• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1# init switches to init domain (via init.rc).
2type init, domain;
3permissive init;
4# init is unconfined.
5unconfined_domain(init)
6tmpfs_domain(init)
7relabelto_domain(init)
8# add a rule to handle unlabelled mounts
9allow init unlabeled:filesystem mount;
10
11allow init {fs_type dev_type file_type}:dir_file_class_set relabelto;
12allow init kernel:security load_policy;
13