Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 31 Jan 2014 22:30:11 +0100
From:      Alexander Leidinger <Alexander@Leidinger.net>
To:        Robert Watson <rwatson@FreeBSD.org>
Cc:        svn-src-head@freebsd.org, svn-src-all@freebsd.org, Gleb Smirnoff <glebius@FreeBSD.org>, src-committers@freebsd.org, James Gritton <jamie@freebsd.org>
Subject:   Re: svn commit: r261266 - in head: sys/dev/drm sys/kern sys/sys usr.sbin/jail
Message-ID:  <20140131223011.0000163b@unknown>
In-Reply-To: <alpine.BSF.2.00.1401311231490.36707@fledge.watson.org>
References:  <201401291341.s0TDfDcB068211@svn.freebsd.org> <20140129134344.GW66160@FreeBSD.org> <52E906CD.9050202@freebsd.org> <20140129222210.0000711f@unknown> <alpine.BSF.2.00.1401311231490.36707@fledge.watson.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 31 Jan 2014 12:34:48 +0000 (GMT)
Robert Watson <rwatson@FreeBSD.org> wrote:

> On Wed, 29 Jan 2014, Alexander Leidinger wrote:
> 
> >> It does.  I included a warning in jail.8 that this will pretty
> >> much undo jail security.  There are still reasons some may want to
> >> do this, but it's definitely not for everyone or even most people.
> >
> > It only "unjails" (= basically the same security level as the
> > jail-host with the added benefit of the flexibility of a jail like
> > easy moving from one system to another) the jail which has this
> > flag set. All other jails without the flag can not "escape" to the
> > host.
> >
> > I also have to add that just setting this flag does not give access
> > to the host, you also have to configure a non-default devfs rule
> > for this jail (to have the devices appear in the jail).
> 
> This is not correct: devices do not need to be delegated in devfs for
> PRIV_IO to allow bypass of the Jail security model, due to sysarch()
> and the Linux-emulated equivalent, which turn out direct I/O access
> from a user process without use of a device node.

Ok, then it is just the non-default flag, not the additional devfs part.

I agree with your other post that we are better of to document better
what it means if an admin allows kmem access for a specific jail.

Bye,
Alexander.

-- 
http://www.Leidinger.net    Alexander @ Leidinger.net: PGP ID = B0063FE7
http://www.FreeBSD.org       netchild @ FreeBSD.org  : PGP ID = 72077137



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20140131223011.0000163b>