Page MenuHomeFreeBSD

capabilities.conf: try to clarify what system calls are in here

Authored by emaste on Wed, Mar 18, 7:33 PM.

Diff Detail

rS FreeBSD src repository
Automatic diff as part of commit; lint not applicable.
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

emaste created this revision.Wed, Mar 18, 7:33 PM
emaste added a reviewer: rstone.
emaste added inline comments.
34 ↗(On Diff #69658)

maybe "no purpose, so they are not listed here and not permitted in capability mode."

emaste added inline comments.Wed, Mar 18, 7:38 PM
31 ↗(On Diff #69658)

by "fully or partially" I'm trying to convey that the system call either never accesses gn or aa (say, close), or internally performs capability mode checks (say, openat). Would be good to have a way to concisely express this.

jhb accepted this revision.Thu, Mar 26, 5:50 PM
jhb added inline comments.
31 ↗(On Diff #69658)


34 ↗(On Diff #69658)

I would drop the comma after "purpose" and keep the text you have. Maybe add a comma after "In capability mode"

This revision is now accepted and ready to land.Thu, Mar 26, 5:50 PM