]> glassweightruler.freedombox.rocks Git - waydroid.git/blob - data/configs/android_app
Policies have been adjusted for Android 11.
[waydroid.git] / data / configs / android_app
1 #include <tunables/global>
2
3 profile android_app flags=(attach_disconnected, complain, mediate_deleted) {
4 #include <abstractions/base>
5 /** ix,
6 /dev** rw,
7 network,
8 unix,
9 owner /proc** rw,
10 / r,
11 /* r,
12 deny pivot_root,
13 deny dbus,
14 capability sys_nice,
15 capability wake_alarm,
16 capability setpcap,
17 capability setgid,
18 capability setuid,
19 capability sys_ptrace,
20 capability sys_admin,
21 capability wake_alarm,
22 capability block_suspend,
23 capability sys_time,
24 capability net_admin,
25 capability net_raw,
26 capability net_bind_service,
27 capability kill,
28 capability dac_override,
29 capability chown,
30 mount fstype=tmpfs -> /storage**,
31 mount fstype=tmpfs -> /data/misc/profiles**,
32 mount options in (rw,bind) options in (rw,rbind) -> /storage**,
33 mount options in (rw,bind) options in (rw,rbind) -> /data/misc/profiles**,
34 mount /dev/fuse -> /storage**,
35 mount -> /,
36 umount /storage**,
37
38 ptrace (read,readby,trace,tracedby) peer=android_app//&lxc-waydroid,
39 ptrace (read,trace,readby,tracedby) peer=lxc-waydroid,
40 ptrace (read,trace,readby,tracedby) peer=adbd//&lxc-waydroid,
41
42 signal (send,receive) peer=android_app//&lxc-waydroid,
43 signal (receive) peer=adbd//&lxc-waydroid,
44 signal (send,receive) peer=lxc-waydroid,
45 signal (receive),
46
47 /acct** rwkl,
48 /linkerconfig** r,
49 owner /data** rwkl,
50 /data/app** r,
51 /data/system/unsolzygotesocket rw,
52 /data/dalvik-cache** r,
53 /data/misc** r,
54 /data/lineageos_updates** r,
55 /apex** mr,
56 /data/system_ce/** rw,
57 /data/data/com.android** rw,
58 /data/misc/profiles** rw,
59 /data/user_de/** rw,
60 /storage** rwkl,
61 /data/tombstone** rw,
62 /mnt/user** rw,
63 owner /proc** rw,
64 /proc** r,
65 /proc/*/timerslack_ns w,
66 /system/bin** mr,
67 /system/lib** mr,
68 /system** r,
69 /sys** r,
70 /sys/kernel/debug/tracing** w,
71 /vendor** r,
72 /vendor_extra** r,
73
74 # This seems to be important for Magisk to function
75 # /system/framework** wk,
76
77
78 }