blob: ea3f05486dfea7635b5b6a805229acc54189a08c [file] [log] [blame]
Ray Essick090f4a42016-12-02 11:26:54 -08001# mediaanalytics - daemon for collecting media analytics data
2type mediaanalytics, domain;
3type mediaanalytics_exec, exec_type, file_type;
4
5
6binder_use(mediaanalytics)
7binder_call(mediaanalytics, binderservicedomain)
8binder_service(mediaanalytics)
9
10allow mediaanalytics mediaanalytics_service:service_manager add;
11
12allow mediaanalytics system_server:fd use;
13
14r_dir_file(mediaanalytics, cgroup)
15allow mediaanalytics proc_meminfo:file r_file_perms;
16
17###
18### neverallow rules
19###
20
21# mediaanalytics should never execute any executable without a
22# domain transition
23neverallow mediaanalytics { file_type fs_type }:file execute_no_trans;
24
25# mediaanalytics should never need network access. Disallow network sockets.
26neverallow mediaanalytics domain:{ tcp_socket udp_socket rawip_socket } *;