Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1274695 > unrolled thread

[PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

Started byTejun Heo <tj@kernel.org>
First post2015-11-21 17:20 +0100
Last post2015-11-23 22:00 +0100
Articles 11 — 4 participants

Back to article view | Back to linux.kernel


Contents

  [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup Tejun Heo <tj@kernel.org> - 2015-11-21 17:20 +0100
    [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions Tejun Heo <tj@kernel.org> - 2015-11-21 17:20 +0100
      Re: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions Pablo Neira Ayuso <pablo@netfilter.org> - 2015-11-22 21:40 +0100
      Re: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions Pablo Neira Ayuso <pablo@netfilter.org> - 2015-11-22 21:40 +0100
    Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Daniel Wagner <daniel.wagner@bmw-carit.de> - 2015-11-23 08:20 +0100
      Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Daniel Wagner <daniel.wagner@bmw-carit.de> - 2015-11-23 10:00 +0100
        Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Tejun Heo <tj@kernel.org> - 2015-11-23 17:00 +0100
          Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Daniel Wagner <daniel.wagner@bmw-carit.de> - 2015-11-23 17:00 +0100
          Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Tejun Heo <tj@kernel.org> - 2015-11-23 21:00 +0100
    Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match  in xt_cgroup David Miller <davem@davemloft.net> - 2015-11-23 21:50 +0100
      Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in  xt_cgroup Tejun Heo <tj@kernel.org> - 2015-11-23 22:00 +0100

#1274695 — [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromTejun Heo <tj@kernel.org>
Date2015-11-21 17:20 +0100
Subject[PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qxj3j-7GJ-3@gated-at.bofh.it>
Hello,

This is v3 of the xt_cgroup2 patchset.  Changes from the last take are

* Folded cgroup2 path matching into xt_cgroup as a new revision rather
  than a separate xt_cgroup2 match as suggested by Pablo.

* Refreshed on top of Nina's net_cls dynamic config update fix patch.
  I included the fix patch as part of this series to ease reviewing.

The changes from v1 to v2 are

* Instead of adding sock->sk_cgroup separately, sock->sk_cgrp_data now
  carries either (prioidx, classid) pair or cgroup2 pointer.  This
  avoids inflating struct sock with yet another cgroup related field.
  Unfortunately, this does add some complexity but that's the
  trade-off and the complexity is contained in cgroup proper.

* Various small updats as per David and Jan's reviews.


In cgroup v1, dealing with cgroup membership was difficult because the
number of membership associations was unbound.  As a result, cgroup v1
grew several controllers whose primary purpose is either tagging
membership or pull in configuration knobs from other subsystems so
that cgroup membership test can be avoided.

net_cls and net_prio controllers are examples of the latter.  They
allow configuring network-specific attributes from cgroup side so that
network subsystem can avoid testing cgroup membership; unfortunately,
these are not only cumbersome but also problematic.

Both net_cls and net_prio aren't properly hierarchical.  Both inherit
configuration from the parent on creation but there's no interaction
afterwards.  An ancestor doesn't restrict the behavior in its subtree
in anyway and configuration changes aren't propagated downwards.
Especially when combined with cgroup delegation, this is problematic
because delegatees can mess up whatever network configuration
implemented at the system level.  net_prio would allow the delegatees
to set whatever priority value regardless of CAP_NET_ADMIN and net_cls
the same for classid.

While it is possible to solve these issues from controller side by
implementing hierarchical allowable ranges in both controllers, it
would involve quite a bit of complexity in the controllers and further
obfuscate network configuration as it becomes even more difficult to
tell what's actually being configured looking from the network side.
While not much can be done for v1 at this point, as membership
handling is sane on cgroup v2, it'd be better to make cgroup matching
behave like other network matches and classifiers than introducing
further complications.

This patchset includes the following nine patches.

 0001-cgroup-record-ancestor-IDs-and-reimplement-cgroup_is.patch
 0002-kernfs-implement-kernfs_walk_and_get.patch
 0003-cgroup-implement-cgroup_get_from_path-and-expose-cgr.patch
 0004-cgroups-Allow-dynamically-changing-net_classid.patch
 0005-netprio_cgroup-limit-the-maximum-css-id-to-USHRT_MAX.patch
 0006-net-wrap-sock-sk_cgrp_prioidx-and-sk_classid-inside-.patch
 0007-sock-cgroup-add-sock-sk_cgroup.patch
 0008-netfilter-prepare-xt_cgroup-for-multi-revisions.patch
 0009-netfilter-implement-xt_cgroup-cgroup2-path-match.patch

0001-0003 are prepatory patches in kernfs and cgroup.  These patches
are available in the following branch which will stay stable.

 git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup.git for-4.5-ancestor-test

0004 is the following net_cls config update fix patch included in this
series to ease reviewing as it causes a conflict with a later patch in
this series.

 http://lkml.kernel.org/g/1448051499-1885574-1-git-send-email-ninasc@fb.com

0005-0007 consolidate two cgroup related fields in struct sock into
cgroup_sock_data and update it so that it can alternatively carry a
cgroup pointer.

0008-0009 implement cgroup2 patch matching in xt_cgroup.

This patchset is on top of v4.4-rc1 and also available in the
following git branch.

 git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup.git review-xt_cgroup2

I'll post iptables extension as a reply.  diffstat follows.  Thanks.

 fs/kernfs/dir.c                          |   46 +++++++++++
 include/linux/cgroup-defs.h              |  126 +++++++++++++++++++++++++++++++
 include/linux/cgroup.h                   |   66 +++++++++++++++-
 include/linux/kernfs.h                   |   12 ++
 include/net/cls_cgroup.h                 |   11 +-
 include/net/netprio_cgroup.h             |   16 +++
 include/net/sock.h                       |   13 ---
 include/uapi/linux/netfilter/xt_cgroup.h |   15 +++
 kernel/cgroup.c                          |  126 ++++++++++++++++++++++++-------
 net/Kconfig                              |    6 +
 net/core/dev.c                           |    3 
 net/core/netclassid_cgroup.c             |   37 ++++++---
 net/core/netprio_cgroup.c                |   19 ++++
 net/core/scm.c                           |    4 
 net/core/sock.c                          |   17 ----
 net/netfilter/nft_meta.c                 |    2 
 net/netfilter/xt_cgroup.c                |  108 ++++++++++++++++++++++----
 17 files changed, 531 insertions(+), 96 deletions(-)

--
tejun
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1274696 — [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions

FromTejun Heo <tj@kernel.org>
Date2015-11-21 17:20 +0100
Subject[PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions
Message-ID<qxj3l-7GJ-33@gated-at.bofh.it>
In reply to#1274695
libxt_cgroup will grow cgroup2 path based match.  Postfix existing
symbols with _v0 and prepare for multi revision registration.  While
at it, rename O_CGROUP to O_CLASSID and fwid to classid.

Signed-off-by: Tejun Heo <tj@kernel.org>
Cc: Daniel Borkmann <dborkman@redhat.com>
Cc: Jan Engelhardt <jengelh@inai.de>
Cc: Pablo Neira Ayuso <pablo@netfilter.org>
---
 extensions/libxt_cgroup.c           |   51 +++++++++++++++++++-----------------
 include/linux/netfilter/xt_cgroup.h |    2 -
 2 files changed, 28 insertions(+), 25 deletions(-)

--- a/extensions/libxt_cgroup.c
+++ b/extensions/libxt_cgroup.c
@@ -3,30 +3,30 @@
 #include <linux/netfilter/xt_cgroup.h>
 
 enum {
-	O_CGROUP = 0,
+	O_CLASSID = 0,
 };
 
-static void cgroup_help(void)
+static void cgroup_help_v0(void)
 {
 	printf(
 "cgroup match options:\n"
-"[!] --cgroup fwid  Match cgroup fwid\n");
+"[!] --cgroup classid            Match cgroup classid\n");
 }
 
-static const struct xt_option_entry cgroup_opts[] = {
+static const struct xt_option_entry cgroup_opts_v0[] = {
 	{
 		.name = "cgroup",
-		.id = O_CGROUP,
+		.id = O_CLASSID,
 		.type = XTTYPE_UINT32,
 		.flags = XTOPT_INVERT | XTOPT_MAND | XTOPT_PUT,
-		XTOPT_POINTER(struct xt_cgroup_info, id)
+		XTOPT_POINTER(struct xt_cgroup_info_v0, id)
 	},
 	XTOPT_TABLEEND,
 };
 
-static void cgroup_parse(struct xt_option_call *cb)
+static void cgroup_parse_v0(struct xt_option_call *cb)
 {
-	struct xt_cgroup_info *cgroupinfo = cb->data;
+	struct xt_cgroup_info_v0 *cgroupinfo = cb->data;
 
 	xtables_option_parse(cb);
 	if (cb->invert)
@@ -34,34 +34,37 @@ static void cgroup_parse(struct xt_optio
 }
 
 static void
-cgroup_print(const void *ip, const struct xt_entry_match *match, int numeric)
+cgroup_print_v0(const void *ip, const struct xt_entry_match *match, int numeric)
 {
-	const struct xt_cgroup_info *info = (void *) match->data;
+	const struct xt_cgroup_info_v0 *info = (void *) match->data;
 
 	printf(" cgroup %s%u", info->invert ? "! ":"", info->id);
 }
 
-static void cgroup_save(const void *ip, const struct xt_entry_match *match)
+static void cgroup_save_v0(const void *ip, const struct xt_entry_match *match)
 {
-	const struct xt_cgroup_info *info = (void *) match->data;
+	const struct xt_cgroup_info_v0 *info = (void *) match->data;
 
