There is one other bit that needs to be documented in clone, although I am not certain where/how. The sequences: unshare(CLONE_NEWPID). clone(CLONE_VM) setns(fd, CLONE_NEWPID). clone(CLONE_VM). Now fail. Basically the rule is all threads must be in the same pid namespace. The joy of reviews with good comments that come much later than hoped. Eric _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linuxfoundation.org/mailman/listinfo/containers