author | gd78059 |
Thu, 04 Oct 2007 13:32:50 -0700 | |
changeset 5181 | b280720be441 |
parent 4962 | 44219572abba |
child 7408 | eff7960d93cd |
permissions | -rw-r--r-- |
0 | 1 |
#!/bin/sh |
2 |
# |
|
3 |
# CDDL HEADER START |
|
4 |
# |
|
5 |
# The contents of this file are subject to the terms of the |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
6 |
# Common Development and Distribution License (the "License"). |
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
7 |
# You may not use this file except in compliance with the License. |
0 | 8 |
# |
9 |
# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE |
|
10 |
# or http://www.opensolaris.org/os/licensing. |
|
11 |
# See the License for the specific language governing permissions |
|
12 |
# and limitations under the License. |
|
13 |
# |
|
14 |
# When distributing Covered Code, include this CDDL HEADER in each |
|
15 |
# file and include the License file at usr/src/OPENSOLARIS.LICENSE. |
|
16 |
# If applicable, add the following below this CDDL HEADER, with the |
|
17 |
# fields enclosed by brackets "[]" replaced with your own identifying |
|
18 |
# information: Portions Copyright [yyyy] [name of copyright owner] |
|
19 |
# |
|
20 |
# CDDL HEADER END |
|
21 |
# |
|
22 |
# |
|
23 |
# ident "%Z%%M% %I% %E% SMI" |
|
24 |
# |
|
3448 | 25 |
# Copyright 2007 Sun Microsystems, Inc. All rights reserved. |
0 | 26 |
# Use is subject to license terms. |
27 |
# |
|
28 |
# NOTE: When a change is made to the source file for |
|
29 |
# /etc/security/device_policy a corresponding change must be made to |
|
30 |
# this class-action script. |
|
31 |
# |
|
32 |
while read src dest |
|
33 |
do |
|
34 |
if [ ! -f $dest ] ; then |
|
35 |
cp $src $dest |
|
36 |
continue |
|
37 |
fi |
|
38 |
||
39 |
# changes |
|
40 |
cp $dest $dest.$$ |
|
41 |
sed < $dest.$$ > $dest \ |
|
42 |
-e '/md:admin/s/read_priv_set=sys_config/ /' \ |
|
43 |
-e '/^icmp[ ]*read_priv_set=net_rawaccess[ ]*write_priv_set=net_rawaccess$/d' \ |
|
3448 | 44 |
-e '/^icmp6[ ]*read_priv_set=net_rawaccess[ ]*write_priv_set=net_rawaccess$/d' \ |
45 |
-e '/^keysock[ ]*read_priv_set=sys_net_config[ ]*write_priv_set=sys_net_config$/d' \ |
|
46 |
-e '/^ipsecah[ ]*read_priv_set=sys_net_config[ ]*write_priv_set=sys_net_config$/d' \ |
|
47 |
-e '/^ipsecesp[ ]*read_priv_set=sys_net_config[ ]*write_priv_set=sys_net_config$/d' \ |
|
48 |
-e '/^spdsock[ ]*read_priv_set=sys_net_config[ ]*write_priv_set=sys_net_config$/d' \ |
|
4962
44219572abba
6557414 autopush doesn't work in exclusive-IP zones
dh155122
parents:
3448
diff
changeset
|
49 |
-e '/^ipf[ ]*read_priv_set=sys_net_config[ ]*write_priv_set=sys_net_config$/d' \ |
44219572abba
6557414 autopush doesn't work in exclusive-IP zones
dh155122
parents:
3448
diff
changeset
|
50 |
-e '/^sad:admin[ ]*read_priv_set=sys_config[ ]*write_priv_set=sys_config$/d' |
0 | 51 |
|
52 |
rm -f $dest.$$ |
|
53 |
||
54 |
# potential additions |
|
3448 | 55 |
additions="aggr aggr:ctl bge dld:ctl dnet keysock ibd icmp icmp6 ipsecah ipsecesp openeepr random spdsock vni ipf pfil scsi_vhci" |
0 | 56 |
|
57 |
for dev in $additions |
|
58 |
do |
|
59 |
# if an entry for this driver exists in the source |
|
60 |
# file... |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
61 |
grep "$dev[ ]" $src > /dev/null 2>&1 |
0 | 62 |
if [ $? = 0 ] ; then |
63 |
# ...and no entry exists in the destination |
|
64 |
# file... |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
65 |
grep "$dev[ ]" $dest > /dev/null 2>&1 |
0 | 66 |
if [ $? != 0 ] ; then |
67 |
# ...then add the entry from |
|
68 |
# the source file to the |
|
69 |
# destination file. |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
70 |
grep "$dev[ ]" $src >> $dest |
0 | 71 |
fi |
72 |
fi |
|
73 |
done |
|
74 |
||
75 |
# potential deletions |
|
5181
b280720be441
6317553 Wrong fix implemented in 4877168 for dmfe Rx buffer unavailable messages.
gd78059
parents:
4962
diff
changeset
|
76 |
deletions="elx dld le" |
0 | 77 |
|
78 |
for dev in $deletions |
|
79 |
do |
|
80 |
# if an entry for this driver exists in the destination |
|
81 |
# file... |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
82 |
grep "$dev[ ]" $dest > /dev/null 2>&1 |
0 | 83 |
if [ $? = 0 ] ; then |
84 |
# ...and no entry exists in the source |
|
85 |
# file... |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
86 |
grep "$dev[ ]" $src > /dev/null 2>&1 |
0 | 87 |
if [ $? != 0 ] ; then |
88 |
# ...then remove the entry from |
|
89 |
# the destination file. |
|
90 |
cp $dest $dest.$$ |
|
1804
102112240ff7
6312408 DDI_NT_MAC macro definition should be removed
ericheng
parents:
907
diff
changeset
|
91 |
grep -v "$dev[ ]" $dest.$$ > $dest |
0 | 92 |
rm -f $dest.$$ |
93 |
fi |
|
94 |
fi |
|
95 |
done |
|
96 |
done |
|
97 |
||
98 |
exit 0 |