Thread (17 messages) 17 messages, 3 authors, 2022-04-25

RE: [net-next 0/4] devlink: add dry run support for flash update

From: "Keller, Jacob E" <jacob.e.keller@intel.com>
Date: 2021-10-11 23:21:57

-----Original Message-----
From: Keller, Jacob E <jacob.e.keller@intel.com>
Sent: Monday, October 11, 2021 1:22 AM
To: Jakub Kicinski <kuba@kernel.org>; Jiri Pirko <jiri@resnulli.us>
Cc: netdev@vger.kernel.org
Subject: RE: [net-next 0/4] devlink: add dry run support for flash update
quoted
-----Original Message-----
From: Jakub Kicinski <kuba@kernel.org>
Sent: Friday, October 08, 2021 11:22 AM
To: Jiri Pirko <jiri@resnulli.us>
Cc: Keller, Jacob E <jacob.e.keller@intel.com>; netdev@vger.kernel.org
Subject: Re: [net-next 0/4] devlink: add dry run support for flash update

On Fri, 8 Oct 2021 14:37:37 +0200 Jiri Pirko wrote:
quoted
Fri, Oct 08, 2021 at 12:41:11PM CEST, jacob.e.keller@intel.com wrote:
quoted
This is an implementation of a previous idea I had discussed on the list at
https://lore.kernel.org/netdev/51a6e7a33c7d40889c80bf37159f210e@intel.co
m/
quoted
quoted
The idea is to allow user space to query whether a given destructive devlink
command would work without actually performing any actions. This is
commonly
quoted
quoted
referred to as a "dry run", and is intended to give tools and system
administrators the ability to test things like flash image validity, or
whether a given option is valid without having to risk performing the update
when not sufficiently ready.

The intention is that all "destructive" commands can be updated to support
the new DEVLINK_ATTR_DRY_RUN, although this series only implements it
for
quoted
quoted
quoted
flash update.

I expect we would want to support this for commands such as reload as well
as other commands which perform some action with no interface to check
state
quoted
quoted
before hand.

I tried to implement the DRY_RUN checks along with useful extended ACK
messages so that even if a driver does not support DRY_RUN, some useful
information can be retrieved. (i.e. the stack indicates that flash update is
supported and will validate the other attributes first before rejecting the
command due to inability to fully validate the run within the driver).
Hmm, old kernel vs. new-userspace, the requested dry-run, won't be
really dry run. I guess that user might be surprised in that case...
Would it be enough to do a policy dump in user space to check attr is
recognized and add a warning that this is required next to the attr
in the uAPI header?
I'd be more in favor of converting either this specific op (or devlink as a whole) to
strict checking. I think that most of the devlink commands and ops would
function better if unknown behaviors were rejected rather than ignored.

If we prefer to avoid that due to historically not being strict, I'm ok with a
userspace check. It does complicate the userspace a bit more, but I agree that
especially for dry_run we don't want it accidentally updating when a dry run was
expected.

There is some maintenance cost to switching to strict checking but I think it's
pretty minimal because the strict checking simply prevents the unknown
attributes from being ignored.

I'm happy to go either direction if we get consensus on this thread though.

Thanks,
Jake
The ice changes in this patch conflict with similar work that I posted on IWL to cleanup some things for devlink reload support, so I'll probably wait to re-submit this until those changes make it through IWL and onto the list proper.

Thanks,
Jake
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help