All of lore.kernel.org
 help / color / mirror / Atom feed
* netns : close all sockets at unshare ?
@ 2007-10-02 21:45 Daniel Lezcano
       [not found] ` <4702BBF4.60903-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
  0 siblings, 1 reply; 6+ messages in thread
From: Daniel Lezcano @ 2007-10-02 21:45 UTC (permalink / raw)
  To: Eric W. Biederman; +Cc: Linux Containers

Hi,

I was looking at some cornercases and trying to figure out what happens 
if someone does:

1 - fd = socket(...)
2 - unshare(CLONE_NEWNET)
3 - bind(fd, ...) / listen(fd, ...)

There is here an interaction between two namespaces.
Trying to catch all these little tricky paths everywhere with the 
network namespace is painful, perhaps we should consider a more radical 
solution.

Shall we close all fd sockets when doing an unshare ? like a 
close-on-exec behavior ?

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2007-10-04 15:27 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-10-02 21:45 netns : close all sockets at unshare ? Daniel Lezcano
     [not found] ` <4702BBF4.60903-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
2007-10-02 22:38   ` Eric W. Biederman
     [not found]     ` <m14ph9i1l3.fsf-T1Yj925okcoyDheHMi7gv2pdwda3JcWeAL8bYrjMMd8@public.gmane.org>
2007-10-03  8:40       ` Daniel Lezcano
     [not found]         ` <47035591.4030300-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
2007-10-03 16:59           ` Eric W. Biederman
     [not found]             ` <m1r6kccexw.fsf-T1Yj925okcoyDheHMi7gv2pdwda3JcWeAL8bYrjMMd8@public.gmane.org>
2007-10-03 19:33               ` Daniel Lezcano
2007-10-04 15:27               ` Cedric Le Goater

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.