- May 01, 2015
-
-
Stephen Smalley authored
Prevent defining any process types without the domain attribute so that all allow and neverallow rules written on domain are applied to all processes. Prevent defining any app process types without the appdomain attribute so that all allow and neverallow rules written on appdomain are applied to all app processes. Change-Id: I4cb565314fd40e1e82c4360efb671b175a1ee389 Signed-off-by:
Stephen Smalley <sds@tycho.nsa.gov>
-
- Apr 29, 2015
-
-
dcashman authored
-
Alex Klyubin authored
This enables access to gatekeeperd for anybody who invokes Android framework APIs. This is necessary because the AndroidKeyStore abstraction offered by the framework API occasionally communicates with gatekeeperd from the calling process. (cherry picked from commit effcac7d) Bug: 20526234 Change-Id: I450242cd085259b3f82f36f359ee65ff27bebd13
-
- Apr 25, 2015
-
-
Nick Kralevich authored
* commit 'aeb110ce': init.te: Don't allow mounting on top of /proc
-
Nick Kralevich authored
* commit 'e05487ac': init.te: Don't allow mounting on top of /proc
-
Nick Kralevich authored
Don't allow init to mount on top of /proc. See https://android-review.googlesource.com/148295 for details. Change-Id: I65f66b39f3a5bfb72facb9f716f4537ac2237af1
-
- Apr 24, 2015
-
-
Jeff Sharkey authored
* commit '20f38b98': Allow vold to move FUSE backing files directly.
-
Jeff Sharkey authored
* commit '90c64542': Allow vold to move FUSE backing files directly.
-
Jeff Vander Stoep authored
* commit 'd2aa96c5': Create context for ctl.console
-
Jeff Sharkey authored
This enables an optimization of bypassing the FUSE overhead when migrating emulated storage between volumes. avc: denied { write } for path="/mnt/expand/6cba9b95-4fc8-4096-b51f-bdb2c007d059/media/obb/.nomedia" dev="dm-0" ino=387843 scontext=u:r:vold:s0 tcontext=u:object_r:media_rw_data_file:s0 tclass=file permissive=1 Bug: 19993667 Change-Id: I2bb9aaca50ed988ded6afec6d7fbe190903707e0
-
Jeff Vander Stoep authored
* commit 'c2e31a77': Create context for ctl.console
-
Jeff Vander Stoep authored
(cherry picked from commit c2e31a77) Change-Id: I92218709fa8cdb71c0369aca8fdd7922df45f7d0
-
Jeffrey Vander Stoep authored
* commit 'bf162a2a': Revert "Create context for ctl.console"
-
Jeff Vander Stoep authored
Change-Id: I1c9fa4da442aa47ae4b7341eab6f788f0329d2d2
-
Jeff Vander Stoep authored
* commit '1bd407a0': Create context for ctl.console
-
Jeffrey Vander Stoep authored
* commit 'eb953648': Revert "Create context for ctl.console"
-
Elliott Hughes authored
* commit 'a331c593': Revert "Revert "SELinux policy changes for re-execing init.""
-
Jeffrey Vander Stoep authored
This reverts commit 525e3747. Change-Id: I64f72073592f7f7553e763402a40c467c639cfce
-
Jeffrey Vander Stoep authored
This reverts commit bbd56b71. Change-Id: I3e295f785aa62de3a04b2f201be97dd7ef0c207f
-
Jeff Vander Stoep authored
* commit 'bbd56b71': Create context for ctl.console
-
Jeff Vander Stoep authored
(cherry picked from commit bbd56b71) Change-Id: I0db435b80678a58cd9a6fbd5d67ba08f8e8d3cd4
-
Jeff Vander Stoep authored
Change-Id: I9ba4952230ec1b811b8ec6cd19c0286ee791bf08
-
Elliott Hughes authored
* commit '5aac86dc': Revert "Revert "SELinux policy changes for re-execing init.""
-
Elliott Hughes authored
This reverts commit c450759e. There was nothing wrong with this change originally --- the companion change in init was broken. Bug: http://b/19702273 Change-Id: I9d806f6ac251734a61aa90c0741bec7118ea0387
-
Nick Kralevich authored
* commit '6b82aaeb': Revert "SELinux policy changes for re-execing init."
-
Nick Kralevich authored
* commit '6d97d9b8': Revert "SELinux policy changes for re-execing init."
-
Nick Kralevich authored
-
Nick Kralevich authored
shamu isn't booting. This reverts commit 46e832f5. Change-Id: Ib697745a9a1618061bc72f8fddd7ee88c1ac5eca
-
Elliott Hughes authored
* commit 'f17bbab7': SELinux policy changes for re-execing init.
-
Nick Kralevich authored
* commit 'b1b5e662': allow adbd to set sys.usb.ffs.ready
-
Elliott Hughes authored
* commit 'ecd57731': SELinux policy changes for re-execing init.
-
Nick Kralevich authored
* commit 'caefbd71': allow adbd to set sys.usb.ffs.ready
-
Elliott Hughes authored
-
Nick Kralevich authored
Needed for https://android-review.googlesource.com/147730 Change-Id: Iceb87f210e4c5d0f39426cc6c96a216a4644eaa9
-
Elliott Hughes authored
Change-Id: I5eca4f1f0f691be7c25e463563e0a4d2ac737448
-
- Apr 20, 2015
-
-
Nick Kralevich authored
* commit '268425b7': gatekeeperd: use more specific label for /data file
-
Nick Kralevich authored
* commit '934cf6ea': gatekeeperd: use more specific label for /data file
-
Nick Kralevich authored
-
- Apr 18, 2015
-
-
Jeff Sharkey authored
* commit '479a536a': Grant apps write access to returned vfat FDs.
-