* [Qemu-devel] [PATCH v5 0/2] balloon: add a feature bit to let Guest OS deflate @ 2015-02-27 6:57 Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 1/2] balloon: call qdev_alias_all_properties for proxy dev in balloon class init Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom Denis V. Lunev 0 siblings, 2 replies; 10+ messages in thread From: Denis V. Lunev @ 2015-02-27 6:57 UTC (permalink / raw) Cc: Denis V. Lunev, Michael S. Tsirkin, qemu-devel, Raushaniya Maksudova, Anthony Liguori Excessive virtio_balloon inflation can cause invocation of OOM-killer, when Linux is under severe memory pressure. Various mechanisms are responsible for correct virtio_balloon memory management. Nevertheless it is often the case that these control tools does not have enough time to react on fast changing memory load. As a result OS runs out of memory and invokes OOM-killer. The balancing of memory by use of the virtio balloon should not cause the termination of processes while there are pages in the balloon. Now there is no way for virtio balloon driver to free memory at the last moment before some process get killed by OOM-killer. This does not provide a security breach as balloon itself is running inside Guest OS and is working in the cooperation with the host. Thus some improvements from Guest side should be considered as normal. To solve the problem, introduce a virtio_balloon callback which is expected to be called from the oom notifier call chain in out_of_memory() function. If virtio balloon could release some memory, it will make the system to return and retry the allocation that forced the out of memory killer to run. This behavior should be enabled if and only if appropriate feature bit is set on the device. It is off by default. This functionality was recently merged into vanilla Linux (actually in linux-next at the moment) commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 Author: Raushaniya Maksudova <rmaksudova@parallels.com> Date: Mon Nov 10 09:36:29 2014 +1030 This patch adds respective control bits into QEMU. It introduces deflate-on-oom option for baloon device which do the trick. Changes from v4: - spelling corrected according to suggestions from Eric Blake Changes from v3: - ported to git://git.kernel.org/pub/scm/virt/kvm/mst/qemu.git tags/for_upstream_rebased Changes from v2: - fixed mistake with bit number in virtio_balloon_get_features Changes from v1: - From: in patch 1 according to the original ownership - feature processing in patch 2 as suggested by Michael. It could be done without additional field, but this will require to move the property level up, i.e. to PCI & CCW level. Signed-off-by: Raushaniya Maksudova <rmaksudova@parallels.com> Signed-off-by: Denis V. Lunev <den@openvz.org> CC: Anthony Liguori <aliguori@amazon.com> CC: Michael S. Tsirkin <mst@redhat.com> GIT [PATCH 1/2] balloon: call qdev_alias_all_properties for proxy dev in ^ permalink raw reply [flat|nested] 10+ messages in thread
* [Qemu-devel] [PATCH 1/2] balloon: call qdev_alias_all_properties for proxy dev in balloon class init 2015-02-27 6:57 [Qemu-devel] [PATCH v5 0/2] balloon: add a feature bit to let Guest OS deflate Denis V. Lunev @ 2015-02-27 6:57 ` Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom Denis V. Lunev 1 sibling, 0 replies; 10+ messages in thread From: Denis V. Lunev @ 2015-02-27 6:57 UTC (permalink / raw) Cc: Raushaniya Maksudova, Michael S. Tsirkin, qemu-devel, Christian Borntraeger, Anthony Liguori, Denis V. Lunev The idea is that all other virtio devices are calling this helper to merge properties of the proxy device. This is the only difference in between this helper and code in inside virtio_instance_init_common. The patch should not cause any harm as property list in generic balloon code is empty. This also allows to avoid some dummy errors like fixed by this commit 91ba21208839643603e7f7fa5864723c3f371ebe Author: Gonglei <arei.gonglei@huawei.com> Date: Tue Sep 30 14:10:35 2014 +0800 virtio-balloon: fix virtio-balloon child refcount in transports Signed-off-by: Denis V. Lunev <den@openvz.org> Signed-off-by: Raushaniya Maksudova <rmaksudova@parallels.com> Revieved-by: Cornelia Huck <cornelia.huck@de.ibm.com> CC: Christian Borntraeger <borntraeger@de.ibm.com> CC: Anthony Liguori <aliguori@amazon.com> CC: Michael S. Tsirkin <mst@redhat.com> Signed-off-by: Denis V. Lunev <den@openvz.org> --- hw/s390x/virtio-ccw.c | 5 ++--- hw/virtio/virtio-pci.c | 5 ++--- 2 files changed, 4 insertions(+), 6 deletions(-) diff --git a/hw/s390x/virtio-ccw.c b/hw/s390x/virtio-ccw.c index 3fee4aa..ffbb9c2 100644 --- a/hw/s390x/virtio-ccw.c +++ b/hw/s390x/virtio-ccw.c @@ -898,9 +898,8 @@ static void balloon_ccw_stats_set_poll_interval(Object *obj, struct Visitor *v, static void virtio_ccw_balloon_instance_init(Object *obj) { VirtIOBalloonCcw *dev = VIRTIO_BALLOON_CCW(obj); - object_initialize(&dev->vdev, sizeof(dev->vdev), TYPE_VIRTIO_BALLOON); - object_property_add_child(obj, "virtio-backend", OBJECT(&dev->vdev), NULL); - object_unref(OBJECT(&dev->vdev)); + virtio_instance_init_common(obj, &dev->vdev, sizeof(dev->vdev), + TYPE_VIRTIO_BALLOON); object_property_add(obj, "guest-stats", "guest statistics", balloon_ccw_stats_get_all, NULL, NULL, dev, NULL); diff --git a/hw/virtio/virtio-pci.c b/hw/virtio/virtio-pci.c index 6dd41b9..e7baf7b 100644 --- a/hw/virtio/virtio-pci.c +++ b/hw/virtio/virtio-pci.c @@ -1274,9 +1274,8 @@ static void virtio_balloon_pci_class_init(ObjectClass *klass, void *data) static void virtio_balloon_pci_instance_init(Object *obj) { VirtIOBalloonPCI *dev = VIRTIO_BALLOON_PCI(obj); - object_initialize(&dev->vdev, sizeof(dev->vdev), TYPE_VIRTIO_BALLOON); - object_property_add_child(obj, "virtio-backend", OBJECT(&dev->vdev), NULL); - object_unref(OBJECT(&dev->vdev)); + virtio_instance_init_common(obj, &dev->vdev, sizeof(dev->vdev), + TYPE_VIRTIO_BALLOON); object_property_add(obj, "guest-stats", "guest statistics", balloon_pci_stats_get_all, NULL, NULL, dev, NULL); -- 1.9.1 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-02-27 6:57 [Qemu-devel] [PATCH v5 0/2] balloon: add a feature bit to let Guest OS deflate Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 1/2] balloon: call qdev_alias_all_properties for proxy dev in balloon class init Denis V. Lunev @ 2015-02-27 6:57 ` Denis V. Lunev 2015-04-01 9:44 ` James Bottomley 1 sibling, 1 reply; 10+ messages in thread From: Denis V. Lunev @ 2015-02-27 6:57 UTC (permalink / raw) Cc: Denis V. Lunev, Michael S. Tsirkin, qemu-devel, Raushaniya Maksudova, Anthony Liguori Excessive virtio_balloon inflation can cause invocation of OOM-killer, when Linux is under severe memory pressure. Various mechanisms are responsible for correct virtio_balloon memory management. Nevertheless it is often the case that these control tools does not have enough time to react on fast changing memory load. As a result OS runs out of memory and invokes OOM-killer. The balancing of memory by use of the virtio balloon should not cause the termination of processes while there are pages in the balloon. Now there is no way for virtio balloon driver to free memory at the last moment before some process get killed by OOM-killer. This does not provide a security breach as balloon itself is running inside Guest OS and is working in the cooperation with the host. Thus some improvements from Guest side should be considered as normal. To solve the problem, introduce a virtio_balloon callback which is expected to be called from the oom notifier call chain in out_of_memory() function. If virtio balloon could release some memory, it will make the system return and retry the allocation that forced the out of memory killer to run. This behavior should be enabled if and only if appropriate feature bit is set on the device. It is off by default. This functionality was recently merged into vanilla Linux. commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 Author: Raushaniya Maksudova <rmaksudova@parallels.com> Date: Mon Nov 10 09:36:29 2014 +1030 This patch adds respective control bits into QEMU. It introduces deflate-on-oom option for balloon device which does the trick. Signed-off-by: Denis V. Lunev <den@openvz.org> CC: Raushaniya Maksudova <rmaksudova@parallels.com> CC: Anthony Liguori <aliguori@amazon.com> CC: Michael S. Tsirkin <mst@redhat.com> --- hw/virtio/virtio-balloon.c | 6 ++++-- include/hw/virtio/virtio-balloon.h | 1 + 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/hw/virtio/virtio-balloon.c b/hw/virtio/virtio-balloon.c index 21e449a..cbc5f7f 100644 --- a/hw/virtio/virtio-balloon.c +++ b/hw/virtio/virtio-balloon.c @@ -305,8 +305,8 @@ static void virtio_balloon_set_config(VirtIODevice *vdev, static uint32_t virtio_balloon_get_features(VirtIODevice *vdev, uint32_t f) { - f |= (1 << VIRTIO_BALLOON_F_STATS_VQ); - return f; + VirtIOBalloon *dev = VIRTIO_BALLOON(vdev); + return f | (1u << VIRTIO_BALLOON_F_STATS_VQ) | dev->host_features; } static void virtio_balloon_stat(void *opaque, BalloonInfo *info) @@ -409,6 +409,8 @@ static void virtio_balloon_device_unrealize(DeviceState *dev, Error **errp) } static Property virtio_balloon_properties[] = { + DEFINE_PROP_BIT("deflate-on-oom", VirtIOBalloon, host_features, + VIRTIO_BALLOON_F_DEFLATE_ON_OOM, false), DEFINE_PROP_END_OF_LIST(), }; diff --git a/include/hw/virtio/virtio-balloon.h b/include/hw/virtio/virtio-balloon.h index 4ab8f54..7f49b1f 100644 --- a/include/hw/virtio/virtio-balloon.h +++ b/include/hw/virtio/virtio-balloon.h @@ -36,6 +36,7 @@ typedef struct VirtIOBalloon { QEMUTimer *stats_timer; int64_t stats_last_update; int64_t stats_poll_interval; + uint32_t host_features; } VirtIOBalloon; #endif -- 1.9.1 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-02-27 6:57 ` [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom Denis V. Lunev @ 2015-04-01 9:44 ` James Bottomley 2015-04-01 9:50 ` Michael S. Tsirkin 0 siblings, 1 reply; 10+ messages in thread From: James Bottomley @ 2015-04-01 9:44 UTC (permalink / raw) To: Denis V. Lunev Cc: Michael S. Tsirkin, qemu-devel, Raushaniya Maksudova, Anthony Liguori On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > Excessive virtio_balloon inflation can cause invocation of OOM-killer, > when Linux is under severe memory pressure. Various mechanisms are > responsible for correct virtio_balloon memory management. Nevertheless it > is often the case that these control tools does not have enough time to > react on fast changing memory load. As a result OS runs out of memory and > invokes OOM-killer. The balancing of memory by use of the virtio balloon > should not cause the termination of processes while there are pages in the > balloon. Now there is no way for virtio balloon driver to free memory at > the last moment before some process get killed by OOM-killer. > > This does not provide a security breach as balloon itself is running > inside Guest OS and is working in the cooperation with the host. Thus > some improvements from Guest side should be considered as normal. > > To solve the problem, introduce a virtio_balloon callback which is > expected to be called from the oom notifier call chain in out_of_memory() > function. If virtio balloon could release some memory, it will make the > system return and retry the allocation that forced the out of memory > killer to run. > > This behavior should be enabled if and only if appropriate feature bit > is set on the device. It is off by default. > > This functionality was recently merged into vanilla Linux. > > commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > Author: Raushaniya Maksudova <rmaksudova@parallels.com> > Date: Mon Nov 10 09:36:29 2014 +1030 > > This patch adds respective control bits into QEMU. It introduces > deflate-on-oom option for balloon device which does the trick. What's the status on this, please? It's been over a month since this was posted with no further review feedback, so I think it's ready. Getting this into qemu is blocking our next step which would be adding the feature bit to the virtio spec. James ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-04-01 9:44 ` James Bottomley @ 2015-04-01 9:50 ` Michael S. Tsirkin 2015-04-01 9:51 ` James Bottomley 0 siblings, 1 reply; 10+ messages in thread From: Michael S. Tsirkin @ 2015-04-01 9:50 UTC (permalink / raw) To: James Bottomley Cc: Denis V. Lunev, qemu-devel, Raushaniya Maksudova, Anthony Liguori On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: > On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > > Excessive virtio_balloon inflation can cause invocation of OOM-killer, > > when Linux is under severe memory pressure. Various mechanisms are > > responsible for correct virtio_balloon memory management. Nevertheless it > > is often the case that these control tools does not have enough time to > > react on fast changing memory load. As a result OS runs out of memory and > > invokes OOM-killer. The balancing of memory by use of the virtio balloon > > should not cause the termination of processes while there are pages in the > > balloon. Now there is no way for virtio balloon driver to free memory at > > the last moment before some process get killed by OOM-killer. > > > > This does not provide a security breach as balloon itself is running > > inside Guest OS and is working in the cooperation with the host. Thus > > some improvements from Guest side should be considered as normal. > > > > To solve the problem, introduce a virtio_balloon callback which is > > expected to be called from the oom notifier call chain in out_of_memory() > > function. If virtio balloon could release some memory, it will make the > > system return and retry the allocation that forced the out of memory > > killer to run. > > > > This behavior should be enabled if and only if appropriate feature bit > > is set on the device. It is off by default. > > > > This functionality was recently merged into vanilla Linux. > > > > commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > > Author: Raushaniya Maksudova <rmaksudova@parallels.com> > > Date: Mon Nov 10 09:36:29 2014 +1030 > > > > This patch adds respective control bits into QEMU. It introduces > > deflate-on-oom option for balloon device which does the trick. > > What's the status on this, please? It's been over a month since this > was posted with no further review feedback, so I think it's ready. > Getting this into qemu is blocking our next step which would be adding > the feature bit to the virtio spec. > > James This was posted after soft feature freeze for 2.3, so it'll have to go into 2.4. I don't see why would this block your work on the spec: you should make progress on this meanwhile. -- MST ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-04-01 9:50 ` Michael S. Tsirkin @ 2015-04-01 9:51 ` James Bottomley 2015-04-01 10:18 ` Michael S. Tsirkin 0 siblings, 1 reply; 10+ messages in thread From: James Bottomley @ 2015-04-01 9:51 UTC (permalink / raw) To: Michael S. Tsirkin Cc: Denis V. Lunev, qemu-devel, Raushaniya Maksudova, Anthony Liguori On Wed, 2015-04-01 at 11:50 +0200, Michael S. Tsirkin wrote: > On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: > > On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > > > Excessive virtio_balloon inflation can cause invocation of OOM-killer, > > > when Linux is under severe memory pressure. Various mechanisms are > > > responsible for correct virtio_balloon memory management. Nevertheless it > > > is often the case that these control tools does not have enough time to > > > react on fast changing memory load. As a result OS runs out of memory and > > > invokes OOM-killer. The balancing of memory by use of the virtio balloon > > > should not cause the termination of processes while there are pages in the > > > balloon. Now there is no way for virtio balloon driver to free memory at > > > the last moment before some process get killed by OOM-killer. > > > > > > This does not provide a security breach as balloon itself is running > > > inside Guest OS and is working in the cooperation with the host. Thus > > > some improvements from Guest side should be considered as normal. > > > > > > To solve the problem, introduce a virtio_balloon callback which is > > > expected to be called from the oom notifier call chain in out_of_memory() > > > function. If virtio balloon could release some memory, it will make the > > > system return and retry the allocation that forced the out of memory > > > killer to run. > > > > > > This behavior should be enabled if and only if appropriate feature bit > > > is set on the device. It is off by default. > > > > > > This functionality was recently merged into vanilla Linux. > > > > > > commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > > > Author: Raushaniya Maksudova <rmaksudova@parallels.com> > > > Date: Mon Nov 10 09:36:29 2014 +1030 > > > > > > This patch adds respective control bits into QEMU. It introduces > > > deflate-on-oom option for balloon device which does the trick. > > > > What's the status on this, please? It's been over a month since this > > was posted with no further review feedback, so I think it's ready. > > Getting this into qemu is blocking our next step which would be adding > > the feature bit to the virtio spec. > > > > James > > This was posted after soft feature freeze for 2.3, so it'll have to go > into 2.4. I don't see why would this block your work on the spec: you > should make progress on this meanwhile. I can do that ... I just thought the spec was trailing edge, so I was waiting to have