blob: 60e2274be354b5df836c8f3b930040659f4a33e4 [file] [log] [blame]
Nick Kralevich929da012017-02-16 12:04:40 -08001# /proc/config.gz
Tri Vo41bf08e2018-02-15 18:07:18 -08002type config_gz, fs_type, proc_type;
Dan Cashman91d398d2017-09-26 12:58:29 -07003
Maciej Żenczykowskib13921c2022-05-21 05:03:29 -07004# /sys/fs/bpf/<dir> for mainline tethering use
5# TODO: move S+ fs_bpf_tethering here from public/file.te
6type fs_bpf_net_private, fs_type, bpffs_type;
7type fs_bpf_net_shared, fs_type, bpffs_type;
8type fs_bpf_netd_readonly, fs_type, bpffs_type;
9type fs_bpf_netd_shared, fs_type, bpffs_type;
10
Dan Cashman91d398d2017-09-26 12:58:29 -070011# /data/misc/storaged
12type storaged_data_file, file_type, data_file_type, core_data_file_type;
Vishnu Nair2d6942d2017-11-17 08:23:32 -080013
14# /data/misc/wmtrace for wm traces
15type wm_trace_data_file, file_type, data_file_type, core_data_file_type;
Primiano Tucci1a9f4f72018-01-24 16:07:09 +000016
Hongming Jin58f83412021-02-09 12:03:40 -080017# /data/misc/a11ytrace for accessibility traces
18type accessibility_trace_data_file, file_type, data_file_type, core_data_file_type;
19
Primiano Tucci1a9f4f72018-01-24 16:07:09 +000020# /data/misc/perfetto-traces for perfetto traces
21type perfetto_traces_data_file, file_type, data_file_type, core_data_file_type;
Dan Austin55d90962018-11-29 10:37:18 -080022
Primiano Tucci2f998092021-01-07 17:12:21 +000023# /data/misc/perfetto-traces/bugreport for perfetto traces for bugreports.
24type perfetto_traces_bugreport_data_file, file_type, data_file_type, core_data_file_type;
25
Primiano Tucci512bdb92020-10-13 21:13:09 +010026# /data/misc/perfetto-configs for perfetto configs
27type perfetto_configs_data_file, file_type, data_file_type, core_data_file_type;
28
Mohammad Samiul Islamd2ffd352022-05-11 21:43:54 +010029# /data/misc_{ce/de}/<user>/sdksandbox root data directory for sdk sandbox processes
30type sdk_sandbox_system_data_file, file_type, data_file_type, core_data_file_type;
Bram Bonneb93f26f2022-03-15 18:28:02 +010031# /data/misc_{ce/de}/<user>/sdksandbox/<app-name>/* subdirectory for sdk sandbox processes
32type sdk_sandbox_data_file, file_type, data_file_type, core_data_file_type, app_data_file_type;
33
Dan Austin55d90962018-11-29 10:37:18 -080034# /sys/kernel/debug/kcov for coverage guided kernel fuzzing in userdebug builds.
35type debugfs_kcov, fs_type, debugfs_type;
36
Nick Kralevichfb66c6f2019-01-11 09:37:46 -080037# App executable files in /data/data directories
38type app_exec_data_file, file_type, data_file_type, core_data_file_type;
39typealias app_exec_data_file alias rs_data_file;
Narayan Kamath2ad229c2019-01-14 15:02:12 +000040
41# /data/misc_[ce|de]/rollback : Used by installd to store snapshots
42# of application data.
43type rollback_data_file, file_type, data_file_type, core_data_file_type;
Kiyoung Kimaffa6f32019-07-08 19:02:05 +090044
Tianjieb729aa62021-10-05 22:13:20 -070045# /data/misc_ce/checkin for checkin apps.
46type checkin_data_file, file_type, data_file_type, core_data_file_type;
47
Yifan Hong07a99e12019-08-07 13:01:15 -070048# /data/gsi/ota
49type ota_image_data_file, file_type, data_file_type, core_data_file_type;
Shuo Qian9322cb02019-10-15 13:13:56 -070050
Howard Chen55665d62020-12-25 17:32:13 +080051# /data/gsi_persistent_data
52type gsi_persistent_data_file, file_type, data_file_type, core_data_file_type;
53
Shuo Qian9322cb02019-10-15 13:13:56 -070054# /data/misc/emergencynumberdb
55type emergency_data_file, file_type, data_file_type, core_data_file_type;
Yi Kong239c85d2020-06-18 12:43:23 +080056
57# /data/misc/profcollectd
58type profcollectd_data_file, file_type, data_file_type, core_data_file_type;
Orion Hodson8f75f762020-10-16 15:29:55 +010059
60# /data/misc/apexdata/com.android.art
Alan Stokesfa10a142021-07-12 14:21:48 +010061type apex_art_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
Orion Hodson8f75f762020-10-16 15:29:55 +010062
63# /data/misc/apexdata/com.android.art/staging
64type apex_art_staging_data_file, file_type, data_file_type, core_data_file_type;
Seigo Nonaka9c3707f2021-01-21 13:08:31 -080065
Alan Stokes10fbf232021-07-12 15:12:37 +010066# /data/misc/apexdata/com.android.compos
67type apex_compos_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
68
Alan Stokes53c76a22022-02-08 15:44:06 +000069# legacy labels for various /data/misc[_ce|_de]/*/apexdata directories - retained
70# for backward compatibility b/217581286
71type apex_appsearch_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
72type apex_permission_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
73type apex_scheduling_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
Junyu Laic43dbf82022-04-20 18:48:06 +080074type apex_tethering_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
Alan Stokes53c76a22022-02-08 15:44:06 +000075type apex_wifi_data_file, file_type, data_file_type, core_data_file_type, apex_data_file_type;
76
Seigo Nonaka9c3707f2021-01-21 13:08:31 -080077# /data/font/files
78type font_data_file, file_type, data_file_type, core_data_file_type;
Martijn Coenen6afdb722020-11-27 12:23:54 +010079
Alexander Potapenko0a64d102022-01-28 19:48:27 +010080# /data/misc/dmesgd
81type dmesgd_data_file, file_type, data_file_type, core_data_file_type;
82
Orion Hodson7c6b3eb2021-04-09 15:17:38 +010083# /data/misc/odrefresh
84type odrefresh_data_file, file_type, data_file_type, core_data_file_type;
85
Martijn Coenen6afdb722020-11-27 12:23:54 +010086# /data/misc/odsign
87type odsign_data_file, file_type, data_file_type, core_data_file_type;
satayevafc97912021-03-19 11:08:49 +000088
Shikha Panwar36daf982022-02-24 11:50:35 +000089# /data/misc/odsign_metrics
90type odsign_metrics_file, file_type, data_file_type, core_data_file_type;
91
Andrew Walbran654c5b02021-05-19 17:10:43 +000092# /data/misc/virtualizationservice
93type virtualizationservice_data_file, file_type, data_file_type, core_data_file_type;
94
satayevafc97912021-03-19 11:08:49 +000095# /data/system/environ
96type environ_system_data_file, file_type, data_file_type, core_data_file_type;
Andrew Walbrana995e842021-03-29 17:19:12 +000097
Josh Yang1d967dd2021-12-23 14:37:41 -080098# /data/bootanim
99type bootanim_data_file, file_type, data_file_type, core_data_file_type;
100
Andrew Walbrana995e842021-03-29 17:19:12 +0000101# /dev/kvm
102type kvm_device, dev_type;
Alan Stokesec4a90f2021-09-21 13:32:24 +0100103
104# /apex/com.android.virt/bin/fd_server
105type fd_server_exec, system_file_type, exec_type, file_type;
Jeff Vander Stoep5aa5e5e2021-11-17 08:51:11 +0100106
Alan Stokes766caba2022-02-14 14:33:37 +0000107# /apex/com.android.compos/bin/compsvc
108type compos_exec, exec_type, file_type, system_file_type;
109# /apex/com.android.compos/bin/compos_key_helper
110type compos_key_helper_exec, exec_type, file_type, system_file_type;
111
Jeff Vander Stoep5aa5e5e2021-11-17 08:51:11 +0100112# /metadata/sepolicy
113type sepolicy_metadata_file, file_type;
Jeff Vander Stoepbc0fa662021-12-03 15:21:54 +0100114
115# /dev/selinux/test - used to verify that apex sepolicy is loaded and
116# property labeled.
117type sepolicy_test_file, file_type;
Jiakai Zhangc871c1c2022-07-19 21:29:31 +0100118
119# /apex/com.android.art/bin/art_exec
120# This executable does not have its own domain because it is executed in the caller's domain. For
121# example, it is executed in the `artd` domain when artd calls it.
122type art_exec_exec, system_file_type, exec_type, file_type;
Pete Bentleye6da3b82022-09-16 15:31:39 +0100123
124# Filesystem entry for for PRNG seeder socket. Processes require
125# write permission on this to connect, and needs to be mlstrustedobject
126# in to satisfy MLS constraints for trusted domains.
127type prng_seeder_socket, file_type, coredomain_socket, mlstrustedobject;