From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932662AbcGHSae (ORCPT ); Fri, 8 Jul 2016 14:30:34 -0400 Received: from mail-db5eur01on0090.outbound.protection.outlook.com ([104.47.2.90]:54634 "EHLO EUR01-DB5-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752461AbcGHSa2 (ORCPT ); Fri, 8 Jul 2016 14:30:28 -0400 Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=avagin@virtuozzo.com; Date: Thu, 7 Jul 2016 18:57:59 -0700 From: Andrew Vagin To: "Eric W. Biederman" CC: "Serge E. Hallyn" , Linux API , Containers , lkml , , "Michael Kerrisk (man-pages)" Subject: Re: [CRIU] Introspecting userns relationships to other namespaces? Message-ID: <20160708015758.GA10512@outlook.office365.com> References: <87r3b7pxja.fsf@x220.int.ebiederm.org> <20160706141348.GB20728@mail.hallyn.com> <871t36kbvq.fsf@x220.int.ebiederm.org> MIME-Version: 1.0 Content-Type: text/plain; charset="koi8-r" Content-Disposition: inline In-Reply-To: <871t36kbvq.fsf@x220.int.ebiederm.org> User-Agent: Mutt/1.6.1 (2016-04-27) X-Originating-IP: [67.183.159.197] X-ClientProxiedBy: BY1PR18CA0010.namprd18.prod.outlook.com (10.162.126.20) To HE1PR0801MB1434.eurprd08.prod.outlook.com (10.167.190.18) X-MS-Office365-Filtering-Correlation-Id: 0bc0fc80-a88d-41bb-ae6e-08d3a6d354cc X-Microsoft-Exchange-Diagnostics: 1;HE1PR0801MB1434;2:V47oATUXBfoY3cXLEb/rRPU2jB/9yTqwYNGEQXu1YQ4S76dMAfdDvHEOgVjUBuKL95kPLGb7ComdWT2VrHYM32s0WvCGDdNzJCnbhLLXbrKyde+SNxJQtEGrafyKO22RLxF5Xnu+VrHHaspLsDMbPXIejHGstHVQVdjvP1p0kGqjSghgiRmGRFXrRxRNRFxQ;3:Hl25yJyMac6FJrXpgha5M2GbMYZ81C1O8hRGv6KyDAmblv43DRwUoD96Q9aRseGL9CBmVxQkhVic9Jfchd3mh7kZNmI5os5cAIl+VyKZkJfssHjZ+QMLu6ENzLK5u2kF X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:HE1PR0801MB1434; X-Microsoft-Exchange-Diagnostics: 1;HE1PR0801MB1434;25:wCMEi8MMLeQHY+l2KgtDCD30lWBzs5bLENH3Qf34zAEIpvH19PDDP6+Sg51l4bAhN5yXor0T21pV7e1tdDu7W4X9+dUZ4HhgtM5Om/EDuidO7MiwYSQ96c4bjoFgPmghCygNAJMA39KF/XL+yvarWGY3pR6/5VrDg5SF/SZAELHq/Z+V8S7J8457mghMd1ChH6QeYsh1pCuIdktD1oTLBlGbRp4unl6945+el9kP0qsCLe1IresrF+Rp2rU1IQM8CK+4NBLKy7oMtIpGnp9cwcvVb+4kSKNlyGCy44YUtDAA8o/JZ8VvJbZfsBkh5YCoYpb+RvHcNJxtBbQvBYTHu27yRgrtqXRUgCjweGJLBp1NgmpprG9PTFYU64PcFjcCryB5l3PpzLv1NwMshRil8IMZDYqXWuezxdaiUEYgULoYhp2pxpmrDjDSB+dSr4Jq0AWoPbDyji4kHyJkcpIt4z/YN11f3sxIZlaFpk8xT7MPgKhYKZy8VkiR25ey8NwFZcTb8ZKg/qVDUWSUR/cxeOM0pgBSWEh56SvvuijSp2SKFAhLqRNAbtp1kDdGIQtlfUIRPlTxmrQ1UEYlg84E+rEvJtx3Zp8uLrsEzS5JHyG80rL7RHwZ1mbwkuJRbeltfC08+yQMNeBlWtDCmo4KDgFl6gxUGoP9S5/ApnjCUpgtIxK6dOOmRrnuJHit5TA5W6KyXHiMcWlxryy2xUWGW61NDBAoSG3JjffV2mtptoHp3uzA/70wwZ9Qoya59BcBeLqcgc0BL/qI4t1LJ1BEA3iITH4XZyC/oDMebLPY0OvF6KK9BmVqWF5ZYsBBa7iTyVtv7ybGC2TCQYyaLOMNfS3CBv8HMqO7mdSonxWSe68= X-Microsoft-Exchange-Diagnostics: 