From owner-freebsd-hackers@FreeBSD.ORG Sun May 28 13:50:37 2006 Return-Path: X-Original-To: freebsd-hackers@freebsd.org Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 36ADF16A999 for ; Sun, 28 May 2006 13:50:37 +0000 (UTC) (envelope-from joerg@britannica.bec.de) Received: from hydra.bec.de (www.ostsee-abc.de [62.206.222.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id CA18B43D4C for ; Sun, 28 May 2006 13:50:36 +0000 (GMT) (envelope-from joerg@britannica.bec.de) Received: from britannica.bec.de (unknown [139.30.252.72]) by hydra.bec.de (Postfix) with ESMTP id 17E7335707 for ; Sun, 28 May 2006 15:50:35 +0200 (CEST) Received: by britannica.bec.de (Postfix, from userid 1000) id 568576C745; Sun, 28 May 2006 15:50:12 +0200 (CEST) Date: Sun, 28 May 2006 15:50:12 +0200 From: joerg@britannica.bec.de To: freebsd-hackers@freebsd.org Message-ID: <20060528135012.GB14541@britannica.bec.de> Mail-Followup-To: freebsd-hackers@freebsd.org References: <4479A99E.8080708@aksoft.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4479A99E.8080708@aksoft.net> User-Agent: Mutt/1.5.11 Subject: Re: security.bsd.see_other_uids for jails X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 28 May 2006 13:50:39 -0000 On Sun, May 28, 2006 at 03:46:06PM +0200, Anatoli Klassen wrote: > Hi All, > > if security.bsd.see_other_uids is set to 0, users from the main system > can still see processes from jails if they have (by accident) the save uid. > > For me it's wrong behavior because the main system and the jail are two > different systems where uids are independent. Sorry but you have far bigger security problems if you create such a setup. E.g. "users" from the outer system can ptrace the processes in the jail with the same uid. Short answer is: don't do that. Joerg