Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751388AbWBPRmZ (ORCPT ); Thu, 16 Feb 2006 12:42:25 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751356AbWBPRmZ (ORCPT ); Thu, 16 Feb 2006 12:42:25 -0500 Received: from e2.ny.us.ibm.com ([32.97.182.142]:7623 "EHLO e2.ny.us.ibm.com") by vger.kernel.org with ESMTP id S1751388AbWBPRmZ (ORCPT ); Thu, 16 Feb 2006 12:42:25 -0500 Subject: Re: (pspace,pid) vs true pid virtualization From: Dave Hansen To: Herbert Poetzl Cc: "Eric W. Biederman" , "Serge E. Hallyn" , Kirill Korotaev , linux-kernel@vger.kernel.org, vserver@list.linux-vserver.org, Alan Cox , Arjan van de Ven , Suleiman Souhlal , Hubertus Franke , Cedric Le Goater , Kyle Moffett , Greg , Linus Torvalds , Andrew Morton , Greg KH , Rik van Riel , Alexey Kuznetsov , Andrey Savochkin , Kirill Korotaev , Andi Kleen , Benjamin Herrenschmidt , Jeff Garzik , Trond Myklebust , Jes Sorensen In-Reply-To: <20060216143030.GA27585@MAIL.13thfloor.at> References: <20060215145942.GA9274@sergelap.austin.ibm.com> <20060216143030.GA27585@MAIL.13thfloor.at> Content-Type: text/plain Date: Thu, 16 Feb 2006 09:41:32 -0800 Message-Id: <1140111692.21383.2.camel@localhost.localdomain> Mime-Version: 1.0 X-Mailer: Evolution 2.4.1 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 751 Lines: 18 On Thu, 2006-02-16 at 15:30 +0100, Herbert Poetzl wrote: > > - Should a process have some sort of global (on the machine identifier)? > > this is mandatory, as it is required to kill any process > from the host (admin) context, without entering the pid > space (which would lead to all kind of security issues) Giving admin processes the ability to enter pid spaces seems like it solves an entire class of problems, right?. Could you explain a bit what kinds of security issues it introduces? -- Dave - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/