Gitiles
Code Review
Sign In
gerrit.omnirom.org
/
android_system_sepolicy
/
e4e4d8eeac97274fedbe563fa5d1221671fe13a6
e4e4d8e
Add file contexts for com.android.extservices APEX.
by Dario Freni
· 6 years ago
2e5ce26
Merge "priv_app: Remove permission to read from /data/anr/traces.txt"
by Treehugger Robot
· 6 years ago
71be259
Merge "priv_app: Remove rules for ota_package_file"
by Treehugger Robot
· 6 years ago
291d6b3
Use vndk_prop for old vndk properties
by Justin Yun
· 6 years ago
abba8e6
Merge "access_vectors: remove incorrect comment about mac_admin"
by Treehugger Robot
· 6 years ago
565c685
priv_app: Remove permission to read from /data/anr/traces.txt
by Ashwini Oruganti
· 6 years ago
1372217
Merge "Add selinux contexts for system_config_service"
by Treehugger Robot
· 6 years ago
fbe4afa
Merge "stable aidl Power HAL policy"
by Wei Wang
· 6 years ago
d61b0ce
priv_app: Remove rules for ota_package_file
by Ashwini Oruganti
· 6 years ago
fc52615
Merge "Configure SELinux for PowerManager Caches"
by Collin Fijalkovich
· 6 years ago
89277a4
Merge "Fix spelling of 'system' for android.hardware.identity@1.0-service.example"
by Treehugger Robot
· 6 years ago
bda9c33
Merge "Allow adbd to set/get persist.adb props, system_server to get."
by Joshua Duong
· 6 years ago
834c964
Merge "system_server: TelephonyManager reads /proc/cmdline"
by Treehugger Robot
· 6 years ago
8715460
access_vectors: remove incorrect comment about mac_admin
by Stephen Smalley
· 6 years ago
8943f24
Merge "llkd: requires sys_admin permissions"
by Treehugger Robot
· 6 years ago
a1f829d
Merge "Add sepolicy for usb gadget hal v1.1"
by Treehugger Robot
· 6 years ago
8b5a90a
Merge "Allow gsid to create subdirectories under /metadata/gsi/dsu"
by Howard Chen
· 6 years ago
32b24c0
stable aidl Power HAL policy
by Wei Wang
· 6 years ago
1145b90
Merge "Add rebootescrow default HAL rules"
by Treehugger Robot
· 6 years ago
05ade22
Fix spelling of 'system' for android.hardware.identity@1.0-service.example
by David Zeuthen
· 6 years ago
a5527b4
Merge "Add SELinux policy for Identity Credential HAL"
by Treehugger Robot
· 6 years ago
f644c54
Merge "perf_event: rules for system and simpleperf domain"
by Treehugger Robot
· 6 years ago
70c40e0
Add rebootescrow default HAL rules
by Kenny Root
· 6 years ago
719bf1b
Add selinux contexts for system_config_service
by Hall Liu
· 6 years ago
4bec069
Allow adbd to set/get persist.adb props, system_server to get.
by Joshua Duong
· 6 years ago
41a1b4a
Merge "[SfStats] sepolicy for SfStats' global puller"
by Treehugger Robot
· 6 years ago
ffa0dd9
perf_event: rules for system and simpleperf domain
by Ryan Savitski
· 6 years ago
679b417
Merge "access_vectors: re-organize common file perms"
by Treehugger Robot
· 6 years ago
37daf9f
llkd: requires sys_admin permissions
by Mark Salyzyn
· 6 years ago
edc513c
Merge "Allow apps to read ro.init.userspace_reboot.is_supported"
by Nikita Ioffe
· 6 years ago
4d33dc2
Merge "Allow init to configure dm_verity kernel driver."
by Treehugger Robot
· 6 years ago
a98cdef
Add sepolicy for usb gadget hal v1.1
by Howard Yen
· 6 years ago
f9d45fc
Merge "Allow zygote to bind mount /data/misc/profiles/cur"
by Treehugger Robot
· 6 years ago
3914147
Merge "Give fastbootd permission to mount and write to /metadata/gsi."
by Yifan Hong
· 6 years ago
b8b5da4
Add SELinux policy for Identity Credential HAL
by David Zeuthen
· 6 years ago
cd62a4a
access_vectors: re-organize common file perms
by Stephen Smalley
· 6 years ago
32e7ea0
Allow apps to read ro.init.userspace_reboot.is_supported
by Nikita Ioffe
· 6 years ago
ca6e01a
Allow zygote to bind mount /data/misc/profiles/cur
by Ricky Wai
· 6 years ago
184fe45
Merge "perf_event: define security class and access vectors"
by Treehugger Robot
· 6 years ago
8496548
Configure SELinux for PowerManager Caches
by Collin Fijalkovich
· 6 years ago
bafd0c7
SELinux changes for the hasSystemFeature() binder cache property.
by Lee Shombert
· 6 years ago
80640c5
perf_event: define security class and access vectors
by Ryan Savitski
· 6 years ago
65d6fd4
Merge "priv_app: Remove rules for system_update_service"
by Ashwini Oruganti
· 6 years ago
f5df7b4
[SfStats] sepolicy for SfStats' global puller
by Alec Mouri
· 6 years ago
34a19b7
Merge "Revert "Allow MediaProvider to host FUSE devices.""
by Zimuzo Ezeozue
· 6 years ago
623fb38
Merge "priv_app: Remove rules allowing a priv-app to ptrace itself"
by Treehugger Robot
· 6 years ago
a40840d
priv_app: Remove rules for system_update_service
by Ashwini Oruganti
· 6 years ago
1f9ecdc
Merge "Allow zygote to relabel CE and DE dirs from tmpfs to system_data_file"
by Treehugger Robot
· 6 years ago
6df2792
Merge "priv_app: Remove rules for storaged"
by Treehugger Robot
· 6 years ago
b2b7c02
Allow zygote to relabel CE and DE dirs from tmpfs to system_data_file
by Ricky Wai
· 6 years ago
ddbfce2
Merge "Make cronet file_contexts as "android:path" property"
by Luke Huang
· 6 years ago
a63ba2a
Make cronet file_contexts as "android:path" property
by Luke Huang
· 6 years ago
1fbac29
Merge "Using macro "rx_file_perms" instead of "execute_no_trans"."
by Treehugger Robot
· 6 years ago
88f2ed8
Merge "Add Selinux rule to allow iorapd to execute compiler."
by Treehugger Robot
· 6 years ago
2ba18e9
priv_app: Remove rules allowing a priv-app to ptrace itself
by Ashwini Oruganti
· 6 years ago
75ccb46
priv_app: Remove rules for keystore
by Ashwini Oruganti
· 6 years ago
67e8fcc
Using macro "rx_file_perms" instead of "execute_no_trans".
by Yan Wang
· 6 years ago
d1a8f0d
priv_app: Remove rules for storaged
by Ashwini Oruganti
· 6 years ago
7d844ee
Add Selinux rule to allow iorapd to execute compiler.
by Yan Wang
· 6 years ago
0b099c8
Merge "Add userspace_reboot_config_prop property type"
by Nikita Ioffe
· 6 years ago
7130e67
Merge "Rename sdkext sepolicy to sdkextensions"
by Anton Hansson
· 6 years ago
4f362b1
Merge "priv_app: Remove rules for update_engine"
by Treehugger Robot
· 6 years ago
f596cc8
Add userspace_reboot_config_prop property type
by Nikita Ioffe
· 6 years ago
c66a329
Merge "priv_app.te: Remove auditallows for shell_data_file"
by Treehugger Robot
· 6 years ago
c8c6c00
Merge "Add aidl_lazy_test_server"
by Jon Spivack
· 6 years ago
5d395b2
priv_app: Remove rules for update_engine
by Ashwini Oruganti
· 6 years ago
977fdd9
priv_app.te: Remove auditallows for shell_data_file
by Ashwini Oruganti
· 6 years ago
74a6730
Revert "Allow MediaProvider to host FUSE devices."
by Zimuzo Ezeozue
· 6 years ago
0c68750
Merge "sepolicy: don't construct mappings for ignored types"
by Tri Vo
· 6 years ago
5e4a45f
Merge "Make platform_compat accessible on release builds."
by Andrei-Valentin Onea
· 6 years ago
8c31ddf
sepolicy: don't construct mappings for ignored types
by Tri Vo
· 6 years ago
b841335
Rename sdkext sepolicy to sdkextensions
by Anton Hansson
· 6 years ago
3e93ffb
Merge "vendor_init can set config.disable_cameraservice"
by Treehugger Robot
· 6 years ago
ae2df6b
Add aidl_lazy_test_server
by Jon Spivack
· 6 years ago
86e110e
gmscore_app: Enforce all rules for the domain
by Ashwini Oruganti
· 6 years ago
cbfe879
vendor_init can set config.disable_cameraservice
by Robin Lee
· 6 years ago
a44b9cb
Allow gsid to create subdirectories under /metadata/gsi/dsu
by Howard Chen
· 6 years ago
d5a0edd
Grant appdomain access to app_api_service
by Adam Shih
· 6 years ago
4c37de9
Merge "Don't run permissioncontroller_app in permissive mode"
by Treehugger Robot
· 6 years ago
7d54f03
Don't run permissioncontroller_app in permissive mode
by Ashwini Oruganti
· 6 years ago
50c5d73
Merge "Add sepolicy for binderfs"
by Treehugger Robot
· 6 years ago
5357e76
Temporarily whitelist system_server->storage denials
by Jeff Vander Stoep
· 6 years ago
d38fa3f
Allow init to configure dm_verity kernel driver.
by Martijn Coenen
· 6 years ago
ed0a8eb
Revert "Revert "Define sepolicy for ro.product.vndk.version""
by Justin Yun
· 6 years ago
f536a60
Revert "Define sepolicy for ro.product.vndk.version"
by Justin Yun
· 6 years ago
59e3983
Define sepolicy for ro.product.vndk.version
by Justin Yun
· 6 years ago
6570d6d
permissioncontroller_app: add a rule for IProxyService_service
by Ashwini Oruganti
· 6 years ago
2848fa4
Revert "Reland: "Add userspace_reboot_config_prop property type""
by Nikita Ioffe
· 6 years ago
7b53803
Reland: "Add userspace_reboot_config_prop property type"
by Nikita Ioffe
· 6 years ago
a2f0fdf
Merge "binder_use: Allow servicemanager callbacks"
by Jon Spivack
· 6 years ago
3bd8767
Revert "Add userspace_reboot_config_prop property type"
by Jayachandran Chinnakkannu
· 6 years ago
8b570f0
Add userspace_reboot_config_prop property type
by Nikita Ioffe
· 6 years ago
8a40d6e
Merge "sepolicy: new file_integrity_service"
by Treehugger Robot
· 6 years ago
c639fb6
Merge "Don't audit data_mirror in dumpstate"
by Alan Stokes
· 6 years ago
6ee440b
Merge "Allow linkerconfig to be executed with logwrap"
by Kiyoung Kim
· 6 years ago
af004c3
Merge "Add ro.init.userspace_reboot.is_supported property"
by Nikita Ioffe
· 6 years ago
4b9114a
binder_use: Allow servicemanager callbacks
by Jon Spivack
· 6 years ago
48a7b5a
sepolicy: new file_integrity_service
by Victor Hsieh
· 6 years ago
2e17c05
Don't audit data_mirror in dumpstate
by Ricky Wai
· 6 years ago
b26066c
Merge "Create filegroup for sdkext file contexts"
by Anton Hansson
· 6 years ago
Next »