HomeFreeBSD

Jail and capability mode for shm_rename; add audit support for shm_rename

Description

Jail and capability mode for shm_rename; add audit support for shm_rename

Co-mingling two things here:

  • Addressing some feedback from Konstantin and Kyle re: jail, capability mode, and a few other things
  • Adding audit support as promised.

The audit support change includes a partial refresh of OpenBSM from
upstream, where the change to add shm_rename has already been
accepted. Matthew doesn't plan to work on refreshing anything else to
support audit for those new event types.

Submitted by: Matthew Bryan <matthew.bryan@isilon.com>
Reviewed by: kib
Relnotes: Yes
Sponsored by: Dell EMC Isilon
Differential Revision: https://reviews.freebsd.org/D22083

Details