[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <57271EA8.5080104@suse.de>
Date: Mon, 2 May 2016 19:32:24 +1000
From: Aleksa Sarai <asarai@...e.de>
To: Tejun Heo <tj@...nel.org>, Li Zefan <lizefan@...wei.com>,
Johannes Weiner <hannes@...xchg.org>
Cc: cgroups@...r.kernel.org, linux-kernel@...r.kernel.org,
dev@...ncontainers.org, Aleksa Sarai <cyphar@...har.com>
Subject: Re: [PATCH v2] cgroup: allow management of subtrees by new cgroup
namespaces
> + * 3. cgroup core doesn't allow tasks to be migrated by users that have
> + * write access to two subtrees unless they also have write access to
> + * the common ancestor of the two subtrees. Thus you cannot use a
> + * complicit process in less restrictive cgroup to overcome your own
> + * cgroup restriction.
It appears this restriction isn't actually being applied on cgroupv1.
I'll send an updated patch which makes sure the cgroup.proc common
ancestor restriction is enforced for all hierarchies.
--
Aleksa Sarai
Software Engineer (Containers)
SUSE Linux GmbH
https://www.cyphar.com/
Powered by blists - more mailing lists