoint)))
22752(dontaudit init gpuservice (process (noatsecure)))
22753(allow init gpuservice (process (siginh rlimitinh)))
22754(typetransition init gpuservice_exec process gpuservice)
22755(allow gpuservice adbd (binder (call transfer)))
22756(allow adbd gpuservice (binder (transfer)))
22757(allow gpuservice adbd (fd (use)))
22758(allow gpuservice shell (binder (call transfer)))
22759(allow shell gpuservice (binder (transfer)))
22760(allow gpuservice shell (fd (use)))
22761(allow gpuservice system_server (binder (call transfer)))
22762(allow system_server gpuservice (binder (transfer)))
22763(allow gpuservice system_server (fd (use)))
22764(allow gpuservice servicemanager (binder (call transfer)))
22765(allow servicemanager gpuservice (binder (call transfer)))
22766(allow servicemanager gpuservice (dir (search)))
22767(allow servicemanager gpuservice (file (read open)))
22768(allow servicemanager gpuservice (process (getattr)))
22769(allow gpuservice gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22770(allow gpuservice same_process_hal_file (file (read getattr map execute open)))
22771(allow gpuservice ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
22772(allow gpuservice hwservicemanager_prop (file (read getattr map open)))
22773(allow gpuservice hwservicemanager (binder (call transfer)))
22774(allow hwservicemanager gpuservice (binder (call transfer)))
22775(allow hwservicemanager gpuservice (dir (search)))
22776(allow hwservicemanager gpuservice (file (read map open)))
22777(allow hwservicemanager gpuservice (process (getattr)))
22778(allow gpuservice graphics_device (dir (search)))
22779(allow gpuservice graphics_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22780(allow gpuservice adbd (fd (use)))
22781(allow gpuservice adbd (unix_stream_socket (read write getattr)))
22782(allow gpuservice shell (fifo_file (read write getattr)))
22783(allow gpuservice traced (fd (use)))
22784(allow gpuservice traced_tmpfs (file (read write getattr map)))
22785(allow gpuservice traced_producer_socket (sock_file (write)))
22786(allow gpuservice traced (unix_stream_socket (connectto)))
22787(allow traced gpuservice (fd (use)))
22788(allow gpuservice devpts (chr_file (read write getattr)))
22789(allow gpuservice dumpstate (fd (use)))
22790(allow gpuservice dumpstate (fifo_file (write)))
22791(allow gpuservice stats_service (service_manager (find)))
22792(allow gpuservice statsmanager_service (service_manager (find)))
22793(allow gpuservice statsd (binder (call transfer)))
22794(allow statsd gpuservice (binder (transfer)))
22795(allow gpuservice statsd (fd (use)))
22796(allow gpuservice debugfs_tracing (file (ioctl read getattr lock map open watch watch_reads)))
22797(allow gpuservice self (perf_event (open cpu kernel write)))
22798;;* lmx 52 system/sepolicy/private/gpuservice.te
22799
22800(neverallow gpuservice self (perf_event (tracepoint read)))
22801;;* lme
22802
22803(allow gpuservice fs_bpf (file (read write)))
22804(allow gpuservice bpfloader (bpf (map_read map_write prog_run)))
22805(allow gpuservice gpu_service (service_manager (add find)))
22806;;* lmx 61 system/sepolicy/private/gpuservice.te
22807
22808(neverallow base_typeattr_776 gpu_service (service_manager (add)))
22809;;* lme
22810
22811(allow gpuservice property_socket (sock_file (write)))
22812(allow gpuservice init (unix_stream_socket (connectto)))
22813(allow gpuservice graphics_config_writable_prop (property_service (set)))
22814(allow gpuservice graphics_config_writable_prop (file (read getattr map open)))
22815;;* lmx 66 system/sepolicy/private/gpuservice.te
22816
22817(neverallow base_typeattr_777 graphics_config_writable_prop (property_service (set)))
22818;;* lme
22819
22820(allow gpuservice permission_service (service_manager (find)))
22821(allow init gsid_exec (file (read getattr map execute open)))
22822(allow init gsid (process (transition)))
22823(allow gsid gsid_exec (file (read getattr map execute open entrypoint)))
22824(dontaudit init gsid (process (noatsecure)))
22825(allow init gsid (process (siginh rlimitinh)))
22826(typetransition init gsid_exec process gsid)
22827(allow gsid servicemanager (binder (call transfer)))
22828(allow servicemanager gsid (binder (call transfer)))
22829(allow servicemanager gsid (dir (search)))
22830(allow servicemanager gsid (file (read open)))
22831(allow servicemanager gsid (process (getattr)))
22832(allow gsid gsi_service (service_manager (add find)))
22833;;* lmx 11 system/sepolicy/private/gsid.te
22834
22835(neverallow base_typeattr_778 gsi_service (service_manager (add)))
22836;;* lme
22837
22838(allow gsid vold_service (service_manager (find)))
22839(allow gsid vold (binder (call transfer)))
22840(allow vold gsid (binder (transfer)))
22841(allow gsid vold (fd (use)))
22842(allow gsid property_socket (sock_file (write)))
22843(allow gsid init (unix_stream_socket (connectto)))
22844(allow gsid gsid_prop (property_service (set)))
22845(allow gsid gsid_prop (file (read getattr map open)))
22846(allow gsid dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22847(allow gsid dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
22848(allow gsid self (capability (sys_admin)))
22849(allow gsid self (cap_userns (sys_admin)))
22850(dontaudit gsid self (capability (dac_override)))
22851(dontaudit gsid self (cap_userns (dac_override)))
22852(allow gsid loop_control_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
22853(allow gsid loop_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
22854(allowx gsid loop_device (ioctl blk_file (0x1261)))
22855(allowx gsid loop_device (ioctl blk_file ((range 0x4c00 0x4c01) (range 0x4c04 0x4c05) (range 0x4c08 0x4c09))))
22856(allow gsid sysfs_dm (dir (ioctl read getattr lock open watch watch_reads search)))
22857(allow gsid sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
22858(allow gsid sysfs_dm (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22859(allow gsid sysfs_fs_f2fs (dir (ioctl read getattr lock open watch watch_reads search)))
22860(allow gsid sysfs_fs_f2fs (file (ioctl read getattr lock map open watch watch_reads)))
22861(allow gsid sysfs_fs_f2fs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
22862(allow gsid gsi_metadata_file_type (dir (search)))
22863(allow gsid metadata_file (dir (search)))
22864(allow gsid gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
22865(allow gsid proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
22866(allow gsid proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
22867(allow gsid sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
22868(allow gsid sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
22869(allow gsid block_device (dir (ioctl read getattr lock open watch watch_reads search)))
22870(allow gsid super_block_device_type (blk_file (ioctl read getattr lock map open watch watch_reads)))
22871(allowx gsid super_block_device_type (ioctl blk_file (0x1278 0x127a)))
22872(allowx gsid userdata_block_device (ioctl blk_file (0x1278 0x127a)))
22873(allowx gsid sdcard_block_device (ioctl blk_file (0x1278 0x127a)))
22874(allow gsid mnt_media_rw_file (dir (ioctl read getattr lock open watch watch_reads search)))
22875(allow gsid mnt_media_rw_stub_file (dir (ioctl read getattr lock open watch watch_reads search)))
22876(allow gsid vfat (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22877(allow gsid vfat (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22878(allow gsid sdcard_block_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
22879(allow gsid self (capability (sys_rawio)))
22880(allow gsid self (cap_userns (sys_rawio)))
22881;;* lmx 104 system/sepolicy/private/gsid.te
22882
22883(neverallow base_typeattr_779 gsid_prop (property_service (set)))
22884;;* lme
22885
22886(allow gsid userdata_block_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
22887(allow gsid metadata_file (dir (getattr search)))
22888(allow gsid gsi_metadata_file_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22889(allow gsid ota_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
22890(allow gsid gsi_metadata_file_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22891(allow gsid ota_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22892(allow gsid file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
22893(allow gsid gsi_metadata_file (file (relabelfrom)))
22894(allow gsid gsi_public_metadata_file (file (relabelto)))
22895(allow gsid gsi_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22896(allow gsid ota_image_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
22897(allow gsid gsi_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22898(allow gsid ota_image_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
22899(allowx gsid gsi_data_file (ioctl file (0x6601 0x660b)))
22900(allowx gsid ota_image_data_file (ioctl file (0x6601 0x660b)))
22901(allow gsid system_server (binder (call)))
22902;;* lmx 176 system/sepolicy/private/gsid.te
22903
22904(neverallow base_typeattr_780 gsi_metadata_file_type (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
22905;;* lme
22906
22907;;* lmx 183 system/sepolicy/private/gsid.te
22908
22909(neverallow base_typeattr_780 base_typeattr_781 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22910(neverallow base_typeattr_780 base_typeattr_781 (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22911(neverallow base_typeattr_780 base_typeattr_781 (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22912(neverallow base_typeattr_780 base_typeattr_781 (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22913(neverallow base_typeattr_780 base_typeattr_781 (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22914(neverallow base_typeattr_780 base_typeattr_781 (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22915;;* lme
22916
22917;;* lmx 190 system/sepolicy/private/gsid.te
22918
22919(neverallow base_typeattr_780 gsi_public_metadata_file (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
22920(neverallow base_typeattr_780 gsi_public_metadata_file (lnk_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
22921(neverallow base_typeattr_780 gsi_public_metadata_file (chr_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
22922(neverallow base_typeattr_780 gsi_public_metadata_file (blk_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
22923(neverallow base_typeattr_780 gsi_public_metadata_file (sock_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
22924(neverallow base_typeattr_780 gsi_public_metadata_file (fifo_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
22925;;* lme
22926
22927;;* lmx 196 system/sepolicy/private/gsid.te
22928
22929(neverallow base_typeattr_235 gsi_metadata_file_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22930(neverallow base_typeattr_235 gsi_metadata_file_type (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
22931(neverallow base_typeattr_235 gsi_metadata_file_type (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22932(neverallow base_typeattr_235 gsi_metadata_file_type (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22933(neverallow base_typeattr_235 gsi_metadata_file_type (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22934(neverallow base_typeattr_235 gsi_metadata_file_type (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22935(neverallow base_typeattr_235 gsi_metadata_file_type (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22936;;* lme
22937
22938;;* lmx 202 system/sepolicy/private/gsid.te
22939
22940(neverallow base_typeattr_782 gsi_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22941(neverallow base_typeattr_782 gsi_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
22942(neverallow base_typeattr_782 gsi_data_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22943(neverallow base_typeattr_782 gsi_data_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22944(neverallow base_typeattr_782 gsi_data_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22945(neverallow base_typeattr_782 gsi_data_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22946(neverallow base_typeattr_782 gsi_data_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22947;;* lme
22948
22949;;* lmx 207 system/sepolicy/private/gsid.te
22950
22951(neverallow base_typeattr_778 gsi_data_file (file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22952(neverallow base_typeattr_778 gsi_data_file (lnk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22953(neverallow base_typeattr_778 gsi_data_file (chr_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
22954(neverallow base_typeattr_778 gsi_data_file (blk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22955(neverallow base_typeattr_778 gsi_data_file (sock_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22956(neverallow base_typeattr_778 gsi_data_file (fifo_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
22957;;* lme
22958
22959(allow init hal_allocator_default_exec (file (read getattr map execute open)))
22960(allow init hal_allocator_default (process (transition)))
22961(allow hal_allocator_default hal_allocator_default_exec (file (read getattr map execute open entrypoint)))
22962(dontaudit init hal_allocator_default (process (noatsecure)))
22963(allow init hal_allocator_default (process (siginh rlimitinh)))
22964(typetransition init hal_allocator_default_exec process hal_allocator_default)
22965(allow hal_allocator_default property_socket (sock_file (write)))
22966(allow hal_allocator_default init (unix_stream_socket (connectto)))
22967(allow hal_allocator_default hidl_memory_prop (property_service (set)))
22968(allow hal_allocator_default hidl_memory_prop (file (read getattr map open)))
22969(allow halclientdomain hwservicemanager (binder (call transfer)))
22970(allow hwservicemanager halclientdomain (binder (call transfer)))
22971(allow hwservicemanager halclientdomain (dir (search)))
22972(allow hwservicemanager halclientdomain (file (read map open)))
22973(allow hwservicemanager halclientdomain (process (getattr)))
22974(allow halclientdomain hwservicemanager_prop (file (read getattr map open)))
22975(allow halclientdomain hidl_manager_hwservice (hwservice_manager (find)))
22976(allow halserverdomain hwservicemanager (binder (call transfer)))
22977(allow hwservicemanager halserverdomain (binder (call transfer)))
22978(allow hwservicemanager halserverdomain (dir (search)))
22979(allow hwservicemanager halserverdomain (file (read map open)))
22980(allow hwservicemanager halserverdomain (process (getattr)))
22981(allow halserverdomain system_file (dir (ioctl read getattr lock open watch watch_reads search)))
22982(allow halserverdomain hwservicemanager_prop (file (read getattr map open)))
22983(allow init heapprofd_exec (file (read getattr map execute open)))
22984(allow init heapprofd (process (transition)))
22985(allow heapprofd heapprofd_exec (file (read getattr map execute open entrypoint)))
22986(dontaudit init heapprofd (process (noatsecure)))
22987(allow init heapprofd (process (siginh rlimitinh)))
22988(typetransition init heapprofd_exec process heapprofd)
22989(typetransition heapprofd tmpfs file heapprofd_tmpfs)
22990(allow heapprofd heapprofd_tmpfs (file (read write getattr map)))
22991(allow heapprofd property_socket (sock_file (write)))
22992(allow heapprofd init (unix_stream_socket (connectto)))
22993(allow heapprofd heapprofd_prop (property_service (set)))
22994(allow heapprofd heapprofd_prop (file (read getattr map open)))
22995(allow heapprofd self (capability (kill)))
22996(dontaudit heapprofd domain (dir (open search)))
22997(allow heapprofd traced (fd (use)))
22998(allow heapprofd traced_tmpfs (file (read write getattr map)))
22999(allow heapprofd traced_producer_socket (sock_file (write)))
23000(allow heapprofd traced (unix_stream_socket (connectto)))
23001(allow traced heapprofd (fd (use)))
23002(allow heapprofd nativetest_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23003(allow heapprofd nativetest_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23004(allow heapprofd nativetest_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23005(allow heapprofd system_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
23006(allow heapprofd system_file_type (file (ioctl read getattr lock map open watch watch_reads)))
23007(allow heapprofd system_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23008(allow heapprofd apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23009(allow heapprofd apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23010(allow heapprofd apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23011(allow heapprofd dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23012(allow heapprofd dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23013(allow heapprofd dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23014(allow heapprofd vendor_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
23015(allow heapprofd vendor_file_type (file (ioctl read getattr lock map open watch watch_reads)))
23016(allow heapprofd vendor_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23017(allow heapprofd shell_test_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23018(allow heapprofd shell_test_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23019(allow heapprofd shell_test_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23020(allow heapprofd apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23021(allow heapprofd apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23022(allow heapprofd apex_art_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23023(allow heapprofd apex_module_data_file (dir (getattr search)))
23024(allow heapprofd self (capability (dac_read_search)))
23025(allow heapprofd self (cap_userns (dac_read_search)))
23026(allow heapprofd packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
23027;;* lmx 51 system/sepolicy/private/heapprofd.te
23028
23029(neverallow heapprofd hal_configstore_server (file (read)))
23030(neverallow heapprofd apexd (file (read)))
23031(neverallow heapprofd app_zygote (file (read)))
23032(neverallow heapprofd bpfloader (file (read)))
23033(neverallow heapprofd init (file (read)))
23034(neverallow heapprofd kernel (file (read)))
23035(neverallow heapprofd keystore (file (read)))
23036(neverallow heapprofd llkd (file (read)))
23037(neverallow heapprofd logd (file (read)))
23038(neverallow heapprofd logpersist (file (read)))
23039(neverallow heapprofd recovery (file (read)))
23040(neverallow heapprofd recovery_persist (file (read)))
23041(neverallow heapprofd recovery_refresh (file (read)))
23042(neverallow heapprofd ueventd (file (read)))
23043(neverallow heapprofd vendor_init (file (read)))
23044(neverallow heapprofd vold (file (read)))
23045(neverallow heapprofd webview_zygote (file (read)))
23046(neverallow heapprofd zygote (file (read)))
23047;;* lme
23048
23049;;* lmx 51 system/sepolicy/private/heapprofd.te
23050
23051(neverallow heapprofd hal_configstore_server (process (signal)))
23052(neverallow heapprofd apexd (process (signal)))
23053(neverallow heapprofd app_zygote (process (signal)))
23054(neverallow heapprofd bpfloader (process (signal)))
23055(neverallow heapprofd init (process (signal)))
23056(neverallow heapprofd kernel (process (signal)))
23057(neverallow heapprofd keystore (process (signal)))
23058(neverallow heapprofd llkd (process (signal)))
23059(neverallow heapprofd logd (process (signal)))
23060(neverallow heapprofd logpersist (process (signal)))
23061(neverallow heapprofd recovery (process (signal)))
23062(neverallow heapprofd recovery_persist (process (signal)))
23063(neverallow heapprofd recovery_refresh (process (signal)))
23064(neverallow heapprofd ueventd (process (signal)))
23065(neverallow heapprofd vendor_init (process (signal)))
23066(neverallow heapprofd vold (process (signal)))
23067(neverallow heapprofd webview_zygote (process (signal)))
23068(neverallow heapprofd zygote (process (signal)))
23069;;* lme
23070
23071;;* lmx 72 system/sepolicy/private/heapprofd.te
23072
23073(neverallow heapprofd vendor_file_type (file (write create setattr relabelfrom append unlink link rename)))
23074;;* lme
23075
23076;;* lmx 72 system/sepolicy/private/heapprofd.te
23077
23078(neverallow heapprofd base_typeattr_783 (file (execute execute_no_trans)))
23079;;* lme
23080
23081(allow init hwservicemanager_exec (file (read getattr map execute open)))
23082(allow init hwservicemanager (process (transition)))
23083(allow hwservicemanager hwservicemanager_exec (file (read getattr map execute open entrypoint)))
23084(dontaudit init hwservicemanager (process (noatsecure)))
23085(allow init hwservicemanager (process (siginh rlimitinh)))
23086(typetransition init hwservicemanager_exec process hwservicemanager)
23087(allow hwservicemanager hidl_manager_hwservice (hwservice_manager (add find)))
23088(allow hwservicemanager hidl_base_hwservice (hwservice_manager (add)))
23089;;* lmx 5 system/sepolicy/private/hwservicemanager.te
23090
23091(neverallow base_typeattr_784 hidl_manager_hwservice (hwservice_manager (add)))
23092;;* lme
23093
23094(allow hwservicemanager hidl_token_hwservice (hwservice_manager (add find)))
23095(allow hwservicemanager hidl_base_hwservice (hwservice_manager (add)))
23096;;* lmx 6 system/sepolicy/private/hwservicemanager.te
23097
23098(neverallow base_typeattr_784 hidl_token_hwservice (hwservice_manager (add)))
23099;;* lme
23100
23101(allow hwservicemanager property_socket (sock_file (write)))
23102(allow hwservicemanager init (unix_stream_socket (connectto)))
23103(allow hwservicemanager ctl_interface_start_prop (property_service (set)))
23104(allow hwservicemanager ctl_interface_start_prop (file (read getattr map open)))
23105(allow hwservicemanager property_socket (sock_file (write)))
23106(allow hwservicemanager init (unix_stream_socket (connectto)))
23107(allow hwservicemanager hwservicemanager_prop (property_service (set)))
23108(allow hwservicemanager hwservicemanager_prop (file (read getattr map open)))
23109(allow hwservicemanager system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
23110(allow hwservicemanager system_bootstrap_lib_file (file (read getattr map execute open)))
23111(allow hwservicemanager apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
23112(allow hwservicemanager apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
23113(allow hwservicemanager vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
23114(allow hwservicemanager vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
23115(allow hwservicemanager vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23116(allow init idmap_exec (file (read getattr map execute open)))
23117(allow init idmap (process (transition)))
23118(allow idmap idmap_exec (file (read getattr map execute open entrypoint)))
23119(dontaudit init idmap (process (noatsecure)))
23120(allow init idmap (process (siginh rlimitinh)))
23121(typetransition init idmap_exec process idmap)
23122(allow shell incident_exec (file (read getattr map execute open)))
23123(allow shell incident (process (transition)))
23124(allow incident incident_exec (file (read getattr map execute open entrypoint)))
23125(allow incident shell (process (sigchld)))
23126(dontaudit shell incident (process (noatsecure)))
23127(allow shell incident (process (siginh rlimitinh)))
23128(typetransition shell incident_exec process incident)
23129(allow dumpstate incident_exec (file (read getattr map execute open)))
23130(allow dumpstate incident (process (transition)))
23131(allow incident incident_exec (file (read getattr map execute open entrypoint)))
23132(allow incident dumpstate (process (sigchld)))
23133(dontaudit dumpstate incident (process (noatsecure)))
23134(allow dumpstate incident (process (siginh rlimitinh)))
23135(typetransition dumpstate incident_exec process incident)
23136(allow incident shell (fd (use)))
23137(allow incident dumpstate (fd (use)))
23138(allow incident dumpstate (unix_stream_socket (read write)))
23139(allow incident shell_data_file (file (write)))
23140(allow incident devpts (chr_file (read write)))
23141(allow incident adbd (fd (use)))
23142(allow incident adbd (unix_stream_socket (read write)))
23143(allow incident adbd (process (sigchld)))
23144(allow incident servicemanager (binder (call transfer)))
23145(allow servicemanager incident (binder (call transfer)))
23146(allow servicemanager incident (dir (search)))
23147(allow servicemanager incident (file (read open)))
23148(allow servicemanager incident (process (getattr)))
23149(allow incident incident_service (service_manager (find)))
23150(allow incident incidentd (binder (call transfer)))
23151(allow incidentd incident (binder (transfer)))
23152(allow incident incidentd (fd (use)))
23153(allow incident incidentd (fifo_file (write)))
23154;;* lmx 37 system/sepolicy/private/incident.te
23155
23156(neverallow base_typeattr_785 incident_exec (file (execute execute_no_trans)))
23157;;* lme
23158
23159(allow incidentd incident_helper_exec (file (read getattr map execute open)))
23160(allow incidentd incident_helper (process (transition)))
23161(allow incident_helper incident_helper_exec (file (read getattr map execute open entrypoint)))
23162(allow incident_helper incidentd (process (sigchld)))
23163(dontaudit incidentd incident_helper (process (noatsecure)))
23164(allow incidentd incident_helper (process (siginh rlimitinh)))
23165(typetransition incidentd incident_helper_exec process incident_helper)
23166(allow incident_helper dumpstate (fd (use)))
23167(allow incident_helper incident (fd (use)))
23168(allow incident_helper incidentd (fd (use)))
23169(allow incident_helper shell (fd (use)))
23170(allow incident_helper dumpstate (fifo_file (read write getattr)))
23171(allow incident_helper incident (fifo_file (read write getattr)))
23172(allow incident_helper incidentd (fifo_file (read write getattr)))
23173(allow incident_helper shell (fifo_file (read write getattr)))
23174(allow incident_helper incidentd (unix_stream_socket (read write)))
23175;;* lmx 14 system/sepolicy/private/incident_helper.te
23176
23177(neverallow base_typeattr_786 incident_helper_exec (file (execute execute_no_trans)))
23178;;* lme
23179
23180(allow init incidentd_exec (file (read getattr map execute open)))
23181(allow init incidentd (process (transition)))
23182(allow incidentd incidentd_exec (file (read getattr map execute open entrypoint)))
23183(dontaudit init incidentd (process (noatsecure)))
23184(allow init incidentd (process (siginh rlimitinh)))
23185(typetransition init incidentd_exec process incidentd)
23186(allow incidentd servicemanager (binder (call transfer)))
23187(allow servicemanager incidentd (binder (call transfer)))
23188(allow servicemanager incidentd (dir (search)))
23189(allow servicemanager incidentd (file (read open)))
23190(allow servicemanager incidentd (process (getattr)))
23191(allow incidentd sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
23192(allow incidentd self (capability2 (block_suspend)))
23193(allow incidentd self (cap2_userns (block_suspend)))
23194(allow incidentd system_suspend_server (binder (call transfer)))
23195(allow system_suspend_server incidentd (binder (transfer)))
23196(allow incidentd system_suspend_server (fd (use)))
23197(allow incidentd system_suspend_hwservice (hwservice_manager (find)))
23198(allow incidentd hwservicemanager (binder (call transfer)))
23199(allow hwservicemanager incidentd (binder (call transfer)))
23200(allow hwservicemanager incidentd (dir (search)))
23201(allow hwservicemanager incidentd (file (read map open)))
23202(allow hwservicemanager incidentd (process (getattr)))
23203(allow incidentd hwservicemanager_prop (file (read getattr map open)))
23204(allow incidentd hidl_manager_hwservice (hwservice_manager (find)))
23205(allow incidentd hal_system_suspend_service (service_manager (find)))
23206(allow incidentd servicemanager (binder (call transfer)))
23207(allow servicemanager incidentd (binder (call transfer)))
23208(allow servicemanager incidentd (dir (search)))
23209(allow servicemanager incidentd (file (read open)))
23210(allow servicemanager incidentd (process (getattr)))
23211(allow incidentd domain (dir (ioctl read getattr lock open watch watch_reads search)))
23212(allow incidentd domain (file (ioctl read getattr lock map open watch watch_reads)))
23213(allow incidentd domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23214(allow incidentd incident_helper (process (sigkill)))
23215(allow incidentd system_file (file (execute_no_trans)))
23216(allow incidentd toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
23217(allow incidentd proc_version (file (ioctl read getattr lock map open watch watch_reads)))
23218(allow incidentd statsdw_socket (sock_file (write)))
23219(allow incidentd statsd (unix_dgram_socket (sendto)))
23220(allow incidentd proc_pagetypeinfo (file (ioctl read getattr lock map open watch watch_reads)))
23221(allow incidentd proc_meminfo (file (read open)))
23222(allow incidentd sysfs_devices_system_cpu (file (ioctl read getattr lock map open watch watch_reads)))
23223(allow incidentd domain (process (getattr)))
23224(allow incidentd sysfs_batteryinfo (dir (search)))
23225(allow incidentd sysfs_batteryinfo (file (ioctl read getattr lock map open watch watch_reads)))
23226(allow incidentd stats_service (service_manager (find)))
23227(allow incidentd statsd (binder (call transfer)))
23228(allow statsd incidentd (binder (transfer)))
23229(allow incidentd statsd (fd (use)))
23230(allow incidentd perfetto_traces_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23231(allow incidentd perfetto_traces_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23232(allow incidentd nfc_service (service_manager (find)))
23233(allow incidentd incident_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
23234(allow incidentd incident_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
23235(allow incidentd servicemanager (binder (call transfer)))
23236(allow servicemanager incidentd (binder (call transfer)))
23237(allow servicemanager incidentd (dir (search)))
23238(allow servicemanager incidentd (file (read open)))
23239(allow servicemanager incidentd (process (getattr)))
23240(allow incidentd hwservicemanager (binder (call transfer)))
23241(allow hwservicemanager incidentd (binder (call transfer)))
23242(allow hwservicemanager incidentd (dir (search)))
23243(allow hwservicemanager incidentd (file (read map open)))
23244(allow hwservicemanager incidentd (process (getattr)))
23245(allow incidentd hwservicemanager (hwservice_manager (list)))
23246(allow incidentd hwservicemanager_prop (file (read getattr map open)))
23247(allow incidentd hidl_manager_hwservice (hwservice_manager (find)))
23248(allow incidentd proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
23249(allow incidentd proc_pid_max (file (ioctl read getattr lock map open watch watch_reads)))
23250(allow incidentd proc_pipe_conf (file (ioctl read getattr lock map open watch watch_reads)))
23251(allow incidentd proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
23252(allow incidentd appdomain (process (signal)))
23253(allow incidentd ephemeral_app (process (signal)))
23254(allow incidentd system_server (process (signal)))
23255(allow incidentd hal_audio_server (process (signal)))
23256(allow incidentd hal_bluetooth_server (process (signal)))
23257(allow incidentd hal_camera_server (process (signal)))
23258(allow incidentd hal_codec2_server (process (signal)))
23259(allow incidentd hal_face_server (process (signal)))
23260(allow incidentd hal_graphics_allocator_server (process (signal)))
23261(allow incidentd hal_graphics_composer_server (process (signal)))
23262(allow incidentd hal_health_server (process (signal)))
23263(allow incidentd hal_omx_server (process (signal)))
23264(allow incidentd hal_sensors_server (process (signal)))
23265(allow incidentd hal_vr_server (process (signal)))
23266(allow incidentd audioserver (process (signal)))
23267(allow incidentd cameraserver (process (signal)))
23268(allow incidentd drmserver (process (signal)))
23269(allow incidentd inputflinger (process (signal)))
23270(allow incidentd mediadrmserver (process (signal)))
23271(allow incidentd mediaextractor (process (signal)))
23272(allow incidentd mediametrics (process (signal)))
23273(allow incidentd mediaserver (process (signal)))
23274(allow incidentd sdcardd (process (signal)))
23275(allow incidentd statsd (process (signal)))
23276(allow incidentd surfaceflinger (process (signal)))
23277(allow incidentd system_server (binder (call transfer)))
23278(allow system_server incidentd (binder (transfer)))
23279(allow incidentd system_server (fd (use)))
23280(allow incidentd appdomain (binder (call transfer)))
23281(allow appdomain incidentd (binder (transfer)))
23282(allow incidentd appdomain (fd (use)))
23283;;* lmx 122 system/sepolicy/private/incidentd.te
23284
23285(neverallow incidentd base_typeattr_224 (process (ptrace)))
23286;;* lme
23287
23288(allow incidentd self (capability (kill)))
23289(allow incidentd self (cap_userns (kill)))
23290(allow incidentd tombstoned_intercept_socket (sock_file (write)))
23291(allow incidentd tombstoned (unix_stream_socket (connectto)))
23292(allow incidentd shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
23293(allow incidentd zygote_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
23294(allow incidentd device_config_runtime_native_prop (file (read getattr map open)))
23295(allow incidentd device_config_runtime_native_boot_prop (file (read getattr map open)))
23296(allow incidentd odsign_prop (file (read getattr map open)))
23297(allow incidentd system_file (file (lock)))
23298(dontaudit incidentd dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23299(dontaudit incidentd apex_module_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23300(dontaudit incidentd apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
23301(dontaudit incidentd tmpfs (file (ioctl read write getattr lock append map execute open watch watch_reads execute_no_trans)))
23302(allow incidentd apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
23303(allow incidentd misc_logd_file (dir (ioctl read getattr lock open watch watch_reads search)))
23304(allow incidentd misc_logd_file (file (ioctl read getattr lock map open watch watch_reads)))
23305(allow incidentd misc_logd_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
23306(allow incidentd base_typeattr_787 (service_manager (find)))
23307(allow incidentd incident_service (service_manager (add find)))
23308;;* lmx 171 system/sepolicy/private/incidentd.te
23309
23310(neverallow base_typeattr_788 incident_service (service_manager (add)))
23311;;* lme
23312
23313(allow incidentd dumpstate (fd (use)))
23314(allow incidentd incident (fd (use)))
23315(allow incidentd dumpstate (fifo_file (write)))
23316(allow incidentd incident (fifo_file (write)))
23317(allow incidentd incident (binder (call transfer)))
23318(allow incident incidentd (binder (transfer)))
23319(allow incidentd incident (fd (use)))
23320(allow incidentd build_attestation_prop (file (read getattr map open)))
23321;;* lmx 212 system/sepolicy/private/incidentd.te
23322
23323(neverallow base_typeattr_789 incident_data_file (file (write create getattr setattr lock append map unlink rename execute open execute_no_trans)))
23324;;* lme
23325
23326;;* lmx 214 system/sepolicy/private/incidentd.te
23327
23328(neverallow base_typeattr_790 incident_data_file (file (ioctl read getattr lock map open watch watch_reads)))
23329;;* lme
23330
23331;;* lmx 216 system/sepolicy/private/incidentd.te
23332
23333(neverallow base_typeattr_789 incident_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
23334;;* lme
23335
23336(typetransition init tmpfs file init_tmpfs)
23337(allow init init_tmpfs (file (read write getattr map)))
23338(allow init rootfs (file (read getattr map execute open)))
23339(allow init slideshow (process (transition)))
23340(allow slideshow rootfs (file (read getattr map execute open entrypoint)))
23341(dontaudit init slideshow (process (noatsecure)))
23342(allow init slideshow (process (siginh rlimitinh)))
23343(allow init charger_exec (file (read getattr map execute open)))
23344(allow init charger (process (transition)))
23345(allow charger charger_exec (file (read getattr map execute open entrypoint)))
23346(dontaudit init charger (process (noatsecure)))
23347(allow init charger (process (siginh rlimitinh)))
23348(typetransition init charger_exec process charger)
23349(allow init e2fs_exec (file (read getattr map execute open)))
23350(allow init e2fs (process (transition)))
23351(allow e2fs e2fs_exec (file (read getattr map execute open entrypoint)))
23352(dontaudit init e2fs (process (noatsecure)))
23353(allow init e2fs (process (siginh rlimitinh)))
23354(typetransition init e2fs_exec process e2fs)
23355(allow init bpfloader_exec (file (read getattr map execute open)))
23356(allow init bpfloader (process (transition)))
23357(allow bpfloader bpfloader_exec (file (read getattr map execute open entrypoint)))
23358(dontaudit init bpfloader (process (noatsecure)))
23359(allow init bpfloader (process (siginh rlimitinh)))
23360(typetransition init bpfloader_exec process bpfloader)
23361(allow init shell_exec (file (read getattr map execute open)))
23362(allow init shell (process (transition)))
23363(allow shell shell_exec (file (read getattr map execute open entrypoint)))
23364(dontaudit init shell (process (noatsecure)))
23365(allow init shell (process (siginh rlimitinh)))
23366(allow init init_exec (file (read getattr map execute open)))
23367(allow init ueventd (process (transition)))
23368(allow ueventd init_exec (file (read getattr map execute open entrypoint)))
23369(dontaudit init ueventd (process (noatsecure)))
23370(allow init ueventd (process (siginh rlimitinh)))
23371(allow init init_exec (file (read getattr map execute open)))
23372(allow init vendor_init (process (transition)))
23373(allow vendor_init init_exec (file (read getattr map execute open entrypoint)))
23374(dontaudit init vendor_init (process (noatsecure)))
23375(allow init vendor_init (process (siginh rlimitinh)))
23376(allow init rootfs (file (read getattr map execute open)))
23377(allow init toolbox_exec (file (read getattr map execute open)))
23378(allow init modprobe (process (transition)))
23379(allow modprobe rootfs (file (read getattr map execute open entrypoint)))
23380(allow modprobe toolbox_exec (file (read getattr map execute open entrypoint)))
23381(dontaudit init modprobe (process (noatsecure)))
23382(allow init modprobe (process (siginh rlimitinh)))
23383(allow init sysfs_dm (file (read)))
23384(allow init sysfs_loop (dir (ioctl read getattr lock open watch watch_reads search)))
23385(allow init sysfs_loop (file (ioctl read write getattr lock append map open watch watch_reads)))
23386(allow init sysfs_type (file (read getattr)))
23387(allow init dev_type (dir (ioctl read getattr lock open watch watch_reads search)))
23388(allow init dev_type (blk_file (getattr)))
23389(allow init proc_drop_caches (file (ioctl read write getattr lock append map open watch watch_reads)))
23390(allow init property_socket (sock_file (write)))
23391(allow init init (unix_stream_socket (connectto)))
23392(allow init powerctl_prop (property_service (set)))
23393(allow init powerctl_prop (file (read getattr map open)))
23394(allow init property_socket (sock_file (write)))
23395(allow init init (unix_stream_socket (connectto)))
23396(allow init userspace_reboot_exported_prop (property_service (set)))
23397(allow init userspace_reboot_exported_prop (file (read getattr map open)))
23398;;* lmx 62 system/sepolicy/private/init.te
23399
23400(neverallow base_typeattr_223 userspace_reboot_exported_prop (property_service (set)))
23401;;* lme
23402
23403(allow init self (perf_event (open cpu)))
23404(allow init self (capability2 (perfmon)))
23405(allow init self (cap2_userns (perfmon)))
23406;;* lmx 72 system/sepolicy/private/init.te
23407
23408(neverallow init self (perf_event (kernel tracepoint read write)))
23409;;* lme
23410
23411(dontaudit init self (perf_event (kernel tracepoint read write)))
23412(allow init snapuserd_socket (sock_file (write)))
23413(allow init snapuserd (unix_stream_socket (connectto)))
23414(allow init ota_metadata_file (dir (lock)))
23415(allow init vd_device (blk_file (relabelto)))
23416(allow init property_socket (sock_file (write)))
23417(allow init init (unix_stream_socket (connectto)))
23418(allow init init_perf_lsm_hooks_prop (property_service (set)))
23419(allow init init_perf_lsm_hooks_prop (file (read getattr map open)))
23420;;* lmx 89 system/sepolicy/private/init.te
23421
23422(neverallow base_typeattr_223 init_perf_lsm_hooks_prop (property_service (set)))
23423;;* lme
23424
23425(allow init property_socket (sock_file (write)))
23426(allow init init (unix_stream_socket (connectto)))
23427(allow init vts_status_prop (property_service (set)))
23428(allow init vts_status_prop (file (read getattr map open)))
23429;;* lmx 93 system/sepolicy/private/init.te
23430
23431(neverallow base_typeattr_223 vts_status_prop (property_service (set)))
23432;;* lme
23433
23434;;* lmx 96 system/sepolicy/private/init.te
23435
23436(neverallow base_typeattr_223 bootloader_prop (property_service (set)))
23437;;* lme
23438
23439;;* lmx 99 system/sepolicy/private/init.te
23440
23441(neverallow base_typeattr_223 hal_instrumentation_prop (property_service (set)))
23442;;* lme
23443
23444;;* lmx 102 system/sepolicy/private/init.te
23445
23446(neverallow base_typeattr_223 property_service_version_prop (property_service (set)))
23447;;* lme
23448
23449;;* lmx 105 system/sepolicy/private/init.te
23450
23451(neverallow base_typeattr_223 keystore_listen_prop (property_service (set)))
23452;;* lme
23453
23454(allow init debugfs_bootreceiver_tracing (file (write lock append map open)))
23455(allow init prng_seeder (unix_stream_socket (create bind listen)))
23456(dontaudit init debugfs_tracing_debug (dir (write add_name)))
23457(allow init base_typeattr_791 (chr_file (setattr)))
23458(allow init inputflinger_exec (file (read getattr map execute open)))
23459(allow init inputflinger (process (transition)))
23460(allow inputflinger inputflinger_exec (file (read getattr map execute open entrypoint)))
23461(dontaudit init inputflinger (process (noatsecure)))
23462(allow init inputflinger (process (siginh rlimitinh)))
23463(typetransition init inputflinger_exec process inputflinger)
23464(allow init installd_exec (file (read getattr map execute open)))
23465(allow init installd (process (transition)))
23466(allow installd installd_exec (file (read getattr map execute open entrypoint)))
23467(dontaudit init installd (process (noatsecure)))
23468(allow init installd (process (siginh rlimitinh)))
23469(typetransition init installd_exec process installd)
23470(allow installd migrate_legacy_obb_data_exec (file (read getattr map execute open)))
23471(allow installd migrate_legacy_obb_data (process (transition)))
23472(allow migrate_legacy_obb_data migrate_legacy_obb_data_exec (file (read getattr map execute open entrypoint)))
23473(allow migrate_legacy_obb_data installd (process (sigchld)))
23474(dontaudit installd migrate_legacy_obb_data (process (noatsecure)))
23475(allow installd migrate_legacy_obb_data (process (siginh rlimitinh)))
23476(typetransition installd migrate_legacy_obb_data_exec process migrate_legacy_obb_data)
23477(allow installd shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
23478(allow installd dex2oat_exec (file (read getattr map execute open)))
23479(allow installd dex2oat (process (transition)))
23480(allow dex2oat dex2oat_exec (file (read getattr map execute open entrypoint)))
23481(allow dex2oat installd (process (sigchld)))
23482(dontaudit installd dex2oat (process (noatsecure)))
23483(allow installd dex2oat (process (siginh rlimitinh)))
23484(typetransition installd dex2oat_exec process dex2oat)
23485(allow installd dexoptanalyzer_exec (file (read getattr map execute open)))
23486(allow installd dexoptanalyzer (process (transition)))
23487(allow dexoptanalyzer dexoptanalyzer_exec (file (read getattr map execute open entrypoint)))
23488(allow dexoptanalyzer installd (process (sigchld)))
23489(dontaudit installd dexoptanalyzer (process (noatsecure)))
23490(allow installd dexoptanalyzer (process (siginh rlimitinh)))
23491(typetransition installd dexoptanalyzer_exec process dexoptanalyzer)
23492(allow installd viewcompiler_exec (file (read getattr map execute open)))
23493(allow installd viewcompiler (process (transition)))
23494(allow viewcompiler viewcompiler_exec (file (read getattr map execute open entrypoint)))
23495(allow viewcompiler installd (process (sigchld)))
23496(dontaudit installd viewcompiler (process (noatsecure)))
23497(allow installd viewcompiler (process (siginh rlimitinh)))
23498(typetransition installd viewcompiler_exec process viewcompiler)
23499(allow installd profman_exec (file (read getattr map execute open)))
23500(allow installd profman (process (transition)))
23501(allow profman profman_exec (file (read getattr map execute open entrypoint)))
23502(allow profman installd (process (sigchld)))
23503(dontaudit installd profman (process (noatsecure)))
23504(allow installd profman (process (siginh rlimitinh)))
23505(typetransition installd profman_exec process profman)
23506(allow installd idmap_exec (file (read getattr map execute open)))
23507(allow installd idmap (process (transition)))
23508(allow idmap idmap_exec (file (read getattr map execute open entrypoint)))
23509(allow idmap installd (process (sigchld)))
23510(dontaudit installd idmap (process (noatsecure)))
23511(allow installd idmap (process (siginh rlimitinh)))
23512(typetransition installd idmap_exec process idmap)
23513(allow installd dumpstate (fd (use)))
23514(allow installd dumpstate (fifo_file (ioctl read getattr lock map open watch watch_reads)))
23515(allow installd app_exec_data_file (file (unlink)))
23516(allow installd rollback_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
23517(allow installd rollback_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
23518(allow installd device_config_runtime_native_prop (file (read getattr map open)))
23519(allow installd device_config_runtime_native_boot_prop (file (read getattr map open)))
23520(allow installd apk_verity_prop (file (read getattr map open)))
23521(allow installd odsign_prop (file (read getattr map open)))
23522(allow installd staging_data_file (file (unlink)))
23523(allow installd staging_data_file (dir (read write getattr open remove_name search rmdir)))
23524(allow installd dex2oat (process (signal)))
23525(allow installd dexoptanalyzer (process (signal)))
23526(allow installd profman (process (sigkill)))
23527(allow installd dex2oat (process (sigkill)))
23528(allow installd dexoptanalyzer (process (sigkill)))
23529(allow installd sdk_sandbox_system_data_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
23530(allow installd untrusted_app_all (fd (use)))
23531(allow installd gmscore_app (fd (use)))
23532(allow installd priv_app (fd (use)))
23533(allowx installd app_data_file_type (ioctl file (0x6685)))
23534(typetransition isolated_app tmpfs file appdomain_tmpfs)
23535(allow isolated_app isolated_app_userfaultfd (anon_inode (ioctl read create)))
23536(dontaudit su isolated_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23537;;* lmx 10 system/sepolicy/private/isolated_app.te
23538
23539(neverallow base_typeattr_643 isolated_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23540;;* lme
23541
23542(allow isolated_app appdomain_tmpfs (file (read write getattr map execute)))
23543;;* lmx 10 system/sepolicy/private/isolated_app.te
23544
23545(neverallow base_typeattr_792 base_typeattr_643 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
23546;;* lme
23547
23548;;* lmx 10 system/sepolicy/private/isolated_app.te
23549
23550(neverallow base_typeattr_793 isolated_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
23551;;* lme
23552
23553;;* lmx 10 system/sepolicy/private/isolated_app.te
23554
23555(neverallow base_typeattr_794 isolated_app (process (ptrace)))
23556;;* lme
23557
23558(allow isolated_app webviewupdate_service (service_manager (find)))
23559(allow isolated_app untrusted_app_all (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23560(allow isolated_app untrusted_app_all (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23561(allow isolated_app ephemeral_app (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23562(allow isolated_app ephemeral_app (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23563(allow isolated_app priv_app (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23564(allow isolated_app priv_app (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
23565(allow isolated_app sdcard_type (file (read write getattr lock append map)))
23566(allow isolated_app fuse (file (read write getattr lock append map)))
23567(allow isolated_app media_rw_data_file (file (read write getattr lock append map)))
23568(allow isolated_app webview_zygote (fd (use)))
23569(allow isolated_app webview_zygote (process (sigchld)))
23570(allow isolated_app webview_zygote (unix_dgram_socket (write)))
23571(allow isolated_app webview_zygote_tmpfs (file (read)))
23572(allow isolated_app_all app_data_file (file (read write getattr lock append map)))
23573(allow isolated_app_all privapp_data_file (file (read write getattr lock append map)))
23574(allow isolated_app_all sdk_sandbox_data_file (file (read write getattr lock append map)))
23575(allow isolated_app_all activity_service (service_manager (find)))
23576(allow isolated_app_all display_service (service_manager (find)))
23577(allow isolated_app_all self (process (ptrace)))
23578(allow isolated_app_all app_zygote (fd (use)))
23579(allow isolated_app_all app_zygote (process (sigchld)))
23580(allow isolated_app_all app_zygote (unix_dgram_socket (write)))
23581(dontaudit isolated_app_all shell_data_file (dir (search)))
23582(allow isolated_app_all apk_tmp_file (file (read getattr)))
23583(allow isolated_app_all apk_private_tmp_file (file (read getattr)))
23584;;* lmx 44 system/sepolicy/private/isolated_app_all.te
23585
23586(neverallow isolated_app_all app_data_file_type (file (open)))
23587;;* lme
23588
23589;;* lmx 49 system/sepolicy/private/isolated_app_all.te
23590
23591(neverallow isolated_app_all anr_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto map unlink link rename execute quotaon mounton audit_access execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23592;;* lme
23593
23594;;* lmx 50 system/sepolicy/private/isolated_app_all.te
23595
23596(neverallow isolated_app_all anr_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
23597;;* lme
23598
23599;;* lmx 53 system/sepolicy/private/isolated_app_all.te
23600
23601(neverallow base_typeattr_795 hwbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23602;;* lme
23603
23604;;* lmx 54 system/sepolicy/private/isolated_app_all.te
23605
23606(neverallow base_typeattr_795 base_typeattr_224 (hwservice_manager (add find list)))
23607;;* lme
23608
23609;;* lmx 57 system/sepolicy/private/isolated_app_all.te
23610
23611(neverallow isolated_app_all vndbinder_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23612;;* lme
23613
23614;;* lmx 61 system/sepolicy/private/isolated_app_all.te
23615
23616(neverallow base_typeattr_795 base_typeattr_224 (service_manager (add list)))
23617;;* lme
23618
23619;;* lmx 71 system/sepolicy/private/isolated_app_all.te
23620
23621(neverallow base_typeattr_795 base_typeattr_796 (service_manager (find)))
23622;;* lme
23623
23624;;* lmx 74 system/sepolicy/private/isolated_app_all.te
23625
23626(neverallow isolated_app_all gpu_device (chr_file (ioctl read write getattr lock append map execute open watch watch_reads)))
23627;;* lme
23628
23629;;* lmx 77 system/sepolicy/private/isolated_app_all.te
23630
23631(neverallow isolated_app_all cache_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
23632;;* lme
23633
23634;;* lmx 78 system/sepolicy/private/isolated_app_all.te
23635
23636(neverallow isolated_app_all cache_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23637;;* lme
23638
23639;;* lmx 82 system/sepolicy/private/isolated_app_all.te
23640
23641(neverallow isolated_app_all sdcard_type (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
23642(neverallow isolated_app_all fuse (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
23643(neverallow isolated_app_all mnt_user_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
23644(neverallow isolated_app_all storage_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
23645;;* lme
23646
23647;;* lmx 83 system/sepolicy/private/isolated_app_all.te
23648
23649(neverallow isolated_app_all mnt_user_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23650(neverallow isolated_app_all mnt_user_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23651(neverallow isolated_app_all mnt_user_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23652(neverallow isolated_app_all mnt_user_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23653(neverallow isolated_app_all mnt_user_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23654(neverallow isolated_app_all mnt_user_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23655(neverallow isolated_app_all storage_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23656(neverallow isolated_app_all storage_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23657(neverallow isolated_app_all storage_file (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23658(neverallow isolated_app_all storage_file (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23659(neverallow isolated_app_all storage_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23660(neverallow isolated_app_all storage_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23661;;* lme
23662
23663;;* lmx 84 system/sepolicy/private/isolated_app_all.te
23664
23665(neverallow isolated_app_all sdcard_type (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23666(neverallow isolated_app_all sdcard_type (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23667(neverallow isolated_app_all sdcard_type (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23668(neverallow isolated_app_all sdcard_type (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23669(neverallow isolated_app_all sdcard_type (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23670(neverallow isolated_app_all fuse (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23671(neverallow isolated_app_all fuse (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23672(neverallow isolated_app_all fuse (blk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23673(neverallow isolated_app_all fuse (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23674(neverallow isolated_app_all fuse (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23675;;* lme
23676
23677;;* lmx 85 system/sepolicy/private/isolated_app_all.te
23678
23679(neverallow isolated_app_all sdcard_type (file (ioctl create setattr relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23680(neverallow isolated_app_all fuse (file (ioctl create setattr relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23681;;* lme
23682
23683;;* lmx 88 system/sepolicy/private/isolated_app_all.te
23684
23685(neverallow isolated_app_all usbaccessory_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23686(neverallow isolated_app_all usb_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
23687;;* lme
23688
23689;;* lmx 91 system/sepolicy/private/isolated_app_all.te
23690
23691(neverallow isolated_app_all webview_zygote (sock_file (write)))
23692;;* lme
23693
23694;;* lmx 104 system/sepolicy/private/isolated_app_all.te
23695
23696(neverallow base_typeattr_795 base_typeattr_797 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
23697;;* lme
23698
23699;;* lmx 125 system/sepolicy/private/isolated_app_all.te
23700
23701(neverallow isolated_app_all untrusted_app_all (socket (create)))
23702(neverallow isolated_app_all untrusted_app_all (tcp_socket (create)))
23703(neverallow isolated_app_all untrusted_app_all (udp_socket (create)))
23704(neverallow isolated_app_all untrusted_app_all (rawip_socket (create)))
23705(neverallow isolated_app_all untrusted_app_all (netlink_socket (create)))
23706(neverallow isolated_app_all untrusted_app_all (packet_socket (create)))
23707(neverallow isolated_app_all untrusted_app_all (key_socket (create)))
23708(neverallow isolated_app_all untrusted_app_all (netlink_route_socket (create)))
23709(neverallow isolated_app_all untrusted_app_all (netlink_tcpdiag_socket (create)))
23710(neverallow isolated_app_all untrusted_app_all (netlink_nflog_socket (create)))
23711(neverallow isolated_app_all untrusted_app_all (netlink_xfrm_socket (create)))
23712(neverallow isolated_app_all untrusted_app_all (netlink_selinux_socket (create)))
23713(neverallow isolated_app_all untrusted_app_all (netlink_audit_socket (create)))
23714(neverallow isolated_app_all untrusted_app_all (netlink_dnrt_socket (create)))
23715(neverallow isolated_app_all untrusted_app_all (netlink_kobject_uevent_socket (create)))
23716(neverallow isolated_app_all untrusted_app_all (appletalk_socket (create)))
23717(neverallow isolated_app_all untrusted_app_all (tun_socket (create)))
23718(neverallow isolated_app_all untrusted_app_all (netlink_iscsi_socket (create)))
23719(neverallow isolated_app_all untrusted_app_all (netlink_fib_lookup_socket (create)))
23720(neverallow isolated_app_all untrusted_app_all (netlink_connector_socket (create)))
23721(neverallow isolated_app_all untrusted_app_all (netlink_netfilter_socket (create)))
23722(neverallow isolated_app_all untrusted_app_all (netlink_generic_socket (create)))
23723(neverallow isolated_app_all untrusted_app_all (netlink_scsitransport_socket (create)))
23724(neverallow isolated_app_all untrusted_app_all (netlink_rdma_socket (create)))
23725(neverallow isolated_app_all untrusted_app_all (netlink_crypto_socket (create)))
23726(neverallow isolated_app_all untrusted_app_all (sctp_socket (create)))
23727(neverallow isolated_app_all untrusted_app_all (icmp_socket (create)))
23728(neverallow isolated_app_all untrusted_app_all (ax25_socket (create)))
23729(neverallow isolated_app_all untrusted_app_all (ipx_socket (create)))
23730(neverallow isolated_app_all untrusted_app_all (netrom_socket (create)))
23731(neverallow isolated_app_all untrusted_app_all (atmpvc_socket (create)))
23732(neverallow isolated_app_all untrusted_app_all (x25_socket (create)))
23733(neverallow isolated_app_all untrusted_app_all (rose_socket (create)))
23734(neverallow isolated_app_all untrusted_app_all (decnet_socket (create)))
23735(neverallow isolated_app_all untrusted_app_all (atmsvc_socket (create)))
23736(neverallow isolated_app_all untrusted_app_all (rds_socket (create)))
23737(neverallow isolated_app_all untrusted_app_all (irda_socket (create)))
23738(neverallow isolated_app_all untrusted_app_all (pppox_socket (create)))
23739(neverallow isolated_app_all untrusted_app_all (llc_socket (create)))
23740(neverallow isolated_app_all untrusted_app_all (can_socket (create)))
23741(neverallow isolated_app_all untrusted_app_all (tipc_socket (create)))
23742(neverallow isolated_app_all untrusted_app_all (bluetooth_socket (create)))
23743(neverallow isolated_app_all untrusted_app_all (iucv_socket (create)))
23744(neverallow isolated_app_all untrusted_app_all (rxrpc_socket (create)))
23745(neverallow isolated_app_all untrusted_app_all (isdn_socket (create)))
23746(neverallow isolated_app_all untrusted_app_all (phonet_socket (create)))
23747(neverallow isolated_app_all untrusted_app_all (ieee802154_socket (create)))
23748(neverallow isolated_app_all untrusted_app_all (caif_socket (create)))
23749(neverallow isolated_app_all untrusted_app_all (alg_socket (create)))
23750(neverallow isolated_app_all untrusted_app_all (nfc_socket (create)))
23751(neverallow isolated_app_all untrusted_app_all (vsock_socket (create)))
23752(neverallow isolated_app_all untrusted_app_all (kcm_socket (create)))
23753(neverallow isolated_app_all untrusted_app_all (qipcrtr_socket (create)))
23754(neverallow isolated_app_all untrusted_app_all (smc_socket (create)))
23755(neverallow isolated_app_all untrusted_app_all (xdp_socket (create)))
23756(neverallow isolated_app_all ephemeral_app (socket (create)))
23757(neverallow isolated_app_all ephemeral_app (tcp_socket (create)))
23758(neverallow isolated_app_all ephemeral_app (udp_socket (create)))
23759(neverallow isolated_app_all ephemeral_app (rawip_socket (create)))
23760(neverallow isolated_app_all ephemeral_app (netlink_socket (create)))
23761(neverallow isolated_app_all ephemeral_app (packet_socket (create)))
23762(neverallow isolated_app_all ephemeral_app (key_socket (create)))
23763(neverallow isolated_app_all ephemeral_app (netlink_route_socket (create)))
23764(neverallow isolated_app_all ephemeral_app (netlink_tcpdiag_socket (create)))
23765(neverallow isolated_app_all ephemeral_app (netlink_nflog_socket (create)))
23766(neverallow isolated_app_all ephemeral_app (netlink_xfrm_socket (create)))
23767(neverallow isolated_app_all ephemeral_app (netlink_selinux_socket (create)))
23768(neverallow isolated_app_all ephemeral_app (netlink_audit_socket (create)))
23769(neverallow isolated_app_all ephemeral_app (netlink_dnrt_socket (create)))
23770(neverallow isolated_app_all ephemeral_app (netlink_kobject_uevent_socket (create)))
23771(neverallow isolated_app_all ephemeral_app (appletalk_socket (create)))
23772(neverallow isolated_app_all ephemeral_app (tun_socket (create)))
23773(neverallow isolated_app_all ephemeral_app (netlink_iscsi_socket (create)))
23774(neverallow isolated_app_all ephemeral_app (netlink_fib_lookup_socket (create)))
23775(neverallow isolated_app_all ephemeral_app (netlink_connector_socket (create)))
23776(neverallow isolated_app_all ephemeral_app (netlink_netfilter_socket (create)))
23777(neverallow isolated_app_all ephemeral_app (netlink_generic_socket (create)))
23778(neverallow isolated_app_all ephemeral_app (netlink_scsitransport_socket (create)))
23779(neverallow isolated_app_all ephemeral_app (netlink_rdma_socket (create)))
23780(neverallow isolated_app_all ephemeral_app (netlink_crypto_socket (create)))
23781(neverallow isolated_app_all ephemeral_app (sctp_socket (create)))
23782(neverallow isolated_app_all ephemeral_app (icmp_socket (create)))
23783(neverallow isolated_app_all ephemeral_app (ax25_socket (create)))
23784(neverallow isolated_app_all ephemeral_app (ipx_socket (create)))
23785(neverallow isolated_app_all ephemeral_app (netrom_socket (create)))
23786(neverallow isolated_app_all ephemeral_app (atmpvc_socket (create)))
23787(neverallow isolated_app_all ephemeral_app (x25_socket (create)))
23788(neverallow isolated_app_all ephemeral_app (rose_socket (create)))
23789(neverallow isolated_app_all ephemeral_app (decnet_socket (create)))
23790(neverallow isolated_app_all ephemeral_app (atmsvc_socket (create)))
23791(neverallow isolated_app_all ephemeral_app (rds_socket (create)))
23792(neverallow isolated_app_all ephemeral_app (irda_socket (create)))
23793(neverallow isolated_app_all ephemeral_app (pppox_socket (create)))
23794(neverallow isolated_app_all ephemeral_app (llc_socket (create)))
23795(neverallow isolated_app_all ephemeral_app (can_socket (create)))
23796(neverallow isolated_app_all ephemeral_app (tipc_socket (create)))
23797(neverallow isolated_app_all ephemeral_app (bluetooth_socket (create)))
23798(neverallow isolated_app_all ephemeral_app (iucv_socket (create)))
23799(neverallow isolated_app_all ephemeral_app (rxrpc_socket (create)))
23800(neverallow isolated_app_all ephemeral_app (isdn_socket (create)))
23801(neverallow isolated_app_all ephemeral_app (phonet_socket (create)))
23802(neverallow isolated_app_all ephemeral_app (ieee802154_socket (create)))
23803(neverallow isolated_app_all ephemeral_app (caif_socket (create)))
23804(neverallow isolated_app_all ephemeral_app (alg_socket (create)))
23805(neverallow isolated_app_all ephemeral_app (nfc_socket (create)))
23806(neverallow isolated_app_all ephemeral_app (vsock_socket (create)))
23807(neverallow isolated_app_all ephemeral_app (kcm_socket (create)))
23808(neverallow isolated_app_all ephemeral_app (qipcrtr_socket (create)))
23809(neverallow isolated_app_all ephemeral_app (smc_socket (create)))
23810(neverallow isolated_app_all ephemeral_app (xdp_socket (create)))
23811(neverallow isolated_app_all priv_app (socket (create)))
23812(neverallow isolated_app_all priv_app (tcp_socket (create)))
23813(neverallow isolated_app_all priv_app (udp_socket (create)))
23814(neverallow isolated_app_all priv_app (rawip_socket (create)))
23815(neverallow isolated_app_all priv_app (netlink_socket (create)))
23816(neverallow isolated_app_all priv_app (packet_socket (create)))
23817(neverallow isolated_app_all priv_app (key_socket (create)))
23818(neverallow isolated_app_all priv_app (netlink_route_socket (create)))
23819(neverallow isolated_app_all priv_app (netlink_tcpdiag_socket (create)))
23820(neverallow isolated_app_all priv_app (netlink_nflog_socket (create)))
23821(neverallow isolated_app_all priv_app (netlink_xfrm_socket (create)))
23822(neverallow isolated_app_all priv_app (netlink_selinux_socket (create)))
23823(neverallow isolated_app_all priv_app (netlink_audit_socket (create)))
23824(neverallow isolated_app_all priv_app (netlink_dnrt_socket (create)))
23825(neverallow isolated_app_all priv_app (netlink_kobject_uevent_socket (create)))
23826(neverallow isolated_app_all priv_app (appletalk_socket (create)))
23827(neverallow isolated_app_all priv_app (tun_socket (create)))
23828(neverallow isolated_app_all priv_app (netlink_iscsi_socket (create)))
23829(neverallow isolated_app_all priv_app (netlink_fib_lookup_socket (create)))
23830(neverallow isolated_app_all priv_app (netlink_connector_socket (create)))
23831(neverallow isolated_app_all priv_app (netlink_netfilter_socket (create)))
23832(neverallow isolated_app_all priv_app (netlink_generic_socket (create)))
23833(neverallow isolated_app_all priv_app (netlink_scsitransport_socket (create)))
23834(neverallow isolated_app_all priv_app (netlink_rdma_socket (create)))
23835(neverallow isolated_app_all priv_app (netlink_crypto_socket (create)))
23836(neverallow isolated_app_all priv_app (sctp_socket (create)))
23837(neverallow isolated_app_all priv_app (icmp_socket (create)))
23838(neverallow isolated_app_all priv_app (ax25_socket (create)))
23839(neverallow isolated_app_all priv_app (ipx_socket (create)))
23840(neverallow isolated_app_all priv_app (netrom_socket (create)))
23841(neverallow isolated_app_all priv_app (atmpvc_socket (create)))
23842(neverallow isolated_app_all priv_app (x25_socket (create)))
23843(neverallow isolated_app_all priv_app (rose_socket (create)))
23844(neverallow isolated_app_all priv_app (decnet_socket (create)))
23845(neverallow isolated_app_all priv_app (atmsvc_socket (create)))
23846(neverallow isolated_app_all priv_app (rds_socket (create)))
23847(neverallow isolated_app_all priv_app (irda_socket (create)))
23848(neverallow isolated_app_all priv_app (pppox_socket (create)))
23849(neverallow isolated_app_all priv_app (llc_socket (create)))
23850(neverallow isolated_app_all priv_app (can_socket (create)))
23851(neverallow isolated_app_all priv_app (tipc_socket (create)))
23852(neverallow isolated_app_all priv_app (bluetooth_socket (create)))
23853(neverallow isolated_app_all priv_app (iucv_socket (create)))
23854(neverallow isolated_app_all priv_app (rxrpc_socket (create)))
23855(neverallow isolated_app_all priv_app (isdn_socket (create)))
23856(neverallow isolated_app_all priv_app (phonet_socket (create)))
23857(neverallow isolated_app_all priv_app (ieee802154_socket (create)))
23858(neverallow isolated_app_all priv_app (caif_socket (create)))
23859(neverallow isolated_app_all priv_app (alg_socket (create)))
23860(neverallow isolated_app_all priv_app (nfc_socket (create)))
23861(neverallow isolated_app_all priv_app (vsock_socket (create)))
23862(neverallow isolated_app_all priv_app (kcm_socket (create)))
23863(neverallow isolated_app_all priv_app (qipcrtr_socket (create)))
23864(neverallow isolated_app_all priv_app (smc_socket (create)))
23865(neverallow isolated_app_all priv_app (xdp_socket (create)))
23866(neverallow isolated_app_all sdk_sandbox_all (socket (create)))
23867(neverallow isolated_app_all sdk_sandbox_all (tcp_socket (create)))
23868(neverallow isolated_app_all sdk_sandbox_all (udp_socket (create)))
23869(neverallow isolated_app_all sdk_sandbox_all (rawip_socket (create)))
23870(neverallow isolated_app_all sdk_sandbox_all (netlink_socket (create)))
23871(neverallow isolated_app_all sdk_sandbox_all (packet_socket (create)))
23872(neverallow isolated_app_all sdk_sandbox_all (key_socket (create)))
23873(neverallow isolated_app_all sdk_sandbox_all (netlink_route_socket (create)))
23874(neverallow isolated_app_all sdk_sandbox_all (netlink_tcpdiag_socket (create)))
23875(neverallow isolated_app_all sdk_sandbox_all (netlink_nflog_socket (create)))
23876(neverallow isolated_app_all sdk_sandbox_all (netlink_xfrm_socket (create)))
23877(neverallow isolated_app_all sdk_sandbox_all (netlink_selinux_socket (create)))
23878(neverallow isolated_app_all sdk_sandbox_all (netlink_audit_socket (create)))
23879(neverallow isolated_app_all sdk_sandbox_all (netlink_dnrt_socket (create)))
23880(neverallow isolated_app_all sdk_sandbox_all (netlink_kobject_uevent_socket (create)))
23881(neverallow isolated_app_all sdk_sandbox_all (appletalk_socket (create)))
23882(neverallow isolated_app_all sdk_sandbox_all (tun_socket (create)))
23883(neverallow isolated_app_all sdk_sandbox_all (netlink_iscsi_socket (create)))
23884(neverallow isolated_app_all sdk_sandbox_all (netlink_fib_lookup_socket (create)))
23885(neverallow isolated_app_all sdk_sandbox_all (netlink_connector_socket (create)))
23886(neverallow isolated_app_all sdk_sandbox_all (netlink_netfilter_socket (create)))
23887(neverallow isolated_app_all sdk_sandbox_all (netlink_generic_socket (create)))
23888(neverallow isolated_app_all sdk_sandbox_all (netlink_scsitransport_socket (create)))
23889(neverallow isolated_app_all sdk_sandbox_all (netlink_rdma_socket (create)))
23890(neverallow isolated_app_all sdk_sandbox_all (netlink_crypto_socket (create)))
23891(neverallow isolated_app_all sdk_sandbox_all (sctp_socket (create)))
23892(neverallow isolated_app_all sdk_sandbox_all (icmp_socket (create)))
23893(neverallow isolated_app_all sdk_sandbox_all (ax25_socket (create)))
23894(neverallow isolated_app_all sdk_sandbox_all (ipx_socket (create)))
23895(neverallow isolated_app_all sdk_sandbox_all (netrom_socket (create)))
23896(neverallow isolated_app_all sdk_sandbox_all (atmpvc_socket (create)))
23897(neverallow isolated_app_all sdk_sandbox_all (x25_socket (create)))
23898(neverallow isolated_app_all sdk_sandbox_all (rose_socket (create)))
23899(neverallow isolated_app_all sdk_sandbox_all (decnet_socket (create)))
23900(neverallow isolated_app_all sdk_sandbox_all (atmsvc_socket (create)))
23901(neverallow isolated_app_all sdk_sandbox_all (rds_socket (create)))
23902(neverallow isolated_app_all sdk_sandbox_all (irda_socket (create)))
23903(neverallow isolated_app_all sdk_sandbox_all (pppox_socket (create)))
23904(neverallow isolated_app_all sdk_sandbox_all (llc_socket (create)))
23905(neverallow isolated_app_all sdk_sandbox_all (can_socket (create)))
23906(neverallow isolated_app_all sdk_sandbox_all (tipc_socket (create)))
23907(neverallow isolated_app_all sdk_sandbox_all (bluetooth_socket (create)))
23908(neverallow isolated_app_all sdk_sandbox_all (iucv_socket (create)))
23909(neverallow isolated_app_all sdk_sandbox_all (rxrpc_socket (create)))
23910(neverallow isolated_app_all sdk_sandbox_all (isdn_socket (create)))
23911(neverallow isolated_app_all sdk_sandbox_all (phonet_socket (create)))
23912(neverallow isolated_app_all sdk_sandbox_all (ieee802154_socket (create)))
23913(neverallow isolated_app_all sdk_sandbox_all (caif_socket (create)))
23914(neverallow isolated_app_all sdk_sandbox_all (alg_socket (create)))
23915(neverallow isolated_app_all sdk_sandbox_all (nfc_socket (create)))
23916(neverallow isolated_app_all sdk_sandbox_all (vsock_socket (create)))
23917(neverallow isolated_app_all sdk_sandbox_all (kcm_socket (create)))
23918(neverallow isolated_app_all sdk_sandbox_all (qipcrtr_socket (create)))
23919(neverallow isolated_app_all sdk_sandbox_all (smc_socket (create)))
23920(neverallow isolated_app_all sdk_sandbox_all (xdp_socket (create)))
23921(neverallow isolated_app_all self (socket (create)))
23922(neverallow isolated_app_all self (tcp_socket (create)))
23923(neverallow isolated_app_all self (udp_socket (create)))
23924(neverallow isolated_app_all self (rawip_socket (create)))
23925(neverallow isolated_app_all self (netlink_socket (create)))
23926(neverallow isolated_app_all self (packet_socket (create)))
23927(neverallow isolated_app_all self (key_socket (create)))
23928(neverallow isolated_app_all self (netlink_route_socket (create)))
23929(neverallow isolated_app_all self (netlink_tcpdiag_socket (create)))
23930(neverallow isolated_app_all self (netlink_nflog_socket (create)))
23931(neverallow isolated_app_all self (netlink_xfrm_socket (create)))
23932(neverallow isolated_app_all self (netlink_selinux_socket (create)))
23933(neverallow isolated_app_all self (netlink_audit_socket (create)))
23934(neverallow isolated_app_all self (netlink_dnrt_socket (create)))
23935(neverallow isolated_app_all self (netlink_kobject_uevent_socket (create)))
23936(neverallow isolated_app_all self (appletalk_socket (create)))
23937(neverallow isolated_app_all self (tun_socket (create)))
23938(neverallow isolated_app_all self (netlink_iscsi_socket (create)))
23939(neverallow isolated_app_all self (netlink_fib_lookup_socket (create)))
23940(neverallow isolated_app_all self (netlink_connector_socket (create)))
23941(neverallow isolated_app_all self (netlink_netfilter_socket (create)))
23942(neverallow isolated_app_all self (netlink_generic_socket (create)))
23943(neverallow isolated_app_all self (netlink_scsitransport_socket (create)))
23944(neverallow isolated_app_all self (netlink_rdma_socket (create)))
23945(neverallow isolated_app_all self (netlink_crypto_socket (create)))
23946(neverallow isolated_app_all self (sctp_socket (create)))
23947(neverallow isolated_app_all self (icmp_socket (create)))
23948(neverallow isolated_app_all self (ax25_socket (create)))
23949(neverallow isolated_app_all self (ipx_socket (create)))
23950(neverallow isolated_app_all self (netrom_socket (create)))
23951(neverallow isolated_app_all self (atmpvc_socket (create)))
23952(neverallow isolated_app_all self (x25_socket (create)))
23953(neverallow isolated_app_all self (rose_socket (create)))
23954(neverallow isolated_app_all self (decnet_socket (create)))
23955(neverallow isolated_app_all self (atmsvc_socket (create)))
23956(neverallow isolated_app_all self (rds_socket (create)))
23957(neverallow isolated_app_all self (irda_socket (create)))
23958(neverallow isolated_app_all self (pppox_socket (create)))
23959(neverallow isolated_app_all self (llc_socket (create)))
23960(neverallow isolated_app_all self (can_socket (create)))
23961(neverallow isolated_app_all self (tipc_socket (create)))
23962(neverallow isolated_app_all self (bluetooth_socket (create)))
23963(neverallow isolated_app_all self (iucv_socket (create)))
23964(neverallow isolated_app_all self (rxrpc_socket (create)))
23965(neverallow isolated_app_all self (isdn_socket (create)))
23966(neverallow isolated_app_all self (phonet_socket (create)))
23967(neverallow isolated_app_all self (ieee802154_socket (create)))
23968(neverallow isolated_app_all self (caif_socket (create)))
23969(neverallow isolated_app_all self (alg_socket (create)))
23970(neverallow isolated_app_all self (nfc_socket (create)))
23971(neverallow isolated_app_all self (vsock_socket (create)))
23972(neverallow isolated_app_all self (kcm_socket (create)))
23973(neverallow isolated_app_all self (qipcrtr_socket (create)))
23974(neverallow isolated_app_all self (smc_socket (create)))
23975(neverallow isolated_app_all self (xdp_socket (create)))
23976;;* lme
23977
23978(typetransition isolated_compute_app tmpfs file appdomain_tmpfs)
23979(allow isolated_compute_app isolated_compute_app_userfaultfd (anon_inode (ioctl read create)))
23980(dontaudit su isolated_compute_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23981;;* lmx 14 system/sepolicy/private/isolated_compute_app.te
23982
23983(neverallow base_typeattr_798 isolated_compute_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
23984;;* lme
23985
23986(allow isolated_compute_app appdomain_tmpfs (file (read write getattr map execute)))
23987;;* lmx 14 system/sepolicy/private/isolated_compute_app.te
23988
23989(neverallow base_typeattr_799 base_typeattr_798 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
23990;;* lme
23991
23992;;* lmx 14 system/sepolicy/private/isolated_compute_app.te
23993
23994(neverallow base_typeattr_800 isolated_compute_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
23995;;* lme
23996
23997;;* lmx 14 system/sepolicy/private/isolated_compute_app.te
23998
23999(neverallow base_typeattr_801 isolated_compute_app (process (ptrace)))
24000;;* lme
24001
24002(allow isolated_compute_app isolated_compute_allowed_service (service_manager (find)))
24003(allow isolated_compute_app isolated_compute_allowed_device (chr_file (ioctl read write map)))
24004(allow isolated_compute_app hwservicemanager (binder (call transfer)))
24005(allow hwservicemanager isolated_compute_app (binder (call transfer)))
24006(allow hwservicemanager isolated_compute_app (dir (search)))
24007(allow hwservicemanager isolated_compute_app (file (read map open)))
24008(allow hwservicemanager isolated_compute_app (process (getattr)))
24009(allow isolated_compute_app dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
24010(allow isolated_compute_app untrusted_app_all (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24011(allow isolated_compute_app untrusted_app_all (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24012(allow isolated_compute_app ephemeral_app (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24013(allow isolated_compute_app ephemeral_app (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24014(allow isolated_compute_app priv_app (tcp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24015(allow isolated_compute_app priv_app (udp_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
24016(allow isolated_compute_app toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24017(allow init iw_exec (file (read getattr map execute open)))
24018(allow init iw (process (transition)))
24019(allow iw iw_exec (file (read getattr map execute open entrypoint)))
24020(dontaudit init iw (process (noatsecure)))
24021(allow init iw (process (siginh rlimitinh)))
24022(typetransition init iw_exec process iw)
24023(allow kernel init_exec (file (read getattr map execute open)))
24024(allow kernel init (process (transition)))
24025(allow init init_exec (file (read getattr map execute open entrypoint)))
24026(allow init kernel (process (sigchld)))
24027(dontaudit kernel init (process (noatsecure)))
24028(allow kernel init (process (siginh rlimitinh)))
24029(typetransition kernel init_exec process init)
24030(allow kernel snapuserd_exec (file (read getattr map execute open)))
24031(allow kernel snapuserd (process (transition)))
24032(allow snapuserd snapuserd_exec (file (read getattr map execute open entrypoint)))
24033(allow snapuserd kernel (process (sigchld)))
24034(dontaudit kernel snapuserd (process (noatsecure)))
24035(allow kernel snapuserd (process (siginh rlimitinh)))
24036(typetransition kernel snapuserd_exec process snapuserd)
24037(allow kernel otapreopt_chroot (fd (use)))
24038(allow kernel postinstall_file (file (read)))
24039(allow kernel tmpfs (blk_file (getattr relabelfrom)))
24040(allow kernel tmpfs (chr_file (getattr relabelfrom)))
24041(allow kernel tmpfs (lnk_file (getattr relabelfrom)))
24042(allow kernel tmpfs (dir (read relabelfrom open)))
24043(allow kernel block_device (blk_file (relabelto)))
24044(allow kernel block_device (lnk_file (relabelto)))
24045(allow kernel dm_device (chr_file (relabelto)))
24046(allow kernel dm_device (blk_file (relabelto)))
24047(allow kernel dm_user_device (dir (read relabelto open search)))
24048(allow kernel dm_user_device (chr_file (relabelto)))
24049(allow kernel kmsg_device (chr_file (relabelto)))
24050(allow kernel null_device (chr_file (relabelto)))
24051(allow kernel random_device (chr_file (relabelto)))
24052(allow kernel snapuserd_exec (file (relabelto)))
24053(allow kernel kmsg_device (chr_file (write)))
24054(allow kernel gsid (fd (use)))
24055(dontaudit kernel metadata_file (dir (search)))
24056(dontaudit kernel ota_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
24057(dontaudit kernel sysfs (dir (ioctl read getattr lock open watch watch_reads search)))
24058(dontaudit kernel sysfs (file (read write open)))
24059(dontaudit kernel sysfs (chr_file (read write open)))
24060(dontaudit kernel dm_device (chr_file (ioctl)))
24061(dontaudit kernel self (capability (setgid sys_admin mknod)))
24062(dontaudit kernel dm_user_device (dir (write add_name)))
24063(dontaudit kernel dm_user_device (chr_file (create setattr)))
24064(dontaudit kernel tmpfs (lnk_file (read)))
24065(dontaudit kernel tmpfs (blk_file (read open)))
24066(allow init keystore_exec (file (read getattr map execute open)))
24067(allow init keystore (process (transition)))
24068(allow keystore keystore_exec (file (read getattr map execute open entrypoint)))
24069(dontaudit init keystore (process (noatsecure)))
24070(allow init keystore (process (siginh rlimitinh)))
24071(typetransition init keystore_exec process keystore)
24072(dontaudit keystore hal_remotelyprovisionedcomponent_avf_service (service_manager (find)))
24073(allow keystore platform_app (binder (call)))
24074(allow keystore device_logging_prop (file (read getattr map open)))
24075(allow keystore remote_prov_prop (file (read getattr map open)))
24076(allow keystore device_config_remote_key_provisioning_native_prop (file (read getattr map open)))
24077(allow keystore statsdw_socket (sock_file (write)))
24078(allow keystore statsd (unix_dgram_socket (sendto)))
24079(allow keystore keystore2_key_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
24080(allow keystore keystore_listen_prop (file (read getattr map open)))
24081(allow keystore vold (binder (transfer)))
24082(allow keystore property_socket (sock_file (write)))
24083(allow keystore init (unix_stream_socket (connectto)))
24084(allow keystore keystore_crash_prop (property_service (set)))
24085(allow keystore keystore_crash_prop (file (read getattr map open)))
24086;;* lmx 47 system/sepolicy/private/keystore.te
24087
24088(neverallow base_typeattr_561 keystore_crash_prop (property_service (set)))
24089;;* lme
24090
24091(allow keystore apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
24092(allow keystore apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
24093(allow keystore vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
24094(allow keystore vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24095(allow keystore vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24096(allow init linkerconfig_exec (file (read getattr map execute open)))
24097(allow init linkerconfig (process (transition)))
24098(allow linkerconfig linkerconfig_exec (file (read getattr map execute open entrypoint)))
24099(dontaudit init linkerconfig (process (noatsecure)))
24100(allow init linkerconfig (process (siginh rlimitinh)))
24101(typetransition init linkerconfig_exec process linkerconfig)
24102(allow linkerconfig linkerconfig_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24103(allow linkerconfig linkerconfig_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24104(allow linkerconfig kmsg_device (chr_file (write lock append map open)))
24105(allow linkerconfig devpts (chr_file (ioctl read write getattr)))
24106(allow linkerconfig apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
24107(allow linkerconfig apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
24108(allow linkerconfig vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
24109(allow linkerconfig vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24110(allow linkerconfig vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24111(allow linkerconfig otapreopt_chroot (fd (use)))
24112(allow linkerconfig postinstall_apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
24113(allow linkerconfig postinstall_apex_mnt_dir (file (ioctl read getattr lock map open watch watch_reads)))
24114;;* lmx 30 system/sepolicy/private/linkerconfig.te
24115
24116(neverallow base_typeattr_802 linkerconfig_exec (file (execute execute_no_trans)))
24117;;* lme
24118
24119(allow init llkd_exec (file (read getattr map execute open)))
24120(allow init llkd (process (transition)))
24121(allow llkd llkd_exec (file (read getattr map execute open entrypoint)))
24122(dontaudit init llkd (process (noatsecure)))
24123(allow init llkd (process (siginh rlimitinh)))
24124(typetransition init llkd_exec process llkd)
24125(allow llkd llkd_prop (file (read getattr map open)))
24126(allow llkd self (capability (kill)))
24127(allow llkd self (cap_userns (kill)))
24128(allow llkd self (capability (ipc_lock)))
24129(allow llkd self (cap_userns (ipc_lock)))
24130(allow llkd domain (process (sigkill)))
24131(allow llkd domain (dir (ioctl read getattr lock open watch watch_reads search)))
24132(allow llkd domain (file (ioctl read getattr lock map open watch watch_reads)))
24133(allow llkd domain (lnk_file (read)))
24134(allow llkd proc_hung_task (file (ioctl read write getattr lock append map open watch watch_reads)))
24135(allow llkd proc_sysrq (file (ioctl read write getattr lock append map open watch watch_reads)))
24136(allow llkd kmsg_device (chr_file (write lock append map open)))
24137;;* lmx 49 system/sepolicy/private/llkd.te
24138
24139(neverallow base_typeattr_223 llkd (process (transition dyntransition)))
24140;;* lme
24141
24142;;* lmx 50 system/sepolicy/private/llkd.te
24143
24144(neverallow domain llkd (process (ptrace)))
24145;;* lme
24146
24147;;* lmx 53 system/sepolicy/private/llkd.te
24148
24149(neverallow base_typeattr_224 llkd (process (noatsecure)))
24150;;* lme
24151
24152(allow init lmkd_exec (file (read getattr map execute open)))
24153(allow init lmkd (process (transition)))
24154(allow lmkd lmkd_exec (file (read getattr map execute open entrypoint)))
24155(dontaudit init lmkd (process (noatsecure)))
24156(allow init lmkd (process (siginh rlimitinh)))
24157(typetransition init lmkd_exec process lmkd)
24158(allow lmkd property_socket (sock_file (write)))
24159(allow lmkd init (unix_stream_socket (connectto)))
24160(allow lmkd system_lmk_prop (property_service (set)))
24161(allow lmkd system_lmk_prop (file (read getattr map open)))
24162(allow lmkd property_socket (sock_file (write)))
24163(allow lmkd init (unix_stream_socket (connectto)))
24164(allow lmkd lmkd_prop (property_service (set)))
24165(allow lmkd lmkd_prop (file (read getattr map open)))
24166(allow lmkd device_config_lmkd_native_prop (file (read getattr map open)))
24167(allow lmkd fs_bpf (file (read)))
24168(allow lmkd bpfloader (bpf (map_read)))
24169;;* lmx 18 system/sepolicy/private/lmkd.te
24170
24171(neverallow base_typeattr_803 lmkd_prop (property_service (set)))
24172;;* lme
24173
24174(allow init logd_exec (file (read getattr map execute open)))
24175(allow init logd (process (transition)))
24176(allow logd logd_exec (file (read getattr map execute open entrypoint)))
24177(dontaudit init logd (process (noatsecure)))
24178(allow init logd (process (siginh rlimitinh)))
24179(typetransition init logd_exec process logd)
24180(allow logd device_logging_prop (file (read getattr map open)))
24181;;* lmx 17 system/sepolicy/private/logd.te
24182
24183(neverallow logd base_typeattr_804 (file (write create append)))
24184;;* lme
24185
24186;;* lmx 32 system/sepolicy/private/logd.te
24187
24188(neverallow base_typeattr_805 runtime_event_log_tags_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24189;;* lme
24190
24191;;* lmx 43 system/sepolicy/private/logd.te
24192
24193(neverallow base_typeattr_806 runtime_event_log_tags_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24194;;* lme
24195
24196(allow logd servicemanager (binder (call transfer)))
24197(allow servicemanager logd (binder (call transfer)))
24198(allow servicemanager logd (dir (search)))
24199(allow servicemanager logd (file (read open)))
24200(allow servicemanager logd (process (getattr)))
24201(allow logd system_server (binder (call transfer)))
24202(allow system_server logd (binder (transfer)))
24203(allow logd system_server (fd (use)))
24204(allow logd logd_service (service_manager (add find)))
24205;;* lmx 50 system/sepolicy/private/logd.te
24206
24207(neverallow base_typeattr_807 logd_service (service_manager (add)))
24208;;* lme
24209
24210(allow logd logcat_service (service_manager (find)))
24211;;* lmx 28 system/sepolicy/private/logpersist.te
24212
24213(neverallow logpersist file_type (file (write create append)))
24214;;* lme
24215
24216;;* lmx 29 system/sepolicy/private/logpersist.te
24217
24218(neverallow base_typeattr_808 misc_logd_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24219;;* lme
24220
24221;;* lmx 30 system/sepolicy/private/logpersist.te
24222
24223(neverallow base_typeattr_223 misc_logd_file (file (write create setattr relabelfrom append unlink link rename)))
24224;;* lme
24225
24226;;* lmx 31 system/sepolicy/private/logpersist.te
24227
24228(neverallow base_typeattr_223 misc_logd_file (dir (write relabelfrom link rename add_name remove_name reparent rmdir)))
24229;;* lme
24230
24231(allow init lpdumpd_exec (file (read getattr map execute open)))
24232(allow init lpdumpd (process (transition)))
24233(allow lpdumpd lpdumpd_exec (file (read getattr map execute open entrypoint)))
24234(dontaudit init lpdumpd (process (noatsecure)))
24235(allow init lpdumpd (process (siginh rlimitinh)))
24236(typetransition init lpdumpd_exec process lpdumpd)
24237(allow lpdumpd servicemanager (binder (call transfer)))
24238(allow servicemanager lpdumpd (binder (call transfer)))
24239(allow servicemanager lpdumpd (dir (search)))
24240(allow servicemanager lpdumpd (file (read open)))
24241(allow servicemanager lpdumpd (process (getattr)))
24242(allow lpdumpd lpdump_service (service_manager (add find)))
24243;;* lmx 8 system/sepolicy/private/lpdumpd.te
24244
24245(neverallow base_typeattr_809 lpdump_service (service_manager (add)))
24246;;* lme
24247
24248(allow lpdumpd block_device (dir (ioctl read getattr lock open watch watch_reads search)))
24249(allow lpdumpd super_block_device_type (blk_file (ioctl read getattr lock map open watch watch_reads)))
24250(allow lpdumpd sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
24251(allow lpdumpd sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
24252(allow lpdumpd gsi_metadata_file_type (dir (search)))
24253(allow lpdumpd metadata_file (dir (search)))
24254(allow lpdumpd gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24255(allow lpdumpd proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
24256(allow lpdumpd proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
24257(allow lpdumpd sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
24258(allow lpdumpd sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
24259(allow lpdumpd sysfs_dt_firmware_android (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24260(allow lpdumpd proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
24261(allow lpdumpd virtual_ab_prop (file (read getattr map open)))
24262(allow lpdumpd metadata_file (dir (search)))
24263(allow lpdumpd ota_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
24264(allow lpdumpd ota_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24265;;* lmx 39 system/sepolicy/private/lpdumpd.te
24266
24267(neverallow base_typeattr_810 lpdump_service (service_manager (find)))
24268;;* lme
24269
24270;;* lmx 47 system/sepolicy/private/lpdumpd.te
24271
24272(neverallow base_typeattr_811 lpdumpd (binder (call)))
24273;;* lme
24274
24275(allow init mdnsd_exec (file (read getattr map execute open)))
24276(allow init mdnsd (process (transition)))
24277(allow mdnsd mdnsd_exec (file (read getattr map execute open entrypoint)))
24278(dontaudit init mdnsd (process (noatsecure)))
24279(allow init mdnsd (process (siginh rlimitinh)))
24280(typetransition init mdnsd_exec process mdnsd)
24281(allow mdnsd proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
24282(allow mdnsd proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
24283(allow mdnsd proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24284(allow init mediadrmserver_exec (file (read getattr map execute open)))
24285(allow init mediadrmserver (process (transition)))
24286(allow mediadrmserver mediadrmserver_exec (file (read getattr map execute open entrypoint)))
24287(dontaudit init mediadrmserver (process (noatsecure)))
24288(allow init mediadrmserver (process (siginh rlimitinh)))
24289(typetransition init mediadrmserver_exec process mediadrmserver)
24290(auditallow mediadrmserver hal_graphics_allocator_server (binder (call)))
24291(allow init mediaextractor_exec (file (read getattr map execute open)))
24292(allow init mediaextractor (process (transition)))
24293(allow mediaextractor mediaextractor_exec (file (read getattr map execute open entrypoint)))
24294(dontaudit init mediaextractor (process (noatsecure)))
24295(allow init mediaextractor (process (siginh rlimitinh)))
24296(typetransition init mediaextractor_exec process mediaextractor)
24297(typetransition mediaextractor tmpfs file mediaextractor_tmpfs)
24298(allow mediaextractor mediaextractor_tmpfs (file (read write getattr map)))
24299(allow mediaextractor appdomain_tmpfs (file (read write getattr map)))
24300(allow mediaextractor mediaserver_tmpfs (file (read write getattr map)))
24301(allow mediaextractor system_server_tmpfs (file (read write getattr map)))
24302(allow mediaextractor device_config_media_native_prop (file (read getattr map open)))
24303(allow mediaextractor device_config_swcodec_native_prop (file (read getattr map open)))
24304(allow init mediametrics_exec (file (read getattr map execute open)))
24305(allow init mediametrics (process (transition)))
24306(allow mediametrics mediametrics_exec (file (read getattr map execute open entrypoint)))
24307(dontaudit init mediametrics (process (noatsecure)))
24308(allow init mediametrics (process (siginh rlimitinh)))
24309(typetransition init mediametrics_exec process mediametrics)
24310(allow mediametrics stats_service (service_manager (find)))
24311(allow mediametrics statsmanager_service (service_manager (find)))
24312(allow mediametrics statsd (binder (call transfer)))
24313(allow statsd mediametrics (binder (transfer)))
24314(allow mediametrics statsd (fd (use)))
24315(typetransition mediaprovider tmpfs file appdomain_tmpfs)
24316(allow mediaprovider mediaprovider_userfaultfd (anon_inode (ioctl read create)))
24317(dontaudit su mediaprovider_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24318;;* lmx 7 system/sepolicy/private/mediaprovider.te
24319
24320(neverallow base_typeattr_812 mediaprovider_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24321;;* lme
24322
24323(allow mediaprovider appdomain_tmpfs (file (read write getattr map execute)))
24324;;* lmx 7 system/sepolicy/private/mediaprovider.te
24325
24326(neverallow base_typeattr_813 base_typeattr_812 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24327;;* lme
24328
24329;;* lmx 7 system/sepolicy/private/mediaprovider.te
24330
24331(neverallow base_typeattr_814 mediaprovider (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24332;;* lme
24333
24334;;* lmx 7 system/sepolicy/private/mediaprovider.te
24335
24336(neverallow base_typeattr_815 mediaprovider (process (ptrace)))
24337;;* lme
24338
24339(allow mediaprovider cache_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24340(allow mediaprovider cache_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24341(allow mediaprovider cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24342(dontaudit mediaprovider cache_private_backup_file (dir (getattr)))
24343(dontaudit mediaprovider cache_recovery_file (dir (getattr)))
24344(allow mediaprovider mnt_media_rw_file (dir (search)))
24345(allow mediaprovider app_api_service (service_manager (find)))
24346(allow mediaprovider audioserver_service (service_manager (find)))
24347(allow mediaprovider cameraserver_service (service_manager (find)))
24348(allow mediaprovider drmserver_service (service_manager (find)))
24349(allow mediaprovider mediaextractor_service (service_manager (find)))
24350(allow mediaprovider mediaserver_service (service_manager (find)))
24351(allow mediaprovider ringtone_file (file (read write getattr)))
24352(allow mediaprovider mtp_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
24353(allow mediaprovider functionfs (dir (search)))
24354(allow mediaprovider functionfs (file (ioctl read write getattr lock append map open watch watch_reads)))
24355(allowx mediaprovider functionfs (ioctl file (0x6782)))
24356(allowx mediaprovider functionfs (ioctl file (0x67e7)))
24357(allow mediaprovider ffs_config_prop (file (read getattr map open)))
24358(allow mediaprovider property_socket (sock_file (write)))
24359(allow mediaprovider init (unix_stream_socket (connectto)))
24360(allow mediaprovider ffs_control_prop (property_service (set)))
24361(allow mediaprovider ffs_control_prop (file (read getattr map open)))
24362(allow mediaprovider drm_service_config_prop (file (read getattr map open)))
24363(typetransition mediaprovider_app tmpfs file appdomain_tmpfs)
24364(allow mediaprovider_app mediaprovider_app_userfaultfd (anon_inode (ioctl read create)))
24365(dontaudit su mediaprovider_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24366;;* lmx 6 system/sepolicy/private/mediaprovider_app.te
24367
24368(neverallow base_typeattr_816 mediaprovider_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24369;;* lme
24370
24371(allow mediaprovider_app appdomain_tmpfs (file (read write getattr map execute)))
24372;;* lmx 6 system/sepolicy/private/mediaprovider_app.te
24373
24374(neverallow base_typeattr_817 base_typeattr_816 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24375;;* lme
24376
24377;;* lmx 6 system/sepolicy/private/mediaprovider_app.te
24378
24379(neverallow base_typeattr_818 mediaprovider_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24380;;* lme
24381
24382;;* lmx 6 system/sepolicy/private/mediaprovider_app.te
24383
24384(neverallow base_typeattr_819 mediaprovider_app (process (ptrace)))
24385;;* lme
24386
24387(allow mediaprovider_app mnt_pass_through_file (dir (ioctl read getattr lock open watch watch_reads search)))
24388(allow mediaprovider_app mnt_pass_through_file (file (ioctl read getattr lock map open watch watch_reads)))
24389(allow mediaprovider_app mnt_pass_through_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24390(allow mediaprovider_app fuse_device (chr_file (ioctl read write getattr)))
24391(allow mediaprovider_app fuseblk (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24392(allow mediaprovider_app fuseblk (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24393(allow mediaprovider_app media_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
24394(allow mediaprovider_app media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24395(allow mediaprovider_app media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24396(allow mediaprovider_app drmserver_service (service_manager (find)))
24397(allow mediaprovider_app mediaserver_service (service_manager (find)))
24398(allow mediaprovider_app audioserver_service (service_manager (find)))
24399(allow mediaprovider_app mediametrics_service (service_manager (find)))
24400(allow mediaprovider_app app_api_service (service_manager (find)))
24401(allow mediaprovider_app gpuservice (binder (call transfer)))
24402(allow gpuservice mediaprovider_app (binder (transfer)))
24403(allow mediaprovider_app gpuservice (fd (use)))
24404(allow mediaprovider_app statsmanager_service (service_manager (find)))
24405(allow mediaprovider_app statsd (binder (call transfer)))
24406(allow statsd mediaprovider_app (binder (transfer)))
24407(allow mediaprovider_app statsd (fd (use)))
24408(allow mediaprovider_app proc_pipe_conf (file (ioctl read getattr lock map open watch watch_reads)))
24409(allowx mediaprovider_app media_rw_data_file (ioctl file ((range 0x581f 0x5820))))
24410(allowx mediaprovider_app media_rw_data_file (ioctl dir ((range 0x581f 0x5820))))
24411(allowx mediaprovider_app media_rw_data_file (ioctl file ((range 0x6601 0x6602))))
24412(allowx mediaprovider_app media_rw_data_file (ioctl dir ((range 0x6601 0x6602))))
24413(allow mediaprovider_app mnt_media_rw_file (dir (search)))
24414(allow mediaprovider_app proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
24415(allow mediaprovider_app storage_config_prop (file (read getattr map open)))
24416(allow mediaprovider_app drm_service_config_prop (file (read getattr map open)))
24417(allow mediaprovider_app gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
24418(allow mediaprovider_app gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
24419(dontaudit mediaprovider_app sysfs_vendor_sched (dir (search)))
24420(dontaudit mediaprovider_app sysfs_vendor_sched (file (write lock append map open)))
24421(allow mediaprovider_app fs_bpf (file (read)))
24422(allow mediaprovider_app bpfloader (bpf (map_read map_write prog_run)))
24423(allow mediaprovider_app bootanim_oem_file (file (ioctl read getattr lock map open watch watch_reads)))
24424(allow init mediaserver_exec (file (read getattr map execute open)))
24425(allow init mediaserver (process (transition)))
24426(allow mediaserver mediaserver_exec (file (read getattr map execute open entrypoint)))
24427(dontaudit init mediaserver (process (noatsecure)))
24428(allow init mediaserver (process (siginh rlimitinh)))
24429(typetransition init mediaserver_exec process mediaserver)
24430(typetransition mediaserver tmpfs file mediaserver_tmpfs)
24431(allow mediaserver mediaserver_tmpfs (file (read write getattr map)))
24432(allow mediaserver appdomain_tmpfs (file (read write getattr map)))
24433(allow mediaserver property_socket (sock_file (write)))
24434(allow mediaserver init (unix_stream_socket (connectto)))
24435(allow mediaserver audio_prop (property_service (set)))
24436(allow mediaserver audio_prop (file (read getattr map open)))
24437(allow mediaserver drm_service_config_prop (file (read getattr map open)))
24438(allow mediaserver media_config_prop (file (read getattr map open)))
24439(allow mediaserver device_config_media_native_prop (file (read getattr map open)))
24440(allow mediaserver property_socket (sock_file (write)))
24441(allow mediaserver init (unix_stream_socket (connectto)))
24442(allow mediaserver ctl_mediatranscoding_prop (property_service (set)))
24443(allow mediaserver ctl_mediatranscoding_prop (file (read getattr map open)))
24444(allow mediaserver sdk_sandbox_data_file (file (read getattr)))
24445(allow mediaserver stats_service (service_manager (find)))
24446(allow mediaserver statsmanager_service (service_manager (find)))
24447(allow mediaserver statsd (binder (call transfer)))
24448(allow statsd mediaserver (binder (transfer)))
24449(allow mediaserver statsd (fd (use)))
24450(allow mediaserver virtual_camera (binder (call transfer)))
24451(allow virtual_camera mediaserver (binder (transfer)))
24452(allow mediaserver virtual_camera (fd (use)))
24453(allow init mediaswcodec_exec (file (read getattr map execute open)))
24454(allow init mediaswcodec (process (transition)))
24455(allow mediaswcodec mediaswcodec_exec (file (read getattr map execute open entrypoint)))
24456(dontaudit init mediaswcodec (process (noatsecure)))
24457(allow init mediaswcodec (process (siginh rlimitinh)))
24458(typetransition init mediaswcodec_exec process mediaswcodec)
24459(allow mediaswcodec device_config_media_native_prop (file (read getattr map open)))
24460(allow mediaswcodec device_config_swcodec_native_prop (file (read getattr map open)))
24461(allow init mediatranscoding_exec (file (read getattr map execute open)))
24462(allow init mediatranscoding (process (transition)))
24463(allow mediatranscoding mediatranscoding_exec (file (read getattr map execute open entrypoint)))
24464(dontaudit init mediatranscoding (process (noatsecure)))
24465(allow init mediatranscoding (process (siginh rlimitinh)))
24466(typetransition init mediatranscoding_exec process mediatranscoding)
24467(typetransition mediatranscoding tmpfs file mediatranscoding_tmpfs)
24468(allow mediatranscoding mediatranscoding_tmpfs (file (read write getattr map)))
24469(allow mediatranscoding appdomain_tmpfs (file (read write getattr map)))
24470(allow mediatranscoding servicemanager (binder (call transfer)))
24471(allow servicemanager mediatranscoding (binder (call transfer)))
24472(allow servicemanager mediatranscoding (dir (search)))
24473(allow servicemanager mediatranscoding (file (read open)))
24474(allow servicemanager mediatranscoding (process (getattr)))
24475(allow mediatranscoding binderservicedomain (binder (call transfer)))
24476(allow binderservicedomain mediatranscoding (binder (transfer)))
24477(allow mediatranscoding binderservicedomain (fd (use)))
24478(allow mediatranscoding appdomain (binder (call transfer)))
24479(allow appdomain mediatranscoding (binder (transfer)))
24480(allow mediatranscoding appdomain (fd (use)))
24481(allow mediatranscoding mediatranscoding_service (service_manager (add find)))
24482;;* lmx 15 system/sepolicy/private/mediatranscoding.te
24483
24484(neverallow base_typeattr_820 mediatranscoding_service (service_manager (add)))
24485;;* lme
24486
24487(allow mediatranscoding mediaserver_service (service_manager (find)))
24488(allow mediatranscoding mediametrics_service (service_manager (find)))
24489(allow mediatranscoding mediaextractor_service (service_manager (find)))
24490(allow mediatranscoding package_native_service (service_manager (find)))
24491(allow mediatranscoding thermal_service (service_manager (find)))
24492(allow mediatranscoding system_server (fd (use)))
24493(allow mediatranscoding activity_service (service_manager (find)))
24494(allow mediatranscoding sdcardfs (file (read write getattr)))
24495(allow mediatranscoding media_rw_data_file (file (read write getattr)))
24496(allow mediatranscoding apk_data_file (file (read getattr)))
24497(allow mediatranscoding app_data_file (file (read write getattr)))
24498(allow mediatranscoding shell_data_file (file (read write getattr)))
24499(allow mediatranscoding statsdw_socket (sock_file (write)))
24500(allow mediatranscoding statsd (unix_dgram_socket (sendto)))
24501(allow mediatranscoding dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
24502(allow mediatranscoding gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
24503(allow mediatranscoding gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
24504(allow mediatranscoding media_config_prop (file (read getattr map open)))
24505;;* lmx 53 system/sepolicy/private/mediatranscoding.te
24506
24507(neverallow mediatranscoding fs_type (file (execute_no_trans)))
24508(neverallow mediatranscoding file_type (file (execute_no_trans)))
24509;;* lme
24510
24511;;* lmx 65 system/sepolicy/private/mediatranscoding.te
24512
24513(neverallow mediatranscoding domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
24514(neverallow mediatranscoding domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
24515;;* lme
24516
24517;;* lmx 66 system/sepolicy/private/mediatranscoding.te
24518
24519(neverallow mediatranscoding domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
24520;;* lme
24521
24522(allow init mediatuner_exec (file (read getattr map execute open)))
24523(allow init mediatuner (process (transition)))
24524(allow mediatuner mediatuner_exec (file (read getattr map execute open entrypoint)))
24525(dontaudit init mediatuner (process (noatsecure)))
24526(allow init mediatuner (process (siginh rlimitinh)))
24527(typetransition init mediatuner_exec process mediatuner)
24528(allow mediatuner servicemanager (binder (call transfer)))
24529(allow servicemanager mediatuner (binder (call transfer)))
24530(allow servicemanager mediatuner (dir (search)))
24531(allow servicemanager mediatuner (file (read open)))
24532(allow servicemanager mediatuner (process (getattr)))
24533(allow mediatuner appdomain (binder (call transfer)))
24534(allow appdomain mediatuner (binder (transfer)))
24535(allow mediatuner appdomain (fd (use)))
24536(allow mediatuner mediatuner_service (service_manager (add find)))
24537;;* lmx 14 system/sepolicy/private/mediatuner.te
24538
24539(neverallow base_typeattr_821 mediatuner_service (service_manager (add)))
24540;;* lme
24541
24542(allow mediatuner system_server (fd (use)))
24543(allow mediatuner tv_tuner_resource_mgr_service (service_manager (find)))
24544(allow mediatuner package_native_service (service_manager (find)))
24545(allow mediatuner system_server (binder (call transfer)))
24546(allow system_server mediatuner (binder (transfer)))
24547(allow mediatuner system_server (fd (use)))
24548(allow mediatuner tuner_config_prop (file (read getattr map open)))
24549(allow mediatuner tuner_server_ctl_prop (file (read getattr map open)))
24550;;* lmx 32 system/sepolicy/private/mediatuner.te
24551
24552(neverallow mediatuner fs_type (file (execute_no_trans)))
24553(neverallow mediatuner file_type (file (execute_no_trans)))
24554;;* lme
24555
24556;;* lmx 35 system/sepolicy/private/mediatuner.te
24557
24558(neverallowx mediatuner domain (ioctl tcp_socket (0x6900 0x6902)))
24559(neverallowx mediatuner domain (ioctl udp_socket (0x6900 0x6902)))
24560(neverallowx mediatuner domain (ioctl rawip_socket (0x6900 0x6902)))
24561;;* lme
24562
24563;;* lmx 35 system/sepolicy/private/mediatuner.te
24564
24565(neverallowx mediatuner domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
24566(neverallowx mediatuner domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
24567(neverallowx mediatuner domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
24568;;* lme
24569
24570;;* lmx 35 system/sepolicy/private/mediatuner.te
24571
24572(neverallowx mediatuner domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
24573(neverallowx mediatuner domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
24574(neverallowx mediatuner domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
24575;;* lme
24576
24577(allow migrate_legacy_obb_data media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24578(allow migrate_legacy_obb_data media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24579(allow migrate_legacy_obb_data shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24580(allow migrate_legacy_obb_data toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24581(allow migrate_legacy_obb_data self (capability (chown dac_override dac_read_search fowner fsetid)))
24582(allow migrate_legacy_obb_data mnt_user_file (dir (search)))
24583(allow migrate_legacy_obb_data mnt_user_file (lnk_file (read)))
24584(allow migrate_legacy_obb_data storage_file (dir (search)))
24585(allow migrate_legacy_obb_data storage_file (lnk_file (read)))
24586(allow migrate_legacy_obb_data sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24587(allow migrate_legacy_obb_data sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24588(allow migrate_legacy_obb_data installd (fd (use)))
24589(allow migrate_legacy_obb_data installd (file (read)))
24590(allow init misctrl_exec (file (read getattr map execute open)))
24591(allow init misctrl (process (transition)))
24592(allow misctrl misctrl_exec (file (read getattr map execute open entrypoint)))
24593(dontaudit init misctrl (process (noatsecure)))
24594(allow init misctrl (process (siginh rlimitinh)))
24595(typetransition init misctrl_exec process misctrl)
24596(allow misctrl misc_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
24597(allow misctrl block_device (dir (ioctl read getattr lock open watch watch_reads search)))
24598(allow misctrl gsi_metadata_file_type (dir (search)))
24599(allow misctrl metadata_file (dir (search)))
24600(allow misctrl gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24601(allow misctrl proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
24602(allow misctrl proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
24603(allow misctrl property_socket (sock_file (write)))
24604(allow misctrl init (unix_stream_socket (connectto)))
24605(allow misctrl misctrl_prop (property_service (set)))
24606(allow misctrl misctrl_prop (file (read getattr map open)))
24607(dontaudit misctrl sysfs_dt_firmware_android (dir (search)))
24608(dontaudit misctrl vendor_property_type (file (read)))
24609;;* lmx 12 system/sepolicy/private/mlstrustedsubject.te
24610
24611(neverallow base_typeattr_822 app_data_file (file (create setattr relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24612(neverallow base_typeattr_822 privapp_data_file (file (create setattr relabelfrom relabelto unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24613;;* lme
24614
24615;;* lmx 18 system/sepolicy/private/mlstrustedsubject.te
24616
24617(neverallow base_typeattr_822 app_data_file (dir (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
24618(neverallow base_typeattr_822 privapp_data_file (dir (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
24619;;* lme
24620
24621;;* lmx 28 system/sepolicy/private/mlstrustedsubject.te
24622
24623(neverallow base_typeattr_823 app_data_file (dir (read getattr search)))
24624(neverallow base_typeattr_823 privapp_data_file (dir (read getattr search)))
24625;;* lme
24626
24627(allow init mm_events_exec (file (read getattr map execute open)))
24628(allow init mm_events (process (transition)))
24629(allow mm_events mm_events_exec (file (read getattr map execute open entrypoint)))
24630(dontaudit init mm_events (process (noatsecure)))
24631(allow init mm_events (process (siginh rlimitinh)))
24632(typetransition init mm_events_exec process mm_events)
24633(allow mm_events shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24634(allow mm_events toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24635(allow mm_events perfetto_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
24636(allow mm_events perfetto_exec (file (read getattr map execute open)))
24637(allow mm_events perfetto (process (transition)))
24638(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
24639(allow perfetto mm_events (process (sigchld)))
24640(dontaudit mm_events perfetto (process (noatsecure)))
24641(allow mm_events perfetto (process (siginh rlimitinh)))
24642(typetransition mm_events perfetto_exec process perfetto)
24643(allow init mtectrl_exec (file (read getattr map execute open)))
24644(allow init mtectrl (process (transition)))
24645(allow mtectrl mtectrl_exec (file (read getattr map execute open entrypoint)))
24646(dontaudit init mtectrl (process (noatsecure)))
24647(allow init mtectrl (process (siginh rlimitinh)))
24648(typetransition init mtectrl_exec process mtectrl)
24649(allow mtectrl property_socket (sock_file (write)))
24650(allow mtectrl init (unix_stream_socket (connectto)))
24651(allow mtectrl arm64_memtag_prop (property_service (set)))
24652(allow mtectrl arm64_memtag_prop (file (read getattr map open)))
24653(allow mtectrl misc_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
24654(allow mtectrl block_device (dir (ioctl read getattr lock open watch watch_reads search)))
24655(allow mtectrl gsi_metadata_file_type (dir (search)))
24656(allow mtectrl metadata_file (dir (search)))
24657(allow mtectrl gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
24658(allow mtectrl proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
24659(allow mtectrl proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
24660(dontaudit mtectrl sysfs_dt_firmware_android (dir (search)))
24661(dontaudit mtectrl vendor_property_type (file (read)))
24662(allow base_typeattr_824 node_type (tcp_socket (node_bind)))
24663(allow base_typeattr_824 node_type (udp_socket (node_bind)))
24664(allow base_typeattr_824 node_type (rawip_socket (node_bind)))
24665(allow base_typeattr_824 node_type (icmp_socket (node_bind)))
24666(allow base_typeattr_824 port_type (udp_socket (name_bind)))
24667(allow base_typeattr_824 port_type (tcp_socket (name_bind)))
24668(allow base_typeattr_825 self (netlink_route_socket (bind nlmsg_readpriv nlmsg_getneigh)))
24669(allow init netd_exec (file (read getattr map execute open)))
24670(allow init netd (process (transition)))
24671(allow netd netd_exec (file (read getattr map execute open entrypoint)))
24672(dontaudit init netd (process (noatsecure)))
24673(allow init netd (process (siginh rlimitinh)))
24674(typetransition init netd_exec process netd)
24675(allow netd dnsmasq_exec (file (read getattr map execute open)))
24676(allow netd dnsmasq (process (transition)))
24677(allow dnsmasq dnsmasq_exec (file (read getattr map execute open entrypoint)))
24678(allow dnsmasq netd (process (sigchld)))
24679(dontaudit netd dnsmasq (process (noatsecure)))
24680(allow netd dnsmasq (process (siginh rlimitinh)))
24681(typetransition netd dnsmasq_exec process dnsmasq)
24682(allow netd fs_bpf (dir (search)))
24683(allow netd fs_bpf_vendor (dir (search)))
24684(allow netd fs_bpf_netd_readonly (dir (search)))
24685(allow netd fs_bpf_netd_shared (dir (search)))
24686(allow netd fs_bpf (file (read getattr)))
24687(allow netd fs_bpf_vendor (file (read getattr)))
24688(allow netd fs_bpf_netd_readonly (file (read getattr)))
24689(allow netd fs_bpf_netd_shared (file (read getattr)))
24690(allow netd fs_bpf (file (write)))
24691(allow netd fs_bpf_netd_shared (file (write)))
24692(allow netd bpfloader (bpf (map_read map_write prog_run)))
24693(allow netd self (key_socket (create)))
24694(allow netd property_socket (sock_file (write)))
24695(allow netd init (unix_stream_socket (connectto)))
24696(allow netd ctl_mdnsd_prop (property_service (set)))
24697(allow netd ctl_mdnsd_prop (file (read getattr map open)))
24698(allow netd property_socket (sock_file (write)))
24699(allow netd init (unix_stream_socket (connectto)))
24700(allow netd netd_stable_secret_prop (property_service (set)))
24701(allow netd netd_stable_secret_prop (file (read getattr map open)))
24702(allow netd adbd_config_prop (file (read getattr map open)))
24703(allow netd hwservicemanager_prop (file (read getattr map open)))
24704(allow netd device_config_netd_native_prop (file (read getattr map open)))
24705(allow netd statsdw_socket (sock_file (write)))
24706(allow netd statsd (unix_dgram_socket (sendto)))
24707(allow netd network_stack (binder (call transfer)))
24708(allow network_stack netd (binder (transfer)))
24709(allow netd network_stack (fd (use)))
24710(allow netd dumpstate (fd (use)))
24711(allow netd dumpstate (fifo_file (write getattr)))
24712;;* lmx 41 system/sepolicy/private/netd.te
24713
24714(neverallow base_typeattr_826 netd_stable_secret_prop (file (ioctl read getattr lock map open watch watch_reads)))
24715;;* lme
24716
24717;;* lmx 45 system/sepolicy/private/netd.te
24718
24719(neverallow base_typeattr_827 netd_stable_secret_prop (property_service (set)))
24720;;* lme
24721
24722(allow netutils_wrapper system_file (dir (ioctl read getattr lock open watch watch_reads search)))
24723(allow netutils_wrapper system_file (file (ioctl read getattr lock map open watch watch_reads)))
24724(allow netutils_wrapper system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24725(allow netutils_wrapper self (capability (net_raw)))
24726(allow netutils_wrapper self (cap_userns (net_raw)))
24727(allow netutils_wrapper system_file (file (execute execute_no_trans)))
24728(allow netutils_wrapper proc_net_type (file (read getattr open)))
24729(allow netutils_wrapper self (rawip_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24730(allow netutils_wrapper self (udp_socket (ioctl read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24731(allow netutils_wrapper self (capability (net_admin)))
24732(allow netutils_wrapper self (cap_userns (net_admin)))
24733(allow netutils_wrapper self (netlink_route_socket (read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh)))
24734(allow netutils_wrapper self (netlink_xfrm_socket (read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
24735(allow netutils_wrapper netd_service (service_manager (find)))
24736(allow netutils_wrapper dnsresolver_service (service_manager (find)))
24737(allow netutils_wrapper mdns_service (service_manager (find)))
24738(allow netutils_wrapper servicemanager (binder (call transfer)))
24739(allow servicemanager netutils_wrapper (binder (call transfer)))
24740(allow servicemanager netutils_wrapper (dir (search)))
24741(allow servicemanager netutils_wrapper (file (read open)))
24742(allow servicemanager netutils_wrapper (process (getattr)))
24743(allow netutils_wrapper netd (binder (call transfer)))
24744(allow netd netutils_wrapper (binder (transfer)))
24745(allow netutils_wrapper netd (fd (use)))
24746(allow netutils_wrapper fs_bpf (dir (search)))
24747(allow netutils_wrapper fs_bpf_vendor (dir (search)))
24748(allow netutils_wrapper fs_bpf_netd_shared (dir (search)))
24749(allow netutils_wrapper fs_bpf (file (read getattr)))
24750(allow netutils_wrapper fs_bpf_vendor (file (read getattr)))
24751(allow netutils_wrapper fs_bpf_netd_shared (file (read getattr)))
24752(allow netutils_wrapper fs_bpf (file (write)))
24753(allow netutils_wrapper bpfloader (bpf (prog_run)))
24754(allow netutils_wrapper net_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
24755(allow netutils_wrapper net_data_file (file (ioctl read getattr lock map open watch watch_reads)))
24756(allow netutils_wrapper net_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
24757(allow base_typeattr_717 netutils_wrapper_exec (file (read getattr map execute open)))
24758(allow base_typeattr_717 netutils_wrapper (process (transition)))
24759(allow netutils_wrapper netutils_wrapper_exec (file (read getattr map execute open entrypoint)))
24760(allow netutils_wrapper base_typeattr_717 (process (sigchld)))
24761(dontaudit base_typeattr_717 netutils_wrapper (process (noatsecure)))
24762(allow base_typeattr_717 netutils_wrapper (process (siginh rlimitinh)))
24763(typetransition base_typeattr_717 netutils_wrapper_exec process netutils_wrapper)
24764(dontaudit netutils_wrapper self (capability (sys_resource)))
24765(dontaudit netutils_wrapper self (cap_userns (sys_resource)))
24766(dontaudit netutils_wrapper sysfs_type (file (read)))
24767;;* lmx 47 system/sepolicy/private/netutils_wrapper.te
24768
24769(neverallow netutils_wrapper self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
24770(neverallow netutils_wrapper self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
24771;;* lme
24772
24773(typetransition network_stack tmpfs file appdomain_tmpfs)
24774(allow network_stack network_stack_userfaultfd (anon_inode (ioctl read create)))
24775(dontaudit su network_stack_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24776;;* lmx 6 system/sepolicy/private/network_stack.te
24777
24778(neverallow base_typeattr_828 network_stack_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24779;;* lme
24780
24781(allow network_stack appdomain_tmpfs (file (read write getattr map execute)))
24782;;* lmx 6 system/sepolicy/private/network_stack.te
24783
24784(neverallow base_typeattr_829 base_typeattr_828 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24785;;* lme
24786
24787;;* lmx 6 system/sepolicy/private/network_stack.te
24788
24789(neverallow base_typeattr_830 network_stack (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24790;;* lme
24791
24792;;* lmx 6 system/sepolicy/private/network_stack.te
24793
24794(neverallow base_typeattr_831 network_stack (process (ptrace)))
24795;;* lme
24796
24797(allow network_stack self (capability (net_bind_service net_broadcast net_admin net_raw)))
24798(allow network_stack self (cap_userns (net_bind_service net_broadcast net_admin net_raw)))
24799(allow network_stack self (capability2 (wake_alarm)))
24800(allow network_stack self (cap2_userns (wake_alarm)))
24801(allowx network_stack self (ioctl udp_socket (0x6900 0x6902)))
24802(allowx network_stack self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
24803(allowx network_stack self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
24804(allow network_stack self (packet_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24805(allow network_stack self (netlink_route_socket (nlmsg_write)))
24806(allow network_stack self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24807(allow network_stack self (netlink_nflog_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24808(allow network_stack self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24809(allow network_stack self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24810(allow network_stack app_api_service (service_manager (find)))
24811(allow network_stack dnsresolver_service (service_manager (find)))
24812(allow network_stack mdns_service (service_manager (find)))
24813(allow network_stack netd_service (service_manager (find)))
24814(allow network_stack network_watchlist_service (service_manager (find)))
24815(allow network_stack radio_service (service_manager (find)))
24816(allow network_stack system_config_service (service_manager (find)))
24817(allow network_stack radio_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24818(allow network_stack radio_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24819(allow network_stack netd (binder (call transfer)))
24820(allow netd network_stack (binder (transfer)))
24821(allow network_stack netd (fd (use)))
24822(allow network_stack self (key_socket (create)))
24823(dontaudit network_stack self (key_socket (getopt)))
24824(allow network_stack device_config_connectivity_prop (file (read getattr map open)))
24825(allow network_stack self (netlink_tcpdiag_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
24826(allow network_stack self (netlink_netfilter_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
24827(allow network_stack network_stack_service (service_manager (find)))
24828(allow network_stack fs_bpf_tethering (dir (search)))
24829(allow network_stack fs_bpf_net_private (dir (search)))
24830(allow network_stack fs_bpf_net_shared (dir (search)))
24831(allow network_stack fs_bpf_netd_readonly (dir (search)))
24832(allow network_stack fs_bpf_netd_shared (dir (search)))
24833(allow network_stack fs_bpf_tethering (file (read write getattr)))
24834(allow network_stack fs_bpf_net_private (file (read write getattr)))
24835(allow network_stack fs_bpf_net_shared (file (read write getattr)))
24836(allow network_stack fs_bpf_netd_readonly (file (read write getattr)))
24837(allow network_stack fs_bpf_netd_shared (file (read write getattr)))
24838(allow network_stack bpfloader (bpf (map_read map_write prog_run)))
24839(allow network_stack device_config_tethering_u_or_later_native_prop (file (read getattr map open)))
24840(allow network_stack self (netlink_xfrm_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
24841(allow network_stack tun_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
24842(allowx network_stack tun_device (ioctl chr_file (0x54ca 0x54cd 0x54d2 0x54e2)))
24843;;* lmx 83 system/sepolicy/private/network_stack.te
24844
24845(neverallow base_typeattr_668 fs_bpf_net_private (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
24846;;* lme
24847
24848;;* lmx 84 system/sepolicy/private/network_stack.te
24849
24850(neverallow base_typeattr_668 fs_bpf_net_private (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24851;;* lme
24852
24853;;* lmx 87 system/sepolicy/private/network_stack.te
24854
24855(neverallow base_typeattr_669 fs_bpf_net_shared (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
24856;;* lme
24857
24858;;* lmx 88 system/sepolicy/private/network_stack.te
24859
24860(neverallow base_typeattr_669 fs_bpf_net_shared (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24861;;* lme
24862
24863;;* lmx 92 system/sepolicy/private/network_stack.te
24864
24865(neverallow base_typeattr_670 fs_bpf_netd_readonly (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
24866;;* lme
24867
24868;;* lmx 93 system/sepolicy/private/network_stack.te
24869
24870(neverallow base_typeattr_670 fs_bpf_netd_readonly (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24871;;* lme
24872
24873;;* lmx 94 system/sepolicy/private/network_stack.te
24874
24875(neverallow netd fs_bpf_netd_readonly (file (write)))
24876;;* lme
24877
24878;;* lmx 98 system/sepolicy/private/network_stack.te
24879
24880(neverallow base_typeattr_671 fs_bpf_netd_shared (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
24881;;* lme
24882
24883;;* lmx 99 system/sepolicy/private/network_stack.te
24884
24885(neverallow base_typeattr_671 fs_bpf_netd_shared (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24886;;* lme
24887
24888;;* lmx 100 system/sepolicy/private/network_stack.te
24889
24890(neverallow netutils_wrapper fs_bpf_netd_shared (file (write)))
24891;;* lme
24892
24893;;* lmx 103 system/sepolicy/private/network_stack.te
24894
24895(neverallow base_typeattr_668 fs_bpf_tethering (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
24896;;* lme
24897
24898;;* lmx 104 system/sepolicy/private/network_stack.te
24899
24900(neverallow base_typeattr_668 fs_bpf_tethering (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
24901;;* lme
24902
24903(typetransition nfc tmpfs file appdomain_tmpfs)
24904(allow nfc nfc_userfaultfd (anon_inode (ioctl read create)))
24905(dontaudit su nfc_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24906;;* lmx 3 system/sepolicy/private/nfc.te
24907
24908(neverallow base_typeattr_832 nfc_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24909;;* lme
24910
24911(allow nfc appdomain_tmpfs (file (read write getattr map execute)))
24912;;* lmx 3 system/sepolicy/private/nfc.te
24913
24914(neverallow base_typeattr_833 base_typeattr_832 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24915;;* lme
24916
24917;;* lmx 3 system/sepolicy/private/nfc.te
24918
24919(neverallow base_typeattr_834 nfc (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
24920;;* lme
24921
24922;;* lmx 3 system/sepolicy/private/nfc.te
24923
24924(neverallow base_typeattr_835 nfc (process (ptrace)))
24925;;* lme
24926
24927(allow nfc nfc_service (service_manager (add find)))
24928;;* lmx 7 system/sepolicy/private/nfc.te
24929
24930(neverallow base_typeattr_832 nfc_service (service_manager (add)))
24931;;* lme
24932
24933(allow nfc nfc_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24934(allow nfc nfc_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24935(allow nfc nfc_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24936(allow nfc nfc_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24937(allow nfc nfc_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24938(allow nfc nfc_logs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
24939(allow nfc nfc_logs_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24940(allow nfc audioserver_service (service_manager (find)))
24941(allow nfc drmserver_service (service_manager (find)))
24942(allow nfc mediametrics_service (service_manager (find)))
24943(allow nfc mediaextractor_service (service_manager (find)))
24944(allow nfc mediaserver_service (service_manager (find)))
24945(allow nfc radio_service (service_manager (find)))
24946(allow nfc app_api_service (service_manager (find)))
24947(allow nfc system_api_service (service_manager (find)))
24948(allow nfc vr_manager_service (service_manager (find)))
24949(allow nfc secure_element_service (service_manager (find)))
24950(allow nfc property_socket (sock_file (write)))
24951(allow nfc init (unix_stream_socket (connectto)))
24952(allow nfc nfc_prop (property_service (set)))
24953(allow nfc nfc_prop (file (read getattr map open)))
24954(allow nfc shell_data_file (file (read)))
24955(allow odrefresh apex_module_data_file (dir (getattr search)))
24956(allow odrefresh apex_art_data_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
24957(allow odrefresh apex_art_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24958(allow odrefresh odrefresh_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
24959(allow odrefresh odrefresh_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24960(allow odrefresh odrefresh_userfaultfd (anon_inode (ioctl read create)))
24961(dontaudit su odrefresh_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24962;;* lmx 14 system/sepolicy/private/odrefresh.te
24963
24964(neverallow base_typeattr_836 odrefresh_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
24965;;* lme
24966
24967(allow odrefresh apex_art_staging_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
24968(allow odrefresh apex_art_staging_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
24969(allow odrefresh dex2oat_exec (file (read getattr map execute open)))
24970(allow odrefresh dex2oat (process (transition)))
24971(allow dex2oat dex2oat_exec (file (read getattr map execute open entrypoint)))
24972(allow dex2oat odrefresh (process (sigchld)))
24973(dontaudit odrefresh dex2oat (process (noatsecure)))
24974(allow odrefresh dex2oat (process (siginh rlimitinh)))
24975(typetransition odrefresh dex2oat_exec process dex2oat)
24976(allow odrefresh dex2oat (process (sigkill)))
24977(allow odrefresh dexoptanalyzer_exec (file (read getattr map execute open)))
24978(allow odrefresh dexoptanalyzer (process (transition)))
24979(allow dexoptanalyzer dexoptanalyzer_exec (file (read getattr map execute open entrypoint)))
24980(allow dexoptanalyzer odrefresh (process (sigchld)))
24981(dontaudit odrefresh dexoptanalyzer (process (noatsecure)))
24982(allow odrefresh dexoptanalyzer (process (siginh rlimitinh)))
24983(typetransition odrefresh dexoptanalyzer_exec process dexoptanalyzer)
24984(allow odrefresh dexoptanalyzer (process (sigkill)))
24985(allow odrefresh odsign_devpts (chr_file (read write)))
24986(allow odrefresh odsign (fd (use)))
24987(allow odrefresh apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
24988(allow odrefresh property_socket (sock_file (write)))
24989(allow odrefresh init (unix_stream_socket (connectto)))
24990(allow odrefresh bootanim_system_prop (property_service (set)))
24991(allow odrefresh bootanim_system_prop (file (read getattr map open)))
24992(allow odrefresh device_config_runtime_native_prop (file (read getattr map open)))
24993(allow odrefresh device_config_runtime_native_boot_prop (file (read getattr map open)))
24994(dontaudit odrefresh adbd (fd (use)))
24995(dontaudit odrefresh shell (fd (use)))
24996(dontaudit odrefresh devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
24997(dontaudit odrefresh adbd (unix_stream_socket (read write getattr)))
24998;;* lmx 55 system/sepolicy/private/odrefresh.te
24999
25000(neverallow base_typeattr_837 apex_art_staging_data_file (file (open)))
25001;;* lme
25002
25003;;* lmx 59 system/sepolicy/private/odrefresh.te
25004
25005(neverallow base_typeattr_838 odrefresh_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
25006;;* lme
25007
25008;;* lmx 60 system/sepolicy/private/odrefresh.te
25009
25010(neverallow base_typeattr_838 odrefresh_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25011;;* lme
25012
25013(allow init odsign_exec (file (read getattr map execute open)))
25014(allow init odsign (process (transition)))
25015(allow odsign odsign_exec (file (read getattr map execute open entrypoint)))
25016(dontaudit init odsign (process (noatsecure)))
25017(allow init odsign (process (siginh rlimitinh)))
25018(typetransition init odsign_exec process odsign)
25019(allow odsign odsign_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25020(allow odsign odsign_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25021(allow odsign odsign_metrics_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25022(allow odsign odsign_metrics_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25023(typetransition odsign devpts chr_file odsign_devpts)
25024(allow odsign odsign_devpts (chr_file (ioctl read write getattr open)))
25025(allowx odsign odsign_devpts (ioctl chr_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
25026;;* lmx 21 system/sepolicy/private/odsign.te
25027
25028(neverallowx base_typeattr_224 odsign_devpts (ioctl chr_file (0x5412)))
25029;;* lme
25030
25031(allowx odsign apex_art_data_file (ioctl file (0x6601 (range 0x6685 0x6686))))
25032(allow odsign servicemanager (binder (call transfer)))
25033(allow servicemanager odsign (binder (call transfer)))
25034(allow servicemanager odsign (dir (search)))
25035(allow servicemanager odsign (file (read open)))
25036(allow servicemanager odsign (process (getattr)))
25037(allow keystore odsign (dir (search)))
25038(allow keystore odsign (file (read open)))
25039(allow keystore odsign (process (getattr)))
25040(allow odsign apc_service (service_manager (find)))
25041(allow odsign keystore_service (service_manager (find)))
25042(allow odsign legacykeystore_service (service_manager (find)))
25043(allow odsign keystore (binder (call transfer)))
25044(allow keystore odsign (binder (transfer)))
25045(allow odsign keystore (fd (use)))
25046(allow keystore odsign (binder (call transfer)))
25047(allow odsign keystore (binder (transfer)))
25048(allow keystore odsign (fd (use)))
25049(allow odsign odsign_key (keystore2_key (delete get_info rebind use)))
25050(allow odsign apex_module_data_file (dir (getattr search)))
25051(allow odsign apex_art_data_file (dir (ioctl read write getattr lock rename open watch watch_reads add_name remove_name search rmdir)))
25052(allow odsign apex_art_data_file (file (ioctl read write getattr lock append map unlink open watch watch_reads)))
25053(allow odsign odrefresh_exec (file (read getattr map execute open)))
25054(allow odsign odrefresh (process (transition)))
25055(allow odrefresh odrefresh_exec (file (read getattr map execute open entrypoint)))
25056(allow odrefresh odsign (process (sigchld)))
25057(dontaudit odsign odrefresh (process (noatsecure)))
25058(allow odsign odrefresh (process (siginh rlimitinh)))
25059(typetransition odsign odrefresh_exec process odrefresh)
25060(allow odsign fsverity_init_exec (file (read getattr map execute open)))
25061(allow odsign fsverity_init (process (transition)))
25062(allow fsverity_init fsverity_init_exec (file (read getattr map execute open entrypoint)))
25063(allow fsverity_init odsign (process (sigchld)))
25064(dontaudit odsign fsverity_init (process (noatsecure)))
25065(allow odsign fsverity_init (process (siginh rlimitinh)))
25066(typetransition odsign fsverity_init_exec process fsverity_init)
25067(allow odsign compos_verify_exec (file (read getattr map execute open)))
25068(allow odsign compos_verify (process (transition)))
25069(allow compos_verify compos_verify_exec (file (read getattr map execute open entrypoint)))
25070(allow compos_verify odsign (process (sigchld)))
25071(dontaudit odsign compos_verify (process (noatsecure)))
25072(allow odsign compos_verify (process (siginh rlimitinh)))
25073(typetransition odsign compos_verify_exec process compos_verify)
25074(allow odsign property_socket (sock_file (write)))
25075(allow odsign init (unix_stream_socket (connectto)))
25076(allow odsign odsign_prop (property_service (set)))
25077(allow odsign odsign_prop (file (read getattr map open)))
25078;;* lmx 62 system/sepolicy/private/odsign.te
25079
25080(neverallow base_typeattr_839 odsign_prop (property_service (set)))
25081;;* lme
25082
25083(allow odsign property_socket (sock_file (write)))
25084(allow odsign init (unix_stream_socket (connectto)))
25085(allow odsign ctl_odsign_prop (property_service (set)))
25086(allow odsign ctl_odsign_prop (file (read getattr map open)))
25087;;* lmx 68 system/sepolicy/private/odsign.te
25088
25089(neverallow base_typeattr_840 odsign_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
25090;;* lme
25091
25092;;* lmx 69 system/sepolicy/private/odsign.te
25093
25094(neverallow base_typeattr_840 odsign_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25095;;* lme
25096
25097(allow init ot_daemon_exec (file (read getattr map execute open)))
25098(allow init ot_daemon (process (transition)))
25099(allow ot_daemon ot_daemon_exec (file (read getattr map execute open entrypoint)))
25100(dontaudit init ot_daemon (process (noatsecure)))
25101(allow init ot_daemon (process (siginh rlimitinh)))
25102(typetransition init ot_daemon_exec process ot_daemon)
25103(allow ot_daemon apex_module_data_file (dir (search)))
25104(allow ot_daemon apex_tethering_data_file (dir (ioctl read write create getattr lock open watch watch_reads add_name remove_name search)))
25105(allow ot_daemon apex_tethering_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25106(allow ot_daemon tun_device (chr_file (read write)))
25107(allow ot_daemon system_server (rawip_socket (read write getattr setattr lock append map bind connect getopt setopt shutdown)))
25108(allow ot_daemon servicemanager (binder (call transfer)))
25109(allow servicemanager ot_daemon (binder (call transfer)))
25110(allow servicemanager ot_daemon (dir (search)))
25111(allow servicemanager ot_daemon (file (read open)))
25112(allow servicemanager ot_daemon (process (getattr)))
25113(allow ot_daemon ot_daemon_service (service_manager (add find)))
25114;;* lmx 33 system/sepolicy/private/ot_daemon.te
25115
25116(neverallow base_typeattr_841 ot_daemon_service (service_manager (add)))
25117;;* lme
25118
25119(allow ot_daemon system_server (binder (call transfer)))
25120(allow system_server ot_daemon (binder (transfer)))
25121(allow ot_daemon system_server (fd (use)))
25122(allow ot_daemon statsdw_socket (sock_file (write)))
25123(allow ot_daemon statsd (unix_dgram_socket (sendto)))
25124(allow ot_daemon dumpstate (fd (use)))
25125(allow ot_daemon dumpstate (fifo_file (write)))
25126(allow otapreopt_chroot postinstall_file (dir (mounton search)))
25127(allow otapreopt_chroot apex_mnt_dir (dir (mounton)))
25128(allow otapreopt_chroot device (dir (mounton)))
25129(allow otapreopt_chroot linkerconfig_file (dir (mounton)))
25130(allow otapreopt_chroot rootfs (dir (mounton)))
25131(allow otapreopt_chroot sysfs (dir (mounton)))
25132(allow otapreopt_chroot system_data_root_file (dir (mounton)))
25133(allow otapreopt_chroot system_file (dir (mounton)))
25134(allow otapreopt_chroot vendor_file (dir (mounton)))
25135(allow otapreopt_chroot self (capability (sys_chroot sys_admin)))
25136(allow otapreopt_chroot self (cap_userns (sys_chroot sys_admin)))
25137(allow otapreopt_chroot block_device (dir (search)))
25138(allow otapreopt_chroot labeledfs (filesystem (mount unmount)))
25139(allow otapreopt_chroot dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
25140(allow otapreopt_chroot postinstall_file (filesystem (unmount)))
25141(dontaudit otapreopt_chroot kernel (process (setsched)))
25142(allow otapreopt_chroot file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
25143(allow otapreopt_chroot postinstall_file (dir (ioctl read getattr lock open watch watch_reads search)))
25144(allow otapreopt_chroot apexd_prop (file (read getattr map open)))
25145(allow otapreopt_chroot postinstall (fd (use)))
25146(allow otapreopt_chroot postinstall (fifo_file (read write getattr)))
25147(allow otapreopt_chroot update_engine (fd (use)))
25148(allow otapreopt_chroot update_engine (fifo_file (write)))
25149(allow otapreopt_chroot postinstall_dexopt_exec (file (read getattr map execute open)))
25150(allow otapreopt_chroot postinstall_dexopt (process (transition)))
25151(allow postinstall_dexopt postinstall_dexopt_exec (file (read getattr map execute open entrypoint)))
25152(allow postinstall_dexopt otapreopt_chroot (process (sigchld)))
25153(dontaudit otapreopt_chroot postinstall_dexopt (process (noatsecure)))
25154(allow otapreopt_chroot postinstall_dexopt (process (siginh rlimitinh)))
25155(typetransition otapreopt_chroot postinstall_dexopt_exec process postinstall_dexopt)
25156(allow otapreopt_chroot linkerconfig_exec (file (read getattr map execute open)))
25157(allow otapreopt_chroot linkerconfig (process (transition)))
25158(allow linkerconfig linkerconfig_exec (file (read getattr map execute open entrypoint)))
25159(allow linkerconfig otapreopt_chroot (process (sigchld)))
25160(dontaudit otapreopt_chroot linkerconfig (process (noatsecure)))
25161(allow otapreopt_chroot linkerconfig (process (siginh rlimitinh)))
25162(typetransition otapreopt_chroot linkerconfig_exec process linkerconfig)
25163(allow otapreopt_chroot apexd_exec (file (read getattr map execute open)))
25164(allow otapreopt_chroot apexd (process (transition)))
25165(allow apexd apexd_exec (file (read getattr map execute open entrypoint)))
25166(allow apexd otapreopt_chroot (process (sigchld)))
25167(dontaudit otapreopt_chroot apexd (process (noatsecure)))
25168(allow otapreopt_chroot apexd (process (siginh rlimitinh)))
25169(typetransition otapreopt_chroot apexd_exec process apexd)
25170(allow otapreopt_chroot linkerconfig_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
25171(allow otapreopt_chroot linkerconfig_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25172(allow otapreopt_chroot loop_control_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
25173(allow otapreopt_chroot loop_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
25174(allowx otapreopt_chroot loop_device (ioctl blk_file (0x1261)))
25175(allowx otapreopt_chroot loop_device (ioctl blk_file ((range 0x4c00 0x4c01) (range 0x4c04 0x4c05) (range 0x4c08 0x4c0a))))
25176(allow otapreopt_chroot sysfs_loop (dir (ioctl read getattr lock open watch watch_reads search)))
25177(allow otapreopt_chroot sysfs_loop (file (ioctl read write getattr lock append map open watch watch_reads)))
25178(allow otapreopt_chroot tmpfs (filesystem (mount)))
25179(allow otapreopt_chroot tmpfs (dir (relabelfrom)))
25180(allow otapreopt_chroot postinstall_apex_mnt_dir (dir (relabelto)))
25181(allow otapreopt_chroot postinstall_apex_mnt_dir (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25182(allow otapreopt_chroot postinstall_apex_mnt_dir (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25183(allow otapreopt_chroot postinstall_apex_mnt_dir (dir (mounton)))
25184(allow otapreopt_chroot block_device (dir (ioctl read getattr lock open watch watch_reads search)))
25185(allow otapreopt_chroot postinstall_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25186(allow otapreopt_chroot cold_boot_done_prop (file (read getattr map open)))
25187(allow otapreopt_chroot linkerconfig_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
25188(allow init otapreopt_slot_exec (file (read getattr map execute open)))
25189(allow init otapreopt_slot (process (transition)))
25190(allow otapreopt_slot otapreopt_slot_exec (file (read getattr map execute open entrypoint)))
25191(dontaudit init otapreopt_slot (process (noatsecure)))
25192(allow init otapreopt_slot (process (siginh rlimitinh)))
25193(typetransition init otapreopt_slot_exec process otapreopt_slot)
25194(allow otapreopt_slot ota_data_file (dir (ioctl read write getattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25195(allow otapreopt_slot ota_data_file (file (getattr)))
25196(allow otapreopt_slot ota_data_file (lnk_file (getattr)))
25197(allow otapreopt_slot ota_data_file (lnk_file (read)))
25198(allow otapreopt_slot dalvikcache_data_file (dir (read write getattr open add_name remove_name search rmdir)))
25199(allow otapreopt_slot dalvikcache_data_file (file (getattr unlink)))
25200(allow otapreopt_slot dalvikcache_data_file (lnk_file (read getattr unlink)))
25201(allow otapreopt_slot shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
25202(allow otapreopt_slot toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
25203(typetransition perfetto tmpfs file perfetto_tmpfs)
25204(allow perfetto perfetto_tmpfs (file (read write getattr map)))
25205(allow init perfetto_exec (file (read getattr map execute open)))
25206(allow init perfetto (process (transition)))
25207(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
25208(dontaudit init perfetto (process (noatsecure)))
25209(allow init perfetto (process (siginh rlimitinh)))
25210(typetransition init perfetto_exec process perfetto)
25211(allow perfetto traced_consumer_socket (sock_file (write)))
25212(allow perfetto traced (unix_stream_socket (connectto)))
25213(allow perfetto traced (fd (use)))
25214(allow perfetto traced_tmpfs (file (read write getattr map)))
25215(allow perfetto traced_producer_socket (sock_file (write)))
25216(allow perfetto traced (unix_stream_socket (connectto)))
25217(allow traced perfetto (fd (use)))
25218(allow perfetto perfetto_traces_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25219(allow perfetto perfetto_traces_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25220(allow perfetto perfetto_traces_bugreport_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25221(allow perfetto perfetto_traces_bugreport_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25222(allow perfetto perfetto_traces_profiling_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25223(allow perfetto perfetto_traces_profiling_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25224(allow perfetto tracingproxy_service (service_manager (find)))
25225(allow perfetto servicemanager (binder (call transfer)))
25226(allow servicemanager perfetto (binder (call transfer)))
25227(allow servicemanager perfetto (dir (search)))
25228(allow servicemanager perfetto (file (read open)))
25229(allow servicemanager perfetto (process (getattr)))
25230(allow perfetto system_server (binder (call transfer)))
25231(allow system_server perfetto (binder (transfer)))
25232(allow perfetto system_server (fd (use)))
25233(allow perfetto perfetto_configs_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25234(allow perfetto perfetto_configs_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25235(allow perfetto shell (fd (use)))
25236(allow perfetto statsd (fd (use)))
25237(allow perfetto su (fd (use)))
25238(allow perfetto mm_events (fd (use)))
25239(allow perfetto shell (fifo_file (ioctl read write getattr)))
25240(allow perfetto statsd (fifo_file (ioctl read write getattr)))
25241(allow perfetto su (fifo_file (ioctl read write getattr)))
25242(allow perfetto system_server (fifo_file (ioctl read write getattr)))
25243(allow perfetto mm_events (fifo_file (ioctl read write getattr)))
25244(allow perfetto adbd (fd (use)))
25245(allow perfetto adbd (unix_stream_socket (read write)))
25246(allow perfetto adbd (process (sigchld)))
25247(allow perfetto statsdw_socket (sock_file (write)))
25248(allow perfetto statsd (unix_dgram_socket (sendto)))
25249(allow perfetto devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
25250(allow perfetto incident_service (service_manager (find)))
25251(allow perfetto incidentd (binder (call transfer)))
25252(allow incidentd perfetto (binder (transfer)))
25253(allow perfetto incidentd (fd (use)))
25254(dontaudit perfetto adbd (unix_stream_socket (getattr)))
25255(dontauditx perfetto adbd (ioctl unix_stream_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
25256(dontauditx perfetto su (ioctl unix_stream_socket ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
25257(dontauditx perfetto shell (ioctl fifo_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
25258;;* lmx 94 system/sepolicy/private/perfetto.te
25259
25260(neverallow base_typeattr_842 perfetto_traces_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
25261;;* lme
25262
25263;;* lmx 103 system/sepolicy/private/perfetto.te
25264
25265(neverallow base_typeattr_843 perfetto_traces_data_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25266;;* lme
25267
25268;;* lmx 109 system/sepolicy/private/perfetto.te
25269
25270(neverallow perfetto self (process (execmem)))
25271;;* lme
25272
25273;;* lmx 112 system/sepolicy/private/perfetto.te
25274
25275(neverallow perfetto dev_type (blk_file (read write)))
25276;;* lme
25277
25278;;* lmx 115 system/sepolicy/private/perfetto.te
25279
25280(neverallow perfetto domain (process (ptrace)))
25281;;* lme
25282
25283;;* lmx 133 system/sepolicy/private/perfetto.te
25284
25285(neverallow perfetto base_typeattr_844 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
25286;;* lme
25287
25288;;* lmx 138 system/sepolicy/private/perfetto.te
25289
25290(neverallow perfetto base_typeattr_845 (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
25291;;* lme
25292
25293;;* lmx 146 system/sepolicy/private/perfetto.te
25294
25295(neverallow perfetto base_typeattr_846 (file (ioctl read create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25296;;* lme
25297
25298(allow init performanced_exec (file (read getattr map execute open)))
25299(allow init performanced (process (transition)))
25300(allow performanced performanced_exec (file (read getattr map execute open entrypoint)))
25301(dontaudit init performanced (process (noatsecure)))
25302(allow init performanced (process (siginh rlimitinh)))
25303(typetransition init performanced_exec process performanced)
25304(typetransition permissioncontroller_app tmpfs file appdomain_tmpfs)
25305(allow permissioncontroller_app permissioncontroller_app_userfaultfd (anon_inode (ioctl read create)))
25306(dontaudit su permissioncontroller_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25307;;* lmx 6 system/sepolicy/private/permissioncontroller_app.te
25308
25309(neverallow base_typeattr_847 permissioncontroller_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25310;;* lme
25311
25312(allow permissioncontroller_app appdomain_tmpfs (file (read write getattr map execute)))
25313;;* lmx 6 system/sepolicy/private/permissioncontroller_app.te
25314
25315(neverallow base_typeattr_848 base_typeattr_847 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25316;;* lme
25317
25318;;* lmx 6 system/sepolicy/private/permissioncontroller_app.te
25319
25320(neverallow base_typeattr_849 permissioncontroller_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25321;;* lme
25322
25323;;* lmx 6 system/sepolicy/private/permissioncontroller_app.te
25324
25325(neverallow base_typeattr_850 permissioncontroller_app (process (ptrace)))
25326;;* lme
25327
25328(allow permissioncontroller_app app_api_service (service_manager (find)))
25329(allow permissioncontroller_app system_api_service (service_manager (find)))
25330(allow permissioncontroller_app gpuservice (binder (call transfer)))
25331(allow gpuservice permissioncontroller_app (binder (transfer)))
25332(allow permissioncontroller_app gpuservice (fd (use)))
25333(allow permissioncontroller_app radio_service (service_manager (find)))
25334(allow permissioncontroller_app incident_service (service_manager (find)))
25335(allow permissioncontroller_app incidentd (binder (call transfer)))
25336(allow incidentd permissioncontroller_app (binder (transfer)))
25337(allow permissioncontroller_app incidentd (fd (use)))
25338(allow permissioncontroller_app incidentd (fifo_file (read write)))
25339(allow permissioncontroller_app gpu_device (dir (search)))
25340(typetransition platform_app tmpfs file appdomain_tmpfs)
25341(allow platform_app platform_app_userfaultfd (anon_inode (ioctl read create)))
25342(dontaudit su platform_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25343;;* lmx 7 system/sepolicy/private/platform_app.te
25344
25345(neverallow base_typeattr_851 platform_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25346;;* lme
25347
25348(allow platform_app appdomain_tmpfs (file (read write getattr map execute)))
25349;;* lmx 7 system/sepolicy/private/platform_app.te
25350
25351(neverallow base_typeattr_852 base_typeattr_851 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25352;;* lme
25353
25354;;* lmx 7 system/sepolicy/private/platform_app.te
25355
25356(neverallow base_typeattr_853 platform_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25357;;* lme
25358
25359;;* lmx 7 system/sepolicy/private/platform_app.te
25360
25361(neverallow base_typeattr_854 platform_app (process (ptrace)))
25362;;* lme
25363
25364(allow platform_app shell_data_file (dir (search)))
25365(allow platform_app shell_data_file (file (read getattr open)))
25366(allow platform_app icon_file (file (read getattr open)))
25367(allow platform_app apk_tmp_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25368(allow platform_app apk_private_tmp_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25369(allow platform_app apk_tmp_file (file (ioctl read write getattr lock append map open watch watch_reads)))
25370(allow platform_app apk_private_tmp_file (file (ioctl read write getattr lock append map open watch watch_reads)))
25371(allow platform_app apk_private_data_file (dir (search)))
25372(allow platform_app asec_apk_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25373(allow platform_app asec_apk_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25374(allow platform_app media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25375(allow platform_app media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25376(allow platform_app cache_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25377(allow platform_app cache_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25378(allow platform_app mnt_media_rw_file (dir (ioctl read getattr lock open watch watch_reads search)))
25379(allow platform_app sdcard_type (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25380(allow platform_app sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25381(allow platform_app rootfs (dir (getattr)))
25382(allow platform_app radio_cdma_ecm_prop (file (read getattr map open)))
25383;;* lmx 46 system/sepolicy/private/platform_app.te
25384
25385(neverallow base_typeattr_855 persist_wm_debug_prop (property_service (set)))
25386;;* lme
25387
25388(allow platform_app proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
25389(allow platform_app proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
25390(allow platform_app proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
25391(allow platform_app proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25392(allow platform_app audioserver_service (service_manager (find)))
25393(allow platform_app cameraserver_service (service_manager (find)))
25394(allow platform_app drmserver_service (service_manager (find)))
25395(allow platform_app mediaserver_service (service_manager (find)))
25396(allow platform_app mediametrics_service (service_manager (find)))
25397(allow platform_app mediaextractor_service (service_manager (find)))
25398(allow platform_app mediadrmserver_service (service_manager (find)))
25399(allow platform_app persistent_data_block_service (service_manager (find)))
25400(allow platform_app radio_service (service_manager (find)))
25401(allow platform_app thermal_service (service_manager (find)))
25402(allow platform_app app_api_service (service_manager (find)))
25403(allow platform_app system_api_service (service_manager (find)))
25404(allow platform_app vr_manager_service (service_manager (find)))
25405(allow platform_app stats_service (service_manager (find)))
25406(allow platform_app statsd (binder (call transfer)))
25407(allow statsd platform_app (binder (transfer)))
25408(allow platform_app statsd (fd (use)))
25409(allow platform_app preloads_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25410(allow platform_app preloads_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25411(allow platform_app preloads_media_file (file (ioctl read getattr lock map open watch watch_reads)))
25412(allow platform_app preloads_media_file (dir (ioctl read getattr lock open watch watch_reads search)))
25413(allow platform_app runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
25414(allow platform_app system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
25415(allow platform_app property_socket (sock_file (write)))
25416(allow platform_app init (unix_stream_socket (connectto)))
25417(allow platform_app test_boot_reason_prop (property_service (set)))
25418(allow platform_app test_boot_reason_prop (file (read getattr map open)))
25419(allow platform_app keyguard_config_prop (file (read getattr map open)))
25420(allow platform_app qemu_hw_prop (file (read getattr map open)))
25421(allow platform_app last_boot_reason_prop (file (read getattr map open)))
25422(allow platform_app app_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25423(dontaudit platform_app debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
25424(allow platform_app virtualizationmanager_exec (file (read getattr map execute open)))
25425(allow platform_app virtualizationmanager (process (transition)))
25426(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
25427(allow virtualizationmanager platform_app (process (sigchld)))
25428(dontaudit platform_app virtualizationmanager (process (noatsecure)))
25429(allow platform_app virtualizationmanager (process (siginh rlimitinh)))
25430(typetransition platform_app virtualizationmanager_exec process virtualizationmanager)
25431(allow crosvm platform_app (unix_stream_socket (ioctl read write getattr)))
25432(allow virtualizationmanager platform_app (unix_stream_socket (ioctl read write getattr)))
25433(allow crosvm platform_app (fd (use)))
25434(allow virtualizationmanager platform_app (fd (use)))
25435(allow platform_app virtualizationmanager (fd (use)))
25436(allow crosvm platform_app (fifo_file (ioctl read write getattr)))
25437(allow virtualizationmanager platform_app (fifo_file (ioctl read write getattr)))
25438(allow platform_app virtualizationmanager (vsock_socket (read write getattr getopt)))
25439(allow platform_app hypervisor_prop (file (read getattr map open)))
25440(allow platform_app virtualizationservice_data_file (file (read getattr)))
25441;;* lmx 135 system/sepolicy/private/platform_app.te
25442
25443(neverallow base_typeattr_223 persist_sysui_builder_extras_prop (property_service (set)))
25444;;* lme
25445
25446;;* lmx 138 system/sepolicy/private/platform_app.te
25447
25448(neverallow platform_app fuse_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25449;;* lme
25450
25451(allow postinstall otapreopt_chroot_exec (file (read getattr map execute open)))
25452(allow postinstall otapreopt_chroot (process (transition)))
25453(allow otapreopt_chroot otapreopt_chroot_exec (file (read getattr map execute open entrypoint)))
25454(allow otapreopt_chroot postinstall (process (sigchld)))
25455(dontaudit postinstall otapreopt_chroot (process (noatsecure)))
25456(allow postinstall otapreopt_chroot (process (siginh rlimitinh)))
25457(typetransition postinstall otapreopt_chroot_exec process otapreopt_chroot)
25458(allow postinstall rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
25459(allow postinstall_dexopt dex2oat_exec (file (read getattr map execute open)))
25460(allow postinstall_dexopt dex2oat (process (transition)))
25461(allow dex2oat dex2oat_exec (file (read getattr map execute open entrypoint)))
25462(allow dex2oat postinstall_dexopt (process (sigchld)))
25463(dontaudit postinstall_dexopt dex2oat (process (noatsecure)))
25464(allow postinstall_dexopt dex2oat (process (siginh rlimitinh)))
25465(typetransition postinstall_dexopt dex2oat_exec process dex2oat)
25466(allow postinstall_dexopt postinstall_file (file (read getattr map execute open)))
25467(allow postinstall_dexopt dex2oat (process (transition)))
25468(allow dex2oat postinstall_file (file (read getattr map execute open entrypoint)))
25469(allow dex2oat postinstall_dexopt (process (sigchld)))
25470(dontaudit postinstall_dexopt dex2oat (process (noatsecure)))
25471(allow postinstall_dexopt dex2oat (process (siginh rlimitinh)))
25472(typetransition postinstall_dexopt postinstall_file process dex2oat)
25473(allow postinstall_dexopt derive_classpath_exec (file (read getattr map execute open)))
25474(allow postinstall_dexopt derive_classpath (process (transition)))
25475(allow derive_classpath derive_classpath_exec (file (read getattr map execute open entrypoint)))
25476(allow derive_classpath postinstall_dexopt (process (sigchld)))
25477(dontaudit postinstall_dexopt derive_classpath (process (noatsecure)))
25478(allow postinstall_dexopt derive_classpath (process (siginh rlimitinh)))
25479(typetransition postinstall_dexopt derive_classpath_exec process derive_classpath)
25480(typetransition postinstall_dexopt tmpfs file postinstall_dexopt_tmpfs)
25481(allow postinstall_dexopt postinstall_dexopt_tmpfs (file (read write getattr map)))
25482(allow postinstall_dexopt postinstall_dexopt_tmpfs (file (open)))
25483(allow postinstall_dexopt self (capability (chown dac_override dac_read_search fowner fsetid setgid setuid)))
25484(allow postinstall_dexopt self (cap_userns (chown dac_override dac_read_search fowner fsetid setgid setuid)))
25485(allow postinstall_dexopt postinstall_file (filesystem (getattr)))
25486(allow postinstall_dexopt postinstall_file (dir (read getattr search)))
25487(allow postinstall_dexopt postinstall_file (lnk_file (read getattr)))
25488(allow postinstall_dexopt proc_filesystems (file (read getattr open)))
25489(allow postinstall_dexopt rootfs (file (ioctl read getattr lock map open watch watch_reads)))
25490(allow postinstall_dexopt tmpfs (file (read)))
25491(allow postinstall_dexopt odsign_prop (file (read getattr map open)))
25492(allow postinstall_dexopt postinstall_apex_mnt_dir (dir (getattr search)))
25493(allow postinstall_dexopt apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25494(allow postinstall_dexopt apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25495(allow postinstall_dexopt apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25496(allow postinstall_dexopt vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
25497(allow postinstall_dexopt vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
25498(allow postinstall_dexopt vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25499(allow postinstall_dexopt vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
25500(allow postinstall_dexopt vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
25501(allow postinstall_dexopt vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25502(allow postinstall_dexopt vendor_apex_metadata_file (dir (getattr search)))
25503(allow postinstall_dexopt dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25504(allow postinstall_dexopt dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25505(allow postinstall_dexopt dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25506(allow postinstall_dexopt user_profile_root_file (dir (getattr search)))
25507(allow postinstall_dexopt user_profile_data_file (dir (getattr search)))
25508(allow postinstall_dexopt user_profile_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25509(dontaudit postinstall_dexopt user_profile_data_file (file (write)))
25510(allow postinstall_dexopt ota_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25511(allow postinstall_dexopt ota_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25512(allow postinstall_dexopt ota_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25513(allow postinstall_dexopt dalvikcache_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
25514(allow postinstall_dexopt dalvikcache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25515(allow postinstall_dexopt dalvikcache_data_file (dir (relabelto)))
25516(allow postinstall_dexopt dalvikcache_data_file (file (relabelto link)))
25517(allow postinstall_dexopt selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
25518(allow postinstall_dexopt selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
25519(allow postinstall_dexopt selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25520(allow postinstall_dexopt selinuxfs (file (write lock append map open)))
25521(allow postinstall_dexopt kernel (security (check_context)))
25522(allow postinstall_dexopt selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
25523(allow postinstall_dexopt selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
25524(allow postinstall_dexopt selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25525(allow postinstall_dexopt selinuxfs (file (write lock append map open)))
25526(allow postinstall_dexopt kernel (security (compute_av)))
25527(allow postinstall_dexopt self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25528(allow postinstall_dexopt postinstall (process (sigchld)))
25529(allow postinstall_dexopt otapreopt_chroot (fd (use)))
25530(allow postinstall_dexopt device_config_runtime_native_prop (file (read getattr map open)))
25531(allow postinstall_dexopt device_config_runtime_native_boot_prop (file (read getattr map open)))
