i'm not sure xinetd's position on adding support for OS-specific features, but Linux namespaces are a very powerful tool that can help provide security. Solaris/FreeBSD have semi-equiv functionality called jails.
on the Linux side, you can spawn each new process in a unique mount/user/network/process/shared memory namespace so that the child cannot access resources of other processes, and any changes it happens to make (via exploits?) are lost when it exits.
it can be hacked around if you have a recent util-linux package, but it'd be nicer if xinetd supported it directly.
server = /usr/bin/unshare
server_args = -muin -- /your/program
i'm not sure xinetd's position on adding support for OS-specific features, but Linux namespaces are a very powerful tool that can help provide security. Solaris/FreeBSD have semi-equiv functionality called jails.
on the Linux side, you can spawn each new process in a unique mount/user/network/process/shared memory namespace so that the child cannot access resources of other processes, and any changes it happens to make (via exploits?) are lost when it exits.
it can be hacked around if you have a recent util-linux package, but it'd be nicer if xinetd supported it directly.