summaryrefslogtreecommitdiff
path: root/etc/root
diff options
context:
space:
mode:
authorRicardo Mestre <mestre@cvs.openbsd.org>2019-08-10 01:30:54 +0000
committerRicardo Mestre <mestre@cvs.openbsd.org>2019-08-10 01:30:54 +0000
commit3a2b5b6269ed550cbc37a571c4cfe7615e9bf12e (patch)
tree5e11e9264158aabd05e080b19b5ed321ce3dd5b6 /etc/root
parent7f429250c453f4a46f6680a28b067efe439ade11 (diff)
Like we did on other daemons that cannot be pledged due to forbidden ioctls the
main process can be unveiled to restrict filesystem access. In this case we can restrict it to only read, although it must be the entire / since the daemon is able to include config files from anywhere. Additionally the ldpe process currently has cpath promise to unlink the socket, nevertheless the socket is actually unlinked from the main proc so this permission can be removed. As we discussed before, leaving the socket behind doesn't do any harm that's why I didn't unveil it in the main proc. OK deraadt@
Diffstat (limited to 'etc/root')
0 files changed, 0 insertions, 0 deletions