25532(allow init preloads_copy_exec (file (read getattr map execute open)))
25533(allow init preloads_copy (process (transition)))
25534(allow preloads_copy preloads_copy_exec (file (read getattr map execute open entrypoint)))
25535(dontaudit init preloads_copy (process (noatsecure)))
25536(allow init preloads_copy (process (siginh rlimitinh)))
25537(typetransition init preloads_copy_exec process preloads_copy)
25538(allow preloads_copy shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
25539(allow preloads_copy toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
25540(allow preloads_copy preloads_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25541(allow preloads_copy preloads_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25542(allow preloads_copy preloads_media_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25543(allow preloads_copy preloads_media_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25544(allow preloads_copy system_file (dir (ioctl read getattr lock open watch watch_reads search)))
25545(dontaudit preloads_copy postinstall_mnt_dir (dir (search)))
25546(allow preopt2cachename cppreopts (fd (use)))
25547(allow preopt2cachename cppreopts (fifo_file (read write getattr)))
25548(allow preopt2cachename proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
25549(typetransition priv_app tmpfs file appdomain_tmpfs)
25550(allow priv_app priv_app_userfaultfd (anon_inode (ioctl read create)))
25551(dontaudit su priv_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25552;;* lmx 6 system/sepolicy/private/priv_app.te
25553
25554(neverallow base_typeattr_856 priv_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
25555;;* lme
25556
25557(allow priv_app appdomain_tmpfs (file (read write getattr map execute)))
25558;;* lmx 6 system/sepolicy/private/priv_app.te
25559
25560(neverallow base_typeattr_857 base_typeattr_856 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25561;;* lme
25562
25563;;* lmx 6 system/sepolicy/private/priv_app.te
25564
25565(neverallow base_typeattr_858 priv_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25566;;* lme
25567
25568;;* lmx 6 system/sepolicy/private/priv_app.te
25569
25570(neverallow base_typeattr_859 priv_app (process (ptrace)))
25571;;* lme
25572
25573(typetransition priv_app devpts chr_file priv_app_devpts)
25574(allow priv_app priv_app_devpts (chr_file (ioctl read write getattr open)))
25575(allowx priv_app priv_app_devpts (ioctl chr_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
25576;;* lmx 15 system/sepolicy/private/priv_app.te
25577
25578(neverallowx base_typeattr_224 priv_app_devpts (ioctl chr_file (0x5412)))
25579;;* lme
25580
25581(allow priv_app privapp_data_file (file (execute)))
25582(allow priv_app system_linker_exec (file (execute_no_trans)))
25583(allow priv_app privapp_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25584(allow priv_app app_api_service (service_manager (find)))
25585(allow priv_app system_api_service (service_manager (find)))
25586(allow priv_app audioserver_service (service_manager (find)))
25587(allow priv_app cameraserver_service (service_manager (find)))
25588(allow priv_app drmserver_service (service_manager (find)))
25589(allow priv_app mediadrmserver_service (service_manager (find)))
25590(allow priv_app mediaextractor_service (service_manager (find)))
25591(allow priv_app mediametrics_service (service_manager (find)))
25592(allow priv_app mediaserver_service (service_manager (find)))
25593(allow priv_app music_recognition_service (service_manager (find)))
25594(allow priv_app network_watchlist_service (service_manager (find)))
25595(allow priv_app nfc_service (service_manager (find)))
25596(allow priv_app oem_lock_service (service_manager (find)))
25597(allow priv_app persistent_data_block_service (service_manager (find)))
25598(allow priv_app radio_service (service_manager (find)))
25599(allow priv_app recovery_service (service_manager (find)))
25600(allow priv_app stats_service (service_manager (find)))
25601(allow priv_app cache_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25602(allow priv_app cache_recovery_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25603(allow priv_app cache_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25604(allow priv_app cache_recovery_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25605(allow priv_app cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25606(allow priv_app media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
25607(allow priv_app media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
25608(allow priv_app shell_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25609(allow priv_app shell_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25610(allow priv_app trace_data_file (file (read getattr)))
25611(allow priv_app wm_trace_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25612(allow priv_app wm_trace_data_file (file (getattr)))
25613(allow priv_app perfetto_traces_bugreport_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25614(allow priv_app perfetto_traces_bugreport_data_file (file (getattr)))
25615(allow priv_app perfetto_traces_data_file (dir (search)))
25616(allow priv_app perfetto (fd (use)))
25617(allow priv_app perfetto_traces_data_file (file (read getattr)))
25618(allow priv_app apk_tmp_file (dir (ioctl read getattr lock open watch watch_reads search)))
25619(allow priv_app apk_private_tmp_file (dir (ioctl read getattr lock open watch watch_reads search)))
25620(allow priv_app apk_tmp_file (file (ioctl read getattr lock map open watch watch_reads)))
25621(allow priv_app apk_private_tmp_file (file (ioctl read getattr lock map open watch watch_reads)))
25622(allow priv_app vold (fd (use)))
25623(allow priv_app fuse_device (chr_file (read write)))
25624(allow priv_app proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
25625(allow priv_app sysfs_type (dir (search)))
25626(allow priv_app sysfs_zram (dir (ioctl read getattr lock open watch watch_reads search)))
25627(allow priv_app sysfs_zram (file (ioctl read getattr lock map open watch watch_reads)))
25628(allow priv_app sysfs_zram (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25629(allow priv_app rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
25630(allow priv_app rootfs (file (ioctl read getattr lock map open watch watch_reads)))
25631(allow priv_app rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
25632(allow priv_app statsd (binder (call transfer)))
25633(allow statsd priv_app (binder (transfer)))
25634(allow priv_app statsd (fd (use)))
25635(allow priv_app ringtone_file (file (read write getattr)))
25636(allow priv_app preloads_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25637(allow priv_app preloads_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25638(allow priv_app preloads_media_file (file (ioctl read getattr lock map open watch watch_reads)))
25639(allow priv_app preloads_media_file (dir (ioctl read getattr lock open watch watch_reads search)))
25640(allow priv_app runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
25641(allow priv_app incident_service (service_manager (find)))
25642(allow priv_app incidentd (binder (call transfer)))
25643(allow incidentd priv_app (binder (transfer)))
25644(allow priv_app incidentd (fd (use)))
25645(allow priv_app incidentd (fifo_file (read write)))
25646(allow priv_app dynamic_system_prop (file (read getattr map open)))
25647(dontaudit priv_app exec_type (file (getattr)))
25648(dontaudit priv_app device (dir (read)))
25649(dontaudit priv_app fs_bpf (dir (search)))
25650(dontaudit priv_app net_dns_prop (file (read)))
25651(dontaudit priv_app proc (file (read)))
25652(dontaudit priv_app proc_interrupts (file (read)))
25653(dontaudit priv_app proc_modules (file (read)))
25654(dontaudit priv_app proc_net (file (read)))
25655(dontaudit priv_app proc_stat (file (read)))
25656(dontaudit priv_app proc_version (file (read)))
25657(dontaudit priv_app sysfs (dir (read)))
25658(dontaudit priv_app sysfs (file (read)))
25659(dontaudit priv_app sysfs_android_usb (file (read)))
25660(dontaudit priv_app sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
25661(dontaudit priv_app wifi_config_prop (file (read)))
25662(dontaudit priv_app wifi_hal_prop (file (read)))
25663(dontaudit priv_app wifi_prop (file (read)))
25664(allow priv_app system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
25665(allowx priv_app apk_data_file (ioctl file ((range 0x671f 0x6720) 0x6722 0x6724)))
25666(allow priv_app incremental_control_file (file (ioctl read getattr)))
25667(allowx priv_app incremental_control_file (ioctl file (0x6721)))
25668(allow priv_app incremental_prop (file (read getattr map open)))
25669(allow priv_app device_config_aconfig_flags_prop (file (read getattr map open)))
25670(allow priv_app system_boot_reason_prop (file (read getattr map open)))
25671(allow priv_app apex_data_file (dir (search)))
25672(allow priv_app staging_data_file (file (ioctl read getattr lock map open watch watch_reads)))
25673(allow priv_app staging_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
25674(allow priv_app vendor_apex_file (dir (ioctl read getattr lock open watch watch_reads search)))
25675(allow priv_app vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
25676(allow priv_app system_app_data_file (file (read getattr)))
25677(allow priv_app rs_exec (file (read getattr map execute open)))
25678(allow priv_app rs (process (transition)))
25679(allow rs rs_exec (file (read getattr map execute open entrypoint)))
25680(allow rs priv_app (process (sigchld)))
25681(dontaudit priv_app rs (process (noatsecure)))
25682(allow priv_app rs (process (siginh rlimitinh)))
25683(typetransition priv_app rs_exec process rs)
25684(allow priv_app app_exec_data_file (file (ioctl read getattr lock map unlink execute open watch watch_reads)))
25685(allow priv_app virtualizationmanager_exec (file (read getattr map execute open)))
25686(allow priv_app virtualizationmanager (process (transition)))
25687(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
25688(allow virtualizationmanager priv_app (process (sigchld)))
25689(dontaudit priv_app virtualizationmanager (process (noatsecure)))
25690(allow priv_app virtualizationmanager (process (siginh rlimitinh)))
25691(typetransition priv_app virtualizationmanager_exec process virtualizationmanager)
25692(allow crosvm priv_app (unix_stream_socket (ioctl read write getattr)))
25693(allow virtualizationmanager priv_app (unix_stream_socket (ioctl read write getattr)))
25694(allow crosvm priv_app (fd (use)))
25695(allow virtualizationmanager priv_app (fd (use)))
25696(allow priv_app virtualizationmanager (fd (use)))
25697(allow crosvm priv_app (fifo_file (ioctl read write getattr)))
25698(allow virtualizationmanager priv_app (fifo_file (ioctl read write getattr)))
25699(allow priv_app virtualizationmanager (vsock_socket (read write getattr getopt)))
25700(allow priv_app hypervisor_prop (file (read getattr map open)))
25701(allow priv_app virtualizationservice_data_file (file (read getattr)))
25702;;* lmx 217 system/sepolicy/private/priv_app.te
25703
25704(neverallow priv_app domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25705;;* lme
25706
25707;;* lmx 220 system/sepolicy/private/priv_app.te
25708
25709(neverallow priv_app domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25710;;* lme
25711
25712;;* lmx 223 system/sepolicy/private/priv_app.te
25713
25714(neverallow priv_app kmsg_device (chr_file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25715;;* lme
25716
25717;;* lmx 227 system/sepolicy/private/priv_app.te
25718
25719(neverallow priv_app debugfs_type (file (read)))
25720;;* lme
25721
25722;;* lmx 232 system/sepolicy/private/priv_app.te
25723
25724(neverallow priv_app service_manager_type (service_manager (add)))
25725;;* lme
25726
25727;;* lmx 236 system/sepolicy/private/priv_app.te
25728
25729(neverallow priv_app property_socket (sock_file (write)))
25730;;* lme
25731
25732;;* lmx 237 system/sepolicy/private/priv_app.te
25733
25734(neverallow priv_app init (unix_stream_socket (connectto)))
25735;;* lme
25736
25737;;* lmx 238 system/sepolicy/private/priv_app.te
25738
25739(neverallow priv_app property_type (property_service (set)))
25740;;* lme
25741
25742;;* lmx 248 system/sepolicy/private/priv_app.te
25743
25744(neverallow priv_app mlstrustedsubject (process (fork)))
25745;;* lme
25746
25747;;* lmx 256 system/sepolicy/private/priv_app.te
25748
25749(neverallow priv_app file_type (file (link)))
25750;;* lme
25751
25752;;* lmx 260 system/sepolicy/private/priv_app.te
25753
25754(neverallow priv_app trace_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
25755;;* lme
25756
25757;;* lmx 261 system/sepolicy/private/priv_app.te
25758
25759(neverallow priv_app trace_data_file (file (write create setattr relabelfrom append unlink link rename open)))
25760;;* lme
25761
25762;;* lmx 264 system/sepolicy/private/priv_app.te
25763
25764(neverallow priv_app cgroup (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25765;;* lme
25766
25767;;* lmx 265 system/sepolicy/private/priv_app.te
25768
25769(neverallow priv_app cgroup_v2 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25770;;* lme
25771
25772;;* lmx 271 system/sepolicy/private/priv_app.te
25773
25774(neverallow priv_app base_typeattr_860 (file (execute execute_no_trans)))
25775;;* lme
25776
25777;;* lmx 274 system/sepolicy/private/priv_app.te
25778
25779(neverallow priv_app base_typeattr_860 (lnk_file (read getattr open)))
25780;;* lme
25781
25782;;* lmx 277 system/sepolicy/private/priv_app.te
25783
25784(neverallow priv_app sysfs_net (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
25785;;* lme
25786
25787;;* lmx 281 system/sepolicy/private/priv_app.te
25788
25789(neverallowx priv_app domain (ioctl tcp_socket (0x6900 0x6902)))
25790(neverallowx priv_app domain (ioctl udp_socket (0x6900 0x6902)))
25791(neverallowx priv_app domain (ioctl rawip_socket (0x6900 0x6902)))
25792(neverallowx priv_app domain (ioctl icmp_socket (0x6900 0x6902)))
25793;;* lme
25794
25795;;* lmx 281 system/sepolicy/private/priv_app.te
25796
25797(neverallowx priv_app domain (ioctl tcp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
25798(neverallowx priv_app domain (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
25799(neverallowx priv_app domain (ioctl rawip_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
25800(neverallowx priv_app domain (ioctl icmp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
25801;;* lme
25802
25803;;* lmx 281 system/sepolicy/private/priv_app.te
25804
25805(neverallowx priv_app domain (ioctl tcp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
25806(neverallowx priv_app domain (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
25807(neverallowx priv_app domain (ioctl rawip_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
25808(neverallowx priv_app domain (ioctl icmp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
25809;;* lme
25810
25811;;* lmx 282 system/sepolicy/private/priv_app.te
25812
25813(neverallow priv_app base_typeattr_224 (netlink_route_socket (ioctl)))
25814(neverallow priv_app base_typeattr_224 (netlink_selinux_socket (ioctl)))
25815;;* lme
25816
25817;;* lmx 295 system/sepolicy/private/priv_app.te
25818
25819(neverallow priv_app base_typeattr_224 (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25820(neverallow priv_app base_typeattr_224 (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25821(neverallow priv_app base_typeattr_224 (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25822(neverallow priv_app base_typeattr_224 (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25823(neverallow priv_app base_typeattr_224 (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
25824(neverallow priv_app base_typeattr_224 (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25825(neverallow priv_app base_typeattr_224 (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
25826(neverallow priv_app base_typeattr_224 (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
25827(neverallow priv_app base_typeattr_224 (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25828(neverallow priv_app base_typeattr_224 (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25829(neverallow priv_app base_typeattr_224 (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25830(neverallow priv_app base_typeattr_224 (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
25831(neverallow priv_app base_typeattr_224 (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25832(neverallow priv_app base_typeattr_224 (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25833(neverallow priv_app base_typeattr_224 (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25834(neverallow priv_app base_typeattr_224 (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25835(neverallow priv_app base_typeattr_224 (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25836(neverallow priv_app base_typeattr_224 (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25837(neverallow priv_app base_typeattr_224 (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25838(neverallow priv_app base_typeattr_224 (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25839(neverallow priv_app base_typeattr_224 (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
25840(neverallow priv_app base_typeattr_224 (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25841(neverallow priv_app base_typeattr_224 (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25842(neverallow priv_app base_typeattr_224 (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25843(neverallow priv_app base_typeattr_224 (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25844(neverallow priv_app base_typeattr_224 (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25845(neverallow priv_app base_typeattr_224 (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25846(neverallow priv_app base_typeattr_224 (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25847(neverallow priv_app base_typeattr_224 (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25848(neverallow priv_app base_typeattr_224 (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25849(neverallow priv_app base_typeattr_224 (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25850(neverallow priv_app base_typeattr_224 (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25851(neverallow priv_app base_typeattr_224 (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25852(neverallow priv_app base_typeattr_224 (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25853(neverallow priv_app base_typeattr_224 (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25854(neverallow priv_app base_typeattr_224 (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25855(neverallow priv_app base_typeattr_224 (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25856(neverallow priv_app base_typeattr_224 (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25857(neverallow priv_app base_typeattr_224 (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25858(neverallow priv_app base_typeattr_224 (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25859(neverallow priv_app base_typeattr_224 (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25860(neverallow priv_app base_typeattr_224 (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25861(neverallow priv_app base_typeattr_224 (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25862(neverallow priv_app base_typeattr_224 (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25863(neverallow priv_app base_typeattr_224 (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25864(neverallow priv_app base_typeattr_224 (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25865(neverallow priv_app base_typeattr_224 (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25866(neverallow priv_app base_typeattr_224 (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
25867;;* lme
25868
25869(allow priv_app keystore (keystore2 (report_off_body)))
25870(allow priv_app pm_archiving_enabled_prop (file (read getattr map open)))
25871(allow init prng_seeder_exec (file (read getattr map execute open)))
25872(allow init prng_seeder (process (transition)))
25873(allow prng_seeder prng_seeder_exec (file (read getattr map execute open entrypoint)))
25874(dontaudit init prng_seeder (process (noatsecure)))
25875(allow init prng_seeder (process (siginh rlimitinh)))
25876(typetransition init prng_seeder_exec process prng_seeder)
25877(allow prng_seeder prng_seeder (unix_stream_socket (read write getattr accept)))
25878(allow prng_seeder hw_random_device (chr_file (read open)))
25879(allow prng_seeder kmsg_debug_device (chr_file (ioctl write getattr lock append map open)))
25880(allow profman system_file (file (read getattr lock map)))
25881(allow profman vendor_app_file (file (read getattr lock map)))
25882(allow profman apk_data_file (file (read getattr lock map)))
25883(allow profman artd (fd (use)))
25884(allow profman installd (fd (use)))
25885(allow profman artd_tmpfs (file (read getattr lock map)))
25886;;* lmx 2 system/sepolicy/private/property.te
25887
25888(neverallow base_typeattr_250 adbd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25889;;* lme
25890
25891;;* lmx 3 system/sepolicy/private/property.te
25892
25893(neverallow base_typeattr_250 apexd_payload_metadata_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25894;;* lme
25895
25896;;* lmx 4 system/sepolicy/private/property.te
25897
25898(neverallow base_typeattr_250 ctl_snapuserd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25899;;* lme
25900
25901;;* lmx 5 system/sepolicy/private/property.te
25902
25903(neverallow base_typeattr_250 crashrecovery_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25904;;* lme
25905
25906;;* lmx 6 system/sepolicy/private/property.te
25907
25908(neverallow base_typeattr_250 device_config_core_experiments_team_internal_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25909;;* lme
25910
25911;;* lmx 7 system/sepolicy/private/property.te
25912
25913(neverallow base_typeattr_250 device_config_lmkd_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25914;;* lme
25915
25916;;* lmx 8 system/sepolicy/private/property.te
25917
25918(neverallow base_typeattr_250 device_config_mglru_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25919;;* lme
25920
25921;;* lmx 9 system/sepolicy/private/property.te
25922
25923(neverallow base_typeattr_250 device_config_profcollect_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25924;;* lme
25925
25926;;* lmx 10 system/sepolicy/private/property.te
25927
25928(neverallow base_typeattr_250 device_config_remote_key_provisioning_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25929;;* lme
25930
25931;;* lmx 11 system/sepolicy/private/property.te
25932
25933(neverallow base_typeattr_250 device_config_statsd_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25934;;* lme
25935
25936;;* lmx 12 system/sepolicy/private/property.te
25937
25938(neverallow base_typeattr_250 device_config_statsd_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25939;;* lme
25940
25941;;* lmx 13 system/sepolicy/private/property.te
25942
25943(neverallow base_typeattr_250 device_config_storage_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25944;;* lme
25945
25946;;* lmx 14 system/sepolicy/private/property.te
25947
25948(neverallow base_typeattr_250 device_config_sys_traced_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25949;;* lme
25950
25951;;* lmx 15 system/sepolicy/private/property.te
25952
25953(neverallow base_typeattr_250 device_config_window_manager_native_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25954;;* lme
25955
25956;;* lmx 16 system/sepolicy/private/property.te
25957
25958(neverallow base_typeattr_250 device_config_configuration_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25959;;* lme
25960
25961;;* lmx 17 system/sepolicy/private/property.te
25962
25963(neverallow base_typeattr_250 device_config_connectivity_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25964;;* lme
25965
25966;;* lmx 18 system/sepolicy/private/property.te
25967
25968(neverallow base_typeattr_250 device_config_swcodec_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25969;;* lme
25970
25971;;* lmx 19 system/sepolicy/private/property.te
25972
25973(neverallow base_typeattr_250 device_config_tethering_u_or_later_native_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25974;;* lme
25975
25976;;* lmx 20 system/sepolicy/private/property.te
25977
25978(neverallow base_typeattr_250 dmesgd_start_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25979;;* lme
25980
25981;;* lmx 21 system/sepolicy/private/property.te
25982
25983(neverallow base_typeattr_250 fastbootd_protocol_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25984;;* lme
25985
25986;;* lmx 22 system/sepolicy/private/property.te
25987
25988(neverallow base_typeattr_250 gsid_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25989;;* lme
25990
25991;;* lmx 23 system/sepolicy/private/property.te
25992
25993(neverallow base_typeattr_250 init_perf_lsm_hooks_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25994;;* lme
25995
25996;;* lmx 24 system/sepolicy/private/property.te
25997
25998(neverallow base_typeattr_250 init_service_status_private_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
25999;;* lme
26000
26001;;* lmx 25 system/sepolicy/private/property.te
26002
26003(neverallow base_typeattr_250 init_storage_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26004;;* lme
26005
26006;;* lmx 26 system/sepolicy/private/property.te
26007
26008(neverallow base_typeattr_250 init_svc_debug_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26009;;* lme
26010
26011;;* lmx 27 system/sepolicy/private/property.te
26012
26013(neverallow base_typeattr_250 keystore_crash_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26014;;* lme
26015
26016;;* lmx 28 system/sepolicy/private/property.te
26017
26018(neverallow base_typeattr_250 keystore_listen_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26019;;* lme
26020
26021;;* lmx 29 system/sepolicy/private/property.te
26022
26023(neverallow base_typeattr_250 last_boot_reason_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26024;;* lme
26025
26026;;* lmx 30 system/sepolicy/private/property.te
26027
26028(neverallow base_typeattr_250 localization_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26029;;* lme
26030
26031;;* lmx 31 system/sepolicy/private/property.te
26032
26033(neverallow base_typeattr_250 logd_auditrate_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26034;;* lme
26035
26036;;* lmx 32 system/sepolicy/private/property.te
26037
26038(neverallow base_typeattr_250 lower_kptr_restrict_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26039;;* lme
26040
26041;;* lmx 33 system/sepolicy/private/property.te
26042
26043(neverallow base_typeattr_250 net_464xlat_fromvendor_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26044;;* lme
26045
26046;;* lmx 34 system/sepolicy/private/property.te
26047
26048(neverallow base_typeattr_250 net_connectivity_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26049;;* lme
26050
26051;;* lmx 35 system/sepolicy/private/property.te
26052
26053(neverallow base_typeattr_250 netd_stable_secret_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26054;;* lme
26055
26056;;* lmx 36 system/sepolicy/private/property.te
26057
26058(neverallow base_typeattr_250 next_boot_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26059;;* lme
26060
26061;;* lmx 37 system/sepolicy/private/property.te
26062
26063(neverallow base_typeattr_250 odsign_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26064;;* lme
26065
26066;;* lmx 38 system/sepolicy/private/property.te
26067
26068(neverallow base_typeattr_250 misctrl_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26069;;* lme
26070
26071;;* lmx 39 system/sepolicy/private/property.te
26072
26073(neverallow base_typeattr_250 perf_drop_caches_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26074;;* lme
26075
26076;;* lmx 40 system/sepolicy/private/property.te
26077
26078(neverallow base_typeattr_250 pm_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26079;;* lme
26080
26081;;* lmx 41 system/sepolicy/private/property.te
26082
26083(neverallow base_typeattr_250 profcollectd_node_id_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26084;;* lme
26085
26086;;* lmx 42 system/sepolicy/private/property.te
26087
26088(neverallow base_typeattr_250 radio_cdma_ecm_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26089;;* lme
26090
26091;;* lmx 43 system/sepolicy/private/property.te
26092
26093(neverallow base_typeattr_250 remote_prov_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26094;;* lme
26095
26096;;* lmx 44 system/sepolicy/private/property.te
26097
26098(neverallow base_typeattr_250 rollback_test_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26099;;* lme
26100
26101;;* lmx 45 system/sepolicy/private/property.te
26102
26103(neverallow base_typeattr_250 setupwizard_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26104;;* lme
26105
26106;;* lmx 46 system/sepolicy/private/property.te
26107
26108(neverallow base_typeattr_250 snapuserd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26109;;* lme
26110
26111;;* lmx 47 system/sepolicy/private/property.te
26112
26113(neverallow base_typeattr_250 system_adbd_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26114;;* lme
26115
26116;;* lmx 48 system/sepolicy/private/property.te
26117
26118(neverallow base_typeattr_250 system_audio_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26119;;* lme
26120
26121;;* lmx 49 system/sepolicy/private/property.te
26122
26123(neverallow base_typeattr_250 timezone_metadata_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26124;;* lme
26125
26126;;* lmx 50 system/sepolicy/private/property.te
26127
26128(neverallow base_typeattr_250 traced_perf_enabled_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26129;;* lme
26130
26131;;* lmx 51 system/sepolicy/private/property.te
26132
26133(neverallow base_typeattr_250 uprobestats_start_with_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26134;;* lme
26135
26136;;* lmx 52 system/sepolicy/private/property.te
26137
26138(neverallow base_typeattr_250 tuner_server_ctl_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26139;;* lme
26140
26141;;* lmx 53 system/sepolicy/private/property.te
26142
26143(neverallow base_typeattr_250 userspace_reboot_log_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26144;;* lme
26145
26146;;* lmx 54 system/sepolicy/private/property.te
26147
26148(neverallow base_typeattr_250 userspace_reboot_test_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26149;;* lme
26150
26151;;* lmx 55 system/sepolicy/private/property.te
26152
26153(neverallow base_typeattr_250 verity_status_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26154;;* lme
26155
26156;;* lmx 56 system/sepolicy/private/property.te
26157
26158(neverallow base_typeattr_250 zygote_wrap_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26159;;* lme
26160
26161;;* lmx 57 system/sepolicy/private/property.te
26162
26163(neverallow base_typeattr_250 ctl_mediatranscoding_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26164;;* lme
26165
26166;;* lmx 58 system/sepolicy/private/property.te
26167
26168(neverallow base_typeattr_250 ctl_odsign_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26169;;* lme
26170
26171;;* lmx 59 system/sepolicy/private/property.te
26172
26173(neverallow base_typeattr_250 virtualizationservice_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26174;;* lme
26175
26176;;* lmx 60 system/sepolicy/private/property.te
26177
26178(neverallow base_typeattr_250 ctl_apex_load_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26179;;* lme
26180
26181;;* lmx 61 system/sepolicy/private/property.te
26182
26183(neverallow base_typeattr_250 enable_16k_pages_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26184;;* lme
26185
26186;;* lmx 62 system/sepolicy/private/property.te
26187
26188(neverallow base_typeattr_250 sensors_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26189;;* lme
26190
26191;;* lmx 63 system/sepolicy/private/property.te
26192
26193(neverallow base_typeattr_250 hypervisor_pvmfw_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26194;;* lme
26195
26196;;* lmx 64 system/sepolicy/private/property.te
26197
26198(neverallow base_typeattr_250 hypervisor_virtualizationmanager_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26199;;* lme
26200
26201;;* lmx 65 system/sepolicy/private/property.te
26202
26203(neverallow base_typeattr_250 game_manager_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26204;;* lme
26205
26206;;* lmx 66 system/sepolicy/private/property.te
26207
26208(neverallow base_typeattr_250 hidl_memory_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26209;;* lme
26210
26211;;* lmx 67 system/sepolicy/private/property.te
26212
26213(neverallow base_typeattr_250 suspend_debug_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26214;;* lme
26215
26216;;* lmx 70 system/sepolicy/private/property.te
26217
26218(neverallow base_typeattr_250 device_config_virtualization_framework_native_prop (property_service (set)))
26219;;* lme
26220
26221;;* lmx 71 system/sepolicy/private/property.te
26222
26223(neverallow base_typeattr_250 log_file_logger_prop (property_service (set)))
26224;;* lme
26225
26226;;* lmx 72 system/sepolicy/private/property.te
26227
26228(neverallow base_typeattr_250 persist_sysui_builder_extras_prop (property_service (set)))
26229;;* lme
26230
26231;;* lmx 73 system/sepolicy/private/property.te
26232
26233(neverallow base_typeattr_250 persist_sysui_ranking_update_prop (property_service (set)))
26234;;* lme
26235
26236;;* lmx 79 system/sepolicy/private/property.te
26237
26238(neverallow domain base_typeattr_861 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26239;;* lme
26240
26241;;* lmx 79 system/sepolicy/private/property.te
26242
26243(neverallow base_typeattr_250 base_typeattr_862 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26244;;* lme
26245
26246;;* lmx 79 system/sepolicy/private/property.te
26247
26248(neverallow base_typeattr_250 base_typeattr_863 (property_service (set)))
26249;;* lme
26250
26251;;* lmx 79 system/sepolicy/private/property.te
26252
26253(neverallow base_typeattr_572 base_typeattr_864 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26254;;* lme
26255
26256;;* lmx 79 system/sepolicy/private/property.te
26257
26258(neverallow base_typeattr_691 base_typeattr_865 (property_service (set)))
26259;;* lme
26260
26261;;* lmx 122 system/sepolicy/private/property.te
26262
26263(neverallow domain property_type (file (ioctl lock)))
26264;;* lme
26265
26266;;* lmx 148 system/sepolicy/private/property.te
26267
26268(neverallow base_typeattr_224 base_typeattr_866 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26269;;* lme
26270
26271;;* lmx 156 system/sepolicy/private/property.te
26272
26273(neverallow base_typeattr_259 ctl_sigstop_prop (property_service (set)))
26274;;* lme
26275
26276(dontaudit domain ctl_bootanim_prop (property_service (set)))
26277(dontaudit domain ctl_bugreport_prop (property_service (set)))
26278(dontaudit domain ctl_console_prop (property_service (set)))
26279(dontaudit domain ctl_dumpstate_prop (property_service (set)))
26280(dontaudit domain ctl_fuse_prop (property_service (set)))
26281(dontaudit domain ctl_mdnsd_prop (property_service (set)))
26282(dontaudit domain ctl_rildaemon_prop (property_service (set)))
26283(dontaudit domain ctl_default_prop (property_service (set)))
26284;;* lmx 175 system/sepolicy/private/property.te
26285
26286(neverallow base_typeattr_867 init_storage_prop (property_service (set)))
26287;;* lme
26288
26289;;* lmx 180 system/sepolicy/private/property.te
26290
26291(neverallow base_typeattr_223 init_svc_debug_prop (property_service (set)))
26292;;* lme
26293
26294;;* lmx 187 system/sepolicy/private/property.te
26295
26296(neverallow base_typeattr_855 init_svc_debug_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26297;;* lme
26298
26299;;* lmx 196 system/sepolicy/private/property.te
26300
26301(neverallow base_typeattr_868 misctrl_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26302;;* lme
26303
26304;;* lmx 202 system/sepolicy/private/property.te
26305
26306(neverallow base_typeattr_869 misctrl_prop (property_service (set)))
26307;;* lme
26308
26309;;* lmx 204 system/sepolicy/private/property.te
26310
26311(neverallow base_typeattr_870 base_typeattr_871 (property_service (set)))
26312;;* lme
26313
26314;;* lmx 204 system/sepolicy/private/property.te
26315
26316(neverallow base_typeattr_872 nfc_prop (property_service (set)))
26317;;* lme
26318
26319;;* lmx 204 system/sepolicy/private/property.te
26320
26321(neverallow base_typeattr_873 radio_control_prop (property_service (set)))
26322;;* lme
26323
26324;;* lmx 204 system/sepolicy/private/property.te
26325
26326(neverallow base_typeattr_874 radio_prop (property_service (set)))
26327;;* lme
26328
26329;;* lmx 204 system/sepolicy/private/property.te
26330
26331(neverallow base_typeattr_875 bluetooth_prop (property_service (set)))
26332;;* lme
26333
26334;;* lmx 204 system/sepolicy/private/property.te
26335
26336(neverallow base_typeattr_876 exported_bluetooth_prop (property_service (set)))
26337;;* lme
26338
26339;;* lmx 204 system/sepolicy/private/property.te
26340
26341(neverallow base_typeattr_877 exported_camera_prop (property_service (set)))
26342;;* lme
26343
26344;;* lmx 204 system/sepolicy/private/property.te
26345
26346(neverallow base_typeattr_878 wifi_prop (property_service (set)))
26347;;* lme
26348
26349;;* lmx 204 system/sepolicy/private/property.te
26350
26351(neverallow base_typeattr_879 wifi_hal_prop (property_service (set)))
26352;;* lme
26353
26354;;* lmx 204 system/sepolicy/private/property.te
26355
26356(neverallow base_typeattr_870 base_typeattr_880 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26357;;* lme
26358
26359;;* lmx 204 system/sepolicy/private/property.te
26360
26361(neverallow base_typeattr_872 nfc_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26362;;* lme
26363
26364;;* lmx 204 system/sepolicy/private/property.te
26365
26366(neverallow base_typeattr_874 radio_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26367;;* lme
26368
26369;;* lmx 204 system/sepolicy/private/property.te
26370
26371(neverallow base_typeattr_875 bluetooth_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26372;;* lme
26373
26374;;* lmx 204 system/sepolicy/private/property.te
26375
26376(neverallow base_typeattr_878 wifi_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26377;;* lme
26378
26379;;* lmx 204 system/sepolicy/private/property.te
26380
26381(neverallow base_typeattr_267 suspend_prop (property_service (set)))
26382;;* lme
26383
26384;;* lmx 204 system/sepolicy/private/property.te
26385
26386(neverallow base_typeattr_223 suspend_debug_prop (property_service (set)))
26387;;* lme
26388
26389;;* lmx 204 system/sepolicy/private/property.te
26390
26391(neverallow base_typeattr_855 suspend_debug_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26392;;* lme
26393
26394(dontaudit system_suspend suspend_debug_prop (file (ioctl read getattr lock map open watch watch_reads)))
26395;;* lmx 384 system/sepolicy/private/property.te
26396
26397(neverallow base_typeattr_881 base_typeattr_882 (property_service (set)))
26398;;* lme
26399
26400;;* lmx 404 system/sepolicy/private/property.te
26401
26402(neverallow base_typeattr_267 ffs_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26403(neverallow base_typeattr_267 ffs_control_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26404;;* lme
26405
26406;;* lmx 412 system/sepolicy/private/property.te
26407
26408(neverallow base_typeattr_308 userspace_reboot_log_prop (property_service (set)))
26409;;* lme
26410
26411;;* lmx 421 system/sepolicy/private/property.te
26412
26413(neverallow base_typeattr_308 system_adbd_prop (property_service (set)))
26414;;* lme
26415
26416;;* lmx 432 system/sepolicy/private/property.te
26417
26418(neverallow base_typeattr_883 adbd_config_prop (property_service (set)))
26419;;* lme
26420
26421;;* lmx 441 system/sepolicy/private/property.te
26422
26423(neverallow base_typeattr_884 adbd_prop (property_service (set)))
26424;;* lme
26425
26426;;* lmx 449 system/sepolicy/private/property.te
26427
26428(neverallow base_typeattr_223 apexd_payload_metadata_prop (property_service (set)))
26429;;* lme
26430
26431;;* lmx 459 system/sepolicy/private/property.te
26432
26433(neverallow base_typeattr_885 userspace_reboot_test_prop (property_service (set)))
26434;;* lme
26435
26436;;* lmx 468 system/sepolicy/private/property.te
26437
26438(neverallow base_typeattr_266 surfaceflinger_color_prop (property_service (set)))
26439;;* lme
26440
26441;;* lmx 475 system/sepolicy/private/property.te
26442
26443(neverallow base_typeattr_223 libc_debug_prop (property_service (set)))
26444;;* lme
26445
26446;;* lmx 490 system/sepolicy/private/property.te
26447
26448(neverallow base_typeattr_886 arm64_memtag_prop (property_service (set)))
26449(neverallow base_typeattr_886 gwp_asan_prop (property_service (set)))
26450;;* lme
26451
26452;;* lmx 497 system/sepolicy/private/property.te
26453
26454(neverallow base_typeattr_266 zram_control_prop (property_service (set)))
26455;;* lme
26456
26457;;* lmx 504 system/sepolicy/private/property.te
26458
26459(neverallow base_typeattr_266 dalvik_runtime_prop (property_service (set)))
26460;;* lme
26461
26462;;* lmx 513 system/sepolicy/private/property.te
26463
26464(neverallow base_typeattr_267 usb_config_prop (property_service (set)))
26465(neverallow base_typeattr_267 usb_control_prop (property_service (set)))
26466;;* lme
26467
26468;;* lmx 522 system/sepolicy/private/property.te
26469
26470(neverallow base_typeattr_308 provisioned_prop (property_service (set)))
26471(neverallow base_typeattr_308 retaildemo_prop (property_service (set)))
26472;;* lme
26473
26474;;* lmx 531 system/sepolicy/private/property.te
26475
26476(neverallow base_typeattr_267 provisioned_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26477(neverallow base_typeattr_267 retaildemo_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26478;;* lme
26479
26480;;* lmx 539 system/sepolicy/private/property.te
26481
26482(neverallow base_typeattr_223 init_service_status_prop (property_service (set)))
26483(neverallow base_typeattr_223 init_service_status_private_prop (property_service (set)))
26484;;* lme
26485
26486;;* lmx 548 system/sepolicy/private/property.te
26487
26488(neverallow base_typeattr_887 telephony_status_prop (property_service (set)))
26489;;* lme
26490
26491;;* lmx 556 system/sepolicy/private/property.te
26492
26493(neverallow base_typeattr_259 graphics_config_prop (property_service (set)))
26494;;* lme
26495
26496;;* lmx 564 system/sepolicy/private/property.te
26497
26498(neverallow base_typeattr_888 surfaceflinger_display_prop (property_service (set)))
26499;;* lme
26500
26501;;* lmx 571 system/sepolicy/private/property.te
26502
26503(neverallow base_typeattr_870 packagemanager_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26504;;* lme
26505
26506;;* lmx 577 system/sepolicy/private/property.te
26507
26508(neverallow base_typeattr_267 keyguard_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26509;;* lme
26510
26511;;* lmx 584 system/sepolicy/private/property.te
26512
26513(neverallow base_typeattr_223 localization_prop (property_service (set)))
26514;;* lme
26515
26516;;* lmx 592 system/sepolicy/private/property.te
26517
26518(neverallow base_typeattr_889 oem_unlock_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26519;;* lme
26520
26521;;* lmx 598 system/sepolicy/private/property.te
26522
26523(neverallow base_typeattr_267 storagemanager_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26524;;* lme
26525
26526;;* lmx 606 system/sepolicy/private/property.te
26527
26528(neverallow base_typeattr_890 sendbug_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26529;;* lme
26530
26531;;* lmx 614 system/sepolicy/private/property.te
26532
26533(neverallow base_typeattr_890 camera_calibration_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26534;;* lme
26535
26536;;* lmx 622 system/sepolicy/private/property.te
26537
26538(neverallow base_typeattr_891 hal_dumpstate_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26539;;* lme
26540
26541;;* lmx 633 system/sepolicy/private/property.te
26542
26543(neverallow base_typeattr_223 lower_kptr_restrict_prop (property_service (set)))
26544;;* lme
26545
26546;;* lmx 638 system/sepolicy/private/property.te
26547
26548(neverallow base_typeattr_223 zygote_wrap_prop (property_service (set)))
26549;;* lme
26550
26551;;* lmx 643 system/sepolicy/private/property.te
26552
26553(neverallow base_typeattr_223 verity_status_prop (property_service (set)))
26554;;* lme
26555
26556;;* lmx 649 system/sepolicy/private/property.te
26557
26558(neverallow base_typeattr_259 setupwizard_mode_prop (property_service (set)))
26559;;* lme
26560
26561;;* lmx 654 system/sepolicy/private/property.te
26562
26563(neverallow base_typeattr_223 setupwizard_prop (property_service (set)))
26564;;* lme
26565
26566;;* lmx 663 system/sepolicy/private/property.te
26567
26568(neverallow base_typeattr_260 build_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26569;;* lme
26570
26571;;* lmx 669 system/sepolicy/private/property.te
26572
26573(neverallow base_typeattr_885 sqlite_log_prop (property_service (set)))
26574;;* lme
26575
26576;;* lmx 675 system/sepolicy/private/property.te
26577
26578(neverallow base_typeattr_717 sqlite_log_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26579;;* lme
26580
26581;;* lmx 680 system/sepolicy/private/property.te
26582
26583(neverallow base_typeattr_223 default_prop (property_service (set)))
26584;;* lme
26585
26586;;* lmx 684 system/sepolicy/private/property.te
26587
26588(neverallow domain system_and_vendor_property_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
26589(neverallow domain system_and_vendor_property_type (property_service (set)))
26590;;* lme
26591
26592;;* lmx 691 system/sepolicy/private/property.te
26593
26594(neverallow base_typeattr_892 remote_prov_prop (property_service (set)))
26595;;* lme
26596
26597;;* lmx 698 system/sepolicy/private/property.te
26598
26599(neverallow base_typeattr_885 rollback_test_prop (property_service (set)))
26600;;* lme
26601
26602;;* lmx 704 system/sepolicy/private/property.te
26603
26604(neverallow base_typeattr_617 ctl_apex_load_prop (property_service (set)))
26605;;* lme
26606
26607;;* lmx 712 system/sepolicy/private/property.te
26608
26609(neverallow base_typeattr_893 ctl_apex_load_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26610;;* lme
26611
26612;;* lmx 718 system/sepolicy/private/property.te
26613
26614(neverallow base_typeattr_617 apex_ready_prop (property_service (set)))
26615;;* lme
26616
26617;;* lmx 726 system/sepolicy/private/property.te
26618
26619(neverallow base_typeattr_894 apex_ready_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26620;;* lme
26621
26622;;* lmx 734 system/sepolicy/private/property.te
26623
26624(neverallow base_typeattr_895 profcollectd_node_id_prop (file (ioctl read getattr lock map open watch watch_reads)))
26625;;* lme
26626
26627;;* lmx 739 system/sepolicy/private/property.te
26628
26629(neverallow base_typeattr_223 log_file_logger_prop (property_service (set)))
26630;;* lme
26631
26632;;* lmx 745 system/sepolicy/private/property.te
26633
26634(neverallow base_typeattr_259 usb_uvc_enabled_prop (property_service (set)))
26635;;* lme
26636
26637;;* lmx 752 system/sepolicy/private/property.te
26638
26639(neverallow base_typeattr_896 usb_uvc_enabled_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26640;;* lme
26641
26642;;* lmx 758 system/sepolicy/private/property.te
26643
26644(neverallow base_typeattr_259 pm_archiving_enabled_prop (property_service (set)))
26645;;* lme
26646
26647(typetransition radio tmpfs file appdomain_tmpfs)
26648(allow radio radio_userfaultfd (anon_inode (ioctl read create)))
26649(dontaudit su radio_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26650;;* lmx 3 system/sepolicy/private/radio.te
26651
26652(neverallow base_typeattr_573 radio_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26653;;* lme
26654
26655(allow radio appdomain_tmpfs (file (read write getattr map execute)))
26656;;* lmx 3 system/sepolicy/private/radio.te
26657
26658(neverallow base_typeattr_897 base_typeattr_573 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26659;;* lme
26660
26661;;* lmx 3 system/sepolicy/private/radio.te
26662
26663(neverallow base_typeattr_898 radio (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26664;;* lme
26665
26666;;* lmx 3 system/sepolicy/private/radio.te
26667
26668(neverallow base_typeattr_899 radio (process (ptrace)))
26669;;* lme
26670
26671(allow radio runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
26672(allow radio property_socket (sock_file (write)))
26673(allow radio init (unix_stream_socket (connectto)))
26674(allow radio radio_control_prop (property_service (set)))
26675(allow radio radio_control_prop (file (read getattr map open)))
26676(allow radio property_socket (sock_file (write)))
26677(allow radio init (unix_stream_socket (connectto)))
26678(allow radio radio_prop (property_service (set)))
26679(allow radio radio_prop (file (read getattr map open)))
26680(allow radio property_socket (sock_file (write)))
26681(allow radio init (unix_stream_socket (connectto)))
26682(allow radio net_radio_prop (property_service (set)))
26683(allow radio net_radio_prop (file (read getattr map open)))
26684(allow radio property_socket (sock_file (write)))
26685(allow radio init (unix_stream_socket (connectto)))
26686(allow radio telephony_status_prop (property_service (set)))
26687(allow radio telephony_status_prop (file (read getattr map open)))
26688(allow radio property_socket (sock_file (write)))
26689(allow radio init (unix_stream_socket (connectto)))
26690(allow radio radio_cdma_ecm_prop (property_service (set)))
26691(allow radio radio_cdma_ecm_prop (file (read getattr map open)))
26692(allow radio property_socket (sock_file (write)))
26693(allow radio init (unix_stream_socket (connectto)))
26694(allow radio ctl_rildaemon_prop (property_service (set)))
26695(allow radio ctl_rildaemon_prop (file (read getattr map open)))
26696(allow radio time_prop (file (read getattr map open)))
26697(allow radio platform_compat_service (service_manager (find)))
26698(allow radio uce_service (service_manager (find)))
26699(allow radio emergency_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
26700(allow radio emergency_data_file (file (ioctl read getattr lock map open watch watch_reads)))
26701(allow radio property_socket (sock_file (write)))
26702(allow radio init (unix_stream_socket (connectto)))
26703(allow radio binder_cache_telephony_server_prop (property_service (set)))
26704(allow radio binder_cache_telephony_server_prop (file (read getattr map open)))
26705;;* lmx 32 system/sepolicy/private/radio.te
26706
26707(neverallow base_typeattr_900 binder_cache_telephony_server_prop (property_service (set)))
26708;;* lme
26709
26710(allow radio statsd (binder (call transfer)))
26711(allow statsd radio (binder (transfer)))
26712(allow radio statsd (fd (use)))
26713(allow init recovery_persist_exec (file (read getattr map execute open)))
26714(allow init recovery_persist (process (transition)))
26715(allow recovery_persist recovery_persist_exec (file (read getattr map execute open entrypoint)))
26716(dontaudit init recovery_persist (process (noatsecure)))
26717(allow init recovery_persist (process (siginh rlimitinh)))
26718(typetransition init recovery_persist_exec process recovery_persist)
26719;;* lmx 11 system/sepolicy/private/recovery_persist.te
26720
26721(neverallow recovery_persist base_typeattr_901 (file (write)))
26722;;* lme
26723
26724(allow init recovery_refresh_exec (file (read getattr map execute open)))
26725(allow init recovery_refresh (process (transition)))
26726(allow recovery_refresh recovery_refresh_exec (file (read getattr map execute open entrypoint)))
26727(dontaudit init recovery_refresh (process (noatsecure)))
26728(allow init recovery_refresh (process (siginh rlimitinh)))
26729(typetransition init recovery_refresh_exec process recovery_refresh)
26730;;* lmx 10 system/sepolicy/private/recovery_refresh.te
26731
26732(neverallow recovery_refresh file_type (file (write)))
26733;;* lme
26734
26735(allow rkpd servicemanager (binder (call transfer)))
26736(allow servicemanager rkpd (binder (call transfer)))
26737(allow servicemanager rkpd (dir (search)))
26738(allow servicemanager rkpd (file (read open)))
26739(allow servicemanager rkpd (process (getattr)))
26740(allow init rkpd_exec (file (read getattr map execute open)))
26741(allow init rkpd (process (transition)))
26742(allow rkpd rkpd_exec (file (read getattr map execute open entrypoint)))
26743(dontaudit init rkpd (process (noatsecure)))
26744(allow init rkpd (process (siginh rlimitinh)))
26745(typetransition init rkpd_exec process rkpd)
26746(allow rkpd rkpd_registrar_service (service_manager (add find)))
26747;;* lmx 12 system/sepolicy/private/rkpd.te
26748
26749(neverallow base_typeattr_902 rkpd_registrar_service (service_manager (add)))
26750;;* lme
26751
26752(allow rkpd rkpd_refresh_service (service_manager (add find)))
26753;;* lmx 13 system/sepolicy/private/rkpd.te
26754
26755(neverallow base_typeattr_902 rkpd_refresh_service (service_manager (add)))
26756;;* lme
26757
26758(allow rkpd device_config_remote_key_provisioning_native_prop (file (read getattr map open)))
26759(typetransition rkpdapp tmpfs file appdomain_tmpfs)
26760(allow rkpdapp rkpdapp_userfaultfd (anon_inode (ioctl read create)))
26761(dontaudit su rkpdapp_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26762;;* lmx 7 system/sepolicy/private/rkpd_app.te
26763
26764(neverallow base_typeattr_903 rkpdapp_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26765;;* lme
26766
26767(allow rkpdapp appdomain_tmpfs (file (read write getattr map execute)))
26768;;* lmx 7 system/sepolicy/private/rkpd_app.te
26769
26770(neverallow base_typeattr_904 base_typeattr_903 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26771;;* lme
26772
26773;;* lmx 7 system/sepolicy/private/rkpd_app.te
26774
26775(neverallow base_typeattr_905 rkpdapp (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26776;;* lme
26777
26778;;* lmx 7 system/sepolicy/private/rkpd_app.te
26779
26780(neverallow base_typeattr_906 rkpdapp (process (ptrace)))
26781;;* lme
26782
26783(allow rkpdapp device_config_remote_key_provisioning_native_prop (file (read getattr map open)))
26784(allow rkpdapp property_socket (sock_file (write)))
26785(allow rkpdapp init (unix_stream_socket (connectto)))
26786(allow rkpdapp remote_prov_prop (property_service (set)))
26787(allow rkpdapp remote_prov_prop (file (read getattr map open)))
26788(allow rkpdapp app_api_service (service_manager (find)))
26789(allow rkpdapp mediametrics_service (service_manager (find)))
26790(allow rkpdapp statsmanager_service (service_manager (find)))
26791(allow rkpdapp statsd (binder (call transfer)))
26792(allow statsd rkpdapp (binder (transfer)))
26793(allow rkpdapp statsd (fd (use)))
26794(allow rs app_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
26795(allow rs privapp_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
26796(allow rs app_exec_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
26797(typetransition rs app_data_file file app_exec_data_file)
26798(typetransition rs privapp_data_file file app_exec_data_file)
26799(allow rs system_data_file (lnk_file (read)))
26800(allow rs app_data_file (file (ioctl read getattr lock map open watch watch_reads)))
26801(allow rs privapp_data_file (file (ioctl read getattr lock map open watch watch_reads)))
26802(allow rs app_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
26803(allow rs privapp_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
26804(allow rs app_data_file (dir (remove_name)))
26805(allow rs privapp_data_file (dir (remove_name)))
26806(allow rs vendor_file (dir (ioctl read getattr lock open watch watch_reads search)))
26807(allow rs vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
26808(allow rs vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
26809(allow rs vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
26810(allow rs vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
26811(allow rs vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
26812(allow rs vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
26813(allow rs vendor_apex_metadata_file (dir (getattr search)))
26814(allow rs apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
26815(allow rs apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
26816(allow rs apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
26817(allow rs gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
26818(allow rs ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
26819(allow rs same_process_hal_file (file (ioctl read getattr lock map execute open watch watch_reads)))
26820(allow rs untrusted_app_all (fd (use)))
26821(allow rs ephemeral_app (fd (use)))
26822(allow rs priv_app (fd (use)))
26823(dontaudit rs hal_graphics_allocator (fd (use)))
26824(dontaudit rs surfaceflinger (fd (use)))
26825(dontaudit rs zygote (fd (use)))
26826;;* lmx 41 system/sepolicy/private/rs.te
26827
26828(neverallow rs rs (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
26829(neverallow rs rs (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
26830(neverallow rs rs (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
26831(neverallow rs rs (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
26832;;* lme
26833
26834;;* lmx 42 system/sepolicy/private/rs.te
26835
26836(neverallow base_typeattr_233 rs (process (transition dyntransition)))
26837;;* lme
26838
26839;;* lmx 43 system/sepolicy/private/rs.te
26840
26841(neverallow rs base_typeattr_644 (process (transition dyntransition)))
26842;;* lme
26843
26844;;* lmx 44 system/sepolicy/private/rs.te
26845
26846(neverallow rs app_data_file_type (file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
26847(neverallow rs app_data_file_type (lnk_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
26848(neverallow rs app_data_file_type (chr_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm execute_no_trans entrypoint)))
26849(neverallow rs app_data_file_type (blk_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
26850(neverallow rs app_data_file_type (sock_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
26851(neverallow rs app_data_file_type (fifo_file (write create setattr relabelfrom relabelto append unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm)))
26852;;* lme
26853
26854;;* lmx 46 system/sepolicy/private/rs.te
26855
26856(neverallow rs base_typeattr_224 (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
26857(neverallow rs base_typeattr_224 (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
26858(neverallow rs base_typeattr_224 (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
26859(neverallow rs base_typeattr_224 (icmp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
26860;;* lme
26861
26862(allow init rss_hwm_reset_exec (file (read getattr map execute open)))
26863(allow init rss_hwm_reset (process (transition)))
26864(allow rss_hwm_reset rss_hwm_reset_exec (file (read getattr map execute open entrypoint)))
26865(dontaudit init rss_hwm_reset (process (noatsecure)))
26866(allow init rss_hwm_reset (process (siginh rlimitinh)))
26867(typetransition init rss_hwm_reset_exec process rss_hwm_reset)
26868(allow rss_hwm_reset domain (dir (search)))
26869(allow rss_hwm_reset self (capability (dac_override)))
26870(allow rss_hwm_reset self (cap_userns (dac_override)))
26871(allow rss_hwm_reset domain (file (write lock append map open)))
26872(allow shell runas_exec (file (read getattr map execute open)))
26873(allow shell runas (process (transition)))
26874(allow runas runas_exec (file (read getattr map execute open entrypoint)))
26875(allow runas shell (process (sigchld)))
26876(dontaudit shell runas (process (noatsecure)))
26877(allow shell runas (process (siginh rlimitinh)))
26878(typetransition shell runas_exec process runas)
26879(typetransition runas_app tmpfs file appdomain_tmpfs)
26880(allow runas_app runas_app_userfaultfd (anon_inode (ioctl read create)))
26881(dontaudit su runas_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26882;;* lmx 3 system/sepolicy/private/runas_app.te
26883
26884(neverallow base_typeattr_907 runas_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26885;;* lme
26886
26887(allow runas_app appdomain_tmpfs (file (read write getattr map execute)))
26888;;* lmx 3 system/sepolicy/private/runas_app.te
26889
26890(neverallow base_typeattr_908 base_typeattr_907 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26891;;* lme
26892
26893;;* lmx 3 system/sepolicy/private/runas_app.te
26894
26895(neverallow base_typeattr_909 runas_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26896;;* lme
26897
26898;;* lmx 3 system/sepolicy/private/runas_app.te
26899
26900(neverallow base_typeattr_910 runas_app (process (ptrace)))
26901;;* lme
26902
26903(allow runas_app app_data_file (file (execute_no_trans)))
26904(allow runas_app untrusted_app_all (dir (ioctl read getattr lock open watch watch_reads search)))
26905(allow runas_app untrusted_app_all (file (ioctl read getattr lock map open watch watch_reads)))
26906(allow runas_app untrusted_app_all (lnk_file (ioctl read getattr lock map open watch watch_reads)))
26907(allow runas_app untrusted_app_all (process (sigkill sigstop signal ptrace)))
26908(allow runas_app untrusted_app_all (unix_stream_socket (connectto)))
26909(allow runas_app simpleperf_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
26910(dontaudit runas_app domain (dir (search)))
26911(allow runas_app self (perf_event (open kernel read write)))
26912;;* lmx 32 system/sepolicy/private/runas_app.te
26913
26914(neverallow runas_app self (perf_event (cpu tracepoint)))
26915;;* lme
26916
26917(dontaudit runas_app shell_test_data_file (dir (search)))
26918(typetransition sdcardd system_data_file dir media_rw_data_file)
26919(typetransition sdcardd system_data_file file media_rw_data_file)
26920(typetransition sdk_sandbox_34 tmpfs file appdomain_tmpfs)
26921(allow sdk_sandbox_34 sdk_sandbox_34_userfaultfd (anon_inode (ioctl read create)))
26922(dontaudit su sdk_sandbox_34_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26923;;* lmx 9 system/sepolicy/private/sdk_sandbox_34.te
26924
26925(neverallow base_typeattr_911 sdk_sandbox_34_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
26926;;* lme
26927
26928(allow sdk_sandbox_34 appdomain_tmpfs (file (read write getattr map execute)))
26929;;* lmx 9 system/sepolicy/private/sdk_sandbox_34.te
26930
26931(neverallow base_typeattr_912 base_typeattr_911 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26932;;* lme
26933
26934;;* lmx 9 system/sepolicy/private/sdk_sandbox_34.te
26935
26936(neverallow base_typeattr_913 sdk_sandbox_34 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
26937;;* lme
26938
26939;;* lmx 9 system/sepolicy/private/sdk_sandbox_34.te
26940
26941(neverallow base_typeattr_914 sdk_sandbox_34 (process (ptrace)))
26942;;* lme
26943
26944(allow sdk_sandbox_all system_linker_exec (file (execute_no_trans)))
26945(allow sdk_sandbox_all shell_data_file (file (ioctl read getattr lock map open watch watch_reads)))
26946(allow sdk_sandbox_all shell_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
26947(allow sdk_sandbox_all system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
26948(allow sdk_sandbox_all sdk_sandbox_system_data_file (dir (getattr search)))
26949(allow sdk_sandbox_all sdk_sandbox_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
26950(allow sdk_sandbox_all sdk_sandbox_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
26951(allow sdk_sandbox_all app_data_file (file (read getattr)))
26952(allow sdk_sandbox_all privapp_data_file (file (read getattr)))
26953;;* lmx 39 system/sepolicy/private/sdk_sandbox_all.te
26954
26955(neverallow sdk_sandbox_all app_data_file_type (file (execute execute_no_trans)))
26956;;* lme
26957
26958;;* lmx 42 system/sepolicy/private/sdk_sandbox_all.te
26959
26960(neverallow sdk_sandbox_all domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
26961;;* lme
26962
26963;;* lmx 45 system/sepolicy/private/sdk_sandbox_all.te
26964
26965(neverallow sdk_sandbox_all domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
26966;;* lme
26967
26968;;* lmx 49 system/sepolicy/private/sdk_sandbox_all.te
26969
26970(neverallow sdk_sandbox_all debugfs_type (file (read)))
26971;;* lme
26972
26973;;* lmx 52 system/sepolicy/private/sdk_sandbox_all.te
26974
26975(neverallow sdk_sandbox_all gpu_device (chr_file (execute)))
26976;;* lme
26977
26978;;* lmx 55 system/sepolicy/private/sdk_sandbox_all.te
26979
26980(neverallow sdk_sandbox_all sysfs (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
26981;;* lme
26982
26983;;* lmx 59 system/sepolicy/private/sdk_sandbox_all.te
26984
26985(neverallow sdk_sandbox_all proc (file (ioctl read write create setattr lock relabelfrom append unlink link rename execute open watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans)))
26986;;* lme
26987
26988;;* lmx 62 system/sepolicy/private/sdk_sandbox_all.te
26989
26990(neverallow sdk_sandbox_all sdcard_type (file (create open)))
26991(neverallow sdk_sandbox_all media_rw_data_file (file (create open)))
26992;;* lme
26993
26994;;* lmx 63 system/sepolicy/private/sdk_sandbox_all.te
26995
26996(neverallow sdk_sandbox_all sdcard_type (dir (search)))
26997(neverallow sdk_sandbox_all media_rw_data_file (dir (search)))
26998;;* lme
26999
27000;;* lmx 67 system/sepolicy/private/sdk_sandbox_all.te
27001
27002(neverallow sdk_sandbox_all proc_net (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27003;;* lme
27004
27005;;* lmx 71 system/sepolicy/private/sdk_sandbox_all.te
27006
27007(neverallow sdk_sandbox_all base_typeattr_915 (dir (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27008;;* lme
27009
27010;;* lmx 72 system/sepolicy/private/sdk_sandbox_all.te
27011
27012(neverallow sdk_sandbox_all base_typeattr_915 (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
27013;;* lme
27014
27015;;* lmx 75 system/sepolicy/private/sdk_sandbox_all.te
27016
27017(neverallow sdk_sandbox_all media_rw_data_file (dir (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27018;;* lme
27019
27020;;* lmx 76 system/sepolicy/private/sdk_sandbox_all.te
27021
27022(neverallow sdk_sandbox_all media_rw_data_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27023;;* lme
27024
27025;;* lmx 78 system/sepolicy/private/sdk_sandbox_all.te
27026
27027(neverallow sdk_sandbox_all tmpfs (dir (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27028;;* lme
27029
27030;;* lmx 80 system/sepolicy/private/sdk_sandbox_all.te
27031
27032(neverallow sdk_sandbox_all hal_drm_service (service_manager (find)))
27033;;* lme
27034
27035;;* lmx 90 system/sepolicy/private/sdk_sandbox_all.te
27036
27037(neverallow base_typeattr_916 sdk_sandbox_system_data_file (dir (relabelfrom)))
27038;;* lme
27039
27040;;* lmx 100 system/sepolicy/private/sdk_sandbox_all.te
27041
27042(neverallow base_typeattr_917 sdk_sandbox_system_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
27043;;* lme
27044
27045;;* lmx 110 system/sepolicy/private/sdk_sandbox_all.te
27046
27047(neverallow base_typeattr_916 sdk_sandbox_system_data_file (dir (relabelfrom)))
27048;;* lme
27049
27050;;* lmx 120 system/sepolicy/private/sdk_sandbox_all.te
27051
27052(neverallow base_typeattr_917 sdk_sandbox_system_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
27053;;* lme
27054
27055;;* lmx 123 system/sepolicy/private/sdk_sandbox_all.te
27056
27057(neverallow sdk_sandbox_all sdk_sandbox_system_data_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
27058;;* lme
27059
27060;;* lmx 126 system/sepolicy/private/sdk_sandbox_all.te
27061
27062(neverallow base_typeattr_223 sdk_sandbox_system_data_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
27063;;* lme
27064
27065(typetransition sdk_sandbox_audit tmpfs file appdomain_tmpfs)
27066(allow sdk_sandbox_audit sdk_sandbox_audit_userfaultfd (anon_inode (ioctl read create)))
27067(dontaudit su sdk_sandbox_audit_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27068;;* lmx 14 system/sepolicy/private/sdk_sandbox_audit.te
27069
27070(neverallow base_typeattr_918 sdk_sandbox_audit_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27071;;* lme
27072
27073(allow sdk_sandbox_audit appdomain_tmpfs (file (read write getattr map execute)))
27074;;* lmx 14 system/sepolicy/private/sdk_sandbox_audit.te
27075
27076(neverallow base_typeattr_919 base_typeattr_918 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27077;;* lme
27078
27079;;* lmx 14 system/sepolicy/private/sdk_sandbox_audit.te
27080
27081(neverallow base_typeattr_920 sdk_sandbox_audit (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27082;;* lme
27083
27084;;* lmx 14 system/sepolicy/private/sdk_sandbox_audit.te
27085
27086(neverallow base_typeattr_921 sdk_sandbox_audit (process (ptrace)))
27087;;* lme
27088
27089(auditallow sdk_sandbox_audit ephemeral_app_api_service (service_manager (find)))
27090(auditallow sdk_sandbox_audit cameraserver_service (service_manager (find)))
27091(auditallow sdk_sandbox_audit mediadrmserver_service (service_manager (find)))
27092(auditallow sdk_sandbox_audit radio_service (service_manager (find)))
27093(auditallow sdk_sandbox_audit base_typeattr_922 (file (ioctl read write getattr lock append map open watch watch_reads)))
27094(auditallow sdk_sandbox_audit base_typeattr_922 (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27095(allow sdk_sandbox_current ephemeral_app_api_service (service_manager (find)))
27096(allow sdk_sandbox_current audioserver_service (service_manager (find)))
27097(allow sdk_sandbox_current batteryproperties_service (service_manager (find)))
27098(allow sdk_sandbox_current cameraserver_service (service_manager (find)))
27099(allow sdk_sandbox_current gpu_service (service_manager (find)))
27100(allow sdk_sandbox_current mediaserver_service (service_manager (find)))
27101(allow sdk_sandbox_current mediametrics_service (service_manager (find)))
27102(allow sdk_sandbox_current mediaextractor_service (service_manager (find)))
27103(allow sdk_sandbox_current mediadrmserver_service (service_manager (find)))
27104(allow sdk_sandbox_current radio_service (service_manager (find)))
27105(allow sdk_sandbox_current surfaceflinger_service (service_manager (find)))
27106(allow sdk_sandbox_current activity_service (service_manager (find)))
27107(allow sdk_sandbox_current activity_task_service (service_manager (find)))
27108(allow sdk_sandbox_current appops_service (service_manager (find)))
27109(allow sdk_sandbox_current audio_service (service_manager (find)))
27110(allow sdk_sandbox_current batterystats_service (service_manager (find)))
27111(allow sdk_sandbox_current IProxyService_service (service_manager (find)))
27112(allow sdk_sandbox_current connectivity_service (service_manager (find)))
27113(allow sdk_sandbox_current connmetrics_service (service_manager (find)))
27114(allow sdk_sandbox_current deviceidle_service (service_manager (find)))
27115(allow sdk_sandbox_current display_service (service_manager (find)))
27116(allow sdk_sandbox_current font_service (service_manager (find)))
27117(allow sdk_sandbox_current dropbox_service (service_manager (find)))
27118(allow sdk_sandbox_current platform_compat_service (service_manager (find)))
27119(allow sdk_sandbox_current game_service (service_manager (find)))
27120(allow sdk_sandbox_current graphicsstats_service (service_manager (find)))
27121(allow sdk_sandbox_current hardware_properties_service (service_manager (find)))
27122(allow sdk_sandbox_current hint_service (service_manager (find)))
27123(allow sdk_sandbox_current imms_service (service_manager (find)))
27124(allow sdk_sandbox_current input_method_service (service_manager (find)))
27125(allow sdk_sandbox_current input_service (service_manager (find)))
27126(allow sdk_sandbox_current ipsec_service (service_manager (find)))
27127(allow sdk_sandbox_current launcherapps_service (service_manager (find)))
27128(allow sdk_sandbox_current legacy_permission_service (service_manager (find)))
27129(allow sdk_sandbox_current light_service (service_manager (find)))
27130(allow sdk_sandbox_current locale_service (service_manager (find)))
27131(allow sdk_sandbox_current media_communication_service (service_manager (find)))
27132(allow sdk_sandbox_current media_projection_service (service_manager (find)))
27133(allow sdk_sandbox_current media_router_service (service_manager (find)))
27134(allow sdk_sandbox_current media_session_service (service_manager (find)))
27135(allow sdk_sandbox_current memtrackproxy_service (service_manager (find)))
27136(allow sdk_sandbox_current midi_service (service_manager (find)))
27137(allow sdk_sandbox_current netpolicy_service (service_manager (find)))
27138(allow sdk_sandbox_current netstats_service (service_manager (find)))
27139(allow sdk_sandbox_current network_management_service (service_manager (find)))
27140(allow sdk_sandbox_current notification_service (service_manager (find)))
27141(allow sdk_sandbox_current package_service (service_manager (find)))
27142(allow sdk_sandbox_current permission_service (service_manager (find)))
27143(allow sdk_sandbox_current permissionmgr_service (service_manager (find)))
27144(allow sdk_sandbox_current permission_checker_service (service_manager (find)))
27145(allow sdk_sandbox_current power_service (service_manager (find)))
27146(allow sdk_sandbox_current procstats_service (service_manager (find)))
27147(allow sdk_sandbox_current registry_service (service_manager (find)))
27148(allow sdk_sandbox_current restrictions_service (service_manager (find)))
27149(allow sdk_sandbox_current rttmanager_service (service_manager (find)))
27150(allow sdk_sandbox_current search_service (service_manager (find)))
27151(allow sdk_sandbox_current selection_toolbar_service (service_manager (find)))
27152(allow sdk_sandbox_current sensorservice_service (service_manager (find)))
27153(allow sdk_sandbox_current sensor_privacy_service (service_manager (find)))
27154(allow sdk_sandbox_current servicediscovery_service (service_manager (find)))
27155(allow sdk_sandbox_current settings_service (service_manager (find)))
27156(allow sdk_sandbox_current statusbar_service (service_manager (find)))
27157(allow sdk_sandbox_current storagestats_service (service_manager (find)))
27158(allow sdk_sandbox_current speech_recognition_service (service_manager (find)))
27159(allow sdk_sandbox_current textclassification_service (service_manager (find)))
27160(allow sdk_sandbox_current textservices_service (service_manager (find)))
27161(allow sdk_sandbox_current texttospeech_service (service_manager (find)))
27162(allow sdk_sandbox_current telecom_service (service_manager (find)))
27163(allow sdk_sandbox_current thermal_service (service_manager (find)))
27164(allow sdk_sandbox_current translation_service (service_manager (find)))
27165(allow sdk_sandbox_current tv_iapp_service (service_manager (find)))
27166(allow sdk_sandbox_current tv_input_service (service_manager (find)))
27167(allow sdk_sandbox_current uimode_service (service_manager (find)))
27168(allow sdk_sandbox_current vcn_management_service (service_manager (find)))
27169(allow sdk_sandbox_current webviewupdate_service (service_manager (find)))
27170(allow sdk_sandbox_current tethering_service (service_manager (find)))
27171(typetransition sdk_sandbox_next tmpfs file appdomain_tmpfs)
27172(allow sdk_sandbox_next sdk_sandbox_next_userfaultfd (anon_inode (ioctl read create)))
27173(dontaudit su sdk_sandbox_next_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27174;;* lmx 11 system/sepolicy/private/sdk_sandbox_next.te
27175
27176(neverallow base_typeattr_923 sdk_sandbox_next_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27177;;* lme
27178
27179(allow sdk_sandbox_next appdomain_tmpfs (file (read write getattr map execute)))
27180;;* lmx 11 system/sepolicy/private/sdk_sandbox_next.te
27181
27182(neverallow base_typeattr_924 base_typeattr_923 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27183;;* lme
27184
27185;;* lmx 11 system/sepolicy/private/sdk_sandbox_next.te
27186
27187(neverallow base_typeattr_925 sdk_sandbox_next (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27188;;* lme
27189
27190;;* lmx 11 system/sepolicy/private/sdk_sandbox_next.te
27191
27192(neverallow base_typeattr_926 sdk_sandbox_next (process (ptrace)))
27193;;* lme
27194
27195(allow sdk_sandbox_next audioserver_service (service_manager (find)))
27196(allow sdk_sandbox_next batteryproperties_service (service_manager (find)))
27197(allow sdk_sandbox_next gpu_service (service_manager (find)))
27198(allow sdk_sandbox_next mediaserver_service (service_manager (find)))
27199(allow sdk_sandbox_next mediametrics_service (service_manager (find)))
27200(allow sdk_sandbox_next mediaextractor_service (service_manager (find)))
27201(allow sdk_sandbox_next surfaceflinger_service (service_manager (find)))
27202(allow sdk_sandbox_next activity_service (service_manager (find)))
27203(allow sdk_sandbox_next activity_task_service (service_manager (find)))
27204(allow sdk_sandbox_next appops_service (service_manager (find)))
27205(allow sdk_sandbox_next audio_service (service_manager (find)))
27206(allow sdk_sandbox_next batterystats_service (service_manager (find)))
27207(allow sdk_sandbox_next IProxyService_service (service_manager (find)))
27208(allow sdk_sandbox_next connectivity_service (service_manager (find)))
27209(allow sdk_sandbox_next connmetrics_service (service_manager (find)))
27210(allow sdk_sandbox_next deviceidle_service (service_manager (find)))
27211(allow sdk_sandbox_next display_service (service_manager (find)))
27212(allow sdk_sandbox_next font_service (service_manager (find)))
27213(allow sdk_sandbox_next dropbox_service (service_manager (find)))
27214(allow sdk_sandbox_next platform_compat_service (service_manager (find)))
27215(allow sdk_sandbox_next game_service (service_manager (find)))
27216(allow sdk_sandbox_next graphicsstats_service (service_manager (find)))
27217(allow sdk_sandbox_next hardware_properties_service (service_manager (find)))
27218(allow sdk_sandbox_next hint_service (service_manager (find)))
27219(allow sdk_sandbox_next imms_service (service_manager (find)))
27220(allow sdk_sandbox_next input_method_service (service_manager (find)))
27221(allow sdk_sandbox_next input_service (service_manager (find)))
27222(allow sdk_sandbox_next ipsec_service (service_manager (find)))
27223(allow sdk_sandbox_next launcherapps_service (service_manager (find)))
27224(allow sdk_sandbox_next legacy_permission_service (service_manager (find)))
27225(allow sdk_sandbox_next light_service (service_manager (find)))
27226(allow sdk_sandbox_next locale_service (service_manager (find)))
27227(allow sdk_sandbox_next media_communication_service (service_manager (find)))
27228(allow sdk_sandbox_next media_projection_service (service_manager (find)))
27229(allow sdk_sandbox_next media_router_service (service_manager (find)))
27230(allow sdk_sandbox_next media_session_service (service_manager (find)))
27231(allow sdk_sandbox_next memtrackproxy_service (service_manager (find)))
27232(allow sdk_sandbox_next midi_service (service_manager (find)))
27233(allow sdk_sandbox_next netpolicy_service (service_manager (find)))
27234(allow sdk_sandbox_next netstats_service (service_manager (find)))
27235(allow sdk_sandbox_next network_management_service (service_manager (find)))
27236(allow sdk_sandbox_next notification_service (service_manager (find)))
27237(allow sdk_sandbox_next package_service (service_manager (find)))
27238(allow sdk_sandbox_next permission_service (service_manager (find)))
27239(allow sdk_sandbox_next permissionmgr_service (service_manager (find)))
27240(allow sdk_sandbox_next permission_checker_service (service_manager (find)))
27241(allow sdk_sandbox_next power_service (service_manager (find)))
27242(allow sdk_sandbox_next procstats_service (service_manager (find)))
27243(allow sdk_sandbox_next registry_service (service_manager (find)))
27244(allow sdk_sandbox_next restrictions_service (service_manager (find)))
27245(allow sdk_sandbox_next rttmanager_service (service_manager (find)))
27246(allow sdk_sandbox_next search_service (service_manager (find)))
27247(allow sdk_sandbox_next selection_toolbar_service (service_manager (find)))
27248(allow sdk_sandbox_next sensorservice_service (service_manager (find)))
27249(allow sdk_sandbox_next sensor_privacy_service (service_manager (find)))
27250(allow sdk_sandbox_next servicediscovery_service (service_manager (find)))
27251(allow sdk_sandbox_next settings_service (service_manager (find)))
27252(allow sdk_sandbox_next statusbar_service (service_manager (find)))
27253(allow sdk_sandbox_next storagestats_service (service_manager (find)))
27254(allow sdk_sandbox_next speech_recognition_service (service_manager (find)))
27255(allow sdk_sandbox_next textclassification_service (service_manager (find)))
27256(allow sdk_sandbox_next textservices_service (service_manager (find)))
27257(allow sdk_sandbox_next texttospeech_service (service_manager (find)))
27258(allow sdk_sandbox_next telecom_service (service_manager (find)))
27259(allow sdk_sandbox_next thermal_service (service_manager (find)))
27260(allow sdk_sandbox_next translation_service (service_manager (find)))
27261(allow sdk_sandbox_next tv_iapp_service (service_manager (find)))
27262(allow sdk_sandbox_next tv_input_service (service_manager (find)))
27263(allow sdk_sandbox_next uimode_service (service_manager (find)))
27264(allow sdk_sandbox_next vcn_management_service (service_manager (find)))
27265(allow sdk_sandbox_next webviewupdate_service (service_manager (find)))
27266(allow sdk_sandbox_next tethering_service (service_manager (find)))
27267(typetransition secure_element tmpfs file appdomain_tmpfs)
27268(allow secure_element secure_element_userfaultfd (anon_inode (ioctl read create)))
27269(dontaudit su secure_element_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27270;;* lmx 3 system/sepolicy/private/secure_element.te
27271
27272(neverallow base_typeattr_927 secure_element_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27273;;* lme
27274
27275(allow secure_element appdomain_tmpfs (file (read write getattr map execute)))
27276;;* lmx 3 system/sepolicy/private/secure_element.te
27277
27278(neverallow base_typeattr_928 base_typeattr_927 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27279;;* lme
27280
27281;;* lmx 3 system/sepolicy/private/secure_element.te
27282
27283(neverallow base_typeattr_929 secure_element (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27284;;* lme
27285
27286;;* lmx 3 system/sepolicy/private/secure_element.te
27287
27288(neverallow base_typeattr_930 secure_element (process (ptrace)))
27289;;* lme
27290
27291(allow secure_element secure_element_service (service_manager (add find)))
27292;;* lmx 6 system/sepolicy/private/secure_element.te
27293
27294(neverallow base_typeattr_927 secure_element_service (service_manager (add)))
27295;;* lme
27296
27297(allow secure_element app_api_service (service_manager (find)))
27298(allow secure_element shell_data_file (file (read)))
27299(allow secure_element vendor_uuid_mapping_config_file (file (ioctl read getattr lock map open watch watch_reads)))
27300(allow init servicemanager_exec (file (read getattr map execute open)))
27301(allow init servicemanager (process (transition)))
27302(allow servicemanager servicemanager_exec (file (read getattr map execute open entrypoint)))
27303(dontaudit init servicemanager (process (noatsecure)))
27304(allow init servicemanager (process (siginh rlimitinh)))
27305(typetransition init servicemanager_exec process servicemanager)
27306(allow servicemanager runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
27307(allow servicemanager property_socket (sock_file (write)))
27308(allow servicemanager init (unix_stream_socket (connectto)))
27309(allow servicemanager ctl_interface_start_prop (property_service (set)))
27310(allow servicemanager ctl_interface_start_prop (file (read getattr map open)))
27311(allow servicemanager property_socket (sock_file (write)))
27312(allow servicemanager init (unix_stream_socket (connectto)))
27313(allow servicemanager servicemanager_prop (property_service (set)))
27314(allow servicemanager servicemanager_prop (file (read getattr map open)))
27315(allow servicemanager system_bootstrap_lib_file (dir (ioctl read getattr lock open watch watch_reads search)))
27316(allow servicemanager system_bootstrap_lib_file (file (read getattr map execute open)))
27317(allow servicemanager apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
27318(allow servicemanager apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
27319(allow servicemanager vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
27320(allow servicemanager vendor_apex_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
27321(allow servicemanager vendor_apex_metadata_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27322(typetransition shared_relro tmpfs file appdomain_tmpfs)
27323(allow shared_relro shared_relro_userfaultfd (anon_inode (ioctl read create)))
27324(dontaudit su shared_relro_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27325;;* lmx 5 system/sepolicy/private/shared_relro.te
27326
27327(neverallow base_typeattr_931 shared_relro_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27328;;* lme
27329
27330(allow shared_relro appdomain_tmpfs (file (read write getattr map execute)))
27331;;* lmx 5 system/sepolicy/private/shared_relro.te
27332
27333(neverallow base_typeattr_932 base_typeattr_931 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27334;;* lme
27335
27336;;* lmx 5 system/sepolicy/private/shared_relro.te
27337
27338(neverallow base_typeattr_933 shared_relro (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27339;;* lme
27340
27341;;* lmx 5 system/sepolicy/private/shared_relro.te
27342
27343(neverallow base_typeattr_934 shared_relro (process (ptrace)))
27344;;* lme
27345
27346(allow shared_relro shared_relro_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27347(allow shared_relro shared_relro_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27348(allow shared_relro activity_service (service_manager (find)))
27349(allow shared_relro webviewupdate_service (service_manager (find)))
27350(allow shared_relro package_service (service_manager (find)))
27351(dontaudit shared_relro network_management_service (service_manager (find)))
27352(allow shell uhid_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27353(allow shell debugfs_tracing_debug (dir (ioctl read getattr lock open watch watch_reads search)))
27354(allow shell debugfs_tracing (dir (ioctl read getattr lock open watch watch_reads search)))
27355(allow shell debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
27356(allow shell debugfs_trace_marker (file (getattr)))
27357(allow shell atrace_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27358(allow shell config_gz (file (ioctl read getattr lock map open watch watch_reads)))
27359(allow shell tombstone_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
27360(allow shell tombstone_data_file (file (ioctl read getattr lock map open watch watch_reads)))
27361(typetransition shell tmpfs file appdomain_tmpfs)
27362(allow shell shell_userfaultfd (anon_inode (ioctl read create)))
27363(dontaudit su shell_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27364;;* lmx 26 system/sepolicy/private/shell.te
27365
27366(neverallow base_typeattr_935 shell_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27367;;* lme
27368
27369(allow shell appdomain_tmpfs (file (read write getattr map execute)))
27370;;* lmx 26 system/sepolicy/private/shell.te
27371
27372(neverallow base_typeattr_936 base_typeattr_935 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27373;;* lme
27374
27375;;* lmx 26 system/sepolicy/private/shell.te
27376
27377(neverallow base_typeattr_909 shell (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27378;;* lme
27379
27380;;* lmx 26 system/sepolicy/private/shell.te
27381
27382(neverallow base_typeattr_937 shell (process (ptrace)))
27383;;* lme
27384
27385(allow shell storaged (binder (call transfer)))
27386(allow storaged shell (binder (transfer)))
27387(allow shell storaged (fd (use)))
27388(allow shell selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
27389(allow shell selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
27390(allow shell selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27391(allow shell selinuxfs (file (write lock append map open)))
27392(allow shell kernel (security (compute_av)))
27393(allow shell self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
27394(allow shell selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
27395(allow shell selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
27396(allow shell selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27397(allow shell selinuxfs (file (write lock append map open)))
27398(allow shell kernel (security (check_context)))
27399(allow shell traced_consumer_socket (sock_file (write)))
27400(allow shell traced (unix_stream_socket (connectto)))
27401(allow shell traced (fd (use)))
27402(allow shell traced_tmpfs (file (read write getattr map)))
27403(allow shell traced_producer_socket (sock_file (write)))
27404(allow shell traced (unix_stream_socket (connectto)))
27405(allow traced shell (fd (use)))
27406(allow shell vendor_shell_exec (file (read getattr map execute open)))
27407(allow shell vendor_shell (process (transition)))
27408(allow vendor_shell vendor_shell_exec (file (read getattr map execute open entrypoint)))
27409(allow vendor_shell shell (process (sigchld)))
27410(dontaudit shell vendor_shell (process (noatsecure)))
27411(allow shell vendor_shell (process (siginh rlimitinh)))
27412(typetransition shell vendor_shell_exec process vendor_shell)
27413(allow shell perfetto_exec (file (read getattr map execute open)))
27414(allow shell perfetto (process (transition)))
27415(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
27416(allow perfetto shell (process (sigchld)))
27417(dontaudit shell perfetto (process (noatsecure)))
27418(allow shell perfetto (process (siginh rlimitinh)))
27419(typetransition shell perfetto_exec process perfetto)
27420(allow shell perfetto (process (signal)))
27421(allow shell statsd (binder (call transfer)))
27422(allow statsd shell (binder (transfer)))
27423(allow shell statsd (fd (use)))
27424(allow shell perfetto_traces_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27425(allow shell perfetto_traces_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
27426(allow shell perfetto_traces_bugreport_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27427(allow shell perfetto_traces_bugreport_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
27428(allow shell perfetto_configs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27429(allow shell perfetto_configs_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27430(allow shell gpuservice (binder (call transfer)))
27431(allow gpuservice shell (binder (transfer)))
27432(allow shell gpuservice (fd (use)))
27433(allow shell proc_net_tcp_udp (file (ioctl read getattr lock map open watch watch_reads)))
27434(allow shell system_linker_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27435(allow shell rs_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27436(allow shell dex2oat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27437(allow shell dex2oat_exec (lnk_file (read)))
27438(allow shell property_socket (sock_file (write)))
27439(allow shell init (unix_stream_socket (connectto)))
27440(allow shell lpdumpd_prop (property_service (set)))
27441(allow shell lpdumpd_prop (file (read getattr map open)))
27442(allow shell lpdumpd (binder (call transfer)))
27443(allow lpdumpd shell (binder (transfer)))
27444(allow shell lpdumpd (fd (use)))
27445(allow shell property_socket (sock_file (write)))
27446(allow shell init (unix_stream_socket (connectto)))
27447(allow shell userspace_reboot_test_prop (property_service (set)))
27448(allow shell userspace_reboot_test_prop (file (read getattr map open)))
27449(allow shell property_socket (sock_file (write)))
27450(allow shell init (unix_stream_socket (connectto)))
27451(allow shell power_debug_prop (property_service (set)))
27452(allow shell power_debug_prop (file (read getattr map open)))
27453(allow shell property_socket (sock_file (write)))
27454(allow shell init (unix_stream_socket (connectto)))
27455(allow shell rollback_test_prop (property_service (set)))
27456(allow shell rollback_test_prop (file (read getattr map open)))
27457(allow shell property_socket (sock_file (write)))
27458(allow shell init (unix_stream_socket (connectto)))
27459(allow shell remote_prov_prop (property_service (set)))
27460(allow shell remote_prov_prop (file (read getattr map open)))
27461(allowx shell shell_data_file (ioctl dir ((range 0x6615 0x6616))))
27462(allow shell simpleperf_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27463(allow shell remount_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27464(allow shell self (perf_event (open kernel read write)))
27465;;* lmx 137 system/sepolicy/private/shell.te
27466
27467(neverallow shell self (perf_event (cpu tracepoint)))
27468;;* lme
27469
27470(allow shell vendor_microdroid_file (dir (ioctl read getattr lock open watch watch_reads search)))
27471(allow shell vendor_microdroid_file (file (ioctl read getattr lock map open watch watch_reads)))
27472(allow shell vendor_microdroid_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27473(allow shell apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
27474(allow shell vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
27475(allow shell vendor_apex_file (dir (ioctl read getattr lock open watch watch_reads search)))
27476(allow shell vendor_apex_metadata_file (dir (ioctl read getattr lock open watch watch_reads search)))
27477(allow shell apex_data_file (dir (search)))
27478(allow shell staging_data_file (file (ioctl read getattr lock map open watch watch_reads)))
27479(allow shell property_socket (sock_file (write)))
27480(allow shell init (unix_stream_socket (connectto)))
27481(allow shell shell_prop (property_service (set)))
27482(allow shell shell_prop (file (read getattr map open)))
27483(allow shell property_socket (sock_file (write)))
27484(allow shell init (unix_stream_socket (connectto)))
27485(allow shell ctl_bugreport_prop (property_service (set)))
27486(allow shell ctl_bugreport_prop (file (read getattr map open)))
27487(allow shell property_socket (sock_file (write)))
27488(allow shell init (unix_stream_socket (connectto)))
27489(allow shell ctl_dumpstate_prop (property_service (set)))
27490(allow shell ctl_dumpstate_prop (file (read getattr map open)))
27491(allow shell property_socket (sock_file (write)))
27492(allow shell init (unix_stream_socket (connectto)))
27493(allow shell dumpstate_prop (property_service (set)))
27494(allow shell dumpstate_prop (file (read getattr map open)))
27495(allow shell property_socket (sock_file (write)))
27496(allow shell init (unix_stream_socket (connectto)))
27497(allow shell exported_dumpstate_prop (property_service (set)))
27498(allow shell exported_dumpstate_prop (file (read getattr map open)))
27499(allow shell property_socket (sock_file (write)))
27500(allow shell init (unix_stream_socket (connectto)))
27501(allow shell debug_prop (property_service (set)))
27502(allow shell debug_prop (file (read getattr map open)))
27503(allow shell property_socket (sock_file (write)))
27504(allow shell init (unix_stream_socket (connectto)))
27505(allow shell perf_drop_caches_prop (property_service (set)))
27506(allow shell perf_drop_caches_prop (file (read getattr map open)))
27507(allow shell property_socket (sock_file (write)))
27508(allow shell init (unix_stream_socket (connectto)))
27509(allow shell powerctl_prop (property_service (set)))
27510(allow shell powerctl_prop (file (read getattr map open)))
27511(allow shell property_socket (sock_file (write)))
27512(allow shell init (unix_stream_socket (connectto)))
27513(allow shell log_tag_prop (property_service (set)))
27514(allow shell log_tag_prop (file (read getattr map open)))
27515(allow shell property_socket (sock_file (write)))
27516(allow shell init (unix_stream_socket (connectto)))
27517(allow shell wifi_log_prop (property_service (set)))
27518(allow shell wifi_log_prop (file (read getattr map open)))
27519(allow shell property_socket (sock_file (write)))
27520(allow shell init (unix_stream_socket (connectto)))
27521(allow shell traced_enabled_prop (property_service (set)))
27522(allow shell traced_enabled_prop (file (read getattr map open)))
27523(allow shell property_socket (sock_file (write)))
27524(allow shell init (unix_stream_socket (connectto)))
27525(allow shell logd_auditrate_prop (property_service (set)))
27526(allow shell logd_auditrate_prop (file (read getattr map open)))
27527(allow shell property_socket (sock_file (write)))
27528(allow shell init (unix_stream_socket (connectto)))
27529(allow shell heapprofd_enabled_prop (property_service (set)))
27530(allow shell heapprofd_enabled_prop (file (read getattr map open)))
27531(allow shell property_socket (sock_file (write)))
27532(allow shell init (unix_stream_socket (connectto)))
27533(allow shell traced_perf_enabled_prop (property_service (set)))
27534(allow shell traced_perf_enabled_prop (file (read getattr map open)))
27535(allow shell property_socket (sock_file (write)))
27536(allow shell init (unix_stream_socket (connectto)))
27537(allow shell ctl_gsid_prop (property_service (set)))
27538(allow shell ctl_gsid_prop (file (read getattr map open)))
27539(allow shell property_socket (sock_file (write)))
27540(allow shell init (unix_stream_socket (connectto)))
27541(allow shell ctl_snapuserd_prop (property_service (set)))
27542(allow shell ctl_snapuserd_prop (file (read getattr map open)))
27543(allow shell property_socket (sock_file (write)))
27544(allow shell init (unix_stream_socket (connectto)))
27545(allow shell dynamic_system_prop (property_service (set)))
27546(allow shell dynamic_system_prop (file (read getattr map open)))
27547(allow shell property_socket (sock_file (write)))
27548(allow shell init (unix_stream_socket (connectto)))
27549(allow shell mock_ota_prop (property_service (set)))
27550(allow shell mock_ota_prop (file (read getattr map open)))
27551(allow shell serialno_prop (file (read getattr map open)))
27552(allow shell vendor_security_patch_level_prop (file (read getattr map open)))
27553(allow shell device_logging_prop (file (read getattr map open)))
27554(allow shell bootloader_boot_reason_prop (file (read getattr map open)))
27555(allow shell last_boot_reason_prop (file (read getattr map open)))
27556(allow shell system_boot_reason_prop (file (read getattr map open)))
27557(allow shell hal_keymint (binder (call transfer)))
27558(allow hal_keymint shell (binder (transfer)))
27559(allow shell hal_keymint (fd (use)))
27560(allow shell init_perf_lsm_hooks_prop (file (read getattr map open)))
27561(allow shell build_bootimage_prop (file (read getattr map open)))
27562(allow shell odsign_prop (file (read getattr map open)))
27563(allow shell keystore2_key_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
27564(allow shell shell_key (keystore2_key (delete get_info rebind update use)))
27565(allow shell property_socket (sock_file (write)))
27566(allow shell init (unix_stream_socket (connectto)))
27567(allow shell sqlite_log_prop (property_service (set)))
27568(allow shell sqlite_log_prop (file (read getattr map open)))
27569(allow shell property_socket (sock_file (write)))
27570(allow shell init (unix_stream_socket (connectto)))
27571(allow shell arm64_memtag_prop (property_service (set)))
27572(allow shell arm64_memtag_prop (file (read getattr map open)))
27573(allow shell verity_status_prop (file (read getattr map open)))
27574(allow shell virtual_ab_prop (file (read getattr map open)))
27575;;* lmx 238 system/sepolicy/private/shell.te
27576
27577(neverallow base_typeattr_885 perf_drop_caches_prop (property_service (set)))
27578;;* lme
27579
27580;;* lmx 239 system/sepolicy/private/shell.te
27581
27582(neverallow base_typeattr_938 perf_drop_caches_prop (file (read)))
27583;;* lme
27584
27585(allow shell gsi_metadata_file_type (dir (search)))
27586(allow shell metadata_file (dir (search)))
27587(allow shell gsi_public_metadata_file (file (ioctl read getattr lock map open watch watch_reads)))
27588(allow shell proc_bootconfig (file (ioctl read getattr lock map open watch watch_reads)))
27589(allow shell proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
27590(allow shell apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
27591(allow shell virtualizationmanager_exec (file (read getattr map execute open)))
27592(allow shell virtualizationmanager (process (transition)))
27593(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
27594(allow virtualizationmanager shell (process (sigchld)))
27595(dontaudit shell virtualizationmanager (process (noatsecure)))
27596(allow shell virtualizationmanager (process (siginh rlimitinh)))
27597(typetransition shell virtualizationmanager_exec process virtualizationmanager)
27598(allow crosvm shell (unix_stream_socket (ioctl read write getattr)))
27599(allow virtualizationmanager shell (unix_stream_socket (ioctl read write getattr)))
27600(allow crosvm shell (fd (use)))
27601(allow virtualizationmanager shell (fd (use)))
27602(allow shell virtualizationmanager (fd (use)))
27603(allow crosvm shell (fifo_file (ioctl read write getattr)))
27604(allow virtualizationmanager shell (fifo_file (ioctl read write getattr)))
27605(allow shell virtualizationmanager (vsock_socket (read write getattr getopt)))
27606(allow shell hypervisor_prop (file (read getattr map open)))
27607(allow shell virtualizationservice_data_file (file (read getattr)))
27608(allow shell property_socket (sock_file (write)))
27609(allow shell init (unix_stream_socket (connectto)))
27610(allow shell gwp_asan_prop (property_service (set)))
27611(allow shell gwp_asan_prop (file (read getattr map open)))
27612(allow shell build_attestation_prop (file (read getattr map open)))
27613(allow shell oatdump_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27614(allow base_typeattr_939 simpleperf_exec (file (read getattr map execute open)))
27615(allow base_typeattr_939 simpleperf (process (transition)))
27616(allow simpleperf simpleperf_exec (file (read getattr map execute open entrypoint)))
27617(allow simpleperf base_typeattr_939 (process (sigchld)))
27618(dontaudit base_typeattr_939 simpleperf (process (noatsecure)))
27619(allow base_typeattr_939 simpleperf (process (siginh rlimitinh)))
27620(typetransition base_typeattr_939 simpleperf_exec process simpleperf)
27621(typetransition simpleperf tmpfs file appdomain_tmpfs)
27622(allow simpleperf simpleperf_userfaultfd (anon_inode (ioctl read create)))
27623(dontaudit su simpleperf_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27624;;* lmx 23 system/sepolicy/private/simpleperf.te
27625
27626(neverallow base_typeattr_940 simpleperf_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27627;;* lme
27628
27629(allow simpleperf appdomain_tmpfs (file (read write getattr map execute)))
27630;;* lmx 23 system/sepolicy/private/simpleperf.te
27631
27632(neverallow base_typeattr_941 base_typeattr_940 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27633;;* lme
27634
27635;;* lmx 23 system/sepolicy/private/simpleperf.te
27636
27637(neverallow base_typeattr_909 simpleperf (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
27638;;* lme
27639
27640;;* lmx 23 system/sepolicy/private/simpleperf.te
27641
27642(neverallow base_typeattr_910 simpleperf (process (ptrace)))
27643;;* lme
27644
27645(allow simpleperf untrusted_app_all (process (ptrace)))
27646(allow simpleperf ephemeral_app (process (ptrace)))
27647(allow simpleperf isolated_app (process (ptrace)))
27648(allow simpleperf platform_app (process (ptrace)))
27649(allow simpleperf priv_app (process (ptrace)))
27650(allow simpleperf self (perf_event (open kernel read write)))
27651(allow simpleperf untrusted_app_all (dir (ioctl read getattr lock open watch watch_reads search)))
27652(allow simpleperf ephemeral_app (dir (ioctl read getattr lock open watch watch_reads search)))
27653(allow simpleperf isolated_app (dir (ioctl read getattr lock open watch watch_reads search)))
27654(allow simpleperf platform_app (dir (ioctl read getattr lock open watch watch_reads search)))
27655(allow simpleperf priv_app (dir (ioctl read getattr lock open watch watch_reads search)))
27656(allow simpleperf untrusted_app_all (file (ioctl read getattr lock map open watch watch_reads)))
27657(allow simpleperf untrusted_app_all (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27658(allow simpleperf ephemeral_app (file (ioctl read getattr lock map open watch watch_reads)))
27659(allow simpleperf ephemeral_app (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27660(allow simpleperf isolated_app (file (ioctl read getattr lock map open watch watch_reads)))
27661(allow simpleperf isolated_app (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27662(allow simpleperf platform_app (file (ioctl read getattr lock map open watch watch_reads)))
27663(allow simpleperf platform_app (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27664(allow simpleperf priv_app (file (ioctl read getattr lock map open watch watch_reads)))
27665(allow simpleperf priv_app (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27666(allow untrusted_app_all simpleperf (process (signal)))
27667(allow ephemeral_app simpleperf (process (signal)))
27668(allow isolated_app simpleperf (process (signal)))
27669(allow platform_app simpleperf (process (signal)))
27670(allow priv_app simpleperf (process (signal)))
27671(dontaudit simpleperf domain (dir (search)))
27672;;* lmx 51 system/sepolicy/private/simpleperf.te
27673
27674(neverallow simpleperf self (perf_event (cpu tracepoint)))
27675;;* lme
27676
27677(allow shell simpleperf_app_runner_exec (file (read getattr map execute open)))
27678(allow shell simpleperf_app_runner (process (transition)))
27679(allow simpleperf_app_runner simpleperf_app_runner_exec (file (read getattr map execute open entrypoint)))
27680(allow simpleperf_app_runner shell (process (sigchld)))
27681(dontaudit shell simpleperf_app_runner (process (noatsecure)))
27682(allow shell simpleperf_app_runner (process (siginh rlimitinh)))
27683(typetransition shell simpleperf_app_runner_exec process simpleperf_app_runner)
27684(allow simpleperf_app_runner adbd (fd (use)))
27685(allow simpleperf_app_runner shell (fd (use)))
27686(allow simpleperf_app_runner devpts (chr_file (ioctl read write)))
27687(allow simpleperf_app_runner system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
27688(allow simpleperf_app_runner system_data_file (lnk_file (getattr)))
27689(allow simpleperf_app_runner packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
27690(allow simpleperf_app_runner system_data_file (lnk_file (read)))
27691(allow simpleperf_app_runner self (capability (setgid setuid)))
27692(allow simpleperf_app_runner self (cap_userns (setgid setuid)))
27693(allow simpleperf_app_runner selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
27694(allow simpleperf_app_runner selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
27695(allow simpleperf_app_runner selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27696(allow simpleperf_app_runner selinuxfs (file (write lock append map open)))
27697(allow simpleperf_app_runner kernel (security (check_context)))
27698(allow simpleperf_app_runner self (process (setcurrent)))
27699(allow simpleperf_app_runner untrusted_app_all (process (dyntransition)))
27700(allow simpleperf_app_runner ephemeral_app (process (dyntransition)))
27701(allow simpleperf_app_runner isolated_app (process (dyntransition)))
27702(allow simpleperf_app_runner platform_app (process (dyntransition)))
27703(allow simpleperf_app_runner priv_app (process (dyntransition)))
27704(allow simpleperf_app_runner seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
27705(allow simpleperf_app_runner shell (fifo_file (read write)))
27706(allow simpleperf_app_runner shell_data_file (dir (getattr search)))
27707(allow simpleperf_app_runner shell_data_file (file (write getattr)))
27708;;* lmx 44 system/sepolicy/private/simpleperf_app_runner.te
27709
27710(neverallow simpleperf_app_runner self (capability (chown dac_override dac_read_search fowner fsetid kill setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
27711(neverallow simpleperf_app_runner self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
27712;;* lme
27713
27714;;* lmx 45 system/sepolicy/private/simpleperf_app_runner.te
27715
27716(neverallow simpleperf_app_runner self (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
27717(neverallow simpleperf_app_runner self (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
27718;;* lme
27719
27720(allow init snapshotctl_exec (file (read getattr map execute open)))
27721(allow init snapshotctl (process (transition)))
27722(allow snapshotctl snapshotctl_exec (file (read getattr map execute open entrypoint)))
27723(dontaudit init snapshotctl (process (noatsecure)))
27724(allow init snapshotctl (process (siginh rlimitinh)))
27725(typetransition init snapshotctl_exec process snapshotctl)
27726(allow snapshotctl property_socket (sock_file (write)))
27727(allow snapshotctl init (unix_stream_socket (connectto)))
27728(allow snapshotctl ctl_gsid_prop (property_service (set)))
27729(allow snapshotctl ctl_gsid_prop (file (read getattr map open)))
27730(allow snapshotctl servicemanager (binder (call transfer)))
27731(allow servicemanager snapshotctl (binder (call transfer)))
27732(allow servicemanager snapshotctl (dir (search)))
27733(allow servicemanager snapshotctl (file (read open)))
27734(allow servicemanager snapshotctl (process (getattr)))
27735(allow snapshotctl gsi_service (service_manager (find)))
27736(allow snapshotctl gsid (binder (call transfer)))
27737(allow gsid snapshotctl (binder (transfer)))
27738(allow snapshotctl gsid (fd (use)))
27739(allow snapshotctl metadata_file (dir (search)))
27740(allow snapshotctl ota_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27741(allow snapshotctl ota_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27742(allow snapshotctl sysfs_dt_firmware_android (dir (ioctl read getattr lock open watch watch_reads search)))
27743(allow snapshotctl sysfs_dt_firmware_android (file (ioctl read getattr lock map open watch watch_reads)))
27744(allow snapshotctl sysfs_dt_firmware_android (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27745(allow snapshotctl proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
27746(allow snapshotctl block_device (dir (ioctl read getattr lock open watch watch_reads search)))
27747(allow snapshotctl super_block_device (blk_file (ioctl read getattr lock map open watch watch_reads)))
27748(allow snapshotctl dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27749(allow snapshotctl self (capability (sys_admin)))
27750(allow snapshotctl self (cap_userns (sys_admin)))
27751(allow snapshotctl hwservicemanager (binder (call transfer)))
27752(allow hwservicemanager snapshotctl (binder (call transfer)))
27753(allow hwservicemanager snapshotctl (dir (search)))
27754(allow hwservicemanager snapshotctl (file (read map open)))
27755(allow hwservicemanager snapshotctl (process (getattr)))
27756(allow snapshotctl statsdw_socket (sock_file (write)))
27757(allow snapshotctl statsd (unix_dgram_socket (sendto)))
27758(allow init snapuserd_exec (file (read getattr map execute open)))
27759(allow init snapuserd (process (transition)))
27760(allow snapuserd snapuserd_exec (file (read getattr map execute open entrypoint)))
27761(dontaudit init snapuserd (process (noatsecure)))
27762(allow init snapuserd (process (siginh rlimitinh)))
27763(typetransition init snapuserd_exec process snapuserd)
27764(allow snapuserd kmsg_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27765(allow snapuserd block_device (dir (search)))
27766(allow snapuserd sysfs (dir (read open)))
27767(allow snapuserd sysfs_dm (dir (read open search)))
27768(allow snapuserd sysfs_dm (file (ioctl read getattr lock map open watch watch_reads)))
27769(allow snapuserd block_device (dir (ioctl read getattr lock open watch watch_reads search)))
27770(allow snapuserd dm_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27771(allow snapuserd dm_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
27772(allow snapuserd dm_user_device (dir (ioctl read getattr lock open watch watch_reads search)))
27773(allow snapuserd dm_user_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27774(allow snapuserd snapuserd_socket (unix_stream_socket (read write getattr listen accept)))
27775(allow snapuserd snapuserd_proxy_socket (sock_file (write)))
27776(allow snapuserd self (capability (setgid)))
27777(allow snapuserd self (cap_userns (setgid)))
27778(allow snapuserd kernel (fd (use)))
27779(allow snapuserd property_socket (sock_file (write)))
27780(allow snapuserd init (unix_stream_socket (connectto)))
27781(allow snapuserd snapuserd_prop (property_service (set)))
27782(allow snapuserd snapuserd_prop (file (read getattr map open)))
27783(allow snapuserd virtual_ab_prop (file (read getattr map open)))
27784(allow snapuserd tmpfs (dir (read watch)))
27785;;* lmx 56 system/sepolicy/private/snapuserd.te
27786
27787(neverallow base_typeattr_942 snapuserd_prop (property_service (set)))
27788;;* lme
27789
27790(allow snapuserd metadata_file (dir (search)))
27791(allow snapuserd ota_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27792(allow snapuserd ota_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27793(allow snapuserd snapuserd_log_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
27794(allow snapuserd snapuserd_log_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27795(allow snapuserd proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
27796(allow snapuserd self (capability (ipc_lock)))
27797(allow snapuserd snapuserd_iouring (anon_inode (read write create map)))
27798(allow snapuserd self (io_uring (sqpoll)))
27799;;* lmx 73 system/sepolicy/private/snapuserd.te
27800
27801(neverallow base_typeattr_943 snapuserd_iouring (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
27802;;* lme
27803
27804(dontaudit snapuserd self (capability (ipc_lock)))
27805(dontaudit snapuserd self (cap_userns (ipc_lock)))
27806(allow shell stats_exec (file (read getattr map execute open)))
27807(allow shell stats (process (transition)))
27808(allow stats stats_exec (file (read getattr map execute open entrypoint)))
27809(allow stats shell (process (sigchld)))
27810(dontaudit shell stats (process (noatsecure)))
27811(allow shell stats (process (siginh rlimitinh)))
27812(typetransition shell stats_exec process stats)
27813(allow stats shell (fd (use)))
27814(allow stats adbd (fd (use)))
27815(allow stats adbd (unix_stream_socket (read write)))
27816(allow stats adbd (process (sigchld)))
27817(allow stats servicemanager (binder (call transfer)))
27818(allow servicemanager stats (binder (call transfer)))
27819(allow servicemanager stats (dir (search)))
27820(allow servicemanager stats (file (read open)))
27821(allow servicemanager stats (process (getattr)))
27822(allow stats stats_service (service_manager (find)))
27823(allow stats statsd (binder (call transfer)))
27824(allow statsd stats (binder (transfer)))
27825(allow stats statsd (fd (use)))
27826(allow stats statsd (fifo_file (write)))
27827(allow statsd stats_service (service_manager (add find)))
27828;;* lmx 27 system/sepolicy/private/stats.te
27829
27830(neverallow base_typeattr_944 stats_service (service_manager (add)))
27831;;* lme
27832
27833(allow statsd stats (fd (use)))
27834(allow statsd stats (fifo_file (write)))
27835(allow statsd stats (binder (call transfer)))
27836(allow stats statsd (binder (transfer)))
27837(allow statsd stats (fd (use)))
27838(allow init statsd_exec (file (read getattr map execute open)))
27839(allow init statsd (process (transition)))
27840(allow statsd statsd_exec (file (read getattr map execute open entrypoint)))
27841(dontaudit init statsd (process (noatsecure)))
27842(allow init statsd (process (siginh rlimitinh)))
27843(typetransition init statsd_exec process statsd)
27844(allow statsd perfetto_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
27845(allow statsd perfetto_exec (file (read getattr map execute open)))
27846(allow statsd perfetto (process (transition)))
27847(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
27848(allow perfetto statsd (process (sigchld)))
27849(dontaudit statsd perfetto (process (noatsecure)))
27850(allow statsd perfetto (process (siginh rlimitinh)))
27851(typetransition statsd perfetto_exec process perfetto)
27852(allow statsd statscompanion_service (service_manager (find)))
27853(allow statsd incidentd (fifo_file (write)))
27854(allow statsd system_server (fifo_file (read write getattr)))
27855(allow statsd priv_app (fifo_file (read write getattr)))
27856(allow statsd surfaceflinger (binder (call transfer)))
27857(allow surfaceflinger statsd (binder (transfer)))
27858(allow statsd surfaceflinger (fd (use)))
27859(allow statsd device_config_statsd_native_prop (file (read getattr map open)))
27860(allow statsd device_config_statsd_native_boot_prop (file (read getattr map open)))
27861(allow statsd uprobestats_configs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27862(allow statsd uprobestats_configs_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27863(allow statsd property_socket (sock_file (write)))
27864(allow statsd init (unix_stream_socket (connectto)))
27865(allow statsd uprobestats_start_with_config_prop (property_service (set)))
27866(allow statsd uprobestats_start_with_config_prop (file (read getattr map open)))
27867(allow init storaged_exec (file (read getattr map execute open)))
27868(allow init storaged (process (transition)))
27869(allow storaged storaged_exec (file (read getattr map execute open entrypoint)))
27870(dontaudit init storaged (process (noatsecure)))
27871(allow init storaged (process (siginh rlimitinh)))
27872(typetransition init storaged_exec process storaged)
27873(allow storaged domain (dir (ioctl read getattr lock open watch watch_reads search)))
27874(allow storaged domain (file (ioctl read getattr lock map open watch watch_reads)))
27875(allow storaged domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27876(allow storaged proc_uid_io_stats (file (ioctl read getattr lock map open watch watch_reads)))
27877(allow storaged system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
27878(allow storaged packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
27879(allow storaged storaged_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
27880(allow storaged storaged_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
27881(allow storaged shell (fd (use)))
27882(allow storaged shell (fifo_file (write)))
27883(allow storaged priv_app (fd (use)))
27884(allow storaged gmscore_app (fd (use)))
27885(allow storaged app_data_file (file (write)))
27886(allow storaged privapp_data_file (file (write)))
27887(allow storaged permission_service (service_manager (find)))
27888(allow storaged storaged_service (service_manager (add find)))
27889;;* lmx 45 system/sepolicy/private/storaged.te
27890
27891(neverallow base_typeattr_945 storaged_service (service_manager (add)))
27892;;* lme
27893
27894(allow storaged servicemanager (binder (call transfer)))
27895(allow servicemanager storaged (binder (call transfer)))
27896(allow servicemanager storaged (dir (search)))
27897(allow servicemanager storaged (file (read open)))
27898(allow servicemanager storaged (process (getattr)))
27899(allow storaged system_server (binder (call transfer)))
27900(allow system_server storaged (binder (transfer)))
27901(allow storaged system_server (fd (use)))
27902(allow storaged dumpstate (fd (use)))
27903(allow storaged package_native_service (service_manager (find)))
27904(dontaudit storaged self (capability (dac_override dac_read_search)))
27905(dontaudit storaged self (cap_userns (dac_override dac_read_search)))
27906(allow storaged dumpstate (fifo_file (write)))
27907;;* lmx 68 system/sepolicy/private/storaged.te
27908
27909(neverallow storaged domain (process (ptrace)))
27910;;* lme
27911
27912;;* lmx 69 system/sepolicy/private/storaged.te
27913
27914(neverallow storaged self (capability (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
27915(neverallow storaged self (capability2 (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
27916(neverallow storaged self (cap_userns (chown dac_override dac_read_search fowner fsetid kill setgid setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease audit_write audit_control setfcap)))
27917(neverallow storaged self (cap2_userns (mac_override mac_admin syslog wake_alarm block_suspend audit_read perfmon)))
27918;;* lme
27919
27920(allow init surfaceflinger_exec (file (read getattr map execute open)))
27921(allow init surfaceflinger (process (transition)))
27922(allow surfaceflinger surfaceflinger_exec (file (read getattr map execute open entrypoint)))
27923(dontaudit init surfaceflinger (process (noatsecure)))
27924(allow init surfaceflinger (process (siginh rlimitinh)))
27925(typetransition init surfaceflinger_exec process surfaceflinger)
27926(typetransition surfaceflinger tmpfs file surfaceflinger_tmpfs)
27927(allow surfaceflinger surfaceflinger_tmpfs (file (read write getattr map)))
27928(allow surfaceflinger runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
27929(allow surfaceflinger hidl_token_hwservice (hwservice_manager (find)))
27930(allow surfaceflinger servicemanager (binder (call transfer)))
27931(allow servicemanager surfaceflinger (binder (call transfer)))
27932(allow servicemanager surfaceflinger (dir (search)))
27933(allow servicemanager surfaceflinger (file (read open)))
27934(allow servicemanager surfaceflinger (process (getattr)))
27935(allow surfaceflinger binderservicedomain (binder (call transfer)))
27936(allow binderservicedomain surfaceflinger (binder (transfer)))
27937(allow surfaceflinger binderservicedomain (fd (use)))
27938(allow surfaceflinger appdomain (binder (call transfer)))
27939(allow appdomain surfaceflinger (binder (transfer)))
27940(allow surfaceflinger appdomain (fd (use)))
27941(allow surfaceflinger bootanim (binder (call transfer)))
27942(allow bootanim surfaceflinger (binder (transfer)))
27943(allow surfaceflinger bootanim (fd (use)))
27944(allow surfaceflinger system_server (binder (call transfer)))
27945(allow system_server surfaceflinger (binder (transfer)))
27946(allow surfaceflinger system_server (fd (use)))
27947(allow surfaceflinger adbd (binder (call transfer)))
27948(allow adbd surfaceflinger (binder (transfer)))
27949(allow surfaceflinger adbd (fd (use)))
27950(allow surfaceflinger binderservicedomain (dir (ioctl read getattr lock open watch watch_reads search)))
27951(allow surfaceflinger binderservicedomain (file (ioctl read getattr lock map open watch watch_reads)))
27952(allow surfaceflinger binderservicedomain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27953(allow surfaceflinger appdomain (dir (ioctl read getattr lock open watch watch_reads search)))
27954(allow surfaceflinger appdomain (file (ioctl read getattr lock map open watch watch_reads)))
27955(allow surfaceflinger appdomain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
27956(allow surfaceflinger gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27957(allow surfaceflinger gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
27958(allow surfaceflinger sysfs_gpu (file (ioctl read getattr lock map open watch watch_reads)))
27959(allow surfaceflinger graphics_device (dir (search)))
27960(allow surfaceflinger graphics_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27961(allow surfaceflinger video_device (dir (ioctl read getattr lock open watch watch_reads search)))
27962(allow surfaceflinger video_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
27963(allow surfaceflinger dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
27964(allow surfaceflinger self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
27965(allow surfaceflinger property_socket (sock_file (write)))
27966(allow surfaceflinger init (unix_stream_socket (connectto)))
27967(allow surfaceflinger system_prop (property_service (set)))
27968(allow surfaceflinger system_prop (file (read getattr map open)))
27969(allow surfaceflinger property_socket (sock_file (write)))
27970(allow surfaceflinger init (unix_stream_socket (connectto)))
27971(allow surfaceflinger bootanim_system_prop (property_service (set)))
27972(allow surfaceflinger bootanim_system_prop (file (read getattr map open)))
27973(allow surfaceflinger property_socket (sock_file (write)))
27974(allow surfaceflinger init (unix_stream_socket (connectto)))
27975(allow surfaceflinger exported_system_prop (property_service (set)))
27976(allow surfaceflinger exported_system_prop (file (read getattr map open)))
27977(allow surfaceflinger property_socket (sock_file (write)))
27978(allow surfaceflinger init (unix_stream_socket (connectto)))
27979(allow surfaceflinger exported3_system_prop (property_service (set)))
27980(allow surfaceflinger exported3_system_prop (file (read getattr map open)))
27981(allow surfaceflinger property_socket (sock_file (write)))
27982(allow surfaceflinger init (unix_stream_socket (connectto)))
27983(allow surfaceflinger ctl_bootanim_prop (property_service (set)))
27984(allow surfaceflinger ctl_bootanim_prop (file (read getattr map open)))
27985(allow surfaceflinger property_socket (sock_file (write)))
27986(allow surfaceflinger init (unix_stream_socket (connectto)))
27987(allow surfaceflinger locale_prop (property_service (set)))
27988(allow surfaceflinger locale_prop (file (read getattr map open)))
27989(allow surfaceflinger property_socket (sock_file (write)))
27990(allow surfaceflinger init (unix_stream_socket (connectto)))
27991(allow surfaceflinger surfaceflinger_display_prop (property_service (set)))
27992(allow surfaceflinger surfaceflinger_display_prop (file (read getattr map open)))
27993(allow surfaceflinger property_socket (sock_file (write)))
27994(allow surfaceflinger init (unix_stream_socket (connectto)))
27995(allow surfaceflinger timezone_prop (property_service (set)))
27996(allow surfaceflinger timezone_prop (file (read getattr map open)))
27997(allow surfaceflinger qemu_sf_lcd_density_prop (file (read getattr map open)))
27998(allow surfaceflinger device_config_surface_flinger_native_boot_prop (file (read getattr map open)))
27999(allow surfaceflinger appdomain (fd (use)))
28000(allow surfaceflinger app_data_file (file (read write)))
28001(allow surfaceflinger privapp_data_file (file (read write)))
28002(allow surfaceflinger traced (fd (use)))
28003(allow surfaceflinger traced_tmpfs (file (read write getattr map)))
28004(allow surfaceflinger traced_producer_socket (sock_file (write)))
28005(allow surfaceflinger traced (unix_stream_socket (connectto)))
28006(allow traced surfaceflinger (fd (use)))
28007(allow surfaceflinger adbd (unix_stream_socket (read write getattr)))
28008(allow surfaceflinger dumpstate (binder (call transfer)))
28009(allow dumpstate surfaceflinger (binder (transfer)))
28010(allow surfaceflinger dumpstate (fd (use)))
28011(allow surfaceflinger shell (binder (call transfer)))
28012(allow shell surfaceflinger (binder (transfer)))
28013(allow surfaceflinger shell (fd (use)))
28014(allow surfaceflinger dumpstate (dir (ioctl read getattr lock open watch watch_reads search)))
28015(allow surfaceflinger dumpstate (file (ioctl read getattr lock map open watch watch_reads)))
28016(allow surfaceflinger dumpstate (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28017(allow surfaceflinger surfaceflinger_service (service_manager (add find)))
28018(allow surfaceflinger mediaserver_service (service_manager (find)))
28019(allow surfaceflinger permission_service (service_manager (find)))
28020(allow surfaceflinger power_service (service_manager (find)))
28021(allow surfaceflinger vr_manager_service (service_manager (find)))
28022(allow surfaceflinger window_service (service_manager (find)))
28023(allow surfaceflinger inputflinger_service (service_manager (find)))
28024(allow surfaceflinger self (capability (sys_nice)))
28025(allow surfaceflinger self (cap_userns (sys_nice)))
28026(allow surfaceflinger proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
28027(allow surfaceflinger cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
28028(allow surfaceflinger cgroup (file (ioctl read getattr lock map open watch watch_reads)))
28029(allow surfaceflinger cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28030(allow surfaceflinger cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
28031(allow surfaceflinger cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
28032(allow surfaceflinger cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28033(allow surfaceflinger system_file (dir (ioctl read getattr lock open watch watch_reads search)))
28034(allow surfaceflinger system_file (file (ioctl read getattr lock map open watch watch_reads)))
28035(allow surfaceflinger system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28036(allow surfaceflinger tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
28037(allow surfaceflinger system_server (fd (use)))
28038(allow surfaceflinger system_server (unix_stream_socket (read write)))
28039(allow surfaceflinger ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
28040(allow surfaceflinger dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
28041(allow init pdx_display_client_endpoint_socket_type (unix_stream_socket (create bind)))
28042(allow surfaceflinger pdx_display_client_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
28043(allow surfaceflinger self (process (setsockcreate)))
28044(allow surfaceflinger pdx_display_client_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
28045;;* lmx 121 system/sepolicy/private/surfaceflinger.te
28046
28047(neverallow base_typeattr_946 pdx_display_client_endpoint_socket_type (unix_stream_socket (listen accept)))
28048;;* lme
28049
28050(allow init pdx_display_manager_endpoint_socket_type (unix_stream_socket (create bind)))
28051(allow surfaceflinger pdx_display_manager_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
28052(allow surfaceflinger self (process (setsockcreate)))
28053(allow surfaceflinger pdx_display_manager_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
28054;;* lmx 122 system/sepolicy/private/surfaceflinger.te
28055
28056(neverallow base_typeattr_946 pdx_display_manager_endpoint_socket_type (unix_stream_socket (listen accept)))
28057;;* lme
28058
28059(allow init pdx_display_screenshot_endpoint_socket_type (unix_stream_socket (create bind)))
28060(allow surfaceflinger pdx_display_screenshot_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
28061(allow surfaceflinger self (process (setsockcreate)))
28062(allow surfaceflinger pdx_display_screenshot_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
28063;;* lmx 123 system/sepolicy/private/surfaceflinger.te
28064
28065(neverallow base_typeattr_946 pdx_display_screenshot_endpoint_socket_type (unix_stream_socket (listen accept)))
28066;;* lme
28067
28068(allow init pdx_display_vsync_endpoint_socket_type (unix_stream_socket (create bind)))
28069(allow surfaceflinger pdx_display_vsync_endpoint_socket_type (unix_stream_socket (read write getattr setattr lock append listen accept getopt setopt shutdown)))
28070(allow surfaceflinger self (process (setsockcreate)))
28071(allow surfaceflinger pdx_display_vsync_channel_socket_type (unix_stream_socket (ioctl read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
28072;;* lmx 124 system/sepolicy/private/surfaceflinger.te
28073
28074(neverallow base_typeattr_946 pdx_display_vsync_endpoint_socket_type (unix_stream_socket (listen accept)))
28075;;* lme
28076
28077(allow surfaceflinger pdx_bufferhub_client_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
28078(allow surfaceflinger pdx_bufferhub_client_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
28079(allow surfaceflinger pdx_bufferhub_client_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
28080(allow surfaceflinger pdx_bufferhub_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
28081(allow surfaceflinger pdx_bufferhub_client_server_type (fd (use)))
28082(allow pdx_bufferhub_client_server_type surfaceflinger (fd (use)))
28083(allow surfaceflinger pdx_performance_client_endpoint_dir_type (dir (ioctl read getattr lock open watch watch_reads search)))
28084(allow surfaceflinger pdx_performance_client_endpoint_socket_type (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
28085(allow surfaceflinger pdx_performance_client_endpoint_socket_type (unix_stream_socket (read write shutdown connectto)))
28086(allow surfaceflinger pdx_performance_client_channel_socket_type (unix_stream_socket (read write getattr setattr lock append getopt setopt shutdown)))
28087(allow surfaceflinger pdx_performance_client_server_type (fd (use)))
28088(allow pdx_performance_client_server_type surfaceflinger (fd (use)))
28089(allow surfaceflinger stats_service (service_manager (find)))
28090(allow surfaceflinger statsmanager_service (service_manager (find)))
28091(allow surfaceflinger statsd (binder (call transfer)))
28092(allow statsd surfaceflinger (binder (transfer)))
28093(allow surfaceflinger statsd (fd (use)))
28094(allow surfaceflinger hal_evs (fd (use)))
28095(allow surfaceflinger hal_camera (fd (use)))
28096(dontaudit surfaceflinger vendor_default_prop (file (read)))
28097;;* lmx 156 system/sepolicy/private/surfaceflinger.te
28098
28099(neverallow surfaceflinger sdcard_type (file (ioctl read write getattr lock append map open watch watch_reads)))
28100(neverallow surfaceflinger fuse (file (ioctl read write getattr lock append map open watch watch_reads)))
28101;;* lme
28102
28103(dontaudit surfaceflinger unlabeled (dir (search)))
28104(typetransition system_app tmpfs file appdomain_tmpfs)
28105(allow system_app system_app_userfaultfd (anon_inode (ioctl read create)))
28106(dontaudit su system_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
28107;;* lmx 9 system/sepolicy/private/system_app.te
28108
28109(neverallow base_typeattr_947 system_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
28110;;* lme
28111
28112(allow system_app appdomain_tmpfs (file (read write getattr map execute)))
28113;;* lmx 9 system/sepolicy/private/system_app.te
28114
28115(neverallow base_typeattr_948 base_typeattr_947 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
28116;;* lme
28117
28118;;* lmx 9 system/sepolicy/private/system_app.te
28119
28120(neverallow base_typeattr_949 system_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
28121;;* lme
28122
28123;;* lmx 9 system/sepolicy/private/system_app.te
28124
28125(neverallow base_typeattr_950 system_app (process (ptrace)))
28126;;* lme
28127
28128(allow system_app rootfs (dir (getattr)))
28129(allow system_app system_app_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28130(allow system_app system_app_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28131(allow system_app system_app_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28132(allow system_app misc_user_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28133(allow system_app misc_user_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28134(allow system_app apex_data_file (dir (search)))
28135(allow system_app staging_data_file (file (ioctl read getattr lock map open watch watch_reads)))
28136(allow system_app wallpaper_file (file (ioctl read getattr lock map open watch watch_reads)))
28137(allow system_app icon_file (file (ioctl read getattr lock map open watch watch_reads)))
28138(allow system_app property_socket (sock_file (write)))
28139(allow system_app init (unix_stream_socket (connectto)))
28140(allow system_app adaptive_haptics_prop (property_service (set)))
28141(allow system_app adaptive_haptics_prop (file (read getattr map open)))
28142(allow system_app property_socket (sock_file (write)))
28143(allow system_app init (unix_stream_socket (connectto)))
28144(allow system_app arm64_memtag_prop (property_service (set)))
28145(allow system_app arm64_memtag_prop (file (read getattr map open)))
28146(allow system_app property_socket (sock_file (write)))
28147(allow system_app init (unix_stream_socket (connectto)))
28148(allow system_app bluetooth_a2dp_offload_prop (property_service (set)))
28149(allow system_app bluetooth_a2dp_offload_prop (file (read getattr map open)))
28150(allow system_app property_socket (sock_file (write)))
28151(allow system_app init (unix_stream_socket (connectto)))
28152(allow system_app bluetooth_audio_hal_prop (property_service (set)))
28153(allow system_app bluetooth_audio_hal_prop (file (read getattr map open)))
28154(allow system_app property_socket (sock_file (write)))
28155(allow system_app init (unix_stream_socket (connectto)))
28156(allow system_app bluetooth_prop (property_service (set)))
28157(allow system_app bluetooth_prop (file (read getattr map open)))
28158(allow system_app property_socket (sock_file (write)))
28159(allow system_app init (unix_stream_socket (connectto)))
28160(allow system_app debug_prop (property_service (set)))
28161(allow system_app debug_prop (file (read getattr map open)))
28162(allow system_app property_socket (sock_file (write)))
28163(allow system_app init (unix_stream_socket (connectto)))
28164(allow system_app system_prop (property_service (set)))
28165(allow system_app system_prop (file (read getattr map open)))
28166(allow system_app property_socket (sock_file (write)))
28167(allow system_app init (unix_stream_socket (connectto)))
28168(allow system_app exported_bluetooth_prop (property_service (set)))
28169(allow system_app exported_bluetooth_prop (file (read getattr map open)))
28170(allow system_app property_socket (sock_file (write)))
28171(allow system_app init (unix_stream_socket (connectto)))
28172(allow system_app exported_system_prop (property_service (set)))
28173(allow system_app exported_system_prop (file (read getattr map open)))
28174(allow system_app property_socket (sock_file (write)))
28175(allow system_app init (unix_stream_socket (connectto)))
28176(allow system_app exported3_system_prop (property_service (set)))
28177(allow system_app exported3_system_prop (file (read getattr map open)))
28178(allow system_app property_socket (sock_file (write)))
28179(allow system_app init (unix_stream_socket (connectto)))
28180(allow system_app gesture_prop (property_service (set)))
28181(allow system_app gesture_prop (file (read getattr map open)))
28182(allow system_app property_socket (sock_file (write)))
28183(allow system_app init (unix_stream_socket (connectto)))
28184(allow system_app locale_prop (property_service (set)))
28185(allow system_app locale_prop (file (read getattr map open)))
28186(allow system_app property_socket (sock_file (write)))
28187(allow system_app init (unix_stream_socket (connectto)))
28188(allow system_app logd_prop (property_service (set)))
28189(allow system_app logd_prop (file (read getattr map open)))
28190(allow system_app property_socket (sock_file (write)))
28191(allow system_app init (unix_stream_socket (connectto)))
28192(allow system_app net_radio_prop (property_service (set)))
28193(allow system_app net_radio_prop (file (read getattr map open)))
28194(allow system_app property_socket (sock_file (write)))
28195(allow system_app init (unix_stream_socket (connectto)))
28196(allow system_app timezone_prop (property_service (set)))
28197(allow system_app timezone_prop (file (read getattr map open)))
28198(allow system_app property_socket (sock_file (write)))
28199(allow system_app init (unix_stream_socket (connectto)))
28200(allow system_app usb_control_prop (property_service (set)))
28201(allow system_app usb_control_prop (file (read getattr map open)))
28202(allow system_app property_socket (sock_file (write)))
28203(allow system_app init (unix_stream_socket (connectto)))
28204(allow system_app usb_prop (property_service (set)))
28205(allow system_app usb_prop (file (read getattr map open)))
28206(allow system_app property_socket (sock_file (write)))
28207(allow system_app init (unix_stream_socket (connectto)))
28208(allow system_app log_tag_prop (property_service (set)))
28209(allow system_app log_tag_prop (file (read getattr map open)))
28210(allow system_app property_socket (sock_file (write)))
28211(allow system_app init (unix_stream_socket (connectto)))
28212(allow system_app drm_forcel3_prop (property_service (set)))
28213(allow system_app drm_forcel3_prop (file (read getattr map open)))
28214(auditallow system_app net_radio_prop (property_service (set)))
28215(auditallow system_app usb_control_prop (property_service (set)))
28216(auditallow system_app usb_prop (property_service (set)))
28217(allow system_app property_socket (sock_file (write)))
28218(allow system_app init (unix_stream_socket (connectto)))
28219(allow system_app dynamic_system_prop (property_service (set)))
28220(allow system_app dynamic_system_prop (file (read getattr map open)))
28221(allow system_app property_socket (sock_file (write)))
28222(allow system_app init (unix_stream_socket (connectto)))
28223(allow system_app ctl_default_prop (property_service (set)))
28224(allow system_app ctl_default_prop (file (read getattr map open)))
28225(allow system_app property_socket (sock_file (write)))
28226(allow system_app init (unix_stream_socket (connectto)))
28227(allow system_app ctl_bugreport_prop (property_service (set)))
28228(allow system_app ctl_bugreport_prop (file (read getattr map open)))
28229(allow system_app gsid_prop (file (read getattr map open)))
28230(allow system_app enable_16k_pages_prop (file (read getattr map open)))
28231(allow system_app anr_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name search)))
28232(allow system_app anr_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28233(allow system_app asec_apk_file (file (ioctl read getattr lock map open watch watch_reads)))
28234(allow system_app statsd (binder (call transfer)))
28235(allow statsd system_app (binder (transfer)))
28236(allow system_app statsd (fd (use)))
28237(allow system_app incidentd (binder (call transfer)))
28238(allow incidentd system_app (binder (transfer)))
28239(allow system_app incidentd (fd (use)))
28240(allow system_app servicemanager (binder (call transfer)))
28241(allow servicemanager system_app (binder (call transfer)))
28242(allow servicemanager system_app (dir (search)))
28243(allow servicemanager system_app (file (read open)))
28244(allow servicemanager system_app (process (getattr)))
28245(allow system_app update_engine_stable_service (service_manager (find)))
28246(allow system_app update_engine (binder (call transfer)))
28247(allow update_engine system_app (binder (transfer)))
28248(allow system_app update_engine (fd (use)))
28249(allow system_app servicemanager (service_manager (list)))
28250(allow system_app base_typeattr_951 (service_manager (find)))
28251(dontaudit system_app dnsresolver_service (service_manager (find)))
28252(dontaudit system_app dumpstate_service (service_manager (find)))
28253(dontaudit system_app installd_service (service_manager (find)))
28254(dontaudit system_app mdns_service (service_manager (find)))
28255(dontaudit system_app netd_service (service_manager (find)))
28256(dontaudit system_app virtual_touchpad_service (service_manager (find)))
28257(dontaudit system_app vold_service (service_manager (find)))
28258(dontaudit system_app debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
28259(dontaudit system_app proc_pagetypeinfo (file (ioctl read getattr lock map open watch watch_reads)))
28260(dontaudit system_app sysfs_zram (dir (search)))
28261(allow system_app keystore (keystore2_key (delete get_info grant rebind update use)))
28262(allow system_app wifi_key (keystore2_key (delete get_info rebind update use)))
28263(allow system_app proc_version (file (ioctl read getattr lock map open watch watch_reads)))
28264(allow system_app cgroup (file (write lock append map open)))
28265(allow system_app cgroup_v2 (file (write lock append map open)))
28266(allow system_app cgroup_v2 (dir (write lock open add_name remove_name search)))
28267(allow system_app logd_socket (sock_file (write)))
28268(allow system_app logd (unix_stream_socket (connectto)))
28269(allow system_app runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
28270(allow system_app device_logging_prop (file (read getattr map open)))
28271(allow system_app system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
28272(allow system_app game_manager_config_prop (file (read getattr map open)))
28273(allow system_app oem_unlock_prop (file (read getattr map open)))
28274(allow system_app usb_uvc_enabled_prop (file (read getattr map open)))
28275(allow system_app pm_archiving_enabled_prop (file (read getattr map open)))
28276;;* lmx 185 system/sepolicy/private/system_app.te
28277
28278(neverallow system_app fuse_device (chr_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
28279;;* lme
28280
28281;;* lmx 191 system/sepolicy/private/system_app.te
28282
28283(neverallow system_app shell_data_file (dir (read write create setattr relabelfrom link rename open add_name remove_name reparent search rmdir)))
28284;;* lme
28285
28286;;* lmx 192 system/sepolicy/private/system_app.te
28287
28288(neverallow system_app shell_data_file (file (ioctl read lock open)))
28289;;* lme
28290
28291;;* lmx 195 system/sepolicy/private/system_app.te
28292
28293(neverallow base_typeattr_952 adaptive_haptics_prop (property_service (set)))
28294;;* lme
28295
28296;;* lmx 197 system/sepolicy/private/system_app.te
28297
28298(neverallow base_typeattr_952 drm_forcel3_prop (property_service (set)))
28299;;* lme
28300
28301(typetransition system_server tmpfs file system_server_tmpfs)
28302(allow system_server system_server_tmpfs (file (read write getattr map)))
28303(allow system_server system_server_userfaultfd (anon_inode (ioctl read create)))
28304(dontaudit su system_server_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
28305;;* lmx 17 system/sepolicy/private/system_server.te
28306
28307(neverallow base_typeattr_305 system_server_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
28308;;* lme
28309
28310(allow system_server zygote_tmpfs (file (read map)))
28311(allow system_server appdomain_tmpfs (file (read write getattr map)))
28312(allow system_server proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
28313(allow system_server incremental_control_file (file (ioctl read getattr lock map open watch watch_reads)))
28314(allowx system_server incremental_control_file (ioctl file (0x671e 0x6721 0x6723 (range 0x6725 0x6727))))
28315(allowx system_server apk_data_file (ioctl file ((range 0x6601 0x6602))))
28316(allowx system_server apk_data_file (ioctl file ((range 0x671f 0x6720) 0x6722 0x6724)))
28317(allowx system_server apk_data_file (ioctl file (0xf50c (range 0xf511 0xf513) (range 0xf517 0xf518))))
28318(allowx system_server apk_tmp_file (ioctl file (0x6601)))
28319(allowx system_server apk_tmp_file (ioctl file (0xf512)))
28320(allow system_server sysfs_fs_incfs_metrics (file (ioctl read getattr lock map open watch watch_reads)))
28321(allow system_server sysfs_fs_f2fs (dir (ioctl read getattr lock open watch watch_reads search)))
28322(allow system_server sysfs_fs_f2fs (file (ioctl read getattr lock map open watch watch_reads)))
28323(allow system_server sdk_sandbox_system_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28324(allow system_server dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
28325(allow system_server apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
28326(allow system_server dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
28327(allow system_server apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
28328(dontaudit system_server apex_art_data_file (file (execute)))
28329(allowx system_server dalvikcache_data_file (ioctl file (0x6601)))
28330(allowx system_server dalvikcache_data_file (ioctl file (0xf512)))
28331(allow system_server resourcecache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
28332(allow system_server resourcecache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
28333(allow system_server self (process (ptrace)))
28334(allow system_server zygote (fd (use)))
28335(allow system_server zygote (process (sigchld)))
28336(allow system_server app_zygote (process (sigkill signull getpgid)))
28337(allow system_server crash_dump (process (sigkill signull getpgid)))
28338(allow system_server webview_zygote (process (sigkill signull getpgid)))
28339(allow system_server zygote (process (sigkill signull getpgid)))
28340(allow system_server crosvm (process (sigkill signull getpgid)))
28341(allow system_server virtualizationmanager (process (sigkill signull getpgid)))
28342(allow system_server zygote_exec (file (ioctl read getattr lock map open watch watch_reads)))
28343(allow system_server zygote (unix_stream_socket (getattr getopt)))
28344(allowx system_server self (ioctl udp_socket (0x6900 0x6902)))
28345(allowx system_server self (ioctl udp_socket ((range 0x890b 0x890d) 0x8911 0x8914 0x8916 0x8918 0x891a (range 0x891c 0x8920) (range 0x8922 0x8927) 0x8929 (range 0x8930 0x8932) (range 0x8934 0x8937) 0x8939 (range 0x8940 0x8941) 0x8943 (range 0x8946 0x894b) (range 0x8953 0x8955) (range 0x8960 0x8962) (range 0x8970 0x8971) (range 0x8980 0x8983) (range 0x8990 0x8995) (range 0x89a0 0x89a3) 0x89b0 (range 0x89e0 0x89ff))))
28346(allowx system_server self (ioctl udp_socket (0x8b00 0x8b02 0x8b04 0x8b06 0x8b08 0x8b0a 0x8b0c 0x8b0e 0x8b10 (range 0x8b14 0x8b1d) 0x8b20 0x8b22 0x8b24 0x8b26 0x8b28 (range 0x8b2a 0x8b2c) (range 0x8b30 0x8b36) (range 0x8be0 0x8bff))))
28347(allow system_server appdomain (tcp_socket (ioctl)))
28348(allow system_server self (capability (kill net_bind_service net_broadcast net_admin net_raw ipc_lock sys_ptrace sys_boot sys_nice sys_time sys_tty_config)))
28349(allow system_server self (cap_userns (kill net_bind_service net_broadcast net_admin net_raw ipc_lock sys_ptrace sys_boot sys_nice sys_time sys_tty_config)))
28350(allow system_server self (capability2 (wake_alarm)))
28351(allow system_server self (cap2_userns (wake_alarm)))
28352(allow system_server self (netlink_netfilter_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28353(allow system_server self (netlink_tcpdiag_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
28354(allow system_server self (netlink_kobject_uevent_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28355(allow system_server self (netlink_nflog_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28356(allow system_server self (netlink_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28357(allow system_server self (netlink_generic_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28358(allow system_server config_gz (file (read open)))
28359(allow system_server self (socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28360(allow system_server self (netlink_route_socket (nlmsg_write)))
28361(allow system_server self (netlink_xfrm_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown nlmsg_read nlmsg_write)))
28362(allow system_server appdomain (process (sigkill signal getpgid)))
28363(allow system_server appdomain (process (signull)))
28364(allow system_server appdomain (process (getsched setsched)))
28365(allow system_server audioserver (process (getsched setsched)))
28366(allow system_server hal_audio (process (getsched setsched)))
28367(allow system_server hal_bluetooth (process (getsched setsched)))
28368(allow system_server hal_codec2_server (process (getsched setsched)))
28369(allow system_server hal_omx_server (process (getsched setsched)))
28370(allow system_server mediaswcodec (process (getsched setsched)))
28371(allow system_server cameraserver (process (getsched setsched)))
28372(allow system_server hal_camera (process (getsched setsched)))
28373(allow system_server mediaserver (process (getsched setsched)))
28374(allow system_server bootanim (process (getsched setsched)))
28375(allow system_server kernel (process (getsched setsched)))
28376(allow system_server domain (file (write lock append map open)))
28377(allow system_server domain (dir (ioctl read getattr lock open watch watch_reads search)))
28378(allow system_server domain (file (ioctl read getattr lock map open watch watch_reads)))
28379(allow system_server domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28380(allow system_server proc_uid_cputime_removeuid (file (write getattr lock append map open)))
28381(allow system_server proc_uid_procstat_set (file (write getattr lock append map open)))
28382(allow system_server proc_sysrq (file (ioctl read write getattr lock append map open watch watch_reads)))
28383(allow system_server stats_config_data_file (dir (read write open remove_name search)))
28384(allow system_server stats_config_data_file (file (unlink)))
28385(allow system_server odsign_data_file (dir (search)))
28386(allow system_server odsign_metrics_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search)))
28387(allow system_server odsign_metrics_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
28388(allow system_server sysfs_ion (file (ioctl read getattr lock map open watch watch_reads)))
28389(allow system_server sysfs_dma_heap (file (ioctl read getattr lock map open watch watch_reads)))
28390(allow system_server sysfs_dmabuf_stats (dir (ioctl read getattr lock open watch watch_reads search)))
28391(allow system_server sysfs_dmabuf_stats (file (ioctl read getattr lock map open watch watch_reads)))
28392(allow system_server dmabuf_heap_device (dir (ioctl read getattr lock open watch watch_reads search)))
28393(allow system_server proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
28394(allow system_server self (packet_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28395(allow system_server self (tun_socket (read write create getattr setattr lock append map bind connect getopt setopt shutdown)))
28396(allow system_server lmkd_socket (sock_file (write)))
28397(allow system_server lmkd (unix_stream_socket (connectto)))
28398(allow system_server zygote_socket (sock_file (write)))
28399(allow system_server zygote (unix_stream_socket (connectto)))
28400(allow system_server uncrypt_socket (sock_file (write)))
28401(allow system_server uncrypt (unix_stream_socket (connectto)))
28402(allow system_server statsdw_socket (sock_file (write)))
28403(allow system_server statsd (unix_dgram_socket (sendto)))
28404(allow system_server surfaceflinger (unix_stream_socket (read write setopt)))
28405(allow system_server gpuservice (unix_stream_socket (read write setopt)))
28406(allow system_server webview_zygote (unix_stream_socket (read write setopt connectto)))
28407(allow system_server app_zygote (unix_stream_socket (read write setopt connectto)))
28408(allow system_server servicemanager (binder (call transfer)))
28409(allow servicemanager system_server (binder (call transfer)))
28410(allow servicemanager system_server (dir (search)))
28411(allow servicemanager system_server (file (read open)))
28412(allow servicemanager system_server (process (getattr)))
28413(allow system_server appdomain (binder (call transfer)))
28414(allow appdomain system_server (binder (transfer)))
28415(allow system_server appdomain (fd (use)))
28416(allow system_server artd (binder (call transfer)))
28417(allow artd system_server (binder (transfer)))
28418(allow system_server artd (fd (use)))
28419(allow system_server binderservicedomain (binder (call transfer)))
28420(allow binderservicedomain system_server (binder (transfer)))
28421(allow system_server binderservicedomain (fd (use)))
28422(allow system_server composd (binder (call transfer)))
28423(allow composd system_server (binder (transfer)))
28424(allow system_server composd (fd (use)))
28425(allow system_server dexopt_chroot_setup (binder (call transfer)))
28426(allow dexopt_chroot_setup system_server (binder (transfer)))
28427(allow system_server dexopt_chroot_setup (fd (use)))
28428(allow system_server dumpstate (binder (call transfer)))
28429(allow dumpstate system_server (binder (transfer)))
28430(allow system_server dumpstate (fd (use)))
28431(allow system_server fingerprintd (binder (call transfer)))
28432(allow fingerprintd system_server (binder (transfer)))
28433(allow system_server fingerprintd (fd (use)))
28434(allow system_server gatekeeperd (binder (call transfer)))
28435(allow gatekeeperd system_server (binder (transfer)))
28436(allow system_server gatekeeperd (fd (use)))
28437(allow system_server gpuservice (binder (call transfer)))
28438(allow gpuservice system_server (binder (transfer)))
28439(allow system_server gpuservice (fd (use)))
28440(allow system_server idmap (binder (call transfer)))
28441(allow idmap system_server (binder (transfer)))
28442(allow system_server idmap (fd (use)))
28443(allow system_server installd (binder (call transfer)))
28444(allow installd system_server (binder (transfer)))
28445(allow system_server installd (fd (use)))
28446(allow system_server incidentd (binder (call transfer)))
28447(allow incidentd system_server (binder (transfer)))
28448(allow system_server incidentd (fd (use)))
28449(allow system_server netd (binder (call transfer)))
28450(allow netd system_server (binder (transfer)))
28451(allow system_server netd (fd (use)))
28452(allow system_server ot_daemon (binder (call transfer)))
28453(allow ot_daemon system_server (binder (transfer)))
28454(allow system_server ot_daemon (fd (use)))
28455(allow system_server statsd (binder (call transfer)))
28456(allow statsd system_server (binder (transfer)))
28457(allow system_server statsd (fd (use)))
28458(allow system_server storaged (binder (call transfer)))
28459(allow storaged system_server (binder (transfer)))
28460(allow system_server storaged (fd (use)))
28461(allow system_server update_engine (binder (call transfer)))
28462(allow update_engine system_server (binder (transfer)))
28463(allow system_server update_engine (fd (use)))
28464(allow system_server virtual_camera (binder (call transfer)))
28465(allow virtual_camera system_server (binder (transfer)))
28466(allow system_server virtual_camera (fd (use)))
28467(allow system_server vold (binder (call transfer)))
28468(allow vold system_server (binder (transfer)))
28469(allow system_server vold (fd (use)))
28470(allow system_server logd (binder (call transfer)))
28471(allow logd system_server (binder (transfer)))
28472(allow system_server logd (fd (use)))
28473(allow system_server wificond (binder (call transfer)))
28474(allow wificond system_server (binder (transfer)))
28475(allow system_server wificond (fd (use)))
28476(allow system_server uprobestats (binder (call transfer)))
28477(allow uprobestats system_server (binder (transfer)))
28478(allow system_server uprobestats (fd (use)))
28479(allow system_server hal_graphics_composer (fd (use)))
28480(allow system_server hal_renderscript_hwservice (hwservice_manager (find)))
28481(allow system_server same_process_hal_file (file (read getattr map execute open)))
28482(allow system_server tombstoned_intercept_socket (sock_file (write)))
28483(allow system_server tombstoned (unix_stream_socket (connectto)))
28484(allow system_server hwservicemanager (hwservice_manager (list)))
28485(allow system_server servicemanager (service_manager (list)))
28486(allow system_server hal_audio_server (process (signal)))
28487(allow system_server hal_bluetooth_server (process (signal)))
28488(allow system_server hal_camera_server (process (signal)))
28489(allow system_server hal_codec2_server (process (signal)))
28490(allow system_server hal_face_server (process (signal)))
28491(allow system_server hal_fingerprint_server (process (signal)))
28492(allow system_server hal_gnss_server (process (signal)))
28493(allow system_server hal_graphics_allocator_server (process (signal)))
28494(allow system_server hal_graphics_composer_server (process (signal)))
28495(allow system_server hal_health_server (process (signal)))
28496(allow system_server hal_input_processor_server (process (signal)))
28497(allow system_server hal_light_server (process (signal)))
28498(allow system_server hal_neuralnetworks_server (process (signal)))
28499(allow system_server hal_omx_server (process (signal)))
28500(allow system_server hal_power_server (process (signal)))
28501(allow system_server hal_power_stats_server (process (signal)))
28502(allow system_server hal_sensors_server (process (signal)))
28503(allow system_server hal_vibrator_server (process (signal)))
28504(allow system_server hal_vr_server (process (signal)))
28505(allow system_server system_suspend_server (process (signal)))
28506(allow system_server artd (process (signal)))
28507(allow system_server audioserver (process (signal)))
28508(allow system_server cameraserver (process (signal)))
28509(allow system_server drmserver (process (signal)))
28510(allow system_server gpuservice (process (signal)))
28511(allow system_server inputflinger (process (signal)))
28512(allow system_server keystore (process (signal)))
28513(allow system_server mediadrmserver (process (signal)))
28514(allow system_server mediaextractor (process (signal)))
28515(allow system_server mediametrics (process (signal)))
28516(allow system_server mediaserver (process (signal)))
28517(allow system_server mediaswcodec (process (signal)))
28518(allow system_server mediatranscoding (process (signal)))
28519(allow system_server netd (process (signal)))
28520(allow system_server sdcardd (process (signal)))
28521(allow system_server servicemanager (process (signal)))
28522(allow system_server statsd (process (signal)))
28523(allow system_server surfaceflinger (process (signal)))
28524(allow system_server vold (process (signal)))
28525(allow system_server mediatuner (process (signal)))
28526(allow system_server audioserver (tcp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28527(allow system_server audioserver (udp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28528(allow system_server mediaserver (tcp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28529(allow system_server mediaserver (udp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28530(allow system_server mediadrmserver (tcp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28531(allow system_server mediadrmserver (udp_socket (ioctl read write getattr setattr lock append map bind connect getopt setopt shutdown)))
28532(allow system_server traced (fd (use)))
28533(allow system_server traced_tmpfs (file (read write getattr map)))
28534(allow system_server traced_producer_socket (sock_file (write)))
28535(allow system_server traced (unix_stream_socket (connectto)))
28536(allow traced system_server (fd (use)))
28537(allow system_server file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
28538(allow system_server mac_perms_file (file (ioctl read getattr lock map open watch watch_reads)))
28539(allow system_server selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
28540(allow system_server selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
28541(allow system_server selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28542(allow system_server selinuxfs (file (write lock append map open)))
28543(allow system_server kernel (security (compute_av)))
28544(allow system_server self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
28545(allow system_server sysfs_type (dir (ioctl read getattr lock open watch watch_reads search)))
28546(allow system_server sysfs_android_usb (dir (ioctl read getattr lock open watch watch_reads search)))
28547(allow system_server sysfs_android_usb (file (ioctl read getattr lock map open watch watch_reads)))
28548(allow system_server sysfs_android_usb (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28549(allow system_server sysfs_android_usb (file (write lock append map open)))
28550(allow system_server sysfs_extcon (dir (ioctl read getattr lock open watch watch_reads search)))
28551(allow system_server sysfs_extcon (file (ioctl read getattr lock map open watch watch_reads)))
28552(allow system_server sysfs_extcon (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28553(allow system_server sysfs_ipv4 (dir (ioctl read getattr lock open watch watch_reads search)))
28554(allow system_server sysfs_ipv4 (file (ioctl read getattr lock map open watch watch_reads)))
28555(allow system_server sysfs_ipv4 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28556(allow system_server sysfs_ipv4 (file (write lock append map open)))
28557(allow system_server sysfs_rtc (dir (ioctl read getattr lock open watch watch_reads search)))
28558(allow system_server sysfs_rtc (file (ioctl read getattr lock map open watch watch_reads)))
28559(allow system_server sysfs_rtc (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28560(allow system_server sysfs_switch (dir (ioctl read getattr lock open watch watch_reads search)))
28561(allow system_server sysfs_switch (file (ioctl read getattr lock map open watch watch_reads)))
28562(allow system_server sysfs_switch (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28563(allow system_server sysfs_nfc_power_writable (file (ioctl read write getattr lock append map open watch watch_reads)))
28564(allow system_server sysfs_power (dir (search)))
28565(allow system_server sysfs_power (file (ioctl read write getattr lock append map open watch watch_reads)))
28566(allow system_server sysfs_thermal (dir (search)))
28567(allow system_server sysfs_thermal (file (ioctl read getattr lock map open watch watch_reads)))
28568(allow system_server sysfs_uhid (dir (ioctl read getattr lock open watch watch_reads search)))
28569(allow system_server sysfs_uhid (file (ioctl read write getattr lock append map open watch watch_reads)))
28570(allow system_server sysfs_vibrator (file (write append)))
28571(allow system_server sysfs_usb (file (write lock append map open)))
28572(allow system_server device (dir (ioctl read getattr lock open watch watch_reads search)))
28573(allow system_server mdns_socket (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
28574(allow system_server gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28575(allow system_server gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
28576(allow system_server sysfs_gpu (file (ioctl read getattr lock map open watch watch_reads)))
28577(allow system_server input_device (dir (ioctl read getattr lock open watch watch_reads search)))
28578(allow system_server input_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28579(allow system_server tty_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28580(allow system_server usbaccessory_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28581(allow system_server video_device (dir (ioctl read getattr lock open watch watch_reads search)))
28582(allow system_server video_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28583(allow system_server adbd_socket (sock_file (ioctl read write getattr lock append map open watch watch_reads)))
28584(allow system_server rtc_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28585(allow system_server audio_device (dir (ioctl read getattr lock open watch watch_reads search)))
28586(allow system_server uhid_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28587(allow system_server hidraw_device (dir (ioctl read getattr lock open watch watch_reads search)))
28588(allow system_server hidraw_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28589(allow system_server audio_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28590(allow system_server tun_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
28591(allowx system_server tun_device (ioctl chr_file (0x54ca 0x54cd 0x54d2 0x54e2)))
28592(allow system_server ota_package_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28593(allow system_server ota_package_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28594(allow system_server system_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28595(allow system_server system_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28596(allow system_server system_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28597(allow system_server system_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28598(allow system_server system_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28599(allow system_server packages_list_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28600(allow system_server game_mode_intervention_list_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28601(allow system_server keychain_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28602(allow system_server keychain_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28603(allow system_server keychain_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28604(allow system_server system_userdir_file (dir (ioctl read getattr lock open watch watch_reads search)))
28605(allow system_server apk_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28606(allow system_server apk_data_file (file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
28607(allow system_server apk_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
28608(allow system_server apk_tmp_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28609(allow system_server apk_tmp_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28610(allow system_server vendor_keylayout_file (dir (ioctl read getattr lock open watch watch_reads search)))
28611(allow system_server vendor_keylayout_file (file (ioctl read getattr lock map open watch watch_reads)))
28612(allow system_server vendor_keylayout_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28613(allow system_server vendor_keychars_file (dir (ioctl read getattr lock open watch watch_reads search)))
28614(allow system_server vendor_keychars_file (file (ioctl read getattr lock map open watch watch_reads)))
28615(allow system_server vendor_keychars_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28616(allow system_server vendor_idc_file (dir (ioctl read getattr lock open watch watch_reads search)))
28617(allow system_server vendor_idc_file (file (ioctl read getattr lock map open watch watch_reads)))
28618(allow system_server vendor_idc_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28619(allow system_server input_device_config_prop (file (read getattr map open)))
28620(allow system_server vendor_app_file (dir (ioctl read getattr lock open watch watch_reads search)))
28621(allow system_server vendor_app_file (file (ioctl read getattr lock map open watch watch_reads)))
28622(allow system_server vendor_app_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28623(allow system_server vendor_framework_file (dir (ioctl read getattr lock open watch watch_reads search)))
28624(allow system_server vendor_framework_file (file (ioctl read getattr lock map open watch watch_reads)))
28625(allow system_server vendor_framework_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28626(allow system_server vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
28627(allow system_server vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
28628(allow system_server vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
28629(allow system_server apk_private_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28630(allow system_server apk_private_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28631(allow system_server apk_private_tmp_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28632(allow system_server apk_private_tmp_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28633(allow system_server asec_apk_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28634(allow system_server asec_apk_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28635(allow system_server asec_public_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28636(allow system_server anr_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28637(allow system_server anr_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28638(allow system_server tombstoned_java_trace_socket (sock_file (write)))
28639(allow system_server tombstoned (unix_stream_socket (connectto)))
28640(allow system_server tombstoned (fd (use)))
28641(allow system_server dumpstate (fifo_file (append)))
28642(allow system_server incidentd (fifo_file (append)))
28643(allow system_server incidentd (fifo_file (read)))
28644(allow system_server incident_data_file (file (read)))
28645(allow system_server prereboot_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28646(allow system_server prereboot_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28647(allow system_server perfetto_traces_data_file (file (read getattr)))
28648(allow system_server perfetto (fd (use)))
28649(allow system_server perfetto_exec (file (read getattr map execute open)))
28650(allow system_server perfetto (process (transition)))
28651(allow perfetto perfetto_exec (file (read getattr map execute open entrypoint)))
28652(allow perfetto system_server (process (sigchld)))
28653(dontaudit system_server perfetto (process (noatsecure)))
28654(allow system_server perfetto (process (siginh rlimitinh)))
28655(typetransition system_server perfetto_exec process perfetto)
28656(allow system_server perfetto (fifo_file (read write)))
28657(allow system_server perfetto_traces_profiling_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28658(allow system_server perfetto_traces_profiling_data_file (file (ioctl read write getattr lock append map unlink open watch watch_reads)))
28659(allow system_server perfetto_traces_data_file (dir (search)))
28660(allow system_server backup_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28661(allow system_server backup_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28662(allow system_server dropbox_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28663(allow system_server dropbox_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28664(allow system_server heapdump_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28665(allow system_server heapdump_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28666(allow system_server adb_keys_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28667(allow system_server adb_keys_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28668(allow system_server appcompat_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28669(allow system_server appcompat_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28670(allow system_server emergency_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28671(allow system_server emergency_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28672(allow system_server network_watchlist_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28673(allow system_server network_watchlist_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28674(allow system_server radio_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28675(allow system_server radio_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28676(allow system_server systemkeys_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28677(allow system_server systemkeys_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28678(allow system_server textclassifier_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28679(allow system_server textclassifier_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28680(allow system_server tombstone_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
28681(allow system_server tombstone_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28682(allow system_server vpn_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28683(allow system_server vpn_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28684(allow system_server wifi_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28685(allow system_server wifi_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28686(allow system_server staging_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28687(allow system_server staging_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28688(allow system_server staging_data_file (file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
28689(allow system_server staging_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink link rename open watch watch_reads)))
28690(allow system_server app_data_file_type (dir (read getattr search)))
28691(allow system_server unlabeled (dir (ioctl read getattr lock open watch watch_reads search)))
28692(allow system_server unlabeled (file (ioctl read getattr lock map open watch watch_reads)))
28693(allow system_server system_app_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
28694(allow system_server system_app_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28695(allow system_server app_data_file_type (file (read write getattr append map)))
28696(allow system_server media_rw_data_file (dir (read getattr open search)))
28697(allow system_server media_rw_data_file (file (read write getattr append)))
28698(allow system_server system_server (process (setfscreate)))
28699(allow system_server apk_tmp_file (file (relabelfrom relabelto)))
28700(allow system_server apk_tmp_file (dir (relabelfrom relabelto)))
28701(allow system_server apk_private_tmp_file (file (relabelfrom relabelto)))
28702(allow system_server apk_private_tmp_file (dir (relabelfrom relabelto)))
28703(allow system_server apk_data_file (file (relabelfrom relabelto)))
28704(allow system_server apk_data_file (dir (relabelfrom relabelto)))
28705(allow system_server apk_private_data_file (file (relabelfrom relabelto)))
28706(allow system_server apk_private_data_file (dir (relabelfrom relabelto)))
28707(allow system_server staging_data_file (file (relabelfrom relabelto)))
28708(allow system_server staging_data_file (dir (relabelfrom relabelto)))
28709(allow system_server system_data_file (file (relabelfrom)))
28710(allow system_server wallpaper_file (file (relabelto)))
28711(allow system_server wallpaper_file (file (ioctl read write getattr lock append map unlink rename open watch watch_reads)))
28712(allow system_server system_data_file (file (link)))
28713(allow system_server wallpaper_file (file (link)))
28714(allow system_server system_data_file (dir (relabelfrom)))
28715(allow system_server shortcut_manager_icons (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
28716(allow system_server shortcut_manager_icons (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28717(allow system_server ringtone_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
28718(allow system_server ringtone_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
28719(allow system_server icon_file (file (relabelto)))
28720(allow system_server icon_file (file (ioctl read write getattr lock append map unlink open watch watch_reads)))
28721(allow system_server system_data_file (dir (relabelfrom)))
28722(allow system_server server_configurable_flags_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
28723(allow system_server server_configurable_flags_data_file (file (ioctl read getattr lock map open watch watch_reads)))
28724(allow system_server property_socket (sock_file (write)))
28725(allow system_server init (unix_stream_socket (connectto)))
28726(allow system_server system_prop (property_service (set)))
28727(allow system_server system_prop (file (read getattr map open)))
28728(allow system_server property_socket (sock_file (write)))
28729(allow system_server init (unix_stream_socket (connectto)))
28730(allow system_server bootanim_system_prop (property_service (set)))
28731(allow system_server bootanim_system_prop (file (read getattr map open)))
28732(allow system_server property_socket (sock_file (write)))
28733(allow system_server init (unix_stream_socket (connectto)))
28734(allow system_server bluetooth_prop (property_service (set)))
28735(allow system_server bluetooth_prop (file (read getattr map open)))
28736(allow system_server property_socket (sock_file (write)))
28737(allow system_server init (unix_stream_socket (connectto)))
28738(allow system_server exported_system_prop (property_service (set)))
28739(allow system_server exported_system_prop (file (read getattr map open)))
28740(allow system_server property_socket (sock_file (write)))
28741(allow system_server init (unix_stream_socket (connectto)))
28742(allow system_server exported3_system_prop (property_service (set)))
28743(allow system_server exported3_system_prop (file (read getattr map open)))
28744(allow system_server property_socket (sock_file (write)))
28745(allow system_server init (unix_stream_socket (connectto)))
28746(allow system_server safemode_prop (property_service (set)))
28747(allow system_server safemode_prop (file (read getattr map open)))
28748(allow system_server property_socket (sock_file (write)))
28749(allow system_server init (unix_stream_socket (connectto)))
28750(allow system_server theme_prop (property_service (set)))
28751(allow system_server theme_prop (file (read getattr map open)))
28752(allow system_server property_socket (sock_file (write)))
28753(allow system_server init (unix_stream_socket (connectto)))
28754(allow system_server dhcp_prop (property_service (set)))
28755(allow system_server dhcp_prop (file (read getattr map open)))
28756(allow system_server property_socket (sock_file (write)))
28757(allow system_server init (unix_stream_socket (connectto)))
28758(allow system_server net_connectivity_prop (property_service (set)))
28759(allow system_server net_connectivity_prop (file (read getattr map open)))
28760(allow system_server property_socket (sock_file (write)))
28761(allow system_server init (unix_stream_socket (connectto)))
28762(allow system_server net_radio_prop (property_service (set)))
28763(allow system_server net_radio_prop (file (read getattr map open)))
28764(allow system_server property_socket (sock_file (write)))
28765(allow system_server init (unix_stream_socket (connectto)))
28766(allow system_server net_dns_prop (property_service (set)))
28767(allow system_server net_dns_prop (file (read getattr map open)))
28768(allow system_server property_socket (sock_file (write)))
28769(allow system_server init (unix_stream_socket (connectto)))
28770(allow system_server usb_control_prop (property_service (set)))
28771(allow system_server usb_control_prop (file (read getattr map open)))
28772(allow system_server property_socket (sock_file (write)))
28773(allow system_server init (unix_stream_socket (connectto)))
28774(allow system_server usb_prop (property_service (set)))
28775(allow system_server usb_prop (file (read getattr map open)))
28776(allow system_server property_socket (sock_file (write)))
28777(allow system_server init (unix_stream_socket (connectto)))
28778(allow system_server debug_prop (property_service (set)))
28779(allow system_server debug_prop (file (read getattr map open)))
28780(allow system_server property_socket (sock_file (write)))
28781(allow system_server init (unix_stream_socket (connectto)))
28782(allow system_server powerctl_prop (property_service (set)))
28783(allow system_server powerctl_prop (file (read getattr map open)))
28784(allow system_server property_socket (sock_file (write)))
28785(allow system_server init (unix_stream_socket (connectto)))
28786(allow system_server fingerprint_prop (property_service (set)))
28787(allow system_server fingerprint_prop (file (read getattr map open)))
28788(allow system_server property_socket (sock_file (write)))
28789(allow system_server init (unix_stream_socket (connectto)))
28790(allow system_server device_logging_prop (property_service (set)))
28791(allow system_server device_logging_prop (file (read getattr map open)))
28792(allow system_server property_socket (sock_file (write)))
28793(allow system_server init (unix_stream_socket (connectto)))
28794(allow system_server dumpstate_options_prop (property_service (set)))
28795(allow system_server dumpstate_options_prop (file (read getattr map open)))
28796(allow system_server property_socket (sock_file (write)))
28797(allow system_server init (unix_stream_socket (connectto)))
28798(allow system_server overlay_prop (property_service (set)))
28799(allow system_server overlay_prop (file (read getattr map open)))
28800(allow system_server property_socket (sock_file (write)))
28801(allow system_server init (unix_stream_socket (connectto)))
28802(allow system_server exported_overlay_prop (property_service (set)))
28803(allow system_server exported_overlay_prop (file (read getattr map open)))
28804(allow system_server property_socket (sock_file (write)))
28805(allow system_server init (unix_stream_socket (connectto)))
28806(allow system_server pm_prop (property_service (set)))
28807(allow system_server pm_prop (file (read getattr map open)))
28808(allow system_server property_socket (sock_file (write)))
28809(allow system_server init (unix_stream_socket (connectto)))
28810(allow system_server exported_pm_prop (property_service (set)))
28811(allow system_server exported_pm_prop (file (read getattr map open)))
28812(allow system_server property_socket (sock_file (write)))
28813(allow system_server init (unix_stream_socket (connectto)))
28814(allow system_server socket_hook_prop (property_service (set)))
28815(allow system_server socket_hook_prop (file (read getattr map open)))
28816(allow system_server property_socket (sock_file (write)))
28817(allow system_server init (unix_stream_socket (connectto)))
28818(allow system_server audio_prop (property_service (set)))
28819(allow system_server audio_prop (file (read getattr map open)))
28820(allow system_server property_socket (sock_file (write)))
28821(allow system_server init (unix_stream_socket (connectto)))
28822(allow system_server boot_status_prop (property_service (set)))
28823(allow system_server boot_status_prop (file (read getattr map open)))
28824(allow system_server property_socket (sock_file (write)))
28825(allow system_server init (unix_stream_socket (connectto)))
28826(allow system_server surfaceflinger_color_prop (property_service (set)))
28827(allow system_server surfaceflinger_color_prop (file (read getattr map open)))
28828(allow system_server property_socket (sock_file (write)))
28829(allow system_server init (unix_stream_socket (connectto)))
28830(allow system_server provisioned_prop (property_service (set)))
28831(allow system_server provisioned_prop (file (read getattr map open)))
28832(allow system_server property_socket (sock_file (write)))
28833(allow system_server init (unix_stream_socket (connectto)))
28834(allow system_server retaildemo_prop (property_service (set)))
28835(allow system_server retaildemo_prop (file (read getattr map open)))
28836(allow system_server property_socket (sock_file (write)))
28837(allow system_server init (unix_stream_socket (connectto)))
28838(allow system_server dmesgd_start_prop (property_service (set)))
28839(allow system_server dmesgd_start_prop (file (read getattr map open)))
28840(allow system_server property_socket (sock_file (write)))
28841(allow system_server init (unix_stream_socket (connectto)))
28842(allow system_server locale_prop (property_service (set)))
28843(allow system_server locale_prop (file (read getattr map open)))
28844(allow system_server property_socket (sock_file (write)))
28845(allow system_server init (unix_stream_socket (connectto)))
28846(allow system_server timezone_metadata_prop (property_service (set)))
28847(allow system_server timezone_metadata_prop (file (read getattr map open)))
28848(allow system_server property_socket (sock_file (write)))
28849(allow system_server init (unix_stream_socket (connectto)))
28850(allow system_server timezone_prop (property_service (set)))
28851(allow system_server timezone_prop (file (read getattr map open)))
28852(allow system_server property_socket (sock_file (write)))
28853(allow system_server init (unix_stream_socket (connectto)))
28854(allow system_server crashrecovery_prop (property_service (set)))
28855(allow system_server crashrecovery_prop (file (read getattr map open)))
28856(allow system_server property_socket (sock_file (write)))
28857(allow system_server init (unix_stream_socket (connectto)))
28858(allow system_server ctl_default_prop (property_service (set)))
28859(allow system_server ctl_default_prop (file (read getattr map open)))
28860(allow system_server property_socket (sock_file (write)))
28861(allow system_server init (unix_stream_socket (connectto)))
28862(allow system_server ctl_bugreport_prop (property_service (set)))
28863(allow system_server ctl_bugreport_prop (file (read getattr map open)))
28864(allow system_server property_socket (sock_file (write)))
28865(allow system_server init (unix_stream_socket (connectto)))
28866(allow system_server ctl_gsid_prop (property_service (set)))
28867(allow system_server ctl_gsid_prop (file (read getattr map open)))
28868(allow system_server property_socket (sock_file (write)))
28869(allow system_server init (unix_stream_socket (connectto)))
28870(allow system_server cppreopt_prop (property_service (set)))
28871(allow system_server cppreopt_prop (file (read getattr map open)))
28872(allow system_server property_socket (sock_file (write)))
28873(allow system_server init (unix_stream_socket (connectto)))
28874(allow system_server device_config_core_experiments_team_internal_prop (property_service (set)))
28875(allow system_server device_config_core_experiments_team_internal_prop (file (read getattr map open)))
28876(allow system_server property_socket (sock_file (write)))
28877(allow system_server init (unix_stream_socket (connectto)))
28878(allow system_server device_config_edgetpu_native_prop (property_service (set)))
28879(allow system_server device_config_edgetpu_native_prop (file (read getattr map open)))
28880(allow system_server property_socket (sock_file (write)))
28881(allow system_server init (unix_stream_socket (connectto)))
28882(allow system_server device_config_input_native_boot_prop (property_service (set)))
28883(allow system_server device_config_input_native_boot_prop (file (read getattr map open)))
28884(allow system_server property_socket (sock_file (write)))
28885(allow system_server init (unix_stream_socket (connectto)))
28886(allow system_server device_config_netd_native_prop (property_service (set)))
28887(allow system_server device_config_netd_native_prop (file (read getattr map open)))
28888(allow system_server property_socket (sock_file (write)))
28889(allow system_server init (unix_stream_socket (connectto)))
28890(allow system_server device_config_nnapi_native_prop (property_service (set)))
28891(allow system_server device_config_nnapi_native_prop (file (read getattr map open)))
28892(allow system_server property_socket (sock_file (write)))
28893(allow system_server init (unix_stream_socket (connectto)))
28894(allow system_server device_config_activity_manager_native_boot_prop (property_service (set)))
28895(allow system_server device_config_activity_manager_native_boot_prop (file (read getattr map open)))
28896(allow system_server property_socket (sock_file (write)))
28897(allow system_server init (unix_stream_socket (connectto)))
28898(allow system_server device_config_runtime_native_boot_prop (property_service (set)))
28899(allow system_server device_config_runtime_native_boot_prop (file (read getattr map open)))
28900(allow system_server property_socket (sock_file (write)))
28901(allow system_server init (unix_stream_socket (connectto)))
28902(allow system_server device_config_runtime_native_prop (property_service (set)))
28903(allow system_server device_config_runtime_native_prop (file (read getattr map open)))
28904(allow system_server property_socket (sock_file (write)))
28905(allow system_server init (unix_stream_socket (connectto)))
28906(allow system_server device_config_lmkd_native_prop (property_service (set)))
28907(allow system_server device_config_lmkd_native_prop (file (read getattr map open)))
28908(allow system_server property_socket (sock_file (write)))
28909(allow system_server init (unix_stream_socket (connectto)))
28910(allow system_server device_config_media_native_prop (property_service (set)))
28911(allow system_server device_config_media_native_prop (file (read getattr map open)))
28912(allow system_server property_socket (sock_file (write)))
28913(allow system_server init (unix_stream_socket (connectto)))
28914(allow system_server device_config_camera_native_prop (property_service (set)))
28915(allow system_server device_config_camera_native_prop (file (read getattr map open)))
28916(allow system_server property_socket (sock_file (write)))
28917(allow system_server init (unix_stream_socket (connectto)))
28918(allow system_server device_config_mglru_native_prop (property_service (set)))
28919(allow system_server device_config_mglru_native_prop (file (read getattr map open)))
28920(allow system_server property_socket (sock_file (write)))
28921(allow system_server init (unix_stream_socket (connectto)))
28922(allow system_server device_config_profcollect_native_boot_prop (property_service (set)))
28923(allow system_server device_config_profcollect_native_boot_prop (file (read getattr map open)))
28924(allow system_server property_socket (sock_file (write)))
28925(allow system_server init (unix_stream_socket (connectto)))
28926(allow system_server device_config_statsd_native_prop (property_service (set)))
28927(allow system_server device_config_statsd_native_prop (file (read getattr map open)))
28928(allow system_server property_socket (sock_file (write)))
28929(allow system_server init (unix_stream_socket (connectto)))
28930(allow system_server device_config_statsd_native_boot_prop (property_service (set)))
28931(allow system_server device_config_statsd_native_boot_prop (file (read getattr map open)))
28932(allow system_server property_socket (sock_file (write)))
28933(allow system_server init (unix_stream_socket (connectto)))
28934(allow system_server device_config_storage_native_boot_prop (property_service (set)))
28935(allow system_server device_config_storage_native_boot_prop (file (read getattr map open)))
28936(allow system_server property_socket (sock_file (write)))
28937(allow system_server init (unix_stream_socket (connectto)))
28938(allow system_server device_config_swcodec_native_prop (property_service (set)))
28939(allow system_server device_config_swcodec_native_prop (file (read getattr map open)))
28940(allow system_server property_socket (sock_file (write)))
28941(allow system_server init (unix_stream_socket (connectto)))
28942(allow system_server device_config_sys_traced_prop (property_service (set)))
28943(allow system_server device_config_sys_traced_prop (file (read getattr map open)))
28944(allow system_server property_socket (sock_file (write)))
28945(allow system_server init (unix_stream_socket (connectto)))
28946(allow system_server device_config_window_manager_native_boot_prop (property_service (set)))
28947(allow system_server device_config_window_manager_native_boot_prop (file (read getattr map open)))
28948(allow system_server property_socket (sock_file (write)))
28949(allow system_server init (unix_stream_socket (connectto)))
28950(allow system_server device_config_configuration_prop (property_service (set)))
28951(allow system_server device_config_configuration_prop (file (read getattr map open)))
28952(allow system_server property_socket (sock_file (write)))
28953(allow system_server init (unix_stream_socket (connectto)))
28954(allow system_server device_config_connectivity_prop (property_service (set)))
28955(allow system_server device_config_connectivity_prop (file (read getattr map open)))
28956(allow system_server property_socket (sock_file (write)))
28957(allow system_server init (unix_stream_socket (connectto)))
28958(allow system_server device_config_surface_flinger_native_boot_prop (property_service (set)))
28959(allow system_server device_config_surface_flinger_native_boot_prop (file (read getattr map open)))
28960(allow system_server property_socket (sock_file (write)))
28961(allow system_server init (unix_stream_socket (connectto)))
28962(allow system_server device_config_aconfig_flags_prop (property_service (set)))
28963(allow system_server device_config_aconfig_flags_prop (file (read getattr map open)))
28964(allow system_server property_socket (sock_file (write)))
28965(allow system_server init (unix_stream_socket (connectto)))
28966(allow system_server device_config_vendor_system_native_prop (property_service (set)))
28967(allow system_server device_config_vendor_system_native_prop (file (read getattr map open)))
28968(allow system_server property_socket (sock_file (write)))
28969(allow system_server init (unix_stream_socket (connectto)))
28970(allow system_server device_config_vendor_system_native_boot_prop (property_service (set)))
28971(allow system_server device_config_vendor_system_native_boot_prop (file (read getattr map open)))
28972(allow system_server property_socket (sock_file (write)))
28973(allow system_server init (unix_stream_socket (connectto)))
28974(allow system_server device_config_virtualization_framework_native_prop (property_service (set)))
28975(allow system_server device_config_virtualization_framework_native_prop (file (read getattr map open)))
28976(allow system_server property_socket (sock_file (write)))
28977(allow system_server init (unix_stream_socket (connectto)))
28978(allow system_server device_config_memory_safety_native_boot_prop (property_service (set)))
28979(allow system_server device_config_memory_safety_native_boot_prop (file (read getattr map open)))
28980(allow system_server property_socket (sock_file (write)))
28981(allow system_server init (unix_stream_socket (connectto)))
28982(allow system_server device_config_memory_safety_native_prop (property_service (set)))
28983(allow system_server device_config_memory_safety_native_prop (file (read getattr map open)))
28984(allow system_server property_socket (sock_file (write)))
28985(allow system_server init (unix_stream_socket (connectto)))
28986(allow system_server device_config_remote_key_provisioning_native_prop (property_service (set)))
28987(allow system_server device_config_remote_key_provisioning_native_prop (file (read getattr map open)))
28988(allow system_server property_socket (sock_file (write)))
28989(allow system_server init (unix_stream_socket (connectto)))
28990(allow system_server device_config_tethering_u_or_later_native_prop (property_service (set)))
28991(allow system_server device_config_tethering_u_or_later_native_prop (file (read getattr map open)))
28992(allow system_server property_socket (sock_file (write)))
28993(allow system_server init (unix_stream_socket (connectto)))
28994(allow system_server smart_idle_maint_enabled_prop (property_service (set)))
28995(allow system_server smart_idle_maint_enabled_prop (file (read getattr map open)))
28996(allow system_server property_socket (sock_file (write)))
28997(allow system_server init (unix_stream_socket (connectto)))
28998(allow system_server arm64_memtag_prop (property_service (set)))
28999(allow system_server arm64_memtag_prop (file (read getattr map open)))
29000(allow system_server property_socket (sock_file (write)))
29001(allow system_server init (unix_stream_socket (connectto)))
29002(allow system_server next_boot_prop (property_service (set)))
29003(allow system_server next_boot_prop (file (read getattr map open)))
29004(allow system_server device_config_runtime_native_boot_prop (file (read getattr map open)))
29005(allow system_server device_config_runtime_native_prop (file (read getattr map open)))
29006(allow system_server bootloader_boot_reason_prop (file (read getattr map open)))
29007(allow system_server system_boot_reason_prop (file (read getattr map open)))
29008(allow system_server boottime_prop (file (read getattr map open)))
29009(allow system_server serialno_prop (file (read getattr map open)))
29010(allow system_server property_socket (sock_file (write)))
29011(allow system_server init (unix_stream_socket (connectto)))
29012(allow system_server firstboot_prop (property_service (set)))
29013(allow system_server firstboot_prop (file (read getattr map open)))
29014(allow system_server audio_config_prop (file (read getattr map open)))
29015(allow system_server media_config_prop (file (read getattr map open)))
29016(allow system_server device_config_reset_performed_prop (file (read getattr map open)))
29017(allow system_server property_socket (sock_file (write)))
29018(allow system_server init (unix_stream_socket (connectto)))
29019(allow system_server test_harness_prop (property_service (set)))
29020(allow system_server test_harness_prop (file (read getattr map open)))
29021(allow system_server gsid_prop (file (read getattr map open)))
29022(allow system_server mock_ota_prop (file (read getattr map open)))
29023(allow system_server apk_verity_prop (file (read getattr map open)))
29024(allow system_server wifi_prop (file (read getattr map open)))
29025(allow system_server incremental_prop (file (read getattr map open)))
29026(allow system_server zram_config_prop (file (read getattr map open)))
29027(allow system_server property_socket (sock_file (write)))
29028(allow system_server init (unix_stream_socket (connectto)))
29029(allow system_server zram_control_prop (property_service (set)))
29030(allow system_server zram_control_prop (file (read getattr map open)))
29031(allow system_server property_socket (sock_file (write)))
29032(allow system_server init (unix_stream_socket (connectto)))
29033(allow system_server dalvik_runtime_prop (property_service (set)))
29034(allow system_server dalvik_runtime_prop (file (read getattr map open)))
29035(allow system_server packagemanager_config_prop (file (read getattr map open)))
29036(allow system_server net_464xlat_fromvendor_prop (file (read getattr map open)))
29037(allow system_server hypervisor_prop (file (read getattr map open)))
29038(allow system_server persist_wm_debug_prop (file (read getattr map open)))
29039(allow system_server persist_sysui_builder_extras_prop (file (read getattr map open)))
29040(allow system_server persist_sysui_ranking_update_prop (file (read getattr map open)))
29041(allow system_server tuner_config_prop (file (read getattr map open)))
29042(allow system_server property_socket (sock_file (write)))
29043(allow system_server init (unix_stream_socket (connectto)))
29044(allow system_server tuner_server_ctl_prop (property_service (set)))
29045(allow system_server tuner_server_ctl_prop (file (read getattr map open)))
29046(allow system_server traced_oome_heap_session_count_prop (file (read getattr map open)))
29047(allow system_server sensors_config_prop (file (read getattr map open)))
29048(allow system_server system_ndebug_socket (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29049(allow system_server system_unsolzygote_socket (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29050(allow system_server cache_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29051(allow system_server cache_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
29052(allow system_server cache_recovery_file (dir (ioctl read write create getattr setattr lock relabelfrom rename open watch watch_reads add_name remove_name reparent search rmdir)))
29053(allow system_server cache_file (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
29054(allow system_server cache_recovery_file (file (ioctl read write create getattr setattr lock relabelfrom append map unlink rename open watch watch_reads)))
29055(allow system_server cache_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29056(allow system_server cache_recovery_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29057(allow system_server system_file (dir (ioctl read getattr lock open watch watch_reads search)))
29058(allow system_server system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29059(allow system_server system_file (file (lock)))
29060(allow system_server gps_control (file (ioctl read write getattr lock append map open watch watch_reads)))
29061(allow system_server appdomain (tcp_socket (read write getattr getopt setopt shutdown)))
29062(allow system_server appdomain (udp_socket (read write getattr getopt setopt shutdown)))
29063(allow system_server appdomain (fifo_file (read write getattr)))
29064(allow system_server appdomain (unix_stream_socket (read write getattr)))
29065(allow system_server cache_backup_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29066(allow system_server cache_backup_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29067(allow system_server cache_private_backup_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29068(allow system_server cache_private_backup_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29069(allow system_server usb_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
29070(allow system_server usb_device (dir (ioctl read getattr lock open watch watch_reads search)))
29071(allow system_server fscklogs (dir (ioctl read getattr lock open watch watch_reads search)))
29072(allow system_server fscklogs (file (ioctl read getattr lock map open watch watch_reads)))
29073(allow system_server fscklogs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29074(allow system_server fscklogs (dir (write add_name remove_name)))
29075(allow system_server fscklogs (file (rename)))
29076(allow system_server zygote (unix_dgram_socket (write)))
29077(allow system_server logcat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
29078(allow system_server logdr_socket (sock_file (write)))
29079(allow system_server logd (unix_stream_socket (connectto)))
29080(allow system_server runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
29081(allow system_server sysfs_lowmemorykiller (file (write getattr lock append map open)))
29082(allow system_server pstorefs (dir (ioctl read getattr lock open watch watch_reads search)))
29083(allow system_server pstorefs (file (ioctl read getattr lock map open watch watch_reads)))
29084(allow system_server sysfs_zram (dir (search)))
29085(allow system_server sysfs_zram (file (ioctl read write getattr lock append map open watch watch_reads)))
29086(allow system_server kernel (security (read_policy)))
29087(allow system_server system_server_service (service_manager (add find)))
29088;;* lmx 952 system/sepolicy/private/system_server.te
29089
29090(neverallow base_typeattr_305 system_server_service (service_manager (add)))
29091;;* lme
29092
29093(allow system_server artd_service (service_manager (find)))
29094(allow system_server artd_pre_reboot_service (service_manager (find)))
29095(allow system_server audioserver_service (service_manager (find)))
29096(allow system_server authorization_service (service_manager (find)))
29097(allow system_server batteryproperties_service (service_manager (find)))
29098(allow system_server cameraserver_service (service_manager (find)))
29099(allow system_server compos_service (service_manager (find)))
29100(allow system_server dataloader_manager_service (service_manager (find)))
29101(allow system_server dexopt_chroot_setup_service (service_manager (find)))
29102(allow system_server dnsresolver_service (service_manager (find)))
29103(allow system_server drmserver_service (service_manager (find)))
29104(allow system_server dumpstate_service (service_manager (find)))
29105(allow system_server fingerprintd_service (service_manager (find)))
29106(allow system_server gatekeeper_service (service_manager (find)))
29107(allow system_server gpu_service (service_manager (find)))
29108(allow system_server gsi_service (service_manager (find)))
29109(allow system_server idmap_service (service_manager (find)))
29110(allow system_server incident_service (service_manager (find)))
29111(allow system_server incremental_service (service_manager (find)))
29112(allow system_server installd_service (service_manager (find)))
29113(allow system_server keystore_maintenance_service (service_manager (find)))
29114(allow system_server keystore_metrics_service (service_manager (find)))
29115(allow system_server keystore_service (service_manager (find)))
29116(allow system_server mdns_service (service_manager (find)))
29117(allow system_server mediaserver_service (service_manager (find)))
29118(allow system_server mediametrics_service (service_manager (find)))
29119(allow system_server mediaextractor_service (service_manager (find)))
29120(allow system_server mediadrmserver_service (service_manager (find)))
29121(allow system_server mediatuner_service (service_manager (find)))
29122(allow system_server netd_service (service_manager (find)))
29123(allow system_server nfc_service (service_manager (find)))
29124(allow system_server ot_daemon_service (service_manager (find)))
29125(allow system_server radio_service (service_manager (find)))
29126(allow system_server stats_service (service_manager (find)))
29127(allow system_server storaged_service (service_manager (find)))
29128(allow system_server surfaceflinger_service (service_manager (find)))
29129(allow system_server update_engine_service (service_manager (find)))
29130(allow system_server virtual_camera_service (service_manager (find)))
29131(allow system_server vold_service (service_manager (find)))
29132(allow system_server wifinl80211_service (service_manager (find)))
29133(allow system_server logd_service (service_manager (find)))
29134(allow system_server batteryproperties_service (service_manager (add find)))
29135;;* lmx 1001 system/sepolicy/private/system_server.te
29136
29137(neverallow base_typeattr_305 batteryproperties_service (service_manager (add)))
29138;;* lme
29139
29140(allow system_server keystore (keystore2 (add_auth change_password change_user clear_ns clear_uid get_last_auth_time lock pull_metrics reset unlock)))
29141(allow system_server keystore (keystore2_key (delete get_info grant rebind update use use_dev_id)))
29142(allow system_server wifi_key (keystore2_key (delete get_info rebind update use)))
29143(allow system_server resume_on_reboot_key (keystore2_key (delete get_info rebind update use)))
29144(allow system_server locksettings_key (keystore2_key (delete get_info rebind update use)))
29145(allow system_server block_device (dir (search)))
29146(allow system_server frp_block_device (blk_file (ioctl read write getattr lock append map open watch watch_reads)))
29147(allowx system_server frp_block_device (ioctl blk_file (0x1277 0x127d)))
29148(allow system_server cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29149(allow system_server cgroup (file (setattr)))
29150(allow system_server cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29151(allow system_server cgroup_v2 (file (ioctl read getattr setattr lock map open watch watch_reads)))
29152(allow system_server oemfs (dir (ioctl read getattr lock open watch watch_reads search)))
29153(allow system_server oemfs (file (ioctl read getattr lock map open watch watch_reads)))
29154(allow system_server oemfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29155(allow system_server mnt_user_file (dir (getattr search)))
29156(allow system_server storage_file (dir (getattr search)))
29157(allow system_server mnt_user_file (lnk_file (read getattr)))
29158(allow system_server storage_file (lnk_file (read getattr)))
29159(allow system_server sdcard_type (dir (getattr search)))
29160(allow system_server fuse (dir (getattr search)))
29161(allow system_server mnt_expand_file (dir (ioctl read getattr lock open watch watch_reads search)))
29162(allow system_server fingerprintd_data_file (dir (ioctl read write getattr lock relabelto open watch watch_reads remove_name search rmdir)))
29163(allow system_server fingerprintd_data_file (file (getattr unlink)))
29164(allow system_server vold (fd (use)))
29165(allow system_server fuse_device (chr_file (ioctl read write getattr)))
29166(allow system_server app_fuse_file (file (read write getattr)))
29167(allow system_server configfs (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29168(allow system_server configfs (file (write create getattr unlink open)))
29169(allow system_server adbd (unix_stream_socket (connectto)))
29170(allow system_server adbd (fd (use)))
29171(allow system_server adbd (unix_stream_socket (ioctl read write getattr getopt shutdown)))
29172(allow system_server adbd_prop (file (read getattr map open)))
29173(allow system_server property_socket (sock_file (write)))
29174(allow system_server init (unix_stream_socket (connectto)))
29175(allow system_server system_adbd_prop (property_service (set)))
29176(allow system_server system_adbd_prop (file (read getattr map open)))
29177(allow system_server toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
29178(allowx system_server system_data_file (ioctl file (0x6685)))
29179(allowx system_server apk_data_file (ioctl file (0x6685)))
29180(allowx system_server apk_tmp_file (ioctl file (0x6685)))
29181(allowx system_server apex_system_server_data_file (ioctl file (0x6685)))
29182(allowx system_server apk_data_file (ioctl file (0x6686)))
29183(allowx system_server apk_tmp_file (ioctl file (0x6686)))
29184(allowx system_server apk_tmp_file (ioctl file (0x6602)))
29185(allow system_server postinstall (binder (call transfer)))
29186(allow postinstall system_server (binder (transfer)))
29187(allow system_server postinstall (fd (use)))
29188(allow system_server postinstall (fifo_file (write)))
29189(allow system_server update_engine (fd (use)))
29190(allow system_server update_engine (fifo_file (write)))
29191(allow system_server preloads_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
29192(allow system_server preloads_data_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search rmdir)))
29193(allow system_server preloads_media_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
29194(allow system_server preloads_media_file (dir (ioctl read write getattr lock open watch watch_reads remove_name search rmdir)))
29195(allow system_server cgroup (dir (ioctl read getattr lock open watch watch_reads search)))
29196(allow system_server cgroup (file (ioctl read getattr lock map open watch watch_reads)))
29197(allow system_server cgroup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29198(allow system_server cgroup_v2 (dir (ioctl read getattr lock open watch watch_reads search)))
29199(allow system_server cgroup_v2 (file (ioctl read getattr lock map open watch watch_reads)))
29200(allow system_server cgroup_v2 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29201(allow system_server ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
29202(allow system_server dmabuf_system_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
29203(allow system_server dmabuf_system_secure_heap_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
29204(allow system_server proc_asound (dir (ioctl read getattr lock open watch watch_reads search)))
29205(allow system_server proc_asound (file (ioctl read getattr lock map open watch watch_reads)))
29206(allow system_server proc_asound (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29207(allow system_server proc_net_type (dir (ioctl read getattr lock open watch watch_reads search)))
29208(allow system_server proc_net_type (file (ioctl read getattr lock map open watch watch_reads)))
29209(allow system_server proc_net_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29210(allow system_server proc_qtaguid_stat (dir (ioctl read getattr lock open watch watch_reads search)))
29211(allow system_server proc_qtaguid_stat (file (ioctl read getattr lock map open watch watch_reads)))
29212(allow system_server proc_qtaguid_stat (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29213(allow system_server proc_cmdline (file (ioctl read getattr lock map open watch watch_reads)))
29214(allow system_server proc_loadavg (file (ioctl read getattr lock map open watch watch_reads)))
29215(allow system_server proc_locks (file (ioctl read getattr lock map open watch watch_reads)))
29216(allow system_server proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
29217(allow system_server proc_pagetypeinfo (file (ioctl read getattr lock map open watch watch_reads)))
29218(allow system_server proc_pipe_conf (file (ioctl read getattr lock map open watch watch_reads)))
29219(allow system_server proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
29220(allow system_server proc_uid_cputime_showstat (file (ioctl read getattr lock map open watch watch_reads)))
29221(allow system_server proc_uid_io_stats (file (ioctl read getattr lock map open watch watch_reads)))
29222(allow system_server proc_uid_time_in_state (file (ioctl read getattr lock map open watch watch_reads)))
29223(allow system_server proc_uid_concurrent_active_time (file (ioctl read getattr lock map open watch watch_reads)))
29224(allow system_server proc_uid_concurrent_policy_time (file (ioctl read getattr lock map open watch watch_reads)))
29225(allow system_server proc_version (file (ioctl read getattr lock map open watch watch_reads)))
29226(allow system_server proc_vmallocinfo (file (ioctl read getattr lock map open watch watch_reads)))
29227(allow system_server proc_uid_time_in_state (dir (ioctl read getattr lock open watch watch_reads search)))
29228(allow system_server proc_uid_cpupower (file (ioctl read getattr lock map open watch watch_reads)))
29229(allow system_server rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
29230(allow system_server rootfs (file (ioctl read getattr lock map open watch watch_reads)))
29231(allow system_server rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29232(allow system_server debugfs_tracing_instances (dir (search)))
29233(allow system_server debugfs_wifi_tracing (dir (search)))
29234(allow system_server debugfs_wifi_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
29235(allow system_server debugfs_bootreceiver_tracing (dir (search)))
29236(allow system_server debugfs_bootreceiver_tracing (file (ioctl read getattr lock map open watch watch_reads)))
29237(allow system_server debugfs_tracing (file (ioctl read getattr lock map open watch watch_reads)))
29238(allow system_server fs_bpf (dir (search)))
29239(allow system_server fs_bpf_net_shared (dir (search)))
29240(allow system_server fs_bpf_netd_readonly (dir (search)))
29241(allow system_server fs_bpf_netd_shared (dir (search)))
29242(allow system_server fs_bpf (file (read write getattr)))
29243(allow system_server fs_bpf_net_shared (file (read write getattr)))
29244(allow system_server fs_bpf_netd_readonly (file (read write getattr)))
29245(allow system_server fs_bpf_netd_shared (file (read write getattr)))
29246(allow system_server bpfloader (bpf (map_read map_write prog_run)))
29247(allow system_server self (key_socket (create)))
29248(dontaudit system_server self (key_socket (getopt)))
29249(allow system_server clatd_exec (file (read getattr map execute open)))
29250(allow system_server clatd (process (transition)))
29251(allow clatd clatd_exec (file (read getattr map execute open entrypoint)))
29252(allow clatd system_server (process (sigchld)))
29253(dontaudit system_server clatd (process (noatsecure)))
29254(allow system_server clatd (process (siginh rlimitinh)))
29255(typetransition system_server clatd_exec process clatd)
29256(allow system_server clatd (process (sigkill signal)))
29257(allow system_server user_profile_root_file (dir (getattr search)))
29258(allow system_server user_profile_data_file (dir (getattr search)))
29259(allow system_server user_profile_data_file (file (read getattr open)))
29260(allow system_server profman_dump_data_file (file (write create getattr setattr lock append map open)))
29261(allow system_server profman_dump_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29262(allow system_server system_jvmti_agent_prop (file (read getattr map open)))
29263(allow system_server functionfs (dir (search)))
29264(allow system_server functionfs (file (ioctl read write getattr lock append map open watch watch_reads)))
29265(allow system_server time_prop (file (read getattr map open)))
29266(allow system_server system_lmk_prop (file (read getattr map open)))
29267(allow system_server wifi_config_prop (file (read getattr map open)))
29268(allowx system_server binder_device (ioctl chr_file ((range 0x620e 0x620f))))
29269(allow system_server framework_watchdog_config_prop (file (read getattr map open)))
29270(allow system_server font_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29271(allow system_server font_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29272(allowx system_server font_data_file (ioctl file ((range 0x6685 0x6686))))
29273(allow system_server qemu_hw_prop (file (read getattr map open)))
29274;;* lmx 1282 system/sepolicy/private/system_server.te
29275
29276(neverallow system_server sdcard_type (dir (read write open)))
29277(neverallow system_server fuse (dir (read write open)))
29278;;* lme
29279
29280;;* lmx 1283 system/sepolicy/private/system_server.te
29281
29282(neverallow system_server sdcard_type (file (ioctl read write getattr lock append map open watch watch_reads)))
29283(neverallow system_server fuse (file (ioctl read write getattr lock append map open watch watch_reads)))
29284;;* lme
29285
29286;;* lmx 1293 system/sepolicy/private/system_server.te
29287
29288(neverallow system_server base_typeattr_953 (file (create unlink link open)))
29289;;* lme
29290
29291;;* lmx 1304 system/sepolicy/private/system_server.te
29292
29293(neverallow system_server base_typeattr_954 (file (execute_no_trans)))
29294;;* lme
29295
29296;;* lmx 1308 system/sepolicy/private/system_server.te
29297
29298(neverallow system_server base_typeattr_955 (process (transition)))
29299;;* lme
29300
29301;;* lmx 1309 system/sepolicy/private/system_server.te
29302
29303(neverallow system_server base_typeattr_224 (process (dyntransition)))
29304;;* lme
29305
29306;;* lmx 1312 system/sepolicy/private/system_server.te
29307
29308(neverallow system_server perfetto_traces_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
29309;;* lme
29310
29311;;* lmx 1315 system/sepolicy/private/system_server.te
29312
29313(neverallow base_typeattr_956 system_ndebug_socket (sock_file (write open)))
29314;;* lme
29315
29316;;* lmx 1325 system/sepolicy/private/system_server.te
29317
29318(neverallow base_typeattr_957 system_unsolzygote_socket (sock_file (write open)))
29319;;* lme
29320
29321;;* lmx 1355 system/sepolicy/private/system_server.te
29322
29323(neverallow base_typeattr_958 device_config_activity_manager_native_boot_prop (property_service (set)))
29324(neverallow base_typeattr_958 device_config_input_native_boot_prop (property_service (set)))
29325(neverallow base_typeattr_958 device_config_netd_native_prop (property_service (set)))
29326(neverallow base_typeattr_958 device_config_aconfig_flags_prop (property_service (set)))
29327(neverallow base_typeattr_958 device_config_edgetpu_native_prop (property_service (set)))
29328(neverallow base_typeattr_958 device_config_media_native_prop (property_service (set)))
29329(neverallow base_typeattr_958 device_config_nnapi_native_prop (property_service (set)))
29330(neverallow base_typeattr_958 device_config_runtime_native_boot_prop (property_service (set)))
29331(neverallow base_typeattr_958 device_config_runtime_native_prop (property_service (set)))
29332(neverallow base_typeattr_958 device_config_surface_flinger_native_boot_prop (property_service (set)))
29333(neverallow base_typeattr_958 device_config_core_experiments_team_internal_prop (property_service (set)))
29334(neverallow base_typeattr_958 device_config_lmkd_native_prop (property_service (set)))
29335(neverallow base_typeattr_958 device_config_mglru_native_prop (property_service (set)))
29336(neverallow base_typeattr_958 device_config_remote_key_provisioning_native_prop (property_service (set)))
29337(neverallow base_typeattr_958 device_config_storage_native_boot_prop (property_service (set)))
29338(neverallow base_typeattr_958 device_config_sys_traced_prop (property_service (set)))
29339(neverallow base_typeattr_958 device_config_window_manager_native_boot_prop (property_service (set)))
29340(neverallow base_typeattr_958 device_config_connectivity_prop (property_service (set)))
29341(neverallow base_typeattr_958 device_config_swcodec_native_prop (property_service (set)))
29342(neverallow base_typeattr_958 device_config_tethering_u_or_later_native_prop (property_service (set)))
29343(neverallow base_typeattr_958 next_boot_prop (property_service (set)))
29344;;* lme
29345
29346;;* lmx 1362 system/sepolicy/private/system_server.te
29347
29348(neverallow base_typeattr_308 tuner_server_ctl_prop (property_service (set)))
29349;;* lme
29350
29351;;* lmx 1368 system/sepolicy/private/system_server.te
29352
29353(neverallow system_server dex2oat_exec (file (execute execute_no_trans)))
29354;;* lme
29355
29356;;* lmx 1373 system/sepolicy/private/system_server.te
29357
29358(neverallow system_server data_file_type (file (execute execute_no_trans)))
29359;;* lme
29360
29361;;* lmx 1380 system/sepolicy/private/system_server.te
29362
29363(neverallow system_server base_typeattr_959 (blk_file (write create setattr relabelfrom append unlink link rename)))
29364;;* lme
29365
29366;;* lmx 1381 system/sepolicy/private/system_server.te
29367
29368(neverallow system_server base_typeattr_960 (blk_file (ioctl read getattr lock map open watch watch_reads)))
29369;;* lme
29370
29371;;* lmx 1389 system/sepolicy/private/system_server.te
29372
29373(neverallow system_server self (process (execmem)))
29374;;* lme
29375
29376;;* lmx 1392 system/sepolicy/private/system_server.te
29377
29378(neverallow system_server ashmem_device (chr_file (execute)))
29379(neverallow system_server ashmem_libcutils_device (chr_file (execute)))
29380;;* lme
29381
29382;;* lmx 1395 system/sepolicy/private/system_server.te
29383
29384(neverallow system_server system_server_tmpfs (file (execute)))
29385;;* lme
29386
29387(allow system_server system_server_startup (fd (use)))
29388(allow system_server system_server_startup_tmpfs (file (read write map)))
29389(allow system_server system_server_startup (unix_dgram_socket (write)))
29390(allow system_server apex_service (service_manager (find)))
29391(allow system_server apexd (binder (call)))
29392(allow system_server apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
29393(allow system_server apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
29394(allow system_server system_suspend_control_internal_service (service_manager (find)))
29395(allow system_server system_suspend_control_service (service_manager (find)))
29396(allow system_server system_suspend (binder (call transfer)))
29397(allow system_suspend system_server (binder (transfer)))
29398(allow system_server system_suspend (fd (use)))
29399(allow system_suspend system_server (binder (call transfer)))
29400(allow system_server system_suspend (binder (transfer)))
29401(allow system_suspend system_server (fd (use)))
29402(allow system_server sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
29403(allow system_server self (capability2 (block_suspend)))
29404(allow system_server self (cap2_userns (block_suspend)))
29405(allow system_server system_suspend_server (binder (call transfer)))
29406(allow system_suspend_server system_server (binder (transfer)))
29407(allow system_server system_suspend_server (fd (use)))
29408(allow system_server system_suspend_hwservice (hwservice_manager (find)))
29409(allow system_server hwservicemanager (binder (call transfer)))
29410(allow hwservicemanager system_server (binder (call transfer)))
29411(allow hwservicemanager system_server (dir (search)))
29412(allow hwservicemanager system_server (file (read map open)))
29413(allow hwservicemanager system_server (process (getattr)))
29414(allow system_server hwservicemanager_prop (file (read getattr map open)))
29415(allow system_server hidl_manager_hwservice (hwservice_manager (find)))
29416(allow system_server hal_system_suspend_service (service_manager (find)))
29417(allow system_server servicemanager (binder (call transfer)))
29418(allow servicemanager system_server (binder (call transfer)))
29419(allow servicemanager system_server (dir (search)))
29420(allow servicemanager system_server (file (read open)))
29421(allow servicemanager system_server (process (getattr)))
29422(allow system_server apex_data_file (dir (getattr search)))
29423(allow system_server apex_data_file (file (ioctl read getattr lock map open watch watch_reads)))
29424(allow system_server vendor_apex_file (dir (getattr search)))
29425(allow system_server vendor_apex_file (file (ioctl read getattr lock map open watch watch_reads)))
29426(allow system_server apex_module_data_file (dir (getattr search)))
29427(allow system_server apex_system_server_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29428(allow system_server apex_system_server_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29429(allow system_server apex_tethering_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29430(allow system_server apex_tethering_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29431(allow system_server apex_appsearch_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29432(allow system_server apex_permission_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29433(allow system_server apex_scheduling_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29434(allow system_server apex_wifi_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29435(allow system_server apex_appsearch_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29436(allow system_server apex_permission_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29437(allow system_server apex_scheduling_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29438(allow system_server apex_wifi_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29439(allow system_server metadata_file (dir (search)))
29440(allow system_server password_slot_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29441(allow system_server password_slot_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29442(allow system_server userspace_reboot_metadata_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29443(allow system_server userspace_reboot_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29444(allow system_server staged_install_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29445(allow system_server staged_install_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29446(allow system_server watchdog_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29447(allow system_server watchdog_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29448(allow system_server aconfig_storage_flags_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29449(allow system_server aconfig_storage_flags_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29450(allow system_server repair_mode_metadata_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29451(allow system_server repair_mode_metadata_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29452(allow system_server gsi_persistent_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29453(allow system_server gsi_persistent_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29454(allow system_server odrefresh_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29455(allow system_server odrefresh_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
29456(allow system_server surfaceflinger_exec (file (ioctl read getattr lock map open watch watch_reads)))
29457(allow system_server property_socket (sock_file (write)))
29458(allow system_server init (unix_stream_socket (connectto)))
29459(allow system_server userspace_reboot_log_prop (property_service (set)))
29460(allow system_server userspace_reboot_log_prop (file (read getattr map open)))
29461;;* lmx 1499 system/sepolicy/private/system_server.te
29462
29463(neverallow base_typeattr_261 system_jvmti_agent_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29464;;* lme
29465
29466(allow system_server proc_pressure_mem (file (ioctl read write getattr lock append map open watch watch_reads)))
29467(allow system_server proc_pressure_cpu (file (ioctl read getattr lock map open watch watch_reads)))
29468(allow system_server proc_pressure_io (file (ioctl read getattr lock map open watch watch_reads)))
29469;;* lmx 1508 system/sepolicy/private/system_server.te
29470
29471(neverallow system_server dexoptanalyzer_exec (file (execute execute_no_trans)))
29472;;* lme
29473
29474;;* lmx 1511 system/sepolicy/private/system_server.te
29475
29476(neverallow system_server base_typeattr_305 (process (ptrace)))
29477;;* lme
29478
29479;;* lmx 1515 system/sepolicy/private/system_server.te
29480
29481(neverallow system_server system_server (capability (sys_resource)))
29482(neverallow system_server system_server (cap_userns (sys_resource)))
29483;;* lme
29484
29485;;* lmx 1518 system/sepolicy/private/system_server.te
29486
29487(neverallow base_typeattr_308 password_slot_metadata_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
29488;;* lme
29489
29490;;* lmx 1523 system/sepolicy/private/system_server.te
29491
29492(neverallow base_typeattr_308 password_slot_metadata_file (file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
29493(neverallow base_typeattr_308 password_slot_metadata_file (lnk_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29494(neverallow base_typeattr_308 password_slot_metadata_file (sock_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29495(neverallow base_typeattr_308 password_slot_metadata_file (fifo_file (ioctl read write create setattr lock relabelfrom append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29496;;* lme
29497
29498;;* lmx 1524 system/sepolicy/private/system_server.te
29499
29500(neverallow base_typeattr_308 password_slot_metadata_file (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
29501(neverallow base_typeattr_308 password_slot_metadata_file (lnk_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29502(neverallow base_typeattr_308 password_slot_metadata_file (sock_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29503(neverallow base_typeattr_308 password_slot_metadata_file (fifo_file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29504;;* lme
29505
29506;;* lmx 1527 system/sepolicy/private/system_server.te
29507
29508(neverallow base_typeattr_308 userspace_reboot_metadata_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
29509;;* lme
29510
29511;;* lmx 1528 system/sepolicy/private/system_server.te
29512
29513(neverallow base_typeattr_308 userspace_reboot_metadata_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29514;;* lme
29515
29516;;* lmx 1531 system/sepolicy/private/system_server.te
29517
29518(neverallow base_typeattr_961 aconfig_storage_flags_metadata_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
29519;;* lme
29520
29521;;* lmx 1532 system/sepolicy/private/system_server.te
29522
29523(neverallow base_typeattr_961 aconfig_storage_flags_metadata_file (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29524;;* lme
29525
29526(allow system_server property_socket (sock_file (write)))
29527(allow system_server init (unix_stream_socket (connectto)))
29528(allow system_server binder_cache_system_server_prop (property_service (set)))
29529(allow system_server binder_cache_system_server_prop (file (read getattr map open)))
29530;;* lmx 1537 system/sepolicy/private/system_server.te
29531
29532(neverallow base_typeattr_308 binder_cache_system_server_prop (property_service (set)))
29533;;* lme
29534
29535(allow system_server self (perf_event (open cpu kernel write)))
29536;;* lmx 1542 system/sepolicy/private/system_server.te
29537
29538(neverallow system_server self (perf_event (tracepoint read)))
29539;;* lme
29540
29541(allow system_server shutdown_checkpoints_system_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
29542(allow system_server shutdown_checkpoints_system_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29543;;* lmx 1549 system/sepolicy/private/system_server.te
29544
29545(neverallow base_typeattr_308 socket_hook_prop (property_service (set)))
29546;;* lme
29547
29548;;* lmx 1551 system/sepolicy/private/system_server.te
29549
29550(neverallow base_typeattr_308 boot_status_prop (property_service (set)))
29551;;* lme
29552
29553;;* lmx 1559 system/sepolicy/private/system_server.te
29554
29555(neverallow base_typeattr_261 wifi_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29556;;* lme
29557
29558;;* lmx 1568 system/sepolicy/private/system_server.te
29559
29560(neverallow base_typeattr_962 sysfs_uhid (file (write create setattr relabelfrom append unlink link rename)))
29561;;* lme
29562
29563;;* lmx 1574 system/sepolicy/private/system_server.te
29564
29565(neverallowx base_typeattr_305 binder_device (ioctl chr_file ((range 0x620e 0x620f))))
29566;;* lme
29567
29568;;* lmx 1577 system/sepolicy/private/system_server.te
29569
29570(neverallow base_typeattr_308 font_data_file (file (write create setattr relabelfrom append unlink link rename)))
29571;;* lme
29572
29573;;* lmx 1578 system/sepolicy/private/system_server.te
29574
29575(neverallow base_typeattr_308 font_data_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
29576;;* lme
29577
29578(allow system_server system_font_fallback_file (file (ioctl read getattr lock map open watch watch_reads)))
29579(allow system_server property_socket (sock_file (write)))
29580(allow system_server init (unix_stream_socket (connectto)))
29581(allow system_server dalvik_dynamic_config_prop (property_service (set)))
29582(allow system_server dalvik_dynamic_config_prop (file (read getattr map open)))
29583(allow system_server binderfs_logs (dir (ioctl read getattr lock open watch watch_reads search)))
29584(allow system_server binderfs_logs_stats (file (ioctl read getattr lock map open watch watch_reads)))
29585(allow system_server property_socket (sock_file (write)))
29586(allow system_server init (unix_stream_socket (connectto)))
29587(allow system_server game_manager_config_prop (property_service (set)))
29588(allow system_server game_manager_config_prop (file (read getattr map open)))
29589(allow system_server threadnetwork_config_prop (file (read getattr map open)))
29590;;* lmx 1603 system/sepolicy/private/system_server.te
29591
29592(neverallow base_typeattr_261 threadnetwork_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29593;;* lme
29594
29595(allow system_server pm_archiving_enabled_prop (file (read getattr map open)))
29596;;* lmx 1610 system/sepolicy/private/system_server.te
29597
29598(neverallow base_typeattr_308 crashrecovery_prop (property_service (set)))
29599;;* lme
29600
29601;;* lmx 1611 system/sepolicy/private/system_server.te
29602
29603(neverallow base_typeattr_743 crashrecovery_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29604;;* lme
29605
29606(typetransition system_server_startup tmpfs file system_server_startup_tmpfs)
29607(allow system_server_startup system_server_startup_tmpfs (file (read write getattr map)))
29608(allow system_server_startup self (process (execmem)))
29609(allow system_server_startup system_server_startup_tmpfs (file (read write map execute open)))
29610(allow system_server_startup apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
29611(allow system_server_startup apex_art_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
29612(allow system_server_startup self (process (setcurrent)))
29613(allow system_server_startup system_server (process (dyntransition)))
29614(allow system_server_startup zygote (process (sigchld)))
29615(allow system_server_startup device_config_runtime_native_boot_prop (file (read getattr map open)))
29616(allow system_server_startup device_config_runtime_native_prop (file (read getattr map open)))
29617(allow init system_suspend_exec (file (read getattr map execute open)))
29618(allow init system_suspend (process (transition)))
29619(allow system_suspend system_suspend_exec (file (read getattr map execute open entrypoint)))
29620(dontaudit init system_suspend (process (noatsecure)))
29621(allow init system_suspend (process (siginh rlimitinh)))
29622(typetransition init system_suspend_exec process system_suspend)
29623(allow system_suspend servicemanager (binder (call transfer)))
29624(allow servicemanager system_suspend (binder (call transfer)))
29625(allow servicemanager system_suspend (dir (search)))
29626(allow servicemanager system_suspend (file (read open)))
29627(allow servicemanager system_suspend (process (getattr)))
29628(allow system_suspend system_suspend_control_service (service_manager (add find)))
29629;;* lmx 8 system/sepolicy/private/system_suspend.te
29630
29631(neverallow base_typeattr_963 system_suspend_control_service (service_manager (add)))
29632;;* lme
29633
29634(allow system_suspend hal_system_suspend_service (service_manager (add find)))
29635;;* lmx 10 system/sepolicy/private/system_suspend.te
29636
29637(neverallow base_typeattr_963 hal_system_suspend_service (service_manager (add)))
29638;;* lme
29639
29640(allow system_suspend sysfs_power (file (ioctl read write getattr lock append map open watch watch_reads)))
29641(allow system_suspend sysfs_suspend_stats (dir (ioctl read getattr lock open watch watch_reads search)))
29642(allow system_suspend sysfs_suspend_stats (file (ioctl read getattr lock map open watch watch_reads)))
29643(allow system_suspend sysfs_suspend_stats (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29644(allow system_suspend sysfs_wakeup (dir (ioctl read getattr lock open watch watch_reads search)))
29645(allow system_suspend sysfs_wakeup (file (ioctl read getattr lock map open watch watch_reads)))
29646(allow system_suspend sysfs_wakeup (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29647(allow system_suspend sysfs_wakeup_reasons (dir (ioctl read getattr lock open watch watch_reads search)))
29648(allow system_suspend sysfs_wakeup_reasons (file (ioctl read getattr lock map open watch watch_reads)))
29649(allow system_suspend sysfs_wakeup_reasons (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29650(allow system_suspend sysfs_type (dir (search)))
29651(allow system_suspend suspend_prop (file (read getattr map open)))
29652(allow system_suspend bluetooth (binder (call)))
29653(allow system_suspend dumpstate (fd (use)))
29654(allow system_suspend dumpstate (fifo_file (write)))
29655(allow init sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
29656(allow init self (capability2 (block_suspend)))
29657(allow init self (cap2_userns (block_suspend)))
29658(allow system_suspend sysfs_wake_lock (file (ioctl read write getattr lock append map open watch watch_reads)))
29659(allow system_suspend self (capability2 (block_suspend)))
29660(allow system_suspend self (cap2_userns (block_suspend)))
29661(allow init sysfs_sync_on_suspend (file (write lock append map open)))
29662;;* lmx 56 system/sepolicy/private/system_suspend.te
29663
29664(neverallow base_typeattr_964 system_suspend_control_service (service_manager (find)))
29665;;* lme
29666
29667(allow init tombstoned_exec (file (read getattr map execute open)))
29668(allow init tombstoned (process (transition)))
29669(allow tombstoned tombstoned_exec (file (read getattr map execute open entrypoint)))
29670(dontaudit init tombstoned (process (noatsecure)))
29671(allow init tombstoned (process (siginh rlimitinh)))
29672(typetransition init tombstoned_exec process tombstoned)
29673(allow tombstoned tombstone_config_prop (file (read getattr map open)))
29674;;* lmx 13 system/sepolicy/private/tombstoned.te
29675
29676(neverallow base_typeattr_965 tombstone_config_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29677;;* lme
29678
29679(allow init toolbox_exec (file (read getattr map execute open)))
29680(allow init toolbox (process (transition)))
29681(allow toolbox toolbox_exec (file (read getattr map execute open entrypoint)))
29682(dontaudit init toolbox (process (noatsecure)))
29683(allow init toolbox (process (siginh rlimitinh)))
29684(typetransition init toolbox_exec process toolbox)
29685(allow toolbox virtualizationservice_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search rmdir)))
29686(allow toolbox virtualizationservice_data_file (file (getattr unlink)))
29687(dontaudit toolbox virtualizationservice_data_file (dir (setattr)))
29688(allow init traced_exec (file (read getattr map execute open)))
29689(allow init traced (process (transition)))
29690(allow traced traced_exec (file (read getattr map execute open entrypoint)))
29691(dontaudit init traced (process (noatsecure)))
29692(allow init traced (process (siginh rlimitinh)))
29693(typetransition init traced_exec process traced)
29694(typetransition traced tmpfs file traced_tmpfs)
29695(allow traced traced_tmpfs (file (read write getattr map)))
29696(allow traced self (capability (sys_nice)))
29697(allow traced self (cap_userns (sys_nice)))
29698(allow traced perfetto (fd (use)))
29699(allow traced shell (fd (use)))
29700(allow traced shell (fifo_file (read write)))
29701(allow traced perfetto_traces_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29702(allow traced perfetto_traces_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29703(allow traced traceur_app (fd (use)))
29704(allow traced trace_data_file (file (read write)))
29705(allow traced tracingproxy_service (service_manager (find)))
29706(allow traced servicemanager (binder (call transfer)))
29707(allow servicemanager traced (binder (call transfer)))
29708(allow servicemanager traced (dir (search)))
29709(allow servicemanager traced (file (read open)))
29710(allow servicemanager traced (process (getattr)))
29711(allow traced system_server (binder (call transfer)))
29712(allow system_server traced (binder (transfer)))
29713(allow traced system_server (fd (use)))
29714(allow traced appdomain_tmpfs (file (read write getattr map)))
29715(allow traced surfaceflinger_tmpfs (file (read write getattr map)))
29716(allow traced heapprofd_tmpfs (file (read write getattr map)))
29717(allow traced traced_probes_tmpfs (file (read write getattr map)))
29718(allow traced property_socket (sock_file (write)))
29719(allow traced init (unix_stream_socket (connectto)))
29720(allow traced debug_prop (property_service (set)))
29721(allow traced debug_prop (file (read getattr map open)))
29722(allow traced property_socket (sock_file (write)))
29723(allow traced init (unix_stream_socket (connectto)))
29724(allow traced system_trace_prop (property_service (set)))
29725(allow traced system_trace_prop (file (read getattr map open)))
29726(allow traced property_socket (sock_file (write)))
29727(allow traced init (unix_stream_socket (connectto)))
29728(allow traced traced_lazy_prop (property_service (set)))
29729(allow traced traced_lazy_prop (file (read getattr map open)))
29730(allow traced property_socket (sock_file (write)))
29731(allow traced init (unix_stream_socket (connectto)))
29732(allow traced traced_oome_heap_session_count_prop (property_service (set)))
29733(allow traced traced_oome_heap_session_count_prop (file (read getattr map open)))
29734(allow traced statsdw_socket (sock_file (write)))
29735(allow traced statsd (unix_dgram_socket (sendto)))
29736;;* lmx 81 system/sepolicy/private/traced.te
29737
29738(neverallow traced self (process (execmem)))
29739;;* lme
29740
29741;;* lmx 84 system/sepolicy/private/traced.te
29742
29743(neverallow traced dev_type (blk_file (read write)))
29744;;* lme
29745
29746;;* lmx 87 system/sepolicy/private/traced.te
29747
29748(neverallow traced domain (process (ptrace)))
29749;;* lme
29750
29751;;* lmx 103 system/sepolicy/private/traced.te
29752
29753(neverallow traced base_typeattr_966 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
29754;;* lme
29755
29756;;* lmx 104 system/sepolicy/private/traced.te
29757
29758(neverallow traced system_data_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
29759;;* lme
29760
29761;;* lmx 110 system/sepolicy/private/traced.te
29762
29763(neverallow traced base_typeattr_967 (file (ioctl read create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
29764;;* lme
29765
29766;;* lmx 113 system/sepolicy/private/traced.te
29767
29768(neverallow base_typeattr_223 traced (process (transition)))
29769;;* lme
29770
29771;;* lmx 114 system/sepolicy/private/traced.te
29772
29773(neverallow base_typeattr_224 traced (process (dyntransition)))
29774;;* lme
29775
29776;;* lmx 125 system/sepolicy/private/traced.te
29777
29778(neverallow base_typeattr_968 tracingproxy_service (service_manager (find)))
29779;;* lme
29780
29781(allow init traced_perf_exec (file (read getattr map execute open)))
29782(allow init traced_perf (process (transition)))
29783(allow traced_perf traced_perf_exec (file (read getattr map execute open entrypoint)))
29784(dontaudit init traced_perf (process (noatsecure)))
29785(allow init traced_perf (process (siginh rlimitinh)))
29786(typetransition init traced_perf_exec process traced_perf)
29787(allow traced_perf traced (fd (use)))
29788(allow traced_perf traced_tmpfs (file (read write getattr map)))
29789(allow traced_perf traced_producer_socket (sock_file (write)))
29790(allow traced_perf traced (unix_stream_socket (connectto)))
29791(allow traced traced_perf (fd (use)))
29792(allow traced_perf self (perf_event (open cpu kernel tracepoint read write)))
29793(allow traced_perf self (capability (dac_read_search kill)))
29794(allow traced_perf packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
29795(allow traced_perf nativetest_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
29796(allow traced_perf nativetest_data_file (file (ioctl read getattr lock map open watch watch_reads)))
29797(allow traced_perf nativetest_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29798(allow traced_perf system_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
29799(allow traced_perf system_file_type (file (ioctl read getattr lock map open watch watch_reads)))
29800(allow traced_perf system_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29801(allow traced_perf apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
29802(allow traced_perf apk_data_file (file (ioctl read getattr lock map open watch watch_reads)))
29803(allow traced_perf apk_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29804(allow traced_perf dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
29805(allow traced_perf dalvikcache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
29806(allow traced_perf dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29807(allow traced_perf vendor_file_type (dir (ioctl read getattr lock open watch watch_reads search)))
29808(allow traced_perf vendor_file_type (file (ioctl read getattr lock map open watch watch_reads)))
29809(allow traced_perf vendor_file_type (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29810(allow traced_perf apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
29811(allow traced_perf apex_art_data_file (file (ioctl read getattr lock map open watch watch_reads)))
29812(allow traced_perf apex_art_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29813(allow traced_perf apex_module_data_file (dir (getattr search)))
29814(allow traced_perf proc_kallsyms (file (ioctl read getattr lock map open watch watch_reads)))
29815(allow traced_perf debugfs_tracing (dir (ioctl read getattr lock open watch watch_reads search)))
29816(allow traced_perf debugfs_tracing (file (ioctl read getattr lock map open watch watch_reads)))
29817(dontaudit traced_perf domain (dir (getattr open search)))
29818(dontaudit traced_perf domain (process (signal)))
29819;;* lmx 61 system/sepolicy/private/traced_perf.te
29820
29821(neverallow traced_perf app_data_file_type (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
29822;;* lme
29823
29824;;* lmx 65 system/sepolicy/private/traced_perf.te
29825
29826(neverallow traced_perf hal_configstore_server (file (read)))
29827(neverallow traced_perf apexd (file (read)))
29828(neverallow traced_perf app_zygote (file (read)))
29829(neverallow traced_perf bpfloader (file (read)))
29830(neverallow traced_perf init (file (read)))
29831(neverallow traced_perf kernel (file (read)))
29832(neverallow traced_perf keystore (file (read)))
29833(neverallow traced_perf llkd (file (read)))
29834(neverallow traced_perf logd (file (read)))
29835(neverallow traced_perf ueventd (file (read)))
29836(neverallow traced_perf vendor_init (file (read)))
29837(neverallow traced_perf vold (file (read)))
29838(neverallow traced_perf webview_zygote (file (read)))
29839(neverallow traced_perf zygote (file (read)))
29840;;* lme
29841
29842;;* lmx 65 system/sepolicy/private/traced_perf.te
29843
29844(neverallow traced_perf hal_configstore_server (process (signal)))
