From owner-freebsd-doc@FreeBSD.ORG Mon Feb 12 21:10:15 2007 Return-Path: X-Original-To: freebsd-doc@hub.freebsd.org Delivered-To: freebsd-doc@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 592E016A406 for ; Mon, 12 Feb 2007 21:10:15 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id 45E0F13C49D for ; Mon, 12 Feb 2007 21:10:15 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l1CLAFNH048514 for ; Mon, 12 Feb 2007 21:10:15 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l1CLAFsh048513; Mon, 12 Feb 2007 21:10:15 GMT (envelope-from gnats) Date: Mon, 12 Feb 2007 21:10:15 GMT Message-Id: <200702122110.l1CLAFsh048513@freefall.freebsd.org> To: freebsd-doc@FreeBSD.org From: Remko Lodder Cc: Subject: Re: docs/109105: security.mac.bsdextended.firstmatch_enabled is not enabled X-BeenThere: freebsd-doc@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Remko Lodder List-Id: Documentation project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Feb 2007 21:10:15 -0000 The following reply was made to PR docs/109105; it has been noted by GNATS. From: Remko Lodder To: "Dr. Markus Waldeck" Cc: freebsd-gnats-submit@FreeBSD.org Subject: Re: docs/109105: security.mac.bsdextended.firstmatch_enabled is not enabled Date: Mon, 12 Feb 2007 22:03:01 +0100 Dr. Markus Waldeck wrote: > >> Description: > CUSTOM kernel: > options MAC > kldload mac_bsdextended.ko > > % sysctl security.mac.bsdextended.firstmatch_enabled > security.mac.bsdextended.firstmatch_enabled: 0 > > man mac_bsdextended > security.mac.bsdextended.firstmatch_enabled > Toggle between the old all rules match functionality and the new > first rule matches functionality. This is enabled by default. > > The value 0 means disabled not enabled! >> How-To-Repeat: > % sysctl security.mac.bsdextended.firstmatch_enabled > > % man mac_bsdextended > Hello (again), When are you going to read my emails about asking you over and over again, to give these things a bit of discussion before you are submitting PR's? A little discussion with the developers of the MAC framework could give the proper idea about what is going on. Perhaps the documentation is OK and the code is wrong, or the other way around. You might think that I am a bit grumpy, and yes I am. The PR tickets are not for Support questions (Which this initially is) but for confirmed problems which should be resolved. We cannot resolve this prior to have some investigation going on. So AGAIN: Please ask / discuss these things on the various mailinglists before submitting a ticket to make things more concrete, this will help FreeBSD, you and others! Thanks for your understanding and coorporation. -- Kind regards, Remko Lodder ** remko@elvandar.org FreeBSD ** remko@FreeBSD.org /* Quis custodiet ipsos custodes */