cgroups

cgroup.procs而非cgroup.tasks

nsenter

c执行完后进入go runtime报错
c clone,child process后进入go runtime报错(clone栈地址传错了,应该是栈的高地址)

network 容器ping 外部网络

SNAT 规则是negative bridge