[Devel] Re: [RFC] ns containers (v2): namespace entering

Paul Menage menage at google.com
Thu Feb 22 12:49:34 PST 2007


On 2/22/07, Eric W. Biederman <ebiederm at xmission.com> wrote:
>
> Now it is at least worth investigating if you can leak things if you don't
> enter the pid namespace.  If you can not leak things that potentially
> simplifies big chunks of the problem, and we probably don't need the
> intermediate pid namespace, of your suggestion.

If you're happy to have your partially-entered process be viewing the
system pid namespace rather than (container pid namespace) + (self)
then yes, you don't need the intermediate namespace.

Paul
_______________________________________________
Containers mailing list
Containers at lists.osdl.org
https://lists.osdl.org/mailman/listinfo/containers




More information about the Devel mailing list