kern_jail.c

Clone Tools
  • last updated a few seconds ago
Constraints
Constraints: committers
 
Constraints: files
Constraints: dates
ethersubr: Make the mac address generation more robust

If we create two (vnet) jails and create a bridge interface in each we end up

with the same mac address on both bridge interfaces.

These very often conflicts, resulting in same mac address in both jails.

Mitigate this problem by including the jail name in the mac address.

  1. … 2 more files in changeset.
| kern_jail: missing \0 termination check on osrelease parameter | | If a user spplies a non-\0 terminated osrelease parameter reading it back | may disclose kernel memory. | This is a problem in case of nested jails (children.max > 0, which is not | the default). Otherwise root outside the jail has access to kernel memory | by other means and root inside a jail cannot create a child jail. | | Add the proper \0 check at the end of a supplied osrelease parameter and | make sure any copies of the field will be \0-terminated.

Sync with freebsd

  1. … 276 more files in changeset.
sync with freebsd 10-stable

  1. … 17 more files in changeset.
Refine the "nojail" rc keyword, adding "nojailvnet" for files that don't apply to most jails but do apply to vnet jails. This includes adding a new sysctl "security.jail.vnet" to identify vnet jails.

  1. … 4 more files in changeset.
mark malloc defines static that have no malloc declares.

  1. … 108 more files in changeset.
mark SYSCTL nodes static

  1. … 148 more files in changeset.
verify jail is up

Fix jail name checking that disallowed anything that starts with '0'. The intention was to just limit leading zeros on numeric names. That check is now imporved to allow catching the leading spaces and + that strtoul can pass through.

Obained from: FreeBSD rev 292277

sync with freebsd 9 stable.

  1. … 2449 more files in changeset.
Bring in several improvements from OpenSolaris for dtrace, zfs, etc.

Add kernel code for kernel lock manager for nfs, vfs and vm improvements and general compatibility with the recent network stack changes.

Bring in several improvements and bugfixes from FreeBSD 7.1

Tag $MidnightBSD$

  1. … 748 more files in changeset.
MPSAFE sysctl's

  1. … 1 more file in changeset.
Sync with freebsd

  1. … 148 more files in changeset.