#!/bin/sh
#
# ident	"@(#)i.devpolicy	1.19	08/01/07 SMI"
#
# Copyright 2008 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#
#  NOTE:  When a change is made to the source file for
#  /etc/security/device_policy a corresponding change must be made to
#  this class-action script.
#
while read src dest
do
	if [ ! -f $dest ] ; then
		cp $src $dest
		continue
	fi

	# changes
	cp $dest $dest.$$
	sed < $dest.$$ > $dest \
	    -e '/md:admin/s/read_priv_set=sys_config/			/' \
	    -e '/^icmp[ 	]*read_priv_set=net_rawaccess[ 	]*write_priv_set=net_rawaccess$/d' \
	    -e '/^icmp6[ 	]*read_priv_set=net_rawaccess[ 	]*write_priv_set=net_rawaccess$/d' \
	    -e '/^keysock[ 	]*read_priv_set=sys_net_config[ 	]*write_priv_set=sys_net_config$/d' \
	    -e '/^ipsecah[ 	]*read_priv_set=sys_net_config[ 	]*write_priv_set=sys_net_config$/d' \
	    -e '/^ipsecesp[ 	]*read_priv_set=sys_net_config[ 	]*write_priv_set=sys_net_config$/d' \
	    -e '/^spdsock[ 	]*read_priv_set=sys_net_config[ 	]*write_priv_set=sys_net_config$/d' \
	    -e '/^ipf[ 	]*read_priv_set=sys_net_config[ 	]*write_priv_set=sys_net_config$/d'

	rm -f $dest.$$

	# potential additions
	additions="aggr aggr:ctl bge dld:ctl dnet keysock ibd icmp icmp6 ipsecah ipsecesp openeepr random spdsock vni ipf pfil scsi_vhci"

	for dev in $additions
	do
		# if an entry for this driver exists in the source
		# file...
		grep "$dev[ 	]" $src > /dev/null 2>&1
		if [ $? = 0 ] ; then
			# ...and no entry exists in the destination
			# file...
			grep "$dev[ 	]" $dest > /dev/null 2>&1
			if [ $? != 0 ] ; then
				# ...then add the entry from
				# the source file to the
				# destination file.
				grep "$dev[ 	]" $src >> $dest
			fi
		fi
	done

	# potential deletions
	deletions="elx dld"

	for dev in $deletions
	do
		# if an entry for this driver exists in the destination
		# file...
		grep "$dev[ 	]" $dest > /dev/null 2>&1
		if [ $? = 0 ] ; then
			# ...and no entry exists in the source
			# file...
			grep "$dev[ 	]" $src > /dev/null 2>&1
			if [ $? != 0 ] ; then
				# ...then remove the entry from
				# the destination file.
				cp $dest $dest.$$
				grep -v "$dev[ 	]" $dest.$$ > $dest
				rm -f $dest.$$
			fi
		fi
	done
done

exit 0
