Home | History | Annotate | Download | only in sepolicy

Lines Matching full:domain

2 type vold, domain, domain_deprecated;
23 # domain when working with untrusted block devices
85 allow vold domain:dir r_dir_perms;
86 allow vold domain:{ file lnk_file } r_file_perms;
87 allow vold domain:process { signal sigkill };
98 # Run fsck in the fsck domain.
198 neverallow { domain -vold } vold_data_file:dir ~{ open create read getattr setattr search relabelto ioctl };
199 neverallow { domain -vold } vold_data_file:notdevfile_class_set ~{ relabelto getattr };
200 neverallow { domain -vold -init } vold_data_file:dir *;
201 neverallow { domain -vold -init } vold_data_file:notdevfile_class_set *;
202 neverallow { domain -vold -init } restorecon_prop:property_service set;