Главная
Study mode:
on
1
Intro
2
What are user namespaces?
3
Common setup
4
Filesystem handling
5
The early days
6
The problem
7
VFS idmap shifting
8
New namespaces
9
Integrity Measurements (IMA)
10
Tracing
11
Restricting the user namespace
12
LSM hook
13
System call interception
14
Trusted resources
15
Trusted workloads
16
Conclusion
17
Questions?
Description:
Explore the evolution and current state of user namespaces in this comprehensive conference talk. Delve into exciting developments, including the new VFS API and VFS idmap shifting, which simplify container setup without root filesystem manipulation. Learn about security enhancements, such as LSM-mediated user namespace creation and IMA namespacing for system-wide measurement and checking. Discover solutions to major adoption blockers and the potential deprecation of less secure container options. Gain insights into filesystem handling, integrity measurements, tracing, and trusted resources in user namespaces. Understand the implications for modern container space and the future of user namespace implementation.

What's New in the User Namespace - Recent Developments and Future Outlook

Linux Foundation
Add to list