index
:
FreeBSD-src
RELENG_2_2
RELENG_2_3
RELENG_2_3_0
RELENG_2_3_1
RELENG_2_3_2
RELENG_2_3_3
RELENG_2_3_4
RELENG_2_4
RELENG_2_4_4
RELENG_2_4_OLD
devel
devel-11
releng/10.1
releng/10.3
releng/11.0
releng/11.1
stable/10
stable/11
Raptor Engineering's fork of pfsense FreeBSD src with pfSense changes
Raptor Engineering, LLC
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
sys
/
kern
/
kern_prot.c
Commit message (
Expand
)
Author
Age
Files
Lines
*
o Fix SCTP ICMPv6 error message vulnerability. [SA-16:01.sctp]
glebius
2016-01-14
1
-2
/
+1
*
MFC r277322:
kib
2015-01-25
1
-0
/
+7
*
[SA-14:25] Fix kernel stack disclosure in setlogin(2) / getlogin(2).
des
2014-11-04
1
-15
/
+16
*
Style fix
bapt
2012-11-14
1
-1
/
+1
*
return ERANGE if the buffer is too small to contain the login as documented in
bapt
2012-11-14
1
-0
/
+2
*
Fix a typo. (s/nessesary/necessary/)
hrs
2012-01-08
1
-1
/
+1
*
In order to maximize the re-usability of kernel code in user space this
kmacy
2011-09-16
1
-27
/
+27
*
Notify racct when process credentials change.
trasz
2011-03-31
1
-0
/
+10
*
Add two new system calls, setloginclass(2) and getloginclass(2). This makes
trasz
2011-03-05
1
-0
/
+4
*
Add some FEATURE macros for various features (AUDIT/CAM/IPC/KTR/MAC/NFS/NTP/
netchild
2011-02-25
1
-0
/
+5
*
Revert r210225 - turns out I was wrong; the "/*-" is not license-only
trasz
2010-07-18
1
-16
/
+16
*
The "/*-" comment marker is supposed to denote copyrights. Remove non-copyright
trasz
2010-07-18
1
-16
/
+16
*
Only allocate the space we need before calling kern_getgroups instead
brooks
2010-01-15
1
-1
/
+7
*
Replace the static NGROUPS=NGROUPS_MAX+1=1024 with a dynamic
brooks
2010-01-12
1
-6
/
+6
*
Remove the interim vimage containers, struct vimage and struct procg,
jamie
2009-07-17
1
-15
/
+1
*
Remove crcopy call from seteuid now that it calls crcopysafe.
jamie
2009-07-08
1
-1
/
+0
*
Replace AUDIT_ARG() with variable argument macros with a set more more
rwatson
2009-06-27
1
-15
/
+15
*
Change crsetgroups_locked() (called by crsetgroups()) to sort the
brooks
2009-06-20
1
-10
/
+45
*
Rework the credential code to support larger values of NGROUPS and
brooks
2009-06-19
1
-35
/
+135
*
Move "options MAC" from opt_mac.h to opt_global.h, as it's now in GENERIC
rwatson
2009-06-05
1
-1
/
+0
*
Add internal 'mac_policy_count' counter to the MAC Framework, which is a
rwatson
2009-06-02
1
-2
/
+0
*
Introduce an interm userland-kernel API for creating vnets and
zec
2009-05-31
1
-1
/
+5
*
Add hierarchical jails. A jail may further virtualize its environment
jamie
2009-05-27
1
-19
/
+10
*
Introduce a new virtualization container, provisionally named vprocg, to hold
zec
2009-05-08
1
-0
/
+10
*
Improve the consistency of MAC Framework and MAC policy entry point
rwatson
2009-03-08
1
-9
/
+9
*
The userland_sysctl() function retries sysctl_root() until returned
kib
2008-12-12
1
-1
/
+1
*
Retire the MALLOC and FREE macros. They are an abomination unto style(9).
des
2008-10-23
1
-8
/
+8
*
Add cr_canseeinpcb() doing checks using the cached socket
bz
2008-10-17
1
-0
/
+35
*
Merge first in a series of TrustedBSD MAC Framework KPI changes
rwatson
2007-10-24
1
-18
/
+18
*
Eliminate now-unused SUSER_ALLOWJAIL arguments to priv_check_cred(); in
rwatson
2007-06-12
1
-39
/
+20
*
Move per-process audit state from a pointer in the proc structure to
rwatson
2007-06-07
1
-0
/
+9
*
Further system call comment cleanup:
rwatson
2007-03-05
1
-6
/
+4
*
Remove 'MPSAFE' annotations from the comments above most system calls: all
rwatson
2007-03-04
1
-97
/
+3
*
Sort copyrights together.
rwatson
2007-01-08
1
-2
/
+4
*
Add a new priv(9) kernel interface for checking the availability of
rwatson
2006-11-06
1
-89
/
+58
*
Complete break-out of sys/sys/mac.h into sys/security/mac/mac_framework.h
rwatson
2006-10-22
1
-1
/
+1
*
Declare security and security.bsd sysctl hierarchies in sysctl.h along
rwatson
2006-09-17
1
-3
/
+1
*
Add kern_setgroups() and kern_getgroups() and use them to implement
jhb
2006-07-06
1
-25
/
+42
*
Audit the arguments (user/group IDs) for the system calls that set these IDs.
wsalamon
2006-02-06
1
-0
/
+17
*
Use the refcount API to manage the reference count for user credentials
jhb
2005-09-27
1
-16
/
+6
*
Introduce p_canwait() and MAC Framework and MAC Policy entry points
rwatson
2005-04-18
1
-0
/
+31
*
Introduce new MAC Framework and MAC Policy entry points to control the use
rwatson
2005-04-16
1
-53
/
+137
*
Impose the upper limit on signals that are allowed between kernel threads
sobomax
2005-03-18
1
-2
/
+2
*
Linuxthreads uses not only signal 32 but several signals >= 32.
sobomax
2005-03-18
1
-5
/
+5
*
In linux emulation layer try to detect attempt to use linux_clone() to
sobomax
2005-03-03
1
-0
/
+12
*
Backout addition of SIGTHR into the list of signals allowed to be delivered
sobomax
2005-02-13
1
-1
/
+0
*
Backout previous change (disabling of security checks for signals delivered
sobomax
2005-02-13
1
-4
/
+5
*
Split out kill(2) syscall service routine into user-level and kernel part, the
sobomax
2005-02-13
1
-5
/
+4
*
Add SIGTHR (32) into list of signals permitted to be delivered to the
sobomax
2005-02-11
1
-0
/
+1
*
Style cleanup: with removal of mutex operations, we can also remove
rwatson
2005-01-23
1
-4
/
+2
[next]