Gitiles
Code Review
Sign In
gerrit.omnirom.org
/
android_system_sepolicy
/
a5121f64a6f4af9dd6394a64aa9c386fe2167006
a5121f6
Add com.android.resolv-file_contexts to /system/sepolicy/apex
by chenbruce
· 7 years ago
7ef01c3
Merge "Allow iw to be run at init phase."
by Treehugger Robot
· 7 years ago
920232b
Merge "vold: allow ioctls BLKDISCARD and BLKGETSIZE"
by Treehugger Robot
· 7 years ago
5791e6e
Merge "Fix the bound size and the variable name"
by Treehugger Robot
· 7 years ago
fefc887
vold: allow ioctls BLKDISCARD and BLKGETSIZE
by Nick Kralevich
· 7 years ago
2e23af5
Allow iw to be run at init phase.
by Tomasz Wasilczyk
· 7 years ago
a8dd89f
Merge "Add userdebug selinux config for heapprofd."
by Florian Mayer
· 7 years ago
b32113e
Merge "Added system property (dumpstate.unroot) to run dumpstate as shell."
by Treehugger Robot
· 7 years ago
45f4847
Add userdebug selinux config for heapprofd.
by Florian Mayer
· 7 years ago
57d66ef
Fix the bound size and the variable name
by liwugang
· 7 years ago
f0dc093
Merge "SELinux changes for AppFuse"
by Treehugger Robot
· 7 years ago
6a9a852
Merge "Move file_contexts for APEXes to under /system/sepolicy"
by Jiyong Park
· 7 years ago
0c1848b
SELinux changes for AppFuse
by Risan
· 7 years ago
03ccac0
Move file_contexts for APEXes to under /system/sepolicy
by Jiyong Park
· 7 years ago
a106218
OWNERS: add cbrubaker
by Nick Kralevich
· 7 years ago
ced1751
Remove mtd_device type.
by Tri Vo
· 7 years ago
ca5b01b
Merge "Remove dead *_device types from system sepolicy."
by Treehugger Robot
· 7 years ago
c496db3
Add SELinux service for RoleManagerService
by Eugene Susla
· 7 years ago
049c03d
bluetooth: allow TUNGETIFF TUNSETIFF
by Nick Kralevich
· 7 years ago
b805ada
Remove dead *_device types from system sepolicy.
by Tri Vo
· 7 years ago
3e8f7bc
Merge "Use LOCAL_ADDITIONAL_M4DEFS for file_contexts"
by Tri Vo
· 7 years ago
b965e3c
Sepolicies for server configural flags reset
by Hongyi Zhang
· 7 years ago
f40942f
Add rules for /product{,_services}/overlay
by Mårten Kongstad
· 7 years ago
7924dc6
[SEPolicy] Configure policy for gpu service.
by Peiyong Lin
· 7 years ago
ac6352d
Merge "Allow bufferhub service to allocate buffer"
by Treehugger Robot
· 7 years ago
e3c52b6
Merge "Allow adbd to read perfetto_traces_data_file."
by Treehugger Robot
· 7 years ago
e7f1354
Merge changes from topic "runas_exec"
by Yabin Cui
· 7 years ago
da54e5f
Added system property (dumpstate.unroot) to run dumpstate as shell.
by Felipe Leme
· 7 years ago
5faae3a
Merge "apexd_prop is defined for PRODUCT_COMPATIBLE_PROPERTY = false case"
by Treehugger Robot
· 7 years ago
f270aea
Allow adbd to read perfetto_traces_data_file.
by Florian Mayer
· 7 years ago
6a62606
Merge changes Ie0396d59,I75b2bade
by Martijn Coenen
· 7 years ago
341476d
Allow apexd to configure /sys/block/dm-
by Martijn Coenen
· 7 years ago
ac2b2d4
Allow the kernel to access apexd file descriptors.
by Martijn Coenen
· 7 years ago
b14c1a9
apexd_prop is defined for PRODUCT_COMPATIBLE_PROPERTY = false case
by Jiyong Park
· 7 years ago
1cffee6
Use LOCAL_ADDITIONAL_M4DEFS for file_contexts
by Mustafa Yigit Bilgen
· 7 years ago
52261e7
Add placeholder sepolicy for iris and face
by Kevin Chyn
· 7 years ago
1e58323
Allow bufferhub service to allocate buffer
by Fan Xu
· 7 years ago
05668e4
Merge "Remove buffer_hub_service compat mapping"
by Fan Xu
· 7 years ago
ffa2b61
Add runas_app domain to allow running app data file via run-as.
by Yabin Cui
· 7 years ago
5dc2c8c
Revert "Revert "Enforce execve() restrictions for API > 28""
by Yabin Cui
· 7 years ago
2bb0085
Merge "Don't label /dev/{ akm8973.* accelerometer } from system sepolicy"
by Tri Vo
· 7 years ago
fe39ed3
Don't label /dev/{ akm8973.* accelerometer } from system sepolicy
by Tri Vo
· 7 years ago
2d74a45
Remove buffer_hub_service compat mapping
by Fan Xu
· 7 years ago
2b76694
Merge "New service: intelligence_service"
by Felipe Leme
· 7 years ago
2da651b
Merge "Neverallow vendor access to system_file."
by Tri Vo
· 7 years ago
c7eb1cd
Clatd: allow clatd use ioctl
by Luke Huang
· 7 years ago
9410105
Neverallow vendor access to system_file.
by Tri Vo
· 7 years ago
5bf0c63
New service: intelligence_service
by Felipe Leme
· 7 years ago
41ab29e
Allow SystemUI to talk to ADB service
by Kenny Root
· 7 years ago
9d8f7ea
sgdisk: allow BLKRRPART
by Nick Kralevich
· 7 years ago
5c48444
Merge "Update access_vectors"
by Treehugger Robot
· 7 years ago
ced51dd
Merge "tun_device: enforce ioctl restrictions"
by Nick Kralevich
· 7 years ago
b3b9461
apexd exports its status via sysprop
by Jiyong Park
· 7 years ago
ea1775d
Update access_vectors
by Nick Kralevich
· 7 years ago
5152fc8
Merge "Don't check PRODUCT_SHIPPING_API_LEVEL to determine fake treble."
by Treehugger Robot
· 7 years ago
f0dc5ea
Merge "sgdisk: add blk_file ioctls"
by Treehugger Robot
· 7 years ago
619c1ef
tun_device: enforce ioctl restrictions
by Nick Kralevich
· 7 years ago
691ee93
Merge "sepolicy for server configurable flags"
by Treehugger Robot
· 7 years ago
0d23383
Don't check PRODUCT_SHIPPING_API_LEVEL to determine fake treble.
by Tri Vo
· 7 years ago
79d3651
sgdisk: add blk_file ioctls
by Nick Kralevich
· 7 years ago
33442f5
fastboot: /mnt/scratch refined access on userdebug
by Mark Salyzyn
· 7 years ago
96c6d14
Merge "export init.svc.bugreport"
by Minchan Kim
· 7 years ago
a6f9892
sepolicy for server configurable flags
by Hongyi Zhang
· 7 years ago
f1a856e
Merge "Reland "Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble""
by Treehugger Robot
· 7 years ago
fac9bc0
export init.svc.bugreport
by Minchan Kim
· 7 years ago
b4afdea
Merge "isolated_app: add mmaps"
by Treehugger Robot
· 7 years ago
16572cc
Merge "Allow BLKIOMIN and BLKALIGNOFF ioctls to the super device in fastbootd."
by David Anderson
· 7 years ago
0025220
isolated_app: add mmaps
by Nick Kralevich
· 7 years ago
caf42d6
Transient SELinux domain for system_server JIT
by Nick Kralevich
· 7 years ago
29db0eb
Merge "Revert "Enforce execve() restrictions for API > 28""
by Treehugger Robot
· 7 years ago
15d1a12
Revert "Enforce execve() restrictions for API > 28"
by Nick Kralevich
· 7 years ago
bf0bf05
Allow BLKIOMIN and BLKALIGNOFF ioctls to the super device in fastbootd.
by David Anderson
· 7 years ago
9087b77
Reland "Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble"
by Tri Vo
· 7 years ago
18f5431
Merge "Revert "Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble""
by Wei Wang
· 7 years ago
9c91bba
Revert "Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble"
by Wei Wang
· 7 years ago
3ce25d1
Merge "Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble"
by Tri Vo
· 7 years ago
c4cf986
Revert "SELinux changes for AppFuse"
by Nick Kralevich
· 7 years ago
581e6c4
Merge "Enforce execve() restrictions for API > 28"
by Treehugger Robot
· 7 years ago
a94e6e5
Merge "drop priv_app app_data_file:file execute;"
by Treehugger Robot
· 7 years ago
0dd738d
Enforce execve() restrictions for API > 28
by Nick Kralevich
· 7 years ago
f2cad2d
vold does more than LOOP_GET_STATUS64.
by Jeff Sharkey
· 7 years ago
e1ddd74
drop priv_app app_data_file:file execute;
by Nick Kralevich
· 7 years ago
de8dfc7
Merge "Switch to r_file_perms"
by Treehugger Robot
· 7 years ago
0bfa7b5
Switch to r_file_perms
by Nick Kralevich
· 7 years ago
67ed432
SELinux changes for AppFuse
by Risan
· 7 years ago
3eae9de
Merge "same_process_hal_file: access to individual coredomains"
by Tri Vo
· 7 years ago
90cf5a7
same_process_hal_file: access to individual coredomains
by Tri Vo
· 7 years ago
5292449
Merge "Don't label /dev/tegra.* from core policy"
by Tri Vo
· 7 years ago
173a1d9
Allow apexd more ioctl cmds for loop devices
by Jiyong Park
· 7 years ago
2ea956c
Don't label /dev/tegra.* from core policy
by Tri Vo
· 7 years ago
8844f28
Default undefined PRODUCT_SHIPPING_API_LEVEL to fake treble
by Tri Vo
· 7 years ago
d5c5ef9
Sepolicy for bufferhub hwservice
by Jiwen 'Steve' Cai
· 7 years ago
564eb9d
Merge "Properly escape dots in file_contexts filenames"
by Anton Hansson
· 7 years ago
77e0611
Merge pie-platform-release to aosp-master - DO NOT MERGE
by Bill Yi
· 7 years ago
554f181
Merge "sepolicy: Allow apps to get info from priv_app by ashmem"
by Treehugger Robot
· 7 years ago
b10f4eb
Added a new system properties for IWLAN operation mode
by Jack Yu
· 7 years ago
854adfd
Merge "Add sepolicy for preloads_copy script"
by Anton Hansson
· 7 years ago
fc1980e
Merge "Combine vendor-init-actionable with vendor-init-readable"
by Tom Cherry
· 7 years ago
c6742db
Properly escape dots in file_contexts filenames
by Anton Hansson
· 7 years ago
30dd711
Combine vendor-init-actionable with vendor-init-readable
by Tom Cherry
· 7 years ago
Next »