From owner-freebsd-fs@FreeBSD.ORG Wed Mar 28 20:26:28 2012 Return-Path: Delivered-To: freebsd-fs@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id A54E21065670 for ; Wed, 28 Mar 2012 20:26:28 +0000 (UTC) (envelope-from phillip.nordwall@gmail.com) Received: from mail-ob0-f182.google.com (mail-ob0-f182.google.com [209.85.214.182]) by mx1.freebsd.org (Postfix) with ESMTP id 5DA638FC17 for ; Wed, 28 Mar 2012 20:26:28 +0000 (UTC) Received: by obbuo13 with SMTP id uo13so2358565obb.13 for ; Wed, 28 Mar 2012 13:26:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=mMLg97R3tIZE1AuU7rCwOIT1kolEDmPB6rs4awsNpA8=; b=jOPRK8mkAqvKPjkSJs7cxsYYi5fXWKUrof47oldbNFIo3BXelgh9N5vhzsFyJdKnOe 0pkRfMvC0CYR0g9zWoMwNh6+7CfsIe3ZDC8+yI7lXqExXRottpJfVv7BPc9mF6yVDDGt dy+EddQdsu17wVhjSQjXRarJskpC5M6xUpW/0G0DVLMMMRQuncLo0BGfmPHYUE8DPSwz EiPAqzaj45dxyn+XGCPKXI8zCwJhF0nJ6hg2naTfRb3Dr6DngmfmKCD3BY+s+zh2vdFH aVWZ7dmfxF/BbcKEBYIXHJEXM2JCAsnJQvK8d/lkVpLetpFGbUcRDGJM92ZIA4J/VDtd 4wPw== MIME-Version: 1.0 Received: by 10.182.127.20 with SMTP id nc20mr39495574obb.66.1332966387482; Wed, 28 Mar 2012 13:26:27 -0700 (PDT) Sender: phillip.nordwall@gmail.com Received: by 10.182.43.225 with HTTP; Wed, 28 Mar 2012 13:26:27 -0700 (PDT) In-Reply-To: References: Date: Wed, 28 Mar 2012 13:26:27 -0700 X-Google-Sender-Auth: v-2hBzEEZNyMD8pWM3XeuWz77xY Message-ID: From: Phillip Nordwall To: Beeblebrox Content-Type: text/plain; charset=ISO-8859-1 X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-fs@freebsd.org Subject: Re: jailed NFS server X-BeenThere: freebsd-fs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Filesystems List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Mar 2012 20:26:28 -0000 Good luck, and if you have success let us know. We had 2 people with FreeBSD server experience spend 3 days each on getting this to work on FreeBSD 8.0 before giving up do to other pressing business. Phillip Nordwall On Wed, Mar 28, 2012 at 1:20 PM, Beeblebrox wrote: > Is it possible to get an NFS server working from inside a Jail, where host > storage is on ZFS? I get errors from mountd and nfsd when started inside > jail (exports file has no V4 line and simple one-line test export). mountd > & nfsd errors are: > mountd[2580]: Can't delete exports for V4: > mountd[2580]: can't delete exports for /: Operation not permitted > mountd[2580]: can't change attributes for /home > mountd[2580]: bad exports list line /home -network 192.168.2.0/24 > nfsd[2583 ]: Can't read stable storage > file > > I have a modified host /etc/sysctl.conf as below, per post by PJD: > > http://www.mailinglistarchive.com/html/freebsd-current@freebsd.org/2007-07/msg01185.html > Not that I really know whether these settings are valid, but at least I got > rid of rpcbind errors. > > > > security.jail.jailed: 1 > > > > security.jail.mount_allowed: 1 > > > > security.jail.chflags_allowed: 1 > > > > security.jail.allow_raw_sockets: 0 > > > > security.jail.enforce_statfs: 2 > > > > security.jail.sysvipc_allowed: 1 > > > > security.jail.socket_unixiproute_only: 1 > > > > security.jail.set_hostname_allowed: 1 > > > > ## security.jail.enforce_statfs=0 > > > > vfs.nfsd.nfs_privport=1 > > > > vfs.nfsd.server_max_nfsvers=4 > > Then I start NFS manually form inside jail to observe any faults (Jail IP > is 192.168.2.1): > #> service rpcbind onestart -h 192.168.2.1 > #> service mountd onestart -r -n -p 59 -l -h 192.168.2.1 > #> service nfsd onestart -u -t -n 4 -l -h 192.168.2.1 > > Thanks & Regards. > _______________________________________________ > freebsd-fs@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-fs > To unsubscribe, send any mail to "freebsd-fs-unsubscribe@freebsd.org" >