From nobody Tue Aug 27 17:47:49 2024 X-Original-To: freebsd-questions@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4WtZkv6K3qz52XqZ for ; Tue, 27 Aug 2024 17:47:51 +0000 (UTC) (envelope-from des@freebsd.org) Received: from smtp.freebsd.org (smtp.freebsd.org [96.47.72.83]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4WtZkv3sjCz4WVx; Tue, 27 Aug 2024 17:47:51 +0000 (UTC) (envelope-from des@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1724780871; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Z+xCyt5RseQtDyXq301y6/tuaCydwFQK4n8ilh3YiuE=; b=I2ZfgivddDk2OD24RVEReu5MYpLusItxvjgXIQ4nTa6ZrZ2vUkFmMutg9G/DYr5sssFo2r PRkap2XE/2hJGkS53iHh6EHqVA1kpfMcqR6Nqkim8Jd3NDZmJlPr7AUd9JaWSpjOEuZU6s TW5+wyyyuHANswjg/ZOIvV36+2a8dCc0Nd228TpTXLdKUGitLH4EWvBAyvOd1LDtLh430e QzDf2y1KolQ0jT4yl1yhayAjjodwcfZHcuXVDx90fygMNFE2OwUsWqolYtyr3B8HyLcCu1 WWsvh4S0NnWUnSZ5fKm0LOYpVX7I4R4rrnZfaJX5BvUA/5+Q5Hz1RFQj314DyQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1724780871; a=rsa-sha256; cv=none; b=Y7o3mS87YXsNj/pSjReQjAxwiGywna0F2Y8JQVEbH4gmB1FIJZ2/b4NXuJkX9tnbI6RDvk OvAyHQNYVUz6Opo18zbTJCCC5dS8RIJN7Sb1z4x+uv777AxUcX9bLujXV8YRNmyTZrNDKS o9+zB0OhBXAqzdaKI61Vfakw7v4uhh2WZ/iVpx/TlLsRNKR4T9DMRfQMnS4nxbhvYz50UO zyPtOE28afMRvp/WVJhC/4nv3tXfJRuExi5eCH64MN0mA1Fjc2+nIPdTnNVqSGpmjj9axH KpLeOs+FuJswGgJ2gYk/MMf0WkmUNw8PN2uN1BuPjZdwqShho6OJf4Ro4mK9ww== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1724780871; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Z+xCyt5RseQtDyXq301y6/tuaCydwFQK4n8ilh3YiuE=; b=af9urb2J8g4BKX2CapD2tHQF9LHoxnvLgCbseSc5P16hVP/P5A+Yj5d+ddZqTXaDJaw2AG bAd4kTECixVI6uYDQjCBWsLZwszjeyI7JsSiObGdrYPIsJep2f53CC1aU9FPV9d8pD+fxP xk2VUfmFEZVvOmVoxoDCSa0amJZFBNKiIu+d8QAsE8lLzEX0b9PsD3aYgycNi+0guICHt+ JwzwNrlI63sw4YwJcjs/yqqLe5pGngv0DJA4V7YZoByl6CLyX6+jdME6A4lWat4s/5mHxL m+NU3SoliiYWLTCtX2cuAryHn8tmgQjduOFvkJxQpLRcdI3qc2FbElL+zUOIPQ== Received: from ltc.des.dev (unknown [IPv6:2a01:e0a:386:9c20:922e:16ff:fef1:acef]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) (Authenticated sender: des) by smtp.freebsd.org (Postfix) with ESMTPSA id 4WtZkv2n19zPlY; Tue, 27 Aug 2024 17:47:51 +0000 (UTC) (envelope-from des@freebsd.org) Received: by ltc.des.dev (Postfix, from userid 1001) id 302298CE81; Tue, 27 Aug 2024 19:47:49 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: doug@safeport.com Cc: doug@fledge.watson.org, Andrea Venturoli , freebsd-questions@freebsd.org Subject: Re: security.bsd.see_other_uids/gids and jails In-Reply-To: (doug@safeport.com's message of "Tue, 27 Aug 2024 17:14:32 +0000 (UTC)") References: <902826c1-fc50-48aa-867d-8010b5814df2@netfence.it> <61ed9412-563-a5f-a3c0-66ff23cb5ac4@safeport.com> <0fe260da-43ff-4c14-9807-7b81cec37c83@netfence.it> <86jzg23q61.fsf@ltc.des.dev> User-Agent: Gnus/5.13 (Gnus v5.13) Date: Tue, 27 Aug 2024 19:47:49 +0200 Message-ID: <861q29503e.fsf@ltc.des.dev> List-Id: User questions List-Archive: https://lists.freebsd.org/archives/freebsd-questions List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-questions@freebsd.org Sender: owner-freebsd-questions@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable doug@safeport.com writes: > Dag-Erling Sm=C3=B8rgrav writes: > > - `security.bsd.see_other_uids` is not settable from within a jail and > > never was (it does not, and never did, have the `CTLFLAG_PRISON` > > flag), so if you successfully did this, it is _your_ system which is > > =E2=80=9Cseriously messed up=E2=80=9D. > So a facility that worked in 12.2 was taken away in 14.1? Did you even read what I wrote? DES --=20 Dag-Erling Sm=C3=B8rgrav - des@FreeBSD.org