netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Kirill A. Shutemov" <kas@openvz.org>
To: "Kirill A. Shutemov" <kas@openvz.org>
Cc: Rob Landley <rlandley@parallels.com>,
	Rob Landley <rob@landley.net>,
	Trond Myklebust <Trond.Myklebust@netapp.com>,
	"J. Bruce Fields" <bfields@fieldses.org>,
	Neil Brown <neilb@suse.de>, Pavel Emelyanov <xemul@parallels.com>,
	linux-nfs@vger.kernel.org,
	"David S. Miller" <davem@davemloft.net>,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 00/12] make rpc_pipefs be mountable multiple time
Date: Mon, 3 Jan 2011 18:53:57 +0200	[thread overview]
Message-ID: <20110103165357.GA32196@shutemov.name> (raw)
In-Reply-To: <20101231130329.GA3610@shutemov.name>

On Fri, Dec 31, 2010 at 03:03:29PM +0200, Kirill A. Shutemov wrote:
> On Thu, Dec 30, 2010 at 06:52:43AM -0600, Rob Landley wrote:
> > On 12/30/2010 05:45 AM, Kirill A. Shutemov wrote:
> > > Currently, there is no association between rpc_pipefs and mount namespace,
> > 
> > There is in that the root context doesn't need to have this mounted, and 
> > new namespaces do.  So there's an existing association between a LACK of 
> > a namespace and a different default behavior.
> >
> > My understanding (correct me if I'm wrong) is that the historical 
> > behavior is that there's only one, and it doesn't actually live anywhere 
> > in the filesystem tree.  You're adding a special location.  I'm 
> > wondering if there's any way for that location not to be special.
> 
> /var/lib/net/rpc_pipefs is default path where userspace part of NFS stack
> (gssd, idmapd) want to see rpc_pipefs
> 
> > > so I don't see simple way to restrict number of rpc_pipefs per mount
> > > namespace. Associating mount namespace with rpc_pipefs is not a good idea,
> > > I think.
> > 
> > I'm talking about associating a default rpc_pipefs instance with a 
> > namespace, which it seems to me you're already doing by emulating the 
> > legacy behavior.  Before you CLONE_NEWNS you get a magic default mount 
> > that doesn't exist in the tree.  After you CLONE_NEWNS you get something 
> > like -EINVAL unless you supply your own default.
> 
> Root namespace is special. In case of nfsroot you need rpc_pipefs before
> root available.
> 
> > (I'm actually not sure 
> > why new namespaces don't fall back to the magic global one...)
> 
> It breaks isolation. Container should not use host's rpc_pipefs without
> host's permission.
>  
> > I'm suggesting that if the user doesn't specify -o rpcmount then the 
> > default could be the first rpc_pipefs mount visible to the current 
> > process context, rather than a specific path.  Logic to do that exists 
> > in the proc/self/mounts code (which I'm reading through now...).
> 
> static int check_rpc_pipefs(struct vfsmount *mnt, void *arg)
> {
>         struct vfsmount **rpcmount = arg;
>         struct path path = {
>                 .mnt = mnt,
>                 .dentry = mnt->mnt_root,
>         };
> 
>         if (!mnt->mnt_sb)
>                 return 0;
>         if (mnt->mnt_sb->s_magic != RPCAUTH_GSSMAGIC)
>                 return 0;
> 
>         if (!path_is_under(&path, &current->fs->root))
>                 return 0;
> 
>         *rpcmount = mntget(mnt);
>         return 1;
> }
> 
> struct vfsmount *get_rpc_pipefs(const char *p)
> {
>         int error;
>         struct vfsmount *rpcmount = ERR_PTR(-EINVAL);
>         struct path path;
> 
>         if (!p) {
>                 iterate_mounts(check_rpc_pipefs, &rpcmount,
>                                 current->nsproxy->mnt_ns->root);
> 
>                 if (IS_ERR(rpcmount) && (current->nsproxy->mnt_ns ==
>                                         init_task.nsproxy->mnt_ns))
>                         return mntget(init_rpc_pipefs);
> 
>                 return rpcmount;
>         }
> 
>         error = kern_path(p, LOOKUP_FOLLOW | LOOKUP_DIRECTORY, &path);
>         if (error)
>                 return ERR_PTR(error);
> 
>         check_rpc_pipefs(path.mnt, &rpcmount);
>         path_put(&path);
> 
>         return rpcmount;
> }
> EXPORT_SYMBOL_GPL(get_rpc_pipefs);
> 
> Something like this? Patch to replace patch #10 attached.

Any comments?

-- 
 Kirill A. Shutemov

  reply	other threads:[~2011-01-03 16:53 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-12-29 13:14 [PATCH v2 00/12] make rpc_pipefs be mountable multiple time Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 01/12] sunrpc: mount rpc_pipefs on initialization Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 02/12] sunrpc: introduce init_rpc_pipefs Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 03/12] sunrpc: push init_rpc_pipefs up to rpc_create() callers Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 04/12] sunrpc: tag svc_serv with rpc_pipefs mount point Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 05/12] sunrpc: get rpc_pipefs mount point for svc_serv from callers Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 06/12] lockd: get rpc_pipefs mount point " Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 07/12] sunrpc: get rpc_pipefs mount point for rpcb_create[_local] " Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 08/12] sunrpc: tag pipefs field of cache_detail with rpc_pipefs mount point Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 10/12] sunrpc: introduce get_rpc_pipefs() Kirill A. Shutemov
2010-12-29 13:14 ` [PATCH v2 12/12] sunrpc: make rpc_pipefs be mountable multiple times Kirill A. Shutemov
     [not found] ` <1293628470-28386-1-git-send-email-kas-GEFAQzZX7r8dnm+yROfE0A@public.gmane.org>
2010-12-29 13:14   ` [PATCH v2 09/12] nfs: per-rpc_pipefs dns cache Kirill A. Shutemov
2010-12-29 13:14   ` [PATCH v2 11/12] nfs: introduce mount option 'rpcmount' Kirill A. Shutemov
2010-12-30  2:13   ` [PATCH v2 00/12] make rpc_pipefs be mountable multiple time Rob Landley
2010-12-30  8:51     ` Kirill A. Shutemov
     [not found]       ` <20101230085139.GA29697-oKw7cIdHH8eLwutG50LtGA@public.gmane.org>
2010-12-30  9:10         ` Rob Landley
     [not found]           ` <4D1C4C7C.6050606-bzQdu9zFT3WakBO8gow8eQ@public.gmane.org>
2010-12-30  9:44             ` Kirill A. Shutemov
2010-12-30 10:05               ` Rob Landley
     [not found]                 ` <4D1C5953.6020200-bzQdu9zFT3WakBO8gow8eQ@public.gmane.org>
2010-12-30 10:44                   ` Kirill A. Shutemov
     [not found]                     ` <20101230104416.GA31824-oKw7cIdHH8eLwutG50LtGA@public.gmane.org>
2010-12-30 11:05                       ` Rob Landley
     [not found]                         ` <AANLkTim2QrkSW0HufD5wp=-8ikwydN5SUS+fdWK6JHqb-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2010-12-30 11:45                           ` Kirill A. Shutemov
2010-12-30 12:52                             ` Rob Landley
2010-12-31 13:03                               ` Kirill A. Shutemov
2011-01-03 16:53                                 ` Kirill A. Shutemov [this message]
     [not found]                                 ` <20101231130329.GA3610-oKw7cIdHH8eLwutG50LtGA@public.gmane.org>
2011-01-03 20:38                                   ` Rob Landley
2010-12-31 16:54                   ` Trond Myklebust
2011-01-03 20:48                     ` Rob Landley
2011-01-05 11:41   ` Al Viro
     [not found]     ` <20110105114155.GN19804-3bDd1+5oDREiFSDQTTA3OLVCufUGDwFn@public.gmane.org>
2011-01-05 13:40       ` Kirill A. Shutemov
2011-01-07 11:12     ` Kirill A. Shutemov
2011-01-07 11:19       ` Kirill A. Shutemov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110103165357.GA32196@shutemov.name \
    --to=kas@openvz.org \
    --cc=Trond.Myklebust@netapp.com \
    --cc=bfields@fieldses.org \
    --cc=davem@davemloft.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=neilb@suse.de \
    --cc=netdev@vger.kernel.org \
    --cc=rlandley@parallels.com \
    --cc=rob@landley.net \
    --cc=xemul@parallels.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).