Mult looks interesting, but there's not a lot of material I could find
online, other than on archive.org.

It's also rather more radical than what I was thinking of - which is
something more akin to how FreeBSD jail works - I was thinking of starting
by adding a syscall (which must be called by uid 0) that creates a new
"jail ID" for the calling process, after checking it's not already in a
jail (i.e, it's in jail ID 0).

Then any other syscalls that interact with other processes check if the
jail ID matches - if not, it acts as if the target PID does not exist.

With this a simple userland utility could do a chroot and then call the new
SYS_JAIL syscall and have process table isolation.

Once that's working, it should be possible to integrate a facility for
isolation of network interfaces and so on - i'd also want to isolate
devices too (for obvious reasons - imagine if a jailed process can just
access the block device for the root filesystem).

But that's my basic idea - instead of a whole new process table, just
adding a single field and checking it, and slowly integrating checks on
other subsystems.

Anyone got thoughts?

On Mon, 28 Sept 2026 at 20:59, Janne Johansson <[email protected]> wrote:

> Den mån 28 sep. 2026 kl 21:35 skrev Gwen Nelson <[email protected]>:
>
>> Hey all
>> I'm considering implementing a jail-like subsystem for OpenBSD as part of
>> restarting an old pubnix project.
>> I don't mean porting or reproducing FreeBSD jails. I have some ideas for
>> an implementation designed around OpenBSD's existing architecture and
>> conventions.
>> Before spending significant time developing it, I'd like to establish
>> whether such a facility would be considered desirable in principle,
>> assuming an implementation met the project's technical and code-quality
>> standards.
>> If there's no interest in such a facility upstream, that's fine; I'll
>> design it as an external project instead.
>>
>> I'm particularly interested in whether this has been discussed
>> previously, and whether there are architectural or policy reasons the
>> project has deliberately avoided this kind of abstraction.
>>
>
> Around the time for OpenBSD 4.4, Kristaps Dzonsons made "mult" work on
> OpenBSD, enough for allowing sshd to run in such a "jail".
>
> Interview about the idea:
>
> https://bsdtalk.blogspot.com/2008/02/bsdtalk140-mult-project-with-kristaps.html
>
> In the end, sshd on OpenBSD probably fared better with pledge, unveil and
> privsep, but I am sure someone would like to have jail-a-likes for network
> services on OpenBSD given how popular the namespacing thing on linux and
> FreeBSD jails have become.
>
> If it would ever go into base? No idea.
>
> --
> May the most significant bit of your life be positive.
>

Reply via email to