-
-
Notifications
You must be signed in to change notification settings - Fork 29
Comparing changes
Open a pull request
base repository: GrapheneOS/platform_system_sepolicy
base: 15-qpr2
head repository: MaximilianGaedig/platform_system_sepolicy
compare: 11
Commits on Jul 2, 2020
-
Snap for 6649874 from 9b70a2c to rvc-qpr1-release
Change-Id: I46b1abbab762e507c2597ff71fd9851935c93a55
android-build-team Robot committedJul 2, 2020 Configuration menu - View commit details
-
Copy full SHA for 88da915 - Browse repository at this point
Copy the full SHA 88da915View commit details
Commits on Jul 7, 2020
-
Snap for 6659731 from b258c98 to rvc-qpr1-release
Change-Id: I519503f53b69d961b2c35b2f0b3932a4937a715c
android-build-team Robot committedJul 7, 2020 Configuration menu - View commit details
-
Copy full SHA for f9c56d0 - Browse repository at this point
Copy the full SHA f9c56d0View commit details
Commits on Jul 11, 2020
-
Snap for 6672721 from 6ec36ff to rvc-qpr1-release
Change-Id: If033855bed21bc91af9f5463a54530a403ad7428
android-build-team Robot committedJul 11, 2020 Configuration menu - View commit details
-
Copy full SHA for 11787c5 - Browse repository at this point
Copy the full SHA 11787c5View commit details
Commits on Jul 14, 2020
-
Snap for 6680110 from 6f5797a to rvc-qpr1-release
Change-Id: I113529076189614dd3265ee04a977dac40e7fc9b
android-build-team Robot committedJul 14, 2020 Configuration menu - View commit details
-
Copy full SHA for 259cb0a - Browse repository at this point
Copy the full SHA 259cb0aView commit details
Commits on Jul 17, 2020
-
Snap for 6689685 from e30b4b6 to rvc-qpr1-release
Change-Id: I6b10279efe1b5f840a16aeb41b703883638cc1ca
android-build-team Robot committedJul 17, 2020 Configuration menu - View commit details
-
Copy full SHA for e4a0ed6 - Browse repository at this point
Copy the full SHA e4a0ed6View commit details
Commits on Jul 23, 2020
-
Snap for 6703926 from 0bee120 to rvc-qpr1-release
Change-Id: Id30fef085c4667f6b7f60514a31517334fe38d7e
android-build-team Robot committedJul 23, 2020 Configuration menu - View commit details
-
Copy full SHA for 7028de1 - Browse repository at this point
Copy the full SHA 7028de1View commit details
Commits on Jul 29, 2020
-
Snap for 6720487 from 88b86a7 to rvc-qpr1-release
Change-Id: Iff1d3b3ff6bb9aefb5ac0586da56799f23f1df21
android-build-team Robot committedJul 29, 2020 Configuration menu - View commit details
-
Copy full SHA for 6c87df6 - Browse repository at this point
Copy the full SHA 6c87df6View commit details
Commits on Aug 4, 2020
-
Snap for 6736586 from df3b4ea to rvc-qpr1-release
Change-Id: I2dfdd0141a1d05961dc060a440d2191b33d8f600
android-build-team Robot committedAug 4, 2020 Configuration menu - View commit details
-
Copy full SHA for 0f0954c - Browse repository at this point
Copy the full SHA 0f0954cView commit details
Commits on Aug 11, 2020
-
Snap for 6755001 from 112a122 to rvc-qpr1-release
Change-Id: Ic843d6d636513bb0d54e43f3576242710091daac
android-build-team Robot committedAug 11, 2020 Configuration menu - View commit details
-
Copy full SHA for d7bcf17 - Browse repository at this point
Copy the full SHA d7bcf17View commit details
Commits on Aug 13, 2020
-
Snap for 6761348 from 202b346 to rvc-qpr1-release
Change-Id: Ib93d202e73cccde7872b55c79d75636bbed0836d
