All of lore.kernel.org
 help / color / mirror / Atom feed
From: Milan Broz <mbroz@redhat.com>
To: Linux Kernel Mailing List <linux-kernel@vger.kernel.org>
Cc: device-mapper development <dm-devel@redhat.com>,
	Kay Sievers <kay.sievers@vrfy.org>,
	"David S. Miller" <davem@davemloft.net>,
	containers@lists.osdl.org
Subject: Re: clone() with CLONE_NEWNET breaks kobject_uevent_env()
Date: Fri, 19 Aug 2011 09:52:07 +0200	[thread overview]
Message-ID: <4E4E1627.8010902@redhat.com> (raw)
In-Reply-To: <4E4CDF44.5080109@redhat.com>

(added cc to containers list)

On 08/18/2011 11:45 AM, Milan Broz wrote:
> Hi,
> 
> after analysing very strange report (with running chromium
> some device-mapper ioctl functions started to fail) I found
> interesting problem:
> 
> If you run clone() with CLONE_NEWNET (which is chromium using
> for sanboxing), udev namespace is cloned too (newly registered
> in uevent_sock_list) and netlink send (except the first in list)
> fails with -ESRCH.
> 
> This causes that _every_ call of kobject_uevent_env() return failure.
> 
> Most of users silently ignores  kobject_uevent() return value,
> so the problem was invisible for long time.
> 
> Unfortunately dm checks return value and reports failure,
> taking the wrong error path.
> 
> How is this supposed to work?
> 
> Why cloning net namespace breaks the udev netlink subsystem?
> 
> Is it bug or we need to do something differently?
> (I do not think ignoring return value is the proper way...)

I forgot to explicitly mention that running clone with CLONE_NEWNET
causes kobject_uevent_env() to fail _outside_ of cloned namespace
(for all kernel users in fact).

(The former problem is described here
http://article.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/5256
but it is IMHO generic problem. Instrumenting  kobject_uevent() shows
that it returns send failure really to all events.)

Can anyone please explain this behavior?

Milan

  reply	other threads:[~2011-08-19  7:52 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-08-18  9:45 clone() with CLONE_NEWNET breaks kobject_uevent_env() Milan Broz
2011-08-19  7:52 ` Milan Broz [this message]
2011-08-19  9:13 ` [dm-devel] " Eric W. Biederman
2011-08-19  9:13   ` Eric W. Biederman
2011-08-19 10:22   ` Milan Broz
2011-08-19 11:43     ` Eric W. Biederman
2011-08-19 11:59       ` Milan Broz
2011-08-19 18:39         ` Eric W. Biederman
2011-08-19 20:41           ` Milan Broz
2011-08-22 13:51             ` [PATCH] kobj_uevent: Ignore if some listeners cannot handle message Milan Broz
2011-08-22 16:24               ` Kay Sievers
2011-08-22 19:49               ` Eric W. Biederman
2011-08-22 20:05                 ` Milan Broz
2011-08-19 10:26   ` [dm-devel] clone() with CLONE_NEWNET breaks kobject_uevent_env() Kay Sievers

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4E4E1627.8010902@redhat.com \
    --to=mbroz@redhat.com \
    --cc=containers@lists.osdl.org \
    --cc=davem@davemloft.net \
    --cc=dm-devel@redhat.com \
    --cc=kay.sievers@vrfy.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.