Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions cgroup/cgroup_test.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
package cgroup

import (
"os"
"path"
"testing"

Expand Down Expand Up @@ -236,3 +237,17 @@ func TestContainerByCgroup(t *testing.T) {
as.Equal("ba7b10d15d16e10e3de7a2dcd408a3d971169ae303f46cfad4c5453c6326fee2", id)
as.Nil(err)
}

// The registry relies on a process in systemd's /init.scope, or in the root
// cgroup, having an empty Id: it is not cached as ignored, so its exec after
// systemd moves it to a unit's cgroup is seen.
func TestInitScopeAndRootHaveEmptyId(t *testing.T) {
for _, content := range []string{"0::/init.scope\n", "0::/\n"} {
f := path.Join(t.TempDir(), "cgroup")
require.NoError(t, os.WriteFile(f, []byte(content), 0644))
cg, err := NewFromProcessCgroupFile(f)
require.NoError(t, err)
assert.Equal(t, "", cg.Id, content)
assert.Equal(t, ContainerTypeStandaloneProcess, cg.ContainerType, content)
}
}
7 changes: 6 additions & 1 deletion containers/registry.go
Original file line number Diff line number Diff line change
Expand Up @@ -640,7 +640,12 @@ func (r *Registry) getOrCreateContainer(pid uint32) *Container {
}
id := calcId(cg, md)
if id == "" {
if cg.Id == "/init.scope" && pid != 1 {
// systemd forks a unit's process inside its own /init.scope and
// moves it to the unit's cgroup before exec. Caching the pid as
// ignored here would drop that exec, and a unit that does nothing
// else would never be detected. /init.scope and the root cgroup
// both parse to an empty Id (cgroup.go skips them).
if cg.Id == "" && pid != 1 {
klog.V(5).InfoS("ignoring without persisting", "cg", cg.Id, "pid", pid)
} else {
klog.V(5).InfoS("ignoring", "cg", cg.Id, "pid", pid)
Expand Down
Loading