From: Dave Hansen <haveblue@us.ibm.com>
To: Ulrich Drepper <drepper@redhat.com>
Cc: Pavel Emelyanov <xemul@openvz.org>, Ingo Molnar <mingo@elte.hu>,
Linus Torvalds <torvalds@linux-foundation.org>,
Andrew Morton <akpm@linux-foundation.org>,
linux-kernel@vger.kernel.org
Subject: Re: [patch] PID namespace design bug, workaround
Date: Thu, 01 Nov 2007 09:12:28 -0700 [thread overview]
Message-ID: <1193933548.6271.78.camel@localhost> (raw)
In-Reply-To: <4729E936.4040400@redhat.com>
On Thu, 2007-11-01 at 07:56 -0700, Ulrich Drepper wrote:
> Pavel Emelyanov wrote:
> > With this set we'll be able to mark pid namespaces as EXPERIMENTAL
> > or even BROKEN, so nobody will be able to crate them. So can we, please,
> > keep things as they are for now - the appropriate fix will be ready
> > soon.
>
> You sound far too optimistic for my taste. I probably haven't seen the
> proposal you have in mind but everything else I have seen simply doesn't
> work without breaking something.
Yeah, we definitely realize that this inhibits things that were
perfectly fine before.
As Eric mentioned in his reply to your message last year, the primary
goal here is isolation. We'd eventually like to be able to pick a
container up and move it to another system. That's going to be awfully
hard if the container is sharing a resource with a part of the system
which is not moving.
Pid namespaces (along with the others) give us the isolation to keep
these interactions from happening except in a controlled manner,
breaking the ties that might bind it to one particular system.
Think of how many user-visible apis deal with files and filenames.
However, there can certainly be files that are unavailable to certain
processes based on their membership in a particular filesystem
namespaces. In fact, we use chroot() to try and _make_ certain files
unavailable.
-- Dave
next prev parent reply other threads:[~2007-11-01 16:12 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-11-01 14:43 [patch] PID namespace design bug, workaround Ingo Molnar
2007-11-01 14:51 ` Pavel Emelyanov
2007-11-01 14:56 ` Peter Zijlstra
2007-11-01 15:06 ` Pavel Emelyanov
2007-11-01 15:17 ` Ingo Molnar
2007-11-01 15:30 ` Pavel Emelyanov
2007-11-01 14:56 ` Ulrich Drepper
2007-11-01 15:05 ` Pavel Emelyanov
2007-11-02 0:21 ` Ulrich Drepper
2007-11-02 7:55 ` Pavel Emelyanov
2007-11-02 8:04 ` Andrew Morton
2007-11-02 8:14 ` Pavel Emelyanov
2007-11-02 14:05 ` Ulrich Drepper
2007-11-02 14:21 ` Pavel Emelyanov
2007-11-02 15:34 ` Ulrich Drepper
2007-11-02 15:58 ` Pavel Emelyanov
2007-11-02 21:39 ` Theodore Tso
2007-11-03 4:34 ` Ulrich Drepper
2007-11-06 7:49 ` Pavel Emelyanov
2007-11-03 20:01 ` sukadev
2007-11-04 7:17 ` Eric W. Biederman
2007-11-02 17:30 ` Dave Hansen
2007-11-02 17:39 ` Linus Torvalds
2007-11-03 4:02 ` Nicholas Miell
2007-11-03 20:12 ` Ingo Molnar
2007-11-03 22:40 ` Linus Torvalds
2007-11-03 23:55 ` Arjan van de Ven
2007-11-04 0:21 ` david
2007-11-04 10:38 ` [patch] PID namespaces Ingo Molnar
2007-11-04 20:12 ` Dave Hansen
2007-11-05 14:47 ` Denys Vlasenko
2007-11-20 22:53 ` Futexes and network filesystems Er ic W. Biederman
2007-11-21 6:16 ` Kyle Moffett
2007-11-21 6:30 ` Eric W. Biederman
2007-11-01 16:12 ` Dave Hansen [this message]
2007-11-01 14:53 ` [patch] PID namespace design bug, workaround Ulrich Drepper
2007-11-01 15:05 ` Ingo Molnar
2007-11-01 18:57 ` Theodore Tso
2007-11-01 19:53 ` Ingo Molnar
2007-11-02 0:23 ` Ulrich Drepper
2007-11-01 15:02 ` Pavel Emelyanov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1193933548.6271.78.camel@localhost \
--to=haveblue@us.ibm.com \
--cc=akpm@linux-foundation.org \
--cc=drepper@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=torvalds@linux-foundation.org \
--cc=xemul@openvz.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox