diff options
author | Ricardo Mestre <mestre@cvs.openbsd.org> | 2017-07-04 23:13:10 +0000 |
---|---|---|
committer | Ricardo Mestre <mestre@cvs.openbsd.org> | 2017-07-04 23:13:10 +0000 |
commit | e4ba1fcc6e45eaefb6f8f64ffb6a3c7950918143 (patch) | |
tree | fefcd1607256dac17473025e78d213bd8531ad4e | |
parent | 19095986117f7d1580d3e225a098d2e8b5c5a34b (diff) |
Revert back previous, pledge cannot be enabled on the privsep'd proc yet, at
least not as is
Reported by tim@, OK deraadt@ to backout the pledge for now
-rw-r--r-- | sbin/pflogd/privsep.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/sbin/pflogd/privsep.c b/sbin/pflogd/privsep.c index 6b81bc6339a..00ed9ca6a74 100644 --- a/sbin/pflogd/privsep.c +++ b/sbin/pflogd/privsep.c @@ -1,4 +1,4 @@ -/* $OpenBSD: privsep.c,v 1.25 2017/06/12 23:37:44 mestre Exp $ */ +/* $OpenBSD: privsep.c,v 1.26 2017/07/04 23:13:09 mestre Exp $ */ /* * Copyright (c) 2003 Can Erkin Acar @@ -118,8 +118,11 @@ priv_init(void) setproctitle("[priv]"); close(socks[1]); +#if notyet + /* This needs to do bpf ioctl */ if (pledge("stdio rpath wpath cpath sendfd proc bpf", NULL) == -1) err(1, "pledge"); +#endif while (!gotsig_chld) { if (may_read(socks[0], &cmd, sizeof(int))) |