From owner-cvs-all Mon Aug 19 12: 4:57 2002 Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A0BA637B400; Mon, 19 Aug 2002 12:04:53 -0700 (PDT) Received: from freefall.freebsd.org (freefall.FreeBSD.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 56A8243E6A; Mon, 19 Aug 2002 12:04:53 -0700 (PDT) (envelope-from rwatson@FreeBSD.org) Received: from freefall.freebsd.org (rwatson@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.4/8.12.4) with ESMTP id g7JJ4rJU027954; Mon, 19 Aug 2002 12:04:53 -0700 (PDT) (envelope-from rwatson@freefall.freebsd.org) Received: (from rwatson@localhost) by freefall.freebsd.org (8.12.4/8.12.4/Submit) id g7JJ4rZX027953; Mon, 19 Aug 2002 12:04:53 -0700 (PDT) Message-Id: <200208191904.g7JJ4rZX027953@freefall.freebsd.org> From: Robert Watson Date: Mon, 19 Aug 2002 12:04:53 -0700 (PDT) To: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: src/sys/kern kern_ktrace.c kern_mac.c tty_tty.c vfs_syscalls.c vfs_vnops.c src/sys/security/mac_biba mac_biba.c src/sys/security/mac_bsdextended mac_bsdextended.c src/sys/security/mac_mls mac_mls.c src/sys/security/mac_none mac_none.c ... X-FreeBSD-CVS-Branch: HEAD Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG rwatson 2002/08/19 12:04:53 PDT Modified files: sys/kern kern_ktrace.c kern_mac.c tty_tty.c vfs_syscalls.c vfs_vnops.c sys/security/mac_biba mac_biba.c sys/security/mac_bsdextended mac_bsdextended.c sys/security/mac_mls mac_mls.c sys/security/mac_none mac_none.c sys/security/mac_test mac_test.c sys/sys mac.h mac_policy.h Log: Pass active_cred and file_cred into the MAC framework explicitly for mac_check_vnode_{poll,read,stat,write}(). Pass in fp->f_cred when calling these checks with a struct file available. Otherwise, pass NOCRED. All currently MAC policies use active_cred, but could now offer the cached credential semantic used for the base system security model. Obtained from: TrustedBSD Project Sponsored by: DARPA, NAI Labs Revision Changes Path 1.72 +1 -1 src/sys/kern/kern_ktrace.c 1.14 +20 -12 src/sys/kern/kern_mac.c 1.44 +6 -5 src/sys/kern/tty_tty.c 1.283 +11 -4 src/sys/kern/vfs_syscalls.c 1.165 +8 -6 src/sys/kern/vfs_vnops.c 1.5 +12 -12 src/sys/security/mac_biba/mac_biba.c 1.2 +6 -5 src/sys/security/mac_bsdextended/mac_bsdextended.c 1.5 +12 -12 src/sys/security/mac_mls/mac_mls.c 1.5 +8 -8 src/sys/security/mac_none/mac_none.c 1.5 +8 -8 src/sys/security/mac_test/mac_test.c 1.8 +8 -4 src/sys/sys/mac.h 1.9 +8 -4 src/sys/sys/mac_policy.h To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message