summaryrefslogtreecommitdiffstats
path: root/sys/dev/agp
diff options
context:
space:
mode:
authorcsjp <csjp@FreeBSD.org>2004-08-22 02:03:41 +0000
committercsjp <csjp@FreeBSD.org>2004-08-22 02:03:41 +0000
commitd0350352a9ac6f35143f8c18966f26aa3970c902 (patch)
tree79d531ed91847970f3f74d5bc5548c045c45bd58 /sys/dev/agp
parent2989f4181e7709db305f59b9f47870562880f9f8 (diff)
downloadFreeBSD-src-d0350352a9ac6f35143f8c18966f26aa3970c902.zip
FreeBSD-src-d0350352a9ac6f35143f8c18966f26aa3970c902.tar.gz
Currently, if the secure level is low enough, system flags can
be manipulated by prison root. In 4.x prison root can not manipulate system flags, regardless of the security level. This behavior should remain consistent to avoid any surprises which could lead to security problems for system administrators which give out privileged access to jails. This commit changes suser_cred's flag argument from SUSER_ALLOWJAIL to 0. This will prevent prison root from being able to manipulate system flags on files. This may be a MFC candidate for RELENG_5. Discussed with: cperciva Reviewed by: rwatson Approved by: bmilekic (mentor) PR: kern/70298
Diffstat (limited to 'sys/dev/agp')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud