freebsd-dev/sys
David Bright 2d5603fe65 Jail and capability mode for shm_rename; add audit support for shm_rename
Co-mingling two things here:

  * Addressing some feedback from Konstantin and Kyle re: jail,
    capability mode, and a few other things
  * Adding audit support as promised.

The audit support change includes a partial refresh of OpenBSM from
upstream, where the change to add shm_rename has already been
accepted. Matthew doesn't plan to work on refreshing anything else to
support audit for those new event types.

Submitted by:	Matthew Bryan <matthew.bryan@isilon.com>
Reviewed by:	kib
Relnotes:	Yes
Sponsored by:	Dell EMC Isilon
Differential Revision:	https://reviews.freebsd.org/D22083
2019-11-18 13:31:16 +00:00
..
amd64 amd64 copyout: remove irrelevant comment. 2019-11-17 14:41:47 +00:00
arm Add a sv_copyout_auxargs() hook in sysentvec. 2019-11-15 18:42:13 +00:00
arm64 Achieve two goals at once: (1) Avoid an unnecessary broadcast TLB 2019-11-17 17:38:53 +00:00
bsm Jail and capability mode for shm_rename; add audit support for shm_rename 2019-11-18 13:31:16 +00:00
cam Fix a race between daopen and damediapoll 2019-11-13 01:58:43 +00:00
cddl MFV r354378,r354379,r354386: 10499 Multi-modifier protection (MMP) 2019-11-18 09:38:35 +00:00
compat Jail and capability mode for shm_rename; add audit support for shm_rename 2019-11-18 13:31:16 +00:00
conf fix up r354804, add new ZFS file mmp.c to kernel files 2019-11-18 10:46:55 +00:00
contrib Update to Zstandard 1.4.4 2019-11-16 16:39:08 +00:00
crypto Fix the armv8 crypto driver after r354170. 2019-10-30 10:41:10 +00:00
ddb ddb(4): Add some support for lexing IPv6 addresses 2019-09-09 16:32:23 +00:00
dev TSX Asynchronous Abort mitigation for Intel CVE-2019-11135. 2019-11-16 00:26:42 +00:00
dts dtso: allwinner: Add an overlay for H3 thermal node 2019-08-24 13:26:34 +00:00
fs Replace OBJ_MIGHTBEDIRTY with a system using atomics. Remove the TMPFS_DIRTY 2019-10-29 21:06:34 +00:00
gdb gdb(4): Implement support for NoAckMode 2019-10-17 22:37:25 +00:00
geom Add GEOM attribute to report physical device name, and report it 2019-11-09 17:30:19 +00:00
gnu arm: dts: ti: Fix mmc3 instance by setting it to disabled 2019-10-07 08:11:49 +00:00
i386 Use a sv_copyout_auxargs hook in the Linux ELF ABIs. 2019-11-15 23:01:43 +00:00
isa
kern Jail and capability mode for shm_rename; add audit support for shm_rename 2019-11-18 13:31:16 +00:00
kgssapi Stop using des_cblock * for arguments to DES functions. 2019-08-26 17:25:07 +00:00
libkern Rename the macros to extract a single arm64 ID field. 2019-10-30 10:06:57 +00:00
mips Combine ELF sysvecs for MIPS to reduce code duplication. 2019-11-15 19:00:20 +00:00
modules Add the pvscsi driver to the tree. 2019-11-14 23:31:20 +00:00
net if_llatbl: change htable_unlink_entry() to early exist if no work to do 2019-11-15 23:12:19 +00:00
net80211 Don't use if_maddr_rlock() in 802.11, use epoch(9) directly instead. 2019-10-10 23:55:33 +00:00
netgraph Fix regression from r353026. Pointer was increased instead of value 2019-11-02 03:09:17 +00:00
netinet Add boundary and overflow checks to the formulas used in the TCP CUBIC 2019-11-16 12:00:22 +00:00
netinet6 nd6: retire defrouter_select(), use _fib() variant. 2019-11-16 00:17:35 +00:00
netipsec netinet*: replace IP6_EXTHDR_GET() 2019-11-15 21:44:17 +00:00
netpfil pf: Must be in NET_EPOCH to call icmp_error 2019-10-18 03:36:26 +00:00
netsmb Stop using des_cblock * for arguments to DES functions. 2019-08-26 17:25:07 +00:00
nfs
nfsclient
nfsserver
nlm
ofed Prevent potential underflow in ibcore. 2019-11-15 11:46:53 +00:00
opencrypto kTLS support for TLS 1.3 2019-09-27 19:17:40 +00:00
powerpc powerpc: Re-add -Wno-redundant-decls to DPAA build flags 2019-11-17 20:49:24 +00:00
riscv RISC-V: busdma_bounce: fix BUS_DMA_ALLOCNOW for non-paged aligned sizes 2019-11-16 01:25:51 +00:00
rpc Avoid relying on header pollution from sys/refcount.h. 2019-07-29 20:26:01 +00:00
security Jail and capability mode for shm_rename; add audit support for shm_rename 2019-11-18 13:31:16 +00:00
sparc64 Add a sv_copyout_auxargs() hook in sysentvec. 2019-11-15 18:42:13 +00:00
sys Jail and capability mode for shm_rename; add audit support for shm_rename 2019-11-18 13:31:16 +00:00
teken Adjust teken to allow build as part of loader 2019-09-05 18:07:40 +00:00
tests
tools Add makesyscalls.lua, a rewrite of makesyscalls.sh 2019-11-17 14:08:19 +00:00
ufs In ufs_dir_dd_ino(), always initialize *dd_vp since the caller expects it. 2019-11-12 00:32:33 +00:00
vm Add a helper function for testing a swap block and freeing it if empty. 2019-11-17 18:38:37 +00:00
x86 TSX Asynchronous Abort mitigation for Intel CVE-2019-11135. 2019-11-16 00:26:42 +00:00
xdr
xen
Makefile