Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 566ae3eb authored by Nick Kralevich's avatar Nick Kralevich Committed by android-build-merger
Browse files

Merge "init.rc: Lock down access to /proc/net/fib_trie" into oc-mr1-dev

am: c3090ba2

Change-Id: I9ffa9c76b807c8439f05388f4b8aae3d131bac5a
parents 096d8034 c3090ba2
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -148,6 +148,9 @@ on init
    write /proc/sys/net/ipv4/conf/all/accept_redirects 0
    write /proc/sys/net/ipv6/conf/all/accept_redirects 0

    # /proc/net/fib_trie leaks interface IP addresses
    chmod 0400 /proc/net/fib_trie

    # Create cgroup mount points for process groups
    mkdir /dev/cpuctl
    mount cgroup none /dev/cpuctl cpu