Gitiles
Code Review
Sign In
LeafOS
/
LeafOS-Project
/
android_system_sepolicy
/
9128735f1f02603c6c35de40a5c2eeb6e8cdc2e6
/
public
/
system_server.te
5425c87
Allow the shell to disable charging.
by Michael Rosenfeld
· 3 years, 4 months ago
85acf6e
Fix broken neverallow rules
by Inseob Kim
· 4 years ago
c3c52ae
Define power.battery_input.suspended property
by Dmitri Plotnikov
· 4 years, 6 months ago
9f5d0d9
Initial selinux policy support for memfd
by Jeff Vander Stoep
· 6 years ago
41a2abf
Properly Treble-ize tmpfs access
by Jeff Vander Stoep
· 6 years ago
59322f1
Move system_server policy to private
by Alex Klyubin
· 8 years ago
4c40d73
Merge ephemeral data and apk files into app
by Chad Brubaker
· 8 years ago
d33a9a1
logd: restrict access to /dev/event-log-tags
by Mark Salyzyn
· 8 years ago
384a73d
Remove hal_light from system_server domain
by Alex Klyubin
· 8 years ago
ae206f1
sepolicy for usb hal
by Badhri Jagan Sridharan
· 8 years ago
606d2fd
te_macros: introduce add_service() macro
by William Roberts
· 8 years ago
c86f42b
Add sepolicy for drm HALs
by Jeff Tinker
· 8 years ago
3918540
rename mediaanalytics->mediametrics, wider access
by Ray Essick
· 8 years ago
0223ca5
system_server: add hal_lights permission
by Steven Moreland
· 8 years ago
9d8edca
wificond_service: drop system_service typeattribute
by William Roberts
· 8 years ago
d5b6043
more ephemeral_app cleanup
by Nick Kralevich
· 8 years ago
2796009
Fix fingerprint crypto operations.
by Jim Miller
· 8 years ago
3a6bc68
allow init and system_server access to tracing
by mukesh agrawal
· 9 years ago
cb3eb4e
Introduce crash_dump debugging helper.
by Josh Gao
· 8 years ago
7ae1d23
Don't open appfuse files in apps.
by Daichi Hirono
· 8 years ago
828433c
Define policy for /proc/uid_procstat/set.
by Jeff Sharkey
· 8 years ago
54e0e5a
New SeLinux policy for fingerprint HIDL
by Jim Miller
· 8 years ago
953c439
add selinux policy for GNSS hal
by Hridya Valsaraju
· 8 years ago
be27f92
Add selinux policy for Bluetooth HAL
by Andre Eisenbach
· 8 years ago
c9d46d4
Add sepolicy for sensors
by Ashutosh Joshi
· 8 years ago
e8d0bda
Add sepolicy for contexthub HAL
by Ashutosh Joshi
· 8 years ago
062236a
Remove access to ro.runtime.firstboot from apps
by Alex Klyubin
· 8 years ago
2015107
Restrict access to ro.serialno and ro.boot.serialno
by Alex Klyubin
· 8 years ago
e91740a
Allow hal_audio to set scheduling policy for its threads
by Mikhail Naganov
· 8 years ago
bb9a388
Assign a label to the ro.boottime.* properties
by Nick Kralevich
· 8 years ago
a95c52e
Add sepolicy for consumerir HIDL HAL
by Connor O'Brien
· 8 years ago
02ed21e
hal_wifi: Allow system_server to access wifi HIDL services
by Roshan Pius
· 8 years ago
8b1d452
installd has moved on to Binder; goodbye socket!
by Jeff Sharkey
· 8 years ago
2e00e63
sepolicy: add version_policy tool and version non-platform policy.
by dcashman
· 8 years ago
e160d14
Rules for new installd Binder interface.
by Jeff Sharkey
· 8 years ago
090f4a4
Allow access to mediaanalytics service
by Ray Essick
· 8 years ago
17c675b
Allow system_server to measure emulated stats.
by Jeff Sharkey
· 8 years ago
55e86a3
system_server: Delete system_file:file execute_no_trans;
by Nick Kralevich
· 8 years ago
dd958e5
Add sepolicy for gralloc-alloc HAL
by Chia-I Wu
· 8 years ago
6f090f6
Label ephemeral APKs and handle their install/uninstall
by Chad Brubaker
· 8 years ago
dc43f7c
Add the "webview_zygote" domain.
by Robert Sesek
· 8 years ago
0e1cbf5
Add persist.vendor.overlay. to properties
by Jason Monk
· 8 years ago
58305da
Revert "Restore system_server ioctl socket access."
by Nick Kralevich
· 8 years ago
9785f2a
sepolicy: Add policy for thermal HIDL service
by Polina Bondarenko
· 8 years ago
ec3285c
Restore system_server ioctl socket access.
by dcashman
· 8 years ago
0a924a6
hal_memtrack: Add sepolicy for memtrack service.
by Ruchi Kandoi
· 8 years ago
3c30c4e
hal_power: Add sepolicy for power service.
by Ruchi Kandoi
· 8 years ago
1ec710c
Sepolicy for light hal.
by Steven Moreland
· 8 years ago
b5f5931
Added permissions for the dumpstate service.
by Felipe Leme
· 8 years ago
8044129
system_server: allow appendable file descriptors
by Nick Kralevich
· 8 years ago
27ae545
clean up hal types
by Jeff Vander Stoep
· 8 years ago
2370fc7
sepolicy for boot_control HAL service
by Connor O'Brien
· 8 years ago
7ba0485
sepolicy: Add policy for VR HIDL service.
