aboutsummaryrefslogtreecommitdiff
path: root/share
diff options
context:
space:
mode:
authorEdward Tomasz Napierala <trasz@FreeBSD.org>2015-07-25 15:56:49 +0000
committerEdward Tomasz Napierala <trasz@FreeBSD.org>2015-07-25 15:56:49 +0000
commit208a8b953215180de3134785b3950d3709047624 (patch)
tree39dadc5e9ee6c8946ae2751cd976dbee6846aecc /share
parent6fd04eff667b3bb07bb44143978caafde8df3e82 (diff)
Update Capsicum and Mandatory Access Control manual pages
to no longer claim they are experimental. Reviewed by: rwatson@, wblock@ MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D2985
Notes
Notes: svn path=/head/; revision=285873
Diffstat (limited to 'share')
-rw-r--r--share/man/man4/capsicum.46
-rw-r--r--share/man/man4/mac.410
-rw-r--r--share/man/man4/mac_ifoff.410
-rw-r--r--share/man/man4/mac_mls.410
-rw-r--r--share/man/man4/mac_none.410
-rw-r--r--share/man/man4/mac_partition.410
-rw-r--r--share/man/man4/mac_seeotheruids.410
-rw-r--r--share/man/man4/mac_stub.410
-rw-r--r--share/man/man4/mac_test.410
-rw-r--r--share/man/man4/procdesc.46
-rw-r--r--share/man/man9/mac.917
11 files changed, 11 insertions, 98 deletions
diff --git a/share/man/man4/capsicum.4 b/share/man/man4/capsicum.4
index 9290cbcf0328..1d208b04a94c 100644
--- a/share/man/man4/capsicum.4
+++ b/share/man/man4/capsicum.4
@@ -26,7 +26,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd October 19, 2013
+.Dd July 25, 2015
.Dt CAPSICUM 4
.Os
.Sh NAME
@@ -125,7 +125,3 @@ and
.An Kris Kennaway Aq Mt kris@FreeBSD.org
at Google, Inc., and
.An Pawel Jakub Dawidek Aq Mt pawel@dawidek.net .
-.Sh BUGS
-.Nm
-is considered experimental in
-.Fx .
diff --git a/share/man/man4/mac.4 b/share/man/man4/mac.4
index b1ff1d951d8e..0c143139d7e0 100644
--- a/share/man/man4/mac.4
+++ b/share/man/man4/mac.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd October 30, 2007
+.Dd July 25, 2015
.Dt MAC 4
.Os
.Sh NAME
@@ -239,14 +239,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_ifoff.4 b/share/man/man4/mac_ifoff.4
index 87c73b250888..3800eeaf4cb4 100644
--- a/share/man/man4/mac_ifoff.4
+++ b/share/man/man4/mac_ifoff.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 10, 2002
+.Dd July 25, 2015
.Dt MAC_IFOFF 4
.Os
.Sh NAME
@@ -118,14 +118,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_mls.4 b/share/man/man4/mac_mls.4
index b314fb5ca3a9..9f98c465bd37 100644
--- a/share/man/man4/mac_mls.4
+++ b/share/man/man4/mac_mls.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 1, 2002
+.Dd July 25, 2015
.Dt MAC_MLS 4
.Os
.Sh NAME
@@ -236,14 +236,6 @@ Inc.\& under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_none.4 b/share/man/man4/mac_none.4
index ed13ca6f6dc7..ea5b75b34f53 100644
--- a/share/man/man4/mac_none.4
+++ b/share/man/man4/mac_none.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 1, 2002
+.Dd July 25, 2015
.Dt MAC_NONE 4
.Os
.Sh NAME
@@ -98,14 +98,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_partition.4 b/share/man/man4/mac_partition.4
index 296635edaf06..e19b1bc49731 100644
--- a/share/man/man4/mac_partition.4
+++ b/share/man/man4/mac_partition.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 9, 2002
+.Dd July 25, 2015
.Dt MAC_PARTITION 4
.Os
.Sh NAME
@@ -118,14 +118,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_seeotheruids.4 b/share/man/man4/mac_seeotheruids.4
index c870ca00d3ed..7cc3e8880915 100644
--- a/share/man/man4/mac_seeotheruids.4
+++ b/share/man/man4/mac_seeotheruids.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd October 6, 2005
+.Dd July 25, 2015
.Dt MAC_SEEOTHERUIDS 4
.Os
.Sh NAME
@@ -116,14 +116,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_stub.4 b/share/man/man4/mac_stub.4
index 89491f1605c2..77896876470e 100644
--- a/share/man/man4/mac_stub.4
+++ b/share/man/man4/mac_stub.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 1, 2002
+.Dd July 25, 2015
.Dt MAC_STUB 4
.Os
.Sh NAME
@@ -101,14 +101,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/mac_test.4 b/share/man/man4/mac_test.4
index e86d4bd0f140..6f14792faee7 100644
--- a/share/man/man4/mac_test.4
+++ b/share/man/man4/mac_test.4
@@ -30,7 +30,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd December 1, 2002
+.Dd July 25, 2015
.Dt MAC_TEST 4
.Os
.Sh NAME
@@ -102,14 +102,6 @@ under DARPA/SPAWAR contract N66001-01-C-8035
.Pq Dq CBOSS ,
as part of the DARPA CHATS research program.
.Sh BUGS
-See
-.Xr mac 9
-concerning appropriateness for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.
diff --git a/share/man/man4/procdesc.4 b/share/man/man4/procdesc.4
index ec8c827f29ec..ce32a24646da 100644
--- a/share/man/man4/procdesc.4
+++ b/share/man/man4/procdesc.4
@@ -29,7 +29,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd August 21, 2013
+.Dd July 25, 2015
.Dt PROCDESC 4
.Os
.Sh NAME
@@ -85,7 +85,3 @@ at the University of Cambridge, and
and
.An Kris Kennaway Aq Mt kris@FreeBSD.org
at Google, Inc.
-.Sh BUGS
-.Nm
-is considered experimental in
-.Fx .
diff --git a/share/man/man9/mac.9 b/share/man/man9/mac.9
index cc05c5a1f323..d1e86ad79234 100644
--- a/share/man/man9/mac.9
+++ b/share/man/man9/mac.9
@@ -33,7 +33,7 @@
.\"
.\" $FreeBSD$
.\"
-.Dd July 10, 2006
+.Dd July 25, 2015
.Dt MAC 9
.Os
.Sh NAME
@@ -62,14 +62,6 @@ opportunity to modify security behavior at those MAC API entry points.
Both consumers of the API (normal kernel services) and security modules
must be aware of the semantics of the API calls, particularly with respect
to synchronization primitives (such as locking).
-.Ss Note on Appropriateness for Production Use
-The
-.Tn TrustedBSD
-MAC Framework included in
-.Fx 5.0
-is considered experimental, and should not be deployed in production
-environments without careful consideration of the risks associated with
-the use of experimental operating system features.
.Ss Kernel Objects Supported by the Framework
The MAC framework manages labels on a variety of types of in-kernel
objects, including process credentials, vnodes, devfs_dirents, mount
@@ -232,13 +224,6 @@ Additional contributors include:
and
.An Tim Robbins .
.Sh BUGS
-See the earlier section in this document concerning appropriateness
-for production use.
-The
-.Tn TrustedBSD
-MAC Framework is considered experimental in
-.Fx .
-.Pp
While the MAC Framework design is intended to support the containment of
the root user, not all attack channels are currently protected by entry
point checks.