Page MenuHomeFreeBSD

jamie (James Gritton)
User

Projects

User Details

User Since
Aug 3 2014, 10:29 PM (635 w, 6 d)

Recent Activity

Thu, Oct 8

jamie committed rG8436cbdb909a: jaildesc: Lock prison pointer when filling kinfo (authored by jamie).
jaildesc: Lock prison pointer when filling kinfo
Thu, Oct 8, 3:43 AM

Mon, Oct 5

jamie committed rGa5ae2a9bfb1c: jaildesc: Lock prison pointer when filling kinfo (authored by jamie).
jaildesc: Lock prison pointer when filling kinfo
Mon, Oct 5, 11:57 PM
jamie closed D60392: jaildesc: Lock prison pointer when filling kinfo.
Mon, Oct 5, 11:57 PM · Jails
jamie accepted D60392: jaildesc: Lock prison pointer when filling kinfo.

I don't see you on the committer list - do you want me to commit this for you?

Mon, Oct 5, 11:31 PM · Jails

Sat, Oct 3

jamie added a comment to D60273: jail: declare argument structure of jail(2) with const fields.

The const strings seem unlike to cause any trouble, but I wonder what code is out there along the lines of:

Sat, Oct 3, 5:00 PM

Fri, Oct 2

jamie committed rGd9e2caccfac1: jail: note existing process/prison lock order in witness. (authored by jamie).
jail: note existing process/prison lock order in witness.
Fri, Oct 2, 10:19 PM

Wed, Sep 30

jamie added a comment to D59748: Jail init process and virtual reboot.
In D59748#1380508, @bz wrote:

I have an old (non-stack) stack open (I believe from 2018) of which you would have been a reviewer:
D15556 Initial vps (virtual process space) framework for jails.
D15570 Virtualization of basic variables and locks for jail+vps.
D15865 Provide process space virtualisation functionality for jails.
D15906 Implement "global" process (and zombie) lists loops iterating over all vps instances and all processes in each.

Just in case it helps taking this one level further; a rebase will certainly not be easy.

Wed, Sep 30, 6:32 PM
jamie added a comment to D59748: Jail init process and virtual reboot.

Some thinking about this:

  1. Actually prison0 is almost identical to other unprivileged prisons. After we have virtual init, then is it possible to fast reboot prison0 ( let's forget kill 1 right now ) ?

I could be added with some new flag to specify it. But I don't know about the utility: usually when you're rebooting the whole system, you want to reset hardware state, or change a kernel, or something else more than this virtual reboot provides.

Wed, Sep 30, 6:19 PM

Tue, Sep 29

jamie added a comment to D59748: Jail init process and virtual reboot.

This is interesting. I asked Claude Code to help a bit with the review...

Ah, my first encounter with Claude. So how much of this was Claude Code, and how much was you?

Tue, Sep 29, 11:55 PM
jamie updated the diff for D60003: Combine duplicated code in prison_deref and prison_deref_kill.

Decouple the question of mac_prison_destroy's expected state, which is independent of the rest of the patch.

Tue, Sep 29, 2:40 AM

Mon, Sep 28

jamie accepted D60025: sys/uio: add updateiov().
Mon, Sep 28, 7:39 PM
jamie accepted D60026: jail_{get,set}: user_ implementations.
Mon, Sep 28, 7:39 PM

Fri, Sep 25

jamie accepted D60030: sysvshm: Fix locking in shm_prison_set().

Look good. I was hesitant because it's an sx lock, but I don't see any mutexes held when it's locked. I suspect that hesitance was why I didn't do it tthe same as sysv_sem and sysv_msg in the first place, but that was a while ago and has totally escaped my memory.

Fri, Sep 25, 7:51 PM
jamie added inline comments to D60003: Combine duplicated code in prison_deref and prison_deref_kill.
Fri, Sep 25, 7:26 PM
jamie updated the diff for D60003: Combine duplicated code in prison_deref and prison_deref_kill.

Always call prison_deref_remove with both allprison and the prison lock held. That's the documented requirement for changing pr_state; otherwise some thread with a locked prison might find it disappear out from under them. This reverse to the old behavior of prison_deref_kill delaying the removal from the sibling list, but not delaying any of the other operations.

Fri, Sep 25, 5:08 AM
jamie added a comment to D60003: Combine duplicated code in prison_deref and prison_deref_kill.

