kevans
26d6f82958
tuntap(4): restrict scope of net.link.tap.user_open slightly
...
net.link.tap.user_open has historically allowed non-root users to do devfs
cloning and open /dev/tap* nodes based on permissions. Loosen this up to
make it only allow users to do devfs cloning -- we no longer check it in
tunopen.
This allows tap devices to be created that can actually be opened by a user,
rather than swiftly restricting them to root because the magic sysctl has
not been set.
The sysctl has not yet been completely deprecated, because more thought is
needed for how to handle the devfs cloning case. There is not an easy
suitable replacement for the sysctl there, and more care needs to be placed
in determining whether that's OK or not.
PR: 200185
2019-10-21 14:38:11 +00:00
..
2019-02-11 05:17:31 +00:00
2019-06-29 00:48:33 +00:00
2017-11-27 15:23:17 +00:00
2017-11-20 19:43:44 +00:00
2018-06-13 17:04:41 +00:00
2018-06-13 17:04:41 +00:00
2019-09-09 21:32:42 +00:00
2017-11-27 15:23:17 +00:00
2019-06-29 00:48:33 +00:00
2019-05-20 00:38:23 +00:00
2019-05-13 13:45:28 +00:00
2019-03-15 11:21:20 +00:00
2017-11-27 15:23:17 +00:00
2019-10-17 21:33:01 +00:00
2019-10-17 21:33:01 +00:00
2019-10-19 20:48:53 +00:00
2019-10-17 21:33:01 +00:00
2018-05-31 09:11:21 +00:00
2019-10-17 00:34:53 +00:00
2017-11-27 15:23:17 +00:00
2019-08-27 00:01:56 +00:00
2019-08-27 00:01:56 +00:00
2019-07-14 03:49:48 +00:00
2019-03-09 01:12:59 +00:00
2019-05-29 01:08:30 +00:00
2018-05-11 05:00:40 +00:00
2018-07-24 16:35:52 +00:00
2019-05-20 00:38:23 +00:00
2019-08-01 14:17:31 +00:00
2017-11-27 15:23:17 +00:00
2018-07-24 16:35:52 +00:00
2017-11-20 19:43:44 +00:00
2018-07-24 16:35:52 +00:00
2019-01-31 23:01:03 +00:00
2017-11-27 15:23:17 +00:00
2018-07-24 16:35:52 +00:00
2019-10-07 22:40:05 +00:00
2018-03-27 20:51:49 +00:00
2019-10-07 22:40:05 +00:00
2018-10-21 18:06:15 +00:00
2019-04-24 09:05:45 +00:00
2019-04-24 09:05:45 +00:00
2018-11-16 14:21:57 +00:00
2019-08-27 00:01:56 +00:00
2019-05-03 14:43:21 +00:00
2019-05-20 00:38:23 +00:00
2019-05-20 00:38:23 +00:00
2017-11-20 19:43:44 +00:00
2018-07-24 16:35:52 +00:00
2019-10-07 22:40:05 +00:00
2018-04-23 21:10:33 +00:00
2018-08-22 18:19:56 +00:00
2019-10-09 16:21:50 +00:00
2017-11-27 15:23:17 +00:00
2017-11-27 15:23:17 +00:00
2019-10-10 23:54:37 +00:00
2019-10-10 23:50:32 +00:00
2019-10-18 21:53:27 +00:00
2019-07-25 22:23:34 +00:00
2019-10-21 14:38:11 +00:00
2017-11-20 19:43:44 +00:00
2019-10-17 16:23:03 +00:00
2019-05-20 00:38:23 +00:00
2019-10-17 20:18:07 +00:00
2019-07-24 16:10:20 +00:00
2017-12-30 04:03:53 +00:00
2019-10-17 16:23:03 +00:00
2019-09-17 18:49:13 +00:00
2018-05-11 20:08:28 +00:00
2019-05-06 20:56:41 +00:00
2019-06-15 11:07:41 +00:00
2019-10-17 16:23:03 +00:00
2019-09-30 15:59:07 +00:00
2017-11-20 19:43:44 +00:00
2019-05-09 11:34:46 +00:00
2019-01-03 23:06:05 +00:00
2017-11-27 15:23:17 +00:00
2019-10-07 22:40:05 +00:00
2017-11-27 15:23:17 +00:00
2019-03-18 12:22:23 +00:00
2019-09-01 14:47:41 +00:00
2018-12-05 11:57:16 +00:00
2019-09-01 14:47:41 +00:00
2019-03-10 17:20:09 +00:00
2019-03-10 17:20:09 +00:00
2017-11-20 19:43:44 +00:00
2019-03-15 11:08:44 +00:00
2018-06-16 08:26:23 +00:00
2017-11-20 19:43:44 +00:00
2018-06-16 08:26:23 +00:00
2018-06-16 19:21:09 +00:00
2017-11-20 19:43:44 +00:00
2017-11-20 19:43:44 +00:00
2017-11-20 19:43:44 +00:00
2019-05-08 23:39:24 +00:00
2019-10-18 15:20:24 +00:00
2019-10-18 15:20:24 +00:00
2019-10-07 22:40:05 +00:00
2019-08-17 00:10:56 +00:00
2017-11-20 19:43:44 +00:00
2017-11-20 19:43:44 +00:00
2019-10-08 11:06:24 +00:00
2019-10-07 14:24:59 +00:00