freebsd kernel with SKQ
Go to file
Crist J. Clark b0d226932e The ancient and outdated concept of "privileged ports" in UNIX-type
OSes has probably caused more problems than it ever solved. Allow the
user to retire the old behavior by specifying their own privileged
range with,

  net.inet.ip.portrange.reservedhigh  default = IPPORT_RESERVED - 1
  net.inet.ip.portrange.reservedlo    default = 0

Now you can run that webserver without ever needing root at all. Or
just imagine, an ftpd that can really drop privileges, rather than
just set the euid, and still do PORT data transfers from 20/tcp.

Two edge cases to note,

  # sysctl net.inet.ip.portrange.reservedhigh=0

Opens all ports to everyone, and,

  # sysctl net.inet.ip.portrange.reservedhigh=65535

Locks all network activity to root only (which could actually have
been achieved before with ipfw(8), but is somewhat more
complicated).

For those who stick to the old religion that 0-1023 belong to root and
root alone, don't touch the knobs (or even lock them by raising
securelevel(8)), and nothing changes.
2003-02-21 05:28:27 +00:00
bin We can simplify this Makefile down to a single line now. 2003-02-19 16:56:30 +00:00
contrib This commit was generated by cvs2svn to compensate for changes in r110989, 2003-02-16 11:28:55 +00:00
crypto Resolve conflicts after import of OpenSSL 0.9.7a. 2003-02-19 23:24:16 +00:00
etc We stopped reloading rc.conf for each script a long time ago. Things 2003-02-16 20:46:08 +00:00
games "Happiness" is a noun. 2003-02-18 20:49:12 +00:00
gnu Some things don't build for PowerPC yet. 2003-02-21 02:30:51 +00:00
include Implement dlinfo() function. 2003-02-13 17:47:44 +00:00
kerberos5 Define OPENSSL_DES_LIBDES_COMPATIBILITY so that Heimdal will build with 2003-01-21 14:08:24 +00:00
kerberosIV update version numbers to (consistenly): 2002-10-23 06:12:21 +00:00
lib Some things don't build for PowerPC yet. 2003-02-21 02:30:51 +00:00
libexec Do not remove object from the lists at the unref_dag() stage. 2003-02-17 20:58:27 +00:00
release Modified release notes: OpenSSL-0.9.7a. 2003-02-20 17:26:11 +00:00
sbin Don't try to build devd when NO_CXX is set. 2003-02-21 02:16:35 +00:00
secure Regenerate man pages after import of OpenSSL 0.9.7a. 2003-02-19 23:30:52 +00:00
share mdoc(7) police: tidy up. 2003-02-20 20:22:20 +00:00
sys The ancient and outdated concept of "privileged ports" in UNIX-type 2003-02-21 05:28:27 +00:00
tools Adjust code for new kse_release interface. 2003-02-20 08:24:22 +00:00
usr.bin Some things don't build for PowerPC yet. 2003-02-21 02:30:51 +00:00
usr.sbin Some things don't build for PowerPC yet. 2003-02-21 02:30:51 +00:00
COPYRIGHT
MAINTAINERS Nuke xargs, I haven't had to help anyone with it, so I assume it stands on 2003-02-18 00:07:06 +00:00
Makefile Don't spam sys/${MACHINE}/conf/ with _.${MACHINE}.makeLINT. 2003-02-19 16:57:12 +00:00
Makefile.inc1 Add -DNOMAN to the list. 2003-02-11 19:21:13 +00:00
Makefile.upgrade
README Fix broken handbook links. 2002-07-21 16:45:30 +00:00
UPDATING Acutally document how to make a LINT kernel config, besides telling all it 2003-02-13 17:55:12 +00:00

This is the top level of the FreeBSD source directory.  This file
was last revised on:
$FreeBSD$

For copyright information, please see the file COPYRIGHT in this
directory (additional copyright information also exists for some
sources in this tree - please see the specific source directories for
more information).

The Makefile in this directory supports a number of targets for
building components (or all) of the FreeBSD source tree, the most
commonly used one being ``world'', which rebuilds and installs
everything in the FreeBSD system from the source tree except the
kernel, the kernel-modules and the contents of /etc.  The
``buildkernel'' and ``installkernel'' targets build and install
the kernel and the modules (see below).  Please see the top of
the Makefile in this directory for more information on the
standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process, documentation
for which can be found at:
   http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html
And in the config(8) man page.
Note: If you want to build and install the kernel with the
``buildkernel'' and ``installkernel'' targets, you might need to build
world before.  More information is available in the handbook.

The sample kernel configuration files reside in the sys/<arch>/conf
sub-directory (assuming that you've installed the kernel sources), the
file named GENERIC being the one used to build your initial installation
kernel.  The file NOTES contains entries and documentation for all possible
devices, not just those commonly used.  It is the successor of the ancient
LINT file, but in contrast to LINT, it is not buildable as a kernel but a
pure reference and documentation file.


Source Roadmap:
---------------
bin		System/user commands.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

games		Amusements.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

kerberosIV	KerberosIV (eBones) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

sys		Kernel sources.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.


For information on synchronizing your source tree with one or more of
the FreeBSD Project's development branches, please see:

  http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/synching.html