summaryrefslogtreecommitdiff
path: root/usr/src/pkgdefs/common_files/i.devpolicy
blob: 811a2db18b4655799738ef0791bf3bd811f0886d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
#!/bin/sh
#
# CDDL HEADER START
#
# The contents of this file are subject to the terms of the
# Common Development and Distribution License (the "License").
# You may not use this file except in compliance with the License.
#
# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
# or http://www.opensolaris.org/os/licensing.
# See the License for the specific language governing permissions
# and limitations under the License.
#
# When distributing Covered Code, include this CDDL HEADER in each
# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
# If applicable, add the following below this CDDL HEADER, with the
# fields enclosed by brackets "[]" replaced with your own identifying
# information: Portions Copyright [yyyy] [name of copyright owner]
#
# CDDL HEADER END
#
#
# ident	"%Z%%M%	%I%	%E% SMI"
#
# Copyright 2006 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#
#  NOTE:  When a change is made to the source file for
#  /etc/security/device_policy a corresponding change must be made to
#  this class-action script.
#
while read src dest
do
	if [ ! -f $dest ] ; then
		cp $src $dest
		continue
	fi

	# changes
	cp $dest $dest.$$
	sed < $dest.$$ > $dest \
	    -e '/md:admin/s/read_priv_set=sys_config/			/' \
	    -e '/^icmp[ 	]*read_priv_set=net_rawaccess[ 	]*write_priv_set=net_rawaccess$/d' \
	    -e '/^icmp6[ 	]*read_priv_set=net_rawaccess[ 	]*write_priv_set=net_rawaccess$/d'

	rm -f $dest.$$

	# potential additions
	additions="aggr aggr:ctl bge dld:ctl dnet ibd icmp icmp6 openeepr random vni ipf pfil scsi_vhci"

	for dev in $additions
	do
		# if an entry for this driver exists in the source
		# file...
		grep "$dev[ 	]" $src > /dev/null 2>&1
		if [ $? = 0 ] ; then
			# ...and no entry exists in the destination
			# file...
			grep "$dev[ 	]" $dest > /dev/null 2>&1
			if [ $? != 0 ] ; then
				# ...then add the entry from
				# the source file to the
				# destination file.
				grep "$dev[ 	]" $src >> $dest
			fi
		fi
	done

	# potential deletions
	deletions="elx dld"

	for dev in $deletions
	do
		# if an entry for this driver exists in the destination
		# file...
		grep "$dev[ 	]" $dest > /dev/null 2>&1
		if [ $? = 0 ] ; then
			# ...and no entry exists in the source
			# file...
			grep "$dev[ 	]" $src > /dev/null 2>&1
			if [ $? != 0 ] ; then
				# ...then remove the entry from
				# the destination file.
				cp $dest $dest.$$
				grep -v "$dev[ 	]" $dest.$$ > $dest
				rm -f $dest.$$
			fi
		fi
	done
done

exit 0