/dev/pf is usable in vnet jails, so don't hide the node there.
We shouldn't expose /dev/pf in regular jails, as that gives them control
over the host (or parent vnet jail) firewall.
Differential D26537
devfs.rules: unhide pf in vnet jails kp on Sep 23 2020, 7:14 PM. Authored by Tags None Referenced Files
Details
/dev/pf is usable in vnet jails, so don't hide the node there. We shouldn't expose /dev/pf in regular jails, as that gives them control
Diff Detail
Event TimelineComment Actions Did we ever fix this one? https://www.openbsd.org/errata48.html https://ftp.openbsd.org/pub/OpenBSD/patches/4.8/common/005_pf.patch Comment Actions Oh wow, and not even I could remember that ... Good to know I can finally forget about it for real ;-) Comment Actions We'll probably want to add more of these in the future for vnets, so happy we start to lay the grounds. Comment Actions jail (and ezjail) already make it possible to set the desired devise rules, so in that respect it's already done. |