From owner-freebsd-hackers@FreeBSD.ORG Wed Feb 23 16:28:29 2005 Return-Path: Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 01C4B16A4CE for ; Wed, 23 Feb 2005 16:28:29 +0000 (GMT) Received: from hydra.bec.de (www.ostsee-abc.de [62.206.222.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id A2B0343D46 for ; Wed, 23 Feb 2005 16:28:28 +0000 (GMT) (envelope-from joerg@britannica.bec.de) Received: from britannica.bec.de (unknown [139.30.252.67]) by hydra.bec.de (Postfix) with ESMTP id 98D9C35710 for ; Wed, 23 Feb 2005 17:28:26 +0100 (CET) Received: by britannica.bec.de (Postfix, from userid 1001) id 9F2A7A6; Wed, 23 Feb 2005 17:27:07 +0100 (CET) Date: Wed, 23 Feb 2005 17:27:07 +0100 From: Joerg Sonnenberger To: freebsd-hackers@freebsd.org Message-ID: <20050223162707.GA1113@britannica.bec.de> Mail-Followup-To: freebsd-hackers@freebsd.org References: <20050221221656.GA64212@freebsd.czest.pl> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20050221221656.GA64212@freebsd.czest.pl> User-Agent: Mutt/1.5.8i Subject: Re: [PATCH] Dangerous jail()<->ioctl interactions. X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Feb 2005 16:28:29 -0000 On Mon, Feb 21, 2005 at 10:16:56PM +0000, Wojciech A. Koszek wrote: > Hello hackers, > I would like to let you know I've been doing [partial] audit of ioctl() > code. There are some places, which may interest you. These are: > > sys/cam/cam_xpt.c > sys/contrib/ipfilter/netinet/ip_fil.c > sys/contrib/pf/net/pf_ioctl.c > sys/dev/ata/ata-all.c > sys/dev/md/md.c > sys/geom/geom_ctl.c I would argue that the controlling device are not supposed to be in a jail if you are concerned about something attacking your system with it. At least for FreeBSD 4, MAKEDEV jail doesn't create any of those. Joerg