Thread (3 messages) flat view 3 messages, 2 authors, 2012-07-12

Re: [PATCH 2/2] bonding: debugfs and network namespaces are incompatible

From: Jay Vosburgh <hidden>
Date: 2012-07-10 19:14:49

	[ adding netdev back to cc: ]

Eric W. Biederman [off-list ref] wrote:
Jay Vosburgh [off-list ref] wrote:
quoted
David Miller [off-list ref] wrote:
quoted
From: ebiederm@xmission.com (Eric W. Biederman)
Date: Mon, 09 Jul 2012 13:52:43 -0700
quoted
The bonding debugfs support has been broken in the presence of
network
quoted
quoted
namespaces since it has been added.  The debugfs support does not
handle
quoted
quoted
multiple bonding devices with the same name in different network
namespaces.

I haven't had any bug reports, and I'm not interested in getting
any.
quoted
quoted
Disable the debugfs support when network namespaces are enabled.

Signed-off-by: "Eric W. Biederman" <redacted>
Applied.
Since distro kernels appear to set CONFIG_NET_NS, doesn't this
effectively disable debugfs for bonding on most distros?
Yes.
quoted
Do the other network device drivers that support debugfs have a
similar problem?  E.g., if each of two namespaces have an skge device
with the same name, will there be a debugfs conflict there as well?
I haven't run across any of those network devices, but if they create a
debugfs entry that embeds the device name it will be a problem.
	A quick grep suggests that cxgb4, skge, sky2, stmmac, ipoib and
half a dozen of the wireless drivers all create files in debugfs.  I did
not check exhaustively, but at least some of them include the device
name.
Last I looked any custom user space interface from network devices was
rare and bonding using debugfs is the first instance of using debugfs
from networking devices I have seen.

I think the problem will be a little less severe for physical network
devices as they all start in the initial network namespace and so start
with distinct names.

With bonding I can do "ip link add type bond" in any network namespace
and get another bond0.  So name conflicts are very much expeted with all
virtual networking devices.
	Fair enough, although it is trivial to rename any network device
such that a conflict would occur.

	It looks like some of the drivers use fixed names for some
things as well.
But if you know of any other networking devices using debugsfs that
code should probably get the same treatment as the bonding debugfs code.
	Is there no alternative than simply disabling debugfs whenever
network namespaces are enabled?  The information bonding displays via
debugfs is useful, and having it unavailable on all distro kernels seems
a bit harsh.

	Why is the logic already in the driver not sufficient?  If the
attempt to create the debugfs directory with the interface name fails,
then it merely prints a warning and continues without the debugfs for
that interface.

	-J

---
	-Jay Vosburgh, IBM Linux Technology Center, fubar@us.ibm.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help