17 ms·
Clear Linux Project
- kbenson 11y agoHow they purport to do packaging is interesting, but I'm not sure it will work well in the end. Having "bundles" that contain immutable sets of packages sounds good from a stability point of view, but unless they are entirely self contained, you'll undoubtedly run into a library that you need to updated for one bundle that then forces you to update another entire bundle. If each bundle is entirely self contained (allowing it to have it's own set of libraries), you're essentially recreating what's a static binary through package semantics. This comes with the usual downsides of static binaries. I'm interested in seeing it tried though. The learning is in the doing.
- drewg123 11y agoSelf contained packages are not a new idea. For example, PC-BSD has been doing this for years, via their PBI package format. See the description of PBI here: http://www.pcbsd.org/en/package-management http://www.pcbsd.org/en/package-management I think PBI does de-duplication at the package manager level by manipulating hard-links to common files, rather than installing multiple copies.
- kbenson 11y agoSelf contained packages are not the problem, individualized libraries shipped along with those packages are. How does PBI handle minor library version differences then? If one package provides and uses mylib-1.3.1 and another provides and uses mylib-1.3.5, how is that distinguished as the core library level (the plain .so file)? My understanding of what Clear Linux is attempting allows this level of granularity to ensure a package (really an amalgamation of individual packages in the sense of most current unixy distros) is functional and updated as a whole.
- drewg123 11y agoI believe that PBI works the same way. It allows different packages to independently use multiple versions of the same lib simultaneously. There is deduplication via hardlinks ONLY when the checksums match. That's what made it attractive to me: I've painted myself into a corner several times when trying to install Ubuntu PPAs that want conflicting versions of shared libs
- tracker1 11y agoI'm almost of the mindset that just having userspace apps as lxc containers with everything an app needs may be better for the most-used applications... Given how relatively cheap even fairly big SSDs are, is it really worth the storage savings for your browser to share a couple .so files with your mp3 player? I actually like how PC-BSD pbi packages work... given the number of times solutions have been made to work around the issue and reduce space... I'm not sure it's always worth it. At least not in the desktop space.
- kbenson 11y agoImagine the problem of tracking down all the different versions of a library when an exploit is found. If you have 20, or even 50 different apps that bundled openssl, imagine the hassle of making sure each one was vetted and updated as needed, not to mention the delay in getting all the different packages rebuilt and pushed (which may be a small delay, or may not, depending on the vendor).
- tracker1 11y agoYou regularly use 20 or 50 end-user applications that use openssl? I'm not talking the low-level OS applications here... I'm talking end-user applications and major exposed services. For that matter, each of those applications needs to be updated, vetted and packaged... it's a matter of the level and completeness of packages.
- kbenson 11y agoWhat's considered an end user application? Installed languages (Perl, Python, Ruby, etc)? Would you consider all of regular userspace one "app", or split it into multiple chunks (dev tools, web tools, etc)? Wget, curl and chrome all use openssl. smtpd? httpd? sqld? sshd? ntpd? This may be illuminating, it's the list of RPMs that have a requirement containing the string ssl: # for RPM in `rpm -aq --qf '%{NAME}\n'`; do rpm -qR $RPM | grep -iq ssl && echo -n "$RPM "; done python-ldap libssh2 mailx Percona-Server-server-55 abrt-addon-ccpp libfprint qpid-cpp-client-ssl perl-Crypt-SSLeay ntp httpd-tools openssh openssl-devel pam_mysql redhat-lsb-core Percona-Server-client-55 sssd-common perl-IO-Socket-SSL qt squid openssl098e elinks ipa-python python-nss compat-openldap Percona-Server-shared-55 systemtap-runtime perl-Net-SSLeay python-libs Percona-Server-shared-compat openssl systemtap-client qpid-cpp-server-ssl certmonger python-urllib3 openssh-server nss_compat_ossl openldap percona-toolkit pyOpenSSL git sssd-common-pac wget ntpdate openssh-clients openssl systemtap-devel postfix nss-tools perl-DBD-MySQL libcurl curl sssd-proxy libesmtp That's just for SSL, which while it's used in many applications and services, generally is limited to items that communicate externally, for the most part. What about when it's a core library that everything uses? tzdata updates often... We want correct time representations, right? Gzip is used by a lot of applications. What about glibc? It's not an easy problem, but that's why I'm interested in how it turns out.
- derefr 11y ago> I think PBI does de-duplication at the package manager level by manipulating hard-links to common files, rather than installing multiple copies. Which is, itself, a bad reinvention of Plan 9's Venti filesystem. Having one, or two, or a million files on disk containing the same data should take up as much space as having just one. "Hard links" are a policy-level way to express shared mutability; deduplication of backing storage, meanwhile, should be a mechanism-level implementation detail.
- FooBarWidget 11y agoWell, there is something to be said for the 'worse is better' approach.
- chongli 11y agoZFS has support for block-level deduplication and it comes with heavy memory and performance requirements. File-level deduplication with hard links is lightweight and requires no special support (besides a filesystem which supports hard links, obviously).
