1. e4e4d8e Add file contexts for com.android.extservices APEX. by Dario Freni · 6 years ago
  2. 2e5ce26 Merge "priv_app: Remove permission to read from /data/anr/traces.txt" by Treehugger Robot · 6 years ago
  3. 71be259 Merge "priv_app: Remove rules for ota_package_file" by Treehugger Robot · 6 years ago
  4. 291d6b3 Use vndk_prop for old vndk properties by Justin Yun · 6 years ago
  5. abba8e6 Merge "access_vectors: remove incorrect comment about mac_admin" by Treehugger Robot · 6 years ago
  6. 565c685 priv_app: Remove permission to read from /data/anr/traces.txt by Ashwini Oruganti · 6 years ago
  7. 1372217 Merge "Add selinux contexts for system_config_service" by Treehugger Robot · 6 years ago
  8. fbe4afa Merge "stable aidl Power HAL policy" by Wei Wang · 6 years ago
  9. d61b0ce priv_app: Remove rules for ota_package_file by Ashwini Oruganti · 6 years ago
  10. fc52615 Merge "Configure SELinux for PowerManager Caches" by Collin Fijalkovich · 6 years ago
  11. 89277a4 Merge "Fix spelling of 'system' for android.hardware.identity@1.0-service.example" by Treehugger Robot · 6 years ago
  12. bda9c33 Merge "Allow adbd to set/get persist.adb props, system_server to get." by Joshua Duong · 6 years ago
  13. 834c964 Merge "system_server: TelephonyManager reads /proc/cmdline" by Treehugger Robot · 6 years ago
  14. 8715460 access_vectors: remove incorrect comment about mac_admin by Stephen Smalley · 6 years ago
  15. 8943f24 Merge "llkd: requires sys_admin permissions" by Treehugger Robot · 6 years ago
  16. a1f829d Merge "Add sepolicy for usb gadget hal v1.1" by Treehugger Robot · 6 years ago
  17. 8b5a90a Merge "Allow gsid to create subdirectories under /metadata/gsi/dsu" by Howard Chen · 6 years ago
  18. 32b24c0 stable aidl Power HAL policy by Wei Wang · 6 years ago
  19. 1145b90 Merge "Add rebootescrow default HAL rules" by Treehugger Robot · 6 years ago
  20. 05ade22 Fix spelling of 'system' for android.hardware.identity@1.0-service.example by David Zeuthen · 6 years ago
  21. a5527b4 Merge "Add SELinux policy for Identity Credential HAL" by Treehugger Robot · 6 years ago
  22. f644c54 Merge "perf_event: rules for system and simpleperf domain" by Treehugger Robot · 6 years ago
  23. 70c40e0 Add rebootescrow default HAL rules by Kenny Root · 6 years ago
  24. 719bf1b Add selinux contexts for system_config_service by Hall Liu · 6 years ago
  25. 4bec069 Allow adbd to set/get persist.adb props, system_server to get. by Joshua Duong · 6 years ago
  26. 41a1b4a Merge "[SfStats] sepolicy for SfStats' global puller" by Treehugger Robot · 6 years ago
  27. ffa0dd9 perf_event: rules for system and simpleperf domain by Ryan Savitski · 6 years ago
  28. 679b417 Merge "access_vectors: re-organize common file perms" by Treehugger Robot · 6 years ago
  29. 37daf9f llkd: requires sys_admin permissions by Mark Salyzyn · 6 years ago
  30. edc513c Merge "Allow apps to read ro.init.userspace_reboot.is_supported" by Nikita Ioffe · 6 years ago
  31. 4d33dc2 Merge "Allow init to configure dm_verity kernel driver." by Treehugger Robot · 6 years ago
  32. a98cdef Add sepolicy for usb gadget hal v1.1 by Howard Yen · 6 years ago
  33. f9d45fc Merge "Allow zygote to bind mount /data/misc/profiles/cur" by Treehugger Robot · 6 years ago
  34. 3914147 Merge "Give fastbootd permission to mount and write to /metadata/gsi." by Yifan Hong · 6 years ago
  35. b8b5da4 Add SELinux policy for Identity Credential HAL by David Zeuthen · 6 years ago
  36. cd62a4a access_vectors: re-organize common file perms by Stephen Smalley · 6 years ago
  37. 32e7ea0 Allow apps to read ro.init.userspace_reboot.is_supported by Nikita Ioffe · 6 years ago
  38. ca6e01a Allow zygote to bind mount /data/misc/profiles/cur by Ricky Wai · 6 years ago
  39. 184fe45 Merge "perf_event: define security class and access vectors" by Treehugger Robot · 6 years ago
  40. 8496548 Configure SELinux for PowerManager Caches by Collin Fijalkovich · 6 years ago
  41. bafd0c7 SELinux changes for the hasSystemFeature() binder cache property. by Lee Shombert · 6 years ago
  42. 80640c5 perf_event: define security class and access vectors by Ryan Savitski · 6 years ago
  43. 65d6fd4 Merge "priv_app: Remove rules for system_update_service" by Ashwini Oruganti · 6 years ago
  44. f5df7b4 [SfStats] sepolicy for SfStats' global puller by Alec Mouri · 6 years ago
  45. 34a19b7 Merge "Revert "Allow MediaProvider to host FUSE devices."" by Zimuzo Ezeozue · 6 years ago
  46. 623fb38 Merge "priv_app: Remove rules allowing a priv-app to ptrace itself" by Treehugger Robot · 6 years ago
  47. a40840d priv_app: Remove rules for system_update_service by Ashwini Oruganti · 6 years ago
  48. 1f9ecdc Merge "Allow zygote to relabel CE and DE dirs from tmpfs to system_data_file" by Treehugger Robot · 6 years ago
  49. 6df2792 Merge "priv_app: Remove rules for storaged" by Treehugger Robot · 6 years ago
  50. b2b7c02 Allow zygote to relabel CE and DE dirs from tmpfs to system_data_file by Ricky Wai · 6 years ago
  51. ddbfce2 Merge "Make cronet file_contexts as "android:path" property" by Luke Huang · 6 years ago
  52. a63ba2a Make cronet file_contexts as "android:path" property by Luke Huang · 6 years ago
  53. 1fbac29 Merge "Using macro "rx_file_perms" instead of "execute_no_trans"." by Treehugger Robot · 6 years ago
  54. 88f2ed8 Merge "Add Selinux rule to allow iorapd to execute compiler." by Treehugger Robot · 6 years ago
  55. 2ba18e9 priv_app: Remove rules allowing a priv-app to ptrace itself by Ashwini Oruganti · 6 years ago
  56. 75ccb46 priv_app: Remove rules for keystore by Ashwini Oruganti · 6 years ago
  57. 67e8fcc Using macro "rx_file_perms" instead of "execute_no_trans". by Yan Wang · 6 years ago
  58. d1a8f0d priv_app: Remove rules for storaged by Ashwini Oruganti · 6 years ago
  59. 7d844ee Add Selinux rule to allow iorapd to execute compiler. by Yan Wang · 6 years ago
  60. 0b099c8 Merge "Add userspace_reboot_config_prop property type" by Nikita Ioffe · 6 years ago
  61. 7130e67 Merge "Rename sdkext sepolicy to sdkextensions" by Anton Hansson · 6 years ago
  62. 4f362b1 Merge "priv_app: Remove rules for update_engine" by Treehugger Robot · 6 years ago
  63. f596cc8 Add userspace_reboot_config_prop property type by Nikita Ioffe · 6 years ago
  64. c66a329 Merge "priv_app.te: Remove auditallows for shell_data_file" by Treehugger Robot · 6 years ago
  65. c8c6c00 Merge "Add aidl_lazy_test_server" by Jon Spivack · 6 years ago
  66. 5d395b2 priv_app: Remove rules for update_engine by Ashwini Oruganti · 6 years ago
  67. 977fdd9 priv_app.te: Remove auditallows for shell_data_file by Ashwini Oruganti · 6 years ago
  68. 74a6730 Revert "Allow MediaProvider to host FUSE devices." by Zimuzo Ezeozue · 6 years ago
  69. 0c68750 Merge "sepolicy: don't construct mappings for ignored types" by Tri Vo · 6 years ago
  70. 5e4a45f Merge "Make platform_compat accessible on release builds." by Andrei-Valentin Onea · 6 years ago
  71. 8c31ddf sepolicy: don't construct mappings for ignored types by Tri Vo · 6 years ago
  72. b841335 Rename sdkext sepolicy to sdkextensions by Anton Hansson · 6 years ago
  73. 3e93ffb Merge "vendor_init can set config.disable_cameraservice" by Treehugger Robot · 6 years ago
  74. ae2df6b Add aidl_lazy_test_server by Jon Spivack · 6 years ago
  75. 86e110e gmscore_app: Enforce all rules for the domain by Ashwini Oruganti · 6 years ago
  76. cbfe879 vendor_init can set config.disable_cameraservice by Robin Lee · 6 years ago
  77. a44b9cb Allow gsid to create subdirectories under /metadata/gsi/dsu by Howard Chen · 6 years ago
  78. d5a0edd Grant appdomain access to app_api_service by Adam Shih · 6 years ago
  79. 4c37de9 Merge "Don't run permissioncontroller_app in permissive mode" by Treehugger Robot · 6 years ago
  80. 7d54f03 Don't run permissioncontroller_app in permissive mode by Ashwini Oruganti · 6 years ago
  81. 50c5d73 Merge "Add sepolicy for binderfs" by Treehugger Robot · 6 years ago
  82. 5357e76 Temporarily whitelist system_server->storage denials by Jeff Vander Stoep · 6 years ago
  83. d38fa3f Allow init to configure dm_verity kernel driver. by Martijn Coenen · 6 years ago
  84. ed0a8eb Revert "Revert "Define sepolicy for ro.product.vndk.version"" by Justin Yun · 6 years ago
  85. f536a60 Revert "Define sepolicy for ro.product.vndk.version" by Justin Yun · 6 years ago
  86. 59e3983 Define sepolicy for ro.product.vndk.version by Justin Yun · 6 years ago
  87. 6570d6d permissioncontroller_app: add a rule for IProxyService_service by Ashwini Oruganti · 6 years ago
  88. 2848fa4 Revert "Reland: "Add userspace_reboot_config_prop property type"" by Nikita Ioffe · 6 years ago
  89. 7b53803 Reland: "Add userspace_reboot_config_prop property type" by Nikita Ioffe · 6 years ago
  90. a2f0fdf Merge "binder_use: Allow servicemanager callbacks" by Jon Spivack · 6 years ago
  91. 3bd8767 Revert "Add userspace_reboot_config_prop property type" by Jayachandran Chinnakkannu · 6 years ago
  92. 8b570f0 Add userspace_reboot_config_prop property type by Nikita Ioffe · 6 years ago
  93. 8a40d6e Merge "sepolicy: new file_integrity_service" by Treehugger Robot · 6 years ago
  94. c639fb6 Merge "Don't audit data_mirror in dumpstate" by Alan Stokes · 6 years ago
  95. 6ee440b Merge "Allow linkerconfig to be executed with logwrap" by Kiyoung Kim · 6 years ago
  96. af004c3 Merge "Add ro.init.userspace_reboot.is_supported property" by Nikita Ioffe · 6 years ago
  97. 4b9114a binder_use: Allow servicemanager callbacks by Jon Spivack · 6 years ago
  98. 48a7b5a sepolicy: new file_integrity_service by Victor Hsieh · 6 years ago
  99. 2e17c05 Don't audit data_mirror in dumpstate by Ricky Wai · 6 years ago
  100. b26066c Merge "Create filegroup for sdkext file contexts" by Anton Hansson · 6 years ago