Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1183770 > unrolled thread
| Started by | Vivek Goyal <vgoyal@redhat.com> |
|---|---|
| First post | 2015-07-14 17:10 +0200 |
| Last post | 2015-07-15 12:50 +0200 |
| Articles | 6 — 3 participants |
Back to article view | Back to linux.kernel
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available Vivek Goyal <vgoyal@redhat.com> - 2015-07-14 17:10 +0200
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available dwalker@fifo99.com - 2015-07-14 17:40 +0200
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available dwalker@fifo99.com - 2015-07-14 17:50 +0200
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available Vivek Goyal <vgoyal@redhat.com> - 2015-07-14 18:20 +0200
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available Vivek Goyal <vgoyal@redhat.com> - 2015-07-14 17:50 +0200
Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> - 2015-07-15 12:50 +0200
| From | Vivek Goyal <vgoyal@redhat.com> |
|---|---|
| Date | 2015-07-14 17:10 +0200 |
| Subject | Re: [PATCH 1/3] panic: Disable crash_kexec_post_notifiers if kdump is not available |
| Message-ID | <pMa0i-3Rk-25@gated-at.bofh.it> |
On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: > On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: > > dwalker@fifo99.com writes: > > > > > On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: > > >> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: > > >> > > >> > You can call panic notifiers and kmsg dumpers before kdump by > > >> > specifying "crash_kexec_post_notifiers" as a boot parameter. > > >> > However, it doesn't make sense if kdump is not available. In that > > >> > case, disable "crash_kexec_post_notifiers" boot parameter so that > > >> > you can't change the value of the parameter. > > >> > > >> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> > > > > > > I think it would make sense if he just replaced "kdump" with "kexec". > > > > It would be less insane, however it still makes no sense as without > > kexec on panic support crash_kexec is a noop. So the value of the > > seeting makes no difference. > > Can you explain more, I don't really understand what you mean. Are you suggesting > the whole "crash_kexec_post_notifiers" feature has no value ? Daniel, BTW, why are you using crash_kexec_post_notifiers commandline? Why not without it? Thanks Vivek -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [next] | [standalone]
| From | dwalker@fifo99.com |
|---|---|
| Date | 2015-07-14 17:40 +0200 |
| Message-ID | <pMatj-4pB-27@gated-at.bofh.it> |
| In reply to | #1183770 |
On Tue, Jul 14, 2015 at 11:02:08AM -0400, Vivek Goyal wrote: > On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: > > On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: > > > dwalker@fifo99.com writes: > > > > > > > On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: > > > >> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: > > > >> > > > >> > You can call panic notifiers and kmsg dumpers before kdump by > > > >> > specifying "crash_kexec_post_notifiers" as a boot parameter. > > > >> > However, it doesn't make sense if kdump is not available. In that > > > >> > case, disable "crash_kexec_post_notifiers" boot parameter so that > > > >> > you can't change the value of the parameter. > > > >> > > > >> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> > > > > > > > > I think it would make sense if he just replaced "kdump" with "kexec". > > > > > > It would be less insane, however it still makes no sense as without > > > kexec on panic support crash_kexec is a noop. So the value of the > > > seeting makes no difference. > > > > Can you explain more, I don't really understand what you mean. Are you suggesting > > the whole "crash_kexec_post_notifiers" feature has no value ? > > Daniel, > > BTW, why are you using crash_kexec_post_notifiers commandline? Why not > without it? It was explained in the prior thread but to rehash, the notifiers are used to do a switch over from the crashed machine to another redundant machine. Daniel -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | dwalker@fifo99.com |
|---|---|
| Date | 2015-07-14 17:50 +0200 |
| Message-ID | <pMaCZ-4AR-9@gated-at.bofh.it> |
| In reply to | #1183789 |
On Tue, Jul 14, 2015 at 11:40:40AM -0400, Vivek Goyal wrote: > On Tue, Jul 14, 2015 at 03:34:30PM +0000, dwalker@fifo99.com wrote: > > On Tue, Jul 14, 2015 at 11:02:08AM -0400, Vivek Goyal wrote: > > > On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: > > > > On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: > > > > > dwalker@fifo99.com writes: > > > > > > > > > > > On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: > > > > > >> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: > > > > > >> > > > > > >> > You can call panic notifiers and kmsg dumpers before kdump by > > > > > >> > specifying "crash_kexec_post_notifiers" as a boot parameter. > > > > > >> > However, it doesn't make sense if kdump is not available. In that > > > > > >> > case, disable "crash_kexec_post_notifiers" boot parameter so that > > > > > >> > you can't change the value of the parameter. > > > > > >> > > > > > >> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> > > > > > > > > > > > > I think it would make sense if he