]> glassweightruler.freedombox.rocks Git - waydroid.git/commitdiff
Policies have been adjusted for Android 11.
authorАзалия Смарагдова <charming.flurry@yandex.ru>
Fri, 4 Nov 2022 11:33:28 +0000 (16:33 +0500)
committerAlessandro Astone <ales.astone@gmail.com>
Fri, 18 Nov 2022 14:19:17 +0000 (15:19 +0100)
data/configs/android_app
data/configs/lxc-waydroid

index 7adc67e7b9564a0a5334778e08308779f0a6f74b..be8fa4be995b5539b2283950a7c0751c9b107032 100644 (file)
@@ -1,6 +1,6 @@
 #include <tunables/global>
 
-profile android_app flags=(mediate_deleted,attach_disconnected,complain) {
+profile android_app flags=(attach_disconnected, complain, mediate_deleted) {
   #include <abstractions/base>
   /** ix,
   /dev** rw,
@@ -26,8 +26,11 @@ profile android_app flags=(mediate_deleted,attach_disconnected,complain) {
   capability net_bind_service,
   capability kill,
   capability dac_override,
+  capability chown,
   mount fstype=tmpfs -> /storage**,
+  mount fstype=tmpfs -> /data/misc/profiles**,
   mount options in (rw,bind) options in (rw,rbind) -> /storage**,
+  mount options in (rw,bind) options in (rw,rbind) -> /data/misc/profiles**,
   mount /dev/fuse -> /storage**,
   mount -> /,
   umount /storage**,
@@ -42,8 +45,11 @@ profile android_app flags=(mediate_deleted,attach_disconnected,complain) {
   signal (receive),
 
   /acct** rwkl,
+  /linkerconfig** r,
   owner /data** rwkl,
   /data/app** r,
+  /data/system/unsolzygotesocket rw,
+  /data/dalvik-cache** r,
   /data/misc** r,
   /data/lineageos_updates** r,
   /apex** mr,
index b82d318ab4a5ddbb60ee227bcf702507d1af2109..4dad2059be9bf3cb64bbc7d810cea2f6d1fc24ad 100644 (file)
@@ -1,6 +1,6 @@
 #include <tunables/global>
 
-profile lxc-waydroid flags=(mediate_deleted,attach_disconnected,complain) {
+profile lxc-waydroid flags=(attach_disconnected, complain, mediate_deleted) {
   #include <abstractions/base>
   /** ix,
   /system/bin/app_process Pix -> lxc-waydroid//&android_app,
@@ -24,8 +24,9 @@ profile lxc-waydroid flags=(mediate_deleted,attach_disconnected,complain) {
   /var** rw,
   /run** rw,
   /mnt** rw,
-  /apex** rw,
+  /apex** rwk,
   /sbin** rw,
+  /linkerconfig** rwk,
   /system** k,
   mount,
   umount,