-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chroot because pivot_root manpage says so #12
Comments
pivot_root(2):
This means that using
TODO: verify the above claim experimentally The manpage for |
Apologies for my earlier laconic explanation. What I meant was that pivot_root(2) man page recommends By the way, pivot_root(2):
|
Just found out lxc does the pivot_root thing: https://github.com/lxc/lxc/blob/4faaed332b99e60c0e1eed7dcc697f4fbf4f9441/src/lxc/conf.c#L1496 I still don't approve of this personally. |
Yeah, but pivot_root(8) does. I'm not sure why there is a difference, will need to look into that.
I am aware that the use of This would break some things, require changes elsewhere in the system, and AFAIK would not make any observable behaviour better. Unless I'm missing something. |
I guess a little uncompliance is fine given how often we update the kernel on prod |
I can't help but notice we're not using pivot_root(8) here.
One reason I can think of is that pivot_root(8) is a binary and its execution of this seems to be for the reason mentioned and out of convenience, to break up whatever Links to the Past are left. |
sio2jail/src/ns/MountNamespaceListener.cc
Lines 66 to 67 in 184eda3
no.
The text was updated successfully, but these errors were encountered: