tweak previous: drop stray blank line, drop a few words that accidentally
stayed behind, and fix some plural->singular issues;
feedback and OK mglocker@, and OK jca@ on an earlier version
Create the weak global _permit_setugid which must match the setuid/setgid
mode of the executable file. This is documented in execve(2).
The libc startup validation code to do this is not enabled yet.
xlock is setgid (auth), but does not use the bsd.prog.mk build infrastructure,
so it needs manual definition of "mode_t _permit_setugid = S_ISGID". The other
setgid program in X11R6 is xterm (group utmp), but it is built using bsd.prog.mk
and automatically picks up the _permit_setugid variable.
Update libexpat to version 2.8.5.
Changes relevant for OpenBSD have been backported earlier. Compiler
warning #1362 has been disabled, it does not work with gcc 4.2.1.
Move the hash table declarations into a separate header file as
this is needed for #1355. Convert salt test to non deprecated
XML_SetHashSalt16Bytes() function. Library bump is not necessary.
OK deraadt@
update to py3-dulwich-1.2.17
make a start at trying to allow rust/no-rust builds, but I'm not sure if
there's a good way to add SUPDISTFILES for the crates..
Simplify kern.video.record logic to avoid bcopy with unchecked parameters
kern.video.record was intended to mimic kern.audio.record in handing
over only zeroed frames to userland. The mmap code unconditionally used
bcopy with arguments passed from userland, even on error, which may
result in arbitrary memory zeroing. This is only reachable if the
permissions on /dev/video* have been changed to allow non-root users but
kern.video.record is still zero.
Instead of this complicated logic, keep kern.video.record for now but
turn it into an extra perm check in open(2).
Issue reported by Acts1631 who proposed a different fix. Documentation
changes to follow, courtesy of mglocker@. ok kirill@ mglocker@
Simplify kern.video.record logic to avoid bcopy with unchecked parameters
kern.video.record was intended to mimic kern.audio.record in handing
over only zeroed frames to userland. The mmap code unconditionally used
bcopy with arguments passed from userland, even on error, which may
result in arbitrary memory zeroing. This is only reachable if the
permissions on /dev/video* have been changed to allow non-root users but
kern.video.record is still zero.
Instead of this complicated logic, keep kern.video.record for now but
turn it into an extra perm check in open(2).
Issue reported by Acts1631 who proposed a different fix. Documentation
changes to follow, courtesy of mglocker@. ok kirill@ mglocker@