In Solaris 10, it was common to have zones created with read-only versions of /usr
, shared from the global zone. This had assorted benefits, one of which was to disallow overwriting of system binaries from the zone.
Solaris 11 zones offer the option of having fixed, or
immutable zones. The typical configuration will lock down all files other than those under clearly volatile filesystems such as /tmp
and /var/tmp
(including local filesystems such as /export/home
).
It is possible to choose from three different types of immutable configurations. They have varying degrees of inhibition, but all of them have the following features in common:
It is no longer possible to install IPS packages
Persistently enabled SMF services cannot be changed
SMF manifests cannot be added from the normal locations
The three individualized types of immutable zones, set through the file-mac-profile
property of zonecfg
are as follows: