/[base]
ViewVC logotype

Revision 339446


Jump to revision: Previous Next
Author: jamie
Date: Sat Oct 20 16:20:36 2018 UTC (5 years, 8 months ago)
Changed paths: 6
Log Message:
MFC r339409, r339420:

  Add a new jail permission, allow.read_msgbuf.  When true, jailed processes
  can see the dmesg buffer (this is the current behavior).  When false (the
  new default), dmesg will be unavailable to jailed users, whether root or
  not.

  The security.bsd.unprivileged_read_msgbuf sysctl still works as before,
  controlling system-wide whether non-root users can see the buffer.

PR:		211580
Submitted by:	bz


Changed paths

Path Details
Directorystable/11/ modified , props changed
Directorystable/11/sys/kern/kern_jail.c modified , text changed
Directorystable/11/sys/kern/kern_priv.c modified , text changed
Directorystable/11/sys/kern/subr_prf.c modified , text changed
Directorystable/11/sys/sys/jail.h modified , text changed
Directorystable/11/usr.sbin/jail/jail.8 modified , text changed

  ViewVC Help
Powered by ViewVC 1.1.27