diff options
author | Theo de Raadt <deraadt@cvs.openbsd.org> | 2015-11-20 23:16:01 +0000 |
---|---|---|
committer | Theo de Raadt <deraadt@cvs.openbsd.org> | 2015-11-20 23:16:01 +0000 |
commit | 3d9909217d438dcb7957ccecb6416b9280b2f26d (patch) | |
tree | 96878ab7e1b0a0591a8d3482db4e894bc4aa90be /usr.sbin/bgpd/session.c | |
parent | 64ebaa2fa1742aa7c0f6986fe1a517e5e3cc717a (diff) |
Neuter the pledge domain checking for listen, getpeername, and getsockname
also. The idea is much like rpath is with files, you get an fd and then
you can play with it somewhat. In the socket space once you have a fd, you
can play with it somewhat. So you cannot bind, but you can accept. You
can listen, getpeername, getsockname, and of course set/getsockopt is
somewhat available.. yes, this makes pledge the anti-capsicum, kind of
like salt from Secovlje.. reasoning due to a conversation with tedu
Diffstat (limited to 'usr.sbin/bgpd/session.c')
0 files changed, 0 insertions, 0 deletions