diff options
author | Ricardo Mestre <mestre@cvs.openbsd.org> | 2019-08-10 01:30:54 +0000 |
---|---|---|
committer | Ricardo Mestre <mestre@cvs.openbsd.org> | 2019-08-10 01:30:54 +0000 |
commit | 3a2b5b6269ed550cbc37a571c4cfe7615e9bf12e (patch) | |
tree | 5e11e9264158aabd05e080b19b5ed321ce3dd5b6 /etc/root | |
parent | 7f429250c453f4a46f6680a28b067efe439ade11 (diff) |
Like we did on other daemons that cannot be pledged due to forbidden ioctls the
main process can be unveiled to restrict filesystem access. In this case we can
restrict it to only read, although it must be the entire / since the daemon is
able to include config files from anywhere.
Additionally the ldpe process currently has cpath promise to unlink the socket,
nevertheless the socket is actually unlinked from the main proc so this
permission can be removed. As we discussed before, leaving the socket behind
doesn't do any harm that's why I didn't unveil it in the main proc.
OK deraadt@
Diffstat (limited to 'etc/root')
0 files changed, 0 insertions, 0 deletions