From owner-freebsd-bugs@FreeBSD.ORG Mon Aug 4 01:30:14 2003 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F044637B401 for ; Mon, 4 Aug 2003 01:30:14 -0700 (PDT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 949B643FB1 for ; Mon, 4 Aug 2003 01:30:14 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.9/8.12.9) with ESMTP id h748UEUp077743 for ; Mon, 4 Aug 2003 01:30:14 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.9/8.12.9/Submit) id h748UEuU077742; Mon, 4 Aug 2003 01:30:14 -0700 (PDT) Date: Mon, 4 Aug 2003 01:30:14 -0700 (PDT) Message-Id: <200308040830.h748UEuU077742@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Dmitry Morozovsky Subject: Re: kern/55163: [patch] hide kld system details from jails X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Dmitry Morozovsky List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 Aug 2003 08:30:15 -0000 The following reply was made to PR kern/55163; it has been noted by GNATS. From: Dmitry Morozovsky To: Yar Tikhiy Cc: FreeBSD-gnats-submit@FreeBSD.org Subject: Re: kern/55163: [patch] hide kld system details from jails Date: Mon, 4 Aug 2003 12:26:23 +0400 (MSD) On Mon, 4 Aug 2003, Yar Tikhiy wrote: YT> Could you please provide a short rationale YT> for the feature you're proposing? Well, security thru obscurity is not the best technique ;-) However, it seems that reveal too much info about host system for jail user, or even for jail admin, is not always the best. We plan to use it together with Pawel Jakub Dawidek's jailfsstat kernel module. This code path is rare, so no performance problem I think. Any objections? Sincerely, D.Marck [DM5020, MCK-RIPE, DM3-RIPN] ------------------------------------------------------------------------ *** Dmitry Morozovsky --- D.Marck --- Wild Woozle --- marck@rinet.ru *** ------------------------------------------------------------------------