1. 18 Dec, 2013 1 commit
    • Stephen Smalley's avatar
      Confine shell domain in -user builds only. · 712ca0a4
      Stephen Smalley authored
      
      Confine the domain for an adb shell in -user builds only.
      The shell domain in non-user builds is left permissive.
      init_shell (shell spawned by init, e.g.  console service)
      remains unconfined by this change.
      Introduce a shelldomain attribute for rules common to all shell
      domains, assign it to the shell types, and add shelldomain.te for
      its rules.
      
      Change-Id: I01ee2c7ef80b61a9db151abe182ef9af7623c461
      Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
      712ca0a4
  2. 09 Dec, 2013 1 commit
  3. 02 Dec, 2013 1 commit
  4. 27 Sep, 2013 1 commit
  5. 20 May, 2013 1 commit
    • repo sync's avatar
      Make all domains unconfined. · 77d4731e
      repo sync authored
      This prevents denials from being generated by the base policy.
      Over time, these rules will be incrementally tightened to improve
      security.
      
      Change-Id: I4be1c987a5d69ac784a56d42fc2c9063c402de11
      77d4731e
  6. 06 May, 2013 1 commit
  7. 05 Apr, 2013 1 commit
  8. 04 Apr, 2013 1 commit
  9. 27 Mar, 2013 1 commit
  10. 22 Mar, 2013 3 commits
  11. 19 Mar, 2013 1 commit
  12. 27 Nov, 2012 2 commits
  13. 04 Apr, 2012 1 commit
    • Stephen Smalley's avatar
      Add policy for property service. · 124720a6
      Stephen Smalley authored
      New property_contexts file for property selabel backend.
      New property.te file with property type declarations.
      New property_service security class and set permission.
      Allow rules for setting properties.
      124720a6
  14. 08 Mar, 2012 1 commit
  15. 07 Mar, 2012 2 commits
  16. 12 Jan, 2012 1 commit
  17. 04 Jan, 2012 1 commit