git: e608f0713da4 - stable/13 - jail.8: Update the allow.nfsd section

From: Rick Macklem <>
Date: Mon, 22 May 2023 18:28:35 UTC
The branch stable/13 has been updated by rmacklem:


commit e608f0713da49a3ef30fd52b56bdb709fc00f77b
Author:     Rick Macklem <>
AuthorDate: 2023-03-14 22:28:02 +0000
Commit:     Rick Macklem <>
CommitDate: 2023-05-22 18:27:45 +0000

    jail.8: Update the allow.nfsd section
    This patch updates the information for "allow.nfsd"
    and adds configuration information.
    This is a content change.
    (cherry picked from commit c0f94fee0bdddcc07f216f9723544f78ace5155a)
 usr.sbin/jail/jail.8 | 54 ++++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 44 insertions(+), 10 deletions(-)

diff --git a/usr.sbin/jail/jail.8 b/usr.sbin/jail/jail.8
index c9d929b89d4a..909abfef2708 100644
--- a/usr.sbin/jail/jail.8
+++ b/usr.sbin/jail/jail.8
@@ -25,7 +25,7 @@
 .\" $FreeBSD$
-.Dd December 11, 2022
+.Dd March 12, 2023
 .Dt JAIL 8
@@ -586,17 +586,49 @@ memory subject to
 and resource limits.
 .It Va allow.nfsd
-.Xr mountd 8
+.Xr mountd 8 ,
+.Xr nfsd 8 ,
+.Xr nfsuserd 8 ,
+.Xr gssd 8
-.Xr nfsd 8
-daemons are permitted to run inside a vnet-enabled jail.
-The kernel must have been compiled with the
-.Sy VNET_NFSD option
+.Xr rpc.tlsservd 8
+daemons are permitted to run inside a properly configured vnet-enabled jail.
+The jail's root must be a file system mount point and
+.Va enforce_statfs
+must not be set to 0, so that
+.Xr mountd 8
+can export file systems visible within the jail.
+.Va enforce_statfs
+must be set to 1 if file systems mounted under the
+jail's file system need to be exported by
+.Xr mount 8 .
+For exporting only the jail's file system, a setting of 2
+is sufficient.
+If the kernel configuration does not include the
+.Pa nfsd.ko
+must be loaded outside of the jails.
+This is normally done by adding
+.Dq nfsd
+.Va kld_list
+in the
+.Xr rc.conf 5
+file outside of the jails.
+Similarily, if the
+.Xr gssd 8
+is to be run in a jail, either the kernel
+option needs to be specified or
+.Dq kgssapi
-.Sy NFSD option
-as well as the
-.Sy VIMAGE option
-for this to be available.
+.Dq kgssapi_krb5
+need to be in
+.Va kld_list
+in the
+.Xr rc.conf 5
+file outside of the jails.
 .It Va allow.reserved_ports
 The jail root may bind to ports lower than 1024.
 .It Va allow.unprivileged_proc_debug
@@ -1372,6 +1404,8 @@ environment of the first jail.
 .Xr jexec 8 ,
 .Xr jls 8 ,
 .Xr mount 8 ,
+.Xr mountd 8 ,
+.Xr nfsd 8 ,
 .Xr reboot 8 ,
 .Xr rpcbind 8 ,
 .Xr sendmail 8 ,