1 #include <tunables/global>
3 profile android_app flags=(mediate_deleted,attach_disconnected,complain) {
4 #include <abstractions/base>
15 capability wake_alarm,
19 capability sys_ptrace,
21 capability wake_alarm,
22 capability block_suspend,
26 capability net_bind_service,
28 capability dac_override,
29 mount fstype=tmpfs -> /storage**,
30 mount options in (rw,bind) options in (rw,rbind) -> /storage**,
31 mount /dev/fuse -> /storage**,
35 ptrace (read,readby,trace,tracedby) peer=android_app//&lxc-waydroid,
36 ptrace (read,trace,readby,tracedby) peer=lxc-waydroid,
37 ptrace (read,trace,readby,tracedby) peer=adbd//&lxc-waydroid,
39 signal (send,receive) peer=android_app//&lxc-waydroid,
40 signal (receive) peer=adbd//&lxc-waydroid,
41 signal (send,receive) peer=lxc-waydroid,
48 /data/lineageos_updates** r,
50 /data/system_ce/** rw,
51 /data/data/com.android** rw,
52 /data/misc/profiles** rw,
59 /proc/*/timerslack_ns w,
64 /sys/kernel/debug/tracing** w,
68 # This seems to be important for Magisk to function
69 # /system/framework** wk,