]> glassweightruler.freedombox.rocks Git - waydroid.git/blob - data/configs/android_app
Temporarily switching all profiles to "complain" mode in order to work out policy...
[waydroid.git] / data / configs / android_app
1 #include <tunables/global>
2
3 profile android_app flags=(mediate_deleted,attach_disconnected,complain) {
4 #include <abstractions/base>
5 /** ix,
6 /dev** rw,
7 network,
8 unix,
9 owner /proc** rw,
10 / r,
11 /* r,
12 deny pivot_root,
13 deny dbus,
14 capability sys_nice,
15 capability wake_alarm,
16 capability setpcap,
17 capability setgid,
18 capability setuid,
19 capability sys_ptrace,
20 capability sys_admin,
21 capability wake_alarm,
22 capability block_suspend,
23 capability sys_time,
24 capability net_admin,
25 capability net_raw,
26 capability net_bind_service,
27 capability kill,
28 capability dac_override,
29 mount fstype=tmpfs -> /storage**,
30 mount options in (rw,bind) options in (rw,rbind) -> /storage**,
31 mount /dev/fuse -> /storage**,
32 mount -> /,
33 umount /storage**,
34
35 ptrace (read,readby,trace,tracedby) peer=android_app//&lxc-waydroid,
36 ptrace (read,trace,readby,tracedby) peer=lxc-waydroid,
37 ptrace (read,trace,readby,tracedby) peer=adbd//&lxc-waydroid,
38
39 signal (send,receive) peer=android_app//&lxc-waydroid,
40 signal (receive) peer=adbd//&lxc-waydroid,
41 signal (send,receive) peer=lxc-waydroid,
42 signal (receive),
43
44 /acct** rwkl,
45 owner /data** rwkl,
46 /data/app** r,
47 /data/misc** r,
48 /data/lineageos_updates** r,
49 /apex** mr,
50 /data/system_ce/** rw,
51 /data/data/com.android** rw,
52 /data/misc/profiles** rw,
53 /data/user_de/** rw,
54 /storage** rwkl,
55 /data/tombstone** rw,
56 /mnt/user** rw,
57 owner /proc** rw,
58 /proc** r,
59 /proc/*/timerslack_ns w,
60 /system/bin** mr,
61 /system/lib** mr,
62 /system** r,
63 /sys** r,
64 /sys/kernel/debug/tracing** w,
65 /vendor** r,
66 /vendor_extra** r,
67
68 # This seems to be important for Magisk to function
69 # /system/framework** wk,
70
71
72 }