From mboxrd@z Thu Jan 1 00:00:00 1970 From: Jonathan Corbet Subject: Re: [RFC][PATCH] ns: Syscalls for better namespace sharing control. v2 Date: Wed, 3 Mar 2010 13:29:31 -0700 Message-ID: <20100303132931.11afb659@bike.lwn.net> References: <4B4F24AC.70105@trash.net> <1263481549.23480.24.camel@bigi> <4B4F3A50.1050400@trash.net> <1263490403.23480.109.camel@bigi> <4B50403A.6010507@trash.net> <1263568754.23480.142.camel@bigi> <1266875729.3673.12.camel@bigi> <1266931623.3973.643.camel@bigi> <1266934817.3973.654.camel@bigi> <1266966581.3973.675.camel@bigi> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Cc: Ben Greear , Linux Netdev List , containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org, Netfilter Development Mailinglist , Daniel Lezcano To: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman) Return-path: In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org List-Id: netdev.vger.kernel.org Quick question: > +void set_namespace(unsigned long nstype, void *ns) > +{ > + struct task_struct *tsk = current; > + struct nsproxy *new_nsproxy; > + > + new_nsproxy = create_new_namespaces(0, tsk, tsk->fs); > + switch(nstype) { > + case NSTYPE_NET: > + put_net(new_nsproxy->net_ns); > + new_nsproxy->net_ns = get_net(ns); > + break; > + } > + > + switch_task_namespaces(tsk, new_nsproxy); > +} I assume that, at some future point when more than one namespace type is supported, there will be a check to ensure that the type of the given namespace matches nstype? I can imagine all kinds of mayhem that could result in the case of an accidental (or intentional) mismatch. Actually, why does setns() require the nstype parameter at all? A namespace fd is certainly going to have to know what sort of namespace it represents... Thanks, jon