Quoting Pavel Emelyanov (xemul@openvz.org):That describes the final intent for user namespaces. Currently all they do is provide for separate accounting for the same uid in different user namespaces. To provide actual isolation/security, you would currently want to use an LSM. I'm currently playing with some selinux policy infrastructure to make that easier. So as for the description, for now it should probably read something like: Enable experimental support for user namespaces. This is a function used by container-based virtualisation systems (e.g. vservers). User namespaces are intended to ensure that processes with the same uid which are in different containers are isolated from each other. Currently user namespaces provide separate accounting, while isolation must be provided using SELinux or a custom security module. Answer Y if you require container-based virtualisation like vservers. If unsure, say N. thanks, -serge --
| Jens Axboe | Re: [BUG] New Kernel Bugs |
| KAMEZAWA Hiroyuki | Re: 2.6.24-rc3-mm1 |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| Gerrit Renker | [PATCH 0/37] dccp: Feature negotiation - last call for comments |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Jarek Poplawski | Re: [BUG #12364] Re: HTB - very bad precision? HFSC works fine! 2.6.28 |
| Alexey Dobriyan | Re: [GIT]: Networking |
