freebsd-dev/sys
Bjoern A. Zeeb 6aaa0b3cf1 Prevent a superuser inside a jail from modifying the dedicated
root cpuset of that jail.
Processes inside the jail will still be able to change child sets.
A superuser outside of a jail will still be able to change the jail cpuset
and thus limit the number of cpus available to the jail.

Problem reported by: 000.fbsd@quip.cz (Miroslav Lachman)
PR:		kern/134050
Reviewed by:	jeff
MFC after:	3 weeks
X-MFC:		backout r191596
2009-04-28 21:00:50 +00:00
..
amd64 Reduce the number of bounce zones (and thus the number of bounce pages 2009-04-23 20:24:19 +00:00
arm Reduce the number of bounce zones (and thus the number of bounce pages 2009-04-23 20:24:19 +00:00
boot A simple rewrite of biossmap.c: 2009-04-15 17:31:22 +00:00
bsm Merge OpenBSM 1.1 from OpenBSM vendor branch to head. 2009-04-19 16:17:13 +00:00
cam Get rid of the device index number stored in the sa(4) unit number. 2009-04-20 10:40:42 +00:00
cddl Remove VOP_LEASE and supporting functions. This hasn't been used since 2009-04-10 10:52:19 +00:00
compat In preparation for turning on options VIMAGE in next commits, 2009-04-26 22:06:42 +00:00
conf Add suppport for ISA and ISA interrupts to make the ATA 2009-04-24 03:51:11 +00:00
contrib In preparation for turning on options VIMAGE in next commits, 2009-04-26 22:06:42 +00:00
crypto identify routine takes driver_t *, not device_t *. 2009-02-05 19:30:28 +00:00
ddb Prefer prototypes to k&r definitions. 2009-03-09 13:32:19 +00:00
dev - Change some softc members to be unsigned where more appropriate. 2009-04-28 20:49:47 +00:00
fs Remove VOP_LEASE and supporting functions. This hasn't been used since 2009-04-10 10:52:19 +00:00
gdb
geom - Remove assertion of topology lock remaining from 7.x gvinum. It is not needed, 2009-04-18 16:36:27 +00:00
gnu Fix two issues with bufdaemon, often causing the processes to hang in 2009-03-16 15:39:46 +00:00
i386 Reduce the number of bounce zones (and thus the number of bounce pages 2009-04-23 20:24:19 +00:00
ia64 Remove isa_irq_pending(). It's not used. 2009-04-24 03:43:20 +00:00
isa Allow syscons to work on amd64 and i386 without any hints: 2009-03-05 19:10:17 +00:00
kern Prevent a superuser inside a jail from modifying the dedicated 2009-04-28 21:00:50 +00:00
kgssapi
legacy/dev Remove kue_fw.h, missed in previous IFF_NEEDSGIANT USB driver garbage 2009-04-17 09:48:20 +00:00
libkern Add memmove() to the kernel, making the kernel compile with Clang. 2009-02-28 16:21:25 +00:00
mips Don't conditionally define CACHE_LINE_SHIFT, as we anticipate sizing 2009-04-20 12:59:23 +00:00
modules Build sound modules on PowerPC. 2009-04-19 21:37:45 +00:00
net replace IFQ_ENQUEUE + if_start with if_transmit 2009-04-27 22:46:26 +00:00
net80211 Store the tx seq# of an 802.11 frame in the mbuf pkthdr; this will be 2009-04-27 17:39:41 +00:00
netatalk Lock interface address list lock around ifaddr inserts and deletes 2009-04-19 22:01:38 +00:00
netgraph In preparation to make options VIMAGE operational, where needed, 2009-04-26 07:14:50 +00:00
netinet Don't require packet to match a route (any route; this information wasn't 2009-04-28 11:10:33 +00:00
netinet6 In preparation for turning on options VIMAGE in next commits, 2009-04-26 22:06:42 +00:00
netipsec key_gettunnel() has been unsued with FAST_IPSEC (now IPSEC). 2009-04-27 21:04:16 +00:00
netipx Make the SPX code use its own copies of insque()/remque(). 2009-04-26 21:03:27 +00:00
netnatm Remove IFF_NEEDSGIANT, a compatibility infrastructure introduced 2009-03-15 14:21:05 +00:00
netncp
netsmb
nfs Adding sys/nfs/nfssvc.h and sys/nfs/nfs_nfssvc.c in preparation for 2009-04-07 19:06:51 +00:00
nfs4client Remove VOP_LEASE and supporting functions. This hasn't been used since 2009-04-10 10:52:19 +00:00
nfsclient Remove trailing spaces 2009-04-13 19:54:33 +00:00
nfsserver Change nfsserver so that it uses the nfssvc() system call provided 2009-04-12 19:04:27 +00:00
nlm
opencrypto
pc98 Migrate the olpt(4) driver to si_drv1 instead of using dev2unit(). 2009-04-15 19:58:41 +00:00
pci For RTL8139C+ controllers, have controller handle padding short 2009-04-20 07:13:04 +00:00
powerpc Zero PCB during early AIM PowerPC init. 2009-04-24 08:57:54 +00:00
rpc Added a field to the SVCXPRT structure that the nfsv4 server can 2009-04-16 16:26:35 +00:00
security Temporarily relax the constraints on argument size checking for A_GETCOND; 2009-04-19 23:28:08 +00:00
sparc64 Don't conditionally define CACHE_LINE_SHIFT, as we anticipate sizing 2009-04-20 12:59:23 +00:00
sun4v Don't conditionally define CACHE_LINE_SHIFT, as we anticipate sizing 2009-04-20 12:59:23 +00:00
sys Remove the unused insque() and remque() functions. 2009-04-26 21:06:11 +00:00
tools Add SDT DTrace probes for VFS vnode operations in the vfs:vop 2009-03-29 03:30:15 +00:00
ufs Change the semantics of i_modrev/va_filerev to what is required for 2009-04-27 16:46:16 +00:00
vm Use the acquired reference to the vmspace instead of direct dereferencing 2009-04-28 11:45:36 +00:00
xdr Add memmove() to the kernel, making the kernel compile with Clang. 2009-02-28 16:21:25 +00:00
xen Fix the Xen build for i386 PV mode. 2009-04-01 17:06:28 +00:00
Makefile Removal pccard directory requires removing it from the list of things 2009-02-15 18:19:24 +00:00