Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1271711 > unrolled thread
| Started by | Octavian Purdila <octavian.purdila@intel.com> |
|---|---|
| First post | 2015-11-17 23:50 +0100 |
| Last post | 2015-11-23 22:50 +0100 |
| Articles | 8 on this page of 28 — 5 participants |
Back to article view | Back to linux.kernel
[RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-17 23:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-19 17:00 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-19 22:00 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 16:20 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-20 00:40 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 15:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 16:20 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 16:40 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 16:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-20 21:40 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 23:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-22 23:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-23 14:00 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-23 22:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-20 00:30 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Richard Weinberger <richard.weinberger@gmail.com> - 2015-11-20 01:00 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-20 02:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 15:30 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 16:30 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 16:40 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Brian Foster <bfoster@redhat.com> - 2015-11-20 16:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Theodore Ts'o <tytso@mit.edu> - 2015-11-20 21:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 14:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-20 22:10 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-20 23:30 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-22 23:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Octavian Purdila <octavian.purdila@intel.com> - 2015-11-23 02:50 +0100
Re: [RFC PATCH] xfs: support for non-mmu architectures Dave Chinner <david@fromorbit.com> - 2015-11-23 22:50 +0100
Page 2 of 2 — ← Prev page 1 [2]
| From | Brian Foster <bfoster@redhat.com> |
|---|---|
| Date | 2015-11-20 16:50 +0100 |
| Message-ID | <qwW6K-Fa-33@gated-at.bofh.it> |
| In reply to | #1274192 |
On Fri, Nov 20, 2015 at 05:31:59PM +0200, Octavian Purdila wrote: > On Fri, Nov 20, 2015 at 5:24 PM, Brian Foster <bfoster@redhat.com> wrote: > > On Fri, Nov 20, 2015 at 04:26:28PM +0200, Octavian Purdila wrote: > >> On Fri, Nov 20, 2015 at 2:58 AM, Dave Chinner <david@fromorbit.com> wrote: > >> > On Fri, Nov 20, 2015 at 12:54:02AM +0100, Richard Weinberger wrote: > >> >> On Fri, Nov 20, 2015 at 12:24 AM, Dave Chinner <david@fromorbit.com> wrote: > >> >> > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: > >> >> >> Naive implementation for non-mmu architectures: allocate physically > >> >> >> contiguous xfs buffers with alloc_pages. Terribly inefficient with > >> >> >> memory and fragmentation on high I/O loads but it may be good enough > >> >> >> for basic usage (which most non-mmu architectures will need). > >> >> > > >> >> > Can you please explain why you want to use XFS on low end, basic > >> >> > non-MMU devices? XFS is a high performance, enterprise/HPC level > >> >> > filesystem - it's not a filesystem designed for small IoT level > >> >> > devices - so I'm struggling to see why we'd want to expend any > >> >> > effort to make XFS work on such devices.... > >> >> > >> >> The use case is the Linux Kernel Library: > >> >> https://lkml.org/lkml/2015/11/3/706 > >> >> > >> >> Using LKL and fuse you can mount any kernel filesystem using fuse > >> >> as non-root. > >> > > >> > IOWs, because we said no to unprivileged mounts, instead the > >> > proposal is to linking all the kernel code into userspace so you can > >> > do unprivielged mounts that way? > >> > > >> > >> LKL's goal is to make it easy for various applications to reuse Linux > >> kernel code instead of re-implementing it. Mounting filesystem images > >> is just one of the applications. > >> > >> > IOWs, you get to say "it secure because it's in userspace" and leave > >> > us filesystem people with all the shit that comes with allowing > >> > users to mount random untrusted filesystem images using code that > >> > was never designed to allow that to happen? > >> > > >> > >> It is already possible to mount arbitrary filesystem images in > >> userspace using VMs . LKL doesn't change that, it just reduces the > >> amount of dependencies you need to do so. > >> > > > > Perhaps a dumb question, but I'm not quite putting 2+2 together here. > > When I see nommu, I'm generally thinking hardware characteristics, but > > we're talking about a userspace kernel library here. So can you > > elaborate on how this relates to nommu? Does this library emulate kernel > > mechanisms in userspace via nommu mode or something of that nature? > > > > LKL is currently implemented as a virtual non-mmu architecture. That > makes it simpler and it will also allow us to support environments > where it is not possible to emulate paging (e.g. bootloaders). > Ok, so we aren't necessarily talking about running on typically limited, mmu-less hardware. Thanks! Brian > _______________________________________________ > xfs mailing list > xfs@oss.sgi.com > http://oss.sgi.com/mailman/listinfo/xfs -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Theodore Ts'o <tytso@mit.edu> |
