Prevents against unterminated user chains in iptables policy 62/118562/2
authorAnish Singhania <a.singhania@samsung.com>
Thu, 9 Mar 2017 14:02:41 +0000 (19:32 +0530)
committerRafal Krypa <r.krypa@samsung.com>
Mon, 13 Mar 2017 07:13:37 +0000 (08:13 +0100)
[Model] SM-Z400F
[BinType] AP
[Customer] Open

[Issue#]
[Request] PM
[Occurrence Version]

[Problem] Kernel panic occurs on enabling nether flags
[Cause & Measure] Add unconditional return rules to two use defined chains created
[Checking Method]

[Team] Security
[Developer] Anish Singhania
[Solution company] Samsung
[Change Type] Market Issue

Change-Id: I8a5cbacc2418d5268599ebbcc581cfe7227d88d1
Signed-off-by: Anish Singhania <a.singhania@samsung.com>
Signed-off-by: Rafal Krypa <r.krypa@samsung.com>
conf/nether.rules

index 71b6464f790d2c094fc110b549ada66693d684b5..b31ba4615950fa01f50da12d614f819349bfc7a3 100644 (file)
@@ -37,6 +37,8 @@ COMMIT
 -A OUTPUT -m mark --mark 0x3 -j NETHER-DENY
 -A OUTPUT -m mark --mark 0x4 -j NETHER-ALLOWLOG
 -A NETHER-ALLOWLOG -j AUDIT --type accept
+-A NETHER-ALLOWLOG -j RETURN
 -A NETHER-DENY -j AUDIT --type reject
 -A NETHER-DENY -j REJECT --reject-with icmp-port-unreachable
+-A NETHER-DENY -j RETURN
 COMMIT