Gitiles
Code Review
Sign In
gerrit-public.fairphone.software
/
fp2-dev
/
platform
/
external
/
sepolicy
/
refs/tags/FP2-open-16.11.0
/
untrusted_app.te
bf626ce
appdomain: relax netlink_socket neverallow rule
by Nick Kralevich
· 9 years ago
9d94204
sepolicy: allow system apps to access ASEC
by Pawit Pornkitprasan
· 9 years ago
e2547c3
allow untrusted_app read /data/anr/traces.txt
by Nick Kralevich
· 10 years ago
36fb1f1
relax neverallow rules on NETLINK_KOBJECT_UEVENT sockets
by Nick Kralevich
· 10 years ago
1c1eb86
DO NOT MERGE. Allow untrusted_app access to temporary apk files.
by dcashman
· 10 years ago
bf69632
DO NOT MERGE: Remove service_manager audit_allows.
by Riley Spahn
· 10 years ago
4a24475
Further refined service_manager auditallow statements.
by Riley Spahn
· 10 years ago
354d6ca
Remove radio_service from untrusted_app auditallow.
by Riley Spahn
· 10 years ago
344fc10
Add access control for each service_manager action.
by Riley Spahn
· 10 years ago
f583566
Don't use don't
by Nick Kralevich
· 10 years ago
99d86c7
ensure that untrusted_app can't set properties
by Nick Kralevich
· 10 years ago
76206ab
Add neverallow rules further restricing service_manager.
by Riley Spahn
· 10 years ago
78706f9
add execmod to various app domains
by Nick Kralevich
· 10 years ago
4bdd13e
untrusted_app: neverallow debugfs
by Nick Kralevich
· 10 years ago
3a4eb96
Make the untrusted_app domain enforcing.
by Stephen Smalley
· 10 years ago
9ba844f
Coalesce shared_app, media_app, release_app into untrusted_app.
by Stephen Smalley
· 10 years ago
b0db712
Clean up, unify, and deduplicate app domain rules.
by Stephen Smalley
· 10 years ago
1eb9403
Remove redundant socket rules.
by Stephen Smalley
· 10 years ago
d823f83
Clarify meaning of untrusted_app and app domain assignment logic.
by Stephen Smalley
· 10 years ago
48b1883
Introduce asec_public_file type.
by Robert Craig
· 10 years ago
623975f
Support forcing permissive domains to unconfined.
by Nick Kralevich
· 10 years ago
6531712
Allow untrusted apps to execute binaries from their sandbox directories.
by Stephen Smalley
· 10 years ago
2dc4acf
Isolate untrusted app ptys from other domains.
by Stephen Smalley
· 11 years ago
2f40a17
Revert "Add the ability to write shell files to the untrusted_app domain."
by Nick Kralevich
· 11 years ago
29d0d40
Add the ability to write shell files to the untrusted_app domain.
by Geremy Condra
· 11 years ago
7cda86e
Permit apps to bind TCP/UDP sockets to a hostname
by Alex Klyubin
· 11 years ago
24617fc
Move isolated_app.te / untrusted_app.te into permissive
by Nick Kralevich
· 11 years ago
59faed0
Allow apps to create listening ports
by Nick Kralevich
· 11 years ago
8a2ebe3
Temporarily allow untrusted apps to read shell data files.
by Nick Kralevich
· 11 years ago
6634a10
untrusted_app.te / isolated_app.te / app.te first pass
by Nick Kralevich
· 11 years ago
748fdef
Move *_app into their own file
by Nick Kralevich
· 11 years ago