All of lore.kernel.org
 help / color / mirror / Atom feed
* Containers don't handle keys, but should they?
@ 2008-03-14 11:37 David Howells
       [not found] ` <7519.1205494679-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
       [not found] ` <20080314145447.GG9741-6s5zFf/epYLPQpwDFJZrxKsjOiXwFzmk@public.gmane.org>
  0 siblings, 2 replies; 5+ messages in thread
From: David Howells @ 2008-03-14 11:37 UTC (permalink / raw)
  To: containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA
  Cc: dhowells-H+wXaHxf7aLQT0dZR+AlfA,
	akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b


Am I right in thinking that a UID in one container is not necessarily
equivalent to the numerically equivalent UID in another container?

If that's the case then the key management code will need changing as it
assumes all keys belonging to one numeric UID eat out of the same quota and
the numeric UIDs are used in security checks.

Furthermore, processes in one container can access keys created by a process
in another container by ID.  Is this desirable or not?

David

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2008-03-14 16:17 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-03-14 11:37 Containers don't handle keys, but should they? David Howells
     [not found] ` <7519.1205494679-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2008-03-14 11:44   ` Kirill Korotaev
2008-03-14 14:54   ` Serge E. Hallyn
     [not found] ` <20080314145447.GG9741-6s5zFf/epYLPQpwDFJZrxKsjOiXwFzmk@public.gmane.org>
2008-03-14 15:49   ` David Howells
     [not found]     ` <8853.1205509760-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2008-03-14 16:17       ` Serge E. Hallyn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.