Open iptables-restore pipes with O_CLOEXEC.
This improves security and reliability, and also avoids keeping superflous fds open in iptables-restore processes: the pipe fds that are dup2()d are never closed. Bug: 28362720 Test: bullhead builds, boots Test: netd_{unit,integration}_test pass Change-Id: Ifb57082a6c711f0684fc37a254076e84ad097b6e
Loading
Please register or sign in to comment