On Mon, Sep 28, 2026 at 09:13:10PM +0100, Gwen Nelson wrote:
> My basic idea is to implement a lightweight jail - just seperate out
> namespaces for process table and network interfaces etc - i'll be doing
> this anyway, but if there's a chance it could be used in base, i'll
> obviously have to conform to the upstream coding style and i'll license my
> work appropriately.

First read about rtable(4) as that provides something like "namespacing"
for network resources already.

Often there is a desire to use namespacing as a way to simply hide
resources (e.g. ps(1) not reporting other processes). There may be valid
reasons for that but often instead of worrying about that simply
creating multiple users can often work fine.

I would also try to avoid the mistakes Docker and other container
systems made of trying to reduce what root can do (which are now being
addressed in Linux through better support for user namespaces and making
uid 0 in the container not be uid 0 outside it). Instead consider APIs
along the lines of pledge(2) and unveil(2) that can work for an
unprivileged user.

It is unlikely that a "jail" subsystem would be wanted in base, although
if the APIs it uses could be applied to programs in base there could be
interest. (A closely related example being O_BELOW[1], which is still
being explored, that could allow an unprivileged chroot like operation.)

[1]: https://marc.info/?l=openbsd-tech&m=174844109910709&w=2

Reply via email to