From owner-freebsd-current@FreeBSD.ORG Sat May 15 13:05:14 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3711F16A4CE; Sat, 15 May 2004 13:05:14 -0700 (PDT) Received: from fledge.watson.org (fledge.watson.org [204.156.12.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id B7E8A43D39; Sat, 15 May 2004 13:05:13 -0700 (PDT) (envelope-from robert@fledge.watson.org) Received: from fledge.watson.org (localhost [127.0.0.1]) by fledge.watson.org (8.12.11/8.12.11) with ESMTP id i4FK4UuC007451; Sat, 15 May 2004 16:04:30 -0400 (EDT) (envelope-from robert@fledge.watson.org) Received: from localhost (robert@localhost)i4FK4UbB007448; Sat, 15 May 2004 16:04:30 -0400 (EDT) (envelope-from robert@fledge.watson.org) Date: Sat, 15 May 2004 16:04:30 -0400 (EDT) From: Robert Watson X-Sender: robert@fledge.watson.org To: Pawel Jakub Dawidek In-Reply-To: <20040515200401.GB845@darkness.comp.waw.pl> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: Julian Elischer cc: FreeBSD current users Subject: Re: jail and chflags [patch] X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 15 May 2004 20:05:14 -0000 On Sat, 15 May 2004, Pawel Jakub Dawidek wrote: > +> +> comments? yeahs? neys? > +> > +> Whoa! This looks very serious. > > Ok, false alarm:) After discussion with rwatson@ and cperciva@, it looks > that changing those flags is permitted due to per-jail securelevels, > which were intruduced in 5.x. However, we might want to think about setting the securelevel in a jail to at least 1 on creation for compatibility reasons... Robert N M Watson FreeBSD Core Team, TrustedBSD Projects robert@fledge.watson.org Senior Research Scientist, McAfee Research