- tbronchain 11y agoIf they are micro-vms, container-style, I don't think they will have such need to share any library? -in theory, at least- .. I mean, it is possible to completely isolate them, all. It may end-up very heavy though, but, and I can be wrong on this, with the constant growth of storage capacities, network bandwidth, RAM capacity, and the progress made to lighten "containers", I don't think this "heavy" downside I see of immutable infrastructures will be a real issue in the future.
- kbenson 11y agoNo, but identifying which of your 20 micro-VMs is susceptible to the next OpenSSL exploit, and rolling out the fixes may be. It's both simpler in some aspects and more complex in others to lave local library versions for every app/service. Managing service prerequisites becomes easy and managing service feature updates becomes easier than it was, but managing service security updates becomes more complex. Juggling these different needs and capabilities is where it gets interesting.
- tbronchain 11y agoI got your point. I guess it just lead to a turning point, where end-users won't have to worry about security updates for x or y library, but more about updating the application they're using. In the case you use containers/micro-vms, if there is a security update to do, the container "maintainer" would be in charge to push the security update, then you just need to update your container. I'm not sure which one is the most constraining, dealing with conflicts or being careful on relating on well maintained "containers". I guess, for production environments, the second option looks like a wise choice.
- Merkur 11y agoI didn't find very mutch information about it.. yet. :( anyone played with it?
- zxcvcxz 11y agoDownload link didn't work for me in firefox for some reason, had to paste the link: https://download.clearlinux.org/ https://download.clearlinux.org/
- Merkur 11y agoLWN got an article about it... https://lwn.net/Articles/644675/ https://lwn.net/Articles/644675/
- 4ad 11y agoPublic link: http://lwn.net/SubscriberLink/644675/5be656c24083e53b/ http://lwn.net/SubscriberLink/644675/5be656c24083e53b/
- Merkur 11y agothx!
- zatkin 11y agoIs it bad to send an LWN Subscriber link to a large number of people? Will they get upset? They mention that they'll remove the feature if it gets abused.
- deleted 11y ago[deleted]
- leni536 11y agoRelevant discussion: https://news.ycombinator.com/item?id=9153832 https://news.ycombinator.com/item?id=9153832
- bboreham 11y agoFrom https://lwn.net/op/FAQ.lwn#slinks https://lwn.net/op/FAQ.lwn#slinks: "Where is it appropriate to post a subscriber link? Almost anywhere. Private mail, messages to project mailing lists, and blog entries are all appropriate. As long as people do not use subscriber links as a way to defeat our attempts to gain subscribers, we are happy to see them shared."
- mbrzusto 11y agoi wonder if it builds with icc? seems like a matter of pride they should get that working.
- pyvpx 11y agothat was my first guess at "how'd they make it faster?" icc is sometimes a shockingly better (read: compiled code that is faster) compiler.
- smegel 11y agoI am surprised they didn't go down the container route for OS updates like CoreOS. I think I like that approach.
- philips 11y agoThis does use containers and in fact they have some interesting modifications that they have made to the rkt container runtime to use KVM isolation instead of just namespaces and cgroups. See a link in 4ad's comment for an LWN article. Those modifications are exciting for me as one of the developers of rkt. We built rkt with this concept of "stages"[1] where the rkt stage1 here is being swapped out from the default which uses "Linux containers" and instead executing lkvm. In this case the Clear Containers team was able to swap out the stage1 with some fairly minimal code changes to rkt which are going upstream. Cool stuff! [1] https://github.com/coreos/rkt/blob/master/Documentation/devel/architecture.md https://github.com/coreos/rkt/blob/master/Documentation/deve...
- dbbolton 11y agoAfter reading the overview and features, I'm left wondering: * what tangible benefits would I get from using Clear Linux over my own heavily customized/handrolled linux server? * how does the update system handle breakage/conflicts? * are any of Intel's changes likely to make it into other existing distros or kernels?
- ramidarigaz 11y agoThis was linked elsewhere in the comments. I think it answers some of your questions: http://lwn.net/SubscriberLink/644675/5be656c24083e53b/ http://lwn.net/SubscriberLink/644675/5be656c24083e53b/
- zobzu 11y agoI just tried it. it is fast. its a VM really, but packaged like a container. On my laptop, it starts about as fast as a Docker container, ie less than a second. This is quite impressive.
- zymhan 11y agoI'm not so sure that running a container is directly analagous to using it in a VM.
- stephen-mw 11y agoWhen using something like LXD I can barely tell the difference.
- zobzu 11y agoWhile namespacing allows you to do various things, most container setups are vm-replacements, running either full OS or not, they're used for the same purpose in the end (ie resources separation)
- Alupis 11y ago> most container setups are vm-replacements, running either full OS or not, they're used for the same purpose in the end (ie resources separation) No they are not. A VM is a completely different system, while a container is a packaged application. VM's provide an awful lot more than just resource separation... security and isolation being at the top of the list. The problem we see here is an awful lot of people think a container is a drop-in replacement for a VM, when it is usually not.
