| Commit message (Expand) | Author | Age | Files | Lines |
* | Change the way rctl interfaces with jails by introducing prison_racct | Edward Tomasz Napierala | 2011-05-03 | 1 | -1/+12 |
* | Add racct. It's an API to keep per-process, per-jail, per-loginclass | Edward Tomasz Napierala | 2011-03-29 | 1 | -1/+6 |
* | - Merge changes to the base system to support OFED. These include | Jeff Roberson | 2011-03-21 | 1 | -1/+1 |
* | Add ip4.saddrsel/ip4.nosaddrsel (and equivalent for ip6) to control | Bjoern A. Zeeb | 2010-01-17 | 1 | -0/+6 |
* | Throughout the network stack we have a few places of | Bjoern A. Zeeb | 2009-12-13 | 1 | -0/+1 |
* | Make it possible to change the vnet sysctl variables on jails | Bjoern A. Zeeb | 2009-08-13 | 1 | -0/+1 |
* | Some jail parameters (in particular, "ip4" and "ip6" for IP address | Jamie Gritton | 2009-07-25 | 1 | -7/+17 |
* | Clean up struct prison, with the recent fields in more logical places, | Jamie Gritton | 2009-06-24 | 1 | -13/+15 |
* | Add a limit for child jails via the "children.cur" and "children.max" | Jamie Gritton | 2009-06-23 | 1 | -4/+21 |
* | Manage vnets via the jail system. If a jail is given the boolean | Jamie Gritton | 2009-06-15 | 1 | -0/+2 |
* | Rename the host-related prison fields to be the same as the host.* | Jamie Gritton | 2009-06-13 | 1 | -3/+3 |
* | Add counterparts to getcredhostname: | Jamie Gritton | 2009-06-13 | 1 | -1/+4 |
* | Place hostnames and similar information fully under the prison system. | Jamie Gritton | 2009-05-29 | 1 | -0/+6 |
* | Add support for the arbitrary named jail parameters used by jail_set(2) | Jamie Gritton | 2009-05-27 | 1 | -13/+5 |
* | Add hierarchical jails. A jail may further virtualize its environment | Jamie Gritton | 2009-05-27 | 1 | -18/+97 |
* | Move the per-prison Linux MIB from a private one-off pointer to the new | Jamie Gritton | 2009-05-07 | 1 | -1/+1 |
* | Add a constant PR_MAXMETHOD to better define the jail/OSD interface. | Jamie Gritton | 2009-05-05 | 1 | -0/+1 |
* | Introduce the extensible jail framework, using the same "name=value" | Jamie Gritton | 2009-04-29 | 1 | -11/+61 |
* | With the permission of phk@ change the license on remaining jail code | Jamie Gritton | 2009-04-29 | 1 | -6/+23 |
* | Whitespace/spelling fixes in advance of upcoming functional changes. | Jamie Gritton | 2009-03-27 | 1 | -6/+5 |
* | Remove obsolete prison_service declarations. | Jamie Gritton | 2009-02-17 | 1 | -16/+0 |
* | Don't allow creating a socket with a protocol family that the current | Jamie Gritton | 2009-02-05 | 1 | -0/+1 |
* | For consistency with prison_{local,remote,check}_ipN rename | Bjoern A. Zeeb | 2009-01-25 | 1 | -2/+2 |
* | MFp4: | Bjoern A. Zeeb | 2008-11-29 | 1 | -7/+80 |
* | Update ZFS from version 6 to 13 and bring some FreeBSD-specific changes. | Pawel Jakub Dawidek | 2008-11-17 | 1 | -2/+7 |
* | Revert rev. 178124 as requested by kris@. Having jail id not being | Xin LI | 2008-06-19 | 1 | -0/+2 |
* | Instead of rolling our own jail number allocation procedure, use | Xin LI | 2008-04-11 | 1 | -2/+0 |
* | Implement functionality I called 'jail services'. | Pawel Jakub Dawidek | 2007-04-05 | 1 | -1/+19 |
* | Make prison_find() globally accessible. | Pawel Jakub Dawidek | 2007-04-05 | 1 | -0/+1 |
* | Add a new priv(9) kernel interface for checking the availability of | Robert Watson | 2006-11-06 | 1 | -0/+1 |
* | Rename sysctl security.jail.getfsstatroot_only to security.jail.enforce_statfs | Pawel Jakub Dawidek | 2005-06-09 | 1 | -1/+4 |
* | Make prison structure visible from userland if _WANT_PRISON is defined | Pawel Jakub Dawidek | 2005-03-20 | 1 | -1/+5 |
* | Add a new sysctl, "security.jail.chflags_allowed", which controls the | Colin Percival | 2005-02-08 | 1 | -0/+1 |
* | /* -> /*- for license, minor formatting changes | Warner Losh | 2005-01-07 | 1 | -1/+1 |
* | Correct mutexes names in comment. | Pawel Jakub Dawidek | 2004-11-24 | 1 | -2/+2 |
* | Give jail(8) the feature to allow raw sockets from within a | Bosko Milekic | 2004-04-26 | 1 | -0/+1 |
* | By default, when a process in jail calls getfsstat(), only return the | Robert Watson | 2004-02-14 | 1 | -0/+3 |
* | Defer the vrele() on a jail's root vnode reference from prison_free() | Robert Watson | 2004-01-23 | 1 | -1/+3 |
* | o In struct prison, add an allprison linked list of prisons (protected | Mike Barcroft | 2003-04-09 | 1 | -0/+20 |
* | Include <sys/queue.h> so that this file provides its own namespace | Bruce Evans | 2002-05-06 | 1 | -0/+1 |
* | Remove __P | Alfred Perlstein | 2002-03-19 | 1 | -10/+10 |
* | Make getcredhostname() take a buffer and the buffer's size | Robert Drehmel | 2002-02-27 | 1 | -1/+1 |
* | Add a function which returns the correct hostname for a given | Robert Drehmel | 2002-02-27 | 1 | -0/+1 |
* | o Introduce pr_mtx into struct prison, providing protection for the | Robert Watson | 2001-12-03 | 1 | -8/+17 |
* | o Introduce pr_securelevel, which holds a per-jail securelevel. | Robert Watson | 2001-09-26 | 1 | -0/+1 |
* | o Move per-process jail pointer (p->pr_prison) to inside of the subject | Robert Watson | 2001-02-21 | 1 | -1/+17 |
* | o Deny access to System V IPC from within jail by default, as in the | Robert Watson | 2000-10-31 | 1 | -0/+1 |
* | o Modify jail to limit creation of sockets to UNIX domain sockets, | Robert Watson | 2000-06-04 | 1 | -0/+1 |
* | Yet-another-update: rename ``kern.prison'' to a new sysctl root entry, | Robert Watson | 2000-02-12 | 1 | -1/+1 |
* | Fix sysctl namespace for jail: move the kern.jailcansethostname to | Robert Watson | 2000-02-10 | 1 | -0/+5 |