Re: (pspace,pid) vs true pid virtualization

From: Dave Hansen
Date: Thu Feb 16 2006 - 12:40:14 EST


On Thu, 2006-02-16 at 15:30 +0100, Herbert Poetzl wrote:
> > - Should a process have some sort of global (on the machine identifier)?
>
> this is mandatory, as it is required to kill any process
> from the host (admin) context, without entering the pid
> space (which would lead to all kind of security issues)

Giving admin processes the ability to enter pid spaces seems like it
solves an entire class of problems, right?. Could you explain a bit
what kinds of security issues it introduces?

-- Dave

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/