diff --git a/selinux/my-servicemanager.te b/selinux/my-servicemanager.te new file mode 100644 index 0000000..855244c --- /dev/null +++ b/selinux/my-servicemanager.te @@ -0,0 +1,10 @@ + +module my-servicemanager 1.0; + +require { + type unconfined_service_t; + class binder set_context_mgr; +} + +#============= unconfined_service_t ============== +allow unconfined_service_t self:binder set_context_mgr;