- 09b27c7 Add "DO NOT ADD statements" comments to public by Inseob Kim · 1 year, 5 months ago
- 75806ef Minimize public policy by Inseob Kim · 1 year, 5 months ago
- 7c4f8a8 Allow vendor_overlay_file from vendor apex by Jooyung Han · 2 years, 3 months ago
- 9a59923 Restrict creating per-user encrypted directories by Eric Biggers · 3 years, 4 months ago
- 7be3e86 Remove obsolete rule allowing installd to use fsverity ioctls by Eric Biggers · 3 years, 5 months ago
- 7c81cab Added permission to allow for ioctl to be added to install_data_file by Shikha Malhotra · 3 years, 6 months ago
- ddfb8a9 Adding more permission for selinux to some attributes and flags by Shikha Malhotra · 3 years, 8 months ago
- d577958 allow installd to kill dex2oat and dexoptanalyzer by Keun young Park · 4 years, 2 months ago
- 9ec5327 Add fusefs_type for FUSE filesystems by Thiébaud Weksteen · 4 years, 3 months ago
- f1a60ca [sepolicy] allow installd to query apps installed on Incremental File System by Songchun Fan · 4 years, 3 months ago
- 6a22e37 Add sepolicy for installd check sdcardfs usage property by juanjuan.hou · 4 years, 5 months ago
- aa4ce95 sepolicy: rules for uid/pid cgroups v2 hierarchy by Marco Ballesio · 4 years, 7 months ago
- aa8bb3a Revert^3 "sepolicy: rules for uid/pid cgroups v2 hierarchy" by Marco Ballesio · 4 years, 7 months ago
- a54bed6 Revert^2 "sepolicy: rules for uid/pid cgroups v2 hierarchy" by Marco Ballesio · 4 years, 7 months ago
- 7aa4041 Split user_profile_data_file label. by Alan Stokes · 4 years, 9 months ago
- 51c04ac Revert "sepolicy: rules for uid/pid cgroups v2 hierarchy" by Jonglin Lee · 4 years, 9 months ago
- f46d7a2 sepolicy: rules for uid/pid cgroups v2 hierarchy by Marco Ballesio · 4 years, 10 months ago
- f8ad339 Introduce app_data_file_type attribute. by Alan Stokes · 4 years, 10 months ago
- b01e1d9 Revert "Introduce app_data_file_type attribute." by Alan Stokes · 4 years, 10 months ago
- 27e0c74 Introduce app_data_file_type attribute. by Alan Stokes · 4 years, 10 months ago
- 080a57a Allow installd to read /proc/filesystems. by Martijn Coenen · 6 years ago
- fcf599c Grant vold, installd, zygote and apps access to /mnt/pass_through by Zim · 6 years ago
- a2f0fdf Merge "binder_use: Allow servicemanager callbacks" by Jon Spivack · 6 years ago
- 4b9114a binder_use: Allow servicemanager callbacks by Jon Spivack · 6 years ago
- 5b1b423 Allow Zygote and Installd to remount directories in /data/data by Ricky Wai · 6 years ago
- bfcddbe sepolicy: remove ashmemd by Tri Vo · 6 years ago
- 1fc4495 Merge "Move layout_version to /data/misc/installd" am: 7f9c607b4f by Paul Crowley · 6 years ago
- 04023ad Move layout_version to /data/misc/installd by Paul Crowley · 6 years ago
- 533363b Merge "Sepolicy for IAshmem HIDL interface" am: b374835ffb am: 99a5e65385 by Kalesh Singh · 6 years ago
- 46303aa Sepolicy for IAshmem HIDL interface by Kalesh Singh · 6 years ago
- 653d0f1 Expand deletion powers to all "sdcard_type". by Jeff Sharkey · 6 years ago
- b6591f6 Allow installd to scan JARs in /vendor/framework. by Nicolas Geoffray · 7 years ago
- 73d0a67 sepolicy for ashmemd by Tri Vo · 7 years ago
- 7397ebd Allow fs-verity setup within system_server by Victor Hsieh · 7 years ago
- 0045ecb installd: add fsverity ioctls by Nick Kralevich · 7 years ago
- 5e37271 Introduce system_file_type by Nick Kralevich · 7 years ago
- 342362a sepolicy: grant dac_read_search to domains with dac_override by Benjamin Gordon · 7 years ago
- 23c9d91 Start partitioning off privapp_data_file from app_data_file by Nick Kralevich · 7 years ago
- 06bac37 Installd doesn't need to create cgroup files. by Alan Stokes · 7 years ago
- 9b2e0cb sepolicy: Add rules for non-init namespaces by Benjamin Gordon · 8 years ago
- 97b0890 Allow installd to read system_data_file:lnk_file by Calin Juravle · 8 years ago
- 2cf7fba domain_deprecate: remove system_data_file access am: 2b75437dc8 by Jeff Vander Stoep · 8 years ago
- 2b75437 domain_deprecate: remove system_data_file access by Jeff Vander Stoep · 8 years ago
- dd57e69 Allow installd to delete files via sdcardfs. by Jeff Sharkey · 8 years ago
- 76aab82 Move domain_deprecated into private policy by Jeff Vander Stoep · 8 years ago
- 72f4c61 Allow installd to delete files via sdcardfs. by Jeff Sharkey · 8 years ago
- aeada24 Allow installd to read vendor_overlay_file by Jaekyun Seok · 8 years ago
- 1b5f81a sepolicy: restrict /vendor/app from most coredomains by Sandeep Patil · 8 years ago
- 1e14996 seapp_context: explicitly label all seapp context files by Sandeep Patil · 8 years ago
- c9cf736 file_context: explicitly label all file context files by Sandeep Patil · 8 years ago
- b238fe6 Split preloads into media_file and data_file by Fyodor Kupolov · 8 years ago
- 2b29112 SElinux: Clean up code related to foreign dex use by Calin Juravle · 9 years ago
- a64b685 Allow installd to delete from preloads/file_cache by Fyodor Kupolov · 9 years ago
- 4c40d73 Merge ephemeral data and apk files into app by Chad Brubaker · 9 years ago
- 606d2fd te_macros: introduce add_service() macro by William Roberts · 9 years ago
- 86c7689 Allow installd to measure size of dexopt links. by Jeff Sharkey · 9 years ago
- fe1de04 Allow installd to get/set filesystem quotas. by Jeff Sharkey · 9 years ago
- 2e00e63 sepolicy: add version_policy tool and version non-platform policy. by dcashman · 9 years ago
- e160d14 Rules for new installd Binder interface. by Jeff Sharkey · 9 years ago
- 6f090f6 Label ephemeral APKs and handle their install/uninstall by Chad Brubaker · 9 years ago
- 68f2336 installd: r_dir_file(installd, system_file) by Nick Kralevich · 9 years ago
- 06cf31e Rename autoplay_app to ephemeral_app by Chad Brubaker · 9 years ago
- cc39f63 Split general policy into public and private components. by dcashman · 9 years ago[Renamed (94%) from installd.te]
- 03daf85 Sepolicy: Adapt for new A/B OTA flow by Andreas Gampe · 9 years ago
- 7ef8073 audit domain_deprecated perms for removal by Jeff Vander Stoep · 9 years ago
- 5a54e40 Allow installd to delete the foreign-dex folder am: a4e2aa1345 by Amith Yamasani · 9 years ago
- a4e2aa1 Allow installd to delete the foreign-dex folder by Amith Yamasani · 9 years ago
- 90b0089 SELinux policy for /data/misc/profman am: a5d0792508 by David Sehr · 9 years ago
- a5d0792 SELinux policy for /data/misc/profman by David Sehr · 9 years ago
- c46ef41 Merge "Selinux: Policies for otapreopt_chroot and postinstall_dexopt" into nyc-dev by Andreas Gampe · 9 years ago
- e5d8a94 Selinux: Policies for otapreopt_chroot and postinstall_dexopt by Andreas Gampe · 9 years ago
- e249da0 Leftovers of SELinux policy reload mechanism am: 1c983327cf by Janis Danisevskis · 9 years ago
- 1c98332 Leftovers of SELinux policy reload mechanism by Janis Danisevskis · 9 years ago
- 837bc42 Add SElinux policies to allow foreign dex usage tracking. by Calin Juravle · 10 years ago
- 89625c9 Update permissions for the dedicated profile folders by Calin Juravle · 10 years ago
- 47ebae1 Selinux: introduce policy for OTA preopt by Andreas Gampe · 10 years ago
- ae72bf2 Populate autoplay_app with minimal set of permissions by Jeff Vander Stoep · 10 years ago
- 2469b32 Remove handling of dalvik-cache/profiles by Calin Juravle · 10 years ago
- d22987b Create attribute for moving perms out of domain by Jeff Vander Stoep · 10 years ago
- a1d78ff am b01a18b9: Merge "grant installd rx perms on toybox" by Jeffrey Vander Stoep · 10 years ago
- 628e7f7 grant installd rx perms on toybox by Jeff Vander Stoep · 10 years ago
- 8328eaf am 3cba84e2: Merge "Run idmap in its own domain." by Daniel Cashman · 10 years ago
- b335e38 Run idmap in its own domain. by Stephen Smalley · 10 years ago
- f8fd5ab installd restorecon now requires getattr. by Jeff Sharkey · 10 years ago
- 9aafd4a Allow installd to link apk_data_file and dalvikcache_data_file. by Narayan Kamath · 10 years ago
- ecc82e0 Allow installd to move APKs. by Jeff Sharkey · 10 years ago
- 8f821db Allow installd to move APKs. by Jeff Sharkey · 10 years ago
- 8da7876 Allow installd to move around private app data. by Jeff Sharkey · 10 years ago
- 44c95e9 Allow installd to dexopt apps on expanded storage. by Jeff Sharkey · 10 years ago
- b87a4b1 Support for storing OAT files in app directory by Fyodor Kupolov · 11 years ago
- 0d0d5aa installd: drop noatsecure for dex2oat by Nick Kralevich · 11 years ago
- 51bfecf Pull keychain-data policy out of system-data by Robin Lee · 11 years ago
- 8ee37b4 reconcile aosp (c103da877b72aae80616dbc192982aaf75dfe888) after branching. Please do not merge. by Ed Heyl · 11 years ago
- fad4d5f Fix SELinux policies to allow resource overlays. by Nick Kralevich · 11 years ago
- 8670305 Remove world-read access to /data/dalvik-cache/profiles by Nick Kralevich · 11 years ago
- 89b9ff7 Allow installd to chown/chmod app data files. by Stephen Smalley · 11 years ago
- d2622fd Allow installd to stat asec files and /data/media files. by Stephen Smalley · 11 years ago
- 6f6c425 Adjust rules around /data/app entities by Christopher Tate · 11 years ago
- f85c1fc Allow installd, vold, system_server unlabeled access. by Stephen Smalley · 11 years ago
- d30060a Allow installd to unlink /data/media files and search /data/app-asec. by Stephen Smalley · 11 years ago