Re: [RFC][PATCH] cgroup: Add new capability to allow a process to migrate other tasks between cgroups

From: Tejun Heo
Date: Wed Oct 05 2016 - 11:27:32 EST


Hello,

On Tue, Oct 04, 2016 at 11:25:29PM -0500, Serge E. Hallyn wrote:
> > > If anything I'd say the GLOBAL_ROOT_UID check could be taken out since
> > > otherwise a host-root task effectively cannot drop this capability.
> >
> > Is this ok to leave for a separate patch?
>
> Yeah. And I'm not sure whether Tejun would object to that idea.

With the capability, I think it'd be better to get rid of the explicit
UID check, but can we please rename the cap to CAP_CGROUP_MIGRATE and
loop in linux-api mailing list and ppl who are more familiar with
CAPs?

Thanks!

--
tejun