HomeFreeBSD

mac_ipacl: new MAC policy module to limit jail/vnet IP configuration

Description

mac_ipacl: new MAC policy module to limit jail/vnet IP configuration

The mac_ipacl policy module enables fine-grained control over IP address
configuration within VNET jails from the base system.
It allows the root user to define rules governing IP addresses for
jails and their interfaces using the sysctl interface.

Requested by: multiple
Sponsored by: Google, Inc. (GSoC 2019)
MFC after: 2 months
Reviewed by: bz, dch (both earlier versions)
Differential Revision: https://reviews.freebsd.org/D20967

Details

Provenance
shivankAuthored on Jul 25 2023, 8:27 PM
bzCommitted on Jul 26 2023, 12:07 AM
Reviewer
bz
Differential Revision
D20967: new MAC policy module - mac_ipacl
Parents
rGa1b675731301: arm64 lib32: enable building of lib32 on arm64
Branches
Unknown
Tags
Unknown