The test of (INVALID && pr_ref == 0) guarantees the "was valid, no longer is" status. When a prison is created, it's INVALID and initialized with pr_ref = 1. The only other time the state is INVALID is when the prison dies, i.e. reaches pr_ref == 0. It's certainly non-obvious, so I can add a comment for it.

Fri, Sep 25, 4:14 AM

Thu, Sep 24

jamie added a comment to D60003: Combine duplicated code in prison_deref and prison_deref_kill.

Just on typing the description, I've found a problem: the reason mac_prison_destroy couldn't count on the prison being locked is that I call it from prison_deref_kill with a delay. The purpose of the delay is so I'm not mangling a prison's sibling list as I traverse it (and by that time the prison is no longer locked). But prison_deref_remove sets pr_state = PRISON_STATE_INVALID, which is only allowed when the mutex is held.

Thu, Sep 24, 11:50 PM
jamie updated the summary of D60003: Combine duplicated code in prison_deref and prison_deref_kill.
Thu, Sep 24, 11:38 PM
jamie requested review of D60003: Combine duplicated code in prison_deref and prison_deref_kill.
Thu, Sep 24, 11:36 PM
jamie accepted D59984: jail: Fix a race in prison_deref().

Yes, I'm referring to a prison I don't hold a reference to, without allprison_lock held. My bad. This look good, with the common path not adding any extra steps.

Thu, Sep 24, 5:59 PM
jamie accepted D59983: jail: Simplify refcount manipulation routines.

I wasn't familiar with __diagused. Yes, this is all cleaner.

Thu, Sep 24, 5:26 PM

Wed, Sep 23

jamie committed rG10a3562a019b: jail: set default root directory for a jail to its parent's root. (authored by jamie).
jail: set default root directory for a jail to its parent's root.
Wed, Sep 23, 11:26 PM

Wed, Sep 16

jamie requested review of D59748: Jail init process and virtual reboot.
Wed, Sep 16, 11:17 PM

Sep 10 2026

jamie accepted D59577: libjail, jls(8), jail(8): use the JAIL_PARAM_* constants.

Ah yes, they're in libjail as well.

Sep 10 2026, 7:28 PM
jamie accepted D59572: jail: define well-known parameter names in sys/jail.h.
Sep 10 2026, 6:59 PM
jamie added a comment to D59572: jail: define well-known parameter names in sys/jail.h.

Now that I think about it, jail(8) and jls(8) code is also rife with these strings.

Sep 10 2026, 6:35 PM
jamie added a comment to D59572: jail: define well-known parameter names in sys/jail.h.

It would make sense to broaden their use, with bare string literals also being used in vfs_copyopt and vfs_setopt calls.

Sep 10 2026, 6:24 PM

Aug 24 2026

jamie added a comment to D54099: kern: jail: allow specifying a cpuset.parent at creation time.

What's the significance of the parent cpuset being marked CPU_SET_ROOT? This question didn't block my approval, because I really just don't understand the implications. Before, root cpusets had a 1:1 correspondence with jails, and now they don't.

Aug 24 2026, 2:18 AM
jamie accepted D54099: kern: jail: allow specifying a cpuset.parent at creation time.
Aug 24 2026, 2:08 AM
jamie added inline comments to D54099: kern: jail: allow specifying a cpuset.parent at creation time.
Aug 24 2026, 2:01 AM
jamie added inline comments to D54099: kern: jail: allow specifying a cpuset.parent at creation time.
Aug 24 2026, 12:35 AM

Jul 5 2026

jamie accepted D58049: jaildesc: Publish the new fd only after the jaildesc is initialized.
Jul 5 2026, 10:01 PM
jamie committed rG5ba2b4f773c2: jail: prevent a race between jail_attach in different threads (authored by jamie).
jail: prevent a race between jail_attach in different threads
Jul 5 2026, 5:14 AM
jamie committed rG530ee2980c50: jail: clean up locking around do_jail_attach (authored by jamie).
jail: clean up locking around do_jail_attach
Jul 5 2026, 5:14 AM
jamie committed rG334c8ba7dd9c: jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails (authored by jamie).
jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails
Jul 5 2026, 5:14 AM
jamie committed rGa4df9e3efa30: jail: prevent a race between jail_attach in different threads (authored by jamie).
jail: prevent a race between jail_attach in different threads
Jul 5 2026, 2:55 AM
jamie committed rGaca9811160f4: jail: prevent a null derefence on array parameter assignment (authored by jamie).
jail: prevent a null derefence on array parameter assignment
Jul 5 2026, 2:51 AM
jamie committed rGcb0b277f71b6: jail: prevent a null derefence on array parameter assignment (authored by jamie).
jail: prevent a null derefence on array parameter assignment
Jul 5 2026, 2:51 AM

