Gitiles
Code Review
Sign In
review.evervolv.com
/
android_external_sepolicy
/
HEAD
5df9a87
system: Allow access from system services to the adbd socket
by Ricardo Cerqueira
· 13 years ago
jellybean-4.3
a06295a
system: Explicitly allow access to sysfs_writable
by Ricardo Cerqueira
· 13 years ago
cf2cd83
sdcard: Add missing capability
by Ricardo Cerqueira
· 13 years ago
b1bfd12
zygote: Allow bind filesystem remount
by Ricardo Cerqueira
· 13 years ago
4e98c74
Fix adb access to its own keys directory
by Ricardo Cerqueira
· 13 years ago
499e0b2
Allow binder access from surfaceflinger to apps
by Ricardo Cerqueira
· 13 years ago
e72c64e
Add a key directory argument to insertkeys.py
by Geremy Condra
· 13 years ago
92379b9
Add policy for __properties__ device.
by Geremy Condra
· 13 years ago
ceb8caf
Disable mmac for now
by Ricardo Cerqueira
· 13 years ago
b2bb726
ping: add exec_type
by Chirayu Desai
· 13 years ago
beed852
Allow drmserver to read the wv keys.
by Geremy Condra
· 13 years ago
f4647bd
Add policy for ping.
by repo sync
· 13 years ago
e74ed5e
Allow Performance Settings to set sys.cpufreq.restored
by dhacker29
· 13 years ago
b5c32a3
Let system components and apps set the enforce state
by Ricardo Cerqueira
· 13 years ago
96cea0c
Fix MMAC permissions
by Ricardo Cerqueira
· 13 years ago
2666f2d
Merge branch 'selinux' into cm-10.1
by Ricardo Cerqueira
· 13 years ago
4ba45a3
Fix priority in /cache/dalvik-cache labelling
by Ricardo Cerqueira
· 13 years ago
e83c5a9
Fix some failures in the Settings app
by Ricardo Cerqueira
· 13 years ago
ccd2d60
Fix rild's usage of its netlink socket
by Ricardo Cerqueira
· 13 years ago
188a3a5
Fix adbd's access to its own authorized keys file
by Ricardo Cerqueira
· 13 years ago
47ad856
Add a new context for Google-authored apps
by Ricardo Cerqueira
· 13 years ago
0f49406
Add context for CM's alternate dalvik-cache path
by Ricardo Cerqueira
· 13 years ago
18c1cbc
Revert "ISSUE 6849488 Bluedroid stack, remove system/bluetooth."
by Kenny Root
· 14 years ago
d7cc9ae
keystore daemon can be used by third party apps running in any level.
by Stephen Smalley
· 13 years ago
f59b9d7
Exempt bluetooth domain from property_service set.
by Robert Craig
· 13 years ago
043c7c0
Label another node with uinput_device.
by Robert Craig
· 13 years ago
aecb16a
Label /dev/video4[0-9] nodes as camera_device.
by Stephen Smalley
· 13 years ago
ab6357d
Add a disableAudioCapture boolean to disable audio capture.
by Stephen Smalley
· 13 years ago
7b00c5e
Introduce new uinput_device domain.
by Robert Craig
· 13 years ago
b0fcb3a
Add disableAudio boolean to disable audio access.
by Stephen Smalley
· 13 years ago
9bb18c1
Wrap more rules under the disableBluetooth boolean.
by Stephen Smalley
· 13 years ago
352f58f
Invert camera and bluetooth booleans.
by Stephen Smalley
· 13 years ago
e0cd769
Introduce booleans for disabling camera and bluetooth.
by Stephen Smalley
· 13 years ago
b3d4a48
Split shell domain into separate domains for adb shell vs init-spawned shell.
by Stephen Smalley
· 13 years ago
cf2af8c
Introduce untrustedappdomain attribute
by William Roberts
· 13 years ago
e345ef4
Remove another device-specific device node and type.
by Stephen Smalley
· 13 years ago
faee59a
Delete legacy devices and label mdns and gps sockets.
by Stephen Smalley
· 13 years ago
395d756
Revert "Allow logwrapper to be used by all daemons spawned by init"
by Stephen Smalley
· 13 years ago
29bee59
Allow logwrapper to be used by all daemons spawned by init
by William Roberts
· 13 years ago
f97b834
Allow file types to be associated with the rootfs.
by Stephen Smalley
· 13 years ago
51973a9
Various updates to policy.
by Robert Craig
· 13 years ago
3717458
Merge branch 'master' into seandroid
by Stephen Smalley
· 13 years ago
df05a11
Label all files under /sys/qemu_trace with sysfs_writable.
by Stephen Smalley
· 13 years ago
97ff811
Merge "Add non_system_app_set"
by Geremy Condra
· 13 years ago
03fe014
Add further assertions.
by Stephen Smalley
· 13 years ago
09258ad
Drop domain write access to sysfs for the emulator.
by Stephen Smalley
· 13 years ago
2524fc8
Remove sys_nice capability from domains.
by Stephen Smalley
· 13 years ago
82ec720
Add further neverallow assertions.
by Stephen Smalley
· 13 years ago
8cd20ef
Add non_system_app_set
by William Roberts
· 13 years ago
8ad9d7a
Merged in billcroberts/external-sepolicy/nsa-seandroid-runas (pull request #15)
by seandroid
· 13 years ago
6329721
Support strict duplicate checking
by William Roberts
· 13 years ago
de1020a
run-as support for all non system apps
by William Roberts
· 13 years ago
fb3bc20
Add non_system_app_set
by William Roberts
· 13 years ago
bc38824
Drop sys_module from system_server.
by Stephen Smalley
· 13 years ago
3f58b30
Merged in billcroberts/external-sepolicy/nsa-seandroid-checkseapp (pull request #13)
by seandroid
· 13 years ago
9dbb7de
Support strict duplicate checking
by William Roberts
· 13 years ago
d334b17
Fix segfault on -v with duplicates
by William Roberts
· 13 years ago
1e8c061
Fix segfault on -v with duplicates
by William Roberts
· 13 years ago
82fdb48
Introduce new hostapd domain.
by Robert Craig
· 13 years ago
9a67168
Sundry policy updates.
by Robert Craig
· 13 years ago
22da626
Merge branch 'master' into seandroid
by Stephen Smalley
· 13 years ago
6c4c27e
Give domains read access to security_file domain.
by William Roberts
· 13 years ago
fc18c7a
run-as policy fixes.
by Stephen Smalley
· 13 years ago
cd516a3
run-as policy fixes.
by Stephen Smalley
· 13 years ago
47756b7
Merge branch 'master' into seandroid
by Stephen Smalley
· 13 years ago
c80389e
Give domains read access to security_file domain.
by William Roberts
· 13 years ago
8bb3080
Add new domains for private apps.
by Robert Craig
· 13 years ago
0bca157
Merge "Drop SELinux management rules from AOSP."
by Geremy Condra
· 13 years ago
4ac4bc0
Document the relevant tests associated with specific rules.
by Stephen Smalley
· 13 years ago
4b60cc3
Do not allow reading all directories for the CTS.
by Stephen Smalley
· 13 years ago
33da609
Allow all domains to read /dev symlinks.
by Stephen Smalley
· 13 years ago
c37856c
Remove unnecessary rules.
by Stephen Smalley
· 13 years ago
cfd9b6b
Allow apps to execute the shell or system commands unconditionally.
by Stephen Smalley
· 13 years ago
ab0cd21
Allow fstat of platform app /data/data files.
by Stephen Smalley
· 13 years ago
b0957fa
Coalesce rules for allowing execution of shared objects by app domains.
by Stephen Smalley
· 13 years ago
80c9ba5
Strip unnecessary trailing semicolon on macro calls.
by Stephen Smalley
· 13 years ago
2b73223
Allow all domains to read the log devices.
by Stephen Smalley
· 13 years ago
88ae559
Drop SELinux management rules from AOSP.
by Stephen Smalley
· 13 years ago
434b4df
Document the relevant tests.
by Stephen Smalley
· 13 years ago
3bedf8d
Do not allow reading all directories.
by Stephen Smalley
· 13 years ago
561818d
Allow all domains to read /dev symlinks.
by Stephen Smalley
· 13 years ago
24b2bbf
Remove unnecessary rules.
by Stephen Smalley
· 13 years ago
a99320b
Allow apps to execute the shell or system commands unconditionally.
by Stephen Smalley
· 13 years ago
c0af807
Allow fstat of platform app /data/data files.
by Stephen Smalley
· 13 years ago
4cd71f2
Allow all appdomains to execute system_data_file.
by Stephen Smalley
· 13 years ago
34403c1
Strip unnecessary trailing semicolon on macro calls.
by Stephen Smalley
· 13 years ago
d0517a8
Allow all domains to read the log devices.
by Stephen Smalley
· 13 years ago
45d74e8
Move admin-related policy to seadmin.te.
by Stephen Smalley
· 13 years ago
9e11559
Merge branch 'master' into seandroid
by Stephen Smalley
· 13 years ago
cebe6a6
Allow ueventd to relabel sysfs nodes.
by Stephen Smalley
· 13 years ago
5b6a13f
Give domains read access to security_file domain.
by Robert Craig
· 13 years ago
e6e4630
Add new domains for paid apps.
by Robert Craig
· 13 years ago
84c46de
Remove unneeded device type.
by Robert Craig
· 13 years ago
e543a8b
Increase policy version to 26.
by Stephen Smalley
· 13 years ago
98d16f6
Increase policy version to 26.
by Stephen Smalley
· 13 years ago
866e290
Merge branch 'master' into seandroid
by Stephen Smalley
· 13 years ago
f4d5f3e
Merge "Add missing seinfo tag from mac_permissions.xml policy."
by Geremy Condra
· 13 years ago
2ae799e
Drop separate domain for browser.
by Stephen Smalley
· 13 years ago
0ecb0f8
Eliminate most of the app policy booleans.
by Stephen Smalley
· 13 years ago
b0b772c
Drop sample vpn entry.
by Stephen Smalley
· 13 years ago
Next »