Re: [PATCH rdma-next 08/13] RDMA/cgroup: Scope rdma cgroup device visibility to the net namespace
Tao Cui <[email protected]>
| Newsgroups | org.kernel.vger.cgroups,org.kernel.vger.linux-kselftest,org.kernel.vger.linux-rdma,org.kernel.vger.linux-s390,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
在 2026/7/13 17:34, Jiri Pirko 写道: > Thu, Jul 09, 2026 at 03:04:23PM +0200, [email protected] wrote: >> Hi. >> >> On Thu, Jul 09, 2026 at 11:55:27AM +0200, Jiri Pirko <[email protected]> wrote: >>> index 993446ab66d0..4523c1884d67 100644 >>> --- a/Documentation/admin-guide/cgroup-v2.rst >>> +++ b/Documentation/admin-guide/cgroup-v2.rst >>> @@ -2752,6 +2752,13 @@ RDMA >>> The "rdma" controller regulates the distribution and accounting of >>> RDMA resources. >>> >>> +When RDMA devices are isolated per network namespace (exclusive mode), >>> +device names are unique only within a network namespace. The device lines >>> +below are therefore scoped to the reading or writing process's network >>> +namespace: only devices accessible from that namespace are listed, and a >>> +limit is applied to the device of that name in that namespace. Configure >>> +limits from the same network namespace as the workloads. >> >> OK. >> >>> --- a/include/linux/cgroup_rdma.h >>> +++ b/include/linux/cgroup_rdma.h >>> @@ -7,6 +7,7 @@ >>> #define _CGROUP_RDMA_H >>> >>> #include <linux/cgroup.h> >>> +#include <net/net_namespace.h> >>> >>> enum rdmacg_resource_type { >>> RDMACG_RESOURCE_HCA_HANDLE, >>> @@ -34,6 +35,15 @@ struct rdmacg_device { >>> struct list_head dev_node; >>> struct list_head rpools; >>> char *name; >>> + /* >>> + * Net namespace the device belongs to. @netns_shared mirrors >>> + * ib_devices_shared_netns: when true the device is visible from every >>> + * net namespace (shared mode); otherwise @net is the only namespace >>> + * that may see and configure it. @netns_shared is updated when the >>> + * sharing mode changes, so use {READ,WRITE}_ONCE() to access it. >>> + */ >>> + possible_net_t net; >>> + bool netns_shared; >> >> Any reason to store the netns_shared split per device? (IIUC, it's a >> global parameter.) > > No reason, changed. > Hi Jiri, A question on the v2 you mentioned to Michal. Once netns_shared stops being cached per rdmacg_device, rdmacg_device_visible() in kernel/cgroup/rdma.c still needs the current sharing mode, whose authoritative value lives in the IB core (ib_devices_shared_netns). How do you plan to expose it there without the generic cgroup controller reaching back into drivers/infiniband/? Exporting the global, or keeping an IB-side update hook, both feel a bit awkward; it would be good to see which direction you took. On the mechanism itself: it's the right call that rdmacg_try_charge() stays out of the scoping. Charging takes the rdmacg_device pointer directly (no name lookup), and a task can only charge a device it already holds a handle to, so applying visibility there would be wrong. The scoping deliberately touches only the name-based lookup (the write path) and the enumeration (read/show) paths -- worth keeping that invariant in mind so a later patch doesn't grow the filter. Thanks, Tao> Thanks! > >> >> Thanks, >> Michal > > >