All of lore.kernel.org
 help / color / mirror / Atom feed
From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
To: "Serge E. Hallyn" <serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org>
Cc: netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org,
	serge.hallyn-GeWIH/nMZzLQT0dZR+AlfA@public.gmane.org,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	libo.chen-hv44wF8Li93QT0dZR+AlfA@public.gmane.org,
	netfilter-devel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	guz.fnst-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org,
	akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org
Subject: Re: [PATCH v3 00/11] Add namespace support for syslog
Date: Wed, 14 Aug 2013 12:21:47 -0700	[thread overview]
Message-ID: <87a9kkcc38.fsf@xmission.com> (raw)
In-Reply-To: <20130814153017.GA18403-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org> (Serge E. Hallyn's message of "Wed, 14 Aug 2013 15:30:17 +0000")

"Serge E. Hallyn" <serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org> writes:

> Quoting Rui Xiang (rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org):
>> On 2013/8/8 9:37, Gao feng wrote:
>> > On 08/07/2013 03:55 PM, Eric W. Biederman wrote:
>> >>
>> >> Since this still has not been addressed.  I am going to repeat Andrews
>> >> objection again.
>> >>
>> >> Isn't there a better way to get iptables information out than to use
>> >> syslog.  I did not have time to follow up on that but it did appear that
>> >> someone did have a better way to get the information out.
>> >>
>> >> Essentially the argument against this goes.  The kernel logging facility
>> >> is really not a particularly good tool to be using for anything other
>> >> than kernel debugging information, and there appear to be no substantial
>> >> uses for a separate syslog that should not be done in other ways.
>> > 
>> > containerizing syslog is not only for iptables, it also isolates the /dev/kmsg,
>> > /proc/kmsg, syslog(2)... user space tools in container may use this interface
>> > to read/generate syslog.
>> > 
>> > But I don't know how important/urgent this containerizing syslog work is,
>> > Rui Xiang, can you find an important/popular user space tool which uses this
>> > interfaces to generate kernel syslog?
>> > 
>> 
>> There are some other cases. Some warnings (bad mount options for tmpfs,
>> bad uid owner for many of them, etc) emerged in the container should
>> be exported to the container. Some belong on the host - if they show 
>> a corrupt superblock which may indicate an attempt by the container 
>> to crash the kernel. Like these, Kernel will print out warnings when 
>> userspace in container uses a deprecated something or other, and these
>> logs should be invisible and specific for current container.
>> 
>> I can't say this work is terribly compelling and important, but the 
>> impact may be obvious, IMO.
>
> Aug  9 21:49:13 sergeh1 kernel: [4644829.672768] init: Failed to spawn network-interface (veth8Ehlvj) post-stop process: unable to change root directory: No such file ricr:aeohgrticr  cfe rty444984 n:aetswnw-ta(ht -rrsultheoit: hlrro<4865i:i sntkta(ht ttpe btheoit: hlrrob r6ezt)nrgoadgte644915 c0pt(tyg ti wd a
> Aug  9 21:49:13 sergeh1 kernel: X3f d-6:uigitra ora
> Aug  9 22:19:54 sergeh1 kernel: 6[642.175 X3f d-6:mutdflsse ihodrddt oe==99 rfl=lccnanrdfutwt-etn"nm=/a/ah/x/lu-ui/m.AExdu"pi=91 om=mut sye"x3name="/devlo0" lg=r"ol pmc r=3an19pfel-nireu-tntgne/rc/cldudmHEqu d97o=otfy=x"ra=d/o/fg""8b:o vhc)nrgibdte646013 veeMzWe oso d<[4715]xr r1eMc egset
> Aug

That is certainly a mess.  Now I don't believe we allow processes in a
user namespace to write to the kernels log (certainly we shouldn't be)
so part of that is not a problem.

What is interleaving messages into syslog?

And to be clear my only perspective is that we need to make certain we
have this thought out.

