Gitiles
Code Review
Sign In
LeafOS
/
LeafOS-Project
/
android_system_sepolicy
/
0ce8184bed8e1d4823f32dc030b03770671aa1a6
/
public
/
adbd.te
da4e51b
Add shell_test_data_file for /data/local/tests
by Colin Cross
· 4 years, 6 months ago
55e5c9b
Move system property rules to private
by Inseob Kim
· 5 years ago
cfeaa1c
Allow adb start/stop mdnsd via ctl.start/stop
by Changyeon Jo
· 6 years ago
5e37271
Introduce system_file_type
by Nick Kralevich
· 6 years ago
22f9819
Revert "Revert "Reduce the number of processes that can start adbd""
by Samuel Ha
· 7 years ago
b5dc613
Revert "Reduce the number of processes that can start adbd"
by Samuel Ha
· 7 years ago
faebeac
Reduce the number of processes that can start adbd
by Luis Hector Chavez
· 7 years ago
5846c79
Moving adbd from rootdir to system/bin
by Bowgo Tsai
· 8 years ago
8309f0a
Move adbd policy to private
by Alex Klyubin
· 8 years ago
4c40d73
Merge ephemeral data and apk files into app
by Chad Brubaker
· 8 years ago
d5b6043
more ephemeral_app cleanup
by Nick Kralevich
· 8 years ago
cb3eb4e
Introduce crash_dump debugging helper.
by Josh Gao
· 8 years ago
a3bc3cf
Remove support for legacy f_adb interface.
by Josh Gao
· 8 years ago
2015107
Restrict access to ro.serialno and ro.boot.serialno
by Alex Klyubin
· 8 years ago
06cf31e
Rename autoplay_app to ephemeral_app
by Chad Brubaker
· 8 years ago
cc39f63
Split general policy into public and private components.
by dcashman
· 9 years ago
[Renamed (98%) from adbd.te]
2c4718f
resolve merge conflicts of 56ed8a4 to stage-aosp-master
by Jeff Vander Stoep
· 9 years ago
d743dde
adbd: allow reading apk_data_file
by Jeff Vander Stoep
· 9 years ago
7fcb3a6
adbd: allow reading rootfs dir
by Jeff Vander Stoep
· 9 years ago
90b0089
SELinux policy for /data/misc/profman am: a5d0792508
by David Sehr
· 9 years ago
a5d0792
SELinux policy for /data/misc/profman
by David Sehr
· 9 years ago
72e69f5
Restore /mnt/sdcard symlink read access am: e3151bd
by Nick Kralevich
· 9 years ago
e3151bd
Restore /mnt/sdcard symlink read access
by Nick Kralevich
· 9 years ago
4bd9eb0
resolve merge conflicts of c09ae49 to nyc-dev-plus-aosp
by Nick Kralevich
· 9 years ago
6c768d7
adbd: disallow non-shell domain transitions.
by Nick Kralevich
· 9 years ago
d25d57a
Allow access to media_rw_data_file for now.
by Daniel Rosenberg
· 9 years ago
bb90999
Allow shell and adbd access to media_rw_data_file for now.
by Daniel Rosenberg
· 9 years ago
cdf60cc
Merge "SELinux rule for ro.device_owner and persist.logd.security" am: 65d364b91a
by Rubin Xu
· 9 years ago
0c8286f
SELinux rule for ro.device_owner and persist.logd.security
by Rubin Xu
· 9 years ago
693791c
Merge "adbd.te: remove allow adbd toolbox_exec:file rx_file_perms" am: eed6bbdc43
by Nick Kralevich
· 9 years ago
155e710
adbd.te: remove allow adbd toolbox_exec:file rx_file_perms
by Nick Kralevich
· 9 years ago
14c4486
Merge "Allow adbd to pull sepolicy from device." am: 7a46e73cb6 am: 2e40b7471c
by Daniel Cashman
· 9 years ago
0fb0ab4
Allow adbd to pull sepolicy from device.
by dcashman
· 9 years ago
146f910
Change /dev/ion from read-only to read-write am: 71fd337f04 am: 637af04edd
by Nick Kralevich
· 9 years ago
71fd337
Change /dev/ion from read-only to read-write
by Nick Kralevich
· 9 years ago
1a45a90
adbd: allow ddms screen capture to work again am: 5e8402df43 am: 8e5436460b
by Nick Kralevich
· 9 years ago
3a5e337
adbd: allow "adb pull /sdcard/" am: b899f4fc33 am: e9d43070e4 am: 80c34f6aef
by Nick Kralevich
· 9 years ago
5e8402d
adbd: allow ddms screen capture to work again
by Nick Kralevich
· 9 years ago
b899f4f
adbd: allow "adb pull /sdcard/"
by Nick Kralevich
· 9 years ago
ab26b48
Remove domain_deprecated from adbd and shell am: 8ca19368da am: 78d03007ae
by Nick Kralevich
· 9 years ago
8ca1936
Remove domain_deprecated from adbd and shell
by Nick Kralevich
· 9 years ago
ae72bf2
Populate autoplay_app with minimal set of permissions
by Jeff Vander Stoep
· 9 years ago
d22987b
Create attribute for moving perms out of domain
by Jeff Vander Stoep
· 9 years ago
5e6930e
am 05056457: adb: add adbd -> shell signal permissions.
by David Pursell
· 9 years ago
0505645
adb: add adbd -> shell signal permissions.
by David Pursell
· 9 years ago
b086886
am 7af012fc: Merge "Only allow toolbox exec where /system exec was already allowed."
by Nick Kralevich
· 10 years ago
a3c97a7
Only allow toolbox exec where /system exec was already allowed.
