Re: unveil ifstated

2018-10-30 Thread Theo de Raadt
Looks good to me. Ricardo Mestre wrote: > ifstated(8) needs to load configfile from within the main loop, but also to > reload it on SIGHUP so unveil(2) it with read permissions. Additionally all > commands are exec'ed through /bin/sh instead of directly so we can just > unveil(2) /bin/sh with

unveil ifstated

2018-10-30 Thread Ricardo Mestre
Hi, ifstated(8) needs to load configfile from within the main loop, but also to reload it on SIGHUP so unveil(2) it with read permissions. Additionally all commands are exec'ed through /bin/sh instead of directly so we can just unveil(2) /bin/sh with x perms. Since /bin/sh is already used on