Re: automatic creation of a chroot environment

Mario Marietto <[email protected]> Thu, 16 Jul 2026 14:22:55 +0200
Newsgroups gmane.os.freebsd.devel.hackers
Message-ID <CA+1FSihVVpTnuH8qm6AiRiNHiMAwD5piHknsxbvmNqLbR0s8Fw@mail.gmail.com>
>Would be this valuable one vermaden is issuing weekly.
>URL below is the latest one.
>https://vermaden.wordpress.com/2026/07/13/valuable-news-2026-07-13/

I don't see qemu+vmm. Someone knows if it has been reported and where ?
thanks.

On Thu, Jul 16, 2026 at 2:13 PM Tomoaki AOKI <[email protected]>
wrote:

> Would be this valuable one vermaden is issueing weekly.
> URL below is the latest one.
>
>   https://vermaden.wordpress.com/2026/07/13/valuable-news-2026-07-13/
>
> On Thu, 16 Jul 2026 12:18:18 +0200
> Mario Marietto <[email protected]> wrote:
>
> > ---> Thank You for sharing, I will add this to the next VN.
> >
> > What's VN ? If I remember correctly, did you also add in your VN the
> > project of the virtualization of a Linux/Freebsd vm using qemu
> accelerated
> > with bhyve / vmm ?
> > Can you share the link ? just curious. thanks.
> >
> > ---> 1. How is that better than 'Service Jails'?
> > ---> 2. How is that better than 'Single Process Jails'?
> >
> > Waiting for the replies to those questions for improving the idea.
> Something's
> > cooking in my little head, but I don't know what yet....
> >
> > Mario.
> >
> > On Thu, Jul 16, 2026 at 9:09 AM vermaden <[email protected]> wrote:
> >
> > > Hi,
> > >
> > > > I've been using chroot for a long time to reduce
> > > > the risk of web application hacking on my server.
> > > >
> > > > Some time ago, I decided it was time to automate
> > > > the creation of chroot environments and create a
> > > > universal solution for any application/port that
> > > > would be easily customizable.
> > > >
> > > > For simple applications and ports, it usually works
> > > > with minimal effort, but for complex ones, it takes
> > > > a bit more tinkering.
> > > >
> > > > The current implementation creates a RO chroot,
> > > > without setuid files, with one user and one group.
> > > > All RW locations are mounted with noexec and
> > > > nosuid. This makes escaping such a chroot
> > > > environment extremely difficult, and webshell
> > > > and other PHP hacks become impossible.
> > > >
> > > > I hope someone finds this useful.
> > > >
> > > > https://github.com/rozhuk-im/chroot_env
> > >
> > > Thank You for sharing, I will add this to next VN.
> > >
> > > Two questions out of curiosity ...
> > >
> > > 1. How is that better then 'Service Jails'?
> > >
> > > 2. How is that better then 'Single Process Jails'?
> > >
> > >
> > >
> https://vermaden.wordpress.com/2023/06/28/freebsd-jails-containers/#single-process-jails
> > >
> > > Thanks,
> > > vermaden
> > >
> > >
> > >
> >
> > --
> > Mario.
>
>
> --
> Tomoaki AOKI    <[email protected]>
>
>

-- 
Mario.