On 9/29/26 04:01, Gwen Nelson wrote:
Mult looks interesting, but there's not a lot of material I could find
online, other than on archive.org.

It's also rather more radical than what I was thinking of - which is something more akin to how FreeBSD jail works - I was thinking of
starting by adding a syscall (which must be called by uid 0) that
creates a new "jail ID" for the calling process, after checking it's
not already in a jail (i.e, it's in jail ID 0).

Then any other syscalls that interact with other processes check if
the jail ID matches - if not, it acts as if the target PID does not
exist.

With this a simple userland utility could do a chroot and then call
the new SYS_JAIL syscall and have process table isolation.

Once that's working, it should be possible to integrate a facility for
isolation of network interfaces and so on - i'd also want to isolate devices too (for obvious reasons - imagine if a jailed process can
just access the block device for the root filesystem).

But that's my basic idea - instead of a whole new process table, just adding a single field and checking it, and slowly integrating checks
on other subsystems.

Anyone got thoughts?

There was once sysjail too.  It might be useful to note:

http://www.watson.org/~robert/2007woot/

https://www.usenix.org/legacy/event/woot07/tech/full_papers/watson/watson.pdf

/Lars

Reply via email to