From owner-svn-soc-all@FreeBSD.ORG Sat Jul 20 19:23:44 2013 Return-Path: Delivered-To: svn-soc-all@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by hub.freebsd.org (Postfix) with ESMTP id C16B714A for ; Sat, 20 Jul 2013 19:23:44 +0000 (UTC) (envelope-from dpl@FreeBSD.org) Received: from socsvn.freebsd.org (socsvn.freebsd.org [IPv6:2001:1900:2254:206a::50:2]) by mx1.freebsd.org (Postfix) with ESMTP id B1B80127 for ; Sat, 20 Jul 2013 19:23:44 +0000 (UTC) Received: from socsvn.freebsd.org ([127.0.1.124]) by socsvn.freebsd.org (8.14.7/8.14.7) with ESMTP id r6KJNiXo031429 for ; Sat, 20 Jul 2013 19:23:44 GMT (envelope-from dpl@FreeBSD.org) Received: (from www@localhost) by socsvn.freebsd.org (8.14.7/8.14.6/Submit) id r6KJNi1b031424 for svn-soc-all@FreeBSD.org; Sat, 20 Jul 2013 19:23:44 GMT (envelope-from dpl@FreeBSD.org) Date: Sat, 20 Jul 2013 19:23:44 GMT Message-Id: <201307201923.r6KJNi1b031424@socsvn.freebsd.org> X-Authentication-Warning: socsvn.freebsd.org: www set sender to dpl@FreeBSD.org using -f From: dpl@FreeBSD.org To: svn-soc-all@FreeBSD.org Subject: socsvn commit: r254982 - soc2013/dpl/head/lib/libz MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-soc-all@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: SVN commit messages for the entire Summer of Code repository List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 20 Jul 2013 19:23:44 -0000 Author: dpl Date: Sat Jul 20 19:23:44 2013 New Revision: 254982 URL: http://svnweb.FreeBSD.org/socsvn/?view=rev&rev=254982 Log: Zlib gzip code is limited now. Modified: soc2013/dpl/head/lib/libz/gzlib.c Modified: soc2013/dpl/head/lib/libz/gzlib.c ============================================================================== --- soc2013/dpl/head/lib/libz/gzlib.c Sat Jul 20 16:58:17 2013 (r254981) +++ soc2013/dpl/head/lib/libz/gzlib.c Sat Jul 20 19:23:44 2013 (r254982) @@ -18,6 +18,14 @@ #endif #endif +#if defined(__FreeBSD__) +# include +# if __FreeBSD_version >= 900041 +# define CAPSICUM +# include +# endif +#endif + /* Local functions */ local void gz_reset OF((gz_statep)); local gzFile gz_open OF((const void *, int, const char *)); @@ -251,6 +259,10 @@ free(state); return NULL; } +#ifdef CAPSICUM + cap_rights_limit(state->fd, CAP_READ|CAP_SEEK|CAP_WRITE|CAP_FSTAT); + printf("CAPSICUM: fd %d limited\n", state->fd); +#endif if (state->mode == GZ_APPEND) state->mode = GZ_WRITE; /* simplify later checks */