[Bug 296521] bin/pfctl: pf's netlink conversion blocks non-VNET jails from using pfctl (no allow.pf / RTNL_F_ALLOW_NONVNET_JAIL equivalent)

[email protected] Sun, 05 Jul 2026 08:30:27 +0000
Newsgroups gmane.os.freebsd.devel.pf4freebsd
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D296521

Marek Zarychta <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected].
                   |                            |pl

--- Comment #1 from Marek Zarychta <[email protected]> ---
Is this an actual bug, or simply a stricter implementation?

For non-VNET jails, PF is expected to be managed from the host. As far as I
understand, that's the recommended and documented deployment model.

On the other hand, if this used to work, perhaps it should still be allowed=
 for
compatibility reasons.

What is the intended behaviour for the other firewalls? In particular, are =
IPFW
and IPF expected to be manageable from non-VNET jails, or are they managed
exclusively from the host?

--=20
You are receiving this mail because:
You are the assignee for the bug.=