/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/bundlemanager/bundle_framework/system/ |
H A D | installs.te | 18 allow installs data_app_el1_file:dir { add_name getattr open read remove_name rmdir search write se… 22 allow installs data_app_el2_file:dir { add_name create getattr open read remove_name search setattr… 25 allow installs data_app_el5_file:dir { add_name create getattr open read remove_name search setattr… 30 allow installs data_service_el1_file:dir { remove_name search rmdir getattr setattr rename }; 32 …e_el2_file:dir { add_name create open read search setattr write getattr rmdir remove_name rename }; 33 allow installs data_service_el2_hmdfs:dir { getattr setattr rmdir remove_name rename }; 37 …e_el5_file:dir { add_name create open read search setattr write getattr rmdir remove_name rename }; 55 allow installs data_local:dir { add_name create setattr getattr open read remove_name rmdir search … 57 allow installs data_local_arkcache:dir { add_name create setattr getattr open read remove_name rmdi… 60 allow installs data_local_arkprofile:dir { add_name create setattr getattr open read remove_name rm… [all …]
|
H A D | ark_aot_compiler.te | 32 allow ark_aot_compiler data_local_arkprofile:dir { search add_name remove_name write }; 34 …er data_local_arkcache:dir { add_name create setattr getattr open read remove_name rmdir search wr…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/security/huks/system/ |
H A D | huks.te | 20 allow huks_service data_service_el1_file:dir { search create write open read add_name remove_name }; 22 …ta_service_el1_public_huksService_file:dir { add_name create open read remove_name search write rm… 24 allow huks_service data_service_el2_file:dir { search create write open read add_name remove_name }; 26 …ta_service_el2_public_huksService_file:dir { add_name create open read remove_name search write rm… 28 allow huks_service data_service_el4_file:dir { search create write open read add_name remove_name }; 30 …ta_service_el2_userId_huksService_file:dir { add_name create open read remove_name search write ge… 32 …ta_service_el4_userId_huksService_file:dir { add_name create open read remove_name search write ge… 35 allow huks_service data_data_huksService_file:dir { add_name create open read remove_name search wr…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/filemanagement/user_file_service/system/ |
H A D | normal_hap.te | 14 …_el1_file:dir { create read open rename reparent search write rmdir getattr remove_name add_name }; 16 allow normal_hap_attr vfat:dir { add_name create open read remove_name rename reparent rmdir write … 20 …ttr exfat:dir { create read open rename reparent search write rmdir getattr remove_name add_name }; 23 …attr ntfs:dir { create read open rename reparent search write rmdir getattr remove_name add_name };
|
H A D | storage_daemon.te | 20 # avc: denied { remove_name } for pid=262 comm="storage_daemon" name="F0C2A58FC2A55A9C" dev="tmp… 22 allow storage_daemon mnt_external_file:dir { remove_name rmdir };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/update/module_update/system/ |
H A D | module_update_service.te | 19 allow module_update_service data_file:dir { remove_name search write add_name create setattr read o… 20 allow module_update_service data_module_update:dir { getattr open read remove_name rmdir write sear… 21 allow module_update_service data_module_update_package:dir { open read remove_name rmdir search wri… 44 allow module_update_service update_firmware_file:dir { add_name search write remove_name getattr ap… 46 allow module_update_service data_updater_file:dir { add_name search write remove_name getattr }; 65 …date_service tmpfs:dir { create mounton open read rmdir setattr write add_name write remove_name }; 100 #avc denied { write remove_name } for pid=5784, comm="system/bin/sa_main" name="/block" dev="" ino=… 101 allow module_update_service dev_block_volfile:dir { write remove_name };
|
H A D | init.te | 14 allow init data_module_update:dir { add_name create getattr link open read relabelto remove_name se… 34 allow init tmpfs:dir { remove_name rmdir };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/update/updater_sa/system/ |
H A D | updater_sa.te | 20 allow updater_sa data_ota_package:dir { add_name search write remove_name getattr }; 34 allow updater_sa data_service_el1_file:dir { search write add_name remove_name read open getattr }; 41 allow updater_sa update_firmware_file:dir { search read open write getattr add_name remove_name }; 44 allow updater_sa data_file:dir { read open write getattr setattr add_name remove_name }; 52 allow updater_sa update_dupdate_engine_file:dir { add_name create getattr open read remove_name rmd… 56 allow updater_sa update_update_service_file:dir { add_name create getattr open read remove_name rmd…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/filemanagement/dfs_service/system/ |
H A D | cloudfiledaemon.te | 37 … cloudfiledaemon data_service_el2_hmdfs:dir { create search read open write add_name remove_name }; 39 allow cloudfiledaemon hmdfs:dir { search write remove_name add_name create open read rmdir rename r… 51 allow cloudfiledaemon data_service_el1_file:dir { search write add_name create remove_name read ope… 53 allow cloudfiledaemon cloudfile_data_file:dir { search write add_name create remove_name read open … 61 allow cloudfiledaemon data_user_file:dir { read open search add_name write remove_name create rmdir…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/multimodalinput/input/system/ |
H A D | udevd.te | 18 allow udevd data_service_el1_file:dir { search write add_name create getattr remove_name read open … 24 allow udevd dev_char_file:dir { search write remove_name }; 30 allow udevd dev_input_file:dir { remove_name rmdir };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/filemanagement/storage_service/system/ |
