aboutsummaryrefslogtreecommitdiffstats
path: root/recovery.te
Commit message (Expand)AuthorAgeFilesLines
* sepolicy: Fixup neverallows for non-shipping builds..Adnan Begovic2015-10-161-2/+8
* Allow recovery to read files with oemfs labelTao Bao2015-06-101-0/+3
* drop_caches label, vold scratch space on expanded.Jeff Sharkey2015-05-141-2/+1
* Replace unix_socket_connect() and explicit property sets with macroWilliam Roberts2015-05-071-3/+2
* am b76966d6: recovery: remove auditallow for exec_type:dir writesNick Kralevich2015-03-051-4/+2
|\
| * recovery: remove auditallow for exec_type:dir writesNick Kralevich2015-03-051-4/+2
* | am bd050a8e: Allow recovery to access kmsg for log retrievalPatrick Tjin2014-12-101-0/+2
|\ \ | |/ |/|
| * Allow recovery to access kmsg for log retrievalPatrick Tjin2014-12-091-0/+2
| * recovery: allow changing unlabeled symbolic linksNick Kralevich2014-10-231-1/+1
| * reconcile aosp (a7c04dcd748e1a9daf374551303a3bd578305cf9) after branching. Pl...Ed Heyl2014-07-141-2/+0
| * reconcile aosp (4da3bb1481e4e894a7dee3f3b9ec8cef6f6b1aed) after branching. Pl...Ed Heyl2014-07-141-6/+3
| * support newer-style adbd interface in recoveryDoug Zongker2014-07-101-1/+3
* | recovery.te: add /data neverallow rulesNick Kralevich2014-11-051-0/+17
* | recovery: allow changing unlabeled symbolic linksNick Kralevich2014-10-231-1/+1
* | Remove domain:process from unconfinedNick Kralevich2014-07-101-2/+0
* | support newer-style adbd interface in recoveryDoug Zongker2014-07-101-1/+3
* | Rename sdcard_internal/external types.Stephen Smalley2014-07-081-6/+3
|/
* recovery: allow read access to fuse filesystemNick Kralevich2014-07-081-0/+1
* recovery: start enforcing SELinux rulesNick Kralevich2014-07-071-1/+0
* recovery: allow relabelto unlabeled and other unlabeled rulesNick Kralevich2014-07-071-0/+5
* recovery: allow creating and reading fuse filesystemsDoug Zongker2014-07-021-0/+7
* Align SELinux property policy with init property_perms.Stephen Smalley2014-06-231-0/+3
* Remove execute_no_trans from unconfineddomain.Stephen Smalley2014-06-191-0/+4
* Address recovery denials.Stephen Smalley2014-06-191-2/+9
* Restrict use of context= mount options.Stephen Smalley2014-06-161-2/+3
* recovery: Allow exec_type on dirs, read for /devNick Kralevich2014-06-151-0/+11
* recovery: don't use single quoteNick Kralevich2014-06-091-1/+1
* Refine recovery domain.Nick Kralevich2014-06-071-1/+5
* refine recovery domain.Nick Kralevich2014-06-041-3/+8
* More recovery rulesNick Kralevich2014-06-041-2/+22
* recovery: enable permissive_or_unconfinedNick Kralevich2014-05-311-1/+1
* Create a separate recovery policy.Stephen Smalley2014-05-301-16/+27
* Clean up kernel, init, and recovery domains.Stephen Smalley2014-05-291-3/+4
* Remove /system write from unconfinedNick Kralevich2014-05-291-1/+5
* Restrict requesting contexts other than policy-defined defaults.Stephen Smalley2014-05-231-0/+3
* Drop unused rules for raw I/O and mknod.Stephen Smalley2014-05-141-4/+0
* Drop relabelto_domain() macro and its associated definitions.Stephen Smalley2014-05-091-1/+0
* Remove block device access from unconfined domains.Stephen Smalley2014-02-121-0/+3
* Remove several superuser capabilities from unconfined domains.Stephen Smalley2014-02-121-0/+4
* Remove mount-related permissions from unconfined domains.Stephen Smalley2014-02-111-0/+1
* Remove MAC capabilities from unconfined domains.Stephen Smalley2014-01-301-0/+2
* ashmem_device is a character device, not a regular file.Stephen Smalley2014-01-131-1/+1
* Allow recovery to execute ashmem_device and tmpfs.Stephen Smalley2014-01-131-1/+2
* Add a domain for the recovery console.Stephen Smalley2014-01-131-0/+11