]> glassweightruler.freedombox.rocks Git - waydroid.git/blob - data/configs/apparmor_profiles/android_app
All AppArmor profiles have been switched to the "enforce" mode.
[waydroid.git] / data / configs / apparmor_profiles / android_app
1 profile android_app flags=(attach_disconnected, mediate_deleted) {
2 /** ix,
3 /dev** rw,
4 network,
5 unix,
6 owner /proc** rw,
7 / r,
8 /* r,
9 deny pivot_root,
10 deny dbus,
11 capability sys_nice,
12 capability wake_alarm,
13 capability setpcap,
14 capability setgid,
15 capability setuid,
16 capability sys_ptrace,
17 capability sys_admin,
18 capability wake_alarm,
19 capability block_suspend,
20 capability sys_time,
21 capability net_admin,
22 capability net_raw,
23 capability net_bind_service,
24 capability kill,
25 capability dac_override,
26 capability chown,
27 mount fstype=tmpfs -> /storage**,
28 mount fstype=tmpfs -> /data/misc/profiles**,
29 mount options in (rw,bind) options in (rw,rbind) -> /storage**,
30 mount options in (rw,bind) options in (rw,rbind) -> /data/misc/profiles**,
31 mount /dev/fuse -> /storage**,
32 mount -> /,
33 umount /storage**,
34
35 ptrace (read,readby,trace,tracedby) peer=android_app//&lxc-waydroid,
36 ptrace (read,trace,readby,tracedby) peer=lxc-waydroid,
37 ptrace (read,trace,readby,tracedby) peer=adbd//&lxc-waydroid,
38
39 signal (send,receive) peer=android_app//&lxc-waydroid,
40 signal (receive) peer=adbd//&lxc-waydroid,
41 signal (send,receive) peer=lxc-waydroid,
42 signal (receive),
43
44 /acct** rwkl,
45 /linkerconfig** r,
46 owner /data** rwkl,
47 /data/app** r,
48 /data/system/unsolzygotesocket rw,
49 /data/dalvik-cache** r,
50 /data/misc** r,
51 /data/lineageos_updates** r,
52 /apex** mr,
53 /data/system_ce/** rw,
54 /data/data/com.android** rw,
55 /data/misc/profiles** rw,
56 /data/user_de/** rw,
57 /storage** rwkl,
58 /data/tombstone** rw,
59 /mnt/user** rw,
60 owner /proc** rw,
61 /proc** r,
62 /proc/*/timerslack_ns w,
63 /system/bin** mr,
64 /system/lib** mr,
65 /system** r,
66 /sys** r,
67 /sys/kernel/debug/tracing** w,
68 /vendor** r,
69 /vendor_extra** r,
70
71 # This seems to be important for Magisk to function
72 # /system/framework** wk,
73
74
75 }