“A couple of months or years(?) ago there was a patch that was submitted to the upstream, which made it possible to limit number of processes in containers (against forkbombs). Is there any news about it?” に対して “Currently there is the kernel memory cgroup control, but I think we need more fine-grained controls, including nrtasks and nrmounts.”