archive mirror
 help / color / mirror / Atom feed
From: Kirill Tkhai <>
Subject: [PATCH v3 0/2] Expose task pid_ns_for_children to userspace
Date: Wed, 3 May 2017 13:32:14 +0300	[thread overview]
Message-ID: <149380742825.3812.2073418607639032138.stgit@localhost.localdomain> (raw)

pid_ns_for_children set by a task is known only to the task itself,
and it's impossible to identify it from outside.

It's a big problem for checkpoint/restore software like CRIU,
because it can't correctly handle tasks, that do setns(CLONE_NEWPID)
in proccess of their work. If they have a custom pid_ns_for_children
before dump, they must have the same ns after restore. Otherwise,
restored task bumped into enviroment it does not expect.

This patchset solves the problem. It exposes pid_ns_for_children
to ns directory in standard way with the name "pid_for_children":

~# ls /proc/5531/ns -l | grep pid
lrwxrwxrwx 1 root root 0 Jan 14 16:38 pid -> pid:[4026531836]
lrwxrwxrwx 1 root root 0 Jan 14 16:38 pid_for_children -> pid:[4026532286]

v3: Check child_reaper without tasklist_lock as we are only interested
in the fact it's not zero, and not in a specific value.

v2: Do not allow to take a pid namespace, if there is no child reaper
created. This prevents race between creation of the child reaper and
other tasks.


Kirill Tkhai (2):
      ns: Allow ns_entries to have custom symlink content
      pidns: Expose task pid_ns_for_children to userspace

 fs/nsfs.c               |    4 +++-
 fs/proc/namespaces.c    |    1 +
 include/linux/proc_ns.h |    2 ++
 kernel/pid_namespace.c  |   28 ++++++++++++++++++++++++++++
 4 files changed, 34 insertions(+), 1 deletion(-)

Signed-off-by: Kirill Tkhai <>

             reply	other threads:[~2017-05-03 10:32 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-05-03 10:32 Kirill Tkhai [this message]
     [not found] ` <149380742825.3812.2073418607639032138.stgit-bi+AKbBUZKY6gyzm1THtWbp2dZbC/>
2017-05-03 10:32   ` [PATCH v3 1/2] ns: Allow ns_entries to have custom symlink content Kirill Tkhai
2017-05-03 10:32   ` [PATCH v3 2/2] pidns: Expose task pid_ns_for_children to userspace Kirill Tkhai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=149380742825.3812.2073418607639032138.stgit@localhost.localdomain \ \ \
    --cc=akpm-de/ \ \
    --cc=ebiederm-aS9lmoZGLiVWk0Htik3J/ \ \ \ \ \ \ \ \ \ \ \ \
    --cc=viro-RmSDqhL/ \

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).