Jul 2 2026

jamie closed D57858: Prevent a jail_attach race between threads.
Jul 2 2026, 10:52 PM
jamie committed rGd4e0f4dab2d7: jail: prevent a race between jail_attach in different threads (authored by jamie).
jail: prevent a race between jail_attach in different threads
Jul 2 2026, 10:52 PM
jamie updated the diff for D57858: Prevent a jail_attach race between threads.

Fix variable declaration order.

Jul 2 2026, 12:26 AM

Jul 1 2026

jamie updated the diff for D57858: Prevent a jail_attach race between threads.

Clean up prison_attach_thread_single a bit so I don't need to different PROC_UNLOCK calls.

Jul 1 2026, 11:56 PM
jamie added inline comments to D57858: Prevent a jail_attach race between threads.
Jul 1 2026, 7:40 PM
jamie updated the diff for D57858: Prevent a jail_attach race between threads.

Move thread_single calls and related code inside a well-commented
wrapper function. Add atomic_load to the process flag read. Fix
tests so they can run in parallel, other small fixes.

Jul 1 2026, 7:37 PM
jamie committed rG6d9bc46cd7fc: jail: prevent a null derefence on array parameter assignment (authored by jamie).
jail: prevent a null derefence on array parameter assignment
Jul 1 2026, 6:38 PM

Jun 28 2026

jamie committed rG8f14ea499fc6: jail: clean up locking around do_jail_attach (authored by jamie).
jail: clean up locking around do_jail_attach
Jun 28 2026, 4:08 PM

Jun 26 2026

jamie updated the diff for D57858: Prevent a jail_attach race between threads.

Add a test for races between jail_attach_jd and chroot. Let all the tests run instead of stopping on the first failure.

Jun 26 2026, 8:04 PM
jamie added a comment to D57858: Prevent a jail_attach race between threads.

I altered the patch to use an sx lock instead of thread single, and it passed the test as expected. But then I added a test for a race between jail_attach_jd and chroot, and it failed.

Jun 26 2026, 7:21 PM
jamie added a comment to D57858: Prevent a jail_attach race between threads.

That's why it's EPERM to jail_attach with any directory fds open. But a concurrent chdir/chroot could work around that, e.g. if the jail_attach happens between path lookup and pwd_chroot().

Jun 26 2026, 6:50 AM
jamie added a comment to D57858: Prevent a jail_attach race between threads.

I'll have to think a little on the chdir question. I considered it and chroot briefly, but only after I decided on single threading anyway, and I figured they weren't a problem because of the boundary requirement. Without that, it seems likely that a jail_attach in parallel with a chroot would have the same outcome.

Jun 26 2026, 6:08 AM
jamie added a comment to D57858: Prevent a jail_attach race between threads.

I could do that, but I actually considered single threading to be the smaller hammer, because it only affects other threads in the process instead of any process attaching to any jail. But even if not single threading, I could have a jail_attach sx that's only used for multi-threaded processes.

Jun 26 2026, 5:43 AM
jamie added inline comments to D57858: Prevent a jail_attach race between threads.
Jun 26 2026, 4:35 AM
jamie updated the diff for D57858: Prevent a jail_attach race between threads.

Move the thread_single and thread_single_end calls from do_jail_attach to the system call level (kern_jail_set, sys_jail_attach, sys_jail_attach_jd). Return ERESTART instead of EAGAIN for lost races.

Jun 26 2026, 4:33 AM
jamie added inline comments to D57858: Prevent a jail_attach race between threads.
Jun 26 2026, 2:39 AM

Jun 25 2026

jamie requested review of D57858: Prevent a jail_attach race between threads.
Jun 25 2026, 11:07 PM
jamie committed rG3584cde63e41: jail: clean up locking around do_jail_attach (authored by jamie).
jail: clean up locking around do_jail_attach
Jun 25 2026, 3:24 AM

Jun 24 2026

jamie committed rG315238df5323: jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails (authored by jamie).
jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails
Jun 24 2026, 5:48 PM

Jun 23 2026

jamie updated the diff for D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .

Don't change refcount_acquire to prison_proc_hold - the INVARIANTS test makes then not the same.

Jun 23 2026, 10:16 PM
jamie added inline comments to D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .
Jun 23 2026, 10:15 PM

Jun 20 2026

jamie updated the diff for D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .

New diff with drflags pointer passed to do_jail_attach. I also removed the requirement that the jail be locked, which hasn't been the case since pr_ref and pr_uref went atomic.

Jun 20 2026, 7:53 PM
jamie added inline comments to D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .
Jun 20 2026, 3:45 PM
jamie accepted D57697: kern: add a security knob to disable unprivileged access to kenv.
Jun 20 2026, 1:34 PM

Jun 19 2026

jamie committed rGe91e8ebefadc: jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails (authored by jamie).
jail: call PR_METHOD_ATTACH again (with old jail) if the first call fails
Jun 19 2026, 7:46 PM
jamie updated the diff for D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .

Removed an unrelated fix to a different jail_attach problem.

Jun 19 2026, 6:24 PM
jamie added inline comments to D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .
Jun 19 2026, 5:56 PM
jamie requested review of D57674: Clean up locking around do_jail_attach, fixing zombie jails from jail_attach_jd .
Jun 19 2026, 5:51 PM

Jun 12 2026

jamie committed rG4938fd9361b4: jail: Don't double-free the current prison in kern_jail_set/get (authored by jamie).
jail: Don't double-free the current prison in kern_jail_set/get
Jun 12 2026, 6:00 PM

Jun 9 2026

jamie committed rGb52dc2067618: jail: Don't double-free the current prison in kern_jail_set/get (authored by jamie).
jail: Don't double-free the current prison in kern_jail_set/get
Jun 9 2026, 10:33 PM

May 30 2026

jamie added a comment to D57278: sys/kern/kern_jail: Improve subsystem flag handling.

Yes, the current setup is an ad-hoc mess, and could use some work. But maybe we *should* refactor the whole thing. Not to the point of ABI change with different parameters, but at least with enough specification inside to be able to know and report the state of subsystems. The current setup of a single bit works for the majority of systems, which can't be disabled. But the truly three-way systems could be standardized with separate "enabled" and "new" flags. There's usually a "real" state that uses something aside from a bit, such as the existence of the pr_addrs array, but these could exist along with the bitmask.

May 30 2026, 11:32 PM

May 29 2026

jamie accepted D57280: libjail: fix fetching mac.label for multiple jails.

The key point is "there aren't any other jps_get implementations." So it's all yours :-)

May 29 2026, 7:34 PM
jamie accepted D56967: jail: add allow.mount.all to allow mounting any filesystem.

Only one little thing to go, so I'll call it approval. Since the parameter is allow.mount.all, the associated flag should be PR_ALLOW_MOUNT_ALL, not PR_ALLOW_MOUNT_ANY.

May 29 2026, 4:39 AM

May 21 2026

jamie added a comment to D56967: jail: add allow.mount.all to allow mounting any filesystem.

No, I still hold that the extra level adds nothing.

May 21 2026, 10:59 PM

May 15 2026

jamie added a comment to D56967: jail: add allow.mount.all to allow mounting any filesystem.

There's no need for the two-layer name "unsafe.all". If you really want both "unsafe" and "all" in the name allow.mount.unsafe_all should do. Better yet would be to keep is simple with allow.mount.all to allow all filesystems, with the understanding that such a thing might be unsafe. As it stands, there's this "allow.mount.unsafe" hierarchy, which suggests that allowing all filesystem types is unsafe, which each of those filesystem types is implicitly labeled as safe.

May 15 2026, 6:15 PM

May 4 2026

jamie accepted D54992: kern: better hierarchical jail semantics for ALLOW_UNPRIV_PARENT_TAMPER.

PR_ALLOW_UNPRIV_PARENT_TAMPER is enough of a corner case (in restricting a parent jail) that I don't foresee anyone else calling prison_chain_allow. But perhaps that's just my own lack of imagination ;-)

May 4 2026, 9:51 PM

Mar 13 2026

jamie accepted D55828: ifnet: Remove unreachable code.
Mar 13 2026, 5:01 PM
jamie added inline comments to D55832: ifnet: if_vmove_(loan|reclaim): Refactor a bit the checking of src / dst vnet.
Mar 13 2026, 4:57 PM

Mar 12 2026

jamie added a comment to D55828: ifnet: Remove unreachable code.

This makes sense in if_vmove_reclaim, where the vnet comes from the held prison. But in if_vmove_loan, you're only holding the prison that will get the interface, not the one that currently has it. That wouldn't affect whether ifp currently belongs to a mid-shutdown vnet.

Mar 12 2026, 5:07 PM

Feb 4 2026

jamie added a comment to D55066: vmm: Allow the use of PCI passthrough in a jail.
In D55066#1259408, @bz wrote:

My historic understanding was that we would have all the pr_* options/check inside kern_jail.c and have accessor functions for them passing td or cred.

Yes, this would be better, but I followed the pattern of the existing allow.vmm knob. I suspect it should be defined in kern_jail.c, not in vmm.ko, so that prison_priv_check() can access it. If there is some consensus on this I'll make that change.

Feb 4 2026, 6:30 PM

Jan 27 2026

jamie accepted D54833: kern: mac: add a prison_cleanup entry point.

Simple from the jail perspective, not delving into the MAC part ;-)

Jan 27 2026, 6:32 PM

Jan 16 2026

jamie accepted D54737: RELNOTES: document the MAC/jail integration.
Jan 16 2026, 1:10 AM

Jan 15 2026

jamie accepted D54660: jexec: Add -e parameter to customize the environment.
Jan 15 2026, 12:18 AM · Jails

Jan 14 2026

jamie added inline comments to D54660: jexec: Add -e parameter to customize the environment.
Jan 14 2026, 6:45 PM · Jails
jamie added a comment to D54660: jexec: Add -e parameter to customize the environment.

Why does it matter that putenv(3) doesn't create a copy?

Jan 14 2026, 12:50 AM · Jails

Jan 6 2026

jamie accepted D53954: [RFC] kern: mac: add various jail MAC hooks.
Jan 6 2026, 5:46 PM

Dec 21 2025

jamie added inline comments to D53958: kern: add a mac.label jail parameter.
Dec 21 2025, 6:00 PM

Dec 17 2025

jamie accepted D54271: jail: Don't define malloc type M_PRISON_RACCT on !RACCT.
Dec 17 2025, 5:46 PM

Dec 3 2025

jamie added inline comments to D53958: kern: add a mac.label jail parameter.
Dec 3 2025, 8:57 PM

Dec 2 2025

jamie added inline comments to D53954: [RFC] kern: mac: add various jail MAC hooks.
Dec 2 2025, 5:07 PM
jamie added inline comments to D53953: kern: mac: add a MAC label to struct prison.
Dec 2 2025, 4:59 PM
jamie accepted D53960: libjail: extend struct handlers to included MAC labels.
Dec 2 2025, 4:29 AM
jamie accepted D53959: libjail: start refactoring struct ioctl support.

The original author should have done this in the first place ;-)

Dec 2 2025, 4:25 AM
jamie added inline comments to D53958: kern: add a mac.label jail parameter.
Dec 2 2025, 4:24 AM
jamie accepted D53956: mac_set_fd(3): add support for jail descriptors.
Dec 2 2025, 4:17 AM
jamie accepted D53955: jaildesc: add an accessor for the struct prison in a jaildesc.
Dec 2 2025, 4:16 AM
jamie added inline comments to D53954: [RFC] kern: mac: add various jail MAC hooks.
Dec 2 2025, 4:16 AM
jamie added inline comments to D53953: kern: mac: add a MAC label to struct prison.
Dec 2 2025, 4:15 AM

Nov 30 2025

jamie committed R9:d255e1a4d565: releases/15.0R/relnotes: note jail descriptors and kevent filters (authored by jamie).
releases/15.0R/relnotes: note jail descriptors and kevent filters
Nov 30 2025, 6:39 PM

Nov 7 2025

jamie accepted D53631: jail.8: Add creating a jail from distribution set.
Nov 7 2025, 5:38 PM

Nov 6 2025

jamie accepted D53612: kern_jail_set(): do not double-free opts.

While I prefer the version I mentioned in the inline notes (it's a little less branchy), I'm also fine with the patch as originally given.

Nov 6 2025, 5:20 PM

Oct 24 2025

jamie committed rGc6bf733736b5: jail: fix an error condition that was returned without setting errno. (authored by jamie).
jail: fix an error condition that was returned without setting errno.
Oct 24 2025, 1:12 AM