Gitiles
Code Review
Sign In
gerrit.omnirom.org
/
android_system_sepolicy
/
1b3cf9171a549200154dae5a6e5b3998efbcfa9d
/
private
1b3cf91
Revert "runas/shell.te: remove {kernel} to perf_event_open"
by Priyanka Advani (xWF)
· 7 months ago
6c9a13f
runas/shell.te: remove {kernel} to perf_event_open
by Primiano Tucci
· 8 months ago
6723891
Enforce unconstrained_vsock_violators
by Steven Moreland
· 8 months ago
81a860e
Don't audit access to proc_net by network_stack - try 2
by Maciej Żenczykowski
· 8 months ago
e3cfc9d
Don't audit access to proc_net by network_stack.
by Maciej Żenczykowski
· 8 months ago
a9b5154
Merge "Revoke the setuid capability from mainline supplicant." into main
by Treehugger Robot
· 8 months ago
586ce31
Revoke the setuid capability from mainline supplicant.
by Gabriel Biren
· 8 months ago
e3723f8
Merge "LE-Audio Software Offload: Add interface between audio and hci HAL's" into main
by Antoine Soulier
· 8 months ago
5d3f5fd
Revert^2 "Fix treble tests to use public cil only"
by Inseob Kim
· 8 months ago
6fe9069
Fix otapreopt_chroot compat build error
by Inseob Kim
· 8 months ago
9a89e43
Merge "Revert "Fix treble tests to use public cil only"" into main
by Inseob Kim
· 8 months ago
5815772
Revert "Fix treble tests to use public cil only"
by Naresh Kumar Podishetty (xWF)
· 8 months ago
8d336e2
Merge "Fix treble tests to use public cil only" into main
by Treehugger Robot
· 8 months ago
eb6b30f
Fix treble tests to use public cil only
by Inseob Kim
· 8 months ago
2874c40
Allow changing persit.wm.debug from system services
by Pierre Barbier de Reuille
· 8 months ago
74a5b12
LE-Audio Software Offload: Add interface between audio and hci HAL's
by Antoine SOULIER
· 9 months ago
2c13d8e
Allow virtual_camera to access ION and DMABUF devices
by Vadim Caen
· 9 months ago
fd4ae7c
Merge "Allow access to /metadata/libprocessgroup for 25Q2 Beta experiment" into main
by Treehugger Robot
· 8 months ago
3aa5ef4
Merge "Add a new tradeinmode property for testing." into main
by Treehugger Robot
· 8 months ago
3cf9a7b
Allow access to /metadata/libprocessgroup for 25Q2 Beta experiment
by T.J. Mercier
· 8 months ago
b8791a5
Merge "Remove ro. from prefetch_boot.record_stop" into main
by Akilesh Kailash
· 8 months ago
9506eb4
Merge "netd.te: allow netd to bind to ports <1024 (including dns: 53 & 853)" into main
by Treehugger Robot
· 8 months ago
86643e5
Merge "introducing unconstrained_vsock_violators" into main
by Treehugger Robot
· 8 months ago
f842499
Expose virtual_camera types to vendor
by Vadim Caen
· 9 months ago
ceebde6
introducing unconstrained_vsock_violators
by Steven Moreland
· 8 months ago
4fa09af
Add a new tradeinmode property for testing.
by David Anderson
· 10 months ago
53cba3e
Allow traced_probes to talk to suspend control service.
by Simon MacMullen
· 8 months ago
2dac36f
Merge "Allow dexopt_chroot_setup to mount on vendor_configs_file." into main
by Jiakai Zhang
· 8 months ago
f337118
Merge "Add navigation_gesture sysprop for fingerprint VHAL" into main
by Jeff Pu
· 8 months ago
57ab576
Merge "Allow system_server access to CMA sysfs nodes" into main
by Isaac Manjarres
· 8 months ago
b017b3f
Merge "Fix: do not guard advanced_protection behind starting_at_board_api" into main
by Hani Kazmi
· 8 months ago
79d603a
Add navigation_gesture sysprop for fingerprint VHAL
by Jeff Pu
· 8 months ago
f435141
Merge "Add basic sepolicy for the IVmCapabilities HAL" into main
by Nikita Ioffe
· 8 months ago
151716f
Fix: do not guard advanced_protection behind starting_at_board_api
by Hani Kazmi
· 8 months ago
439563f
Add basic sepolicy for the IVmCapabilities HAL
by Nikita Ioffe
· 9 months ago
0fdaa84
Merge "Add property context for persist.bluetooth.sniff_offload" into main
by Suneesh Sasikumar
· 8 months ago
5b28157
Merge "Remove sepolicy for forensic service" into main
by Wenhao Wang
· 8 months ago
df505fe
Allow system_server access to CMA sysfs nodes
by Isaac J. Manjarres
· 8 months ago
e743226
Add property context for persist.bluetooth.sniff_offload
by Suneesh Sasikumar
· 8 months ago
9162875
Merge "Remove `fwk_vold_service`'s `dumpstate` permission" into main
by Weston Carvalho
· 8 months ago
550b51c
Allow dexopt_chroot_setup to mount on vendor_configs_file.
by Jiakai Zhang
· 8 months ago
58d80b4
Remove sepolicy for forensic service
by Wenhao Wang
· 8 months ago
15a8dbb
Merge "Allow shell read access to suspend mechanism" into main
by Treehugger Robot
· 8 months ago
f0d74d6
Allow shell read access to suspend mechanism
by Vilas Bhat
· 9 months ago
75c1d8b
Remove `fwk_vold_service`'s `dumpstate` permission
by Weston Carvalho
· 8 months ago
5e10dd9
Merge "Restrict HMS props write access to system server only" into main
by Treehugger Robot
· 8 months ago
dfb01e6
Merge "Add `keystore.module_hash.sent` system prop" into main
by Karuna Wadhera
· 8 months ago
49cdaca
Merge "Add sepolicy for microdroid_mgr to read sysprop servicemanager.installed" into main
by Devin Moore
· 8 months ago
321db8b
Merge "Remove all SELinux policy related to fsverity_init" into main
by Treehugger Robot
· 8 months ago
ad0b4ba
Add `keystore.module_hash.sent` system prop
by Karuna Wadhera
· 8 months ago
c73a0a8
Merge "Run freeze test on trunk* builds" into main
by Treehugger Robot
· 8 months ago
b19ca8d
Run freeze test on trunk* builds
by Inseob Kim
· 8 months ago
274a42f
Merge "Define selinux context" into main
by Eric Biggers
· 8 months ago
c6a45d8
Allow system_app to read hypervisor properties
by Jaewan Kim
· 8 months ago
565a1ee
Merge "Give init and dumpstate access to /proc/allocinfo" into main
by Treehugger Robot
· 8 months ago
36acb81
Merge "sepolicy: dontaudit dumpstate to talk with virtualizationservice" into main
by Treehugger Robot
· 8 months ago
419f7a7
Give init and dumpstate access to /proc/allocinfo
by Alessio Balsini
· 9 months ago
0d8a410
Fix treble_sepolicy_tests and compat files
by Inseob Kim
· 8 months ago
ce679c9
Merge "Add `android.system.vold` to sepolicy" into main
by Weston Carvalho
· 9 months ago
5fadae6
Merge "sepolicy: allow init to share a kallsyms fd with tracing daemons" into main
by Ryan Savitski
· 9 months ago
d4f6b5c
Remove ro. from prefetch_boot.record_stop
by Takaya Saeki
· 9 months ago
22275c1
Declare ro.bluetooth.leaudio_offload.supported
by Mikhail Naganov
· 9 months ago
5135ac0
Add `android.system.vold` to sepolicy
by Weston Carvalho
· 9 months ago
26a6e88
Define selinux context
by Santosh Dronamraju
· 1 year ago
a782c1b
Restrict HMS props write access to system server only
by Xiang Wang
· 9 months ago
0a905ff
Remove all SELinux policy related to fsverity_init
by Victor Hsieh
· 9 months ago
bf4e374
Merge changes from topic "avf_vendor_clients" into main
by Inseob Kim
· 9 months ago
e4e51b4
Merge "Move ranging_service se policy from public to private" into main
by Shreshta Manu
· 9 months ago
a5d57b2
Move ranging_service se policy from public to private
by Shreshta Manu
· 9 months ago
211ab03
Merge "Add BLE sysprop "aggressive_connection_threshold"" into main
by Treehugger Robot
· 9 months ago
9e687fa
Merge "Allow virtual_camera to read and open dmabuf_system_heap_device" into main
by Treehugger Robot
· 9 months ago
47df6a4
Add BLE sysprop "aggressive_connection_threshold"
by Hyundo Moon
· 9 months ago
b1d9ffd
Merge "Revert "Revert "Label audio system properties to load IhalAdapte..."" into main
by Treehugger Robot
· 9 months ago
077cc35
Merge "Allow keystore to monitor and read APEX info" into main
by David Drysdale
· 9 months ago
f476970
Open virtmgr / crosvm / libavf for vendor clients
by Inseob Kim
· 9 months ago
31ef9b8
Merge "Terminal app's package name is com.android.virtualization.terminal" into main
by Jiyong Park
· 9 months ago
24addd3
Fix: do not guard dynamic_instrumentation_service behind starting_at_board_api
by Matt Gilbride
· 9 months ago
17dc3a1
netd.te: allow netd to bind to ports <1024 (including dns: 53 & 853)
by Maciej Żenczykowski
· 9 months ago
335e354
Terminal app's package name is com.android.virtualization.terminal
by Jiyong Park
· 9 months ago
f9cba80
Allow virtual_camera to read and open dmabuf_system_heap_device
by Sachin Kumar Tiwari
· 9 months ago
77c319c
Merge "Merge 24Q4 into AOSP main" into main
by Xin Li
· 9 months ago
4cd0994
sepolicy: allow init to share a kallsyms fd with tracing daemons
by Ryan Savitski
· 9 months ago
556dddf
Add shutdown to tradeinmode
by Paul Lawrence
· 9 months ago
039e167
Revert "Revert "Label audio system properties to load IhalAdapte..."
by Mikhail Naganov
· 9 months ago
fd8fd19
Merge "Add permission to installd to delete `virtualizationservice_data_file`" into main am: 1ce20155b8
by Jeongik Cha
· 9 months ago
1ce2015
Merge "Add permission to installd to delete `virtualizationservice_data_file`" into main
by Jeongik Cha
· 9 months ago
8b941e5
Allow keystore to monitor and read APEX info
by David Drysdale
· 9 months ago
0aacb11
Merge "sepolicy property definitions for WV Trusty VM" into main am: 531d881504
by Orlando Arbildo
· 9 months ago
531d881
Merge "sepolicy property definitions for WV Trusty VM" into main
by Orlando Arbildo
· 9 months ago
b121920
Merge "Add LE connection interval sysprops" into main am: 702663bd33
by Hyundo Moon
· 9 months ago
702663b
Merge "Add LE connection interval sysprops" into main
by Hyundo Moon
· 9 months ago
8ca831b
Add permission to installd to delete `virtualizationservice_data_file`
by Jeongik Cha
· 9 months ago
edd9765
Merge "Revert "Label audio system properties to load IhalAdapterVendorE..."" into main am: 41c4afef51
by Sebastian Pickl
· 9 months ago
41c4afe
Merge "Revert "Label audio system properties to load IhalAdapterVendorE..."" into main
by Sebastian Pickl
· 9 months ago
581aa33
Revert "Label audio system properties to load IhalAdapterVendorE..."
by Sebastian Pickl
· 9 months ago
91653c0
sepolicy: dontaudit dumpstate to talk with virtualizationservice
by Karthik Rathlavath
· 9 months ago
c64d735
sepolicy property definitions for WV Trusty VM
by Orlando Arbildo
· 9 months ago
e81a68c
Merge "Label audio system properties to load IhalAdapterVendorExtension" into main am: 351bcf96a6
by Mikhail Naganov
· 9 months ago
351bcf9
Merge "Label audio system properties to load IhalAdapterVendorExtension" into main
by Mikhail Naganov
· 9 months ago
1b0decb
Merge "Allow system_server access to aconfigd_mainline socket as well" into main am: 79009bc283
by Thomas Girardier
· 9 months ago
Next »