# adbd seclabel is specified in init.rc since | |
# it lives in the rootfs and has no unique file type. | |
type adbd, domain; | |
type adbd_exec, exec_type, file_type, system_file_type; | |
# Only init is allowed to enter the adbd domain via exec() | |
neverallow { domain -init } adbd:process transition; | |
neverallow * adbd:process dyntransition; | |
# Allow adbd start/stop mdnsd via ctl.start | |
set_prop(adbd, ctl_mdnsd_prop) |