the patch accepted, which confirms the implementation. I didn't want to write it into the spec and have the actual implementation changed by review later. James ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-04-01 9:51 ` James Bottomley @ 2015-04-01 10:18 ` Michael S. Tsirkin 2015-05-04 9:47 ` Denis V. Lunev 0 siblings, 1 reply; 10+ messages in thread From: Michael S. Tsirkin @ 2015-04-01 10:18 UTC (permalink / raw) To: James Bottomley Cc: Denis V. Lunev, qemu-devel, Raushaniya Maksudova, Anthony Liguori On Wed, Apr 01, 2015 at 12:51:42PM +0300, James Bottomley wrote: > On Wed, 2015-04-01 at 11:50 +0200, Michael S. Tsirkin wrote: > > On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: > > > On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > > > > Excessive virtio_balloon inflation can cause invocation of OOM-killer, > > > > when Linux is under severe memory pressure. Various mechanisms are > > > > responsible for correct virtio_balloon memory management. Nevertheless it > > > > is often the case that these control tools does not have enough time to > > > > react on fast changing memory load. As a result OS runs out of memory and > > > > invokes OOM-killer. The balancing of memory by use of the virtio balloon > > > > should not cause the termination of processes while there are pages in the > > > > balloon. Now there is no way for virtio balloon driver to free memory at > > > > the last moment before some process get killed by OOM-killer. > > > > > > > > This does not provide a security breach as balloon itself is running > > > > inside Guest OS and is working in the cooperation with the host. Thus > > > > some improvements from Guest side should be considered as normal. > > > > > > > > To solve the problem, introduce a virtio_balloon callback which is > > > > expected to be called from the oom notifier call chain in out_of_memory() > > > > function. If virtio balloon could release some memory, it will make the > > > > system return and retry the allocation that forced the out of memory > > > > killer to run. > > > > > > > > This behavior should be enabled if and only if appropriate feature bit > > > > is set on the device. It is off by default. > > > > > > > > This functionality was recently merged into vanilla Linux. > > > > > > > > commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > > > > Author: Raushaniya Maksudova <rmaksudova@parallels.com> > > > > Date: Mon Nov 10 09:36:29 2014 +1030 > > > > > > > > This patch adds respective control bits into QEMU. It introduces > > > > deflate-on-oom option for balloon device which does the trick. > > > > > > What's the status on this, please? It's been over a month since this > > > was posted with no further review feedback, so I think it's ready. > > > Getting this into qemu is blocking our next step which would be adding > > > the feature bit to the virtio spec. > > > > > > James > > > > This was posted after soft feature freeze for 2.3, so it'll have to go > > into 2.4. I don't see why would this block your work on the spec: you > > should make progress on this meanwhile. > > I can do that ... I just thought the spec was trailing edge, so I was > waiting to have the patch accepted, which confirms the implementation. > I didn't want to write it into the spec and have the actual > implementation changed by review later. > > James > It's up to you really, I would just like to point out two things: - spec process is a long one, assuming we accept a spec change, we go though a public review period, multiple votes etc. About half a year to release a spec revision with new features. So time enough to make minor changes. - oasis process works like this (roughly): spec is written spec goes through a public review process community standard is published 3 implementations are reported spec becomes an oasis standard so implementations aren't required at early stages -- MST ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-04-01 10:18 ` Michael S. Tsirkin @ 2015-05-04 9:47 ` Denis V. Lunev 2015-06-08 14:54 ` James Bottomley 0 siblings, 1 reply; 10+ messages in thread From: Denis V. Lunev @ 2015-05-04 9:47 UTC (permalink / raw) To: Michael S. Tsirkin, James Bottomley Cc: qemu-devel, Raushaniya Maksudova, Anthony Liguori On 01/04/15 13:18, Michael S. Tsirkin wrote: > On Wed, Apr 01, 2015 at 12:51:42PM +0300, James Bottomley wrote: >> On Wed, 2015-04-01 at 11:50 +0200, Michael S. Tsirkin wrote: >>> On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: >>>> On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: >>>>> Excessive virtio_balloon inflation can cause invocation of OOM-killer, >>>>> when Linux is under severe memory pressure. Various mechanisms are >>>>> responsible for correct virtio_balloon memory management. Nevertheless it >>>>> is often the case that these control tools does not have enough time to >>>>> react on fast changing memory load. As a result OS runs out of memory and >>>>> invokes OOM-killer. The balancing of memory by use of the virtio balloon >>>>> should not cause the termination of processes while there are pages in the >>>>> balloon. Now there is no way for virtio balloon driver to free memory at >>>>> the last moment before some process get killed by OOM-killer. >>>>> >>>>> This does not provide a security breach as balloon itself is running >>>>> inside Guest OS and is working in the cooperation with the host. Thus >>>>> some improvements from Guest side should be considered as normal. >>>>> >>>>> To solve the problem, introduce a virtio_balloon callback which is >>>>> expected to be called from the oom notifier call chain in out_of_memory() >>>>> function. If virtio balloon could release some memory, it will make the >>>>> system return and retry the allocation that forced the out of memory >>>>> killer to run. >>>>> >>>>> This behavior should be enabled if and only if appropriate feature bit >>>>> is set on the device. It is off by default. >>>>> >>>>> This functionality was recently merged into vanilla Linux. >>>>> >>>>> commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 >>>>> Author: Raushaniya Maksudova <rmaksudova@parallels.com> >>>>> Date: Mon Nov 10 09:36:29 2014 +1030 >>>>> >>>>> This patch adds respective control bits into QEMU. It introduces >>>>> deflate-on-oom option for balloon device which does the trick. >>>> What's the status on this, please? It's been over a month since this >>>> was posted with no further review feedback, so I think it's ready. >>>> Getting this into qemu is blocking our next step which would be adding >>>> the feature bit to the virtio spec. >>>> >>>> James >>> This was posted after soft feature freeze for 2.3, so it'll have to go >>> into 2.4. I don't see why would this block your work on the spec: you >>> should make progress on this meanwhile. >> I can do that ... I just thought the spec was trailing edge, so I was >> waiting to have the patch accepted, which confirms the implementation. >> I didn't want to write it into the spec and have the actual >> implementation changed by review later. >> >> James >> > It's up to you really, I would just like to point out two things: > - spec process is a long one, assuming we accept a spec change, > we go though a public review period, multiple votes etc. > About half a year to release a spec revision with > new features. > So time enough to make minor changes. > - oasis process works like this (roughly): > spec is written > spec goes through a public review process > community standard is published > 3 implementations are reported > spec becomes an oasis standard > so implementations aren't required at early stages 2.3 is done, 2.4 window is opened.... The patch is applicable for both git://git.kernel.org/pub/scm/virt/kvm/mst/qemu.git and vanilla qemu. How can we proceed? ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-05-04 9:47 ` Denis V. Lunev @ 2015-06-08 14:54 ` James Bottomley 2015-06-08 15:24 ` Michael S. Tsirkin 0 siblings, 1 reply; 10+ messages in thread From: James Bottomley @ 2015-06-08 14:54 UTC (permalink / raw) To: Denis V. Lunev Cc: Anthony Liguori, qemu-devel, Raushaniya Maksudova, Michael S. Tsirkin On Mon, 2015-05-04 at 12:47 +0300, Denis V. Lunev wrote: > On 01/04/15 13:18, Michael S. Tsirkin wrote: > > On Wed, Apr 01, 2015 at 12:51:42PM +0300, James Bottomley wrote: > >> On Wed, 2015-04-01 at 11:50 +0200, Michael S. Tsirkin wrote: > >>> On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: > >>>> On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > >>>>> Excessive virtio_balloon inflation can cause invocation of OOM-killer, > >>>>> when Linux is under severe memory pressure. Various mechanisms are > >>>>> responsible for correct virtio_balloon memory management. Nevertheless it > >>>>> is often the