logoalt Hacker News

Cells for NetBSD: kernel-enforced, jail-like isolation

20 pointsby akagusutoday at 7:54 PM4 commentsview on HN

Comments

eladxtoday at 8:17 PM

I’ve seen a few posts about security extensions for NetBSD over the past several months and most of them build on top of the kauth(9) and secmodel(9) frameworks. I was one of the people who worked on these about twenty years ago (!) and I just wanted to say it’s heartwarming to see people still find our work useful and valuable today. Thank you. :)

phkamptoday at 9:32 PM

And before anybody speculates too much about Matthias use of "jail-like":

I think this can make a lot of sense, because there are many situations, in particular in embedded systems, where you can and should confine at a much smaller scale than jails are really convenient for.

It will also be interesting to see if "Cells" can make inroads in the territory the original ACL abandoned, because writing the rules was so complex that it amount to parallel meta-anti-software development.

Hat tip to Matthias from here.

akagusutoday at 7:54 PM

Cells for NetBSD is an early-stage but steadily maturing system for lightweight, kernel-enforced isolation on NetBSD.

It closes the operational gap between simple chroot environments and full virtualization platforms such as Xen.

Pay08today at 9:33 PM

I'm far from familiar with Linux, is this very different from cgroups?