1. 4ba8707 Merge "Update hostapd domain for /data/misc/wifi/sockets label change." by Nick Kralevich · 11 years ago
  2. bbfa352 Merge "Make inputflinger permissive or unconfined." by Nick Kralevich · 11 years ago
  3. b5558aa Merge "Make lmkd permissive or unconfined." by Nick Kralevich · 11 years ago
  4. d20c0c2 Merge "Finish fixing Zygote descriptor leakage problem" by Dave Platt · 11 years ago
  5. 5487ca0 Remove several superuser capabilities from unconfined domains. by Stephen Smalley · 11 years ago
  6. 3db328f Merge "Make clatd permissive or unconfined." by Daniel Cashman · 11 years ago
  7. b081cc1 Remove mount-related permissions from unconfined domains. by Stephen Smalley · 11 years ago
  8. 48b1883 Introduce asec_public_file type. by Robert Craig · 11 years ago
  9. f206737 Update hostapd domain for /data/misc/wifi/sockets label change. by Stephen Smalley · 11 years ago
  10. f321456 Make clatd permissive or unconfined. by Stephen Smalley · 11 years ago
  11. 2561a9a Make lmkd permissive or unconfined. by Stephen Smalley · 11 years ago
  12. 38b7f43 Make inputflinger permissive or unconfined. by Stephen Smalley · 11 years ago
  13. e21871c Address screenrecord denials. by rpcraig · 11 years ago
  14. 0b218ec Finish fixing Zygote descriptor leakage problem by Dave Platt · 11 years ago
  15. 629c98c Fix NFC image transfer by Nick Kralevich · 11 years ago
  16. 10baf47 Merge "Revert "Move tlcd_sock policy over to manta."" by Nick Kralevich · 11 years ago
  17. 1a1ad95 Revert "Move tlcd_sock policy over to manta." by Nick Kralevich · 11 years ago
  18. 94e0652 Merge "Add file_contexts entries for socket files." by Nick Kralevich · 11 years ago
  19. a7e4ace Add file_contexts entries for socket files. by Stephen Smalley · 11 years ago
  20. 8cd400d Move tlcd_sock policy over to manta. by Stephen Smalley · 11 years ago
  21. ba1a731 allow wpa_cli to work. by Nick Kralevich · 11 years ago
  22. 418e2ab Label /data/misc/wifi/sockets with wpa_socket. by Stephen Smalley · 11 years ago
  23. 8ed750e sepolicy: Add write_logd, read_logd & control_logd by Mark Salyzyn · 11 years ago
  24. a637b2f assert: Do not allow access to generic device:chr_file by William Roberts · 11 years ago
  25. d0919ec assert: do not allow raw access to generic block_device by William Roberts · 11 years ago
  26. b71dae8 Merge "drmserver: allow looking in efs_file directories" by Nick Kralevich · 11 years ago
  27. 9dbd005 Update README. by Robert Craig · 11 years ago
  28. d4f6c5f Merge "Catch nonexistent BOARD_SEPOLICY_UNION policy files." by Nick Kralevich · 11 years ago
  29. 7cbe44f drmserver: allow looking in efs_file directories by Nick Kralevich · 11 years ago
  30. 8d9ef06 Merge "Remove MAC capabilities from unconfined domains." by Nick Kralevich · 11 years ago
  31. 04ee5df Remove MAC capabilities from unconfined domains. by Stephen Smalley · 11 years ago
  32. 0cbf06f Drop the typealias for camera_calibration_file. by Robert Craig · 11 years ago
  33. 208deb3 Allow dumpstate to run am and shell. by Stephen Smalley · 11 years ago
  34. 6b0ff47 Catch nonexistent BOARD_SEPOLICY_UNION policy files. by Robert Craig · 11 years ago
  35. 997680a bluetooth: allow media_rw_data_file by Nick Kralevich · 11 years ago
  36. c669667 Merge "fix healthd charger mode." by Nick Kralevich · 11 years ago
  37. 251ba76 Allow "mkdir /sdcard/foo" by Nick Kralevich · 11 years ago
  38. 0352393 fix healthd charger mode. by Nick Kralevich · 11 years ago
  39. dffe634 Merge "Make drmserver enforcing." by Nick Kralevich · 11 years ago
  40. 1935173 Merge "Move adbd into enforcing (all build types)" by Nick Kralevich · 11 years ago
  41. f956366 Move adbd into enforcing (all build types) by Nick Kralevich · 11 years ago
  42. fed8a2a Remove transition / dyntransition from unconfined by Nick Kralevich · 11 years ago
  43. 5eca63f Make drmserver enforcing. by Nick Kralevich · 11 years ago
  44. 76d1476 Merge "Allow all appdomains to grab file attributes of wallpaper_file." by Nick Kralevich · 11 years ago
  45. 5c9c312 Move shell into enforcing for everyone. by Nick Kralevich · 11 years ago
  46. d233350 Merge "Support running adbd in the su domain." by Nick Kralevich · 11 years ago
  47. fc4c6b7 Allow all appdomains to grab file attributes of wallpaper_file. by Robert Craig · 11 years ago
  48. 7d0f955 Support running adbd in the su domain. by Nick Kralevich · 11 years ago
  49. 2c1a0ad Make healthd enforcing. by Stephen Smalley · 11 years ago
  50. 190c704 Allow healthd to read/write /dev/__null_. by Stephen Smalley · 11 years ago
  51. 129f8df Allow mediaserver to create dirs under /data/mediadrm. by rpcraig · 11 years ago
