Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F149995903
D54391.1791419450.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Flag For Later
Award Token
Size
1 KB
Referenced Files
None
Subscribers
None
D54391.1791419450.diff
View Options
diff --git a/sys/kern/kern_kexec.c b/sys/kern/kern_kexec.c
--- a/sys/kern/kern_kexec.c
+++ b/sys/kern/kern_kexec.c
@@ -342,7 +342,19 @@
{
int error;
- // FIXME: Do w need a better privilege check than PRIV_REBOOT here?
+/*
+ * XXX: Is PRIV_REBOOT sufficient here?
+ *
+ * Loading a new kernel image via kexec_load() is a more powerful operation
+ * than a traditional reboot, as it allows replacing the running kernel
+ * without returning to firmware or the bootloader.
+ *
+ * The current use of PRIV_REBOOT relies on the system security policy
+ * (e.g., MAC frameworks, jail restrictions) to further constrain access
+ * where appropriate. A more specific privilege (e.g., kexec-specific)
+ * could provide finer-grained control in environments requiring stricter
+ * separation of administrative capabilities.
+ */
error = priv_check(td, PRIV_REBOOT);
if (error != 0)
return (error);
diff --git a/sys/kern/kern_ntptime.c b/sys/kern/kern_ntptime.c
--- a/sys/kern/kern_ntptime.c
+++ b/sys/kern/kern_ntptime.c
@@ -388,7 +388,7 @@
time_constant = ntv->constant;
}
if (modes & MOD_TAI) {
- if (ntv->constant > 0) /* XXX zero & negative numbers ? */
+ if (ntv->constant > 0) /* TAI-UTC offset is strictly positive */
time_tai = ntv->constant;
}
#ifdef PPS_SYNC
diff --git a/sys/kern/kern_syscalls.c b/sys/kern/kern_syscalls.c
--- a/sys/kern/kern_syscalls.c
+++ b/sys/kern/kern_syscalls.c
@@ -161,8 +161,13 @@
{
struct sysent *se;
- if (offset == 0)
- return (0); /* XXX? */
+ if (offset == 0) {
+ /*
+ * Syscall number 0 is reserved and is not dynamically registered.
+ * Treat deregistration as a no-op to simplify module unload paths.
+ */
+ return (0);
+ }
se = &sysents[offset];
if ((se->sy_thrcnt & SY_THR_STATIC) != 0)
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Thu, Oct 8, 12:30 AM (6 h, 11 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
30225115
Default Alt Text
D54391.1791419450.diff (1 KB)
Attached To
Mode
D54391: Clarify TAI offset validation in kern_ntptime
Attached
Detach File
Event Timeline
Log In to Comment