Skip to content

fix: skip the ignore cache only for /init.scope (follow-up to #374) - #376

Merged
mayankpande88 merged 1 commit into
mainfrom
fix/init-scope-only
Oct 8, 2026
Merged

mayankpande88 merged 1 commit into
mainfrom
fix/init-scope-only

Conversation

@mayankpande88

Copy link
Copy Markdown
Contributor

Summary

Follow-up to the review of #374.

  • Only /init.scope skips the ignore cache. fix: detect systemd units whose start event sees /init.scope #374 stopped caching every process whose cgroup Id is empty, which includes the root cgroup as well as /init.scope. On hosts without systemd, daemons can run in the root cgroup, and each of their connect, listen and file-open events then re-read /proc/<pid>/cgroup. Cgroup now records whether the process is in /init.scope, and only those pids skip the cache. Root-cgroup processes are cached as they were before fix: detect systemd units whose start event sees /init.scope #374.
  • Remove a no-op cleanup. getOrCreateContainer wrote an entry to containersByPidIgnored and then checked that same entry's age, so it never deleted anything. The periodic sweep already resets the map.

The suggested 1–2s TTL wouldn't have worked here: systemd's exec arrives about 20ms after the fork, so it would still hit the cached entry.

Engineering detail

Test: the cgroup test now covers /init.scope on cgroup v2, /init.scope in the name=systemd hierarchy of a cgroup v1 hybrid, and the root cgroup. All three parse to an empty Id; only the first two report InitScope().

CI: gofmt, goimports, vet, golangci-lint, go test (excluding /containers) and the build all pass in a Linux container with Go 1.26.5.

Local e2e: I built agent binaries from this branch and from main (which includes #374) and ran both with verbose logging, side by side as systemd services on a local Debian 12 VM (kernel 6.1, systemd 252).

  • Root-cgroup process: a long-lived process moved into the root cgroup made about 20 HTTP requests per second for 30s. This branch logged "ignoring" for it once and cached it. Main logged "ignoring without persisting" for it 38 times, once per event.
  • New units: both builds detected 10/10 transient systemd units, so the /init.scope path still works.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors how systemd's /init.scope is detected and handled. It introduces an initScope boolean field and an InitScope() method to the Cgroup struct, allowing the container registry to explicitly check for this scope instead of relying on an empty cgroup ID. This ensures that processes in the root cgroup on hosts without systemd are cached as usual. Additionally, the PR cleans up an ineffective stale PID cleanup block in getOrCreateContainer and updates the unit tests to cover these changes. No review comments were provided, so there is no feedback to address.

…s skipped

#374 stopped caching every pid whose cgroup Id is empty, which covers
the root cgroup as well as /init.scope. On hosts without systemd,
daemons can run in the root cgroup, and each of their connect, listen
and file-open events then re-read /proc/<pid>/cgroup. Cgroup now records
whether the process is in /init.scope, and only those pids skip the
ignore cache. Also drop the inline cleanup in getOrCreateContainer: it
checked the entry it had just written, so it never deleted anything.
@mayankpande88
mayankpande88 merged commit 1456580 into main Oct 8, 2026
7 checks passed
@mayankpande88
mayankpande88 deleted the fix/init-scope-only branch October 8, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants