¥Ñ©ó¨t²ÎºÞ²z¬O§xÃø¤SÁcº¾ªº¤u§@¡A¦]¦¹¤H̶}µo³\¦h¦n¥Î¤u¨ã¡A ¥HÅýºÞ²z¤u§@§ó¥[²³æ»´ÃP¡C ³o¨Ç§ïµ½³q±`¬OÅý¨t²Î¯à°÷¥H§ó²³æªº¤è¦¡¦w¸Ë¡B ³]©w¡BºûÅ@¡A¦Ó¦³¨Ç§ïµ½¥Ø¼Ð«h¬O¨t²Î¦w¥þªº¥¿½T³]©w¡A¨Ï¨ä¯à¯u¥¿µo´§ì¥»¥Î³~¡A ¦Ó«D³´¤J¦w¥þ·ÀI¤§¤¤¡C
FreeBSD ¨t²Î©Ò´£¨Ñªº¤@ºØ¥Î©ó±j¤Æ¦w¥þªº¤u¨ã´N¬O jail ¡C Jail ¬O¥Ñ Poul-Henning Kamp <phk@FreeBSD.org>
©ó
FreeBSD 4.X ¶}©l¾É¤J¡A¦Ó¦b FreeBSD 5.X
¨ü¨ì³\¦h«¤j§ï¨}¦Ó¶°¤j¦¨¡A¦¨¬°±j¤j¦ÓÆF¬¡ªº¤l¨t²Î¡A¥Ø«e¤´¦b«ùÄò¶}µo¡B
¥H´£°ª¨ä¥i¥Î©Ê¡B®Ä¯à»P¦w¥þ¡C
BSD-like §@·~¨t²Î¦Û 4.2BSD °_§Y´£¨Ñ chroot(2)¡C chroot(8) ¥i¥Î¨ÓÅܧó¤@²Õ process ªº®Ú¥Ø¿ý¦ì¸m¡A ÂǦ¹«Ø¥ß»P¹êÅé¨t²Î¤¤¬Û¹jÂ÷ªº¦w¥þÀô¹Ò¡C ³B©ó chrooted Àô¹Òªº process ·|µLªk¤£¯à¦s¨ú¥@¥~ªºÀɮשθ귽¡C ¥Ñ©ó¦¹¦]¯À¡A ¬G§Y¨Ï§ðÀ»ªÌ§ð¯}¬YÓ³B©ó chroot Àô¹Òªº service¡A¤]¤£¯à§ð¯}¾ãÓ¨t²Î¡C chroot(8) ¹ï©ó¨º¨Ç¤£¤Ó»Ýn¼u©Ê©Î½ÆÂø¤S°ª¯ÅªºÂ²³æÀ³¥Î¦Ó¨¥¬Û·í¦n¥Î¡C ¥t¥~¡A¦b¤Þ¤J chroot ·§©Àªº¹Lµ{¤¤¡A´¿¸gµo²{³\¦h¥i²æ°k chroot Àô¹Òªº¤è¦¡¡A ¾¨ºÞ³o¨Ç°ÝÃD¦b¸û·sª©¥»ªº FreeBSD kernel §¡¤w×¥¿¡A¦ý«Ü©úÅã¦a chroot(2) µ´«D¥Î©ó±j¤Æ¦w¥þªº²z·Q¸Ñ¨M¤è®×¡C ¦]¦¹¡A ¶Õ¥²±o¹ê§@·sªº¤l¨t²Î¨Ó¸Ñ¨M³o¨Ç°ÝÃD¡C
³o´N¬O¬°¦ón¶}µo jail ªº³Ì¥Dnì¦]¡C
Jail ¦b¦UºØ¤è¦¡¤À¶i¦XÀ»¡A§ï¶i¶Ç²Î chroot(2) Àô¹Òªº·§©À¡C ¦b¶Ç²Îªº chroot(2) Àô¹Ò¤¤¡A¥u¨î process ¹ï©óÀɮרt²Îªº¦s¨ú³¡¤À¡A ¦Ó¨t²Î¸ê·½ªº¨ä¥L³¡¤À(¨Ò¦p¨t²Î±b¸¹¡B°õ¦æ¤¤ªº process¡Bºô¸ô¤l¨t²Î)«h¬O¥Ñ chroot process »P host ¨t²Îªº¨ä¥L process ¤@°_¦@¨É¡C Jail ¥H¡yµêÀÀ¤Æ¡z¨ÓÂX®i³o¼Ò«¬¡A¤£³æ¥u¦³Àɮרt²Îªº¦s¨ú¡AÁÙ©µ¦ù¨ì ¨t²Î±b¸¹¡BFreeBSD kernel ªººô¸ô¤l¨t²Î¤Î¨ä¥L¨t²Î¸ê·½ªºµêÀÀ¤Æ¡C Ãö©ó³o¨Ç jail Àô¹Ò¦s¨úªº²Ó·L½Õ±±¡A½Ð°Ñ¾\ Section 15.5¡C
