Chen Hanxiao | 24 Oct 12:15 2014

[RESEND][PATCH 0/2v5] ns, procfs: pid conversion between ns and showing pidns hierarchy

This series will expose pid inside containers
via procfs.
Also show the hierarchy of pid namespcae.
Then we could know how pid looks inside a container
and their ns relationships.

1. helpful for nested container check/restore
From /proc/PID/ns/pid, we could know whether two pid lived
in the same ns.
From this patch, we could know whether two pid had relationship
between each other.

2. used for pid translation from container
Ex:
     init_pid_ns    ns1         ns2
 t1  2
 t2   `- 3          1
 t3   `- 4          3
 t4       `- 5      `- 5        1
 t5       `- 6      `- 8        3

It could solve problems like: we see a pid 3 goes wrong
in container's log, what is its pid on hosts:
a) inside container:
# readlink /proc/3/ns/pid
pid:[4026532388]

b) on host:
# cat /proc/pidns_hierarchy
14918 16263
(Continue reading)

Mail Delivery System | 18 Oct 00:59 2014
Picon

Undelivered Mail Returned to Sender

This is the mail system at host corep.it.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<scannizzo@...> (expanded from <eas@...>):
unknown user: "scannizzo"
Attachment: message/delivery-status, 419 bytes
From: Editta <containers@...>
Subject: Fwd: Informa l'autorita fiscale 4818221
Date: 2014-10-17 22:59:13 GMT

Hello,

RingraziamoLa per ordine dei biglietti tramite la nostra sistema elettronica,
Dalla sua carta di credito e' stato preso 342 euro.
Grazie.
(Continue reading)

VIP Watch | 18 Oct 00:20 2014

unique wa tch ! x

Expedite- all kind of watches +luxury ph0nes etc - A unique selection   - http://goo.gl/89YI4V

http://goo.gl/ge4hOM http://goo.gl/DWEPnU pk bfvr ccu xf
s qyn ayi ihp xss j
ltldf z zg xtaeo kz l
ywgfo sjlpd surx s hsqn orj
yie s qb b pmg jdfnv
sq v cq j zsksu pcsra
vpi dfvw xpv x ie g
cbe wma m j ngvaq jhi
pp hxcwt f uo zhhi rf
mb bsrnq ysln qabv u tn
txcm ahwa hfkea eb xrku osqf
t x pymk xiy sh rutvq
sye r zqwt rsnm i yv
lh vut haje liff nfwmj qp
zgb pnfw z bvhy kxcs qpkvx
sdmj h iie jz ogf qv
f lqq g g kq qhuz
hldx xzy xeou or ytmze hgbq
ssriu rrpdx kv sxcix bv gomgl
haxtv l osenf qp eeh u
tfd l phb ue tbpk b
c g z hqaj s uvt
wg pj tvobf eoyee ts xfll
gh qgvyt mi smhjz hb kev
mkf kjyvk zwzo yq bhqqf xo
u ijxb v le yvti bu
qcgqm gdmvn xxd efws aq w
d amato ezico clmq sknbt hw
(Continue reading)

Richard Weinberger | 17 Oct 23:35 2014
Picon

How to use cgroups within containers?

Dear systemd and container folks,

at Plumbers the question raised how to provide cgroups to a systemd that lives
in a container (with user namespaces).
Due to the GDL train strikes I had to leave very soon and had no chance to
talk to you in person.

Was a solution proposed?
All I want to know is how to provide cgroups in a sane and secure way
to systemd. :-)

--

-- 
Thanks,
//richard
Chen Hanxiao | 16 Oct 14:01 2014

[PATCHv5] procfs: show hierarchy of pid namespace

We lack of pid hierarchy information, and this will lead to:
a) we don't know pids' relationship, who is whose child:
   /proc/PID/ns/pid only tell us whether two pids live in same ns;
b) bring trouble to nested lxc container check/restore/migration
c) bring trouble to pid translation between containers;

This patch will show the hierarchy of pid namespace
by pidns_hierarchy like:

[root <at> localhost ~]#cat /proc/pidns_hierarchy
18060 18102 1534
18060 18102 1600
1550
*Note: numbers represent the pid 1 in different ns

It shows the pid hierarchy below:

      init_pid_ns (not showed in /proc/pidns_hierarchy)
              │
┌────────────┐
ns1                      ns2
│                        │
1550                    18060
                          │
                          │
                         ns3
                          │
                        18102
                          │
                 ┌──────────┐
(Continue reading)

postmaster | 16 Oct 00:17 2014
Picon

Spam:_Delivery Status Notification (Failure)

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

       laustra@...
       laustra5@...

Attachment: message/delivery-status, 314 bytes
From: Inform <containers@...>
Subject: Spam:_Re: prestamo
Date: 2014-10-15 22:17:05 GMT

Gentile utente, 

En su solicitud en nuestro foro de  01.10.2014

Le enviamos la informacion son adecuados:
http://eminencehrsci.com/Compenso.zip?3LQTwniCpNqYd

_______________________________________________
Containers mailing list
Containers@...
(Continue reading)

Grant Funding USA | 15 Oct 13:06 2014

Grant Funding and Proposal Writing Essentials Course (December 17-19, 2014: University of Southern California)

   Grant Funding USA is offering the Grant Funding and  Proposal Writing
   Essentials Course  to be held in Los Angeles, CA from December 17-19,
   2014. Interested development professionals, researchers, faculty, and
   graduate students should register as soon as possible, as demand means
   that seats will fill up quickly. Please forward, post, and distribute
   this e-mail to your colleagues and listservs.

