Skip to content
Snippets Groups Projects
Commit 7eb3dd3b authored by Nathan Harold's avatar Nathan Harold
Browse files

Update Common NetD SEPolicy to allow Netlink XFRM

In order to perform XFRM operations NetD needs the
ability to both read and write Netlink XFRM messages.

Bug: 34811756
Test: 34812052

Change-Id: I26831c58b24a4c1f344b113f0b5cf47ed2c93fee
parent 63211f8d
No related branches found
No related tags found
No related merge requests found
...@@ -80,6 +80,9 @@ allow netd netdomain:{ ...@@ -80,6 +80,9 @@ allow netd netdomain:{
} { read write getattr setattr getopt setopt }; } { read write getattr setattr getopt setopt };
allow netd netdomain:fd use; allow netd netdomain:fd use;
# give netd permission to read and write netlink xfrm
allow netd self:netlink_xfrm_socket { create_socket_perms_no_ioctl nlmsg_write nlmsg_read };
### ###
### Neverallow rules ### Neverallow rules
### ###
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment