File tree Expand file tree Collapse file tree 1 file changed +24
-1
lines changed
Expand file tree Collapse file tree 1 file changed +24
-1
lines changed Original file line number Diff line number Diff line change @@ -143,12 +143,14 @@ To run Sylve inside a jail environment, allow the permissions below and adjust
143143the settings as shown:
144144
145145``` ucl
146+ devfs_ruleset=5;
146147allow.vmm;
147148allow.nfsd;
148149allow.mount;
149150allow.mount.zfs;
150151zfs.dataset="tank/sylve";
151152enforce_statfs=1;
153+ children.max="100";
152154vnet;
153155
154156# For Samba
@@ -161,9 +163,30 @@ exec.prestop += "zfs unjail ${name} tank/sylve";
161163exec.prestop += "zfs jailed=off tank/sylve";
162164```
163165
164- Note :
166+ Notes :
165167
166168* Replace ` tank/sylve ` with your desired ZFS dataset.
169+ * Replace ` 100 ` in ` children.max ` with your desired number of maximum hierarchial jails.
170+ * Replace your ` devfs_ruleset ` number based on your own custom rules.
171+ * Add your own desired interface to ` vnet.interface ` .
172+
173+ ### devfs ruleset
174+
175+ Here is the example for your ` devfs.rules ` file:
176+
177+ ``` devfs
178+ [devfsrules_jail_sylve=6]
179+ add include $devfsrules_hide_all
180+ add include $devfsrules_unhide_basic
181+ add include $devfsrules_unhide_login
182+ add include $devfsrules_jail
183+ add include $devfsrules_jail_vnet
184+ add path 'bpf*' unhide
185+ add path 'vmmctl' unhide
186+ add path 'da*' unhide
187+ add path 'ada*' unhide
188+ add path 'nda*' unhide
189+ ```
167190
168191# Contributing
169192
You can’t perform that action at this time.
0 commit comments