aristanetworks / bst

A one-stop shop for process isolation
MIT License
101 stars 9 forks source link

wip: enter: allow bst process to enter cgroups #25

Closed Snaipe closed 2 years ago

Snaipe commented 4 years ago

This is a WIP. I don't really know yet if this is going to end up being useful, given the privilege model (in particular, I don't know yet if bst should bypass the write check on the parent cgroup.procs file, but time will tell).

I'll leave this unmerged until we can determine if this is useful as-is, or if it needs to be reworked.

Snaipe commented 2 years ago

Superseded by #62