 	printf("%s --cgroup %u", info->invert ? " !" : "", info->id);
 }
 
-static struct xtables_match cgroup_match = {
-	.family		= NFPROTO_UNSPEC,
-	.name		= "cgroup",
-	.version	= XTABLES_VERSION,
-	.size		= XT_ALIGN(sizeof(struct xt_cgroup_info)),
-	.userspacesize	= XT_ALIGN(sizeof(struct xt_cgroup_info)),
-	.help		= cgroup_help,
-	.print		= cgroup_print,
-	.save		= cgroup_save,
-	.x6_parse	= cgroup_parse,
-	.x6_options	= cgroup_opts,
+static struct xtables_match cgroup_match[] = {
+	{
+		.family		= NFPROTO_UNSPEC,
+		.revision	= 0,
+		.name		= "cgroup",
+		.version	= XTABLES_VERSION,
+		.size		= XT_ALIGN(sizeof(struct xt_cgroup_info_v0)),
+		.userspacesize	= XT_ALIGN(sizeof(struct xt_cgroup_info_v0)),
+		.help		= cgroup_help_v0,
+		.print		= cgroup_print_v0,
+		.save		= cgroup_save_v0,
+		.x6_parse	= cgroup_parse_v0,
+		.x6_options	= cgroup_opts_v0,
+	},
 };
 
 void _init(void)
 {
-	xtables_register_match(&cgroup_match);
+	xtables_register_matches(cgroup_match, ARRAY_SIZE(cgroup_match));
 }
--- a/include/linux/netfilter/xt_cgroup.h
+++ b/include/linux/netfilter/xt_cgroup.h
@@ -3,7 +3,7 @@
 
 #include <linux/types.h>
 
-struct xt_cgroup_info {
+struct xt_cgroup_info_v0 {
 	__u32 id;
 	__u32 invert;
 };
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1274942 — Re: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions

FromPablo Neira Ayuso <pablo@netfilter.org>
Date2015-11-22 21:40 +0100
SubjectRe: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions
Message-ID<qxJAt-mn-3@gated-at.bofh.it>
In reply to#1274696
On Sun, Nov 22, 2015 at 09:31:28PM +0100, Pablo Neira Ayuso wrote:
> On Sat, Nov 21, 2015 at 11:18:46AM -0500, Tejun Heo wrote:
> > --- a/extensions/libxt_cgroup.c
> > +++ b/extensions/libxt_cgroup.c
> > @@ -3,30 +3,30 @@
> >  #include <linux/netfilter/xt_cgroup.h>
> >  
> >  enum {
> > -	O_CGROUP = 0,
> > +	O_CLASSID = 0,
> >  };
> >  
> > -static void cgroup_help(void)
> > +static void cgroup_help_v0(void)
> >  {
> >  	printf(
> >  "cgroup match options:\n"
> > -"[!] --cgroup fwid  Match cgroup fwid\n");
> > +"[!] --cgroup classid            Match cgroup classid\n");
> 
> We have to keep the old cgroup integer ID around for a while,
> otherwise we'll break users with old kernels and new iptables
> utilities.

Oh, I see.

This is just a rename to prepare the string based identifier.

Sorry for the noise.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1274945 — Re: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions

FromPablo Neira Ayuso <pablo@netfilter.org>
Date2015-11-22 21:40 +0100
SubjectRe: [PATCH 1/2 iptables] libxt_cgroup: prepare for multi revisions
Message-ID<qxJAt-mn-5@gated-at.bofh.it>
In reply to#1274696
On Sat, Nov 21, 2015 at 11:18:46AM -0500, Tejun Heo wrote:
> libxt_cgroup will grow cgroup2 path based match.  Postfix existing
> symbols with _v0 and prepare for multi revision registration.  While
> at it, rename O_CGROUP to O_CLASSID and fwid to classid.
> 
> Signed-off-by: Tejun Heo <tj@kernel.org>
> Cc: Daniel Borkmann <dborkman@redhat.com>
> Cc: Jan Engelhardt <jengelh@inai.de>
> Cc: Pablo Neira Ayuso <pablo@netfilter.org>
> ---
>  extensions/libxt_cgroup.c           |   51 +++++++++++++++++++-----------------
>  include/linux/netfilter/xt_cgroup.h |    2 -
>  2 files changed, 28 insertions(+), 25 deletions(-)
> 
> --- a/extensions/libxt_cgroup.c
> +++ b/extensions/libxt_cgroup.c
> @@ -3,30 +3,30 @@
>  #include <linux/netfilter/xt_cgroup.h>
>  
>  enum {
> -	O_CGROUP = 0,
> +	O_CLASSID = 0,
>  };
>  
> -static void cgroup_help(void)
> +static void cgroup_help_v0(void)
>  {
>  	printf(
>  "cgroup match options:\n"
> -"[!] --cgroup fwid  Match cgroup fwid\n");
> +"[!] --cgroup classid            Match cgroup classid\n");

We have to keep the old cgroup integer ID around for a while,
otherwise we'll break users with old kernels and new iptables
utilities.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275065 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromDaniel Wagner <daniel.wagner@bmw-carit.de>
Date2015-11-23 08:20 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qxTzP-73h-1@gated-at.bofh.it>
In reply to#1274695
Hi Tejun,

On 11/21/2015 05:13 PM, Tejun Heo wrote:
> This is v3 of the xt_cgroup2 patchset.  Changes from the last take are
> 
> * Folded cgroup2 path matching into xt_cgroup as a new revision rather
>   than a separate xt_cgroup2 match as suggested by Pablo.
> 
> * Refreshed on top of Nina's net_cls dynamic config update fix patch.
>   I included the fix patch as part of this series to ease reviewing.

I started to play with your patches and was greeted by this:

[    3.217648] systemd[1]: tmp.mount: Directory /tmp to mount over is not empty, mounting anyway.
[    3.224665] BUG: spinlock bad magic on CPU#1, systemd/1
[    3.225653]  lock: cgroup_sk_update_lock+0x0/0x60, .magic: 00000000, .owner: systemd/1, .owner_cpu: 1
[    3.227034] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #195
[    3.227862] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
[    3.228906]  ffffffff834a2160 ffff88007c043ad0 ffffffff81551edc ffff88007c028000
[    3.229512]  ffff88007c043af0 ffffffff81136868 ffffffff834a2160 ffff88007aff5940
[    3.230105]  ffff88007c043b08 ffffffff81136b05 ffffffff834a2160 ffff88007c043b20
[    3.230716] Call Trace:
[    3.230906]  [<ffffffff81551edc>] dump_stack+0x4e/0x82
[    3.231289]  [<ffffffff81136868>] spin_dump+0x78/0xc0
[    3.231642]  [<ffffffff81136b05>] do_raw_spin_unlock+0x75/0xd0
[    3.232039]  [<ffffffff81bced77>] _raw_spin_unlock+0x27/0x50
[    3.232431]  [<ffffffff819b1848>] update_classid_sock+0x68/0x80
[    3.232836]  [<ffffffff812855c1>] iterate_fd+0x71/0x150
[    3.233197]  [<ffffffff819b1757>] update_classid+0x47/0x80
[    3.233571]  [<ffffffff819b17d4>] cgrp_attach+0x14/0x20
[    3.233929]  [<ffffffff81188951>] cgroup_taskset_migrate+0x1e1/0x330
[    3.234366]  [<ffffffff81188b95>] cgroup_migrate+0xf5/0x190
[    3.234747]  [<ffffffff81188aa5>] ? cgroup_migrate+0x5/0x190
[    3.235130]  [<ffffffff81188da6>] cgroup_attach_task+0x176/0x200
[    3.235543]  [<ffffffff81188c35>] ? cgroup_attach_task+0x5/0x200
[    3.235953]  [<ffffffff8118922d>] __cgroup_procs_write+0x2ad/0x460
[    3.236377]  [<ffffffff81188fde>] ? __cgroup_procs_write+0x5e/0x460
[    3.236805]  [<ffffffff81189414>] cgroup_procs_write+0x14/0x20
[    3.237205]  [<ffffffff81185ae5>] cgroup_file_write+0x35/0x1c0
[    3.237600]  [<ffffffff812e25e1>] kernfs_fop_write+0x141/0x190
[    3.237998]  [<ffffffff81265e78>] __vfs_write+0x28/0xe0
[    3.238361]  [<ffffffff811292c7>] ? percpu_down_read+0x57/0xa0
[    3.238761]  [<ffffffff81268b04>] ? __sb_start_write+0xb4/0xf0
[    3.239154]  [<ffffffff81268b04>] ? __sb_start_write+0xb4/0xf0
[    3.239554]  [<ffffffff812665ec>] vfs_write+0xac/0x1a0
[    3.239930]  [<ffffffff81285fa6>] ? __fget_light+0x66/0x90
[    3.240308]  [<ffffffff81266f09>] SyS_write+0x49/0xb0
[    3.240656]  [<ffffffff81bcfb32>] entry_SYSCALL_64_fastpath+0x12/0x76

I am using a Fedora 23 host with systemd.unified_cgroup_hierarchy=1. The config is
available here:

	http://monom.org/cgroup/config-review-xt_cgroup2

Probably completely rubbish, because it's my random test config.