android-build-team Robot committedAug 13, 2020 Configuration menu - View commit details
-
Copy full SHA for 5c1b607 - Browse repository at this point
Copy the full SHA 5c1b607View commit details
Commits on Aug 18, 2020
-
Snap for 6773961 from 8f6b03c to rvc-qpr1-release
Change-Id: I1e092ba109f3cd79bf24753cf7c4609d7edb36ad
android-build-team Robot committedAug 18, 2020 Configuration menu - View commit details
-
Copy full SHA for ade4da5 - Browse repository at this point
Copy the full SHA ade4da5View commit details
Commits on Aug 20, 2020
-
Snap for 6780056 from f1ecf7a to rvc-qpr1-release
Change-Id: I045091af2bf60f662a1c354f83a26d8344a8af9a
android-build-team Robot committedAug 20, 2020 Configuration menu - View commit details
-
Copy full SHA for 6b5c41b - Browse repository at this point
Copy the full SHA 6b5c41bView commit details
Commits on Aug 28, 2020
-
Snap for 6799200 from e756e98 to rvc-qpr1-release
Change-Id: I9328059a0f6a69bdfc1c8ac5fbb998d93a178d5b
android-build-team Robot committedAug 28, 2020 Configuration menu - View commit details
-
Copy full SHA for 318517a - Browse repository at this point
Copy the full SHA 318517aView commit details
Commits on Sep 7, 2020
-
Snap for 6818149 from a59853f to rvc-qpr1-release
Change-Id: I6668e51362cb0b854187f0d1e3a6d8d52fcc3c76
android-build-team Robot committedSep 7, 2020 Configuration menu - View commit details
-
Copy full SHA for 945dbd9 - Browse repository at this point
Copy the full SHA 945dbd9View commit details
Commits on Sep 8, 2020
-
Snap for 6820514 from 2e4d149 to rvc-qpr1-release
Change-Id: I04a26c37a797ff400016e17eb04365224127d8a1
android-build-team Robot committedSep 8, 2020 Configuration menu - View commit details
-
Copy full SHA for 2128462 - Browse repository at this point
Copy the full SHA 2128462View commit details
Commits on Sep 9, 2020
-
Snap for 6823548 from 6ee8dcd to rvc-qpr1-release
Change-Id: I75f8c30e4d4eb8f0b7229772e8b1a0aa3395acfa
android-build-team Robot committedSep 9, 2020 Configuration menu - View commit details
-
Copy full SHA for c864b4c - Browse repository at this point
Copy the full SHA c864b4cView commit details
Commits on Sep 18, 2020
-
Snap for 6847696 from 63322ae to rvc-qpr1-release
Change-Id: I4661f61f56a7ce98f222d255efc8900fdecaf65f
android-build-team Robot committedSep 18, 2020 Configuration menu - View commit details
-
Copy full SHA for 31e0945 - Browse repository at this point
Copy the full SHA 31e0945View commit details
Commits on Dec 8, 2020
-
sepolicy: Add sdcard_posix_contextmount_type attribute
* Since we can't use contextmount_type for sdcard_posix due to contextmount_type being read only by design we need to declare our own attribute to bypass relabelto neverallow. That way we can mount external ext4/f2fs SD with sdcard_posix context and write permissions. Test: m -j selinux_policy Change-Id: I0dfe49cc0b34dfcce2840198843bde1272cbc61c
Configuration menu - View commit details
-
Copy full SHA for c65d07c - Browse repository at this point
Copy the full SHA c65d07cView commit details -
sepolicy: whitelist recovery from node creation neverallow
Change-Id: If91584e58f3709c0b18eaf9ee12a0c057716f9f3
Configuration menu - View commit details
-
Copy full SHA for c032133 - Browse repository at this point
Copy the full SHA c032133View commit details -
Only require compat mapping files if they exist.
Call build_policy when determing which compat mapping files should be included for a given partition. Bug: 168637766 Test: Built aosp_bonito-userdebug and saw that the compat mapping files in product/etc/sepolicy/mapping were no longer present. Test: Added a test 30.0.cil file to bonito's product private compat directory and saw that it was present at product/etc/sepolicy/mapping. Change-Id: I83cc28a159b24c0a2c0717dae461983250ab6c25
Chris Gross authored and Michael Bestas committedDec 8, 2020 Configuration menu - View commit details
-
Copy full SHA for bb4d016 - Browse repository at this point
Copy the full SHA bb4d016View commit details -
sepolicy: Allow recovery to alter /
This is needed for /etc/fstab, /adb_keys and volmgr Change-Id: I53332a57ce7879d7ba63c4ea3e27add01f5a3a90
Gabriele M authored and Michael Bestas committedDec 8, 2020 Configuration menu - View commit details
-
Copy full SHA for 2741936 - Browse repository at this point
Copy the full SHA 2741936View commit details
Commits on Dec 12, 2020
-
Fix storaged access to /sys/block/mmcblk0/stat after 48027a0
* Commit "storaged: remove access to sysfs_type" denied the storaged daemon access to the sysfs node it needed to do its work. * It also didn't provide any means necessary for adding the necessary rules at a device level, since its sepolicy is private. * Here we define a new sysfs_disk_stat security label, which device maintainers are supposed to add to their genfs_contexts file. This is similar to how hal_health_default and sysfs_batteryinfo is handled. * What prevents the genfs_contexts from being added here directly is that in a typical vendor implementation, these sysfs files are actually symlinks and not a single, unified path SELinux-wise. Change-Id: I13ca09cf2458b22ffb6c70b8a353e891e810c606 Signed-off-by: Vladimir Oltean <olteanv@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 2814cfc - Browse repository at this point
Copy the full SHA 2814cfcView commit details -
sepolicy: Treat proc-based DT fstab the same and sys-based
* Older devices have a DT fstab in proc, so we need to expand our policy to make this first-class like the fancy, new, sys devices Change-Id: I3cfed1e8e9fdf8665f1348fa07fa42d4f37873e9
Configuration menu - View commit details
-
Copy full SHA for 31f3ea2 - Browse repository at this point
Copy the full SHA 31f3ea2View commit details -
Allow init to write to /proc/cpu/alignment
* AOSP init.rc attempts to write to /proc/cpu/alignment, but following 84e181b, general access to procfs nodes is prohibited. * Add an appropriate type, genfscon, and allow to permit this action. Change-Id: I31ad8eaa6ebb6dd57d1b9c4395cb22cdd0d7b3d3 (cherry picked from commit 6213f5041a6e9242b2a23c8cc85d0d76cbc1fc45)
Configuration menu - View commit details
-
Copy full SHA for faa2181 - Browse repository at this point
Copy the full SHA faa2181View commit details
Commits on Mar 2, 2021
-
Merge tag 'android-11.0.0_r32' into staging/lineage-18.1_merge-androi…
Configuration menu - View commit details
-
Copy full SHA for f351416 - Browse repository at this point
Copy the full SHA f351416View commit details
Commits on Mar 21, 2021
-
Allow dumpstate to get thermal and power hal debug info
Bug: 156710131 Bug: 170070222 Test: tested in userdebug with dumpstate.unroot set to true Change-Id: Iabd636f109e719753fdd650f05e1a7af835c49d7 Signed-off-by: TeYuan Wang <kamewang@google.com> (cherry picked from commit 900c723)
Configuration menu - View commit details
-
Copy full SHA for 8baeefa - Browse repository at this point
Copy the full SHA 8baeefaView commit details -
Allow dumpstate to dump hal_light
Bug: 162594434 Bug: 170070222 Test: atest android.security.cts.SELinuxHostTest#testNoBugreportDenials Signed-off-by: Roman Kiryanov <rkir@google.com> Change-Id: I440b5627abe0127324679fcb54bc52a68c44bea4 (cherry picked from commit 83b88d5)
Roman Kiryanov authored and Michael Bestas committedMar 21, 2021 Configuration menu - View commit details
-
Copy full SHA for 73da57f - Browse repository at this point
Copy the full SHA 73da57fView commit details -
Add ro.cdma.home.operator. properties
vendor_init writes ro.cdma.home.operator. properties, and framework codes reads the properties. This adds them to telephony_config_prop to explicitly allow it. Bug: 157958356 Bug: 173683489 Test: boot Change-Id: I3bd515bd7adcc01ec268e4d2b5a6a2f1fbca7deb (cherry picked from commit 18cbb77)
Configuration menu - View commit details
-
Copy full SHA for 46d058f - Browse repository at this point
Copy the full SHA 46d058fView commit details -
Add ro.cpuvulkan.version to property_contexts
Bug: 173683489 Test: vts_treble_sys_prop_test Test: VulkanTest Change-Id: I4d78ed5de6640c4342c4f6c2362976577007a681 (cherry picked from commit f1a7f16)
Configuration menu - View commit details
-
Copy full SHA for 5a9e45a - Browse repository at this point
