1. bf626ce appdomain: relax netlink_socket neverallow rule by Nick Kralevich · 9 years ago
  2. 9d94204 sepolicy: allow system apps to access ASEC by Pawit Pornkitprasan · 9 years ago
  3. e2547c3 allow untrusted_app read /data/anr/traces.txt by Nick Kralevich · 10 years ago
  4. 36fb1f1 relax neverallow rules on NETLINK_KOBJECT_UEVENT sockets by Nick Kralevich · 10 years ago
  5. 1c1eb86 DO NOT MERGE. Allow untrusted_app access to temporary apk files. by dcashman · 10 years ago
  6. bf69632 DO NOT MERGE: Remove service_manager audit_allows. by Riley Spahn · 10 years ago
  7. 4a24475 Further refined service_manager auditallow statements. by Riley Spahn · 10 years ago
  8. 354d6ca Remove radio_service from untrusted_app auditallow. by Riley Spahn · 10 years ago
  9. 344fc10 Add access control for each service_manager action. by Riley Spahn · 10 years ago
  10. f583566 Don't use don't by Nick Kralevich · 10 years ago
  11. 99d86c7 ensure that untrusted_app can't set properties by Nick Kralevich · 10 years ago
  12. 76206ab Add neverallow rules further restricing service_manager. by Riley Spahn · 10 years ago
  13. 78706f9 add execmod to various app domains by Nick Kralevich · 10 years ago
  14. 4bdd13e untrusted_app: neverallow debugfs by Nick Kralevich · 10 years ago
  15. 3a4eb96 Make the untrusted_app domain enforcing. by Stephen Smalley · 10 years ago
  16. 9ba844f Coalesce shared_app, media_app, release_app into untrusted_app. by Stephen Smalley · 10 years ago
  17. b0db712 Clean up, unify, and deduplicate app domain rules. by Stephen Smalley · 10 years ago
  18. 1eb9403 Remove redundant socket rules. by Stephen Smalley · 10 years ago
  19. d823f83 Clarify meaning of untrusted_app and app domain assignment logic. by Stephen Smalley · 10 years ago
  20. 48b1883 Introduce asec_public_file type. by Robert Craig · 10 years ago
  21. 623975f Support forcing permissive domains to unconfined. by Nick Kralevich · 10 years ago
  22. 6531712 Allow untrusted apps to execute binaries from their sandbox directories. by Stephen Smalley · 10 years ago
  23. 2dc4acf Isolate untrusted app ptys from other domains. by Stephen Smalley · 11 years ago
  24. 2f40a17 Revert "Add the ability to write shell files to the untrusted_app domain." by Nick Kralevich · 11 years ago
  25. 29d0d40 Add the ability to write shell files to the untrusted_app domain. by Geremy Condra · 11 years ago
  26. 7cda86e Permit apps to bind TCP/UDP sockets to a hostname by Alex Klyubin · 11 years ago
  27. 24617fc Move isolated_app.te / untrusted_app.te into permissive by Nick Kralevich · 11 years ago
  28. 59faed0 Allow apps to create listening ports by Nick Kralevich · 11 years ago
  29. 8a2ebe3 Temporarily allow untrusted apps to read shell data files. by Nick Kralevich · 11 years ago
  30. 6634a10 untrusted_app.te / isolated_app.te / app.te first pass by Nick Kralevich · 11 years ago
  31. 748fdef Move *_app into their own file by Nick Kralevich · 11 years ago