Why has the device namespace been suggested for Linux when there is a device whitelist controller? [closed]
up vote
0
down vote
favorite
The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev
or otherwise) to particular groups of processes.
However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?
linux linux-kernel cgroups namespace
closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02
Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.
add a comment |
up vote
0
down vote
favorite
The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev
or otherwise) to particular groups of processes.
However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?
linux linux-kernel cgroups namespace
closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02
Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.
add a comment |
up vote
0
down vote
favorite
up vote
0
down vote
favorite
The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev
or otherwise) to particular groups of processes.
However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?
linux linux-kernel cgroups namespace
The device namespace for Linux has been suggested as a new Linux namespace. As far as I know, this namespace would restrict interactions with device files (in /dev
or otherwise) to particular groups of processes.
However, there already exists a device whitelist controller which seemingly does exactly this, so what would the device namespace give that this cgroup controller doesn't give and is there any overlap?
linux linux-kernel cgroups namespace
linux linux-kernel cgroups namespace
asked Nov 22 at 11:48
dippynark
1345
1345
closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02
Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.
closed as primarily opinion-based by Stephen Harris, schily, Romeo Ninov, RalfFriedl, Thomas Nov 22 at 20:02
Many good questions generate some degree of opinion based on expert experience, but answers to this question will tend to be almost entirely based on opinions, rather than facts, references, or specific expertise. If this question can be reworded to fit the rules in the help center, please edit the question.
add a comment |
add a comment |
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes