- bd7f580 Enforce more specific service access. by dcashman · 10 years ago
- 03a6f64 Enforce more specific service access. by dcashman · 10 years ago
- 9bef250 system_server: support hard linking for split APKs by Nick Kralevich · 10 years ago
- 8a06c07 Allow system_server to collect app heapdumps (debug builds only) by Nick Kralevich · 10 years ago
- 91b7c67 Enforce more specific service access. by dcashman · 10 years ago
- 3cc6fc5 Enforce more specific service access. by dcashman · 10 years ago
- 3af8c9d Allow system_server to read oat dir by Fyodor Kupolov · 10 years ago
- d4c78f4 Enforce more specific service access. by dcashman · 10 years ago
- 73d9c2a Initial policy for expanded storage. by Jeff Sharkey · 10 years ago
- e207986 SELinux permissions for gatekeeper TEE proxy by Andres Morales · 10 years ago
- 4cdea7f Assign app_api_service attribute to services. by dcashman · 10 years ago
- b075338 Assign app_api_service attribute to services. by dcashman · 10 years ago
- 513d77b Remove obsolete system_server auditallow logging. by dcashman · 10 years ago
- 8af4e9c Record observed service accesses. by dcashman · 10 years ago
- 8927772 Add keystore add_auth by Chad Brubaker · 10 years ago
- f063f46 Updated policy for external storage. by Jeff Sharkey · 10 years ago
- e8064af Add graphicsstats service by John Reck · 10 years ago
- cd14eb4 Revert "allow system_server to set kernel scheduling priority" by Nick Kralevich · 10 years ago
- acc0842 system_server: neverallow blk_file read/write by Nick Kralevich · 10 years ago
- c01f7fd system_server: remove appdomain:file write by Nick Kralevich · 10 years ago
- 6843a79 am 8f81dcad: Only allow system_server to send commands to zygote. by dcashman · 10 years ago
- 8f81dca Only allow system_server to send commands to zygote. by dcashman · 10 years ago
- b41eb69 am 0560e75e: system_server: allow handling app generated unix_stream_sockets by Nick Kralevich · 10 years ago
- 0560e75 system_server: allow handling app generated unix_stream_sockets by Nick Kralevich · 10 years ago
- efb4bdb am 92b10ddb: Eliminate CAP_SYS_MODULE from system_server by Nick Kralevich · 10 years ago
- 92b10dd Eliminate CAP_SYS_MODULE from system_server by Nick Kralevich · 10 years ago
- 31a8511 am 23f33615: Record observed system_server servicemanager service requests. by dcashman · 10 years ago
- 23f3361 Record observed system_server servicemanager service requests. by dcashman · 10 years ago
- cd31111 am d99ea5a8: Merge "Revert /proc/net related changes" by Nick Kralevich · 10 years ago
- 5cf3994 Revert /proc/net related changes by Nick Kralevich · 10 years ago
- f4c0a09 am 437f7139: am 361cdaff: system_server: neverallow dex2oat exec by Nick Kralevich · 10 years ago
- 361cdaf system_server: neverallow dex2oat exec by Nick Kralevich · 10 years ago
- 854ad12 am a5119ee7: am 566e8fe2: Record service accesses. by dcashman · 10 years ago
- 566e8fe Record service accesses. by dcashman · 10 years ago
- 7dc1417 am c1142451: am 0d16b5ac: Merge "Remove known system_server service accesses from auditing." by dcashman · 10 years ago
- c631ede Remove known system_server service accesses from auditing. by dcashman · 10 years ago
- 5585c30 am acf209e8: am 99940d1a: remove /proc/net read access from domain.te by Nick Kralevich · 10 years ago
- 61e82a2 resolved conflicts for merge of e55f2b81 to lmp-mr1-dev-plus-aosp by dcashman · 10 years ago
- 99940d1 remove /proc/net read access from domain.te by Nick Kralevich · 10 years ago
- 4a89cdf Make system_server_service an attribute. by dcashman · 10 years ago
- 49e7e0c am d8800a10: am cd82557d: Restrict service_manager find and list access. by dcashman · 10 years ago
- cd82557 Restrict service_manager find and list access. by dcashman · 10 years ago
- 6eabeb2 am c230c292: am c48971f6: allow system_server to set ro.build.fingerprint by Nick Kralevich · 10 years ago
- c48971f allow system_server to set ro.build.fingerprint by Nick Kralevich · 10 years ago
- 0ff8576 am 4d9648e3: am b519949d: system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
- 4d9648e am b519949d: system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
- 8526ace am 491c5368: am 2d1650f4: allow system_server to set kernel scheduling priority by Nick Kralevich · 10 years ago
- 2d1650f allow system_server to set kernel scheduling priority by Nick Kralevich · 10 years ago
- b519949 system_server: assert app data files never opened directly by Nick Kralevich · 10 years ago
- 255d409 resolved conflicts for merge of bdec09b9 to lmp-mr1-dev-plus-aosp by Robin Lee · 10 years ago
