Revert r221655:

Various people voiced their concerns about these changes.
Until this is resolved, we should use the old version.
This commit is contained in:
Benedict Reuschling 2011-05-08 14:57:01 +00:00
parent 50df342447
commit 0f3f5331e4
Notes: svn2git 2020-12-20 02:59:44 +00:00
svn path=/head/; revision=221665

View File

@ -34,7 +34,7 @@
.\"
.\" $FreeBSD$
.\"
.Dd May 8, 2011
.Dd January 17, 2010
.Dt JAIL 8
.Os
.Sh NAME
@ -431,7 +431,7 @@ command script can be used:
.Bd -literal
D=/here/is/the/jail
cd /usr/src
mkdir -p -m 0700 $D
mkdir -p $D
make world DESTDIR=$D
make distribution DESTDIR=$D
mount -t devfs devfs $D/dev
@ -448,10 +448,6 @@ in the per-jail devfs.
A simple devfs ruleset for jails is available as ruleset #4 in
.Pa /etc/defaults/devfs.rules .
.Pp
Non-superusers in the host system should not be able to access the
jail's files; otherwise an attacker with root access to the jail
could obtain elevated privileges on the host.
.Pp
In many cases this example would put far more in the jail than needed.
In the other extreme case a jail might contain only one file:
the executable to be run in the jail.