Gitiles
Code Review
Sign In
gerrit-public.fairphone.software
/
fp2-dev
/
platform
/
external
/
sepolicy
/
a792bca38e6a302fbf5f8d63eedf952e77f32c4d
a792bca
Merge "Make dnsmasq permissive or unconfined."
by Nick Kralevich
· 11 years ago
4ba8707
Merge "Update hostapd domain for /data/misc/wifi/sockets label change."
by Nick Kralevich
· 11 years ago
bbfa352
Merge "Make inputflinger permissive or unconfined."
by Nick Kralevich
· 11 years ago
b5558aa
Merge "Make lmkd permissive or unconfined."
by Nick Kralevich
· 11 years ago
d20c0c2
Merge "Finish fixing Zygote descriptor leakage problem"
by Dave Platt
· 11 years ago
5487ca0
Remove several superuser capabilities from unconfined domains.
by Stephen Smalley
· 11 years ago
3db328f
Merge "Make clatd permissive or unconfined."
by Daniel Cashman
· 11 years ago
b081cc1
Remove mount-related permissions from unconfined domains.
by Stephen Smalley
· 11 years ago
48b1883
Introduce asec_public_file type.
by Robert Craig
· 11 years ago
f206737
Update hostapd domain for /data/misc/wifi/sockets label change.
by Stephen Smalley
· 11 years ago
f321456
Make clatd permissive or unconfined.
by Stephen Smalley
· 11 years ago
c6a28f0
Make dnsmasq permissive or unconfined.
by Stephen Smalley
· 11 years ago
2561a9a
Make lmkd permissive or unconfined.
by Stephen Smalley
· 11 years ago
38b7f43
Make inputflinger permissive or unconfined.
by Stephen Smalley
· 11 years ago
e21871c
Address screenrecord denials.
by rpcraig
· 11 years ago
0b218ec
Finish fixing Zygote descriptor leakage problem
by Dave Platt
· 11 years ago
629c98c
Fix NFC image transfer
by Nick Kralevich
· 11 years ago
10baf47
Merge "Revert "Move tlcd_sock policy over to manta.""
by Nick Kralevich
· 11 years ago
1a1ad95
Revert "Move tlcd_sock policy over to manta."
by Nick Kralevich
· 11 years ago
94e0652
Merge "Add file_contexts entries for socket files."
by Nick Kralevich
· 11 years ago
a7e4ace
Add file_contexts entries for socket files.
by Stephen Smalley
· 11 years ago
8cd400d
Move tlcd_sock policy over to manta.
by Stephen Smalley
· 11 years ago
ba1a731
allow wpa_cli to work.
by Nick Kralevich
· 11 years ago
418e2ab
Label /data/misc/wifi/sockets with wpa_socket.
by Stephen Smalley
· 11 years ago
8ed750e
sepolicy: Add write_logd, read_logd & control_logd
by Mark Salyzyn
· 11 years ago
a637b2f
assert: Do not allow access to generic device:chr_file
by William Roberts
· 11 years ago
d0919ec
assert: do not allow raw access to generic block_device
by William Roberts
· 11 years ago
b71dae8
Merge "drmserver: allow looking in efs_file directories"
by Nick Kralevich
· 11 years ago
9dbd005
Update README.
by Robert Craig
· 11 years ago
d4f6c5f
Merge "Catch nonexistent BOARD_SEPOLICY_UNION policy files."
by Nick Kralevich
· 11 years ago
7cbe44f
drmserver: allow looking in efs_file directories
by Nick Kralevich
· 11 years ago
8d9ef06
Merge "Remove MAC capabilities from unconfined domains."
by Nick Kralevich
· 11 years ago
04ee5df
Remove MAC capabilities from unconfined domains.
by Stephen Smalley
· 11 years ago
0cbf06f
Drop the typealias for camera_calibration_file.
by Robert Craig
· 11 years ago
208deb3
Allow dumpstate to run am and shell.
by Stephen Smalley
· 11 years ago
6b0ff47
Catch nonexistent BOARD_SEPOLICY_UNION policy files.
by Robert Craig
· 11 years ago
997680a
bluetooth: allow media_rw_data_file
by Nick Kralevich
· 11 years ago
c669667
Merge "fix healthd charger mode."
by Nick Kralevich
· 11 years ago
251ba76
Allow "mkdir /sdcard/foo"
by Nick Kralevich
· 11 years ago
0352393
fix healthd charger mode.
by Nick Kralevich
· 11 years ago
dffe634
Merge "Make drmserver enforcing."
by Nick Kralevich
· 11 years ago
1935173
Merge "Move adbd into enforcing (all build types)"
by Nick Kralevich
· 11 years ago
f956366
Move adbd into enforcing (all build types)
by Nick Kralevich
· 11 years ago
fed8a2a
Remove transition / dyntransition from unconfined
by Nick Kralevich
· 11 years ago
5eca63f
Make drmserver enforcing.
by Nick Kralevich
· 11 years ago
76d1476
Merge "Allow all appdomains to grab file attributes of wallpaper_file."
by Nick Kralevich
· 11 years ago
5c9c312
Move shell into enforcing for everyone.
by Nick Kralevich
· 11 years ago
d233350
Merge "Support running adbd in the su domain."
by Nick Kralevich
· 11 years ago
fc4c6b7
Allow all appdomains to grab file attributes of wallpaper_file.
by Robert Craig
· 11 years ago
7d0f955
Support running adbd in the su domain.
by Nick Kralevich
· 11 years ago
2c1a0ad
Make healthd enforcing.
by Stephen Smalley
· 11 years ago
190c704
Allow healthd to read/write /dev/__null_.
by Stephen Smalley
· 11 years ago
129f8df
Allow mediaserver to create dirs under /data/mediadrm.
by rpcraig
· 11 years ago
2e7a301
Address bug report denials.
by Nick Kralevich
· 11 years ago
d14e9de
Make bluetooth enforcing (again).
by Stephen Smalley
· 11 years ago
09f6a99
Allow mediaserver to connect to bluetooth.
by Stephen Smalley
· 11 years ago
94f322e
Remove /sys/class/rfkill/rfkill.* lines
by Nick Kralevich
· 11 years ago
05e719b
Merge "Allow drmserver to unlink old socket file."
by Nick Kralevich
· 11 years ago
e9d3660
Merge "Make wpa_supplicant enforcing."
by Nick Kralevich
· 11 years ago
d9b8ef4
Drop legacy device types.
by Stephen Smalley
· 11 years ago
e11935d
Allow drmserver to unlink old socket file.
by Stephen Smalley
· 11 years ago
5eab3ab
Merge "Confine gpsd, but leave it permissive for now."
by Nick Kralevich
· 11 years ago
b1016ed
Make hci_attach enforcing.
by Stephen Smalley
· 11 years ago
63c26f6
Make wpa_supplicant enforcing.
by Stephen Smalley
· 11 years ago
a60abdc
Confine gpsd, but leave it permissive for now.
by Stephen Smalley
· 11 years ago
08fffc5
Revert "Revert "Strip file execute permissions from unconfined domains.""
by Stephen Smalley
· 11 years ago
8aae7bd
Revert "Revert "Strip exec* permissions from unconfined domains.""
by Stephen Smalley
· 11 years ago
9fe4e7b
ashmem_device is a character device, not a regular file.
by Stephen Smalley
· 11 years ago
9a40702
Allow recovery to execute ashmem_device and tmpfs.
by Stephen Smalley
· 11 years ago
810fc5d
Merge "Add an exception for bluetooth to the sysfs neverallow rule."
by Nick Kralevich
· 11 years ago
7611b60
Merge "Support forcing permissive domains to unconfined."
by Nick Kralevich
· 11 years ago
570e5f4
Move adbd into enforcing on user devices
by Nick Kralevich
· 11 years ago
200e97d
Merge "Add a domain for the recovery console."
by Nick Kralevich
· 11 years ago
6d10ca8
Add a domain for the recovery console.
by Stephen Smalley
· 11 years ago
df8af76
Add an exception for bluetooth to the sysfs neverallow rule.
by Stephen Smalley
· 11 years ago
40ce0bb
allow adbd setpcap
by Nick Kralevich
· 11 years ago
623975f
Support forcing permissive domains to unconfined.
by Nick Kralevich
· 11 years ago
06a0d78
Merge "Revert "Strip exec* permissions from unconfined domains.""
by Nick Kralevich
· 11 years ago
89740a6
Revert "Strip exec* permissions from unconfined domains."
by Nick Kralevich
· 11 years ago
e030950
Merge "Do not allow zygote to execve dalvikcache files."
by Nick Kralevich
· 11 years ago
e210b20
Merge "Revert "Make bluetooth enforcing.""
by Nick Kralevich
· 11 years ago
85396e9
Revert "Make bluetooth enforcing."
by Nick Kralevich
· 11 years ago
d7da665
Merge "Create new conditional userdebug_or_eng"
by Nick Kralevich
· 11 years ago
41a487d
Merge "Revert "Strip file execute permissions from unconfined domains.""
by Nick Kralevich
· 11 years ago
43ddc10
Revert "Strip file execute permissions from unconfined domains."
by Nick Kralevich
· 11 years ago
88ce951
Create new conditional userdebug_or_eng
by Nick Kralevich
· 11 years ago
49c995d
Do not allow zygote to execve dalvikcache files.
by Stephen Smalley
· 11 years ago
39fd781
Remove domain init:unix_stream_socket connectto permission.
by Stephen Smalley
· 11 years ago
aef4a46
Merge "Remove legacy rules from dumpstate in init domain."
by Nick Kralevich
· 11 years ago
6933416
Merge changes Ib3604537,I6f5715eb
by Nick Kralevich
· 11 years ago
38b8fc8
Remove legacy rules from dumpstate in init domain.
by Stephen Smalley
· 11 years ago
d832a6d
Merge "Strip file execute permissions from unconfined domains."
by Nick Kralevich
· 11 years ago
c75e35a
Merge "Strip exec* permissions from unconfined domains."
by Nick Kralevich
· 11 years ago
91c290b
Allow access to unlabeled socket and fifo files.
by Stephen Smalley
· 11 years ago
959fdaa
Remove unlabeled execute access from domain, add to appdomain.
by Stephen Smalley
· 11 years ago
c50bf17
Address new system server denial.
by Robert Craig
· 11 years ago
1dd3184
Merge "address denials when playing protected content."
by Nick Kralevich
· 11 years ago
b23d287
Allow keystore to talk to the tee
by Nick Kralevich
· 11 years ago
e45603d
address denials when playing protected content.
by Nick Kralevich
· 11 years ago
d362cdf
Apply a label to /data/mediadrm files.
by rpcraig
· 11 years ago
Next »