Re: Jailed X applications



Quoting mal content <artifact.one@xxxxxxxxxxxxxx> (from Fri, 17 Aug 2007 06:10:39 +0100):

This is better suited for freebsd-jail@ (CCed), please remove freebsd-security@ on reply to move the discussion there.

Has anyone here ever successfully set up a jail for X apps, connecting
to an external X server? I'm trying an experimental sandbox setup here.

I have my X server itself in a jail (needs a kernel patch and some devfs rules), and in the past connected to a jail and started a X11 programm there... IIRC.

I have a jail running on an aliased IP on my local machine and X
programs connect out of the jail to my local X server via an SSH
tunneled TCP connection. All other packets to and from the jail are
denied by the packet filter. The trouble I am having is that many
applications (all X apps so far and a few of the SSH tools) try to open
and read from /dev/tty, which clearly isn't going to happen:

ssh uses a tty (pty?), but normally you have some in a jail. How do you start the jail? There should be devfs mounted in the jail.

Bye,
Alexander.

--
"How do I love thee? My accumulator overflows."

http://www.Leidinger.net Alexander @ Leidinger.net: PGP ID = B0063FE7
http://www.FreeBSD.org netchild @ FreeBSD.org : PGP ID = 72077137
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Jail setup
    ... I need to set up a new mail server at a different building, ... I would put sendmail and its services in a jail to ... can ssh in and run sendmail. ...
    (freebsd-questions)
  • SSH From within a Jail
    ... I am experimenting with jails and have run into a ... I need to ssh from within my jail to another ... any available server that I may have. ... the jail setups I do have a separate aliased IP ...
    (freebsd-hackers)
  • Re: Re: SSH From within a Jail
    ... >To be able to ssh to another server from within a jail, ... >Try to ssh into the jail and then ssh to another box. ... To unsubscribe, ...
    (freebsd-hackers)
  • Re: [FreeBSD/Jails] Wie bekommt ein Shellscript raus, dass es in einem Jail laeuft?
    ... ich habe hier von einem netten Netzler ein minimales FreeBSD-Jail ... Nameserver laufen zu lassen. ... Devicenodes in das chroot kopieren und f?llt, da Jail, auf die Nase, ...
    (de.comp.os.unix.bsd)
  • RE: Future development of Jail (was Re: corporate backers of freebsd)
    ... apparently never run the Microsot authentication server. ... have your answer as to why jail is a dead-end. ... Actually, somebody was paying the jail developer, and then ... FreeBSD server in a commercial corporate network over 13 years ago. ...
    (freebsd-questions)