Zones & Process Rights Management?
All processes running in a non-global zone have limited privileges. All the privileges that would allow the non-global administrator to break the isolation concept have been removed from the inheritable privilege set of the zsched daemon, the one that starts all the others. Another privilege, PRIV_PROC_ZONE, is required to be able to signal or control non-global zone processes from the Global zone. [Update Feb 23 06] : a case has been opened in Sun Architecture Commitee by David Comay. “Configurable Privileges for Zones”. In short, it will be possible to configure a non-global zone through zonecfg so that another set of privileges is given to all Processes in this zone. It will be possible to add/remove privileges to/from a non-global Zone depending on whether you want to extend the possibilities/improve the security. Some privileges will be marked “not addable” while others will be “non removable”. This feature does not yet have a release date.