- 5871d1b resolved conflicts for merge of 51bfecf4 to lmp-dev-plus-aosp by Robin Lee · 10 years ago
- 51bfecf Pull keychain-data policy out of system-data by Robin Lee · 10 years ago
- 86facd9 am 0ed8f86e: am 2380d05f: allow system_server oemfs read access by Nick Kralevich · 10 years ago
- 7fe94a1 am 2380d05f: allow system_server oemfs read access by Nick Kralevich · 10 years ago
- 2380d05 allow system_server oemfs read access by Nick Kralevich · 10 years ago
- f37ce3f Add support for factory reset protection. by dcashman · 10 years ago
- 72acd6b Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
- 43b8bc5 resolved conflicts for merge of 47bd7300 to lmp-dev-plus-aosp by dcashman · 10 years ago
- 47bd730 Add support for factory reset protection. by dcashman · 10 years ago
- f9ea564 am de08be8a: Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
- de08be8 Allow system reset_uid, sync_uid, password_uid by Robin Lee · 10 years ago
- bd6d1f3 am 09eae908: Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
- 09eae90 Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
- 372d0df Remove system_server create access from /data/dalvik-cache by Brian Carlstrom · 10 years ago
- 4a518b8 am 997461bd: Allow system_server to talk to netlink directly. by Sreeram Ramachandran · 10 years ago
- 997461b Allow system_server to talk to netlink directly. by Sreeram Ramachandran · 10 years ago
- d065f04 Resync lmp-dev-plus-aosp with master by Nick Kralevich · 10 years ago
- 7d62ace am aa8e657e: Revert "fix system_server dex2oat exec" by Narayan Kamath · 10 years ago
- aa8e657 Revert "fix system_server dex2oat exec" by Narayan Kamath · 10 years ago
- 9d24d52 am ba992496: Define debuggerd class, permissions, and rules. by Stephen Smalley · 10 years ago
- ba99249 Define debuggerd class, permissions, and rules. by Stephen Smalley · 10 years ago
- bf69632 DO NOT MERGE: Remove service_manager audit_allows. by Riley Spahn · 11 years ago
- d263576 Remove auditallow from system_server. by Riley Spahn · 11 years ago
- 5a25fbf Remove auditallow from system_server. by Riley Spahn · 11 years ago
- 344fc10 Add access control for each service_manager action. by Riley Spahn · 11 years ago
- 10370f5 fix system_server dex2oat exec by Nick Kralevich · 11 years ago
- 81839df reconcile aosp (3a8c5dc05fb7696dd81b8a7c1b2524224154e8ea) after branching. Please do not merge. by Ed Heyl · 11 years ago
- 8395bb4 fix system_server dex2oat exec by Nick Kralevich · 11 years ago
- b8511e0 Add access control for each service_manager action. by Riley Spahn · 11 years ago
- 3a8c5dc Allow oemfs search for system_server and bootanim by Todd Poynor · 11 years ago
- 5d60f04 sepolicy: allow system server to remove cgroups by Colin Cross · 11 years ago
- d8447fd Typedef+rules for SysSer to access persistent block device by Andres Morales · 11 years ago
- be092af Rules to allow installing package directories. by Jeff Sharkey · 11 years ago
- d00eff4 system_server: bring back sdcard_type neverallow rule by Nick Kralevich · 11 years ago
- 596bcc7 Remove keystore auditallow statements from system. by Riley Spahn · 11 years ago
- 1196d2a Adding policies for KeyStore MAC. by Riley Spahn · 11 years ago
- 8c6552a Allow system_server to read all /proc files by Nick Kralevich · 11 years ago
- fee4915 Align SELinux property policy with init property_perms. by Stephen Smalley · 11 years ago
- 97a2cfd Allow Bluetooth app to initiate DHCP service on bt-pan interface. by Paul Jensen · 11 years ago
- 04e730b system_server: allow open /dev/snd and read files by Nick Kralevich · 11 years ago
- 00b180d Eliminate some duplicated rules. by Stephen Smalley · 11 years ago
- fad4d5f Fix SELinux policies to allow resource overlays. by Nick Kralevich · 11 years ago
- a76d9dd system_server profile access by Nick Kralevich · 11 years ago
- 96d9af4 allow system_server getattr on /data/dalvik-cache/profiles by Nick Kralevich · 11 years ago
- 8670305 Remove world-read access to /data/dalvik-cache/profiles by Nick Kralevich · 11 years ago
- f90c41f Add SELinux rules for service_manager. by Riley Spahn · 11 years ago
- 13d5886 system_server: Adds permission to system_server to write sysfs file by Ruchi Kandoi · 11 years ago
- 6bb672e Make the system_server domain enforcing. by Stephen Smalley · 11 years ago
- 2cc6d63 Allow system_server access to /data/media files passed via Binder. by Stephen Smalley · 11 years ago
- f85c1fc Allow installd, vold, system_server unlabeled access. by Stephen Smalley · 11 years ago