|---|---|
| Date | 2015-11-20 21:10 +0100 |
| Message-ID | <qx0am-3x6-21@gated-at.bofh.it> |
| In reply to | #1274104 |
On Fri, Nov 20, 2015 at 04:26:28PM +0200, Octavian Purdila wrote: > It is already possible to mount arbitrary filesystem images in > userspace using VMs . LKL doesn't change that, it just reduces the > amount of dependencies you need to do so. It is true that you can mount arbitrary file systems in userspace using VM's. But those the kvm binary is typically not run with root privileges in the host OS --- at least, not if the system administrator is smart. So a root compromise does not cause a catastrophic security vulnerability, and if the guest OS crashes --- again, not a real problem. In the caase where people are trying to claim that containers are just as secure as VM's, and plan to give container "guest" system administrators root-like powers, the question which immediately comes to mind is whether the LKML/fuse daemon is running inside or outside the container. If it is outside the container, the a potential security compromise of the binary running binary will be catastrophic to the overall security of the host system and all of its containers. If it is inside the container, you will be partially breaking the illusion that the container works just like a VM (since a user runinng "ps" will see all of these mysterious userspace processes that could be killed, etc.), but it significantly reduces the security problems if a maliciously crafted (or maliciously modulated) block device is mounted. > Could you expand of what burden does this use-case put on fs > developers? I am sure that, if needed, we can put restrictions in LKL > to avoid that. The bottom line is who is going to get all of the support calls and nasty e-mails explaining how our "crappy" code has caused some silly container VM system administrator's customers $$$ worth of losses. As long as we can make sure that it's been underlined that the code is being used well outside of its intended scope, and if it breaks, the user gets to keep both pieces, and all complaints, threatened lawsuits, etc. should go to the LKL maintainers or the purveyors of said container-based products, I suppose that should be OK. :-) - Ted -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Octavian Purdila <octavian.purdila@intel.com> |
|---|---|
| Date | 2015-11-20 14:50 +0100 |
| Message-ID | <qwUeB-7Rw-5@gated-at.bofh.it> |
| In reply to | #1273585 |
On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: >> Naive implementation for non-mmu architectures: allocate physically >> contiguous xfs buffers with alloc_pages. Terribly inefficient with >> memory and fragmentation on high I/O loads but it may be good enough >> for basic usage (which most non-mmu architectures will need). > > Can you please explain why you want to use XFS on low end, basic > non-MMU devices? XFS is a high performance, enterprise/HPC level > filesystem - it's not a filesystem designed for small IoT level > devices - so I'm struggling to see why we'd want to expend any > effort to make XFS work on such devices.... > Hi David, Yes XFS as the main fs on this type of devices does not make sense, but does it hurt to be able to perform basic operation on XFS from these devices? Perhaps accessing an external medium formatted with XFS? Another example is accessing VM images that are formatted with XFS. Currently we can do that with tools like libguestfs that use a VM in the background. I am working on a lighter solution for that where we compile the Linux kernel as a library [1]. This allows access to the filesystem without the need to use a full VM. And a final example is linking the bootloader code with LKL to access the filesystem. This has a hard requirement on non-mmu. So, IMHO there are usecases for using XFS on non-mmu architectures. I think it all boils down to: is the patch simple enough to not put an unreasonable maintenance burden on developers? [1] https://github.com/lkl/linux Thanks, Tavi -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Dave Chinner <david@fromorbit.com> |
|---|---|
| Date | 2015-11-20 22:10 +0100 |
| Message-ID | <qx16q-49x-3@gated-at.bofh.it> |
| In reply to | #1274070 |
On Fri, Nov 20, 2015 at 03:43:20PM +0200, Octavian Purdila wrote: > On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: > > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: > >> Naive implementation for non-mmu architectures: allocate physically > >> contiguous xfs buffers with alloc_pages. Terribly inefficient with > >> memory and fragmentation on high I/O loads but it may be good enough > >> for basic usage (which most non-mmu architectures will need). > > > > Can you please explain why you want to use XFS on low end, basic > > non-MMU devices? XFS is a high performance, enterprise/HPC level > > filesystem - it's not a filesystem designed for small IoT level > > devices - so I'm struggling to see why we'd want to expend any > > effort to make XFS work on such devices.... > > > > Hi David, > > Yes XFS as the main fs on this type of devices does not make sense, > but does it hurt to be able to perform basic operation on XFS from > these devices? Perhaps accessing an external medium formatted with > XFS? > > Another example is accessing VM images that are formatted with XFS. > Currently we can do that with tools like libguestfs that use a VM in > the background. I am working on a lighter solution for that where we > compile the Linux kernel as a library [1]. This allows access to the > filesystem without the need to use a full VM. That's hardly a "lighter solution". I'm kinda tired of the ongoing "hack random shit" approach to container development. If you need a XFS-FUSE module to allow safe userspace access to XFS fielsystems then maybe, just maybe, it makes sense to ask the XFS developers how to best go about providing a reliable, up-to-date, tested, maintained and supported XFS-FUSE module? IOWs, a "lighter solution" is to use the libxfs code base that we already maintain across kernel and userspace in the xfsprogs package and write a FUSE wrapper around that. That, immediately, will give you full read-only access to XFS filesystem images via FUSE. Then we (the XFS developers) can test the XFS-FUSE module under normal development conditions as we modify the xfsprogs code base (e.g. via xfstests) and ensure we always release a working, up-to-date FUSE wrapper with each xfsprogs release. And then once a proper read-only FUSE wrapper has been written, then we can discuss what is necessary to enable write access via porting the necessary parts of the kernel code across to the userspace libxfs codebase and hooking them up to the FUSE API... Hmmm? > And a final example is linking the bootloader code with LKL to access > the filesystem. This has a hard requirement on non-mmu. No way. We *can't* support filesystems that have had bootloaders make arbitrary changes to the filesystem without the knowlege of the OS that *owns the filesystem*. Similarly, we cannot support random applications that internally mount and modify filesystem images in ways we can't see, control, test or simulate. Sure, they use the kernel code, but that doesn't stop them from doing stupid shit that could corrupt the filesystem image. So, no, we are not going to support giving random applications direct access to XFS filesystem images, even via LKL. > So, IMHO there are usecases for using XFS on non-mmu architectures. I > think it all boils down to: is the patch simple enough to not put an > unreasonable maintenance burden on developers? Look at it this way: a user tries to mount their XFS-on-LKL-on-FUSE, XFS throughs a memory allocation deadlock warning because of a high order allocation during mount failing (i.e. due to the vmalloc no-mmu hacks). Who has to spend effort to find out why the error is being thrown? It's not the FUSE developers. It's not the LKL developers. XFS is going to be blamed, because it's an XFS error message, and it will be up to the XFS developers to /prove/ that it's not an XFS problem. And then google will find these complaints about XFS causing all sorts of problems, and we're back to the bad old days of everyone blaming XFS for shortcomings and problems in other code we have no control over.. I really don't see how using LKL to give userspace access to XFS filesystems is a better solution than actually writing a proper, supported XFS-FUSE module. LKL is so full of compromises that it's going to be unworkable and unsupportable in practice... Cheers, Dave. -- Dave Chinner david@fromorbit.com -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Octavian Purdila <octavian.purdila@intel.com> |
|---|---|
| Date | 2015-11-20 23:30 +0100 |
| Message-ID | <qx2lQ-4WW-17@gated-at.bofh.it> |
| In reply to | #1274432 |
On Fri, Nov 20, 2015 at 11:08 PM, Dave Chinner <david@fromorbit.com> wrote: > On Fri, Nov 20, 2015 at 03:43:20PM +0200, Octavian Purdila wrote: >> On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: >> > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: >> >> Naive implementation for non-mmu architectures: allocate physically >> >> contiguous xfs buffers with alloc_pages. Terribly inefficient with >> >> memory and fragmentation on high I/O loads but it may be good enough >> >> for basic usage (which most non-mmu architectures will need). >> > >> > Can you please explain why you want to use XFS on low end, basic >> > non-MMU devices? XFS is a high performance, enterprise/HPC level >> > filesystem - it's not a filesystem designed for small IoT level >> > devices - so I'm struggling to see why we'd want to expend any >> > effort to make XFS work on such devices.... >> > >> >> Hi David, >> >> Yes XFS as the main fs on this type of devices does not make sense, >> but does it hurt to be able to perform basic operation on XFS from >> these devices? Perhaps accessing an external medium formatted with >> XFS? >> >> Another example is accessing VM images that are formatted with XFS. >> Currently we can do that with tools like libguestfs that use a VM in >> the background. I am working on a lighter solution for that where we >> compile the Linux kernel as a library [1]. This allows access to the >> filesystem without the need to use a full VM. > > That's hardly a "lighter solution" > > I'm kinda tired of the ongoing "hack random shit" approach to > container development. Since apparently there is a container devs hunting party going on right now, let me quickly confess that LKL has nothing to do with (them be damned) containers :) On a more serious note, LKL was not developed for containers or to try to circumvent privileged mounts. It was developed to allow the Linux kernel code to be reused in things like simple tools that allows one to modify a filesystem image. > If you need a XFS-FUSE module to allow safe > userspace access to XFS fielsystems then maybe, just maybe, it makes > sense to ask the XFS developers how to best go about providing a > reliable, up-to-date, tested, maintained and supported XFS-FUSE > module? > > IOWs, a "lighter solution" is to use the libxfs code base that we > already maintain across kernel and userspace in the xfsprogs package > and write a FUSE wrapper around that. That, immediately, will give > you full read-only access to XFS filesystem images via FUSE. Then we > (the XFS developers) can test the XFS-FUSE module under normal > development conditions as we modify the xfsprogs code base (e.g. via > xfstests) and ensure we always release a working, up-to-date FUSE > wrapper with each xfsprogs release. > > And then once a proper read-only FUSE wrapper has been written, then > we can discuss what is necessary to enable write access via porting > the necessary parts of the kernel code across to the userspace > libxfs codebase and hooking them up to the FUSE API... > > Hmmm? > What about ext4, vfat, btrfs and other filesystems? Also why duplicate the whole thing if you could reuse it? >> And a final example is linking the bootloader code with LKL to access >> the filesystem. This has a hard requirement on non-mmu. > > No way. We *can't* support filesystems that have had bootloaders > make arbitrary changes to the filesystem without the knowlege of the > OS that *owns the filesystem*. Similarly, we cannot support random > applications that internally mount and modify filesystem images in > ways we can't see, control, test or simulate. Sure, they use the > kernel code, but that doesn't stop them from doing stupid shit that > could corrupt the filesystem image. So, no, we are not going to > support giving random applications direct access to XFS filesystem > images, even via LKL. > LKL only exports the Linux kernel system calls and nothing else to applications. Because of that, there should not be any loss of control or visibility to the XFS fs driver. >> So, IMHO there are usecases for using XFS on non-mmu architectures. I >> think it all boils down to: is the patch simple enough to not put an >> unreasonable maintenance burden on developers? > > Look at it this way: a user tries to mount their > XFS-on-LKL-on-FUSE, XFS throughs a memory allocation deadlock > warning because of a high order allocation during mount failing > (i.e. due to the vmalloc no-mmu hacks). > > Who has to spend effort to find out why the error is being thrown? > It's not the FUSE developers. It's not the LKL developers. XFS is > going to be blamed, because it's an XFS error message, and it will > be up to the XFS developers to /prove/ that it's not an XFS problem. > And then google will find these complaints about XFS causing all > sorts of problems, and we're back to the bad old days of everyone > blaming XFS for shortcomings and problems in other code we have no > control over.. > > I really don't see how using LKL to give userspace access to XFS > filesystems is a better solution than actually writing a proper, > supported XFS-FUSE module. LKL is so full of compromises that it's > going to be unworkable and unsupportable in practice... > Could you elaborate on some of these issues? -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Dave Chinner <david@fromorbit.com> |
|---|---|
| Date | 2015-11-22 23:50 +0100 |
| Message-ID | <qxLCi-1G1-11@gated-at.bofh.it> |
| In reply to | #1274458 |
On Sat, Nov 21, 2015 at 12:26:47AM +0200, Octavian Purdila wrote: > On Fri, Nov 20, 2015 at 11:08 PM, Dave Chinner <david@fromorbit.com> wrote: > > On Fri, Nov 20, 2015 at 03:43:20PM +0200, Octavian Purdila wrote: > >> On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: > >> > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: > >> >> Naive implementation for non-mmu architectures: allocate physically > >> >> contiguous xfs buffers with alloc_pages. Terribly inefficient with > >> >> memory and fragmentation on high I/O loads but it may be good enough > >> >> for basic usage (which most non-mmu architectures will need). > >> > > >> > Can you please explain why you want to use XFS on low end, basic > >> > non-MMU devices? XFS is a high performance, enterprise/HPC level > >> > filesystem - it's not a filesystem designed for small IoT level > >> > devices - so I'm struggling to see why we'd want to expend any > >> > effort to make XFS work on such devices.... > >> > > >> > >> Hi David, > >> > >> Yes XFS as the main fs on this type of devices does not make sense, > >> but does it hurt to be able to perform basic operation on XFS from > >> these devices? Perhaps accessing an external medium formatted with > >> XFS? > >> > >> Another example is accessing VM images that are formatted with XFS. > >> Currently we can do that with tools like libguestfs that use a VM in > >> the background. I am working on a lighter solution for that where we > >> compile the Linux kernel as a library [1]. This allows access to the > >> filesystem without the need to use a full VM. > > > > That's hardly a "lighter solution" > > > > I'm kinda tired of the ongoing "hack random shit" approach to > > container development. > > Since apparently there is a container devs hunting party going on > right now, let me quickly confess that LKL has nothing to do with > (them be