Gitiles
Code Review
Sign In
gerrit-public.fairphone.software
/
fp2-dev
/
platform
/
external
/
sepolicy
/
17859404f6a1030488a657c4c406a7b83ea9957c
1785940
Address dnsmasq denials.
by Stephen Smalley
· 10 years ago
d9d9d2f
temp fix for build breakage.
by Nick Kralevich
· 10 years ago
d331e00
Do not allow system_server to access SDcard files.
by Stephen Smalley
· 10 years ago
3dad7b6
Address system_server denials.
by Stephen Smalley
· 10 years ago
23a52e6
allow lmkd to kill processes.
by Nick Kralevich
· 10 years ago
2737cef
Allow stat/read of /data/media files by app domains.
by Stephen Smalley
· 10 years ago
495e9d1
Allow getopt / getattr to bluetooth unix_stream_socket.
by Stephen Smalley
· 10 years ago
28afdd9
Deduplicate binder_call rules.
by Stephen Smalley
· 10 years ago
63b98b1
restore system_server zygote socket rules
by Nick Kralevich
· 10 years ago
f197f8c
Merge "Remove system_server and zygote unlabeled execute access."
by Nick Kralevich
· 10 years ago
b19a191
Merge "Give lmkd kill capability"
by Nick Kralevich
· 10 years ago
0a5f561
uncrypt: allow /dev/block directory access.
by Nick Kralevich
· 10 years ago
24be391
Give lmkd kill capability
by Nick Kralevich
· 10 years ago
37afd3f
Remove system_server and zygote unlabeled execute access.
by Stephen Smalley
· 10 years ago
0296b94
Move qemud and /dev/qemu policy bits to emulator-specific sepolicy.
by Stephen Smalley
· 10 years ago
2c347e0
Drop obsolete keystore_socket type and rules.
by Stephen Smalley
· 10 years ago
dc1cedf
Merge "Clean up socket rules."
by Nick Kralevich
· 10 years ago
de4ff59
Merge "Drop levelFrom=none from untrusted_app entry."
by Nick Kralevich
· 10 years ago
1601132
Clean up socket rules.
by Stephen Smalley
· 10 years ago
85708ec
Resolve overlapping rules between app.te and net.te.
by Stephen Smalley
· 10 years ago
96ff4c0
Add a domain for mdnsd and allow connecting to it.
by Stephen Smalley
· 10 years ago
d107abd
Merge "Remove fsetid from netd."
by Nick Kralevich
· 10 years ago
d581b81
Remove fsetid from netd.
by Stephen Smalley
· 10 years ago
798668f
Merge "Generalize rmnet entry for radio properties."
by Nick Kralevich
· 10 years ago
77470da
Merge "Remove compatibility rules for old /data/media type."
by Nick Kralevich
· 10 years ago
111966d
Merge "Remove redundant socket rules."
by Nick Kralevich
· 10 years ago
6006147
Merge "uncrypt: move into enforcing"
by Nick Kralevich
· 10 years ago
75ac64c
Merge "Allow reading of /data/security/current symlink."
by Nick Kralevich
· 10 years ago
8673468
Drop levelFrom=none from untrusted_app entry.
by Stephen Smalley
· 10 years ago
68deff2
Remove compatibility rules for old /data/media type.
by Stephen Smalley
· 10 years ago
16a6652
Generalize rmnet entry for radio properties.
by Stephen Smalley
· 10 years ago
f926817
Allow reading of /data/security/current symlink.
by Stephen Smalley
· 10 years ago
35102f5
Drop rules for /data/misc/adb legacy type.
by Stephen Smalley
· 10 years ago
1eb9403
Remove redundant socket rules.
by Stephen Smalley
· 10 years ago
2a36dff
Merge "Address SELinux denials with clatd."
by Nick Kralevich
· 10 years ago
5a98304
uncrypt: move into enforcing
by Nick Kralevich
· 10 years ago
a770ee5
Address SELinux denials with clatd.
by Stephen Smalley
· 10 years ago
a88af85
Merge "Clarify meaning of untrusted_app and app domain assignment logic."
by Nick Kralevich
· 10 years ago
d28ac52
Merge "Clarify init_shell, shell, and su domain usage."
by Nick Kralevich
· 10 years ago
49d713a
Merge "Ensure that /data/misc/wifi/sockets is always labeled wpa_socket."
by Nick Kralevich
· 10 years ago
b3cb969
Clarify init_shell, shell, and su domain usage.
by Stephen Smalley
· 10 years ago
d823f83
Clarify meaning of untrusted_app and app domain assignment logic.
by Stephen Smalley
· 10 years ago
335faf2
Allow stat of /sys/module/lowmemorykiller files by system_server.
by Stephen Smalley
· 10 years ago
7ade68d
Ensure that /data/misc/wifi/sockets is always labeled wpa_socket.
by Stephen Smalley
· 10 years ago
b73d321
Merge "Create a label for the root block device."
by Nick Kralevich
· 10 years ago
b8298d7
Merge "Add support for and use new path= specifier in seapp_contexts."
by Nick Kralevich
· 10 years ago
af99ed8
uncrypt: allow /data/local/tmp on userdebug/eng
by Nick Kralevich
· 10 years ago
dfef99a
Create a label for the root block device.
by Robert Craig
· 10 years ago
96eeb1e
initial policy for uncrypt.
by Nick Kralevich
· 10 years ago
41f221f
Merge "Delete unnecessary /data/data entries."
by Nick Kralevich
· 10 years ago
a08cbe1
Merge "lmkd: add sys_resource"
by Nick Kralevich
· 10 years ago
1c73a5c
lmkd: add sys_resource
by Nick Kralevich
· 10 years ago
6139de5
Add support for and use new path= specifier in seapp_contexts.
by Stephen Smalley
· 10 years ago
f4c6579
Delete unnecessary /data/data entries.
by Stephen Smalley
· 10 years ago
116a20f
debuggerd: Allow "debug.db.uid" usage
by Nick Kralevich
· 10 years ago
ba3f9b8
Merge "Allow sdcardd to write to sdcard directory and file."
by Nick Kralevich
· 10 years ago
a475ce7
Merge "Allow dhcp rawip_socket permissions."
by Nick Kralevich
· 10 years ago
7b52ebf
Allow sdcardd to write to sdcard directory and file.
by Stephen Smalley
· 10 years ago
e55aac2
Add debuggerd64 entry for 64-bit debuggerd daemon
by Dan Willemsen
· 10 years ago
515a76b
Allow dhcp rawip_socket permissions.
by dcashman
· 10 years ago
5fa2a19
Make lmkd enforcing.
by Nick Kralevich
· 10 years ago
5467fce
initial lmkd policy.
by Nick Kralevich
· 10 years ago
af21e71
Merge "Make the sdcardd domain enforcing."
by Nick Kralevich
· 10 years ago
bfa785a
Merge "Make racoon permissive or unconfined."
by Nick Kralevich
· 10 years ago
9f5241e
Merge "Remove block device access from unconfined domains."
by Nick Kralevich
· 10 years ago
00abfd6
Merge "Make ppp permissive or unconfined."
by Nick Kralevich
· 10 years ago
9145918
Merge "Make mtp permissive or unconfined."
by Nick Kralevich
· 10 years ago
a792bca
Merge "Make dnsmasq permissive or unconfined."
by Nick Kralevich
· 10 years ago
4ba8707
Merge "Update hostapd domain for /data/misc/wifi/sockets label change."
by Nick Kralevich
· 10 years ago
bbfa352
Merge "Make inputflinger permissive or unconfined."
by Nick Kralevich
· 10 years ago
b5558aa
Merge "Make lmkd permissive or unconfined."
by Nick Kralevich
· 10 years ago
d20c0c2
Merge "Finish fixing Zygote descriptor leakage problem"
by Dave Platt
· 10 years ago
3f40d4f
Remove block device access from unconfined domains.
by Stephen Smalley
· 10 years ago
5487ca0
Remove several superuser capabilities from unconfined domains.
by Stephen Smalley
· 10 years ago
3db328f
Merge "Make clatd permissive or unconfined."
by Daniel Cashman
· 10 years ago
b081cc1
Remove mount-related permissions from unconfined domains.
by Stephen Smalley
· 10 years ago
48b1883
Introduce asec_public_file type.
by Robert Craig
· 10 years ago
f206737
Update hostapd domain for /data/misc/wifi/sockets label change.
by Stephen Smalley
· 10 years ago
f321456
Make clatd permissive or unconfined.
by Stephen Smalley
· 10 years ago
c6a28f0
Make dnsmasq permissive or unconfined.
by Stephen Smalley
· 11 years ago
5970259
Make mtp permissive or unconfined.
by Stephen Smalley
· 11 years ago
cc65fe8
Make ppp permissive or unconfined.
by Stephen Smalley
· 11 years ago
97f7c82
Make racoon permissive or unconfined.
by Stephen Smalley
· 11 years ago
2561a9a
Make lmkd permissive or unconfined.
by Stephen Smalley
· 10 years ago
38b7f43
Make inputflinger permissive or unconfined.
by Stephen Smalley
· 10 years ago
49bd91d
Make the sdcardd domain enforcing.
by Stephen Smalley
· 10 years ago
e21871c
Address screenrecord denials.
by rpcraig
· 10 years ago
0b218ec
Finish fixing Zygote descriptor leakage problem
by Dave Platt
· 10 years ago
629c98c
Fix NFC image transfer
by Nick Kralevich
· 10 years ago
10baf47
Merge "Revert "Move tlcd_sock policy over to manta.""
by Nick Kralevich
· 10 years ago
1a1ad95
Revert "Move tlcd_sock policy over to manta."
by Nick Kralevich
· 10 years ago
94e0652
Merge "Add file_contexts entries for socket files."
by Nick Kralevich
· 10 years ago
a7e4ace
Add file_contexts entries for socket files.
by Stephen Smalley
· 10 years ago
8cd400d
Move tlcd_sock policy over to manta.
by Stephen Smalley
· 10 years ago
ba1a731
allow wpa_cli to work.
by Nick Kralevich
· 10 years ago
418e2ab
Label /data/misc/wifi/sockets with wpa_socket.
by Stephen Smalley
· 10 years ago
8ed750e
sepolicy: Add write_logd, read_logd & control_logd
by Mark Salyzyn
· 11 years ago
a637b2f
assert: Do not allow access to generic device:chr_file
by William Roberts
· 10 years ago
d0919ec
assert: do not allow raw access to generic block_device
by William Roberts
· 10 years ago
b71dae8
Merge "drmserver: allow looking in efs_file directories"
by Nick Kralevich
· 10 years ago
Next »