From owner-cvs-all@FreeBSD.ORG Thu Jun 26 13:41:59 2003 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DC2A837B401; Thu, 26 Jun 2003 13:41:59 -0700 (PDT) Received: from out004.verizon.net (out004pub.verizon.net [206.46.170.142]) by mx1.FreeBSD.org (Postfix) with ESMTP id 79FE243FFD; Thu, 26 Jun 2003 13:41:58 -0700 (PDT) (envelope-from mtm@identd.net) Received: from kokeb.ambesa.net ([138.88.140.205]) by out004.verizon.net (InterMail vM.5.01.05.33 201-253-122-126-133-20030313) with ESMTP id <20030626204157.GTV246.out004.verizon.net@kokeb.ambesa.net>; Thu, 26 Jun 2003 15:41:57 -0500 Date: Thu, 26 Jun 2003 16:41:56 -0400 From: Mike Makonnen To: Robert Watson In-Reply-To: <200306261904.h5QJ4Fdm085354@repoman.freebsd.org> References: <200306261904.h5QJ4Fdm085354@repoman.freebsd.org> X-Mailer: Sylpheed version 0.8.10 (GTK+ 1.2.10; i386-portbld-freebsd5.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Authentication-Info: Submitted using SMTP AUTH at out004.verizon.net from [138.88.140.205] at Thu, 26 Jun 2003 15:41:57 -0500 Message-Id: <20030626204157.GTV246.out004.verizon.net@kokeb.ambesa.net> cc: cvs-src@freebsd.org cc: src-committers@freebsd.org cc: cvs-all@freebsd.org Subject: Re: cvs commit: src/usr.sbin/jail jail.8 X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 26 Jun 2003 20:42:00 -0000 On Thu, 26 Jun 2003 12:04:15 -0700 (PDT) Robert Watson wrote: > rwatson 2003/06/26 12:04:15 PDT > > FreeBSD src repository > > Modified files: > usr.sbin/jail jail.8 > Log: > When pointing users at mount_devfs to populate the /dev of a jail, > tell them that they also need to use devfs rules to prevent > inappropriate devices from appearing in the jail; add an Xref. In > earlier versions of this man page, the user was instructed to use > sh MAKEDEV jail, which only created a minimal set of device nodes. Just an FYI, I'm working on an rc.subr(8) routine (part of an extention to rc.d/jail I'm working on) that will mount and minimally populate a devfs partition. Users can then rely on a "standard" and safe way of doing this kind of thing. Cheers. -- Mike Makonnen | GPG-KEY: http://www.identd.net/~mtm/mtm.asc mtm@identd.net | D228 1A6F C64E 120A A1C9 A3AA DAE1 E2AF DBCC 68B9 mtm@FreeBSD.Org| FreeBSD - The Power To Serve