看板FB_security
標 題Re: Allowing tmpfs to be mounted in jail?
發信站NCTU CS FreeBSD Server (Fri Aug 23 23:43:50 2013)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On Fri, Aug 23, 2013 at 12:37:32AM +0300, Konstantin Belousov wrote:
> On Thu, Aug 22, 2013 at 12:15:29PM -0700, Xin Li wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA512
> >
> > Hi,
> >
> > Do anybody have concerns if I would commit this?
> >
> > Index: sys/fs/tmpfs/tmpfs_vfsops.c
> > ===================================================================
> > - --- sys/fs/tmpfs/tmpfs_vfsops.c (revision 254663)
> > +++ sys/fs/tmpfs/tmpfs_vfsops.c (working copy)
> > @@ -420,4 +420,4 @@ struct vfsops tmpfs_vfsops = {
> > .vfs_statfs = tmpfs_statfs,
> > .vfs_fhtovp = tmpfs_fhtovp,
> > };
> > - -VFS_SET(tmpfs_vfsops, tmpfs, 0);
> > +VFS_SET(tmpfs_vfsops, tmpfs, VFCF_JAIL);
> >
>
> Unrestricted tmpfs mounts can easily consume all available memory,
> making the host unusable. But the change is probably fine, since
> we have global 'disable mount from the jail' flag.
tmpfs in jail must use memory limit from rctl memoryuse, I think.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"