  52. 2e7a301 Address bug report denials. by Nick Kralevich · 11 years ago
  53. d14e9de Make bluetooth enforcing (again). by Stephen Smalley · 11 years ago
  54. 09f6a99 Allow mediaserver to connect to bluetooth. by Stephen Smalley · 11 years ago
  55. 94f322e Remove /sys/class/rfkill/rfkill.* lines by Nick Kralevich · 11 years ago
  56. 05e719b Merge "Allow drmserver to unlink old socket file." by Nick Kralevich · 11 years ago
  57. e9d3660 Merge "Make wpa_supplicant enforcing." by Nick Kralevich · 11 years ago
  58. d9b8ef4 Drop legacy device types. by Stephen Smalley · 11 years ago
  59. e11935d Allow drmserver to unlink old socket file. by Stephen Smalley · 11 years ago
  60. 5eab3ab Merge "Confine gpsd, but leave it permissive for now." by Nick Kralevich · 11 years ago
  61. b1016ed Make hci_attach enforcing. by Stephen Smalley · 11 years ago
  62. 63c26f6 Make wpa_supplicant enforcing. by Stephen Smalley · 11 years ago
  63. a60abdc Confine gpsd, but leave it permissive for now. by Stephen Smalley · 11 years ago
  64. 08fffc5 Revert "Revert "Strip file execute permissions from unconfined domains."" by Stephen Smalley · 11 years ago
  65. 8aae7bd Revert "Revert "Strip exec* permissions from unconfined domains."" by Stephen Smalley · 11 years ago
  66. 9fe4e7b ashmem_device is a character device, not a regular file. by Stephen Smalley · 11 years ago
  67. 9a40702 Allow recovery to execute ashmem_device and tmpfs. by Stephen Smalley · 11 years ago
  68. 810fc5d Merge "Add an exception for bluetooth to the sysfs neverallow rule." by Nick Kralevich · 11 years ago
  69. 7611b60 Merge "Support forcing permissive domains to unconfined." by Nick Kralevich · 11 years ago
  70. 570e5f4 Move adbd into enforcing on user devices by Nick Kralevich · 11 years ago
  71. 200e97d Merge "Add a domain for the recovery console." by Nick Kralevich · 11 years ago
  72. 6d10ca8 Add a domain for the recovery console. by Stephen Smalley · 11 years ago
  73. df8af76 Add an exception for bluetooth to the sysfs neverallow rule. by Stephen Smalley · 11 years ago
  74. 40ce0bb allow adbd setpcap by Nick Kralevich · 11 years ago
  75. 623975f Support forcing permissive domains to unconfined. by Nick Kralevich · 11 years ago
  76. 06a0d78 Merge "Revert "Strip exec* permissions from unconfined domains."" by Nick Kralevich · 11 years ago
  77. 89740a6 Revert "Strip exec* permissions from unconfined domains." by Nick Kralevich · 11 years ago
  78. e030950 Merge "Do not allow zygote to execve dalvikcache files." by Nick Kralevich · 11 years ago
  79. e210b20 Merge "Revert "Make bluetooth enforcing."" by Nick Kralevich · 11 years ago
  80. 85396e9 Revert "Make bluetooth enforcing." by Nick Kralevich · 11 years ago
  81. d7da665 Merge "Create new conditional userdebug_or_eng" by Nick Kralevich · 11 years ago
  82. 41a487d Merge "Revert "Strip file execute permissions from unconfined domains."" by Nick Kralevich · 11 years ago
  83. 43ddc10 Revert "Strip file execute permissions from unconfined domains." by Nick Kralevich · 11 years ago
  84. 88ce951 Create new conditional userdebug_or_eng by Nick Kralevich · 11 years ago
  85. 49c995d Do not allow zygote to execve dalvikcache files. by Stephen Smalley · 11 years ago
  86. 39fd781 Remove domain init:unix_stream_socket connectto permission. by Stephen Smalley · 11 years ago
  87. aef4a46 Merge "Remove legacy rules from dumpstate in init domain." by Nick Kralevich · 11 years ago
  88. 6933416 Merge changes Ib3604537,I6f5715eb by Nick Kralevich · 11 years ago
  89. 38b8fc8 Remove legacy rules from dumpstate in init domain. by Stephen Smalley · 11 years ago
  90. d832a6d Merge "Strip file execute permissions from unconfined domains." by Nick Kralevich · 11 years ago
  91. c75e35a Merge "Strip exec* permissions from unconfined domains." by Nick Kralevich · 11 years ago
  92. 91c290b Allow access to unlabeled socket and fifo files. by Stephen Smalley · 11 years ago
  93. 959fdaa Remove unlabeled execute access from domain, add to appdomain. by Stephen Smalley · 11 years ago
  94. c50bf17 Address new system server denial. by Robert Craig · 11 years ago
  95. 1dd3184 Merge "address denials when playing protected content." by Nick Kralevich · 11 years ago
  96. b23d287 Allow keystore to talk to the tee by Nick Kralevich · 11 years ago
  97. e45603d address denials when playing protected content. by Nick Kralevich · 11 years ago
  98. d362cdf Apply a label to /data/mediadrm files. by rpcraig · 11 years ago
  99. 84a81d1 Merge "Restrict ability to set checkreqprot." by Nick Kralevich · 11 years ago
  100. 5da0881 Strip file execute permissions from unconfined domains. by Stephen Smalley · 11 years ago