- 09b27c7 Add "DO NOT ADD statements" comments to public by Inseob Kim · 1 year, 5 months ago
- 75806ef Minimize public policy by Inseob Kim · 1 year, 5 months ago
- d3db89d Modify SELinux rules to allow vold to use the keymaster HAL directly. am: b1c857c824 am: 769bbce026 by Peter Lee · 1 year, 7 months ago
- 769bbce Modify SELinux rules to allow vold to use the keymaster HAL directly. am: b1c857c824 by Peter Lee · 1 year, 7 months ago
- b1c857c Modify SELinux rules to allow vold to use the keymaster HAL directly. by Peter Lee · 1 year, 7 months ago
- 95930cf Allow vold to rename system_data_file directories by Eric Biggers · 2 years, 3 months ago
- ffb9f88 Allow vold to use FS_IOC_GET_ENCRYPTION_KEY_STATUS by Nathan Huckleberry · 2 years, 7 months ago
- b5f16b2 Allow mkfs/fsck for zoned block device by Jaegeuk Kim · 2 years, 8 months ago
- b0f5998 Allow zoned device support in f2fs by Jaegeuk Kim · 3 years, 4 months ago
- b07c12c Iorapd and friends have been removed by Jeff Vander Stoep · 3 years, 4 months ago
- 9a59923 Restrict creating per-user encrypted directories by Eric Biggers · 3 years, 4 months ago
- bf717e1 vold.te: stop allowing use of keymaster HAL directly by Eric Biggers · 3 years, 5 months ago
- 9bf0a0c Remove some FDE rules and update comments by Eric Biggers · 3 years, 5 months ago
- aabea20 Remove healthd. by Yifan Hong · 3 years, 11 months ago
- 9ec5327 Add fusefs_type for FUSE filesystems by Thiébaud Weksteen · 4 years, 3 months ago
- b382f02 [incfs] Allow everyone read the IncFS sysfs features by Yurii Zubrytskyi · 4 years, 5 months ago
- a999004 Keystore 2.0: sepolicy changes for vold to use keystore2 by Satya Tangirala · 4 years, 6 months ago
- 5854941 Add rules for calling ReadDefaultFstab() by Yi-Yo Chiang · 4 years, 6 months ago
- 806898d Split gsi_metadata_file and add gsi_metadata_file_type attribute by Yi-Yo Chiang · 4 years, 6 months ago
- c04f037 Fix problem whereby incfs can't remove files from .incomplete by Paul Lawrence · 4 years, 7 months ago
- 840d4f3 Add sepolicy for /proc/bootconfig by Devin Moore · 4 years, 7 months ago
- 29c54ec Merge "Allow vold to check apex files" by Randall Huang · 4 years, 8 months ago
- 80dfa06 IncFS: update SE policies for the new API by Yurii Zubrytskyi · 4 years, 8 months ago
- 84f59c8 Allow vold to check apex files by Randall Huang · 4 years, 8 months ago
- dc16f6d Allow vold to run make_f2fs by Jaegeuk Kim · 4 years, 9 months ago
- 7aa4041 Split user_profile_data_file label. by Alan Stokes · 4 years, 9 months ago
- 6273186 Merge "Allow gsid to find and binder-call vold" by Yo Chiang · 4 years, 11 months ago
- ffe786e Allow gsid to find and binder-call vold by Yo Chiang · 5 years ago
- 7d15ce2 Add secdiscard policies for vold_metadata_file by Yo Chiang · 5 years ago
- e939cbd Add F2FS_IOC_SEC_TRIM_FILE ioctl code by Yo Chiang · 5 years ago
- aa2cb51 Add sepolicy for FUSE control filesystem. by Martijn Coenen · 5 years ago
- 19a5cc2 [sepolicy] remove vendor_incremental_module from global sepolicy rules by Songchun Fan · 6 years ago
- 55e5c9b Move system property rules to private by Inseob Kim · 6 years ago
- 94dc474 Merge "vold: allow to set boottime prop" by Jaegeuk Kim · 6 years ago
- 9c38162 vold: allow to set boottime prop by Jaegeuk Kim · 6 years ago
- 3922253 permissions for incremental control file by Songchun Fan · 6 years ago
- fcbfe31 Merge "selinux rules for apk files installed with Incremental" by Songchun Fan · 6 years ago
- 3cf7d1b Merge "selinux rules for loading incremental module" by Songchun Fan · 6 years ago
- 99d9374 selinux rules for loading incremental module by Songchun Fan · 6 years ago
- 020e3ab selinux rules for apk files installed with Incremental by Songchun Fan · 6 years ago
- 127f5e8 Allow vold FS_IOC_{GET|SET}FLAGS ioctl. by Martijn Coenen · 6 years ago
- 5119bec Merge "Grant vold, installd, zygote and apps access to /mnt/pass_through" by Zimuzo Ezeozue · 6 years ago
- fcf599c Grant vold, installd, zygote and apps access to /mnt/pass_through by Zim · 6 years ago
- e0ab03a Add FS_IOC_FS(G|S)ETXATTR to ioctl_defines and allow vold to use it. by Martijn Coenen · 6 years ago
- d1460a1 Merge changes Ide8fc07c,Ia1f51db4 by Martijn Coenen · 6 years ago
- 313cff7 Allow vold to mount on top of /data/media. by Martijn Coenen · 6 years ago
- f5ddc04 Add a new context for property ota.warm_reset by Tianjie Xu · 6 years ago
- 0c8a906 Merge changes from topic "fscrypt-key-mgmt-improvements" by Eric Biggers · 6 years ago
- 36ae663 Allow vold to use new ioctls to add/remove fscrypt keys by Eric Biggers · 6 years ago
- bfcddbe sepolicy: remove ashmemd by Tri Vo · 6 years ago
- aed0f76 Root of /data belongs to init (re-landing) by Paul Crowley · 6 years ago
- d98e311 Revert "Root of /data belongs to init" by Paul Crowley · 6 years ago
- 206b653 Root of /data belongs to init by Paul Crowley · 6 years ago
- 46303aa Sepolicy for IAshmem HIDL interface by Kalesh Singh · 6 years ago
- a5ff1ba sepolicy: add sepolicy rules for vold to write sysfs gc_urgent by YH_Lin · 6 years ago
- 1f1c4c3 Allow apexd to talk to vold. by Martijn Coenen · 6 years ago
- 5b60eb6 vold: write permission to sysfs_devices_block by Tri Vo · 6 years ago
- a532088 Decouple system_suspend from hal attributes. by Tri Vo · 7 years ago
- 84e87b8 Allow restorecon to work on vold_data_files by Paul Lawrence · 7 years ago
- db90b91 Full sepolicy for gsid. by David Anderson · 7 years ago
- 650981d Allow update_verifier to call checkpointing by Daniel Rosenberg · 7 years ago
- fb0ab2e Hide denial seen during boot. by Joel Galenson · 7 years ago
- 73d0a67 sepolicy for ashmemd by Tri Vo · 7 years ago
- f0abbf9 Allow vold to create files at /mnt/user/.* by Sudheer Shanka · 7 years ago
- d7bf921 Allow apexd to write to sysfs loop device parameters. by Martijn Coenen · 7 years ago
- 90e68e9 Remove overpermissive neverallow exceptions. by Paul Crowley · 7 years ago
- f9f7539 Abolish calls to shell in vold by Paul Crowley · 7 years ago
- 478ca55 Allow vold to remount by Daniel Rosenberg · 7 years ago
- 536d341 use hal_bootctl_server in neverallow rule by Nick Kralevich · 7 years ago
- 1c5d223 vold: remove access to /proc/net files by Nick Kralevich · 7 years ago
- fefc887 vold: allow ioctls BLKDISCARD and BLKGETSIZE by Nick Kralevich · 7 years ago
- 0c1848b SELinux changes for AppFuse by Risan · 7 years ago
- c4cf986 Revert "SELinux changes for AppFuse" by Nick Kralevich · 7 years ago
- f2cad2d vold does more than LOOP_GET_STATUS64. by Jeff Sharkey · 7 years ago
- 67ed432 SELinux changes for AppFuse by Risan · 7 years ago
- 787fc8d vold.te: allow BLKSECDISCARD by Nick Kralevich · 7 years ago
- 4c8eaba start enforcing ioctl restrictions on blk_file by Nick Kralevich · 7 years ago
- 877b086 vold: allow FS_IOC_FIEMAP by Nick Kralevich · 7 years ago
- ebc3a1a Move to ioctl whitelisting for plain files / directories by Nick Kralevich · 7 years ago
- 72a88b1 iorapd: Add new binder service iorapd. by Igor Murashkin · 7 years ago
- 2d123fc Ensure vold is a client of hal_bootctl only in Treble mode. by Joel Galenson · 7 years ago
- ac5293b Add bootctl for vold by Daniel Rosenberg · 7 years ago
- 5e37271 Introduce system_file_type by Nick Kralevich · 7 years ago
- 0b67bb8 Further lock down app data by Jeff Vander Stoep · 7 years ago
- 1cef6a9 health.filesystem HAL renamed to health.storage by Yifan Hong · 7 years ago
- 342362a sepolicy: grant dac_read_search to domains with dac_override by Benjamin Gordon · 7 years ago
- dac2a4a Sepolicy for system suspend HAL. by Tri Vo · 7 years ago
- fa5afa2 vold uses health filesystem HAL by Yifan Hong · 7 years ago
- a2bacea Allow vold to mount at /mnt/user/.* by Sudheer Shanka · 7 years ago
- 23c9d91 Start partitioning off privapp_data_file from app_data_file by Nick Kralevich · 7 years ago
- 7b67a61 Allowing vold to search /mnt/vendor/* by Bowgo Tsai · 7 years ago
- 711908e vold: not allowed to read sysfs_batteryinfo by Yifan Hong · 7 years ago
- ab82125 Improve tests protecting private app data by Jeff Vander Stoep · 7 years ago
- be31a68 Allow vendor_init to getattr vold_metadata_file. by Joel Galenson · 7 years ago
- 7a4af30 Start the process of locking down proc/net by Jeff Vander Stoep · 7 years ago
- 42bd163 Add metadata_file class for root of metadata folder. by Paul Crowley · 7 years ago
- d25ccab label /data/vendor{_ce,_de} by Jeff Vander Stoep · 8 years ago
- d9a4e06 Allow vendor_init and e2fs to enable metadata encryption by Paul Crowley · 8 years ago
- dcad0f0 vold: clarify sysfs access by Tri Vo · 8 years ago
- e497145 Whitelist exported platform properties by Jaekyun Seok · 8 years ago