From owner-freebsd-hackers@FreeBSD.ORG Tue Mar 2 10:00:51 2010 Return-Path: Delivered-To: freebsd-hackers@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6F1AA106566C; Tue, 2 Mar 2010 10:00:51 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 2A6B58FC0C; Tue, 2 Mar 2010 10:00:50 +0000 (UTC) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id 970031FFC22; Tue, 2 Mar 2010 10:00:45 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id 7649284549; Tue, 2 Mar 2010 11:00:45 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: xorquewasp@googlemail.com References: <20100226163227.GA15162@logik.internal.network> <4B88074E.7050007@FreeBSD.org> <20100226222113.GA14592@logik.internal.network> <4B884D48.90509@FreeBSD.org> <20100227093409.GA40858@logik.internal.network> <864ol0w4g5.fsf@ds4.des.no> <20100301135829.GB2219@logik.internal.network> <86zl2suo8n.fsf@ds4.des.no> <20100301161901.GC2219@logik.internal.network> <86635frhaa.fsf@ds4.des.no> <20100301220332.GB74816@logik.internal.network> Date: Tue, 02 Mar 2010 11:00:45 +0100 In-Reply-To: <20100301220332.GB74816@logik.internal.network> (xorquewasp@googlemail.com's message of "Mon, 1 Mar 2010 22:03:32 +0000") Message-ID: <86aaurniuq.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.0.95 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: Greg Larkin , freebsd-hackers@FreeBSD.org Subject: Re: package building failure irritation X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Mar 2010 10:00:51 -0000 xorquewasp@googlemail.com writes: > Basically, I have a ton of jails and each jail mounts a shared 'tmp', That's not a good idea, there are too many opportunities for conflicts (software that creates sockets and state directories with non-randomized names in /tmp) and might even allow a compromised jail to compromise the others. > and possibly unshared 'pkg' 'work' 'distfiles' and 'ports' > directories: > > /storage/jails/8.0/x86_64/mk4/pkg /jail/8.0-amd64-mk4/pkg null= fs rw > /storage/jails/8.0/x86_64/mk4/work /jail/8.0-amd64-mk4/work null= fs rw > /storage/distfiles /jail/8.0-amd64-mk4/distfiles null= fs rw > /storage/ports /jail/8.0-amd64-mk4/ports null= fs ro > /storage/shared_tmp /jail/8.0-amd64-mk4/shared_tmp null= fs rw zfs set mountpoint=3D/jail/8.0-amd64-mk4 storage/jails/8.0/x86_64/mk4 Children of storage/jails/8.0/x86_64/mk4 will inherit this property, so they will automatically appear where you expect; alternatively, you can set the mountpoint property for each individual fileset. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no