Gitiles
Code Review
Sign In
LeafOS
/
LeafOS-Project
/
android_system_sepolicy
/
f9ea564a9ee3d80c92d198bf52e28eed7dac509d
f9ea564
am de08be8a: Allow system reset_uid, sync_uid, password_uid
by Robin Lee
· 10 years ago
de08be8
Allow system reset_uid, sync_uid, password_uid
by Robin Lee
· 10 years ago
35651b3
am 372d0df7: Remove system_server create access from /data/dalvik-cache
by Brian Carlstrom
· 10 years ago
bd6d1f3
am 09eae908: Remove system_server create access from /data/dalvik-cache
by Brian Carlstrom
· 10 years ago
09eae90
Remove system_server create access from /data/dalvik-cache
by Brian Carlstrom
· 10 years ago
372d0df
Remove system_server create access from /data/dalvik-cache
by Brian Carlstrom
· 10 years ago
2fd17bc
am 67d58acb: Merge "Add permissive domains check to sepolicy-analyze." into lmp-dev
by dcashman
· 10 years ago
67d58ac
Merge "Add permissive domains check to sepolicy-analyze." into lmp-dev
by dcashman
· 10 years ago
5a4e67c
am 28b26bcf: support kernel writes to external SDcards
by Nick Kralevich
· 10 years ago
c30dd63
Add permissive domains check to sepolicy-analyze.
by dcashman
· 11 years ago
e829ec3
am 4c6b1350: support kernel writes to external SDcards
by Nick Kralevich
· 10 years ago
28b26bc
support kernel writes to external SDcards
by Nick Kralevich
· 10 years ago
4c6b135
support kernel writes to external SDcards
by Nick Kralevich
· 10 years ago
c6f9d44
am 711895db: Allow appdomain read perms on apk_data_files.
by dcashman
· 10 years ago
711895d
Allow appdomain read perms on apk_data_files.
by dcashman
· 10 years ago
0812ac4
am 85f255b8: DO NOT MERGE. Allow debuggerd read access to shared_relro files.
by dcashman
· 10 years ago
106050f
am 0d3f7ddc: remove appdomain\'s ability to examine all of /proc
by Nick Kralevich
· 10 years ago
0d3f7dd
remove appdomain's ability to examine all of /proc
by Nick Kralevich
· 10 years ago
eb8e3d6
am 92d1aa19: Merge "assert that no domain can set default properties"
by Nick Kralevich
· 10 years ago
92d1aa1
Merge "assert that no domain can set default properties"
by Nick Kralevich
· 10 years ago
99aa03d
assert that no domain can set default properties
by Nick Kralevich
· 10 years ago
641caa0
am b8b4f43c: Merge "Add permissive domains check to sepolicy-analyze."
by dcashman
· 10 years ago
99e3573
am 65feafce: tighten up neverallow rules for init binder operations
by Nick Kralevich
· 10 years ago
b8b4f43
Merge "Add permissive domains check to sepolicy-analyze."
by dcashman
· 10 years ago
9793ea7
Add permissive domains check to sepolicy-analyze.
by dcashman
· 11 years ago
65feafc
tighten up neverallow rules for init binder operations
by Nick Kralevich
· 10 years ago
4fe7c92
am cd10eb95: Allow debuggerd read access to shared_relro files.
by dcashman
· 10 years ago
85f255b
DO NOT MERGE. Allow debuggerd read access to shared_relro files.
by dcashman
· 10 years ago
cd10eb9
Allow debuggerd read access to shared_relro files.
by dcashman
· 10 years ago
fd8aafd
am 9a725b28: Allow init to restorecon sysfs files.
by Stephen Smalley
· 10 years ago
9a725b2
Allow init to restorecon sysfs files.
by Stephen Smalley
· 11 years ago
1ce845c
am 302f59aa: Merge "Allow init to restorecon sysfs files."
by Daniel Cashman
· 10 years ago
302f59a
Merge "Allow init to restorecon sysfs files."
by Daniel Cashman
· 10 years ago
a3ff156
resolved conflicts for merge of 4ddc6eb3 to lmp-dev-plus-aosp
by dcashman
· 10 years ago
bef36c0
am a20409bc: Merge "Allow untrusted_app access to temporary apk files."
by dcashman
· 10 years ago
6d5845d
am c15432df: Merge "Allow dumpstate to dump backtraces of certain native processes."
by Daniel Cashman
· 10 years ago
174babc
am feedd3c6: Make system use patchoat to relocate during runtime.
by Alex Light
· 10 years ago
a20409b
Merge "Allow untrusted_app access to temporary apk files."
by dcashman
· 10 years ago
fbbe9e9
Allow untrusted_app access to temporary apk files.
by dcashman
· 10 years ago
c15432d
Merge "Allow dumpstate to dump backtraces of certain native processes."
by Daniel Cashman
· 10 years ago
4ddc6eb
Merge "DO NOT MERGE. Allow untrusted_app access to temporary apk files." into lmp-dev
by dcashman
· 10 years ago
1c1eb86
DO NOT MERGE. Allow untrusted_app access to temporary apk files.
by dcashman
· 10 years ago
feedd3c
Make system use patchoat to relocate during runtime.
by Alex Light
· 10 years ago
58112b4
am fbc8ec2e: Make system use patchoat to relocate during runtime.
by Alex Light
· 10 years ago
fbc8ec2
Make system use patchoat to relocate during runtime.
by Alex Light
· 10 years ago
5a6ac67
am 3fe1bcbb: Merge "Generate selinux_policy.xml as part of CTS build."
by dcashman
· 10 years ago
77a236c
Allow dumpstate to dump backtraces of certain native processes.
by Stephen Smalley
· 10 years ago
3fe1bcb
Merge "Generate selinux_policy.xml as part of CTS build."
by dcashman
· 10 years ago
5cf581c
am d990a78f: Fix neverallow rules to eliminate CTS SELinuxTest warnings.
by Stephen Smalley
· 10 years ago
1d64e08
am 770910bb: Implement broker pattern for imms (3/3)
by Ye Wen
· 10 years ago
d990a78
Fix neverallow rules to eliminate CTS SELinuxTest warnings.
by Stephen Smalley
· 10 years ago
770910b
Implement broker pattern for imms (3/3)
by Ye Wen
· 11 years ago
3d86033
am 21ada26d: Fix neverallow rules to eliminate CTS SELinuxTest warnings.
by Stephen Smalley
· 10 years ago
21ada26
Fix neverallow rules to eliminate CTS SELinuxTest warnings.
by Stephen Smalley
· 10 years ago
704741a
Generate selinux_policy.xml as part of CTS build.
by dcashman
· 10 years ago
4a518b8
am 997461bd: Allow system_server to talk to netlink directly.
by Sreeram Ramachandran
· 10 years ago
997461b
Allow system_server to talk to netlink directly.
by Sreeram Ramachandran
· 10 years ago
ac37061
am fab00f74: Add rttmanager in sepolicy\'s whitelist
by Vinit Deshpande
· 10 years ago
fa617d4
am 840e522e: Remove dumpstate from servicemanager list auditallow.
by Riley Spahn
· 10 years ago
fab00f7
Add rttmanager in sepolicy's whitelist
by Vinit Deshpande
· 10 years ago
840e522
Remove dumpstate from servicemanager list auditallow.
by Riley Spahn
· 10 years ago
d84d9f8
resync with AOSP master
by Nick Kralevich
· 11 years ago
d065f04
Resync lmp-dev-plus-aosp with master
by Nick Kralevich
· 11 years ago
11a29f2
resolved conflicts for merge of 92b9360c to lmp-dev-plus-aosp
by Nick Kralevich
· 11 years ago
f2b7c3b
am 1a61fb3b: Allow sdcardd to read /data/.layout_version
by Nick Kralevich
· 11 years ago
1a61fb3
Allow sdcardd to read /data/.layout_version
by Nick Kralevich
· 11 years ago
7d62ace
am aa8e657e: Revert "fix system_server dex2oat exec"
by Narayan Kamath
· 11 years ago
aa8e657
Revert "fix system_server dex2oat exec"
by Narayan Kamath
· 11 years ago
8a17c00
am 792d8650: Allow sdcardd to read /data/.layout_version
by Nick Kralevich
· 11 years ago
792d865
Allow sdcardd to read /data/.layout_version
by Nick Kralevich
· 11 years ago
9d24d52
am ba992496: Define debuggerd class, permissions, and rules.
