comparison sbin/fjail @ 175:c925150deac8

/var/db/pkg need not to be a separate dataset. It is way more important that /var/cache/pkg is on a separate dataset (because of its size).
author Franz Glasner <hg@dom66.de>
date Tue, 16 Aug 2022 11:13:49 +0200
parents 9b23832722dd
children cf0a91fde79c
comparison
equal deleted inserted replaced
174:9b23832722dd 175:c925150deac8
181 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/audit" 181 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/audit"
182 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/cache" 182 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/cache"
183 zfs create ${_zfsopts} -o exec=off -o setuid=off -o compression=off "${_ds}/var/cache/pkg" 183 zfs create ${_zfsopts} -o exec=off -o setuid=off -o compression=off "${_ds}/var/cache/pkg"
184 zfs create ${_zfsopts} -o exec=off -o setuid=off -o compression=off "${_ds}/var/crash" 184 zfs create ${_zfsopts} -o exec=off -o setuid=off -o compression=off "${_ds}/var/crash"
185 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/db" 185 zfs create ${_zfsopts} -o exec=off -o setuid=off "${_ds}/var/db"
186 zfs create ${_zfsopts} -o exec=on -o setuid=off "${_ds}/var/db/pkg"
187 zfs create ${_zfsopts} -o readonly=on -o exec=off -o setuid=off "${_ds}/var/empty" 186 zfs create ${_zfsopts} -o readonly=on -o exec=off -o setuid=off "${_ds}/var/empty"
188 zfs create ${_zfsopts} -o exec=off -o setuid=off -o primarycache=metadata "${_ds}/var/log" 187 zfs create ${_zfsopts} -o exec=off -o setuid=off -o primarycache=metadata "${_ds}/var/log"
189 zfs create ${_zfsopts} -o exec=off -o setuid=off -o atime=on "${_ds}/var/mail" 188 zfs create ${_zfsopts} -o exec=off -o setuid=off -o atime=on "${_ds}/var/mail"
190 zfs create ${_zfsopts} -o sync=disabled -o exec=off -o setuid=off -o compression=off -o primarycache=all "${_ds}/var/run" 189 zfs create ${_zfsopts} -o sync=disabled -o exec=off -o setuid=off -o compression=off -o primarycache=all "${_ds}/var/run"
191 zfs create ${_zfsopts} -o sync=disabled -o setuid=off "${_ds}/var/tmp" 190 zfs create ${_zfsopts} -o sync=disabled -o setuid=off "${_ds}/var/tmp"