Jail limited user cannot access host mountpoint although jail root can

CyberLeo Kitsana cyberleo at cyberleo.net
Mon Mar 13 10:47:13 UTC 2017


On 03/10/2017 08:59 PM, DaLynX via freebsd-questions wrote:
> Hello,
> 
> I am trying to make my setup work with jails and got stuck in the
> following situation:
> 
> - Host is mounting a fuse filesystem (because I couldn't make it work directly inside the jail - although the /dev/fuse device was accessible) in the jail's chroot.
> - From root at host, everything looks fine.
> - root at jail, too, can access the mounted filesystem, read files, no problem.
> - limited at jail can see the mountpoints but cannot access them in any way (no cd, no ls...) although the file permissions look okay (it's all 755, and for some reason limited is the owner of all mountpoints).
> 
> What could have gone wrong? I tried playing around with
> vfs.usermount on the host or enforce_statfs on the jail but it
> makes no difference.
> 
> Any pointers would be greatly appreciated.

Fuse filesystems include an additional security measure by default
whereby only the uid of the mounter is permitted to access the
mountpoint; even root is forbidden from accessing non-root fuse mounts.

Read up on the allow_other fuse mount option for further details.

-- 
Fuzzy love,
-CyberLeo

<CyberLeo at CyberLeo.Net>
Technical Administrator

CyberLeo.Net Webhosting
http://www.CyberLeo.Net

Element9 Communications
http://www.Element9.net


Furry Peace! - http://www.fur.com/peace/


More information about the freebsd-questions mailing list