> On Sun, Mar 16, 2003 at 02:30:36PM -0800, Mooneer Salem wrote:
> 
>       When i was looking at this i was somewhat frustated with
> the way suser() doesn't really allow any sort of a context-of-check
> to happen easily that i was able to find.  ie, was it for a networking
> check, filesystem, etc..  so my first stab at this ended up with
> every user being able to do raw ip packets which was bad.. i
> ended up doing the p->p_prison save hack instead to get the result
> then applied the prison policy there.
It is time to invent "ping socket" and "traceroute socket"
in addition to tcp, udp, divert so on?


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message

Reply via email to