Copy the full SHA 5a9e45aView commit details -
Sepolicy for dumsys suspend_control in bugreport
Bug: 155836352 Test: adb shell am bug-report && check logcat for denials Change-Id: I8b65ea7c798121679bf27ce667c787a8dcbf5aae (cherry picked from commit 215751a)
Kalesh Singh authored and Michael Bestas committedMar 21, 2021 Configuration menu - View commit details
-
Copy full SHA for 996e744 - Browse repository at this point
Copy the full SHA 996e744View commit details -
Export ro.vendor.product.cpu.abilist*
Bug: 173452246 Test: Read these properties from system_server Change-Id: I26b8bbe153d55a2761ecc304a490a03a27156667
Configuration menu - View commit details
-
Copy full SHA for 95da6f3 - Browse repository at this point
Copy the full SHA 95da6f3View commit details
Commits on Apr 9, 2021
-
disable unused gmscore_app domain
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 8cc89f9 - Browse repository at this point
Copy the full SHA 8cc89f9View commit details -
allow system to use persist.keyguard.camera
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for f74daa0 - Browse repository at this point
Copy the full SHA f74daa0View commit details -
label protected_{fifos,regular} as proc_security
This is needed for init to override the default values. Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for c79f3d4 - Browse repository at this point
Copy the full SHA c79f3d4View commit details -
drop support for preloads_copy
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 167745d - Browse repository at this point
Copy the full SHA 167745dView commit details -
remove priv_app app_data_file execute
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 8cc9cf9 - Browse repository at this point
Copy the full SHA 8cc9cf9View commit details -
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 58ccf25 - Browse repository at this point
Copy the full SHA 58ccf25View commit details -
Moving back towards an exception system. Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 668b83d - Browse repository at this point
Copy the full SHA 668b83dView commit details -
Moving back towards an exception system. Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 7a73e2c - Browse repository at this point
Copy the full SHA 7a73e2cView commit details -
add base system seinfo for shared/release keys
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com> Change-Id: Ic7ecf8a49805772741a4bb6537466a3f1b7b2d5f
Configuration menu - View commit details
-
Copy full SHA for 471e493 - Browse repository at this point
Copy the full SHA 471e493View commit details -
split out untrusted base app domains
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com> Change-Id: I107b8365c938f03b7d98fefa01763cee6732eb57
Configuration menu - View commit details
-
Copy full SHA for d135986 - Browse repository at this point
Copy the full SHA d135986View commit details -
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for f4c9505 - Browse repository at this point
Copy the full SHA f4c9505View commit details -
remove base system app execmod
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 1c743bd - Browse repository at this point
Copy the full SHA 1c743bdView commit details -
remove base system app execmem
GrapheneOS doesn't use the ART JIT compiler. Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 5f5750b - Browse repository at this point
Copy the full SHA 5f5750bView commit details -
remove base app app_data_file execute_no_trans
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for bddf5f5 - Browse repository at this point
Copy the full SHA bddf5f5View commit details -
remove base system app app_data_file execute
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 366d68e - Browse repository at this point
Copy the full SHA 366d68eView commit details -
remove base system app ashmem execute
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 9f2650b - Browse repository at this point
Copy the full SHA 9f2650bView commit details -
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for f862ca4 - Browse repository at this point
Copy the full SHA f862ca4View commit details -
remove base system app tmpfs execute
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 1b70770 - Browse repository at this point
Copy the full SHA 1b70770View commit details -
auditallow apk_data_file execute
For libraries, apps should be migrating to the more modern approach of storing them in the apk uncompressed and mapping them directly from it. This is the most modern approach available for executables and is better than using app data, but ideally it wouldn't be done. For now, audit use of `execute_no_trans` anyway while this is given more thought. Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for eab1c9a - Browse repository at this point
Copy the full SHA eab1c9aView commit details
There are no files selected for viewing