From: Shuah Khan <skhan@linuxfoundation.org>
To: "Michal Koutný" <mkoutny@suse.com>,
"Eric Biederman" <ebiederm@xmission.com>,
"Alexey Gladkov" <legion@kernel.org>
Cc: Kees Cook <keescook@chromium.org>, Shuah Khan <shuah@kernel.org>,
Christian Brauner <brauner@kernel.org>,
Solar Designer <solar@openwall.com>,
Ran Xiaokai <ran.xiaokai@zte.com.cn>,
linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org,
Linux Containers <containers@lists.linux-foundation.org>,
Shuah Khan <skhan@linuxfoundation.org>
Subject: Re: [RFC PATCH 5/6] selftests: Challenge RLIMIT_NPROC in user namespaces
Date: Wed, 9 Feb 2022 18:22:18 -0700 [thread overview]
Message-ID: <f0585ae4-5642-361f-11d6-9399bd9cc550@linuxfoundation.org> (raw)
In-Reply-To: <20220207121800.5079-6-mkoutny@suse.com>
On 2/7/22 5:17 AM, Michal Koutný wrote:
> The services are started in descendant user namepaces, each of them
> should honor the RLIMIT_NPROC that's passed during user namespace
> creation.
>
> main [user_ns_0]
> ` service [user_ns_1]
> ` worker 1
> ` worker 2
> ...
> ` worker k
> ...
> ` service [user_ns_n]
> ` worker 1
> ` worker 2
> ...
> ` worker k
>
> Test uses explicit synchronization, to make sure original parent's limit
> does not interfere with descendants.
>
Thank you for updating the test with the kernel updates. Please see
comments below. A bit of a concern with how long this test will run.
Did you time it?
> Signed-off-by: Michal Koutný <mkoutny@suse.com>
> ---
> .../selftests/rlimits/rlimits-per-userns.c | 154 ++++++++++++++----
> 1 file changed, 125 insertions(+), 29 deletions(-)
>
> diff --git a/tools/testing/selftests/rlimits/rlimits-per-userns.c b/tools/testing/selftests/rlimits/rlimits-per-userns.c
> index 26dc949e93ea..54c1b345e42b 100644
> --- a/tools/testing/selftests/rlimits/rlimits-per-userns.c
> +++ b/tools/testing/selftests/rlimits/rlimits-per-userns.c
> @@ -9,7 +9,9 @@
> #include <sys/resource.h>
> #include <sys/prctl.h>
> #include <sys/stat.h>
> +#include <sys/socket.h>
>
> +#include <assert.h>
> #include <unistd.h>
> #include <stdlib.h>
> #include <stdio.h>
> @@ -21,38 +23,74 @@
> #include <errno.h>
> #include <err.h>
>
> -#define NR_CHILDS 2
> +#define THE_LIMIT 4
> +#define NR_CHILDREN 5
> +
> +static_assert(NR_CHILDREN >= THE_LIMIT-1, "Need slots for limit-1 children.");
>
> static char *service_prog;
> static uid_t user = 60000;
> static uid_t group = 60000;
> +static struct rlimit saved_limit;
> +
> +/* Two uses: main and service */
> +static pid_t child[NR_CHILDREN];
> +static pid_t pid;
>
> static void setrlimit_nproc(rlim_t n)
> {
> - pid_t pid = getpid();
> struct rlimit limit = {
> .rlim_cur = n,
> .rlim_max = n
> };
> -
> - warnx("(pid=%d): Setting RLIMIT_NPROC=%ld", pid, n);
> + if (getrlimit(RLIMIT_NPROC, &saved_limit) < 0)
> + err(EXIT_FAILURE, "(pid=%d): getrlimit(RLIMIT_NPROC)", pid);
>
> if (setrlimit(RLIMIT_NPROC, &limit) < 0)
> err(EXIT_FAILURE, "(pid=%d): setrlimit(RLIMIT_NPROC)", pid);
> +
> + warnx("(pid=%d): Set RLIMIT_NPROC=%ld", pid, n);
> +}
> +
> +static void restore_rlimit_nproc(void)
> +{
> + if (setrlimit(RLIMIT_NPROC, &saved_limit) < 0)
> + err(EXIT_FAILURE, "(pid=%d): setrlimit(RLIMIT_NPROC, saved)", pid);
> + warnx("(pid=%d) Restored RLIMIT_NPROC", pid);
> }
>
> -static pid_t fork_child(void)
> +enum msg_sync {
> + UNSHARE,
> + RLIMIT_RESTORE,
> +};
> +
> +static void sync_notify(int fd, enum msg_sync m)
> {
> - pid_t pid = fork();
> + char tmp = m;
> +
> + if (write(fd, &tmp, 1) < 0)
> + warnx("(pid=%d): failed sync-write", pid);
> +}
>
> - if (pid < 0)
> +static void sync_wait(int fd, enum msg_sync m)
> +{
> + char tmp;
> +
> + if (read(fd, &tmp, 1) < 0)
> + warnx("(pid=%d): failed sync-read", pid);
> +}
> +
> +static pid_t fork_child(int control_fd)
> +{
> + pid_t new_pid = fork();
> +
> + if (new_pid < 0)
> err(EXIT_FAILURE, "fork");
>
> - if (pid > 0)
> - return pid;
> + if (new_pid > 0)
> + return new_pid;
>
> pid = getpid();
> -
> warnx("(pid=%d): New process starting ...", pid);
>
> if (prctl(PR_SET_PDEATHSIG, SIGKILL) < 0)
> @@ -73,6 +111,9 @@ static pid_t fork_child(void)
> if (unshare(CLONE_NEWUSER) < 0)
> err(EXIT_FAILURE, "unshare(CLONE_NEWUSER)");
>
> + sync_notify(control_fd, UNSHARE);
> + sync_wait(control_fd, RLIMIT_RESTORE);
> +
> char *const argv[] = { "service", NULL };
> char *const envp[] = { "I_AM_SERVICE=1", NULL };
>
> @@ -82,37 +123,92 @@ static pid_t fork_child(void)
> err(EXIT_FAILURE, "(pid=%d): execve", pid);
> }
>
> +static void run_service(void)
> +{
> + size_t i;
> + int ret = EXIT_SUCCESS;
> + struct rlimit limit;
> + char user_ns[PATH_MAX];
> +
> + if (getrlimit(RLIMIT_NPROC, &limit) < 0)
> + err(EXIT_FAILURE, "(pid=%d) failed getrlimit", pid);
> + if (readlink("/proc/self/ns/user", user_ns, PATH_MAX) < 0)
> + err(EXIT_FAILURE, "(pid=%d) failed readlink", pid);
> +
> + warnx("(pid=%d) Service instance attempts %i children, limit %lu:%lu, ns=%s",
> + pid, THE_LIMIT, limit.rlim_cur, limit.rlim_max, user_ns);
> +
> + /* test rlimit inside the service, effectively THE_LIMIT-1 becaue of service itself */
> + for (i = 0; i < THE_LIMIT; i++) {
> + child[i] = fork();
> + if (child[i] == 0) {
> + /* service child */
> + pause();
> + exit(EXIT_SUCCESS);
> + }
> + if (child[i] < 0) {
> + warnx("(pid=%d) service fork %lu failed, errno = %i", pid, i+1, errno);
> + if (!(i == THE_LIMIT-1 && errno == EAGAIN))
> + ret = EXIT_FAILURE;
> + } else if (i == THE_LIMIT-1) {
> + warnx("(pid=%d) RLIMIT_NPROC not honored", pid);
> + ret = EXIT_FAILURE;
> + }
> + }
> +
> + /* service cleanup */
> + for (i = 0; i < THE_LIMIT; i++)
> + if (child[i] > 0)
> + kill(child[i], SIGUSR1);
> +
> + for (i = 0; i < THE_LIMIT; i++)
> + if (child[i] > 0)
> + waitpid(child[i], NULL, WNOHANG);
> +
> + if (ret)
> + exit(ret);
> + pause();
> +}
> +
> int main(int argc, char **argv)
> {
> size_t i;
> - pid_t child[NR_CHILDS];
> - int wstatus[NR_CHILDS];
> - int childs = NR_CHILDS;
> - pid_t pid;
> + int control_fd[NR_CHILDREN];
> + int wstatus[NR_CHILDREN];
> + int children = NR_CHILDREN;
> + int sockets[2];
> +
> + pid = getpid();
>
> if (getenv("I_AM_SERVICE")) {
> - pause();
> - exit(EXIT_SUCCESS);
> + run_service();
> + exit(EXIT_FAILURE);
Why is this a failure unconditionally?
> }
>
> service_prog = argv[0];
> - pid = getpid();
>
> warnx("(pid=%d) Starting testcase", pid);
>
> - /*
> - * This rlimit is not a problem for root because it can be exceeded.
