HomeFreeBSD

netstat: strip the binary of sgid

Description

netstat: strip the binary of sgid

Everything in the live path seems to use sysctls these days, with kvm
only being used for pulling information from core dumps. Strip the
binary of /dev/{k,}mem access to reduce the surface area with access
to kmem.

Reviewed by: glebius, markj
Differential Revision: https://reviews.freebsd.org/D47210

Details

Provenance
kevansAuthored on Apr 20 2025, 6:18 PM
Reviewer
glebius
Differential Revision
D47210: netstat: strip the binary of sgid
Parents
rGd8fd55143870: bintrans: disable argument permutation for qp and base64
Branches
Unknown
Tags
Unknown