| Main index | Section 9 | Options |
This function checks if a subject associated to credentials u1 is denied seeing a subject or object associated to credentials u2 by a policy that requires both credentials to have at least one group in common. For this determination, the real and supplementary group IDs are used, but not the effective group IDs, as per realgroupmember(9).
This policy is active if and only if the sysctl(8) variable security.bsd.see_other_gids is set to zero.
As usual, the superuser (effective user ID 0) is exempt from this policy provided that the sysctl(8) variable security.bsd.suser_enabled is non-zero and no active MAC policy explicitly denies the exemption ( see priv_check_cred(9) ).
| CR_CANSEEOTHERGIDS (9) | August 18, 2023 |
| Main index | Section 9 | Options |
Please direct any comments about this manual page service to Ben Bullock. Privacy policy.
| “ | I think Unix and snowflakes are the only two classes of objects in the universe in which no two instances ever match exactly. | ” |
| — Noel Chiappa | ||