tcpdump mailing list archives

Re: FreeBSD sandboxing support via capsicum


From: Guy Harris <guy () alum mit edu>
Date: Thu, 10 Jul 2014 12:22:28 -0700


On Jul 9, 2014, at 5:14 AM, Loganaden Velvindron <logan () elandsys com> wrote:

On Sat, Jul 05, 2014 at 01:34:15PM -0700, Guy Harris wrote:

On Jul 5, 2014, at 1:15 PM, Loganaden Velvindron <logan () elandsys com> wrote:

FreeBSD has designed capsicum which is a sandboxing mechanism.

Please find below a patch against FreeBSD 10 Release:

So this will compile on all versions of FreeBSD, correct?

If not, please update the configure script to test for the relevant APIs, and enable the new code only on systems 
with those APIs.

Thank you for your feeeback.

Updated diff. Feedback welcomed.

Checked in (with some fixes to the configure script - there shouldn't be anything between AC_MSG_CHECKING and 
AC_MSG_RESULT that would print any output, and capsicum should be enabled only if none of the functions were not found).

Michael, should this go into 4.6 or should we wait for the next tcpdump release?
_______________________________________________
tcpdump-workers mailing list
tcpdump-workers () lists tcpdump org
https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers


Current thread: