Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | When system calls indicate an error they return -1, not some arbitrary | deraadt | 2019-06-28 | 3 | -6/+6 |
| | | | | | | value < 0. errno is only updated in this case. Change all (most?) callers of syscalls to follow this better, and let's see if this strictness helps us in the future. | ||||
* | If we pass `file' via args then we need to unveil(2) it with read permission, | mestre | 2018-10-26 | 1 | -3/+17 |
| | | | | | | | | | | | | | | | | otherwise if omitted we need to unveil(2) both _PATH_UNIX and _PATH_KSYMS with same permissions. Unconditionally we need to also unveil(2) dbdir, which by default is _PATH_VARDB but can be changed via args (-o directory), with read/write/create permissions. There are a couple of temp files that will be created but it's inside dbdir so there's no need to unveil(2) them individually. Since we already call pledge(2) before, twice, we need to add "unveil" promise to both of them, and finally call pledge(2) once again with the needed promises except "unveil". OK millert@ | ||||
* | Use <fcntl.h> instead of <sys/file.h> for open() and friends. | guenther | 2018-04-26 | 1 | -8/+4 |
| | | | | | | | Delete a bunch of unnecessary #includes and sort to match style(9) while doing the above cleanup. ok deraadt@ krw@ | ||||
* | The call to setegid(2) was replaced with setresgid(2) a while ago. | tb | 2017-11-21 | 1 | -2/+2 |
| | | | | Adjust error message accordingly. | ||||
* | Use <elf.h> instead of <elf_abi.h> | mpi | 2017-10-27 | 1 | -2/+2 |
| | | | | ok jasper@, jca@, deraadt@ | ||||
* | missing fclose() in an error path | jsg | 2016-09-10 | 1 | -2/+4 |
| | |||||
* | use setresgid() rather than setegid, all 3 gids can go the same way. | deraadt | 2016-04-25 | 1 | -2/+2 |
| | | | | discussion with millert | ||||
* | Remove NULL-checks before free(). ok tb@ | mmcc | 2015-12-10 | 1 | -3/+2 |
| | |||||
* | missing pledge "getpw" for getgrnam(3) | deraadt | 2015-11-23 | 1 | -2/+2 |
| | |||||
* | Set the effective gid to kmem so the fchown of kvm_bsd.db is allowed | millert | 2015-11-08 | 1 | -16/+28 |
| | | | | | by pledge(2). This requires pledge "id" but that can be dropped immediately after the setegid() call. From Theo Buehler | ||||
* | there is a retry path in here which contains rename() and fchown(). | deraadt | 2015-11-05 | 1 | -5/+4 |
| | | | | | Use a slightly larger pledge, earlier on. from gregor best | ||||
* | Implement real "flock" request and add it to userland programs that | millert | 2015-10-16 | 1 | -2/+2 |
| | | | | use pledge and file locking. OK deraadt@ | ||||
* | semarie points out i am already forgetting the rules are very tight around | deraadt | 2015-10-13 | 1 | -6/+2 |
| | | | | | *chown, even "proc fattr" won't let you do such a job. remove early pledge(), only leave call after fchown, before when symbol table work gets done. | ||||
* | oops, a chown appears late on the code. to satisfy this pledge | deraadt | 2015-10-13 | 1 | -9/+16 |
| | | | | | | | | "stdio rpath wpath cpath getpw fattr proc" early on; "proc fattr" allows doing work with other uids on the file. after opening the db, do the chown (replace with fchown since we know fd) and then pledge "stdio rpath"; "rpath" due to tmpfile rename() at the end. mistake spotted by mpi | ||||
* | kvm_mkdb & dev_mkdb are quite similar. pledge "stdio rpath wpath cpath" | deraadt | 2015-10-12 | 1 | -1/+4 |
| | | | | except kvm_mkdb also does "getpw". | ||||
* | stdlib.h is in scope; do not cast malloc/calloc/realloc* | deraadt | 2015-08-20 | 1 | -2/+2 |
| | | | | ok millert krw | ||||
* | do not require <a.out.h> | deraadt | 2015-01-18 | 1 | -2/+1 |
| | |||||
* | Replace <sys/param.h> with <limits.h> and other less dirty headers where | deraadt | 2015-01-16 | 3 | -8/+7 |
| | | | | | | | | | possible. Annotate <sys/param.h> lines with their current reasons. Switch to PATH_MAX, NGROUPS_MAX, HOST_NAME_MAX+1, LOGIN_NAME_MAX, etc. Change MIN() and MAX() to local definitions of MINIMUM() and MAXIMUM() where sensible to avoid pulling in the pollution. These are the files confirmed through binary verification. ok guenther, millert, doug (helped with the verification protocol) | ||||
