Page MenuHomeFreeBSD

oshogbo (Mariusz Zaborski)
User

Projects

User Details

User Since
Aug 19 2014, 3:56 PM (334 w, 2 d)

Recent Activity

Tue, Jan 12

oshogbo committed R10:d2ceee38ca26: casper: convert macros to inline functions (authored by oshogbo).
casper: convert macros to inline functions
Tue, Jan 12, 6:41 PM

Sun, Jan 10

oshogbo requested review of D28083: cat: capsicumize it.
Sun, Jan 10, 11:53 AM
oshogbo committed R10:dcdad299479e: fileargs: add support for realpath (authored by oshogbo).
fileargs: add support for realpath
Sun, Jan 10, 11:44 AM

Sat, Jan 9

oshogbo committed R10:faaf43b2a750: fileargs: add tests (authored by oshogbo).
fileargs: add tests
Sat, Jan 9, 8:57 PM

Mon, Jan 4

oshogbo committed R10:459511895e48: cap_sysctl: expose structures and variables (authored by oshogbo).
cap_sysctl: expose structures and variables
Mon, Jan 4, 7:58 PM
oshogbo committed R10:8c121177f063: casper: convert macros to inline functions (authored by oshogbo).
casper: convert macros to inline functions
Mon, Jan 4, 7:58 PM
oshogbo committed R10:381073282961: lib9p: fix building on systems without capser (authored by oshogbo).
lib9p: fix building on systems without capser
Mon, Jan 4, 7:58 PM

Sun, Jan 3

oshogbo committed R10:845b27372895: bhyve: fix build without casper/capsicum support (authored by oshogbo).
bhyve: fix build without casper/capsicum support
Sun, Jan 3, 5:20 PM
oshogbo committed R10:966026246e62: bhyve: fix build without casper/capsicum support (authored by oshogbo).
bhyve: fix build without casper/capsicum support
Sun, Jan 3, 4:22 PM
oshogbo committed R10:34535dace9f0: cap_net: CAPNET_CONNECT and CAPNET_CONNECTDNS are not mutually exclusive (authored by oshogbo).
cap_net: CAPNET_CONNECT and CAPNET_CONNECTDNS are not mutually exclusive
Sun, Jan 3, 4:12 PM
oshogbo committed R10:b7876aec957e: cap_net: allow to use the service without setting the limits (authored by oshogbo).
cap_net: allow to use the service without setting the limits
Sun, Jan 3, 4:10 PM
oshogbo committed R10:4084669d1867: capser: add cap_net to the list of services (authored by oshogbo).
capser: add cap_net to the list of services
Sun, Jan 3, 4:01 PM

Nov 18 2020

oshogbo added a reviewer for D27161: growfs: use sysexits in place of err/errc/errx(1): oshogbo.

What was motivation for this? Do you have any use case for that?

Nov 18 2020, 10:36 PM
oshogbo committed rD54692: Update my PGP key..
Update my PGP key.
Nov 18 2020, 10:10 PM
oshogbo committed rS367820: Add CTLFLAG_MPSAFE to the suser_enabled sysctl..
Add CTLFLAG_MPSAFE to the suser_enabled sysctl.
Nov 18 2020, 9:26 PM
oshogbo added inline comments to D24832: libcasper: Create a minimal cap_netdb service.
Nov 18 2020, 9:15 PM · capsicum
oshogbo added inline comments to D26958: sockstat: Use libcasper to capsicumize.
Nov 18 2020, 9:10 PM
oshogbo closed D27128: jail: introduce per jail suser_enabled setting.
Nov 18 2020, 9:07 PM
oshogbo committed rS367819: jail: introduce per jail suser_enabled setting.
jail: introduce per jail suser_enabled setting
Nov 18 2020, 9:07 PM
oshogbo added a comment to D27128: jail: introduce per jail suser_enabled setting.

me_igalic.co I will created for this separated review.

Nov 18 2020, 9:04 PM
oshogbo committed rS367818: Fix style nits..
Fix style nits.
Nov 18 2020, 9:00 PM

Nov 13 2020

oshogbo updated the diff for D27128: jail: introduce per jail suser_enabled setting.

Changes after markj@ and jamie@ review.

Nov 13 2020, 9:08 PM
oshogbo added inline comments to D27128: jail: introduce per jail suser_enabled setting.
Nov 13 2020, 4:15 PM
oshogbo updated the diff for D27128: jail: introduce per jail suser_enabled setting.
Nov 13 2020, 4:14 PM

Nov 12 2020

oshogbo updated the diff for D27128: jail: introduce per jail suser_enabled setting.
Nov 12 2020, 6:24 PM

Nov 9 2020

oshogbo added a comment to D27128: jail: introduce per jail suser_enabled setting.

Gotcha, thank you I will refactor the code.

Nov 9 2020, 9:24 PM
oshogbo added a comment to D27128: jail: introduce per jail suser_enabled setting.

If I understand correctly - the allow.* and the suser has a reverted values. You can disable suser, which by default is enabled. I wanted to made it exactly the same as sysctl on the hosts system, but I don't have strong opinion here.
I'm not sure if I understand. Do you suggest to have allow.suser which allow you to change the suser sysctl?
There should be no possibility to get back the suser priviliged inside the jail.
In the scenario I tested you can give/retrieve the suser from the host.

The semantics of an allow.* bit (at least of one included in JAIL_DEFAULT_ALLOW) are exactly the same as you used in the suser_enabled parameter: enabled by default when a top-level jail is created, set to the parent jail's value by default when child jail is created, and cleared in all child jails whenever it's cleared in an existing parent jail. OK, not exactly - your loop to set the child jails will re-add the bit to children if re-added to a parent jail, which is against the general rule of restrictions cascading while easing those restrictions do not.

When I was talking about getting the suser privilege back, it was in the context of having separate parallel host-imposed and jail-controlled bits, both of which must be enabled to work. But that's clearly a dead end - especially now that I consider that the sysctl to revert security.bsd.suser_enabled is unavailable to a suser-disabled system.

Nov 9 2020, 9:14 PM
oshogbo added a comment to D27128: jail: introduce per jail suser_enabled setting.

@kevans Thank you for the review. :) I fixed the typo.
@emaste Sorry, fixed.
@jamie
If I understand correctly - the allow.* and the suser has a reverted values. You can disable suser, which by default is enabled. I wanted to made it exactly the same as sysctl on the hosts system, but I don't have strong opinion here.
I'm not sure if I understand. Do you suggest to have allow.suser which allow you to change the suser sysctl?
There should be no possibility to get back the suser priviliged inside the jail.
In the scenario I tested you can give/retrieve the suser from the host.

Nov 9 2020, 7:46 PM
oshogbo updated the diff for D27128: jail: introduce per jail suser_enabled setting.
Nov 9 2020, 7:39 PM
oshogbo added a reviewer for D27128: jail: introduce per jail suser_enabled setting: jamie.
Nov 9 2020, 1:14 PM

Nov 8 2020

oshogbo committed rS367487: Check if the ZVOL has been written before calling zil_async_to_sync..
Check if the ZVOL has been written before calling zil_async_to_sync.
Nov 8 2020, 2:49 PM

Nov 7 2020

oshogbo abandoned D12945: Introduce phys2disk..
Nov 7 2020, 1:08 AM
oshogbo retitled D27128: jail: introduce per jail suser_enabled setting from jail2: introduce per jail suser_enabled setting to jail: introduce per jail suser_enabled setting.
Nov 7 2020, 1:08 AM

Nov 6 2020

oshogbo requested review of D27128: jail: introduce per jail suser_enabled setting.
Nov 6 2020, 6:23 PM

Nov 4 2020

oshogbo abandoned D27078: Initialize ZILog for ZVOLs.

I created ZFS pull request: https://github.com/openzfs/zfs/pull/11152

Nov 4 2020, 6:59 PM

Nov 3 2020

oshogbo requested review of D27078: Initialize ZILog for ZVOLs.
Nov 3 2020, 6:00 PM

Oct 26 2020

oshogbo added a comment to D24832: libcasper: Create a minimal cap_netdb service.

I would prefer to commit this version. Sorry for me not responding for a while.

Oct 26 2020, 2:56 PM · capsicum
oshogbo added a comment to D26956: libcasper/services/cap_net: Add cap_getprotobyname.

The whole limit infrastructure is missing for capnet,
I think I prefer the cap_netdb for those purpose.
If I recall it we had a few ideas what to add to netdb.

Oct 26 2020, 2:52 PM

Oct 19 2020

oshogbo added a comment to D24327: Add new casper execution service.

From my understanding, doing work in the user interface functions is the same as doing work in user program, as they are the same process. It won't be allowed if program is in cap mode.

Thats right, cap_exec_init, cap_exec_open, cap_exec_close are done potentialy in the sandboxed process.

Oct 19 2020, 5:20 PM · capsicum
oshogbo added inline comments to D24327: Add new casper execution service.
Oct 19 2020, 5:13 PM · capsicum
oshogbo added a comment to D24327: Add new casper execution service.

I was mistaken we need service like this, we just need to work a little bit more on it.

Oct 19 2020, 5:12 PM · capsicum
oshogbo added a comment to D24327: Add new casper execution service.

Ou but I guess you wan't your new process not being in sandbox, right?

Oct 19 2020, 4:25 PM · capsicum
oshogbo added a comment to D24327: Add new casper execution service.

Please don't take this an a criticisms I just would like to know the advantages of this approach.

Oct 19 2020, 4:24 PM · capsicum
oshogbo added a comment to D24327: Add new casper execution service.

I wonder we can't just use fileargs and fexecve?

Oct 19 2020, 3:56 PM · capsicum

Sep 28 2020

oshogbo added inline comments to D26546: bspatch: enter capability mode after dropping fd rights.
Sep 28 2020, 7:40 AM

Sep 6 2020

oshogbo committed rS365382: Remove duplicated line..
Remove duplicated line.
Sep 6 2020, 3:44 PM
oshogbo added inline comments to D26236: Capsicumize file(1).
Sep 6 2020, 2:14 PM · capsicum
oshogbo added inline comments to D25905: Capsicumize fsck_msdosfs.
Sep 6 2020, 2:11 PM · capsicum
oshogbo added inline comments to D25917: Capsicumize fsdb.
Sep 6 2020, 2:10 PM · capsicum
oshogbo added inline comments to D26094: Capsicumize fsck_ffs.
Sep 6 2020, 2:09 PM · capsicum
oshogbo closed D25604: Capsicumize traceroute6.
Sep 6 2020, 2:04 PM · capsicum
oshogbo committed rS365378: traceroute6: capsicumize it.
traceroute6: capsicumize it
Sep 6 2020, 2:04 PM

Aug 18 2020

oshogbo committed rS364355: zfs: add an option to the bootloader to rewind the ZFS checkpoint.
zfs: add an option to the bootloader to rewind the ZFS checkpoint
Aug 18 2020, 7:48 PM
oshogbo closed D24920: zfs: add to bootloader option to rewind the ZFS checkpoint..
Aug 18 2020, 7:48 PM

Aug 16 2020

oshogbo committed rS364276: libcasper: Introduce cap_net a network service for Casper..
libcasper: Introduce cap_net a network service for Casper.
Aug 16 2020, 6:12 PM
oshogbo closed D24688: Introduce cap_net a network service for Casper..
Aug 16 2020, 6:12 PM

Aug 3 2020

oshogbo added inline comments to D25917: Capsicumize fsdb.
Aug 3 2020, 9:24 AM · capsicum
oshogbo added inline comments to D25905: Capsicumize fsck_msdosfs.
Aug 3 2020, 9:23 AM · capsicum
oshogbo added inline comments to D25917: Capsicumize fsdb.
Aug 3 2020, 9:01 AM · capsicum
oshogbo added inline comments to D25604: Capsicumize traceroute6.
Aug 3 2020, 9:00 AM · capsicum

Jul 27 2020

oshogbo added inline comments to D25604: Capsicumize traceroute6.
Jul 27 2020, 12:09 PM · capsicum

Jul 20 2020

oshogbo added inline comments to D25604: Capsicumize traceroute6.
Jul 20 2020, 7:38 AM · capsicum

Jul 10 2020

oshogbo added inline comments to D25604: Capsicumize traceroute6.
Jul 10 2020, 7:50 AM · capsicum
oshogbo added inline comments to D25604: Capsicumize traceroute6.
Jul 10 2020, 7:50 AM · capsicum

Jul 5 2020

oshogbo added inline comments to D24688: Introduce cap_net a network service for Casper..
Jul 5 2020, 10:22 AM
oshogbo updated the diff for D24688: Introduce cap_net a network service for Casper..

Update after emaste, markj and bcr review.

Jul 5 2020, 10:22 AM

Jun 9 2020

oshogbo added a comment to D24688: Introduce cap_net a network service for Casper..

Oh sorry @emaste I some how didn't get the emails from your comments. I will address them ASAP.

Jun 9 2020, 3:21 PM

Jun 1 2020

oshogbo accepted D25095: cap_fileargs: Fix a descriptor leak in the service process..
Jun 1 2020, 3:11 PM

May 21 2020

oshogbo added a comment to D24920: zfs: add to bootloader option to rewind the ZFS checkpoint..

In general, it seems nice. I'd like to see more for description; how the checkpoints would appear, what it means to the boot process, would it mean updates for some manual/handbook? It would nice to refer to zpool, not all people do know where to look for information.

May 21 2020, 3:55 PM

May 20 2020

oshogbo updated the diff for D24920: zfs: add to bootloader option to rewind the ZFS checkpoint..

Typo pointed by @kevans. Thanks!

