Hi,
Please review the attached diff. I removed explicit
KAUTH_RESULT_DENY
assignments in secmodel_bsd44_suser.c, so there's a single,
default
deny in each listener, and "allow" is done
explicitly.
Given this is a change in critical code, I'd appreciate
careful review.
Of course, any other input is welcome.
Thanks,
-e.