summaryrefslogtreecommitdiffstats
path: root/share/man/man9
diff options
context:
space:
mode:
authortrasz <trasz@FreeBSD.org>2015-08-02 09:34:03 +0000
committertrasz <trasz@FreeBSD.org>2015-08-02 09:34:03 +0000
commite063ea329987f541e4ce113c808c2111e4276a23 (patch)
tree48cd40b20c380933f542c9ea3d5af768b5280aea /share/man/man9
parentd141e091d1f32ad5154df0470c20a9fff5f58e9b (diff)
downloadFreeBSD-src-e063ea329987f541e4ce113c808c2111e4276a23.zip
FreeBSD-src-e063ea329987f541e4ce113c808c2111e4276a23.tar.gz
MFC r285873:
Update Capsicum and Mandatory Access Control manual pages to no longer claim they are experimental. Sponsored by: The FreeBSD Foundation
Diffstat (limited to 'share/man/man9')
-rw-r--r--share/man/man9/mac.917
1 files changed, 1 insertions, 16 deletions
diff --git a/share/man/man9/mac.9 b/share/man/man9/mac.9
index cc05c5a..d1e86ad 100644
--- a/share/man/man9/mac.9
+++ b/share/man/man9/mac.9
@@ -33,7 +33,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd July 10, 2006
+.Dd July 25, 2015
.Dt MAC 9
.Os
.Sh NAME
@@ -62,14 +62,6 @@ opportunity to modify security behavior at those MAC API entry points.
Both consumers of the API (normal kernel services) and security modules
must be aware of the semantics of the API calls, particularly with respect
to synchronization primitives (such as locking).
-.Ss Note on Appropriateness for Production Use
-The
-.Tn TrustedBSD
-MAC Framework included in
-.Fx 5.0
-is considered experimental, and should not be deployed in production
-environments without careful consideration of the risks associated with
-the use of experimental operating system features.
.Ss Kernel Objects Supported by the Framework
The MAC framework manages labels on a variety of types of in-kernel
objects, including process credentials, vnodes, devfs_dirents, mount
@@ -232,13 +224,6 @@ Additional contributors include:
and
.An Tim Robbins .
.Sh BUGS
-See the earlier section in this document concerning appropriateness
-for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
OpenPOWER on IntegriCloud