Home » Mailing lists » Users » bug or feature?: ps -el on HN shows all processes, incl. those of VEs 
	| 
		
 |  
	| 
		
 |  
	
		
		
			| Re:  bug or feature?: ps -el on HN shows all processes, incl. those of VEs [message #43989 is a reply to message #43988] | 
			Mon, 07 November 2011 10:00    | 
		 
		
			
				
				
				
					
						  
						Kirill Korotaev
						 Messages: 137 Registered: January 2006 
						
					 | 
					Senior Member  | 
					 | 
		 
		 
	 | 
 
	
		http://wiki.openvz.org/Processes_scope_and_visibility 
Plus, as far as I remember there was a patch somewhere on download.openvz.org or sysctl which allows to hide non-root processes from root VE. 
 
 
On Nov 7, 2011, at 13:35 , <lst_hoe02@kwsoft.de> <lst_hoe02@kwsoft.de> wrote: 
 
> Zitat von "U.Mutlu" <for-gmane@mutluit.com>: 
>  
>> "ps -el" (and also "ps aux" etc.) on the HN shows all processes, 
>> incl. those of VEs. 
>> Is there a way to show, on the HN, only the processes of the HN itself, 
>> excluding the processes of the VEs? 
>  
> This is as far as i know by design. The HN is the Hypervisor and must   
> have a global view what is going on the machine. That's why it is   
> advised to not use any other services beside openvz on the HN. 
>  
> Regards 
>  
> Andreas 
>  
>  
>  
> <smime.p7s><ATT00001.c>
		
		
		
 |  
	| 
		
	 | 
 
 
 |  
	
		
		
			| Re:  bug or feature?: ps -el on HN shows all processes, incl. those of VEs [message #43991 is a reply to message #43989] | 
			Mon, 07 November 2011 10:58    | 
		 
		
			
				
				
				
					
						  
						mator
						 Messages: 2 Registered: February 2009  Location: moscow
						
					 | 
					Junior Member  | 
					 | 
		 
		 
	 | 
 
	
		On Mon, Nov 7, 2011 at 2:00 PM, Kirill Korotaev <dev@parallels.com> wrote: 
> http://wiki.openvz.org/Processes_scope_and_visibility 
> Plus, as far as I remember there was a patch somewhere on download.openvz.org or sysctl which allows to hide non-root processes from root VE. 
> 
> 
> On Nov 7, 2011, at 13:35 , <lst_hoe02@kwsoft.de> <lst_hoe02@kwsoft.de> wrote: 
> 
>> Zitat von "U.Mutlu" <for-gmane@mutluit.com>: 
>> 
>>> "ps -el" (and also "ps aux" etc.) on the HN shows all processes, 
>>> incl. those of VEs. 
>>> Is there a way to show, on the HN, only the processes of the HN itself, 
>>> excluding the processes of the VEs? 
>> 
>> This is as far as i know by design. The HN is the Hypervisor and must 
>> have a global view what is going on the machine. That's why it is 
>> advised to not use any other services beside openvz on the HN. 
 
I know I'm a bit offtopic here, but taking in example solaris 10 with 
it's zones, it's possible to supply 
ps with "-Z" command , which will say what zone/container process 
belongs to. Would be nice, 
to somehow label container processes with container ID in kernel and 
have userland (ps for example, or any other tool) 
to be able to show this label. 
 
Thanks.
		
		
		
 |  
	| 
		
	 | 
 
 
 |  
	
		
		
			| Re:  bug or feature?: ps -el on HN shows all processes, incl.	those of VEs [message #43992 is a reply to message #43991] | 
			Mon, 07 November 2011 11:17   | 
		 
		
			
				
				
				
					
						  
						Kirill Korotaev
						 Messages: 137 Registered: January 2006 
						
					 | 
					Senior Member  | 
					 | 
		 
		 
	 | 
 
	
		On Nov 7, 2011, at 14:58 , Anatoly Pugachev wrote: 
 
> On Mon, Nov 7, 2011 at 2:00 PM, Kirill Korotaev <dev@parallels.com> wrote: 
>> http://wiki.openvz.org/Processes_scope_and_visibility 
>> Plus, as far as I remember there was a patch somewhere on download.openvz.org or sysctl which allows to hide non-root processes from root VE. 
>>  
>>  
>> On Nov 7, 2011, at 13:35 , <lst_hoe02@kwsoft.de> <lst_hoe02@kwsoft.de> wrote: 
>>  
>>> Zitat von "U.Mutlu" <for-gmane@mutluit.com>: 
>>>  
>>>> "ps -el" (and also "ps aux" etc.) on the HN shows all processes, 
>>>> incl. those of VEs. 
>>>> Is there a way to show, on the HN, only the processes of the HN itself, 
>>>> excluding the processes of the VEs? 
>>>  
>>> This is as far as i know by design. The HN is the Hypervisor and must 
>>> have a global view what is going on the machine. That's why it is 
>>> advised to not use any other services beside openvz on the HN. 
>  
> I know I'm a bit offtopic here, but taking in example solaris 10 with 
> it's zones, it's possible to supply 
> ps with "-Z" command , which will say what zone/container process 
> belongs to. Would be nice, 
> to somehow label container processes with container ID in kernel and 
> have userland (ps for example, or any other tool) 
> to be able to show this label. 
 
There are tools vzps and vztop which does that. 
vzps ax -E <VEID> 
will show tasks from specified VE only (and for -E 0 it will show host system tasks only filtering out containers). 
 
Thanks, 
Kirill
		
		
		
 |  
	| 
		
	 | 
 
 
 |   
Goto Forum:
 
 Current Time: Tue Nov 04 10:41:26 GMT 2025 
 Total time taken to generate the page: 0.11261 seconds 
 |