From: "Serge E. Hallyn" <serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
To: sukadev-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org
Cc: kyle-hoO6YkzgTuCM0SS3m2neIg@public.gmane.org,
sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org,
bastian-yyjItF7Rl6lg9hUCZPvPmw@public.gmane.org,
hpa-YMNOUZJC4hwAvxtiuMwx3w@public.gmane.org,
containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org,
xemul-GEFAQzZX7r8dnm+yROfE0A@public.gmane.org,
alan-qBU/x9rampVanCEyBjwyrvXRex20P6io@public.gmane.org,
ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org
Subject: Re: [PATCH 10/10] Document usage of multiple-instances of devpts
Date: Wed, 24 Sep 2008 15:36:50 -0500 [thread overview]
Message-ID: <20080924203650.GC31664@us.ibm.com> (raw)
In-Reply-To: <20080912175347.GK17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
Quoting sukadev-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org (sukadev-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org):
>
> >From 6d2fe9386880157f871667077db3180e9f0083a1 Mon Sep 17 00:00:00 2001
> From: Sukadev Bhattiprolu <sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
> Date: Tue, 9 Sep 2008 10:43:50 -0700
> Subject: [PATCH 10/10] Document usage of multiple-instances of devpts
>
> Signed-off-by: Sukadev Bhattiprolu <sukadev-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
> ---
> Documentation/filesystems/devpts.txt | 122 ++++++++++++++++++++++++++++++++++
> 1 files changed, 122 insertions(+), 0 deletions(-)
> create mode 100644 Documentation/filesystems/devpts.txt
>
> diff --git a/Documentation/filesystems/devpts.txt b/Documentation/filesystems/devpts.txt
> new file mode 100644
> index 0000000..93d9d01
> --- /dev/null
> +++ b/Documentation/filesystems/devpts.txt
> @@ -0,0 +1,122 @@
> +
> +To support containers, we now allow multiple instances of devpts filesystem,
> +such that indices of ptys allocated in one instance are independent of indices
> +allocated in other instances of devpts.
> +
> +To preserve backward compatibility, this support for multiple instances is
> +enabled only if:
> +
> + - CONFIG_DEVPTS_MULTIPLE_INSTANCES=y, and
> + - '-o newinstance' mount option is specified while mounting devpts
> +
> +IOW, devpts now supports both single-instance and multi-instance semantics.
> +
> +If CONFIG_DEVPTS_MULTIPLE_INSTANCES=n, there is no change in behavior and
> +this referred to as the "legacy" mode. In this mode, the new mount options
> +(-o newinstance and -o ptmxmode) will be ignored with a 'bogus option' message
> +on console.
> +
> +If CONFIG_DEVPTS_MULTIPLE_INSTANCES=y and devpts is mounted without the
> +'newinstance' option (as in current start-up scripts) the new mount binds
> +to the initial kernel mount of devpts. This mode is referred to as the
> +'single-instance' mode and the current, single-instance semantics are
> +preserved, i.e PTYs are common across the system.
> +
> +The only difference between this single-instance mode and the legacy mode
> +is the presence of new, '/dev/pts/ptmx' node with permissions 0000, which
> +can safely be ignored.
> +
> +If CONFIG_DEVPTS_MULTIPLE_INSTANCES=y and 'newinstance' option is specified,
> +the mount is considered to be in the multi-instance mode and a new instance
> +of the devpts fs is created. Any ptys created in this instance are independent
> +of ptys in other instances of devpts. Like in the single-instance mode, the
> +/dev/pts/ptmx node is present. To effectively use the multi-instance mode,
> +open of /dev/ptmx must be a redirected to '/dev/pts/ptmx' using a symlink or
> +bind-mount.
> +
> +Eg: A container startup script could do the following:
> +
> + $ chmod 0666 /dev/pts/ptmx
> + $ rm /dev/ptmx
> + $ ln -s pts/ptmx /dev/ptmx
> + $ ns_exec -cm /bin/bash
> +
> + # We are now in new container
> +
> + $ umount /dev/pts
> + $ mount -t devpts -o newinstance lxcpts /dev/pts
> + $ sshd -p 1234
> +
> +where 'ns_exec -cm /bin/bash' calls clone() with CLONE_NEWNS flag and execs
> +/bin/bash in the child process. A pty created by the sshd is not visible in
> +the original mount of /dev/pts.
> +
> +User-space changes
> +------------------
> +
> +In multi-instance mode (i.e '-o newinstance' mount option is specified at least
> +once), following user-space issues should be noted.
> +
> +1. If -o newinstance mount option is never used, /dev/pts/ptmx can be ignored
> + and no change is needed to system-startup scripts.
> +
> +2. To effectively use multi-instance mode (i.e -o newinstance is specified)
> + administrators or startup scripts should "redirect" open of /dev/ptmx to
> + /dev/pts/ptmx using either a bind mount or symlink.
> +
> + $ mount -t devpts -o newinstance devpts /dev/pts
> +
> + followed by either
> +
> + $ rm /dev/ptmx
> + $ ln -s pts/ptmx /dev/ptmx
> + $ chmod 666 /dev/pts/ptmx
> + or
> + $ mount -o bind /dev/pts/ptmx /dev/ptmx
> +
> +3. The '/dev/ptmx -> pts/ptmx' symlink is the preferred method since it
> + enables better error-reporting and treats both single-instance and
> + multi-instance mounts similarly.
> +
> + But this method requires that system-startup scripts set the mode of
> + /dev/pts/ptmx correctly (default mode is 0000). The scripts can set the
> + mode by, either
> +
> + - adding ptmxmode mount option to devpts entry in /etc/fstab, or
> + - using 'chmod 0666 /dev/pts/ptmx'
> +
> +4. If multi-instance mode mount is needed for containers, but the system
> + startup scripts have not yet been updated, container-startup scripts
> + should bind mount /dev/ptmx to /dev/pts/ptmx to avoid breaking single-
> + instance mounts.
> +
> + Or, in general, container-startup scripts should use:
> +
> + mount -t devpts -o newinstance -o ptmxmode 0666 devpts /dev/pts
ptmxmode=0666
That is, of course, crucial, this being the documentation :)
> + if [ ! -L /dev/ptmx ]; then
> + mount -o bind /dev/pts/ptmx /dev/ptmx
> + fi
> +
> + When all devpts mounts are multi-instance, /dev/ptmx can permanently be
> + a symlink to pts/ptmx and the bind mount can be ignored.
> +
> +5. A multi-instance mount that is not accompanied by the /dev/ptmx to
> + /dev/pts/ptmx redirection would result in an unusable/unreachable pty.
> +
> + mount -t devpts -o newinstance lxcpts /dev/pts
> +
> + immediately followed by:
> +
> + open("/dev/ptmx")
> +
> + would create a pty, say /dev/pts/7, in the initial kernel mount.
> + But /dev/pts/7 would be invisible in the new mount.
> +
> +6. The permissions for /dev/pts/ptmx node should be specified when mounting
> + /dev/pts, using the '-o ptmxmode=%o' mount option (default is 0000).
> +
> + mount -t devpts -o newinstance -o ptmxmode=0644 devpts /dev/pts
> +
> + The permissions can be later be changed as usual with 'chmod'.
