Re: Using fs views to isolate untrusted processes: I need an assistant architect in the USA for Phase I of a DARPA funded linux kernel project

From: Tim Hockin
Date: Wed Aug 25 2004 - 16:20:42 EST


On Wed, Aug 25, 2004 at 04:25:24PM -0400, Rik van Riel wrote:
> > You can think of this as chroot on steroids.
>
> Sounds like what you want is pretty much the namespace stuff
> that has been in the kernel since the early 2.4 days.
>
> No need to replicate VFS functionality inside the filesystem.

When I was at Sun, we talked a lot about this. Mike, does Sun have any
iterest in this?

We found a lot of shortcomings in implementing various namespace-ish
things.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/