aboutsummaryrefslogtreecommitdiffstats
path: root/kernel.te
Commit message (Expand)AuthorAgeFilesLines
* Restrict requesting contexts other than policy-defined defaults.Stephen Smalley2014-05-231-0/+2
* Drop unused rules for raw I/O, mknod, and block device access.Stephen Smalley2014-05-141-7/+0
* Revisit kernel setenforceNick Kralevich2014-05-121-1/+3
* Drop relabelto_domain() macro and its associated definitions.Stephen Smalley2014-05-091-1/+0
* Remove block device access from unconfined domains.Stephen Smalley2014-02-121-0/+2
* Remove several superuser capabilities from unconfined domains.Stephen Smalley2014-02-121-0/+5
* Remove mount-related permissions from unconfined domains.Stephen Smalley2014-02-111-0/+1
* Remove transition / dyntransition from unconfinedNick Kralevich2014-01-271-0/+3
* Restrict ability to set checkreqprot.Stephen Smalley2014-01-081-0/+3
* Allow kernel domain, not init domain, to set SELinux enforcing mode.Stephen Smalley2013-12-061-0/+3
* Revert "Allow kernel domain, not init domain, to set SELinux enforcing mode."Nick Kralevich2013-12-061-3/+0
* Allow kernel domain, not init domain, to set SELinux enforcing mode.Stephen Smalley2013-12-061-0/+3
* Make kernel / init enforcingNick Kralevich2013-11-081-1/+0
* Fix more long-tail denials.Geremy Condra2013-09-051-0/+1
* domain.te: Add backwards compatibility for unlabeled filesNick Kralevich2013-07-101-0/+3
* Move domains into per-domain permissive mode.repo sync2013-05-141-0/+1
* SE Android policy.Stephen Smalley2012-01-041-0/+4