> On Sun, Mar 16, 2003 at 02:30:36PM -0800, Mooneer Salem wrote: > > When i was looking at this i was somewhat frustated with > the way suser() doesn't really allow any sort of a context-of-check > to happen easily that i was able to find. ie, was it for a networking > check, filesystem, etc.. so my first stab at this ended up with > every user being able to do raw ip packets which was bad.. i > ended up doing the p->p_prison save hack instead to get the result > then applied the prison policy there. It is time to invent "ping socket" and "traceroute socket" in addition to tcp, udp, divert so on?
To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-hackers" in the body of the message

