LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Containers
User Name
Password
Linux - Containers This forum is for the discussion of all topics relating to Linux containers. Docker, LXC, LXD, runC, containerd, CoreOS, Kubernetes, Mesos, rkt, and all other Linux container platforms are welcome.

Notices


Reply
  Search this Thread
Old 01-13-2017, 05:10 PM   #1
goalotc
LQ Newbie
 
Registered: Jan 2017
Posts: 1

Rep: Reputation: Disabled
Proc connector across pid namespace - a security issue?


I was experimenting monitoring process changes from a container. The container has all namespace of its own. What I did was to first switch to host network namespace, open the proc connector socket, send LISTEN message, switch back to container network namespace, then start receiving notifications.

I didn't receive any notification. This seems to be expected because container and the host are in different Pid namespace.

However, if at this time, I start the same program on the host, then my program running within the container starts receiving notifications for process changes. The pid value is of those in the host Pid namespace.

I am wondering if the notification should be passed to the process in different Pid namespace. If not, if what I observed is a security issue.

The kernel version is 3.19.0-25

Last edited by goalotc; 01-14-2017 at 01:55 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Question about /proc/PID/pagemap, /proc/kpageflags Nakajima Linux - Kernel 2 07-07-2015 03:37 AM
Confluence PID issue. (Removing/clearing stale PID file) vignesh4sh Linux - Server 5 12-05-2012 07:14 AM
Print all PID folders from /proc line-by-line with this format (( PID: command-line )) courteous Linux - Newbie 7 12-12-2010 04:47 PM
pmap or /proc/<pid>smap or /proc/<pid>/status iQoder Linux - Newbie 1 07-16-2009 06:32 PM
/proc/pid/io seems not to work kornelix Linux - Server 5 06-17-2007 02:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Containers

All times are GMT -5. The time now is 05:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration