the VNDIOCSET ioctl path handling bypassed the unveil, so root (or .operator)
authorderaadt <deraadt@openbsd.org>
Thu, 1 Sep 2022 12:28:53 +0000 (12:28 +0000)
committerderaadt <deraadt@openbsd.org>
Thu, 1 Sep 2022 12:28:53 +0000 (12:28 +0000)
commit843678b16716640c8490800ffdc2a3f496f52c6f
treea7e4a5ab5b144cf8bbb10155c37b5393df67433e
parentc7644b4b0a153ebf37a50060c679ac00b92caf5f
the VNDIOCSET ioctl path handling bypassed the unveil, so root (or .operator)
could read a file outside the space.
ok semarie benno tb
sys/dev/vnd.c