From: Daniel Lezcano <dlezcano-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
To: "Serge E. Hallyn" <serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
Cc: Linux Containers
<containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org>
Subject: Re: [PATCH lxc 2/2] lxc-unshare: make CLONE_NEWPID imply CLONE_NEWNS
Date: Tue, 18 May 2010 18:01:52 +0200 [thread overview]
Message-ID: <4BF2B9F0.2080403@fr.ibm.com> (raw)
In-Reply-To: <20100513193447.GA15830-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
On 05/13/2010 09:34 PM, Serge E. Hallyn wrote:
> I would like to also automatically have /proc remounted, but
> that would require digging deeper into lxc_clone.
You should not make that automatically, especially in lxc-clone because
this function is just for cloning a process in a new namespace, nothing
more. We may want to access /proc after cloning, for example to reach
/proc/<pid>/ns/*. The automatic mount, should be done in your child
reaper (like lxc-init), otherwise let the container init to run the
services and mount /proc.
In the case of lxc_unshare, you can add a new option to remount /proc
when there is the pidns or the mountns options.
Otherwise, adding the NEWNS with the NEWPID makes sense for me.
Don't forget lxc_unshare is a simple tool, it is not supposed to replace
lxc-start/lxc-execute, at least it should do a bit more than the
"unshare" command.
> Mind you perhaps having NEWPID imply NEWNS should be done there,
> at src/lxc/namespace.c:lxc_clone anyway. I'm starting here...
> Won't be offended if it's rejected on those grounds :)
>
> Signed-off-by: Serge E. Hallyn<serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
> ---
> src/lxc/lxc_unshare.c | 4 ++++
> 1 files changed, 4 insertions(+), 0 deletions(-)
>
> diff --git a/src/lxc/lxc_unshare.c b/src/lxc/lxc_unshare.c
> index 8db1cb7..8531b59 100644
> --- a/src/lxc/lxc_unshare.c
> +++ b/src/lxc/lxc_unshare.c
> @@ -49,6 +49,7 @@ void usage(char *cmd)
> "\t MOUNT, PID, UTSNAME, IPC, USER, NETWORK\n");
> fprintf(stderr, "\t -u<id> : new id to be set if -s USER is specified\n");
> fprintf(stderr, "\t if -s PID is specified,<command> is mandatory)\n");
> + fprintf(stderr, "\t If -s PID is specified, then -s MOUNT is implied\n");
> _exit(1);
> }
>
> @@ -213,6 +214,9 @@ int main(int argc, char *argv[])
> if (ret)
> usage(argv[0]);
>
> + if (flags& CLONE_NEWPID)
> + flags |= CLONE_NEWNS;
> +
> if (!(flags& CLONE_NEWUSER)&& uid != -1) {
> ERROR("-u<uid> needs -s USER option");
> return 1;
next prev parent reply other threads:[~2010-05-18 16:01 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-05-13 19:34 [PATCH lxc 1/2] lxc-unshare: accept multiple -s options Serge E. Hallyn
[not found] ` <20100513193412.GA15433-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2010-05-13 19:34 ` [PATCH lxc 2/2] lxc-unshare: make CLONE_NEWPID imply CLONE_NEWNS Serge E. Hallyn
[not found] ` <20100513193447.GA15830-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2010-05-18 16:01 ` Daniel Lezcano [this message]
2010-05-18 15:49 ` [PATCH lxc 1/2] lxc-unshare: accept multiple -s options Daniel Lezcano
[not found] ` <4BF2B71A.8020906-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
2010-05-18 16:07 ` Serge E. Hallyn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4BF2B9F0.2080403@fr.ibm.com \
--to=dlezcano-nmtc/0zbporqt0dzr+alfa@public.gmane.org \
--cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
--cc=serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.