All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eric Van Hensbergen <ericvh@gmail.com>
To: Ram <linuxram@us.ibm.com>
Cc: linux-fsdevel@vger.kernel.org,
	Al Viro <viro@parcelfarce.linux.theplanet.co.uk>
Subject: Re: [RFC] User CLONE_NEWNS permission and rlimits
Date: Wed, 20 Apr 2005 07:47:55 -0500	[thread overview]
Message-ID: <a4e6962a05042005476c69a2e@mail.gmail.com> (raw)
In-Reply-To: <1113961818.4920.90.camel@localhost>

On 4/19/05, Ram <linuxram@us.ibm.com> wrote:
> On Tue, 2005-04-19 at 18:24, Eric Van Hensbergen wrote:
> >
> > Is this sufficient to cover any exposure?  What's the correct solution
> > for the shared sub-trees RFC?  Should there be something similar for
> > user mounts/binds?
> 
> A new namespace in a shared subtree realm can create number-of-
> private-namespaces number of mounts or binds depending on the number of
> binds and mounts in the shared tree.
> 
> for example if  there were 10 shared vfsmounts in the original
> namespace, a new private namespace will duplicate 10 of these, and
> any mount or bind attempted in any of these vfsmounts will double the
> number of mounts and binds.
> 
> Hence probably you may want to keep a tab on the number mounts and
> binds a user does, instead of keeping a tab on the number of namespaces
> a user creates.
> 

Yeah, that does make a lot more sense, I suppose in the worst case a
user is guaranteed to not have more namespaces than processes anyways.
 So, should the count of mounts be inclusive of mounts the user
inherits, or only the ones he creates?  I suppose as a resource limit,
it should probably cover both.

         -eric

  parent reply	other threads:[~2005-04-20 12:47 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-04-20  1:24 [RFC] User CLONE_NEWNS permission and rlimits Eric Van Hensbergen
2005-04-20  1:50 ` Ram
2005-04-20  3:02   ` Ritesh Kumar
2005-04-20  3:20     ` Al Viro
2005-04-20  3:38       ` Ritesh Kumar
2005-04-20  4:01         ` Al Viro
2005-04-20 18:03     ` Bryan Henderson
2005-04-20 18:37       ` Ritesh Kumar
2005-04-20 12:47   ` Eric Van Hensbergen [this message]
2005-04-20 17:07     ` Ram

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a4e6962a05042005476c69a2e@mail.gmail.com \
    --to=ericvh@gmail.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linuxram@us.ibm.com \
    --cc=viro@parcelfarce.linux.theplanet.co.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.