1# Copyright (c) 2024 Huawei Device Co., Ltd.
2# Licensed under the Apache License, Version 2.0 (the "License");
3# you may not use this file except in compliance with the License.
4# You may obtain a copy of the License at
5#
6#     http://www.apache.org/licenses/LICENSE-2.0
7#
8# Unless required by applicable law or agreed to in writing, software
9# distributed under the License is distributed on an "AS IS" BASIS,
10# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
11# See the License for the specific language governing permissions and
12# limitations under the License.
13updater_only(`
14
15# avc_audit_slow:267] avc: denied { supervsable } for pid=796, comm="/bin/updater_binary"  scontext=u:r:processdump:s0 tcontext=u:r:processdump:s0 tclass=hmcap permissive=1
16allow processdump processdump:hmcap { supervsable };
17
18# avc_audit_slow:267] avc: denied { getattr } for pid=796, comm="/bin/processdump"  path="/etc/ld-musl-namespace-aarch64.ini" dev="tmpfs" ino=323 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1
19# avc_audit_slow:267] avc: denied { open } for pid=796, comm="/bin/processdump"  path="/etc/ld-musl-namespace-aarch64.ini" dev="tmpfs" ino=323 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1
20# avc_audit_slow:267] avc: denied { read execute } for pid=unknown, comm=unknown, cidx=0x0  path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=781 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1
21# avc_audit_slow:267] avc: denied { read } for pid=unknown, comm=unknown, cidx=0x0  path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=781 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=1
22# avc_audit_slow:267] avc: denied { map } for pid=unknown, comm=unknown, cidx=0x0  path="/lib/ld-musl-aarch64.so.1" dev="tmpfs" ino=779 scontext=u:r:processdump:s0 tcontext=u:object_r:rootfs:s0 tclass=file permissive=0
23allow processdump rootfs:file { getattr open read execute read map};
24
25# avc_audit_slow:267] avc: denied { read } for pid=796, comm="/bin/processdump"  name="/system/etc" dev="tmpfs" ino=997 scontext=u:r:processdump:s0 tcontext=u:object_r:system_etc_file:s0 tclass=lnk_file permissive=1
26allow processdump system_etc_file:lnk_file { read };
27')
28