-
Notifications
You must be signed in to change notification settings - Fork 541
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Should linux fields be in process directly, or a level down? #831
Comments
we've gone back on forth on this. I'm sure @wking could give a historical breakdown. |
On Tue, May 16, 2017 at 10:54:40AM -0700, v1.0.0.batts wrote:
I'm sure @wking could give a historical breakdown.
The current policy (since at least 2016-05-18) seems to be [1]:
If any platform cannot use your setting, namespace it, unless that
would seem weird for aesthetic reasons we're punting on defining.
Maybe this is a call to define those aesthetic reasons or drop the
loophole? The initial shift of Linux-specific stuff into ‘process’
happened in #329, and there was a more recent shift in #789, neither
of which has a lot of discussion about whether namespacing is
appropriate. There *is* some previous discussion about namespacing in
#405; for example, see [2,3,4].
[1]: https://ircbot.wl.linuxfoundation.org/eavesdrop/%23opencontainers/%23opencontainers.2016-05-18.log.html#t2016-05-18T17:41:31
[2]: https://groups.google.com/a/opencontainers.org/d/msg/dev/mM_DWZmXst0/uDPFv8-MBQAJ
[3]: #405 (comment)
[4]: #405 (comment)
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Looking at the spec all-up, it seems that the
Process
struct is imbalanced relative to the spec in general, and shouldn't directly contain the Linux-specific fields, namelyCapabilities, Rlimits, NoNewPrivileges, ApparmorProfile, OOMScoreAdj, SelinuxLabel
and instead mirror the top-levelSpec
structure and have aLinuxProcess
struct with those fields.Something like
Thoughts?
The text was updated successfully, but these errors were encountered: