Den mån 28 sep. 2026 kl 21:35 skrev Gwen Nelson <[email protected]>:

> Hey all
> I'm considering implementing a jail-like subsystem for OpenBSD as part of
> restarting an old pubnix project.
> I don't mean porting or reproducing FreeBSD jails. I have some ideas for
> an implementation designed around OpenBSD's existing architecture and
> conventions.
> Before spending significant time developing it, I'd like to establish
> whether such a facility would be considered desirable in principle,
> assuming an implementation met the project's technical and code-quality
> standards.
> If there's no interest in such a facility upstream, that's fine; I'll
> design it as an external project instead.
>
> I'm particularly interested in whether this has been discussed previously,
> and whether there are architectural or policy reasons the project has
> deliberately avoided this kind of abstraction.
>

Around the time for OpenBSD 4.4, Kristaps Dzonsons made "mult" work on
OpenBSD, enough for allowing sshd to run in such a "jail".

Interview about the idea:
https://bsdtalk.blogspot.com/2008/02/bsdtalk140-mult-project-with-kristaps.html

In the end, sshd on OpenBSD probably fared better with pledge, unveil and
privsep, but I am sure someone would like to have jail-a-likes for network
services on OpenBSD given how popular the namespacing thing on linux and
FreeBSD jails have become.

If it would ever go into base? No idea.

-- 
May the most significant bit of your life be positive.

Reply via email to