[PATCH] Force mountd(8) to a specified port.

Darren Reed avalon at caligula.anu.edu.au
Tue Mar 2 15:24:28 PST 2004


In some mail from Bruce M Simpson, sie said:
> Hi all,
> 
> I have a requirement to run NFS read-only in an Internet-facing colocation
> environment. I am not happy with packet filters alone around rpcbind, call
> me paranoid, so I just spent the last few minutes cutting this patch.
> 
> As you are aware, RPC applications can be forced to listen on a known port
> through the sin/sa argument to bindresvport[_sa](). Why several Linux
> distributions have this feature yet none of the BSDs do is beyond me...
> 
> Please let me know your thoughts. If there are no valid objections I plan
> to commit it.

I'm confused by your first paragraph...the primary purpose of a patch
like this would be, I imagine, to support being able to write filter
rules for your firewall with a specific port defined rather than have
to determine it after rpcbind & mountd have started.

Darren


More information about the freebsd-security mailing list