Re: Accounts with Restricted privileges

From: Dalin S. Owen (dowen@pstis.com)
Date: 05/09/02


From: "Dalin S. Owen" <dowen@pstis.com>
To: "Nielsen" <nielsen@memberwebs.com>
Date: Wed, 8 May 2002 16:11:31 -0600

On December 31, 1969 04:59 pm, you wrote:

That is not good on a system with 1000's of users... and I have different
users and UID's for inside my jails and outside.... Having a seperate quota
file + system for jails would be real nice... maybe when I have time I will
write it.

> Hmmm, I've used quotas in a jail. Just set the quotas on the host system
> with the same user ids. You can't "quota" the root user in a jail, but
> other users can be done quite nicely. Besides if you really want to give a
> quota to directory tree (not a user) you probably should be using vn
> devices.
>
> > I don't want that. I want all other processes to be chrooted too. By
> > now some of you are thinking "jail"... A jail won't cut it, because you
> > can't
>
> use
>
> > quotas in a jail.
>
> all the best,
>
> Nate

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: limit jail disk space
    ... > I mean jail disk limit ... quota settings mapped to it. ... So upon granting fs resources you'd have ...
    (freebsd-hackers)
  • Re: limit jail disk space
    ... The tools may control all limits such as cpu time, ... Vlad GALU said I can look to the quota ... > per jail>diskquota. ... >You want add reference pointer to prison struct from a inode>struct or store at inode struct prison id? ...
    (freebsd-hackers)
  • Re: Re[2]: New kernel and jail
    ... I am trying to rebuild a kernel to enable quota support. ... i?ve added "options QUOTA" to config file (all other options ... When booting with this new kernel jail does not ...
    (freebsd-questions)
  • Re: Jail Quotas - quota.user hard link
    ... Basic operation can be done by specifying a filename, available in the jail, which contains the quotas. ... I'm loosely under the impression that it should be possible to both query and manage quota data on live file systems without ever touching the quota backing file. ... It could be that we don't allow these syscalls to work from within a jail though, or that they look at /etc/fstab to decide if they should use the syscall, which should be fixable. ... You can stick an hourly cron script on the base system containing ...
    (freebsd-hackers)

Quantcast