On Tue, Jun 14, 2011 at 01:55:08PM +0200, Denys Vlasenko wrote: > With sufficient amount of nutty hackery it may be possible to figure is > out, but it will be either racy, or will require labeling (process > groups? session ids? cgroups?) which, in general, is not reliable: > processes can escape from that. > Cgroups. And it is reliable. And processes cannot escape it. That's part of why Cgroups were created, because all of the other options you mentioned have precisely the flaw you point out. Cgroups does not. --CJD -- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel