Gitiles
Code Review
Sign In
LeafOS
/
LeafOS-Project
/
android_system_sepolicy
/
7ba515adc81476601c3c47b0b17762d979c2e599
/
public
/
platform_app.te
3b9fad1
Remove unused *_tmpfs types
by Jeff Vander Stoep
· 6 years ago
41a2abf
Properly Treble-ize tmpfs access
by Jeff Vander Stoep
· 6 years ago
c42d134
Move platform_app policy to private
by Alex Klyubin
· 8 years ago
eb482c4
platform_app.te: remove obsolete rules.
by Nick Kralevich
· 8 years ago
3e8dbf0
Restore app_domain macro and move to private use.
by dcashman
· 8 years ago
6f090f6
Label ephemeral APKs and handle their install/uninstall
by Chad Brubaker
· 8 years ago
cc39f63
Split general policy into public and private components.
by dcashman
· 8 years ago
[Renamed from platform_app.te]
ec75085
selinux: Update policies for mediadrmserver
by Takahiro Aizawa
· 8 years ago
49ac2a3
SELinux policies for /data/preloads directory
by Fyodor Kupolov
· 9 years ago
743969b
Update selinux policy for VrManager AIDL.
by Ruben Brunk
· 9 years ago
33fe478
Modified security policy to allow user to get their own icon.
by Oleksandr Peletskyi
· 9 years ago
8f5a891
Make voiceinteractionservice app_api_service.
by dcashman
· 9 years ago
c3ba2e5
selinux rules for codec process
by Marco Nelissen
· 9 years ago
c8b2143
Allow platform app to get handle to voiceinteraction service.
by dcashman
· 9 years ago
b1bf83f
Revert "selinux rules for codec process"
by Marco Nelissen
· 9 years ago
e037830
selinux: Update policies for cameraserver
by Chien-Yu Chen
· 9 years ago
2afb217
selinux rules for codec process
by Marco Nelissen
· 9 years ago
e97bd88
Creates a new permission for /cache/recovery am: 549ccf77e3 am: b16fc899d7
by Felipe Leme
· 9 years ago
549ccf7
Creates a new permission for /cache/recovery
by Felipe Leme
· 9 years ago
b03831f
Add rules for running audio services in audioserver
by Marco Nelissen
· 9 years ago
d20a46e
Create attribute for moving perms out of domain am: d22987b4da am: e2280fbcdd
by Jeff Vander Stoep
· 9 years ago
d22987b
Create attribute for moving perms out of domain
by Jeff Vander Stoep
· 9 years ago
0f754ed
Update selinux policies for mediaextractor process
by Marco Nelissen
· 9 years ago
c9036fb
Grant platform apps access to /mnt/media_rw.
by Jeff Sharkey
· 10 years ago
bd7f580
Enforce more specific service access.
by dcashman
· 10 years ago
03a6f64
Enforce more specific service access.
by dcashman
· 10 years ago
91b7c67
Enforce more specific service access.
by dcashman
· 10 years ago
3cc6fc5
Enforce more specific service access.
by dcashman
· 10 years ago
d4c78f4
Enforce more specific service access.
by dcashman
· 10 years ago
4cdea7f
Assign app_api_service attribute to services.
by dcashman
· 10 years ago
b075338
Assign app_api_service attribute to services.
by dcashman
· 10 years ago
d12993f
Add system_api_service and app_api_service attributes.
by dcashman
· 10 years ago
8af4e9c
Record observed service accesses.
by dcashman
· 10 years ago
e8064af
Add graphicsstats service
by John Reck
· 10 years ago
23f3361
Record observed system_server servicemanager service requests.
by dcashman
· 10 years ago
566e8fe
Record service accesses.
by dcashman
· 10 years ago
c631ede
Remove known system_server service accesses from auditing.
by dcashman
· 10 years ago
4a89cdf
Make system_server_service an attribute.
by dcashman
· 10 years ago
3fbeb18
Allow find access to drmserver_service from nfc and platform_app.
by dcashman
· 10 years ago
cd82557
Restrict service_manager find and list access.
by dcashman
· 10 years ago
b8511e0
Add access control for each service_manager action.
by Riley Spahn
· 10 years ago
d335682
Let DCS read staged APK clusters.
by Jeff Sharkey
· 10 years ago
8429c9b
Make platform_app enforcing.
by Stephen Smalley
· 11 years ago
7785206
Remove platform_app shell_data_file:lnk_file read access.
by Stephen Smalley
· 11 years ago
9ba844f
Coalesce shared_app, media_app, release_app into untrusted_app.
by Stephen Smalley
· 11 years ago
f9c3257
Get rid of separate download_file type.
by Stephen Smalley
· 11 years ago
b0db712
Clean up, unify, and deduplicate app domain rules.
by Stephen Smalley
· 11 years ago
623975f
Support forcing permissive domains to unconfined.
by Nick Kralevich
· 11 years ago
527316a
Allow use of art as the Android runtime.
by Stephen Smalley
· 11 years ago
e13fabd
Label /data/media with its own type and allow access.
by Stephen Smalley
· 11 years ago
5637099
Confine all app domains, but make them permissive for now.
by Stephen Smalley
· 11 years ago
353c72e
Move unconfined domains out of permissive mode.
by Nick Kralevich
· 11 years ago
748fdef
Move *_app into their own file
by Nick Kralevich
· 11 years ago