From owner-cvs-src@FreeBSD.ORG Sun Feb 15 08:21:53 2004 Return-Path: Delivered-To: cvs-src@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6070C16A4CF; Sun, 15 Feb 2004 08:21:53 -0800 (PST) Received: from milla.ask33.net (milla.ask33.net [217.197.166.60]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4E80B43D1D; Sun, 15 Feb 2004 08:21:51 -0800 (PST) (envelope-from nick@milla.ask33.net) Received: by milla.ask33.net (Postfix, from userid 1001) id 800B83ABB80; Sun, 15 Feb 2004 17:24:55 +0100 (CET) Date: Sun, 15 Feb 2004 17:24:55 +0100 From: Pawel Jakub Dawidek To: Robert Watson Message-ID: <20040215162455.GZ14639@garage.freebsd.pl> References: <200402141919.i1EJJmKY089610@repoman.freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="vMk55pD2JuhdWiRw" Content-Disposition: inline In-Reply-To: <200402141919.i1EJJmKY089610@repoman.freebsd.org> X-PGP-Key-URL: http://people.freebsd.org/~pjd/pjd.asc X-OS: FreeBSD 4.8-RELEASE-p13 i386 X-URL: http://garage.freebsd.pl User-Agent: Mutt/1.5.1i cc: cvs-src@FreeBSD.org cc: src-committers@FreeBSD.org cc: cvs-all@FreeBSD.org Subject: Re: cvs commit: src/sys/kern kern_jail.c X-BeenThere: cvs-src@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Feb 2004 16:21:53 -0000 --vMk55pD2JuhdWiRw Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Feb 14, 2004 at 11:19:48AM -0800, Robert Watson wrote: +> Commiter: Robert Watson +> Branch: HEAD +>=20 +> Files: +> 1.38 src/sys/kern/kern_jail.c =20 +>=20 +> Log: +> By default, don't allow processes in a jail to list the set of +> jails in the system. Previous behavior (allowed) may be restored +> by setting security.jail.list_allowed=3D1. Are you planning to leave this sysctl? IMHO the previous behaviour was just bad, this was a bug, and restoring this behaviour shouldn't be permitted. But if this sysctl is just a temporary solution and will be removed in the future, it is ok (but maybe BURN_BRIDGES should be added?). PS. This functionality is quite fresh, I'm not sure if someone started to depend on it... --=20 Pawel Jakub Dawidek http://www.FreeBSD.org pjd@FreeBSD.org http://garage.freebsd.pl FreeBSD committer Am I Evil? Yes, I Am! --vMk55pD2JuhdWiRw Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iD8DBQFAL51XForvXbEpPzQRAg8KAJkBHBzBeemFesTSMv6iwsXyz3JKXwCfSV31 8N1jJ4PkbSEAs9dy8VvKn84= =lAwr -----END PGP SIGNATURE----- --vMk55pD2JuhdWiRw--