From nobody Tue Aug 27 16:07:34 2024 X-Original-To: freebsd-questions@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WtXWF2S5sz52P16 for ; Tue, 27 Aug 2024 16:07:37 +0000 (UTC) (envelope-from des@freebsd.org) Received: from smtp.freebsd.org (smtp.freebsd.org [IPv6:2610:1c1:1:606c::24b:4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WtXWF1dFSz4JlB; Tue, 27 Aug 2024 16:07:37 +0000 (UTC) (envelope-from des@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1724774857; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6gB6mGdRJYmNuMZbMzBdAQGPYTgQjuFqu68DJw5dNvI=; b=ESfayf1C1b8xyjd54O814cH+PgrHWkfP7n8HxfJvUGDJS+6LyUkDLzIdELmuGZCFF99DRk Ma1k/qd/GsMrZzdkkdprl8xxbeBOPUy420EMSGkItTyXjksy7H3cQli3gXuYDIr8CcDWqU 27Lg03YJ3Bc+OnshGjLhsiJbpCvQipnapYMCOxwo628UiG1bVXJRjewGxbz7EaHQYwDuSx aAy7tckFWEmvVVKnbDoPNofrRhs9o120CojU5Ij23j1Q5eDXjWYdslfyTKSIQfi7gvZKgr iLhLe7laTsZf7hGHi8hkKXQFv7dq1Rt4RMaB0rNNe5akP/XcmTojfhcdMnJljg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1724774857; a=rsa-sha256; cv=none; b=EjyfF0N97X0TBysHQ9O/dlrBkn/nh9sQ06RZVC1OsbCi3CFS+oO1nXI51BoM+39/BIT418 4nxx+OPAl/dhCz/+/XTBi7bpDa6IdMNqNqV4lHmcUBjQv7KNE1u1rznht1siHKrzTBvyya NCGGzwpT8JnojUtlbpx3d9xd7YvApTKrzeb3MpxsaTVlLyvAaHaIzGUPhUvz3EiZE+9kGY bhiDPsRbpI9x+ks4VOKDFsyq1nb9yhkU/qhejs+s1dpwBFJtBXbTxj6w+JPh+zRM3yCIDp r5rG7stOGU40jUXtyykyM8GoOEknzM9Lhf0D75gcNuZ8zcsHd7D0e1x24fNrqQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1724774857; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6gB6mGdRJYmNuMZbMzBdAQGPYTgQjuFqu68DJw5dNvI=; b=TtM6sXDVJEgs0+Owu00xXlj0PO3tOxD7lDSpOwoUlzsklKvewk8dWnA5fk6fqAWkX/qvCh O7A0Q7XMX+k6bYj8s/xP/ia989CPDt3UXIiBX5krlCvKadHA8Srb0c8W4RAPk4u9CW4w0j B6keLEDciLclCmQUmAae4x2PUzyLt3oPfnxKYeT+N+pl9ii0B2paohP4BOl71I8nt1AJx2 R7JwPMULaVm2iKYLOFK0WAf0twvaXX86Zlu4TrH18irK1J9rP+76r+2jOx06JC4sRcL0Qy DSBaDF+a+Keani0H4KbUoqeDlr8EJADCttMskIB+d8FkqL5rRMnLwlY86AFrXg== Received: from ltc.des.dev (unknown [91.174.26.112]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) (Authenticated sender: des) by smtp.freebsd.org (Postfix) with ESMTPSA id 4WtXWF0JG3zP78; Tue, 27 Aug 2024 16:07:37 +0000 (UTC) (envelope-from des@freebsd.org) Received: by ltc.des.dev (Postfix, from userid 1001) id E91638CD09; Tue, 27 Aug 2024 18:07:34 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: doug@safeport.com Cc: Andrea Venturoli , doug@fledge.watson.org, freebsd-questions@freebsd.org Subject: Re: security.bsd.see_other_uids/gids and jails In-Reply-To: (doug@safeport.com's message of "Sat, 24 Aug 2024 17:30:37 +0000 (UTC)") References: <902826c1-fc50-48aa-867d-8010b5814df2@netfence.it> <61ed9412-563-a5f-a3c0-66ff23cb5ac4@safeport.com> <0fe260da-43ff-4c14-9807-7b81cec37c83@netfence.it> User-Agent: Gnus/5.13 (Gnus v5.13) Date: Tue, 27 Aug 2024 18:07:34 +0200 Message-ID: <86jzg23q61.fsf@ltc.des.dev> List-Id: User questions List-Archive: https://lists.freebsd.org/archives/freebsd-questions List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-questions@freebsd.org Sender: owner-freebsd-questions@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable doug@safeport.com writes: > If you did this command as root, your system is seriously messed up. I > did this on a 12.2 system runing as 12.2 jail. This is neither relevant nor helpful. - 12.2 is four years old and no longer supported. - `security.bsd.see_other_uids` is not settable from within a jail and never was (it does not, and never did, have the `CTLFLAG_PRISON` flag), so if you successfully did this, it is _your_ system which is =E2=80=9Cseriously messed up=E2=80=9D. - None of this answers the original question, which was whether it can be changed on a per-jail basis, and the answer to that is no, it applies equally to all users, jailed or unjailed. Only nodes in the `security.jail.param` subtree can be changed per-jail. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@FreeBSD.org