@kaveman Thank you so much for mentioning my little experiment with bringing Jails to NetBSD here - I really appreciate it.
In the meantime I’ve brought it to a somewhat usable state (at least in its core) and experimented with some interesting - though highly experimental - integration paths with UVM and NPF.
I’m currently thinking about what the best next step would be. One idea is a stripped-down version that complements the kernel code - essentially just secmodel_jail+kauth+jailctl+jailmgr, but without UVM and without NPF integration - possibly as a pkgsrc package?
The current experimental state is described here:
https://www.petermann-digital.de/blog/netbsd-secmodel_jail-update/
(Sorry - at the moment it’s available in German only.)
