Skip to content
Snippets Groups Projects
Commit 109f9e62 authored by Nick Kralevich's avatar Nick Kralevich Committed by Gerrit Code Review
Browse files

Merge "Restore netdomain allow rules."

parents ede81a8a ca0759b1
No related branches found
No related tags found
No related merge requests found
...@@ -2,3 +2,17 @@ ...@@ -2,3 +2,17 @@
type node, node_type; type node, node_type;
type netif, netif_type; type netif, netif_type;
type port, port_type; type port, port_type;
# Use network sockets.
allow netdomain self:{ tcp_socket udp_socket } *;
# Connect to ports.
allow netdomain port_type:tcp_socket name_connect;
# Bind to ports.
allow netdomain node_type:{ tcp_socket udp_socket } node_bind;
allow netdomain port_type:udp_socket name_bind;
allow netdomain port_type:tcp_socket name_bind;
# Get route information.
allow netdomain self:netlink_route_socket { create bind read nlmsg_read };
# Talks to netd via dnsproxyd socket.
unix_socket_connect(netdomain, dnsproxyd, netd)
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment