From 421312ed52f32f7ddd1dbb03573c7e26a1e49cbb Mon Sep 17 00:00:00 2001 From: deraadt <> Date: Sun, 20 Jul 2014 04:29:07 +0000 Subject: [PATCH] no longer play with /dev/log --- src/etc/systrace/usr_sbin_lpd | 3 +-- src/etc/systrace/usr_sbin_named | 3 +-- 2 files changed, 2 insertions(+), 4 deletions(-) diff --git a/src/etc/systrace/usr_sbin_lpd b/src/etc/systrace/usr_sbin_lpd index bcc2ffc4..bb9e9b71 100644 --- a/src/etc/systrace/usr_sbin_lpd +++ b/src/etc/systrace/usr_sbin_lpd @@ -1,4 +1,4 @@ -# $OpenBSD: usr_sbin_lpd,v 1.6 2014/07/14 05:48:18 guenther Exp $ +# $OpenBSD: usr_sbin_lpd,v 1.7 2014/07/20 04:29:07 deraadt Exp $ # # Policy for lpd. # This policy works for the default configuration of lpd. @@ -14,7 +14,6 @@ Policy: /usr/sbin/lpd, Emulation: native native-chmod: filename eq "/var/run/printer" then permit native-chown: filename eq "/var/run/printer" then permit native-close: permit - native-connect: sockaddr eq "/dev/log" then permit native-connect: sockaddr match "inet-*:53" then permit native-connect: sockaddr sub ":515" then permit native-dup2: permit diff --git a/src/etc/systrace/usr_sbin_named b/src/etc/systrace/usr_sbin_named index 70257d12..d7b4277c 100644 --- a/src/etc/systrace/usr_sbin_named +++ b/src/etc/systrace/usr_sbin_named @@ -1,4 +1,4 @@ -# $OpenBSD: usr_sbin_named,v 1.7 2014/07/14 05:48:18 guenther Exp $ +# $OpenBSD: usr_sbin_named,v 1.8 2014/07/20 04:29:07 deraadt Exp $ # # Policy for named that uses named user and chroots to /var/named # This policy works for the default configuration of named. @@ -14,7 +14,6 @@ Policy: /usr/sbin/named, Emulation: native native-chroot: filename eq "/var/named" then permit native-close: permit native-closefrom: permit - native-connect: sockaddr eq "/dev/log" then permit native-connect: sockaddr match "inet-*" then permit native-dup2: permit native-exit: permit