cheers,
daniel
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275141 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromDaniel Wagner <daniel.wagner@bmw-carit.de>
Date2015-11-23 10:00 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qxV8D-7TP-35@gated-at.bofh.it>
In reply to#1275065
On 11/23/2015 08:11 AM, Daniel Wagner wrote:
> [    3.217648] systemd[1]: tmp.mount: Directory /tmp to mount over is not empty, mounting anyway.
> [    3.224665] BUG: spinlock bad magic on CPU#1, systemd/1
> [    3.225653]  lock: cgroup_sk_update_lock+0x0/0x60, .magic: 00000000, .owner: systemd/1, .owner_cpu: 1
> [    3.227034] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #195
> [    3.227862] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
> [    3.228906]  ffffffff834a2160 ffff88007c043ad0 ffffffff81551edc ffff88007c028000
> [    3.229512]  ffff88007c043af0 ffffffff81136868 ffffffff834a2160 ffff88007aff5940
> [    3.230105]  ffff88007c043b08 ffffffff81136b05 ffffffff834a2160 ffff88007c043b20
> [    3.230716] Call Trace:
> [    3.230906]  [<ffffffff81551edc>] dump_stack+0x4e/0x82
> [    3.231289]  [<ffffffff81136868>] spin_dump+0x78/0xc0
> [    3.231642]  [<ffffffff81136b05>] do_raw_spin_unlock+0x75/0xd0
> [    3.232039]  [<ffffffff81bced77>] _raw_spin_unlock+0x27/0x50
> [    3.232431]  [<ffffffff819b1848>] update_classid_sock+0x68/0x80
> [    3.232836]  [<ffffffff812855c1>] iterate_fd+0x71/0x150
> [    3.233197]  [<ffffffff819b1757>] update_classid+0x47/0x80
> [    3.233571]  [<ffffffff819b17d4>] cgrp_attach+0x14/0x20
> [    3.233929]  [<ffffffff81188951>] cgroup_taskset_migrate+0x1e1/0x330
> [    3.234366]  [<ffffffff81188b95>] cgroup_migrate+0xf5/0x190
> [    3.234747]  [<ffffffff81188aa5>] ? cgroup_migrate+0x5/0x190
> [    3.235130]  [<ffffffff81188da6>] cgroup_attach_task+0x176/0x200
> [    3.235543]  [<ffffffff81188c35>] ? cgroup_attach_task+0x5/0x200
> [    3.235953]  [<ffffffff8118922d>] __cgroup_procs_write+0x2ad/0x460
> [    3.236377]  [<ffffffff81188fde>] ? __cgroup_procs_write+0x5e/0x460
> [    3.236805]  [<ffffffff81189414>] cgroup_procs_write+0x14/0x20
> [    3.237205]  [<ffffffff81185ae5>] cgroup_file_write+0x35/0x1c0
> [    3.237600]  [<ffffffff812e25e1>] kernfs_fop_write+0x141/0x190
> [    3.237998]  [<ffffffff81265e78>] __vfs_write+0x28/0xe0
> [    3.238361]  [<ffffffff811292c7>] ? percpu_down_read+0x57/0xa0
> [    3.238761]  [<ffffffff81268b04>] ? __sb_start_write+0xb4/0xf0
> [    3.239154]  [<ffffffff81268b04>] ? __sb_start_write+0xb4/0xf0
> [    3.239554]  [<ffffffff812665ec>] vfs_write+0xac/0x1a0
> [    3.239930]  [<ffffffff81285fa6>] ? __fget_light+0x66/0x90
> [    3.240308]  [<ffffffff81266f09>] SyS_write+0x49/0xb0
> [    3.240656]  [<ffffffff81bcfb32>] entry_SYSCALL_64_fastpath+0x12/0x76

I have enabled a few additional cgroup controllers as well, because I was
trying to figure out why I only see the 'memory' cgroup controller in 
cgroup.controllers. pid and io show up but not net_prio or net_cls.
Not sure why systemd (v227) is not mounting them.

Though, after a while a similar call trace is produced. I guess this
has nothing to do with the current changes.

[   11.594536] ------------[ cut here ]------------
[   11.595274] WARNING: CPU: 1 PID: 1 at kernel/cgroup_pids.c:97 pids_cancel.constprop.6+0x31/0x40()
[   11.595958] Modules linked in:
[   11.596199] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #196
[   11.596689] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
[   11.597632]  ffffffff81f66d8b ffff88007c04bb90 ffffffff8155ccdc 0000000000000000
[   11.598234]  ffff88007c04bbc8 ffffffff810de202 ffff8800793dda00 ffff88007a096800
[   11.598877]  ffff88007c04bc80 ffff88007a6b6200 0000000000000001 ffff88007c04bbd8
[   11.599547] Call Trace:
[   11.599784]  [<ffffffff8155ccdc>] dump_stack+0x4e/0x82
[   11.600197]  [<ffffffff810de202>] warn_slowpath_common+0x82/0xc0
[   11.600705]  [<ffffffff810de2fa>] warn_slowpath_null+0x1a/0x20
[   11.601208]  [<ffffffff8118e261>] pids_cancel.constprop.6+0x31/0x40
[   11.601764]  [<ffffffff8118e32d>] pids_can_attach+0x6d/0xf0
[   11.602245]  [<ffffffff811887fa>] cgroup_taskset_migrate+0x6a/0x330
[   11.602795]  [<ffffffff81188bb5>] cgroup_migrate+0xf5/0x190
[   11.603276]  [<ffffffff81188ac5>] ? cgroup_migrate+0x5/0x190
[   11.603788]  [<ffffffff81188dc6>] cgroup_attach_task+0x176/0x200
[   11.604308]  [<ffffffff81188c55>] ? cgroup_attach_task+0x5/0x200
[   11.604831]  [<ffffffff8118924d>] __cgroup_procs_write+0x2ad/0x460
[   11.605367]  [<ffffffff81188ffe>] ? __cgroup_procs_write+0x5e/0x460
[   11.605929]  [<ffffffff81189434>] cgroup_procs_write+0x14/0x20
[   11.606448]  [<ffffffff81185af5>] cgroup_file_write+0x35/0x1c0
[   11.606931]  [<ffffffff812e94f1>] kernfs_fop_write+0x141/0x190
[   11.607401]  [<ffffffff81269b18>] __vfs_write+0x28/0xe0
[   11.607834]  [<ffffffff811292d7>] ? percpu_down_read+0x57/0xa0
[   11.608366]  [<ffffffff8126c7a4>] ? __sb_start_write+0xb4/0xf0
[   11.608874]  [<ffffffff8126c7a4>] ? __sb_start_write+0xb4/0xf0
[   11.609343]  [<ffffffff8126a28c>] vfs_write+0xac/0x1a0
[   11.609843]  [<ffffffff81289db6>] ? __fget_light+0x66/0x90
[   11.610315]  [<ffffffff8126aba9>] SyS_write+0x49/0xb0
[   11.610756]  [<ffffffff81bdb4f2>] entry_SYSCALL_64_fastpath+0x12/0x76
[   11.611305] ---[ end trace 7f953d0ce5af99ea ]---

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275506 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromTejun Heo <tj@kernel.org>
Date2015-11-23 17:00 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qy1H4-3Pv-17@gated-at.bofh.it>
In reply to#1275141
On Mon, Nov 23, 2015 at 09:54:32AM +0100, Daniel Wagner wrote:
...
> > [    3.224665] BUG: spinlock bad magic on CPU#1, systemd/1
> > [    3.225653]  lock: cgroup_sk_update_lock+0x0/0x60, .magic: 00000000, .owner: systemd/1, .owner_cpu: 1
> > [    3.227034] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #195
> > [    3.227862] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
> > [    3.228906]  ffffffff834a2160 ffff88007c043ad0 ffffffff81551edc ffff88007c028000
> > [    3.229512]  ffff88007c043af0 ffffffff81136868 ffffffff834a2160 ffff88007aff5940
> > [    3.230105]  ffff88007c043b08 ffffffff81136b05 ffffffff834a2160 ffff88007c043b20
> > [    3.230716] Call Trace:
> > [    3.230906]  [<ffffffff81551edc>] dump_stack+0x4e/0x82
> > [    3.231289]  [<ffffffff81136868>] spin_dump+0x78/0xc0
> > [    3.231642]  [<ffffffff81136b05>] do_raw_spin_unlock+0x75/0xd0
> > [    3.232039]  [<ffffffff81bced77>] _raw_spin_unlock+0x27/0x50
> > [    3.232431]  [<ffffffff819b1848>] update_classid_sock+0x68/0x80
> > [    3.232836]  [<ffffffff812855c1>] iterate_fd+0x71/0x150
> > [    3.233197]  [<ffffffff819b1757>] update_classid+0x47/0x80
> > [    3.233571]  [<ffffffff819b17d4>] cgrp_attach+0x14/0x20
> > [    3.233929]  [<ffffffff81188951>] cgroup_taskset_migrate+0x1e1/0x330
> > [    3.234366]  [<ffffffff81188b95>] cgroup_migrate+0xf5/0x190
> > [    3.235130]  [<ffffffff81188da6>] cgroup_attach_task+0x176/0x200
> > [    3.235953]  [<ffffffff8118922d>] __cgroup_procs_write+0x2ad/0x460
> > [    3.236805]  [<ffffffff81189414>] cgroup_procs_write+0x14/0x20
> > [    3.237205]  [<ffffffff81185ae5>] cgroup_file_write+0x35/0x1c0
> > [    3.237600]  [<ffffffff812e25e1>] kernfs_fop_write+0x141/0x190
> > [    3.237998]  [<ffffffff81265e78>] __vfs_write+0x28/0xe0
> > [    3.239554]  [<ffffffff812665ec>] vfs_write+0xac/0x1a0
> > [    3.240308]  [<ffffffff81266f09>] SyS_write+0x49/0xb0
> > [    3.240656]  [<ffffffff81bcfb32>] entry_SYSCALL_64_fastpath+0x12/0x76
> 
> I have enabled a few additional cgroup controllers as well, because I was
> trying to figure out why I only see the 'memory' cgroup controller in 
> cgroup.controllers. pid and io show up but not net_prio or net_cls.
> Not sure why systemd (v227) is not mounting them.

net_prio and net_cls aren't gonna be on the v2 hierarchy.  The match
in this patchset is being introduced to replace them; however, you can
mount them separately on a v1 hierarchy and use the same as before.

> Though, after a while a similar call trace is produced. I guess this
> has nothing to do with the current changes.
> 
> [   11.594536] ------------[ cut here ]------------
> [   11.595274] WARNING: CPU: 1 PID: 1 at kernel/cgroup_pids.c:97 pids_cancel.constprop.6+0x31/0x40()
> [   11.595958] Modules linked in:
> [   11.596199] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #196
> [   11.596689] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
> [   11.597632]  ffffffff81f66d8b ffff88007c04bb90 ffffffff8155ccdc 0000000000000000
> [   11.598234]  ffff88007c04bbc8 ffffffff810de202 ffff8800793dda00 ffff88007a096800
> [   11.598877]  ffff88007c04bc80 ffff88007a6b6200 0000000000000001 ffff88007c04bbd8
> [   11.599547] Call Trace:
> [   11.599784]  [<ffffffff8155ccdc>] dump_stack+0x4e/0x82
> [   11.600197]  [<ffffffff810de202>] warn_slowpath_common+0x82/0xc0
> [   11.600705]  [<ffffffff810de2fa>] warn_slowpath_null+0x1a/0x20
> [   11.601208]  [<ffffffff8118e261>] pids_cancel.constprop.6+0x31/0x40
> [   11.601764]  [<ffffffff8118e32d>] pids_can_attach+0x6d/0xf0

Yeah, this is a known problem regarding css's lifetime.  Working on
it.  The earlier dump, I think, is likely to have been caused by the
same issue.

Thanks.

-- 
tejun
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275509 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromDaniel Wagner <daniel.wagner@bmw-carit.de>
Date2015-11-23 17:00 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qy1H4-3Pv-15@gated-at.bofh.it>
In reply to#1275506
On 11/23/2015 04:53 PM, Tejun Heo wrote:
> On Mon, Nov 23, 2015 at 09:54:32AM +0100, Daniel Wagner wrote:
> ...
>>> [    3.224665] BUG: spinlock bad magic on CPU#1, systemd/1
>>> [    3.225653]  lock: cgroup_sk_update_lock+0x0/0x60, .magic: 00000000, .owner: systemd/1, .owner_cpu: 1
>>> [    3.227034] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #195
>>> [    3.227862] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
>>> [    3.228906]  ffffffff834a2160 ffff88007c043ad0 ffffffff81551edc ffff88007c028000
>>> [    3.229512]  ffff88007c043af0 ffffffff81136868 ffffffff834a2160 ffff88007aff5940
>>> [    3.230105]  ffff88007c043b08 ffffffff81136b05 ffffffff834a2160 ffff88007c043b20
>>> [    3.230716] Call Trace:
>>> [    3.230906]  [<ffffffff81551edc>] dump_stack+0x4e/0x82
>>> [    3.231289]  [<ffffffff81136868>] spin_dump+0x78/0xc0
>>> [    3.231642]  [<ffffffff81136b05>] do_raw_spin_unlock+0x75/0xd0
>>> [    3.232039]  [<ffffffff81bced77>] _raw_spin_unlock+0x27/0x50
>>> [    3.232431]  [<ffffffff819b1848>] update_classid_sock+0x68/0x80
>>> [    3.232836]  [<ffffffff812855c1>] iterate_fd+0x71/0x150
>>> [    3.233197]  [<ffffffff819b1757>] update_classid+0x47/0x80
>>> [    3.233571]  [<ffffffff819b17d4>] cgrp_attach+0x14/0x20
>>> [    3.233929]  [<ffffffff81188951>] cgroup_taskset_migrate+0x1e1/0x330
>>> [    3.234366]  [<ffffffff81188b95>] cgroup_migrate+0xf5/0x190
>>> [    3.235130]  [<ffffffff81188da6>] cgroup_attach_task+0x176/0x200
>>> [    3.235953]  [<ffffffff8118922d>] __cgroup_procs_write+0x2ad/0x460
>>> [    3.236805]  [<ffffffff81189414>] cgroup_procs_write+0x14/0x20
>>> [    3.237205]  [<ffffffff81185ae5>] cgroup_file_write+0x35/0x1c0
>>> [    3.237600]  [<ffffffff812e25e1>] kernfs_fop_write+0x141/0x190
>>> [    3.237998]  [<ffffffff81265e78>] __vfs_write+0x28/0xe0
>>> [    3.239554]  [<ffffffff812665ec>] vfs_write+0xac/0x1a0
>>> [    3.240308]  [<ffffffff81266f09>] SyS_write+0x49/0xb0
>>> [    3.240656]  [<ffffffff81bcfb32>] entry_SYSCALL_64_fastpath+0x12/0x76
>>
>> I have enabled a few additional cgroup controllers as well, because I was
>> trying to figure out why I only see the 'memory' cgroup controller in 
>> cgroup.controllers. pid and io show up but not net_prio or net_cls.
>> Not sure why systemd (v227) is not mounting them.
> 
> net_prio and net_cls aren't gonna be on the v2 hierarchy.  The match
> in this patchset is being introduced to replace them; however, you can
> mount them separately on a v1 hierarchy and use the same as before.

Okay, I could have figured that myself I guess. I mounted the v1
hierarchy and it works as you have described it.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275791 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromTejun Heo <tj@kernel.org>
Date2015-11-23 21:00 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qy5rl-6jA-33@gated-at.bofh.it>
In reply to#1275506
Hello,

On Mon, Nov 23, 2015 at 10:53:46AM -0500, Tejun Heo wrote:
> > [   11.594536] ------------[ cut here ]------------
> > [   11.595274] WARNING: CPU: 1 PID: 1 at kernel/cgroup_pids.c:97 pids_cancel.constprop.6+0x31/0x40()
> > [   11.595958] Modules linked in:
> > [   11.596199] CPU: 1 PID: 1 Comm: systemd Not tainted 4.4.0-rc1+ #196
> > [   11.596689] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.8.2-0-g33fbe13 by qemu-project.org 04/01/2014
> > [   11.597632]  ffffffff81f66d8b ffff88007c04bb90 ffffffff8155ccdc 0000000000000000
> > [   11.598234]  ffff88007c04bbc8 ffffffff810de202 ffff8800793dda00 ffff88007a096800
> > [   11.598877]  ffff88007c04bc80 ffff88007a6b6200 0000000000000001 ffff88007c04bbd8
> > [   11.599547] Call Trace:
> > [   11.599784]  [<ffffffff8155ccdc>] dump_stack+0x4e/0x82
> > [   11.600197]  [<ffffffff810de202>] warn_slowpath_common+0x82/0xc0
> > [   11.600705]  [<ffffffff810de2fa>] warn_slowpath_null+0x1a/0x20
> > [   11.601208]  [<ffffffff8118e261>] pids_cancel.constprop.6+0x31/0x40
> > [   11.601764]  [<ffffffff8118e32d>] pids_can_attach+0x6d/0xf0
> 
> Yeah, this is a known problem regarding css's lifetime.  Working on
> it.  The earlier dump, I think, is likely to have been caused by the
> same issue.

Just posted the fix for this issue.  Can you please verify the fix?

 http://lkml.kernel.org/g/20151123195541.GA19072@mtj.duckdns.org

Thanks a lot!

-- 
tejun
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275839 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromDavid Miller <davem@davemloft.net>
Date2015-11-23 21:50 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qy6dI-6Rx-23@gated-at.bofh.it>
In reply to#1274695
From: Tejun Heo <tj@kernel.org>
Date: Sat, 21 Nov 2015 11:13:52 -0500

> * Refreshed on top of Nina's net_cls dynamic config update fix patch.
>   I included the fix patch as part of this series to ease reviewing.

I put this into the 'net' tree as it's a bug fix, so can you respin
this after I next merge 'net' into 'net-next'?  I'll let you know.

There'll probably be at least some minor feedback meanwhile anyways.

Thanks.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1275849 — Re: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup

FromTejun Heo <tj@kernel.org>
Date2015-11-23 22:00 +0100
SubjectRe: [PATCHSET v3] netfilter, cgroup: implement cgroup2 path match in xt_cgroup
Message-ID<qy6no-6VJ-17@gated-at.bofh.it>
In reply to#1275839
On Mon, Nov 23, 2015 at 03:45:23PM -0500, David Miller wrote:
> > * Refreshed on top of Nina's net_cls dynamic config update fix patch.
> >   I included the fix patch as part of this series to ease reviewing.
> 
> I put this into the 'net' tree as it's a bug fix, so can you respin
> this after I next merge 'net' into 'net-next'?  I'll let you know.

Sure thing.

Thanks.

-- 
tejun
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web