Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Nov 1999 03:16:58 +0900
From:      "Daniel C. Sobral" <dcs@newsguy.com>
To:        Yoshinobu Inoue <shin@nd.net.fujitsu.co.jp>
Cc:        phk@critter.freebsd.dk, beyssac@enst.fr, freebsd-hackers@FreeBSD.ORG, freebsd-security@FreeBSD.ORG
Subject:   Re: Should jail treat ip-number?
Message-ID:  <3832F11A.6D206BEC@newsguy.com>
References:  <19991110022852N.shin@nd.net.fujitsu.co.jp> <24337.942169052@critter.freebsd.dk> <19991110025853X.shin@nd.net.fujitsu.co.jp> <19991110013913.A5181@enst.fr> <19991117134132S.shin@nd.net.fujitsu.co.jp>

next in thread | previous in thread | raw e-mail | index | archive | help
Yoshinobu Inoue wrote:
> 
>   -As already commented, checking those addresses which
>    already specified by other jail'ed processes is necessary.

I disagree. The address is specified by the admin of the machine.
Letting him shoot himself in the foot is not particular bad, and the
test can be performed by the userland tools used to manage the
machine.

> solution:
>   Don't specify addresses via jail(2), and let kernel select
>   any non binded address.
>   Loop in_ifaddr list and try in_pcblookup_hash() for each
>   of addresses, just as in_pcbbind does it to search for non
>   binded port.
> 
> A weak point of this solution is that processes in a same jail
> won't be necessariliy binded to a same address, but does it
> matters?

Ok, question: I "buy" a virtual server on the machine to run an
internet daemon of mine. I need the IP to that server to access the
daemon. How do the admin of the machine ensures that _my_ jail will
have the fixed IP assigned to me always with your solution?

--
Daniel C. Sobral			(8-DCS)
dcs@newsguy.com
dcs@freebsd.org

	"Then again maybe not going to heaven would be a blessing. Relkin
liked a certain amount of peace and harmony, since there'd been a
pronounced shortage of them in his own life; however, nothing but
peace and harmony, forever and forever? He wasn't sure about that.
And no beer? Very dubious proposition."



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3832F11A.6D206BEC>