HomeFreeBSD

Add some new options to mac_bsdestended. We can now match on:
rS157986Unpublished

Unpublished Commit ยท Learn More

No further details are available.

Description

Add some new options to mac_bsdestended. We can now match on:

subject: ranges of uid, ranges of gid, jail id
objects: ranges of uid, ranges of gid, filesystem,

		object is suid, object is sgid, object matches subject uid/gid
		object type

We can also negate individual conditions. The ruleset language is
a superset of the previous language, so old rules should continue
to work.

These changes require a change to the API between libugidfw and the
mac_bsdextended module. Add a version number, so we can tell if
we're running mismatched versions.

Update man pages to reflect changes, add extra test cases to
test_ugidfw.c and add a shell script that checks that the the
module seems to do what we expect.

Suggestions from: rwatson, trhodes
Reviewed by: trhodes
MFC after: 2 months

Details

Provenance
dwmaloneAuthored on
Parents
rS157985: style(9) treatment following fixups.
Branches
Unknown
Tags
Unknown