git: 3c8f8432b6f6 - main - ctl.4: Document the assumption that CTL HA runs only on trusted networks

Mark Johnston <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.src,gmane.os.freebsd.current.scm
Message-ID <[email protected]>
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=3c8f8432b6f653128016c6aaf826e1efb7ee1cec

commit 3c8f8432b6f653128016c6aaf826e1efb7ee1cec
Author:     Mark Johnston <[email protected]>
AuthorDate: 2026-08-04 13:42:53 +0000
Commit:     Mark Johnston <[email protected]>
CommitDate: 2026-08-05 13:09:08 +0000

    ctl.4: Document the assumption that CTL HA runs only on trusted networks
    
    The CTL High Availablity clustering feature allows a pair of hosts to
    implement transparent failover.  The implementation uses a TCP
    connection to exchange messages.  There is no authentication mechanism
    and the protocol itself embeds kernel pointers in the messages exchanged
    between HA hosts.  This property (of CTL_MSG_DATAMOVE messages
    specifically), as well as insufficient validation of inbound messages,
    mean that anyone able to access a CTL HA port is able to remotely
    execute code on that host.
    
    Provide a warning to this effect in the CTL man page.
    
    Reported by:    Ryan of Calif.io
    Reviewed by:    ziaee, ken, mav
    MFC after:      3 days
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D58622
---
 share/man/man4/ctl.4 | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/share/man/man4/ctl.4 b/share/man/man4/ctl.4
index cac9e616f9db..904f0d672b83 100644
--- a/share/man/man4/ctl.4
+++ b/share/man/man4/ctl.4
@@ -22,7 +22,7 @@
 .\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 .\" SUCH DAMAGE.
-.Dd March 29, 2017
+.Dd August 4, 2026
 .Dt CTL 4
 .Os
 .Sh NAME
@@ -163,6 +163,11 @@ Defaults to 0.
 .It Va kern.cam.ctl.ha_peer
 String value, specifying method to establish connection to peer HA node.
 Can be "listen IP:port", "connect IP:port" or empty.
+.Pp
+.Sy NOTE:
+HA must be configured only on trusted networks: there is no authentication
+mechanism built in to the implementation, and the HA protocol effectively
+permits remote code execution on the peer node.
 .It Va kern.cam.ctl.ha_link
 Reports present state of connection between HA cluster nodes:
 .Bl -tag -offset indent -compact
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.