HomeFreeBSD

devfs.rules: unhide pf in vnet jails

Description

devfs.rules: unhide pf in vnet jails

/dev/pf is usable in vnet jails, so don't hide the node there.

We shouldn't expose /dev/pf in regular jails, as that gives them control over
the host (or parent vnet jail) firewall.

Reviewed by: bz
Differential Revision: https://reviews.freebsd.org/D26537

Details

Provenance
kpAuthored on
Reviewer
bz
Differential Revision
D26537: devfs.rules: unhide pf in vnet jails
Parents
rS366460: MFC r366247:
Branches
Unknown
Tags
Unknown