index
:
android_external_sepolicy
caf/cm-12.0
caf/cm-12.1
cm-10.1
cm-10.2
cm-11.0
cm-12.0
cm-12.1
cm-13.0
jellybean
jellybean-stable
mr1.1-staging
shipping/cm-11.0
stable/cm-10.2
stable/cm-11.0
stable/cm-11.0-XNF8Y
stable/cm-11.0-XNF9X
stable/cm-11.0-XNG2S
stable/cm-11.0-XNG3C
stable/cm-12.0-YNG1I
stable/cm-12.0-YNG1T
stable/cm-12.0-YNG1TA
stable/cm-12.0-YNG3C
stable/cm-12.0-YNG4N
stable/cm-12.1-YOG3C
stable/cm-12.1-YOG4P
stable/cm-12.1-YOG7D
stable/cm-13.0-ZNH0E
stable/cm-13.0-ZNH2K
stable/cm-13.0-ZNH2KB
stable/cm-13.0-ZNH5Y
staging/cm-12.0-caf
staging/cm-12.1
staging/cm-13.0+r22
Unnamed repository; edit this file 'description' to name the repository.
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
unconfined.te
Commit message (
Expand
)
Author
Age
Files
Lines
*
Remove block device access from unconfined domains.
Stephen Smalley
2014-02-12
1
-1
/
+1
*
Remove several superuser capabilities from unconfined domains.
Stephen Smalley
2014-02-12
1
-1
/
+1
*
Remove mount-related permissions from unconfined domains.
Stephen Smalley
2014-02-11
1
-1
/
+0
*
Remove MAC capabilities from unconfined domains.
Stephen Smalley
2014-01-30
1
-1
/
+2
*
Remove transition / dyntransition from unconfined
Nick Kralevich
2014-01-27
1
-1
/
+1
*
Revert "Revert "Strip file execute permissions from unconfined domains.""
Stephen Smalley
2014-01-13
1
-3
/
+4
*
Revert "Revert "Strip exec* permissions from unconfined domains.""
Stephen Smalley
2014-01-13
1
-4
/
+4
*
Revert "Strip exec* permissions from unconfined domains."
Nick Kralevich
2014-01-10
1
-4
/
+4
*
Strip exec* permissions from unconfined domains.
Stephen Smalley
2014-01-08
1
-4
/
+4
*
Restrict ability to set checkreqprot.
Stephen Smalley
2014-01-08
1
-1
/
+1
*
Don't allow zygote init:binder call
Nick Kralevich
2014-01-03
1
-1
/
+1
*
Restrict mapping low memory.
Stephen Smalley
2013-12-09
1
-1
/
+0
*
Restrict ptrace access by debuggerd and unconfineddomain.
Stephen Smalley
2013-12-09
1
-1
/
+1
*
Restrict the ability to set usermodehelpers and proc security settings.
Stephen Smalley
2013-12-06
1
-1
/
+3
*
Restrict the ability to set SELinux enforcing mode to init.
Stephen Smalley
2013-12-02
1
-1
/
+1
*
Neverallow access to the kmem device from userspace.
Geremy Condra
2013-11-07
1
-1
/
+1
*
Clarify the expectations for the unconfined template.
Nick Kralevich
2013-10-21
1
-0
/
+18
*
Only init should be able to load a security policy
Nick Kralevich
2013-07-15
1
-1
/
+1
*
domain.te: Add backwards compatibility for unlabeled files
Nick Kralevich
2013-07-10
1
-2
/
+2
*
Clean up remaining denials.
repo sync
2013-05-22
1
-1
/
+1
*
Make all domains unconfined.
repo sync
2013-05-20
1
-1
/
+1
*
Require entrypoint to be explicitly granted for unconfined domains.
Stephen Smalley
2013-03-21
1
-3
/
+2
*
Update binder-related policy.
Stephen Smalley
2013-03-19
1
-1
/
+1
*
Add policy for property service.
Stephen Smalley
2012-04-04
1
-0
/
+1
*
SE Android policy.
Stephen Smalley
2012-01-04
1
-0
/
+23