Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Process Isolation for NetBSD and OpenBSD, Kristaps Dzonsons

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
5,757
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Apr 19, 2009

Process Isolation for NetBSD and OpenBSD, Kristaps Dzonsons

In NetBSD and OpenBSD, user-land process and process-context isolation is limited to credential cross-checks, file-system chroot and explicit systrace/kauth applications. I'll demonstrate a working mechanism of isolated process trees in branched OpenBSD-4.4 and NetBSD-5.0-beta kernels where an isolated process is started by a system call similar to fork; following that, the child process and its descendants execute in a context isolated from the caller. This system is the continued work of "mult" -- first prototyped in a branched NetBSD-3.1 kernel and isolating all system resources -- pared down to a lightweight, auditable patch of process-only separation for both OpenBSD and NetBSD. I specifically address solutions to performance issues and mechanism design with an eye toward more resources being isolated in the future.

Source: Jason Dixon

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:

Top Comments

  • Unix for nerds. :D

  • @jameswx09 isn't that a bit tautological?

see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • I love FreeBSD and NetBSD for server

  • Very Interesting.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more