d22987b4da
Motivation: Domain is overly permissive. Start removing permissions from domain and assign them to the domain_deprecated attribute. Domain_deprecated and domain can initially be assigned to all domains. The goal is to not assign domain_deprecated to new domains and to start removing domain_deprecated where it is not required or reassigning the appropriate permissions to the inheriting domain when necessary. Bug: 25433265 Change-Id: I8b11cb137df7bdd382629c98d916a73fe276413c
12 lines
307 B
Text
12 lines
307 B
Text
# vpn tunneling protocol manager
|
|
type mtp, domain, domain_deprecated;
|
|
type mtp_exec, exec_type, file_type;
|
|
|
|
init_daemon_domain(mtp)
|
|
net_domain(mtp)
|
|
|
|
# pptp policy
|
|
allow mtp self:socket create_socket_perms;
|
|
allow mtp self:capability net_raw;
|
|
allow mtp ppp:process signal;
|
|
allow mtp vpn_data_file:dir search;
|