1. bd7f580 Enforce more specific service access. by dcashman · 10 years ago
  2. 03a6f64 Enforce more specific service access. by dcashman · 10 years ago
  3. 9bef250 system_server: support hard linking for split APKs by Nick Kralevich · 10 years ago
  4. 8a06c07 Allow system_server to collect app heapdumps (debug builds only) by Nick Kralevich · 10 years ago
  5. 91b7c67 Enforce more specific service access. by dcashman · 10 years ago
  6. 3cc6fc5 Enforce more specific service access. by dcashman · 10 years ago
  7. 3af8c9d Allow system_server to read oat dir by Fyodor Kupolov · 10 years ago
  8. d4c78f4 Enforce more specific service access. by dcashman · 10 years ago
  9. 73d9c2a Initial policy for expanded storage. by Jeff Sharkey · 10 years ago
  10. e207986 SELinux permissions for gatekeeper TEE proxy by Andres Morales · 10 years ago
  11. 4cdea7f Assign app_api_service attribute to services. by dcashman · 10 years ago
  12. b075338 Assign app_api_service attribute to services. by dcashman · 10 years ago
  13. 513d77b Remove obsolete system_server auditallow logging. by dcashman · 10 years ago
  14. 8af4e9c Record observed service accesses. by dcashman · 10 years ago
  15. 8927772 Add keystore add_auth by Chad Brubaker · 10 years ago
  16. f063f46 Updated policy for external storage. by Jeff Sharkey · 10 years ago
  17. e8064af Add graphicsstats service by John Reck · 10 years ago
  18. cd14eb4 Revert "allow system_server to set kernel scheduling priority" by Nick Kralevich · 10 years ago
  19. acc0842 system_server: neverallow blk_file read/write by Nick Kralevich · 10 years ago
  20. c01f7fd system_server: remove appdomain:file write by Nick Kralevich · 10 years ago
  21. 6843a79 am 8f81dcad: Only allow system_server to send commands to zygote. by dcashman · 10 years ago
  22. 8f81dca Only allow system_server to send commands to zygote. by dcashman · 10 years ago
  23. b41eb69 am 0560e75e: system_server: allow handling app generated unix_stream_sockets by Nick Kralevich · 10 years ago
  24. 0560e75 system_server: allow handling app generated unix_stream_sockets by Nick Kralevich · 10 years ago
  25. efb4bdb am 92b10ddb: Eliminate CAP_SYS_MODULE from system_server by Nick Kralevich · 10 years ago
  26. 92b10dd Eliminate CAP_SYS_MODULE from system_server by Nick Kralevich · 10 years ago
  27. 31a8511 am 23f33615: Record observed system_server servicemanager service requests. by dcashman · 10 years ago
  28. 23f3361 Record observed system_server servicemanager service requests. by dcashman · 10 years ago
  29. cd31111 am d99ea5a8: Merge "Revert /proc/net related changes" by Nick Kralevich · 10 years ago
  30. 5cf3994 Revert /proc/net related changes by Nick Kralevich · 10 years ago
  31. f4c0a09 am 437f7139: am 361cdaff: system_server: neverallow dex2oat exec by Nick Kralevich · 10 years ago
  32. 361cdaf system_server: neverallow dex2oat exec by Nick Kralevich · 10 years ago
  33. 854ad12 am a5119ee7: am 566e8fe2: Record service accesses. by dcashman · 10 years ago
  34. 566e8fe Record service accesses. by dcashman · 10 years ago
  35. 7dc1417 am c1142451: am 0d16b5ac: Merge "Remove known system_server service accesses from auditing." by dcashman · 10 years ago
  36. c631ede Remove known system_server service accesses from auditing. by dcashman · 10 years ago
  37. 5585c30 am acf209e8: am 99940d1a: remove /proc/net read access from domain.te by Nick Kralevich · 10 years ago
  38. 61e82a2 resolved conflicts for merge of e55f2b81 to lmp-mr1-dev-plus-aosp by dcashman · 10 years ago
  39. 99940d1 remove /proc/net read access from domain.te by Nick Kralevich · 10 years ago
  40. 4a89cdf Make system_server_service an attribute. by dcashman · 10 years ago
  41. 49e7e0c am d8800a10: am cd82557d: Restrict service_manager find and list access. by dcashman · 10 years ago
  42. cd82557 Restrict service_manager find and list access. by dcashman · 10 years ago
  43. 6eabeb2 am c230c292: am c48971f6: allow system_server to set ro.build.fingerprint by Nick Kralevich · 10 years ago
  44. c48971f allow system_server to set ro.build.fingerprint by Nick Kralevich · 10 years ago
  45. 0ff8576 am 4d9648e3: am b519949d: system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
  46. 4d9648e am b519949d: system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
  47. 8526ace am 491c5368: am 2d1650f4: allow system_server to set kernel scheduling priority by Nick Kralevich · 10 years ago
  48. 2d1650f allow system_server to set kernel scheduling priority by Nick Kralevich · 10 years ago
  49. b519949 system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
  50. 255d409 resolved conflicts for merge of bdec09b9 to lmp-mr1-dev-plus-aosp by Robin Lee · 10 years ago
  51. 5871d1b resolved conflicts for merge of 51bfecf4 to lmp-dev-plus-aosp by Robin Lee · 10 years ago
  52. 51bfecf Pull keychain-data policy out of system-data by Robin Lee · 10 years ago
  53. 86facd9 am 0ed8f86e: am 2380d05f: allow system_server oemfs read access by Nick Kralevich · 10 years ago
  54. 7fe94a1 am 2380d05f: allow system_server oemfs read access by Nick Kralevich · 10 years ago
  55. 2380d05 allow system_server oemfs read access by Nick Kralevich · 10 years ago
  56. f37ce3f Add support for factory reset protection. by dcashman · 10 years ago
  57. 72acd6b Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
  58. 43b8bc5 resolved conflicts for merge of 47bd7300 to lmp-dev-plus-aosp by dcashman · 10 years ago
  59. 47bd730 Add support for factory reset protection. by dcashman · 10 years ago
  60. f9ea564 am de08be8a: Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
  61. de08be8 Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
  62. bd6d1f3 am 09eae908: Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
  63. 09eae90 Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
  64. 372d0df Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
  65. 4a518b8 am 997461bd: Allow system_server to talk to netlink directly. by Sreeram Ramachandran · 10 years ago
  66. 997461b Allow system_server to talk to netlink directly. by Sreeram Ramachandran · 10 years ago
  67. d065f04 Resync lmp-dev-plus-aosp with master by Nick Kralevich · 10 years ago
  68. 7d62ace am aa8e657e: Revert "fix system_server dex2oat exec" by Narayan Kamath · 10 years ago
  69. aa8e657 Revert "fix system_server dex2oat exec" by Narayan Kamath · 10 years ago
  70. 9d24d52 am ba992496: Define debuggerd class, permissions, and rules. by Stephen Smalley · 10 years ago
  71. ba99249 Define debuggerd class, permissions, and rules. by Stephen Smalley · 10 years ago
  72. bf69632 DO NOT MERGE: Remove service_manager audit_allows. by Riley Spahn · 11 years ago
  73. d263576 Remove auditallow from system_server. by Riley Spahn · 11 years ago
  74. 5a25fbf Remove auditallow from system_server. by Riley Spahn · 11 years ago
  75. 344fc10 Add access control for each service_manager action. by Riley Spahn · 11 years ago
  76. 10370f5 fix system_server dex2oat exec by Nick Kralevich · 11 years ago
  77. 81839df reconcile aosp (3a8c5dc05fb7696dd81b8a7c1b2524224154e8ea) after branching. Please do not merge. by Ed Heyl · 11 years ago
  78. 8395bb4 fix system_server dex2oat exec by Nick Kralevich · 11 years ago
  79. b8511e0 Add access control for each service_manager action. by Riley Spahn · 11 years ago
  80. 3a8c5dc Allow oemfs search for system_server and bootanim by Todd Poynor · 11 years ago
  81. 5d60f04 sepolicy: allow system server to remove cgroups by Colin Cross · 11 years ago
  82. d8447fd Typedef+rules for SysSer to access persistent block device by Andres Morales · 11 years ago
  83. be092af Rules to allow installing package directories. by Jeff Sharkey · 11 years ago
  84. d00eff4 system_server: bring back sdcard_type neverallow rule by Nick Kralevich · 11 years ago
  85. 596bcc7 Remove keystore auditallow statements from system. by Riley Spahn · 11 years ago
  86. 1196d2a Adding policies for KeyStore MAC. by Riley Spahn · 11 years ago
  87. 8c6552a Allow system_server to read all /proc files by Nick Kralevich · 11 years ago
  88. fee4915 Align SELinux property policy with init property_perms. by Stephen Smalley · 11 years ago
  89. 97a2cfd Allow Bluetooth app to initiate DHCP service on bt-pan interface. by Paul Jensen · 11 years ago
  90. 04e730b system_server: allow open /dev/snd and read files by Nick Kralevich · 11 years ago
  91. 00b180d Eliminate some duplicated rules. by Stephen Smalley · 11 years ago
  92. fad4d5f Fix SELinux policies to allow resource overlays. by Nick Kralevich · 11 years ago
  93. a76d9dd system_server profile access by Nick Kralevich · 11 years ago
  94. 96d9af4 allow system_server getattr on /data/dalvik-cache/profiles by Nick Kralevich · 11 years ago
  95. 8670305 Remove world-read access to /data/dalvik-cache/profiles by Nick Kralevich · 11 years ago
  96. f90c41f Add SELinux rules for service_manager. by Riley Spahn · 11 years ago
  97. 13d5886 system_server: Adds permission to system_server to write sysfs file by Ruchi Kandoi · 11 years ago
  98. 6bb672e Make the system_server domain enforcing. by Stephen Smalley · 11 years ago
  99. 2cc6d63 Allow system_server access to /data/media files passed via Binder. by Stephen Smalley · 11 years ago
  100. f85c1fc Allow installd, vold, system_server unlabeled access. by Stephen Smalley · 11 years ago