cr_seeotheruids(9) determine visibility of objects given their user credentials

SYNOPSIS

Ft int Fn cr_seeotheruids struct ucred *u1 struct ucred *u2

DESCRIPTION

This function determines the visibility of objects in the kernel based on the real user IDs in the credentials Fa u1 and Fa u2 associated with them.

The visibility of objects is influenced by the sysctl(8) variable security.bsd.see_other_uids If this variable is non-zero then all objects in the kernel are visible to each other irrespective of their user IDs. If this variable is zero then the object with credentials Fa u2 is visible to the object with credentials Fa u1 if either Fa u1 is the super-user credential, or if Fa u1 and Fa u2 have the same real user ID.

SYSCTL VARIABLES

security.bsd.see_other_uids
Must be non-zero if objects with unprivileged credentials are to be able to see each other.

RETURN VALUES

This function returns zero if the object with credential Fa u1 can ``see'' the object with credential Fa u2 , or Er ESRCH otherwise.