From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755214AbcETQSV (ORCPT ); Fri, 20 May 2016 12:18:21 -0400 Received: from mail-io0-f196.google.com ([209.85.223.196]:33324 "EHLO mail-io0-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752021AbcETQST (ORCPT ); Fri, 20 May 2016 12:18:19 -0400 Date: Fri, 20 May 2016 09:17:59 -0700 From: Tejun Heo To: James Bottomley Cc: Aleksa Sarai , Li Zefan , Johannes Weiner , Aleksa Sarai , cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, dev@opencontainers.org Subject: Re: [PATCH v4 0/2] cgroup: allow management of subtrees by new cgroup namespaces Message-ID: <20160520161759.GD5632@htj.duckdns.org> References: <1463196000-13900-1-git-send-email-asarai@suse.de> <573F23D0.2030500@suse.de> <20160520152244.GB5632@htj.duckdns.org> <1463758258.8091.3.camel@HansenPartnership.com> <20160520160352.GC5632@htj.duckdns.org> <1463760550.8091.13.camel@HansenPartnership.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1463760550.8091.13.camel@HansenPartnership.com> User-Agent: Mutt/1.6.1 (2016-04-27) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello, James. On Fri, May 20, 2016 at 12:09:10PM -0400, James Bottomley wrote: > I think it's just different definitions. If you take on our definition > of being able to set up a container without any admin intervention, do > you see our problem: we can't get the initial delegation of the > hierarchy. Yeah, I can see the difference but we can't solve that by special casing NS case. This is stemming from the fact that an unpriv application can't create its sub-cgroups without explicit delegation from the root and that has always been an explicit design choice. It's tied to who's responsible for cleanup afterwards and what happens when the process gets migrated to a different cgroup. The latter is an important issue on v1 hierarchies because migrating tasks sometimes is used as a way to control resource distribution. Thanks. -- tejun