damned) containers :) > > On a more serious note, LKL was not developed for containers or to try > to circumvent privileged mounts. It was developed to allow the Linux > kernel code to be reused in things like simple tools that allows one > to modify a filesystem image. Anything tool that modifies an XFS filesystem that is not directly maintained by the XFS developers voids any kind of support we can supply. Just like the fact we don't support tainted kernels because the 3rd party binary code is unknowable (and usually crap), having the kernel code linked with random 3rd party userspace application code is completely unsupportable by us. Remember that with most kernel code a bug just results in a panic and reboot, and everything just continues on again after the system comes up again. In contrast, a bug in the storage code can cause *persistent damage* that can cause data loss or corruption that cannot be fixed without data loss of some kind. Ultimately, as the maintainer I'm responsible for XFS not eating our users' data, and part of that responsibility involves telling people who want to do daft things that "no, that's a *bad idea*". > > If you need a XFS-FUSE module to allow safe > > userspace access to XFS fielsystems then maybe, just maybe, it makes > > sense to ask the XFS developers how to best go about providing a > > reliable, up-to-date, tested, maintained and supported XFS-FUSE > > module? > > > > IOWs, a "lighter solution" is to use the libxfs code base that we > > already maintain across kernel and userspace in the xfsprogs package > > and write a FUSE wrapper around that. That, immediately, will give > > you full read-only access to XFS filesystem images via FUSE. Then we > > (the XFS developers) can test the XFS-FUSE module under normal > > development conditions as we modify the xfsprogs code base (e.g. via > > xfstests) and ensure we always release a working, up-to-date FUSE > > wrapper with each xfsprogs release. > > > > And then once a proper read-only FUSE wrapper has been written, then > > we can discuss what is necessary to enable write access via porting > > the necessary parts of the kernel code across to the userspace > > libxfs codebase and hooking them up to the FUSE API... > > > > Hmmm? > > > > What about ext4, vfat, btrfs and other filesystems? Ted has also raised exactly the same issues w.r.t. ext4. > Also why duplicate > the whole thing if you could reuse it? Do you use a hammer when you need to tighten a screw? Yes, you can "reuse a hammer" for this purpose, but there's going to be collateral damage because using the screw outside it's original design and architecture constraints presents a high risk of things going wrong. > >> And a final example is linking the bootloader code with LKL to access > >> the filesystem. This has a hard requirement on non-mmu. > > > > No way. We *can't* support filesystems that have had bootloaders > > make arbitrary changes to the filesystem without the knowlege of the > > OS that *owns the filesystem*. Similarly, we cannot support random > > applications that internally mount and modify filesystem images in > > ways we can't see, control, test or simulate. Sure, they use the > > kernel code, but that doesn't stop them from doing stupid shit that > > could corrupt the filesystem image. So, no, we are not going to > > support giving random applications direct access to XFS filesystem > > images, even via LKL. > > > > LKL only exports the Linux kernel system calls and nothing else to > applications. Because of that, there should not be any loss of control > or visibility to the XFS fs driver. It runs in the same address space as the user application, yes? And hence application bugs can cause the kernel code to malfunction, yes? > > I really don't see how using LKL to give userspace access to XFS > > filesystems is a better solution than actually writing a proper, > > supported XFS-FUSE module. LKL is so full of compromises that it's > > going to be unworkable and unsupportable in practice... > > Could you elaborate on some of these issues? Start with "is a no-mmu architecture" and all the compromises that means the kernel code needs to make, add a topping of "runs in the same address space as the application", add a new flavour of kernel binary taint and finish it off with "LKL linked applications will never be tested by their developers over the full functionality the LKL provides them with". Cheers, Dave. -- Dave Chinner david@fromorbit.com -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Octavian Purdila <octavian.purdila@intel.com> |
|---|---|
| Date | 2015-11-23 02:50 +0100 |
| Message-ID | <qxOqu-3rN-9@gated-at.bofh.it> |
| In reply to | #1274987 |