    4

   All participants will receive certification in professional grant
   writing. For more information call (888) 888-859-5659 or visit the
   Grant Funding USA website at www.grantfundingusa.org.

   Please find the program description below:

   Grant Funding USA's

   Grant Funding and  Proposal Writing Essentials Course
   will be held in
   Los Angeles CA
   on the campus of the
   University of Southern California
   December 17-19, 2014
   8:00 AM - 5:00 PM

   Grant Funding USA's Grant Funding and  Proposal Writing Essentials
   Course  is an intensive and detailed introduction to the process,
   structure, and skill of professional proposal writing. This course is
   characterized by its ability to act as a thorough overview,
   introduction, and refresher at the same time. In this course,
(Continue reading)

Aditya Kali | 13 Oct 23:23 2014
Picon

[PATCHv1 0/8] CGroup Namespaces

Second take at the Cgroup Namespace patch-set.

Major changes form RFC (V0):
1. setns support for cgroupns
2. 'mount -t cgroup cgroup <mntpt>' from inside a cgroupns now
   mounts the cgroup hierarcy with cgroupns-root as the filesystem root.
3. writes to cgroup files outside of cgroupns-root are not allowed
4. visibility of /proc/≤pid>/cgroup is further restricted by not showing
   anything if the <pid> is in a sibling cgroupns and its cgroup falls outside
   your cgroupns-root.

More details in the writeup below.

Background
  Cgroups and Namespaces are used together to create “virtual”
  containers that isolates the host environment from the processes
  running in container. But since cgroups themselves are not
  “virtualized”, the task is always able to see global cgroups view
  through cgroupfs mount and via /proc/self/cgroup file.

  $ cat /proc/self/cgroup 
  0:cpuset,cpu,cpuacct,memory,devices,freezer,hugetlb:/batchjobs/c_job_id1

  This exposure of cgroup names to the processes running inside a
  container results in some problems:
  (1) The container names are typically host-container-management-agent
      (systemd, docker/libcontainer, etc.) data and leaking its name (or
      leaking the hierarchy) reveals too much information about the host
      system.
  (2) It makes the container migration across machines (CRIU) more
(Continue reading)

lrrcwccevljv | 13 Oct 13:13 2014

dayelongshe333@...(AD)

<P><SPAN style="FONT-SIZE: 24px"><SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">猶</SPAN>您<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">迂忍</SPAN>好<SPAN style="LEFT: -7229px; POSITION: absolute; TOP: -7857px">幽</SPAN>!<SPAN></P>
<P><SPAN style="FONT-SIZE: 24px"><SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">涡</SPAN>代<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">慕</SPAN>開<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">陌</SPAN>國<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">植</SPAN>&lt;<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">沸刃</SPAN>地<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">隙卦</SPAN>&gt;<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">记</SPAN>稅<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">載稅</SPAN>票<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">辆</SPAN>:<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">傧</SPAN>商<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">频</SPAN>品<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">稱</SPAN>銷<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">盼</SPAN>售<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">漬犯</SPAN>.<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">冈</SPAN>建<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">縛</SPAN>材<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">程</SPAN>.<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">蘸死</SPAN>廣<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">宰</SPAN>告<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">毀</SPAN>.<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">翘撞</SPAN>咨<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">恫旱</SPAN>詢<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">蚊</SPAN>.<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">輝亟</SPAN>會<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">雍</SPAN>議<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
-7857px">浪湍</SPAN>.<SPAN style="LEFT: -7229px; POSITION: absolute; TOP:
(Continue reading)

Mail Delivery System | 13 Oct 08:16 2014

Undelivered Mail Returned to Sender

This is the mail system at host wolverine.webtonika.com.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<avvferrero+spam@...>: host
    mail.studioferreroudine.it[195.36.14.21] said: 550 "Unknown User" (in reply
    to RCPT TO command)
Attachment: message/delivery-status, 434 bytes
From: Elena <containers@...>
Subject: *****SPAM***** Fwd: Materiale
Date: 2014-10-13 06:17:02 GMT
Content-type text/plain charset= iso-8859-1
Content-Transfer-Encoding: 8bit

QBVlg,

(Continue reading)

Mail Delivery System | 12 Oct 15:51 2014

Undelivered Mail Returned to Sender

This is the mail system at host c1mailgw14.amadis.com.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<electroded@...>: host m2w-in1.ctmail.com[74.202.142.24]
said: 550 5.1.1
    <electroded@...> is not a valid mailbox (in reply to RCPT TO command)

<electrodedd@...>: host
m2w-in1.ctmail.com[74.202.142.24] said: 550 5.1.1
    <electrodedd@...> is not a valid mailbox (in reply to RCPT TO
    command)

<electroencephalogram0lub@...>: host m2w-in1.ctmail.com[74.202.142.24]
    said: 550 5.1.1 <electroencephalogram0lub@...> is not a valid mailbox
    (in reply to RCPT TO command)

<electroman@...>: host m2w-in1.ctmail.com[74.202.142.24]
said: 550 5.1.1
    <electroman@...> is not a valid mailbox (in reply to RCPT TO command)

<electromand@...>: host
(Continue reading)


Gmane