From: Daniel Colascione <firstname.lastname@example.org> To: "Serge E. Hallyn" <email@example.com> Cc: Christian Brauner <firstname.lastname@example.org>, "Eric W. Biederman" <email@example.com>, linux-kernel <firstname.lastname@example.org>, Linux API <email@example.com>, Andy Lutomirski <firstname.lastname@example.org>, Arnd Bergmann <email@example.com>, Jann Horn <firstname.lastname@example.org>, Andrew Morton <email@example.com>, Oleg Nesterov <firstname.lastname@example.org>, Aleksa Sarai <email@example.com>, Al Viro <firstname.lastname@example.org>, Linux FS Devel <email@example.com>, Tim Murray <firstname.lastname@example.org>, linux-man <email@example.com>, Kees Cook <firstname.lastname@example.org>, Florian Weimer <email@example.com>, firstname.lastname@example.org, email@example.com Subject: Re: [PATCH v4] signal: add taskfd_send_signal() syscall Date: Thu, 6 Dec 2018 17:39:18 -0800 Message-ID: <CAKOZuesqmPvYoibx3MvVj86EMWRRW4My=7n6iiiBJa+MXo-GJA@mail.gmail.com> (raw) In-Reply-To: <20181207005917.GA11302@mail.hallyn.com> On Thu, Dec 6, 2018 at 4:59 PM Serge E. Hallyn <firstname.lastname@example.org> wrote: > > On Thu, Dec 06, 2018 at 04:34:54PM -0800, Daniel Colascione wrote: > > On Thu, Dec 6, 2018 at 4:31 PM Serge E. Hallyn <email@example.com> wrote: > > > > > > On Fri, Dec 07, 2018 at 12:17:45AM +0100, Christian Brauner wrote: > > > > On Thu, Dec 06, 2018 at 11:39:48PM +0100, Christian Brauner wrote: > > > > > On Thu, Dec 06, 2018 at 03:46:53PM -0600, Eric W. Biederman wrote: > > > > > > Christian Brauner <firstname.lastname@example.org> writes: > > > > > > > > > > > > >> Your intention is to add the thread case to support pthreads once the > > > > > > >> process case is sorted out. So this is something that needs to be made > > > > > > >> clear. Did I miss how you plan to handle threads? > > > > > > > > > > > > > > Yeah, maybe you missed it in the commit message  which is based on a > > > > > > > discussion with Andy  and Arnd : > > > > > > > > > > > > Looking at your references I haven't missed it. You are not deciding > > > > > > anything as of yet to keep it simple. Except you are returning > > > > > > EOPNOTSUPP. You are very much intending to do something. > > > > > > > > > > That was clear all along and was pointed at every occassion in the > > > > > threads. I even went through the hazzle to give you all of the > > > > > references when there's lore.kernel.org. > > > > > > > > > > > > > > > > > Decide. Do you use the flags parameter or is the width of the > > > > > > target depending on the flags. > > > > > > > > Ok, let's try to be constructive. I understand the general concern for > > > > the future so let's put a contract into the commit message stating that > > > > the width of the target aka *what is signaled* will be based on a flag > > > > parameter if we ever extend it: > > > > > > > > taskfd_send_signal(fd, SIGSTOP, NULL, TASKFD_PGID); > > > > taskfd_send_signal(fd, SIGSTOP, NULL, TASKFD_TID); > > > > > > > > with the current default being > > > > > > > > taskfd_send_signal(fd, SIGSTOP, NULL, TASKFD_PID); > > > > > > > > This seems to me the cleanest solution as we only use one type of file > > > > descriptor. Can everyone be on board with this? If so I'm going to send > > > > out a new version of the patch. > > > > > > > > Christian > > > > > > I'm on board with this, but I think you need to also clarify what exactly > > > the fd stands for. I think that (a) userspace should not have to care > > > about the struct pid implementation, and so (b) the procfd should stand > > > for all the pids. So when taskfd_send_signal(fd, SIGSTOP, NULL, TASKFD_PGID) > > > becomes implemented, then open(/proc/5) will pin all three pids, as will > > > open(/proc/5/task/6). > > > > This change doesn't "pin" any PID, and it makes no sense to make a > > process FD stand for all its threads. What does that even mean? > > Currently the patch relies on the procfd inode saving a copy to the PIDTYPE_PID > pid. struct pid doesn't have a type field. The interpretation depends on the caller's use of the struct pid, and in the current path, that's PIDTYPE_PID. What, specifically, is wrong with the current approach? > I'm not sure offhand, can it go to the PIDTYPE_PGID from that after the > task has died, or not? I didn't think so. If it can then great. You're arguing that something that does, in fact, work, is somehow broken in some unspecified way. The kill_pid_info lookup works fine. What, specifically, is wrong with the semantics as implemented? > The point is (a) these are details which should not have to bother userspace, These details *don't* bother userspace. You're raising concerns that are either imaginary or long-since addressed. Does the patch cause some kind of maintenance burden? No, it doesn't, not moreso than any other piece of code. Does the interface have unclear semantics? No, it clearly sends a signal to a process, just like kill. Does the patch expose kernel implementation details? No, it doesn't, because the interface is simply not defined in terms of these details. Do we need to change how signal delivery works? No, because if it's fine for kill, it's fine for this facility, and if some future signal cleanup separates the cases more, that cleanup can change this code as well. The change is well-documented, simple, extensible, and addresses an actual problem. Every legitimate technical criticism has now been addressed. I don't understand where this opposition is coming from, since the objections refer to nothing that's actually in the patch or exposed to the user. > and (b) how to decide who we're sending the signal to (tid/pid/pgid) should > be specified in precisely one way. So either a flag, or comign from the type > of fd that was opened. You can't send signals to a thread with the current patch. There's no ambiguity in providing zero ways to do something.
