Received: by 2002:a89:d88:0:b0:1fa:5c73:8e2d with SMTP id eb8csp810151lqb; Fri, 24 May 2024 14:10:41 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCXYIb9r1feEuVPx9DYdugN53VWHli5NbrKwg1Y8S2ZDnMmTCw/CQHYDFyqtwv6+6k3/PEdWvm24INEGiTw2S34mF5k3RsDvLtwNqgrQkA== X-Google-Smtp-Source: AGHT+IH+g546vo7xye3+NyikKz9AMfVKJ/ZdBTZQNv97f5O5q7YJ5AHZxlFA97AG4AhTnjtXk9Cq X-Received: by 2002:a05:6a20:9783:b0:1af:d9a3:f399 with SMTP id adf61e73a8af0-1b212dfe3e3mr3509775637.29.1716585041023; Fri, 24 May 2024 14:10:41 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1716585041; cv=pass; d=google.com; s=arc-20160816; b=zNV92uppHoyWPyAq4/CizlnROvsW9jgLpRrQdg70exTLtzHBxF6v5V6nbDfEMIwLy2 inAsSLkosDvmUD3eLIRDvxCcnHWe3F0VGFlIJeSZKiHF70kYBu+oi7O7QbTGicamgzo1 +u6VN/4G7js6flQkn7hO+Rn/iFdNYKHsE9/Wp4z9GIUz9kcQtamNBps2QqPWcFthN3am 8S6kH3J3ZmhXbuk9MVFDFsf0Tc7pEP3Lwm4Pd6U6t93wqauKF584bZ+Cfq851TjNFnvu SF5xvg5pUQd67A4Y1ZyOmXw1pz8DQu0Dqic7rcAsfjBdoZl8EC/bmnHSjNdW8RP8z9Q9 AXpg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:list-unsubscribe:list-subscribe :list-id:precedence:dkim-signature; bh=IkKuU4yp54waIwA456gQUHmRrLLSQ6nNxxNfaMdF938=; fh=/mVJ7ttUDVkNuWz4KEXPIAtLtKsHB0YkTufT4la7M9A=; b=JcsXsbWk2NT8VmjDN7vhwa2JQdqHhvvjXgkGon5a4TEXWjPphYM/s+NfZksD65qHUM OlX4AxTqnK0CApyMxw3Ubsac8e1PVSpJjgKoRyHjdYcZD3oQByq+kTRkdedlvLPNTobj hmUXk3bOQKelyPuGgwAL0o+mAQmrti0ZMaJyjdg867E2LcynGA0lpTRTIR+OVJkYzzwx vu5jDScAiqjMnr9j5eFPNRgbFFNkI/tMhzaJvXL3tMHixxSrQEB377g5KK1OBT6CmOWd zuB5KP6SGdsDC3gwa+0UDxMj7NKfHHTfs3S27yCsvXbafsw8JNypnlkUst5L80SobRDa 2PwQ==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=IOuREHgY; arc=pass (i=1 spf=pass spfdomain=gmail.com dkim=pass dkdomain=gmail.com dmarc=pass fromdomain=gmail.com); spf=pass (google.com: domain of linux-kernel+bounces-189139-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-189139-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [139.178.88.99]) by mx.google.com with ESMTPS id 41be03b00d2f7-6822bbc751asi1858045a12.895.2024.05.24.14.10.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 May 2024 14:10:41 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-189139-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) client-ip=139.178.88.99; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=IOuREHgY; arc=pass (i=1 spf=pass spfdomain=gmail.com dkim=pass dkdomain=gmail.com dmarc=pass fromdomain=gmail.com); spf=pass (google.com: domain of linux-kernel+bounces-189139-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-189139-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id A122B28208D for ; Fri, 24 May 2024 21:10:40 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 0B8028529E; Fri, 24 May 2024 21:10:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="IOuREHgY" Received: from mail-ej1-f52.google.com (mail-ej1-f52.google.com [209.85.218.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B2C1482D6C; Fri, 24 May 2024 21:10:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716585033; cv=none; b=giBExFABKQYwJSQz2YvGXCGshEj1EnRdMEwXI1J9XEKs2SFuLTgrrAQKg3VImM4N2A+8EFKlyBNNhtkwiVXC3252uWGAdDqoq52DquA8BdyeBkvOkGccANQkD8+65Qv1zLvKf+H7+Qa720WsTArf3Xc1F2q5drkm2DOf0ZuLTw4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716585033; c=relaxed/simple; bh=IkKuU4yp54waIwA456gQUHmRrLLSQ6nNxxNfaMdF938=; h=MIME-Version:References:In-Reply-To:From:Date:Message-ID:Subject: To:Cc:Content-Type; b=Kh57T8ZaY+prHT2g/muBd6PJ2AqicCS7qU3wzvMTSS+8dUsixypHqYyRs83oeNJwh3wweGVDj9rvyMcohnP4T3POkskRin6MWwBGQ2s/MkRocxdWrzjgpm+7deZaXBzhavaORaJkCH8XqZB2Kqmg2wrqRIvDWDf3pY8fc1vIazA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=IOuREHgY; arc=none smtp.client-ip=209.85.218.