racoon: allow ioctl TUNSETIFF
Used by
bf16586a33/main.c (116)
Addresses the following denial:
audit(0.0:8126): avc: denied { ioctl } for comm="racoon" path="/dev/tun" dev="tmpfs" ino=25329 ioctlcmd=0x54ca scontext=u:r:racoon:s0 tcontext=u:object_r:tun_device:s0 tclass=chr_file permissive=0
Test: policy compiles.
Change-Id: Ia26077d4a9e810c7006d4b979d6b7e9ca154b485
This commit is contained in:
parent
7ef01c34ed
commit
3ddaa63bde
1 changed files with 1 additions and 0 deletions
|
@ -10,6 +10,7 @@ allowxperm racoon self:udp_socket ioctl { SIOCSIFFLAGS SIOCSIFADDR SIOCSIFNETMAS
|
|||
binder_use(racoon)
|
||||
|
||||
allow racoon tun_device:chr_file r_file_perms;
|
||||
allowxperm racoon tun_device:chr_file ioctl TUNSETIFF;
|
||||
allow racoon cgroup:dir { add_name create };
|
||||
allow racoon kernel:system module_request;
|
||||
|
||||
|
|
Loading…
Reference in a new issue