From: Oleg Nesterov <oleg@tv-sign.ru>
To: Roland McGrath <roland@redhat.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Davide Libenzi <davidel@xmailserver.org>,
"Eric W. Biederman" <ebiederm@xmission.com>,
Ingo Molnar <mingo@elte.hu>,
Laurent Riffard <laurent.riffard@free.fr>,
Pavel Emelyanov <xemul@openvz.org>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 4/5] don't panic if /sbin/init exits or killed
Date: Mon, 17 Mar 2008 02:03:46 +0300 [thread overview]
Message-ID: <20080316230346.GA379@tv-sign.ru> (raw)
In-Reply-To: <20080316221938.D217026F995@magilla.localdomain>
On 03/16, Roland McGrath wrote:
>
(re-ordered)
> Have you tested how recoverable it really is? I wonder what happens
> with init having exited when things get reparented to it. Don't the
> zombies just pile up?
Yes sure, we leak the re-parented zombies, and nobody can take care of
/etc/inittab. As expected.
But otherwise the system runs fine.
> BUG() does not seem right to me. This does not diagnose any kernel bug.
> The kernel source location and backtrace are not useful. In fact, they
> are likely to mislead the user into reporting the bug to the wrong place
> (because it will look like a kernel bug).
But panic() isn't better? It doesn't provide any useful info.
> I gather your motivation is to get something "recoverable" rather than
> always rebooting. This might be useful for developers like you and me.
> I suspect that conservative administrators of production systems prefer
> the current behavior. If the boot init dies, that is reasonably likely
> to be a "catastrophic" failure of the system as a whole as far as the
> proprietor of a production system is concerned. That is, the system may
> no longer behave as expected in ways essential for its normal operation.
> If it sticks around in that condition, appearing to be available but not
> doing everything it should, that is usually worse than a quick and
> orderly crash (which the installation's procedures and monitoring
> infrastructure are often prepared to handle).
Well, I think the generic "if we have a chance to survive, we should try
to survive" rule is good.
If the boot init dies, at least the admin has a chance to figure out what
has happened, and -o remount,ro /.
Every BUG/BUG_ON in fact means the system is not useable, but still it does
not panic(), but tries to proceed.
In short, I can't see why panic() is better. Except we have panic_timeout,
but we can take it into account if init exits.
> panic is a bit extreme for the situation, where we have no reason yet to
> think kernel data structures are inconsistent. A sync+reboot or sync+crash
> without bust_spinlocks et al might be better.
>
> For letting init die and calling it recoverable for hacking purposes, a
> sysctl to disable the panic/crash makes sense. But I don't think we
> should change the default setting.
OK, I won't argue (not that I agree ;).
Oleg.
next prev parent reply other threads:[~2008-03-16 23:04 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-16 15:54 Oleg Nesterov
2008-03-16 22:19 ` Roland McGrath
2008-03-16 22:54 ` Krzysztof Halasa
2008-03-16 23:03 ` Oleg Nesterov [this message]
2008-03-16 22:55 ` Alan Cox
2008-03-16 23:32 ` Roland McGrath
2008-03-16 23:49 ` Oleg Nesterov
2008-03-16 23:59 ` Roland McGrath
2008-03-17 0:05 ` Oleg Nesterov
[not found] ` <1205850955.6466.61.camel@moss-spartans.epoch.ncsc.mil>
2008-03-18 15:41 ` Oleg Nesterov
2008-03-29 5:47 ` H. Peter Anvin
2008-03-29 10:51 ` Oleg Nesterov
[not found] <a83rs-N7-9@gated-at.bofh.it>
[not found] ` <a89wR-8k4-3@gated-at.bofh.it>
[not found] ` <a8a9t-1pV-21@gated-at.bofh.it>
[not found] ` <a8aCw-2hv-31@gated-at.bofh.it>
2008-03-18 17:41 ` Bodo Eggert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080316230346.GA379@tv-sign.ru \
--to=oleg@tv-sign.ru \
--cc=akpm@linux-foundation.org \
--cc=davidel@xmailserver.org \
--cc=ebiederm@xmission.com \
--cc=laurent.riffard@free.fr \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=roland@redhat.com \
--cc=xemul@openvz.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®