- 40ce0bb allow adbd setpcap by Nick Kralevich · 11 years ago
- 06a0d78 Merge "Revert "Strip exec* permissions from unconfined domains."" by Nick Kralevich · 11 years ago
- 89740a6 Revert "Strip exec* permissions from unconfined domains." by Nick Kralevich · 11 years ago
- e030950 Merge "Do not allow zygote to execve dalvikcache files." by Nick Kralevich · 11 years ago
- e210b20 Merge "Revert "Make bluetooth enforcing."" by Nick Kralevich · 11 years ago
- 85396e9 Revert "Make bluetooth enforcing." by Nick Kralevich · 11 years ago
- d7da665 Merge "Create new conditional userdebug_or_eng" by Nick Kralevich · 11 years ago
- 41a487d Merge "Revert "Strip file execute permissions from unconfined domains."" by Nick Kralevich · 11 years ago
- 43ddc10 Revert "Strip file execute permissions from unconfined domains." by Nick Kralevich · 11 years ago
- 88ce951 Create new conditional userdebug_or_eng by Nick Kralevich · 11 years ago
- 49c995d Do not allow zygote to execve dalvikcache files. by Stephen Smalley · 11 years ago
- 39fd781 Remove domain init:unix_stream_socket connectto permission. by Stephen Smalley · 11 years ago
- aef4a46 Merge "Remove legacy rules from dumpstate in init domain." by Nick Kralevich · 11 years ago
- 6933416 Merge changes Ib3604537,I6f5715eb by Nick Kralevich · 11 years ago
- 38b8fc8 Remove legacy rules from dumpstate in init domain. by Stephen Smalley · 11 years ago
- d832a6d Merge "Strip file execute permissions from unconfined domains." by Nick Kralevich · 11 years ago
- c75e35a Merge "Strip exec* permissions from unconfined domains." by Nick Kralevich · 11 years ago
- 91c290b Allow access to unlabeled socket and fifo files. by Stephen Smalley · 11 years ago
- 959fdaa Remove unlabeled execute access from domain, add to appdomain. by Stephen Smalley · 11 years ago
- c50bf17 Address new system server denial. by Robert Craig · 11 years ago
- 1dd3184 Merge "address denials when playing protected content." by Nick Kralevich · 11 years ago
- b23d287 Allow keystore to talk to the tee by Nick Kralevich · 11 years ago
- e45603d address denials when playing protected content. by Nick Kralevich · 11 years ago
- d362cdf Apply a label to /data/mediadrm files. by rpcraig · 11 years ago
- 84a81d1 Merge "Restrict ability to set checkreqprot." by Nick Kralevich · 11 years ago
- 5da0881 Strip file execute permissions from unconfined domains. by Stephen Smalley · 11 years ago
- c0493c8 Drop extra _system_file types. by Stephen Smalley · 11 years ago
- 4e416ea Strip exec* permissions from unconfined domains. by Stephen Smalley · 11 years ago
- 8b51674 Restrict ability to set checkreqprot. by Stephen Smalley · 11 years ago
- fa4002f Merge "Adding permissions needed to remove cache" by Nick Kralevich · 11 years ago
- 1bf61c4 Make /proc/net a proc_net type. by Robert Craig · 11 years ago
- 529fcbe Create proc_net type for /proc/sys/net entries. by Robert Craig · 11 years ago
- 11c48d4 Merge "Remove ping domain." by Nick Kralevich · 11 years ago
- a506613 Fix denials triggered by adb shell screencap. by Stephen Smalley · 11 years ago
- 396015c Remove ping domain. by Stephen Smalley · 11 years ago
- 5f29026 Revert "Make surfaceflinger domain enforcing." by Nick Kralevich · 11 years ago
- a6f88c7 Revert "Make ping enforcing." by Nick Kralevich · 11 years ago
- b8ac06f Revert "Make mediaserver enforcing." by Nick Kralevich · 11 years ago
- 3d770d2 surfaceflinger: fix bugreport screenshot functionality by Nick Kralevich · 11 years ago
- 37339c7 fix mediaserver selinux denials. by Nick Kralevich · 11 years ago
- a4e28f2 Merge "Allow dumpstate to write shell files" by Nick Kralevich · 11 years ago
- bfa3cd5 Allow dumpstate to write shell files by Nick Kralevich · 11 years ago
- a730e50 Don't allow zygote init:binder call by Nick Kralevich · 11 years ago
- ed1648a Merge "Address adb backup/restore denials." by Nick Kralevich · 11 years ago
- c4021ce Address adb backup/restore denials. by Stephen Smalley · 11 years ago
- 301e61e Merge "Make mediaserver enforcing." by Nick Kralevich · 11 years ago
- 14a7764 Merge "Make media_app enforcing." by Nick Kralevich · 11 years ago
- af28817 Merge "Make nfc enforcing." by Nick Kralevich · 11 years ago
- 782af9e Merge "Make radio enforcing." by Nick Kralevich · 11 years ago
- ee3cfd2 Merge "Make bluetooth enforcing." by Nick Kralevich · 11 years ago
- aef19eb Merge "Make surfaceflinger domain enforcing." by Nick Kralevich · 11 years ago
- 4e39317 Merge "Confine adbd but leave it permissive for now." by Nick Kralevich · 11 years ago
- e7ec2f5 Only allow PROT_EXEC for ashmem where required. by Stephen Smalley · 11 years ago
- ad7df7b Remove execmem permission from domain, add to appdomain. by Stephen Smalley · 11 years ago
- 527316a Allow use of art as the Android runtime. by Stephen Smalley · 11 years ago
- 81e74b1 Confine adbd but leave it permissive for now. by Stephen Smalley · 11 years ago
- 588bb5c Merge "Confine sdcardd, but leave it permissive for now." by Nick Kralevich · 11 years ago
- c48fd77 Confine dhcp, but leave it permissive for now. by Stephen Smalley · 11 years ago
- 9cc6d8d Adding permissions needed to remove cache by jaejyn.shin · 11 years ago
- c17d30a Delete dalvikcache_data_file write/setattr access from shell. by Stephen Smalley · 11 years ago
- d28ceeb Merge "shell: allow setting debug_prop and powerctl_prop" by Nick Kralevich · 11 years ago
- fe907e5 Merge "vold: allow wakelocks, fsck logs" by Nick Kralevich · 11 years ago
- 9969a4d Merge "Allow dumpsys" by Nick Kralevich · 11 years ago
- 20a791a shell: allow setting debug_prop and powerctl_prop by Nick Kralevich · 11 years ago
- a2c4cb3 Merge "Allow dumpstate to use ping." by Nick Kralevich · 11 years ago
- 5153890 Allow dumpsys by Nick Kralevich · 11 years ago
- 3753c81 vold: allow wakelocks, fsck logs by Nick Kralevich · 11 years ago
- 13e44ec allow system_server block_suspend by Nick Kralevich · 11 years ago
- 15abc95 Confine sdcardd, but leave it permissive for now. by Stephen Smalley · 11 years ago
- 815e981 Merge "Make bluetooth, nfc, radio and shell adb-installable" by Nick Kralevich · 11 years ago
- f5e9000 Make bluetooth, nfc, radio and shell adb-installable by Takeshi Aimi · 11 years ago
- f6bf7ef Allow dumpstate to use ping. by Nick Kralevich · 11 years ago
- b63e485 Merge "Confine shell domain in -user builds only." by Nick Kralevich · 11 years ago
- 712ca0a Confine shell domain in -user builds only. by Stephen Smalley · 11 years ago
- 5946937 Add rules to permit CTS security-related tests to run. by Stephen Smalley · 11 years ago
- ae2a35c Merge "Label /data/media with its own type and allow access." by Nick Kralevich · 11 years ago
- e13fabd Label /data/media with its own type and allow access. by Stephen Smalley · 11 years ago
- c4d7c0d system_server.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
- 61dc350 app.te: allow getopt/getattr on zygote socket by Nick Kralevich · 11 years ago
- 09e6abd initial dumpstate domain by Nick Kralevich · 11 years ago
- caa6a32 initial inputflinger domain by Nick Kralevich · 11 years ago
- 96c266c Merge "put netd into net_domain" by Nick Kralevich · 11 years ago
- 8b0ce1b Merge "Label /data/misc/zoneinfo" by Nick Kralevich · 11 years ago
- bc19050 put netd into net_domain by Nick Kralevich · 11 years ago
- 3867c03 Merge "alphabetize /data/misc entries." by Nick Kralevich · 11 years ago
- 7466f9b Label /data/misc/zoneinfo by Nick Kralevich · 11 years ago
- 6a32eec alphabetize /data/misc entries. by Nick Kralevich · 11 years ago
- 8fff872 Merge "Make tee enforcing." by Nick Kralevich · 11 years ago
- 8ad2259 Make bootanim domain enforcing. by Stephen Smalley · 11 years ago
- 4b237c9 Merge "Make watchdogd enforcing." by Nick Kralevich · 11 years ago
- a11c56e Make surfaceflinger domain enforcing. by Stephen Smalley · 11 years ago
- acde43f Define a domain for the bootanim service. by Stephen Smalley · 11 years ago
- 3ba9012 Move gpu_device type and rules to core policy. by Stephen Smalley · 11 years ago
- cf6b350 Allow apps to execute ping by Nick Kralevich · 11 years ago
- ca9ba32 Merge "Make ping enforcing." by Nick Kralevich · 11 years ago
- 21a6a6b Merge "Allow system_app to set properties" by Nick Kralevich · 11 years ago
- b71be5c Merge "Make the runas domain enforcing." by Nick Kralevich · 11 years ago
- 3e78000 Allow system_app to set properties by Nick Kralevich · 11 years ago
- 6531712 Allow untrusted apps to execute binaries from their sandbox directories. by Stephen Smalley · 11 years ago
- 27daf18 Make the runas domain enforcing. by Stephen Smalley · 11 years ago