From: "Aneesh Kumar K. V" <aneesh.kumar@linux.vnet.ibm.com>
To: Neil Brown <neilb@suse.de>, Andreas Dilger <andreas.dilger@oracle.com>
Cc: hch@infradead.org,
"viro\@zeniv.linux.org.uk" <viro@zeniv.linux.org.uk>,
"adilger\@sun.com" <adilger@sun.com>,
"corbet\@lwn.net" <corbet@lwn.net>,
"serue\@us.ibm.com" <serue@us.ibm.com>,
"hooanon05\@yahoo.co.jp" <hooanon05@yahoo.co.jp>,
"bfields\@fieldses.org" <bfields@fieldses.org>,
"linux-fsdevel\@vger.kernel.org" <linux-fsdevel@vger.kernel.org>,
"sfrench\@us.ibm.com" <sfrench@us.ibm.com>,
"philippe.deniel\@CEA.FR" <philippe.deniel@CEA.FR>,
"linux-kernel\@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH -V14 0/11] Generic name to handle and open by handle syscalls
Date: Sat, 03 Jul 2010 21:34:00 +0530 [thread overview]
Message-ID: <87630w1rin.fsf@linux.vnet.ibm.com> (raw)
In-Reply-To: <20100703080904.78e4e7e1@notabene.brown>
On Sat, 3 Jul 2010 08:09:04 +1000, Neil Brown <neilb@suse.de> wrote:
> On Fri, 2 Jul 2010 10:12:47 -0600
> Andreas Dilger <andreas.dilger@oracle.com> wrote:
>
> > On 2010-07-02, at 01:05, hch@infradead.org wrote:
> > > On Thu, Jul 01, 2010 at 10:02:29PM -0600, Andreas Dilger wrote:
> > >> I'd like to be able to use this interface to implement the distributed open call proposed by the POSIX HECWG. This allows one client to do the path traversal, broadcast the file handle to the (maybe) 1M processes in the job via MPI, and then the other clients can open the file by handle without doing 1M times the full path traversal (which might be 10's of RPCs per process).
> > >
> > > The proposal is doomed anyway. If we allow any sort of open by handle
> > > system call for unprivilegued users we need to do reconnect the dentry
> > > to the dcache path anyway (reconnect_path), which is more expensive than
> > > a normal path lookup.
> >
> > I haven't looked at this part of the VFS in a while, but it looks like an implementation issue specific to knfsd, and shouldn't be needed for regular files. i.e. if exportfs_encode_fh() is never used on a disconnected file, then this overhead is not incurred.
> >
> > The above use of open_by_handle() is not for userspace NFS/Samba re-export, but to allow applications to open regular files for IO.
> >
>
> From my recollection of implementing dentry reconnection there are two
> needs for it.
>
> Firstly it is needed for directories so that the VFS can effectively lock
> against directory rename races which could otherwise create disconnected
> subtrees (where the first parent is a member only of one of its
> descendants). So if you get a filehandle for a directory it *must* be
> properly connected to the root for rename to be safe. This operation is
> faster than a full path lookup if the dentry is already is cache, and slower
> if it and any of the path is not in cache.
> You could possibly delay the full-connection of the dentry until the first
> attempt to rename beneath it. I'm not sure how much VFS surgery that would
> require.
>
> Secondly it is needed if you want to enforce the rule that the contents of a
> directory are only accessible if the 'x' bit on the directory is set.
> kNFSd does not enforce this (unless subtree_check is specified), partly
> because it is hard to do correctly and partly because we have to trust the
> client any, so trusting it to check the 'x' bit is very little extra trust.
>
> Note that it is not possible to reliably perform filehandle lookup for
> non-directories if you need a fully reconnected dentry, as
> cross-directory-renames can confuse the situation beyond recovery.
>
> Maybe open-by-handle should require DAC_OVERRIDE, or maybe a new
> DAC_X_OVERRIDE. And if those aren't provided it only works for directories.
> ???
>
Currently I have the below in open_by_handle
/*
* With handle we don't look at the execute bit on the
* the directory. Ideally we would like CAP_DAC_SEARCH.
