Conversation

Jarkko Sakkinen

After fighting with container nesting, I think that this concept would still make sense:

https://lwn.net/Articles/723477/

It's not discussed in the cover letter but obviously this would be much better tool for "full user space nesting" than namespace based containers.

I.e., kind of between Podman and Kata Containers as an infrastructure.
1
0
0
The patch set was rejected on basis of having already namespaces etc. but obviously the need was still there. Otherwise, Arjan van Der Ven and his team would not have put to get clear containers (which came later known as kata containers).

Quite often at least I end up using VM, not for full system emulation but because Podman or similar is not too great "in the edges".
1
0
0

@jarkko I talked to David Howells about it last year at LPC and told him it should be revived. I poked him with a stick earlier this year to remind him of this too.

I really would love to see this available in the kernel because it's just hard to do the right thing otherwise.

1
0
0
@Conan_Kudo yeah, it would have immediate use.

when i read the cover letter, i think the idea is great but the cover letter should talk about user needs (such as nesting related and stuff like that).
1
0
0

Jarkko Sakkinen

Edited 4 days ago
@Conan_Kudo I pinged from David whether he still has a Git branch for this work. No answer yet.

Just would want to try rebase/compile on top of 6.15-rcX, no bandwidth atm :-) BTW, I have channel with David at OFTC called "#linux-security", if you want to hang out there.

It's a total idle channel, for occasional keyring sync ups and stuff like that so except long response times :-) Still, could be forum to sync up with this and random kernel stuff.
1
0
0

@jarkko Just joined and 👋

0
0
1