Re: [PATCH 0/9] namespaces: Introduction

From: Eric W. Biederman
Date: Mon May 22 2006 - 12:55:32 EST

Yep. I bungle my description pretty badly.

The key points.
- Simply messing with pid == 1 is not enough, you need to filter
which pids are accessible.
- pid isolation by permission checks and pid isolation via
pid visibility are competing implementations.
- pid isolation by permission checks (except for the pid == 1 case)
can currently be implemented with a security module.

