Re: user namespace and fully visible proc and sys mounts

From: Andy Lutomirski
Date: Mon Mar 07 2016 - 19:25:04 EST


On Mon, Mar 7, 2016 at 4:07 PM, Eric W. Biederman <ebiederm@xxxxxxxxxxxx> wrote:
> Andy Lutomirski <luto@xxxxxxxxxxxxxx> writes:
>
>> On a related note, can we *please* find a way to constrain namespace
>> creation in a way that might satisfy the RHEL crowd?
>
> I am not certain to what you are referrring.
>
> As long as folks are willing to work with me I am happy to help design
> and design something that makes things better for everyone. If someone
> pushes hard, suggestes crappy patches, and does not listen to
> constructive feedback I will shoot their patches down (especially when I
> am sick and tired as I have been more than I would like this development
> cycle).

I think we should add some mechanism that will allow the right to
create various namespaces to be constrained in a useful and usable
manner. I'll start a new thread.