> +
> + chmod 666 /dev/pts/ptmx
> --
> 1.5.2.5
next prev parent reply other threads:[~2008-09-24 20:36 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-09-12 17:48 [PATCH 0/10][v4]: Enable multiple devpts instances sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912174845.GA17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-12 17:50 ` [PATCH 01/10] Remove devpts_root global sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175057.GB17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 17:04 ` Serge E. Hallyn
2008-09-12 17:51 ` [PATCH 02/10] Per-mount allocated_ptys sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175116.GC17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 17:14 ` Serge E. Hallyn
[not found] ` <20080924171408.GB25255-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-27 1:12 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
2008-09-12 17:51 ` [PATCH 03/10] Per-mount 'config' object sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175135.GD17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 17:20 ` Serge E. Hallyn
2008-09-12 17:51 ` [PATCH 04/10] Extract option parsing to new function sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175153.GE17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 17:23 ` Serge E. Hallyn
2008-09-12 17:52 ` [PATCH 05/10] Add DEVPTS_MULTIPLE_INSTANCES config token sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175210.GF17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 17:24 ` Serge E. Hallyn
2008-09-12 17:52 ` [PATCH 06/10] Define mknod_ptmx() sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175237.GG17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 18:21 ` Serge E. Hallyn
[not found] ` <20080924182125.GF25255-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-26 21:32 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
2008-09-24 18:50 ` Serge E. Hallyn
[not found] ` <20080924185046.GA31535-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-26 21:29 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080926212954.GE31505-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 13:14 ` Serge E. Hallyn
2008-09-12 17:52 ` [PATCH 07/10] Update ptmx permissions during remount sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175252.GH17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 18:30 ` Serge E. Hallyn
2008-09-12 17:53 ` [PATCH 08/10] Define get_sb_ref() sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175308.GI17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 19:20 ` Serge E. Hallyn
2008-09-24 19:55 ` Dave Hansen
2008-09-26 21:21 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080926212115.GD31505-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-26 21:31 ` Dave Hansen
2008-09-27 0:47 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080927004727.GA2161-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 14:00 ` Cedric Le Goater
[not found] ` <48E0DF71.2070007-NmTC/0ZBporQT0dZR+AlfA@public.gmane.org>
2008-09-30 15:13 ` Serge E. Hallyn
[not found] ` <20080930151325.GA26713-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-10-01 12:38 ` Cedric Le Goater
2008-09-27 20:29 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080927202924.GA16208-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-10-04 3:09 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
2008-09-12 17:53 ` [PATCH 09/10] Enable multiple instances of devpts sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175322.GJ17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-24 20:26 ` Serge E. Hallyn
[not found] ` <20080924202616.GB31664-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-26 21:03 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080926210347.GB31505-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 13:01 ` Serge E. Hallyn
[not found] ` <20080929130131.GA12531-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 15:18 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080929151828.GA10202-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 15:29 ` Serge E. Hallyn
[not found] ` <20080929152951.GA32518-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-29 15:58 ` Cedric Le Goater
2008-09-29 14:06 ` Cedric Le Goater
2008-09-12 17:53 ` [PATCH 10/10] Document usage of multiple-instances " sukadev-r/Jw6+rmf7HQT0dZR+AlfA
[not found] ` <20080912175347.GK17350-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-19 15:33 ` Alan Cox
[not found] ` <20080919163311.626b715f-qBU/x9rampVanCEyBjwyrvXRex20P6io@public.gmane.org>
2008-09-19 16:53 ` H. Peter Anvin
2008-09-20 16:17 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
[not found] ` <20080920161717.GA23693-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-22 13:29 ` Serge E. Hallyn
[not found] ` <20080922132937.GA11932-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-22 19:25 ` Serge E. Hallyn
2008-09-22 16:16 ` Serge E. Hallyn
[not found] ` <20080922161658.GA27087-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-22 16:33 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
2008-09-24 20:36 ` Serge E. Hallyn [this message]
[not found] ` <20080924203650.GC31664-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-09-26 21:05 ` sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080924203650.GC31664@us.ibm.com \
--to=serue-r/jw6+rmf7hqt0dzr+alfa@public.gmane.org \
--cc=alan-qBU/x9rampVanCEyBjwyrvXRex20P6io@public.gmane.org \
--cc=bastian-yyjItF7Rl6lg9hUCZPvPmw@public.gmane.org \
--cc=containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org \
--cc=ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org \
--cc=hpa-YMNOUZJC4hwAvxtiuMwx3w@public.gmane.org \
--cc=kyle-hoO6YkzgTuCM0SS3m2neIg@public.gmane.org \
--cc=sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org \
--cc=sukadev-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org \
--cc=xemul-GEFAQzZX7r8dnm+yROfE0A@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.