cap_sysctlbyname for hw.vmm.destroy

Ionuț Mihalache ionut.mihalache1506 at gmail.com
Mon Apr 26 14:16:27 UTC 2021


Hello,

I am working on adding capsicum support for the bhyve snapshot feature. At
the end of the suspend process, the guest should be destroyed and the code
handles this part with a sysctlbyname call which is not working in
capability mode. I don't know what is the problem but even when using
cap_sysctlbyname I still get the same error code (EPERM). I tried the
example from the documentation aswell [1] and still the same error code.
What could be the problem? I have a FreeBSD13 host and a FreeBSD13 guest.

[1] -
https://www.freebsd.org/cgi/man.cgi?query=cap_sysctl&apropos=0&sektion=0&manpath=FreeBSD+13-current&arch=default&format=html


More information about the freebsd-hackers mailing list