OpenVZ Forum


Home » General » Support » mainline kernel
icon8.gif  mainline kernel [message #50900] Tue, 26 November 2013 20:30 Go to next message
xaxaxa is currently offline  xaxaxa
Messages: 11
Registered: August 2012
Location: Vancouver, BC
Junior Member
are there plans to release a mainline-based openvz kernel?
My experience has been that mainline kernels tend to be much more stable than rhel kernels. I've encountered a few random freezes/kernel panics in the past with rhel6 (both stock centos rhel6 kernel and openvz rhel6 kernel), and I've always been running the latest stable version.
In addition, I find the rhel6 kernel extremely feature-incomplete:
* no codel support
* virtually no ARM support
* incompatible with AUFS and tuxonice patches
* VERY buggy btrfs code (I can instantly kernel-panic a rhel6/centos6 system by plugging in and unplugging one of my btrfs usb drives)
* no f2fs
* incomplete hardware support; the driver for my server's network card is in mainline, but not in rhel6
* no seccomp
* no nested pid namespaces, meaning I can't run things like chromium in an openvz container (without a hack)
* no tcp fast open
* bad numa scheduling

The openvz patches has a few issues too, most notably very bad network performance between ve <-> ve, and outside <-> ve (100% cpu usage to only get 50MB/s transfer with simple tcp connection; outside <-> host is fast though); I've tried both venet and veth, and got the same results.

so for now, I'm stuck with linux-vserver; I used to use openvz, but over time the kernel issues started to become a huge maintenance burden.

Re: mainline kernel [message #50903 is a reply to message #50900] Wed, 27 November 2013 08:31 Go to previous messageGo to next message
pavel.odintsov is currently offline  pavel.odintsov
Messages: 24
Registered: February 2010
Junior Member
Hello, xaxaxa!

You can use 3.8+ kernel, almost all features from OpenVZ it has. There are no plans for supporting mainline kernel (information from developers) but in near future we wait release on RHEL7 kernel.

P.S.
AUFS is so buggy for upstream too.


Re: mainline kernel [message #50907 is a reply to message #50900] Wed, 27 November 2013 22:29 Go to previous messageGo to next message
xaxaxa is currently offline  xaxaxa
Messages: 11
Registered: August 2012
Location: Vancouver, BC
Junior Member
is using vzctl with a mainline (3.x) kernel considered secure? if I create a container, is it reasonable to assume root in the container can't break out?
Re: mainline kernel [message #50911 is a reply to message #50907] Thu, 28 November 2013 09:22 Go to previous message
pavel.odintsov is currently offline  pavel.odintsov
Messages: 24
Registered: February 2010
Junior Member
I tough it's no secure enough for production use but for internal use it's ok.

Previous Topic: Monitoring VE's - Load is important?
Next Topic: vzdump - backup failes, rsync error
Goto Forum:
  


Current Time: Thu May 02 02:01:50 GMT 2024

Total time taken to generate the page: 0.01796 seconds