index
:
android_external_sepolicy
caf/cm-12.0
caf/cm-12.1
cm-10.1
cm-10.2
cm-11.0
cm-12.0
cm-12.1
cm-13.0
jellybean
jellybean-stable
mr1.1-staging
shipping/cm-11.0
stable/cm-10.2
stable/cm-11.0
stable/cm-11.0-XNF8Y
stable/cm-11.0-XNF9X
stable/cm-11.0-XNG2S
stable/cm-11.0-XNG3C
stable/cm-12.0-YNG1I
stable/cm-12.0-YNG1T
stable/cm-12.0-YNG1TA
stable/cm-12.0-YNG3C
stable/cm-12.0-YNG4N
stable/cm-12.1-YOG3C
stable/cm-12.1-YOG4P
stable/cm-12.1-YOG7D
stable/cm-13.0-ZNH0E
stable/cm-13.0-ZNH2K
stable/cm-13.0-ZNH2KB
stable/cm-13.0-ZNH5Y
staging/cm-12.0-caf
staging/cm-12.1
staging/cm-13.0+r22
Unnamed repository; edit this file 'description' to name the repository.
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
te_macros
Commit message (
Expand
)
Author
Age
Files
Lines
*
Further restrict socket ioctls available to apps
Jeff Vander Stoep
2016-05-27
1
-1
/
+1
*
Remove service_manager_local_audit_domain.
dcashman
2015-06-08
1
-8
/
+0
*
Allow /dev/klog access, drop mknod and __null__ access
Nick Kralevich
2015-06-08
1
-11
/
+0
*
Replace unix_socket_connect() and explicit property sets with macro
William Roberts
2015-05-07
1
-0
/
+20
*
logd: allow access to system files
Mark Salyzyn
2015-03-11
1
-3
/
+0
*
Allow platform_app access to keystore.
dcashman
2015-03-02
1
-0
/
+1
*
Delete unconfined domain
Nick Kralevich
2015-02-28
1
-22
/
+0
*
Make system_server_service an attribute.
dcashman
2015-01-14
1
-1
/
+0
*
selinux: add pstore
Mark Salyzyn
2015-01-14
1
-0
/
+1
*
Dependencies for new goldfish service domains.
Stephen Smalley
2014-09-27
1
-1
/
+2
*
Add fine grained access control to DrmManagerService.
Riley Spahn
2014-07-24
1
-0
/
+10
*
Add access control for each service_manager action.
Riley Spahn
2014-07-14
1
-0
/
+13
*
Adding policies for KeyStore MAC.
Riley Spahn
2014-06-26
1
-0
/
+12
*
Eliminate some duplicated rules.
Stephen Smalley
2014-06-17
1
-17
/
+0
*
Don't grant domain device:dir rw_dir_perms
Nick Kralevich
2014-06-04
1
-4
/
+1
*
Create a separate recovery policy.
Stephen Smalley
2014-05-30
1
-0
/
+6
*
Introduce wakelock_use()
Nick Kralevich
2014-05-23
1
-0
/
+10
*
Drop relabelto_domain() macro and its associated definitions.
Stephen Smalley
2014-05-09
1
-7
/
+0
*
Coalesce shared_app, media_app, release_app into untrusted_app.
Stephen Smalley
2014-04-04
1
-8
/
+0
*
Allow domains to stat and open their entrypoint executables.
Stephen Smalley
2014-03-26
1
-1
/
+1
*
sepolicy: Add write_logd, read_logd & control_logd
Mark Salyzyn
2014-02-04
1
-9
/
+32
*
Support forcing permissive domains to unconfined.
Nick Kralevich
2014-01-11
1
-0
/
+11
*
Create new conditional userdebug_or_eng
Nick Kralevich
2014-01-09
1
-0
/
+6
*
Only allow PROT_EXEC for ashmem where required.
Stephen Smalley
2014-01-02
1
-4
/
+3
*
Restrict the ability to set SELinux enforcing mode to init.
Stephen Smalley
2013-12-02
1
-6
/
+2
*
Allow write access to ashmem allocated regions
Nick Kralevich
2013-11-27
1
-1
/
+1
*
Clarify the expectations for the unconfined template.
Nick Kralevich
2013-10-21
1
-1
/
+3
*
Isolate untrusted app ptys from other domains.
Stephen Smalley
2013-09-27
1
-0
/
+14
*
write_klog also requires write permission to the directory.
Stephen Smalley
2013-09-10
1
-1
/
+1
*
Allow access to /data/security/current symbolic link.
Stephen Smalley
2013-09-10
1
-1
/
+3
*
domain.te: Add backwards compatibility for unlabeled files
Nick Kralevich
2013-07-10
1
-0
/
+7
*
am 50e37b93: Move domains into per-domain permissive mode.
gcondra@google.com
2013-05-15
1
-0
/
+1
|
\
|
*
Move domains into per-domain permissive mode.
repo sync
2013-05-14
1
-0
/
+1
*
|
resolved conflicts for merge of 77ec892b to jb-mr2-dev-plus-aosp
Alex Klyubin
2013-05-09
1
-0
/
+11
|
\
|
|
*
SELinux policy for users of libcutils klog_write.
Alex Klyubin
2013-05-09
1
-0
/
+11
|
*
Give domains read access to security_file domain.
William Roberts
2013-04-05
1
-3
/
+1
*
|
Add non_system_app_set
William Roberts
2013-05-02
1
-0
/
+5
*
|
Give domains read access to security_file domain.
William Roberts
2013-04-05
1
-3
/
+1
|
/
*
Move policy files
William Roberts
2013-03-22
1
-0
/
+62
*
Update binder-related policy.
Stephen Smalley
2013-03-19
1
-13
/
+6
*
Only enforce per-app process and file isolation via SELinux for third party a...
Stephen Smalley
2012-07-27
1
-0
/
+8
*
Policy changes to support running the latest CTS.
Stephen Smalley
2012-03-07
1
-3
/
+0
*
Allow Settings to set enforcing and booleans if settings_manage_selinux is true.
Stephen Smalley
2012-02-02
1
-0
/
+18
*
Allow reading of properties area, which is now created before init has switch...
Stephen Smalley
2012-01-12
1
-0
/
+3
*
SE Android policy.
Stephen Smalley
2012-01-04
1
-0
/
+207