Subject: Re: KAUTH_REQ_NETWORK_SOCKET_OPEN
To: None <tech-kern@NetBSD.org>
From: David Young <dyoung@pobox.com>
List: tech-kern
Date: 01/30/2007 22:07:11
On Wed, Jan 31, 2007 at 01:28:26AM +0100, Joerg Sonnenberger wrote:
> On Wed, Jan 31, 2007 at 12:16:15AM +0000, Iain Hibbert wrote:
> > 1. specifically allow (PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI) access to all..
> > 2. rewrite the HCI socket code so that its not socket based..
> 
> 3. Make the check honour the domain of the socket?

ISTR I had to do that for PF_ROUTE.

(FWIW, I do not think the BSD security model for raw sockets is standing
the test of time, and I am thankful for the opportunity to correct it
with kauth.)

Dave

-- 
David Young             OJC Technologies
dyoung@ojctech.com      Urbana, IL * (217) 278-3933