cgroup: destroy the cgroup if its setup fails - #2242
Merged
Merged
Conversation
If libcrun_cgroup_enter fails after the cgroup has been created (e.g. setting a resource limit fails because of an invalid value), it returns an error without the cgroup status, so the caller has nothing to destroy and the cgroup is left behind. For example, "crun run" with an invalid CPU period correctly fails, but leaves an empty cgroup, which in turn makes it impossible to remove its parent. Destroy the cgroup in such case. If the cgroup creation itself fails, it is not destroyed, as it might be pre-existing. Found by the "set cpu period with no quota (invalid period)" runc integration test. Signed-off-by: Kir Kolyshkin <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If
libcrun_cgroup_enterfails after the cgroup has been created (e.g. setting a resource limit fails because of an invalid value), it returns an error without the cgroup status, so the caller has nothing to destroy and the cgroup is left behind.For example,
crun runwith an invalid CPU period correctly fails, but leaves an empty cgroup, which in turn makes it impossible to remove its parent.Destroy the cgroup in such case. If the cgroup creation itself fails, it is not destroyed, as it might be pre-existing.
Found by the "set cpu period with no quota (invalid period)" runc integration test (see #2238), with a check added to runc tests that the container cgroup is removed (opencontainers/runc#5455).