On Mon, Nov 23, 2015 at 12:44 AM, Dave Chinner <david@fromorbit.com> wrote: > On Sat, Nov 21, 2015 at 12:26:47AM +0200, Octavian Purdila wrote: >> On Fri, Nov 20, 2015 at 11:08 PM, Dave Chinner <david@fromorbit.com> wrote: >> > On Fri, Nov 20, 2015 at 03:43:20PM +0200, Octavian Purdila wrote: >> >> On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: >> >> > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: >> >> >> Naive implementation for non-mmu architectures: allocate physically >> >> >> contiguous xfs buffers with alloc_pages. Terribly inefficient with >> >> >> memory and fragmentation on high I/O loads but it may be good enough >> >> >> for basic usage (which most non-mmu architectures will need). >> >> > >> >> > Can you please explain why you want to use XFS on low end, basic >> >> > non-MMU devices? XFS is a high performance, enterprise/HPC level >> >> > filesystem - it's not a filesystem designed for small IoT level >> >> > devices - so I'm struggling to see why we'd want to expend any >> >> > effort to make XFS work on such devices.... >> >> > >> >> >> >> Hi David, >> >> >> >> Yes XFS as the main fs on this type of devices does not make sense, >> >> but does it hurt to be able to perform basic operation on XFS from >> >> these devices? Perhaps accessing an external medium formatted with >> >> XFS? >> >> >> >> Another example is accessing VM images that are formatted with XFS. >> >> Currently we can do that with tools like libguestfs that use a VM in >> >> the background. I am working on a lighter solution for that where we >> >> compile the Linux kernel as a library [1]. This allows access to the >> >> filesystem without the need to use a full VM. >> > >> > That's hardly a "lighter solution" >> > >> > I'm kinda tired of the ongoing "hack random shit" approach to >> > container development. >> >> Since apparently there is a container devs hunting party going on >> right now, let me quickly confess that LKL has nothing to do with >> (them be damned) containers :) >> >> On a more serious note, LKL was not developed for containers or to try >> to circumvent privileged mounts. It was developed to allow the Linux >> kernel code to be reused in things like simple tools that allows one >> to modify a filesystem image. > > Anything tool that modifies an XFS filesystem that is not directly > maintained by the XFS developers voids any kind of support we can > supply. Just like the fact we don't support tainted kernels because > the 3rd party binary code is unknowable (and usually crap), having > the kernel code linked with random 3rd party userspace application > code is completely unsupportable by us. > Perhaps tainting the kernel is a solution when running unknown applications linked with LKL. I would argue that applications that are maintained together with LKL (e.g. lklfuse in tools/lkl) should not taint the kernel because those applications will be under the control of kernel developers. I would also argue that mounting a filesystem read-only should not taint the kernel either. > Remember that with most kernel code a bug just results in a panic > and reboot, and everything just continues on again after the system > comes up again. In contrast, a bug in the storage code can cause > *persistent damage* that can cause data loss or corruption that > cannot be fixed without data loss of some kind. > > Ultimately, as the maintainer I'm responsible for XFS not eating our > users' data, and part of that responsibility involves telling people > who want to do daft things that "no, that's a *bad idea*". > I understand how critical filesystem issues are and I appreciate your feedback. Sorry to drag you deeper into this but as you know, no good deed goes unpunished :) >> > If you need a XFS-FUSE module to allow safe >> > userspace access to XFS fielsystems then maybe, just maybe, it makes >> > sense to ask the XFS developers how to best go about providing a >> > reliable, up-to-date, tested, maintained and supported XFS-FUSE >> > module? >> > >> > IOWs, a "lighter solution" is to use the libxfs code base that we >> > already maintain across kernel and userspace in the xfsprogs package >> > and write a FUSE wrapper around that. That, immediately, will give >> > you full read-only access to XFS filesystem images via FUSE. Then we >> > (the XFS developers) can test the XFS-FUSE module under normal >> > development conditions as we modify the xfsprogs code base (e.g. via >> > xfstests) and ensure we always release a working, up-to-date FUSE >> > wrapper with each xfsprogs release. >> > >> > And then once a proper read-only FUSE wrapper has been written, then >> > we can discuss what is necessary to enable write access via porting >> > the necessary parts of the kernel code across to the userspace >> > libxfs codebase and hooking them up to the FUSE API... >> > >> > Hmmm? >> > >> >> What about ext4, vfat, btrfs and other filesystems? > > Ted has also raised exactly the same issues w.r.t. ext4. > >> Also why duplicate >> the whole thing if you could reuse it? > > Do you use a hammer when you need to tighten a screw? Yes, you can > "reuse a hammer" for this purpose, but there's going to be > collateral damage because using the screw outside it's original > design and architecture constraints presents a high risk of things > going wrong. > First, lets try to discuss the potential collateral damage before calling it a hammer. It may just be just an unfamiliar screw-driver :) >> >> And a final example is linking the bootloader code with LKL to access >> >> the filesystem. This has a hard requirement on non-mmu. >> > >> > No way. We *can't* support filesystems that have had bootloaders >> > make arbitrary changes to the filesystem without the knowlege of the >> > OS that *owns the filesystem*. Similarly, we cannot support random >> > applications that internally mount and modify filesystem images in >> > ways we can't see, control, test or simulate. Sure, they use the >> > kernel code, but that doesn't stop them from doing stupid shit that >> > could corrupt the filesystem image. So, no, we are not going to >> > support giving random applications direct access to XFS filesystem >> > images, even via LKL. >> > >> >> LKL only exports the Linux kernel system calls and nothing else to >> applications. Because of that, there should not be any loss of control >> or visibility to the XFS fs driver. > > It runs in the same address space as the user application, yes? And > hence application bugs can cause the kernel code to malfunction, > yes? > Most non-mmu architecture have the same issue and nevertheless non-mmu is still supported in Linux (including most filesystems). Also, filesystem code runs in the same address space with other kernel code and drivers and a bug anywhere in the kernel can cause filesystem code to malfunction. Applications maintained together with LKL and in the kernel tree will be as safe as drivers and other kernel code with regard to filesystem malfunctions. We can taint the kernel when LKL is linked with unknown applications. >> > I really don't see how using LKL to give userspace access to XFS >> > filesystems is a better solution than actually writing a proper, >> > supported XFS-FUSE module. LKL is so full of compromises that it's >> > going to be unworkable and unsupportable in practice... >> >> Could you elaborate on some of these issues? > > Start with "is a no-mmu architecture" and all the compromises that > means the kernel code needs to make, I don't see non-mmu as a compromise. It is supported by Linux and most filesystems work fine on non-mmu architectures. LKL can be implemented as a mmu architecture. Having it as a non-mmu architecture has the advantages of allowing it to run in more constrained environments like bootloaders. > add a topping of "runs in the > same address space as the application", I've addressed this concern above. > add a new flavour of kernel > binary taint I am not sure I understand, are you saying that it is an issue to add a new taint flavor? > and finish it off with "LKL linked applications will > never be tested by their developers over the full functionality the > LKL provides them with". > You lost me here. Why does an application developer have to test the full functionality of a library it is linked with? -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [next] | [standalone]
| From | Dave Chinner <david@fromorbit.com> |
|---|---|
| Date | 2015-11-23 22:50 +0100 |
| Message-ID | <qy79M-7sk-17@gated-at.bofh.it> |
| In reply to | #1275006 |
On Mon, Nov 23, 2015 at 03:41:49AM +0200, Octavian Purdila wrote: > On Mon, Nov 23, 2015 at 12:44 AM, Dave Chinner <david@fromorbit.com> wrote: > > On Sat, Nov 21, 2015 at 12:26:47AM +0200, Octavian Purdila wrote: > >> On Fri, Nov 20, 2015 at 11:08 PM, Dave Chinner <david@fromorbit.com> wrote: > >> > On Fri, Nov 20, 2015 at 03:43:20PM +0200, Octavian Purdila wrote: > >> >> On Fri, Nov 20, 2015 at 1:24 AM, Dave Chinner <david@fromorbit.com> wrote: > >> >> > On Wed, Nov 18, 2015 at 12:46:21AM +0200, Octavian Purdila wrote: > >> >> >> Naive implementation for non-mmu architectures: allocate physically > >> >> >> contiguous xfs buffers with alloc_pages. Terribly inefficient with > >> >> >> memory and fragmentation on high I/O loads but it may be good enough > >> >> >> for basic usage (which most non-mmu architectures will need). > >> >> > > >> >> > Can you please explain why you want to use XFS on low end, basic > >> >> > non-MMU devices? XFS is a high performance, enterprise/HPC level > >> >> > filesystem - it's not a filesystem designed for small IoT level > >> >> > devices - so I'm struggling to see why we'd want to expend any > >> >> > effort to make XFS work on such devices.... > >> >> > > >> >> > >> >> Hi David, > >> >> > >> >> Yes XFS as the main fs on this type of devices does not make sense, > >> >> but does it hurt to be able to perform basic operation on XFS from > >> >> these devices? Perhaps accessing an external medium formatted with > >> >> XFS? > >> >> > >> >> Another example is accessing VM images that are formatted with XFS. > >> >> Currently we can do that with tools like libguestfs that use a VM in > >> >> the background. I am working on a lighter solution for that where we > >> >> compile the Linux kernel as a library [1]. This allows access to the > >> >> filesystem without the need to use a full VM. > >> > > >> > That's hardly a "lighter solution" > >> > > >> > I'm kinda tired of the ongoing "hack random shit" approach to > >> > container development. > >> > >> Since apparently there is a container devs hunting party going on > >> right now, let me quickly confess that LKL has nothing to do with > >> (them be damned) containers :) > >> > >> On a more serious note, LKL was not developed for containers or to try > >> to circumvent privileged mounts. It was developed to allow the Linux > >> kernel code to be reused in things like simple tools that allows one > >> to modify a filesystem image. > > > > Anything tool that modifies an XFS filesystem that is not directly > > maintained by the XFS developers voids any kind of support we can > > supply. Just like the fact we don't support tainted kernels because > > the 3rd party binary code is unknowable (and usually crap), having > > the kernel code linked with random 3rd party userspace application > > code is completely unsupportable by us. > > > > Perhaps tainting the kernel is a solution when running unknown > applications linked with LKL. It's not the *kernel* that is the problem - it is LKL that is the tainted code! > I would argue that applications that are maintained together with LKL > (e.g. lklfuse in tools/lkl) should not taint the kernel because those > applications will be under the control of kernel developers. I completely disagree. Just because the code is in the kernel tree, it doesn't mean it's controlled, reviewed, tested or maintained by the relevant subsystem maintainers. If the subsystem maintainers are not actively maintaining/testing those tools, then users can't expect the subsystem maintainers to support them. > I would > also argue that mounting a filesystem read-only should not taint the > kernel either. LKL != kernel. > >> >> And a final example is linking the bootloader code with LKL to access > >> >> the filesystem. This has a hard requirement on non-mmu. > >> > > >> > No way. We *can't* support filesystems that have had bootloaders > >> > make arbitrary changes to the filesystem without the knowlege of the > >> > OS that *owns the filesystem*. Similarly, we cannot support random > >> > applications that internally mount and modify filesystem images in > >> > ways we can't see, control, test or simulate. Sure, they use the > >> > kernel code, but that doesn't stop them from doing stupid shit that > >> > could corrupt the filesystem image. So, no, we are not going to > >> > support giving random applications direct access to XFS filesystem > >> > images, even via LKL. > >> > > >> > >> LKL only exports the Linux kernel system calls and nothing else to > >> applications. Because of that, there should not be any loss of control > >> or visibility to the XFS fs driver. > > > > It runs in the same address space as the user application, yes? And > > hence application bugs can cause the kernel code to malfunction, > > yes? > > > > Most non-mmu architecture have the same issue and nevertheless non-mmu > is still supported in Linux (including most filesystems). That doesn't mean all subsystems in the kernel support users on non-mmu systems. > Also, filesystem code runs in the same address space with other kernel > code and drivers and a bug anywhere in the kernel can cause filesystem > code to malfunction. Well, yes, but we have trust other kernel developers keep their ship in good shape, too. But we don't trust *out of tree code* - that taints the kernel and most upstream kernel developers will notice such taints when there are weird errors being reported.... But you want to extend that trust to whatever random code gets chucked into tools/lkl. I'm stretched far enough already having to keep up with mm, VFS, locking and filesystem developments that I don't have time to keep up with what LKL is doing or what applications people are writing. You're not going to get subsystem maintainers being able to find the time to review and test applications that get stuffed into tools/lkl, so from that perspective it's still a complete crapshoot. > >> > I really don't see how using LKL to give userspace access to XFS > >> > filesystems is a better solution than actually writing a proper, > >> > supported XFS-FUSE module. LKL is so full of compromises that it's > >> > going to be unworkable and unsupportable in practice... > >> > >> Could you elaborate on some of these issues? > > > > Start with "is a no-mmu architecture" and all the compromises that > > means the kernel code needs to make, > > I don't see non-mmu as a compromise. It is supported by Linux and most > filesystems work fine on non-mmu architectures. most != all. XFS is unashamedly aimed and developed for high performance systems. i.e. enterprise servers, HPC, fileservers, cloud storage infrastructure, etc. IOWs, we don't even develop for desktop machines, even though XFS performs adequately for most desktop workloads. We've never cared about non-mmu systems because of the requirements we have on virtually mapped buffers and the fact they don't exist in the target markets XFS aimed at. And, really, LKL doesn't change that... > LKL can be implemented > as a mmu architecture. Having it as a non-mmu architecture has the > advantages of allowing it to run in more constrained environments like > bootloaders. The OS owns the filesystem, not the bootloader. If the bootloader is modifying filesystems (e.g. by running log recovery to mount the fs internally to find the kernel/initrd files), then the boot loader compromises the filesystem integrity. We don't not support such configurations at all. > > and finish it off with "LKL linked applications will > > never be tested by their developers over the full functionality the > > LKL provides them with". > > You lost me here. Why does an application developer have to test the > full functionality of a library it is linked with? How much filesystem testing did you actually do with lklfuse? What about load testing? Data integrity/crash/power fail and recovery testing? Scalability testing? Or have you just assumed that it'll all just work fine because the kernel fs developers test this stuff? Yes, we've tested the kernel code along these lines *in kernel space*. That doesn't mean that an LKL application that uses the kernel functionality *in user space* will behave the same way or, indeed, function correctly in adverse circumstances. Application developers are not going to be aware of such issues, and they aren't going to test for such situations - they are simply going to assume "this works just fine" until it doesn't.... Cheers, Dave. -- Dave Chinner david@fromorbit.com -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.kernel
csiph-web