From owner-cvs-src-old@FreeBSD.ORG Fri Jan 9 21:58:52 2009 Return-Path: Delivered-To: cvs-src-old@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 9B01C1065672 for ; Fri, 9 Jan 2009 21:58:52 +0000 (UTC) (envelope-from bz@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id 88E538FC1B for ; Fri, 9 Jan 2009 21:58:52 +0000 (UTC) (envelope-from bz@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.3/8.14.3) with ESMTP id n09LwqBk025574 for ; Fri, 9 Jan 2009 21:58:52 GMT (envelope-from bz@repoman.freebsd.org) Received: (from svn2cvs@localhost) by repoman.freebsd.org (8.14.3/8.14.3/Submit) id n09Lwq8m025573 for cvs-src-old@freebsd.org; Fri, 9 Jan 2009 21:58:52 GMT (envelope-from bz@repoman.freebsd.org) Message-Id: <200901092158.n09Lwq8m025573@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: svn2cvs set sender to bz@repoman.freebsd.org using -f From: "Bjoern A. Zeeb" Date: Fri, 9 Jan 2009 21:57:49 +0000 (UTC) To: cvs-src-old@freebsd.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: src/sys/net rtsock.c src/sys/netinet in.c src/sys/netinet6 in6.c X-BeenThere: cvs-src-old@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 09 Jan 2009 21:58:52 -0000 bz 2009-01-09 21:57:49 UTC FreeBSD src repository Modified files: sys/net rtsock.c sys/netinet in.c sys/netinet6 in6.c Log: SVN rev 186980 on 2009-01-09 21:57:49Z by bz Restrict arp, ndp and theoretically the FIB listing (if not read with libkvm) to the addresses of a prison, when inside a jail. [1] As the patch from the PR was pre-'new-arp', add checks to the llt_dump handlers as well. While touching RTM_GET in route_output(), consistently use curthread credentials rather than the creds from the socket there. [2] PR: kern/68189 Submitted by: Mark Delany [1] Discussed with: rwatson [2] Reviewed by: rwatson MFC after: 4 weeks Revision Changes Path 1.161 +12 -2 src/sys/net/rtsock.c 1.118 +4 -0 src/sys/netinet/in.c 1.96 +4 -0 src/sys/netinet6/in6.c