Page MenuHomeFreeBSD

libc: allow posix_fallocate in capability mode
ClosedPublic

Authored by emaste on Oct 11 2017, 7:46 PM.
Tags
None
Referenced Files
F168192268: D12640.id.diff
Wed, Aug 26, 7:38 PM
F168183217: D12640.diff
Wed, Aug 26, 6:30 PM
Unknown Object (File)
Mon, Aug 24, 9:58 PM
Unknown Object (File)
Mon, Aug 24, 9:57 PM
Unknown Object (File)
Fri, Aug 14, 4:44 AM
Unknown Object (File)
Wed, Aug 12, 7:08 PM
Unknown Object (File)
Sat, Aug 8, 5:28 PM
Unknown Object (File)
Sat, Aug 8, 10:45 AM
Subscribers
None

Details

Summary

posix_fallocate is logically equivalent to writing zero blocks to the desired file size and there is no reason to prevent calling it in capability mode. posix_fallocate already checked for the CAP_WRITE right, so we merely need to list it in capabilities.conf.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Per discussion on the recent capsicum call, posix_fallocate could require CAP_PWRITE (aka CAP_WRITE | CAP_SEEK) instead of just CAP_WRITE.

Require CAP_PWRITE (CAP_WRITE | CAP_SEEK) for posix_fallocate.

This revision is now accepted and ready to land.Oct 12 2017, 2:04 AM
This revision was automatically updated to reflect the committed changes.