linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Containers over 9p in 3.14
@ 2014-05-20 17:03 Alin Dobre
  2014-05-21  6:52 ` [V9fs-developer] " Dominique Martinet
       [not found] ` <537B8AFA.4080303-1hSFou9RDDldEee+Cai+ZQ@public.gmane.org>
  0 siblings, 2 replies; 6+ messages in thread
From: Alin Dobre @ 2014-05-20 17:03 UTC (permalink / raw)
  To: linux-fsdevel-u79uwXL29TY76Z2rM5mHXA,
	containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA,
	v9fs-developer-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f,
	Eric W. Biederman, Eric Van Hensbergen

Hello,

We are using 9p to run containers on top of remote filesystems, and it
works correctly using the 3.13.11 kernel. However, there were a bunch of
updates in the fs/9p area in 3.14 which seem to have broken the
namespaces support for containers.

A simple description of how we run the container over 9p is:
- on the remote source host we run diod as 9p server
- on the local host we mount the filesystem in /some/path
- also locally, we run
  contain /some/path /bin/bash

In 3.14 (3.14.4 to be exact), the contain command can no longer mount
the dev filesystem via mount("tmpfs", "dev", "tmpfs", 0, "mode=0755")
after unsharing IPC, NS, USER, UTS and NET, but before unsharing PID.
The above call returns an EPERM. You can look at the very simple code in
contain.c and mount.c at [1].

This call used to work fine in 3.13. I haven't tried to bisect and find
out the exact patch that introduces the problem, but it's one of "git
log --oneline b26d4cd.. fs/9p".

I can provide you with any additional information that might be needed.

Thank you for any feedback.

Cheers,
Ailn.

[1] https://github.com/arachsys/containers

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2014-05-21 21:15 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-05-20 17:03 Containers over 9p in 3.14 Alin Dobre
2014-05-21  6:52 ` [V9fs-developer] " Dominique Martinet
2014-05-21  8:02   ` [PATCH] 9P: fix return value in v9fs_fid_xattr_set Dominique Martinet
2014-05-21 13:14     ` Alin Dobre
2014-05-21  8:07   ` [V9fs-developer] Containers over 9p in 3.14 Alin Dobre
     [not found] ` <537B8AFA.4080303-1hSFou9RDDldEee+Cai+ZQ@public.gmane.org>
2014-05-21 21:15   ` Eric W. Biederman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).