Make the xtables lock readable only by AID_RADIO and root.
Anyone who can read this file can call flock(..., LOCK_EX) on it, thereby blocking any future iptables commands from running. Restrict it to user AID_RADIO, which includes device-specific network management daemons, and group root. Bug: 36108349 Test: see https://android-review.googlesource.com/#/c/348939/ Change-Id: I4dae4b5a835fabdc1a61a330e0446b39651f8156
Loading
Please register or sign in to comment