commit | 7045e27d4946330f3152218fdaa81b37d02b6d6c | [log] [tgz] |
---|---|---|
author | Lorenzo Colitti <lorenzo@google.com> | Fri Jun 13 21:36:01 2014 +0900 |
committer | Lorenzo Colitti <lorenzo@google.com> | Fri Jun 13 21:44:10 2014 +0900 |
tree | cd9137751fe8cfc55f890a061bcf8f9519c1f6f5 | |
parent | b9b471e1e3788a398adeb0a04bfc52d6ba7c3cf6 [diff] |
Create the tun device after dropping root privileges. Currently, clatd creates the clat4 interface as root using root's dac_override abilities. Instead, change the drop_root code to acquire membership in the AID_VPN group, and use that membership to create the interface. This removes the need for dac_override. Change-Id: I1f824254f52a441f21c5b7963d9993be88cea2db