by Stephen Smalley
· 10 years ago
b4807fe
am 82966219: Merge "Replace unix_socket_connect() and explicit property sets with macro"
by Nick Kralevich
· 10 years ago
625a352
Replace unix_socket_connect() and explicit property sets with macro
by William Roberts
· 10 years ago
2d425de
am b1b5e662: am caefbd71: allow adbd to set sys.usb.ffs.ready
by Nick Kralevich
· 10 years ago
caefbd7
allow adbd to set sys.usb.ffs.ready
by Nick Kralevich
· 10 years ago
346a468
am bf75239c: am 4f4a4754: Merge "Apps need more than just search."
by Jeff Sharkey
· 10 years ago
3bdc0ab
Apps need more than just search.
by Jeff Sharkey
· 10 years ago
c63d824
am 2768f1cb: am 93fd6f0a: Consistent external storage policy.
by Jeff Sharkey
· 10 years ago
93fd6f0
Consistent external storage policy.
by Jeff Sharkey
· 10 years ago
dee73f9
am 106ca81b: am 2714e41a: am b4876619: Merge "bootchart: add policy rules for bootchart"
by Nick Kralevich
· 10 years ago
2714e41
am b4876619: Merge "bootchart: add policy rules for bootchart"
by Nick Kralevich
· 10 years ago
cc38e6d
bootchart: add policy rules for bootchart
by Yongqin Liu
· 10 years ago
880938a
am 49e7e0c2: am d8800a10: am cd82557d: Restrict service_manager find and list access.
by dcashman
· 10 years ago
49e7e0c
am d8800a10: am cd82557d: Restrict service_manager find and list access.
by dcashman
· 10 years ago
cd82557
Restrict service_manager find and list access.
by dcashman
· 10 years ago
cb71b82
am c4ed15a8: am 2c38b3b8: DO NOT MERGE: allow access to labeled executables in /system
by Nick Kralevich
· 10 years ago
2c38b3b
DO NOT MERGE: allow access to labeled executables in /system
by Nick Kralevich
· 10 years ago
973877d
Allow adbd to write to /data/adb
by Nick Kralevich
· 10 years ago
3e6da14
Enable selinux read_policy for adb pull.
by dcashman
· 10 years ago
309cc66
Enable selinux read_policy for adb pull.
by dcashman
· 10 years ago
45731c7
Annotate MLS trusted subjects and objects.
by Stephen Smalley
· 10 years ago
bf69632
DO NOT MERGE: Remove service_manager audit_allows.
by Riley Spahn
· 11 years ago
14aa7c0
Refine service_manager find auditallow statements.
by Riley Spahn
· 11 years ago
88157ea
Refine service_manager find auditallow statements.
by Riley Spahn
· 11 years ago
7563a6f
reconcile aosp (a7c04dcd748e1a9daf374551303a3bd578305cf9) after branching. Please do not merge.
by Ed Heyl
· 11 years ago
a7c04dc
Remove domain:process from unconfined
by Nick Kralevich
· 11 years ago
98b7ab5
allow adb push to create directories.
by Nick Kralevich
· 11 years ago
4fd4a20
Allow adbd / shell /data/anr access
by Nick Kralevich
· 11 years ago
24b5622
Remove obsolete vdc rule.
by Nick Kralevich
· 11 years ago
356f4be
Restrict requesting contexts other than policy-defined defaults.
by Stephen Smalley
· 11 years ago
77cc055
Label /dev/usb-ffs/adb functionfs
by Nick Kralevich
· 11 years ago
ddde8c2
Allow adbd access to gpu_device.
by dcashman
· 11 years ago
0296b94
Move qemud and /dev/qemu policy bits to emulator-specific sepolicy.
by Stephen Smalley
· 11 years ago
35102f5
Drop rules for /data/misc/adb legacy type.
by Stephen Smalley
· 11 years ago
f956366
Move adbd into enforcing (all build types)
by Nick Kralevich
· 11 years ago
7d0f955
Support running adbd in the su domain.
by Nick Kralevich
· 11 years ago
570e5f4
Move adbd into enforcing on user devices
by Nick Kralevich
· 11 years ago
40ce0bb
allow adbd setpcap
by Nick Kralevich
· 11 years ago
81e74b1
Confine adbd but leave it permissive for now.
by Stephen Smalley
· 11 years ago
48759ca
Support run-as and ndk-gdb functionality.
by Stephen Smalley
· 11 years ago
353c72e
Move unconfined domains out of permissive mode.
by Nick Kralevich
· 11 years ago
5554075
Label adb keys file and allow access to it.
by Stephen Smalley
· 11 years ago
77d4731
Make all domains unconfined.
by repo sync
· 12 years ago
3b9fd5f
SELinux policy: let adbd drop Linux capabilities.
by Alex Klyubin
· 12 years ago
9504a50
Allow ADB to interact extensively with system_data_files.
by repo sync
· 12 years ago
1e25b98
Revert "Add the sysrq_file special file and give ADB write access."
by Nick Kralevich
· 12 years ago
bb2591e
Add the sysrq_file special file and give ADB write access.
by Geremy Condra
· 12 years ago
81fe5f7
Allow all domains to read the log devices.
by Stephen Smalley
· 12 years ago
2c83100
Fix various SELinux denials.
by Geremy Condra
· 12 years ago
e69552b
Revert "Revert "Various minor policy fixes based on CTS.""
by Geremy Condra
· 12 years ago
ba84bf1
Revert "Various minor policy fixes based on CTS."
by Geremy Condra
· 12 years ago
8a814a7
Various minor policy fixes based on CTS.
by Stephen Smalley
· 12 years ago
61c80d5
Update policy for Android 4.2 / latest master.
by Stephen Smalley
· 12 years ago
2cb1b31
Allow adbd to access the qemu device and label /dev/eac correctly.
by Stephen Smalley
· 13 years ago
Next »