Skip to content

Commit

Permalink
util: vircgroupv2: stop enabling missing controllers with systemd
Browse files Browse the repository at this point in the history
Because of a systemd delegation policy [1] we should not write to any
cgroups files owned by systemd which in case of cgroups v2 includes
'cgroups.subtree_control'.

systemd will enable controllers automatically for us to have them
available for VM cgroups.

[1] <https://github.com/systemd/systemd/blob/master/docs/CGROUP_DELEGATION.md>

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
  • Loading branch information
phrdina committed Jun 28, 2019
1 parent d117431 commit 62dd4d2
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 1 deletion.
2 changes: 1 addition & 1 deletion src/util/vircgroup.c
Expand Up @@ -1082,7 +1082,7 @@ virCgroupEnableMissingControllers(char *path,
&tmp) < 0)
goto cleanup;

if (virCgroupMakeGroup(parent, tmp, true, VIR_CGROUP_NONE) < 0) {
if (virCgroupMakeGroup(parent, tmp, true, VIR_CGROUP_SYSTEMD) < 0) {
virCgroupFree(&tmp);
goto cleanup;
}
Expand Down
3 changes: 3 additions & 0 deletions src/util/vircgroupbackend.h
Expand Up @@ -34,6 +34,9 @@ typedef enum {
* attaching tasks
*/
VIR_CGROUP_THREAD = 1 << 1, /* cgroup v2 handles threads differently */
VIR_CGROUP_SYSTEMD = 1 << 2, /* with systemd and cgroups v2 we cannot
* manually enable controllers that systemd
* doesn't know how to delegate */
} virCgroupBackendFlags;

typedef enum {
Expand Down
5 changes: 5 additions & 0 deletions src/util/vircgroupv2.c
Expand Up @@ -395,6 +395,11 @@ virCgroupV2MakeGroup(virCgroupPtr parent ATTRIBUTE_UNUSED,
VIR_AUTOFREE(char *) path = NULL;
int controller;

if (flags & VIR_CGROUP_SYSTEMD) {
VIR_DEBUG("Running with systemd so we should not create cgroups ourselves.");
return 0;
}

VIR_DEBUG("Make group %s", group->path);

controller = virCgroupV2GetAnyController(group);
Expand Down

0 comments on commit 62dd4d2

Please sign in to comment.