Eric

WARNING: multiple messages have this Message-ID (diff)
From: ebiederm@xmission.com (Eric W. Biederman)
To: "Serge E. Hallyn" <serge@hallyn.com>
Cc: Rui Xiang <rui.xiang@huawei.com>,
	Gao feng <gaofeng@cn.fujitsu.com>,
	netdev@vger.kernel.org, containers@lists.linux-foundation.org,
	serge.hallyn@ubuntu.com, linux-kernel@vger.kernel.org,
	libo.chen@huawei.com, netfilter-devel@vger.kernel.org,
	guz.fnst@cn.fujitsu.com, akpm@linux-foundation.org
Subject: Re: [PATCH v3 00/11] Add namespace support for syslog
Date: Wed, 14 Aug 2013 12:21:47 -0700	[thread overview]
Message-ID: <87a9kkcc38.fsf@xmission.com> (raw)
In-Reply-To: <20130814153017.GA18403@mail.hallyn.com> (Serge E. Hallyn's message of "Wed, 14 Aug 2013 15:30:17 +0000")

"Serge E. Hallyn" <serge@hallyn.com> writes:

> Quoting Rui Xiang (rui.xiang@huawei.com):
>> On 2013/8/8 9:37, Gao feng wrote:
>> > On 08/07/2013 03:55 PM, Eric W. Biederman wrote:
>> >>
>> >> Since this still has not been addressed.  I am going to repeat Andrews
>> >> objection again.
>> >>
>> >> Isn't there a better way to get iptables information out than to use
>> >> syslog.  I did not have time to follow up on that but it did appear that
>> >> someone did have a better way to get the information out.
>> >>
>> >> Essentially the argument against this goes.  The kernel logging facility
>> >> is really not a particularly good tool to be using for anything other
>> >> than kernel debugging information, and there appear to be no substantial
>> >> uses for a separate syslog that should not be done in other ways.
>> > 
>> > containerizing syslog is not only for iptables, it also isolates the /dev/kmsg,
>> > /proc/kmsg, syslog(2)... user space tools in container may use this interface
>> > to read/generate syslog.
>> > 
>> > But I don't know how important/urgent this containerizing syslog work is,
>> > Rui Xiang, can you find an important/popular user space tool which uses this
>> > interfaces to generate kernel syslog?
>> > 
>> 
>> There are some other cases. Some warnings (bad mount options for tmpfs,
>> bad uid owner for many of them, etc) emerged in the container should
>> be exported to the container. Some belong on the host - if they show 
>> a corrupt superblock which may indicate an attempt by the container 
>> to crash the kernel. Like these, Kernel will print out warnings when 
>> userspace in container uses a deprecated something or other, and these
>> logs should be invisible and specific for current container.
>> 
>> I can't say this work is terribly compelling and important, but the 
>> impact may be obvious, IMO.
>
> Aug  9 21:49:13 sergeh1 kernel: [4644829.672768] init: Failed to spawn network-interface (veth8Ehlvj) post-stop process: unable to change root directory: No such file ricr:aeohgrticr  cfe rty444984 n:aetswnw-ta(ht -rrsultheoit: hlrro<4865i:i sntkta(ht ttpe btheoit: hlrrob r6ezt)nrgoadgte644915 c0pt(tyg ti wd a
> Aug  9 21:49:13 sergeh1 kernel: X3f d-6:uigitra ora
> Aug  9 22:19:54 sergeh1 kernel: 6[642.175 X3f d-6:mutdflsse ihodrddt oe==99 rfl=lccnanrdfutwt-etn"nm=/a/ah/x/lu-ui/m.AExdu"pi=91 om=mut sye"x3name="/devlo0" lg=r"ol pmc r=3an19pfel-nireu-tntgne/rc/cldudmHEqu d97o=otfy=x"ra=d/o/fg""8b:o vhc)nrgibdte646013 veeMzWe oso d<[4715]xr r1eMc egset
> Aug

That is certainly a mess.  Now I don't believe we allow processes in a
user namespace to write to the kernels log (certainly we shouldn't be)
so part of that is not a problem.

What is interleaving messages into syslog?

And to be clear my only perspective is that we need to make certain we
have this thought out.

Eric

  parent reply	other threads:[~2013-08-14 19:21 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-08-07  7:37 [PATCH v3 00/11] Add namespace support for syslog Rui Xiang
2013-08-07  7:37 ` Rui Xiang
2013-08-07  7:37 ` Rui Xiang
     [not found] ` <1375861035-24320-1-git-send-email-rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-07  7:37   ` [PATCH v3 01/11] syslog_ns: add syslog_namespace and put/get_syslog_ns Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37   ` [PATCH v3 02/11] syslog_ns: add syslog_ns into user_namespace Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37   ` [PATCH v3 03/11] syslog_ns: add init syslog_ns for global syslog Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37   ` [PATCH v3 04/11] syslog_ns: make syslog handling per namespace Rui Xiang
2013-08-07  7:37   ` [PATCH v3 05/11] syslog_ns: make permisiion check per user namespace Rui Xiang
2013-08-07  7:37   ` [PATCH v3 06/11] syslog_ns: use init syslog_ns for console action Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37   ` [PATCH v3 07/11] syslog_ns: implement function for creating syslog ns Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
     [not found]     ` <1375861035-24320-8-git-send-email-rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-07 18:59       ` Ben Hutchings
2013-08-07 18:59         ` Ben Hutchings
2013-08-07  7:37   ` [PATCH v3 08/11] syslog_ns: implement ns_printk for specific syslog_ns Rui Xiang
2013-08-07  7:37   ` [PATCH v3 09/11] syslog_ns: implement ns_printk_emit " Rui Xiang
2013-08-07  7:37   ` [PATCH v3 10/11] syslog_ns: implement ns_console_unlock " Rui Xiang
2013-08-07  7:37   ` [PATCH v3 11/11] netfilter: use ns_printk in iptable context Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  7:37     ` Rui Xiang
2013-08-07  9:17     ` Pablo Neira Ayuso
     [not found]     ` <1375861035-24320-12-git-send-email-rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-07  9:17       ` Pablo Neira Ayuso
2013-08-07  7:55   ` [PATCH v3 00/11] Add namespace support for syslog Eric W. Biederman
2013-08-07  7:55     ` Eric W. Biederman
2013-08-07 13:48     ` Serge Hallyn
     [not found]     ` <878v0evssv.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2013-08-07 13:48       ` Serge Hallyn
2013-08-08  1:37       ` Gao feng
2013-08-08  1:37         ` Gao feng
     [not found]         ` <5202F65F.40002-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2013-08-08 11:13           ` Rui Xiang
2013-08-08 11:13             ` Rui Xiang
     [not found]             ` <52037D50.2050109-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-14 15:30               ` Serge E. Hallyn
2013-08-14 15:30                 ` Serge E. Hallyn
     [not found]                 ` <20130814153017.GA18403-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2013-08-14 19:21                   ` Eric W. Biederman [this message]
2013-08-14 19:21                     ` Eric W. Biederman
     [not found]                     ` <87a9kkcc38.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2013-08-17 13:38                       ` Serge E. Hallyn
2013-08-17 13:38                         ` Serge E. Hallyn
2013-08-07  7:37 ` [PATCH v3 04/11] syslog_ns: make syslog handling per namespace Rui Xiang
     [not found]   ` <1375861035-24320-5-git-send-email-rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-07 18:52     ` Ben Hutchings
2013-08-07 18:52       ` Ben Hutchings
2013-08-07  7:37 ` [PATCH v3 05/11] syslog_ns: make permisiion check per user namespace Rui Xiang
     [not found]   ` <1375861035-24320-6-git-send-email-rui.xiang-hv44wF8Li93QT0dZR+AlfA@public.gmane.org>
2013-08-07 18:41     ` Ben Hutchings
2013-08-07 18:41   ` Ben Hutchings
2013-08-07  7:37 ` [PATCH v3 08/11] syslog_ns: implement ns_printk for specific syslog_ns Rui Xiang
2013-08-07  7:37 ` [PATCH v3 09/11] syslog_ns: implement ns_printk_emit " Rui Xiang
2013-08-07  7:37 ` [PATCH v3 10/11] syslog_ns: implement ns_console_unlock " Rui Xiang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87a9kkcc38.fsf@xmission.com \
    --to=ebiederm-as9lmozglivwk0htik3j/w@public.gmane.org \
    --cc=akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=guz.fnst-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org \
    --cc=libo.chen-hv44wF8Li93QT0dZR+AlfA@public.gmane.org \
    --cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=netfilter-devel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org \
    --cc=serge.hallyn-GeWIH/nMZzLQT0dZR+AlfA@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.