- 0ead839 lineage: Assign bash the same label as the default shell by Bruno Martins · 5 years ago
- a771885 sepolicy: recovery: fix neverallows by Alessandro · 4 years, 9 months ago
- 177e4ad sepolicy: recovery: allow reading fbe key version by Alessandro · 4 years, 9 months ago
- b9f79b3 sepolicy: recovery: allow mounting of internal storage by Alessandro · 4 years, 9 months ago
- fb92a02 sepolicy: recovery: allow mounting of usb storage by Alessandro Astone · 6 years ago
- 4368f9b sepolicy: recovery: Allow volume manager write to /sys/*/uevent by Michael Bestas · 6 years ago
- 31b9bc5 sepolicy: recovery: Add policy for /dev/block/volmgr by Michael Bestas · 6 years ago
- e89d910 sepolicy: recovery: Fix the volume manager blkid.tab denial by Adrian DC · 8 years ago
- 2b04642 sepolicy: recovery: Allow reading proc_filesystems by Michael Bestas · 6 years ago
- f51b60c sepolicy: recovery: Add policy for volume manager by Alessandro Astone · 6 years ago
- 158f077 sepolicy: New type sdcard_posix for labeled filesystems by Tom Marshall · 10 years ago
- bd85ca1 lineage: Introduce a new flag to exclude fuseblk sepolicy by theimpulson · 4 years, 9 months ago
- 9a42ed5 exynos: Allow livedisplay to write to /data/vendor/display by Danny Wood · 4 years, 10 months ago
- 6d42fe1 exynos: Add hal_lineage_livedisplay policy by Andreas Schneider · 4 years, 10 months ago
- ff91532 legacy-common: Simplify legacy camera HAL1 rules by Alessandro Astone · 4 years, 10 months ago
- b542aee sepolicy: Add rules required for TARGET_HAS_LEGACY_CAMERA_HAL1 by Bruno Martins · 4 years, 10 months ago
- 0a1291e sepolicy: Nuke sdfat from genfs by Erfan Abdi · 4 years, 10 months ago
- 02de8d7 gallery_app: Allow binder call with gpuservice by PIPIPIG233666 · 4 years, 10 months ago
- 8e2091f snap_app: Allow binder call with gpuservice by PIPIPIG233666 · 5 years ago
- 6f988f2 sepolicy: Label ro.telephony.use_old_mnc_mcc_format by LuK1337 · 5 years ago
- e4b006b Move lineage framework service declarations to private by dianlujitao · 5 years ago
- 070e37e sepolicy: vendor: Label CryptfsHW HIDL HAL by Artem Borisov · 5 years ago
- 1f11b66 Remove Style API related rules by Bruno Martins · 5 years ago
- ccc533f sepolicy: Label and address Trust's system variant denials by theimpulson · 5 years ago
- cfac4c9 sepolicy: Label and address denials of livedisplay's system variant by theimpulson · 5 years ago
- 8ca697b sepolicy: Move hal_lineage_livedisplay_sysfs rule to proper location by Rashed Abdel-Tawab · 5 years ago
- 521a64f sepolicy: allow sysfs livedisplay hal read privs to sysfs_graphics dirs by Dan Pasanen · 5 years ago
- 09ce66f sepolicy: Allow Snap to execute bcc by LuK1337 · 5 years ago
- 4ab5398 Add adb_root rules by Luca Stefani · 5 years ago
- a3f0aa1 Kill su and sudaemon by Luca Stefani · 5 years ago
- 5ec4de4 sepolicy: qcom: RIP legacy by LuK1337 · 5 years ago
- b4506f9 Kill sysinit by Luca Stefani · 5 years ago
- 6357883 sepolicy: Make recovery permissive by Luca Stefani · 5 years ago
- 67b6293 sepolicy: vendor: Migrate to power 1.2 by Davide Garberi · 5 years ago
- aad9035 sepolicy: Allow uncrypt to open OTA package as rw by Luca Stefani · 6 years ago
- fbb21ce lineage: Label our legacy Wi-Fi service by Bruno Martins · 5 years ago
- 85711a4 sepolicy: Drop fsck.exfat label by LuK1337 · 5 years ago
- 2312169 sepolicy: Mark mkfs and sysinit as system_file_type by LuK1337 · 5 years ago
- 0320541 sepolicy: Actually remove sepolicy for lineagehw by Bruno Martins · 5 years ago
- e54e2dd sepolicy: Remove sepolicy for lineagehw by Paul Keith · 6 years ago
- a09f4a8 sepolicy: Add hal_lineage_fod domain by LuK1337 · 6 years ago
- 7125675 lineage: Guard neverallowed policy for system_file with userdebug/eng by Nolen Johnson · 5 years ago
- ac26bd2 sepolicy: Add hal_lineage_camera_motor domain by LuK1337 · 5 years ago
- 00b3ad1 sepolicy: qcom: Label /d/rpmh by LuK1337 · 5 years ago
- f3ffbac sepolicy: Dontaudit sysinit by Jan Altensen · 5 years ago
- 4015af6 sepolicy: Break livedisplay hal policy into impl independent ones by dianlujitao · 6 years ago
- 6fd87ce sepolicy: qcom: Rename common to vendor to avoid confusion by dianlujitao · 6 years ago
- 5fa3bba sepolicy: Move power hal service label to dynamic by dianlujitao · 6 years ago
- cd8e8d2 sepolicy: Move touch hal policy to dynamic by dianlujitao · 6 years ago
- 627e634 sepolicy: Move livedisplay hal policy to dynamic by dianlujitao · 6 years ago
- 370b40b sepolicy: Dynamically build trust policy into system/vendor by dianlujitao · 6 years ago
- 71566b5 Revert "sepol: Label vendor.qcom.bluetooth.soc" by Atman · 6 years ago
- c249d09 sepol: Label vendor.qcom.bluetooth.soc by Rashed Abdel-Tawab · 6 years ago
- 1e69dc3 qcom: Extend untrusted_app access to battery/power supply sysfs by Michael Bestas · 6 years ago
- 0a5dfb2 sepolicy: allow recovery to setenforce by Alessandro Astone · 6 years ago
- 4cd1a2f sepolicy: recovery: allow reading fbe key version by Alessandro Astone · 6 years ago
- b0b4727 sepolicy: recovery: allow mounting of usb storage by Alessandro Astone · 6 years ago
- cc71484 sepolicy: recovery: allow recovery to read battery info by Alessandro Astone · 6 years ago
- d3941b0 sepolicy: recovery: Allow setting sys.usb.config by Michael Bestas · 6 years ago
- 7c07f0e sepolicy: recovery: Allow volume manager write to /sys/*/uevent by Michael Bestas · 6 years ago
- 340f8b9 sepolicy: recovery: Add policy for /dev/block/volmgr by Michael Bestas · 6 years ago
- 5e9a260 sepolicy: recovery: Fix the volume manager blkid.tab denial by Adrian DC · 8 years ago
- 6b14545 sepolicy: recovery: Allow reading proc_filesystems by Michael Bestas · 6 years ago
- a816a39 sepolicy: recovery: Add policy for volume manager by Alessandro Astone · 6 years ago
- b05e6a9 Allow Gallery to access system_app_data_file by dianlujitao · 6 years ago
- 351eedd sepolicy: Move superuser policy to private by dianlujitao · 6 years ago
- 72c407d common: Restrict HAL permissions to server side by dianlujitao · 6 years ago
- 78fce70 common: Mark platform_app as hal_lineage_livedisplay client by dianlujitao · 6 years ago
- a21eabf common: Label livedisplay 2.0 sysfs service by Paul Keith · 6 years ago
- 16c5b62 Remove minivold rules by Michael Bestas · 6 years ago
- f982155 Move snap/gallery definitions back to private by Michael Bestas · 6 years ago
- 6c19eed Clean-up recovery rules a bit by Luca Stefani · 6 years ago
- 7e67a4b Label adb.network.port as system_prop by Michael Bestas · 6 years ago
- 3937322 Make backuptool permissive only in non user builds by Luca Stefani · 6 years ago
- 3f58c82 Make sysinit permissive by Luca Stefani · 6 years ago
- c0eb879 lineage: Use set_prop() macro for setting adb tcp property by LuK1337 · 6 years ago
- ff9271d Snap and gallery require to run vendor code by Luca Stefani · 6 years ago
- da24d05 Remove not allowed rule by Luca Stefani · 6 years ago
- de42705 Revert "common: Add sf_lcd_density_prop type and labelled props" by dianlujitao · 6 years ago
- b986852 qcom: Remove power HAL 1.0 label by Michael Bestas · 6 years ago
- c8ceb6f sepolicies: add Trust hal by Joey · 6 years ago
- 701b30d common: Migrate to livedisplay 2.0 by Bruno Martins · 6 years ago
- 1c44e50 common: Add vendor.lineage.touch rules by Michael Bestas · 6 years ago
- c72a806 lineage: Rewrite Lineage Power HAL rules by Bruno Martins · 6 years ago
- 87d305d lineage: Properly write rules for Lineage LiveDisplay as a HAL by Bruno Martins · 6 years ago
- e6c3ce0 sepolicy: Allow recovery update_engine to setexec backuptool by Rashed Abdel-Tawab · 6 years ago
- 0211a9c sepolicy: Allow Settings to read ro.vendor.build.security_patch by Rashed Abdel-Tawab · 6 years ago
- 80e3105 common: Improve label of I/O sched tuning nodes by Nico · 6 years ago
- 8df8725 lineage: Address perf HAL denial with boost enabled by dianlujitao · 6 years ago
- aaad39f Allow LiveDisplay to access vendor display property by dianlujitao · 6 years ago
- 17ee363 common: Allow init to relabel I/O sched tuning nodes by dianlujitao · 6 years ago
- dd4ff84 common: Label and allow access over LiveDisplay sysfs nodes by Bruno Martins · 6 years ago
- 55699af common: Expand labeling of sysfs_vibrator nodes using genfscon by Kevin F. Haggerty · 6 years ago
- 618adbf Make A/B backuptool permissive by Luca Stefani · 6 years ago
- 75ac3aa selinux: add domain for Gallery by codeworkx · 6 years ago
- 8857acd move snap_app type definition to public by jrior001 · 6 years ago
- 037f27a selinux: add domain for snap by codeworkx · 7 years ago
- 837e029 common: Label and allow init to write to I/O sched tuning nodes by Kevin F. Haggerty · 6 years ago
- 75c6cf9 common: Allow adbd to set a system_prop by Kevin F. Haggerty · 6 years ago
- a60a7e7 Label lineage.service.adb.root as system prop by Luca Stefani · 6 years ago