| typeattribute shared_relro coredomain; |
| |
| # The shared relro process is a Java program forked from the zygote, so it |
| # inherits from app to get basic permissions it needs to run. |
| app_domain(shared_relro) |
| |
| allow shared_relro shared_relro_file:dir rw_dir_perms; |
| allow shared_relro shared_relro_file:file create_file_perms; |
| |
| allow shared_relro activity_service:service_manager find; |
| allow shared_relro webviewupdate_service:service_manager find; |
| allow shared_relro package_service:service_manager find; |
| |
| # StrictMode may attempt to find this service, failure is harmless. |
| dontaudit shared_relro network_management_service:service_manager find; |