[lxc-devel] CGroup Namespaces (v10)
Serge E. Hallyn
serge at hallyn.com
Fri Feb 12 23:22:21 UTC 2016
On Fri, Feb 12, 2016 at 11:09:06AM -0500, Tejun Heo wrote:
> On Fri, Feb 12, 2016 at 12:18:28AM +0100, Alban Crequy wrote:
> > I just noticed commit c38c4597e4bf ("netfilter: implement xt_cgroup
> > cgroup2 path match") which, as far as I understand, introduces a new
> > userland facing API containing the full cgroup path. Does it mean that
> > the cgroupns patchset should include cgroup path translation in
> > xt_cgroup?
> I don't think so. None of netfilter configuration is namespaced in
> any way. They're system-global by nature.
I assume at some point you'll want the set ported onto for-4.6 or
linux-next? My 2016-02-03/cgns set still cherrypick cleanly onto
for-4.6 at the moment, but I haven't tried linux-next, and I haven't
done build+test since 4.5-rc1 came out.
More information about the Containers