1. 48966b6 Add plumbing for new tee_service_contexts by Nikita Ioffe · 11 months ago
  2. 9b32308 Add BOARD_GENFS_LABELS_VERSION by Inseob Kim · 10 months ago
  3. abfc8b0 Revert^5 "Allow system server to access udc sysfs" by Roy Luo · 10 months ago
  4. d85b55d Collapse task_profiles_api_file into task_profiles_file by T.J. Mercier · 11 months ago
  5. 55c17f2 Collapse cgroup_desc_api_file into cgroup_desc_file by T.J. Mercier · 11 months ago
  6. c7b6e6c Merge "Adjust sepolicy for memevents with lmkd and system_server" into main by Treehugger Robot · 1 year ago
  7. 63880c5 Adjust sepolicy for memevents with lmkd and system_server by Carlos Galo · 1 year ago
  8. b268115 Revert "add compaction_proactiveness type" by Martin Liu · 1 year ago
  9. dcf51fb Revert "Guard proc_compaction_proactiveness" by Martin Liu · 1 year ago
  10. dbca625 Revert "sepolicy: remove all remaining qtaguid stuff." by Bart Sears · 1 year, 1 month ago
  11. af08bd3 sepolicy: remove all remaining qtaguid stuff. by Maciej Żenczykowski · 1 year, 1 month ago
  12. e09cefc Revert^4 "Allow system server to access udc sysfs" by Roy Luo · 1 year, 2 months ago
  13. b18e810 Revert^3 "Allow system server to access udc sysfs" by Pechetty Sravani · 1 year, 2 months ago
  14. 0fab925 Revert^2 "Allow system server to access udc sysfs" by Roy Luo · 1 year, 2 months ago
  15. bbdc1e2 Revert "Allow system server to access udc sysfs" by Roy Luo · 1 year, 2 months ago
  16. 3c21d8f Allow system server to access udc sysfs by Roy Luo · 1 year, 4 months ago
  17. 248f0e0 Update transaction log permissions. by Steven Moreland · 1 year, 4 months ago
  18. b071882 Allow system app and update_engine to read OTA from /vendor by Pawan Wagh · 1 year, 4 months ago
  19. 716260a Allow shell read access to cgroup state by T.J. Mercier · 1 year, 4 months ago
  20. ec218a7 Guard proc_compaction_proactiveness by Inseob Kim · 1 year, 5 months ago
  21. 3458c57 Guard new types with starting_at_board_api macro by Inseob Kim · 1 year, 5 months ago
  22. f739691 add compaction_proactiveness type by Martin Liu · 1 year, 5 months ago
  23. dfc018f Merge "Allow system_server to read binderfs state file" into main by Devin Moore · 1 year, 5 months ago
  24. 9645657 Allow system_server to read binderfs state file by Devin Moore · 1 year, 7 months ago
  25. 09b27c7 Add "DO NOT ADD statements" comments to public by Inseob Kim · 1 year, 5 months ago
  26. 75806ef Minimize public policy by Inseob Kim · 1 year, 5 months ago
  27. ea1bd5d lmkd: Add sepolicy rules around bpf for lmkd by Carlos Galo · 1 year, 6 months ago
  28. 1f915b4 label boot animations on oem with bootanim_oem_file by Håkan Kvist · 1 year, 7 months ago
  29. 6c8210d selinux setup for files under /metadata/aconfig dir by Dennis Shen · 1 year, 7 months ago
  30. 878f7f1 Merge "system_server: remove access to proc/memhealth/*" into main by Carlos Galo · 1 year, 7 months ago
  31. 4a9f07f system_server: remove access to proc/memhealth/* by Carlos Galo · 1 year, 7 months ago
  32. 0d6679a [Thread] move ot-daemon socket to /dev/socket/ot-daemon by Kangping Dong · 1 year, 8 months ago
  33. ed25d94 vendor_microdroid_file shouldn't be overwrited by Seungjae Yoo · 1 year, 10 months ago
  34. d2a0892 Introduce vendor_microdroid_file for microdroid vendor image by Seungjae Yoo · 1 year, 10 months ago
  35. 52aa503 add percpu_pagelist_high_fraction type by Martin Liu · 1 year, 10 months ago
  36. ebe1316 Create sepolicy for allowing system_server rw in /metadata/repair-mode by Rhed Jao · 2 years, 4 months ago
  37. 0b3f585 Allow system server read binderfs stats by Li Li · 1 year, 11 months ago
  38. 75603e3 allow writes to /sys/power/sync_on_suspend from init by Steve Muckle · 1 year, 11 months ago
  39. 004cc8c system_server: allow access to proc/memhealth/* by Carlos Galo · 2 years ago
  40. b6211b8 Introduce vendor_apex_metadata_file by Jooyung Han · 2 years, 3 months ago
  41. dbe230a Allow snapuserd to write log files to /data/misc by Kelvin Zhang · 2 years, 4 months ago
  42. 6b5da95 Use kernel sys/fs/fuse/features/fuse_bpf flag to enable fuse_bpf by Paul Lawrence · 2 years, 6 months ago
  43. 863cedf Merge "Allow dumpstate to read /data/system/shutdown-checkpoints/" by Treehugger Robot · 2 years, 7 months ago
  44. dd4c5fa Merge "Adds support for fuseblk binaries." by Alfred Piccioni · 2 years, 7 months ago
  45. 35541e1 Allow dumpstate to read /data/system/shutdown-checkpoints/ by Woody Lin · 2 years, 7 months ago
  46. 01fd5eb Merge "Restrict system server from reading statsd data" by Jeffrey Huang · 2 years, 7 months ago
  47. fcf5a91 Restrict system server from reading statsd data by Jeffrey Huang · 2 years, 7 months ago
  48. 30ae427 Adds support for fuseblk binaries. by Alfred Piccioni · 2 years, 8 months ago
  49. 3e1dc57 Add NTFS support in sepolicy. by Alfred Piccioni · 2 years, 10 months ago
  50. afa8ca6 Merge "much more finegrained bpf selinux privs for networking mainline" by Maciej Żenczykowski · 3 years, 3 months ago
  51. b13921c much more finegrained bpf selinux privs for networking mainline by Maciej Żenczykowski · 3 years, 4 months ago
  52. 37888b3 Remove TZUvA feature. by Neil Fuller · 6 years ago
  53. b07c12c Iorapd and friends have been removed by Jeff Vander Stoep · 3 years, 4 months ago
  54. 9a59923 Restrict creating per-user encrypted directories by Eric Biggers · 3 years, 4 months ago
  55. a933980 Adds GPU sepolicy to support devices with DRM gralloc/rendering by Jason Macnak · 3 years, 7 months ago
  56. 6ba4146 Merge changes from topic "mglru-exp" by Kalesh Singh · 3 years, 5 months ago
  57. 98f6349 Add sepolicy for Multi-Gen LRU sysfs control by Kalesh Singh · 3 years, 5 months ago
  58. 8337d04 Add label and permission for game_mode_intervention.list by Andy Yu · 3 years, 6 months ago
  59. 7582132 sepolicy: allow access to binderfs feature files by Carlos Llamas · 3 years, 7 months ago
  60. 4a55689 system_dlkm: sepolicy: add system_dlkm_file_type by Ramji Jiyani · 3 years, 7 months ago
  61. c27d24c Allow BPF programs from vendor. by Steven Moreland · 6 years ago
  62. 04cddf8 Merge "Allow bpfloader to read fuse's bpf_prog number" by Paul Lawrence · 3 years, 9 months ago
  63. ce54266 Added sepolicy rule for vendor uuid mapping config by Rajesh Nyamagoud · 3 years, 10 months ago
  64. e3e26b7 Allow bpfloader to read fuse's bpf_prog number by Paul Lawrence · 3 years, 10 months ago
  65. 3702f33 introduce new 'proc_bpf' for bpf related sysctls by Maciej Żenczykowski · 3 years, 10 months ago
  66. 5e016c1 Merge "Stop using the bdev_type and sysfs_block_type SELinux attributes" by Bart Van Assche · 3 years, 10 months ago
  67. 37919f5 Merge "Remove references to nonplat sepolicy" by Treehugger Robot · 3 years, 10 months ago
  68. f098071 Remove references to nonplat sepolicy by Jeff Vander Stoep · 3 years, 10 months ago
  69. 6092d63 Allow init to write to /proc/cpu/alignment by Alistair Delva · 3 years, 10 months ago
  70. 4374a1f Stop using the bdev_type and sysfs_block_type SELinux attributes by Bart Van Assche · 4 years ago
  71. e3cfa9e Revert "Remove the bdev_type and sysfs_block_type SELinux attributes" by Bart Van Assche · 3 years, 10 months ago
  72. 63930d3 Remove the bdev_type and sysfs_block_type SELinux attributes by Bart Van Assche · 4 years ago
  73. e8739ba Revert "Remove the bdev_type and sysfs_block_type SELinux attributes" by Michał Brzeziński · 3 years, 11 months ago
  74. c50f669 Remove the bdev_type and sysfs_block_type SELinux attributes by Bart Van Assche · 4 years ago
  75. 27f77dc Grant apexd access the SELinux type sysfs_devices_block by Bart Van Assche · 4 years ago
  76. 6988677 Allow init to execute extra_free_kbytes.sh script by Suren Baghdasaryan · 4 years, 1 month ago
  77. 11d2b1c Merge "Don't prevent crosvm from accessing vendor-owned VM disk images" by Jiyong Park · 4 years, 1 month ago
  78. ec50aa5 Allow the init and apexd processes to read all block device properties by Bart Van Assche · 4 years, 1 month ago
  79. 3fee5a4 Don't prevent crosvm from accessing vendor-owned VM disk images by Jiyong Park · 4 years, 1 month ago
  80. b31ec34 Move vendor_sched to common sepolicy by Rick Yiu · 4 years, 1 month ago
  81. bf5b6ce Add new snapuserd socket and property rules. by David Anderson · 4 years, 1 month ago
  82. fa10a14 Refactor apex data file types. by Alan Stokes · 4 years, 2 months ago
  83. 4db56b0 allow init to access watermark_boost_factor by Martin Liu · 4 years, 2 months ago
  84. 9ec5327 Add fusefs_type for FUSE filesystems by Thiébaud Weksteen · 4 years, 3 months ago
  85. 0b2553a Allow the appsearch apex access to the apexdata misc_ce dir. by Alexander Dorokhine · 4 years, 4 months ago
  86. f35c70b Merge changes If26ba23d,Ibea38822 by Hridya Valsaraju · 4 years, 4 months ago
  87. 633f7ca [sepolicy] allow system server to read incfs metrics from sysfs by Songchun Fan · 4 years, 4 months ago
  88. 23f9f51 Revert "Revert "Add neverallows for debugfs access"" by Hridya Valsaraju · 4 years, 4 months ago
  89. 7362f58 Merge changes from topic "revert-1668411-MWQWEZISXF" by Hridya Valsaraju · 4 years, 5 months ago
  90. e95e0ec Revert "Add neverallows for debugfs access" by Hridya Valsaraju · 4 years, 5 months ago
  91. 005ae59 Merge changes from topic "debugfs_neverallow" by Treehugger Robot · 4 years, 5 months ago
  92. a0b504a Add neverallows for debugfs access by Hridya Valsaraju · 4 years, 6 months ago
  93. c50fecd Allow traced_probes to read devfreq by David Massoud · 4 years, 5 months ago
  94. 49806a1 Merge "Add vendor_kernel_modules type to public." by Yabin Cui · 4 years, 5 months ago
  95. 2e2df6b Add vendor_kernel_modules type to public. by Yabin Cui · 4 years, 5 months ago
  96. 806898d Split gsi_metadata_file and add gsi_metadata_file_type attribute by Yi-Yo Chiang · 4 years, 6 months ago
  97. 3d52817 Selinux policy for bootreceiver tracing instance by Alexander Potapenko · 4 years, 6 months ago
  98. 08a25e6 Revert "Selinux policy for bootreceiver tracing instance" by Wonsik Kim · 4 years, 6 months ago
  99. 31251aa Selinux policy for bootreceiver tracing instance by Alexander Potapenko · 4 years, 6 months ago
  100. 840d4f3 Add sepolicy for /proc/bootconfig by Devin Moore · 4 years, 7 months ago