case that these control tools does not have enough time to > >>>>> react on fast changing memory load. As a result OS runs out of memory and > >>>>> invokes OOM-killer. The balancing of memory by use of the virtio balloon > >>>>> should not cause the termination of processes while there are pages in the > >>>>> balloon. Now there is no way for virtio balloon driver to free memory at > >>>>> the last moment before some process get killed by OOM-killer. > >>>>> > >>>>> This does not provide a security breach as balloon itself is running > >>>>> inside Guest OS and is working in the cooperation with the host. Thus > >>>>> some improvements from Guest side should be considered as normal. > >>>>> > >>>>> To solve the problem, introduce a virtio_balloon callback which is > >>>>> expected to be called from the oom notifier call chain in out_of_memory() > >>>>> function. If virtio balloon could release some memory, it will make the > >>>>> system return and retry the allocation that forced the out of memory > >>>>> killer to run. > >>>>> > >>>>> This behavior should be enabled if and only if appropriate feature bit > >>>>> is set on the device. It is off by default. > >>>>> > >>>>> This functionality was recently merged into vanilla Linux. > >>>>> > >>>>> commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > >>>>> Author: Raushaniya Maksudova <rmaksudova@parallels.com> > >>>>> Date: Mon Nov 10 09:36:29 2014 +1030 > >>>>> > >>>>> This patch adds respective control bits into QEMU. It introduces > >>>>> deflate-on-oom option for balloon device which does the trick. > >>>> What's the status on this, please? It's been over a month since this > >>>> was posted with no further review feedback, so I think it's ready. > >>>> Getting this into qemu is blocking our next step which would be adding > >>>> the feature bit to the virtio spec. > >>>> > >>>> James > >>> This was posted after soft feature freeze for 2.3, so it'll have to go > >>> into 2.4. I don't see why would this block your work on the spec: you > >>> should make progress on this meanwhile. > >> I can do that ... I just thought the spec was trailing edge, so I was > >> waiting to have the patch accepted, which confirms the implementation. > >> I didn't want to write it into the spec and have the actual > >> implementation changed by review later. > >> > >> James > >> > > It's up to you really, I would just like to point out two things: > > - spec process is a long one, assuming we accept a spec change, > > we go though a public review period, multiple votes etc. > > About half a year to release a spec revision with > > new features. > > So time enough to make minor changes. > > - oasis process works like this (roughly): > > spec is written > > spec goes through a public review process > > community standard is published > > 3 implementations are reported > > spec becomes an oasis standard > > so implementations aren't required at early stages > 2.3 is done, 2.4 window is opened.... > > The patch is applicable for both > git://git.kernel.org/pub/scm/virt/kvm/mst/qemu.git > and vanilla qemu. > > How can we proceed? The spec update supporting this feature is published for review: https://www.oasis-open.org/committees/download.php/55709/virtio-v1.0-csprd04.zip It's probably a good idea to have the implementation there as well. Do we need to resend these patches? James ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom 2015-06-08 14:54 ` James Bottomley @ 2015-06-08 15:24 ` Michael S. Tsirkin 0 siblings, 0 replies; 10+ messages in thread From: Michael S. Tsirkin @ 2015-06-08 15:24 UTC (permalink / raw) To: James Bottomley Cc: Denis V. Lunev, qemu-devel, Raushaniya Maksudova, Anthony Liguori On Mon, Jun 08, 2015 at 07:54:42AM -0700, James Bottomley wrote: > On Mon, 2015-05-04 at 12:47 +0300, Denis V. Lunev wrote: > > On 01/04/15 13:18, Michael S. Tsirkin wrote: > > > On Wed, Apr 01, 2015 at 12:51:42PM +0300, James Bottomley wrote: > > >> On Wed, 2015-04-01 at 11:50 +0200, Michael S. Tsirkin wrote: > > >>> On Wed, Apr 01, 2015 at 12:44:28PM +0300, James Bottomley wrote: > > >>>> On Fri, 2015-02-27 at 09:57 +0300, Denis V. Lunev wrote: > > >>>>> Excessive virtio_balloon inflation can cause invocation of OOM-killer, > > >>>>> when Linux is under severe memory pressure. Various mechanisms are > > >>>>> responsible for correct virtio_balloon memory management. Nevertheless