{"repo":"GrapheneOS/platform_system_sepolicy","free":true,"listed":false,"github":"https://github.com/GrapheneOS/platform_system_sepolicy","clone":"git clone https://github.com/GrapheneOS/platform_system_sepolicy.git","description":"Base SELinux policy (extended by per-device repositories)","language":"Python","stars":22,"topics":["android","security","privacy","grapheneos"],"license":null,"category":"mobile-apps","readme_excerpt":"Android SEPolicy This directory contains the core Android SELinux policy configuration. It defines the domains and types for the AOSP services and apps common to all devices. Device-specific policy should be placed under a separate device/ / /sepolicy subdirectory and linked into the policy build as described below. Policy Generation Additional, per device, policy files can be added into the policy build. These files should have each line including the final line terminated by a newline character ( 0x0A ). This will allow files to be concatenated and processed whenever the m4 (1) macro processor is called by the build process. Adding the newline will also make the intermediate text files easier to read when debugging build failures. The sets of file, service and property contexts files will automatically have a newline inserted between each file as these are common failure points. These device policy files can be configured through the use of the BOARD VENDOR SEPOLICY DIRS variable. This variable should be set in the BoardConfig.mk file in the device or vendor directories. BOARD VENDOR SEPOLICY DIRS contains a list of directories to search for additional policy files. Order matters in this list. For example, if you have 2 instances of widget.te files in the BOARD VENDOR SEPOLICY DIRS search path, then the first one found (at the first search dir containing the file) will be concatenated first. Reviewing out/target/product/ /obj/ETC/vendor sepolicy.conf intermediates/vendor se","default_branch":null,"files":null,"tree":[],"storefront":"/r/GrapheneOS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/GrapheneOS/platform_system_sepolicy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}