Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
L
lxc
Project
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Chen Yisong
lxc
Commits
95ab26af
Unverified
Commit
95ab26af
authored
Feb 17, 2021
by
Christian Brauner
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
cgroups: rework unified controller delegation
Signed-off-by:
Christian Brauner
<
christian.brauner@ubuntu.com
>
parent
e4db08ed
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
37 additions
and
35 deletions
+37
-35
cgfsng.c
src/lxc/cgroups/cgfsng.c
+37
-35
No files found.
src/lxc/cgroups/cgfsng.c
View file @
95ab26af
...
@@ -3185,13 +3185,14 @@ __cgfsng_ops static bool cgfsng_devices_activate(struct cgroup_ops *ops, struct
...
@@ -3185,13 +3185,14 @@ __cgfsng_ops static bool cgfsng_devices_activate(struct cgroup_ops *ops, struct
static
bool
__cgfsng_delegate_controllers
(
struct
cgroup_ops
*
ops
,
const
char
*
cgroup
)
static
bool
__cgfsng_delegate_controllers
(
struct
cgroup_ops
*
ops
,
const
char
*
cgroup
)
{
{
__do_close
int
fd_base
=
-
EBADF
;
__do_close
int
dfd_final
=
-
EBADF
;
__do_free
char
*
add_controllers
=
NULL
,
*
base_path
=
NULL
;
__do_free
char
*
add_controllers
=
NULL
,
*
copy
=
NULL
;
__do_free_string_list
char
**
parts
=
NULL
;
struct
hierarchy
*
unified
=
ops
->
unified
;
struct
hierarchy
*
unified
=
ops
->
unified
;
ssize_t
parts_len
;
int
dfd_cur
=
unified
->
dfd_base
;
char
**
i
t
;
int
re
t
;
size_t
full_len
=
0
;
size_t
full_len
=
0
;
char
*
cur
;
char
**
it
;
if
(
!
ops
->
hierarchies
||
!
pure_unified_layout
(
ops
)
||
if
(
!
ops
->
hierarchies
||
!
pure_unified_layout
(
ops
)
||
!
unified
->
controllers
[
0
])
!
unified
->
controllers
[
0
])
...
@@ -3217,42 +3218,43 @@ static bool __cgfsng_delegate_controllers(struct cgroup_ops *ops, const char *cg
...
@@ -3217,42 +3218,43 @@ static bool __cgfsng_delegate_controllers(struct cgroup_ops *ops, const char *cg
(
void
)
strlcat
(
add_controllers
,
" "
,
full_len
+
1
);
(
void
)
strlcat
(
add_controllers
,
" "
,
full_len
+
1
);
}
}
base_path
=
must_make_path
(
unified
->
mountpoint
,
unified
->
container_base_path
,
NULL
);
copy
=
strdup
(
cgroup
);
fd_base
=
lxc_open_dirfd
(
base_path
);
if
(
!
copy
)
if
(
fd_base
<
0
)
return
false
;
if
(
!
unified_cgroup_fd
(
fd_base
))
return
log_error_errno
(
false
,
EINVAL
,
"File descriptor does not refer to cgroup2 filesystem"
);
parts
=
lxc_string_split
(
cgroup
,
'/'
);
if
(
!
parts
)
return
false
;
return
false
;
parts_len
=
lxc_array_len
((
void
**
)
parts
);
/*
if
(
parts_len
>
0
)
* Placing the write to cgroup.subtree_control before the open() is
parts_len
--
;
* intentional because of the cgroup2 delegation model. It enforces
* that leaf cgroups don't have any controllers enabled for delegation.
for
(
ssize_t
i
=
-
1
;
i
<
parts_len
;
i
++
)
{
*/
int
ret
;
lxc_iterate_parts
(
cur
,
copy
,
"/"
)
{
/*
if
(
i
>=
0
)
{
* Even though we vetted the paths when we parsed the config
int
fd_next
;
* we're paranoid here and check that the path is neither
* absolute nor walks upwards.
*/
if
(
abspath
(
cur
))
return
syserrno_set
(
-
EINVAL
,
"No absolute paths allowed"
);
fd_next
=
open_at
(
fd_base
,
parts
[
i
],
PROTECT_OPATH_DIRECTORY
,
PROTECT_LOOKUP_BENEATH
,
0
);
if
(
strnequal
(
cur
,
".."
,
STRLITERALLEN
(
".."
)))
if
(
fd_next
<
0
)
return
syserrno_set
(
-
EINVAL
,
"No upward walking paths allowed"
);
return
log_error_errno
(
false
,
errno
,
"Failed to open %d(%s)"
,
fd_next
,
parts
[
i
]);
close_prot_errno_move
(
fd_base
,
fd_next
);
}
ret
=
lxc_writeat
(
fd_base
,
"cgroup.subtree_control"
,
add_controllers
,
full_len
);
ret
=
lxc_writeat
(
dfd_cur
,
"cgroup.subtree_control"
,
add_controllers
,
full_len
);
if
(
ret
<
0
)
if
(
ret
<
0
)
return
log_error_errno
(
false
,
errno
,
return
syserrno
(
-
errno
,
"Could not enable
\"
%s
\"
controllers in the unified cgroup %d"
,
add_controllers
,
dfd_cur
);
"Could not enable
\"
%s
\"
controllers in the unified cgroup %d(%s)"
,
add_controllers
,
fd_base
,
(
i
>=
0
)
?
parts
[
i
]
:
unified
->
container_base_path
);
TRACE
(
"Enabled
\"
%s
\"
controllers in the unified cgroup %d"
,
add_controllers
,
dfd_cur
);
TRACE
(
"Enable
\"
%s
\"
controllers in the unified cgroup %d(%s)"
,
dfd_final
=
open_at
(
dfd_cur
,
cur
,
PROTECT_OPATH_DIRECTORY
,
PROTECT_LOOKUP_BENEATH
,
0
);
add_controllers
,
fd_base
,
(
i
>=
0
)
?
parts
[
i
]
:
unified
->
container_base_path
);
if
(
dfd_final
<
0
)
return
syserrno
(
-
errno
,
"Fail to open directory %d(%s)"
,
dfd_cur
,
cur
);
if
(
dfd_cur
!=
unified
->
dfd_base
)
close
(
dfd_cur
);
/*
* Leave dfd_final pointing to the last fd we opened so
* it will be automatically zapped if we return early.
*/
dfd_cur
=
dfd_final
;
}
}
return
true
;
return
true
;
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment