From mboxrd@z Thu Jan 1 00:00:00 1970 From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman) Subject: Re: [PATCH] pidns: Limit kill -1 and cap_set_all Date: Mon, 29 Oct 2007 11:59:48 -0600 Message-ID: References: <1193673738.24087.176.camel@localhost> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: In-Reply-To: <1193673738.24087.176.camel@localhost> (Dave Hansen's message of "Mon, 29 Oct 2007 09:02:18 -0700") List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org To: Dave Hansen Cc: linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, Linux Containers , Andrew Morton , Linus Torvalds , Oleg Nesterov , Pavel Emelyanov List-Id: containers.vger.kernel.org Dave Hansen writes: > On Fri, 2007-10-26 at 14:37 -0600, Eric W. Biederman wrote: >> >> +static int pid_in_pid_ns(struct pid *pid, struct pid_namespace *ns) >> +{ >> + return pid && (ns->level <= pid->level) && >> + pid->numbers[ns->level].ns == ns; >> +} > > Could we blow this out a little bit? (I think the blown-out version > lends itself to being better commented, and easier to read.) Also, can > we think of any better name for this? It seems a bit funky that: > > pid_in_pid_ns(mypid, &init_pid_ns); > > would _ever_ return 0. It can't. > So, it isn't truly a test for belonging *in* a > namespace, but having that namespace be the lowest level one. No. It is precisely a test for being in a namespace. We first check ns->level to make certain it doesn't fall out of the array, and then we check to see if the namespace we are looking for is at that level. pid->numbers[0].ns == &init_pid_ns. > I think > Suka toyed with calling it an "active" or "primary" pid namespace. That > differentiated mere membership in a pid namespace from the one that > actually molds that pid's view of the world. What we want for the test is a test for membership. > static int pid_in_pid_ns(struct pid *pid, struct pid_namespace *ns) > { > if (!pid) > return 0; > if (ns->level > pid->level) > return 0; > if (pid->numbers[ns->level].ns != ns) > return 0; > return 1; > } I don't have a problem with that. The rest of the checks for this in kernel/pid.c are in the same form. Eric