From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Stefan Agner Date: Thu, 3 Mar 2022 15:43:10 +0100 Subject: [PATCH] Implement Device Resources updates Add support to update Device Resources with runc update. Signed-off-by: Stefan Agner --- libcontainer/specconv/spec_linux.go | 4 ++-- update.go | 26 +++++++++++++++++++------- 2 files changed, 21 insertions(+), 9 deletions(-) diff --git a/libcontainer/specconv/spec_linux.go b/libcontainer/specconv/spec_linux.go index 5aafa2ef..999f8b48 100644 --- a/libcontainer/specconv/spec_linux.go +++ b/libcontainer/specconv/spec_linux.go @@ -436,7 +436,7 @@ func CreateLibcontainerConfig(opts *CreateOpts) (*configs.Config, error) { return nil, err } - defaultAllowedDevices := createDefaultDevicesCgroups(config) + defaultAllowedDevices := CreateDefaultDevicesCgroups(config) c, err := CreateCgroupConfig(opts, defaultAllowedDevices) if err != nil { @@ -1104,7 +1104,7 @@ next: return nil } -func createDefaultDevicesCgroups(config *configs.Config) []*devices.Device { +func CreateDefaultDevicesCgroups(config *configs.Config) []*devices.Device { defaultAllowedDevices := []*devices.Device{} next: for _, ad := range AllowedDevices { diff --git a/update.go b/update.go index 11a15718..5e9f89b5 100644 --- a/update.go +++ b/update.go @@ -13,6 +13,7 @@ import ( "github.com/docker/go-units" "github.com/opencontainers/runc/libcontainer/intelrdt" + "github.com/opencontainers/runc/libcontainer/specconv" "github.com/opencontainers/runtime-spec/specs-go" "github.com/urfave/cli" ) @@ -358,6 +359,24 @@ other options are ignored. config.Cgroups.Resources.PidsLimit = r.Pids.Limit config.Cgroups.Resources.Unified = r.Unified + if len(r.Devices) > 0 { + config.Cgroups.Resources.Devices = nil + defaultAllowedDevices := specconv.CreateDefaultDevicesCgroups(&config) + + err = specconv.CreateCgroupDeviceConfig(config.Cgroups.Resources, &r, defaultAllowedDevices) + if err != nil { + return err + } + config.Cgroups.SkipDevices = false + } else { + // If "runc update" is not changing device configuration, add + // this to skip device update. + // This helps in case an extra plugin (nvidia GPU) applies some + // configuration on top of what runc does. + // Note this field is not saved into container's state.json. + config.Cgroups.SkipDevices = true + } + // Update Intel RDT l3CacheSchema := context.String("l3-cache-schema") memBwSchema := context.String("mem-bw-schema") @@ -385,13 +404,6 @@ other options are ignored. } } - // XXX(kolyshkin@): currently "runc update" is unable to change - // device configuration, so add this to skip device update. - // This helps in case an extra plugin (nvidia GPU) applies some - // configuration on top of what runc does. - // Note this field is not saved into container's state.json. - config.Cgroups.SkipDevices = true - return container.Set(config) }, }