Gitiles
Code Review
Sign In
review.shift-gmbh.com
/
SHIFTPHONES
/
android_device_lineage_sepolicy
/
8ca697b6c2d7145b71cebfc311185d2d14455723
8ca697b
sepolicy: Move hal_lineage_livedisplay_sysfs rule to proper location
by Rashed Abdel-Tawab
· 5 years ago
521a64f
sepolicy: allow sysfs livedisplay hal read privs to sysfs_graphics dirs
by Dan Pasanen
· 5 years ago
09ce66f
sepolicy: Allow Snap to execute bcc
by LuK1337
· 5 years ago
4ab5398
Add adb_root rules
by Luca Stefani
· 5 years ago
a3f0aa1
Kill su and sudaemon
by Luca Stefani
· 5 years ago
5ec4de4
sepolicy: qcom: RIP legacy
by LuK1337
· 5 years ago
b4506f9
Kill sysinit
by Luca Stefani
· 5 years ago
6357883
sepolicy: Make recovery permissive
by Luca Stefani
· 5 years ago
67b6293
sepolicy: vendor: Migrate to power 1.2
by Davide Garberi
· 5 years ago
aad9035
sepolicy: Allow uncrypt to open OTA package as rw
by Luca Stefani
· 6 years ago
fbb21ce
lineage: Label our legacy Wi-Fi service
by Bruno Martins
· 5 years ago
85711a4
sepolicy: Drop fsck.exfat label
by LuK1337
· 5 years ago
2312169
sepolicy: Mark mkfs and sysinit as system_file_type
by LuK1337
· 5 years ago
0320541
sepolicy: Actually remove sepolicy for lineagehw
by Bruno Martins
· 5 years ago
e54e2dd
sepolicy: Remove sepolicy for lineagehw
by Paul Keith
· 6 years ago
a09f4a8
sepolicy: Add hal_lineage_fod domain
by LuK1337
· 6 years ago
7125675
lineage: Guard neverallowed policy for system_file with userdebug/eng
by Nolen Johnson
· 5 years ago
ac26bd2
sepolicy: Add hal_lineage_camera_motor domain
by LuK1337
· 5 years ago
00b3ad1
sepolicy: qcom: Label /d/rpmh
by LuK1337
· 5 years ago
f3ffbac
sepolicy: Dontaudit sysinit
by Jan Altensen
· 5 years ago
4015af6
sepolicy: Break livedisplay hal policy into impl independent ones
by dianlujitao
· 6 years ago
6fd87ce
sepolicy: qcom: Rename common to vendor to avoid confusion
by dianlujitao
· 6 years ago
5fa3bba
sepolicy: Move power hal service label to dynamic
by dianlujitao
· 6 years ago
cd8e8d2
sepolicy: Move touch hal policy to dynamic
by dianlujitao
· 6 years ago
627e634
sepolicy: Move livedisplay hal policy to dynamic
by dianlujitao
· 6 years ago
370b40b
sepolicy: Dynamically build trust policy into system/vendor
by dianlujitao
· 6 years ago
71566b5
Revert "sepol: Label vendor.qcom.bluetooth.soc"
by Atman
· 6 years ago
c249d09
sepol: Label vendor.qcom.bluetooth.soc
by Rashed Abdel-Tawab
· 6 years ago
1e69dc3
qcom: Extend untrusted_app access to battery/power supply sysfs
by Michael Bestas
· 6 years ago
0a5dfb2
sepolicy: allow recovery to setenforce
by Alessandro Astone
· 6 years ago
4cd1a2f
sepolicy: recovery: allow reading fbe key version
by Alessandro Astone
· 6 years ago
b0b4727
sepolicy: recovery: allow mounting of usb storage
by Alessandro Astone
· 6 years ago
cc71484
sepolicy: recovery: allow recovery to read battery info
by Alessandro Astone
· 6 years ago
d3941b0
sepolicy: recovery: Allow setting sys.usb.config
by Michael Bestas
· 6 years ago
7c07f0e
sepolicy: recovery: Allow volume manager write to /sys/*/uevent
by Michael Bestas
· 6 years ago
340f8b9
sepolicy: recovery: Add policy for /dev/block/volmgr
by Michael Bestas
· 6 years ago
5e9a260
sepolicy: recovery: Fix the volume manager blkid.tab denial
by Adrian DC
· 8 years ago
6b14545
sepolicy: recovery: Allow reading proc_filesystems
by Michael Bestas
· 6 years ago
a816a39
sepolicy: recovery: Add policy for volume manager
by Alessandro Astone
· 6 years ago
b05e6a9
Allow Gallery to access system_app_data_file
by dianlujitao
· 6 years ago
351eedd
sepolicy: Move superuser policy to private
by dianlujitao
· 6 years ago
72c407d
common: Restrict HAL permissions to server side
by dianlujitao
· 6 years ago
78fce70
common: Mark platform_app as hal_lineage_livedisplay client
by dianlujitao
· 6 years ago
a21eabf
common: Label livedisplay 2.0 sysfs service
by Paul Keith
· 6 years ago
16c5b62
Remove minivold rules
by Michael Bestas
· 6 years ago
f982155
Move snap/gallery definitions back to private
by Michael Bestas
· 6 years ago
6c19eed
Clean-up recovery rules a bit
by Luca Stefani
· 6 years ago
7e67a4b
Label adb.network.port as system_prop
by Michael Bestas
· 6 years ago
3937322
Make backuptool permissive only in non user builds
by Luca Stefani
· 6 years ago
3f58c82
