Repository navigation
fix: skip the ignore cache only for /init.scope (follow-up to #374) - #376
Merged
Merged
Conversation
There was a problem hiding this comment.
Code Review
This pull request refactors how systemd's /init.scope is detected and handled. It introduces an initScope boolean field and an InitScope() method to the Cgroup struct, allowing the container registry to explicitly check for this scope instead of relying on an empty cgroup ID. This ensures that processes in the root cgroup on hosts without systemd are cached as usual. Additionally, the PR cleans up an ineffective stale PID cleanup block in getOrCreateContainer and updates the unit tests to cover these changes. No review comments were provided, so there is no feedback to address.
blue4209211
approved these changes
Oct 8, 2026
…s skipped #374 stopped caching every pid whose cgroup Id is empty, which covers the root cgroup as well as /init.scope. On hosts without systemd, daemons can run in the root cgroup, and each of their connect, listen and file-open events then re-read /proc/<pid>/cgroup. Cgroup now records whether the process is in /init.scope, and only those pids skip the ignore cache. Also drop the inline cleanup in getOrCreateContainer: it checked the entry it had just written, so it never deleted anything.
mayankpande88
force-pushed
the
fix/init-scope-only
branch
from
October 8, 2026 09:31
e8ac511 to
2c7792c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to the review of #374.
/init.scopeskips the ignore cache. fix: detect systemd units whose start event sees /init.scope #374 stopped caching every process whose cgroup Id is empty, which includes the root cgroup as well as/init.scope. On hosts without systemd, daemons can run in the root cgroup, and each of their connect, listen and file-open events then re-read/proc/<pid>/cgroup.Cgroupnow records whether the process is in/init.scope, and only those pids skip the cache. Root-cgroup processes are cached as they were before fix: detect systemd units whose start event sees /init.scope #374.getOrCreateContainerwrote an entry tocontainersByPidIgnoredand then checked that same entry's age, so it never deleted anything. The periodic sweep already resets the map.The suggested 1–2s TTL wouldn't have worked here: systemd's exec arrives about 20ms after the fork, so it would still hit the cached entry.
Engineering detail
Test: the cgroup test now covers
/init.scopeon cgroup v2,/init.scopein thename=systemdhierarchy of a cgroup v1 hybrid, and the root cgroup. All three parse to an empty Id; only the first two reportInitScope().CI: gofmt, goimports, vet, golangci-lint,
go test(excluding/containers) and the build all pass in a Linux container with Go 1.26.5.Local e2e: I built agent binaries from this branch and from main (which includes #374) and ran both with verbose logging, side by side as systemd services on a local Debian 12 VM (kernel 6.1, systemd 252).
/init.scopepath still works.