H A D | ueventd.te | 14 allow ueventd dev_block_file:dir { create remove_name }; 17 allow ueventd dev_block_volfile:dir { remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/graphic/graphic/public/ |
H A D | shader.te | 13 …data_local_shadercache:dir { create setattr getattr open read add_name remove_name search unlink w… 17 allow hap_domain data_local_shadercache:dir { create setattr getattr open read add_name remove_name…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/distributeddatamgr/distributeddatamgr/system/ |
H A D | distributeddata.te | 19 allow distributeddata data_app_el1_database_file:dir { add_name create open read remove_name rmdir … 21 allow distributeddata data_app_el2_database_file:dir { add_name create open read remove_name rmdir … 23 allow distributeddata data_app_el3_database_file:dir { add_name create open read remove_name rmdir … 25 allow distributeddata data_app_el4_database_file:dir { add_name create open read remove_name rmdir … 30 allow distributeddata data_service_el1_file:dir { add_name create getattr open read remove_name rmd… 62 allow distributeddata normal_hap_data_file_attr:dir { add_name create getattr remove_name rmdir sea… 90 …_basic_hap_data_file_attr:dir { getattr open read search write add_name create remove_name rmdir }; 94 …m_core_hap_data_file_attr:dir { getattr open read search write add_name create remove_name rmdir }; 225 …steboard_service:dir { read write create getattr setattr open add_name remove_name search rmdir io…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/drivers/peripheral/usb/vendor/ |
H A D | init.te | 14 allow init configfs:dir { add_name create mounton open read search setattr write remove_name }; 19 allow init data_service_el1_file:dir { relabelto getattr search write add_name remove_name read ope…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/communication/nfc/system/ |
H A D | nfc_service.te | 26 allow nfc_service hiview_file:dir { open read remove_name search write }; 30 #avc:denied { remove_name } scontext=u:r:nfc_service:s0 tcontext=u:object_r:data_nfc:s0 tclass=dir 31 allow nfc_service data_nfc:dir { write add_name remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/security/access_token/system/ |
H A D | neverallow.te | 17 …cesstoken_service accesstoken_data_file:dir ~{ search add_name open read write remove_name ioctl }; 23 neverallow privacy_service accesstoken_data_file:dir ~{ search add_name open read write remove_name…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/base/te/ |
H A D | kernel.te | 19 allow kernel device:dir { add_name remove_name rmdir search write }; 23 allow kernel pstorefs:dir { open read remove_name search write };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/multimedia/player/system/ |
H A D | normal_hap.te | 14 #avc: denied { remove_name } for pid=1916 comm="com.ohos.medial" name="03.jpg" dev="mmcblk0p11" … 15 allow normal_hap_attr data_user_file:dir { remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/drivers/peripheral/thermal/vendor/ |
H A D | power_host.te | 17 #avc: denied { remove_name } for pid=436 comm="power_host" name="thermal.007.20220724-172607" dev="… 18 allow power_host data_log:dir { open read remove_name search write open read remove_name write sear…
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/print/print_service/system/ |
H A D | scan_service.te | 28 allow scan_service data_service_el1_public_print_service_file:dir { search remove_name add_name wri… 59 allow scan_service data_service_el2_file:dir { add_name remove_name search write }; 69 …w installs data_service_scan_service_driver_file:dir { write add_name search getattr remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/liteos/toybox/public/ |
H A D | sh.te | 70 # avc: denied { write remove_name search } for pid=25100, comm="bin/rm" scontext=u:r:sh:s0 tcontext… 71 allow sh hmdfs:dir { write remove_name search rmdir }; 76 # avc: denied { write remove_name search } for pid=25100, comm="bin/rm" scontext=u:r:sh:s0 tcontext… 77 allow sh data_user_file:dir { write remove_name search rmdir };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/drivers/adapter/vendor/ |
H A D | ueventd.te | 14 #avc: denied { remove_name } for pid=2085 comm="ueventd" name="sample_service1" dev="tmpfs" ino=… 20 allow ueventd dev_file:dir { remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/update/sys_installer_sa/system/ |
H A D | sys_installer_sa.te | 59 allow sys_installer_sa data_ota_package:dir { add_name search write remove_name }; 63 allow sys_installer_sa data_updater_file:dir { add_name search write remove_name getattr }; 72 allow sys_installer_sa update_firmware_file:dir { add_name search write remove_name getattr append … 109 # avc: denied { remove_name } for pid=1092 comm="IPC_2_1112" name="updater_binary" dev="tmpfs" i… 110 allow sys_installer_sa tmpfs:dir { add_name open read write remove_name };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/security/asset/system/ |
H A D | asset_service.te | 16 …_service_el1_public_asset_service_file:dir { add_name create open read remove_name search write rm… 22 …a_service_el2_user_id_asset_service_file:dir { search write add_name open read remove_name ioctl };
|
/ohos5.0/base/security/selinux_adapter/sepolicy/ohos_policy/distributeddatamgr/pasteboard/system/ |
H A D | pasteboard_service.te | 37 …e_el2_pasteboard_service:dir { read write create getattr open add_name remove_name search rmdir io… 41 allow storage_daemon data_service_el2_pasteboard_service:dir { relabelto lock rename remove_name rm…
|