* But we don't have that
*/
if (!capable(CAP_DAC_READ_SEARCH)) {
retval = -EPERM;
goto out_err;
}
-aneesh
prev parent reply other threads:[~2010-07-03 16:04 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-06-15 17:12 [PATCH -V14 0/11] Generic name to handle and open by handle syscalls Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 01/11] exportfs: Return the minimum required handle size Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 02/11] vfs: Add name to file handle conversion support Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 03/11] vfs: Add open by file handle support Aneesh Kumar K.V
2010-07-07 15:17 ` Nick Piggin
2010-07-07 16:16 ` Aneesh Kumar K. V
2010-06-15 17:12 ` [PATCH -V14 04/11] vfs: Allow handle based open on symlinks Aneesh Kumar K.V
2010-07-07 15:23 ` Nick Piggin
2010-07-07 16:24 ` Aneesh Kumar K. V
2010-07-07 16:57 ` Nick Piggin
2010-07-07 17:53 ` Aneesh Kumar K. V
2010-07-07 18:20 ` Nick Piggin
2010-07-07 16:48 ` Nick Piggin
2010-07-08 10:42 ` Aneesh Kumar K. V
2010-06-15 17:12 ` [PATCH -V14 05/11] vfs: Support null pathname in readlink Aneesh Kumar K.V
2010-07-07 15:27 ` Nick Piggin
2010-07-07 16:32 ` Aneesh Kumar K. V
2010-07-07 17:03 ` Nick Piggin
2010-06-15 17:12 ` [PATCH -V14 06/11] ext4: Copy fs UUID to superblock Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 07/11] x86: Add new syscalls for x86_32 Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 08/11] x86: Add new syscalls for x86_64 Aneesh Kumar K.V
2010-06-15 17:12 ` [PATCH -V14 09/11] ext3: Copy fs UUID to superblock Aneesh Kumar K.V
2010-06-15 17:13 ` [PATCH -V14 10/11] vfs: Support null pathname in faccessat Aneesh Kumar K.V
2010-06-15 17:13 ` [PATCH -V14 11/11] vfs: Support null pathname in linkat Aneesh Kumar K.V
2010-07-01 16:28 ` [PATCH -V14 0/11] Generic name to handle and open by handle syscalls Aneesh Kumar K. V
2010-07-01 20:41 ` Neil Brown
2010-07-01 21:15 ` Aneesh Kumar K. V
2010-07-06 16:10 ` J. Bruce Fields
2010-07-06 17:09 ` Aneesh Kumar K. V
2010-07-06 23:23 ` Dave Chinner
2010-07-06 23:36 ` Neil Brown
2010-07-07 2:11 ` Dave Chinner
2010-07-07 2:57 ` Neil Brown
2010-07-07 12:44 ` Miklos Szeredi
2010-07-07 12:57 ` J. Bruce Fields
2010-07-07 13:10 ` Miklos Szeredi
2010-07-07 13:17 ` J. Bruce Fields
2010-07-07 13:35 ` Miklos Szeredi
2010-07-07 14:45 ` J. Bruce Fields
2010-07-07 16:33 ` Aneesh Kumar K. V
2010-07-07 16:39 ` J. Bruce Fields
2010-07-07 22:21 ` Neil Brown
2010-07-07 22:25 ` J. Bruce Fields
2010-07-08 0:03 ` Andreas Dilger
2010-07-08 5:03 ` Neil Brown
2010-07-08 10:40 ` Aneesh Kumar K. V
2010-07-08 11:52 ` Miklos Szeredi
2010-07-08 12:21 ` Neil Brown
2010-07-09 18:42 ` Andreas Dilger
2010-07-10 4:58 ` Aneesh Kumar K. V
2010-07-07 7:40 ` Andreas Dilger
2010-07-07 15:05 ` J. Bruce Fields
2010-07-07 17:02 ` Andreas Dilger
2010-07-07 17:37 ` J. Bruce Fields
2010-07-07 18:05 ` Nick Piggin
2010-07-07 23:49 ` Andreas Dilger
2010-07-07 18:18 ` Aneesh Kumar K. V
2010-07-07 20:39 ` Alan Cox
2010-07-07 23:54 ` Andreas Dilger
2010-07-02 4:02 ` Andreas Dilger
2010-07-02 7:05 ` hch
2010-07-02 16:12 ` Andreas Dilger
2010-07-02 22:09 ` Neil Brown
2010-07-02 22:47 ` Andreas Dilger
2010-07-03 16:04 ` Aneesh Kumar K. V [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87630w1rin.fsf@linux.vnet.ibm.com \
--to=aneesh.kumar@linux.vnet.ibm.com \
--cc=adilger@sun.com \
--cc=andreas.dilger@oracle.com \
--cc=bfields@fieldses.org \
--cc=corbet@lwn.net \
--cc=hch@infradead.org \
--cc=hooanon05@yahoo.co.jp \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=neilb@suse.de \
--cc=philippe.deniel@CEA.FR \
--cc=serue@us.ibm.com \
--cc=sfrench@us.ibm.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).