From: Michael J Coss <michael.coss@alcatel-lucent.com>
To: Greg KH <gregkh@linuxfoundation.org>
Cc: davem@davemloft.net, linux-kernel@vger.kernel.org,
containers@lists.linuxcontainers.org, serge.hallyn@ubuntu.com,
stgraber@ubuntu.com
Subject: Re: [PATCH 0/3] kobject: support namespace aware udev
Date: Wed, 9 Sep 2015 15:05:29 -0400 [thread overview]
Message-ID: <55F082F9.7050305@alcatel-lucent.com> (raw)
In-Reply-To: <20150909035400.GA5153@kroah.com>
On 9/8/2015 11:54 PM, Greg KH wrote:
> On Tue, Sep 08, 2015 at 10:10:27PM -0400, Michael J. Coss wrote:
>> Currently when a uevent occurs, the event is replicated and sent to every
>> listener on the kernel netlink socket, ignoring network namespaces boundaries,
>> forwarding events to every listener in every network namespace.
>>
>> With the expanded use of containers, it would be useful to be able to
>> regulate this flow of events to specific containers. By restricting
>> the events to only the host network namespace, it allows for a userspace
>> program to provide a system wide policy on which events are routed where.
> Interesting, but why do you need a container to get a uevent at all?
> What uevents do a container care about?
>
> thanks,
>
> greg k-h
>
In our use case, we run a full desktop inside the container, including
X. We run the Xserver in headless mode, and forward a uevent to the
container to allow binding/unbinding of remote keyboard, mice, and
displays. So I want the add/del keyboard events, add/del mouse events,
and add/del display events. This is just one use case, I could image
others. The bottom line is that the current behavior is to broadcast to
everyone all uevents, and I don't see that as correct as it crosses the
network namespace boundaries. It seems to me that you would want to
provide controls as to where you want to forward those uevents, and
that is not a policy that I believe should be in the kernel but rather
in user space.
--
---Michael J Coss
next prev parent reply other threads:[~2015-09-09 19:05 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-09-09 2:10 Michael J. Coss
2015-09-09 2:10 ` [PATCH 1/3] lib/kobject_uevent.c: disable broadcast of uevents to other namespaces Michael J. Coss
2015-09-11 0:36 ` Eric W. Biederman
2015-09-11 18:21 ` Michael J Coss
2015-09-09 2:10 ` [PATCH 2/3] lib/kobject_uevent.c: add uevent forwarding function Michael J. Coss
2015-09-09 3:55 ` Greg KH
2015-09-09 19:24 ` Michael J Coss
2015-09-09 20:11 ` Greg KH
2015-09-10 5:43 ` Amir Goldstein
2015-09-10 5:58 ` Greg KH
2015-09-11 0:54 ` Eric W. Biederman
2015-09-11 18:43 ` [COMMERCIAL] " Michael J Coss
2015-09-09 2:10 ` [PATCH 3/3] net/udevns: Netlink module to forward uevent to containers Michael J. Coss
2015-09-11 1:05 ` Eric W. Biederman
2015-09-11 19:01 ` Michael J Coss
2015-09-09 3:54 ` [PATCH 0/3] kobject: support namespace aware udev Greg KH
2015-09-09 19:05 ` Michael J Coss [this message]
2015-09-09 20:09 ` Greg KH
2015-09-09 20:16 ` Michael J Coss
2015-09-09 20:28 ` Greg KH
2015-09-09 20:55 ` [COMMERCIAL] " Michael J Coss
2015-09-10 5:21 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55F082F9.7050305@alcatel-lucent.com \
--to=michael.coss@alcatel-lucent.com \
--cc=containers@lists.linuxcontainers.org \
--cc=davem@davemloft.net \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=serge.hallyn@ubuntu.com \
--cc=stgraber@ubuntu.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome