Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    bff98015
    Enforce ioctl command whitelisting on all sockets · bff98015
    Jeff Vander Stoep authored
    Remove the ioctl permission for most socket types. For others, such as
    tcp/udp/rawip/unix_dgram/unix_stream set a default unprivileged whitelist
    that individual domains may extend (except where neverallowed like
    untrusted_app). Enforce via a neverallowxperm rule.
    
    Change-Id: I15548d830f8eff1fd4d64005c5769ca2be8d4ffe
    bff98015
    History
    Enforce ioctl command whitelisting on all sockets
    Jeff Vander Stoep authored
    Remove the ioctl permission for most socket types. For others, such as
    tcp/udp/rawip/unix_dgram/unix_stream set a default unprivileged whitelist
    that individual domains may extend (except where neverallowed like
    untrusted_app). Enforce via a neverallowxperm rule.
    
    Change-Id: I15548d830f8eff1fd4d64005c5769ca2be8d4ffe