29845(neverallow traced_perf apexd (process (signal)))
29846(neverallow traced_perf app_zygote (process (signal)))
29847(neverallow traced_perf bpfloader (process (signal)))
29848(neverallow traced_perf init (process (signal)))
29849(neverallow traced_perf kernel (process (signal)))
29850(neverallow traced_perf keystore (process (signal)))
29851(neverallow traced_perf llkd (process (signal)))
29852(neverallow traced_perf logd (process (signal)))
29853(neverallow traced_perf ueventd (process (signal)))
29854(neverallow traced_perf vendor_init (process (signal)))
29855(neverallow traced_perf vold (process (signal)))
29856(neverallow traced_perf webview_zygote (process (signal)))
29857(neverallow traced_perf zygote (process (signal)))
29858;;* lme
29859
29860(allow init traced_probes_exec (file (read getattr map execute open)))
29861(allow init traced_probes (process (transition)))
29862(allow traced_probes traced_probes_exec (file (read getattr map execute open entrypoint)))
29863(dontaudit init traced_probes (process (noatsecure)))
29864(allow init traced_probes (process (siginh rlimitinh)))
29865(typetransition init traced_probes_exec process traced_probes)
29866(typetransition traced_probes tmpfs file traced_probes_tmpfs)
29867(allow traced_probes traced_probes_tmpfs (file (read write getattr map)))
29868(allow traced_probes traced (fd (use)))
29869(allow traced_probes traced_tmpfs (file (read write getattr map)))
29870(allow traced_probes traced_producer_socket (sock_file (write)))
29871(allow traced_probes traced (unix_stream_socket (connectto)))
29872(allow traced traced_probes (fd (use)))
29873(allow traced_probes debugfs_tracing (dir (ioctl read getattr lock open watch watch_reads search)))
29874(allow traced_probes debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
29875(allow traced_probes debugfs_trace_marker (file (getattr)))
29876(allow traced_probes debugfs_tracing_printk_formats (file (ioctl read getattr lock map open watch watch_reads)))
29877(allow traced_probes debugfs_tracing_instances (dir (search)))
29878(allow traced_probes debugfs_mm_events_tracing (dir (search)))
29879(allow traced_probes debugfs_mm_events_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
29880(allow traced_probes self (capability (sys_nice)))
29881(allow traced_probes self (cap_userns (sys_nice)))
29882(allow traced_probes domain (dir (ioctl read getattr lock open watch watch_reads search)))
29883(allow traced_probes domain (file (ioctl read getattr lock map open watch watch_reads)))
29884(allow traced_probes domain (lnk_file (ioctl read getattr lock map open watch watch_reads)))
29885(allow traced_probes proc_kallsyms (file (ioctl read getattr lock map open watch watch_reads)))
29886(allow traced_probes packages_list_file (file (ioctl read getattr lock map open watch watch_reads)))
29887(allow traced_probes game_mode_intervention_list_file (file (ioctl read getattr lock map open watch watch_reads)))
29888(allow traced_probes kmsg_device (chr_file (write)))
29889(allow traced_probes system_file (dir (read open)))
29890(allow traced_probes self (capability (dac_read_search)))
29891(allow traced_probes self (cap_userns (dac_read_search)))
29892(allow traced_probes apk_data_file (dir (read getattr open search)))
29893(allow traced_probes apex_module_data_file (dir (read getattr open search)))
29894(allow traced_probes apex_art_data_file (dir (read getattr open search)))
29895(allow traced_probes dalvikcache_data_file (dir (read getattr open search)))
29896(allow traced_probes system_app_data_file (dir (read getattr open search)))
29897(allow traced_probes backup_data_file (dir (read getattr open search)))
29898(allow traced_probes bootstat_data_file (dir (read getattr open search)))
29899(allow traced_probes update_engine_data_file (dir (read getattr open search)))
29900(allow traced_probes update_engine_log_data_file (dir (read getattr open search)))
29901(allow traced_probes user_profile_root_file (dir (read getattr open search)))
29902(allow traced_probes user_profile_data_file (dir (read getattr open search)))
29903(allow traced_probes atrace_exec (file (read getattr map execute open)))
29904(allow traced_probes atrace (process (transition)))
29905(allow atrace atrace_exec (file (read getattr map execute open entrypoint)))
29906(allow atrace traced_probes (process (sigchld)))
29907(dontaudit traced_probes atrace (process (noatsecure)))
29908(allow traced_probes atrace (process (siginh rlimitinh)))
29909(typetransition traced_probes atrace_exec process atrace)
29910(allow traced_probes atrace (process (sigkill)))
29911(allow traced_probes proc_buddyinfo (file (ioctl read getattr lock map open watch watch_reads)))
29912(allow traced_probes proc_meminfo (file (ioctl read getattr lock map open watch watch_reads)))
29913(allow traced_probes proc_pressure_cpu (file (ioctl read getattr lock map open watch watch_reads)))
29914(allow traced_probes proc_pressure_io (file (ioctl read getattr lock map open watch watch_reads)))
29915(allow traced_probes proc_pressure_mem (file (ioctl read getattr lock map open watch watch_reads)))
29916(allow traced_probes proc_stat (file (ioctl read getattr lock map open watch watch_reads)))
29917(allow traced_probes proc_vmstat (file (ioctl read getattr lock map open watch watch_reads)))
29918(allow traced_probes sysfs_devfreq_dir (dir (ioctl read getattr lock open watch watch_reads search)))
29919(allow traced_probes sysfs_devfreq_cur (file (ioctl read getattr lock map open watch watch_reads)))
29920(allow traced_probes proc_diskstats (file (ioctl read getattr lock map open watch watch_reads)))
29921(allow traced_probes statsdw_socket (sock_file (write)))
29922(allow traced_probes statsd (unix_dgram_socket (sendto)))
29923(allow traced_probes statsd (binder (call transfer)))
29924(allow statsd traced_probes (binder (transfer)))
29925(allow traced_probes statsd (fd (use)))
29926(allow traced_probes stats_service (service_manager (find)))
29927;;* lmx 121 system/sepolicy/private/traced_probes.te
29928
29929(neverallow traced_probes self (process (execmem)))
29930;;* lme
29931
29932;;* lmx 124 system/sepolicy/private/traced_probes.te
29933
29934(neverallow traced_probes dev_type (blk_file (read write)))
29935;;* lme
29936
29937;;* lmx 127 system/sepolicy/private/traced_probes.te
29938
29939(neverallow traced_probes domain (process (ptrace)))
29940;;* lme
29941
29942;;* lmx 152 system/sepolicy/private/traced_probes.te
29943
29944(neverallow traced_probes base_typeattr_969 (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
29945;;* lme
29946
29947;;* lmx 153 system/sepolicy/private/traced_probes.te
29948
29949(neverallow traced_probes system_data_file (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent rmdir)))
29950;;* lme
29951
29952;;* lmx 159 system/sepolicy/private/traced_probes.te
29953
29954(neverallow traced_probes base_typeattr_970 (file (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
29955;;* lme
29956
29957;;* lmx 162 system/sepolicy/private/traced_probes.te
29958
29959(neverallow base_typeattr_223 traced_probes (process (transition)))
29960;;* lme
29961
29962;;* lmx 163 system/sepolicy/private/traced_probes.te
29963
29964(neverallow base_typeattr_224 traced_probes (process (dyntransition)))
29965;;* lme
29966
29967(typetransition traceur_app tmpfs file appdomain_tmpfs)
29968(allow traceur_app traceur_app_userfaultfd (anon_inode (ioctl read create)))
29969(dontaudit su traceur_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29970;;* lmx 3 system/sepolicy/private/traceur_app.te
29971
29972(neverallow base_typeattr_971 traceur_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
29973;;* lme
29974
29975(allow traceur_app appdomain_tmpfs (file (read write getattr map execute)))
29976;;* lmx 3 system/sepolicy/private/traceur_app.te
29977
29978(neverallow base_typeattr_972 base_typeattr_971 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29979;;* lme
29980
29981;;* lmx 3 system/sepolicy/private/traceur_app.te
29982
29983(neverallow base_typeattr_973 traceur_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
29984;;* lme
29985
29986;;* lmx 3 system/sepolicy/private/traceur_app.te
29987
29988(neverallow base_typeattr_974 traceur_app (process (ptrace)))
29989;;* lme
29990
29991(allow traceur_app debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
29992(allow traceur_app debugfs_tracing_debug (dir (ioctl read getattr lock open watch watch_reads search)))
29993(allow traceur_app trace_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
29994(allow traceur_app trace_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29995(allow traceur_app wm_trace_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
29996(allow traceur_app wm_trace_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
29997(allow traceur_app atrace_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
29998(allow traceur_app perfetto_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
29999(allow traceur_app traced_consumer_socket (sock_file (write)))
30000(allow traceur_app traced (unix_stream_socket (connectto)))
30001(dontaudit traceur_app debugfs_tracing_debug (file (audit_access)))
30002(allow traceur_app property_socket (sock_file (write)))
30003(allow traceur_app init (unix_stream_socket (connectto)))
30004(allow traceur_app debug_prop (property_service (set)))
30005(allow traceur_app debug_prop (file (read getattr map open)))
30006(typetransition ueventd tmpfs file ueventd_tmpfs)
30007(allow ueventd ueventd_tmpfs (file (read write getattr map)))
30008(allow ueventd property_socket (sock_file (write)))
30009(allow ueventd init (unix_stream_socket (connectto)))
30010(allow ueventd cold_boot_done_prop (property_service (set)))
30011(allow ueventd cold_boot_done_prop (file (read getattr map open)))
30012(allow init uncrypt_exec (file (read getattr map execute open)))
30013(allow init uncrypt (process (transition)))
30014(allow uncrypt uncrypt_exec (file (read getattr map execute open entrypoint)))
30015(dontaudit init uncrypt (process (noatsecure)))
30016(allow init uncrypt (process (siginh rlimitinh)))
30017(typetransition init uncrypt_exec process uncrypt)
30018(allow uncrypt property_socket (sock_file (write)))
30019(allow uncrypt init (unix_stream_socket (connectto)))
30020(allow uncrypt powerctl_prop (property_service (set)))
30021(allow uncrypt powerctl_prop (file (read getattr map open)))
30022(typetransition untrusted_app tmpfs file appdomain_tmpfs)
30023(allow untrusted_app untrusted_app_userfaultfd (anon_inode (ioctl read create)))
30024(dontaudit su untrusted_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30025;;* lmx 13 system/sepolicy/private/untrusted_app.te
30026
30027(neverallow base_typeattr_975 untrusted_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30028;;* lme
30029
30030(allow untrusted_app appdomain_tmpfs (file (read write getattr map execute)))
30031;;* lmx 13 system/sepolicy/private/untrusted_app.te
30032
30033(neverallow base_typeattr_976 base_typeattr_975 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30034;;* lme
30035
30036;;* lmx 13 system/sepolicy/private/untrusted_app.te
30037
30038(neverallow base_typeattr_977 untrusted_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30039;;* lme
30040
30041;;* lmx 13 system/sepolicy/private/untrusted_app.te
30042
30043(neverallow base_typeattr_978 untrusted_app (process (ptrace)))
30044;;* lme
30045
30046(allow untrusted_app sdk_sandbox_data_file (fd (use)))
30047(allow untrusted_app sdk_sandbox_data_file (file (write)))
30048;;* lmx 23 system/sepolicy/private/untrusted_app.te
30049
30050(neverallow untrusted_app sdk_sandbox_data_file (file (create open)))
30051;;* lme
30052
30053(typetransition untrusted_app_25 tmpfs file appdomain_tmpfs)
30054(allow untrusted_app_25 untrusted_app_25_userfaultfd (anon_inode (ioctl read create)))
30055(dontaudit su untrusted_app_25_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30056;;* lmx 13 system/sepolicy/private/untrusted_app_25.te
30057
30058(neverallow base_typeattr_979 untrusted_app_25_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30059;;* lme
30060
30061(allow untrusted_app_25 appdomain_tmpfs (file (read write getattr map execute)))
30062;;* lmx 13 system/sepolicy/private/untrusted_app_25.te
30063
30064(neverallow base_typeattr_980 base_typeattr_979 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30065;;* lme
30066
30067;;* lmx 13 system/sepolicy/private/untrusted_app_25.te
30068
30069(neverallow base_typeattr_981 untrusted_app_25 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30070;;* lme
30071
30072;;* lmx 13 system/sepolicy/private/untrusted_app_25.te
30073
30074(neverallow base_typeattr_982 untrusted_app_25 (process (ptrace)))
30075;;* lme
30076
30077(allow untrusted_app_25 proc_misc (file (ioctl read getattr lock map open watch watch_reads)))
30078(allow untrusted_app_25 proc_tty_drivers (file (ioctl read getattr lock map open watch watch_reads)))
30079(allow untrusted_app_25 apk_data_file (file (execmod)))
30080(allow untrusted_app_25 app_data_file (file (execmod)))
30081(allow untrusted_app_25 asec_public_file (file (execmod)))
30082(allow untrusted_app_25 app_data_file (file (execute_no_trans)))
30083(auditallow untrusted_app_25 app_data_file (file (execute execute_no_trans)))
30084(allow untrusted_app_25 dex2oat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30085(allow untrusted_app_25 ashmem_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
30086(auditallow untrusted_app_25 ashmem_device (chr_file (open)))
30087(allow untrusted_app_25 mnt_sdcard_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30088(allow untrusted_app_25 self (netlink_route_socket (nlmsg_getneigh)))
30089(auditallow untrusted_app_25 self (netlink_route_socket (nlmsg_getneigh)))
30090(allow untrusted_app_25 mdnsd_socket (sock_file (write)))
30091(allow untrusted_app_25 mdnsd (unix_stream_socket (connectto)))
30092(allow untrusted_app_25 apk_data_file (dir (watch watch_reads)))
30093(allow untrusted_app_25 apk_data_file (file (watch watch_reads)))
30094(typetransition untrusted_app_27 tmpfs file appdomain_tmpfs)
30095(allow untrusted_app_27 untrusted_app_27_userfaultfd (anon_inode (ioctl read create)))
30096(dontaudit su untrusted_app_27_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30097;;* lmx 13 system/sepolicy/private/untrusted_app_27.te
30098
30099(neverallow base_typeattr_983 untrusted_app_27_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30100;;* lme
30101
30102(allow untrusted_app_27 appdomain_tmpfs (file (read write getattr map execute)))
30103;;* lmx 13 system/sepolicy/private/untrusted_app_27.te
30104
30105(neverallow base_typeattr_984 base_typeattr_983 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30106;;* lme
30107
30108;;* lmx 13 system/sepolicy/private/untrusted_app_27.te
30109
30110(neverallow base_typeattr_985 untrusted_app_27 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30111;;* lme
30112
30113;;* lmx 13 system/sepolicy/private/untrusted_app_27.te
30114
30115(neverallow base_typeattr_986 untrusted_app_27 (process (ptrace)))
30116;;* lme
30117
30118(allow untrusted_app_27 apk_data_file (file (execmod)))
30119(allow untrusted_app_27 app_data_file (file (execmod)))
30120(allow untrusted_app_27 asec_public_file (file (execmod)))
30121(allow untrusted_app_27 app_data_file (file (execute_no_trans)))
30122(auditallow untrusted_app_27 app_data_file (file (execute execute_no_trans)))
30123(allow untrusted_app_27 dex2oat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30124(allow untrusted_app_27 ashmem_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
30125(auditallow untrusted_app_27 ashmem_device (chr_file (open)))
30126(allow untrusted_app_27 mnt_sdcard_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30127(allow untrusted_app_27 self (netlink_route_socket (nlmsg_getneigh)))
30128(auditallow untrusted_app_27 self (netlink_route_socket (nlmsg_getneigh)))
30129(allow untrusted_app_27 mdnsd_socket (sock_file (write)))
30130(allow untrusted_app_27 mdnsd (unix_stream_socket (connectto)))
30131(allow untrusted_app_27 apk_data_file (dir (watch watch_reads)))
30132(allow untrusted_app_27 apk_data_file (file (watch watch_reads)))
30133(typetransition untrusted_app_29 tmpfs file appdomain_tmpfs)
30134(allow untrusted_app_29 untrusted_app_29_userfaultfd (anon_inode (ioctl read create)))
30135(dontaudit su untrusted_app_29_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30136;;* lmx 13 system/sepolicy/private/untrusted_app_29.te
30137
30138(neverallow base_typeattr_987 untrusted_app_29_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30139;;* lme
30140
30141(allow untrusted_app_29 appdomain_tmpfs (file (read write getattr map execute)))
30142;;* lmx 13 system/sepolicy/private/untrusted_app_29.te
30143
30144(neverallow base_typeattr_988 base_typeattr_987 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30145;;* lme
30146
30147;;* lmx 13 system/sepolicy/private/untrusted_app_29.te
30148
30149(neverallow base_typeattr_989 untrusted_app_29 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30150;;* lme
30151
30152;;* lmx 13 system/sepolicy/private/untrusted_app_29.te
30153
30154(neverallow base_typeattr_990 untrusted_app_29 (process (ptrace)))
30155;;* lme
30156
30157(allow untrusted_app_29 self (netlink_route_socket (nlmsg_getneigh)))
30158(auditallow untrusted_app_29 self (netlink_route_socket (nlmsg_getneigh)))
30159(allow untrusted_app_29 mdnsd_socket (sock_file (write)))
30160(allow untrusted_app_29 mdnsd (unix_stream_socket (connectto)))
30161(allow untrusted_app_29 apk_data_file (dir (watch watch_reads)))
30162(allow untrusted_app_29 apk_data_file (file (watch watch_reads)))
30163(typetransition untrusted_app_30 tmpfs file appdomain_tmpfs)
30164(allow untrusted_app_30 untrusted_app_30_userfaultfd (anon_inode (ioctl read create)))
30165(dontaudit su untrusted_app_30_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30166;;* lmx 15 system/sepolicy/private/untrusted_app_30.te
30167
30168(neverallow base_typeattr_991 untrusted_app_30_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30169;;* lme
30170
30171(allow untrusted_app_30 appdomain_tmpfs (file (read write getattr map execute)))
30172;;* lmx 15 system/sepolicy/private/untrusted_app_30.te
30173
30174(neverallow base_typeattr_992 base_typeattr_991 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30175;;* lme
30176
30177;;* lmx 15 system/sepolicy/private/untrusted_app_30.te
30178
30179(neverallow base_typeattr_993 untrusted_app_30 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30180;;* lme
30181
30182;;* lmx 15 system/sepolicy/private/untrusted_app_30.te
30183
30184(neverallow base_typeattr_994 untrusted_app_30 (process (ptrace)))
30185;;* lme
30186
30187(allow untrusted_app_30 self (netlink_route_socket (nlmsg_getneigh)))
30188(auditallow untrusted_app_30 self (netlink_route_socket (nlmsg_getneigh)))
30189(allow untrusted_app_30 mdnsd_socket (sock_file (write)))
30190(allow untrusted_app_30 mdnsd (unix_stream_socket (connectto)))
30191(allow untrusted_app_30 apk_data_file (dir (watch watch_reads)))
30192(allow untrusted_app_30 apk_data_file (file (watch watch_reads)))
30193(typetransition untrusted_app_32 tmpfs file appdomain_tmpfs)
30194(allow untrusted_app_32 untrusted_app_32_userfaultfd (anon_inode (ioctl read create)))
30195(dontaudit su untrusted_app_32_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30196;;* lmx 13 system/sepolicy/private/untrusted_app_32.te
30197
30198(neverallow base_typeattr_995 untrusted_app_32_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30199;;* lme
30200
30201(allow untrusted_app_32 appdomain_tmpfs (file (read write getattr map execute)))
30202;;* lmx 13 system/sepolicy/private/untrusted_app_32.te
30203
30204(neverallow base_typeattr_996 base_typeattr_995 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30205;;* lme
30206
30207;;* lmx 13 system/sepolicy/private/untrusted_app_32.te
30208
30209(neverallow base_typeattr_997 untrusted_app_32 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30210;;* lme
30211
30212;;* lmx 13 system/sepolicy/private/untrusted_app_32.te
30213
30214(neverallow base_typeattr_998 untrusted_app_32 (process (ptrace)))
30215;;* lme
30216
30217(allow untrusted_app_32 sdk_sandbox_data_file (fd (use)))
30218(allow untrusted_app_32 sdk_sandbox_data_file (file (write)))
30219;;* lmx 23 system/sepolicy/private/untrusted_app_32.te
30220
30221(neverallow untrusted_app_32 sdk_sandbox_data_file (file (create open)))
30222;;* lme
30223
30224(allow untrusted_app_32 mdnsd_socket (sock_file (write)))
30225(allow untrusted_app_32 mdnsd (unix_stream_socket (connectto)))
30226(allow untrusted_app_32 apk_data_file (dir (watch watch_reads)))
30227(allow untrusted_app_32 apk_data_file (file (watch watch_reads)))
30228(allow untrusted_app_all privapp_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30229(allow untrusted_app_all app_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30230(auditallow untrusted_app_all app_data_file (file (execute)))
30231(allow untrusted_app_all system_linker_exec (file (execute_no_trans)))
30232(allow untrusted_app_all privapp_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30233(allow untrusted_app_all app_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30234(allow untrusted_app_all app_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30235(allow untrusted_app_all app_data_file (fifo_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30236(allow untrusted_app_all app_exec_data_file (file (ioctl read getattr lock map unlink execute open watch watch_reads)))
30237(allow untrusted_app_all asec_apk_file (file (ioctl read getattr lock map open watch watch_reads)))
30238(allow untrusted_app_all asec_apk_file (dir (ioctl read getattr lock open watch watch_reads search)))
30239(allow untrusted_app_all asec_public_file (file (execute)))
30240(allow untrusted_app_all shell_data_file (file (ioctl read getattr lock map open watch watch_reads)))
30241(allow untrusted_app_all shell_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
30242(allow untrusted_app_all trace_data_file (file (read getattr)))
30243;;* lmx 65 system/sepolicy/private/untrusted_app_all.te
30244
30245(neverallow untrusted_app_all trace_data_file (dir (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
30246;;* lme
30247
30248;;* lmx 66 system/sepolicy/private/untrusted_app_all.te
30249
30250(neverallow untrusted_app_all trace_data_file (file (write create setattr relabelfrom append unlink link rename open)))
30251;;* lme
30252
30253;;* lmx 69 system/sepolicy/private/untrusted_app_all.te
30254
30255(neverallow untrusted_app_all debugfs_tracing (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30256;;* lme
30257
30258(allow untrusted_app_all apk_tmp_file (file (read getattr)))
30259(allow untrusted_app_all apk_private_tmp_file (file (read getattr)))
30260(allow untrusted_app_all system_app_data_file (file (read write getattr)))
30261(allow untrusted_app_all media_rw_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
30262(allow untrusted_app_all media_rw_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30263(allow untrusted_app_all servicemanager (service_manager (list)))
30264(allow untrusted_app_all audioserver_service (service_manager (find)))
30265(allow untrusted_app_all cameraserver_service (service_manager (find)))
30266(allow untrusted_app_all drmserver_service (service_manager (find)))
30267(allow untrusted_app_all mediaserver_service (service_manager (find)))
30268(allow untrusted_app_all mediaextractor_service (service_manager (find)))
30269(allow untrusted_app_all mediametrics_service (service_manager (find)))
30270(allow untrusted_app_all mediadrmserver_service (service_manager (find)))
30271(allow untrusted_app_all nfc_service (service_manager (find)))
30272(allow untrusted_app_all radio_service (service_manager (find)))
30273(allow untrusted_app_all app_api_service (service_manager (find)))
30274(allow untrusted_app_all vr_manager_service (service_manager (find)))
30275(allow untrusted_app_all self (process (ptrace)))
30276(allow untrusted_app_all runas_app (unix_stream_socket (connectto)))
30277(allow untrusted_app_all runas_app (process (sigchld)))
30278(allow untrusted_app_all sysfs_hwrandom (dir (search)))
30279(allow untrusted_app_all sysfs_hwrandom (file (ioctl read getattr lock map open watch watch_reads)))
30280(allow untrusted_app_all preloads_media_file (dir (ioctl read getattr lock open watch watch_reads search)))
30281(allow untrusted_app_all preloads_media_file (file (ioctl read getattr lock map open watch watch_reads)))
30282(allow untrusted_app_all preloads_data_file (dir (search)))
30283(allow untrusted_app_all vendor_app_file (dir (read getattr open search)))
30284(allow untrusted_app_all vendor_app_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30285(allow untrusted_app_all vendor_app_file (lnk_file (read getattr open)))
30286(allow untrusted_app_all system_server (udp_socket (read write getattr connect getopt setopt recvfrom sendto)))
30287(allow untrusted_app_all rs_exec (file (read getattr map execute open)))
30288(allow untrusted_app_all rs (process (transition)))
30289(allow rs rs_exec (file (read getattr map execute open entrypoint)))
30290(allow rs untrusted_app_all (process (sigchld)))
30291(dontaudit untrusted_app_all rs (process (noatsecure)))
30292(allow untrusted_app_all rs (process (siginh rlimitinh)))
30293(typetransition untrusted_app_all rs_exec process rs)
30294(dontaudit untrusted_app_all debugfs_tracing (file (ioctl read write getattr lock append map open watch watch_reads)))
30295(dontaudit untrusted_app_all net_dns_prop (file (read)))
30296(dontaudit untrusted_app_all proc_stat (file (read)))
30297(dontaudit untrusted_app_all proc_uptime (file (read)))
30298(dontaudit untrusted_app_all proc_vmstat (file (read)))
30299(dontaudit untrusted_app_all proc_zoneinfo (file (read)))
30300(typetransition untrusted_app_all devpts chr_file untrusted_app_all_devpts)
30301(allow untrusted_app_all untrusted_app_all_devpts (chr_file (ioctl read write getattr open)))
30302(allowx untrusted_app_all untrusted_app_all_devpts (ioctl chr_file ((range 0x5401 0x5404) 0x540b (range 0x540e 0x5411) (range 0x5413 0x5414) (range 0x5450 0x5451))))
30303;;* lmx 157 system/sepolicy/private/untrusted_app_all.te
30304
30305(neverallowx base_typeattr_224 untrusted_app_all_devpts (ioctl chr_file (0x5412)))
30306;;* lme
30307
30308(allow untrusted_app_all virtualizationmanager_exec (file (read getattr map execute open)))
30309(allow untrusted_app_all virtualizationmanager (process (transition)))
30310(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
30311(allow virtualizationmanager untrusted_app_all (process (sigchld)))
30312(dontaudit untrusted_app_all virtualizationmanager (process (noatsecure)))
30313(allow untrusted_app_all virtualizationmanager (process (siginh rlimitinh)))
30314(typetransition untrusted_app_all virtualizationmanager_exec process virtualizationmanager)
30315(allow crosvm untrusted_app_all (unix_stream_socket (ioctl read write getattr)))
30316(allow virtualizationmanager untrusted_app_all (unix_stream_socket (ioctl read write getattr)))
30317(allow crosvm untrusted_app_all (fd (use)))
30318(allow virtualizationmanager untrusted_app_all (fd (use)))
30319(allow untrusted_app_all virtualizationmanager (fd (use)))
30320(allow crosvm untrusted_app_all (fifo_file (ioctl read write getattr)))
30321(allow virtualizationmanager untrusted_app_all (fifo_file (ioctl read write getattr)))
30322(allow untrusted_app_all virtualizationmanager (vsock_socket (read write getattr getopt)))
30323(allow untrusted_app_all hypervisor_prop (file (read getattr map open)))
30324(allow untrusted_app_all virtualizationservice_data_file (file (read getattr)))
30325(allow init update_engine_exec (file (read getattr map execute open)))
30326(allow init update_engine (process (transition)))
30327(allow update_engine update_engine_exec (file (read getattr map execute open entrypoint)))
30328(dontaudit init update_engine (process (noatsecure)))
30329(allow init update_engine (process (siginh rlimitinh)))
30330(typetransition init update_engine_exec process update_engine)
30331(allow update_engine gsi_service (service_manager (find)))
30332(allow update_engine gsid (binder (call transfer)))
30333(allow gsid update_engine (binder (transfer)))
30334(allow update_engine gsid (fd (use)))
30335(allow update_engine property_socket (sock_file (write)))
30336(allow update_engine init (unix_stream_socket (connectto)))
30337(allow update_engine ctl_gsid_prop (property_service (set)))
30338(allow update_engine ctl_gsid_prop (file (read getattr map open)))
30339(allow update_engine property_socket (sock_file (write)))
30340(allow update_engine init (unix_stream_socket (connectto)))
30341(allow update_engine ctl_snapuserd_prop (property_service (set)))
30342(allow update_engine ctl_snapuserd_prop (file (read getattr map open)))
30343(allow update_engine property_socket (sock_file (write)))
30344(allow update_engine init (unix_stream_socket (connectto)))
30345(allow update_engine ota_prop (property_service (set)))
30346(allow update_engine ota_prop (file (read getattr map open)))
30347(allow update_engine ota_build_prop (file (read getattr map open)))
30348(allow update_engine gsid_prop (file (read getattr map open)))
30349(allow update_engine gki_apex_prepostinstall (binder (call transfer)))
30350(allow gki_apex_prepostinstall update_engine (binder (transfer)))
30351(allow update_engine gki_apex_prepostinstall (fd (use)))
30352(allow update_engine system_app (binder (call transfer)))
30353(allow system_app update_engine (binder (transfer)))
30354(allow update_engine system_app (fd (use)))
30355(allow update_engine snapuserd (unix_stream_socket (connectto)))
30356(allow update_engine snapuserd_socket (sock_file (write)))
30357(allow update_engine snapuserd_prop (file (read getattr map open)))
30358(allow update_engine apex_service (service_manager (find)))
30359(allow update_engine apexd (binder (call transfer)))
30360(allow apexd update_engine (binder (transfer)))
30361(allow update_engine apexd (fd (use)))
30362(allow update_engine servicemanager (binder (call transfer)))
30363(allow servicemanager update_engine (binder (call transfer)))
30364(allow servicemanager update_engine (dir (search)))
30365(allow servicemanager update_engine (file (read open)))
30366(allow servicemanager update_engine (process (getattr)))
30367(allow update_engine_common postinstall_exec (file (read getattr map execute open)))
30368(allow update_engine_common postinstall (process (transition)))
30369(allow postinstall postinstall_exec (file (read getattr map execute open entrypoint)))
30370(allow postinstall update_engine_common (process (sigchld)))
30371(dontaudit update_engine_common postinstall (process (noatsecure)))
30372(allow update_engine_common postinstall (process (siginh rlimitinh)))
30373(typetransition update_engine_common postinstall_exec process postinstall)
30374(allow update_engine_common postinstall_file (file (read getattr map execute open)))
30375(allow update_engine_common postinstall (process (transition)))
30376(allow postinstall postinstall_file (file (read getattr map execute open entrypoint)))
30377(allow postinstall update_engine_common (process (sigchld)))
30378(dontaudit update_engine_common postinstall (process (noatsecure)))
30379(allow update_engine_common postinstall (process (siginh rlimitinh)))
30380(typetransition update_engine_common postinstall_file process postinstall)
30381(allow update_engine_common labeledfs (filesystem (mount unmount relabelfrom)))
30382(allow init update_verifier_exec (file (read getattr map execute open)))
30383(allow init update_verifier (process (transition)))
30384(allow update_verifier update_verifier_exec (file (read getattr map execute open entrypoint)))
30385(dontaudit init update_verifier (process (noatsecure)))
30386(allow init update_verifier (process (siginh rlimitinh)))
30387(typetransition init update_verifier_exec process update_verifier)
30388(allow update_verifier property_socket (sock_file (write)))
30389(allow update_verifier init (unix_stream_socket (connectto)))
30390(allow update_verifier powerctl_prop (property_service (set)))
30391(allow update_verifier powerctl_prop (file (read getattr map open)))
30392(allow update_verifier property_socket (sock_file (write)))
30393(allow update_verifier init (unix_stream_socket (connectto)))
30394(allow update_verifier ota_prop (property_service (set)))
30395(allow update_verifier ota_prop (file (read getattr map open)))
30396(allow update_verifier snapuserd_socket (sock_file (write)))
30397(allow update_verifier snapuserd (unix_stream_socket (connectto)))
30398(allow update_verifier virtual_ab_prop (file (read getattr map open)))
30399(allow init uprobestats_exec (file (read getattr map execute open)))
30400(allow init uprobestats (process (transition)))
30401(allow uprobestats uprobestats_exec (file (read getattr map execute open entrypoint)))
30402(dontaudit init uprobestats (process (noatsecure)))
30403(allow init uprobestats (process (siginh rlimitinh)))
30404(typetransition init uprobestats_exec process uprobestats)
30405(allow uprobestats fs_bpf_uprobestats (file (read write)))
30406(allow uprobestats fs_bpf_uprobestats (dir (search)))
30407(allow uprobestats bpfloader (bpf (map_read map_write prog_run)))
30408(allow uprobestats self (capability2 (perfmon)))
30409(allow uprobestats self (perf_event (open cpu write)))
30410(allow uprobestats sysfs_uprobe (file (read open)))
30411(allow uprobestats sysfs_uprobe (dir (search)))
30412(allow uprobestats oatdump_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30413(allow uprobestats statsdw_socket (sock_file (write)))
30414(allow uprobestats statsd (unix_dgram_socket (sendto)))
30415(allow uprobestats servicemanager (binder (call transfer)))
30416(allow servicemanager uprobestats (binder (call transfer)))
30417(allow servicemanager uprobestats (dir (search)))
30418(allow servicemanager uprobestats (file (read open)))
30419(allow servicemanager uprobestats (process (getattr)))
30420(allow uprobestats activity_service (service_manager (find)))
30421(allow uprobestats system_server (binder (call transfer)))
30422(allow system_server uprobestats (binder (transfer)))
30423(allow uprobestats system_server (fd (use)))
30424(allow uprobestats package_native_service (service_manager (find)))
30425(allow uprobestats base_typeattr_233 (dir (ioctl read getattr lock open watch watch_reads search)))
30426(allow uprobestats base_typeattr_233 (file (ioctl read getattr lock map open watch watch_reads)))
30427(allow uprobestats base_typeattr_233 (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30428(allow uprobestats uprobestats_configs_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
30429(allow uprobestats uprobestats_configs_data_file (file (ioctl read getattr lock map unlink open watch watch_reads)))
30430(allow init usbd_exec (file (read getattr map execute open)))
30431(allow init usbd (process (transition)))
30432(allow usbd usbd_exec (file (read getattr map execute open entrypoint)))
30433(dontaudit init usbd (process (noatsecure)))
30434(allow init usbd (process (siginh rlimitinh)))
30435(typetransition init usbd_exec process usbd)
30436(allow usbd system_prop (file (read getattr map open)))
30437(allow usbd property_socket (sock_file (write)))
30438(allow usbd init (unix_stream_socket (connectto)))
30439(allow usbd ctl_default_prop (property_service (set)))
30440(allow usbd ctl_default_prop (file (read getattr map open)))
30441(allow usbd property_socket (sock_file (write)))
30442(allow usbd init (unix_stream_socket (connectto)))
30443(allow usbd ctl_adbd_prop (property_service (set)))
30444(allow usbd ctl_adbd_prop (file (read getattr map open)))
30445(allow init vdc_exec (file (read getattr map execute open)))
30446(allow init vdc (process (transition)))
30447(allow vdc vdc_exec (file (read getattr map execute open entrypoint)))
30448(dontaudit init vdc (process (noatsecure)))
30449(allow init vdc (process (siginh rlimitinh)))
30450(typetransition init vdc_exec process vdc)
30451(allow vdc vehicle_binding_util (fd (use)))
30452(allow init vehicle_binding_util_exec (file (read getattr map execute open)))
30453(allow init vehicle_binding_util (process (transition)))
30454(allow vehicle_binding_util vehicle_binding_util_exec (file (read getattr map execute open entrypoint)))
30455(dontaudit init vehicle_binding_util (process (noatsecure)))
30456(allow init vehicle_binding_util (process (siginh rlimitinh)))
30457(typetransition init vehicle_binding_util_exec process vehicle_binding_util)
30458(allow vehicle_binding_util kmsg_device (chr_file (write getattr lock append map open)))
30459(allow vehicle_binding_util hwservicemanager (binder (call transfer)))
30460(allow hwservicemanager vehicle_binding_util (binder (call transfer)))
30461(allow hwservicemanager vehicle_binding_util (dir (search)))
30462(allow hwservicemanager vehicle_binding_util (file (read map open)))
30463(allow hwservicemanager vehicle_binding_util (process (getattr)))
30464(allow vehicle_binding_util servicemanager (binder (call transfer)))
30465(allow servicemanager vehicle_binding_util (binder (call transfer)))
30466(allow servicemanager vehicle_binding_util (dir (search)))
30467(allow servicemanager vehicle_binding_util (file (read open)))
30468(allow servicemanager vehicle_binding_util (process (getattr)))
30469(allow vehicle_binding_util vdc_exec (file (read getattr map execute open)))
30470(allow vehicle_binding_util vdc (process (transition)))
30471(allow vdc vdc_exec (file (read getattr map execute open entrypoint)))
30472(allow vdc vehicle_binding_util (process (sigchld)))
30473(dontaudit vehicle_binding_util vdc (process (noatsecure)))
30474(allow vehicle_binding_util vdc (process (siginh rlimitinh)))
30475(typetransition vehicle_binding_util vdc_exec process vdc)
30476(allow vehicle_binding_util devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
30477(dontaudit vendor_init sysfs (dir (write)))
30478(allow vendor_init system_data_root_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
30479(allow vendor_init property_socket (sock_file (write)))
30480(allow vendor_init init (unix_stream_socket (connectto)))
30481(allow vendor_init adbd_config_prop (property_service (set)))
30482(allow vendor_init adbd_config_prop (file (read getattr map open)))
30483(allow vendor_init device_config_virtualization_framework_native_prop (file (read getattr map open)))
30484(allow vendor_init apex_ready_prop (file (read getattr map open)))
30485(allow vendor_init base_typeattr_999 (chr_file (setattr)))
30486(typetransition viewcompiler tmpfs file viewcompiler_tmpfs)
30487(allow viewcompiler viewcompiler_tmpfs (file (read write getattr map)))
30488(allow viewcompiler installd (fd (use)))
30489(allow viewcompiler app_data_file (file (write getattr)))
30490(allow viewcompiler apk_data_file (file (read map)))
30491;;* lmx 25 system/sepolicy/private/viewcompiler.te
30492
30493(neverallow viewcompiler privapp_data_file (file (write create setattr relabelfrom append unlink link rename)))
30494;;* lme
30495
30496(allow init virtual_camera_exec (file (read getattr map execute open)))
30497(allow init virtual_camera (process (transition)))
30498(allow virtual_camera virtual_camera_exec (file (read getattr map execute open entrypoint)))
30499(dontaudit init virtual_camera (process (noatsecure)))
30500(allow init virtual_camera (process (siginh rlimitinh)))
30501(typetransition init virtual_camera_exec process virtual_camera)
30502(allow virtual_camera servicemanager (binder (call transfer)))
30503(allow servicemanager virtual_camera (binder (call transfer)))
30504(allow servicemanager virtual_camera (dir (search)))
30505(allow servicemanager virtual_camera (file (read open)))
30506(allow servicemanager virtual_camera (process (getattr)))
30507(allow virtual_camera cameraserver (binder (call transfer)))
30508(allow cameraserver virtual_camera (binder (transfer)))
30509(allow virtual_camera cameraserver (fd (use)))
30510(allow virtual_camera system_server (binder (call transfer)))
30511(allow system_server virtual_camera (binder (transfer)))
30512(allow virtual_camera system_server (fd (use)))
30513(allow virtual_camera mediaserver (binder (call transfer)))
30514(allow mediaserver virtual_camera (binder (transfer)))
30515(allow virtual_camera mediaserver (fd (use)))
30516(allow virtual_camera appdomain (binder (call transfer)))
30517(allow appdomain virtual_camera (binder (transfer)))
30518(allow virtual_camera appdomain (fd (use)))
30519(allow virtual_camera base_typeattr_369 (fd (use)))
30520(allow virtual_camera virtual_camera_service (service_manager (add find)))
30521;;* lmx 32 system/sepolicy/private/virtual_camera.te
30522
30523(neverallow base_typeattr_1000 virtual_camera_service (service_manager (add)))
30524;;* lme
30525
30526(allow virtual_camera gpu_device (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
30527(allow virtual_camera gpu_device (dir (ioctl read getattr lock open watch watch_reads search)))
30528(allow virtual_camera hal_graphics_composer (fd (use)))
30529(allow virtual_camera dumpstate (fd (use)))
30530(allow virtual_camera dumpstate (fifo_file (write)))
30531(allow virtual_camera permission_service (service_manager (find)))
30532(allow init virtual_touchpad_exec (file (read getattr map execute open)))
30533(allow init virtual_touchpad (process (transition)))
30534(allow virtual_touchpad virtual_touchpad_exec (file (read getattr map execute open entrypoint)))
30535(dontaudit init virtual_touchpad (process (noatsecure)))
30536(allow init virtual_touchpad (process (siginh rlimitinh)))
30537(typetransition init virtual_touchpad_exec process virtual_touchpad)
30538(allow virtualizationmanager adbd (fd (use)))
30539(allow virtualizationmanager adbd (unix_stream_socket (read write getattr)))
30540(allow virtualizationmanager devpts (chr_file (ioctl read write getattr)))
30541(allow virtualizationmanager servicemanager (binder (call transfer)))
30542(allow servicemanager virtualizationmanager (binder (call transfer)))
30543(allow servicemanager virtualizationmanager (dir (search)))
30544(allow servicemanager virtualizationmanager (file (read open)))
30545(allow servicemanager virtualizationmanager (process (getattr)))
30546(allow virtualizationmanager virtualization_service (service_manager (find)))
30547(allow virtualizationmanager virtualizationservice (binder (call transfer)))
30548(allow virtualizationservice virtualizationmanager (binder (transfer)))
30549(allow virtualizationmanager virtualizationservice (fd (use)))
30550(allow virtualizationmanager system_server (binder (call transfer)))
30551(allow system_server virtualizationmanager (binder (transfer)))
30552(allow virtualizationmanager system_server (fd (use)))
30553(allow virtualizationmanager package_native_service (service_manager (find)))
30554(allow virtualizationmanager permission_service (service_manager (find)))
30555(allow virtualizationmanager crosvm_exec (file (read getattr map execute open)))
30556(allow virtualizationmanager crosvm (process (transition)))
30557(allow crosvm crosvm_exec (file (read getattr map execute open entrypoint)))
30558(allow crosvm virtualizationmanager (process (sigchld)))
30559(dontaudit virtualizationmanager crosvm (process (noatsecure)))
30560(allow virtualizationmanager crosvm (process (siginh rlimitinh)))
30561(typetransition virtualizationmanager crosvm_exec process crosvm)
30562(allow virtualizationmanager crosvm (process (sigkill)))
30563(allow virtualizationmanager virtualizationservice_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
30564(allow virtualizationmanager virtualizationservice_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30565(allow virtualizationmanager virtualizationservice_data_file (sock_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30566(allow virtualizationmanager apk_data_file (file (read getattr)))
30567(allow virtualizationmanager app_data_file (file (read write getattr)))
30568(allow virtualizationmanager privapp_data_file (file (read write getattr)))
30569(allow virtualizationmanager apex_compos_data_file (file (read write getattr)))
30570(allow virtualizationmanager apex_virt_data_file (file (read write getattr)))
30571(allow virtualizationmanager shell_data_file (file (read write getattr)))
30572(allow virtualizationmanager apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
30573(allow virtualizationmanager apex_data_file (dir (search)))
30574(allow virtualizationmanager staging_data_file (file (ioctl read getattr lock map open watch watch_reads)))
30575(allow virtualizationmanager staging_data_file (dir (search)))
30576(allow virtualizationmanager derive_classpath_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30577(allow virtualizationmanager apex_mnt_dir (dir (ioctl read getattr lock open watch watch_reads search)))
30578(dontaudit virtualizationmanager self (dir (write)))
30579(allow virtualizationmanager self (vsock_socket (read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
30580(allow virtualizationmanager hypervisor_prop (file (read getattr map open)))
30581(allow virtualizationmanager hypervisor_restricted_prop (file (read getattr map open)))
30582(dontaudit virtualizationmanager hypervisor_pvmfw_prop (file (read)))
30583;;* lmx 72 system/sepolicy/private/virtualizationmanager.te
30584
30585(neverallow base_typeattr_855 hypervisor_pvmfw_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30586;;* lme
30587
30588(dontaudit virtualizationmanager hypervisor_virtualizationmanager_prop (file (read)))
30589;;* lmx 77 system/sepolicy/private/virtualizationmanager.te
30590
30591(neverallow base_typeattr_855 hypervisor_virtualizationmanager_prop (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30592;;* lme
30593
30594(allow virtualizationmanager tombstoned_crash_socket (sock_file (write)))
30595(allow virtualizationmanager tombstoned (unix_stream_socket (connectto)))
30596(allow virtualizationmanager tombstone_data_file (file (getattr append)))
30597(allow virtualizationmanager tombstoned (fd (use)))
30598(allow virtualizationmanager proc_dt_avf (dir (ioctl read getattr lock open watch watch_reads search)))
30599(allow virtualizationmanager proc_dt_avf (file (ioctl read getattr lock map open watch watch_reads)))
30600(allow virtualizationmanager proc_dt_avf (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30601(allow virtualizationmanager sysfs_dt_avf (dir (ioctl read getattr lock open watch watch_reads search)))
30602(allow virtualizationmanager sysfs_dt_avf (file (ioctl read getattr lock map open watch watch_reads)))
30603(allow virtualizationmanager sysfs_dt_avf (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30604(allow virtualizationmanager vendor_microdroid_file (dir (ioctl read getattr lock open watch watch_reads search)))
30605(allow virtualizationmanager vendor_microdroid_file (file (ioctl read getattr lock map open watch watch_reads)))
30606(allow virtualizationmanager vendor_microdroid_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30607;;* lmx 105 system/sepolicy/private/virtualizationmanager.te
30608
30609(neverallow domain vendor_microdroid_file (dir (write create setattr relabelfrom link rename add_name remove_name reparent rmdir)))
30610;;* lme
30611
30612;;* lmx 106 system/sepolicy/private/virtualizationmanager.te
30613
30614(neverallow domain vendor_microdroid_file (file (write create setattr relabelfrom append unlink link rename)))
30615;;* lme
30616
30617(allow virtualizationmanager crosvm (dir (ioctl read getattr lock open watch watch_reads search)))
30618(allow virtualizationmanager crosvm (file (ioctl read getattr lock map open watch watch_reads)))
30619(allow virtualizationmanager crosvm (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30620(dontaudit virtualizationmanager apex_module_data_file (dir (search)))
30621(allow init virtualizationservice_exec (file (read getattr map execute open)))
30622(allow init virtualizationservice (process (transition)))
30623(allow virtualizationservice virtualizationservice_exec (file (read getattr map execute open entrypoint)))
30624(dontaudit init virtualizationservice (process (noatsecure)))
30625(allow init virtualizationservice (process (siginh rlimitinh)))
30626(typetransition init virtualizationservice_exec process virtualizationservice)
30627(allow virtualizationservice servicemanager (binder (call transfer)))
30628(allow servicemanager virtualizationservice (binder (call transfer)))
30629(allow servicemanager virtualizationservice (dir (search)))
30630(allow servicemanager virtualizationservice (file (read open)))
30631(allow servicemanager virtualizationservice (process (getattr)))
30632(allow virtualizationservice virtualization_service (service_manager (add find)))
30633;;* lmx 16 system/sepolicy/private/virtualizationservice.te
30634
30635(neverallow base_typeattr_1001 virtualization_service (service_manager (add)))
30636;;* lme
30637
30638(allow virtualizationservice system_server (binder (call transfer)))
30639(allow system_server virtualizationservice (binder (transfer)))
30640(allow virtualizationservice system_server (fd (use)))
30641(allow virtualizationservice permission_service (service_manager (find)))
30642(allow virtualizationservice remote_provisioning_service (binder (call transfer)))
30643(allow remote_provisioning_service virtualizationservice (binder (transfer)))
30644(allow virtualizationservice remote_provisioning_service (fd (use)))
30645(allow virtualizationservice remote_provisioning_service (service_manager (find)))
30646(allow virtualizationservice self (capability (sys_resource)))
30647(allow virtualizationservice virtualizationmanager (process (setrlimit)))
30648(allow virtualizationservice self (capability (chown)))
30649(allow virtualizationservice virtualizationservice_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
30650(allow virtualizationservice virtualizationservice_data_file (sock_file (unlink)))
30651(allow virtualizationservice virtualizationservice_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30652(allow virtualizationservice adbd (fd (use)))
30653(allow virtualizationservice adbd (unix_stream_socket (read write)))
30654(allow virtualizationservice virtualizationmanager_exec (file (read getattr map execute open)))
30655(allow virtualizationservice virtualizationmanager (process (transition)))
30656(allow virtualizationmanager virtualizationmanager_exec (file (read getattr map execute open entrypoint)))
30657(allow virtualizationmanager virtualizationservice (process (sigchld)))
30658(dontaudit virtualizationservice virtualizationmanager (process (noatsecure)))
30659(allow virtualizationservice virtualizationmanager (process (siginh rlimitinh)))
30660(typetransition virtualizationservice virtualizationmanager_exec process virtualizationmanager)
30661(allow crosvm virtualizationservice (unix_stream_socket (ioctl read write getattr)))
30662(allow virtualizationmanager virtualizationservice (unix_stream_socket (ioctl read write getattr)))
30663(allow crosvm virtualizationservice (fd (use)))
30664(allow virtualizationmanager virtualizationservice (fd (use)))
30665(allow virtualizationservice virtualizationmanager (fd (use)))
30666(allow crosvm virtualizationservice (fifo_file (ioctl read write getattr)))
30667(allow virtualizationmanager virtualizationservice (fifo_file (ioctl read write getattr)))
30668(allow virtualizationservice virtualizationmanager (vsock_socket (read write getattr getopt)))
30669(allow virtualizationservice hypervisor_prop (file (read getattr map open)))
30670(allow virtualizationservice virtualizationservice_data_file (file (read getattr)))
30671(allow virtualizationservice apex_module_data_file (dir (getattr search)))
30672(allow virtualizationservice apex_virt_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
30673(allow virtualizationservice apex_virt_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
30674(allow virtualizationservice self (vsock_socket (read write create getattr setattr lock append map bind connect listen accept getopt setopt shutdown)))
30675(allow virtualizationservice property_socket (sock_file (write)))
30676(allow virtualizationservice init (unix_stream_socket (connectto)))
30677(allow virtualizationservice virtualizationservice_prop (property_service (set)))
30678(allow virtualizationservice virtualizationservice_prop (file (read getattr map open)))
30679(allow virtualizationservice statsdw_socket (sock_file (write)))
30680(allow virtualizationservice statsd (unix_dgram_socket (sendto)))
30681(allow virtualizationservice tombstoned_crash_socket (sock_file (write)))
30682(allow virtualizationservice tombstoned (unix_stream_socket (connectto)))
30683(allow virtualizationservice tombstone_data_file (file (getattr append)))
30684(allow virtualizationservice tombstoned (fd (use)))
30685(allow virtualizationservice vfio_device (chr_file (getattr)))
30686(allow virtualizationservice vfio_device (dir (ioctl read getattr lock open watch watch_reads search)))
30687(allow virtualizationservice virtualizationmanager (fd (use)))
30688(allow virtualizationservice vendor_configs_file (dir (ioctl read getattr lock open watch watch_reads search)))
30689(allow virtualizationservice vendor_configs_file (file (ioctl read getattr lock map open watch watch_reads)))
30690(allow virtualizationservice vendor_configs_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30691;;* lmx 102 system/sepolicy/private/virtualizationservice.te
30692
30693(neverallow base_typeattr_1002 virtualizationservice_prop (property_service (set)))
30694;;* lme
30695
30696;;* lmx 109 system/sepolicy/private/virtualizationservice.te
30697
30698(neverallow base_typeattr_1003 virtualizationservice_data_file (file (create open)))
30699;;* lme
30700
30701;;* lmx 115 system/sepolicy/private/virtualizationservice.te
30702
30703(neverallow virtualizationservice base_typeattr_1004 (process (setrlimit)))
30704;;* lme
30705
30706(allow init vold_exec (file (read getattr map execute open)))
30707(allow init vold (process (transition)))
30708(allow vold vold_exec (file (read getattr map execute open entrypoint)))
30709(dontaudit init vold (process (noatsecure)))
30710(allow init vold (process (siginh rlimitinh)))
30711(typetransition init vold_exec process vold)
30712(allow vold sgdisk_exec (file (read getattr map execute open)))
30713(allow vold sgdisk (process (transition)))
30714(allow sgdisk sgdisk_exec (file (read getattr map execute open entrypoint)))
30715(allow sgdisk vold (process (sigchld)))
30716(dontaudit vold sgdisk (process (noatsecure)))
30717(allow vold sgdisk (process (siginh rlimitinh)))
30718(typetransition vold sgdisk_exec process sgdisk)
30719(allow vold sdcardd_exec (file (read getattr map execute open)))
30720(allow vold sdcardd (process (transition)))
30721(allow sdcardd sdcardd_exec (file (read getattr map execute open entrypoint)))
30722(allow sdcardd vold (process (sigchld)))
30723(dontaudit vold sdcardd (process (noatsecure)))
30724(allow vold sdcardd (process (siginh rlimitinh)))
30725(typetransition vold sdcardd_exec process sdcardd)
30726(allow vold fuseblkd_untrusted_exec (file (read getattr map execute open)))
30727(allow vold fuseblkd_untrusted (process (transition)))
30728(allow fuseblkd_untrusted fuseblkd_untrusted_exec (file (read getattr map execute open entrypoint)))
30729(allow fuseblkd_untrusted vold (process (sigchld)))
30730(dontaudit vold fuseblkd_untrusted (process (noatsecure)))
30731(allow vold fuseblkd_untrusted (process (siginh rlimitinh)))
30732(typetransition vold fuseblkd_untrusted_exec process fuseblkd_untrusted)
30733(allow vold e2fs_exec (file (read getattr map execute open)))
30734(allow vold e2fs (process (transition)))
30735(allow e2fs e2fs_exec (file (read getattr map execute open entrypoint)))
30736(allow e2fs vold (process (sigchld)))
30737(dontaudit vold e2fs (process (noatsecure)))
30738(allow vold e2fs (process (siginh rlimitinh)))
30739(typetransition vold e2fs_exec process e2fs)
30740(allow vold blkid_exec (file (read getattr map execute open)))
30741(allow vold blkid (process (transition)))
30742(allow blkid blkid_exec (file (read getattr map execute open entrypoint)))
30743(allow blkid vold (process (sigchld)))
30744(dontaudit vold blkid (process (noatsecure)))
30745(allow vold blkid (process (siginh rlimitinh)))
30746(allow vold blkid_exec (file (read getattr map execute open)))
30747(allow vold blkid_untrusted (process (transition)))
30748(allow blkid_untrusted blkid_exec (file (read getattr map execute open entrypoint)))
30749(allow blkid_untrusted vold (process (sigchld)))
30750(dontaudit vold blkid_untrusted (process (noatsecure)))
30751(allow vold blkid_untrusted (process (siginh rlimitinh)))
30752(allow vold fsck_exec (file (read getattr map execute open)))
30753(allow vold fsck (process (transition)))
30754(allow fsck fsck_exec (file (read getattr map execute open entrypoint)))
30755(allow fsck vold (process (sigchld)))
30756(dontaudit vold fsck (process (noatsecure)))
30757(allow vold fsck (process (siginh rlimitinh)))
30758(allow vold fsck_exec (file (read getattr map execute open)))
30759(allow vold fsck_untrusted (process (transition)))
30760(allow fsck_untrusted fsck_exec (file (read getattr map execute open entrypoint)))
30761(allow fsck_untrusted vold (process (sigchld)))
30762(dontaudit vold fsck_untrusted (process (noatsecure)))
30763(allow vold fsck_untrusted (process (siginh rlimitinh)))
30764(typetransition vold storage_file dir storage_stub_file)
30765(typetransition vold mnt_media_rw_file dir mnt_media_rw_stub_file)
30766(allow vold vold_config_prop (file (read getattr map open)))
30767(allow vold storage_config_prop (file (read getattr map open)))
30768(allow vold incremental_prop (file (read getattr map open)))
30769(allow vold gsid_prop (file (read getattr map open)))
30770(allow vold property_socket (sock_file (write)))
30771(allow vold init (unix_stream_socket (connectto)))
30772(allow vold vold_prop (property_service (set)))
30773(allow vold vold_prop (file (read getattr map open)))
30774(allow vold property_socket (sock_file (write)))
30775(allow vold init (unix_stream_socket (connectto)))
30776(allow vold vold_status_prop (property_service (set)))
30777(allow vold vold_status_prop (file (read getattr map open)))
30778(allow vold property_socket (sock_file (write)))
30779(allow vold init (unix_stream_socket (connectto)))
30780(allow vold powerctl_prop (property_service (set)))
30781(allow vold powerctl_prop (file (read getattr map open)))
30782(allow vold property_socket (sock_file (write)))
30783(allow vold init (unix_stream_socket (connectto)))
30784(allow vold ctl_fuse_prop (property_service (set)))
30785(allow vold ctl_fuse_prop (file (read getattr map open)))
30786(allow vold property_socket (sock_file (write)))
30787(allow vold init (unix_stream_socket (connectto)))
30788(allow vold restorecon_prop (property_service (set)))
30789(allow vold restorecon_prop (file (read getattr map open)))
30790(allow vold property_socket (sock_file (write)))
30791(allow vold init (unix_stream_socket (connectto)))
30792(allow vold ota_prop (property_service (set)))
30793(allow vold ota_prop (file (read getattr map open)))
30794(allow vold property_socket (sock_file (write)))
30795(allow vold init (unix_stream_socket (connectto)))
30796(allow vold boottime_prop (property_service (set)))
30797(allow vold boottime_prop (file (read getattr map open)))
30798(allow vold property_socket (sock_file (write)))
30799(allow vold init (unix_stream_socket (connectto)))
30800(allow vold boottime_public_prop (property_service (set)))
30801(allow vold boottime_public_prop (file (read getattr map open)))
30802(allow vold vold_key (keystore2_key (convert_storage_key_to_ephemeral delete get_info manage_blob rebind req_forced_op update use)))
30803(allow vold keystore (binder (call)))
30804(allow vold keystore_service (service_manager (find)))
30805(allow vold keystore_maintenance_service (service_manager (find)))
30806(allow vold keystore (keystore2 (early_boot_ended)))
30807(allow vold keystore (keystore2 (delete_all_keys)))
30808;;* lmx 73 system/sepolicy/private/vold.te
30809
30810(neverallow base_typeattr_1005 vold_service (service_manager (find)))
30811;;* lme
30812
30813(allow vold system_userdir_file (dir (write add_name remove_name)))
30814(allow vold vendor_userdir_file (dir (write add_name remove_name)))
30815(allow vold media_userdir_file (dir (write add_name remove_name)))
30816;;* lmx 101 system/sepolicy/private/vold.te
30817
30818(neverallow base_typeattr_339 system_userdir_file (dir (write add_name remove_name)))
30819(neverallow base_typeattr_339 vendor_userdir_file (dir (write add_name remove_name)))
30820(neverallow base_typeattr_339 media_userdir_file (dir (write add_name remove_name)))
30821;;* lme
30822
30823(allow vold vold_prepare_subdirs_exec (file (read getattr map execute open)))
30824(allow vold vold_prepare_subdirs (process (transition)))
30825(allow vold_prepare_subdirs vold_prepare_subdirs_exec (file (read getattr map execute open entrypoint)))
30826(allow vold_prepare_subdirs vold (process (sigchld)))
30827(dontaudit vold vold_prepare_subdirs (process (noatsecure)))
30828(allow vold vold_prepare_subdirs (process (siginh rlimitinh)))
30829(typetransition vold vold_prepare_subdirs_exec process vold_prepare_subdirs)
30830(allow vold_prepare_subdirs system_file (file (execute_no_trans)))
30831(allow vold_prepare_subdirs shell_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30832(allow vold_prepare_subdirs toolbox_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
30833(allow vold_prepare_subdirs devpts (chr_file (ioctl read write getattr lock append map open watch watch_reads)))
30834(allow vold_prepare_subdirs vold (fd (use)))
30835(allow vold_prepare_subdirs vold (fifo_file (read write)))
30836(allow vold_prepare_subdirs file_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
30837(allow vold_prepare_subdirs self (capability (chown dac_override dac_read_search fowner)))
30838(allow vold_prepare_subdirs self (cap_userns (chown dac_override dac_read_search fowner)))
30839(allow vold_prepare_subdirs self (process (setfscreate)))
30840(allow vold_prepare_subdirs system_data_file (dir (read write relabelfrom open add_name remove_name rmdir)))
30841(allow vold_prepare_subdirs vendor_data_file (dir (read write relabelfrom open add_name remove_name rmdir)))
30842(allow vold_prepare_subdirs sdk_sandbox_system_data_file (dir (read write relabelfrom open add_name remove_name rmdir)))
30843(allow vold_prepare_subdirs apex_data_file_type (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30844(allow vold_prepare_subdirs system_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30845(allow vold_prepare_subdirs apex_module_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30846(allow vold_prepare_subdirs apex_rollback_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30847(allow vold_prepare_subdirs vold_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30848(allow vold_prepare_subdirs backup_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30849(allow vold_prepare_subdirs fingerprint_vendor_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30850(allow vold_prepare_subdirs face_vendor_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30851(allow vold_prepare_subdirs iris_vendor_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30852(allow vold_prepare_subdirs storaged_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30853(allow vold_prepare_subdirs sdk_sandbox_system_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30854(allow vold_prepare_subdirs sdk_sandbox_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30855(allow vold_prepare_subdirs rollback_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30856(allow vold_prepare_subdirs checkin_data_file (dir (ioctl read write create getattr setattr lock relabelto rename open watch watch_reads add_name remove_name reparent search rmdir)))
30857(allow vold_prepare_subdirs apex_data_file_type (file (getattr unlink)))
30858(allow vold_prepare_subdirs system_data_file (file (getattr unlink)))
30859(allow vold_prepare_subdirs apex_module_data_file (file (getattr unlink)))
30860(allow vold_prepare_subdirs apex_rollback_data_file (file (getattr unlink)))
30861(allow vold_prepare_subdirs vold_data_file (file (getattr unlink)))
30862(allow vold_prepare_subdirs backup_data_file (file (getattr unlink)))
30863(allow vold_prepare_subdirs fingerprint_vendor_data_file (file (getattr unlink)))
30864(allow vold_prepare_subdirs face_vendor_data_file (file (getattr unlink)))
30865(allow vold_prepare_subdirs iris_vendor_data_file (file (getattr unlink)))
30866(allow vold_prepare_subdirs storaged_data_file (file (getattr unlink)))
30867(allow vold_prepare_subdirs sdk_sandbox_data_file (file (getattr unlink)))
30868(allow vold_prepare_subdirs rollback_data_file (file (getattr unlink)))
30869(allow vold_prepare_subdirs checkin_data_file (file (getattr unlink)))
30870(allow vold_prepare_subdirs apex_art_staging_data_file (file (getattr unlink)))
30871(allow vold_prepare_subdirs apex_mnt_dir (dir (read open)))
30872(allow vold_prepare_subdirs mnt_expand_file (dir (search)))
30873(allow vold_prepare_subdirs user_profile_data_file (dir (getattr relabelfrom search)))
30874(allow vold_prepare_subdirs user_profile_root_file (dir (getattr relabelfrom relabelto search)))
30875(allow vold_prepare_subdirs apex_tethering_data_file (dir (relabelfrom)))
30876(allow vold_prepare_subdirs apex_appsearch_data_file (dir (relabelfrom)))
30877(allow vold_prepare_subdirs apex_permission_data_file (dir (relabelfrom)))
30878(allow vold_prepare_subdirs apex_scheduling_data_file (dir (relabelfrom)))
30879(allow vold_prepare_subdirs apex_wifi_data_file (dir (relabelfrom)))
30880(allow vold_prepare_subdirs unlabeled (dir (search)))
30881(dontaudit vold_prepare_subdirs proc (file (ioctl read getattr lock map open watch watch_reads)))
30882(dontaudit vold_prepare_subdirs unlabeled (file (ioctl read getattr lock map open watch watch_reads)))
30883(typetransition vzwomatrigger_app tmpfs file appdomain_tmpfs)
30884(allow vzwomatrigger_app vzwomatrigger_app_userfaultfd (anon_inode (ioctl read create)))
30885(dontaudit su vzwomatrigger_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30886;;* lmx 6 system/sepolicy/private/vzwomatrigger_app.te
30887
30888(neverallow base_typeattr_1006 vzwomatrigger_app_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30889;;* lme
30890
30891(allow vzwomatrigger_app appdomain_tmpfs (file (read write getattr map execute)))
30892;;* lmx 6 system/sepolicy/private/vzwomatrigger_app.te
30893
30894(neverallow base_typeattr_1007 base_typeattr_1006 (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30895;;* lme
30896
30897;;* lmx 6 system/sepolicy/private/vzwomatrigger_app.te
30898
30899(neverallow base_typeattr_1008 vzwomatrigger_app (file (ioctl read write create setattr lock relabelfrom append unlink link rename open watch watch_mount watch_sb watch_with_perm watch_reads)))
30900;;* lme
30901
30902;;* lmx 6 system/sepolicy/private/vzwomatrigger_app.te
30903
30904(neverallow base_typeattr_1009 vzwomatrigger_app (process (ptrace)))
30905;;* lme
30906
30907(allow init watchdogd_exec (file (read getattr map execute open)))
30908(allow init watchdogd (process (transition)))
30909(allow watchdogd watchdogd_exec (file (read getattr map execute open entrypoint)))
30910(dontaudit init watchdogd (process (noatsecure)))
30911(allow init watchdogd (process (siginh rlimitinh)))
30912(typetransition init watchdogd_exec process watchdogd)
30913(typetransition webview_zygote tmpfs file webview_zygote_tmpfs)
30914(allow webview_zygote webview_zygote_tmpfs (file (read write getattr map)))
30915(allow webview_zygote webview_zygote_userfaultfd (anon_inode (ioctl read create)))
30916(dontaudit su webview_zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30917;;* lmx 13 system/sepolicy/private/webview_zygote.te
30918
30919(neverallow base_typeattr_1010 webview_zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
30920;;* lme
30921
30922(allow webview_zygote apk_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
30923(allow webview_zygote apk_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30924(allow webview_zygote shared_relro_file (dir (search)))
30925(allow webview_zygote shared_relro_file (file (ioctl read getattr lock map open watch watch_reads)))
30926(allow webview_zygote self (capability (setgid setuid)))
30927(allow webview_zygote self (cap_userns (setgid setuid)))
30928(allow webview_zygote self (capability (setpcap)))
30929(allow webview_zygote self (cap_userns (setpcap)))
30930(allow webview_zygote self (process (setcurrent)))
30931(allow webview_zygote isolated_app (process (dyntransition)))
30932(allow webview_zygote dalvikcache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
30933(allow webview_zygote apex_art_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
30934(allow webview_zygote dalvikcache_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30935(allow webview_zygote dalvikcache_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30936(allow webview_zygote apex_art_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
30937(allow webview_zygote apex_module_data_file (dir (search)))
30938(allow webview_zygote vendor_apex_metadata_file (dir (search)))
30939(allow webview_zygote self (process (execmem)))
30940(allow webview_zygote debugfs_trace_marker (file (getattr)))
30941(allow webview_zygote system_server (process (getpgid)))
30942(allow webview_zygote isolated_app (process (setpgid)))
30943(dontaudit webview_zygote mnt_expand_file (dir (getattr)))
30944(dontaudit webview_zygote dex2oat_exec (file (execute)))
30945(allow webview_zygote seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
30946(allow webview_zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
30947(allow webview_zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
30948(allow webview_zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30949(allow webview_zygote selinuxfs (file (write lock append map open)))
30950(allow webview_zygote kernel (security (check_context)))
30951(allow webview_zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
30952(allow webview_zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
30953(allow webview_zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30954(allow webview_zygote selinuxfs (file (write lock append map open)))
30955(allow webview_zygote kernel (security (compute_av)))
30956(allow webview_zygote self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
30957(allow webview_zygote system_file (dir (ioctl read getattr lock open watch watch_reads search)))
30958(allow webview_zygote zygote_tmpfs (file (read getattr)))
30959(allow webview_zygote zygote (fd (use)))
30960(allow webview_zygote zygote (process (sigchld)))
30961(allow webview_zygote vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
30962(allow webview_zygote vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
30963(allow webview_zygote vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30964(allow webview_zygote same_process_hal_file (file (read getattr map execute open)))
30965(allow webview_zygote system_data_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
30966(allow webview_zygote system_unsolzygote_socket (sock_file (write)))
30967(allow webview_zygote system_server (unix_dgram_socket (sendto)))
30968(allow webview_zygote device_config_runtime_native_prop (file (read getattr map open)))
30969(allow webview_zygote device_config_runtime_native_boot_prop (file (read getattr map open)))
30970(allow zygote odsign_prop (file (read getattr map open)))
30971(allow webview_zygote resourcecache_data_file (file (ioctl read getattr lock map open watch watch_reads)))
30972(allow webview_zygote resourcecache_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
30973;;* lmx 105 system/sepolicy/private/webview_zygote.te
30974
30975(neverallow webview_zygote base_typeattr_643 (process (dyntransition)))
30976;;* lme
30977
30978;;* lmx 108 system/sepolicy/private/webview_zygote.te
30979
30980(neverallow webview_zygote base_typeattr_644 (process (transition)))
30981;;* lme
30982
30983;;* lmx 112 system/sepolicy/private/webview_zygote.te
30984
30985(neverallow webview_zygote base_typeattr_224 (file (execute_no_trans)))
30986;;* lme
30987
30988;;* lmx 116 system/sepolicy/private/webview_zygote.te
30989
30990(neverallow base_typeattr_645 webview_zygote (process (dyntransition)))
30991;;* lme
30992
30993;;* lmx 119 system/sepolicy/private/webview_zygote.te
30994
30995(neverallow webview_zygote property_socket (sock_file (write)))
30996;;* lme
30997
30998;;* lmx 120 system/sepolicy/private/webview_zygote.te
30999
31000(neverallow webview_zygote property_type (property_service (set)))
31001;;* lme
31002
31003;;* lmx 123 system/sepolicy/private/webview_zygote.te
31004
31005(neverallow webview_zygote app_data_file_type (file (ioctl read write getattr lock append map execute open watch watch_reads execute_no_trans)))
31006;;* lme
31007
31008;;* lmx 129 system/sepolicy/private/webview_zygote.te
31009
31010(neverallow webview_zygote base_typeattr_646 (service_manager (find)))
31011;;* lme
31012
31013;;* lmx 132 system/sepolicy/private/webview_zygote.te
31014
31015(neverallow webview_zygote gpu_device (chr_file (ioctl read write getattr lock append map execute open watch watch_reads execute_no_trans)))
31016;;* lme
31017
31018;;* lmx 135 system/sepolicy/private/webview_zygote.te
31019
31020(neverallow webview_zygote cache_file (dir (write create setattr relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access execmod watch_mount watch_sb watch_with_perm add_name remove_name reparent rmdir)))
31021;;* lme
31022
31023;;* lmx 136 system/sepolicy/private/webview_zygote.te
31024
31025(neverallow webview_zygote cache_file (file (ioctl write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads execute_no_trans entrypoint)))
31026;;* lme
31027
31028;;* lmx 153 system/sepolicy/private/webview_zygote.te
31029
31030(neverallow webview_zygote domain (socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31031(neverallow webview_zygote domain (tcp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect)))
31032(neverallow webview_zygote domain (udp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
31033(neverallow webview_zygote domain (rawip_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
31034(neverallow webview_zygote domain (netlink_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31035(neverallow webview_zygote domain (packet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31036(neverallow webview_zygote domain (key_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31037(neverallow webview_zygote domain (netlink_route_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_readpriv nlmsg_getneigh)))
31038(neverallow webview_zygote domain (netlink_tcpdiag_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
31039(neverallow webview_zygote domain (netlink_nflog_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31040(neverallow webview_zygote domain (netlink_xfrm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write)))
31041(neverallow webview_zygote domain (netlink_audit_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind nlmsg_read nlmsg_write nlmsg_relay nlmsg_readpriv nlmsg_tty_audit)))
31042(neverallow webview_zygote domain (netlink_dnrt_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31043(neverallow webview_zygote domain (netlink_kobject_uevent_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31044(neverallow webview_zygote domain (appletalk_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31045(neverallow webview_zygote domain (tun_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind attach_queue)))
31046(neverallow webview_zygote domain (netlink_iscsi_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31047(neverallow webview_zygote domain (netlink_fib_lookup_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31048(neverallow webview_zygote domain (netlink_connector_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31049(neverallow webview_zygote domain (netlink_netfilter_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31050(neverallow webview_zygote domain (netlink_generic_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31051(neverallow webview_zygote domain (netlink_scsitransport_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31052(neverallow webview_zygote domain (netlink_rdma_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31053(neverallow webview_zygote domain (netlink_crypto_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31054(neverallow webview_zygote domain (sctp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind name_connect association)))
31055(neverallow webview_zygote domain (icmp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind node_bind)))
31056(neverallow webview_zygote domain (ax25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31057(neverallow webview_zygote domain (ipx_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31058(neverallow webview_zygote domain (netrom_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31059(neverallow webview_zygote domain (atmpvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31060(neverallow webview_zygote domain (x25_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31061(neverallow webview_zygote domain (rose_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31062(neverallow webview_zygote domain (decnet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31063(neverallow webview_zygote domain (atmsvc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31064(neverallow webview_zygote domain (rds_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31065(neverallow webview_zygote domain (irda_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31066(neverallow webview_zygote domain (pppox_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31067(neverallow webview_zygote domain (llc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31068(neverallow webview_zygote domain (can_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31069(neverallow webview_zygote domain (tipc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31070(neverallow webview_zygote domain (bluetooth_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31071(neverallow webview_zygote domain (iucv_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31072(neverallow webview_zygote domain (rxrpc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31073(neverallow webview_zygote domain (isdn_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31074(neverallow webview_zygote domain (phonet_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31075(neverallow webview_zygote domain (ieee802154_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31076(neverallow webview_zygote domain (caif_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31077(neverallow webview_zygote domain (alg_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31078(neverallow webview_zygote domain (nfc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31079(neverallow webview_zygote domain (vsock_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31080(neverallow webview_zygote domain (kcm_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31081(neverallow webview_zygote domain (qipcrtr_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31082(neverallow webview_zygote domain (smc_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31083(neverallow webview_zygote domain (xdp_socket (ioctl read write create getattr setattr lock relabelfrom relabelto append map bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31084;;* lme
31085
31086;;* lmx 162 system/sepolicy/private/webview_zygote.te
31087
31088(neverallow webview_zygote bluetooth_a2dp_offload_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31089(neverallow webview_zygote bluetooth_audio_hal_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31090(neverallow webview_zygote bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31091(neverallow webview_zygote exported_bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31092;;* lme
31093
31094(allow wificond property_socket (sock_file (write)))
31095(allow wificond init (unix_stream_socket (connectto)))
31096(allow wificond wifi_hal_prop (property_service (set)))
31097(allow wificond wifi_hal_prop (file (read getattr map open)))
31098(allow wificond property_socket (sock_file (write)))
31099(allow wificond init (unix_stream_socket (connectto)))
31100(allow wificond wifi_prop (property_service (set)))
31101(allow wificond wifi_prop (file (read getattr map open)))
31102(allow wificond property_socket (sock_file (write)))
31103(allow wificond init (unix_stream_socket (connectto)))
31104(allow wificond ctl_default_prop (property_service (set)))
31105(allow wificond ctl_default_prop (file (read getattr map open)))
31106(allow wificond hwservicemanager_prop (file (read getattr map open)))
31107(allow wificond legacykeystore_service (service_manager (find)))
31108(allow init wificond_exec (file (read getattr map execute open)))
31109(allow init wificond (process (transition)))
31110(allow wificond wificond_exec (file (read getattr map execute open entrypoint)))
31111(dontaudit init wificond (process (noatsecure)))
31112(allow init wificond (process (siginh rlimitinh)))
31113(typetransition init wificond_exec process wificond)
31114(allow init zygote_exec (file (read getattr map execute open)))
31115(allow init zygote (process (transition)))
31116(allow zygote zygote_exec (file (read getattr map execute open entrypoint)))
31117(dontaudit init zygote (process (noatsecure)))
31118(allow init zygote (process (siginh rlimitinh)))
31119(typetransition init zygote_exec process zygote)
31120(typetransition zygote tmpfs file zygote_tmpfs)
31121(allow zygote zygote_tmpfs (file (read write getattr map)))
31122(allow zygote runtime_event_log_tags_file (file (ioctl read getattr lock map open watch watch_reads)))
31123(allow zygote self (capability (chown dac_override dac_read_search fowner setgid setuid)))
31124(allow zygote self (cap_userns (chown dac_override dac_read_search fowner setgid setuid)))
31125(allow zygote self (capability (setpcap)))
31126(allow zygote self (cap_userns (setpcap)))
31127(allow zygote self (process (setcurrent)))
31128(allow zygote system_server_startup (process (dyntransition)))
31129(allow zygote appdomain (process (dyntransition)))
31130(allow zygote webview_zygote (process (dyntransition)))
31131(allow zygote app_zygote (process (dyntransition)))
31132(allow zygote appdomain (dir (getattr search)))
31133(allow zygote appdomain (file (ioctl read getattr lock map open watch watch_reads)))
31134(allow zygote zygote_userfaultfd (anon_inode (ioctl read create)))
31135(dontaudit su zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
31136;;* lmx 27 system/sepolicy/private/zygote.te
31137
31138(neverallow base_typeattr_645 zygote_userfaultfd (anon_inode (ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads)))
31139;;* lme
31140
31141(allow zygote system_server (process (getpgid setpgid)))
31142(allow zygote appdomain (process (getpgid setpgid)))
31143(allow zygote webview_zygote (process (getpgid setpgid)))
31144(allow zygote app_zygote (process (getpgid setpgid)))
31145(allow zygote system_data_file (dir (ioctl read getattr lock open watch watch_reads search)))
31146(allow zygote system_data_file (file (ioctl read getattr lock map open watch watch_reads)))
31147(allow zygote mnt_expand_file (dir (getattr)))
31148(allow zygote dalvikcache_data_file (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
31149(allow zygote dalvikcache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31150(allow zygote dalvikcache_data_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31151(allow zygote resourcecache_data_file (dir (ioctl read write getattr lock open watch watch_reads add_name remove_name search)))
31152(allow zygote resourcecache_data_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31153(allow zygote dalvikcache_data_file (file (execute)))
31154(allow zygote apex_module_data_file (dir (search)))
31155(allow zygote apex_art_data_file (dir (getattr search)))
31156(allow zygote apex_art_data_file (file (ioctl read getattr lock map execute open watch watch_reads)))
31157(allow zygote properties_device (dir (mounton search)))
31158(allow zygote system_data_file (dir (mounton search)))
31159(allow zygote system_userdir_file (dir (mounton search)))
31160(allow zygote user_profile_root_file (dir (mounton search)))
31161(allow zygote user_profile_data_file (dir (mounton search)))
31162(allow zygote media_rw_data_file (dir (mounton search)))
31163(allow zygote mirror_data_file (dir (search)))
31164(allow zygote mnt_expand_file (dir (read open search)))
31165(allow zygote app_data_file_type (dir (getattr)))
31166(allow zygote tmpfs (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
31167(allow zygote tmpfs (lnk_file (create)))
31168(allow zygote tmpfs (dir (relabelfrom)))
31169(allow zygote tmpfs (lnk_file (relabelfrom)))
31170(allow zygote system_userdir_file (dir (relabelto)))
31171(allow zygote system_data_file (dir (relabelto)))
31172(allow zygote system_data_file (lnk_file (relabelto)))
31173(allow zygote sdk_sandbox_system_data_file (dir (getattr relabelto search)))
31174(allow zygote proc_filesystems (file (ioctl read getattr lock map open watch watch_reads)))
31175(allow zygote self (process (execmem)))
31176(allow zygote zygote_tmpfs (file (execute)))
31177(allow zygote ashmem_libcutils_device (chr_file (execute)))
31178(allow zygote idmap_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
31179(allow zygote dex2oat_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
31180(allow zygote vendor_overlay_file (dir (ioctl read getattr lock open watch watch_reads search)))
31181(allow zygote vendor_overlay_file (file (ioctl read getattr lock map open watch watch_reads)))
31182(allow zygote vendor_overlay_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31183(allow zygote cgroup (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
31184(allow zygote cgroup (file (ioctl read getattr setattr lock map open watch watch_reads)))
31185(allow zygote cgroup (lnk_file (ioctl read getattr setattr lock map open watch watch_reads)))
31186(allow zygote cgroup_v2 (dir (ioctl read write create getattr setattr lock rename open watch watch_reads add_name remove_name reparent search rmdir)))
31187(allow zygote cgroup_v2 (file (ioctl read getattr setattr lock map open watch watch_reads)))
31188(allow zygote cgroup_v2 (lnk_file (ioctl read getattr setattr lock map open watch watch_reads)))
31189(allow zygote self (capability (sys_admin)))
31190(allow zygote self (cap_userns (sys_admin)))
31191(allow zygote pmsg_device (chr_file (getattr)))
31192(allow zygote debugfs_trace_marker (file (getattr)))
31193(allow zygote seapp_contexts_file (file (ioctl read getattr lock map open watch watch_reads)))
31194(allow zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
31195(allow zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
31196(allow zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31197(allow zygote selinuxfs (file (write lock append map open)))
31198(allow zygote kernel (security (check_context)))
31199(allow zygote selinuxfs (dir (ioctl read getattr lock open watch watch_reads search)))
31200(allow zygote selinuxfs (file (ioctl read getattr lock map open watch watch_reads)))
31201(allow zygote selinuxfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31202(allow zygote selinuxfs (file (write lock append map open)))
31203(allow zygote kernel (security (compute_av)))
31204(allow zygote self (netlink_selinux_socket (read write create getattr setattr lock relabelfrom relabelto append bind connect listen accept getopt setopt shutdown recvfrom sendto name_bind)))
31205(allow zygote proc_cpuinfo (file (mounton)))
31206(allow zygote rootfs (dir (mounton)))
31207(allow zygote tmpfs (filesystem (mount unmount)))
31208(allow zygote fuse (filesystem (unmount)))
31209(allow zygote sdcardfs (filesystem (unmount)))
31210(allow zygote labeledfs (filesystem (unmount)))
31211(allow zygote mnt_user_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
31212(allow zygote mnt_user_file (lnk_file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31213(allow zygote mnt_user_file (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31214(allow zygote mnt_pass_through_file (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
31215(allow zygote storage_file (dir (mounton search)))
31216(allow zygote sdcard_type (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
31217(allow zygote fuse (dir (ioctl read write create getattr setattr lock rename mounton open watch watch_reads add_name remove_name reparent search rmdir)))
31218(allow zygote sdcard_type (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31219(allow zygote fuse (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31220(allow zygote zygote_exec (file (ioctl read getattr lock map execute open watch watch_reads execute_no_trans)))
31221(allow zygote statsdw_socket (sock_file (write)))
31222(allow zygote statsd (unix_dgram_socket (sendto)))
31223(allow zygote rootfs (dir (ioctl read getattr lock open watch watch_reads search)))
31224(allow zygote rootfs (file (ioctl read getattr lock map open watch watch_reads)))
31225(allow zygote rootfs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31226(allow zygote system_file (dir (ioctl read getattr lock open watch watch_reads search)))
31227(allow zygote system_file (file (ioctl read getattr lock map open watch watch_reads)))
31228(allow zygote system_file (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31229(allow zygote oemfs (dir (search)))
31230(allow zygote ion_device (chr_file (ioctl read getattr lock map open watch watch_reads)))
31231(allow zygote tmpfs (dir (ioctl read getattr lock open watch watch_reads search)))
31232(allow zygote same_process_hal_file (file (read getattr map execute open)))
31233(allow zygote build_attestation_prop (file (read getattr map open)))
31234(allow zygote storage_config_prop (file (read getattr map open)))
31235(allow zygote overlay_prop (file (read getattr map open)))
31236(allow zygote exported_overlay_prop (file (read getattr map open)))
31237(allow zygote device_config_runtime_native_prop (file (read getattr map open)))
31238(allow zygote device_config_runtime_native_boot_prop (file (read getattr map open)))
31239(allow zygote device_config_window_manager_native_boot_prop (file (read getattr map open)))
31240(dontaudit zygote self (capability (fsetid sys_resource)))
31241(dontaudit zygote self (cap_userns (fsetid sys_resource)))
31242(dontaudit zygote media_rw_data_file (dir (read setattr open)))
31243(allow zygote system_server (fd (use)))
31244(allow zygote system_unsolzygote_socket (sock_file (write)))
31245(allow zygote system_server (unix_dgram_socket (sendto)))
31246(allow zygote media_variant_prop (file (read getattr map open)))
31247(allow zygote odsign_prop (file (read getattr map open)))
31248(allow zygote packagemanager_config_prop (file (read getattr map open)))
31249(allow zygote qemu_sf_lcd_density_prop (file (read getattr map open)))
31250(allow zygote persist_wm_debug_prop (file (read getattr map open)))
31251(allow zygote persist_sysui_builder_extras_prop (file (read getattr map open)))
31252(allow zygote persist_sysui_ranking_update_prop (file (read getattr map open)))
31253(allow zygote apex_info_file (file (ioctl read getattr lock map open watch watch_reads)))
31254(allow zygote vendor_apex_file (dir (getattr search)))
31255(allow zygote vendor_apex_file (file (getattr)))
31256(allow zygote vendor_apex_metadata_file (dir (search)))
31257(allow zygote sysfs_fs_f2fs (dir (ioctl read getattr lock open watch watch_reads search)))
31258(allow zygote sysfs_fs_f2fs (file (ioctl read getattr lock map open watch watch_reads)))
31259(allow zygote sysfs_fs_f2fs (lnk_file (ioctl read getattr lock map open watch watch_reads)))
31260(allow zygote system_font_fallback_file (file (ioctl read getattr lock map open watch watch_reads)))
31261;;* lmx 289 system/sepolicy/private/zygote.te
31262
31263(neverallow zygote base_typeattr_1011 (process (dyntransition)))
31264;;* lme
31265
31266;;* lmx 298 system/sepolicy/private/zygote.te
31267
31268(neverallow zygote base_typeattr_1012 (file (execute execute_no_trans)))
31269;;* lme
31270
31271;;* lmx 306 system/sepolicy/private/zygote.te
31272
31273(neverallow zygote bluetooth_a2dp_offload_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31274(neverallow zygote bluetooth_audio_hal_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31275(neverallow zygote bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31276(neverallow zygote exported_bluetooth_prop (file (ioctl read write create getattr setattr lock append map unlink rename open watch watch_reads)))
31277;;* lme
31278
31279;;* lmx 309 system/sepolicy/private/zygote.te
31280
31281(neverallow zygote app_data_file_type (dir (ioctl read write create setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton audit_access open execmod watch watch_mount watch_sb watch_with_perm watch_reads add_name remove_name reparent search rmdir)))
31282;;* lme
31283
31284(typetransition zygote zygote anon_inode "[userfaultfd]" zygote_userfaultfd)
31285(typetransition webview_zygote webview_zygote anon_inode "[userfaultfd]" webview_zygote_userfaultfd)
31286(typetransition vzwomatrigger_app vzwomatrigger_app anon_inode "[userfaultfd]" vzwomatrigger_app_userfaultfd)
31287(typetransition untrusted_app_32 untrusted_app_32 anon_inode "[userfaultfd]" untrusted_app_32_userfaultfd)
31288(typetransition untrusted_app_30 untrusted_app_30 anon_inode "[userfaultfd]" untrusted_app_30_userfaultfd)
31289(typetransition untrusted_app_29 untrusted_app_29 anon_inode "[userfaultfd]" untrusted_app_29_userfaultfd)
31290(typetransition untrusted_app_27 untrusted_app_27 anon_inode "[userfaultfd]" untrusted_app_27_userfaultfd)
31291(typetransition untrusted_app_25 untrusted_app_25 anon_inode "[userfaultfd]" untrusted_app_25_userfaultfd)
31292(typetransition untrusted_app untrusted_app anon_inode "[userfaultfd]" untrusted_app_userfaultfd)
31293(typetransition traceur_app traceur_app anon_inode "[userfaultfd]" traceur_app_userfaultfd)
31294(typetransition system_server system_data_file sock_file "unsolzygotesocket" system_unsolzygote_socket)
31295(typetransition system_server system_data_file sock_file "ndebugsocket" system_ndebug_socket)
31296(typetransition system_server system_server anon_inode "[userfaultfd]" system_server_userfaultfd)
31297(typetransition system_app system_app anon_inode "[userfaultfd]" system_app_userfaultfd)
31298(typetransition snapuserd snapuserd anon_inode "[io_uring]" snapuserd_iouring)
31299(typetransition simpleperf simpleperf anon_inode "[userfaultfd]" simpleperf_userfaultfd)
31300(typetransition shell shell anon_inode "[userfaultfd]" shell_userfaultfd)
31301(typetransition shared_relro shared_relro anon_inode "[userfaultfd]" shared_relro_userfaultfd)
31302(typetransition secure_element secure_element anon_inode "[userfaultfd]" secure_element_userfaultfd)
31303(typetransition sdk_sandbox_next sdk_sandbox_next anon_inode "[userfaultfd]" sdk_sandbox_next_userfaultfd)
31304(typetransition sdk_sandbox_audit sdk_sandbox_audit anon_inode "[userfaultfd]" sdk_sandbox_audit_userfaultfd)
31305(typetransition sdk_sandbox_34 sdk_sandbox_34 anon_inode "[userfaultfd]" sdk_sandbox_34_userfaultfd)
31306(typetransition runas_app runas_app anon_inode "[userfaultfd]" runas_app_userfaultfd)
31307(typetransition rkpdapp rkpdapp anon_inode "[userfaultfd]" rkpdapp_userfaultfd)
31308(typetransition radio radio anon_inode "[userfaultfd]" radio_userfaultfd)
31309(typetransition priv_app priv_app anon_inode "[userfaultfd]" priv_app_userfaultfd)
31310(typetransition platform_app platform_app anon_inode "[userfaultfd]" platform_app_userfaultfd)
31311(typetransition permissioncontroller_app permissioncontroller_app anon_inode "[userfaultfd]" permissioncontroller_app_userfaultfd)
31312(typetransition odrefresh odrefresh anon_inode "[userfaultfd]" odrefresh_userfaultfd)
31313(typetransition nfc nfc anon_inode "[userfaultfd]" nfc_userfaultfd)
31314(typetransition network_stack network_stack anon_inode "[userfaultfd]" network_stack_userfaultfd)
31315(typetransition mediaprovider_app mediaprovider_app anon_inode "[userfaultfd]" mediaprovider_app_userfaultfd)
31316(typetransition mediaprovider mediaprovider anon_inode "[userfaultfd]" mediaprovider_userfaultfd)
31317(typetransition isolated_compute_app isolated_compute_app anon_inode "[userfaultfd]" isolated_compute_app_userfaultfd)
31318(typetransition isolated_app isolated_app anon_inode "[userfaultfd]" isolated_app_userfaultfd)
31319(typetransition gmscore_app gmscore_app anon_inode "[userfaultfd]" gmscore_app_userfaultfd)
31320(typetransition fastbootd fastbootd anon_inode "[io_uring]" fastbootd_iouring)
31321(typetransition ephemeral_app ephemeral_app anon_inode "[userfaultfd]" ephemeral_app_userfaultfd)
31322(typetransition dexoptanalyzer dexoptanalyzer anon_inode "[userfaultfd]" dexoptanalyzer_userfaultfd)
31323(typetransition dexopt_chroot_setup dexopt_chroot_setup anon_inode "[userfaultfd]" dexopt_chroot_setup_userfaultfd)
31324(typetransition dex2oat dex2oat anon_inode "[userfaultfd]" dex2oat_userfaultfd)
31325(typetransition device_as_webcam device_as_webcam anon_inode "[userfaultfd]" device_as_webcam_userfaultfd)
31326(typetransition bluetooth bluetooth anon_inode "[userfaultfd]" bluetooth_userfaultfd)
31327(typetransition artd artd anon_inode "[userfaultfd]" artd_userfaultfd)
31328(typetransition app_zygote app_zygote anon_inode "[userfaultfd]" app_zygote_userfaultfd)
31329(typeattribute base_typeattr_1012)
31330(typeattributeset base_typeattr_1012 (and (data_file_type ) (not (dalvikcache_data_file apex_art_data_file ))))
31331(typeattribute base_typeattr_1011)
31332(typeattributeset base_typeattr_1011 (not (appdomain app_zygote webview_zygote system_server_startup ) ))
31333(typeattribute base_typeattr_1010)
31334(typeattributeset base_typeattr_1010 (and (domain ) (not (webview_zygote ))))
31335(typeattribute base_typeattr_1009)
31336(typeattributeset base_typeattr_1009 (and (domain ) (not (crash_dump runas_app simpleperf vzwomatrigger_app ))))
31337(typeattribute base_typeattr_1008)
31338(typeattributeset base_typeattr_1008 (and (appdomain ) (not (runas_app shell simpleperf vzwomatrigger_app ))))
31339(typeattribute base_typeattr_1007)
31340(typeattributeset base_typeattr_1007 (and (vzwomatrigger_app ) (not (runas_app shell simpleperf ))))
31341(typeattribute base_typeattr_1006)
31342(typeattributeset base_typeattr_1006 (and (domain ) (not (vzwomatrigger_app ))))
31343(typeattribute base_typeattr_1005)
31344(typeattributeset base_typeattr_1005 (and (domain ) (not (apexd system_server update_verifier vdc vold gsid ))))
31345(typeattribute base_typeattr_1004)
31346(typeattributeset base_typeattr_1004 (and (domain ) (not (virtualizationmanager virtualizationservice ))))
31347(typeattribute base_typeattr_1003)
31348(typeattributeset base_typeattr_1003 (and (domain ) (not (init virtualizationmanager virtualizationservice ))))
31349(typeattribute base_typeattr_1002)
31350(typeattributeset base_typeattr_1002 (and (domain ) (not (init virtualizationservice ))))
31351(typeattribute base_typeattr_1001)
31352(typeattributeset base_typeattr_1001 (and (domain ) (not (virtualizationservice ))))
31353(typeattribute base_typeattr_1000)
31354(typeattributeset base_typeattr_1000 (and (domain ) (not (virtual_camera ))))
31355(typeattribute base_typeattr_999)
31356(typeattributeset base_typeattr_999 (and (dev_type ) (not (vm_manager_device_type keychord_device hw_random_device port_device lowpan_device ))))
31357(typeattribute base_typeattr_998)
31358(typeattributeset base_typeattr_998 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app_32 ))))
31359(typeattribute base_typeattr_997)
31360(typeattributeset base_typeattr_997 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app_32 ))))
31361(typeattribute base_typeattr_996)
31362(typeattributeset base_typeattr_996 (and (untrusted_app_32 ) (not (runas_app shell simpleperf ))))
31363(typeattribute base_typeattr_995)
31364(typeattributeset base_typeattr_995 (and (domain ) (not (untrusted_app_32 ))))
31365(typeattribute base_typeattr_994)
31366(typeattributeset base_typeattr_994 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app_30 ))))
31367(typeattribute base_typeattr_993)
31368(typeattributeset base_typeattr_993 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app_30 ))))
31369(typeattribute base_typeattr_992)
31370(typeattributeset base_typeattr_992 (and (untrusted_app_30 ) (not (runas_app shell simpleperf ))))
31371(typeattribute base_typeattr_991)
31372(typeattributeset base_typeattr_991 (and (domain ) (not (untrusted_app_30 ))))
31373(typeattribute base_typeattr_990)
31374(typeattributeset base_typeattr_990 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app_29 ))))
31375(typeattribute base_typeattr_989)
31376(typeattributeset base_typeattr_989 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app_29 ))))
31377(typeattribute base_typeattr_988)
31378(typeattributeset base_typeattr_988 (and (untrusted_app_29 ) (not (runas_app shell simpleperf ))))
31379(typeattribute base_typeattr_987)
31380(typeattributeset base_typeattr_987 (and (domain ) (not (untrusted_app_29 ))))
31381(typeattribute base_typeattr_986)
31382(typeattributeset base_typeattr_986 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app_27 ))))
31383(typeattribute base_typeattr_985)
31384(typeattributeset base_typeattr_985 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app_27 ))))
31385(typeattribute base_typeattr_984)
31386(typeattributeset base_typeattr_984 (and (untrusted_app_27 ) (not (runas_app shell simpleperf ))))
31387(typeattribute base_typeattr_983)
31388(typeattributeset base_typeattr_983 (and (domain ) (not (untrusted_app_27 ))))
31389(typeattribute base_typeattr_982)
31390(typeattributeset base_typeattr_982 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app_25 ))))
31391(typeattribute base_typeattr_981)
31392(typeattributeset base_typeattr_981 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app_25 ))))
31393(typeattribute base_typeattr_980)
31394(typeattributeset base_typeattr_980 (and (untrusted_app_25 ) (not (runas_app shell simpleperf ))))
31395(typeattribute base_typeattr_979)
31396(typeattributeset base_typeattr_979 (and (domain ) (not (untrusted_app_25 ))))
31397(typeattribute base_typeattr_978)
31398(typeattributeset base_typeattr_978 (and (domain ) (not (crash_dump runas_app simpleperf untrusted_app ))))
31399(typeattribute base_typeattr_977)
31400(typeattributeset base_typeattr_977 (and (appdomain ) (not (runas_app shell simpleperf untrusted_app ))))
31401(typeattribute base_typeattr_976)
31402(typeattributeset base_typeattr_976 (and (untrusted_app ) (not (runas_app shell simpleperf ))))
31403(typeattribute base_typeattr_975)
31404(typeattributeset base_typeattr_975 (and (domain ) (not (untrusted_app ))))
31405(typeattribute base_typeattr_974)
31406(typeattributeset base_typeattr_974 (and (domain ) (not (crash_dump runas_app simpleperf traceur_app ))))
31407(typeattribute base_typeattr_973)
31408(typeattributeset base_typeattr_973 (and (appdomain ) (not (runas_app shell simpleperf traceur_app ))))
31409(typeattribute base_typeattr_972)
31410(typeattributeset base_typeattr_972 (and (traceur_app ) (not (runas_app shell simpleperf ))))
31411(typeattribute base_typeattr_971)
31412(typeattributeset base_typeattr_971 (and (domain ) (not (traceur_app ))))
31413(typeattribute base_typeattr_970)
31414(typeattributeset base_typeattr_970 (and (data_file_type ) (not (packages_list_file game_mode_intervention_list_file ))))
31415(typeattribute base_typeattr_969)
31416(typeattributeset base_typeattr_969 (and (data_file_type ) (not (system_data_root_file system_data_file system_userdir_file vendor_data_file vendor_userdir_file apk_data_file dalvikcache_data_file user_profile_root_file user_profile_data_file apex_module_data_file bootstat_data_file media_userdir_file update_engine_data_file update_engine_log_data_file system_app_data_file backup_data_file apex_art_data_file ))))
31417(typeattribute base_typeattr_968)
31418(typeattributeset base_typeattr_968 (and (domain ) (not (dumpstate perfetto shell system_server traced traceur_app ))))
31419(typeattribute base_typeattr_967)
31420(typeattributeset base_typeattr_967 (and (data_file_type ) (not (trace_data_file perfetto_traces_data_file ))))
31421(typeattribute base_typeattr_966)
31422(typeattributeset base_typeattr_966 (and (data_file_type ) (not (system_data_root_file system_data_file system_userdir_file vendor_data_file vendor_userdir_file media_userdir_file perfetto_traces_data_file ))))
31423(typeattribute base_typeattr_965)
31424(typeattributeset base_typeattr_965 (and (domain ) (not (dumpstate init tombstoned vendor_init ))))
31425(typeattribute base_typeattr_964)
31426(typeattributeset base_typeattr_964 (and (domain ) (not (atrace bluetooth dumpstate system_server traceur_app system_suspend ))))
31427(typeattribute base_typeattr_963)
31428(typeattributeset base_typeattr_963 (and (domain ) (not (system_suspend ))))
31429(typeattribute base_typeattr_962)
31430(typeattributeset base_typeattr_962 (and (domain ) (not (init system_server ueventd vendor_init ))))
31431(typeattribute base_typeattr_961)
31432(typeattributeset base_typeattr_961 (and (domain ) (not (init system_server aconfigd ))))
31433(typeattribute base_typeattr_960)
31434(typeattributeset base_typeattr_960 (and (dev_type ) (not (vd_device frp_block_device ))))
31435(typeattribute base_typeattr_959)
31436(typeattributeset base_typeattr_959 (and (dev_type ) (not (frp_block_device ))))
31437(typeattribute base_typeattr_958)
31438(typeattributeset base_typeattr_958 (and (domain ) (not (flags_health_check init system_server ))))
31439(typeattribute base_typeattr_957)
31440(typeattributeset base_typeattr_957 (and (domain ) (not (app_zygote init system_server webview_zygote zygote ))))
31441(typeattribute base_typeattr_956)
31442(typeattributeset base_typeattr_956 (and (domain ) (not (crash_dump init system_server ))))
31443(typeattribute base_typeattr_955)
31444(typeattributeset base_typeattr_955 (and (domain ) (not (crash_dump perfetto clatd ))))
31445(typeattribute base_typeattr_954)
31446(typeattributeset base_typeattr_954 (and (file_type ) (not (logcat_exec toolbox_exec ))))
31447(typeattribute base_typeattr_953)
31448(typeattributeset base_typeattr_953 (and (app_data_file_type ) (not (radio_data_file system_app_data_file ))))
31449(typeattribute base_typeattr_952)
31450(typeattributeset base_typeattr_952 (and (domain ) (not (init system_app ))))
31451(typeattribute base_typeattr_951)
31452(typeattributeset base_typeattr_951 (and (service_manager_type ) (not (apex_service default_android_service dnsresolver_service dumpstate_service installd_service lpdump_service mdns_service netd_service system_suspend_control_internal_service system_suspend_control_service virtual_touchpad_service vold_service tracingproxy_service ))))
31453(typeattribute base_typeattr_950)
31454(typeattributeset base_typeattr_950 (and (domain ) (not (crash_dump runas_app simpleperf system_app ))))
31455(typeattribute base_typeattr_949)
31456(typeattributeset base_typeattr_949 (and (appdomain ) (not (runas_app shell simpleperf system_app ))))
31457(typeattribute base_typeattr_948)
31458(typeattributeset base_typeattr_948 (and (system_app ) (not (runas_app shell simpleperf ))))
31459(typeattribute base_typeattr_947)
31460(typeattributeset base_typeattr_947 (and (domain ) (not (system_app ))))
31461(typeattribute base_typeattr_946)
31462(typeattributeset base_typeattr_946 (and (domain ) (not (surfaceflinger ))))
31463(typeattribute base_typeattr_945)
31464(typeattributeset base_typeattr_945 (and (domain ) (not (storaged ))))
31465(typeattribute base_typeattr_944)
31466(typeattributeset base_typeattr_944 (and (domain ) (not (statsd ))))
31467(typeattribute base_typeattr_943)
31468(typeattributeset base_typeattr_943 (and (domain ) (not (snapuserd ))))
31469(typeattribute base_typeattr_942)
31470(typeattributeset base_typeattr_942 (and (domain ) (not (init snapuserd ))))
31471(typeattribute base_typeattr_941)
31472(typeattributeset base_typeattr_941 (and (simpleperf ) (not (runas_app shell simpleperf ))))
31473(typeattribute base_typeattr_940)
31474(typeattributeset base_typeattr_940 (and (domain ) (not (simpleperf ))))
31475(typeattribute base_typeattr_939)
31476(typeattributeset base_typeattr_939 (and (untrusted_app_all ephemeral_app isolated_app platform_app priv_app ) (not (runas_app ))))
31477(typeattribute base_typeattr_938)
31478(typeattributeset base_typeattr_938 (and (domain ) (not (dumpstate init shell ))))
31479(typeattribute base_typeattr_937)
31480(typeattributeset base_typeattr_937 (and (domain ) (not (crash_dump runas_app shell simpleperf ))))
31481(typeattribute base_typeattr_936)
31482(typeattributeset base_typeattr_936 (and (shell ) (not (runas_app shell simpleperf ))))
31483(typeattribute base_typeattr_935)
31484(typeattributeset base_typeattr_935 (and (domain ) (not (shell ))))
31485(typeattribute base_typeattr_934)
31486(typeattributeset base_typeattr_934 (and (domain ) (not (crash_dump runas_app shared_relro simpleperf ))))
31487(typeattribute base_typeattr_933)
31488(typeattributeset base_typeattr_933 (and (appdomain ) (not (runas_app shared_relro shell simpleperf ))))
31489(typeattribute base_typeattr_932)
31490(typeattributeset base_typeattr_932 (and (shared_relro ) (not (runas_app shell simpleperf ))))
31491(typeattribute base_typeattr_931)
31492(typeattributeset base_typeattr_931 (and (domain ) (not (shared_relro ))))
31493(typeattribute base_typeattr_930)
31494(typeattributeset base_typeattr_930 (and (domain ) (not (crash_dump runas_app secure_element simpleperf ))))
31495(typeattribute base_typeattr_929)
31496(typeattributeset base_typeattr_929 (and (appdomain ) (not (runas_app secure_element shell simpleperf ))))
31497(typeattribute base_typeattr_928)
31498(typeattributeset base_typeattr_928 (and (secure_element ) (not (runas_app shell simpleperf ))))
31499(typeattribute base_typeattr_927)
31500(typeattributeset base_typeattr_927 (and (domain ) (not (secure_element ))))
31501(typeattribute base_typeattr_926)
31502(typeattributeset base_typeattr_926 (and (domain ) (not (crash_dump runas_app simpleperf sdk_sandbox_next ))))
31503(typeattribute base_typeattr_925)
31504(typeattributeset base_typeattr_925 (and (appdomain ) (not (runas_app shell simpleperf sdk_sandbox_next ))))
31505(typeattribute base_typeattr_924)
31506(typeattributeset base_typeattr_924 (and (sdk_sandbox_next ) (not (runas_app shell simpleperf ))))
31507(typeattribute base_typeattr_923)
31508(typeattributeset base_typeattr_923 (and (domain ) (not (sdk_sandbox_next ))))
31509(typeattribute base_typeattr_922)
31510(typeattributeset base_typeattr_922 (and (property_type ) (not (system_property_type ))))
31511(typeattribute base_typeattr_921)
31512(typeattributeset base_typeattr_921 (and (domain ) (not (crash_dump runas_app simpleperf sdk_sandbox_audit ))))
31513(typeattribute base_typeattr_920)
31514(typeattributeset base_typeattr_920 (and (appdomain ) (not (runas_app shell simpleperf sdk_sandbox_audit ))))
31515(typeattribute base_typeattr_919)
31516(typeattributeset base_typeattr_919 (and (sdk_sandbox_audit ) (not (runas_app shell simpleperf ))))
31517(typeattribute base_typeattr_918)
31518(typeattributeset base_typeattr_918 (and (domain ) (not (sdk_sandbox_audit ))))
31519(typeattribute base_typeattr_917)
31520(typeattributeset base_typeattr_917 (and (domain ) (not (init installd system_server vold_prepare_subdirs zygote sdk_sandbox_all ))))
31521(typeattribute base_typeattr_916)
31522(typeattributeset base_typeattr_916 (and (domain ) (not (init installd system_server vold_prepare_subdirs ))))
31523(typeattribute base_typeattr_915)
31524(typeattributeset base_typeattr_915 (and (app_data_file_type ) (not (shell_data_file radio_data_file sdk_sandbox_data_file ))))
31525(typeattribute base_typeattr_914)
31526(typeattributeset base_typeattr_914 (and (domain ) (not (crash_dump runas_app simpleperf sdk_sandbox_34 ))))
31527(typeattribute base_typeattr_913)
31528(typeattributeset base_typeattr_913 (and (appdomain ) (not (runas_app shell simpleperf sdk_sandbox_34 ))))
31529(typeattribute base_typeattr_912)
31530(typeattributeset base_typeattr_912 (and (sdk_sandbox_34 ) (not (runas_app shell simpleperf ))))
31531(typeattribute base_typeattr_911)
31532(typeattributeset base_typeattr_911 (and (domain ) (not (sdk_sandbox_34 ))))
31533(typeattribute base_typeattr_910)
31534(typeattributeset base_typeattr_910 (and (domain ) (not (crash_dump runas_app simpleperf ))))
31535(typeattribute base_typeattr_909)
31536(typeattributeset base_typeattr_909 (and (appdomain ) (not (runas_app shell simpleperf ))))
31537(typeattribute base_typeattr_908)
31538(typeattributeset base_typeattr_908 (and (runas_app ) (not (runas_app shell simpleperf ))))
31539(typeattribute base_typeattr_907)
31540(typeattributeset base_typeattr_907 (and (domain ) (not (runas_app ))))
31541(typeattribute base_typeattr_906)
31542(typeattributeset base_typeattr_906 (and (domain ) (not (crash_dump rkpdapp runas_app simpleperf ))))
31543(typeattribute base_typeattr_905)
31544(typeattributeset base_typeattr_905 (and (appdomain ) (not (rkpdapp runas_app shell simpleperf ))))
31545(typeattribute base_typeattr_904)
31546(typeattributeset base_typeattr_904 (and (rkpdapp ) (not (runas_app shell simpleperf ))))
31547(typeattribute base_typeattr_903)
31548(typeattributeset base_typeattr_903 (and (domain ) (not (rkpdapp ))))
31549(typeattribute base_typeattr_902)
31550(typeattributeset base_typeattr_902 (and (domain ) (not (rkpd ))))
31551(typeattribute base_typeattr_901)
31552(typeattributeset base_typeattr_901 (and (file_type ) (not (recovery_data_file ))))
31553(typeattribute base_typeattr_900)
31554(typeattributeset base_typeattr_900 (and (domain ) (not (init radio ))))
31555(typeattribute base_typeattr_899)
31556(typeattributeset base_typeattr_899 (and (domain ) (not (crash_dump radio runas_app simpleperf ))))
31557(typeattribute base_typeattr_898)
31558(typeattributeset base_typeattr_898 (and (appdomain ) (not (radio runas_app shell simpleperf ))))
31559(typeattribute base_typeattr_897)
31560(typeattributeset base_typeattr_897 (and (radio ) (not (runas_app shell simpleperf ))))
31561(typeattribute base_typeattr_896)
31562(typeattributeset base_typeattr_896 (and (appdomain ) (not (system_app device_as_webcam ))))
31563(typeattribute base_typeattr_895)
31564(typeattributeset base_typeattr_895 (and (domain ) (not (dumpstate init profcollectd ))))
31565(typeattribute base_typeattr_894)
31566(typeattributeset base_typeattr_894 (and (domain ) (not (coredomain apexd dumpstate vendor_init ))))
31567(typeattribute base_typeattr_893)
31568(typeattributeset base_typeattr_893 (and (domain ) (not (coredomain apexd dumpstate init ))))
31569(typeattribute base_typeattr_892)
31570(typeattributeset base_typeattr_892 (and (domain ) (not (init rkpdapp shell ))))
31571(typeattribute base_typeattr_891)
31572(typeattributeset base_typeattr_891 (and (domain ) (not (hal_dumpstate_server dumpstate init ))))
31573(typeattribute base_typeattr_890)
31574(typeattributeset base_typeattr_890 (and (domain ) (not (appdomain dumpstate init vendor_init ))))
31575(typeattribute base_typeattr_889)
31576(typeattributeset base_typeattr_889 (and (domain ) (not (dumpstate init system_app vendor_init ))))
31577(typeattribute base_typeattr_888)
31578(typeattributeset base_typeattr_888 (and (domain ) (not (init surfaceflinger ))))
31579(typeattribute base_typeattr_887)
31580(typeattributeset base_typeattr_887 (and (domain ) (not (appdomain hal_telephony_server init radio ))))
31581(typeattribute base_typeattr_886)
31582(typeattributeset base_typeattr_886 (and (domain ) (not (init shell system_app system_server mtectrl ))))
31583(typeattribute base_typeattr_885)
31584(typeattributeset base_typeattr_885 (and (domain ) (not (init shell ))))
31585(typeattribute base_typeattr_884)
31586(typeattributeset base_typeattr_884 (and (domain ) (not (adbd init ))))
31587(typeattribute base_typeattr_883)
31588(typeattributeset base_typeattr_883 (and (domain ) (not (adbd init system_server vendor_init ))))
31589(typeattribute base_typeattr_882)
31590(typeattributeset base_typeattr_882 (and (property_type ) (not (extended_core_property_type system_property_type ))))
31591(typeattribute base_typeattr_881)
31592(typeattributeset base_typeattr_881 (and (coredomain ) (not (system_writes_vendor_properties_violators init ))))
31593(typeattribute base_typeattr_880)
31594(typeattributeset base_typeattr_880 (and (core_property_type extended_core_property_type dalvik_config_prop_type exported3_system_prop systemsound_config_prop ) (not (debug_prop logd_prop nfc_prop powerctl_prop radio_prop ))))
31595(typeattribute base_typeattr_879)
31596(typeattributeset base_typeattr_879 (and (domain ) (not (hal_wifi_server dumpstate init vendor_init wificond ))))
31597(typeattribute base_typeattr_878)
31598(typeattributeset base_typeattr_878 (and (domain ) (not (coredomain hal_wifi_server wificond ))))
31599(typeattribute base_typeattr_877)
31600(typeattributeset base_typeattr_877 (and (domain ) (not (coredomain hal_camera_server cameraserver vendor_init ))))
31601(typeattribute base_typeattr_876)
31602(typeattributeset base_typeattr_876 (and (domain ) (not (coredomain hal_bluetooth_server bluetooth vendor_init ))))
31603(typeattribute base_typeattr_875)
31604(typeattributeset base_typeattr_875 (and (domain ) (not (coredomain hal_bluetooth_server bluetooth ))))
31605(typeattribute base_typeattr_874)
31606(typeattributeset base_typeattr_874 (and (domain ) (not (appdomain coredomain hal_telephony_server ))))
31607(typeattribute base_typeattr_873)
31608(typeattributeset base_typeattr_873 (and (domain ) (not (appdomain coredomain hal_telephony_server vendor_init ))))
31609(typeattribute base_typeattr_872)
31610(typeattributeset base_typeattr_872 (and (domain ) (not (appdomain coredomain hal_nfc_server ))))
31611(typeattribute base_typeattr_871)
31612(typeattributeset base_typeattr_871 (and (core_property_type extended_core_property_type exported3_system_prop exported_dumpstate_prop exported_config_prop exported_default_prop exported_system_prop usb_control_prop ) (not (nfc_prop powerctl_prop radio_prop ))))
31613(typeattribute base_typeattr_870)
31614(typeattributeset base_typeattr_870 (and (domain ) (not (appdomain coredomain vendor_init ))))
31615(typeattribute base_typeattr_869)
31616(typeattributeset base_typeattr_869 (and (domain ) (not (init misctrl ))))
31617(typeattribute base_typeattr_868)
31618(typeattributeset base_typeattr_868 (and (domain ) (not (dumpstate init misctrl ))))
31619(typeattribute base_typeattr_867)
31620(typeattributeset base_typeattr_867 (and (domain ) (not (extra_free_kbytes init ))))
31621(typeattribute base_typeattr_866)
31622(typeattributeset base_typeattr_866 (and (core_property_type ) (not (fingerprint_prop restorecon_prop usb_prop config_prop cppreopt_prop dalvik_prop debuggerd_prop dhcp_prop dumpstate_prop net_radio_prop pan_result_prop persist_debug_prop shell_prop vold_prop audio_prop debug_prop logd_prop nfc_prop ota_prop powerctl_prop radio_prop system_prop ))))
31623(typeattribute base_typeattr_865)
31624(typeattributeset base_typeattr_865 (and (vendor_property_type ) (not (vendor_public_property_type ))))
31625(typeattribute base_typeattr_864)
31626(typeattributeset base_typeattr_864 (and (vendor_property_type vendor_internal_property_type ) (not (vendor_restricted_property_type vendor_public_property_type ))))
31627(typeattribute base_typeattr_863)
31628(typeattributeset base_typeattr_863 (and (system_property_type ) (not (system_public_property_type ))))
31629(typeattribute base_typeattr_862)
31630(typeattributeset base_typeattr_862 (and (system_property_type system_internal_property_type ) (not (system_restricted_property_type system_public_property_type ))))
31631(typeattribute base_typeattr_861)
31632(typeattributeset base_typeattr_861 (and (property_type ) (not (system_property_type vendor_property_type ))))
31633(typeattribute base_typeattr_860)
31634(typeattributeset base_typeattr_860 (and (app_data_file_type ) (not (privapp_data_file ))))
31635(typeattribute base_typeattr_859)
31636(typeattributeset base_typeattr_859 (and (domain ) (not (crash_dump priv_app runas_app simpleperf ))))
31637(typeattribute base_typeattr_858)
31638(typeattributeset base_typeattr_858 (and (appdomain ) (not (priv_app runas_app shell simpleperf ))))
31639(typeattribute base_typeattr_857)
31640(typeattributeset base_typeattr_857 (and (priv_app ) (not (runas_app shell simpleperf ))))
31641(typeattribute base_typeattr_856)
31642(typeattributeset base_typeattr_856 (and (domain ) (not (priv_app ))))
31643(typeattribute base_typeattr_855)
31644(typeattributeset base_typeattr_855 (and (domain ) (not (dumpstate init ))))
31645(typeattribute base_typeattr_854)
31646(typeattributeset base_typeattr_854 (and (domain ) (not (crash_dump platform_app runas_app simpleperf ))))
31647(typeattribute base_typeattr_853)
31648(typeattributeset base_typeattr_853 (and (appdomain ) (not (platform_app runas_app shell simpleperf ))))
31649(typeattribute base_typeattr_852)
31650(typeattributeset base_typeattr_852 (and (platform_app ) (not (runas_app shell simpleperf ))))
31651(typeattribute base_typeattr_851)
31652(typeattributeset base_typeattr_851 (and (domain ) (not (platform_app ))))
31653(typeattribute base_typeattr_850)
31654(typeattributeset base_typeattr_850 (and (domain ) (not (crash_dump runas_app simpleperf permissioncontroller_app ))))
31655(typeattribute base_typeattr_849)
31656(typeattributeset base_typeattr_849 (and (appdomain ) (not (runas_app shell simpleperf permissioncontroller_app ))))
31657(typeattribute base_typeattr_848)
31658(typeattributeset base_typeattr_848 (and (permissioncontroller_app ) (not (runas_app shell simpleperf ))))
31659(typeattribute base_typeattr_847)
31660(typeattributeset base_typeattr_847 (and (domain ) (not (permissioncontroller_app ))))
31661(typeattribute base_typeattr_846)
31662(typeattributeset base_typeattr_846 (and (data_file_type ) (not (perfetto_traces_data_file perfetto_traces_bugreport_data_file perfetto_traces_profiling_data_file perfetto_configs_data_file ))))
31663(typeattribute base_typeattr_845)
31664(typeattributeset base_typeattr_845 (and (system_data_file ) (not (perfetto_traces_data_file perfetto_traces_profiling_data_file ))))
31665(typeattribute base_typeattr_844)
31666(typeattributeset base_typeattr_844 (and (data_file_type ) (not (system_data_root_file system_data_file system_userdir_file vendor_data_file vendor_userdir_file media_userdir_file perfetto_traces_data_file perfetto_traces_bugreport_data_file perfetto_traces_profiling_data_file perfetto_configs_data_file ))))
31667(typeattribute base_typeattr_843)
31668(typeattributeset base_typeattr_843 (and (domain ) (not (adbd incidentd init perfetto shell traced ))))
31669(typeattribute base_typeattr_842)
31670(typeattributeset base_typeattr_842 (and (domain ) (not (adbd dumpstate incidentd init perfetto priv_app shell system_server traced ))))
31671(typeattribute base_typeattr_841)
31672(typeattributeset base_typeattr_841 (and (domain ) (not (ot_daemon ))))
31673(typeattribute base_typeattr_840)
31674(typeattributeset base_typeattr_840 (and (domain ) (not (init fsverity_init odsign ))))
31675(typeattribute base_typeattr_839)
31676(typeattributeset base_typeattr_839 (and (domain ) (not (init odsign ))))
31677(typeattribute base_typeattr_838)
31678(typeattributeset base_typeattr_838 (and (domain ) (not (init system_server odrefresh ))))
31679(typeattribute base_typeattr_837)
31680(typeattributeset base_typeattr_837 (and (domain ) (not (init compos_fd_server odrefresh ))))
31681(typeattribute base_typeattr_836)
31682(typeattributeset base_typeattr_836 (and (domain ) (not (odrefresh ))))
31683(typeattribute base_typeattr_835)
31684(typeattributeset base_typeattr_835 (and (domain ) (not (crash_dump nfc runas_app simpleperf ))))
31685(typeattribute base_typeattr_834)
31686(typeattributeset base_typeattr_834 (and (appdomain ) (not (nfc runas_app shell simpleperf ))))
31687(typeattribute base_typeattr_833)
31688(typeattributeset base_typeattr_833 (and (nfc ) (not (runas_app shell simpleperf ))))
31689(typeattribute base_typeattr_832)
31690(typeattributeset base_typeattr_832 (and (domain ) (not (nfc ))))
31691(typeattribute base_typeattr_831)
31692(typeattributeset base_typeattr_831 (and (domain ) (not (crash_dump network_stack runas_app simpleperf ))))
31693(typeattribute base_typeattr_830)
31694(typeattributeset base_typeattr_830 (and (appdomain ) (not (network_stack runas_app shell simpleperf ))))
31695(typeattribute base_typeattr_829)
31696(typeattributeset base_typeattr_829 (and (network_stack ) (not (runas_app shell simpleperf ))))
31697(typeattribute base_typeattr_828)
31698(typeattributeset base_typeattr_828 (and (domain ) (not (network_stack ))))
31699(typeattribute base_typeattr_827)
31700(typeattributeset base_typeattr_827 (and (domain ) (not (init netd ))))
31701(typeattribute base_typeattr_826)
31702(typeattributeset base_typeattr_826 (and (domain ) (not (dumpstate init netd ))))
31703(typeattribute base_typeattr_825)
31704(typeattributeset base_typeattr_825 (and (netdomain ) (not (untrusted_app_all ephemeral_app mediaprovider priv_app sdk_sandbox_all ))))
31705(typeattribute base_typeattr_824)
31706(typeattributeset base_typeattr_824 (and (netdomain ) (not (ephemeral_app sdk_sandbox_all ))))
31707(typeattribute base_typeattr_823)
31708(typeattributeset base_typeattr_823 (and (mlstrustedsubject ) (not (adbd artd installd runas system_server zygote ))))
31709(typeattribute base_typeattr_822)
31710(typeattributeset base_typeattr_822 (and (mlstrustedsubject ) (not (artd installd ))))
31711(typeattribute base_typeattr_821)
31712(typeattributeset base_typeattr_821 (and (domain ) (not (mediatuner ))))
31713(typeattribute base_typeattr_820)
31714(typeattributeset base_typeattr_820 (and (domain ) (not (mediatranscoding ))))
31715(typeattribute base_typeattr_819)
31716(typeattributeset base_typeattr_819 (and (domain ) (not (crash_dump runas_app simpleperf mediaprovider_app ))))
31717(typeattribute base_typeattr_818)
31718(typeattributeset base_typeattr_818 (and (appdomain ) (not (runas_app shell simpleperf mediaprovider_app ))))
31719(typeattribute base_typeattr_817)
31720(typeattributeset base_typeattr_817 (and (mediaprovider_app ) (not (runas_app shell simpleperf ))))
31721(typeattribute base_typeattr_816)
31722(typeattributeset base_typeattr_816 (and (domain ) (not (mediaprovider_app ))))
31723(typeattribute base_typeattr_815)
31724(typeattributeset base_typeattr_815 (and (domain ) (not (crash_dump mediaprovider runas_app simpleperf ))))
31725(typeattribute base_typeattr_814)
31726(typeattributeset base_typeattr_814 (and (appdomain ) (not (mediaprovider runas_app shell simpleperf ))))
31727(typeattribute base_typeattr_813)
31728(typeattributeset base_typeattr_813 (and (mediaprovider ) (not (runas_app shell simpleperf ))))
31729(typeattribute base_typeattr_812)
31730(typeattributeset base_typeattr_812 (and (domain ) (not (mediaprovider ))))
31731(typeattribute base_typeattr_811)
31732(typeattributeset base_typeattr_811 (and (domain ) (not (dumpstate servicemanager shell lpdumpd ))))
31733(typeattribute base_typeattr_810)
31734(typeattributeset base_typeattr_810 (and (domain ) (not (dumpstate shell lpdumpd ))))
31735(typeattribute base_typeattr_809)
31736(typeattributeset base_typeattr_809 (and (domain ) (not (lpdumpd ))))
31737(typeattribute base_typeattr_808)
31738(typeattributeset base_typeattr_808 (and (domain ) (not (dumpstate incidentd init ))))
31739(typeattribute base_typeattr_807)
31740(typeattributeset base_typeattr_807 (and (domain ) (not (logd ))))
31741(typeattribute base_typeattr_806)
31742(typeattributeset base_typeattr_806 (and (appdomain ) (not (bluetooth platform_app priv_app radio shell system_app ))))
31743(typeattribute base_typeattr_805)
31744(typeattributeset base_typeattr_805 (and (domain ) (not (appdomain bootstat dumpstate init logd servicemanager surfaceflinger system_server zygote ))))
31745(typeattribute base_typeattr_804)
31746(typeattributeset base_typeattr_804 (and (file_type ) (not (runtime_event_log_tags_file shell_data_file ))))
31747(typeattribute base_typeattr_803)
31748(typeattributeset base_typeattr_803 (and (domain ) (not (init lmkd vendor_init ))))
31749(typeattribute base_typeattr_802)
31750(typeattributeset base_typeattr_802 (and (domain ) (not (init otapreopt_chroot linkerconfig ))))
31751(typeattribute base_typeattr_801)
31752(typeattributeset base_typeattr_801 (and (domain ) (not (crash_dump isolated_compute_app runas_app simpleperf ))))
31753(typeattribute base_typeattr_800)
31754(typeattributeset base_typeattr_800 (and (appdomain ) (not (isolated_compute_app runas_app shell simpleperf ))))
31755(typeattribute base_typeattr_799)
31756(typeattributeset base_typeattr_799 (and (isolated_compute_app ) (not (runas_app shell simpleperf ))))
31757(typeattribute base_typeattr_798)
31758(typeattributeset base_typeattr_798 (and (domain ) (not (isolated_compute_app ))))
31759(typeattribute base_typeattr_797)
31760(typeattributeset base_typeattr_797 (and (sysfs_type ) (not (sysfs_transparent_hugepage sysfs_usb sysfs_fs_fuse_features sysfs_fs_incfs_features sysfs_devices_system_cpu ))))
31761(typeattribute base_typeattr_796)
31762(typeattributeset base_typeattr_796 (and (service_manager_type ) (not (activity_service display_service webviewupdate_service ))))
31763(typeattribute base_typeattr_795)
31764(typeattributeset base_typeattr_795 (and (isolated_app_all ) (not (isolated_compute_app ))))
31765(typeattribute base_typeattr_794)
31766(typeattributeset base_typeattr_794 (and (domain ) (not (crash_dump isolated_app runas_app simpleperf ))))
31767(typeattribute base_typeattr_793)
31768(typeattributeset base_typeattr_793 (and (appdomain ) (not (isolated_app runas_app shell simpleperf ))))
31769(typeattribute base_typeattr_792)
31770(typeattributeset base_typeattr_792 (and (isolated_app ) (not (runas_app shell simpleperf ))))
31771(typeattribute base_typeattr_791)
31772(typeattributeset base_typeattr_791 (and (dev_type ) (not (vm_manager_device_type keychord_device hw_random_device port_device ))))
31773(typeattribute base_typeattr_790)
31774(typeattributeset base_typeattr_790 (and (domain ) (not (incidentd init system_server vold ))))
31775(typeattribute base_typeattr_789)
31776(typeattributeset base_typeattr_789 (and (domain ) (not (incidentd init vold ))))
31777(typeattribute base_typeattr_788)
31778(typeattributeset base_typeattr_788 (and (domain ) (not (incidentd ))))
31779(typeattribute base_typeattr_787)
31780(typeattributeset base_typeattr_787 (and (system_server_service app_api_service system_api_service ) (not (tracingproxy_service ))))
31781(typeattribute base_typeattr_786)
31782(typeattributeset base_typeattr_786 (and (domain ) (not (incident_helper incidentd shell ))))
31783(typeattribute base_typeattr_785)
31784(typeattributeset base_typeattr_785 (and (domain ) (not (dumpstate incident shell su ))))
31785(typeattribute base_typeattr_784)
31786(typeattributeset base_typeattr_784 (and (domain ) (not (hwservicemanager ))))
31787(typeattribute base_typeattr_783)
31788(typeattributeset base_typeattr_783 (and (vendor_file_type ) (not (vndk_sp_file ))))
31789(typeattribute base_typeattr_782)
31790(typeattributeset base_typeattr_782 (and (domain ) (not (init gsid ))))
31791(typeattribute base_typeattr_781)
31792(typeattributeset base_typeattr_781 (and (gsi_metadata_file_type ) (not (gsi_public_metadata_file ))))
31793(typeattribute base_typeattr_780)
31794(typeattributeset base_typeattr_780 (and (domain ) (not (fastbootd init gsid ))))
31795(typeattribute base_typeattr_779)
31796(typeattributeset base_typeattr_779 (and (domain ) (not (update_engine_common fastbootd init recovery gsid ))))
31797(typeattribute base_typeattr_778)
31798(typeattributeset base_typeattr_778 (and (domain ) (not (gsid ))))
31799(typeattribute base_typeattr_777)
31800(typeattributeset base_typeattr_777 (and (domain ) (not (gpuservice init vendor_init ))))
31801(typeattribute base_typeattr_776)
31802(typeattributeset base_typeattr_776 (and (domain ) (not (gpuservice ))))
31803(typeattribute base_typeattr_775)
31804(typeattributeset base_typeattr_775 (and (domain ) (not (dumpstate gmscore_app init vendor_init ))))
31805(typeattribute base_typeattr_774)
31806(typeattributeset base_typeattr_774 (and (domain ) (not (crash_dump gmscore_app runas_app simpleperf ))))
31807(typeattribute base_typeattr_773)
31808(typeattributeset base_typeattr_773 (and (appdomain ) (not (gmscore_app runas_app shell simpleperf ))))
31809(typeattribute base_typeattr_772)
31810(typeattributeset base_typeattr_772 (and (gmscore_app ) (not (runas_app shell simpleperf ))))
31811(typeattribute base_typeattr_771)
31812(typeattributeset base_typeattr_771 (and (domain ) (not (gmscore_app ))))
31813(typeattribute base_typeattr_770)
31814(typeattributeset base_typeattr_770 (and (fs_type file_type ) (not (fuseblkd_untrusted_exec ))))
31815(typeattribute base_typeattr_769)
31816(typeattributeset base_typeattr_769 (and (fs_type file_type ) (not (fuseblkd_exec ))))
31817(typeattribute base_typeattr_768)
31818(typeattributeset base_typeattr_768 (and (domain ) (not (fuseblkd_untrusted ))))
31819(typeattribute base_typeattr_767)
31820(typeattributeset base_typeattr_767 (and (domain ) (not (fastbootd ))))
31821(typeattribute base_typeattr_766)
31822(typeattributeset base_typeattr_766 (and (domain ) (not (evsmanagerd ))))
31823(typeattribute base_typeattr_765)
31824(typeattributeset base_typeattr_765 (and (domain ) (not (crash_dump ephemeral_app runas_app simpleperf ))))
31825(typeattribute base_typeattr_764)
31826(typeattributeset base_typeattr_764 (and (appdomain ) (not (ephemeral_app runas_app shell simpleperf ))))
31827(typeattribute base_typeattr_763)
31828(typeattributeset base_typeattr_763 (and (ephemeral_app ) (not (runas_app shell simpleperf ))))
31829(typeattribute base_typeattr_762)
31830(typeattributeset base_typeattr_762 (and (domain ) (not (ephemeral_app ))))
31831(typeattribute base_typeattr_761)
31832(typeattributeset base_typeattr_761 (and (domain ) (not (init aconfigd ))))
31833(typeattribute base_typeattr_760)
31834(typeattributeset base_typeattr_760 (and (domain ) (not (gmscore_app init vold_prepare_subdirs ))))
31835(typeattribute base_typeattr_759)
31836(typeattributeset base_typeattr_759 (and (domain ) (not (appdomain artd installd system_server traced_probes ))))
31837(typeattribute base_typeattr_758)
31838(typeattributeset base_typeattr_758 (and (domain ) (not (appdomain adbd artd dumpstate init installd simpleperf_app_runner system_server ))))
31839(typeattribute base_typeattr_757)
31840(typeattributeset base_typeattr_757 (and (domain ) (not (adbd artd dumpstate init installd shell vold ))))
31841(typeattribute base_typeattr_756)
31842(typeattributeset base_typeattr_756 (and (domain ) (not (appdomain adbd artd dumpstate installd ))))
31843(typeattribute base_typeattr_755)
31844(typeattributeset base_typeattr_755 (and (domain ) (not (init kernel vendor_modprobe uprobestats ))))
31845(typeattribute base_typeattr_754)
31846(typeattributeset base_typeattr_754 (and (domain ) (not (ueventd vendor_init ))))
31847(typeattribute base_typeattr_753)
31848(typeattributeset base_typeattr_753 (and (debugfs_type ) (not (tracefs_type ))))
31849(typeattribute base_typeattr_752)
31850(typeattributeset base_typeattr_752 (and (domain ) (not (vendor_modprobe ))))
31851(typeattribute base_typeattr_751)
31852(typeattributeset base_typeattr_751 (and (domain ) (not (init traced_perf traced_probes vendor_init ))))
31853(typeattribute base_typeattr_750)
31854(typeattributeset base_typeattr_750 (and (domain ) (not (init otapreopt_chroot ))))
31855(typeattribute base_typeattr_749)
31856(typeattributeset base_typeattr_749 (and (vendor_file_type ) (not (vendor_task_profiles_file vendor_app_file vendor_configs_file same_process_hal_file vndk_sp_file vendor_framework_file vendor_overlay_file vendor_public_lib_file vendor_public_framework_file vendor_microdroid_file vendor_keylayout_file vendor_keychars_file vendor_idc_file vendor_uuid_mapping_config_file vendor_apex_file vendor_apex_metadata_file vendor_service_contexts_file vendor_aconfig_storage_file ))))
31857(typeattribute base_typeattr_748)
31858(typeattributeset base_typeattr_748 (and (coredomain ) (not (system_executes_vendor_violators crash_dump heapprofd init kernel shell traced_perf ueventd vold crosvm ))))
31859(typeattribute base_typeattr_747)
31860(typeattributeset base_typeattr_747 (and (coredomain ) (not (heapprofd init logd mdnsd netd prng_seeder tombstoned traced traced_perf ))))
31861(typeattribute base_typeattr_746)
31862(typeattributeset base_typeattr_746 (and (domain ) (not (appdomain coredomain socket_between_core_and_vendor_violators ))))
31863(typeattribute base_typeattr_745)
31864(typeattributeset base_typeattr_745 (and (coredomain ) (not (appdomain bootanim crash_dump heapprofd init kernel traced_perf ueventd ))))
31865(typeattribute base_typeattr_744)
31866(typeattributeset base_typeattr_744 (and (domain ) (not (init vendor_init art_boot ))))
31867(typeattribute base_typeattr_743)
31868(typeattributeset base_typeattr_743 (and (domain ) (not (dumpstate init system_server ))))
31869(typeattribute base_typeattr_742)
31870(typeattributeset base_typeattr_742 (and (domain ) (not (fsck init installd zygote ))))
31871(typeattribute base_typeattr_741)
31872(typeattributeset base_typeattr_741 (and (domain ) (not (hal_bootctl_server fastbootd init kernel recovery tee ueventd uncrypt gsid ))))
31873(typeattribute base_typeattr_740)
31874(typeattributeset base_typeattr_740 (and (debugfs_type ) (not (debugfs_tracing_debug ))))
31875(typeattribute base_typeattr_739)
31876(typeattributeset base_typeattr_739 (and (fs_type ) (not (fusefs_type sdcard_type ))))
31877(typeattribute base_typeattr_738)
31878(typeattributeset base_typeattr_738 (and (domain ) (not (apexd init kernel otapreopt_chroot recovery update_engine vold zygote ))))
31879(typeattribute base_typeattr_737)
31880(typeattributeset base_typeattr_737 (not (apexd artd dnsmasq dumpstate heapprofd init installd lmkd netd recovery rss_hwm_reset sdcardd tee traced_perf traced_probes ueventd uncrypt vendor_init vold vold_prepare_subdirs zygote migrate_legacy_obb_data postinstall_dexopt ) ))
31881(typeattribute base_typeattr_736)
31882(typeattributeset base_typeattr_736 (not (apexd artd dnsmasq dumpstate init installd lmkd netd recovery rss_hwm_reset sdcardd tee ueventd uncrypt vendor_init vold vold_prepare_subdirs zygote migrate_legacy_obb_data postinstall_dexopt ) ))
31883(typeattribute base_typeattr_735)
31884(typeattributeset base_typeattr_735 (and (domain ) (not (apexd init vold_prepare_subdirs compos_fd_server composd odrefresh odsign ))))
31885(typeattribute base_typeattr_734)
31886(typeattributeset base_typeattr_734 (and (domain ) (not (artd init installd zygote cppreopts dex2oat otapreopt_slot postinstall_dexopt ))))
31887(typeattribute base_typeattr_733)
31888(typeattributeset base_typeattr_733 (and (file_type ) (not (exec_type system_file_type vendor_file_type system_lib_file system_linker_exec postinstall_file ))))
31889(typeattribute base_typeattr_732)
31890(typeattributeset base_typeattr_732 (and (domain ) (not (appdomain app_zygote shell webview_zygote zygote system_server_startup ))))
31891(typeattribute base_typeattr_731)
31892(typeattributeset base_typeattr_731 (and (fs_type ) (not (rootfs ))))
31893(typeattribute base_typeattr_730)
31894(typeattributeset base_typeattr_730 (and (domain ) (not (appdomain bootanim recovery ))))
31895(typeattribute base_typeattr_729)
31896(typeattributeset base_typeattr_729 (and (domain ) (not (init installd system_server ))))
31897(typeattribute base_typeattr_728)
31898(typeattributeset base_typeattr_728 (and (domain ) (not (adbd apexd init installd kernel priv_app shell system_app system_server crosvm virtualizationmanager ))))
31899(typeattribute base_typeattr_727)
31900(typeattributeset base_typeattr_727 (and (domain ) (not (apexd init installd priv_app system_server virtualizationmanager ))))
31901(typeattribute base_typeattr_726)
31902(typeattributeset base_typeattr_726 (and (domain ) (not (artd installd ))))
31903(typeattribute base_typeattr_725)
31904(typeattributeset base_typeattr_725 (and (domain ) (not (appdomain app_zygote artd installd rs ))))
31905(typeattribute base_typeattr_724)
31906(typeattributeset base_typeattr_724 (and (domain ) (not (appdomain artd installd rs ))))
31907(typeattribute base_typeattr_723)
31908(typeattributeset base_typeattr_723 (and (domain ) (not (appdomain adbd app_zygote artd installd profman rs runas system_server zygote dexoptanalyzer viewcompiler ))))
31909(typeattribute base_typeattr_722)
31910(typeattributeset base_typeattr_722 (and (domain ) (not (gmscore_app priv_app ))))
31911(typeattribute base_typeattr_721)
31912(typeattributeset base_typeattr_721 (and (domain ) (not (dumpstate system_server vold storaged ))))
31913(typeattribute base_typeattr_720)
31914(typeattributeset base_typeattr_720 (and (domain ) (not (hal_bootctl_server fastbootd init recovery ueventd uncrypt update_engine vendor_init vendor_misc_writer vold misctrl mtectrl ))))
31915(typeattribute base_typeattr_719)
31916(typeattributeset base_typeattr_719 (and (domain ) (not (hal_audio_server hal_camera_server hal_cas_server hal_codec2_server hal_configstore_server hal_drm_server hal_omx_server app_zygote artd audioserver cameraserver init kernel mediadrmserver mediaextractor mediametrics mediaserver mediatranscoding system_server ueventd vendor_init webview_zygote mediatuner ))))
31917(typeattribute base_typeattr_718)
31918(typeattributeset base_typeattr_718 (and (domain ) (not (untrusted_app_all isolated_app_all ephemeral_app ))))
31919(typeattribute base_typeattr_717)
31920(typeattributeset base_typeattr_717 (and (domain ) (not (appdomain coredomain ))))
31921(typeattribute base_typeattr_716)
31922(typeattributeset base_typeattr_716 (and (domain ) (not (appdomain rs ))))
31923(typeattribute base_typeattr_715)
31924(typeattributeset base_typeattr_715 (and (domain ) (not (hal_configstore_server apexd app_zygote bpfloader crash_dump init kernel keystore llkd logd ueventd vendor_init vold webview_zygote zygote crosvm ))))
31925(typeattribute base_typeattr_714)
31926(typeattributeset base_typeattr_714 (and (domain ) (not (hal_configstore_server apexd app_zygote bpfloader crash_dump init kernel keystore llkd logd logpersist recovery recovery_persist recovery_refresh ueventd vendor_init vold webview_zygote zygote crosvm ))))
31927(typeattribute base_typeattr_713)
31928(typeattributeset base_typeattr_713 (and (domain ) (not (dexoptanalyzer ))))
31929(typeattribute base_typeattr_712)
31930(typeattributeset base_typeattr_712 (and (domain ) (not (dexopt_chroot_setup ))))
31931(typeattribute base_typeattr_711)
31932(typeattributeset base_typeattr_711 (and (domain ) (not (dex2oat ))))
31933(typeattribute base_typeattr_710)
31934(typeattributeset base_typeattr_710 (and (domain ) (not (crash_dump runas_app simpleperf device_as_webcam ))))
31935(typeattribute base_typeattr_709)
31936(typeattributeset base_typeattr_709 (and (appdomain ) (not (runas_app shell simpleperf device_as_webcam ))))
31937(typeattribute base_typeattr_708)
31938(typeattributeset base_typeattr_708 (and (device_as_webcam ) (not (runas_app shell simpleperf ))))
31939(typeattribute base_typeattr_707)
31940(typeattributeset base_typeattr_707 (and (domain ) (not (device_as_webcam ))))
31941(typeattribute base_typeattr_706)
31942(typeattributeset base_typeattr_706 (and (domain ) (not (init derive_sdk ))))
31943(typeattribute base_typeattr_705)
31944(typeattributeset base_typeattr_705 (and (domain ) (not (crosvm virtualizationmanager ))))
31945(typeattribute base_typeattr_704)
31946(typeattributeset base_typeattr_704 (and (app_data_file_type ) (not (shell_data_file app_data_file privapp_data_file ))))
31947(typeattribute base_typeattr_703)
31948(typeattributeset base_typeattr_703 (and (vendor_file_type ) (not (vendor_task_profiles_file vendor_configs_file vndk_sp_file vendor_microdroid_file vendor_vm_file vendor_vm_data_file ))))
31949(typeattribute base_typeattr_702)
31950(typeattributeset base_typeattr_702 (and (appdomain coredomain ) (not (ueventd crosvm ))))
31951(typeattribute base_typeattr_701)
31952(typeattributeset base_typeattr_701 (and (appdomain coredomain ) (not (shell ueventd crosvm ))))
31953(typeattribute base_typeattr_700)
31954(typeattributeset base_typeattr_700 (and (domain ) (not (crosvm ))))
31955(typeattribute base_typeattr_699)
31956(typeattributeset base_typeattr_699 (and (domain ) (not (ueventd crosvm ))))
31957(typeattribute base_typeattr_698)
31958(typeattributeset base_typeattr_698 (and (domain ) (not (shell ueventd crosvm ))))
31959(typeattribute base_typeattr_697)
31960(typeattributeset base_typeattr_697 (and (domain ) (not (apexd bpfloader crash_dump init kernel keystore llkd logd ueventd vendor_init vold ))))
31961(typeattribute base_typeattr_696)
31962(typeattributeset base_typeattr_696 (and (dmabuf_heap_device_type ) (not (dmabuf_system_heap_device dmabuf_system_secure_heap_device ))))
31963(typeattribute base_typeattr_695)
31964(typeattributeset base_typeattr_695 (and (coredomain ) (not (init ueventd ))))
31965(typeattribute base_typeattr_694)
31966(typeattributeset base_typeattr_694 (and (coredomain ) (not (adbd init mediaprovider system_server ))))
31967(typeattribute base_typeattr_693)
31968(typeattributeset base_typeattr_693 (and (coredomain ) (not (init system_server ))))
31969(typeattribute base_typeattr_692)
31970(typeattributeset base_typeattr_692 (and (coredomain ) (not (bootstat charger dumpstate init logd logpersist recovery_persist recovery_refresh shell system_server ))))
31971(typeattribute base_typeattr_691)
31972(typeattributeset base_typeattr_691 (and (coredomain ) (not (init ))))
31973(typeattribute base_typeattr_690)
31974(typeattributeset base_typeattr_690 (and (coredomain ) (not (atrace dumpstate gpuservice init shell system_server traced_perf traced_probes traceur_app ))))
31975(typeattribute base_typeattr_689)
31976(typeattributeset base_typeattr_689 (and (coredomain ) (not (apexd fsck init ueventd ))))
31977(typeattribute base_typeattr_688)
31978(typeattributeset base_typeattr_688 (and (coredomain ) (not (init vold ))))
31979(typeattribute base_typeattr_687)
31980(typeattributeset base_typeattr_687 (and (coredomain ) (not (appdomain app_zygote artd heapprofd idmap init installd rs system_server traced_perf webview_zygote zygote dex2oat dexoptanalyzer postinstall_dexopt ))))
31981(typeattribute base_typeattr_686)
31982(typeattributeset base_typeattr_686 (and (coredomain ) (not (appdomain artd heapprofd idmap init installd mediaserver profman rs system_server traced_perf dex2oat dexoptanalyzer postinstall_dexopt ))))
31983(typeattribute base_typeattr_685)
31984(typeattributeset base_typeattr_685 (and (coredomain ) (not (appdomain artd heapprofd idmap init installd rs system_server traced_perf dex2oat dexoptanalyzer postinstall_dexopt ))))
31985(typeattribute base_typeattr_684)
31986(typeattributeset base_typeattr_684 (and (coredomain ) (not (apexd init ueventd vold ))))
31987(typeattribute base_typeattr_683)
31988(typeattributeset base_typeattr_683 (and (domain ) (not (odsign ))))
31989(typeattribute base_typeattr_682)
31990(typeattributeset base_typeattr_682 (and (domain ) (not (composd ))))
31991(typeattribute base_typeattr_681)
31992(typeattributeset base_typeattr_681 (and (domain ) (not (charger charger_vendor dumpstate init vendor_init ))))
31993(typeattribute base_typeattr_680)
31994(typeattributeset base_typeattr_680 (and (domain ) (not (charger charger_vendor init vendor_init ))))
31995(typeattribute base_typeattr_679)
31996(typeattributeset base_typeattr_679 (and (domain ) (not (charger dumpstate init ))))
31997(typeattribute base_typeattr_678)
31998(typeattributeset base_typeattr_678 (and (coredomain ) (not (bpfloader netd netutils_wrapper ))))
31999(typeattribute base_typeattr_677)
32000(typeattributeset base_typeattr_677 (and (domain ) (not (bpfloader init ))))
32001(typeattribute base_typeattr_676)
32002(typeattributeset base_typeattr_676 (and (domain ) (not (bpfloader gpuservice lmkd netd network_stack system_server mediaprovider_app uprobestats ))))
32003(typeattribute base_typeattr_675)
32004(typeattributeset base_typeattr_675 (and (domain ) (not (hal_health_server bpfloader gpuservice netd netutils_wrapper network_stack system_server mediaprovider_app uprobestats ))))
32005(typeattribute base_typeattr_674)
32006(typeattributeset base_typeattr_674 (and (bpffs_type ) (not (fs_bpf_vendor ))))
32007(typeattribute base_typeattr_673)
32008(typeattributeset base_typeattr_673 (and (domain ) (not (bpfloader gpuservice netd netutils_wrapper network_stack system_server uprobestats ))))
32009(typeattribute base_typeattr_672)
32010(typeattributeset base_typeattr_672 (and (domain ) (not (bpfloader uprobestats ))))
32011(typeattribute base_typeattr_671)
32012(typeattributeset base_typeattr_671 (and (domain ) (not (bpfloader netd netutils_wrapper network_stack system_server ))))
32013(typeattribute base_typeattr_670)
32014(typeattributeset base_typeattr_670 (and (domain ) (not (bpfloader netd network_stack system_server ))))
32015(typeattribute base_typeattr_669)
32016(typeattributeset base_typeattr_669 (and (domain ) (not (bpfloader network_stack system_server ))))
32017(typeattribute base_typeattr_668)
32018(typeattributeset base_typeattr_668 (and (domain ) (not (bpfloader network_stack ))))
32019(typeattribute base_typeattr_667)
32020(typeattributeset base_typeattr_667 (and (domain ) (not (bpfloader gpuservice lmkd netd netutils_wrapper system_server mediaprovider_app ))))
32021(typeattribute base_typeattr_666)
32022(typeattributeset base_typeattr_666 (and (domain ) (not (bpfloader ))))
32023(typeattribute base_typeattr_665)
32024(typeattributeset base_typeattr_665 (and (bpffs_type ) (not (fs_bpf ))))
32025(typeattribute base_typeattr_664)
32026(typeattributeset base_typeattr_664 (and (domain ) (not (bpfdomain ))))
32027(typeattribute base_typeattr_663)
32028(typeattributeset base_typeattr_663 (and (bpfdomain ) (not (bpfloader netd netutils_wrapper network_stack system_server ))))
32029(typeattribute base_typeattr_662)
32030(typeattributeset base_typeattr_662 (and (domain ) (not (init vendor_init boringssl_self_test vendor_boringssl_self_test ))))
32031(typeattribute base_typeattr_661)
32032(typeattributeset base_typeattr_661 (and (domain ) (not (bootstat init system_server ))))
32033(typeattribute base_typeattr_660)
32034(typeattributeset base_typeattr_660 (and (domain ) (not (bootanim bootstat dumpstate init platform_app recovery shell system_server ))))
32035(typeattribute base_typeattr_659)
32036(typeattributeset base_typeattr_659 (and (domain ) (not (bluetooth init ))))
32037(typeattribute base_typeattr_658)
32038(typeattributeset base_typeattr_658 (and (domain ) (not (bluetooth crash_dump runas_app simpleperf ))))
32039(typeattribute base_typeattr_657)
32040(typeattributeset base_typeattr_657 (and (appdomain ) (not (bluetooth runas_app shell simpleperf ))))
32041(typeattribute base_typeattr_656)
32042(typeattributeset base_typeattr_656 (and (bluetooth ) (not (runas_app shell simpleperf ))))
32043(typeattribute base_typeattr_655)
32044(typeattributeset base_typeattr_655 (and (domain ) (not (bluetooth ))))
32045(typeattribute base_typeattr_654)
32046(typeattributeset base_typeattr_654 (and (fs_type file_type ) (not (shell_exec blkid_exec ))))
32047(typeattribute base_typeattr_653)
32048(typeattributeset base_typeattr_653 (and (domain ) (not (automotive_display_service ))))
32049(typeattribute base_typeattr_652)
32050(typeattributeset base_typeattr_652 (and (domain ) (not (audioserver ))))
32051(typeattribute base_typeattr_651)
32052(typeattributeset base_typeattr_651 (and (service_manager_type ) (not (apex_service default_android_service dnsresolver_service dumpstate_service incident_service installd_service lpdump_service mdns_service netd_service vold_service stats_service tracingproxy_service ))))
32053(typeattribute base_typeattr_650)
32054(typeattributeset base_typeattr_650 (not (art_exec_exec ) ))
32055(typeattribute base_typeattr_649)
32056(typeattributeset base_typeattr_649 (and (domain ) (not (artd ))))
32057(typeattribute base_typeattr_648)
32058(typeattributeset base_typeattr_648 (and (domain ) (not (app_zygote prng_seeder ))))
32059(typeattribute base_typeattr_647)
32060(typeattributeset base_typeattr_647 (and (domain ) (not (app_zygote logd system_server ))))
32061(typeattribute base_typeattr_646)
32062(typeattributeset base_typeattr_646 (and (service_manager_type ) (not (activity_service webviewupdate_service ))))
32063(typeattribute base_typeattr_645)
32064(typeattributeset base_typeattr_645 (and (domain ) (not (zygote ))))
32065(typeattribute base_typeattr_644)
32066(typeattributeset base_typeattr_644 (and (domain ) (not (crash_dump ))))
32067(typeattribute base_typeattr_643)
32068(typeattributeset base_typeattr_643 (and (domain ) (not (isolated_app ))))
32069(typeattribute base_typeattr_642)
32070(typeattributeset base_typeattr_642 (and (domain ) (not (app_zygote ))))
32071(typeattribute base_typeattr_641)
32072(typeattributeset base_typeattr_641 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 ))))
32073(typeattribute base_typeattr_640)
32074(typeattributeset base_typeattr_640 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (mediaprovider mediaprovider_app ))))
32075(typeattribute base_typeattr_639)
32076(typeattributeset base_typeattr_639 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (untrusted_app_25 ))))
32077(typeattribute base_typeattr_638)
32078(typeattributeset base_typeattr_638 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (mediaprovider_app ))))
32079(typeattribute base_typeattr_637)
32080(typeattributeset base_typeattr_637 (and (fs_type file_type ) (not (sdcard_type fuse user_profile_data_file media_rw_data_file app_data_file privapp_data_file app_exec_data_file ))))
32081(typeattribute base_typeattr_636)
32082(typeattributeset base_typeattr_636 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 ))))
32083(typeattribute base_typeattr_635)
32084(typeattributeset base_typeattr_635 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (untrusted_app_27 untrusted_app_25 ))))
32085(typeattribute base_typeattr_634)
32086(typeattributeset base_typeattr_634 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (runas_app untrusted_app_27 untrusted_app_25 ))))
32087(typeattribute base_typeattr_633)
32088(typeattributeset base_typeattr_633 (and (untrusted_app_all isolated_app_all ephemeral_app isolated_app isolated_compute_app mediaprovider untrusted_app untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 mediaprovider_app ) (not (mediaprovider ))))
32089(typeattribute base_typeattr_632)
32090(typeattributeset base_typeattr_632 (and (debugfs_type ) (not (debugfs_kcov ))))
32091(typeattribute base_typeattr_631)
32092(typeattributeset base_typeattr_631 (and (appdomain ) (not (untrusted_app_32 untrusted_app_30 untrusted_app_29 untrusted_app_27 untrusted_app_25 ))))
32093(typeattribute base_typeattr_630)
32094(typeattributeset base_typeattr_630 (and (appdomain ) (not (device_as_webcam ))))
32095(typeattribute base_typeattr_629)
32096(typeattributeset base_typeattr_629 (and (data_file_type ) (not (system_data_file apk_data_file dalvikcache_data_file apex_art_data_file ))))
32097(typeattribute base_typeattr_628)
32098(typeattributeset base_typeattr_628 (and (appdomain ) (not (mlstrustedsubject isolated_app_all sdk_sandbox_all ))))
32099(typeattribute base_typeattr_627)
32100(typeattributeset base_typeattr_627 (and (appdomain ) (not (isolated_app_all sdk_sandbox_all ))))
32101(typeattribute base_typeattr_626)
32102(typeattributeset base_typeattr_626 (and (appdomain ) (not (isolated_app_all ephemeral_app sdk_sandbox_all ))))
32103(typeattribute base_typeattr_625)
32104(typeattributeset base_typeattr_625 (and (appdomain ) (not (ephemeral_app sdk_sandbox_all ))))
32105(typeattribute base_typeattr_624)
32106(typeattributeset base_typeattr_624 (and (appdomain ) (not (mediaprovider_app ))))
32107(typeattribute base_typeattr_623)
32108(typeattributeset base_typeattr_623 (and (domain ) (not (appdomain crash_dump rs virtualizationmanager ))))
32109(typeattribute base_typeattr_622)
32110(typeattributeset base_typeattr_622 (and (appdomain ) (not (sdk_sandbox_all ))))
32111(typeattribute base_typeattr_621)
32112(typeattributeset base_typeattr_621 (and (appdomain ) (not (untrusted_app_all isolated_app_all ephemeral_app platform_app priv_app shell system_app sdk_sandbox_all ))))
32113(typeattribute base_typeattr_620)
32114(typeattributeset base_typeattr_620 (and (domain ) (not (apexd init otapreopt_chroot ))))
32115(typeattribute base_typeattr_619)
32116(typeattributeset base_typeattr_619 (and (domain ) (not (apexd init vold_prepare_subdirs ))))
32117(typeattribute base_typeattr_618)
32118(typeattributeset base_typeattr_618 (and (domain ) (not (apexd init kernel ))))
32119(typeattribute base_typeattr_617)
32120(typeattributeset base_typeattr_617 (and (domain ) (not (apexd init ))))
32121(typeattribute base_typeattr_616)
32122(typeattributeset base_typeattr_616 (and (domain ) (not (crash_dump shell ))))
32123(typeattribute base_typeattr_615)
32124(typeattributeset base_typeattr_615 (and (hal_lazy_test_client ) (not (halclientdomain ))))
32125(typeattribute base_typeattr_614)
32126(typeattributeset base_typeattr_614 (and (hal_lazy_test_server ) (not (hal_lazy_test ))))
32127(typeattribute base_typeattr_613)
32128(typeattributeset base_typeattr_613 (and (hal_lazy_test_server ) (not (halserverdomain ))))
32129(typeattribute base_typeattr_612)
32130(typeattributeset base_typeattr_612 (and (domain ) (not (wificond ))))
32131(typeattribute base_typeattr_611)
32132(typeattributeset base_typeattr_611 (and (domain ) (not (hal_bootctl_server hal_health_storage_server hal_keymaster_server system_suspend_server hwservicemanager keystore servicemanager system_server ))))
32133(typeattribute base_typeattr_610)
32134(typeattributeset base_typeattr_610 (and (domain ) (not (init kernel vold vold_prepare_subdirs ))))
32135(typeattribute base_typeattr_609)
32136(typeattributeset base_typeattr_609 (and (domain ) (not (kernel vold vold_prepare_subdirs ))))
32137(typeattribute base_typeattr_608)
32138(typeattributeset base_typeattr_608 (and (domain ) (not (init vold vold_prepare_subdirs ))))
32139(typeattribute base_typeattr_607)
32140(typeattributeset base_typeattr_607 (and (domain ) (not (vold vold_prepare_subdirs ))))
32141(typeattribute base_typeattr_606)
32142(typeattributeset base_typeattr_606 (and (sysfs_type ) (not (sysfs_batteryinfo ))))
32143(typeattribute base_typeattr_605)
32144(typeattributeset base_typeattr_605 (and (domain ) (not (virtual_touchpad ))))
32145(typeattribute base_typeattr_604)
32146(typeattributeset base_typeattr_604 (and (coredomain ) (not (init modprobe ))))
32147(typeattribute base_typeattr_603)
32148(typeattributeset base_typeattr_603 (and (domain ) (not (init logd prng_seeder su vendor_init ))))
32149(typeattribute base_typeattr_602)
32150(typeattributeset base_typeattr_602 (and (sysfs_type ) (not (sysfs_usermodehelper ))))
32151(typeattribute base_typeattr_601)
32152(typeattributeset base_typeattr_601 (and (fs_type ) (not (bpffs_type contextmount_type fusefs_type sdcard_type rootfs proc_uid_time_in_state proc_uid_concurrent_active_time proc_uid_concurrent_policy_time ))))
32153(typeattribute base_typeattr_600)
32154(typeattributeset base_typeattr_600 (and (fs_type ) (not (bpffs_type contextmount_type fusefs_type debugfs_type sdcard_type keychord_device rootfs proc_uid_time_in_state proc_uid_concurrent_active_time proc_uid_concurrent_policy_time ))))
32155(typeattribute base_typeattr_599)
32156(typeattributeset base_typeattr_599 (and (file_type ) (not (bpffs_type exec_type core_data_file_type system_file_type system_dlkm_file_type vendor_file_type gsi_metadata_file_type vold_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file userspace_reboot_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file mnt_product_file ))))
32157(typeattribute base_typeattr_598)
32158(typeattributeset base_typeattr_598 (and (file_type ) (not (bpffs_type exec_type core_data_file_type system_file_type system_dlkm_file_type vendor_file_type gsi_metadata_file_type unlabeled vold_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file userspace_reboot_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file apex_mnt_dir ))))
32159(typeattribute base_typeattr_597)
32160(typeattributeset base_typeattr_597 (and (file_type ) (not (bpffs_type exec_type core_data_file_type system_file_type system_dlkm_file_type vendor_file_type gsi_metadata_file_type unlabeled vold_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file userspace_reboot_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file ))))
32161(typeattribute base_typeattr_596)
32162(typeattributeset base_typeattr_596 (and (file_type ) (not (bpffs_type exec_type core_data_file_type system_file_type system_dlkm_file_type vendor_file_type debugfs_type gsi_metadata_file_type unlabeled vold_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file userspace_reboot_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file runtime_event_log_tags_file apex_info_file ))))
32163(typeattribute base_typeattr_595)
32164(typeattributeset base_typeattr_595 (and (file_type ) (not (bpffs_type exec_type core_data_file_type system_file_type system_dlkm_file_type vendor_file_type gsi_metadata_file_type unlabeled vold_metadata_file password_slot_metadata_file apex_metadata_file ota_metadata_file userspace_reboot_metadata_file aconfig_storage_metadata_file aconfig_storage_flags_metadata_file mnt_product_file ))))
32165(typeattribute base_typeattr_594)
32166(typeattributeset base_typeattr_594 (and (domain ) (not (update_engine ))))
32167(typeattribute base_typeattr_593)
32168(typeattributeset base_typeattr_593 (and (vendor_file_type ) (not (vendor_app_file vendor_overlay_file ))))
32169(typeattribute base_typeattr_592)
32170(typeattributeset base_typeattr_592 (and (service_manager_type ) (not (apex_service default_android_service dnsresolver_service gatekeeper_service incident_service installd_service lpdump_service mdns_service netd_service virtual_touchpad_service vold_service ))))
32171(typeattribute base_typeattr_591)
32172(typeattributeset base_typeattr_591 (and (fs_type file_type ) (not (toolbox_exec ))))
32173(typeattribute base_typeattr_590)
32174(typeattributeset base_typeattr_590 (and (domain ) (not (system_suspend_server ))))
32175(typeattribute base_typeattr_589)
32176(typeattributeset base_typeattr_589 (and (domain ) (not (system_suspend_internal_server atrace dumpstate system_server traceur_app ))))
32177(typeattribute base_typeattr_588)
32178(typeattributeset base_typeattr_588 (and (domain ) (not (system_suspend_internal_server ))))
32179(typeattribute base_typeattr_587)
32180(typeattributeset base_typeattr_587 (and (domain ) (not (init shell system_server vendor_init ))))
32181(typeattribute base_typeattr_586)
32182(typeattributeset base_typeattr_586 (and (domain ) (not (init statsd system_server vold ))))
32183(typeattribute base_typeattr_585)
32184(typeattributeset base_typeattr_585 (and (domain ) (not (init statsd vold ))))
32185(typeattribute base_typeattr_584)
32186(typeattributeset base_typeattr_584 (and (domain ) (not (stats_service_server ))))
32187(typeattribute base_typeattr_583)
32188(typeattributeset base_typeattr_583 (and (service_manager_type ) (not (apex_service default_android_service dnsresolver_service gatekeeper_service incident_service installd_service mdns_service netd_service system_suspend_control_internal_service system_suspend_control_service virtual_touchpad_service vold_service hal_keymint_service hal_secureclock_service hal_sharedsecret_service ))))
32189(typeattribute base_typeattr_582)
32190(typeattributeset base_typeattr_582 (and (fs_type file_type ) (not (sgdisk_exec ))))
32191(typeattribute base_typeattr_581)
32192(typeattributeset base_typeattr_581 (and (domain ) (not (servicemanager ))))
32193(typeattribute base_typeattr_580)
32194(typeattributeset base_typeattr_580 (and (domain ) (not (hwservicemanager init vendor_init vndservicemanager ))))
32195(typeattribute base_typeattr_579)
32196(typeattributeset base_typeattr_579 (not (service_manager_type vndservice_manager_type ) ))
32197(typeattribute base_typeattr_578)
32198(typeattributeset base_typeattr_578 (and (domain ) (not (sensor_service_server ))))
32199(typeattribute base_typeattr_577)
32200(typeattributeset base_typeattr_577 (and (domain ) (not (scheduler_service_server ))))
32201(typeattribute base_typeattr_576)
32202(typeattributeset base_typeattr_576 (and (appdomain ) (not (system_app ))))
32203(typeattribute base_typeattr_575)
32204(typeattributeset base_typeattr_575 (and (domain ) (not (remote_provisioning_service_server ))))
32205(typeattribute base_typeattr_574)
32206(typeattributeset base_typeattr_574 (and (data_file_type ) (not (cache_file cache_recovery_file ))))
32207(typeattribute base_typeattr_573)
32208(typeattributeset base_typeattr_573 (and (domain ) (not (radio ))))
32209(typeattribute base_typeattr_572)
32210(typeattributeset base_typeattr_572 (and (coredomain ) (not (dumpstate init ))))
32211(typeattribute base_typeattr_571)
32212(typeattributeset base_typeattr_571 (and (domain ) (not (recovery update_engine ))))
32213(typeattribute base_typeattr_570)
32214(typeattributeset base_typeattr_570 (and (domain ) (not (performanced ))))
32215(typeattribute base_typeattr_569)
32216(typeattributeset base_typeattr_569 (and (domain ) (not (dumpstate netd netutils_wrapper network_stack system_server ))))
32217(typeattribute base_typeattr_568)
32218(typeattributeset base_typeattr_568 (and (domain ) (not (netd ))))
32219(typeattribute base_typeattr_567)
32220(typeattributeset base_typeattr_567 (and (domain ) (not (mediaserver ))))
32221(typeattribute base_typeattr_566)
32222(typeattributeset base_typeattr_566 (and (domain ) (not (mediametrics ))))
32223(typeattribute base_typeattr_565)
32224(typeattributeset base_typeattr_565 (and (domain ) (not (mediaextractor ))))
32225(typeattribute base_typeattr_564)
32226(typeattributeset base_typeattr_564 (and (domain ) (not (mediadrmserver ))))
32227(typeattribute base_typeattr_563)
32228(typeattributeset base_typeattr_563 (and (domain ) (not (init logd ))))
32229(typeattribute base_typeattr_562)
32230(typeattributeset base_typeattr_562 (and (app_data_file_type system_data_file packages_list_file ) (not (shell_data_file ))))
32231(typeattribute base_typeattr_561)
32232(typeattributeset base_typeattr_561 (and (domain ) (not (init keystore ))))
32233(typeattribute base_typeattr_560)
32234(typeattributeset base_typeattr_560 (and (domain ) (not (keystore ))))
32235(typeattribute base_typeattr_559)
32236(typeattributeset base_typeattr_559 (and (domain ) (not (servicemanager system_server ))))
32237(typeattribute base_typeattr_558)
32238(typeattributeset base_typeattr_558 (and (domain ) (not (dumpstate servicemanager system_server ))))
32239(typeattribute base_typeattr_557)
32240(typeattributeset base_typeattr_557 (and (domain ) (not (dumpstate installd system_server ))))
32241(typeattribute base_typeattr_556)
32242(typeattributeset base_typeattr_556 (and (domain ) (not (installd ))))
32243(typeattribute base_typeattr_555)
32244(typeattributeset base_typeattr_555 (and (domain ) (not (init toolbox vendor_init vold ))))
32245(typeattribute base_typeattr_554)
32246(typeattributeset base_typeattr_554 (and (fs_type file_type ) (not (init_exec ))))
32247(typeattribute base_typeattr_553)
32248(typeattributeset base_typeattr_553 (and (fs_type ) (not (bpffs_type contextmount_type fusefs_type sdcard_type rootfs ))))
32249(typeattribute base_typeattr_552)
32250(typeattributeset base_typeattr_552 (and (fs_type ) (not (bpffs_type contextmount_type fusefs_type proc_type sysfs_type debugfs_type sdcard_type keychord_device rootfs ))))
