configstore@1.1.policy 1.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455
  1. # Copyright (C) 2017 The Android Open Source Project
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. futex: 1
  15. # ioctl: arg1 == BINDER_WRITE_READ
  16. ioctl: arg1 == 0xc0306201
  17. # prctl: arg0 == PR_SET_NAME || arg0 == PR_SET_VMA || arg0 == PR_SET_TIMERSLACK
  18. # || arg0 == PR_GET_NO_NEW_PRIVS # used by crash_dump
  19. # prctl: arg0 == 15 || arg0 == 0x53564d41 || arg0 == 29 || arg0 == 39
  20. # TODO(b/68162846) reduce scope of prctl() based on arguments
  21. prctl: 1
  22. openat: 1
  23. mmap: 1
  24. mprotect: 1
  25. close: 1
  26. getuid: 1
  27. read: 1
  28. faccessat: 1
  29. write: 1
  30. fstat: 1
  31. clone: 1
  32. sched_setscheduler: 1
  33. munmap: 1
  34. lseek: 1
  35. sigaltstack: 1
  36. writev: 1
  37. setpriority: 1
  38. restart_syscall: 1
  39. exit: 1
  40. exit_group: 1
  41. rt_sigreturn: 1
  42. getrlimit: 1
  43. madvise: 1
  44. getdents64: 1
  45. clock_gettime: 1
  46. # used during process crash by crash_dump to dump process info
  47. rt_sigprocmask: 1
  48. rt_sigaction: 1
  49. # socket: arg0 == AF_LOCAL
  50. socket: arg0 == 1
  51. connect: 1
  52. recvmsg: 1
  53. rt_tgsigqueueinfo: 1