[Devel] Re: Network virtualization/isolation

Eric W. Biederman ebiederm at xmission.com
Mon Dec 4 07:45:42 PST 2006


Dmitry Mishin <dim at openvz.org> writes:

> On Sunday 03 December 2006 19:00, Eric W. Biederman wrote:
>> Ok.  Just a quick summary of where I see the discussion.
>>
>> We all agree that L2 isolation is needed at some point.
> As we all agreed on this, may be it is time to send patches one-by-one?
> For the beggining, I propose to resend Cedric's empty namespace patch as base 
> for others - it is really empty, but necessary in order to move further.
>
> After this patch and the following net namespace unshare patch will be 
> accepted, I could send network devices virtualization patches for review and 
> discussion.
>
> What do you think?

I think sending out these patches for review sounds great.

For merge order I think enabling the unshare/clone flags to anyone
but developers should be about the last thing we do.

Starting with clone/unshare sounds to me like hitching up the cart
before it is built.

I really need to focus on finishing up the pid namespace, so except
for a little review and conversation I'm not going to help much on the
network side.

Of course I need to mess with unix domain sockets to properly
implement the pid namespace.  Because of the pid credential passing.

Eric




More information about the Devel mailing list