by Craig Donner
· 8 years ago
2d9d3e6
Cleanup and renaming of vibrator HAL sepolicy
by Prashant Malani
· 8 years ago
c86eb96
Add sysfs rule for vibrator in system_server
by Prashant Malani
· 8 years ago
b32b4a1
sepolicy: Add policy for vibrator HIDL service
by Prashant Malani
· 8 years ago
06cf31e
Rename autoplay_app to ephemeral_app
by Chad Brubaker
· 8 years ago
abb5c72
system_server: Allow hwservicemanager to make binder calls
by Prashant Malani
· 8 years ago
cc39f63
Split general policy into public and private components.
by dcashman
· 9 years ago
[Renamed (98%) from system_server.te]
a5a8072
Let system_server writes to dumpstate.options property.
by Felipe Leme
· 8 years ago
3189945
Allow system_server to delete directories in preloads
by Fyodor Kupolov
· 9 years ago
88323b2
allow system_server to set bootanim scheduling priority
by Wei Wang
· 9 years ago
b7ebb32
Allow cppreopts to work with selinux
by Alex Light
· 9 years ago
bff9801
Enforce ioctl command whitelisting on all sockets
by Jeff Vander Stoep
· 9 years ago
7ef8073
audit domain_deprecated perms for removal
by Jeff Vander Stoep
· 8 years ago
1e17051
Allow system_server to call wificond via Binder
by Christopher Wiley
· 9 years ago
bf18eca
Separate permissions to set WiFi related properties
by Christopher Wiley
· 9 years ago
28a896b
Allow system_server to make keystore_data_file links am: a67411c952
by Chad Brubaker
· 9 years ago
a67411c
Allow system_server to make keystore_data_file links
by Chad Brubaker
· 9 years ago
5e6aa65
resolve merge conflicts of 5423db6 to stage-aosp-master
by dcashman
· 9 years ago
5423db6
restrict access to timing information in /proc
by Daniel Micay
· 9 years ago
e402564
sepolicy: Add CAP_WAKE_ALARM to system_server.te am: 19b6485f5e
by John Stultz
· 9 years ago
19b6485
sepolicy: Add CAP_WAKE_ALARM to system_server.te
by John Stultz
· 9 years ago
c15090b
sepolicy: Add policy for sdcardfs and configfs
by Daniel Rosenberg
· 9 years ago
aeebec1
resolve merge conflicts of b71cf12 to nyc-dev-plus-aosp
by dcashman
· 9 years ago
17cfd3f
Keep pre-existing sysfs write permissions.
by dcashman
· 9 years ago
80fc292
Merge "sepolicy: broaden system_server access to foreign_dex_data_file." into nyc-dev
by Narayan Kamath
· 9 years ago
d82df3b
sepolicy: broaden system_server access to foreign_dex_data_file.
by Narayan Kamath
· 9 years ago
72f0fbb
SELinux policies for /data/preloads directory am: 49ac2a3d7a
by Fyodor Kupolov
· 9 years ago
49ac2a3
SELinux policies for /data/preloads directory
by Fyodor Kupolov
· 9 years ago
0bc35bd
sepolicy: broaden system_server access to foreign_dex_data_file{dir}.
by Narayan Kamath
· 9 years ago
13bdd39
sepolicy: broaden system_server access to foreign_dex_data_file{dir}.
by Narayan Kamath
· 9 years ago
3119945
Merge changes from topic \'dump_bluetooth_through_debuggerd\' into nyc-dev
by Andreas Gampe
· 9 years ago
50c2909
Merge changes from topic 'dump_bluetooth_through_debuggerd' into nyc-dev
by Andreas Gampe
· 9 years ago
cbfa8dd
Sepolicy: Allow debuggerd to dump backtraces of Bluetooth
by Andreas Gampe
· 9 years ago
0983db4
Sepolicy: Refactor long lines for debuggerd backtraces
by Andreas Gampe
· 9 years ago
e806cc9
move gpsd domain to device specific policy am: 3ba2d46616 am: 30a5ea5c72
by Jeff Vander Stoep
· 9 years ago
3ba2d46
move gpsd domain to device specific policy
by Jeff Vander Stoep
· 9 years ago
70f3aa9
Merge "Add CAP_IPC_LOCK and pinner to system_server" into nyc-dev am: 95fd38169b
by Philip Cuadra
· 9 years ago
95fd381
Merge "Add CAP_IPC_LOCK and pinner to system_server" into nyc-dev
by Philip Cuadra
· 9 years ago
96da70e
Add CAP_IPC_LOCK and pinner to system_server
by Philip Cuadra
· 9 years ago
68d3d9f
Allow the system to rename wallpaper files am: 39cfed0b23
by Christopher Tate
· 9 years ago
39cfed0
Allow the system to rename wallpaper files
by Christopher Tate
· 9 years ago
3e23ae9
Merge "reduce duplicate SELinux rules" am: b4720ae am: d266768
by Treehugger Robot
· 9 years ago
3493682
reduce duplicate SELinux rules
by Nick Kralevich
· 9 years ago
c46ef41
Merge "Selinux: Policies for otapreopt_chroot and postinstall_dexopt" into nyc-dev
by Andreas Gampe
· 9 years ago
8785a64
Merge "Selinux: Policies for otapreopt_chroot and postinstall_dexopt" into nyc-dev
by TreeHugger Robot
· 9 years ago
e5d8a94
Selinux: Policies for otapreopt_chroot and postinstall_dexopt
by Andreas Gampe
· 9 years ago
0d397af
Merge changes I9cdd52a2,Idf00e7a6 into nyc-dev am: fbb6d2de1c
by mukesh agrawal
· 9 years ago
fbb6d2d
Merge changes I9cdd52a2,Idf00e7a6 into nyc-dev
by Mukesh Agrawal
· 9 years ago
Next »