* | the kvm database only needs to be readable by kmem group. make it so. | tedu | 2014-12-23 | 1 | -6/+15 |
| | |||||
* | Make sure the correct errno is reported by warn* or err* and not | guenther | 2014-07-20 | 1 | -2/+2 |
| | | | | | | the errno of an intervening cleanup operation like close/unlink/etc. Diff from Doug Hogan (doug (at) acyclic.org) | ||||
* | Use errc/warnc to simplify code. | guenther | 2014-05-20 | 1 | -2/+2 |
| | | | | | | Also, in 'ftp', always put the error message last, after the hostname/ipaddr. ok jsing@ krw@ millert@ | ||||
* | remove the code that iterates over binary types, since everything is now | deraadt | 2013-11-12 | 1 | -21/+9 |
| | | | | ELF. | ||||
* | tedu a.out support | deraadt | 2013-10-15 | 1 | -375/+1 |
| | |||||
* | Correct format string mismatches turned up by -Wformat=2 | guenther | 2013-08-22 | 1 | -2/+2 |
| | | | | suggestions and ok millert@ | ||||
* | Allow for a kernel linked at address zero; ok guenther@ millert@ | miod | 2013-01-29 | 1 | -3/+4 |
| | |||||
* | iterate over e_shnum using Elf32_Word instead of int | deraadt | 2012-04-06 | 1 | -2/+3 |
| | |||||
* | patch a whole bunch of memory leaks, parfait only spotted one of them | deraadt | 2009-11-11 | 1 | -22/+41 |
| | | | | ok miod jsg | ||||
* | rcsid[] and sccsid[] and copyright[] are essentially unmaintained (and | deraadt | 2009-10-27 | 3 | -33/+3 |
| | | | | | | | unmaintainable). these days, people use source. these id's do not provide any benefit, and do hurt the small install media (the 33,000 line diff is essentially mechanical) ok with the idea millert, ok dms | ||||
* | use calloc() to avoid malloc(n * m) overflows; checked by djm canacar jsg | deraadt | 2007-09-02 | 1 | -3/+3 |
| | |||||
* | convert to new .Dd format; | jmc | 2007-05-31 | 1 | -2/+2 |
| | |||||
* | do not use section names for locating a string tab; miod@ ok | mickey | 2007-03-18 | 1 | -29/+18 |
| | |||||
* | fix off-by-ones in path truncation checks. from Han Boetes; ok deraadt@ | djm | 2005-04-14 | 1 | -4/+4 |
| | |||||
* | Use sysctl to get the running kernel version instead of grotting | millert | 2004-11-24 | 1 | -44/+22 |
| | | | | | through kmem. Fixes false positives on machines where the memory is not cleared between boots. OK deraadt@, tedu@, jaredy@ | ||||
* | add -o option to generate kvm database in alternate directory; | djm | 2003-11-21 | 2 | -17/+48 |
| | | | | manpage nits jmc@ ok tedu@ | ||||
* | realloc fixes; markus ok | deraadt | 2003-09-25 | 1 | -6/+26 |
| | |||||
* | ansi and protos | deraadt | 2003-06-26 | 3 | -36/+15 |
| | |||||
* | - section reorder | jmc | 2003-06-12 | 1 | -2/+2 |
| | | | | | | - macro fixes - kill whitespace at EOL - new sentence, new line | ||||
* | Remove the advertising clause in the UCB license which Berkeley | millert | 2003-06-02 | 5 | -33/+13 |
| | | | | rescinded 22 July 1999. Proofed by myself and Theo. | ||||
* | use snamesize and realloc properly. ok tdeval@ | tedu | 2003-04-06 | 2 | -12/+16 |
| | |||||
* | strlcpy; tedu ok | deraadt | 2003-04-04 | 1 | -5/+6 |
| | |||||
* | be better about the STT_NOTYPE symbols, not all become N_UNDEF this way; pefo@ ok | mickey | 2002-11-30 | 1 | -3/+19 |
| | |||||
* | prepend the underscore always for elf, this makes kvm_bsd.db work on elf platforms; drahn@ millert@ ok | mickey | 2002-10-25 | 1 | -11/+6 |
| | |||||
* | fopen() does not return < 0 | deraadt | 2002-09-06 | 1 | -3/+3 |
| | |||||
* | minor KNF | deraadt | 2002-05-30 | 1 | -5/+4 |
| | |||||
* | bring in prototypes | deraadt | 2002-03-25 | 1 | -3/+3 |
| | |||||
* | kill more registers. | mpech | 2002-03-14 | 2 | -12/+12 |
| | | | | millert@ ok | ||||
* | Fix ELF so it works with /dev/ksyms. Also make 'detection' of ksyms | pefo | 2002-02-20 | 1 | -34/+66 |
| | | | | a little more robust by looking at the actual namelist filename. | ||||
* | Part one of userland __P removal. Done with a simple regexp with some minor hand editing to make comments line up correctly. Another pass is forthcoming that handles the cases that could not be done automatically. | millert | 2002-02-16 | 3 | -11/+11 |
| | |||||
* | MAP_COPY -> MAP_SHARED (it's ok in this case (/dev/ksyms)) | art | 2001-05-11 | 1 | -3/+3 |
| | |||||
* | ELF: fallback to malloc when mmap fails. for /dev/ksyms. | art | 2001-02-03 | 1 | -7/+27 |
| |