# adbd seclabel is specified in init.rc since # it lives in the rootfs and has no unique file type. type adbd, domain; type adbd_exec, exec_type, file_type, system_file_type; # Only init is allowed to enter the adbd domain via exec() neverallow { domain -init } adbd:process transition; neverallow * adbd:process dyntransition; # Allow adbd start/stop mdnsd via ctl.start set_prop(adbd, ctl_mdnsd_prop)