Date: Mon, 28 Jun 2004 09:11:18 +0200 From: Pawel Jakub Dawidek <pjd@FreeBSD.org> To: Julian Elischer <julian@elischer.org> Cc: bzeeb+freebsd@zabbadoz.net Subject: Re: jail getfsstat patches. Message-ID: <20040628071118.GQ12007@darkness.comp.waw.pl> In-Reply-To: <Pine.BSF.4.21.0406272339040.19712-100000@InterJet.elischer.org> References: <20040627101951.GJ12007@darkness.comp.waw.pl> <Pine.BSF.4.21.0406272339040.19712-100000@InterJet.elischer.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--TtkpuTP0dmHnYFts Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Jun 27, 2004 at 11:40:48PM -0700, Julian Elischer wrote: +> > On Sun, Jun 27, 2004 at 08:59:32AM +0200, Pawel Jakub Dawidek wrote: +> > +> If you give me a few days (maybe I'll be ready today) I'll try to p= repare +> > +> patch to commit so we can review it together. +> >=20 +> > Ok, here it goes: +> >=20 +> > http://people.freebsd.org/~pjd/patches/jail_enforce_statfs.patch +> >=20 +> > As you can see, all mac_check_mount_stat() calls are placed after a +> > prison_canseemount() call, so we can considern moving mac_check_mount_= stat() +> > to prison_canseemount() function. +> >=20 +>=20 +> The patch looks good to me but I don't have a 5.x machine with jails at +> the moment (I may try set up a small jail tomorrow to test it). +>=20 +> do you have a 4.x version? I don't have 4.x boxes, so I can't prepare one for 4.x. Could you try to port it? It should be easy. --=20 Pawel Jakub Dawidek http://www.FreeBSD.org pjd@FreeBSD.org http://garage.freebsd.pl FreeBSD committer Am I Evil? Yes, I Am! --TtkpuTP0dmHnYFts Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQFA38SWForvXbEpPzQRAsDNAKCY/exV1jpKxlJdqBqOIWwdWrtsVgCbBYXP MnTFKaEgJ7TvqrWwkg3Eubo= =KncK -----END PGP SIGNATURE----- --TtkpuTP0dmHnYFts--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040628071118.GQ12007>