[GIT PULL] namespaces related fixes for v4.11-rc1

Eric W. Biederman ebiederm at xmission.com
Thu Feb 23 01:29:45 UTC 2017


Aleksa Sarai <asarai at suse.de> writes:

>> The only known user of this prctl systemd
>> forks all children after the prctl.  So no userspace regressions will
>> occur.
>
> Note that runC and containerd (and thus Docker) as well as cri-o use the prctl
> as well -- to be able to collect exit codes from a non-child process (namely to
> collect the exit code from PID 1 in the container).

Are any of those affected by the change?  I would not expect so.  As it
would require having children or grand children whose exit codes you
don't want to collect.

Eric



More information about the Containers mailing list