All of lore.kernel.org
 help / color / mirror / Atom feed
* how to do not allow to mount /cgroup inside container?
@ 2009-08-25 12:17 Krzysztof Taraszka
       [not found] ` <ac1c4bf20908250517j43d49f9fv1b5d6d5beae8aa-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
  0 siblings, 1 reply; 8+ messages in thread
From: Krzysztof Taraszka @ 2009-08-25 12:17 UTC (permalink / raw)
  To: lxc-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f,
	containers-qjLDD68F18O7TbgM5vRIOg

Hi,

I was looking for possibility to secure lxc container to do not allow 'root
container user'  from changing limits from cgroup. Right now without STACK64
or SELinux he can do this easily.
I read the http://www.ibm.com/developerworks/linux/library/l-lxc-security/cookbook
and decided to use STACK64 kernel mechanism.
Well... mounting cgroup inside container fails (great!, i am looked for that
;)) but networking fails too (interface bring up, sshd bring up, connection
beetween host and container is, but 'mtr', 'ping' even 'apt-get update'
fails and I do not know why). I secure my container exactly like in the
cookbook.

Is there any other possilbility to have secure container without network
problems or any hint now to enable networking with stack64 enabled? If so,
maybe the l-lxc-security cookbook have to updated? Maybe another kernel
patch to do not allow container to mount cgroup when the mount call come
from container?

Any ideas?

-- 
Krzysztof Taraszka

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2009-08-25 20:25 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-25 12:17 how to do not allow to mount /cgroup inside container? Krzysztof Taraszka
     [not found] ` <ac1c4bf20908250517j43d49f9fv1b5d6d5beae8aa-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-08-25 12:47   ` Daniel Lezcano
     [not found]     ` <4A93DD67.5030905-GANU6spQydw@public.gmane.org>
2009-08-25 14:05       ` Serge E. Hallyn
     [not found]         ` <20090825140537.GA19644-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-08-25 14:43           ` Krzysztof Taraszka
     [not found]             ` <ac1c4bf20908250743t9c30c27ud3ff649003465334-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-08-25 14:51               ` Krzysztof Taraszka
2009-08-25 17:45               ` Serge E. Hallyn
     [not found]                 ` <20090825174509.GA26679-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-08-25 20:12                   ` Krzysztof Taraszka
     [not found]                     ` <ac1c4bf20908251312w11ac752vb9298beae15f6536-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-08-25 20:25                       ` Serge E. Hallyn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.