1. bfa3cd5 Allow dumpstate to write shell files by Nick Kralevich · 11 years ago
  2. ed1648a Merge "Address adb backup/restore denials." by Nick Kralevich · 11 years ago
  3. c4021ce Address adb backup/restore denials. by Stephen Smalley · 11 years ago
  4. 301e61e Merge "Make mediaserver enforcing." by Nick Kralevich · 11 years ago
  5. 14a7764 Merge "Make media_app enforcing." by Nick Kralevich · 11 years ago
  6. af28817 Merge "Make nfc enforcing." by Nick Kralevich · 11 years ago
  7. 782af9e Merge "Make radio enforcing." by Nick Kralevich · 11 years ago
  8. ee3cfd2 Merge "Make bluetooth enforcing." by Nick Kralevich · 11 years ago
  9. aef19eb Merge "Make surfaceflinger domain enforcing." by Nick Kralevich · 11 years ago
  10. 4e39317 Merge "Confine adbd but leave it permissive for now." by Nick Kralevich · 11 years ago
  11. e7ec2f5 Only allow PROT_EXEC for ashmem where required. by Stephen Smalley · 11 years ago
  12. ad7df7b Remove execmem permission from domain, add to appdomain. by Stephen Smalley · 11 years ago
  13. 527316a Allow use of art as the Android runtime. by Stephen Smalley · 11 years ago
  14. 81e74b1 Confine adbd but leave it permissive for now. by Stephen Smalley · 11 years ago
  15. 588bb5c Merge "Confine sdcardd, but leave it permissive for now." by Nick Kralevich · 11 years ago
  16. c48fd77 Confine dhcp, but leave it permissive for now. by Stephen Smalley · 11 years ago
  17. c17d30a Delete dalvikcache_data_file write/setattr access from shell. by Stephen Smalley · 11 years ago
  18. d28ceeb Merge "shell: allow setting debug_prop and powerctl_prop" by Nick Kralevich · 11 years ago
  19. fe907e5 Merge "vold: allow wakelocks, fsck logs" by Nick Kralevich · 11 years ago
  20. 9969a4d Merge "Allow dumpsys" by Nick Kralevich · 11 years ago
  21. 20a791a shell: allow setting debug_prop and powerctl_prop by Nick Kralevich · 11 years ago
  22. a2c4cb3 Merge "Allow dumpstate to use ping." by Nick Kralevich · 11 years ago
  23. 5153890 Allow dumpsys by Nick Kralevich · 11 years ago
  24. 3753c81 vold: allow wakelocks, fsck logs by Nick Kralevich · 11 years ago
  25. 13e44ec allow system_server block_suspend by Nick Kralevich · 11 years ago
  26. 15abc95 Confine sdcardd, but leave it permissive for now. by Stephen Smalley · 11 years ago
  27. 815e981 Merge "Make bluetooth, nfc, radio and shell adb-installable" by Nick Kralevich · 11 years ago
  28. f5e9000 Make bluetooth, nfc, radio and shell adb-installable by Takeshi Aimi · 11 years ago
  29. f6bf7ef Allow dumpstate to use ping. by Nick Kralevich · 11 years ago
  30. b63e485 Merge "Confine shell domain in -user builds only." by Nick Kralevich · 11 years ago
  31. 712ca0a Confine shell domain in -user builds only. by Stephen Smalley · 11 years ago
  32. 5946937 Add rules to permit CTS security-related tests to run. by Stephen Smalley · 11 years ago
  33. ae2a35c Merge "Label /data/media with its own type and allow access." by Nick Kralevich · 11 years ago
  34. e13fabd Label /data/media with its own type and allow access. by Stephen Smalley · 11 years ago
  35. c4d7c0d system_server.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
  36. 61dc350 app.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
  37. 09e6abd initial dumpstate domain by Nick Kralevich · 11 years ago
  38. caa6a32 initial inputflinger domain by Nick Kralevich · 11 years ago
  39. 96c266c Merge "put netd into net_domain" by Nick Kralevich · 11 years ago
  40. 8b0ce1b Merge "Label /data/misc/zoneinfo" by Nick Kralevich · 11 years ago
  41. bc19050 put netd into net_domain by Nick Kralevich · 11 years ago
  42. 3867c03 Merge "alphabetize /data/misc entries." by Nick Kralevich · 11 years ago
  43. 7466f9b Label /data/misc/zoneinfo by Nick Kralevich · 11 years ago
  44. 6a32eec alphabetize /data/misc entries. by Nick Kralevich · 11 years ago
  45. 8fff872 Merge "Make tee enforcing." by Nick Kralevich · 11 years ago
  46. 8ad2259 Make bootanim domain enforcing. by Stephen Smalley · 11 years ago
  47. 4b237c9 Merge "Make watchdogd enforcing." by Nick Kralevich · 11 years ago
  48. a11c56e Make surfaceflinger domain enforcing. by Stephen Smalley · 11 years ago
  49. acde43f Define a domain for the bootanim service. by Stephen Smalley · 11 years ago
  50. 3ba9012 Move gpu_device type and rules to core policy. by Stephen Smalley · 11 years ago
  51. cf6b350 Allow apps to execute ping by Nick Kralevich · 11 years ago
