From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 60A8E80069 for ; Wed, 26 Aug 2026 13:10:42 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QD9Qu9008351; Wed, 26 Aug 2026 16:09:27 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QD9Qu9008351 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="wSYgKAf/" Received: from mail-ed1-f69.google.com (mail-ed1-f69.google.com [209.85.208.69]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 67QD9Egi008320 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Wed, 26 Aug 2026 16:09:15 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 67QD9Egi008320 Received: by mail-ed1-f69.google.com with SMTP id 4fb4d7f45d1cf-6a5dfdbf015so1032282a12.0 for ; Wed, 26 Aug 2026 06:09:14 -0700 (PDT) X-Gm-Message-State: AFuF++kyhAWY2+TDVmKBkK6mYC0ZrSEKvsWGk5jF6rc5IwiiQpojF9ip x9lwzBVhoh3cIEoo609UJT0HODdditHPUOe7feXGtnoB2ohcFXC2uT8gCJPXvYNfEqOqLwdVhzd NPeMT88HhzzJXD1Fvv3KnaqW9X7gz/qgYfEEluyvpQ1iugd4VdFhlcQ== X-Gm-Gg: AR+sD11QLR3ABfvpEeOYIq6sf0hJRIbOzQwSQjzH9WETpDxdRptK2jYM1U0jlvN8GqD aKQsPRR/ZYJI2sggG76UfJHUFccmwZO5XVBpkMw5BHELOcRJWHcC5SkUCdFDuoHcrBrFQLM3o4G ufpslfrLVJ7WR37VVoAdjNZMnoa2COgOgIru/e49TJxwLiDASkj2Wf/85RXOvFawjl6la+9eDPN sZGMM4PInDwQ4zEQfJojZn7MgR5IrilKwpMy+DZsd/fGRWefGSqgmmHp8vFHD9nO6umIl/w1sW2 EU2fsltrHExjQ5M4gfyQE+EMUDz1TWo0vWSgyAoiioreHuvx73kkCaCjFsnw/oagUShhIU4PugS /ZcBbSRYBjyB6IHy9 X-Received: by 2002:a05:6402:548a:b0:69f:fa13:ed3 with SMTP id 4fb4d7f45d1cf-6a5df6722e6mr9010188a12.16.1787749754621; Wed, 26 Aug 2026 06:09:14 -0700 (PDT) X-Received: by 2002:a05:6402:548a:b0:69f:fa13:ed3 with SMTP id 4fb4d7f45d1cf-6a5df6722e6mr9010082a12.16.1787749754119; Wed, 26 Aug 2026 06:09:14 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787749754; cv=none; d=google.com; s=arc-20260327; b=MyG2RfdJJCqhhajeefnl218kyynnKbu7eiR9uM1HVCfFgb+oOx5hOjByPo0jK4FZnK pvYSgfgbk9y5WUWN7n9qFRPSUOTchyfeVOMabnVRTr88KgTezfBVgp/MYzJqFvBmY7nV KtvQ/FEqlahTRKafNMg1LekSLOh/vreQ23zrycqDoi5NdwW8+O7gbtC1VgN8ENKQcdIv KUQ+XS9RiklO1EZfjLhlZegnU0lOSRDnTJYA8vONA0DWD0+dSdBR9mos/jOPYSPpidIU h5wGtKALsENvyczonKEshpNcmyGmZ6tLR1gclgMNBBmrrsIoLnCgmGuMtfT4GaMQ8Opo 9mMg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=subject:in-reply-to:cc:to:from:message-id:date:dkim-signature; bh=IndukJkX3AJoE3TcHgqF/Syq4BPfCz9KyNre8h/NzKQ=; fh=UoUx/ScICNSLS7LR9gyUDsZM8Zuq0DvPxxrx16Z82mE=; b=s/yn7F5wUn8FS63aUMeZnjcyKbYrJF1UvWblyFKT3tJYQXe3DtPK+hORSfqD64+q1w +drS4iGZUl3hq/jT+4RldOXW1BCtKIl/mOM6ibgxC1wDxamTLMJGXIbcf5UN8Ym/WdJ1 rxfnUfQst4m1uJNUwGPUZRwRMhoY5o+dLiB2qxoUSggeILAc+KjoVnf/FFdlqQqvfQwc fZYzoa1aMFe7dHv4Szj1z66Yg/NYHjtb0CQAGg0quG0/XiMyX5cHT2wPij2DOJ1tWmoj V9NWlIUxpGkVuuT7Yx0Yrf7VC/hG4vgQCwndu//uXsBoP2Lv47l2dbD+r0HUdZo/BdYR RQwA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="wSYgKAf/"; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id 4fb4d7f45d1cf-6a5deaa27f1si4352963a12.189.2026.08.26.06.09.