From: Daniel Lezcano <daniel.lezcano@free.fr>
To: akpm@linux-foundation.org
Cc: oleg@tv-sign.ru, bonbons@linux-vserver.org,
containers@lists.linux-foundation.org,
linux-kernel@vger.kernel.org, serge@hallyn.com
Subject: [PATCH 0/2] Send a SIGCHLD to the init's pid namespace parent when reboot
Date: Thu, 11 Aug 2011 22:23:59 +0200 [thread overview]
Message-ID: <1313094241-3674-1-git-send-email-daniel.lezcano@free.fr> (raw)
From: Daniel Lezcano <dlezcano@fr.ibm.com>
In the case of a VPS, when we shutdown/halt/reboot the container, the
reboot utility will invoke the sys_reboot syscall which has the bad
effect to reboot the host. The way to fix that is to drop the
CAP_SYS_REBOOT capability in the container.
In this case, the container shutdowns correctly but, at the end, the
init process is waiting indefinitely and we have the containers stuck
with one process (the init process).
In order to fix that, we used a hypervisor process, parent of the
container's init process, watching for the container's utmp file and
detecting when the runlevel changes. When this runlevel change is
detected we wait for the container to have one process left and then we
kill the container's init.
That works well if we modify the distro configuration files, we make
/var/run to not be a tmpfs and we remove all the files inside this
directory when the container boots. *But* as soon as we upgrade the
container distro, all the tweaks are lost. So this method works but at
the cost of tweaking the containers configuration files again and again,
each time there is an update, which is not tolerable in a production
environment.
This patchset solves the problem by send a SIGCHLD signal to the process
parent of the init process of the child pid namespace. By this way, we know
when a pid namespace wanted to reboot/halt/shutdown and we can take advantage
of that to kill, restart or suspend the container.
Daniel Lezcano (2):
add SA_CLDREBOOT flag
Notify container-init parent a 'reboot' occured
arch/alpha/include/asm/signal.h | 2 +
arch/arm/include/asm/signal.h | 2 +
arch/avr32/include/asm/signal.h | 2 +
arch/cris/include/asm/signal.h | 2 +
arch/h8300/include/asm/signal.h | 2 +
arch/ia64/include/asm/signal.h | 2 +
arch/m32r/include/asm/signal.h | 2 +
arch/m68k/include/asm/signal.h | 2 +
arch/mips/include/asm/signal.h | 2 +
arch/mn10300/include/asm/signal.h | 2 +
arch/parisc/include/asm/signal.h | 2 +
arch/powerpc/include/asm/signal.h | 2 +
arch/s390/include/asm/signal.h | 2 +
arch/sparc/include/asm/signal.h | 2 +-
arch/x86/include/asm/signal.h | 2 +
arch/xtensa/include/asm/signal.h | 2 +
include/asm-generic/siginfo.h | 3 +-
include/asm-generic/signal.h | 2 +
include/linux/sched.h | 1 +
kernel/signal.c | 40 +++++++++++++++++++++++++++++++++++++
kernel/sys.c | 20 ++++++++++++++++-
21 files changed, 94 insertions(+), 4 deletions(-)
--
1.7.4.1
next reply other threads:[~2011-08-11 20:24 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-08-11 20:23 Daniel Lezcano [this message]
2011-08-11 20:24 ` [PATCH 1/2] add SA_CLDREBOOT flag Daniel Lezcano
2011-08-14 16:15 ` Oleg Nesterov
2011-08-14 16:36 ` Bruno Prémont
2011-08-14 17:10 ` Oleg Nesterov
2011-08-11 20:24 ` [PATCH 2/2] Notify container-init parent a 'reboot' occured Daniel Lezcano
2011-08-11 21:09 ` Serge Hallyn
2011-08-11 21:30 ` Daniel Lezcano
2011-08-11 21:50 ` Serge Hallyn
2011-08-12 16:29 ` Serge Hallyn
2011-08-12 20:42 ` Daniel Lezcano
2011-08-12 21:13 ` Serge Hallyn
2011-08-13 0:19 ` Matt Helsley
2011-08-13 14:41 ` Daniel Lezcano
2011-08-14 16:01 ` Oleg Nesterov
2011-08-14 16:17 ` [PATCH 0/2] Send a SIGCHLD to the init's pid namespace parent when reboot Oleg Nesterov
2011-08-14 21:36 ` Serge E. Hallyn
2011-08-15 14:47 ` Oleg Nesterov
2011-08-15 17:39 ` Serge E. Hallyn
2011-08-15 17:50 ` Daniel Lezcano
2011-08-18 23:46 ` Daniel Lezcano
2011-08-19 15:24 ` Oleg Nesterov
2011-08-22 12:28 ` Daniel Lezcano
2011-08-22 15:44 ` Oleg Nesterov
2011-08-22 16:31 ` Bruno Prémont
2011-08-22 17:39 ` Oleg Nesterov
2011-08-22 19:17 ` Bruno Prémont
2011-08-23 13:33 ` Oleg Nesterov
2011-08-23 14:09 ` Greg Kurz
2011-08-23 14:29 ` Oleg Nesterov
2011-08-24 19:44 ` Bruno Prémont
2011-08-25 15:37 ` Oleg Nesterov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1313094241-3674-1-git-send-email-daniel.lezcano@free.fr \
--to=daniel.lezcano@free.fr \
--cc=akpm@linux-foundation.org \
--cc=bonbons@linux-vserver.org \
--cc=containers@lists.linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=oleg@tv-sign.ru \
--cc=serge@hallyn.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®