Skip to content
Snippets Groups Projects
Commit 9a6fb6b0 authored by Lorenzo Colitti's avatar Lorenzo Colitti Committed by android-build-merger
Browse files

Don't allow dumpstate to call ioctl on netlink_tcpdiag_socket. am: a8239c61...

Don't allow dumpstate to call ioctl on netlink_tcpdiag_socket. am: a8239c61 am: 1376638d am: 0a10b00e
am: d0ed9d0a

Change-Id: I439bd7cf7cd1e3b8d6f64357db66c44b53cca1c0
parents ef086b6f d0ed9d0a
No related branches found
No related tags found
No related merge requests found
......@@ -142,7 +142,7 @@ allow dumpstate net_data_file:dir search;
allow dumpstate net_data_file:file r_file_perms;
# List sockets via ss.
allow dumpstate self:netlink_tcpdiag_socket { create_socket_perms nlmsg_read };
allow dumpstate self:netlink_tcpdiag_socket { create_socket_perms_no_ioctl nlmsg_read };
# Access /data/tombstones.
allow dumpstate tombstone_data_file:dir r_dir_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment