Subject: Re: KAUTH_REQ_NETWORK_SOCKET_OPEN
To: None <tech-kern@NetBSD.org>
From: David Young <dyoung@pobox.com>
List: tech-kern
Date: 01/30/2007 22:07:11
On Wed, Jan 31, 2007 at 01:28:26AM +0100, Joerg Sonnenberger wrote:
> On Wed, Jan 31, 2007 at 12:16:15AM +0000, Iain Hibbert wrote:
> > 1. specifically allow (PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI) access to all..
> > 2. rewrite the HCI socket code so that its not socket based..
>
> 3. Make the check honour the domain of the socket?
ISTR I had to do that for PF_ROUTE.
(FWIW, I do not think the BSD security model for raw sockets is standing
the test of time, and I am thankful for the opportunity to correct it
with kauth.)
Dave
--
David Young OJC Technologies
dyoung@ojctech.com Urbana, IL * (217) 278-3933