-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Commit
Go 1.23 tightens access to internal symbols, and even puts runc into "hall of shame" for using an internal symbol (recently added by commit da68c8e). So, while not impossible, it becomes harder to access those internal symbols, and it is a bad idea in general. Assuming Go 1.23 comes with https://go.dev/cl/588076, we can clean the internal rlimit cache by setting the RLIMIT_NOFILE for ourselves, essentially disabling the rlimit cache. NOTE this also relies on golang.org/x/sys/unix having https://go.dev/cl/476695. Signed-off-by: Kir Kolyshkin <[email protected]>
- Loading branch information
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
//go:build !go1.23 | ||
|
||
package system | ||
|
||
import ( | ||
"sync/atomic" | ||
"syscall" | ||
|
||
"golang.org/x/sys/unix" | ||
) | ||
|
||
//go:linkname syscallOrigRlimitNofile syscall.origRlimitNofile | ||
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / compile-buildtags
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / cross-i386 (runc_nodmz)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / cross-i386
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.21.x, rootless)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.21.x)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.20.x)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x, rootless, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x, runc_nodmz)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / lint
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / lint
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / lint
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / lint
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.20.x, rootless)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.21.x, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.20.x, rootless, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.20.x, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.21.x, rootless, -race)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.21.x, criu-dev)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (actuated-arm64-6cpu-8gb, 1.21.x)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x, rootless)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-22.04, 1.21.x, criu-dev)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (actuated-arm64-6cpu-8gb, 1.21.x, rootless)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.20.x)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.20.x, rootless)
Check failure on line 12 in libcontainer/system/rlimit_linux_go122.go GitHub Actions / test (ubuntu-20.04, 1.20.x, rootless, -race)
|
||
var syscallOrigRlimitNofile atomic.Pointer[syscall.Rlimit] | ||
|
||
// ClearRlimitNofileCache clears go runtime's nofile rlimit cache. | ||
// The argument is process RLIMIT_NOFILE values. | ||
func ClearRlimitNofileCache(_ *unix.Rlimit) { | ||
// As reported in issue #4195, the new version of go runtime(since 1.19) | ||
// will cache rlimit-nofile. Before executing execve, the rlimit-nofile | ||
// of the process will be restored with the cache. In runc, this will | ||
// cause the rlimit-nofile setting by the parent process for the container | ||
// to become invalid. It can be solved by clearing this cache. But | ||
// unfortunately, go stdlib doesn't provide such function, so we need to | ||
// link to the private var `origRlimitNofile` in package syscall to hack. | ||
syscallOrigRlimitNofile.Store(nil) | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
//go:build go1.23 | ||
|
||
package system | ||
|
||
import ( | ||
"sync/atomic" | ||
"syscall" | ||
|
||
"golang.org/x/sys/unix" | ||
) | ||
|
||
// CleanRlimitNofileCache sets RLIMIT_NOFILE for the current process. This is | ||
// not needed per se, but rather to clean the origRlimitNofile cache in Go. | ||
// | ||
// The implementation relies on go.dev/cl/588076. | ||
func ClearRlimitNofileCache(lim *unix.Rlimit) { | ||
// Ignore the return values since we only need to clean the cache, | ||
// the limit is going to be set via unix.Prlimit elsewhere. | ||
_ = syscall.Setrlimit(syscall.RLIMIT_NOFILE, lim) | ||
} |