Print this page
7029 want per-process exploit mitigation features (secflags)
7030 want basic address space layout randomization (aslr)
7031 noexec_user_stack should be a secflag
7032 want a means to forbid mappings around NULL.


 125         pool-level importance.
 126 -->
 127 <!ELEMENT tmp_pool   EMPTY>
 128 
 129 <!ATTLIST tmp_pool   importance      CDATA #REQUIRED>
 130 
 131 <!ELEMENT pset               EMPTY>
 132 
 133 <!ATTLIST pset               ncpu_min        CDATA #REQUIRED
 134                         ncpu_max        CDATA #REQUIRED>
 135 
 136 <!ELEMENT mcap               EMPTY>
 137 
 138 <!ATTLIST mcap               physcap         CDATA #REQUIRED>
 139 
 140 <!ELEMENT admin      EMPTY>
 141 
 142 <!ATTLIST admin      user            CDATA #REQUIRED
 143                         auths           CDATA #REQUIRED>
 144 






 145 <!ELEMENT zone               (filesystem | inherited-pkg-dir | network | device |
 146                         deleted-device | rctl | attr | dataset | package |
 147                         patch | dev-perm | tmp_pool | pset |
 148                         mcap | admin)*>
 149 
 150 <!ATTLIST zone               name            CDATA #REQUIRED
 151                         zonepath        CDATA #REQUIRED
 152                         autoboot        (true | false) #REQUIRED
 153                         ip-type         CDATA ""
 154                         hostid          CDATA ""
 155                         pool            CDATA ""
 156                         limitpriv       CDATA ""
 157                         bootargs        CDATA ""
 158                         brand           CDATA ""
 159                         scheduling-class        CDATA ""
 160                         fs-allowed      CDATA ""
 161                         version         NMTOKEN #FIXED '1'>


 125         pool-level importance.
 126 -->
 127 <!ELEMENT tmp_pool   EMPTY>
 128 
 129 <!ATTLIST tmp_pool   importance      CDATA #REQUIRED>
 130 
 131 <!ELEMENT pset               EMPTY>
 132 
 133 <!ATTLIST pset               ncpu_min        CDATA #REQUIRED
 134                         ncpu_max        CDATA #REQUIRED>
 135 
 136 <!ELEMENT mcap               EMPTY>
 137 
 138 <!ATTLIST mcap               physcap         CDATA #REQUIRED>
 139 
 140 <!ELEMENT admin      EMPTY>
 141 
 142 <!ATTLIST admin      user            CDATA #REQUIRED
 143                         auths           CDATA #REQUIRED>
 144 
 145 <!ELEMENT security-flags     EMPTY>
 146 
 147 <!ATTLIST security-flags             default         CDATA ""
 148                         lower           CDATA ""
 149                         upper           CDATA "">
 150 
 151 <!ELEMENT zone               (filesystem | inherited-pkg-dir | network | device |
 152                         deleted-device | rctl | attr | dataset | package |
 153                         patch | dev-perm | tmp_pool | pset |
 154                         mcap | admin | security-flags)*>
 155 
 156 <!ATTLIST zone               name            CDATA #REQUIRED
 157                         zonepath        CDATA #REQUIRED
 158                         autoboot        (true | false) #REQUIRED
 159                         ip-type         CDATA ""
 160                         hostid          CDATA ""
 161                         pool            CDATA ""
 162                         limitpriv       CDATA ""
 163                         bootargs        CDATA ""
 164                         brand           CDATA ""
 165                         scheduling-class        CDATA ""
 166                         fs-allowed      CDATA ""
 167                         version         NMTOKEN #FIXED '1'>