aboutsummaryrefslogtreecommitdiff
path: root/recovery.te
AgeCommit message (Expand)Author
2015-06-10Allow recovery to read files with oemfs labelTao Bao
2015-05-14drop_caches label, vold scratch space on expanded.Jeff Sharkey
2015-05-07Replace unix_socket_connect() and explicit property sets with macroWilliam Roberts
2015-03-05am b76966d6: recovery: remove auditallow for exec_type:dir writesNick Kralevich
2015-03-05recovery: remove auditallow for exec_type:dir writesNick Kralevich
2014-12-10am bd050a8e: Allow recovery to access kmsg for log retrievalPatrick Tjin
2014-12-09Allow recovery to access kmsg for log retrievalPatrick Tjin
2014-11-05recovery.te: add /data neverallow rulesNick Kralevich
2014-10-23recovery: allow changing unlabeled symbolic linksNick Kralevich
2014-10-23recovery: allow changing unlabeled symbolic linksNick Kralevich
2014-07-14reconcile aosp (a7c04dcd748e1a9daf374551303a3bd578305cf9) after branching. Pl...Ed Heyl
2014-07-14reconcile aosp (4da3bb1481e4e894a7dee3f3b9ec8cef6f6b1aed) after branching. Pl...Ed Heyl
2014-07-10support newer-style adbd interface in recoveryDoug Zongker
2014-07-10Remove domain:process from unconfinedNick Kralevich
2014-07-10support newer-style adbd interface in recoveryDoug Zongker
2014-07-08Rename sdcard_internal/external types.Stephen Smalley
2014-07-08recovery: allow read access to fuse filesystemNick Kralevich
2014-07-07recovery: start enforcing SELinux rulesNick Kralevich
2014-07-07recovery: allow relabelto unlabeled and other unlabeled rulesNick Kralevich
2014-07-02recovery: allow creating and reading fuse filesystemsDoug Zongker
2014-06-23Align SELinux property policy with init property_perms.Stephen Smalley
2014-06-19Remove execute_no_trans from unconfineddomain.Stephen Smalley
2014-06-19Address recovery denials.Stephen Smalley
2014-06-16Restrict use of context= mount options.Stephen Smalley
2014-06-15recovery: Allow exec_type on dirs, read for /devNick Kralevich
2014-06-09recovery: don't use single quoteNick Kralevich
2014-06-07Refine recovery domain.Nick Kralevich
2014-06-04refine recovery domain.Nick Kralevich
2014-06-04More recovery rulesNick Kralevich
2014-05-31recovery: enable permissive_or_unconfinedNick Kralevich
2014-05-30Create a separate recovery policy.Stephen Smalley
2014-05-29Clean up kernel, init, and recovery domains.Stephen Smalley
2014-05-29Remove /system write from unconfinedNick Kralevich
2014-05-23Restrict requesting contexts other than policy-defined defaults.Stephen Smalley
2014-05-14Drop unused rules for raw I/O and mknod.Stephen Smalley
2014-05-09Drop relabelto_domain() macro and its associated definitions.Stephen Smalley
2014-02-12Remove block device access from unconfined domains.Stephen Smalley
2014-02-12Remove several superuser capabilities from unconfined domains.Stephen Smalley
2014-02-11Remove mount-related permissions from unconfined domains.Stephen Smalley
2014-01-30Remove MAC capabilities from unconfined domains.Stephen Smalley
2014-01-13ashmem_device is a character device, not a regular file.Stephen Smalley
2014-01-13Allow recovery to execute ashmem_device and tmpfs.Stephen Smalley
2014-01-13Add a domain for the recovery console.Stephen Smalley