We restrict the (optional) input file and output files. It would be
nice to restrict the KVM files, but that's up to libkvm.
We wait until after kvm_nlist() is invoked to cap_enter() because
kldsym() isn't supported in the Capsicum sandbox.
Differential D7921
ktrdump(8): Capsicumify cem on Sep 18 2016, 6:19 AM. Authored by Tags None Referenced Files
Subscribers
Details
We restrict the (optional) input file and output files. It would be We wait until after kvm_nlist() is invoked to cap_enter() because
Diff Detail
Event Timeline
Comment Actions
|