[zones-discuss] chroot env into zone

2008-11-12 Thread Maciej Browarski
Hello, I've running chroot environment (only apache, php and mysql)on Solaris 10u5 and I want this environment move to ZONE environment. Problem is with packages because zoneadm install all packages from global ZONE. Is there only way that I install this ZONE and after installing ZONE remove

Re: [zones-discuss] chroot env into zone

2008-11-12 Thread C. Bergström
Maciej Browarski wrote: Hello, I've running chroot environment (only apache, php and mysql)on Solaris 10u5 and I want this environment move to ZONE environment. Problem is with packages because zoneadm install all packages from global ZONE. Is there only way that I install this ZONE and

[zones-discuss] Code Review for 6613349 setuid not allowed message could be more useful

2008-11-12 Thread Jason King
I'm looking for reviewers for '6613349 setuid not allowed message could be more useful'. I've tested it on a b101 system without any issues. It's pretty straightforward (and small) -- just modifying the message to display the filesystem path (instead of the device number) and making it zone

Re: [zones-discuss] Code Review for 6613349 setuid not allowed message could be more useful

2008-11-12 Thread Casper . Dik
I'm looking for reviewers for '6613349 setuid not allowed message could be more useful'. I've tested it on a b101 system without any issues. It's pretty straightforward (and small) -- just modifying the message to display the filesystem path (instead of the device number) and making it zone

Re: [zones-discuss] Code Review for 6613349 setuid not allowed message could be more useful

2008-11-12 Thread Jason King
On Wed, Nov 12, 2008 at 12:46 PM, [EMAIL PROTECTED] wrote: I'm looking for reviewers for '6613349 setuid not allowed message could be more useful'. I've tested it on a b101 system without any issues. It's pretty straightforward (and small) -- just modifying the message to display the

Re: [zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-12 Thread Tommy McNeely
Well, I forgot to mention that we were using S10u6, but the idea I had was to apply the filter rules in the global zone. As far as I can tell, crossbow is not integrated with NV or OS either :) It looks like we are going to need to somehow wrapper it, or put the entire ipf.conf for all zones

Re: [zones-discuss] chroot env into zone

2008-11-12 Thread Tommy McNeely
Start with a real minimal build of Solaris, build a sparse zone. The zones then take ~200MB. No, its not a CHROOT, but you can chroot apps that support it (named) within the zone so that there is absolutely nothing that can be accessed if it somehow is broken... but the minimal install should

Re: [zones-discuss] ipfilter (ipf.conf) entries in zonecfg?

2008-11-12 Thread Tommy McNeely
I have about 50-60 zones spread across 3 security contexts ;) ~tommy On Nov 12, 2008, at 6:38 PM, Ha Bailey wrote: Have you considered Trusted Extensions? As long as you do not need multiple zones of the same security context on the same physical server, it might work out for you. (in

Re: [zones-discuss] Somewhat unusual exclusive-IP type configuration needed

2008-11-12 Thread Joe Barbey
Steffen Weiberle wrote: On 10/20/08 10:58, Joe Barbey wrote: Hi all, I've got a situation that doesn't seem to be really covered in the various docs I've read up to now. I have a number of servers where I want to do something like the following, if possible. Any help would be greatly

Re: [zones-discuss] static routes vs default routes (zones in different subnets)

2008-11-12 Thread Nicolas Dorfsman
Hi all, I'm pleased to read I'm not the sole victim of what I'm calling the solaris zone route bug. Please take a look below to my comment. Le 10 nov. 08 à 17:51, Tommy McNeely a écrit : On Nov 10, 2008, at 7:09 AM, Paul Kraus wrote: On Sun, Nov 9, 2008 at 10:34 PM, Tommy