jail ¨ã¦³¤U¦C¥|¶µ¯S¦â¡G
¥Ø¿ý¤l¾ð(directory subtree) ¡X¡X ¤]´N¬O¶i¤J jail ªº°_ÂI¡C ¤@¥¹¶i¤J jail ¤§«á¡Aprocess ´N¤£¦A³Q¤¹³\¸õ¨ì subtree ¥H¥~¡C &¶Ç²Î·|¼vÅT¨ì man.chroot.2; ³Ìªì³]pªº¦w¥þ°ÝÃD¡A´N¤£·|¦A¼vÅT FreeBSD jail¡C
¥D¾÷¦WºÙ(hostname) ¡X¡X ¥Î©ó jail ªº hostname¡C ¥Ñ©ó jail ¥Dn¥Î©óºô¸ôªA°È¡A¦]¦¹Y¦U jail ¬Ò¦³¦WºÙ¡A ¹ï©ó¨t²ÎºÞ²z¤u§@ªºÂ²¤Æ·|¬Û·í¦³®Ä¡C
IP address ¡X¡X ¬O¥Î¨Óµ¹ jail ¨Ï¥Î¡A ¨Ã¥B¦b jail ¥Í©R¶g´Á¤º³£µLªkÅܧó¡C ³q±` jail ªº IP address ¬O²{¦³ºô¥dªº alias address¡A¦ý³o¨Ã¤£¬O¥²¶·ªº¡C
«ü¥O(Command) ¡X¡X ·Ç³Æ¦b jail ¤º°õ¦æªº§¹¾ã¸ô®|¡C ³o«ü¥O¬O¬Û¹ï©ó jail Àô¹Òªº®Ú¥Ø¿ý¡Aµø jail Àô¹ÒªºÃþ«¬¤£¦P¡A¦Ó¦³©Ò®t²§¡C
°£¤F¤Wz¤§¥~¡Ajail ¤]¥i¾Ö¦³¦Û¤vªº±b¸¹¤Î root ±b¸¹¡C ·íµM¡A³o¸Ìªºroot Åv¤O·|¨ü¨î©ó jail Àô¹Ò¤º¡C ¨Ã¥B±q host ¨t²Îªº¨¤«×¨Ó¬Ý¡Ajail ªº root ¨Ã«DµL©Ò¤£¯àªº±b¸¹¡C ¦¹¥~ jail ªº root ¨Ã¤£¯à°õ¦æ¨ä¹ï©ó jail(8) Àô¹Ò¥H¥~ªº¤@¨ÇÃöÁä©Ê¾Þ§@¡C Ãö©ó root ªº¯à¤O»P¨î¡A±N©óµy«áªº Section 15.5 ¤¶²Ð¤§¡C
¥»¤å¤Î¨ä¥L¤å¥ó¡A¥i¥Ñ¦¹¤U¸ü¡Gftp://ftp.FreeBSD.org/pub/FreeBSD/doc/¡C
Y¦³ FreeBSD ¤è±ºÃ°Ý¡A½Ð¥ý¾\Ū FreeBSD ¬ÛÃö¤å¥ó¡A¦p¤£¯à¸Ñ¨Mªº¸Ü¡A¦A¬¢¸ß
<questions@FreeBSD.org>¡C
Ãö©ó¥»¤å¥óªº°ÝÃD¡A½Ð¬¢¸ß <doc@FreeBSD.org>¡C