May 20 2020, 6:22 PM

May 19 2020

oshogbo added a reviewer for D24920: zfs: add to bootloader option to rewind the ZFS checkpoint.: allanjude.
May 19 2020, 5:09 PM
oshogbo requested review of D24920: zfs: add to bootloader option to rewind the ZFS checkpoint..
May 19 2020, 5:08 PM

May 11 2020

oshogbo added a comment to D24688: Introduce cap_net a network service for Casper..

Thank you @bcr and @greg_unrelenting.technology

May 11 2020, 8:28 PM
oshogbo updated the diff for D24688: Introduce cap_net a network service for Casper..

Man pages fixes.

May 11 2020, 8:27 PM

May 5 2020

oshogbo added a reviewer for D24688: Introduce cap_net a network service for Casper.: bcr.
May 5 2020, 8:46 AM

May 4 2020

oshogbo added reviewers for D24688: Introduce cap_net a network service for Casper.: emaste, markj.
May 4 2020, 7:22 PM
oshogbo requested review of D24688: Introduce cap_net a network service for Casper..
May 4 2020, 7:21 PM

Apr 11 2020

oshogbo committed rS359808: zfs: Add option for forcible unmounting dataset while receiving snapshot..
zfs: Add option for forcible unmounting dataset while receiving snapshot.
Apr 11 2020, 5:55 PM
oshogbo closed D22306: zfs: add option for forcible unmounting dataset while receiving snapshot..
Apr 11 2020, 5:54 PM
oshogbo committed rS359807: decryptcore: load the nls data.
decryptcore: load the nls data
Apr 11 2020, 5:30 PM

Apr 8 2020

oshogbo committed rS359730: logger: temporarily disable Capsicum when a host is provided.
logger: temporarily disable Capsicum when a host is provided
Apr 8 2020, 6:43 PM

Apr 7 2020

oshogbo accepted D24323: casper: Export functions to C++.
Apr 7 2020, 3:39 PM

Mar 12 2020

oshogbo closed D23744: Added casper service to logger.
Mar 12 2020, 7:56 PM
oshogbo committed rS358919: logger: capsicumize.
logger: capsicumize
Mar 12 2020, 7:56 PM

Mar 11 2020

oshogbo accepted D23744: Added casper service to logger.

If you want I can commit this for you.

Mar 11 2020, 2:18 PM

Feb 19 2020

oshogbo added a comment to D23744: Added casper service to logger.

Some more notes.

Feb 19 2020, 4:02 PM
oshogbo added inline comments to D23744: Added casper service to logger.
Feb 19 2020, 3:55 PM

Feb 7 2020

oshogbo accepted D23387: geli taste: allow GELIBOOT tagged providers as well.

Oh sorry I miss read the patch.
Then this looks good to me :)

Feb 7 2020, 7:58 PM
oshogbo added a comment to D23387: geli taste: allow GELIBOOT tagged providers as well.

This doesn't break multiple encrypted disks?
If I have 3 disk and only one should be decrypted by the loader?

Feb 7 2020, 7:29 PM

Feb 5 2020

oshogbo committed rS357604: MFCr356928:.
MFCr356928:
Feb 5 2020, 9:17 PM
oshogbo committed rS357603: MFCr356926:.
MFCr356926:
Feb 5 2020, 9:16 PM
oshogbo committed rS357602: MFCr356925:.
MFCr356925:
Feb 5 2020, 9:14 PM
oshogbo committed rS357601: MFCr356928:.
MFCr356928:
Feb 5 2020, 9:12 PM
oshogbo committed rS357600: MFCr356926:.
MFCr356926:
Feb 5 2020, 9:11 PM
oshogbo committed rS357599: MFCr356925:.
MFCr356925:
Feb 5 2020, 9:06 PM

Jan 20 2020

oshogbo committed rS356928: When MK_CASPER=no is set remove files which are not needed to run system..
When MK_CASPER=no is set remove files which are not needed to run system.
Jan 20 2020, 7:56 PM
oshogbo committed rS356926: Even when the MK_CASPER is set to "no" we still want to install man pages.
Even when the MK_CASPER is set to "no" we still want to install man pages
Jan 20 2020, 7:52 PM
oshogbo committed rS356925: Those files are already removed in ObsoleteFiles.\.
Those files are already removed in ObsoleteFiles.\
Jan 20 2020, 7:48 PM

Jan 6 2020

oshogbo added a comment to D22306: zfs: add option for forcible unmounting dataset while receiving snapshot..

Like Matt suggested I checked the behavior on Linux as well.

Jan 6 2020, 1:27 PM

Jan 3 2020

oshogbo added a comment to D23022: inetd: a light introduction to capsicum.

Thank you for working on this!
This doesn't seems like simple peace of code.

Jan 3 2020, 5:15 PM