Den mån 28 sep. 2026 kl 21:35 skrev Gwen Nelson <[email protected]>:
> Hey all > I'm considering implementing a jail-like subsystem for OpenBSD as part of > restarting an old pubnix project. > I don't mean porting or reproducing FreeBSD jails. I have some ideas for > an implementation designed around OpenBSD's existing architecture and > conventions. > Before spending significant time developing it, I'd like to establish > whether such a facility would be considered desirable in principle, > assuming an implementation met the project's technical and code-quality > standards. > If there's no interest in such a facility upstream, that's fine; I'll > design it as an external project instead. > > I'm particularly interested in whether this has been discussed previously, > and whether there are architectural or policy reasons the project has > deliberately avoided this kind of abstraction. > Around the time for OpenBSD 4.4, Kristaps Dzonsons made "mult" work on OpenBSD, enough for allowing sshd to run in such a "jail". Interview about the idea: https://bsdtalk.blogspot.com/2008/02/bsdtalk140-mult-project-with-kristaps.html In the end, sshd on OpenBSD probably fared better with pledge, unveil and privsep, but I am sure someone would like to have jail-a-likes for network services on OpenBSD given how popular the namespacing thing on linux and FreeBSD jails have become. If it would ever go into base? No idea. -- May the most significant bit of your life be positive.

