Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-05 Thread Greg Kurz
On Fri, 2011-09-02 at 17:06 +0200, Nico wrote: > Even with lxc, "ps xua..." show only processes in the cgroup, so yes > /proc is already "virtualized". You're right about "free" reporting > host values with lxc, but it's done in openvz, and I don't know about > vservers. Well, /proc is pid namespa

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-04 Thread Michael H. Warfield
On Sun, 2011-09-04 at 21:53 +0200, axel.schoe...@gmx.de wrote: > Hi, > > in my opinion it's never a bad idea to drop the sys_admin cap. except you > really need it. It's been my personal experience that it's ALWAYS a bad experience to drop sys_admin cap when you are doing a full system containe

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-04 Thread axel . schoener
Hi, in my opinion it's never a bad idea to drop the sys_admin cap. except you really need it. I' ve searched for some help because i'm using ubuntu only for some study (normally gentoo). I found a little help here: http://qemu-buch.de/de/index.php/QEMU-KVM- Buch/_Anhang/_Weitere_Virtualisierer_u

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-02 Thread Michael H. Warfield
On Fri, 2011-09-02 at 08:35 +0400, Michael Tokarev wrote: > On 02.09.2011 00:46, Daniel Lezcano wrote: > > On 09/01/2011 09:30 PM, Nico wrote: > >> Hi, > >> > >> I just wanted to give it a try again with lxc after one year, > >> this is so bad same bugs are always here : > >> > >> * you can do a "

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-02 Thread Nico
Dear Jäkel, 2011/9/2 Jäkel, Guido : > Dear Nico, > >>I mean lxc was integrated into 2.6.27 kernel, this is october 2008 >>!!!, nearly three years from now, into the >>stable branch, but is not usable in production in 2011 !! > > I'm not involved in lxc-dev yet, but to my knowledge you're using wro

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-02 Thread Nico
Dear Jäkel, > Dear Nico, > > currently LXC is far away from being usable for a "non-userfriendly" usecase > like e.g. providing virtual root servers to 3rd parties. I mean lxc was integrated into 2.6.27 kernel, this is october 2008 !!!, nearly three years from now, into the stable branch, but is

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-02 Thread Nico
>> >> Argh ! I still don't understand how that can happen with a CLONE_NEWNS >> and a pivot_root. >> Do you have particular mount options on your host's rootfs ? > > In order for guest remount to NOT influence host mount, you have to > give -o bind option to mount inside guest.  If you don't specif

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-02 Thread Nico
Daniel, sorry for double Post, I forgot to cc lxc-devel >>> >>> * you can do a "mount -o romount,ro /" inside container (reported >>> since first times ... :( ), >>> and host filesystem is remounted ro !! >> >> Argh ! I still don't understand how that can happen with a CLONE_NEWNS >> and a pi

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-01 Thread Michael Tokarev
On 02.09.2011 00:46, Daniel Lezcano wrote: > On 09/01/2011 09:30 PM, Nico wrote: >> Hi, >> >> I just wanted to give it a try again with lxc after one year, >> this is so bad same bugs are always here : >> >> * you can do a "mount -o romount,ro /" inside container (reported >> since first times ...

Re: [lxc-devel] mount ro in guest change host filesystem to ro

2011-09-01 Thread Daniel Lezcano
On 09/01/2011 09:30 PM, Nico wrote: > Hi, > > I just wanted to give it a try again with lxc after one year, > this is so bad same bugs are always here : > > * you can do a "mount -o romount,ro /" inside container (reported > since first times ... :( ), > and host filesystem is remounted ro !! Argh

[lxc-devel] mount ro in guest change host filesystem to ro

2011-09-01 Thread Nico
Hi, I just wanted to give it a try again with lxc after one year, this is so bad same bugs are always here : * you can do a "mount -o romount,ro /" inside container (reported since first times ... :( ), and host filesystem is remounted ro !! * you can rmmod host modules from guest ! * so strang