- bfa3cd5 Allow dumpstate to write shell files by Nick Kralevich · 11 years ago
- ed1648a Merge "Address adb backup/restore denials." by Nick Kralevich · 11 years ago
- c4021ce Address adb backup/restore denials. by Stephen Smalley · 11 years ago
- 301e61e Merge "Make mediaserver enforcing." by Nick Kralevich · 11 years ago
- 14a7764 Merge "Make media_app enforcing." by Nick Kralevich · 11 years ago
- af28817 Merge "Make nfc enforcing." by Nick Kralevich · 11 years ago
- 782af9e Merge "Make radio enforcing." by Nick Kralevich · 11 years ago
- ee3cfd2 Merge "Make bluetooth enforcing." by Nick Kralevich · 11 years ago
- aef19eb Merge "Make surfaceflinger domain enforcing." by Nick Kralevich · 11 years ago
- 4e39317 Merge "Confine adbd but leave it permissive for now." by Nick Kralevich · 11 years ago
- e7ec2f5 Only allow PROT_EXEC for ashmem where required. by Stephen Smalley · 11 years ago
- ad7df7b Remove execmem permission from domain, add to appdomain. by Stephen Smalley · 11 years ago
- 527316a Allow use of art as the Android runtime. by Stephen Smalley · 11 years ago
- 81e74b1 Confine adbd but leave it permissive for now. by Stephen Smalley · 11 years ago
- 588bb5c Merge "Confine sdcardd, but leave it permissive for now." by Nick Kralevich · 11 years ago
- c48fd77 Confine dhcp, but leave it permissive for now. by Stephen Smalley · 11 years ago
- c17d30a Delete dalvikcache_data_file write/setattr access from shell. by Stephen Smalley · 11 years ago
- d28ceeb Merge "shell: allow setting debug_prop and powerctl_prop" by Nick Kralevich · 11 years ago
- fe907e5 Merge "vold: allow wakelocks, fsck logs" by Nick Kralevich · 11 years ago
- 9969a4d Merge "Allow dumpsys" by Nick Kralevich · 11 years ago
- 20a791a shell: allow setting debug_prop and powerctl_prop by Nick Kralevich · 11 years ago
- a2c4cb3 Merge "Allow dumpstate to use ping." by Nick Kralevich · 11 years ago
- 5153890 Allow dumpsys by Nick Kralevich · 11 years ago
- 3753c81 vold: allow wakelocks, fsck logs by Nick Kralevich · 11 years ago
- 13e44ec allow system_server block_suspend by Nick Kralevich · 11 years ago
- 15abc95 Confine sdcardd, but leave it permissive for now. by Stephen Smalley · 11 years ago
- 815e981 Merge "Make bluetooth, nfc, radio and shell adb-installable" by Nick Kralevich · 11 years ago
- f5e9000 Make bluetooth, nfc, radio and shell adb-installable by Takeshi Aimi · 11 years ago
- f6bf7ef Allow dumpstate to use ping. by Nick Kralevich · 11 years ago
- b63e485 Merge "Confine shell domain in -user builds only." by Nick Kralevich · 11 years ago
- 712ca0a Confine shell domain in -user builds only. by Stephen Smalley · 11 years ago
- 5946937 Add rules to permit CTS security-related tests to run. by Stephen Smalley · 11 years ago
- ae2a35c Merge "Label /data/media with its own type and allow access." by Nick Kralevich · 11 years ago
- e13fabd Label /data/media with its own type and allow access. by Stephen Smalley · 11 years ago
- c4d7c0d system_server.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
- 61dc350 app.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
- 09e6abd initial dumpstate domain by Nick Kralevich · 11 years ago
- caa6a32 initial inputflinger domain by Nick Kralevich · 11 years ago
- 96c266c Merge "put netd into net_domain" by Nick Kralevich · 11 years ago
- 8b0ce1b Merge "Label /data/misc/zoneinfo" by Nick Kralevich · 11 years ago
- bc19050 put netd into net_domain by Nick Kralevich · 11 years ago
- 3867c03 Merge "alphabetize /data/misc entries." by Nick Kralevich · 11 years ago
- 7466f9b Label /data/misc/zoneinfo by Nick Kralevich · 11 years ago
- 6a32eec alphabetize /data/misc entries. by Nick Kralevich · 11 years ago
- 8fff872 Merge "Make tee enforcing." by Nick Kralevich · 11 years ago
- 8ad2259 Make bootanim domain enforcing. by Stephen Smalley · 11 years ago
- 4b237c9 Merge "Make watchdogd enforcing." by Nick Kralevich · 11 years ago
- a11c56e Make surfaceflinger domain enforcing. by Stephen Smalley · 11 years ago
- acde43f Define a domain for the bootanim service. by Stephen Smalley · 11 years ago
- 3ba9012 Move gpu_device type and rules to core policy. by Stephen Smalley · 11 years ago
- cf6b350 Allow apps to execute ping by Nick Kralevich · 11 years ago
- ca9ba32 Merge "Make ping enforcing." by Nick Kralevich · 11 years ago
- 21a6a6b Merge "Allow system_app to set properties" by Nick Kralevich · 11 years ago
- b71be5c Merge "Make the runas domain enforcing." by Nick Kralevich · 11 years ago
- 3e78000 Allow system_app to set properties by Nick Kralevich · 11 years ago
- 6531712 Allow untrusted apps to execute binaries from their sandbox directories. by Stephen Smalley · 11 years ago
- 27daf18 Make the runas domain enforcing. by Stephen Smalley · 11 years ago
- 0bc1737 Merge "Support run-as and ndk-gdb functionality." by Nick Kralevich · 11 years ago
- e6a7b37 Restrict mapping low memory. by Stephen Smalley · 11 years ago
- 48759ca Support run-as and ndk-gdb functionality. by Stephen Smalley · 11 years ago
- 95e0842 Restrict ptrace access by debuggerd and unconfineddomain. by Stephen Smalley · 11 years ago
- 82fc3b5 Allow app-app communication via pipes by Nick Kralevich · 11 years ago
- 49db268 Merge "Make debuggerd enforcing." by Nick Kralevich · 11 years ago
- 2c55c53 am fea6e66f: Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- fea6e66 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- a6c9cdf am 9e8b8d9f: Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
- 9e8b8d9 Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
- 6c8cbac am bf12e225: Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- bf12e22 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- 156b5db am 2b392fcc: Move lmkd into it\'s own domain. by Nick Kralevich · 11 years ago
- d5f77d7 am 7adb999e: Restrict the ability to set usermodehelpers and proc security settings. by Stephen Smalley · 11 years ago
- 2b392fc Move lmkd into it's own domain. by Nick Kralevich · 11 years ago
- 5495507 Make tee enforcing. by Stephen Smalley · 11 years ago
- 1c670cc Make watchdogd enforcing. by Stephen Smalley · 11 years ago
- 6463c49 Make radio enforcing. by Stephen Smalley · 11 years ago
- cc96454 Make mediaserver enforcing. by Stephen Smalley · 11 years ago
- edc8f38 Make media_app enforcing. by Stephen Smalley · 11 years ago
- 56a1a7e Make nfc enforcing. by Stephen Smalley · 11 years ago
- 1b556c3 Make ping enforcing. by Stephen Smalley · 11 years ago
- 2eba9c5 Make bluetooth enforcing. by Stephen Smalley · 11 years ago
- a161840 Make debuggerd enforcing. by Stephen Smalley · 11 years ago
- 7adb999 Restrict the ability to set usermodehelpers and proc security settings. by Stephen Smalley · 11 years ago
- b96f677 Merge commit '4ab298359613736281e10accaed3a6ffe1fe590a' into HEAD by The Android Open Source Project · 11 years ago
- aa37683 Fix new rild denials. by Robert Craig · 11 years ago
- b254764 Drop tegra specific label from policy. by Robert Craig · 11 years ago
- 8824c55 Merge "Allow SELinuxPolicyInstallReceiver to work." by Nick Kralevich · 11 years ago
- d99e6d5 Restrict the ability to set SELinux enforcing mode to init. by Stephen Smalley · 11 years ago
- a49ba92 Allow SELinuxPolicyInstallReceiver to work. by Stephen Smalley · 11 years ago
- 51ce2f0 Merge "Make the isolated_app domain enforcing." by Nick Kralevich · 11 years ago
- 081aed2 Default to socket_device for anything under /dev/socket. by Stephen Smalley · 11 years ago
- 08ecc02 Make the isolated_app domain enforcing. by Stephen Smalley · 11 years ago
- 4768553 Allow write access to ashmem allocated regions by Nick Kralevich · 11 years ago
- 2ffd52a am 043b9027: Confine watchdogd, but leave it permissive for now. by Stephen Smalley · 11 years ago
- 6af0cc2 Merge commit '060f6fa67e1d9779d2d8357659ae530d65171faa' into HEAD by The Android Open Source Project · 11 years ago
- 043b902 Confine watchdogd, but leave it permissive for now. by Stephen Smalley · 11 years ago
- 7ef2b39 am 1ed3caf7: Merge "Add support for duplicate allow rule detection (-D / --dups)." by Nick Kralevich · 11 years ago
- 1ed3caf Merge "Add support for duplicate allow rule detection (-D / --dups)." by Nick Kralevich · 11 years ago
- bec54f4 Add support for duplicate allow rule detection (-D / --dups). by Stephen Smalley · 11 years ago
- 65d4e83 am 006260e5: Merge "Confine hostapd, but leave it permissive for now." by Nick Kralevich · 11 years ago
- 006260e Merge "Confine hostapd, but leave it permissive for now." by Nick Kralevich · 11 years ago