32251(typeattribute base_typeattr_551)
32252(typeattributeset base_typeattr_551 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type app_data_file privapp_data_file ))))
32253(typeattribute base_typeattr_550)
32254(typeattributeset base_typeattr_550 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type shell_data_file nativetest_data_file apex_mnt_dir credstore_data_file keystore_data_file vold_data_file gsi_data_file app_data_file privapp_data_file system_app_data_file misc_logd_file ))))
32255(typeattribute base_typeattr_549)
32256(typeattributeset base_typeattr_549 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type shell_data_file nativetest_data_file credstore_data_file keystore_data_file vold_data_file gsi_data_file app_data_file privapp_data_file system_app_data_file misc_logd_file ))))
32257(typeattribute base_typeattr_548)
32258(typeattributeset base_typeattr_548 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type debugfs_type runtime_event_log_tags_file shell_data_file nativetest_data_file apex_info_file credstore_data_file keystore_data_file vold_data_file gsi_data_file app_data_file privapp_data_file system_app_data_file misc_logd_file ))))
32259(typeattribute base_typeattr_547)
32260(typeattributeset base_typeattr_547 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type system_userdir_file vendor_userdir_file shell_data_file nativetest_data_file credstore_data_file keystore_data_file media_userdir_file vold_data_file app_data_file privapp_data_file system_app_data_file misc_logd_file ))))
32261(typeattribute base_typeattr_546)
32262(typeattributeset base_typeattr_546 (and (file_type ) (not (bpffs_type exec_type system_file_type system_dlkm_file_type vendor_file_type nativetest_data_file app_data_file privapp_data_file system_app_data_file misc_logd_file ))))
32263(typeattribute base_typeattr_545)
32264(typeattributeset base_typeattr_545 (and (fs_type ) (not (debugfs_type ))))
32265(typeattribute base_typeattr_544)
32266(typeattributeset base_typeattr_544 (and (domain ) (not (idmap ))))
32267(typeattribute base_typeattr_543)
32268(typeattributeset base_typeattr_543 (not (hwservice_manager_type ) ))
32269(typeattribute base_typeattr_542)
32270(typeattributeset base_typeattr_542 (and (domain ) (not (hal_wifi_supplicant_client hal_wifi_supplicant_server atrace shell system_app traceur_app ))))
32271(typeattribute base_typeattr_541)
32272(typeattributeset base_typeattr_541 (and (domain ) (not (hal_wifi_supplicant_client hal_wifi_supplicant_server ))))
32273(typeattribute base_typeattr_540)
32274(typeattributeset base_typeattr_540 (and (domain ) (not (hal_wifi_supplicant_server ))))
32275(typeattribute base_typeattr_539)
32276(typeattributeset base_typeattr_539 (and (domain ) (not (hal_wifi_hostapd_client hal_wifi_hostapd_server atrace shell system_app traceur_app ))))
32277(typeattribute base_typeattr_538)
32278(typeattributeset base_typeattr_538 (and (domain ) (not (hal_wifi_hostapd_client hal_wifi_hostapd_server ))))
32279(typeattribute base_typeattr_537)
32280(typeattributeset base_typeattr_537 (and (domain ) (not (hal_wifi_hostapd_server ))))
32281(typeattribute base_typeattr_536)
32282(typeattributeset base_typeattr_536 (and (domain ) (not (hal_wifi_client hal_wifi_server atrace shell system_app traceur_app ))))
32283(typeattribute base_typeattr_535)
32284(typeattributeset base_typeattr_535 (and (domain ) (not (hal_wifi_client hal_wifi_server ))))
32285(typeattribute base_typeattr_534)
32286(typeattributeset base_typeattr_534 (and (domain ) (not (hal_wifi_server ))))
32287(typeattribute base_typeattr_533)
32288(typeattributeset base_typeattr_533 (and (domain ) (not (hal_weaver_client hal_weaver_server atrace shell system_app traceur_app ))))
32289(typeattribute base_typeattr_532)
32290(typeattributeset base_typeattr_532 (and (domain ) (not (hal_weaver_client hal_weaver_server ))))
32291(typeattribute base_typeattr_531)
32292(typeattributeset base_typeattr_531 (and (domain ) (not (hal_weaver_server ))))
32293(typeattribute base_typeattr_530)
32294(typeattributeset base_typeattr_530 (and (domain ) (not (hal_vr_client hal_vr_server ))))
32295(typeattribute base_typeattr_529)
32296(typeattributeset base_typeattr_529 (and (domain ) (not (hal_vr_server ))))
32297(typeattribute base_typeattr_528)
32298(typeattributeset base_typeattr_528 (and (domain ) (not (hal_vibrator_client hal_vibrator_server atrace shell system_app traceur_app ))))
32299(typeattribute base_typeattr_527)
32300(typeattributeset base_typeattr_527 (and (domain ) (not (hal_vibrator_client hal_vibrator_server ))))
32301(typeattribute base_typeattr_526)
32302(typeattributeset base_typeattr_526 (and (domain ) (not (hal_vibrator_server ))))
32303(typeattribute base_typeattr_525)
32304(typeattributeset base_typeattr_525 (and (domain ) (not (hal_vehicle_client hal_vehicle_server atrace shell system_app traceur_app ))))
32305(typeattribute base_typeattr_524)
32306(typeattributeset base_typeattr_524 (and (domain ) (not (hal_vehicle_client hal_vehicle_server ))))
32307(typeattribute base_typeattr_523)
32308(typeattributeset base_typeattr_523 (and (domain ) (not (hal_vehicle_server ))))
32309(typeattribute base_typeattr_522)
32310(typeattributeset base_typeattr_522 (and (domain ) (not (hal_uwb_client hal_uwb_server atrace shell system_app traceur_app ))))
32311(typeattribute base_typeattr_521)
32312(typeattributeset base_typeattr_521 (and (domain ) (not (hal_uwb_server ))))
32313(typeattribute base_typeattr_520)
32314(typeattributeset base_typeattr_520 (and (domain ) (not (hal_usb_gadget_client hal_usb_gadget_server ))))
32315(typeattribute base_typeattr_519)
32316(typeattributeset base_typeattr_519 (and (domain ) (not (hal_usb_gadget_client hal_usb_gadget_server atrace shell system_app traceur_app ))))
32317(typeattribute base_typeattr_518)
32318(typeattributeset base_typeattr_518 (and (domain ) (not (hal_usb_gadget_server ))))
32319(typeattribute base_typeattr_517)
32320(typeattributeset base_typeattr_517 (and (domain ) (not (hal_usb_client hal_usb_server ))))
32321(typeattribute base_typeattr_516)
32322(typeattributeset base_typeattr_516 (and (domain ) (not (hal_usb_client hal_usb_server atrace shell system_app traceur_app ))))
32323(typeattribute base_typeattr_515)
32324(typeattributeset base_typeattr_515 (and (domain ) (not (hal_usb_server ))))
32325(typeattribute base_typeattr_514)
32326(typeattributeset base_typeattr_514 (and (domain ) (not (hal_tv_tuner_client hal_tv_tuner_server atrace shell system_app traceur_app ))))
32327(typeattribute base_typeattr_513)
32328(typeattributeset base_typeattr_513 (and (domain ) (not (hal_tv_tuner_client hal_tv_tuner_server ))))
32329(typeattribute base_typeattr_512)
32330(typeattributeset base_typeattr_512 (and (domain ) (not (hal_tv_tuner_server ))))
32331(typeattribute base_typeattr_511)
32332(typeattributeset base_typeattr_511 (and (domain ) (not (hal_tv_input_client hal_tv_input_server atrace shell system_app traceur_app ))))
32333(typeattribute base_typeattr_510)
32334(typeattributeset base_typeattr_510 (and (domain ) (not (hal_tv_input_client hal_tv_input_server ))))
32335(typeattribute base_typeattr_509)
32336(typeattributeset base_typeattr_509 (and (domain ) (not (hal_tv_input_server ))))
32337(typeattribute base_typeattr_508)
32338(typeattributeset base_typeattr_508 (and (domain ) (not (hal_tv_hdmi_earc_client hal_tv_hdmi_earc_server atrace shell system_app traceur_app ))))
32339(typeattribute base_typeattr_507)
32340(typeattributeset base_typeattr_507 (and (domain ) (not (hal_tv_hdmi_earc_server ))))
32341(typeattribute base_typeattr_506)
32342(typeattributeset base_typeattr_506 (and (domain ) (not (hal_tv_hdmi_connection_client hal_tv_hdmi_connection_server atrace shell system_app traceur_app ))))
32343(typeattribute base_typeattr_505)
32344(typeattributeset base_typeattr_505 (and (domain ) (not (hal_tv_hdmi_connection_server ))))
32345(typeattribute base_typeattr_504)
32346(typeattributeset base_typeattr_504 (and (domain ) (not (hal_tv_hdmi_cec_client hal_tv_hdmi_cec_server atrace shell system_app traceur_app ))))
32347(typeattribute base_typeattr_503)
32348(typeattributeset base_typeattr_503 (and (domain ) (not (hal_tv_hdmi_cec_server ))))
32349(typeattribute base_typeattr_502)
32350(typeattributeset base_typeattr_502 (and (domain ) (not (hal_tv_cec_client hal_tv_cec_server ))))
32351(typeattribute base_typeattr_501)
32352(typeattributeset base_typeattr_501 (and (domain ) (not (hal_tv_cec_server ))))
32353(typeattribute base_typeattr_500)
32354(typeattributeset base_typeattr_500 (and (domain ) (not (hal_threadnetwork_client hal_threadnetwork_server atrace shell system_app traceur_app ))))
32355(typeattribute base_typeattr_499)
32356(typeattributeset base_typeattr_499 (and (domain ) (not (hal_threadnetwork_server ))))
32357(typeattribute base_typeattr_498)
32358(typeattributeset base_typeattr_498 (and (domain ) (not (hal_thermal_client hal_thermal_server atrace shell system_app traceur_app ))))
32359(typeattribute base_typeattr_497)
32360(typeattributeset base_typeattr_497 (and (domain ) (not (hal_thermal_client hal_thermal_server ))))
32361(typeattribute base_typeattr_496)
32362(typeattributeset base_typeattr_496 (and (domain ) (not (hal_thermal_server ))))
32363(typeattribute base_typeattr_495)
32364(typeattributeset base_typeattr_495 (and (domain ) (not (hal_tetheroffload_client hal_tetheroffload_server atrace shell system_app traceur_app ))))
32365(typeattribute base_typeattr_494)
32366(typeattributeset base_typeattr_494 (and (domain ) (not (hal_tetheroffload_client hal_tetheroffload_server ))))
32367(typeattribute base_typeattr_493)
32368(typeattributeset base_typeattr_493 (and (domain ) (not (hal_tetheroffload_server ))))
32369(typeattribute base_typeattr_492)
32370(typeattributeset base_typeattr_492 (and (domain ) (not (hal_telephony_client hal_telephony_server atrace shell system_app traceur_app ))))
32371(typeattribute base_typeattr_491)
32372(typeattributeset base_typeattr_491 (and (domain ) (not (hal_telephony_client hal_telephony_server ))))
32373(typeattribute base_typeattr_490)
32374(typeattributeset base_typeattr_490 (and (domain ) (not (hal_telephony_server ))))
32375(typeattribute base_typeattr_489)
32376(typeattributeset base_typeattr_489 (and (domain ) (not (hal_sensors_client hal_sensors_server ))))
32377(typeattribute base_typeattr_488)
32378(typeattributeset base_typeattr_488 (and (domain ) (not (hal_sensors_server ))))
32379(typeattribute base_typeattr_487)
32380(typeattributeset base_typeattr_487 (and (domain ) (not (hal_secure_element_client hal_secure_element_server atrace shell system_app traceur_app ))))
32381(typeattribute base_typeattr_486)
32382(typeattributeset base_typeattr_486 (and (domain ) (not (hal_secure_element_client hal_secure_element_server ))))
32383(typeattribute base_typeattr_485)
32384(typeattributeset base_typeattr_485 (and (domain ) (not (hal_secure_element_server ))))
32385(typeattribute base_typeattr_484)
32386(typeattributeset base_typeattr_484 (and (domain ) (not (hal_secretkeeper_client hal_secretkeeper_server atrace shell system_app traceur_app ))))
32387(typeattribute base_typeattr_483)
32388(typeattributeset base_typeattr_483 (and (domain ) (not (hal_secretkeeper_server ))))
32389(typeattribute base_typeattr_482)
32390(typeattributeset base_typeattr_482 (and (domain ) (not (hal_remotelyprovisionedcomponent_avf_client hal_remotelyprovisionedcomponent_avf_server atrace shell system_app traceur_app ))))
32391(typeattribute base_typeattr_481)
32392(typeattributeset base_typeattr_481 (and (domain ) (not (hal_remotelyprovisionedcomponent_avf_server ))))
32393(typeattribute base_typeattr_480)
32394(typeattributeset base_typeattr_480 (and (domain ) (not (hal_remoteaccess_client hal_remoteaccess_server atrace shell system_app traceur_app ))))
32395(typeattribute base_typeattr_479)
32396(typeattributeset base_typeattr_479 (and (domain ) (not (hal_remoteaccess_server ))))
32397(typeattribute base_typeattr_478)
32398(typeattributeset base_typeattr_478 (and (domain ) (not (hal_rebootescrow_client hal_rebootescrow_server atrace shell system_app traceur_app ))))
32399(typeattribute base_typeattr_477)
32400(typeattributeset base_typeattr_477 (and (domain ) (not (hal_rebootescrow_server ))))
32401(typeattribute base_typeattr_476)
32402(typeattributeset base_typeattr_476 (and (domain ) (not (hal_power_stats_client hal_power_stats_server atrace shell system_app traceur_app ))))
32403(typeattribute base_typeattr_475)
32404(typeattributeset base_typeattr_475 (and (domain ) (not (hal_power_stats_client hal_power_stats_server ))))
32405(typeattribute base_typeattr_474)
32406(typeattributeset base_typeattr_474 (and (domain ) (not (hal_power_stats_server ))))
32407(typeattribute base_typeattr_473)
32408(typeattributeset base_typeattr_473 (and (domain ) (not (hal_power_client hal_power_server atrace shell system_app traceur_app ))))
32409(typeattribute base_typeattr_472)
32410(typeattributeset base_typeattr_472 (and (domain ) (not (hal_power_client hal_power_server ))))
32411(typeattribute base_typeattr_471)
32412(typeattributeset base_typeattr_471 (and (domain ) (not (hal_power_server ))))
32413(typeattribute base_typeattr_470)
32414(typeattributeset base_typeattr_470 (and (domain ) (not (hal_omx_client hal_omx_server ))))
32415(typeattribute base_typeattr_469)
32416(typeattributeset base_typeattr_469 (and (domain ) (not (hal_omx_server ))))
32417(typeattribute base_typeattr_468)
32418(typeattributeset base_typeattr_468 (and (domain ) (not (hal_oemlock_client hal_oemlock_server atrace shell system_app traceur_app ))))
32419(typeattribute base_typeattr_467)
32420(typeattributeset base_typeattr_467 (and (domain ) (not (hal_oemlock_client hal_oemlock_server ))))
32421(typeattribute base_typeattr_466)
32422(typeattributeset base_typeattr_466 (and (domain ) (not (hal_oemlock_server ))))
32423(typeattribute base_typeattr_465)
32424(typeattributeset base_typeattr_465 (and (domain ) (not (hal_nlinterceptor_client hal_nlinterceptor_server atrace shell system_app traceur_app ))))
32425(typeattribute base_typeattr_464)
32426(typeattributeset base_typeattr_464 (and (domain ) (not (hal_nlinterceptor_server ))))
32427(typeattribute base_typeattr_463)
32428(typeattributeset base_typeattr_463 (and (domain ) (not (hal_nfc_client hal_nfc_server atrace shell system_app traceur_app ))))
32429(typeattribute base_typeattr_462)
32430(typeattributeset base_typeattr_462 (and (domain ) (not (hal_nfc_client hal_nfc_server ))))
32431(typeattribute base_typeattr_461)
32432(typeattributeset base_typeattr_461 (and (domain ) (not (hal_nfc_server ))))
32433(typeattribute base_typeattr_460)
32434(typeattributeset base_typeattr_460 (and (fs_type file_type ) (not (shell_exec toolbox_exec ))))
32435(typeattribute base_typeattr_459)
32436(typeattributeset base_typeattr_459 (and (halserverdomain ) (not (hal_dumpstate_server hal_telephony_server ))))
32437(typeattribute base_typeattr_458)
32438(typeattributeset base_typeattr_458 (and (halserverdomain ) (not (hal_automotive_socket_exemption hal_bluetooth_server hal_can_controller_server hal_nlinterceptor_server hal_telephony_server hal_tetheroffload_server hal_wifi_server hal_wifi_hostapd_server hal_wifi_supplicant_server ))))
32439(typeattribute base_typeattr_457)
32440(typeattributeset base_typeattr_457 (and (halserverdomain ) (not (hal_automotive_socket_exemption hal_bluetooth_server hal_can_controller_server hal_nlinterceptor_server hal_telephony_server hal_tetheroffload_server hal_uwb_server hal_uwb_vendor_server hal_wifi_server hal_wifi_hostapd_server hal_wifi_supplicant_server ))))
32441(typeattribute base_typeattr_456)
32442(typeattributeset base_typeattr_456 (and (halserverdomain ) (not (hal_bluetooth_server hal_can_controller_server hal_nlinterceptor_server hal_telephony_server hal_uwb_server hal_uwb_vendor_server hal_wifi_server hal_wifi_hostapd_server hal_wifi_supplicant_server ))))
32443(typeattribute base_typeattr_455)
32444(typeattributeset base_typeattr_455 (and (domain ) (not (hal_neuralnetworks_client hal_neuralnetworks_server atrace shell system_app traceur_app ))))
32445(typeattribute base_typeattr_454)
32446(typeattributeset base_typeattr_454 (and (domain ) (not (hal_neuralnetworks_client hal_neuralnetworks_server ))))
32447(typeattribute base_typeattr_453)
32448(typeattributeset base_typeattr_453 (and (domain ) (not (hal_neuralnetworks_server ))))
32449(typeattribute base_typeattr_452)
32450(typeattributeset base_typeattr_452 (and (domain ) (not (hal_memtrack_client hal_memtrack_server atrace shell system_app traceur_app ))))
32451(typeattribute base_typeattr_451)
32452(typeattributeset base_typeattr_451 (and (domain ) (not (hal_memtrack_client hal_memtrack_server ))))
32453(typeattribute base_typeattr_450)
32454(typeattributeset base_typeattr_450 (and (domain ) (not (hal_memtrack_server ))))
32455(typeattribute base_typeattr_449)
32456(typeattributeset base_typeattr_449 (and (domain ) (not (hal_macsec_client hal_macsec_server atrace shell system_app traceur_app ))))
32457(typeattribute base_typeattr_448)
32458(typeattributeset base_typeattr_448 (and (domain ) (not (hal_macsec_server ))))
32459(typeattribute base_typeattr_447)
32460(typeattributeset base_typeattr_447 (and (domain ) (not (hal_lowpan_server init ueventd ))))
32461(typeattribute base_typeattr_446)
32462(typeattributeset base_typeattr_446 (and (domain ) (not (hal_lowpan_client hal_lowpan_server ))))
32463(typeattribute base_typeattr_445)
32464(typeattributeset base_typeattr_445 (and (domain ) (not (hal_lowpan_server ))))
32465(typeattribute base_typeattr_444)
32466(typeattributeset base_typeattr_444 (and (domain ) (not (hal_light_client hal_light_server atrace shell system_app traceur_app ))))
32467(typeattribute base_typeattr_443)
32468(typeattributeset base_typeattr_443 (and (domain ) (not (hal_light_client hal_light_server ))))
32469(typeattribute base_typeattr_442)
32470(typeattributeset base_typeattr_442 (and (domain ) (not (hal_light_server ))))
32471(typeattribute base_typeattr_441)
32472(typeattributeset base_typeattr_441 (and (domain ) (not (hal_keymint_client hal_keymint_server atrace shell system_app traceur_app ))))
32473(typeattribute base_typeattr_440)
32474(typeattributeset base_typeattr_440 (and (domain ) (not (hal_keymint_server ))))
32475(typeattribute base_typeattr_439)
32476(typeattributeset base_typeattr_439 (and (domain ) (not (hal_keymaster_client hal_keymaster_server ))))
32477(typeattribute base_typeattr_438)
32478(typeattributeset base_typeattr_438 (and (domain ) (not (hal_keymaster_server ))))
32479(typeattribute base_typeattr_437)
32480(typeattributeset base_typeattr_437 (and (domain ) (not (hal_ivn_client hal_ivn_server atrace shell system_app traceur_app ))))
32481(typeattribute base_typeattr_436)
32482(typeattributeset base_typeattr_436 (and (domain ) (not (hal_ivn_server ))))
32483(typeattribute base_typeattr_435)
32484(typeattributeset base_typeattr_435 (and (domain ) (not (hal_ir_client hal_ir_server ))))
32485(typeattribute base_typeattr_434)
32486(typeattributeset base_typeattr_434 (and (domain ) (not (hal_ir_client hal_ir_server atrace shell system_app traceur_app ))))
32487(typeattribute base_typeattr_433)
32488(typeattributeset base_typeattr_433 (and (domain ) (not (hal_ir_server ))))
32489(typeattribute base_typeattr_432)
32490(typeattributeset base_typeattr_432 (and (domain ) (not (hal_input_processor_client hal_input_processor_server atrace shell system_app traceur_app ))))
32491(typeattribute base_typeattr_431)
32492(typeattributeset base_typeattr_431 (and (domain ) (not (hal_input_processor_server ))))
32493(typeattribute base_typeattr_430)
32494(typeattributeset base_typeattr_430 (and (domain ) (not (hal_input_classifier_client hal_input_classifier_server ))))
32495(typeattribute base_typeattr_429)
32496(typeattributeset base_typeattr_429 (and (domain ) (not (hal_input_classifier_server ))))
32497(typeattribute base_typeattr_428)
32498(typeattributeset base_typeattr_428 (and (domain ) (not (hal_identity_client hal_identity_server atrace shell system_app traceur_app ))))
32499(typeattribute base_typeattr_427)
32500(typeattributeset base_typeattr_427 (and (domain ) (not (hal_identity_server ))))
32501(typeattribute base_typeattr_426)
32502(typeattributeset base_typeattr_426 (and (domain ) (not (hal_health_storage_client hal_health_storage_server atrace shell system_app traceur_app ))))
32503(typeattribute base_typeattr_425)
32504(typeattributeset base_typeattr_425 (and (domain ) (not (hal_health_storage_client hal_health_storage_server ))))
32505(typeattribute base_typeattr_424)
32506(typeattributeset base_typeattr_424 (and (domain ) (not (hal_health_storage_server ))))
32507(typeattribute base_typeattr_423)
32508(typeattributeset base_typeattr_423 (and (domain ) (not (hal_health_client hal_health_server atrace shell system_app traceur_app ))))
32509(typeattribute base_typeattr_422)
32510(typeattributeset base_typeattr_422 (and (domain ) (not (hal_health_client hal_health_server ))))
32511(typeattribute base_typeattr_421)
32512(typeattributeset base_typeattr_421 (and (domain ) (not (hal_health_server ))))
32513(typeattribute base_typeattr_420)
32514(typeattributeset base_typeattr_420 (and (domain ) (not (hal_graphics_composer_client hal_graphics_composer_server atrace shell system_app traceur_app ))))
32515(typeattribute base_typeattr_419)
32516(typeattributeset base_typeattr_419 (and (domain ) (not (hal_graphics_composer_client hal_graphics_composer_server ))))
32517(typeattribute base_typeattr_418)
32518(typeattributeset base_typeattr_418 (and (domain ) (not (hal_graphics_composer_server ))))
32519(typeattribute base_typeattr_417)
32520(typeattributeset base_typeattr_417 (and (domain ) (not (hal_graphics_allocator_client hal_graphics_allocator_server atrace shell system_app traceur_app ))))
32521(typeattribute base_typeattr_416)
32522(typeattributeset base_typeattr_416 (and (domain ) (not (hal_graphics_allocator_client hal_graphics_allocator_server ))))
32523(typeattribute base_typeattr_415)
32524(typeattributeset base_typeattr_415 (and (domain ) (not (hal_graphics_allocator_server ))))
32525(typeattribute base_typeattr_414)
32526(typeattributeset base_typeattr_414 (and (domain ) (not (hal_gnss_client hal_gnss_server atrace shell system_app traceur_app ))))
32527(typeattribute base_typeattr_413)
32528(typeattributeset base_typeattr_413 (and (domain ) (not (hal_gnss_client hal_gnss_server ))))
32529(typeattribute base_typeattr_412)
32530(typeattributeset base_typeattr_412 (and (domain ) (not (hal_gnss_server ))))
32531(typeattribute base_typeattr_411)
32532(typeattributeset base_typeattr_411 (and (domain ) (not (hal_gatekeeper_client hal_gatekeeper_server atrace shell system_app traceur_app ))))
32533(typeattribute base_typeattr_410)
32534(typeattributeset base_typeattr_410 (and (domain ) (not (hal_gatekeeper_client hal_gatekeeper_server ))))
32535(typeattribute base_typeattr_409)
32536(typeattributeset base_typeattr_409 (and (domain ) (not (hal_gatekeeper_server ))))
32537(typeattribute base_typeattr_408)
32538(typeattributeset base_typeattr_408 (and (domain ) (not (hal_fingerprint_client hal_fingerprint_server atrace shell system_app traceur_app ))))
32539(typeattribute base_typeattr_407)
32540(typeattributeset base_typeattr_407 (and (domain ) (not (hal_fingerprint_client hal_fingerprint_server ))))
32541(typeattribute base_typeattr_406)
32542(typeattributeset base_typeattr_406 (and (domain ) (not (hal_fingerprint_server ))))
32543(typeattribute base_typeattr_405)
32544(typeattributeset base_typeattr_405 (and (domain ) (not (hal_fastboot_client hal_fastboot_server atrace shell system_app traceur_app ))))
32545(typeattribute base_typeattr_404)
32546(typeattributeset base_typeattr_404 (and (domain ) (not (hal_fastboot_server ))))
32547(typeattribute base_typeattr_403)
32548(typeattributeset base_typeattr_403 (and (domain ) (not (hal_face_client hal_face_server atrace shell system_app traceur_app ))))
32549(typeattribute base_typeattr_402)
32550(typeattributeset base_typeattr_402 (and (domain ) (not (hal_face_client hal_face_server ))))
32551(typeattribute base_typeattr_401)
32552(typeattributeset base_typeattr_401 (and (domain ) (not (hal_face_server ))))
32553(typeattribute base_typeattr_400)
32554(typeattributeset base_typeattr_400 (and (domain ) (not (hal_evs_client hal_evs_server atrace shell system_app traceur_app ))))
32555(typeattribute base_typeattr_399)
32556(typeattributeset base_typeattr_399 (and (domain ) (not (hal_evs_server ))))
32557(typeattribute base_typeattr_398)
32558(typeattributeset base_typeattr_398 (and (domain ) (not (hal_evs_server evsmanagerd ))))
32559(typeattribute base_typeattr_397)
32560(typeattributeset base_typeattr_397 (and (domain ) (not (hal_dumpstate_client hal_dumpstate_server atrace shell system_app traceur_app ))))
32561(typeattribute base_typeattr_396)
32562(typeattributeset base_typeattr_396 (and (domain ) (not (hal_dumpstate_client hal_dumpstate_server ))))
32563(typeattribute base_typeattr_395)
32564(typeattributeset base_typeattr_395 (and (domain ) (not (hal_dumpstate_server ))))
32565(typeattribute base_typeattr_394)
32566(typeattributeset base_typeattr_394 (and (domain ) (not (hal_drm_client hal_drm_server atrace shell system_app traceur_app ))))
32567(typeattribute base_typeattr_393)
32568(typeattributeset base_typeattr_393 (and (domain ) (not (hal_drm_client hal_drm_server ))))
32569(typeattribute base_typeattr_392)
32570(typeattributeset base_typeattr_392 (and (domain ) (not (hal_drm_server ))))
32571(typeattribute base_typeattr_391)
32572(typeattributeset base_typeattr_391 (and (domain ) (not (hal_contexthub_client hal_contexthub_server ))))
32573(typeattribute base_typeattr_390)
32574(typeattributeset base_typeattr_390 (and (domain ) (not (hal_contexthub_server ))))
32575(typeattribute base_typeattr_389)
32576(typeattributeset base_typeattr_389 (and (domain ) (not (hal_confirmationui_client hal_confirmationui_server atrace shell system_app traceur_app ))))
32577(typeattribute base_typeattr_388)
32578(typeattributeset base_typeattr_388 (and (domain ) (not (hal_confirmationui_client hal_confirmationui_server ))))
32579(typeattribute base_typeattr_387)
32580(typeattributeset base_typeattr_387 (and (domain ) (not (hal_confirmationui_server ))))
32581(typeattribute base_typeattr_386)
32582(typeattributeset base_typeattr_386 (and (data_file_type ) (not (anr_data_file tombstone_data_file ))))
32583(typeattribute base_typeattr_385)
32584(typeattributeset base_typeattr_385 (and (domain ) (not (hal_configstore_server logd prng_seeder tombstoned ))))
32585(typeattribute base_typeattr_384)
32586(typeattributeset base_typeattr_384 (and (domain ) (not (hal_configstore_client hal_configstore_server ))))
32587(typeattribute base_typeattr_383)
32588(typeattributeset base_typeattr_383 (and (domain ) (not (hal_configstore_server ))))
32589(typeattribute base_typeattr_382)
32590(typeattributeset base_typeattr_382 (and (appdomain ) (not (isolated_app_all ))))
32591(typeattribute base_typeattr_381)
32592(typeattributeset base_typeattr_381 (and (domain ) (not (hal_codec2_client hal_codec2_server atrace shell system_app traceur_app ))))
32593(typeattribute base_typeattr_380)
32594(typeattributeset base_typeattr_380 (and (domain ) (not (hal_codec2_client hal_codec2_server ))))
32595(typeattribute base_typeattr_379)
32596(typeattributeset base_typeattr_379 (and (domain ) (not (hal_codec2_server ))))
32597(typeattribute base_typeattr_378)
32598(typeattributeset base_typeattr_378 (and (domain ) (not (hal_cas_client hal_cas_server atrace shell system_app traceur_app ))))
32599(typeattribute base_typeattr_377)
32600(typeattributeset base_typeattr_377 (and (domain ) (not (hal_cas_client hal_cas_server ))))
32601(typeattribute base_typeattr_376)
32602(typeattributeset base_typeattr_376 (and (domain ) (not (hal_cas_server ))))
32603(typeattribute base_typeattr_375)
32604(typeattributeset base_typeattr_375 (and (domain ) (not (hal_can_controller_client hal_can_controller_server atrace shell system_app traceur_app ))))
32605(typeattribute base_typeattr_374)
32606(typeattributeset base_typeattr_374 (and (domain ) (not (hal_can_bus_client hal_can_bus_server ))))
32607(typeattribute base_typeattr_373)
32608(typeattributeset base_typeattr_373 (and (domain ) (not (hal_can_bus_server ))))
32609(typeattribute base_typeattr_372)
32610(typeattributeset base_typeattr_372 (and (domain ) (not (hal_can_controller_client hal_can_controller_server ))))
32611(typeattribute base_typeattr_371)
32612(typeattributeset base_typeattr_371 (and (domain ) (not (hal_can_controller_server ))))
32613(typeattribute base_typeattr_370)
32614(typeattributeset base_typeattr_370 (and (halserverdomain ) (not (hal_camera_server ))))
32615(typeattribute base_typeattr_369)
32616(typeattributeset base_typeattr_369 (and (appdomain ) (not (isolated_app ))))
32617(typeattribute base_typeattr_368)
32618(typeattributeset base_typeattr_368 (and (domain ) (not (hal_camera_client hal_camera_server atrace shell system_app traceur_app ))))
32619(typeattribute base_typeattr_367)
32620(typeattributeset base_typeattr_367 (and (domain ) (not (hal_camera_client hal_camera_server ))))
32621(typeattribute base_typeattr_366)
32622(typeattributeset base_typeattr_366 (and (domain ) (not (hal_camera_server ))))
32623(typeattribute base_typeattr_365)
32624(typeattributeset base_typeattr_365 (and (domain ) (not (hal_broadcastradio_client hal_broadcastradio_server atrace shell system_app traceur_app ))))
32625(typeattribute base_typeattr_364)
32626(typeattributeset base_typeattr_364 (and (domain ) (not (hal_broadcastradio_client hal_broadcastradio_server ))))
32627(typeattribute base_typeattr_363)
32628(typeattributeset base_typeattr_363 (and (domain ) (not (hal_broadcastradio_server ))))
32629(typeattribute base_typeattr_362)
32630(typeattributeset base_typeattr_362 (and (domain ) (not (hal_bootctl_client hal_bootctl_server atrace shell system_app traceur_app ))))
32631(typeattribute base_typeattr_361)
32632(typeattributeset base_typeattr_361 (and (domain ) (not (hal_bootctl_client hal_bootctl_server ))))
32633(typeattribute base_typeattr_360)
32634(typeattributeset base_typeattr_360 (and (domain ) (not (hal_bootctl_server ))))
32635(typeattribute base_typeattr_359)
32636(typeattributeset base_typeattr_359 (and (domain ) (not (hal_bluetooth_client hal_bluetooth_server atrace shell system_app traceur_app ))))
32637(typeattribute base_typeattr_358)
32638(typeattributeset base_typeattr_358 (and (domain ) (not (hal_bluetooth_client hal_bluetooth_server ))))
32639(typeattribute base_typeattr_357)
32640(typeattributeset base_typeattr_357 (and (domain ) (not (hal_bluetooth_server ))))
32641(typeattribute base_typeattr_356)
32642(typeattributeset base_typeattr_356 (and (domain ) (not (hal_authsecret_client hal_authsecret_server atrace shell system_app traceur_app ))))
32643(typeattribute base_typeattr_355)
32644(typeattributeset base_typeattr_355 (and (domain ) (not (hal_authsecret_client hal_authsecret_server ))))
32645(typeattribute base_typeattr_354)
32646(typeattributeset base_typeattr_354 (and (domain ) (not (hal_authsecret_server ))))
32647(typeattribute base_typeattr_353)
32648(typeattributeset base_typeattr_353 (and (domain ) (not (hal_authgraph_client hal_authgraph_server atrace shell system_app traceur_app ))))
32649(typeattribute base_typeattr_352)
32650(typeattributeset base_typeattr_352 (and (domain ) (not (hal_authgraph_server ))))
32651(typeattribute base_typeattr_351)
32652(typeattributeset base_typeattr_351 (and (domain ) (not (hal_audiocontrol_client hal_audiocontrol_server atrace shell system_app traceur_app ))))
32653(typeattribute base_typeattr_350)
32654(typeattributeset base_typeattr_350 (and (domain ) (not (hal_audiocontrol_client hal_audiocontrol_server ))))
32655(typeattribute base_typeattr_349)
32656(typeattributeset base_typeattr_349 (and (domain ) (not (hal_audiocontrol_server ))))
32657(typeattribute base_typeattr_348)
32658(typeattributeset base_typeattr_348 (and (halserverdomain ) (not (hal_audio_server hal_omx_server ))))
32659(typeattribute base_typeattr_347)
32660(typeattributeset base_typeattr_347 (and (domain ) (not (hal_audio_client hal_audio_server atrace shell system_app traceur_app ))))
32661(typeattribute base_typeattr_346)
32662(typeattributeset base_typeattr_346 (and (domain ) (not (hal_audio_client hal_audio_server ))))
32663(typeattribute base_typeattr_345)
32664(typeattributeset base_typeattr_345 (and (domain ) (not (hal_audio_server ))))
32665(typeattribute base_typeattr_344)
32666(typeattributeset base_typeattr_344 (and (domain ) (not (hal_atrace_client hal_atrace_server ))))
32667(typeattribute base_typeattr_343)
32668(typeattributeset base_typeattr_343 (and (domain ) (not (hal_atrace_server ))))
32669(typeattribute base_typeattr_342)
32670(typeattributeset base_typeattr_342 (and (domain ) (not (hal_allocator_client hal_allocator_server ))))
32671(typeattribute base_typeattr_341)
32672(typeattributeset base_typeattr_341 (and (domain ) (not (hal_allocator_server ))))
32673(typeattribute base_typeattr_340)
32674(typeattributeset base_typeattr_340 (and (domain ) (not (gatekeeperd ))))
32675(typeattribute base_typeattr_339)
32676(typeattributeset base_typeattr_339 (and (domain ) (not (vold ))))
32677(typeattribute base_typeattr_338)
32678(typeattributeset base_typeattr_338 (and (fs_type file_type ) (not (fsck_exec ))))
32679(typeattribute base_typeattr_337)
32680(typeattributeset base_typeattr_337 (and (domain ) (not (init vold ))))
32681(typeattribute base_typeattr_336)
32682(typeattributeset base_typeattr_336 (and (domain ) (not (flags_health_check init ))))
32683(typeattribute base_typeattr_335)
32684(typeattributeset base_typeattr_335 (and (domain ) (not (fingerprintd ))))
32685(typeattribute base_typeattr_334)
32686(typeattributeset base_typeattr_334 (and (domain ) (not (dumpstate shell system_server traceur_app ))))
32687(typeattribute base_typeattr_333)
32688(typeattributeset base_typeattr_333 (and (domain ) (not (dumpstate ))))
32689(typeattribute base_typeattr_332)
32690(typeattributeset base_typeattr_332 (and (service_manager_type ) (not (hal_service_type apex_service default_android_service dumpstate_service gatekeeper_service virtual_touchpad_service vold_service ))))
32691(typeattribute base_typeattr_331)
32692(typeattributeset base_typeattr_331 (and (domain ) (not (drmserver ))))
32693(typeattribute base_typeattr_330)
32694(typeattributeset base_typeattr_330 (and (domain ) (not (init traced_probes vendor_init ))))
32695(typeattribute base_typeattr_329)
32696(typeattributeset base_typeattr_329 (and (domain ) (not (ephemeral_app untrusted_app_27 untrusted_app_25 ))))
32697(typeattribute base_typeattr_328)
32698(typeattributeset base_typeattr_328 (and (domain ) (not (hal_codec2_server hal_omx_server ))))
32699(typeattribute base_typeattr_327)
32700(typeattributeset base_typeattr_327 (and (coredomain ) (not (apexd charger incidentd init recovery shell ueventd ))))
32701(typeattribute base_typeattr_326)
32702(typeattributeset base_typeattr_326 (and (coredomain ) (not (appdomain ))))
32703(typeattribute base_typeattr_325)
32704(typeattributeset base_typeattr_325 (and (coredomain ) (not (system_writes_mnt_vendor_violators init ueventd vold ))))
32705(typeattribute base_typeattr_324)
32706(typeattributeset base_typeattr_324 (not (coredomain ) ))
32707(typeattribute base_typeattr_323)
32708(typeattributeset base_typeattr_323 (not (system_file_type system_dlkm_file_type vendor_file_type rootfs ) ))
32709(typeattribute base_typeattr_322)
32710(typeattributeset base_typeattr_322 (and (domain ) (not (artd installd profman ))))
32711(typeattribute base_typeattr_321)
32712(typeattributeset base_typeattr_321 (and (domain ) (not (init vendor_init vold ))))
32713(typeattribute base_typeattr_320)
32714(typeattributeset base_typeattr_320 (not (hwservicemanager ) ))
32715(typeattribute base_typeattr_319)
32716(typeattributeset base_typeattr_319 (not (servicemanager vndservicemanager ) ))
32717(typeattribute base_typeattr_318)
32718(typeattributeset base_typeattr_318 (and (domain ) (not (installd shell ))))
32719(typeattribute base_typeattr_317)
32720(typeattributeset base_typeattr_317 (and (domain ) (not (appdomain artd installd ))))
32721(typeattribute base_typeattr_316)
32722(typeattributeset base_typeattr_316 (and (appdomain ) (not (shell simpleperf ))))
32723(typeattribute base_typeattr_315)
32724(typeattributeset base_typeattr_315 (and (domain ) (not (app_zygote runas simpleperf_app_runner webview_zygote zygote ))))
32725(typeattribute base_typeattr_314)
32726(typeattributeset base_typeattr_314 (and (domain ) (not (adbd init runas zygote ))))
32727(typeattribute base_typeattr_313)
32728(typeattributeset base_typeattr_313 (and (domain ) (not (init installd system_app system_server toolbox vold_prepare_subdirs ))))
32729(typeattribute base_typeattr_312)
32730(typeattributeset base_typeattr_312 (not (domain ) ))
32731(typeattribute base_typeattr_311)
32732(typeattributeset base_typeattr_311 (and (domain ) (not (init zygote ))))
32733(typeattribute base_typeattr_310)
32734(typeattributeset base_typeattr_310 (and (domain ) (not (untrusted_app_27 untrusted_app_25 ))))
32735(typeattribute base_typeattr_309)
32736(typeattributeset base_typeattr_309 (and (file_type ) (not (apk_data_file app_data_file asec_public_file ))))
32737(typeattribute base_typeattr_308)
32738(typeattributeset base_typeattr_308 (and (domain ) (not (init system_server ))))
32739(typeattribute base_typeattr_307)
32740(typeattributeset base_typeattr_307 (and (domain ) (not (dumpstate incidentd system_server ))))
32741(typeattribute base_typeattr_306)
32742(typeattributeset base_typeattr_306 (and (domain ) (not (app_zygote system_server webview_zygote ))))
32743(typeattribute base_typeattr_305)
32744(typeattributeset base_typeattr_305 (and (domain ) (not (system_server ))))
32745(typeattribute base_typeattr_304)
32746(typeattributeset base_typeattr_304 (and (domain ) (not (system_server zygote ))))
32747(typeattribute base_typeattr_303)
32748(typeattributeset base_typeattr_303 (and (system_file_type ) (not (crash_dump_exec system_event_log_tags_file system_lib_file system_group_file system_linker_exec system_linker_config_file system_passwd_file system_seccomp_policy_file system_security_cacerts_file system_zoneinfo_file task_profiles_file task_profiles_api_file file_contexts_file property_contexts_file netutils_wrapper_exec shell_exec toolbox_exec ))))
32749(typeattribute base_typeattr_302)
32750(typeattributeset base_typeattr_302 (and (vendor_file_type ) (not (same_process_hal_file ))))
32751(typeattribute base_typeattr_301)
32752(typeattributeset base_typeattr_301 (and (coredomain ) (not (system_executes_vendor_violators shell ))))
32753(typeattribute base_typeattr_300)
32754(typeattributeset base_typeattr_300 (and (vendor_file_type ) (not (vendor_app_file same_process_hal_file vndk_sp_file vendor_public_lib_file vendor_public_framework_file ))))
32755(typeattribute base_typeattr_299)
32756(typeattributeset base_typeattr_299 (and (coredomain ) (not (system_executes_vendor_violators init shell ueventd ))))
32757(typeattribute base_typeattr_298)
32758(typeattributeset base_typeattr_298 (and (file_type ) (not (vendor_file_type init_exec ))))
32759(typeattribute base_typeattr_297)
32760(typeattributeset base_typeattr_297 (and (file_type ) (not (system_file_type postinstall_file ))))
32761(typeattribute base_typeattr_296)
32762(typeattributeset base_typeattr_296 (and (system_file_type ) (not (crash_dump_exec system_lib_file system_linker_exec netutils_wrapper_exec shell_exec toolbox_exec ))))
32763(typeattribute base_typeattr_295)
32764(typeattributeset base_typeattr_295 (and (domain ) (not (appdomain coredomain vendor_executes_system_violators vendor_init ))))
32765(typeattribute base_typeattr_294)
32766(typeattributeset base_typeattr_294 (and (coredomain ) (not (init shell ueventd ))))
32767(typeattribute base_typeattr_293)
32768(typeattributeset base_typeattr_293 (and (coredomain ) (not (data_between_core_and_vendor_violators init ))))
32769(typeattribute base_typeattr_292)
32770(typeattributeset base_typeattr_292 (and (coredomain ) (not (data_between_core_and_vendor_violators init vold vold_prepare_subdirs ))))
32771(typeattribute base_typeattr_291)
32772(typeattributeset base_typeattr_291 (and (domain ) (not (appdomain coredomain data_between_core_and_vendor_violators ))))
32773(typeattribute base_typeattr_290)
32774(typeattributeset base_typeattr_290 (and (core_data_file_type ) (not (system_data_root_file system_data_file vendor_data_file vendor_userdir_file unencrypted_data_file ))))
32775(typeattribute base_typeattr_289)
32776(typeattributeset base_typeattr_289 (and (core_data_file_type ) (not (system_data_root_file system_data_file vendor_data_file vendor_userdir_file ))))
32777(typeattribute base_typeattr_288)
32778(typeattributeset base_typeattr_288 (and (core_data_file_type ) (not (unencrypted_data_file ))))
32779(typeattribute base_typeattr_287)
32780(typeattributeset base_typeattr_287 (and (vendor_init ) (not (data_between_core_and_vendor_violators ))))
32781(typeattribute base_typeattr_286)
32782(typeattributeset base_typeattr_286 (and (domain ) (not (appdomain coredomain data_between_core_and_vendor_violators vendor_init ))))
32783(typeattribute base_typeattr_285)
32784(typeattributeset base_typeattr_285 (and (data_file_type ) (not (core_data_file_type app_data_file_type vendor_data_file ))))
32785(typeattribute base_typeattr_284)
32786(typeattributeset base_typeattr_284 (and (data_file_type ) (not (core_data_file_type app_data_file_type ))))
32787(typeattribute base_typeattr_283)
32788(typeattributeset base_typeattr_283 (and (coredomain ) (not (appdomain data_between_core_and_vendor_violators init vold_prepare_subdirs ))))
32789(typeattribute base_typeattr_282)
32790(typeattributeset base_typeattr_282 (and (dev_type file_type ) (not (core_data_file_type app_data_file_type coredomain_socket unlabeled ))))
32791(typeattribute base_typeattr_281)
32792(typeattributeset base_typeattr_281 (and (coredomain ) (not (socket_between_core_and_vendor_violators init ueventd ))))
32793(typeattribute base_typeattr_280)
32794(typeattributeset base_typeattr_280 (and (core_data_file_type coredomain_socket unlabeled ) (not (pdx_endpoint_socket_type pdx_channel_socket_type app_data_file privapp_data_file ))))
32795(typeattribute base_typeattr_279)
32796(typeattributeset base_typeattr_279 (and (domain ) (not (appdomain coredomain socket_between_core_and_vendor_violators data_between_core_and_vendor_violators vendor_init ))))
32797(typeattribute base_typeattr_278)
32798(typeattributeset base_typeattr_278 (and (domain ) (not (coredomain socket_between_core_and_vendor_violators ))))
32799(typeattribute base_typeattr_277)
32800(typeattributeset base_typeattr_277 (and (coredomain ) (not (adbd init ))))
32801(typeattribute base_typeattr_276)
32802(typeattributeset base_typeattr_276 (and (coredomain ) (not (shell ))))
32803(typeattribute base_typeattr_275)
32804(typeattributeset base_typeattr_275 (and (coredomain ) (not (shell ueventd ))))
32805(typeattribute base_typeattr_274)
32806(typeattributeset base_typeattr_274 (and (service_manager_type ) (not (app_api_service ephemeral_app_api_service hal_service_type apc_service audioserver_service cameraserver_service drmserver_service credstore_service keystore_maintenance_service keystore_service legacykeystore_service mediaserver_service mediametrics_service mediaextractor_service mediadrmserver_service nfc_service radio_service virtual_touchpad_service vr_manager_service ))))
32807(typeattribute base_typeattr_273)
32808(typeattributeset base_typeattr_273 (and (appdomain ) (not (coredomain ))))
32809(typeattribute base_typeattr_272)
32810(typeattributeset base_typeattr_272 (and (domain ) (not (hwservicemanager servicemanager vndservicemanager ))))
32811(typeattribute base_typeattr_271)
32812(typeattributeset base_typeattr_271 (and (domain ) (not (fastbootd recovery update_engine ))))
32813(typeattribute base_typeattr_270)
32814(typeattributeset base_typeattr_270 (and (domain ) (not (hal_fastboot_server e2fs fastbootd fsck init recovery vold ))))
32815(typeattribute base_typeattr_269)
32816(typeattributeset base_typeattr_269 (and (domain ) (not (init recovery system_server ueventd ))))
32817(typeattribute base_typeattr_268)
32818(typeattributeset base_typeattr_268 (and (domain ) (not (hal_camera_server hal_cas_server hal_drm_server hal_keymint_server adbd dumpstate fastbootd init mediadrmserver mediaserver recovery shell system_server vendor_init ))))
32819(typeattribute base_typeattr_267)
32820(typeattributeset base_typeattr_267 (and (domain ) (not (coredomain vendor_init ))))
32821(typeattribute base_typeattr_266)
32822(typeattributeset base_typeattr_266 (and (domain ) (not (init system_server vendor_init ))))
32823(typeattribute base_typeattr_265)
32824(typeattributeset base_typeattr_265 (and (fs_type ) (not (contextmount_type ))))
32825(typeattribute base_typeattr_264)
32826(typeattributeset base_typeattr_264 (and (domain ) (not (adbd crash_dump heapprofd init shell ))))
32827(typeattribute base_typeattr_263)
32828(typeattributeset base_typeattr_263 (and (domain ) (not (adbd init shell ))))
32829(typeattribute base_typeattr_262)
32830(typeattributeset base_typeattr_262 (and (domain ) (not (init kernel recovery ))))
32831(typeattribute base_typeattr_261)
32832(typeattributeset base_typeattr_261 (and (domain ) (not (dumpstate init system_server vendor_init ))))
32833(typeattribute base_typeattr_260)
32834(typeattributeset base_typeattr_260 (and (domain ) (not (dumpstate init vendor_init ))))
32835(typeattribute base_typeattr_259)
32836(typeattributeset base_typeattr_259 (and (domain ) (not (init vendor_init ))))
32837(typeattribute base_typeattr_258)
32838(typeattributeset base_typeattr_258 (and (domain ) (not (init ueventd ))))
32839(typeattribute base_typeattr_257)
32840(typeattributeset base_typeattr_257 (and (file_type ) (not (exec_type postinstall_file ))))
32841(typeattribute base_typeattr_256)
32842(typeattributeset base_typeattr_256 (and (domain ) (not (shell ueventd ))))
32843(typeattribute base_typeattr_255)
32844(typeattributeset base_typeattr_255 (and (domain ) (not (prng_seeder shell ueventd ))))
32845(typeattribute base_typeattr_254)
32846(typeattributeset base_typeattr_254 (and (domain ) (not (kernel ))))
32847(typeattribute base_typeattr_253)
32848(typeattributeset base_typeattr_253 (and (domain ) (not (init kernel ueventd vold ))))
32849(typeattribute base_typeattr_252)
32850(typeattributeset base_typeattr_252 (and (domain ) (not (init recovery ))))
32851(typeattribute base_typeattr_251)
32852(typeattributeset base_typeattr_251 (and (domain ) (not (domain ))))
32853(typeattribute base_typeattr_250)
32854(typeattributeset base_typeattr_250 (and (domain ) (not (coredomain ))))
32855(typeattribute base_typeattr_249)
32856(typeattributeset base_typeattr_249 (and (domain ) (not (isolated_app servicemanager vndservicemanager ))))
32857(typeattribute base_typeattr_248)
32858(typeattributeset base_typeattr_248 (and (domain ) (not (hwservicemanager vndservicemanager ))))
32859(typeattribute base_typeattr_247)
32860(typeattributeset base_typeattr_247 (and (domain ) (not (display_service_server ))))
32861(typeattribute base_typeattr_246)
32862(typeattributeset base_typeattr_246 (and (domain ) (not (credstore ))))
32863(typeattribute base_typeattr_245)
32864(typeattributeset base_typeattr_245 (and (domain ) (not (cameraserver ))))
32865(typeattribute base_typeattr_244)
32866(typeattributeset base_typeattr_244 (and (domain ) (not (camera_service_server ))))
32867(typeattribute base_typeattr_243)
32868(typeattributeset base_typeattr_243 (and (domain ) (not (bufferhubd ))))
32869(typeattribute base_typeattr_242)
32870(typeattributeset base_typeattr_242 (and (domain ) (not (bootstat init ))))
32871(typeattribute base_typeattr_241)
32872(typeattributeset base_typeattr_241 (and (appdomain ) (not (bluetooth system_app ))))
32873(typeattribute base_typeattr_240)
32874(typeattributeset base_typeattr_240 (and (appdomain ) (not (bluetooth nfc ))))
32875(typeattribute base_typeattr_239)
32876(typeattributeset base_typeattr_239 (and (appdomain ) (not (untrusted_app_all isolated_app_all platform_app priv_app ))))
32877(typeattribute base_typeattr_238)
32878(typeattributeset base_typeattr_238 (and (domain ) (not (credstore init ))))
32879(typeattribute base_typeattr_237)
32880(typeattributeset base_typeattr_237 (and (appdomain ) (not (platform_app ))))
32881(typeattribute base_typeattr_236)
32882(typeattributeset base_typeattr_236 (and (domain ) (not (appdomain perfetto ))))
32883(typeattribute base_typeattr_235)
32884(typeattributeset base_typeattr_235 (and (appdomain ) (not (shell ))))
32885(typeattribute base_typeattr_234)
32886(typeattributeset base_typeattr_234 (and (domain ) (not (appdomain crash_dump ))))
32887(typeattribute base_typeattr_233)
32888(typeattributeset base_typeattr_233 (and (domain ) (not (appdomain ))))
32889(typeattribute base_typeattr_232)
32890(typeattributeset base_typeattr_232 (and (appdomain ) (not (radio ))))
32891(typeattribute base_typeattr_231)
32892(typeattributeset base_typeattr_231 (and (appdomain ) (not (network_stack ))))
32893(typeattribute base_typeattr_230)
32894(typeattributeset base_typeattr_230 (and (appdomain ) (not (bluetooth ))))
32895(typeattribute base_typeattr_229)
32896(typeattributeset base_typeattr_229 (and (appdomain ) (not (nfc ))))
32897(typeattribute base_typeattr_228)
32898(typeattributeset base_typeattr_228 (and (appdomain ) (not (bluetooth network_stack ))))
32899(typeattribute base_typeattr_227)
32900(typeattributeset base_typeattr_227 (and (domain ) (not (apexd init servicemanager system_server update_engine ))))
32901(typeattribute base_typeattr_226)
32902(typeattributeset base_typeattr_226 (and (domain ) (not (apexd init system_server update_engine ))))
32903(typeattribute base_typeattr_225)
32904(typeattributeset base_typeattr_225 (and (domain ) (not (apexd ))))
32905(typeattribute base_typeattr_224)
32906(typeattributeset base_typeattr_224 (all))
32907(typeattribute base_typeattr_223)
32908(typeattributeset base_typeattr_223 (and (domain ) (not (init ))))
32909(typeattribute base_typeattr_222)
32910(typeattributeset base_typeattr_222 (and (hal_wifi_supplicant_client ) (not (halclientdomain ))))
32911(typeattribute base_typeattr_221)
32912(typeattributeset base_typeattr_221 (and (hal_wifi_supplicant_server ) (not (hal_wifi_supplicant ))))
32913(typeattribute base_typeattr_220)
32914(typeattributeset base_typeattr_220 (and (hal_wifi_supplicant_server ) (not (halserverdomain ))))
32915(typeattribute base_typeattr_219)
32916(typeattributeset base_typeattr_219 (and (hal_wifi_hostapd_client ) (not (halclientdomain ))))
32917(typeattribute base_typeattr_218)
32918(typeattributeset base_typeattr_218 (and (hal_wifi_hostapd_server ) (not (hal_wifi_hostapd ))))
32919(typeattribute base_typeattr_217)
32920(typeattributeset base_typeattr_217 (and (hal_wifi_hostapd_server ) (not (halserverdomain ))))
32921(typeattribute base_typeattr_216)
32922(typeattributeset base_typeattr_216 (and (hal_wifi_client ) (not (halclientdomain ))))
32923(typeattribute base_typeattr_215)
32924(typeattributeset base_typeattr_215 (and (hal_wifi_server ) (not (hal_wifi ))))
32925(typeattribute base_typeattr_214)
32926(typeattributeset base_typeattr_214 (and (hal_wifi_server ) (not (halserverdomain ))))
32927(typeattribute base_typeattr_213)
32928(typeattributeset base_typeattr_213 (and (hal_weaver_client ) (not (halclientdomain ))))
32929(typeattribute base_typeattr_212)
32930(typeattributeset base_typeattr_212 (and (hal_weaver_server ) (not (hal_weaver ))))
32931(typeattribute base_typeattr_211)
32932(typeattributeset base_typeattr_211 (and (hal_weaver_server ) (not (halserverdomain ))))
32933(typeattribute base_typeattr_210)
32934(typeattributeset base_typeattr_210 (and (hal_vr_client ) (not (halclientdomain ))))
32935(typeattribute base_typeattr_209)
32936(typeattributeset base_typeattr_209 (and (hal_vr_server ) (not (hal_vr ))))
32937(typeattribute base_typeattr_208)
32938(typeattributeset base_typeattr_208 (and (hal_vr_server ) (not (halserverdomain ))))
32939(typeattribute base_typeattr_207)
32940(typeattributeset base_typeattr_207 (and (hal_vibrator_client ) (not (halclientdomain ))))
32941(typeattribute base_typeattr_206)
32942(typeattributeset base_typeattr_206 (and (hal_vibrator_server ) (not (hal_vibrator ))))
32943(typeattribute base_typeattr_205)
32944(typeattributeset base_typeattr_205 (and (hal_vibrator_server ) (not (halserverdomain ))))
32945(typeattribute base_typeattr_204)
32946(typeattributeset base_typeattr_204 (and (hal_vehicle_client ) (not (halclientdomain ))))
32947(typeattribute base_typeattr_203)
32948(typeattributeset base_typeattr_203 (and (hal_vehicle_server ) (not (hal_vehicle ))))
32949(typeattribute base_typeattr_202)
32950(typeattributeset base_typeattr_202 (and (hal_vehicle_server ) (not (halserverdomain ))))
32951(typeattribute base_typeattr_201)
32952(typeattributeset base_typeattr_201 (and (hal_uwb_vendor_client ) (not (halclientdomain ))))
32953(typeattribute base_typeattr_200)
32954(typeattributeset base_typeattr_200 (and (hal_uwb_vendor_server ) (not (hal_uwb_vendor ))))
32955(typeattribute base_typeattr_199)
32956(typeattributeset base_typeattr_199 (and (hal_uwb_vendor_server ) (not (halserverdomain ))))
32957(typeattribute base_typeattr_198)
32958(typeattributeset base_typeattr_198 (and (hal_uwb_client ) (not (halclientdomain ))))
32959(typeattribute base_typeattr_197)
32960(typeattributeset base_typeattr_197 (and (hal_uwb_server ) (not (hal_uwb ))))
32961(typeattribute base_typeattr_196)
32962(typeattributeset base_typeattr_196 (and (hal_uwb_server ) (not (halserverdomain ))))
32963(typeattribute base_typeattr_195)
32964(typeattributeset base_typeattr_195 (and (hal_usb_gadget_client ) (not (halclientdomain ))))
32965(typeattribute base_typeattr_194)
32966(typeattributeset base_typeattr_194 (and (hal_usb_gadget_server ) (not (hal_usb_gadget ))))
32967(typeattribute base_typeattr_193)
32968(typeattributeset base_typeattr_193 (and (hal_usb_gadget_server ) (not (halserverdomain ))))
32969(typeattribute base_typeattr_192)
32970(typeattributeset base_typeattr_192 (and (hal_usb_client ) (not (halclientdomain ))))
32971(typeattribute base_typeattr_191)
32972(typeattributeset base_typeattr_191 (and (hal_usb_server ) (not (hal_usb ))))
32973(typeattribute base_typeattr_190)
32974(typeattributeset base_typeattr_190 (and (hal_usb_server ) (not (halserverdomain ))))
32975(typeattribute base_typeattr_189)
32976(typeattributeset base_typeattr_189 (and (hal_tv_tuner_client ) (not (halclientdomain ))))
32977(typeattribute base_typeattr_188)
32978(typeattributeset base_typeattr_188 (and (hal_tv_tuner_server ) (not (hal_tv_tuner ))))
32979(typeattribute base_typeattr_187)
32980(typeattributeset base_typeattr_187 (and (hal_tv_tuner_server ) (not (halserverdomain ))))
32981(typeattribute base_typeattr_186)
32982(typeattributeset base_typeattr_186 (and (hal_tv_input_client ) (not (halclientdomain ))))
32983(typeattribute base_typeattr_185)
32984(typeattributeset base_typeattr_185 (and (hal_tv_input_server ) (not (hal_tv_input ))))
32985(typeattribute base_typeattr_184)
32986(typeattributeset base_typeattr_184 (and (hal_tv_input_server ) (not (halserverdomain ))))
32987(typeattribute base_typeattr_183)
32988(typeattributeset base_typeattr_183 (and (hal_tv_hdmi_earc_client ) (not (halclientdomain ))))
32989(typeattribute base_typeattr_182)
32990(typeattributeset base_typeattr_182 (and (hal_tv_hdmi_earc_server ) (not (hal_tv_hdmi_earc ))))
32991(typeattribute base_typeattr_181)
32992(typeattributeset base_typeattr_181 (and (hal_tv_hdmi_earc_server ) (not (halserverdomain ))))
32993(typeattribute base_typeattr_180)
32994(typeattributeset base_typeattr_180 (and (hal_tv_hdmi_connection_client ) (not (halclientdomain ))))
32995(typeattribute base_typeattr_179)
32996(typeattributeset base_typeattr_179 (and (hal_tv_hdmi_connection_server ) (not (hal_tv_hdmi_connection ))))
32997(typeattribute base_typeattr_178)
32998(typeattributeset base_typeattr_178 (and (hal_tv_hdmi_connection_server ) (not (halserverdomain ))))
32999(typeattribute base_typeattr_177)
33000(typeattributeset base_typeattr_177 (and (hal_tv_hdmi_cec_client ) (not (halclientdomain ))))
33001(typeattribute base_typeattr_176)
33002(typeattributeset base_typeattr_176 (and (hal_tv_hdmi_cec_server ) (not (hal_tv_hdmi_cec ))))
33003(typeattribute base_typeattr_175)
33004(typeattributeset base_typeattr_175 (and (hal_tv_hdmi_cec_server ) (not (halserverdomain ))))
33005(typeattribute base_typeattr_174)
33006(typeattributeset base_typeattr_174 (and (hal_tv_cec_client ) (not (halclientdomain ))))
33007(typeattribute base_typeattr_173)
33008(typeattributeset base_typeattr_173 (and (hal_tv_cec_server ) (not (hal_tv_cec ))))
33009(typeattribute base_typeattr_172)
33010(typeattributeset base_typeattr_172 (and (hal_tv_cec_server ) (not (halserverdomain ))))
33011(typeattribute base_typeattr_171)
33012(typeattributeset base_typeattr_171 (and (hal_threadnetwork_client ) (not (halclientdomain ))))
33013(typeattribute base_typeattr_170)
33014(typeattributeset base_typeattr_170 (and (hal_threadnetwork_server ) (not (hal_threadnetwork ))))
33015(typeattribute base_typeattr_169)
33016(typeattributeset base_typeattr_169 (and (hal_threadnetwork_server ) (not (halserverdomain ))))
33017(typeattribute base_typeattr_168)
33018(typeattributeset base_typeattr_168 (and (hal_thermal_client ) (not (halclientdomain ))))
33019(typeattribute base_typeattr_167)
33020(typeattributeset base_typeattr_167 (and (hal_thermal_server ) (not (hal_thermal ))))
33021(typeattribute base_typeattr_166)
33022(typeattributeset base_typeattr_166 (and (hal_thermal_server ) (not (halserverdomain ))))
33023(typeattribute base_typeattr_165)
33024(typeattributeset base_typeattr_165 (and (hal_tetheroffload_client ) (not (halclientdomain ))))
33025(typeattribute base_typeattr_164)
33026(typeattributeset base_typeattr_164 (and (hal_tetheroffload_server ) (not (hal_tetheroffload ))))
33027(typeattribute base_typeattr_163)
33028(typeattributeset base_typeattr_163 (and (hal_tetheroffload_server ) (not (halserverdomain ))))
33029(typeattribute base_typeattr_162)
33030(typeattributeset base_typeattr_162 (and (hal_telephony_client ) (not (halclientdomain ))))
33031(typeattribute base_typeattr_161)
33032(typeattributeset base_typeattr_161 (and (hal_telephony_server ) (not (hal_telephony ))))
33033(typeattribute base_typeattr_160)
33034(typeattributeset base_typeattr_160 (and (hal_telephony_server ) (not (halserverdomain ))))
33035(typeattribute base_typeattr_159)
33036(typeattributeset base_typeattr_159 (and (hal_sensors_client ) (not (halclientdomain ))))
33037(typeattribute base_typeattr_158)
33038(typeattributeset base_typeattr_158 (and (hal_sensors_server ) (not (hal_sensors ))))
33039(typeattribute base_typeattr_157)
33040(typeattributeset base_typeattr_157 (and (hal_sensors_server ) (not (halserverdomain ))))
33041(typeattribute base_typeattr_156)
33042(typeattributeset base_typeattr_156 (and (hal_secure_element_client ) (not (halclientdomain ))))
33043(typeattribute base_typeattr_155)
33044(typeattributeset base_typeattr_155 (and (hal_secure_element_server ) (not (hal_secure_element ))))
33045(typeattribute base_typeattr_154)
33046(typeattributeset base_typeattr_154 (and (hal_secure_element_server ) (not (halserverdomain ))))
33047(typeattribute base_typeattr_153)
33048(typeattributeset base_typeattr_153 (and (hal_remotelyprovisionedcomponent_avf_client ) (not (halclientdomain ))))
33049(typeattribute base_typeattr_152)
33050(typeattributeset base_typeattr_152 (and (hal_remotelyprovisionedcomponent_avf_server ) (not (hal_remotelyprovisionedcomponent_avf ))))
33051(typeattribute base_typeattr_151)
33052(typeattributeset base_typeattr_151 (and (hal_remotelyprovisionedcomponent_avf_server ) (not (halserverdomain ))))
33053(typeattribute base_typeattr_150)
33054(typeattributeset base_typeattr_150 (and (hal_secretkeeper_client ) (not (halclientdomain ))))
33055(typeattribute base_typeattr_149)
33056(typeattributeset base_typeattr_149 (and (hal_secretkeeper_server ) (not (hal_secretkeeper ))))
33057(typeattribute base_typeattr_148)
33058(typeattributeset base_typeattr_148 (and (hal_secretkeeper_server ) (not (halserverdomain ))))
33059(typeattribute base_typeattr_147)
33060(typeattributeset base_typeattr_147 (and (hal_remoteaccess_client ) (not (halclientdomain ))))
33061(typeattribute base_typeattr_146)
33062(typeattributeset base_typeattr_146 (and (hal_remoteaccess_server ) (not (hal_remoteaccess ))))
33063(typeattribute base_typeattr_145)
33064(typeattributeset base_typeattr_145 (and (hal_remoteaccess_server ) (not (halserverdomain ))))
33065(typeattribute base_typeattr_144)
33066(typeattributeset base_typeattr_144 (and (hal_rebootescrow_client ) (not (halclientdomain ))))
33067(typeattribute base_typeattr_143)
33068(typeattributeset base_typeattr_143 (and (hal_rebootescrow_server ) (not (hal_rebootescrow ))))
33069(typeattribute base_typeattr_142)
33070(typeattributeset base_typeattr_142 (and (hal_rebootescrow_server ) (not (halserverdomain ))))
33071(typeattribute base_typeattr_141)
33072(typeattributeset base_typeattr_141 (and (hal_power_stats_client ) (not (halclientdomain ))))
33073(typeattribute base_typeattr_140)
33074(typeattributeset base_typeattr_140 (and (hal_power_stats_server ) (not (hal_power_stats ))))
33075(typeattribute base_typeattr_139)
33076(typeattributeset base_typeattr_139 (and (hal_power_stats_server ) (not (halserverdomain ))))
33077(typeattribute base_typeattr_138)
33078(typeattributeset base_typeattr_138 (and (hal_power_client ) (not (halclientdomain ))))
33079(typeattribute base_typeattr_137)
33080(typeattributeset base_typeattr_137 (and (hal_power_server ) (not (hal_power ))))
33081(typeattribute base_typeattr_136)
33082(typeattributeset base_typeattr_136 (and (hal_power_server ) (not (halserverdomain ))))
33083(typeattribute base_typeattr_135)
33084(typeattributeset base_typeattr_135 (and (hal_omx_client ) (not (halclientdomain ))))
33085(typeattribute base_typeattr_134)
33086(typeattributeset base_typeattr_134 (and (hal_omx_server ) (not (hal_omx ))))
33087(typeattribute base_typeattr_133)
33088(typeattributeset base_typeattr_133 (and (hal_omx_server ) (not (halserverdomain ))))
33089(typeattribute base_typeattr_132)
33090(typeattributeset base_typeattr_132 (and (hal_oemlock_client ) (not (halclientdomain ))))
33091(typeattribute base_typeattr_131)
33092(typeattributeset base_typeattr_131 (and (hal_oemlock_server ) (not (hal_oemlock ))))
33093(typeattribute base_typeattr_130)
33094(typeattributeset base_typeattr_130 (and (hal_oemlock_server ) (not (halserverdomain ))))
33095(typeattribute base_typeattr_129)
33096(typeattributeset base_typeattr_129 (and (hal_nlinterceptor_client ) (not (halclientdomain ))))
33097(typeattribute base_typeattr_128)
33098(typeattributeset base_typeattr_128 (and (hal_nlinterceptor_server ) (not (hal_nlinterceptor ))))
33099(typeattribute base_typeattr_127)
33100(typeattributeset base_typeattr_127 (and (hal_nlinterceptor_server ) (not (halserverdomain ))))
33101(typeattribute base_typeattr_126)
33102(typeattributeset base_typeattr_126 (and (hal_nfc_client ) (not (halclientdomain ))))
33103(typeattribute base_typeattr_125)
33104(typeattributeset base_typeattr_125 (and (hal_nfc_server ) (not (hal_nfc ))))
33105(typeattribute base_typeattr_124)
33106(typeattributeset base_typeattr_124 (and (hal_nfc_server ) (not (halserverdomain ))))
33107(typeattribute base_typeattr_123)
33108(typeattributeset base_typeattr_123 (and (hal_neuralnetworks_client ) (not (halclientdomain ))))
33109(typeattribute base_typeattr_122)
33110(typeattributeset base_typeattr_122 (and (hal_neuralnetworks_server ) (not (hal_neuralnetworks ))))
33111(typeattribute base_typeattr_121)
33112(typeattributeset base_typeattr_121 (and (hal_neuralnetworks_server ) (not (halserverdomain ))))
33113(typeattribute base_typeattr_120)
33114(typeattributeset base_typeattr_120 (and (hal_memtrack_client ) (not (halclientdomain ))))
33115(typeattribute base_typeattr_119)
33116(typeattributeset base_typeattr_119 (and (hal_memtrack_server ) (not (hal_memtrack ))))
33117(typeattribute base_typeattr_118)
33118(typeattributeset base_typeattr_118 (and (hal_memtrack_server ) (not (halserverdomain ))))
33119(typeattribute base_typeattr_117)
33120(typeattributeset base_typeattr_117 (and (hal_macsec_client ) (not (halclientdomain ))))
33121(typeattribute base_typeattr_116)
33122(typeattributeset base_typeattr_116 (and (hal_macsec_server ) (not (hal_macsec ))))
33123(typeattribute base_typeattr_115)
33124(typeattributeset base_typeattr_115 (and (hal_macsec_server ) (not (halserverdomain ))))
33125(typeattribute base_typeattr_114)
33126(typeattributeset base_typeattr_114 (and (hal_lowpan_client ) (not (halclientdomain ))))
33127(typeattribute base_typeattr_113)
33128(typeattributeset base_typeattr_113 (and (hal_lowpan_server ) (not (hal_lowpan ))))
33129(typeattribute base_typeattr_112)
33130(typeattributeset base_typeattr_112 (and (hal_lowpan_server ) (not (halserverdomain ))))
33131(typeattribute base_typeattr_111)
33132(typeattributeset base_typeattr_111 (and (hal_light_client ) (not (halclientdomain ))))
33133(typeattribute base_typeattr_110)
33134(typeattributeset base_typeattr_110 (and (hal_light_server ) (not (hal_light ))))
33135(typeattribute base_typeattr_109)
33136(typeattributeset base_typeattr_109 (and (hal_light_server ) (not (halserverdomain ))))
33137(typeattribute base_typeattr_108)
33138(typeattributeset base_typeattr_108 (and (hal_keymint_client ) (not (halclientdomain ))))
33139(typeattribute base_typeattr_107)
33140(typeattributeset base_typeattr_107 (and (hal_keymint_server ) (not (hal_keymint ))))
33141(typeattribute base_typeattr_106)
33142(typeattributeset base_typeattr_106 (and (hal_keymint_server ) (not (halserverdomain ))))
33143(typeattribute base_typeattr_105)
33144(typeattributeset base_typeattr_105 (and (hal_keymaster_client ) (not (halclientdomain ))))
33145(typeattribute base_typeattr_104)
33146(typeattributeset base_typeattr_104 (and (hal_keymaster_server ) (not (hal_keymaster ))))
33147(typeattribute base_typeattr_103)
33148(typeattributeset base_typeattr_103 (and (hal_keymaster_server ) (not (halserverdomain ))))
33149(typeattribute base_typeattr_102)
33150(typeattributeset base_typeattr_102 (and (hal_ivn_client ) (not (halclientdomain ))))
33151(typeattribute base_typeattr_101)
33152(typeattributeset base_typeattr_101 (and (hal_ivn_server ) (not (hal_ivn ))))
33153(typeattribute base_typeattr_100)
33154(typeattributeset base_typeattr_100 (and (hal_ivn_server ) (not (halserverdomain ))))
33155(typeattribute base_typeattr_99)
33156(typeattributeset base_typeattr_99 (and (hal_ir_client ) (not (halclientdomain ))))
33157(typeattribute base_typeattr_98)
33158(typeattributeset base_typeattr_98 (and (hal_ir_server ) (not (hal_ir ))))
33159(typeattribute base_typeattr_97)
33160(typeattributeset base_typeattr_97 (and (hal_ir_server ) (not (halserverdomain ))))
33161(typeattribute base_typeattr_96)
33162(typeattributeset base_typeattr_96 (and (hal_input_processor_client ) (not (halclientdomain ))))
33163(typeattribute base_typeattr_95)
33164(typeattributeset base_typeattr_95 (and (hal_input_processor_server ) (not (hal_input_processor ))))
33165(typeattribute base_typeattr_94)
33166(typeattributeset base_typeattr_94 (and (hal_input_processor_server ) (not (halserverdomain ))))
33167(typeattribute base_typeattr_93)
33168(typeattributeset base_typeattr_93 (and (hal_input_classifier_client ) (not (halclientdomain ))))
33169(typeattribute base_typeattr_92)
33170(typeattributeset base_typeattr_92 (and (hal_input_classifier_server ) (not (hal_input_classifier ))))
33171(typeattribute base_typeattr_91)
33172(typeattributeset base_typeattr_91 (and (hal_input_classifier_server ) (not (halserverdomain ))))
33173(typeattribute base_typeattr_90)
33174(typeattributeset base_typeattr_90 (and (hal_identity_client ) (not (halclientdomain ))))
33175(typeattribute base_typeattr_89)
33176(typeattributeset base_typeattr_89 (and (hal_identity_server ) (not (hal_identity ))))
33177(typeattribute base_typeattr_88)
33178(typeattributeset base_typeattr_88 (and (hal_identity_server ) (not (halserverdomain ))))
33179(typeattribute base_typeattr_87)
33180(typeattributeset base_typeattr_87 (and (hal_health_storage_client ) (not (halclientdomain ))))
33181(typeattribute base_typeattr_86)
33182(typeattributeset base_typeattr_86 (and (hal_health_storage_server ) (not (hal_health_storage ))))
33183(typeattribute base_typeattr_85)
33184(typeattributeset base_typeattr_85 (and (hal_health_storage_server ) (not (halserverdomain ))))
33185(typeattribute base_typeattr_84)
33186(typeattributeset base_typeattr_84 (and (hal_health_client ) (not (halclientdomain ))))
33187(typeattribute base_typeattr_83)
33188(typeattributeset base_typeattr_83 (and (hal_health_server ) (not (hal_health ))))
33189(typeattribute base_typeattr_82)
33190(typeattributeset base_typeattr_82 (and (hal_health_server ) (not (halserverdomain ))))
33191(typeattribute base_typeattr_81)
33192(typeattributeset base_typeattr_81 (and (hal_graphics_composer_client ) (not (halclientdomain ))))
33193(typeattribute base_typeattr_80)
33194(typeattributeset base_typeattr_80 (and (hal_graphics_composer_server ) (not (hal_graphics_composer ))))
33195(typeattribute base_typeattr_79)
33196(typeattributeset base_typeattr_79 (and (hal_graphics_composer_server ) (not (halserverdomain ))))
33197(typeattribute base_typeattr_78)
33198(typeattributeset base_typeattr_78 (and (hal_graphics_allocator_client ) (not (halclientdomain ))))
33199(typeattribute base_typeattr_77)
33200(typeattributeset base_typeattr_77 (and (hal_graphics_allocator_server ) (not (hal_graphics_allocator ))))
33201(typeattribute base_typeattr_76)
33202(typeattributeset base_typeattr_76 (and (hal_graphics_allocator_server ) (not (halserverdomain ))))
33203(typeattribute base_typeattr_75)
33204(typeattributeset base_typeattr_75 (and (hal_gnss_client ) (not (halclientdomain ))))
33205(typeattribute base_typeattr_74)
33206(typeattributeset base_typeattr_74 (and (hal_gnss_server ) (not (hal_gnss ))))
33207(typeattribute base_typeattr_73)
33208(typeattributeset base_typeattr_73 (and (hal_gnss_server ) (not (halserverdomain ))))
33209(typeattribute base_typeattr_72)
33210(typeattributeset base_typeattr_72 (and (hal_gatekeeper_client ) (not (halclientdomain ))))
33211(typeattribute base_typeattr_71)
33212(typeattributeset base_typeattr_71 (and (hal_gatekeeper_server ) (not (hal_gatekeeper ))))
33213(typeattribute base_typeattr_70)
33214(typeattributeset base_typeattr_70 (and (hal_gatekeeper_server ) (not (halserverdomain ))))
33215(typeattribute base_typeattr_69)
33216(typeattributeset base_typeattr_69 (and (hal_fingerprint_client ) (not (halclientdomain ))))
33217(typeattribute base_typeattr_68)
33218(typeattributeset base_typeattr_68 (and (hal_fingerprint_server ) (not (hal_fingerprint ))))
33219(typeattribute base_typeattr_67)
33220(typeattributeset base_typeattr_67 (and (hal_fingerprint_server ) (not (halserverdomain ))))
33221(typeattribute base_typeattr_66)
33222(typeattributeset base_typeattr_66 (and (hal_fastboot_client ) (not (halclientdomain ))))
33223(typeattribute base_typeattr_65)
33224(typeattributeset base_typeattr_65 (and (hal_fastboot_server ) (not (hal_fastboot ))))
33225(typeattribute base_typeattr_64)
33226(typeattributeset base_typeattr_64 (and (hal_fastboot_server ) (not (halserverdomain ))))
33227(typeattribute base_typeattr_63)
33228(typeattributeset base_typeattr_63 (and (hal_face_client ) (not (halclientdomain ))))
33229(typeattribute base_typeattr_62)
33230(typeattributeset base_typeattr_62 (and (hal_face_server ) (not (hal_face ))))
33231(typeattribute base_typeattr_61)
33232(typeattributeset base_typeattr_61 (and (hal_face_server ) (not (halserverdomain ))))
33233(typeattribute base_typeattr_60)
33234(typeattributeset base_typeattr_60 (and (hal_evs_client ) (not (halclientdomain ))))
33235(typeattribute base_typeattr_59)
33236(typeattributeset base_typeattr_59 (and (hal_evs_server ) (not (hal_evs ))))
33237(typeattribute base_typeattr_58)
33238(typeattributeset base_typeattr_58 (and (hal_evs_server ) (not (halserverdomain ))))
33239(typeattribute base_typeattr_57)
33240(typeattributeset base_typeattr_57 (and (hal_dumpstate_client ) (not (halclientdomain ))))
33241(typeattribute base_typeattr_56)
33242(typeattributeset base_typeattr_56 (and (hal_dumpstate_server ) (not (hal_dumpstate ))))
33243(typeattribute base_typeattr_55)
33244(typeattributeset base_typeattr_55 (and (hal_dumpstate_server ) (not (halserverdomain ))))
33245(typeattribute base_typeattr_54)
33246(typeattributeset base_typeattr_54 (and (hal_drm_client ) (not (halclientdomain ))))
33247(typeattribute base_typeattr_53)
33248(typeattributeset base_typeattr_53 (and (hal_drm_server ) (not (hal_drm ))))
33249(typeattribute base_typeattr_52)
33250(typeattributeset base_typeattr_52 (and (hal_drm_server ) (not (halserverdomain ))))
33251(typeattribute base_typeattr_51)
33252(typeattributeset base_typeattr_51 (and (hal_contexthub_client ) (not (halclientdomain ))))
33253(typeattribute base_typeattr_50)
33254(typeattributeset base_typeattr_50 (and (hal_contexthub_server ) (not (hal_contexthub ))))
33255(typeattribute base_typeattr_49)
33256(typeattributeset base_typeattr_49 (and (hal_contexthub_server ) (not (halserverdomain ))))
33257(typeattribute base_typeattr_48)
33258(typeattributeset base_typeattr_48 (and (hal_confirmationui_client ) (not (halclientdomain ))))
33259(typeattribute base_typeattr_47)
33260(typeattributeset base_typeattr_47 (and (hal_confirmationui_server ) (not (hal_confirmationui ))))
33261(typeattribute base_typeattr_46)
33262(typeattributeset base_typeattr_46 (and (hal_confirmationui_server ) (not (halserverdomain ))))
33263(typeattribute base_typeattr_45)
33264(typeattributeset base_typeattr_45 (and (hal_configstore_client ) (not (halclientdomain ))))
33265(typeattribute base_typeattr_44)
33266(typeattributeset base_typeattr_44 (and (hal_configstore_server ) (not (hal_configstore ))))
33267(typeattribute base_typeattr_43)
33268(typeattributeset base_typeattr_43 (and (hal_configstore_server ) (not (halserverdomain ))))
33269(typeattribute base_typeattr_42)
33270(typeattributeset base_typeattr_42 (and (hal_codec2_client ) (not (halclientdomain ))))
33271(typeattribute base_typeattr_41)
33272(typeattributeset base_typeattr_41 (and (hal_codec2_server ) (not (hal_codec2 ))))
33273(typeattribute base_typeattr_40)
33274(typeattributeset base_typeattr_40 (and (hal_codec2_server ) (not (halserverdomain ))))
33275(typeattribute base_typeattr_39)
33276(typeattributeset base_typeattr_39 (and (hal_cas_client ) (not (halclientdomain ))))
33277(typeattribute base_typeattr_38)
33278(typeattributeset base_typeattr_38 (and (hal_cas_server ) (not (hal_cas ))))
33279(typeattribute base_typeattr_37)
33280(typeattributeset base_typeattr_37 (and (hal_cas_server ) (not (halserverdomain ))))
33281(typeattribute base_typeattr_36)
33282(typeattributeset base_typeattr_36 (and (hal_can_controller_client ) (not (halclientdomain ))))
33283(typeattribute base_typeattr_35)
33284(typeattributeset base_typeattr_35 (and (hal_can_controller_server ) (not (hal_can_controller ))))
33285(typeattribute base_typeattr_34)
33286(typeattributeset base_typeattr_34 (and (hal_can_controller_server ) (not (halserverdomain ))))
33287(typeattribute base_typeattr_33)
33288(typeattributeset base_typeattr_33 (and (hal_can_bus_client ) (not (halclientdomain ))))
33289(typeattribute base_typeattr_32)
33290(typeattributeset base_typeattr_32 (and (hal_can_bus_server ) (not (hal_can_bus ))))
33291(typeattribute base_typeattr_31)
33292(typeattributeset base_typeattr_31 (and (hal_can_bus_server ) (not (halserverdomain ))))
33293(typeattribute base_typeattr_30)
33294(typeattributeset base_typeattr_30 (and (hal_camera_client ) (not (halclientdomain ))))
33295(typeattribute base_typeattr_29)
33296(typeattributeset base_typeattr_29 (and (hal_camera_server ) (not (hal_camera ))))
33297(typeattribute base_typeattr_28)
33298(typeattributeset base_typeattr_28 (and (hal_camera_server ) (not (halserverdomain ))))
33299(typeattribute base_typeattr_27)
33300(typeattributeset base_typeattr_27 (and (hal_broadcastradio_client ) (not (halclientdomain ))))
33301(typeattribute base_typeattr_26)
33302(typeattributeset base_typeattr_26 (and (hal_broadcastradio_server ) (not (hal_broadcastradio ))))
33303(typeattribute base_typeattr_25)
33304(typeattributeset base_typeattr_25 (and (hal_broadcastradio_server ) (not (halserverdomain ))))
33305(typeattribute base_typeattr_24)
33306(typeattributeset base_typeattr_24 (and (hal_bootctl_client ) (not (halclientdomain ))))
33307(typeattribute base_typeattr_23)
33308(typeattributeset base_typeattr_23 (and (hal_bootctl_server ) (not (hal_bootctl ))))
33309(typeattribute base_typeattr_22)
33310(typeattributeset base_typeattr_22 (and (hal_bootctl_server ) (not (halserverdomain ))))
33311(typeattribute base_typeattr_21)
33312(typeattributeset base_typeattr_21 (and (hal_bluetooth_client ) (not (halclientdomain ))))
33313(typeattribute base_typeattr_20)
33314(typeattributeset base_typeattr_20 (and (hal_bluetooth_server ) (not (hal_bluetooth ))))
33315(typeattribute base_typeattr_19)
33316(typeattributeset base_typeattr_19 (and (hal_bluetooth_server ) (not (halserverdomain ))))
33317(typeattribute base_typeattr_18)
33318(typeattributeset base_typeattr_18 (and (hal_authsecret_client ) (not (halclientdomain ))))
33319(typeattribute base_typeattr_17)
33320(typeattributeset base_typeattr_17 (and (hal_authsecret_server ) (not (hal_authsecret ))))
33321(typeattribute base_typeattr_16)
33322(typeattributeset base_typeattr_16 (and (hal_authsecret_server ) (not (halserverdomain ))))
33323(typeattribute base_typeattr_15)
33324(typeattributeset base_typeattr_15 (and (hal_authgraph_client ) (not (halclientdomain ))))
33325(typeattribute base_typeattr_14)
33326(typeattributeset base_typeattr_14 (and (hal_authgraph_server ) (not (hal_authgraph ))))
33327(typeattribute base_typeattr_13)
33328(typeattributeset base_typeattr_13 (and (hal_authgraph_server ) (not (halserverdomain ))))
33329(typeattribute base_typeattr_12)
33330(typeattributeset base_typeattr_12 (and (hal_audiocontrol_client ) (not (halclientdomain ))))
33331(typeattribute base_typeattr_11)
33332(typeattributeset base_typeattr_11 (and (hal_audiocontrol_server ) (not (hal_audiocontrol ))))
33333(typeattribute base_typeattr_10)
33334(typeattributeset base_typeattr_10 (and (hal_audiocontrol_server ) (not (halserverdomain ))))
33335(typeattribute base_typeattr_9)
33336(typeattributeset base_typeattr_9 (and (hal_audio_client ) (not (halclientdomain ))))
33337(typeattribute base_typeattr_8)
33338(typeattributeset base_typeattr_8 (and (hal_audio_server ) (not (hal_audio ))))
33339(typeattribute base_typeattr_7)
33340(typeattributeset base_typeattr_7 (and (hal_audio_server ) (not (halserverdomain ))))
33341(typeattribute base_typeattr_6)
33342(typeattributeset base_typeattr_6 (and (hal_atrace_client ) (not (halclientdomain ))))
33343(typeattribute base_typeattr_5)
33344(typeattributeset base_typeattr_5 (and (hal_atrace_server ) (not (hal_atrace ))))
33345(typeattribute base_typeattr_4)
33346(typeattributeset base_typeattr_4 (and (hal_atrace_server ) (not (halserverdomain ))))
33347(typeattribute base_typeattr_3)
33348(typeattributeset base_typeattr_3 (and (hal_allocator_client ) (not (halclientdomain ))))
33349(typeattribute base_typeattr_2)
33350(typeattributeset base_typeattr_2 (and (hal_allocator_server ) (not (hal_allocator ))))
33351(typeattribute base_typeattr_1)
33352(typeattributeset base_typeattr_1 (and (hal_allocator_server ) (not (halserverdomain ))))
33353; THIS IS A WORKAROUND for the current limitations of the module policy language
33354; This should be used sparingly until we figure out a saner way to achieve the
33355; stuff below, for example, by improving typeattribute statement of module
33356; language.
33357;
33358; NOTE: This file has no effect on recovery policy.
33359
33360; Apps, except isolated apps, are clients of Allocator HAL
33361; Unfortunately, we can't currently express this in module policy language:
33362;     typeattribute { appdomain -isolated_app_all } hal_allocator_client;
33363;     typeattribute hal_allocator_client halclientdomain;
33364(typeattributeset hal_allocator_client ((and (appdomain) ((not (isolated_app_all))))))
33365(typeattributeset halclientdomain (hal_allocator_client))
33366
33367; Apps, except isolated apps, are clients of OMX-related services
33368; Unfortunately, we can't currently express this in module policy language:
33369(typeattributeset hal_omx_client ((and (appdomain) ((not (isolated_app))))))
33370
33371; Apps, except isolated apps, are clients of Codec2-related services
33372; Unfortunately, we can't currently express this in module policy language:
33373(typeattributeset hal_codec2_client ((and (appdomain) ((not (isolated_app))))))
33374
33375; Apps, except isolated apps and SDK sandboxes, are clients of Drm-related services
33376; Unfortunately, we can't currently express this in module policy language:
33377(typeattributeset hal_drm_client ((and (appdomain) ((not (or (isolated_app_all) (sdk_sandbox_all)))))))
33378
33379; Apps, except isolated apps, are clients of Configstore HAL
33380; Unfortunately, we can't currently express this in module policy language:
33381;     typeattribute { appdomain -isolated_app_all } hal_configstore_client;
33382(typeattributeset hal_configstore_client ((and (appdomain) ((not (isolated_app_all))))))
33383
33384; Apps, except isolated apps, are clients of Graphics Allocator HAL
33385; Unfortunately, we can't currently express this in module policy language:
33386;     typeattribute { appdomain -isolated_app } hal_graphics_allocator_client;
33387(typeattributeset hal_graphics_allocator_client ((and (appdomain) ((not (isolated_app))))))
33388
33389; Apps, except isolated apps, are clients of Cas HAL
33390; Unfortunately, we can't currently express this in module policy language:
33391;     typeattribute { appdomain -isolated_app_all } hal_cas_client;
33392(typeattributeset hal_cas_client ((and (appdomain) ((not (isolated_app_all))))))
33393
33394; Domains hosting Camera HAL implementations are clients of Allocator HAL
33395; Unfortunately, we can't currently express this in module policy language:
33396;     typeattribute hal_camera hal_allocator_client;
33397(typeattributeset hal_allocator_client (hal_camera))
33398
33399; Apps, except isolated apps, are clients of Neuralnetworks HAL
33400; Unfortunately, we can't currently express this in module policy language:
33401;     typeattribute { appdomain -isolated_app_all } hal_neuralnetworks_client;
33402(typeattributeset hal_neuralnetworks_client ((and (appdomain) ((not (isolated_app))))))
33403
33404; TODO(b/112056006): move these to mapping files when/if we implement 'versioned' attributes.
33405; Rename untrusted_app_visible_* to untrusted_app_visible_*_violators.
33406; Unfortunately, we can't currently express this in module policy language:
33407;     typeattribute untrusted_app_visible_hwservice untrusted_app_visible_hwservice_violators;
33408;     typeattribute untrusted_app_visible_halserver untrusted_app_visible_halserver_violators;
33409(typeattribute untrusted_app_visible_hwservice)
33410(typeattributeset untrusted_app_visible_hwservice_violators (untrusted_app_visible_hwservice))
33411(typeattribute untrusted_app_visible_halserver)
33412(typeattributeset untrusted_app_visible_halserver_violators (untrusted_app_visible_halserver))
33413
33414; Properties having both system_property_type and vendor_property_type are illegal
33415; Unfortunately, we can't currently express this in module policy language:
33416;     typeattribute { system_property_type && vendor_property_type } system_and_vendor_property_type;
33417(typeattribute system_and_vendor_property_type)
33418(typeattributeset system_and_vendor_property_type ((and (system_property_type) (vendor_property_type))))
33419