blob: 6c2e37db08b25ded15a5fdff33269419a177da5e [file] [log] [blame]
# Drop (user, group) to (nobody, nobody)
allow servicemanager self:capability { setuid setgid setpcap net_raw };
allow servicemanager init:dir search;
allow servicemanager init:file { read open };
allow servicemanager init:process getattr;
#HACK allow servicemanager init_shell:dir search;
#HACK allow servicemanager init_shell:file { read open };
#HACK allow servicemanager init_shell:process getattr;