by Stephen Smalley
· 11 years ago
f0c4cdf
am 12b8f79d: Allow dumpstate to read /data/tombstones.
by Christopher Ferris
· 11 years ago
ba99249
Define debuggerd class, permissions, and rules.
by Stephen Smalley
· 11 years ago
12b8f79
Allow dumpstate to read /data/tombstones.
by Christopher Ferris
· 11 years ago
665bc08
resolved conflicts for merge of b2eaa28d to lmp-dev-plus-aosp
by Christopher Ferris
· 11 years ago
92b9360
Merge "Add fine grained access control to DrmManagerService."
by Nick Kralevich
· 11 years ago
70f75ce
Add fine grained access control to DrmManagerService.
by Riley Spahn
· 11 years ago
b2eaa28
Allow dumpstate to read /data/tombstones.
by Christopher Ferris
· 11 years ago
6a6f67d
am af4a3db0: Merge "DO NOT MERGE. Update readme to reflect addition of SEPOLICY_IGNORE." into lmp-dev
by dcashman
· 11 years ago
24def63
am 5a45ed4a: Merge "Update readme to reflect addition of SEPOLICY_IGNORE."
by dcashman
· 11 years ago
af4a3db
Merge "DO NOT MERGE. Update readme to reflect addition of SEPOLICY_IGNORE." into lmp-dev
by dcashman
· 11 years ago
ea44c79
DO NOT MERGE. Update readme to reflect addition of SEPOLICY_IGNORE.
by dcashman
· 11 years ago
5a45ed4
Merge "Update readme to reflect addition of SEPOLICY_IGNORE."
by dcashman
· 11 years ago
a8e4ecd
Update readme to reflect addition of SEPOLICY_IGNORE.
by dcashman
· 11 years ago
6152ee4
am 9f49e9f9: Merge "Move MmsService into phone process (2/2)" into lmp-dev
by Ye Wen
· 11 years ago
68417e6
am 9d2703a5: Prohibit execute to fs_type other than rootfs for most domains.
by Stephen Smalley
· 11 years ago
9d2703a
Prohibit execute to fs_type other than rootfs for most domains.
by Stephen Smalley
· 11 years ago
1688fb0
am 3cfc7ea8: sepolicy: allow charger to read /sys/fs/pstore/console-ramoops
by Colin Cross
· 11 years ago
3cfc7ea
sepolicy: allow charger to read /sys/fs/pstore/console-ramoops
by Colin Cross
· 11 years ago
070180d
am bb96bffc: sepolicy: allow charger to read /sys/fs/pstore/console-ramoops
by Colin Cross
· 11 years ago
bb96bff
sepolicy: allow charger to read /sys/fs/pstore/console-ramoops
by Colin Cross
· 11 years ago
f6f6fc5
am 4644ac48: Prohibit execute to fs_type other than rootfs for most domains.
by Stephen Smalley
· 11 years ago
4644ac4
Prohibit execute to fs_type other than rootfs for most domains.
by Stephen Smalley
· 11 years ago
9f49e9f
Merge "Move MmsService into phone process (2/2)" into lmp-dev
by Ye Wen
· 11 years ago
eb8d86c
Move MmsService into phone process (2/2)
by Ye Wen
· 11 years ago
54e0d85
am bf696327: DO NOT MERGE: Remove service_manager audit_allows.
by Riley Spahn
· 11 years ago
bf69632
DO NOT MERGE: Remove service_manager audit_allows.
by Riley Spahn
· 11 years ago
8750fa6
am 4a24475b: Further refined service_manager auditallow statements.
by Riley Spahn
· 11 years ago
4a24475
Further refined service_manager auditallow statements.
by Riley Spahn
· 11 years ago
0d6d86b
am 958ef563: Merge "Further refined service_manager auditallow statements."
by Nick Kralevich
· 11 years ago
Next »