Need for SysV IPC to be confined to jail instances

2007-11-24 Thread Gabor Tjong A Hung
Dear all, I have come to understand that postgresql needs sys v ipc. I haven't tried to figure out why exactly, but I'm sure they have good reasons. As I came to understand, if you enable jail_sysvipc_allow in rc.conf I am defeating the purpose of a jail. So basically I if you want pgsql in

Re: Need for SysV IPC to be confined to jail instances

2007-11-24 Thread Peter Jeremy
On Sat, Nov 24, 2007 at 12:11:18PM +0100, Gabor Tjong A Hung wrote: As I came to understand, if you enable jail_sysvipc_allow in rc.conf I am defeating the purpose of a jail. Not totally defeating the purpose but SysV IPC is not jail-aware so any jailed process can see and affect the global SysV