- b0a9951 Allow kernel thread to read app data files by Nick Kralevich · 10 years ago
- 28b26bc support kernel writes to external SDcards by Nick Kralevich · 10 years ago
- e9c90bd reconcile aosp (4da3bb1481e4e894a7dee3f3b9ec8cef6f6b1aed) after branching. Please do not merge. by Ed Heyl · 10 years ago
- a1558be Allow kernel sdcard read access as well for MTP sync. by Stephen Smalley · 10 years ago
- eb6b74f Allow kernel sdcard access for MTP sync. by Stephen Smalley · 10 years ago
- f3c3a1a Remove execute_no_trans from unconfineddomain. by Stephen Smalley · 10 years ago
- bac4ccc Prevent adding transitions to kernel or init domains. by Stephen Smalley · 10 years ago
- 718bf84 Allow mounting of usbfs. by Stephen Smalley · 10 years ago
- 73b0346 Explictly allow init and kernel unlabeled access. by Stephen Smalley · 10 years ago
- eb1bbf2 Clean up kernel, init, and recovery domains. by Stephen Smalley · 10 years ago
- 03ce512 Remove /system write from unconfined by Nick Kralevich · 10 years ago
- 356f4be Restrict requesting contexts other than policy-defined defaults. by Stephen Smalley · 10 years ago
- cdae7de Drop unused rules for raw I/O, mknod, and block device access. by Stephen Smalley · 10 years ago
- abae8a9 Revisit kernel setenforce by Nick Kralevich · 10 years ago
- 02dac03 Drop relabelto_domain() macro and its associated definitions. by Stephen Smalley · 10 years ago
- 3f40d4f Remove block device access from unconfined domains. by Stephen Smalley · 10 years ago
- 5487ca0 Remove several superuser capabilities from unconfined domains. by Stephen Smalley · 10 years ago
- b081cc1 Remove mount-related permissions from unconfined domains. by Stephen Smalley · 10 years ago
- fed8a2a Remove transition / dyntransition from unconfined by Nick Kralevich · 10 years ago
- 8b51674 Restrict ability to set checkreqprot. by Stephen Smalley · 10 years ago
- fea6e66 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 10 years ago
- 9e8b8d9 Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode." by Nick Kralevich · 10 years ago
- bf12e22 Allow kernel domain, not init domain, to set SELinux enforcing mode. by Stephen Smalley · 10 years ago
- b1d8164 Make kernel / init enforcing by Nick Kralevich · 11 years ago
- 217f8af Fix more long-tail denials. by Geremy Condra · 11 years ago
- 0c9708b domain.te: Add backwards compatibility for unlabeled files by Nick Kralevich · 11 years ago
- 50e37b9 Move domains into per-domain permissive mode. by repo sync · 11 years ago
- 2dd4e51 SE Android policy. by Stephen Smalley · 12 years ago