on 2012/11/17 00:35, Eric W. Biederman wrote: > From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx> > > Set nr_hashed to -1 just before we schedule the work to cleanup proc. > Test nr_hashed just before we hash a new pid and if nr_hashed is < 0 > fail. > > This guaranteees that processes never enter a pid namespaces after we > have cleaned up the state to support processes in a pid namespace. > > Currently sending SIGKILL to all of the process in a pid namespace as > init exists gives us this guarantee but we need something a little > stronger to support unsharing and joining a pid namespace. > > Acked-by: "Serge E. Hallyn" <serge@xxxxxxxxxx> > Signed-off-by: Eric W. Biederman <ebiederm@xxxxxxxxxxxx> > --- Acked-by: Gao feng <gaofeng@xxxxxxxxxxxxxx> _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linuxfoundation.org/mailman/listinfo/containers