aboutsummaryrefslogtreecommitdiffstats
path: root/domain.te
Commit message (Expand)AuthorAgeFilesLines
* am a331c593: am 5aac86dc: Revert "Revert "SELinux policy changes for re-execi...Elliott Hughes2015-04-241-1/+2
|\
| * Revert "Revert "SELinux policy changes for re-execing init.""Elliott Hughes2015-04-241-1/+2
* | am 6b82aaeb: am 6d97d9b8: Merge "Revert "SELinux policy changes for re-execin...Nick Kralevich2015-04-241-2/+1
|\|
| * Revert "SELinux policy changes for re-execing init."Nick Kralevich2015-04-241-2/+1
* | am f17bbab7: am ecd57731: Merge "SELinux policy changes for re-execing init."Elliott Hughes2015-04-241-1/+2
|\|
| * SELinux policy changes for re-execing init.Elliott Hughes2015-04-231-1/+2
* | Merge "Remove recovery from mknod neverallow rule"Nick Kralevich2015-04-151-1/+1
|\ \
| * | Remove recovery from mknod neverallow ruleNick Kralevich2015-04-141-1/+1
* | | am 38885bc4: am e96c3abe: Add neverallow for mounting on procdcashman2015-04-141-0/+2
|\ \ \ | |/ / |/| / | |/
| * Add neverallow for mounting on procdcashman2015-04-141-0/+2
* | am 29f90b1e: am 7f2bb0c1: Merge "Enforce more specific service access."dcashman2015-04-091-3/+0
|\|
| * Enforce more specific service access.dcashman2015-04-091-3/+0
* | am 41c5ead3: am b62b2020: Merge "domain: relax execmod restrictions"Nick Kralevich2015-04-021-1/+4
|\|
| * domain: relax execmod restrictionsNick Kralevich2015-04-011-1/+4
| * Adding e4crypt supportPaul Lawrence2015-03-271-0/+1
* | am 1df53474: am a7eb161e: Merge "add neverallow rules for execmod"Nick Kralevich2015-03-251-0/+15
|\|
| * add neverallow rules for execmodNick Kralevich2015-03-241-0/+15
* | am 671d16fe: am 581f25b0: Merge "Add new "procrank" SELinux domain."Nick Kralevich2015-03-191-1/+8
|\|
| * Add new "procrank" SELinux domain.Nick Kralevich2015-03-191-1/+8
* | am f836abef: am 8bd13687: neverallow su_exec:file executeNick Kralevich2015-03-151-0/+5
|\|
| * neverallow su_exec:file executeNick Kralevich2015-03-141-0/+5
* | Adding e4crypt supportPaul Lawrence2015-03-131-0/+1
* | am 1193bdf4: am 6843a793: am 8f81dcad: Only allow system_server to send comma...dcashman2015-03-101-0/+4
|\|
| * Only allow system_server to send commands to zygote.dcashman2015-03-091-0/+4
* | Revert "Allow recovery to create device nodes and modify rootfs"Nick Kralevich2015-03-021-2/+2
|/
* Allow init to execute /sbin/slideshowSami Tolvanen2015-02-261-1/+1
* Revert /proc/net related changesNick Kralevich2015-02-251-2/+1
* sepolicy: remove block_device access from install_recoveryStephen Smalley2015-02-241-1/+1
* neverallow mounton lnk_file fifo_file sock_fileNick Kralevich2015-02-231-0/+4
* domain.te: neverallow System V IPC classesNick Kralevich2015-02-111-0/+18
* Remove service_manager_type auditing of shell source domain.dcashman2015-02-061-1/+1
* don't allow mounting on top of /system files/directoriesNick Kralevich2015-02-051-0/+3
* Add compile time checks for /data/dalvik-cache accessNick Kralevich2015-01-301-0/+10
* domain.te: allow /proc/net/psched accessNick Kralevich2015-01-221-0/+2
* remove /proc/net read access from domain.teNick Kralevich2015-01-141-1/+0
* Make system_server_service an attribute.dcashman2015-01-141-0/+3
* Restrict service_manager find and list access.dcashman2014-12-151-5/+0
* Add neverallow rule for set_context_mgr.dcashman2014-12-101-0/+3
* Revert " Add neverallow rule for set_context_mgr."dcashman2014-12-091-3/+0
* Add neverallow rule for set_context_mgr.dcashman2014-12-051-0/+3
* Allow recovery to create device nodes and modify rootfsNick Kralevich2014-11-071-2/+2
* recovery.te: add /data neverallow rulesNick Kralevich2014-11-051-2/+2
* allow coredump functionalityNick Kralevich2014-10-311-0/+4
* Remove -unconfineddomain from neverallow rules.Stephen Smalley2014-10-211-5/+6
* Remove block_device:blk_file access from fsck.Stephen Smalley2014-10-211-1/+1
* Define specific block device types for system and recovery partitions.Stephen Smalley2014-10-021-0/+6
* Do not allow init to execute anything without changing domains.Stephen Smalley2014-09-281-1/+5
* zygote: allow replacing /proc/cpuinfoNick Kralevich2014-09-261-0/+1
* Add support for factory reset protection.dcashman2014-09-191-0/+2
* Remove /dev/log/* accessNick Kralevich2014-09-181-2/+0