[Bug 296521] bin/pfctl: pf's netlink conversion blocks non-VNET jails from using pfctl (no allow.pf / RTNL_F_ALLOW_NONVNET_JAIL equivalent)
[email protected] Sun, 05 Jul 2026 10:12:10 +0000
| Newsgroups | gmane.os.freebsd.devel.pf4freebsd |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D296521 Marek Zarychta <[email protected]> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |[email protected] --- Comment #2 from Marek Zarychta <[email protected]> --- Perhaps this behaviour should be discussed on the freebsd-net@ mailing list. Currently, non-VNET jails can be permitted to manipulate routing tables via= the security.jail.param.allow.routing setting. If modifying the FIB is consider= ed acceptable in a non-VNET jail under controlled circumstances, then perhaps firewall management should be governed by a similar dedicated permission or sysctl knob, rather than being treated as an all-or-nothing capability. At the very least, it would be useful to clarify whether the current behavi= our is an intentional policy decision or an unintended regression. --=20 You are receiving this mail because: You are the assignee for the bug.=