From owner-freebsd-net@FreeBSD.ORG Sun Jan 6 17:56:46 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8AB0416A468 for ; Sun, 6 Jan 2008 17:56:46 +0000 (UTC) (envelope-from julian@elischer.org) Received: from outG.internet-mail-service.net (outG.internet-mail-service.net [216.240.47.230]) by mx1.freebsd.org (Postfix) with ESMTP id 7895A13C448 for ; Sun, 6 Jan 2008 17:56:46 +0000 (UTC) (envelope-from julian@elischer.org) Received: from mx0.idiom.com (HELO idiom.com) (216.240.32.160) by out.internet-mail-service.net (qpsmtpd/0.40) with ESMTP; Sun, 06 Jan 2008 09:56:45 -0800 Received: from julian-mac.elischer.org (localhost [127.0.0.1]) by idiom.com (Postfix) with ESMTP id 17711126E36; Sun, 6 Jan 2008 09:56:45 -0800 (PST) Message-ID: <4781166D.2010108@elischer.org> Date: Sun, 06 Jan 2008 09:57:01 -0800 From: Julian Elischer User-Agent: Thunderbird 2.0.0.9 (Macintosh/20071031) MIME-Version: 1.0 To: Mykola Dzham References: <4772F123.5030303@elischer.org> <477416CC.4090906@elischer.org> <477D2EF3.2060909@elischer.org> <20080106112033.GA40991@expo.ukrweb.net> In-Reply-To: <20080106112033.GA40991@expo.ukrweb.net> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: Qing Li , FreeBSD Net , arch@freebsd.org, Ivo Vachkov , Robert Watson , Vadim Goncharov Subject: Re: resend: multiple routing table roadmap (format fix) X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Jan 2008 17:56:46 -0000 Mykola Dzham wrote: > Julian Elischer wrote: >> setfib 3 /bin/sh >> >> now by default everythign you do uses table 3. >> or even >> >> setfib 3 jail {blah} >> >> and all the procs in the jail use table 3. You also need to do >> setfib 3 jexec xxx >> for extra processes you add to the jail afterwards. > > Is it possible to deny setfib after setfib N /bin/sh ? Or call setfib > from jail? If yes this can be usable for restriction jail on some > different fib > I hadn't considered that.. though possibly what you want is vimage().