From owner-freebsd-current@FreeBSD.ORG Fri May 21 06:30:29 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B357B16A4CE; Fri, 21 May 2004 06:30:29 -0700 (PDT) Received: from transport.cksoft.de (transport.cksoft.de [62.111.66.27]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0474643D39; Fri, 21 May 2004 06:30:29 -0700 (PDT) (envelope-from bzeeb-lists@lists.zabbadoz.net) Received: from transport.cksoft.de (localhost [127.0.0.1]) by transport.cksoft.de (Postfix) with ESMTP id 5CF0C1FF903; Fri, 21 May 2004 15:30:08 +0200 (CEST) Received: by transport.cksoft.de (Postfix, from userid 66) id 87A691FFDD4; Fri, 21 May 2004 15:30:06 +0200 (CEST) Received: by mail.int.zabbadoz.net (Postfix, from userid 1060) id 30DFD154E5; Fri, 21 May 2004 13:24:55 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.int.zabbadoz.net (Postfix) with ESMTP id 25133154E2; Fri, 21 May 2004 13:24:56 +0000 (UTC) Date: Fri, 21 May 2004 13:24:56 +0000 (UTC) From: "Bjoern A. Zeeb" X-X-Sender: bz@e0-0.zab2.int.zabbadoz.net To: Ruslan Ermilov In-Reply-To: <20040521090217.GB57989@ip.net.ua> Message-ID: References: <20040520220145.GN4567@genius.tao.org.uk> <20040521081419.GB89262@cell.sick.ru> <20040521090217.GB57989@ip.net.ua> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Virus-Scanned: by AMaViS cksoft-s20020300-20031204bz on transport.cksoft.de cc: freebsd-current@freebsd.org Subject: Re: Call for a hacker.... security.bsd.see_other_uids in jails only X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 May 2004 13:30:29 -0000 On Fri, 21 May 2004, Ruslan Ermilov wrote: > > A more general solution will be better, but harder to implement: make > > some sysctl branches (e.g. security.bsd) local per jail, and possibility to > > change them only from host machine. > > > I like the idea of per-jail sysctl MIB trees, e.g.: > > jail..security.bsd jail ID is not too good; we would need s.th. that could be treated 'perstistent' between reboots. Perhaps not use sysctl at all ... -- Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT there is no 'do you really want to quit ?'-button in RL.