Uploaded image for project: 'Container Tools'
  1. Container Tools
  2. RUN-2566

crun uses BPFProgram=device: to configure the devices cgroup

XMLWordPrintable

    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • rhel-container-tools
    • RUN 270, RUN 271, RUN 272, RUN 273, RUN 274

      crun currently uses the systemd d-bus API to set up device cgroups.  Update the runtime to use BPFProgram=device: on cgroup v2 instead to avoid multiple conversions of rules and to express all the rules without the limitations imposed by systemd.  The same generator used for the cgroupfs driver can be used to generate the ebpf.

       

      On cgroup v1 crun will still use the current implementation, but it should not matter because cgroup v1 support is going to be dropped this year.

              kolyshkin Kirill Kolyshkin
              gscrivan@redhat.com Giuseppe Scrivano
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: