Re: Need for SysV IPC to be confined to jail instances



On Sat, Nov 24, 2007 at 12:11:18PM +0100, Gabor Tjong A Hung wrote:
As I came to understand, if you enable jail_sysvipc_allow in rc.conf I am
defeating the purpose of a jail.

Not totally defeating the purpose but SysV IPC is not jail-aware so
any jailed process can see and affect the global SysV IPC state.

I got a suggestion that it might be possible to have sys v ipc confined to
a jail instance and perhaps let it work like a telephone number.

This has come up before. See (eg):
http://www.freebsd.org/cgi/query-pr.cgi?pr=48471
and the thread beginning
http://lists.freebsd.org/pipermail/freebsd-current/2006-April/062261.html

--
Peter Jeremy
Please excuse any delays as the result of my ISP's inability to implement
an MTA that is either RFC2821-compliant or matches their claimed behaviour.

Attachment: pgpU8to3IUm0e.pgp
Description: PGP signature



Relevant Pages

  • Re: Jail + sysv shmem
    ... > private SysV IPC memory spaces for the host system and each jail: ... > ask for SysV IPC inside of jailed hosting environments. ... Public PGP key: http://www.metro.cx/pubkey-gmc.asc Wondering about the funny attachment your mail program can't read? ...
    (freebsd-hackers)
  • Re: jail2 patchset 12
    ... Some time ago I finished the next public jail2 patchset. ... jail2 supports per-jail SYSV IPC namespaces. ... all jail-related code was moved under 'options JAIL'. ...
    (freebsd-hackers)
  • Re: Jail + sysv shmem
    ... > For a while i've been wanting shared memory to be usable withing jails, ... private SysV IPC memory spaces for the host system and each jail: ... ask for SysV IPC inside of jailed hosting environments. ...
    (freebsd-hackers)
  • Re: started playing with jails
    ... jail would corrupt the shared memory of the postgres outside the jail. ... now that you mention it I do recall discussions of multiple instances peeing in each others pools so to speak. ... the TCP port number it binds to as its SYSV IPC ID... ...
    (freebsd-questions)
  • Re: hang the minister
    ... *solely for the purpose of producing child porn*. ... The one that comes to mind immediately is the investigation into the 'Wonderland' Club. ... landing people in jail could land us in jail too. ...
    (uk.legal)