Re: unveil confusion

2020-04-23 Thread Peter J. Philipp
On Thu, Apr 23, 2020 at 11:20:45AM +0200, Hiltjo Posthuma wrote: > > beta$ ps ax | grep unveiltest > > 40907 pg S+U 0:00.01 ./unveiltest > > 40013 ph R+/2 0:00.00 grep unveiltest > Hi, > > Below the quoted part it says in the man page: > > "After establishing a collection of pa

Re: unveil confusion

2020-04-23 Thread Hiltjo Posthuma
On Thu, Apr 23, 2020 at 09:33:51AM +0200, Peter J. Philipp wrote: > Hi, > > From the unveil manpage: > > The first call to unveil() removes visibility of the entire filesystem > from all other filesystem-related system calls (such as open(2), chmod(2) > and rename(2)), except for t

unveil confusion

2020-04-23 Thread Peter J. Philipp
Hi, >From the unveil manpage: The first call to unveil() removes visibility of the entire filesystem from all other filesystem-related system calls (such as open(2), chmod(2) and rename(2)), except for the specified path and permissions. Can the first call also be the last? I hav