HomeFreeBSD

devfs.rules: unhide pf in vnet jails

Description

devfs.rules: unhide pf in vnet jails

/dev/pf is usable in vnet jails, so don't hide the node there.

We shouldn't expose /dev/pf in regular jails, as that gives them control over
the host (or parent vnet jail) firewall.

Reviewed by: bz
Differential Revision: https://reviews.freebsd.org/D26537

Details

Provenance
kpAuthored on Oct 5 2020, 7:26 PM
Parents
rG262270841959: Tweak arm64's cpu_fetch_syscall_args(). This should make it possible
Branches
Unknown
Tags
Unknown