Page MenuHomeFreeBSD

libjail: fix fetching mac.label for multiple jails
ClosedPublic

Authored by kevans on May 27 2026, 6:50 PM.
Tags
None
Referenced Files
F174828051: D57280.id178752.diff
Tue, Oct 6, 6:56 AM
Unknown Object (File)
Sun, Oct 4, 12:30 AM
Unknown Object (File)
Sat, Oct 3, 9:52 PM
Unknown Object (File)
Sat, Oct 3, 2:17 AM
Unknown Object (File)
Fri, Oct 2, 11:43 PM
Unknown Object (File)
Fri, Oct 2, 9:38 PM
Unknown Object (File)
Thu, Oct 1, 3:42 PM
Unknown Object (File)
Tue, Sep 29, 9:33 AM
Subscribers

Details

Summary

When doing a basic jls -n, jls(8) will jailparam_get() the mac.label
for every jail on the system using the same set of jailparams, and thus
the same jp_value. We only init the mac_t the first time, so the first
jail would populate it with ? from /etc/mac.conf and the resulting
jail_get(2) would clobber it with the empty string, then a second jail
would try to pass the empty string to the kernel and fail because it
must have a non-zero length.

Fix it by invoking jps_get() every time. Drop some comments to note
that jps_get() will be invoked with zero || garbage from previous call,
and be sure that we don't leak our previous mac_t. There aren't any
other jps_get implementations at this time, so this shouldn't cause any
unexpected problems.

Reported by: ivy

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

jamie added a subscriber: jamie.

The key point is "there aren't any other jps_get implementations." So it's all yours :-)

This revision was not accepted when it landed; it landed in state Needs Review.Wed, Sep 9, 9:25 PM
This revision was automatically updated to reflect the committed changes.