From owner-freebsd-questions@freebsd.org Wed Sep 2 14:15:04 2015 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 510EB9C9388 for ; Wed, 2 Sep 2015 14:15:04 +0000 (UTC) (envelope-from niklaas@kulturflatrate.net) Received: from mail2.kulturflatrate.net (mail2.kulturflatrate.net [IPv6:2a01:4f8:121:52ad::3:1]) by mx1.freebsd.org (Postfix) with ESMTP id 1A388F4F for ; Wed, 2 Sep 2015 14:15:04 +0000 (UTC) (envelope-from niklaas@kulturflatrate.net) Received: from [192.168.0.25] (mail.kulturflatrate.net [IPv6:2a01:488:66:1000:2ea3:77dd:0:1]) (Authenticated sender: niklaas@kulturflatrate.net) by mail2.kulturflatrate.net (Postfix) with ESMTPSA id 5FBD23E2E1; Wed, 2 Sep 2015 16:15:02 +0200 (CEST) Subject: Re: Jail causes host to reboot To: Adam Vande More References: <55E6E26A.1040706@kulturflatrate.net> Cc: FreeBSD Questions From: Niklaas Baudet von Gersdorff X-Enigmail-Draft-Status: N1110 Message-ID: <55E704D4.2050607@kulturflatrate.net> Date: Wed, 2 Sep 2015 16:16:52 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Sep 2015 14:15:04 -0000 On 02/09/15 15:56, Adam Vande More wrote: > A jail is used for isolation and security. It isn't intended to prevent > kernel panics and other such issues. For example, if a jail accesses a > corrupt fs, it may cause a panic and probably a reboot depending on > configuration. An expectation of jails protecting against such a thing > is misguided. Thanks for this clarification. So, in case someone is able to get access to a jail and causes a kernel panic, the person can compromise the entire host system? I doubt that it is possible but you saying "depending on configuration" brought up the following question: Is there a way to tell the host system to only shut down the jail (and maybe send an email to me) in case the jail causes a panic and not reboot the entire system? Am I right that the only way to prevent such failure is virtualising an entire operating system instead of using a jail?