[RFC] per-containers tcp buffer limitation
wagi at monom.org
Thu Aug 25 05:55:39 PDT 2011
On 08/25/2011 04:16 AM, Eric W. Biederman wrote:
> KAMEZAWA Hiroyuki<kamezawa.hiroyu at jp.fujitsu.com> writes:
>> On Wed, 24 Aug 2011 22:28:59 -0300
>> Glauber Costa<glommer at parallels.com> wrote:
>>> On 08/24/2011 09:35 PM, Eric W. Biederman wrote:
>>>> Glauber Costa<glommer at parallels.com> writes:
>>> Hi Eric,
>>> Thanks for your attention.
>>> So, this that you propose was my first implementation. I ended up
>>> throwing it away after playing with it for a while.
>>> One of the first problems that arise from that, is that the sysctls are
>>> a tunable visible from inside the container. Those limits, however, are
>>> to be set from the outside world. The code is not much better than that
>>> either, and instead of creating new cgroup structures and linking them
>>> to the protocol, we end up doing it for net ns. We end up increasing
>>> structures just the same...
> You don't need to add a netns member to sockets.
> But I do agree that there are odd permission issues with using the
> existing sysctls and making them per namespace.
> However almost everything I have seen with memory limits I have found
> very strange. They all seem like a very bad version of disabling memory
> over commits.
Please apply the same rules for not cursing my family no further then
the 3rd generation for my idea:
I'd like to solve a use case where it is necessary to count all bytes
transmitted and received by an application . So far I have found two
unsatisfying solution for it. The first one is to hook into libc and
count the bytes there. I don't think I have to say I don't like this.
The second idea was to use the trick Google has used for Android .
They add a hook into __sock_sendmsg and __sock_recvmsg and then count
the bytes per UID. To get this working all application have to use an
unique UID. So not very nice either.
After reading a bit up on cgroup I think that would be the right place
to count the traffic. Unfortunately, with net_cls I can count the
outgoing traffic but not the incoming one. If I understood Glauber
approach correctly adding some statistic counters would be easy to do.
Of course I don't know the impact of this.
More information about the Containers