Make sysinit permissive
by Luca Stefani
· 6 years ago
c0eb879
lineage: Use set_prop() macro for setting adb tcp property
by LuK1337
· 6 years ago
ff9271d
Snap and gallery require to run vendor code
by Luca Stefani
· 6 years ago
da24d05
Remove not allowed rule
by Luca Stefani
· 6 years ago
de42705
Revert "common: Add sf_lcd_density_prop type and labelled props"
by dianlujitao
· 6 years ago
b986852
qcom: Remove power HAL 1.0 label
by Michael Bestas
· 6 years ago
c8ceb6f
sepolicies: add Trust hal
by Joey
· 6 years ago
701b30d
common: Migrate to livedisplay 2.0
by Bruno Martins
· 6 years ago
1c44e50
common: Add vendor.lineage.touch rules
by Michael Bestas
· 6 years ago
c72a806
lineage: Rewrite Lineage Power HAL rules
by Bruno Martins
· 6 years ago
87d305d
lineage: Properly write rules for Lineage LiveDisplay as a HAL
by Bruno Martins
· 6 years ago
e6c3ce0
sepolicy: Allow recovery update_engine to setexec backuptool
by Rashed Abdel-Tawab
· 6 years ago
0211a9c
sepolicy: Allow Settings to read ro.vendor.build.security_patch
by Rashed Abdel-Tawab
· 6 years ago
80e3105
common: Improve label of I/O sched tuning nodes
by Nico
· 6 years ago
8df8725
lineage: Address perf HAL denial with boost enabled
by dianlujitao
· 6 years ago
aaad39f
Allow LiveDisplay to access vendor display property
by dianlujitao
· 6 years ago
17ee363
common: Allow init to relabel I/O sched tuning nodes
by dianlujitao
· 6 years ago
dd4ff84
common: Label and allow access over LiveDisplay sysfs nodes
by Bruno Martins
· 6 years ago
55699af
common: Expand labeling of sysfs_vibrator nodes using genfscon
by Kevin F. Haggerty
· 6 years ago
618adbf
Make A/B backuptool permissive
by Luca Stefani
· 6 years ago
75ac3aa
selinux: add domain for Gallery
by codeworkx
· 6 years ago
8857acd
move snap_app type definition to public
by jrior001
· 6 years ago
037f27a
selinux: add domain for snap
by codeworkx
· 7 years ago
837e029
common: Label and allow init to write to I/O sched tuning nodes
by Kevin F. Haggerty
· 6 years ago
75c6cf9
common: Allow adbd to set a system_prop
by Kevin F. Haggerty
· 6 years ago
a60a7e7
Label lineage.service.adb.root as system prop
by Luca Stefani
· 6 years ago
0c74f7b
common: Label common basic USB HAL
by Bruno Martins
· 6 years ago
a85377e
sepolicy: Update to match new qcom sepolicy
by Rashed Abdel-Tawab
· 6 years ago
31b0919
sepol: Remove recovery access to vold_socket
by Rashed Abdel-Tawab
· 6 years ago
aafd2bf
sepol: Remove exfat context and set sdFAT to exFAT
by Rashed Abdel-Tawab
· 6 years ago
f1ad321
sepolicy: recovery: Allow (re)mounting system
by Paul Keith
· 6 years ago
f126e29
Make fuseblk use vfat context
by Luca Stefani
· 6 years ago
65ae242
Revert "sepolicy: qcom: Allow nfc to read and execute files in /vendor on full treble"
by LuK1337
· 7 years ago
c9b0d95
sepolicy: add rules for updater and update_engine
by Dan Pasanen
· 8 years ago
37422f7
common: add update_engine policies
by Dan Pasanen
· 7 years ago
41ac4fa
sepolicy: Label aw2013 HIDL light HAL
by Michael Bestas
· 7 years ago
0f4572f
sepolicy: introduce Trust interface
by Joey
· 7 years ago
953c9ca
sepolicy: Add legacy-mm livedisplay label
by Ethan Chen
· 7 years ago
ea92881
sepolicy: qcom: Allow nfc to read and execute files in /vendor on full treble
by LuK1337
· 7 years ago
956eaed
Revert "sepolicy: suppress denial logspam"
by Michael Bestas
· 7 years ago
98c7f8d
Allow recovery write to sysfs_graphics
by Michael Bestas
· 7 years ago
541bcf2
Remove adb.secure recovery property context
by Michael Bestas
· 7 years ago
5ebc0dc
sepolicy: Add rules for LiveDisplay HIDL HAL
by Bruno Martins
· 7 years ago
b95e366
common: Remove stale ntfs genfscon policy
by Paul Keith
· 7 years ago
43701f1
sepolicy: Change recovery_prop to lineage_recovery_prop
by Rashed Abdel-Tawab
· 7 years ago
467738e
recovery: Use r_dir_file macro
by Ethan Chen
· 7 years ago
bc6bf77
sepolicy: recovery: Allow reading battery and usb status
by Tom Marshall
· 7 years ago
b64134a
sepolicy: Allow vold to exec sgdisk
by Tom Marshall
· 7 years ago
dca65ca
sepolicy: Improve external storage rules
by David
· 7 years ago
8290552
sepolicy: allow untrusted app to find styleInterface
by Joey
· 7 years ago
a14df93
sepolicy: add style api
by Joey
· 7 years ago
Next »