aboutsummaryrefslogtreecommitdiffstats
path: root/unconfined.te
Commit message (Expand)AuthorAgeFilesLines
* Remove block device access from unconfined domains.Stephen Smalley2014-02-121-1/+1
* Remove several superuser capabilities from unconfined domains.Stephen Smalley2014-02-121-1/+1
* Remove mount-related permissions from unconfined domains.Stephen Smalley2014-02-111-1/+0
* Remove MAC capabilities from unconfined domains.Stephen Smalley2014-01-301-1/+2
* Remove transition / dyntransition from unconfinedNick Kralevich2014-01-271-1/+1
* Revert "Revert "Strip file execute permissions from unconfined domains.""Stephen Smalley2014-01-131-3/+4
* Revert "Revert "Strip exec* permissions from unconfined domains.""Stephen Smalley2014-01-131-4/+4
* Revert "Strip exec* permissions from unconfined domains."Nick Kralevich2014-01-101-4/+4
* Strip exec* permissions from unconfined domains.Stephen Smalley2014-01-081-4/+4
* Restrict ability to set checkreqprot.Stephen Smalley2014-01-081-1/+1
* Don't allow zygote init:binder callNick Kralevich2014-01-031-1/+1
* Restrict mapping low memory.Stephen Smalley2013-12-091-1/+0
* Restrict ptrace access by debuggerd and unconfineddomain.Stephen Smalley2013-12-091-1/+1
* Restrict the ability to set usermodehelpers and proc security settings.Stephen Smalley2013-12-061-1/+3
* Restrict the ability to set SELinux enforcing mode to init.Stephen Smalley2013-12-021-1/+1
* Neverallow access to the kmem device from userspace.Geremy Condra2013-11-071-1/+1
* Clarify the expectations for the unconfined template.Nick Kralevich2013-10-211-0/+18
* Only init should be able to load a security policyNick Kralevich2013-07-151-1/+1
* domain.te: Add backwards compatibility for unlabeled filesNick Kralevich2013-07-101-2/+2
* Clean up remaining denials.repo sync2013-05-221-1/+1
* Make all domains unconfined.repo sync2013-05-201-1/+1
* Require entrypoint to be explicitly granted for unconfined domains.Stephen Smalley2013-03-211-3/+2
* Update binder-related policy.Stephen Smalley2013-03-191-1/+1
* Add policy for property service.Stephen Smalley2012-04-041-0/+1
* SE Android policy.Stephen Smalley2012-01-041-0/+23