Why has the device namespace been suggested for Linux when there is a device whitelist controller? [closed]











up vote
0
down vote

favorite












The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev or otherwise) to particular groups of processes.



However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?










share|improve this question













closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02


Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.



















    up vote
    0
    down vote

    favorite












    The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev or otherwise) to particular groups of processes.



    However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?










    share|improve this question













    closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02


    Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.

















      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev or otherwise) to particular groups of processes.



      However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?










      share|improve this question













      The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev or otherwise) to particular groups of processes.



      However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?







      linux linux-kernel cgroups namespace






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 22 at 11:48









      dippynark

      1345




      1345




      closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02


      Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.






      closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02


      Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.





























          active

          oldest

          votes






















          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes

          Popular posts from this blog

          Morgemoulin

          Scott Moir

          Souastre