Re: [RFC][PATCH 5/6] Define helper functions to unshare pid namespace

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



sukadev@xxxxxxxxxx writes:

> From: Sukadev Bhattiprolu <sukadev@xxxxxxxxxx>
> Subject: [RFC][PATCH 5/6] Define helper functions to unshare pid namespace
>
> Define clone_pid_ns() and unshare_pid_ns() functions that will be
> used in the next patch to unshare pid namespace.
>
> Changelog: 
> 	- Rewrite of orignal code in -lxc from Cedric Le Goater to enforce
> 	  setsid() requirement on unshare().

Why do we need a setsid() before we unshare?
I know it is almost always the correct thing to do but what requires
the setsid?

Doing the setsid before we switch pid namespaces appears the wrong
order to me.

I am not convinced that unshare can be done safely for a pid
namespace.  Changing the meaning or definition of pid on a running
process is questionable.

Eric
_______________________________________________
Containers mailing list
Containers@xxxxxxxxxxxxxx
https://lists.osdl.org/mailman/listinfo/containers


[Index of Archives]     [Cgroups]     [Netdev]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Bugtraq]     [Yosemite Forum]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux Admin]     [Samba]

  Powered by Linux