blob: d2ddcbeba729f00a54790ec2bfae2f03b0eaf660 [file] [log] [blame]
Marko Man5e33b842018-08-26 23:15:26 +02001r_dir_file(update_engine, mnt_user_file)
2r_dir_file(update_engine, storage_file)
3
Marko Manc83cecc2018-09-01 19:21:27 +02004allow update_engine self:capability { chown fsetid };
Marko Man5e33b842018-08-26 23:15:26 +02005
6allow update_engine labeledfs:filesystem { mount unmount };
7
maxwen81239f42018-10-03 19:13:17 +02008allow update_engine { otapreopt_chroot_exec toolbox_exec }:file rx_file_perms;
Marko Manc83cecc2018-09-01 19:21:27 +02009
10allow update_engine labeledfs:filesystem mount;
maxwen81239f42018-10-03 19:13:17 +020011allow update_engine rootfs:file { create setattr write rx_file_perms unlink relabelfrom rename };
12allow update_engine rootfs:dir { create write open add_name read rmdir remove_name };
13
14allow update_engine system_data_file:file { create read write open unlink };
15allow update_engine system_data_file:dir { create write add_name read remove_name unlink };
16
17allow update_engine system_file:file { create setattr write relabelto relabelfrom rx_file_perms unlink };
18allow update_engine system_file:dir { create setattr write rmdir remove_name add_name };
19
Marko Manc83cecc2018-09-01 19:21:27 +020020allow update_engine storage_file:lnk_file read;
Marko Manc83cecc2018-09-01 19:21:27 +020021allow update_engine toolbox_exec:file { execute getattr };