git: af488533df80 - stable/15 - ctl.4: Document the assumption that CTL HA runs only on trusted networks

Mark Johnston <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.src
Message-ID <6a82fa2a.3ca91.6374857c__34917.7405166969$1786968708$gmane$org@gitrepo.freebsd.org>
The branch stable/15 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=af488533df8075a4d231773edf8db715f03ab2bf

commit af488533df8075a4d231773edf8db715f03ab2bf
Author:     Mark Johnston <[email protected]>
AuthorDate: 2026-08-04 13:42:53 +0000
Commit:     Mark Johnston <[email protected]>
CommitDate: 2026-08-17 12:07:41 +0000

    ctl.4: Document the assumption that CTL HA runs only on trusted networks
    
    The CTL High Availablity clustering feature allows a pair of hosts to
    implement transparent failover.  The implementation uses a TCP
    connection to exchange messages.  There is no authentication mechanism
    and the protocol itself embeds kernel pointers in the messages exchanged
    between HA hosts.  This property (of CTL_MSG_DATAMOVE messages
    specifically), as well as insufficient validation of inbound messages,
    mean that anyone able to access a CTL HA port is able to remotely
    execute code on that host.
    
    Provide a warning to this effect in the CTL man page.
    
    Reported by:    Ryan of Calif.io
    Reviewed by:    ziaee, ken, mav
    MFC after:      3 days
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D58622
    
    (cherry picked from commit 3c8f8432b6f653128016c6aaf826e1efb7ee1cec)
---
 share/man/man4/ctl.4 | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/share/man/man4/ctl.4 b/share/man/man4/ctl.4
index cac9e616f9db..904f0d672b83 100644
--- a/share/man/man4/ctl.4
+++ b/share/man/man4/ctl.4
@@ -22,7 +22,7 @@
 .\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 .\" SUCH DAMAGE.
-.Dd March 29, 2017
+.Dd August 4, 2026
 .Dt CTL 4
 .Os
 .Sh NAME
@@ -163,6 +163,11 @@ Defaults to 0.
 .It Va kern.cam.ctl.ha_peer
 String value, specifying method to establish connection to peer HA node.
 Can be "listen IP:port", "connect IP:port" or empty.
+.Pp
+.Sy NOTE:
+HA must be configured only on trusted networks: there is no authentication
+mechanism built in to the implementation, and the HA protocol effectively
+permits remote code execution on the peer node.
 .It Va kern.cam.ctl.ha_link
 Reports present state of connection between HA cluster nodes:
 .Bl -tag -offset indent -compact
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.