1###
2### Untrusted_27.
3###
4### This file defines the rules for untrusted apps running with
5### 25 < targetSdkVersion <= 27.
6###
7### This file defines the rules for untrusted apps.
8### Apps are labeled based on mac_permissions.xml (maps signer and
9### optionally package name to seinfo value) and seapp_contexts (maps UID
10### and optionally seinfo value to domain for process and type for data
11### directory).  The untrusted_app_27 domain is the default assignment in
12### seapp_contexts for any app with UID between APP_AID (10000)
13### and AID_ISOLATED_START (99000) if the app has no specific seinfo
14### value as determined from mac_permissions.xml.  In current AOSP, this
15### domain is assigned to all non-system apps as well as to any system apps
16### that are not signed by the platform key.  To move
17### a system app into a specific domain, add a signer entry for it to
18### mac_permissions.xml and assign it one of the pre-existing seinfo values
19### or define and use a new seinfo value in both mac_permissions.xml and
20### seapp_contexts.
21###
22
23typeattribute untrusted_app_27 coredomain;
24
25app_domain(untrusted_app_27)
26untrusted_app_domain(untrusted_app_27)
27net_domain(untrusted_app_27)
28bluetooth_domain(untrusted_app_27)
29