Commits

Show all
Author Commit Message Labels Comments Date
Robert Craig
Add persist.mac_enforcing_mode property
Tags
2 tags
Branches
seandroid-4.0.4
Joshua Brindle
add SELinux network labeling script to startup Change-Id: I47100243b04d9629d44c8962eafeacabdcd0e6d2 Signed-off-by: Joshua Brindle <jbrindle@tresys.com>
Branches
seandroid-4.0.4
Stephen Smalley
Set the SELinux security label on new directories. Automatically set the SELinux security label on directories created by init.rc. This avoids the need to separately call restorecon on each such directory from the init.rc file.
Branches
seandroid-4.0.4
Stephen Smalley
Code cleanups based on AOSP review of 36321.
Branches
seandroid-4.0.4
Stephen Smalley
Fix error messages when unable to load sepolicy or file_contexts. Don't just display the last pathname we tried, as it may be irrelevant.
Branches
seandroid-4.0.4
Stephen Smalley
Skip the ro. prefix before any MAC permission checks.
Branches
seandroid-4.0.4
Stephen Smalley
Implement SELinux/MAC permission checks for the init property service. Requires updated libselinux, sepolicy, and build.
Branches
seandroid-4.0.4
Stephen Smalley
Fix permissions/ownerships on /data/tombstones and /data/anr.
Branches
seandroid-4.0.4
Stephen Smalley
restorecon /data/anr
Branches
seandroid-4.0.4
Stephen Smalley
Restart installd on policy reload.
Branches
seandroid-4.0.4
Stephen Smalley
Allow system UID to set enforcing status and booleans.
Branches
seandroid-4.0.4
Stephen Smalley
Check /data/system/file_contexts first in restorecon.
Branches
seandroid-4.0.4
Stephen Smalley
Support for reloading SELinux policy and file_contexts upon updates, and support for loading them from /data/system rather than / if present there.
Branches
seandroid-4.0.4
Stephen Smalley
Modify init.rc and init.goldfish.rc for SE Android. If on the emulator, set a policy boolean and restore the context of /sys/qemu_trace to allow accesses not normally permitted on a device. Set the security context for the init process. Restore the security contexts of various runtime directories and files. Specify the security context for services launched from the rootfs since we cannot label their executables. Change-Id: I166ffc267e8e0543732e71…
Branches
seandroid-4.0.4
Stephen Smalley
Add support for -R (recurse) to init chown builtin. This is helpful for setting ownerships on entire directory trees, such as sysfs and selinuxfs, particularly when the precise set of files is dynamically generated at runtime. Change-Id: I81070ea36fd7ffcab4ee8b3ef1bb0028d4b7839c Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov> Conflicts: init/builtins.c
Branches
seandroid-4.0.4
Stephen Smalley
Extend toolbox with SE Android support. Add -Z option to ls and ps for displaying security contexts. Modify id to display security context. Add new SELinux commands: chcon, getenforce, getsebool, load_policy, restorecon, runcon, setenforce, setsebool. Change-Id: Ia20941be4a6cd706fe392fed6e38a37d880ec5f1
Branches
seandroid-4.0.4
Stephen Smalley
Extend init and ueventd for SE Android. Add SE Android support for init and ueventd. init: - Load policy at boot. - Set the security context for service daemons and their sockets. - New built-in commands: setcon, setenforce, restorecon, setsebool. - New option for services: seclabel. ueventd: - Set the security context for device directories and nodes. Change-Id: I98ed752cde503c94d99dfa5b5a47e3c33db16aac Conflicts: init/init.c
Branches
seandroid-4.0.4
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
Tags
5 tags
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
Chia-chi Yeh
init.rc: update the permission of /data/local. Bug: 6131945 Change-Id: I3094a471dcfb02b786f47b6778c8fed3726325ec
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
Xavier Ducrohet
Add USB vendor IDs for Quanta, INQ and Sony. Change-Id: I224e067d9a64e8e9e7afbad0760a4b07f965bf83
Tags
android-cts-4.0.3_r2
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
Andrew Hsieh
Add Intel's vendor ID to adb Change-Id: I81da3ea11bfd44395f6895fe51e477ff1e7fa25b
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
benoitandroid
Merge "HACK: Export androidboot.modelno as ro.boot.modelno -- DO NOT MERGE" into ics-mr1
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
benoitandroid
HACK: Export androidboot.modelno as ro.boot.modelno -- DO NOT MERGE Export androidboot.modelno command line parameter as ro.boot.modelno property, so that we can set the USB iProduct string to the correct value on Stingray. Bug: 5853250 Change-Id: Idc413f15dc4d9d02027589d1b11bdf50e0a79ccc
The Android Automerger
merge in ics-mr1-release history after reset to ics-mr1
  1. Prev
  2. Next