Page MenuHomeFreeBSD

devfs.rules: Correctly unhide pf in vnet jails
ClosedPublic

Authored by zlei on Nov 3 2021, 10:02 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Mar 21, 11:56 PM
Unknown Object (File)
Tue, Mar 17, 12:49 PM
Unknown Object (File)
Tue, Mar 17, 9:19 AM
Unknown Object (File)
Tue, Mar 17, 3:40 AM
Unknown Object (File)
Mon, Mar 16, 5:43 AM
Unknown Object (File)
Sun, Mar 15, 5:42 PM
Unknown Object (File)
Wed, Mar 11, 3:12 AM
Unknown Object (File)
Mon, Mar 9, 6:56 PM
Subscribers

Details

Summary

The revision D26537 introduced a new devfs rule devfsrules_jail_vnet. It includes rule devfsrules_jail which include other rules. Unfortunately devfs could not recursively parse the action include and thus devfsrules_jail_vnet will expose all nodes.

Obtained from: Gijs Peskens <gijs@peskens.net>
PR: 255660

Test Plan
service devfs restart
mount -t devfs devfs /tmp/dev
devfs -m /tmp/dev rule -s 5 applyset

and manually verify mount point.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable