summaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorJason McIntyre <jmc@cvs.openbsd.org>2015-09-09 21:54:03 +0000
committerJason McIntyre <jmc@cvs.openbsd.org>2015-09-09 21:54:03 +0000
commit77865bff7888a21b6ccc0d958c961ce2dcacf3cb (patch)
treec2018e01804c45ccbaa8ba69bdf319899635360d /lib
parentc70608aef8f7aedb3c17fc2779d5cd4694d06602 (diff)
seperate->separate;
while here, i've adjusted the formatting of one list
Diffstat (limited to 'lib')
-rw-r--r--lib/libc/sys/tame.212
1 files changed, 9 insertions, 3 deletions
diff --git a/lib/libc/sys/tame.2 b/lib/libc/sys/tame.2
index b5a82b75d7a..4250e4288ac 100644
--- a/lib/libc/sys/tame.2
+++ b/lib/libc/sys/tame.2
@@ -1,4 +1,4 @@
-.\" $OpenBSD: tame.2,v 1.25 2015/09/09 17:56:59 deraadt Exp $
+.\" $OpenBSD: tame.2,v 1.26 2015/09/09 21:54:02 jmc Exp $
.\"
.\" Copyright (c) 2015 Nicholas Marriott <nicm@openbsd.org>
.\"
@@ -102,13 +102,15 @@ permit the following system calls:
.Pp
Some system calls, when allowed, have restrictions applied to them:
.Pp
-.Bl -tag -width "tmppath" -offset indent -compact
+.Bl -tag -width "readlink(2)" -offset indent -compact
.It Xr access 2
May check for existence of
.Pa /etc/localtime .
+.Pp
.It Xr adjtime 2
Read-only, for
.Xr ntpd 8 .
+.Pp
.It Xr chmod 2
.It Xr fchmod 2
.It Xr fchmodat 2
@@ -118,6 +120,7 @@ Read-only, for
.It Xr fchownat 2
Setuid/setgid/sticky bits are ignored.
The user or group cannot be changed on a file.
+.Pp
.It Xr open 2
May open
.Pa /etc/localtime ,
@@ -127,9 +130,11 @@ and files ending in
.Pa libc.cat
below the directory
.Pa /usr/share/nls/ .
+.Pp
.It Xr readlink 2
May operate on
.Pa /etc/malloc.conf .
+.Pp
.It Xr sysctl 3
A small set of read-only operations are allowed, sufficient to
support:
@@ -138,6 +143,7 @@ support:
.Xr getifaddrs 3 ,
.Xr uname 3 ,
system sensor readings.
+.Pp
.It Xr tame 2
Can only reduce permissions; can only set a list of
.Pa paths
@@ -146,7 +152,7 @@ once.
.Pp
The
.Ar request
-is specified as a string, with space seperate keywords:
+is specified as a string, with space separate keywords:
.Bl -tag -width "tmppath" -offset indent
.It Va "malloc"
To allow use of the