index
:
android_external_sepolicy
caf/cm-12.0
caf/cm-12.1
cm-10.1
cm-10.2
cm-11.0
cm-12.0
cm-12.1
cm-13.0
jellybean
jellybean-stable
mr1.1-staging
shipping/cm-11.0
stable/cm-10.2
stable/cm-11.0
stable/cm-11.0-XNF8Y
stable/cm-11.0-XNF9X
stable/cm-11.0-XNG2S
stable/cm-11.0-XNG3C
stable/cm-12.0-YNG1I
stable/cm-12.0-YNG1T
stable/cm-12.0-YNG1TA
stable/cm-12.0-YNG3C
stable/cm-12.0-YNG4N
stable/cm-12.1-YOG3C
stable/cm-12.1-YOG4P
stable/cm-12.1-YOG7D
stable/cm-13.0-ZNH0E
stable/cm-13.0-ZNH2K
stable/cm-13.0-ZNH2KB
stable/cm-13.0-ZNH5Y
staging/cm-12.0-caf
staging/cm-12.1
staging/cm-13.0+r22
Unnamed repository; edit this file 'description' to name the repository.
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
domain.te
Commit message (
Expand
)
Author
Age
Files
Lines
*
Revisit kernel setenforce
Nick Kralevich
2014-05-12
1
-1
/
+2
*
Drop relabelto_domain() macro and its associated definitions.
Stephen Smalley
2014-05-09
1
-3
/
+0
*
Drop rw access to unlabeled files.
Stephen Smalley
2014-05-08
1
-17
/
+3
*
Audit accesses on unlabeled files.
Stephen Smalley
2014-04-18
1
-0
/
+3
*
Define a type for /data/dalvik-cache/profiles.
Stephen Smalley
2014-04-09
1
-0
/
+2
*
Deduplicate neverallow rules on selinuxfs operations.
Stephen Smalley
2014-03-10
1
-0
/
+8
*
Allow all domains to read from socket_device directory.
Robert Craig
2014-03-06
1
-1
/
+1
*
Address system_server denials.
Stephen Smalley
2014-03-05
1
-0
/
+2
*
Clean up socket rules.
Stephen Smalley
2014-02-25
1
-1
/
+2
*
Allow reading of /data/security/current symlink.
Stephen Smalley
2014-02-24
1
-1
/
+2
*
initial policy for uncrypt.
Nick Kralevich
2014-02-19
1
-2
/
+2
*
Remove block device access from unconfined domains.
Stephen Smalley
2014-02-12
1
-1
/
+1
*
Remove several superuser capabilities from unconfined domains.
Stephen Smalley
2014-02-12
1
-0
/
+10
*
Remove mount-related permissions from unconfined domains.
Stephen Smalley
2014-02-11
1
-0
/
+5
*
Introduce asec_public_file type.
Robert Craig
2014-02-11
1
-0
/
+4
*
sepolicy: Add write_logd, read_logd & control_logd
Mark Salyzyn
2014-02-04
1
-0
/
+3
*
assert: Do not allow access to generic device:chr_file
William Roberts
2014-02-03
1
-0
/
+5
*
assert: do not allow raw access to generic block_device
William Roberts
2014-02-03
1
-0
/
+4
*
Remove MAC capabilities from unconfined domains.
Stephen Smalley
2014-01-30
1
-0
/
+3
*
Support running adbd in the su domain.
Nick Kralevich
2014-01-23
1
-0
/
+14
*
Drop legacy device types.
Stephen Smalley
2014-01-16
1
-1
/
+0
*
Remove domain init:unix_stream_socket connectto permission.
Stephen Smalley
2014-01-09
1
-3
/
+0
*
Allow access to unlabeled socket and fifo files.
Stephen Smalley
2014-01-09
1
-2
/
+1
*
Remove unlabeled execute access from domain, add to appdomain.
Stephen Smalley
2014-01-09
1
-1
/
+1
*
Restrict ability to set checkreqprot.
Stephen Smalley
2014-01-08
1
-1
/
+1
*
Create proc_net type for /proc/sys/net entries.
Robert Craig
2014-01-07
1
-0
/
+1
*
Don't allow zygote init:binder call
Nick Kralevich
2014-01-03
1
-0
/
+4
*
Address adb backup/restore denials.
Stephen Smalley
2014-01-03
1
-1
/
+2
*
Remove execmem permission from domain, add to appdomain.
Stephen Smalley
2014-01-02
1
-1
/
+1
*
Confine shell domain in -user builds only.
Stephen Smalley
2013-12-18
1
-5
/
+8
*
Label /data/misc/zoneinfo
Nick Kralevich
2013-12-13
1
-0
/
+3
*
Restrict ptrace access by debuggerd and unconfineddomain.
Stephen Smalley
2013-12-09
1
-0
/
+3
*
Allow kernel domain, not init domain, to set SELinux enforcing mode.
Stephen Smalley
2013-12-06
1
-2
/
+11
*
Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode."
Nick Kralevich
2013-12-06
1
-11
/
+2
*
Allow kernel domain, not init domain, to set SELinux enforcing mode.
Stephen Smalley
2013-12-06
1
-2
/
+11
*
Restrict the ability to set usermodehelpers and proc security settings.
Stephen Smalley
2013-12-06
1
-0
/
+5
*
Drop tegra specific label from policy.
Robert Craig
2013-12-05
1
-1
/
+0
*
Restrict the ability to set SELinux enforcing mode to init.
Stephen Smalley
2013-12-02
1
-2
/
+2
*
Neverallow access to the kmem device from userspace.
Geremy Condra
2013-11-07
1
-0
/
+4
*
Move goldfish-specific rules to their own directory.
Stephen Smalley
2013-11-06
1
-6
/
+0
*
Move sysfs_devices_system_cpu to the central policy.
Nick Kralevich
2013-10-30
1
-0
/
+1
*
Start confining ueventd
William Roberts
2013-10-08
1
-2
/
+2
*
Restrict access to /dev/hw_random to system_server and init.
Alex Klyubin
2013-10-03
1
-0
/
+3
*
Make sure exec_type is assigned to all entrypoint types.
Stephen Smalley
2013-09-27
1
-0
/
+3
*
1/2: Rename domain "system" to "system_server".
Alex Klyubin
2013-09-17
1
-1
/
+1
*
Remove sys_nice capability from domains.
Stephen Smalley
2013-09-13
1
-3
/
+0
*
Drop domain write access to sysfs for the emulator.
Stephen Smalley
2013-09-13
1
-2
/
+1
*
Permit writing to /dev/random and /dev/urandom.
Alex Klyubin
2013-09-10
1
-2
/
+2
*
Fix denials encountered while getting bugreports.
Geremy Condra
2013-08-30
1
-1
/
+1
*
Only init should be able to load a security policy
Nick Kralevich
2013-07-15
1
-0
/
+7
[next]