Thinking about this some more. What is especially attractive if we do
all namespaces this way is that it solves two lurking problems.
1) How do you keep a namespace around without a process in it.
2) How do you enter a container.
If we could land the namespaces in the filesystem we could easily
persist them past the point where a process is present in one if we so
choose.
Entering a container would be a matter of replacing your current
namespaces mounts with namespace mounts take from the filesystem.
I expect performance would degrade in practice, but it is tempting
to implement it and run a benchmark and see if we can measure anything.
Eric
--