HomeFreeBSD

MAC/do: Introduce rules reference counting

Description

MAC/do: Introduce rules reference counting

This is going to be used in subsequent commits to keep rules alive even
if disconnected from their jail in the meantime. We'll indeed have to
release the prison lock between two uses (outright rejection, final
granting) where the rules must absolutely stay the same for security reasons.

Reviewed by: bapt
Approved by: markj (mentor)
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D47619

Details

Provenance
olceAuthored on Jul 19 2024, 3:30 PM
Reviewer
bapt
Differential Revision
D47619: MAC/do: Introduce rules reference counting
Parents
rGddb3eb4efe55: New setcred() system call and associated MAC hooks
Branches
Unknown
Tags
Unknown