> - */
> - setrlimit_nproc(1);
> -
> - for (i = 0; i < NR_CHILDS; i++) {
> - child[i] = fork_child();
> + setrlimit_nproc(THE_LIMIT);
> + for (i = 0; i < NR_CHILDREN; i++) {
> + if (socketpair(AF_UNIX, SOCK_DGRAM | SOCK_CLOEXEC, 0, sockets) < 0)
> + err(EXIT_FAILURE, "(pid=%d) socketpair failed", pid);
> + control_fd[i] = sockets[0];
> + child[i] = fork_child(sockets[1]);
> wstatus[i] = 0;
> + }
> +
> + for (i = 0; i < NR_CHILDREN; i++)
> + sync_wait(control_fd[i], UNSHARE);
> + restore_rlimit_nproc();
> +
> + for (i = 0; i < NR_CHILDREN; i++) {
> + sync_notify(control_fd[i], RLIMIT_RESTORE);
> usleep(250000);
How long does this test now run for with this loop?
> }
>
> while (1) {
> - for (i = 0; i < NR_CHILDS; i++) {
> + for (i = 0; i < NR_CHILDREN; i++) {
> if (child[i] <= 0)
> continue;
>
> @@ -126,22 +222,22 @@ int main(int argc, char **argv)
> warn("(pid=%d): waitpid(%d)", pid, child[i]);
>
> child[i] *= -1;
> - childs -= 1;
> + children -= 1;
> }
>
> - if (!childs)
> + if (!children)
> break;
>
> usleep(250000);
>
> - for (i = 0; i < NR_CHILDS; i++) {
> + for (i = 0; i < NR_CHILDREN; i++) {
> if (child[i] <= 0)
> continue;
> kill(child[i], SIGUSR1);
> }
> }
>
> - for (i = 0; i < NR_CHILDS; i++) {
> + for (i = 0; i < NR_CHILDREN; i++) {
> if (WIFEXITED(wstatus[i]))
> warnx("(pid=%d): pid %d exited, status=%d",
> pid, -child[i], WEXITSTATUS(wstatus[i]));
>
Please a add few more comments in the code path.
thanks,
-- Shuah
next prev parent reply other threads:[~2022-02-10 1:22 UTC|newest]
Thread overview: 78+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-02-07 12:17 [RFC PATCH 0/6] RLIMIT_NPROC in ucounts fixups Michal Koutný
2022-02-07 12:17 ` [RFC PATCH 1/6] set_user: Perform RLIMIT_NPROC capability check against new user credentials Michal Koutný
2022-02-10 1:14 ` Solar Designer
2022-02-10 1:57 ` Eric W. Biederman
2022-02-11 20:32 ` Eric W. Biederman
2022-02-12 22:14 ` Solar Designer
2022-02-15 11:55 ` Michal Koutný
2022-02-07 12:17 ` [RFC PATCH 2/6] set*uid: Check RLIMIT_PROC against new credentials Michal Koutný
2022-02-07 12:17 ` [RFC PATCH 3/6] cred: Count tasks by their real uid into RLIMIT_NPROC Michal Koutný
2022-02-07 12:17 ` [RFC PATCH 4/6] ucounts: Allow root to override RLIMIT_NPROC Michal Koutný
2022-02-10 0:21 ` Eric W. Biederman
2022-02-07 12:17 ` [RFC PATCH 5/6] selftests: Challenge RLIMIT_NPROC in user namespaces Michal Koutný
2022-02-10 1:22 ` Shuah Khan [this message]
2022-02-15 9:45 ` Michal Koutný
2022-02-07 12:18 ` [RFC PATCH 6/6] selftests: Test RLIMIT_NPROC in clone-created " Michal Koutný
2022-02-10 1:25 ` Shuah Khan
2022-02-15 9:34 ` Michal Koutný
2022-02-08 13:54 ` [RFC PATCH 0/6] RLIMIT_NPROC in ucounts fixups Eric W. Biederman
2022-02-11 2:01 ` [PATCH 0/8] ucounts: RLIMIT_NPROC fixes Eric W. Biederman
2022-02-11 2:13 ` [PATCH 1/8] ucounts: Fix RLIMIT_NPROC regression Eric W. Biederman
2022-02-14 18:37 ` Michal Koutný
2022-02-16 15:22 ` Eric W. Biederman
2022-02-11 2:13 ` [PATCH 2/8] ucounts: Fix set_cred_ucounts Eric W. Biederman
2022-02-15 11:10 ` Michal Koutný
2022-02-11 2:13 ` [PATCH 3/8] ucounts: Fix and simplify RLIMIT_NPROC handling during setuid()+execve Eric W. Biederman
2022-02-12 23:17 ` Solar Designer
2022-02-14 15:10 ` Eric W. Biederman
2022-02-14 17:43 ` Eric W. Biederman
2022-02-15 10:25 ` Michal Koutný
2022-02-16 15:35 ` Eric W. Biederman
2022-02-11 2:13 ` [PATCH 4/8] ucounts: Only except the root user in init_user_ns from RLIMIT_NPROC Eric W. Biederman
2022-02-15 10:54 ` Michal Koutný
2022-02-16 15:41 ` Eric W. Biederman
2022-02-11 2:13 ` [PATCH 5/8] ucounts: Handle wrapping in is_ucounts_overlimit Eric W. Biederman
2022-02-12 22:36 ` Solar Designer
2022-02-14 15:23 ` Eric W. Biederman
2022-02-14 15:23 ` Eric W. Biederman
2022-02-15 11:25 ` Michal Koutný
2022-02-14 17:16 ` David Laight
2022-02-11 2:13 ` [PATCH 6/8] ucounts: Handle inc_rlimit_ucounts wrapping in fork Eric W. Biederman
2022-02-11 11:34 ` Alexey Gladkov
2022-02-11 17:50 ` Eric W. Biederman
2022-02-11 18:32 ` Shuah Khan
2022-02-11 18:40 ` Alexey Gladkov
2022-02-11 19:56 ` Eric W. Biederman
2022-02-11 2:13 ` [PATCH 7/8] rlimit: For RLIMIT_NPROC test the child not the parent for capabilites Eric W. Biederman
2022-02-11 2:13 ` [PATCH 8/8] ucounts: Use the same code to enforce RLIMIT_NPROC in fork and exec Eric W. Biederman
2022-02-11 18:22 ` [PATCH 0/8] ucounts: RLIMIT_NPROC fixes Shuah Khan
2022-02-11 19:23 ` Eric W. Biederman
2022-02-15 11:37 ` Michal Koutný
2022-02-16 15:56 ` [PATCH v2 0/5] " Eric W. Biederman
2022-02-16 15:58 ` [PATCH v2 1/5] rlimit: Fix RLIMIT_NPROC enforcement failure caused by capability calls in set_user Eric W. Biederman
2022-02-16 17:42 ` Solar Designer
2022-02-16 15:58 ` [PATCH v2 2/5] ucounts: Enforce RLIMIT_NPROC not RLIMIT_NPROC+1 Eric W. Biederman
2022-02-16 15:58 ` [PATCH v2 3/5] ucounts: Base set_cred_ucounts changes on the real user Eric W. Biederman
2022-02-16 15:58 ` [PATCH v2 4/5] ucounts: Move RLIMIT_NPROC handling after set_user Eric W. Biederman
2022-02-16 15:58 ` [PATCH v2 5/5] ucounts: Handle wrapping in is_ucounts_overlimit Eric W. Biederman
2022-02-16 17:28 ` Shuah Khan
2022-02-18 15:34 ` [GIT PULL] ucounts: RLIMIT_NPROC fixes for v5.17 Eric W. Biederman
2022-02-20 19:05 ` pr-tracker-bot
2022-03-03 0:12 ` [GIT PULL] ucounts: Regression fix " Eric W. Biederman
2022-03-03 0:30 ` pr-tracker-bot
2022-02-12 15:32 ` [RFC PATCH 0/6] RLIMIT_NPROC in ucounts fixups Etienne Dechamps
2022-02-15 10:11 ` Michal Koutný
2022-02-23 0:57 ` Eric W. Biederman
2022-02-23 18:00 ` How should rlimits, suid exec, and capabilities interact? Eric W. Biederman
2022-02-23 19:44 ` Andy Lutomirski
2022-02-23 21:28 ` Willy Tarreau
2022-02-23 19:50 ` Linus Torvalds
2022-02-24 1:24 ` Eric W. Biederman
2022-02-24 1:41 ` Linus Torvalds
2022-02-24 2:12 ` Eric W. Biederman
2022-02-24 15:41 ` [PATCH] ucounts: Fix systemd LimigtNPROC with private users regression Eric W. Biederman
2022-02-24 16:28 ` Kees Cook
2022-02-24 18:53 ` Michal Koutný
2022-02-25 0:29 ` Eric W. Biederman
2022-02-24 3:00 ` How should rlimits, suid exec, and capabilities interact? David Laight
2022-02-24 1:32 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f0585ae4-5642-361f-11d6-9399bd9cc550@linuxfoundation.org \
--to=skhan@linuxfoundation.org \
--cc=brauner@kernel.org \
--cc=containers@lists.linux-foundation.org \
--cc=ebiederm@xmission.com \
--cc=keescook@chromium.org \
--cc=legion@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=mkoutny@suse.com \
--cc=ran.xiaokai@zte.com.cn \
--cc=shuah@kernel.org \
--cc=solar@openwall.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®