summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMaciej Żenczykowski <maze@google.com>2020-01-24 05:24:06 -0800
committerMaciej Żenczykowski <maze@google.com>2020-01-24 05:25:25 -0800
commitc3199dc0cdc1a658fce75d11694c21fd990948a9 (patch)
treec30aed3c33762c13414ebd920a1bf6f6b1730cfe
parent36c8f501aaf82b9a3c45e4b5d46bfd9e7531c982 (diff)
downloadpoplar-c3199dc0cdc1a658fce75d11694c21fd990948a9.tar.gz
netd does not require and should not have SYS_ADMIN nor module loading privs
Any required functionally should be built into the kernel. Test: NA Signed-off-by: Maciej Żenczykowski <maze@google.com> Change-Id: Ide42a95a36707a2fec3b641cbdcacfbc44a16d3d
-rw-r--r--sepolicy/netd.te2
1 files changed, 0 insertions, 2 deletions
diff --git a/sepolicy/netd.te b/sepolicy/netd.te
deleted file mode 100644
index a4af5c0..0000000
--- a/sepolicy/netd.te
+++ /dev/null
@@ -1,2 +0,0 @@
-allow netd kernel:system { module_request };
-allow netd self:capability { sys_admin sys_module };