Thread (10 messages) 10 messages, 4 authors, 2010-02-27

Re: [RFC][PATCH] ns: Syscalls for better namespace sharing control.

From: Pavel Emelyanov <hidden>
Date: 2010-02-27 08:30:02
Also in: netfilter-devel

Possibly related (same subject, not in this thread)

Eric W. Biederman wrote:
Pavel Emelyanov [off-list ref] writes:
quoted
quoted
quoted
Yet another set of per-namespace IDs along with CLONE_NEWXXX ones?
I currently have a way to create all namespaces we have with one
syscall. Why don't we have an ability to enter them all with one syscall?
The CLONE_NEWXXX series of bits has been an royal pain to work with,
and it appears to be unnecessary complications for no gain.
That's the answer for the "Yet another set..." question.
How about the "Why don't we have..." one?
I am not certain which question you are asking:

Why don't we have an ability to enter all namespaces with one syscall
invocation?
Exactly. Please add at least the NSTYPE_NSPROXY or whatever, that will
pin all namespaces of a given pid from the very beginning.
Why don't we have a syscall that allows us to enter every namespace?
This one is done in the patch, no?

Although the approach is OK for me, there's one design issue, that came
up to my mind recently: can we use this fd to wail for a namespace to 
stop? I currently don't see this ability, but this is something I require
badly.

Thoughts?
Eric
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help