1# Copyright (c) 2024 Huawei Device Co., Ltd. 2# Licensed under the Apache License, Version 2.0 (the "License"); 3# you may not use this file except in compliance with the License. 4# You may obtain a copy of the License at 5# 6# http://www.apache.org/licenses/LICENSE-2.0 7# 8# Unless required by applicable law or agreed to in writing, software 9# distributed under the License is distributed on an "AS IS" BASIS, 10# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 11# See the License for the specific language governing permissions and 12# limitations under the License. 13updater_only(` 14 15# avc_audit_slow:267] avc: denied { supervsable } for pid=796, comm="/bin/updater_binary" scontext=u:r:processdump:s0 tcontext=u:r:processdump:s0 tclass=hmcap permissive=1 16allow processdump processdump:hmcap { supervsable }; 17 18# avc_audit_slow:267] avc: denied { getattr } for pid=796, comm="/bin/processdump" path="/etc/ld-musl-namespace-aarch64.ini" dev="tmpfs" ino=323 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1 19# avc_audit_slow:267] avc: denied { open } for pid=796, comm="/bin/processdump" path="/etc/ld-musl-namespace-aarch64.ini" dev="tmpfs" ino=323 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1 20# avc_audit_slow:267] avc: denied { read execute } for pid=unknown, comm=unknown, cidx=0x0 path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=781 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1 21# avc_audit_slow:267] avc: denied { read } for pid=unknown, comm=unknown, cidx=0x0 path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=781 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1 22# avc_audit_slow:267] avc: denied { map } for pid=unknown, comm=unknown, cidx=0x0 path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=779 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=0 23allow processdump rootfs:file { getattr open read execute read map}; 24 25# avc_audit_slow:267] avc: denied { read } for pid=796, comm="/bin/processdump" name="/system/etc" dev="tmpfs" ino=997 scontext=u:r:processdump:s0 tcontext=u:object_r:system_etc_file:s0 tclass=lnk_file permissive=1 26allow processdump system_etc_file:lnk_file { read }; 27') 28