- buster 11y ago> No they are not. A VM is a completely different system, while a container is a packaged application. I think you have a misunderstanding of terms here, possibly confused by all the fuzz around Docker. A container is nothing more then a virtualization technology on OS level[1]. What you are talking about is something like rkt, which is how to run an app inside a container[2]. From the point of your app there is no difference between a VM, OpenVZ or LXC. [1] https://en.wikipedia.org/wiki/Operating-system-level_virtualization https://en.wikipedia.org/wiki/Operating-system-level_virtual... [2] https://github.com/coreos/rkt/blob/master/Documentation/app-container.md https://github.com/coreos/rkt/blob/master/Documentation/app-...
- Thaxll 11y agoI just tried on my desktop, woot it's super fast! [ 0.000000] KERNEL supported cpus: [ 0.000000] Intel GenuineIntel [ 0.000000] e820: BIOS-provided physical RAM map: ... [ 1.245851] calling fuse_init+0x0/0x1b6 [fuse] @ 1 [ 1.245853] fuse init (API version 7.23) [ 1.246299] initcall fuse_init+0x0/0x1b6 [fuse] returned 0 after 431 usecs
- voltagex_ 11y agoAnyone know what they might be doing for the speed increase?
- graycoder 11y agoSeeing as it's Intel I might guess that they either have extra instructions in the instruction set they know about or other optimizations that they know to look for. Seeing as they only support 4th generation and E5 v3... it wouldn't surprise me.
- n3mes1s 11y agoread the hypervisor part of the lwn article: https://lwn.net/SubscriberLink/644675/5be656c24083e53b/ https://lwn.net/SubscriberLink/644675/5be656c24083e53b/ quote: "With kvmtool, we no longer need a BIOS or UEFI; instead we can jump directly into the Linux kernel. Kvmtool is not cost-free, of course; starting kvmtool and creating the CPU contexts takes approximately 30 milliseconds."
- drewg123 11y agoOne issue where "pure" containers have an advantage over VMs is IO. For network intensive workloads, there is a choice between the efficiency of SR-IOV and the control & manageability of a virtual NIC like virtio-net. In order to get efficiency, you need to use SR-IOV, which (the last time I checked) still made lots of admins nervous when running untrusted guests. Sure, the guest could be isolated from internal resources via a vlan, but it could still be launching malicious code onto the internet, and it may be difficult to track its traffic for billing purposes, especially if you want to differentiate between external & internal traffic. SR-IOV NICs also have limited number of queues and VFs, so it is hard to over-commit servers. So in order to maintain control of guests, you end up doubling the kernel overhead by using a virtual NIC (eg, virtio-net) in the VM and a physical NIC in the hypervisor. Now you have twice the overhead, twice the packet pushing, more memory copies, VM exits, etc. The nice thing about containers is that there is no need to choose. You get the efficiency of running just a single kernel, along with all the accounting and firewalling rules to maintain control & be able to bill the guest.
- justincormack 11y agoSR-IOV should not really make you nervous, it uses the iommu. Billing might have some issues I guess. There are higher performance virtual network setups eg see http://www.virtualopensystems.com/en/solutions/guides/snabbswitch-qemu/ http://www.virtualopensystems.com/en/solutions/guides/snabbs... Container networking has overheads, the virtual network pairs and the natting is not costless at all, and most people with network intensive applications are allocating physical interfaces to containers anyway.
- mrmondo 11y agoCorrect me if I'm wrong but shouldn't 'Cloud' have a lower case C if it's not a product?
- frozenport 11y agoWould be cool if it built with ICC, like the old Linux DNA project.
- Meai 11y agoI dont quite understand what this is: Is it a linux distribution that can have a graphical interface like Gnome 3? My question is essentially: Is it more like Ubuntu or more like Docker?
- oldsj 11y agoMore like CoreOS
- jcoffland 11y agoJust what we need a Linux distro who's main goal is apparently to promote Intel products. The language used to describe it makes this quite clear. "The goal of Clear Linux OS, is to showcase the best of Intel Architecture technology...". This is a blatent attempt to exclude ARM who is gaining Linux market share. Whatever innovation they might bring to the table, I will avoid it purely on the basis that its aim is to benefit Intel rather than the user. Dot org my ass.
- kasabali 11y agoThe site is weak but you should check the LWN link given in this thread. They have done some cool stuff actually.
- vidarh 11y agoI don't think they really expect you to want to use it directly. As it says, it's a showcase. But a lot of the technology might make it into other distros in more generic forms.
- digi_owl 11y agoNot the first time Intel does this. Moblin was started because MS balked at making Windows for a Intel chip that didn't offer PCI enumeration.
- lqdc13 11y agoUnless I am not getting something, are the developers expected to manually compile everything that isn't in a bundle? And then recompile again whenever a bundle gets updated?
- rgborn 11y agoWould very much like to see a comparison of Clear Containers and LXD. Would also like to know why Intel decided to do their own thing and not just help with the LXD project.