On 5/16/16 16:19 , David Preece wrote:
> On 17 May 2016 at 10:54:20 AM, Patrick Mooney ([email protected]) 
> wrote:
> An LX-branded zone instantiates a significant amount of brand-specific data 
> in order to "impersonate" the Linux syscall interface for the processes it 
> contains.  It is possible to run native binaries inside a branded zone thanks 
> to a hook in the elfexec logic which causes the branding to be removed for 
> that specific process.
> Ah, got it. Adding branding and taking it off again are very different 
> processes.

In addition, a bigger problem as I see it are the expectations of the
environment. The question of where is the /proc I understand, where do
things live in what paths? While it's possible to imagine a world where
we did all the branding and unbranding always based on the elf
information, it'd be hard to have multiple things co-exist due to those
different expectations. If the only thing you had was a binary that
wanted to run some system calls and exit, that'd be a slightly different
story, but not one we're focused on, as most things want the surrounding
environment.

Robert


-------------------------------------------
smartos-discuss
Archives: https://www.listbox.com/member/archive/184463/=now
RSS Feed: https://www.listbox.com/member/archive/rss/184463/25769125-55cfbc00
Modify Your Subscription: 
https://www.listbox.com/member/?member_id=25769125&id_secret=25769125-7688e9fb
Powered by Listbox: http://www.listbox.com

Reply via email to