Skip to content
Snippets Groups Projects
Commit 80b1b43a authored by Lorenzo Colitti's avatar Lorenzo Colitti Committed by Gerrit Code Review
Browse files

Merge "Remove clatd's dac_override abilities."

parents ee43230f 1d75c90b
No related branches found
No related tags found
No related merge requests found
...@@ -17,9 +17,6 @@ allow clatd netd:unix_dgram_socket { read write }; ...@@ -17,9 +17,6 @@ allow clatd netd:unix_dgram_socket { read write };
allow clatd self:capability { net_admin net_raw setuid setgid }; allow clatd self:capability { net_admin net_raw setuid setgid };
# TODO: Run clatd in vpn group to avoid need for this on /dev/tun.
allow clatd self:capability dac_override;
allow clatd self:netlink_route_socket nlmsg_write; allow clatd self:netlink_route_socket nlmsg_write;
allow clatd self:{ packet_socket rawip_socket tun_socket } create_socket_perms; allow clatd self:{ packet_socket rawip_socket tun_socket } create_socket_perms;
allow clatd tun_device:chr_file rw_file_perms; allow clatd tun_device:chr_file rw_file_perms;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment