X11 in a jail (was: Re: NFS mount inside jail fails)

2011-05-26 Thread Alexander Leidinger
Quoting Doug Ambrisko (from Wed, 25 May 2011 09:42:20 -0700 (PDT)): CCing jails@ Alexander Leidinger writes: | Quoting Doug Ambrisko (from Thu, 19 May 2011 | 14:38:40 -0700 (PDT)): | | > Alexander Leidinger writes: | > | On Thu, 19 May 2011 10:24:59 -0700 (PDT) Doug Ambrisko | > | wrote: |

Re: NFS mount inside jail fails

2011-05-25 Thread Doug Ambrisko
Alexander Leidinger writes: | Quoting Doug Ambrisko (from Thu, 19 May 2011 | 14:38:40 -0700 (PDT)): | | > Alexander Leidinger writes: | > | On Thu, 19 May 2011 10:24:59 -0700 (PDT) Doug Ambrisko | > | wrote: | > | | > | > doesn't have access to it anymore either. Running an X server in a | >

Re: NFS mount inside jail fails

2011-05-20 Thread Alexander Leidinger
Quoting Doug Ambrisko (from Thu, 19 May 2011 14:38:40 -0700 (PDT)): Alexander Leidinger writes: | On Thu, 19 May 2011 10:24:59 -0700 (PDT) Doug Ambrisko | wrote: | | > doesn't have access to it anymore either. Running an X server in a | > vimage has some issues. Most are pretty easy to ove

Re: NFS mount inside jail fails

2011-05-19 Thread Alexander Leidinger
On Thu, 19 May 2011 10:24:59 -0700 (PDT) Doug Ambrisko wrote: > doesn't have access to it anymore either. Running an X server in a > vimage has some issues. Most are pretty easy to over-come. Are you using my patch (http://www.leidinger.net/FreeBSD/current-patches/0_jail.diff) + a custom devfs

Re: NFS mount inside jail fails

2011-05-19 Thread Doug Ambrisko
Alexander Leidinger writes: | On Thu, 19 May 2011 10:24:59 -0700 (PDT) Doug Ambrisko | wrote: | | > doesn't have access to it anymore either. Running an X server in a | > vimage has some issues. Most are pretty easy to over-come. | | Are you using my patch | (http://www.leidinger.net/FreeBSD/c

Re: NFS mount inside jail fails

2011-05-19 Thread Doug Ambrisko
Arnaud Lacombe writes: | Hi, | | On Wed, May 18, 2011 at 10:03 AM, Pawel Jakub Dawidek wrote: | > On Tue, May 17, 2011 at 10:17:12PM +0200, Alexander Leidinger wrote: | >> On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno | >> wrote: | >> | >> > Silly thing I ran into today. ?User wanted to NFS mou

Re: NFS mount inside jail fails

2011-05-19 Thread Alexander Leidinger
Quoting Arnaud Lacombe (from Wed, 18 May 2011 22:37:24 -0400): Hi, On Wed, May 18, 2011 at 10:03 AM, Pawel Jakub Dawidek wrote: There are some file systems types that can't be securely mounted within a jail no matter what, like UFS, MSDOFS, EXTFS, XFS, REISERFS, NTFS, etc.  because the

Re: NFS mount inside jail fails

2011-05-18 Thread Arnaud Lacombe
Hi, On Wed, May 18, 2011 at 10:03 AM, Pawel Jakub Dawidek wrote: > On Tue, May 17, 2011 at 10:17:12PM +0200, Alexander Leidinger wrote: >> On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno >> wrote: >> >> > Silly thing I ran into today.  User wanted to NFS mount a dir inside a >> > jail.  After I gr

Re: NFS mount inside jail fails

2011-05-18 Thread Kostik Belousov
On Wed, May 18, 2011 at 04:03:26PM +0200, Pawel Jakub Dawidek wrote: > On Tue, May 17, 2011 at 10:17:12PM +0200, Alexander Leidinger wrote: > > On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno > > wrote: > > > > > Silly thing I ran into today. User wanted to NFS mount a dir inside a > > > jail. Af

Re: NFS mount inside jail fails

2011-05-18 Thread Pawel Jakub Dawidek
On Tue, May 17, 2011 at 10:17:12PM +0200, Alexander Leidinger wrote: > On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno > wrote: > > > Silly thing I ran into today. User wanted to NFS mount a dir inside a > > jail. After I groaned about the security implication of this, I noted > > that there is a

Re: NFS mount inside jail fails

2011-05-17 Thread Julian Elischer
On 5/17/11 1:17 PM, Alexander Leidinger wrote: On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno wrote: Silly thing I ran into today. User wanted to NFS mount a dir inside a jail. After I groaned about the security implication of this, I noted that there is a sysctl that looks like it should allo

Re: NFS mount inside jail fails

2011-05-17 Thread Alexander Leidinger
On Tue, 17 May 2011 12:56:40 -0700 Sean Bruno wrote: > Silly thing I ran into today. User wanted to NFS mount a dir inside a > jail. After I groaned about the security implication of this, I noted > that there is a sysctl that looks like it should allow this. Namely, > security.jail.mount_allo

NFS mount inside jail fails

2011-05-17 Thread Sean Bruno
Silly thing I ran into today. User wanted to NFS mount a dir inside a jail. After I groaned about the security implication of this, I noted that there is a sysctl that looks like it should allow this. Namely, security.jail.mount_allowed. I noted that setting this follows a path that *should* ha