next prev parent reply index Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top 2018-12-06 12:18 Christian Brauner 2018-12-06 12:30 ` Florian Weimer 2018-12-06 12:45 ` Jürg Billeter 2018-12-06 13:12 ` Florian Weimer 2018-12-06 13:18 ` Jürg Billeter 2018-12-06 13:20 ` Florian Weimer 2018-12-06 13:40 ` Eric W. Biederman 2018-12-06 13:44 ` Florian Weimer 2018-12-06 14:27 ` Aleksa Sarai 2018-12-06 14:46 ` Eric W. Biederman 2018-12-06 12:53 ` Christian Brauner 2018-12-06 13:17 ` Florian Weimer 2018-12-06 15:01 ` Eric W. Biederman 2018-12-06 16:17 ` Daniel Colascione 2018-12-06 17:24 ` Eric W. Biederman 2018-12-06 17:41 ` Christian Brauner 2018-12-06 18:30 ` Kees Cook 2018-12-06 22:27 ` Serge E. Hallyn 2018-12-06 17:14 ` Christian Brauner 2018-12-06 19:17 ` Eric W. Biederman 2018-12-06 19:30 ` Christian Brauner 2018-12-06 20:29 ` Eric W. Biederman 2018-12-06 20:37 ` Daniel Colascione 2018-12-06 22:22 ` Eric W. Biederman 2018-12-06 22:43 ` Daniel Colascione 2018-12-06 21:31 ` Christian Brauner 2018-12-06 21:46 ` Eric W. Biederman 2018-12-06 22:01 ` Daniel Colascione 2018-12-06 22:39 ` Christian Brauner 2018-12-06 23:17 ` Christian Brauner 2018-12-07 0:31 ` Serge E. Hallyn 2018-12-07 0:34 ` Daniel Colascione 2018-12-07 0:59 ` Serge E. Hallyn 2018-12-07 1:39 ` Daniel Colascione [this message] 2018-12-07 1:54 ` Christian Brauner 2018-12-07 16:49 ` Serge E. Hallyn 2018-12-07 16:47 ` Serge E. Hallyn 2018-12-08 21:46 ` kbuild test robot
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to='CAKOZuesqmPvYoibx3MvVj86EMWRRW4My=7n6iiiBJa+MXo-GJA@mail.gmail.com' \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
LKML Archive on lore.kernel.org Archives are clonable: git clone --mirror https://lore.kernel.org/lkml/0 lkml/git/0.git git clone --mirror https://lore.kernel.org/lkml/1 lkml/git/1.git git clone --mirror https://lore.kernel.org/lkml/2 lkml/git/2.git git clone --mirror https://lore.kernel.org/lkml/3 lkml/git/3.git git clone --mirror https://lore.kernel.org/lkml/4 lkml/git/4.git git clone --mirror https://lore.kernel.org/lkml/5 lkml/git/5.git git clone --mirror https://lore.kernel.org/lkml/6 lkml/git/6.git git clone --mirror https://lore.kernel.org/lkml/7 lkml/git/7.git git clone --mirror https://lore.kernel.org/lkml/8 lkml/git/8.git # If you have public-inbox 1.1+ installed, you may # initialize and index your mirror using the following commands: public-inbox-init -V2 lkml lkml/ https://lore.kernel.org/lkml \ email@example.com public-inbox-index lkml Example config snippet for mirrors Newsgroup available over NNTP: nntp://nntp.lore.kernel.org/org.kernel.vger.linux-kernel AGPL code for this site: git clone https://public-inbox.org/public-inbox.git