Permalink
Browse files

Merge "init.rc: setup qtaguid group ownership of ctrl and stat files"

  • Loading branch information...
2 parents d084ec9 + 3e54aab commit fb69c2e2577e056bb7a054343a9f6d781cedbf3d JP Abgrall committed with Gerrit Code Review Jan 5, 2013
Showing with 6 additions and 0 deletions.
  1. +6 −0 rootdir/init.rc
View
@@ -120,6 +120,12 @@ loglevel 3
write /dev/cpuctl/apps/bg_non_interactive/cpu.rt_runtime_us 700000
write /dev/cpuctl/apps/bg_non_interactive/cpu.rt_period_us 1000000
+# qtaguid will limit access to specific data based on group memberships.
+# net_bw_acct grants impersonation of socket owners.
+# net_bw_stats grants access to other apps' detailed tagged-socket stats.
+ chown root net_bw_acct /proc/net/xt_qtaguid/ctrl
+ chown root net_bw_stats /proc/net/xt_qtaguid/stats
+
# Allow everybody to read the xt_qtaguid resource tracking misc dev.
# This is needed by any process that uses socket tagging.
chmod 0644 /dev/xt_qtaguid

0 comments on commit fb69c2e

Please sign in to comment.