Re: [RFC] cgroups: implement device whitelist lsm (v2)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Pavel Emelyanov
Date: Friday, March 14, 2008 - 7:05 am

Serge E. Hallyn wrote:

Thanks!


The way I see this is: cgroups provide a common way to group tasks
and an API for general configuration - that's the controller "face", 
and it's up to the controller to decide where he turns his "back",
IOW where the hooks are placed. For the memory controller - they are
injected directly into the mm code. For this controller, I think it
would be OK to use LSM or about-LSM hooks.


The # of rules usually has a linear dependency on the number of containers
(each of then has to have an access to /dev/null,zero,random at least), so
having 100 containers we will have to scan through a 300-entries list. I'd
vote for a hash table or a radix/binary/rb tree for that. Or any other way
for non-linear search you can provide :)


--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Wed Mar 12, 8:27 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 2:25 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 6:18 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 6:50 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 7:38 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 3:27 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 3:46 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 4:49 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 6:41 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Casey Schaufler, (Thu Mar 13, 7:51 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 2:16 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 2:18 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 2:28 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 6:54 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 6:58 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 6:58 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:00 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 7:05 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:05 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 7:12 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 7:15 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:35 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:37 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:42 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 8:07 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 8:45 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 8:54 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Stephen Smalley, (Fri Mar 14, 9:57 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Sat Mar 15, 5:57 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Sat Mar 15, 5:59 pm)