Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 06 Mar 2014 09:14:52 +0100
From:      Matthias Meyser <meyser@xenet.de>
To:        freebsd-stable@freebsd.org
Subject:   Re: Re: jails and devfs
Message-ID:  <53182E7C.9030403@xenet.de>
In-Reply-To: <53172B3C.4020201@bytecamp.net>
References:  <53172A29.50202@xenet.de> <53172B3C.4020201@bytecamp.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi.
Am 05.03.2014 14:48, schrieb Robert Schulze:
> I've already filed a PR for that:
>
> http://www.freebsd.org/cgi/query-pr.cgi?pr=187079

Thanks! devfs_load_rulesets="YES" workaround did it.

But I think this should fixed asap or everyone updating
FreeBSD end up in running insecure jails.

At least there should be a big fat warning in UPDATING.

Better /etc/rc.d/jail should emit a warning.

Best devfs.rules should be loaded as needed.
This would restore the old behavior an not break POLA.

with regards
    Matthias Meyser

-- 
Matthias Meyser            | XeNET GmbH
Tel.:  +49-5323-9489050    | 38678 Clausthal-Zellerfeld, Marktstrasse 40
Fax:   +49-5323-94014      | Registergericht: Amtsgericht Braunschweig HRB 
110823
Email: Meyser@xenet.de     | Geschaeftsfuehrer: Matthias Meyser



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?53182E7C.9030403>