just replaced "kdump" with "kexec". > > > > > > > > > > It would be less insane, however it still makes no sense as without > > > > > kexec on panic support crash_kexec is a noop. So the value of the > > > > > seeting makes no difference. > > > > > > > > Can you explain more, I don't really understand what you mean. Are you suggesting > > > > the whole "crash_kexec_post_notifiers" feature has no value ? > > > > > > Daniel, > > > > > > BTW, why are you using crash_kexec_post_notifiers commandline? Why not > > > without it? > > > > It was explained in the prior thread but to rehash, the notifiers are used to do a switch > > over from the crashed machine to another redundant machine. > > So why not detect failure using polling or issue notifications from second > kernel. > > IOW, expecting that a crashed machine will be able to deliver notification > reliably is falwed to begin with, IMHO. It's flawed to think you can kexec, but you still do it right ? I've not gotten into the deep details of this switching process, but that's how this interface is used. > If a machine is failing, there are high chance it can't deliver you the > notification. Detecting that failure suing some kind of polling mechanism > might be more reliable. And it will make even kdump mechanism more > reliable so that it does not have to run panic notifiers after the crash. I think what your suggesting is that my company should change how it's hardware works and that's not really an option for me. This isn't a simple thing like checking over the network if the machine is down or not, this is way more complex hardware design. Daniel -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Vivek Goyal <vgoyal@redhat.com> |
|---|---|
| Date | 2015-07-14 18:20 +0200 |
| Message-ID | <pMb61-5o8-5@gated-at.bofh.it> |
| In reply to | #1183800 |
On Tue, Jul 14, 2015 at 03:48:33PM +0000, dwalker@fifo99.com wrote: > On Tue, Jul 14, 2015 at 11:40:40AM -0400, Vivek Goyal wrote: > > On Tue, Jul 14, 2015 at 03:34:30PM +0000, dwalker@fifo99.com wrote: > > > On Tue, Jul 14, 2015 at 11:02:08AM -0400, Vivek Goyal wrote: > > > > On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: > > > > > On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: > > > > > > dwalker@fifo99.com writes: > > > > > > > > > > > > > On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: > > > > > > >> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: > > > > > > >> > > > > > > >> > You can call panic notifiers and kmsg dumpers before kdump by > > > > > > >> > specifying "crash_kexec_post_notifiers" as a boot parameter. > > > > > > >> > However, it doesn't make sense if kdump is not available. In that > > > > > > >> > case, disable "crash_kexec_post_notifiers" boot parameter so that > > > > > > >> > you can't change the value of the parameter. > > > > > > >> > > > > > > >> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> > > > > > > > > > > > > > > I think it would make sense if he just replaced "kdump" with "kexec". > > > > > > > > > > > > It would be less insane, however it still makes no sense as without > > > > > > kexec on panic support crash_kexec is a noop. So the value of the > > > > > > seeting makes no difference. > > > > > > > > > > Can you explain more, I don't really understand what you mean. Are you suggesting > > > > > the whole "crash_kexec_post_notifiers" feature has no value ? > > > > > > > > Daniel, > > > > > > > > BTW, why are you using crash_kexec_post_notifiers commandline? Why not > > > > without it? > > > > > > It was explained in the prior thread but to rehash, the notifiers are used to do a switch > > > over from the crashed machine to another redundant machine. > > > > So why not detect failure using polling or issue notifications from second > > kernel. > > > > IOW, expecting that a crashed machine will be able to deliver notification > > reliably is falwed to begin with, IMHO. > > It's flawed to think you can kexec, but you still do it right ? I've not gotten into > the deep details of this switching process, but that's how this interface is used. Sure. But the deal here is that users of interface know that sometimes it can be unreliable. And in the absence of more reliable mechanism, somewhat less reliable mechanism is fine. > > > If a machine is failing, there are high chance it can't deliver you the > > notification. Detecting that failure suing some kind of polling mechanism > > might be more reliable. And it will make even kdump mechanism more > > reliable so that it does not have to run panic notifiers after the crash. > > I think what your suggesting is that my company should change how it's hardware works > and that's not really an option for me. This isn't a simple thing like checking over the > network if the machine is down or not, this is way more complex hardware design. That means you are ready to live with an unreliable design. There might be cases where notifier does not get run properly and you will not do switch despite the fact that OS has failed. I was just trying to nudge you in a direction which could be more reliable mechanism. Thanks Vivek -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Vivek Goyal <vgoyal@redhat.com> |
|---|---|
| Date | 2015-07-14 17:50 +0200 |
| Message-ID | <pMaCZ-4AR-11@gated-at.bofh.it> |
| In reply to | #1183789 |
On Tue, Jul 14, 2015 at 03:34:30PM +0000, dwalker@fifo99.com wrote: > On Tue, Jul 14, 2015 at 11:02:08AM -0400, Vivek Goyal wrote: > > On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: > > > On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: > > > > dwalker@fifo99.com writes: > > > > > > > > > On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: > > > > >> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: > > > > >> > > > > >> > You can call panic notifiers and kmsg dumpers before kdump by > > > > >> > specifying "crash_kexec_post_notifiers" as a boot parameter. > > > > >> > However, it doesn't make sense if kdump is not available. In that > > > > >> > case, disable "crash_kexec_post_notifiers" boot parameter so that > > > > >> > you can't change the value of the parameter. > > > > >> > > > > >> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> > > > > > > > > > > I think it would make sense if he just replaced "kdump" with "kexec". > > > > > > > > It would be less insane, however it still makes no sense as without > > > > kexec on panic support crash_kexec is a noop. So the value of the > > > > seeting makes no difference. > > > > > > Can you explain more, I don't really understand what you mean. Are you suggesting > > > the whole "crash_kexec_post_notifiers" feature has no value ? > > > > Daniel, > > > > BTW, why are you using crash_kexec_post_notifiers commandline? Why not > > without it? > > It was explained in the prior thread but to rehash, the notifiers are used to do a switch > over from the crashed machine to another redundant machine. So why not detect failure using polling or issue notifications from second kernel. IOW, expecting that a crashed machine will be able to deliver notification reliably is falwed to begin with, IMHO. If a machine is failing, there are high chance it can't deliver you the notification. Detecting that failure suing some kind of polling mechanism might be more reliable. And it will make even kdump mechanism more reliable so that it does not have to run panic notifiers after the crash. Thanks Vivek -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> |
|---|---|
| Date | 2015-07-15 12:50 +0200 |
| Message-ID | <pMsqe-52Z-7@gated-at.bofh.it> |
| In reply to | #1183806 |
(2015/07/15 0:40), Vivek Goyal wrote: > On Tue, Jul 14, 2015 at 03:34:30PM +0000, dwalker@fifo99.com wrote: >> On Tue, Jul 14, 2015 at 11:02:08AM -0400, Vivek Goyal wrote: >>> On Tue, Jul 14, 2015 at 01:59:19PM +0000, dwalker@fifo99.com wrote: >>>> On Mon, Jul 13, 2015 at 08:19:45PM -0500, Eric W. Biederman wrote: >>>>> dwalker@fifo99.com writes: >>>>> >>>>>> On Fri, Jul 10, 2015 at 08:41:28AM -0500, Eric W. Biederman wrote: >>>>>>> Hidehiro Kawai <hidehiro.kawai.ez@hitachi.com> writes: >>>>>>> >>>>>>>> You can call panic notifiers and kmsg dumpers before kdump by >>>>>>>> specifying "crash_kexec_post_notifiers" as a boot parameter. >>>>>>>> However, it doesn't make sense if kdump is not available. In that >>>>>>>> case, disable "crash_kexec_post_notifiers" boot parameter so that >>>>>>>> you can't change the value of the parameter. >>>>>>> >>>>>>> Nacked-by: "Eric W. Biederman" <ebiederm@xmission.com> >>>>>> >>>>>> I think it would make sense if he just replaced "kdump" with "kexec". >>>>> >>>>> It would be less insane, however it still makes no sense as without >>>>> kexec on panic support crash_kexec is a noop. So the value of the >>>>> seeting makes no difference. >>>> >>>> Can you explain more, I don't really understand what you mean. Are you suggesting >>>> the whole "crash_kexec_post_notifiers" feature has no value ? >>> >>> Daniel, >>> >>> BTW, why are you using crash_kexec_post_notifiers commandline? Why not >>> without it? >> >> It was explained in the prior thread but to rehash, the notifiers are used to do a switch >> over from the crashed machine to another redundant machine. > > So why not detect failure using polling or issue notifications from second > kernel. Polling is not sufficient because some kernel parts may be alive even if the responder of the polling is dead. We want to notify the failure after stopping other CPUs. Notifying from second kernel needs to wait for the kernel booted up and device initialization if needed, and this is not applicable if we want to do fast switchover. Notifying just before second kernel, as Eric stated, is one of the reliable option although we can't do complicate things there. For example, we can notify the failure by writing some specific I/O registers in purgatory codes provided by kexec command. Since the purgatory codes are currently embedded into kexec command, so we might need to modify the mechanism to be pluggable because how to notify will differ among vendors. Anyway, this is the case of switchover use case. If we want to save minimal information before kdump, notifiers or kmsg_dump() can be used. > IOW, expecting that a crashed machine will be able to deliver notification > reliably is falwed to begin with, IMHO. I think it depends on what callback is used. Most of panic notifiers just do memory copy or I/O register access. Of course, there are relatively complicate notifiers too, and I'm preparing patch sets for hardening for that case. Regards, Hidehiro Kawai -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web