Date: Tue, 04 Apr 2006 07:55:50 -0400 From: Michael Butler <imb@protected-networks.net> To: Robert Watson <rwatson@FreeBSD.org> Cc: Peter Jeremy <peterjeremy@optushome.com.au>, freebsd-current@FreeBSD.org, freebsd-stable@FreeBSD.org Subject: Re: new feature: private IPC for every jail Message-ID: <44325EC6.9090608@protected-networks.net> In-Reply-To: <20060404124313.B76562@fledge.watson.org> References: <20060403003318.K947@ganymede.hub.org> <20060403163220.F36756@fledge.watson.org> <20060404100750.GG683@turion.vk2pj.dyndns.org> <20060404112938.G76562@fledge.watson.org> <20060404114107.GJ683@turion.vk2pj.dyndns.org> <20060404124313.B76562@fledge.watson.org>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Robert Watson wrote: > Would it make more sense to simply allocate ID's sequentially, and > simply not allow access to objects with a non-matching prison? .. This depends on the expected size of the system-wide pool; sequential allocation invites sequential searches of the name/id-space when looking for items any individual jail-id "owns". However, what would work is a linked list of associated ids from each jail descriptor thereby creating the list of things to deallocate on jail termination, -- Michael Butler, CISSP Security Architect Protected Networks http://www.protected-networks.net [-- Attachment #2 --] 0 *H 010 + 0 *H 00̠10 *H 010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net0 060207140146Z 110308140146Z010 UUS10 UMA10UMedford10U Protected Networks10UMail client10UIain Michael Butler1)0' *H imb@protected-networks.net00 *H 0 F٠`nz,d&IJ1\h݄$Kkw!l@V|/^p#7){T9ŭJw}wυA- >P_׆<Saa2Pkp z0v0 U0 0 `HB0F `HB 97Certificate issued by http://www.protected-networks.net0U)1 R|cDt_*USB0U#0TE66;T>ͤ010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net \#į~b0%U0imb@protected-networks.net0G `HB:8http://www.protected-networks.net/Protected_Networks.crl0IUB0@0><:8http://www.protected-networks.net/Protected_Networks.crl0%U0imb@protected-networks.net0U0 *H -ZeZ $ vJ֖D"Gr(wʁjm1۬dC3#s1 gҦ#4%8:'p Yđ/&s}%Ͳkp#ql"N[X`V0xUlu#Thkۆ^62!a)o.Fj`.#G;DJm5^]YGn3,N^S46o4#ҍ@:m < klm}b5V]d[4GU$O[6d[ӠVKG=`56C&4CZZ:4{%s^/ N$G"BT%i>,hCWF=/M"oFGOMS\~;m7I]w/o Q]*v& <00̠10 *H 010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net0 060207140146Z 110308140146Z010 UUS10 UMA10UMedford10U Protected Networks10UMail client10UIain Michael Butler1)0' *H imb@protected-networks.net00 *H 0 F٠`nz,d&IJ1\h݄$Kkw!l@V|/^p#7){T9ŭJw}wυA- >P_׆<Saa2Pkp z0v0 U0 0 `HB0F `HB 97Certificate issued by http://www.protected-networks.net0U)1 R|cDt_*USB0U#0TE66;T>ͤ010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net \#į~b0%U0imb@protected-networks.net0G `HB:8http://www.protected-networks.net/Protected_Networks.crl0IUB0@0><:8http://www.protected-networks.net/Protected_Networks.crl0%U0imb@protected-networks.net0U0 *H -ZeZ $ vJ֖D"Gr(wʁjm1۬dC3#s1 gҦ#4%8:'p Yđ/&s}%Ͳkp#ql"N[X`V0xUlu#Thkۆ^62!a)o.Fj`.#G;DJm5^]YGn3,N^S46o4#ҍ@:m < klm}b5V]d[4GU$O[6d[ӠVKG=`56C&4CZZ:4{%s^/ N$G"BT%i>,hCWF=/M"oFGOMS\~;m7I]w/o Q]*v& <100010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net10 + u0 *H 1 *H 0 *H 1 060404115550Z0# *H 1Ŭ5r"0F|?0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 +710010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net10*H 1Р010 UUS10 UMA10UMedford10U Protected Networks10UCertificate Authority110/U(Protected Networks Certificate Authority1)0' *H imb@protected-networks.net10 *H W*E"w!Q*yn&| ݩK4{`k $Ʒ)keHzOR>W1 )Bvڽ^nv,1yʜ,}(2'
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44325EC6.9090608>
