linux-only jail possible?

Alexander Leidinger Alexander at
Sun Mar 7 10:35:49 UTC 2010

On Sat, 6 Mar 2010 19:15:12 +0100 Ed Schouten <ed at> wrote:

> I am still in doubt what to do. Maybe we could consider committing a
> patch like this:
> This is a bit more complete. What it does, is that it creates a
> symlink from /proc/%d/fd to /dev/fd, only if the calling process
> matches. Then when you mount fdescfs on /dev/fd, it also does the
> right thing, because it will always readlink() on a character device,
> which also returns an error code.
> Comments, suggestions anyone?

Looks better than the one before. :)


