Skip to content
Snippets Groups Projects
Commit d0ed9d0a authored by Lorenzo Colitti's avatar Lorenzo Colitti Committed by android-build-merger
Browse files

Don't allow dumpstate to call ioctl on netlink_tcpdiag_socket. am: a8239c61 am: 1376638d

am: 0a10b00e

Change-Id: I35ec7f134e24193e189d9fc7c9bd1d325b70ff6a
parents 40196b4b 0a10b00e
No related branches found
No related tags found
No related merge requests found
......@@ -142,7 +142,7 @@ allow dumpstate net_data_file:dir search;
allow dumpstate net_data_file:file r_file_perms;
# List sockets via ss.
allow dumpstate self:netlink_tcpdiag_socket { create_socket_perms nlmsg_read };
allow dumpstate self:netlink_tcpdiag_socket { create_socket_perms_no_ioctl nlmsg_read };
# Access /data/tombstones.
allow dumpstate tombstone_data_file:dir r_dir_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment