Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1560623

Re: Potential issues (security and otherwise) with the current cgroup-bpf API

From Michal Hocko <mhocko@kernel.org>
Newsgroups linux.kernel
Subject Re: Potential issues (security and otherwise) with the current cgroup-bpf API
Date 2017-01-17 15:20 +0100
Message-ID <t0CM9-88g-3@gated-at.bofh.it> (permalink)
References (5 earlier) <sQoKu-3Gs-23@gated-at.bofh.it> <sVuvT-4Rn-5@gated-at.bofh.it> <t047L-1vN-5@gated-at.bofh.it> <t0BZM-7Ce-21@gated-at.bofh.it> <t0C9s-7FP-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue 17-01-17 14:32:04, Peter Zijlstra wrote:
> On Tue, Jan 17, 2017 at 02:03:03PM +0100, Michal Hocko wrote:
> > On Sun 15-01-17 20:19:01, Tejun Heo wrote:
> > [...]
> > > So, what's proposed is a proper part of bpf.  In terms of
> > > implementation, cgroup helps by hosting the pointers but that doesn't
> > > necessarily affect the conceptual structure of it.  Given that, I
> > > don't think it'd be a good idea to add anything to cgroup interface
> > > for this feature.  Introspection is great to have but this should be
> > > introspectable together with other bpf programs using the same
> > > mechanism.  That's where it belongs.
> > 
> > If BPF only piggy backs on top of cgroup to iterate tasks shouldn't we
> > at least enforce that the cgroup has to be a leaf one and no further
> > children groups can be created once there is BPF program attached?
> 
> Why (again) this stupid constraint?
> 
> If you want to use cgroups for tagging (like perf does), _any_ parent
> cgroup will also tag you.
> 
> So creating child cgroups, and placing tasks in it, should not be a
> problem, the BPF thing should apply to all of them.

This would require using hierarchical cgroup iterators to iterate over
tasks. As per Andy's testing this doesn't seem to be the case. I haven't
checked the implementation closely but my understanding was that using
only cgroup specific tasks was intentional.

I do agree that using hierarchy aware cgroup iterators is the right
approach here and we wouldn't see any issue. But I am still not sure
I've wrapped my head around this feature completely.

-- 
Michal Hocko
SUSE Labs

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Michal Hocko <mhocko@kernel.org> - 2017-01-17 14:30 +0100
  Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Peter Zijlstra <peterz@infradead.org> - 2017-01-17 14:40 +0100
    Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Michal Hocko <mhocko@kernel.org> - 2017-01-17 15:20 +0100
      Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Andy Lutomirski <luto@amacapital.net> - 2017-01-17 21:40 +0100
      Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Tejun Heo <tj@kernel.org> - 2017-01-18 23:30 +0100
        Re: Potential issues (security and otherwise) with the current  cgroup-bpf API Michal Hocko <mhocko@kernel.org> - 2017-01-19 10:10 +0100

csiph-web