- 618efe8 kernel: allow rebooting, and writing to /dev/__kmsg__ by Nick Kralevich · 9 years ago
- 5aac86d Revert "Revert "SELinux policy changes for re-execing init."" by Elliott Hughes · 9 years ago
- c450759 Revert "SELinux policy changes for re-execing init." by Nick Kralevich · 9 years ago
- 46e832f SELinux policy changes for re-execing init. by Elliott Hughes · 9 years ago
- 883fcfc kernel: allow usbfs:dir search by Nick Kralevich · 9 years ago
- 753b95f Allow kernel to read asec_image_file. by dcashman · 9 years ago
- 1025d13 kernel.te: fix MTP sync by Nick Kralevich · 9 years ago
- 9fe810b allow kernel to use vold file descriptors by Nick Kralevich · 9 years ago
- 4308ce8 kernel: make kernel an mlstrustedsubject by Nick Kralevich · 9 years ago
- bd5f8e3 kernel: remove permissive_or_unconfined() by Stephen Smalley · 9 years ago
- 0a296fb am f3926937: Merge "Switch kernel and init to permissive_or_unconfined()." by Daniel Cashman · 10 years ago
- a523aac Switch kernel and init to permissive_or_unconfined(). by Stephen Smalley · 10 years ago
- b0a9951 Allow kernel thread to read app data files by Nick Kralevich · 10 years ago
- 28b26bc support kernel writes to external SDcards by Nick Kralevich · 10 years ago
- 4c6b135 support kernel writes to external SDcards by Nick Kralevich · 10 years ago
- e9c90bd reconcile aosp (4da3bb1481e4e894a7dee3f3b9ec8cef6f6b1aed) after branching. Please do not merge. by Ed Heyl · 10 years ago
- 374b2a1 Rename sdcard_internal/external types. by Stephen Smalley · 10 years ago
- a1558be Allow kernel sdcard read access as well for MTP sync. by Stephen Smalley · 10 years ago
- eb6b74f Allow kernel sdcard access for MTP sync. by Stephen Smalley · 10 years ago
- f3c3a1a Remove execute_no_trans from unconfineddomain. by Stephen Smalley · 10 years ago
- bac4ccc Prevent adding transitions to kernel or init domains. by Stephen Smalley · 10 years ago
- 718bf84 Allow mounting of usbfs. by Stephen Smalley · 10 years ago
- 73b0346 Explictly allow init and kernel unlabeled access. by Stephen Smalley · 10 years ago
- eb1bbf2 Clean up kernel, init, and recovery domains. by Stephen Smalley · 10 years ago
- 03ce512 Remove /system write from unconfined by Nick Kralevich · 10 years ago
- 356f4be Restrict requesting contexts other than policy-defined defaults. by Stephen Smalley · 10 years ago
- cdae7de Drop unused rules for raw I/O, mknod, and block device access. by Stephen Smalley · 10 years ago
- abae8a9 Revisit kernel setenforce by Nick Kralevich · 10 years ago
- 02dac03 Drop relabelto_domain() macro and its associated definitions. by Stephen Smalley · 10 years ago
- 3f40d4f Remove block device access from unconfined domains. by Stephen Smalley · 10 years ago
- 5487ca0 Remove several superuser capabilities from unconfined domains. by Stephen Smalley · 10 years ago
- b081cc1 Remove mount-related permissions from unconfined domains. by Stephen Smalley · 10 years ago
- fed8a2a Remove transition / dyntransition from unconfined by Nick Kralevich · 10 years ago
- 8b51674 Restrict ability to set checkreqprot. by Stephen Smalley · 10 years ago
- fea6e66 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- 9e8b8d9 Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 11 years ago
- bf12e22 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 11 years ago
- b1d8164 Make kernel / init enforcing by Nick Kralevich · 11 years ago
- 217f8af Fix more long-tail denials. by Geremy Condra · 11 years ago
- 0c9708b domain.te: Add backwards compatibility for unlabeled files by Nick Kralevich · 11 years ago
- 50e37b9 Move domains into per-domain permissive mode. by repo sync · 11 years ago
- 2dd4e51 SE Android policy. by Stephen Smalley · 12 years ago