Re: CLONE_NEWIPC documentation

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eric W. Biederman
Date: Wednesday, November 19, 2008 - 6:16 pm

Michael Kerrisk <mtk.manpages@googlemail.com> writes:



The above sentence is wrong.

+This flag is intended for the implementation of containers.

Would be correct.

Both control groups and namespaces feed into the user space container
concept.  Control groups are multiprocess resource limits.
Namespaces are affect the mapping from resource name to resource.

What is interesting is you can unshare a sysvipc namespace and still have
sysvipc shared memory mapped from another sysvipc namespace.

This is something that needs to be watched for.

Eric
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
CLONE_NEWIPC documentation, Michael Kerrisk, (Wed Nov 19, 12:12 pm)
Re: CLONE_NEWIPC documentation, Eric W. Biederman, (Wed Nov 19, 6:16 pm)
Re: CLONE_NEWIPC documentation, Cedric Le Goater, (Thu Nov 20, 1:36 am)
Re: CLONE_NEWIPC documentation, Michael Kerrisk, (Thu Nov 20, 4:28 am)
Re: CLONE_NEWIPC documentation, Cedric Le Goater, (Thu Nov 20, 5:26 am)
Re: CLONE_NEWIPC documentation, Michael Kerrisk, (Thu Nov 20, 9:28 am)
Re: CLONE_NEWIPC documentation, Serge E. Hallyn, (Sun Nov 23, 3:48 pm)