it > > >>>>> is often the case that these control tools does not have enough time to > > >>>>> react on fast changing memory load. As a result OS runs out of memory and > > >>>>> invokes OOM-killer. The balancing of memory by use of the virtio balloon > > >>>>> should not cause the termination of processes while there are pages in the > > >>>>> balloon. Now there is no way for virtio balloon driver to free memory at > > >>>>> the last moment before some process get killed by OOM-killer. > > >>>>> > > >>>>> This does not provide a security breach as balloon itself is running > > >>>>> inside Guest OS and is working in the cooperation with the host. Thus > > >>>>> some improvements from Guest side should be considered as normal. > > >>>>> > > >>>>> To solve the problem, introduce a virtio_balloon callback which is > > >>>>> expected to be called from the oom notifier call chain in out_of_memory() > > >>>>> function. If virtio balloon could release some memory, it will make the > > >>>>> system return and retry the allocation that forced the out of memory > > >>>>> killer to run. > > >>>>> > > >>>>> This behavior should be enabled if and only if appropriate feature bit > > >>>>> is set on the device. It is off by default. > > >>>>> > > >>>>> This functionality was recently merged into vanilla Linux. > > >>>>> > > >>>>> commit 5a10b7dbf904bfe01bb9fcc6298f7df09eed77d5 > > >>>>> Author: Raushaniya Maksudova <rmaksudova@parallels.com> > > >>>>> Date: Mon Nov 10 09:36:29 2014 +1030 > > >>>>> > > >>>>> This patch adds respective control bits into QEMU. It introduces > > >>>>> deflate-on-oom option for balloon device which does the trick. > > >>>> What's the status on this, please? It's been over a month since this > > >>>> was posted with no further review feedback, so I think it's ready. > > >>>> Getting this into qemu is blocking our next step which would be adding > > >>>> the feature bit to the virtio spec. > > >>>> > > >>>> James > > >>> This was posted after soft feature freeze for 2.3, so it'll have to go > > >>> into 2.4. I don't see why would this block your work on the spec: you > > >>> should make progress on this meanwhile. > > >> I can do that ... I just thought the spec was trailing edge, so I was > > >> waiting to have the patch accepted, which confirms the implementation. > > >> I didn't want to write it into the spec and have the actual > > >> implementation changed by review later. > > >> > > >> James > > >> > > > It's up to you really, I would just like to point out two things: > > > - spec process is a long one, assuming we accept a spec change, > > > we go though a public review period, multiple votes etc. > > > About half a year to release a spec revision with > > > new features. > > > So time enough to make minor changes. > > > - oasis process works like this (roughly): > > > spec is written > > > spec goes through a public review process > > > community standard is published > > > 3 implementations are reported > > > spec becomes an oasis standard > > > so implementations aren't required at early stages > > 2.3 is done, 2.4 window is opened.... > > > > The patch is applicable for both > > git://git.kernel.org/pub/scm/virt/kvm/mst/qemu.git > > and vanilla qemu. > > > > How can we proceed? > > The spec update supporting this feature is published for review: > > https://www.oasis-open.org/committees/download.php/55709/virtio-v1.0-csprd04.zip > > It's probably a good idea to have the implementation there as well. Do > we need to resend these patches? > > James > Yes, please do. ^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2015-06-08 15:24 UTC | newest] Thread overview: 10+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2015-02-27 6:57 [Qemu-devel] [PATCH v5 0/2] balloon: add a feature bit to let Guest OS deflate Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 1/2] balloon: call qdev_alias_all_properties for proxy dev in balloon class init Denis V. Lunev 2015-02-27 6:57 ` [Qemu-devel] [PATCH 2/2] balloon: add a feature bit to let Guest OS deflate balloon on oom Denis V. Lunev 2015-04-01 9:44 ` James Bottomley 2015-04-01 9:50 ` Michael S. Tsirkin 2015-04-01 9:51 ` James Bottomley 2015-04-01 10:18 ` Michael S. Tsirkin 2015-05-04 9:47 ` Denis V. Lunev 2015-06-08 14:54 ` James Bottomley 2015-06-08 15:24 ` Michael S. Tsirkin
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).