mirror of
https://github.com/hardkernel/linux.git
synced 2026-06-06 19:08:57 +09:00
ANDROID: Turn xt_owner module on
Once xt_qtaguid module is deprecated, the netd strictController which uses owner match to filter egress traffic will not work because xt_qtaguid masquerades as (and implements/extends) the "owner" module on android devices. It can be resolved by turning upstream xt_owner module back on since strictController only targets egress traffic and the upstream xt_owner module works fine in this case. Signed-off-by: Chenbo Feng <fengc@google.com> Bug: 79938294 Test: manual cherry-pick and compile Change-Id: Ia099db025f17f6042384c9f0caf7b941a40b8b84
This commit is contained in:
@@ -143,6 +143,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y
|
||||
CONFIG_NETFILTER_XT_MATCH_LIMIT=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MAC=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MARK=y
|
||||
CONFIG_NETFILTER_XT_MATCH_OWNER=y
|
||||
CONFIG_NETFILTER_XT_MATCH_POLICY=y
|
||||
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y
|
||||
CONFIG_NETFILTER_XT_MATCH_QUOTA=y
|
||||
|
||||
@@ -147,6 +147,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y
|
||||
CONFIG_NETFILTER_XT_MATCH_LIMIT=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MAC=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MARK=y
|
||||
CONFIG_NETFILTER_XT_MATCH_OWNER=y
|
||||
CONFIG_NETFILTER_XT_MATCH_POLICY=y
|
||||
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y
|
||||
CONFIG_NETFILTER_XT_MATCH_QUOTA=y
|
||||
|
||||
Reference in New Issue
Block a user