Files
FrameworkAPI/sepolicy/pawlet_device.te
2025-08-19 12:24:49 -07:00

17 lines
566 B
Plaintext

# Type declarations
type pawlet_device, domain;
type pawlet_device_exec, exec_type, file_type, system_file_type;
# Inherit from core domain
typeattribute pawlet_device coredomain;
# Property access - use vendor property types
get_prop(pawlet_device, vendor_default_prop)
set_prop(pawlet_device, vendor_default_prop)
# Framework interactions
allow pawlet_device framework_res:file { read getattr };
allow pawlet_device system_server:service_manager find;
# Additional file access permissions
allow pawlet_device vendor_default_prop:file { getattr open read map };