Gitiles
Code Review
Sign In
LeafOS
/
LeafOS-Project
/
android_system_sepolicy
/
a893edae3716b33be62edf1b5f3336e6f6bb251b
/
init.te
c626a88
Allow init to relabel rootfs files.
by Stephen Smalley
· 11 years ago
f3c3a1a
Remove execute_no_trans from unconfineddomain.
by Stephen Smalley
· 11 years ago
bac4ccc
Prevent adding transitions to kernel or init domains.
by Stephen Smalley
· 11 years ago
75e2ef9
Restrict use of context= mount options.
by Stephen Smalley
· 11 years ago
ee49c0e
remove shell_data_file from unconfined.
by Nick Kralevich
· 11 years ago
3235f61
Restrict /data/security and setprop selinux.reload_policy access.
by Stephen Smalley
· 11 years ago
73b0346
Explictly allow init and kernel unlabeled access.
by Stephen Smalley
· 11 years ago
eb1bbf2
Clean up kernel, init, and recovery domains.
by Stephen Smalley
· 11 years ago
03ce512
Remove /system write from unconfined
by Nick Kralevich
· 11 years ago
ad0d0fc
Protect /data/property.
by Stephen Smalley
· 11 years ago
685e2f9
remove syslog_* from unconfined
by Nick Kralevich
· 11 years ago
356f4be
Restrict requesting contexts other than policy-defined defaults.
by Stephen Smalley
· 11 years ago
02dac03
Drop relabelto_domain() macro and its associated definitions.
by Stephen Smalley
· 11 years ago
cd905ec
Protect keystore's files.
by Nick Kralevich
· 11 years ago
3f40d4f
Remove block device access from unconfined domains.
by Stephen Smalley
· 11 years ago
5487ca0
Remove several superuser capabilities from unconfined domains.
by Stephen Smalley
· 11 years ago
b081cc1
Remove mount-related permissions from unconfined domains.
by Stephen Smalley
· 11 years ago
fed8a2a
Remove transition / dyntransition from unconfined
by Nick Kralevich
· 11 years ago
fea6e66
Allow kernel domain, not init domain, to set SELinux enforcing mode.
by Stephen Smalley
· 11 years ago
9e8b8d9
Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode."
by Nick Kralevich
· 11 years ago
bf12e22
Allow kernel domain, not init domain, to set SELinux enforcing mode.
by Stephen Smalley
· 11 years ago
7adb999
Restrict the ability to set usermodehelpers and proc security settings.
by Stephen Smalley
· 11 years ago
d99e6d5
Restrict the ability to set SELinux enforcing mode to init.
by Stephen Smalley
· 11 years ago
b1d8164
Make kernel / init enforcing
by Nick Kralevich
· 11 years ago
2637198
Only init should be able to load a security policy
by Nick Kralevich
· 12 years ago
0c9708b
domain.te: Add backwards compatibility for unlabeled files
by Nick Kralevich
· 12 years ago
77d4731
Make all domains unconfined.
by repo sync
· 12 years ago
50e37b9
Move domains into per-domain permissive mode.
by repo sync
· 12 years ago
2dd4e51
SE Android policy.
by Stephen Smalley
· 13 years ago