1;HE1PR0801MB1434;31:rnzZL4I51KIFJjpnxFmv6zBg0aMqkWy3PNBdd2xyBhDAovpCH5KrEW/Rs7fYRpaqXxtURC2DW7/jcQd50hwKEdc/ya6WI8ZwkSUr9JBw/ivaow5dhItaThVFANLscj3l/tuq2lTELHXb5e8Qxn3kvgL91yA5y4ucWFYaguMEawQfJdXSVDnmStXIYGltlSt26rmMK1it83In7a6NC5Yd6Q==;4:wQtvdwZkDyp6au6kASVn3Okv2NA0L16vTs3q8IkXnbVdStR9G4KVm2S5q9M6YRP9TfbZBk4SIZn6VQ36MW1g5aDN/Skc9/hetpn+1fTbi9fw3b9Zabz4h2VQQDOgPvGEb51fWIb555iem3SN2lgKNR4WH1rBzSXD+O368KSPxNC4znq3OK0kPZwZsTpS5ay3+1c2ihnYWANmPwf0uKG8J6Nrs2qW+DVZVUl5vBQL4x994X0BpCQBlEQy4tYE9NSja9AgtI/7RTRwKFVXYg462bBZ+1pny2MuITtUZj6Xlpr3TXqPnY8QRwzHP43YbJRQzPrx0El/kgJwBfZGtTOP5HJSDaycjhXOCjeM8uiqjUtJB9r/OL2OU1hnREDDDSZ/3s41sfqSDJ9cuZ+u6oKWg7c3vb2MCr0GluhT2clVFp0= X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:; X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(6040130)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(6041072)(6043046);SRVR:HE1PR0801MB1434;BCL:0;PCL:0;RULEID:;SRVR:HE1PR0801MB1434; X-Forefront-PRVS: 0997523C40 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10019020)(4630300001)(6009001)(7916002)(24454002)(53234004)(189002)(199003)(50986999)(47776003)(42186005)(54356999)(93886004)(76176999)(66066001)(97736004)(3846002)(92566002)(6116002)(4001350100001)(33656002)(101416001)(305945005)(7736002)(53416004)(2906002)(4326007)(586003)(50466002)(189998001)(110136002)(23686003)(7846002)(106356001)(1076002)(105586002)(81166006)(81156014)(86362001)(9686002)(8676002)(19580395003)(69596002)(19580405001)(83506001)(77096005)(15975445007)(2950100001)(68736007)(18370500001)(26326002);DIR:OUT;SFP:1102;SCL:1;SRVR:HE1PR0801MB1434;H:outlook.office365.com;FPR:;SPF:None;PTR:InfoNoRecords;MX:1;A:1;LANG:en; X-Microsoft-Exchange-Diagnostics: =?koi8-r?Q?1;HE1PR0801MB1434;23:p3Hcb27X60K8/jS4NJ3HEtooFpI7+Ny3xNoJ2UT+3?= =?koi8-r?Q?HVfsCZW0diRXLwlXWI/U3u3mSewSp7BgyPYbOR/BXDJ2xG1Zw5+IK/bvjek7Ic?= =?koi8-r?Q?duq0uVmFQ4CkOHgsXL+SmQmy2cMPNAP1Mlz1q6BHKQiQBwjcgVh6jj1SUYJ9F0?= =?koi8-r?Q?xOlgauJQ5gvkK0Bkjc4CboknpWBJGUxcCC9xRP89ZtbOl2yAEddsesawkqphI2?= =?koi8-r?Q?04cUNvIJ3s+j+qhcPNVe1ne97QehVWlyuw43U40nAPTfGVUO3xaoWOvsw9E0Z/?= =?koi8-r?Q?YeROC/iCsABDdlMTq6YQOpPWJhJ4P+IitJPAjSqbeCuuRQJFpxvJHexqrbL7oX?= =?koi8-r?Q?akb1jZRrqJEUcaAkMAn9phNZk70J3Vb2+BPY4C3l0EDZa75oEgCAtwMB1M1yaA?= =?koi8-r?Q?kqWFwytgEKLMn7KRQ6D3lU2wPuE1uw+N8LmuhH0L4NgjvYVQILwROSbYhXu7HQ?= =?koi8-r?Q?Z7pLt2jqx03UqGYAV4zaLUXphO3GywedQxj2BfYLgMUX7q1JgNkJvGBozHTn/1?= =?koi8-r?Q?h1x6w+yLTHMAP5o3e4M/wIn/DzRTsgb2LgS0HOXkvDqf6kbdm3q4j87bA5Q5ld?= =?koi8-r?Q?FIay+nDXbES2zPFsmTKvVb1XTitiL5C9CWQ6uHOccJA/PJ8Z+P4Gf8PTUQG3+i?= =?koi8-r?Q?67nd2YpDnKGplqMTM5XZsdWS/EgwpYSRSCTo7+yRdYIBpOIwrhvlrV1MgwtLM+?= =?koi8-r?Q?Rd9qViYI70Bk/eynQiQaQmsBbJDGaGyPtmtasix+Sy5+5vWBBIELS9PNQyi6t7?= =?koi8-r?Q?0kT/OiFitxCthvpaaPG7lSTU/wPf5pdrZj42qoZJEZxnFqpbRlC0DdNSennENY?= =?koi8-r?Q?k1MhAmZZWCZSrrT4KvN7BDWCHL05LLJZ9KALgsGUxaCnyximFJS9VE3c/KL/0Q?= =?koi8-r?Q?Ro9p9PyQiC+mBk65fGErS7qD7xJLTp2qSwDOB9hzxjE6eSwMPa5mv2OBk/8FTK?= =?koi8-r?Q?9sbXKgwIBcg4/i6V0dMKadwJv6YN4o1zXFYOXzyV3jnmMbcUVZZ3ArUnrZFNJx?= =?koi8-r?Q?5vf6fmCB41qeVdiNbGcuglYinZquX9C9PBr6zY65Ljgrxvh+hy6Fq/kUHRy1+B?= =?koi8-r?Q?Cmv6J9kMeXrVOssj134qdqeU743kFVgjo3TOqEFUksqenC61Kz5UCatG3zNm8y?= =?koi8-r?Q?Q8lo7wL37sQWhQV6eLPpu/Jlu0z96YX40EGVyYnjRCDssq9uMpWdKYKHnr4meR?