Subject: Re: replace chroot() with a chroot overlay file system?
To: None <tech-security@NetBSD.org>
From: Matthias Scheler <tron@zhadum.de>
List: tech-security
Date: 11/07/2005 08:23:26
On Mon, Nov 07, 2005 at 08:09:47AM +0000, Matthias Scheler wrote:
> Zones are virtual hosts sharing a single kernel. The global zone (the
> real system) has full access rights to everything, all the other so
> called local zones are restricted. They are e.g. trapped in a sub
> directory of the filesystem space, cannot configure network interfaces
> and don't see other zones. Each local zones gets one or more
> IP addresses configured in the global zone for network connectivity.
> Although all zones share one network stack they are limitted to using
> their own IP addresses and have seperate TCP and UDP port spaces.

Here is the link to Sun's documentation about it:

	http://www.sun.com/software/solaris/ds/utilization.jsp

	Kind regards

-- 
Matthias Scheler                                  http://scheler.de/~matthias/