diff --git a/sys/kern/kern_jail.c b/sys/kern/kern_jail.c index f61b3019121..49bc080677f 100644 --- a/sys/kern/kern_jail.c +++ b/sys/kern/kern_jail.c @@ -684,6 +684,7 @@ prison_priv_check(struct ucred *cred, int priv) case PRIV_VFS_FCHROOT: case PRIV_VFS_LINK: case PRIV_VFS_SETGID: + case PRIV_VFS_STAT: case PRIV_VFS_STICKYFILE: return (0); diff --git a/sys/sys/priv.h b/sys/sys/priv.h index ec8be5a8162..94701917945 100644 --- a/sys/sys/priv.h +++ b/sys/sys/priv.h @@ -277,6 +277,7 @@ #define PRIV_VFS_STICKYFILE 341 /* Can set sticky bit on file. */ #define PRIV_VFS_SYSFLAGS 342 /* Can modify system flags. */ #define PRIV_VFS_UNMOUNT 343 /* Can unmount(). */ +#define PRIV_VFS_STAT 344 /* Override vnode MAC stat perm. */ /* * Virtual memory privileges.