blob: 3c37d2bc984c765ac425f916ec19dd85b6d09cbb [file] [log] [blame]
dcashmancc39f632016-07-22 13:13:11 -07001# type_transition must be private policy the domain_trans rules could stay
2# public, but conceptually should go with this
3init_daemon_domain(recovery_persist)
dcashman2e00e632016-10-12 14:58:09 -07004
5# recovery_persist is not allowed to write anywhere other than recovery_data_file
6# TODO: deal with tmpfs_domain pub/priv split properly
7neverallow recovery_persist { file_type -recovery_data_file -recovery_persist_tmpfs userdebug_or_eng(`-coredump_file') }:file write;