Re: [PATCH 06/45] KEYS: Make the keyring quotas controllable through /proc/sys [ver #35]

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: David Howells <dhowells@...>
Cc: <torvalds@...>, <akpm@...>, <trond.myklebust@...>, <chuck.lever@...>, <nfsv4@...>, <linux-kernel@...>, <linux-fsdevel@...>, <selinux@...>, <linux-security-module@...>
Date: Tuesday, April 1, 2008 - 11:29 am

David Howells schrieb:

Hello David,

you're our hero! ;-)

We just hit this wall while migrating from RHEl 3 to RHEL 5 with some of 
our webservers.

[root@lvr11 ~]# cat /proc/key-users
     0:    99 98/98 96/100 1681/10000
    32:     2 2/2 2/100 56/10000
    38:     2 2/2 2/100 56/10000
    43:     2 2/2 2/100 56/10000
    51:     2 2/2 2/100 56/10000
    68:     2 2/2 2/100 56/10000
    81:     2 2/2 2/100 56/10000
    99:     2 2/2 2/100 56/10000
   348:     2 2/2 2/100 58/10000
42216:     2 2/2 2/100 62/10000
55188:     3 3/3 3/100 72/10000
56537:     2 2/2 2/100 62/10000
63743:     2 2/2 2/100 62/10000
68054:     2 2/2 2/100 62/10000

....


We're using OpenAFS on our systems and most of our webpages are stored 
in AFS. We have a lot of small projects for which a separate server 
would be a waste of 'metal'. Even in a virtual environment. So we're 
hosting a lot of apache instances on a single machine. Beause suexec 
doesn't work in an AFS environment, each instance is started by root 
with its own IP (to be able to talk HTTPS) and in a PAG with a separate 
token for a service user (to isolate the projects). Although each apache 
switches  over to the service user, the initial tokens are acquired by root.

On RHEL 3 with the old 2.4 kernel this was never a problem. But now...

Btw.: We have some machines with about hundred (!) different projects 
which need tokens.


Best regards,

Berthold Cogel

-- 
Dr. Berthold Cogel                             University of Cologne
E-Mail: cogel@uni-koeln.de                     ZAIK-US (RRZK)
Tel.:   +49(0)221/470-7873                     Robert-Koch-Str. 10
FAX:    +49(0)221/478-85845                    D-50931 Cologne - Germany
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 00/45] Permit filesystem local caching [ver #35], David Howells, (Fri Mar 28, 10:30 am)
[PATCH 39/45] NFS: FS-Cache page management [ver #35], David Howells, (Fri Mar 28, 10:33 am)
[PATCH 36/45] NFS: Use local disk inode cache [ver #35], David Howells, (Fri Mar 28, 10:33 am)
[PATCH 44/45] NFS: Display local caching state [ver #35], David Howells, (Fri Mar 28, 10:33 am)
[PATCH 28/45] FS-Cache: Make kAFS use FS-Cache [ver #35], David Howells, (Fri Mar 28, 10:32 am)
Re: [PATCH 06/45] KEYS: Make the keyring quotas controllable..., Berthold Cogel, (Tue Apr 1, 11:29 am)