mirror of
https://github.com/torvalds/linux.git
synced 2026-06-07 14:04:54 +02:00
ANDROID: Turn xt_owner module on
Once xt_qtaguid module is deprecated, the netd strictController which uses owner match to filter egress traffic will not work because xt_qtaguid masquerades as (and implements/extends) the "owner" module on android devices. It can be resolved by turning upstream xt_owner module back on since strictController only targets egress traffic and the upstream xt_owner module works fine in this case. Signed-off-by: Chenbo Feng <fengc@google.com> Bug: 79938294 Test: manual cherry-pick and compile Change-Id: Ia099db025f17f6042384c9f0caf7b941a40b8b84
This commit is contained in:
parent
f9df80a9ae
commit
6548078271
|
|
@ -143,6 +143,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y
|
|||
CONFIG_NETFILTER_XT_MATCH_LIMIT=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MAC=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MARK=y
|
||||
CONFIG_NETFILTER_XT_MATCH_OWNER=y
|
||||
CONFIG_NETFILTER_XT_MATCH_POLICY=y
|
||||
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y
|
||||
CONFIG_NETFILTER_XT_MATCH_QUOTA=y
|
||||
|
|
|
|||
|
|
@ -147,6 +147,7 @@ CONFIG_NETFILTER_XT_MATCH_LENGTH=y
|
|||
CONFIG_NETFILTER_XT_MATCH_LIMIT=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MAC=y
|
||||
CONFIG_NETFILTER_XT_MATCH_MARK=y
|
||||
CONFIG_NETFILTER_XT_MATCH_OWNER=y
|
||||
CONFIG_NETFILTER_XT_MATCH_POLICY=y
|
||||
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=y
|
||||
CONFIG_NETFILTER_XT_MATCH_QUOTA=y
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user