On 2004-10-11 16:31, Robert Watson <[EMAIL PROTECTED]> wrote:
> + * NOTE: Regarding access control.  Raw sockets may only be created by
> + * privileged processes; however, as a result of jailed processes and the
> + * ability for processes to downgrade privilege yet retain a reference to the
> + * raw socket.  As such, explicit access control is required here, or when
> + * unimplemented requests are passed to ip_ctloutput(), are required there.

Can we rewrite this descriptive comment a bit?  I can't really understand what
is being said by reading the comment.  Reading the diff of the source is easy,
but we should try to make the comment more comprehensible too ;-)

_______________________________________________
[EMAIL PROTECTED] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to