diff options
| author | Chenbo Feng <fengc@google.com> | 2018-07-23 19:05:56 -0700 |
|---|---|---|
| committer | Chenbo Feng <fengc@google.com> | 2018-07-31 12:36:47 -0700 |
| commit | 661654739d1b73a8054de7002e88ce8961ee74f5 (patch) | |
| tree | 95b7017009125d431325b7449d2c2dc8784360f4 /server/TetherControllerTest.cpp | |
| parent | bdce8eb59d79ed53be0aaac0432492eee39aed4d (diff) | |
Check netutils_wrapper don't use file capabilities
The netutils_wrapper is called by a variety of vendor processes. If the
netutils_wrapper is granted CAP_NET_ADMIN by filesystem capabilities, it
may also grant such capability to all vendor domains that run this
executable. To prevent that, adding a test to make sure the
netutils_wrapper binary doesn't have filesystem capabilities setup.
Bug: 72644927
Test: atest netd_integration_test
Change-Id: I856b0782bcb3f84be2925c995a6f8b64d16ffe33
Diffstat (limited to 'server/TetherControllerTest.cpp')
0 files changed, 0 insertions, 0 deletions
