From owner-freebsd-current@FreeBSD.ORG Mon Jun 28 07:11:20 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5A59216A4CE; Mon, 28 Jun 2004 07:11:20 +0000 (GMT) Received: from darkness.comp.waw.pl (darkness.comp.waw.pl [195.117.238.236]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0816C43D39; Mon, 28 Jun 2004 07:11:20 +0000 (GMT) (envelope-from pjd@darkness.comp.waw.pl) Received: by darkness.comp.waw.pl (Postfix, from userid 1009) id 64DF0ACBCF; Mon, 28 Jun 2004 09:11:18 +0200 (CEST) Date: Mon, 28 Jun 2004 09:11:18 +0200 From: Pawel Jakub Dawidek To: Julian Elischer Message-ID: <20040628071118.GQ12007@darkness.comp.waw.pl> References: <20040627101951.GJ12007@darkness.comp.waw.pl> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="TtkpuTP0dmHnYFts" Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.4.2i X-PGP-Key-URL: http://people.freebsd.org/~pjd/pjd.asc X-OS: FreeBSD 5.2.1-RC2 i386 cc: rwatson@freebsd.org cc: FreeBSD current users cc: bzeeb+freebsd@zabbadoz.net Subject: Re: jail getfsstat patches. X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 28 Jun 2004 07:11:20 -0000 --TtkpuTP0dmHnYFts Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Jun 27, 2004 at 11:40:48PM -0700, Julian Elischer wrote: +> > On Sun, Jun 27, 2004 at 08:59:32AM +0200, Pawel Jakub Dawidek wrote: +> > +> If you give me a few days (maybe I'll be ready today) I'll try to p= repare +> > +> patch to commit so we can review it together. +> >=20 +> > Ok, here it goes: +> >=20 +> > http://people.freebsd.org/~pjd/patches/jail_enforce_statfs.patch +> >=20 +> > As you can see, all mac_check_mount_stat() calls are placed after a +> > prison_canseemount() call, so we can considern moving mac_check_mount_= stat() +> > to prison_canseemount() function. +> >=20 +>=20 +> The patch looks good to me but I don't have a 5.x machine with jails at +> the moment (I may try set up a small jail tomorrow to test it). +>=20 +> do you have a 4.x version? I don't have 4.x boxes, so I can't prepare one for 4.x. Could you try to port it? It should be easy. --=20 Pawel Jakub Dawidek http://www.FreeBSD.org pjd@FreeBSD.org http://garage.freebsd.pl FreeBSD committer Am I Evil? Yes, I Am! --TtkpuTP0dmHnYFts Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQFA38SWForvXbEpPzQRAsDNAKCY/exV1jpKxlJdqBqOIWwdWrtsVgCbBYXP MnTFKaEgJ7TvqrWwkg3Eubo= =KncK -----END PGP SIGNATURE----- --TtkpuTP0dmHnYFts--