Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1762043Ab3IDGPS (ORCPT ); Wed, 4 Sep 2013 02:15:18 -0400 Received: from mx1.redhat.com ([209.132.183.28]:61832 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S934290Ab3IDGPP (ORCPT ); Wed, 4 Sep 2013 02:15:15 -0400 From: Jan Kaluza To: davem@davemloft.net Cc: LKML , netdev@vger.kernel.org, eparis@redhat.com, rgb@redhat.com, tj@kernel.org, lizefan@huawei.com, containers@lists.linux-foundation.org, cgroups@vger.kernel.org, viro@zeniv.linux.org.uk, Jan Kaluza Subject: [PATCH v3 0/3] Send audit/procinfo/cgroup data in socket-level control message Date: Wed, 4 Sep 2013 08:14:18 +0200 Message-Id: <1378275261-4553-1-git-send-email-jkaluza@redhat.com> In-Reply-To: <1377614400-27122-1-git-send-email-jkaluza@redhat.com> References: <1377614400-27122-1-git-send-email-jkaluza@redhat.com> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1932 Lines: 49 Hi, this patchset against net-next (applies also to linux-next) adds 3 new types of "Socket"-level control message (SCM_AUDIT, SCM_PROCINFO and SCM_CGROUP). Server-like processes in many cases need credentials and other metadata of the peer, to decide if the calling process is allowed to request a specific action, or the server just wants to log away this type of information for auditing tasks. The current practice to retrieve such process metadata is to look that information up in procfs with the $PID received over SCM_CREDENTIALS. This is sufficient for long-running tasks, but introduces a race which cannot be worked around for short-living processes; the calling process and all the information in /proc/$PID/ is gone before the receiver of the socket message can look it up. Changes introduced in this patchset can also increase performance of such server-like processes, because current way of opening and parsing /proc/$PID/* files is much more expensive than receiving these metadata using SCM. Changes in v3: - Better description of patches (Thanks to Kay Sievers) Changes in v2: - use PATH_MAX instead of PAGE_SIZE in SCM_CGROUP patch - describe each patch individually Jan Kaluza (3): Send loginuid and sessionid in SCM_AUDIT Send comm and cmdline in SCM_PROCINFO Send cgroup_path in SCM_CGROUP include/linux/socket.h | 9 ++++++ include/net/af_unix.h | 10 ++++++ include/net/scm.h | 67 ++++++++++++++++++++++++++++++++++++++-- net/core/scm.c | 83 ++++++++++++++++++++++++++++++++++++++++++++++++++ net/unix/af_unix.c | 70 ++++++++++++++++++++++++++++++++++++++++++ 5 files changed, 237 insertions(+), 2 deletions(-) -- 1.8.3.1 -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/