Hi,

I'm running privdebug on a process.  One of the privileges asserted
was sys_ip_config.  Since this is not an exclusive-ip zone, this
privilege is not even in the zone's L set.  However, the process runs
fine.  What's happening here?  This is a labeled zone on TX, if that
information is relevant.

Maybe I'm not understanding what privdebug is reporting.  I use
privdebug to determine what's asserted and add it to the E set, but in
this case, it would be a mistake to add sys_ip_config, but yet,
privdebug reports that it's asserted.

CT

Reply via email to