1. 9a725b2 Allow init to restorecon sysfs files. by Stephen Smalley · 10 years ago
  2. 57f1b89 lmkd: avoid locking libsigchain into memory by Nick Kralevich · 10 years ago
  3. 7563a6f reconcile aosp (a7c04dcd748e1a9daf374551303a3bd578305cf9) after branching. Please do not merge. by Ed Heyl · 10 years ago
  4. fee4915 Align SELinux property policy with init property_perms. by Stephen Smalley · 10 years ago
  5. 0db95cc unconfined: remove internet access by Nick Kralevich · 10 years ago
  6. c626a88 Allow init to relabel rootfs files. by Stephen Smalley · 10 years ago
  7. f3c3a1a Remove execute_no_trans from unconfineddomain. by Stephen Smalley · 10 years ago
  8. bac4ccc Prevent adding transitions to kernel or init domains. by Stephen Smalley · 10 years ago
  9. 75e2ef9 Restrict use of context= mount options. by Stephen Smalley · 10 years ago
  10. ee49c0e remove shell_data_file from unconfined. by Nick Kralevich · 10 years ago
  11. 3235f61 Restrict /data/security and setprop selinux.reload_policy access. by Stephen Smalley · 10 years ago
  12. 73b0346 Explictly allow init and kernel unlabeled access. by Stephen Smalley · 10 years ago
  13. eb1bbf2 Clean up kernel, init, and recovery domains. by Stephen Smalley · 10 years ago
  14. 03ce512 Remove /system write from unconfined by Nick Kralevich · 10 years ago
  15. ad0d0fc Protect /data/property. by Stephen Smalley · 10 years ago
  16. 685e2f9 remove syslog_* from unconfined by Nick Kralevich · 10 years ago
  17. 356f4be Restrict requesting contexts other than policy-defined defaults. by Stephen Smalley · 10 years ago
  18. 02dac03 Drop relabelto_domain() macro and its associated definitions. by Stephen Smalley · 11 years ago
  19. cd905ec Protect keystore's files. by Nick Kralevich · 11 years ago
  20. 3f40d4f Remove block device access from unconfined domains. by Stephen Smalley · 11 years ago
  21. 5487ca0 Remove several superuser capabilities from unconfined domains. by Stephen Smalley · 11 years ago
  22. b081cc1 Remove mount-related permissions from unconfined domains. by Stephen Smalley · 11 years ago
  23. fed8a2a Remove transition / dyntransition from unconfined by Nick Kralevich · 11 years ago
  24. fea6e66 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  25. 9e8b8d9 Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
  26. bf12e22 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  27. 7adb999 Restrict the ability to set usermodehelpers and proc security settings. by Stephen Smalley · 11 years ago
  28. d99e6d5 Restrict the ability to set SELinux enforcing mode to init. by Stephen Smalley · 11 years ago
  29. b1d8164 Make kernel / init enforcing by Nick Kralevich · 11 years ago
  30. 2637198 Only init should be able to load a security policy by Nick Kralevich · 11 years ago
  31. 0c9708b domain.te: Add backwards compatibility for unlabeled files by Nick Kralevich · 11 years ago
  32. 77d4731 Make all domains unconfined. by repo sync · 11 years ago
  33. 50e37b9 Move domains into per-domain permissive mode. by repo sync · 12 years ago
  34. 2dd4e51 SE Android policy. by Stephen Smalley · 13 years ago