| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
| |
Submitted by: Jeremie Le Hen <jeremie@le-hen.org>
MFC after: 3 days
|
|
|
|
|
|
| |
newaliases(1) may hang without proper DNS configuration.
Approved by: brueffer
|
|
|
|
|
|
|
|
|
|
| |
started at boot time if specified in
/etc/rc.conf.
PR: docs/81040
Submitted by: matteo
Approved by: trhodes (mentor)
MFC after: 1 week
|
|
|
|
| |
Approved by: re (blanket)
|
|
|
|
| |
Corrected by: brueffer
|
| |
|
|
|
|
|
|
| |
world (there is no /kernel file anymore).
Reminded by: Isaac Levy presentation
|
|
|
|
| |
Approved by: brueffer (mentor)
|
|
|
|
|
|
| |
target of the same name from src/etc/Makefile with a proper
environment, suitable to be used during upgrades and cross-
builds.
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
behaviour of chflags within a jail. If set to 0 (the default), then a
jailed root user is treated as an unprivileged user; if set to 1, then
a jailed root user is treated the same as an unjailed root user.
This is necessary to allow "make installworld" to work inside a jail,
since it attempts to manipulate the system immutable flag on certain
files.
Discussed with: csjp, rwatson
MFC after: 2 weeks
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
hence bump it to 6.
Note that the last commit message was not quite accurate. While the
assumption exists in the code, it's not possible to have an
uninitialized p there because if lflag is set when username is NULL
then execution would be terminated earlier.
|
|
|
|
|
| |
initialized with NULL, while it is not. So let's initialize
it.
|
|
|
|
| |
PR: 56646
|
|
|
|
|
|
|
|
|
| |
program under specific user's credentials, clean the environment and
set only a few variables.
PR: bin/70024
Submitted by: demon
MFC after: 1 month
|
| |
|
|
|
|
|
|
| |
seeing status of mounted file system for jailed processes.
Pass full path of jail's root directory to the kernel. mount(8) utility is
doing the same thing already.
|
| |
|
|
|
|
|
|
| |
to "Since".
Pointed out by: Ceri
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
about the risks of enabling raw sockets in prisons.
Because raw sockets can be used to configure and interact
with various network subsystems, extra caution should be
used where privileged access to jails is given out to
untrusted parties. As such, by default this option is disabled.
A few others and I are currently auditing the kernel
source code to ensure that the use of raw sockets by
privledged prison users is safe.
Approved by: bmilekic (mentor)
|
|
|
|
|
|
|
|
|
| |
o getpwnam(3) returns NULL and does not set errno when the user does
not exist. Bail out with "no such user" instead of "Unknown error: 0".
PR: bin/67262
Submitted by: demon (-U flag)
MFC after: 3 weeks
|
| |
|
|
|
|
|
| |
Obtained from: rwatson's commit log
Approved by: rwatson
|
|
|
|
| |
OK'ed by: bmilekic
|
|
|
|
|
|
| |
inside jails, Christian's last submission.
Submitted by: Christian S.J. Peron <maneo@bsdpro.com>
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
(1) Document the notion of using jail(8) to run "virtual servers" or
just to constrain specific applications. If only running specific
applications, some configuration steps are unnecessary (such as
editing rc.conf).
(2) Add some more subsection headers to break up the bigger chunks of
text.
(3) Clarify the problems associated with applications binding all IP
addresses in the host, and attempt to be more specific about
potential application problems. Document how to force sshd to
bind the the right socket.
(4) Suggest that in a jailed application scenario, you might want to
have the host syslogd listen on the socket in the jail, rather
than running syslogd in the jail.
(5) Catch another reference to /stand/sysinstall.
Approved by: re (bmah implicitly)
|
|
|
|
|
|
| |
-CURRENT, we have /usr/sbin/sysinstall.
Approved by: re (bmah implicitly)
|
|
|
|
|
|
|
| |
settings.
Reviewed by: rwatson
Approved by: blackend (mentor)
|
| |
|
|
|
|
|
|
|
| |
tell them that they also need to use devfs rules to prevent
inappropriate devices from appearing in the jail; add an Xref. In
earlier versions of this man page, the user was instructed to use
sh MAKEDEV jail, which only created a minimal set of device nodes.
|
|
|
|
|
| |
otherwise redirection of stdout to a file using block buffering will
not complete in time.
|
|
|
|
|
|
|
| |
o Add jexec(8) to execute a command in an existing jail.
o Add -j option for killall(1) to kill all processes in a specified
jail.
o Add -i option to jail(8) to output jail ID of newly created jail.
|
|
|
|
| |
Submitted by: demon
|
|
|
|
|
| |
Prodded by: bde
Reviewed by: bde
|
|
|
|
|
|
|
| |
PR: bin/44320
Submitted by: Mike Matsnev <mike@po.cs.msu.su>
Reviewed by: -current
MFC after: 6 weeks
|
|
|
|
| |
Spotted by: Andrew Khlebutin <andreyh@perm.ru>
|
|
|
|
|
|
|
| |
DEVFS is now mandatory in CURRENT.
PR: docs/48095
Submitted by: Grzegorz Czaplinski <G.Czaplinski@prioris.mini.pw.edu.pl>
|
|
|
|
| |
XXX: this example should be updated with a good example of devfs(8) rules.
|
| |
|
|
|
|
|
| |
PR: 38313
Submitted by: Jeff Ito <jeffi@rcn.com>
|
|
|
|
|
| |
Also change one case of blatant __progname abuse (several more remain)
This commit does not touch anything in src/{contrib,crypto,gnu}/.
|
|
|
|
|
|
| |
beneath it.
Reviewed by: rwatson
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
| |
changes.
Approved by: rwatson
Reviewed by: rwatson
|
| |
|