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 06:09:14 -0700 (PDT) Received-SPF: pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b="wSYgKAf/"; spf=pass (google.com: domain of khorenko@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=khorenko@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=Subject:From:Message-Id:Date:Content-Type: MIME-Version; bh=IndukJkX3AJoE3TcHgqF/Syq4BPfCz9KyNre8h/NzKQ=; b=wSYgKAf/PEkV DzaDHHMSomLF42n0+BpUs48DeVkOiaM3UhS/YS0Z9BELk2N2m15ku9lZaTnqONdaJOhu3SsaVMpo0 Pt2aKbuRbOkfDWDt4HHk5HaMzxQkGvR+CtEQsLbQIcauoUwsbe4DgjzJMnp+Rh4urJJiZCbAmMU8p aUJD9FbAmVx1yfxIiYs3FuPo5pkwdC8zp/dTb6BsjiopWU399ZGtDZ0Vr0RUFcogtq1PCeb9Kk3/B EeqxaHmBMkuZPs9C06nFGeKIgW4bOqC6LDMPiL5nQgGjEV8dTpkHcWK6x76tgE63K7/UB3aFNqXd8 i2OKwZOgd4pLRzDPaC88uw==; Received: from ch-demo-asa.virtuozzo.com ([130.117.225.8] helo=f0.sw.ru) by relay.virtuozzo.com with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzDLD-001rmc-0r; Wed, 26 Aug 2026 15:09:13 +0200 Received: from f0.sw.ru (localhost [127.0.0.1]) by f0.sw.ru (8.18.1/8.18.1/Debian-2) with ESMTP id 67QD9DD0890860; Wed, 26 Aug 2026 15:09:13 +0200 Received: (from kostja@localhost) by f0.sw.ru (8.18.1/8.18.1/Submit) id 67QD9D3K890859; Wed, 26 Aug 2026 15:09:13 +0200 Date: Wed, 26 Aug 2026 15:09:13 +0200 Message-Id: <202608261309.67QD9D3K890859@f0.sw.ru> X-Authentication-Warning: f0.sw.ru: kostja set sender to khorenko@virtuozzo.com using -f From: Konstantin Khorenko To: Vasileios Almpanis In-Reply-to: <20260825-connectors-v3-3-7b26773876a0@virtuozzo.com> X-OZ-Fwd: true Cc: OpenVZ devel Subject: Re: [Devel] [PATCH RHEL10 COMMIT] connector: deliver per-VE proc events under an RCU read lock X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git@bitbucket.org:openvz/vzkernel.git after rh10-6.12.0-211.39.1.16.10.vz10 ------> commit d502d5ac74069447eecc819e568b1f626a554e46 Author: Vasileios Almpanis Date: Tue Aug 25 16:19:53 2026 +0000 connector: deliver per-VE proc events under an RCU read lock proc_event_connector_ve() dereferences ve->cn several times and fill_exit_event() dereferences ve->ve_nsproxy assuming the VE cannot stop in the middle of the delivery. This holds while the reported task is alive in the VE: a live task keeps the VE pid namespace busy, so zap_pid_ns_processes() -> ve_exit_ns() cannot start. The next patch makes proc_exit_connector() deliver the exit event with a VE reference pinned before exit_notify(). Once the task is reaped, its pid no longer keeps the pid namespace busy: the container init may be woken up by free_pid() from release_task(), finish zap_pid_ns_processes() and run ve_exit_ns() while the exit event is still being delivered: cpu0: exiting task cpu1: container init do_exit() exit_notify() release_task() free_pid() -------------> wakes zap_pid_ns_processes() proc_exit_connector() ve_exit_ns() proc_event_connector_ve() cn_fini_ve() /* ve->cn */ fill_exit_event() ve_drop_context() /* ve_nsproxy */ ve->ve_nsproxy->... Deliver the event under rcu_read_lock() and recheck the pointers: the previous patch guarantees everything reachable from ve->cn stays alive for the whole read-side critical section once observed, and ve_drop_context() already waits for a grace period before dropping ve_nsproxy. Bail out if the VE is being stopped: its listeners are dead anyway, there is nobody to deliver to. The whole delivery path runs with GFP_NOWAIT and never sleeps, so it is legal inside an RCU read-side critical section. https://virtuozzo.atlassian.net/browse/VSTOR-140421 Feature: ve: ve generic structures Signed-off-by: Vasileios Almpanis Reviewed-by: Konstantin Khorenko --- drivers/connector/cn_proc.c | 36 +++++++++++++++++++++++++++++++++--- drivers/connector/connector.c | 4 ++++ 2 files changed, 37 insertions(+), 3 deletions(-) diff --git a/drivers/connector/cn_proc.c b/drivers/connector/cn_proc.c index 6095c7def7cea..6084308085489 100644 --- a/drivers/connector/cn_proc.c +++ b/drivers/connector/cn_proc.c @@ -89,6 +89,10 @@ static inline void send_msg_ve(struct ve_struct *ve, struct cn_msg *msg) struct local_event *le_ptr; __u32 filter_data[2]; + /* The VE is being stopped, so are its listeners: nothing to do */ + if (!cn) + return; + /* * The following hack with local_event->lock address works only * till the "lock" is the first field in the local_event struct, @@ -172,15 +176,27 @@ static void proc_event_connector_ve(struct task_struct *task, struct cn_msg *msg; __u8 buffer[CN_PROC_MSG_SIZE] __aligned(8); + /* + * The exit event may be delivered when the reported task no + * longer pins the VE (see proc_exit_connector()), so the VE may + * be stopping concurrently. cn_proc_fini_ve() waits for an RCU + * grace period before the connector state is freed, take the RCU + * read lock to make the state observed here stay valid for the + * whole delivery. The path below never sleeps (GFP_NOWAIT). + */ + rcu_read_lock(); + if (proc_event_num_listeners(ve) < 1) - return; + goto out_unlock; msg = cn_msg_fill(buffer, ve, task, what, cookie, fill_event); if (!msg) - return; + goto out_unlock; /* If cn_netlink_send() failed, the data is not sent */ send_msg_ve(ve, msg); +out_unlock: + rcu_read_unlock(); } static void proc_event_connector(struct task_struct *task, @@ -350,9 +366,23 @@ void proc_coredump_connector(struct task_struct *task) static bool fill_exit_event(struct proc_event *ev, struct ve_struct *ve, struct task_struct *task, long cookie_pids) { - struct pid_namespace *pid_ns = ve->ve_nsproxy->pid_ns_for_children; + struct pid_namespace *pid_ns; struct task_struct *parent; struct pids *pids = (struct pids *)cookie_pids; + struct nsproxy *nsproxy; + + /* + * Unlike all other events, the exit event may be delivered after + * the task was reaped, when nothing keeps the VE pid namespace + * busy anymore and the VE may be stopping concurrently. + * ve_drop_context() clears ve_nsproxy and waits for an RCU grace + * period before dropping it; we are called under rcu_read_lock(). + * The VE is dead, so are its listeners: skip the event. + */ + nsproxy = rcu_dereference(ve->ve_nsproxy); + if (!nsproxy) + return false; + pid_ns = nsproxy->pid_ns_for_children; ev->event_data.exit.process_pid = pid_nr_ns(pids->pid, pid_ns); ev->event_data.exit.process_tgid = pid_nr_ns(pids->tgid, pid_ns); diff --git a/drivers/connector/connector.c b/drivers/connector/connector.c index 05c281bb321be..5597801c4af28 100644 --- a/drivers/connector/connector.c +++ b/drivers/connector/connector.c @@ -79,6 +79,10 @@ int cn_netlink_send_mult_ve(struct ve_struct *ve, struct cn_msg *msg, u16 len, u32 group = 0; int found = 0; + /* The VE is being stopped, see proc_event_connector_ve() */ + if (!dev) + return -ENODEV; + if (portid || __group) { group = __group; } else { _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel