[Bug 296521] bin/pfctl: pf's netlink conversion blocks non-VNET jails from using pfctl (no allow.pf / RTNL_F_ALLOW_NONVNET_JAIL equivalent)

[email protected] Sun, 05 Jul 2026 10:12:10 +0000
Newsgroups gmane.os.freebsd.devel.pf4freebsd
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D296521

Marek Zarychta <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #2 from Marek Zarychta <[email protected]> ---
Perhaps this behaviour should be discussed on the freebsd-net@ mailing list.

Currently, non-VNET jails can be permitted to manipulate routing tables via=
 the
security.jail.param.allow.routing setting. If modifying the FIB is consider=
ed
acceptable in a non-VNET jail under controlled circumstances, then perhaps
firewall management should be governed by a similar dedicated permission or
sysctl knob, rather than being treated as an all-or-nothing capability.

At the very least, it would be useful to clarify whether the current behavi=
our
is an intentional policy decision or an unintended regression.

--=20
You are receiving this mail because:
You are the assignee for the bug.=