Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 17 Nov 2005 11:36:36 -0700
From:      "Chad Leigh -- Shire.Net LLC" <chad@shire.net>
To:        Mark Bucciarelli <mark@gaiahost.coop>
Cc:        Free BSD Questions list <freebsd-questions@freebsd.org>
Subject:   Re: nullfs [was: Need urgent help regarding security]
Message-ID:  <C57AB8B2-3349-4787-8354-B91AC6CACC49@shire.net>
In-Reply-To: <20051117143643.GC2572@rabbit>
References:  <51190.68.165.89.71.1132194943.squirrel@mail.el.net> <20051117025112.3707143D45@mx1.FreeBSD.org> <20051117043859.GF26954@localdomain> <D4EE1810-A918-491C-9860-CF12945337A7@shire.net> <20051117143643.GC2572@rabbit>

next in thread | previous in thread | raw e-mail | index | archive | help

On Nov 17, 2005, at 7:36 AM, Mark Bucciarelli wrote:

> On Wed, Nov 16, 2005 at 10:16:16PM -0700, Chad Leigh -- Shire.Net LLC
> wrote:
>
>> I then create one or more jails that use nullfs to READ ONLY mount
>> specific parts of the master hierarchy into the jail.
>
> This is very interesting to me, as I are currently working on a jail
> design and nullfs has a number of question marks next to it, mainly  
> due
> to the scary man page warning. Here are a few of the questions:
>
> How did you decide it was trustworthy?

I did a few tests and read some archived posts from others using it.   
I was previously using a localhost nfs mount but wanted to eliminate  
nfs from the mix due to another issue I was having.

>
> Does it result in lower RAM usage? (The program that is run, for
> example, Apache, comes from the same spot on the disk across all  
> jails.)

Don't know.  Never did any tests.

>
> Is it currently maintained? The man page includes a maintainer
> solicitation.

Don't know.  However, archived posts lead me to believe that bugs  
have been fixed etc recently and the man page may be out of date.

>
> Have you had any problems in production?

Not that I know of.  Seems to be running fine with over 40 jails on  
the machine.  Most are READ ONLY but I do have one jail with a RW / 
usr so it can install ports etc.  I have a /usr/public I install  
ports into for all jails to use.

>
> Have you used it for long?
>

A few months.  Previously I was happily doing the same thing with the  
localhost nfs mount.

best
Chad


> m
>
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions- 
> unsubscribe@freebsd.org"

---
Chad Leigh -- Shire.Net LLC
Your Web App and Email hosting provider
chad@shire.net





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?C57AB8B2-3349-4787-8354-B91AC6CACC49>