]> glassweightruler.freedombox.rocks Git - waydroid.git/blob - data/configs/apparmor_profiles/adbd
All AppArmor profiles have been switched to the "enforce" mode.
[waydroid.git] / data / configs / apparmor_profiles / adbd
1 profile adbd flags=(attach_disconnected,mediate_deleted) {
2 /** ix,
3 /dev** rw,
4 network,
5 unix,
6 owner /proc** rw,
7 / r,
8 /** r,
9 /storage** rwkl,
10 /data** rwkl,
11 /proc** rw,
12 /sys** rw,
13 /dev** rw,
14 /tmp** rw,
15 /var** rw,
16 /run** rw,
17 /mnt** rw,
18 /apex** rw,
19 mount,
20 umount,
21
22 capability sys_nice,
23 capability wake_alarm,
24 capability setpcap,
25 capability setgid,
26 capability setuid,
27 capability sys_ptrace,
28 capability sys_admin,
29 capability wake_alarm,
30 capability block_suspend,
31 capability sys_time,
32 capability net_admin,
33 capability net_raw,
34 capability net_bind_service,
35 capability kill,
36 capability dac_override,
37 capability dac_read_search,
38 capability fsetid,
39 capability mknod,
40 capability syslog,
41 capability chown,
42 capability sys_resource,
43 capability fowner,
44
45 ptrace (read,readby,trace,tracedby) peer=lxc-waydroid,
46 ptrace (read,readby,trace,tracedby) peer=android_app//&lxc-waydroid,
47 ptrace (read,readby,trace,tracedby) peer=adbd//&lxc-waydroid,
48
49 signal (send,receive) peer=lxc-waydroid,
50 signal (send,receive) peer=android_app//&lxc-waydroid,
51 signal (send) peer=adbd//&lxc-waydroid,
52 signal (receive),
53
54 }
55