= =?koi8-r?Q?8hKA/dcnDm+Rtnbs1kk613RfebKP3juoIf9/7su0=3D?= X-Microsoft-Exchange-Diagnostics: 1;HE1PR0801MB1434;6:ImwLSTfgCAzBodN6nuVa0WSTjRNr5tw3/Kr3/N3y+CnqI9AvoO5HpsR+NwG+0JokaiorNvhugCGJjYgPZj//PuyuXwHnHpO87yKTaRNH/p6ETBKAb+a7NTBx9IsjFTvBLYx/6teSOJIdhSqLSV04Ia4+mCSi9jxznImUp9hS0rKQETOOLrl0C7BtkwVVpGcTgJJ50LGhOPLdREx18wT/y6Bpjo/4DrI8nXak2JfHtf4lrBVlhNTCe+kA/WWyjnNzkgbXykJDzyAQ9vi7AsFXfKBMkvM1giHvOYuzXgFohqZ9jRJkVhSTz4a06q3EOlUa;5:lhjCUVfR9cWHqgX7s+Vsqa/ETAxmy/4DnWQbrLIYy5oDzs8ReK/TZXa6By+f9VTVSwOo1NGJISS8vrMx/Lu+y9rCrBOiQXDJpLsLbuw4PMgJ7+k3pgtc8aLm/7hHKPwUHbCT0G7AGzdBEDG1Pt4ZZQ==;24:c7pch4ruF+RpP+htg5fsCt+oIPC0pgM+sSXSEtqU7qAi5+w7SS/Dkfet+7raXWGV+ytPUi/S5ERpYYqSpEk5gWFM9YP46qvT4cTkvKUpkJw=;7:jQUsnqa4pRYY6e8x0a6T77eKnqGD9u7FgWalkFxPePb1TTTWwuv6SmmjQqryvXFq9Ke65AMNMGpLQUT0gHdPb19XxnutyTIzl2VKApNFXmWgxtp7VpmapQ6GyTk/Adnd9azWifKT4W5aJZwPZdtnCxPnUGPDWEXfYmoJWgAm5hFYyeygQpRUbcbE6yF5W+NcXrcMk6MtuOHI48PlqMFYISpHBC9TRES2sUETxgHIWQKlSqlf1FnX5+yGNmfV35ay SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;HE1PR0801MB1434;20:9c2VyiMaXzJvQJcpr61z5h7SDaKLPFMGdgxw0Jk49CDtyVZYsaJz4Ltt3ppvtLdLTrIYXg/yyZsFt8XKvS1m7tZZ7NKx6H4ELcxIarAZrh42NQ8uhTKmau5f7ej/SbgAaztpVh+G3Q+MVZNCiwFS+sB4Vav2U+dAfIaU405nC7E= X-OriginatorOrg: virtuozzo.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 08 Jul 2016 01:58:15.4561 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0801MB1434 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Jul 06, 2016 at 10:46:33AM -0500, Eric W. Biederman wrote: > "Serge E. Hallyn" writes: > > > On Wed, Jul 06, 2016 at 10:41:48AM +0200, Michael Kerrisk (man-pages) wrote: > >> [Rats! Doing now what I should have down to start with. Looping some > >> lists and CRIU and other possibly relevant people into this > >> conversation] > >> > >> Hi Eric, > >> > >> On 5 July 2016 at 23:47, Eric W. Biederman wrote: > >> > "Michael Kerrisk (man-pages)" writes: > >> > > >> >> Hi Eric, > >> >> > >> >> I have a question. Is there any way currently to discover which > >> >> user namespace a particular nonuser namespace is governed by? > >> >> Maybe I am missing something, but there does not seem to be a > >> >> way to do this. Also, can one discover which userns is the > >> >> parent of a given userns? Again, I can't see a way to do this. > >> >> > >> >> The point here is introspecting so that a process might determine > >> >> what its capabilities are when operating on some resource governed > >> >> by a (nonuser) namespace. > >> > > >> > To the best of my knowledge that there is not an interface to get that > >> > information. It would be good to have such an interface for no other > >> > reason than the CRIU folks are going to need it at some point. I am a > >> > bit surprised they have not complained yet. > > > > I don't think they need it. They do in fact have what they need. Assume > > you have tasks T1, T2, T1_1 and T2_1; T1 and T2 are in init_user_ns; T1 > > spawned T1_1 in a new userns; T2 spawned T2_1 which setns()d to T1_1's ns. > > There's some {handwave} uid mapping, does not matter. > > > > At restart, it doesn't matter which task originally created the new userns. > > criu knows T1_1 and T2_1 are in the same userns; it creates the userns, sets > > up the mapping, and T1_1 and T2_1 setns() to it. > > Given that the simple cases are so easy it probably doesn't matter in > that sense. > > However we now have the case where user namespaces own pid namespaces, > and uts namespaces, and network namespaces, and ipc namespaces, and > filesystems. Throw in some mount propagation and use of setns and > things could get confusing. It is something that will need to be > figured out if CRIU is going to properly checkpoint containers > containing containers containing containers containing containers. It isn't a joke:). We have a few requests to support CR of containers with Docker containers inside. And we are going to start this task in a near future, so we would like to have interface to get dependencies between namespaces too. BTW: CRIU already supports nested mount namespaces, because systemd creates them for services. > > Did I mention I like recursion? > > >> > That said in a normal use scenario I don't think that information is > >> > needed. > >> > > >> > Do you have a particular use case besides checkpoint/restart where this > >> > is useful? That might help in coming up with a good userspace interface > >> > for this information. > >> > >> So, I spend a moderate amount of time working with people to introduce > >> them to the namespaces infrastructure, and one topic that comes up now > >> and this introspection/visualization tools. For example, > >> nowadays--thanks to the (bizarrely misnamed) NStgid and NSpid fields > >> in /proc/PID--it's possible to (and someone I was working with did) > >> write tools that introspect the PID namespace hierarchy to show all of > >> process's and their PIDs in the various namespace instance. It's a > >> natural enough thing to want to do, when confronted with the > >> complexity of the namespaces. > >> > >> Someone else then asked me a question that led me to wonder about > >> generally introspecting on the parental relationships between user > >> namespaces and the association of other namespaces types with user > >> namespaces. One use would be visualization, in order to understand the > >> running system. Another would be to answer the question I already > >> mentioned: what capability does process X have to perform operations > >> on a resource governed by namespace Y? > > > > I agree they'll probably want it, but if we want for a real need and > > use case we can do a better job of providing what's needed. > > That two which is why I mentioned CRIU. But yeah it will probably take > a little while to get there. > > Eric > _______________________________________________ > CRIU mailing list > CRIU@openvz.org > https://lists.openvz.org/mailman/listinfo/criu