HomeFreeBSD

bhyve/slirp: Drop privileges before entering capability mode

Description

bhyve/slirp: Drop privileges before entering capability mode

When in restricted mode, the slirp-helper process enters a capsicum
sandbox, after which we cannot look up the uid for the "nobody" user.
Reverse the order.

Reported by: kp
Fixes: 0e62ebd20172 ("bhyve: Move the slirp backend out into a separate process")

Details

Provenance
markjAuthored on Mon, Nov 24, 2:15 PM
Parents
rGbac572b2b1c9: bhyve/slirp: Avoid a nested declaration of environ
Branches
Unknown
Tags
Unknown