summaryrefslogtreecommitdiff
path: root/sys/security/mac_bsdextended
AgeCommit message (Expand)Author
2025-09-17MAC/bsdextended: Restore matching subjects' effective GIDOlivier Certner
2024-12-16MAC: mac_policy.h: Declare common MAC sysctl and jail parameters' nodesOlivier Certner
2024-11-21mac_bsdextended: Remove \n from sysctl descriptionsEd Maste
2023-08-16sys: Remove $FreeBSD$: two-line .h patternWarner Losh
2020-05-21Deduplicate fsid comparisonsRyan Moeller
2020-02-26Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (17 of many)Pawel Biernacki
2018-12-11Remove unused argument to priv_check_cred.Mateusz Guzik
2017-06-13Correct bitwise test in mac_bsdextended ugidfw_rule_valid()Ed Maste
2014-06-28Pull in r267961 and r267973 again. Fix for issues reported will follow.Hans Petter Selasky
2014-06-27Revert r267961, r267973:Glen Barber
2014-06-27Extend the meaning of the CTLFLAG_TUN flag to automatically check ifHans Petter Selasky
2011-11-07Mark all SYSCTL_NODEs static that have no corresponding SYSCTL_DECLs.Ed Schouten
2011-11-07Mark MALLOC_DEFINEs static that have no corresponding MALLOC_DECLAREs.Ed Schouten
2009-05-27Add hierarchical jails. A jail may further virtualize its environmentJamie Gritton
2009-03-29Get rid of VSTAT and replace it with VSTAT_PERMS, which is somewhatEdward Tomasz Napierala
2009-03-09Mark the bsdextended rules sysctl as being mpsafe.Christian S.J. Peron
2009-03-08Remove 'uio' argument from MAC Framework and MAC policy entry points forRobert Watson
2009-01-10Rather than having MAC policies explicitly declare what object typesRobert Watson
2008-11-29MFp4:Bjoern A. Zeeb
2008-10-30The V* flags passed using an accmode_t to the access() and open()Robert Watson
2008-10-28Introduce accmode_t. This is required for NFSv4 ACLs - it will be neccessaryEdward Tomasz Napierala
2008-10-27When the mac_bsdextended policy is unloaded, free rule memory.Robert Watson
2008-10-27Add TrustedBSD credit to new ugidfw_internal.h file.Robert Watson
2008-10-27Break mac_bsdextended.c out into multiple .c files, with the base accessRobert Watson
2008-10-27Copy mac_bsdextended.c to two object-specific files as a prototype for howRobert Watson
2008-10-23Fix a number of style issues in the MALLOC / FREE commit. I've tried toDag-Erling Smørgrav
2008-10-23Retire the MALLOC and FREE macros. They are an abomination unto style(9).Dag-Erling Smørgrav
2008-09-17Remove the suser(9) interface from the kernel. It has been replaced fromAttilio Rao
2008-09-10Remove VSVTX, VSGID and VSUID. This should be a no-op,Edward Tomasz Napierala
2008-08-28Decontextualize the couplet VOP_GETATTR / VOP_SETATTR as the passed threadAttilio Rao
2008-08-23Introduce two related changes to the TrustedBSD MAC Framework:Robert Watson
2008-07-31In mac_bsdextended's auditctl and acct policy access control checks,Robert Watson
2007-10-29Resort TrustedBSD MAC Framework policy entry point implementations andRobert Watson
2007-10-25Consistently name functions for mac_<policy> as <policy>_whatever ratherRobert Watson
2007-10-24Merge first in a series of TrustedBSD MAC Framework KPI changesRobert Watson
2007-09-10Rename mac_check_vnode_delete() MAC Framework and MAC Policy entryRobert Watson
2007-07-05In preparation for 7.0 privilege cleanup, clean up style:Robert Watson
2007-06-13Include priv.h to pick up suser(9) definitions, missed in an earlierRobert Watson
2007-04-23Apply variable name normalization to MAC policies: adopt global conventionsRobert Watson
2007-04-21Allow MAC policy modules to control access to audit configuration systemRobert Watson
2007-02-23More unnecessary include reduction.Robert Watson
2007-02-20Move mapping of MBI_APPEND to MBI_WRITE from inside the rule loop inRobert Watson
2007-02-06Continue 7-CURRENT MAC Framework rearrangement and cleanup:Robert Watson
2006-12-22Move src/sys/sys/mac_policy.h, the kernel interface between the MACRobert Watson
2006-11-06Sweep kernel replacing suser(9) calls with priv(9) calls, assigningRobert Watson
2006-04-23Add some new options to mac_bsdestended. We can now match on:David Malone
2006-03-04Create a mac_bsdextended_check_vp function that takes a cred, aDavid Malone
2006-01-15Fix potential overrun of static stack allocated array which storesChristian S.J. Peron
2005-07-28If a "hole" opens up in the ruleset (i.e.: remove 5), do not returnTom Rhodes
2005-04-22Add locking support to mac_bsdextended:Tom Rhodes