forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
userns: Recommend use of memory control groups.
In the help text describing user namespaces recommend use of memory control groups. In many cases memory control groups are the only mechanism there is to limit how much memory a user who can create user namespaces can use. Acked-by: Serge Hallyn <[email protected]> Signed-off-by: Eric W. Biederman <[email protected]>
- Loading branch information
Showing
2 changed files
with
21 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
There are a lot of kinds of objects in the kernel that don't have | ||
individual limits or that have limits that are ineffective when a set | ||
of processes is allowed to switch user ids. With user namespaces | ||
enabled in a kernel for people who don't trust their users or their | ||
users programs to play nice this problems becomes more acute. | ||
|
||
Therefore it is recommended that memory control groups be enabled in | ||
kernels that enable user namespaces, and it is further recommended | ||
that userspace configure memory control groups to limit how much | ||
memory user's they don't trust to play nice can use. | ||
|
||
Memory control groups can be configured by installing the libcgroup | ||
package present on most distros editing /etc/cgrules.conf, | ||
/etc/cgconfig.conf and setting up libpam-cgroup. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters