<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div>There is a patch: <a href="https://www.illumos.org/issues/7529">https://www.illumos.org/issues/7529</a><br><br><div>--</div>Dmitry Glushenok</div><div id="AppleMailSignature">Jet Infosystems</div><div><br>3 нояб. 2016 г., в 16:23, Дмитрий Глушенок <<a href="mailto:glush@jet.msk.su">glush@jet.msk.su</a>> написал(а):<br><br></div><blockquote type="cite"><div><span>smbd makes it's own privilege set at start:</span><br><span></span><br><span>smbd_daemonize_fini(int fd, int exit_status)</span><br><span>...</span><br><span>    priv_basicset(pset);</span><br><span></span><br><span>    /* list of privileges for smbd */</span><br><span>    (void) priv_addset(pset, PRIV_NET_MAC_AWARE);</span><br><span>    (void) priv_addset(pset, PRIV_NET_PRIVADDR);</span><br><span>    (void) priv_addset(pset, PRIV_PROC_AUDIT);</span><br><span>    (void) priv_addset(pset, PRIV_SYS_DEVICES);</span><br><span>    (void) priv_addset(pset, PRIV_SYS_SMB);</span><br><span>    (void) priv_addset(pset, PRIV_SYS_MOUNT);</span><br><span></span><br><span>    priv_inverse(pset);</span><br><span></span><br><span>    /* turn off unneeded privileges */</span><br><span>    (void) setppriv(PRIV_OFF, PRIV_EFFECTIVE, pset);</span><br><span>...</span><br><span></span><br><span>So, SMF context will not work. For now I've set "ppriv && SIGHUP" in a separate service, which is launched just after smbd.</span><br><span></span><br><span>--</span><br><span>Dmitry Glushenok</span><br><span>Jet Infosystems</span><br><span></span><br><blockquote type="cite"><span>3 нояб. 2016 г., в 15:58, Jim Klimov <<a href="mailto:jimklimov@cos.ru">jimklimov@cos.ru</a>> написал(а):</span><br></blockquote><blockquote type="cite"><span></span><br></blockquote><blockquote type="cite"><span>If that is the case, consider fixing up the method_context privileges in the SMF service for the smb/server.</span><br></blockquote><blockquote type="cite"><span>Good luck and thanks for sharing ;)</span><br></blockquote><span></span><br></div></blockquote></body></html>