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-ej1-f52.google.com with SMTP id a640c23a62f3a-a5a5cb0e6b7so1342994966b.1; Fri, 24 May 2024 14:10:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1716585029; x=1717189829; darn=vger.kernel.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=IkKuU4yp54waIwA456gQUHmRrLLSQ6nNxxNfaMdF938=; b=IOuREHgY7nppp3pZEvSGIC8I+h6OCwmpgq+3/79yx6hSyQkbDUX4KhbE0FPtdpjx9+ Iw01gfbomy6hAvgTDl5of6DbgvptJKAOt5mzjJO9EzvhkyDZF6+QBsBiq3E3BCBEFwr1 URjeriwfYaN5SrqNfUKtjWDBFNWi6afwKf4EINNVG7uP2OS7PMpZcp2pDp8GamsyxDAI n0wbGWhlAwQv1sZQVM9s5XBcuPeOZeC24TA1pqpeOynRlChGk3UNPdXq8gZDnagLVkTy MLo6a/r7GI48sxEnU4odbNM669JVe6DRtvMKwQfWPTgqjF9JwtEwiqg8hmZZvh4Sn9Jc qqGg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1716585029; x=1717189829; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=IkKuU4yp54waIwA456gQUHmRrLLSQ6nNxxNfaMdF938=; b=OGBny2At0MDSjUoJrQWBaK4GM2TpcVbn1LecbCZ8xs7qQUaz5rndO3ytxABV/ty0FW ObucoTb0Wu0dSgdheI7d03CTCPJKUg7+6WkcK/6eZt0gN30NJfXi1Xku3hKQ9hxODJk4 YNCsldtrKWg+GjPOaknDHJSzqWnxyGs0M0Z02ryGPuvjPMOEZ8Ca7/ak5RoNVaOF/doK 7tHZY7/gw7rM+AfgwIkXmg/OhN3I26l2vWGrxqSGWMFV3F3QcQx8gzd451HCi8w3huC/ MGV3m4ClAAJvt9caI60LIsoPj7bqtjgJPCaT71k9Vb9vwsHDWMT5uUmicMWw95USqXJY qF4w== X-Forwarded-Encrypted: i=1; AJvYcCUEz8qPHsT70d0VniKPQ8/+VrG36+f8t5Hu7TBSN8LHiT1rTJ99TnfoP2AhqAhqy80OnnZilDxQ7uvB0oMKfPH76gAEn5WXEnCCS56TiVuH1R4h4C7Yqiq9je0dGBYsHUKdD+YAHnnjsWGoT5/7zJ2ZpEQy X-Gm-Message-State: AOJu0YxlCjkdON0Z4RjIGOP8ujR6KiwWjuQzep4e5OfKEOB2JMUFth0e Qs4m2YLKctLKKvYgyj/aoPX6dSsTo//uDksx/I/kPAoTXASSvTPLHfN8CmegK/p+d2/+5XNlhoF WR9aDUQV1uEIlSg7KSrAqz1jeR2g= X-Received: by 2002:a17:906:6b0b:b0:a59:bae0:b12a with SMTP id a640c23a62f3a-a626536a08bmr227054366b.63.1716585028994; Fri, 24 May 2024 14:10:28 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 References: <096178c9-91de-4752-bdc4-6a31bcdcbaf8@amd.com> <4871a305-5d45-47d2-85f2-d718c423db80@canonical.com> <3b880c7c-0d19-4bb6-9f0f-fb69047f41cd@canonical.com> In-Reply-To: <3b880c7c-0d19-4bb6-9f0f-fb69047f41cd@canonical.com> From: Mateusz Guzik Date: Fri, 24 May 2024 23:10:16 +0200 Message-ID: Subject: Re: [RFC 0/9] Nginx refcount scalability issue with Apparmor enabled and potential solutions To: John Johansen Cc: Neeraj Upadhyay , paul@paul-moore.com, jmorris@namei.org, serge@hallyn.com, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, "Gautham R. Shenoy" , "Shukla, Santosh" , "Narayan, Ananth" , raghavendra.kodsarathimmappa@amd.com, koverstreet@google.com, paulmck@kernel.org, boqun.feng@gmail.com, vinicius.gomes@intel.com Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, Mar 8, 2024 at 9:09=E2=80=AFPM John Johansen wrote: > > On 3/2/24 02:23, Mateusz Guzik wrote: > > On 2/9/24, John Johansen wrote: > >> On 2/6/24 20:40, Neeraj Upadhyay wrote: > >>> Gentle ping. > >>> > >>> John, > >>> > >>> Could you please confirm that: > >>> > >>> a. The AppArmor refcount usage described in the RFC is correct? > >>> b. Approach taken to fix the scalability issue is valid/correct? > >>> > >> > >> Hi Neeraj, > >> > >> I know your patchset has been waiting on review for a long time. > >> Unfortunately I have been very, very busy lately. I will try to > >> get to it this weekend, but I can't promise that I will be able > >> to get the review fully done. > >> > > > > Gentle prod. > > > > Any chances of this getting reviewed in the foreseeable future? Would > > be a real bummer if the patchset fell through the cracks. > > > > yes, sorry I have been unavailable for the last couple of weeks. I am > now back, I have a rather large backlog to try catching up on but this > is has an entry on the list. > So where do we stand here? --=20 Mateusz Guzik