- 48e5326 Allow init to update /metadata/tradeinmode/wipe by David Anderson · 5 months ago
- 840b607 Policy for overlay_remounter by Paul Lawrence · 7 months ago
- 874e974 Revert "Policy for overlay_remounter" by Paul Lawrence · 7 months ago
- 879909f Policy for overlay_remounter by Paul Lawrence · 8 months ago
- 419f7a7 Give init and dumpstate access to /proc/allocinfo by Alessio Balsini · 9 months ago
- 5fadae6 Merge "sepolicy: allow init to share a kallsyms fd with tracing daemons" into main by Ryan Savitski · 9 months ago
- 4cd0994 sepolicy: allow init to share a kallsyms fd with tracing daemons by Ryan Savitski · 9 months ago
- 6154425 Add prop to control PM appcompat by Pawan Wagh · 9 months ago
- 0e30a88 Revert^2 "Add mmd selinux policies for zram setup" by Hung Nguyen · 9 months ago
- 96f236b Merge changes from topic "revert-3316655-MWSNJIMVUE" into main by Bo Hu · 9 months ago
- c2449d3 Revert "Update netlink_audit_socket for nlmsg xperm" by Bo Hu · 9 months ago
- d3cde70 Merge "Revert "Add mmd selinux policies for zram setup"" into main by Satish Yalla · 9 months ago
- 4320235 Revert "Add mmd selinux policies for zram setup" by Satish Yalla · 9 months ago
- 2a6044f Merge "Add mmd selinux policies for zram setup" into main by Treehugger Robot · 9 months ago
- be9c526 Add mmd selinux policies for zram setup by Hung Nguyen · 10 months ago
- d9cc9ac Merge changes I2521cdaa,Idf9eeded,Iede0b259,Ifc5b2ab7,Ib7bb1c9e, ... into main by Thiébaud Weksteen · 9 months ago
- 5bc9bb8 Update netlink_audit_socket for nlmsg xperm by Thiébaud Weksteen · 12 months ago
- 4ba2c4b Add tunables to control prefetch by Akilesh Kailash · 10 months ago
- dd8c090 Prefetch: Add sepolicy to control prefetch properties by Akilesh Kailash · 10 months ago
- f0945b6 Allow init to chown sysfs_firmware_acpi_tables by Rob Barnes · 10 months ago
- c4d0eb2 Revert "Allow init to chown sysfs_firmware_acpi_tables" by Rob Barnes · 10 months ago
- 55c17f2 Collapse cgroup_desc_api_file into cgroup_desc_file by T.J. Mercier · 11 months ago
- 92d3e2b Allow init to chown sysfs_firmware_acpi_tables by Rob Barnes · 11 months ago
- d6889d6 Merge "Allow debugfs_wifi_tracing to create dir" into main by Nate Jiang · 11 months ago
- f3fb64a sepolicy: add rules for bionic.linker.16kb.app_compat.enabled by Kalesh Singh · 1 year ago
- 0b9625d Add labels and permissions for /mnt/vm by Inseob Kim · 1 year, 1 month ago
- dbca625 Revert "sepolicy: remove all remaining qtaguid stuff." by Bart Sears · 1 year, 1 month ago
- af08bd3 sepolicy: remove all remaining qtaguid stuff. by Maciej Żenczykowski · 1 year, 1 month ago
- 3ea355c Allow debugfs_wifi_tracing to create dir by Nate Jiang · 1 year, 3 months ago
- 5f805d0 Merge "sepolicy: Add rules for /sys/kernel/mm/pgsize_migration/enabled" into main by Kalesh Singh · 1 year, 4 months ago
- 3a4c68d sepolicy: Add rules for /sys/kernel/mm/pgsize_migration/enabled by Kalesh Singh · 1 year, 5 months ago
- 27b515e Add SELinux policy for storage areas by Ellen Arteca · 1 year, 4 months ago
- 75806ef Minimize public policy by Inseob Kim · 1 year, 5 months ago
- 8dff040 Revert "Suppress a denial on VM boot" by Nate Myren · 1 year, 11 months ago
- faa538d Suppress a denial on VM boot by Alan Stokes · 1 year, 11 months ago
- ae5869a Introduce vm_manager_device_type for crosvm by Elliot Berman · 2 years, 6 months ago
- 84bb5ee Adjust policy for hypervisor system properties by Keir Fraser · 2 years, 10 months ago
- f0ea953 Fastboot AIDL Sepolicy changes by Sandeep Dhavale · 2 years, 10 months ago
- e6da3b8 Add SEPolicy for PRNG seeder daemon. by Pete Bentley · 3 years ago
- 19a5785 Allow init to launch BootControlHAL in recovery by Kelvin Zhang · 3 years ago
- 8bfdd82 Allow the remote provisioner app to set rkp_only properties by Seth Moore · 3 years, 5 months ago
- aaacfdb Add ro.remote_provisioning.*.rkp_only properties. by Max Bires · 3 years, 7 months ago
- 705db2b recovery init domain_trans to health HAL. by Yifan Hong · 3 years, 10 months ago
- 28f9b97 Merge changes from topic "servicemanager-recovery" by Yifan Hong · 3 years, 10 months ago
- d6b2901 Add recovery service_contexts files. by Yifan Hong · 3 years, 10 months ago
- 9e6dcd7 Merge "sepolicy: Allow creating synthetic trace events" by Kalesh Singh · 3 years, 10 months ago
- fab8e1c sepolicy: Allow creating synthetic trace events by Kalesh Singh · 3 years, 10 months ago
- aabea20 Remove healthd. by Yifan Hong · 3 years, 11 months ago
- 398b0af Stop using the bdev_type and sysfs_block_type SELinux attributes by Bart Van Assche · 3 years, 11 months ago
- 60b7d9a Revert "Stop granting init access to block device properties" by Bart Van Assche · 3 years, 11 months ago
- f20fea5 Stop granting init access to block device properties by Bart Van Assche · 4 years ago
- 645c390 Introduce ro.boot.hypervisor properties by Enrico Granata · 4 years ago
- 6ad5659 Revert "Add userspace_panic_device and userpanic_use" by Woody Lin · 4 years ago
- 7ed2456 Add userspace_panic_device and userpanic_use by Woody Lin · 4 years, 1 month ago
- ec50aa5 Allow the init and apexd processes to read all block device properties by Bart Van Assche · 4 years, 1 month ago
- 9059e21 init.te: Allow init to modify the properties of loop devices by Bart Van Assche · 4 years, 1 month ago
- 3b6a385 Merge "Add crosvm domain and give virtmanager and crosvm necessary permissions." by Andrew Walbran · 4 years, 5 months ago
- a995e84 Add crosvm domain and give virtmanager and crosvm necessary permissions. by Andrew Walbran · 4 years, 5 months ago
- b62be12 Allow apexd to access a new dev_type: virtual disk by Jooyung Han · 4 years, 5 months ago
- 3ccbebb Permit dropping caches from the shell through sys.drop_caches. by Michael Rosenfeld · 4 years, 7 months ago
- 85acf6e Fix broken neverallow rules by Inseob Kim · 4 years, 6 months ago
- 3d52817 Selinux policy for bootreceiver tracing instance by Alexander Potapenko · 4 years, 6 months ago
- 08a25e6 Revert "Selinux policy for bootreceiver tracing instance" by Wonsik Kim · 4 years, 6 months ago
- 31251aa Selinux policy for bootreceiver tracing instance by Alexander Potapenko · 4 years, 6 months ago
- 28befc8 Merge "init sets keystore.boot_level, keystore reads" by Paul Crowley · 4 years, 6 months ago
- b0c5571 init sets keystore.boot_level, keystore reads by Paul Crowley · 4 years, 7 months ago
- d84b67e Fix missing domain transition for snapuserd in recovery. by David Anderson · 4 years, 7 months ago
- 0c0c13a init: Allow interacting with snapuserd and libsnapshot. by David Anderson · 4 years, 10 months ago
- 40c67b2 Remove exported2_default_prop by Inseob Kim · 5 years ago
- 8c34247 Add bootloader_prop for ro.boot. properties by Inseob Kim · 5 years ago
- 212e2b6 Add property contexts for vts props by Inseob Kim · 5 years ago
- 178f0ac Add new perfmon capability2 and use it by Alistair Delva · 5 years ago
- 44f5ffc Add userspace_reboot_log_prop by Nikita Ioffe · 6 years ago
- 52b3d31 Add sysprop for init's perf_event_open LSM hook check by Ryan Savitski · 6 years ago
- b8f4e92 Merge "Allow linkerconfig to be executed from recovery" by Kiyoung Kim · 6 years ago
- 2c271aa Allow linkerconfig to be executed from recovery by Kiyoung Kim · 6 years ago
- 23ba976 Allow init to read /sys/block/dm-XX/dm/name by Nikita Ioffe · 6 years ago
- 7065e46 Add selinux rules for userspace reboot related properties by Nikita Ioffe · 6 years ago
- ecc7e8c Move /sbin/charger to /system/bin/charger. by Tao Bao · 7 years ago
- 147cf64 Allow executing bpfloader from init and modify rules by Joel Fernandes · 7 years ago
- d36b1d5 Allow init to set powerctl property by Branden Archer · 7 years ago
- 1d85efa Add sepolicy for fastbootd by Jerry Zhang · 7 years ago
- c2ab15b Revert "Add sepolicy for fastbootd" by Florian Mayer · 7 years ago
- 0fd3ed3 Add sepolicy for fastbootd by Jerry Zhang · 7 years ago
- 938ab05 Allow init to execute services marked with seclabel u:r:su:s0 in userdebug/eng by Tom Cherry · 7 years ago
- d840374 Move watchdogd out of init and into its own domain by Tom Cherry · 7 years ago
- 06bac37 Installd doesn't need to create cgroup files. by Alan Stokes · 7 years ago
- 832a704 Suppress harmless denials for file creation in cgroupfs. by Alan Stokes · 7 years ago
- 621c24c add vendor_init.te by Tom Cherry · 8 years ago
- 4de505b allow init to run mke2fs tools to format partitions by Jin Qian · 8 years ago
- 5846c79 Moving adbd from rootdir to system/bin by Bowgo Tsai · 8 years ago
- e41af20 Fix coredomain violation for modprobe by Sandeep Patil · 8 years ago
- d46b5d3 Allow init to run vendor toybox for modprobe by Sandeep Patil · 8 years ago
- f693113 SELinux changes for Treble Loadable Kernel Module by Howard Chen · 8 years ago
- f5446eb Vendor domains must not use Binder by Alex Klyubin · 8 years ago
- d363b0f enabled /sbin/modprobe for recovery mode by Jaesoo Lee · 9 years ago
- e9cb763 Remove selinux denial by Paul Lawrence · 9 years ago
- da62cb4 logcat: introduce split to logd and logpersist domains by Mark Salyzyn · 9 years ago
- 137a13d healthd: restore healthd sepolicy for charger mode by Sandeep Patil · 9 years ago
- dc08245 healthd: create SEPolicy for 'charger' and reduce healthd's scope by Sandeep Patil · 9 years ago