Commit Graph

  • 5e65e958c8 basic: non_plat: Drop duplicate proc_dirty label bka Sarthak Roy 2025-12-04 22:03:33 +05:30
  • eccbac7a11 basic: non_plat: Drop system_server neverallow Sarthak Roy 2025-11-19 21:29:42 +05:30
  • 9bc99b2fd0 basic: non_plat: Rename proc_vm_dirty to proc_dirty Yumi Yukimura 2025-09-01 02:33:49 +08:00
  • 5a6829050c basic: non_plat: Allow update_engine to write to bootdevice Erfan Abdi 2023-03-30 23:50:15 +03:30
  • dd2e76aaee basic: non_plat: Label OSS bluetooth AIDL service Mashopy 2025-08-14 21:42:31 +02:00
  • f5c49c44b4 bsp: non_plat: Remove unused drmserver getpidcon policy Sarthak Roy 2025-06-11 12:13:37 +05:30
  • 331a6724d9 basic: non_plat: Label AIDL NXP NFC service bengris32 2024-11-27 00:27:09 +00:00
  • 22d564be27 basic: non_plat: Allow charger_vendor to access drm/fb device nodes bengris32 2024-09-20 13:08:24 +01:00
  • 2bb87dddbe basic: non_plat: Remove mtk_hal_sensors type bengris32 2024-08-27 13:22:25 +01:00
  • 6fcc55b754 debug: Avoid accessing binderfs logs Dhina17 2024-09-14 13:54:03 +05:30
  • 7a087664de basic: non_plat: Drop duplicate declaration of iso9660 Matsvei Niaverau 2024-09-24 15:17:34 +02:00
  • 30d5c6176d basic: plat_private: Drop duplicate declaration of ro.audio.usb.period_us Aaron Kling 2024-08-23 14:16:39 -05:00
  • ff40c184bf basic: non_plat: Use rw_dir_file macro bengris32 2024-06-06 14:15:57 +01:00
  • 05f90a1102 basic: non_plat: Allow libperfmgr to access PPM nodes bengris32 2024-06-06 14:11:41 +01:00
  • 0d10533a25 basic: Allow nvram_daemon to get/set vendor_mtk_service_nvram_restore_prop techyminati 2024-06-17 14:25:34 +05:30
  • 7dd07597c1 basic: non_plat: Address more nvram_daemon denial ZiadTamer 2024-05-23 22:49:58 +03:00
  • 7cb40986f9 basic: Allow power HAL to access mtk devfreq node bengris32 2024-05-20 14:56:34 +02:00
  • ed72d0212d basic: Allow power HAL to access gpufreqv2 node bengris32 2024-05-19 18:30:47 +02:00
  • b0d0eb3154 sepolicy: Inherit common lineage power sepolicy Giovanni Ricca 2024-05-19 18:21:18 +02:00
  • 9db6f1e8a0 basic: non_plat: Allow mtk_hal_usb to create file and directory in configfs Abhinav Kumar 2024-04-28 19:52:14 +05:30
  • 209e8c8f10 sepolicy: Exclude debug sepolicies on user build SamarV-121 2024-03-30 10:58:48 +05:30
  • 4428c661ba basic: non_plat: Allow update_engine to write to logo partition Matsvei Niaverau 2024-04-11 12:33:20 +02:00
  • c33742f894 basic: non_plat: Label logo partition as A/B Matsvei Niaverau 2024-04-11 12:16:26 +02:00
  • d2d073ce17 basic: non_plat: Label MediaTek USB Gadget HAL bengris32 2024-03-01 19:40:59 +00:00
  • 18632d849e basic: non_plat: Allow binder services to r/w su:tcp_socket Yifan Hong 2024-03-22 16:13:29 +00:00
  • c148d3271a basic: Drop dtbo_block_device duplicate declaration Sarthak Roy 2024-03-20 22:48:01 +05:30
  • 850b3d36fd basic: non_plat: Unlabel preloader_raw block devices bengris32 2024-03-01 15:04:53 +00:00
  • d6e1e340cc basic: plat_private: Label create_pl_dev bengris32 2024-02-29 20:37:28 +00:00
  • b2b0b1bb8f basic: non_plat: Label PELT multiplier node bengris32 2024-02-28 21:02:52 +00:00
  • 1263da2195 basic: non_plat: Label AIDL MediaTek USB legacy service Matsvei Niaverau 2024-02-16 15:49:45 +01:00
  • d22a2ab888 basic: non_plat: Address OSS USB gadget HAL denials bengris32 2024-02-15 12:45:19 +00:00
  • ab2549b89a basic: non_plat: Address init.insmod.sh denials Woomymy 2024-02-15 12:02:05 +00:00
  • 40ea9e1bf7 basic: non_plat: Let GPU reload Adam Shih 2024-02-12 21:13:00 +00:00
  • 4098d11dc5 bsp: plat_private: Label system_ext kpoc_charger Matsvei Niaverau 2024-02-09 15:44:33 +01:00
  • 02bdb90a6e basic: non_plat: Allow vendor_init to set audio/pq properties bengris32 2024-02-07 22:53:35 +00:00
  • 66e32b32e1 basic: Allow keymint to set soter props Giovanni Ricca 2024-01-02 21:22:00 +01:00
  • 508c45b356 basic: Allow mtk_hal_nvramagent access to dts nodes Giovanni Ricca 2024-01-02 16:10:24 +01:00
  • 6d2525868e bsp: Allow netutils_wrapper access to misc devices Giovanni Ricca 2024-01-02 16:07:43 +01:00
  • ff24786f5a bsp: Label system_ext vtservice Giovanni Ricca 2024-01-01 22:20:52 +01:00
  • 532b60ca02 sepolicy: Guard invalid labels Giovanni Ricca 2023-12-28 10:35:43 +00:00
  • 6de1ec34cc bsp: plat_private: Define mtk_hal_sf_service Giovanni Ricca 2023-12-27 22:33:42 +00:00
  • c420b9b98e bsp: non_plat: Remove duplicate labels Giovanni Ricca 2023-12-27 22:30:52 +00:00
  • a55780d6aa bsp: plat_private: Allow radio to get system_mtk_vodata_prop bengris32 2023-12-25 12:14:15 +00:00
  • 461b31145f sepolicy: Use BOARD_VENDOR_SEPOLICY_DIRS Felix 2023-12-22 16:31:24 +00:00
  • 88ca19b34a basic: non_plat: Label MediaTek audio service bengris32 2023-12-21 16:30:59 +00:00
  • c5509c7506 basic: non_plat: Label AIDL thermal service bengris32 2023-12-19 22:41:10 +00:00
  • 2864204ce0 sepolicy: Drop duplicate declaration of mediaserver64/drmserver64 Sarthak Roy 2023-09-03 11:14:14 +05:30
  • a58d7459e5 sepolicy: isolated_app -> isolated_app_all SamarV-121 2023-09-03 10:22:36 +05:30
  • d0ef16e8db sepolicy: Drop fuseblk duplicate declaration Sarthak Roy 2023-09-03 09:50:18 +05:30
  • f3e97c194d basic: non_plat: Label AIDL ST NFC service bengris32 2023-10-23 23:25:58 +01:00
  • fd99152e17 basic: non_plat: Allow rebalance_interrupts to read affected_cpus bengris32 2023-09-05 13:18:58 +01:00
  • 011d637e43 basic: non_plat: Import pixel rebalance_interrupts rules bengris32 2023-09-05 13:12:00 +01:00
  • 1313d51047 treewide: Completely drop mtk_hal_audio type bengris32 2023-09-05 00:04:05 +01:00
  • a75fe8033b basic: non_plat: Label AIDL ConsumerIr service bengris32 2023-09-04 23:59:45 +01:00
  • 5deeb70766 basic: non_plat: Kang pixel thermal SEPolicy Woomymy 2023-09-04 23:05:11 +01:00
  • 572ec1ab71 basic: non_plat: Label AIDL MediaTek USB service bengris32 2023-09-04 22:58:39 +01:00
  • 246b7d6cbf basic: non_plat: Label MediaTek health AIDL SamarV-121 2023-08-29 12:20:09 +01:00
  • 9817fe434d basic: non_plat: Allow communication between mtk_hal_power and hal_power_default Woomymy 2023-08-18 22:16:15 +01:00
  • 0f211dd090 basic: non_plat: Share PowerHAL property for libperf and mtkpower bengris32 2023-08-16 21:23:43 +01:00
  • c322485915 sepolicy: bsp: private: Add support for T ims Erfan Abdi 2023-04-08 09:03:04 +03:30
  • 526d1f2d0e sepolicy: basic: non_plat: Allow {vendor_}init to write to sysfs_devices_block bengris32 2023-08-06 22:47:22 +01:00
  • 63f03be658 sepolicy: basic: non_plat: Allow vendor_init to adjust dirty_writeback_centisecs bengris32 2023-08-06 22:17:25 +01:00
  • d73d1700e3 sepolicy: basic: non_plat: Allow Sensors HAL to write to SCP log bengris32 2023-08-06 22:09:46 +01:00
  • e4dbda893d sepolicy: basic: non_plat: Allow PQ HAL to use /dev/ion bengris32 2023-08-06 22:06:52 +01:00
  • 16d912d4b2 sepolicy: basic: non_plat: Label 13000000.mali memtrack nodes bengris32 2023-08-06 20:12:05 +01:00
  • 7d3ebfc10b sepolicy: basic: non_plat: Label /class/thermal sysfs bengris32 2023-08-06 18:00:40 +01:00
  • baea66a53f sepolicy_vndr: add sepolicy for power off alarm nift4 2023-07-22 23:27:03 +02:00
  • 431046546e sepolicy: Add rules for mediatek mali memtrack HAL SamarV-121 2023-04-27 15:56:53 +05:30
  • 168dfe22c0 sepolicy: Initial sepolicy for power-libperfmgr Vaisakh Murali 2022-10-05 20:43:23 +01:00
  • d3173a129b sepolicy: Label stub mtkpower service bengris32 2022-10-05 19:50:42 +01:00
  • cd4658785d sepolicy: Label thunderquake_engine nodes SamarV-121 2023-04-27 14:48:40 +05:30
