193f9894c0
We now have one place that keeps track of (most) devices that are allowed and created within the container. That place is pkg/libcontainer/devices/devices.go This fixes several inconsistencies between which devices were created in the lxc backend and the native backend. It also fixes inconsistencies between wich devices were created and which were allowed. For example, /dev/full was being created but it was not allowed within the cgroup. It also declares the file modes and permissions of the default devices, rather than copying them from the host. This is in line with docker's philosphy of not being host dependent. Docker-DCO-1.1-Signed-off-by: Timothy Hobbs <timothyhobbs@seznam.cz> (github: https://github.com/timthelion)
33 lines
1.7 KiB
Go
33 lines
1.7 KiB
Go
package cgroups
|
|
|
|
import (
|
|
"errors"
|
|
|
|
"github.com/dotcloud/docker/pkg/libcontainer/devices"
|
|
)
|
|
|
|
var (
|
|
ErrNotFound = errors.New("mountpoint not found")
|
|
)
|
|
|
|
type Cgroup struct {
|
|
Name string `json:"name,omitempty"`
|
|
Parent string `json:"parent,omitempty"` // name of parent cgroup or slice
|
|
|
|
AllowAllDevices bool `json:"allow_all_devices,omitempty"` // If this is true allow access to any kind of device within the container. If false, allow access only to devices explicitly listed in the allowed_devices list.
|
|
AllowedDevices []devices.Device `json:"allowed_devices,omitempty"`
|
|
Memory int64 `json:"memory,omitempty"` // Memory limit (in bytes)
|
|
MemoryReservation int64 `json:"memory_reservation,omitempty"` // Memory reservation or soft_limit (in bytes)
|
|
MemorySwap int64 `json:"memory_swap,omitempty"` // Total memory usage (memory + swap); set `-1' to disable swap
|
|
CpuShares int64 `json:"cpu_shares,omitempty"` // CPU shares (relative weight vs. other containers)
|
|
CpuQuota int64 `json:"cpu_quota,omitempty"` // CPU hardcap limit (in usecs). Allowed cpu time in a given period.
|
|
CpuPeriod int64 `json:"cpu_period,omitempty"` // CPU period to be used for hardcapping (in usecs). 0 to use system default.
|
|
CpusetCpus string `json:"cpuset_cpus,omitempty"` // CPU to use
|
|
Freezer string `json:"freezer,omitempty"` // set the freeze value for the process
|
|
|
|
Slice string `json:"slice,omitempty"` // Parent slice to use for systemd
|
|
}
|
|
|
|
type ActiveCgroup interface {
|
|
Cleanup() error
|
|
}
|