![]() |
![]()
| ![]() |
![]()
NAME
SYNOPSISint
DESCRIPTIONThis function is internal. Its functionality is integrated
into the function
cr_bsd_visible(9),
which should be called instead.
This function checks if a subject associated to credentials u1 is denied seeing a subject or object associated to credentials u2 by a policy that requires both credentials to have the same real user ID. This policy is active if and only if the sysctl(8) variable security.bsd.see_other_uids is set to zero. As usual, the superuser (effective user ID 0) is exempt from this policy provided that the sysctl(8) variable security.bsd.suser_enabled is non-zero and no active MAC policy explicitly denies the exemption (see priv_check_cred(9)). RETURN VALUESThe SEE ALSO
|