Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    89e379e9
    shell: Reduce socket ioctl perms · 89e379e9
    Jeff Vander Stoep authored
    Only allow shell to access the same subset of ioctl commands as
    untrusted_app. This reduces the attack surface of the kernel
    available to a local attacker.
    
    Bug: 26324307
    Bug: 26267358
    Change-Id: Ib8ecb9546af5fb480d2622149d4e00ec50cd4cde
    89e379e9
    History
    shell: Reduce socket ioctl perms
    Jeff Vander Stoep authored
    Only allow shell to access the same subset of ioctl commands as
    untrusted_app. This reduces the attack surface of the kernel
    available to a local attacker.
    
    Bug: 26324307
    Bug: 26267358
    Change-Id: Ib8ecb9546af5fb480d2622149d4e00ec50cd4cde
shell.te 4.45 KiB