cgroup: refuse to run in a frozen cgroup - #2243
Merged
Merged
Conversation
If the container cgroup already exists and is frozen, the container process cannot make any progress, and crun run/create hangs forever, with no indication of what is going on. Refuse to use a frozen cgroup, like runc does. With cgroupfs, check it before the container process is put into the cgroup (for cgroup v2, it is created right in it by clone3 with CLONE_INTO_CGROUP). With systemd, the cgroup path is only known after the scope is created, so check it right after that. Check the scope cgroup itself, not the sub-cgroup created by crun inside it, as the latter is not frozen on its own. Found by the "runc run/create should refuse pre-existing frozen cgroup" runc integration test. Signed-off-by: Kir Kolyshkin <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If the container cgroup already exists and is frozen, the container process cannot make any progress, and
crun run/crun createhangs forever, with no indication of what is going on.Refuse to use a frozen cgroup, like runc does:
CLONE_INTO_CGROUP, so the check must happen before that);The error message is the same as in runc:
container's cgroup unexpectedly frozen.Found by the "runc run/create should refuse pre-existing frozen cgroup" runc integration test (see #2238; the test also needed a fix for systemd, see opencontainers/runc#5455).