  • 6c1dc1cc06 sepolicy: Allow init to create xcap sockets SamarV-121 2022-09-14 09:15:40 +05:30
  • 8c706294c1 sepolicy: Add rules for xcap SamarV-121 2023-02-09 12:20:06 +05:30
  • 22b3052286 sepolicy: Allow init to create wfca_rds sockets SamarV-121 2022-09-12 17:11:27 +00:00
  • 5800f20308 Revert "sepolicy: basic: non_plat: Allow mediacodec to read vendor_mtk_hdr_video_prop" LinkBoi00 2023-03-19 22:35:29 +02:00
  • 062b82634e sepolicy: basic: non_plat: Allow audio HAL to read and write vendor_mtk_audio_prop LinkBoi00 2022-12-01 03:17:23 +02:00
  • 40db888e15 sepolicy: basic: non_plat: Label a few more audio properties LinkBoi00 2022-11-29 21:53:33 +02:00
  • 80ca7b0e68 sepolicy: basic: non_plat: Allow rild to access NVRAM HAL LinkBoi00 2022-11-30 23:59:36 +02:00
  • 4683bfcc08 sepolicy: basic: non_plat: Label microtrust SE service LinkBoi00 2022-11-30 10:00:07 +02:00
  • dc84220dbd sepolicy: bsp: plat_private: Fixup musb-hdrc cmode device typo LinkBoi00 2022-10-04 17:01:02 +03:00
  • d62a4a891d sepolicy: basic: non_plat: Label all versioned secure_element services LinkBoi00 2022-11-29 22:36:54 +02:00
  • 6b4f51c3b5 sepolicy: basic: non_plat: Label proper location for libaiselector.so LinkBoi00 2022-11-29 17:27:55 +02:00
  • 3c90852f99 sepolicy: basic: non_plat: Allow mtk fm app to access /dev/fm Zinadin Zidan 2022-10-27 00:36:01 +03:00
  • 3de9a934ad sepolicy: basic: non_plat: Label all versions of MMS service Matsvei Niaverau 2022-10-15 23:48:40 +03:00
  • a5ba3aa187 sepolicy: basic: non_plat: Allow mediacodec to read sysfs_boot_mode SamarV-121 2022-09-18 12:08:22 +05:30
  • b924fa4058 sepolicy: basic: non_plat: Add selinux rules for mtkcodecservice HAL SamarV-121 2022-09-17 11:43:05 +05:30
  • ca74f59339 sepolicy: basic: non_plat: Address vpud_native denials SamarV-121 2022-09-15 19:23:21 +05:30
  • 440f5f9ee7 sepolicy: basic: non_plat: Address mediaswcodec denials SamarV-121 2022-09-15 11:07:05 +05:30
  • 173aae2fb1 sepolicy: bsp: non_plat: Grant all network permissions to ipsec_mon SamarV-121 2022-09-14 22:56:58 +05:30
  • 6f21f83c67 sepolicy: basic: non_plat: Allow mediacodec to read vendor_mtk_hdr_video_prop SamarV-121 2022-09-14 22:40:29 +05:30
  • 8a583e3348 sepolicy: basic: non_plat: Allow mediacodec to read some props SamarV-121 2022-09-13 18:48:52 +05:30
  • 224041dad4 sepolicy: basic: plat_private: Remove mapping files SamarV-121 2022-09-14 10:06:05 +05:30
  • f40f049d12 fixup! sepolicy: basic: non_plat: Add rules for MediaTek GPU HAL * Dropped in S sepolicy but we need it since we have blobs from R. Matsvei Niaverau 2022-10-11 16:59:10 +03:00
  • 812fea90fa sepolicy: basic: non_plat: Allow all unstrusted apps to read thermal info bengris32 2022-09-09 21:37:41 +01:00
  • 952e2e6368 sepolicy: basic: non_plat: Drop proc_cpu_alignment type * Moved into AOSP sepolicy. bengris32 2022-08-26 15:38:09 +01:00
  • e24c0688e9 sepolicy: bsp: Fix Netflix widevine L1 denies TheMalachite 2022-02-07 14:41:41 +06:00
  • 695d5c0359 sepolicy: basic: non_plat: Address Audio HAL tcp_socket neverallow * Due to system SEPolicy/audioserver changes in Android 13, mtk_hal_audio needs to be allowed to create and use TCP sockets. Signed-off-by: bengris32 <bengris32@protonmail.ch> bengris32 2022-08-22 20:49:58 +01:00
  • 0f2e6efe70 sepolicy: basic: non_plat: Drop proc_watermark_boost_factor type * Already defined in AOSP sepolicy. bengris32 2022-08-20 12:08:55 +01:00
  • b2fd09835a sepolicy: basic: non_plat: Drop proc_watermark_scale_factor type * Defined in AOSP T sepolicy. bengris32 2022-08-20 12:08:06 +01:00
  • a17351d505 sepolicy: basic: non_plat: Rename sysfs_gpu to sysfs_gpu_mtk * A duplicate type is already defined in AOSP sepolicy. bengris32 2022-08-20 12:05:57 +01:00