aboutsummaryrefslogtreecommitdiff
AgeCommit message (Expand)Author
2014-08-21sepolicy: make shell domain can operate rootfs and unlabeled domain dirs and ...selinux-hacks-lavaYongqin Liu
2014-08-19app.te: make shell domain the be possible to have permission for networklinaro-armv8-14.08Yongqin Liu
2014-08-06Merge "Allow untrusted_app access to temporary apk files."dcashman
2014-08-06Allow untrusted_app access to temporary apk files.dcashman
2014-08-06Merge "Allow dumpstate to dump backtraces of certain native processes."Daniel Cashman
2014-08-05Make system use patchoat to relocate during runtime.Alex Light
2014-08-01Allow dumpstate to dump backtraces of certain native processes.Stephen Smalley
2014-08-01Merge "Generate selinux_policy.xml as part of CTS build."dcashman
2014-07-29Fix neverallow rules to eliminate CTS SELinuxTest warnings.Stephen Smalley
2014-07-28Generate selinux_policy.xml as part of CTS build.dcashman
2014-07-28Remove dumpstate from servicemanager list auditallow.Riley Spahn
2014-07-25Allow sdcardd to read /data/.layout_versionNick Kralevich
2014-07-24Define debuggerd class, permissions, and rules.Stephen Smalley
2014-07-23Merge "Add fine grained access control to DrmManagerService."Nick Kralevich
2014-07-24Add fine grained access control to DrmManagerService.Riley Spahn
2014-07-22Allow dumpstate to read /data/tombstones.Christopher Ferris
2014-07-22Merge "Update readme to reflect addition of SEPOLICY_IGNORE."dcashman
2014-07-22Update readme to reflect addition of SEPOLICY_IGNORE.dcashman
2014-07-21sepolicy: allow charger to read /sys/fs/pstore/console-ramoopsColin Cross
2014-07-21Prohibit execute to fs_type other than rootfs for most domains.Stephen Smalley
2014-07-17Merge "Further refined service_manager auditallow statements."Nick Kralevich
2014-07-18Further refined service_manager auditallow statements.Riley Spahn
2014-07-17Refine service_manager find auditallow statements.Riley Spahn
2014-07-17Add com.android.net.IProxyService to service_contexts.Riley Spahn
2014-07-17lmkd: avoid locking libsigchain into memoryNick Kralevich
2014-07-16Merge "dex2oat: fix forward-locked upgrades with unlabeled asecs"Nick Kralevich
2014-07-16dex2oat: fix forward-locked upgrades with unlabeled asecsNick Kralevich
2014-07-16Add MediaProjectionManagerService to service listMichael Wright
2014-07-16lmkd: allow lmkd to lock itself in memoryNick Kralevich
2014-07-16Add "webviewupdate" system server service.Torne (Richard Coles)
2014-07-15Merge "dex2oat: fix forward locked apps"Nick Kralevich
2014-07-16Remove auditallow from system_server.Riley Spahn
2014-07-16dex2oat: fix forward locked appsNick Kralevich
2014-07-15Merge "Remove radio_service from untrusted_app auditallow."Nick Kralevich
2014-07-15Remove radio_service from untrusted_app auditallow.Riley Spahn
2014-07-14lmkd: allow removing cgroups and setting self to SCHED_FIFOColin Cross
2014-07-14Tweak rules for su domain.Nick Kralevich
2014-07-14fix system_server dex2oat execNick Kralevich
2014-07-14Add access control for each service_manager action.Riley Spahn
2014-07-10Merge "Put dex2oat in it's own sandbox"Nick Kralevich
2014-07-11Allow oemfs search for system_server and bootanimTodd Poynor
2014-07-10Put dex2oat in it's own sandboxNick Kralevich
2014-07-10Remove domain:process from unconfinedNick Kralevich
2014-07-10support newer-style adbd interface in recoveryDoug Zongker
2014-07-10Merge "Rename sdcard_internal/external types."Nick Kralevich
2014-07-09Merge "install_recovery: start enforcing SELinux rules"Nick Kralevich
2014-07-09allow ueventd sysfs_type lnk_fileNick Kralevich
2014-07-09Drop sys_rawio neverallow for teeNick Kralevich
2014-07-09Don't use don'tNick Kralevich
2014-07-09ensure that untrusted_app can't set propertiesNick Kralevich