Gitiles
Code Review
Sign In
review.gerrithub.io
/
CandySiX-Testing
/
external_sepolicy
/
442c3ebd4c05bed217e756586ac9fcb4c6283d40
/
vold.te
442c3eb
sepolicy: Fixup neverallows for non-shipping builds..
by Adnan Begovic
· 8 years ago
edb21bc
Merge remote-tracking branch 'upstream/marshmallow-release', tag 'android-6.0.0_r1' into HEAD
by Adnan Begovic
· 8 years ago
6b75d09
Let's reinvent storage, yet again!
by Jeff Sharkey
· 8 years ago
887d7af
Define types for userdata and cache block devices.
by Stephen Smalley
· 9 years ago
1d7bc1d
domain: Restore original neverallow rules for shipping builds
by Ricardo Cerqueira
· 8 years ago
769b96f
Allow vold to change priority when benchmarking.
by Jeff Sharkey
· 8 years ago
7617cd4
New "selinux.restorecon" control property.
by Jeff Sharkey
· 8 years ago
e265197
Allow /dev/klog access, drop mknod and __null__ access
by Nick Kralevich
· 8 years ago
35e5015
DO NOT MERGE New ext4enc kernel switching from xattrs to ioctl
by Paul Lawrence
· 8 years ago
e2c0c9d
DO NOT MERGE Securely encrypt the master key
by Paul Lawrence
· 8 years ago
c960596
drop_caches label, vold scratch space on expanded.
by Jeff Sharkey
· 8 years ago
2f5a6a9
Replace unix_socket_connect() and explicit property sets with macro
by William Roberts
· 8 years ago
90c6454
Allow vold to move FUSE backing files directly.
by Jeff Sharkey
· 8 years ago
73d9c2a
Initial policy for expanded storage.
by Jeff Sharkey
· 8 years ago
84e1c61
Different blkid and fsck execution domains.
by Jeff Sharkey
· 9 years ago
4423ecd
Directory for vold to store private data.
by Jeff Sharkey
· 9 years ago
5a5b364
Separate fsck domains to protect userdata.
by Jeff Sharkey
· 9 years ago
f063f46
Updated policy for external storage.
by Jeff Sharkey
· 9 years ago
38af1da
Adding e4crypt support
by Paul Lawrence
· 9 years ago
077da1c
SEAndroid: Updated vold domain related policy
by Ravi Kumar Siddojigari
· 9 years ago
149ccab
sepolicy: allow vold to mount ext4 sdcard
by Michael Bestas
· 9 years ago
00e4df3
sepolicy: New type sdcard_posix for labeled filesystems
by Tom Marshall
· 9 years ago
273d7ea
Label block devices created or accessed by vold with specific types.
by Stephen Smalley
· 9 years ago
cedee69
Fix fsck-related denials with encrypted userdata.
by Stephen Smalley
· 9 years ago
dd053a9
Define types for userdata and cache block devices.
by Stephen Smalley
· 9 years ago
f85c1fc
Allow installd, vold, system_server unlabeled access.
by Stephen Smalley
· 9 years ago
8599e34
Introduce wakelock_use()
by Nick Kralevich
· 9 years ago
02dac03
Drop relabelto_domain() macro and its associated definitions.
by Stephen Smalley
· 9 years ago
d756711
Allow vold to access keymaster
by Paul Lawrence
· 9 years ago
4b3893f
Replace ctl_default_prop access with explicit service property keys.
by Robert Craig
· 10 years ago
01ba683
Allow vold to call to healthd
by Paul Lawrence
· 10 years ago
1601132
Clean up socket rules.
by Stephen Smalley
· 10 years ago
48b1883
Introduce asec_public_file type.
by Robert Craig
· 10 years ago
3753c81
vold: allow wakelocks, fsck logs
by Nick Kralevich
· 10 years ago
4ab2983
am 35e8dcc9: Merge "Let vold mount OBB files on external storage." into klp-dev
by Jeff Sharkey
· 10 years ago
80176dc
Let vold mount OBB files on external storage.
by Jeff Sharkey
· 10 years ago
1d5176c
am 2abfe7d4: Allow vold to invoke blkid, use external ASECs.
by Jeff Sharkey
· 10 years ago
2abfe7d
Allow vold to invoke blkid, use external ASECs.
by Jeff Sharkey
· 10 years ago
d045e56
Partially revert 4fc702eccf2c427a44da4b02342250094ab61192.
by Nick Kralevich
· 10 years ago
4fc702e
DO NOT MERGE Fix denials seen during device upgrade.
by Geremy Condra
· 10 years ago
13a74a3
Merge "Allow vold to start and stop processes via init" into klp-dev
by Geremy Condra
· 10 years ago
7eb786b
Give vold the capability to kill.
by Geremy Condra
· 10 years ago
4974855
Allow vold to start and stop processes via init
by Ken Sumrall
· 10 years ago
b25fe91
Grant fsetid Linux capability to vold.
by Alex Klyubin
· 10 years ago
7914a47
Enable SELinux on vold
by Nick Kralevich
· 10 years ago
77d4731
Make all domains unconfined.
by repo sync
· 10 years ago
50e37b9
Move domains into per-domain permissive mode.
by repo sync
· 10 years ago
c25023e
Merge "SELinux policy: let vold write to device:dir." into jb-mr2-dev
by Alex Klyubin
· 10 years ago
7de339a
SELinux policy: let vold create /data/tmp_mnt
by Alex Klyubin
· 10 years ago
d050c79
SELinux policy: let vold write to device:dir.
by Alex Klyubin
· 10 years ago
77ec892
SELinux policy for users of libcutils klog_write.
by Alex Klyubin
· 10 years ago
c341f23
SELinux policy: let vold setsched of kernel processes.
by Alex Klyubin
· 10 years ago
3b5923f
SELinux policy granting vold the capability to reboot.
by Alex Klyubin
· 10 years ago
7bb2a55
Give domains read access to security_file domain.
by William Roberts
· 10 years ago
0e856a0
Allow all domains to read /dev symlinks.
by Stephen Smalley
· 10 years ago
c195ec3
Split internal and external sdcards
by William Roberts
· 11 years ago
7672eac
Add SELinux policy for asec containers.
by rpcraig
· 11 years ago
1c73516
Address various denials introduced by JB/4.1.
by Stephen Smalley
· 11 years ago
124720a
Add policy for property service.
by Stephen Smalley
· 11 years ago
2dd4e51
SE Android policy.
by Stephen Smalley
· 12 years ago