HP 9000 Containers A.03.01 on HP Integrity Server Administrator Guide HP-UX 11i v3 (5900-3112, June 2013)
• /var/yp
• All subdirectories of /var/spool except /var/spool/cron
In addition, there might be a requirement to share file system mount points to be accessed from
within the HP 9000 container. For information about how to implement mount point sharing, see
Section 8.5 (page 50).
File system sharing is implemented through LOFS, also known as loop-back mounts, to HP 9000
container directories from corresponding native directories. LOFS mounts are performed as a part
of the HP 9000 container startup. This is enabled by configuring /var/hpsrp/<srp_name>/
etc/fstab. The mount points are critical and must always stay active for the proper functioning
of applications inside the HP 9000 container.
Figure 2 (page 47) shows the file system layout with the HP 9000 classic container configured.
Figure 2 HP-UX 11i v3 Integrity file system configured with HP 9000 classic container
While creating a classic container, the following actions take place:
• Adds HP 9000 users to a login group and that group is granted access to the container using
RBAC with the role SRPlogin-<srp_name>.
• Configures /var/hpsrp/<srp_name>/etc/cmpt/fstab with the loop-back mount points
required to implement directory sharing.
• Backs up /sbin, /dev, and all the shared directories inside the container file system. The
backup directories contain -hp9000 suffixed to their original name.
• Merges files from <hp9000_root>/etc and <hp9000_root>/tcb to the corresponding
directories on the HP-UX 11i v3 system based on heuristics.
• Creates a set of symbolic links in <hp9000_root>/usr/lib/security.
7.2 HP 9000 classic container file system 47