[Devel] Re: Network virtualization/isolation
Eric W. Biederman
ebiederm at xmission.com
Mon Dec 4 07:45:42 PST 2006
Dmitry Mishin <dim at openvz.org> writes:
> On Sunday 03 December 2006 19:00, Eric W. Biederman wrote:
>> Ok. Just a quick summary of where I see the discussion.
>>
>> We all agree that L2 isolation is needed at some point.
> As we all agreed on this, may be it is time to send patches one-by-one?
> For the beggining, I propose to resend Cedric's empty namespace patch as base
> for others - it is really empty, but necessary in order to move further.
>
> After this patch and the following net namespace unshare patch will be
> accepted, I could send network devices virtualization patches for review and
> discussion.
>
> What do you think?
I think sending out these patches for review sounds great.
For merge order I think enabling the unshare/clone flags to anyone
but developers should be about the last thing we do.
Starting with clone/unshare sounds to me like hitching up the cart
before it is built.
I really need to focus on finishing up the pid namespace, so except
for a little review and conversation I'm not going to help much on the
network side.
Of course I need to mess with unix domain sockets to properly
implement the pid namespace. Because of the pid credential passing.
Eric
More information about the Devel
mailing list