- Jan 27, 2016
-
-
Jeffrey Vander Stoep authored
am: fde8ca53 * commit 'fde8ca53': zygote: grant perms from domain_deprecated
-
Jeffrey Vander Stoep authored
am: eecaa0b5 * commit 'eecaa0b5': zygote: grant perms from domain_deprecated
-
Jeffrey Vander Stoep authored
-
Daniel Cashman authored
-
Jeff Vander Stoep authored
In preparation of removing permissions from domain_deprecated. Addresses: avc: denied { read } for name="ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file avc: denied { open } for path="/proc/220/net/ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file avc: denied { getattr } for path="/proc/220/net/ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file Change-Id: Ie94d3db3c5dccb8077ef5da26221a6413f5d19c2
-
Jeffrey Vander Stoep authored
am: 7d3e5467 * commit '7d3e5467': Revert "zygote: grant perms from domain_deprecated"
-
Jeffrey Vander Stoep authored
am: 98f60e5c * commit '98f60e5c': Revert "zygote: grant perms from domain_deprecated"
-
dcashman authored
Address the following denial: type=1400 audit(1453854842.899:7): avc: denied { search } for pid=1512 comm="sdcard" name="/" dev="tmpfs" ino=7547 scontext=u:r:sdcardd:s0 tcontext=u:object_r:tmpfs:s0 tclass=dir permissive=0 vold: EmulatedVolume calls sdcard to mount on /storage/emulated. Bug: 26807309 Change-Id: Ifdd7c356589f95165bba489dd06282a4087e9aee
-
Jeffrey Vander Stoep authored
This reverts commit e52fff83. Change-Id: Ieafb5214940585d63ff6f0b4802d8c7d1c126174
-
Jeffrey Vander Stoep authored
-
Jeffrey Vander Stoep authored
This reverts commit e52fff83. Change-Id: Ieafb5214940585d63ff6f0b4802d8c7d1c126174
-
Jeffrey Vander Stoep authored
am: 299e1d5a * commit '299e1d5a': zygote: grant perms from domain_deprecated
-
Jeffrey Vander Stoep authored
am: 4115beae * commit '4115beae': zygote: grant perms from domain_deprecated
-
Jeffrey Vander Stoep authored
-
Jeffrey Vander Stoep authored
-
Jeff Vander Stoep authored
In preparation of removing permissions from domain_deprecated. Addresses: avc: denied { read } for name="ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file avc: denied { open } for path="/proc/220/net/ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file avc: denied { getattr } for path="/proc/220/net/ipv6_route" dev="proc" ino=4026536875 scontext=u:r:zygote:s0 tcontext=u:object_r:proc_net:s0 tclass=file Change-Id: I5b505ad386a445113bc0a1bb35d4f88f7761c048
-
Marco Nelissen authored
-
Jeff Vander Stoep authored
Remove from autoplay Change-Id: Ic9f019f69e5f2dff5e2b8d03d39052486660d791
-
Narayan Kamath authored
am: 2e975396 * commit '2e975396': Revert "Remove domain_deprecated from sdcard domains"
-
Narayan Kamath authored
am: c4121add * commit 'c4121add': Revert "Remove domain_deprecated from sdcard domains"
-
Narayan Kamath authored
-
Narayan Kamath authored
This reverts commit 0c7bc58e. bug: 26807309 Change-Id: I8a7b0e56a0d6f723508d0fddceffdff76eb0459a
-
Jeff Vander Stoep authored
am: 7676d3d9 * commit '7676d3d9': domain: grant write perms to cgroups
-
Jeff Vander Stoep authored
am: be0616ba * commit 'be0616ba': domain: grant write perms to cgroups
-
Jeff Vander Stoep authored
Was moved to domain_deprecated. Move back to domain. Files in /acct/uid/*/tasks are well protected by unix permissions. No information is leaked with write perms. Change-Id: I8017e906950cba41ce350bc0892a36269ade8d53
-
dcashman authored
Address the following denial: type=1400 audit(0.0:853): avc: denied { read } for name="/" dev="proc" ino=1 scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:object_r:proc:s0 tclass=dir permissive=0 Bug: 26806629 Change-Id: Ic2ad91aadac00dc04d7e04f7460d5681d81134f4
-
- Jan 26, 2016
-
-
SimHyunYong authored
am: fa46a737 * commit 'fa46a737': Using r_dir_file macro in domain.te
-
SimHyunYong authored
am: 093ea6fb * commit '093ea6fb': Using r_dir_file macro in domain.te
-
dcashman authored
The services under this label are not meant to be exposed to all apps. Currently only priv_app needs access. Bug: 26799206 Change-Id: I07c60752d6ba78f27f90bf5075bcab47eba90b55
-
Jeffrey Vander Stoep authored
am: dd55b44d * commit 'dd55b44d': Remove domain_deprecated from sdcard domains
-
Jeffrey Vander Stoep authored
am: cdae042a * commit 'cdae042a': Remove domain_deprecated from sdcard domains
-
SimHyunYong authored
r_dir_file(domain, self) allow domain self:dir r_dir_perms; allow domain self:lnk_file r_file_perms; allow domain self:file r_file_perms; te_macros define(`r_dir_file', ` allow $1 $2:dir r_dir_perms; allow $1 $2:{ file lnk_file } r_file_perms; ') Change-Id: I7338f63a1eaa8ca52cd31b51ce841e3dbe46ad4f
-
Jeffrey Vander Stoep authored
-
James Hawkins authored
am: c119fab9 * commit 'c119fab9': bootstat: Fix the SELinux policy after removing domain_deprecated.
-
Jeff Vander Stoep authored
Change-Id: I65d7c0bb306f61dfe0ad2a5581f28dbc2942a1eb
-
James Hawkins authored
am: ae29dea8 * commit 'ae29dea8': bootstat: Fix the SELinux policy after removing domain_deprecated.
-