Topic 01: Linux Namespaces & Process Isolation Primitives

Target Duration: 2–4 minutes (~300–450 spoken words)
Focus: Pointwise verbal delivery covering the 4 namespaces, syscall sequence, PID 1 inheritance rule, and supervisor process controls.


🎙️ Pointwise Spoken Speech (Word-for-Word Delivery)


📋 Step-by-Step Summary (What, How & Why)

Step What Was Done How It Works Why This Mechanism / Order
1. Syscall Selection Chose clone() vs unshare() clone() creates a new child in new namespaces; unshare() detaches the current process. unshare allows the supervisor to prepare namespaces and pivot root before executing the target binary.
2. PID 1 Creation Forked child after PID unshare unshare(CLONE_NEWPID) applies only to future children. Kernel cannot change a running process's PID dynamically without breaking scheduler structs.
3. Mount & /proc Remounted /proc in new mount ns Pivoted apparent root and mounted fresh procfs instance. Prevents container processes from reading host /proc and seeing host processes via ps.
4. Process Cleanup Configured automatic child killing Supervisor signals all children in namespace on exit. Prevents orphaned container processes from leaking to host PID 1 as zombies.
5. Exec Attachment Attached via pidfd_open + setns Acquired process FD to PID 1 and joined its namespaces. Eliminates PID recycling race conditions when joining active containers.

❓ Anticipated Interview Questions & Crisp Answers

Q1: Why can't a process change its own PID namespace dynamically?

Answer: In Linux, a process's PID struct is allocated at process creation and deeply tied to scheduler task structs, signal handling tables, and credentials. Changing it dynamically would break thread group semantics and create kernel inconsistencies. Thus, CLONE_NEWPID only sets the namespace for descendants created on subsequent fork()/clone() calls.

Q2: Why did you use pidfd_open() instead of opening /proc/<pid>/ns/pid?

Answer: Accessing /proc/<pid>/ns/pid is vulnerable to a PID reuse race condition. If the target process exits and another process is assigned the recycled PID before open() runs, setns() would attach to an unrelated process. pidfd_open() creates a file descriptor tied to that exact process instance, eliminating the race.

Q3: What happens if you run ps aux inside a container without remounting /proc?

Answer: ps reads /proc to display process state. If /proc is not remounted in the new mount namespace, the container shares the host's /proc, so ps will list all host processes even though the container's PID namespace is isolated. Remounting procfs reflects only the container's private PID space.