2018-08-17 09:35:42 +02:00
|
|
|
# apexd -- manager for APEX packages
|
|
|
|
type apexd, domain;
|
|
|
|
type apexd_exec, exec_type, file_type, system_file_type;
|
|
|
|
|
|
|
|
binder_use(apexd)
|
|
|
|
add_service(apexd, apex_service)
|
2018-11-01 12:05:20 +01:00
|
|
|
set_prop(apexd, apexd_prop)
|
2018-08-17 09:35:42 +02:00
|
|
|
|
2018-10-18 13:50:06 +02:00
|
|
|
neverallow { domain -init -apexd -system_server } apex_service:service_manager find;
|
|
|
|
neverallow { domain -init -apexd -system_server } apexd:binder call;
|
2018-08-17 09:35:42 +02:00
|
|
|
|
2019-03-05 17:36:36 +01:00
|
|
|
neverallow { domain userdebug_or_eng(`-crash_dump') } apexd:process ptrace;
|
2018-11-01 12:05:20 +01:00
|
|
|
|
|
|
|
# only apexd can set apexd sysprop
|
|
|
|
neverallow { domain -apexd -init } apexd_prop:property_service set;
|