From owner-freebsd-jail@FreeBSD.ORG Thu Aug 16 03:32:44 2012 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx2.freebsd.org (mx2.freebsd.org [IPv6:2001:4f8:fff6::35]) by hub.freebsd.org (Postfix) with ESMTP id 48762106566B; Thu, 16 Aug 2012 03:32:44 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from [127.0.0.1] (hub.freebsd.org [IPv6:2001:4f8:fff6::36]) by mx2.freebsd.org (Postfix) with ESMTP id E876A14DC7F; Thu, 16 Aug 2012 03:32:42 +0000 (UTC) Message-ID: <502C69D9.8040803@FreeBSD.org> Date: Wed, 15 Aug 2012 17:32:41 -1000 From: Doug Barton Organization: http://www.FreeBSD.org/ User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20120714 Thunderbird/14.0 MIME-Version: 1.0 To: Jun Kuriyama References: <7mlihf1vmg.wl%kuriyama@s2factory.co.jp> <502C65A0.2060606@FreeBSD.org> In-Reply-To: X-Enigmail-Version: 1.4.3 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: freebsd-jail@freebsd.org Subject: Re: [patch] etc/rc.d/jail: allow extra parameters for each jails X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Aug 2012 03:32:44 -0000 On 08/15/2012 05:24 PM, Jun Kuriyama wrote: > 2012/8/16 Doug Barton : >> On 08/15/2012 03:19 PM, Jun Kuriyama wrote: >>> #jail_example_flags="-l -U root" # flags for jail(8) >>> +#jail_example_parameters="allow.raw_sockets=1" # extra parameters for this jail >> >> Why not just use _flags for this? > > Current implementation of rc.d/jail uses old command line syntax which > cannot pass parameters to jail(8), so main modifications of my patch > is changing this to use new command line style to use with "-c" flag > and named parameters. > > Then, you are right, these named parameters can be passed via _flags > after my patch. I just want separate command line option flags and > named parameters. I don't have strong argument to add _parameters > variables. I just think adding _parameters may be easy to > configure/understand. Thank you for the explanation. FWIW, this sounds reasonable to me. Doug