diff options
author | Chenbo Feng <fengc@google.com> | 2019-02-08 15:53:02 -0800 |
---|---|---|
committer | Amit Pundir <amit.pundir@linaro.org> | 2019-02-15 12:37:50 +0530 |
commit | 323878e0280a66a531ecad04971cadf98d6d82f2 (patch) | |
tree | 7a4d9cc9dd91bd07eb15e85c0e7aedc17a278bba | |
parent | 17e37d0f223ae3fb5f8ddef4a9ff07a422d82091 (diff) | |
download | kernel_replicant_linux-323878e0280a66a531ecad04971cadf98d6d82f2.tar.gz kernel_replicant_linux-323878e0280a66a531ecad04971cadf98d6d82f2.tar.bz2 kernel_replicant_linux-323878e0280a66a531ecad04971cadf98d6d82f2.zip |
ANDROID: Turn xt_owner module on
Once xt_qtaguid module is deprecated, the netd strictController which
uses owner match to filter egress traffic will not work because
xt_qtaguid masquerades as (and implements/extends) the "owner" module on
android devices. It can be resolved by turning upstream xt_owner module
back on since strictController only targets egress traffic and the
upstream xt_owner module works fine in this case.
Signed-off-by: Chenbo Feng <fengc@google.com>
Bug: 79938294
Test: manual cherry-pick and compile
Change-Id: Ia099db025f17f6042384c9f0caf7b941a40b8b84
-rw-r--r-- | arch/arm64/configs/cuttlefish_defconfig | 1 | ||||
-rw-r--r-- | arch/x86/configs/x86_64_cuttlefish_defconfig | 1 |
2 files changed, 2 insertions, 0 deletions
diff --git a/arch/arm64/configs/cuttlefish_defconfig b/arch/arm64/configs/cuttlefish_defconfig index 6d833e9b5d1c..b724b5fa635f 100644 --- a/arch/arm64/configs/cuttlefish_defconfig +++ b/arch/arm64/configs/cuttlefish_defconfig @@ -141,6 +141,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y CONFIG_NETFILTER_XT_MATCH_LIMIT=y CONFIG_NETFILTER_XT_MATCH_MAC=y CONFIG_NETFILTER_XT_MATCH_MARK=y +CONFIG_NETFILTER_XT_MATCH_OWNER=y CONFIG_NETFILTER_XT_MATCH_POLICY=y CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y CONFIG_NETFILTER_XT_MATCH_QUOTA=y diff --git a/arch/x86/configs/x86_64_cuttlefish_defconfig b/arch/x86/configs/x86_64_cuttlefish_defconfig index e8bc98bbb0db..42bff352e0fa 100644 --- a/arch/x86/configs/x86_64_cuttlefish_defconfig +++ b/arch/x86/configs/x86_64_cuttlefish_defconfig @@ -147,6 +147,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y CONFIG_NETFILTER_XT_MATCH_LIMIT=y CONFIG_NETFILTER_XT_MATCH_MAC=y CONFIG_NETFILTER_XT_MATCH_MARK=y +CONFIG_NETFILTER_XT_MATCH_OWNER=y CONFIG_NETFILTER_XT_MATCH_POLICY=y CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y CONFIG_NETFILTER_XT_MATCH_QUOTA=y |