  52. ca9ba32 Merge "Make ping enforcing." by Nick Kralevich · 11 years ago
  53. 21a6a6b Merge "Allow system_app to set properties" by Nick Kralevich · 11 years ago
  54. b71be5c Merge "Make the runas domain enforcing." by Nick Kralevich · 11 years ago
  55. 3e78000 Allow system_app to set properties by Nick Kralevich · 11 years ago
  56. 6531712 Allow untrusted apps to execute binaries from their sandbox directories. by Stephen Smalley · 11 years ago
  57. 27daf18 Make the runas domain enforcing. by Stephen Smalley · 11 years ago
  58. 0bc1737 Merge "Support run-as and ndk-gdb functionality." by Nick Kralevich · 11 years ago
  59. e6a7b37 Restrict mapping low memory. by Stephen Smalley · 11 years ago
  60. 48759ca Support run-as and ndk-gdb functionality. by Stephen Smalley · 11 years ago
  61. 95e0842 Restrict ptrace access by debuggerd and unconfineddomain. by Stephen Smalley · 11 years ago
  62. 82fc3b5 Allow app-app communication via pipes by Nick Kralevich · 11 years ago
  63. 49db268 Merge "Make debuggerd enforcing." by Nick Kralevich · 11 years ago
  64. 2c55c53 am fea6e66f: Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  65. fea6e66 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  66. a6c9cdf am 9e8b8d9f: Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
  67. 9e8b8d9 Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
  68. 6c8cbac am bf12e225: Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  69. bf12e22 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
  70. 156b5db am 2b392fcc: Move lmkd into it\'s own domain. by Nick Kralevich · 11 years ago
  71. d5f77d7 am 7adb999e: Restrict the ability to set usermodehelpers and proc security settings. by Stephen Smalley · 11 years ago
  72. 2b392fc Move lmkd into it's own domain. by Nick Kralevich · 11 years ago
  73. 5495507 Make tee enforcing. by Stephen Smalley · 11 years ago
  74. 1c670cc Make watchdogd enforcing. by Stephen Smalley · 11 years ago
  75. 6463c49 Make radio enforcing. by Stephen Smalley · 11 years ago
  76. cc96454 Make mediaserver enforcing. by Stephen Smalley · 11 years ago
  77. edc8f38 Make media_app enforcing. by Stephen Smalley · 11 years ago
  78. 56a1a7e Make nfc enforcing. by Stephen Smalley · 11 years ago
  79. 1b556c3 Make ping enforcing. by Stephen Smalley · 11 years ago
  80. 2eba9c5 Make bluetooth enforcing. by Stephen Smalley · 11 years ago
  81. a161840 Make debuggerd enforcing. by Stephen Smalley · 11 years ago
  82. 7adb999 Restrict the ability to set usermodehelpers and proc security settings. by Stephen Smalley · 11 years ago
  83. b96f677 Merge commit '4ab298359613736281e10accaed3a6ffe1fe590a' into HEAD by The Android Open Source Project · 11 years ago
  84. aa37683 Fix new rild denials. by Robert Craig · 11 years ago
  85. b254764 Drop tegra specific label from policy. by Robert Craig · 11 years ago
  86. 8824c55 Merge "Allow SELinuxPolicyInstallReceiver to work." by Nick Kralevich · 11 years ago
  87. d99e6d5 Restrict the ability to set SELinux enforcing mode to init. by Stephen Smalley · 11 years ago
  88. a49ba92 Allow SELinuxPolicyInstallReceiver to work. by Stephen Smalley · 11 years ago
  89. 51ce2f0 Merge "Make the isolated_app domain enforcing." by Nick Kralevich · 11 years ago
  90. 081aed2 Default to socket_device for anything under /dev/socket. by Stephen Smalley · 11 years ago
  91. 08ecc02 Make the isolated_app domain enforcing. by Stephen Smalley · 11 years ago
  92. 4768553 Allow write access to ashmem allocated regions by Nick Kralevich · 11 years ago
  93. 2ffd52a am 043b9027: Confine watchdogd, but leave it permissive for now. by Stephen Smalley · 11 years ago
  94. 6af0cc2 Merge commit '060f6fa67e1d9779d2d8357659ae530d65171faa' into HEAD by The Android Open Source Project · 11 years ago
  95. 043b902 Confine watchdogd, but leave it permissive for now. by Stephen Smalley · 11 years ago
  96. 7ef2b39 am 1ed3caf7: Merge "Add support for duplicate allow rule detection (-D / --dups)." by Nick Kralevich · 11 years ago
  97. 1ed3caf Merge "Add support for duplicate allow rule detection (-D / --dups)." by Nick Kralevich · 11 years ago
  98. bec54f4 Add support for duplicate allow rule detection (-D / --dups). by Stephen Smalley · 11 years ago
  99. 65d4e83 am 006260e5: Merge "Confine hostapd, but leave it permissive for now." by Nick Kralevich · 11 years ago
  100. 006260e Merge "Confine hostapd, but leave it permissive for now." by Nick Kralevich · 11 years ago