[Devel] [patch rh7 1/2] cgroup: mount -- Disable mounting from inside of VE context

Cyrill Gorcunov gorcunov at virtuozzo.com
Fri May 29 01:13:57 PDT 2015


On Fri, May 29, 2015 at 11:09:41AM +0300, Vladimir Davydov wrote:
> On Tue, May 26, 2015 at 06:00:51PM +0300, Cyrill Gorcunov wrote:
> > Even mounting knowing cgroups (ie ones which already known to VE and
> > been mounted by vzctl or any other tool for containter sake) is not
> > that harmless as it might look like. In particular this introduce
> > additional performance hit. So because we are using bindmount
> > strategy to grant cgorups to VE we don't need to mount it from
> > inside of VE anymore and can simply disable.
> > 
> > Signed-off-by: Cyrill Gorcunov <gorcunov at virtuozzo.com>
> > CC: Vladimir Davydov <vdavydov at virtuozzo.com>
> > CC: Konstantin Khorenko <khorenko at virtuozzo.com>
> > CC: Pavel Emelyanov <xemul at virtuozzo.com>
> > CC: Andrey Vagin <avagin at virtuozzo.com>
> 
> Acked-by: Vladimir Davydov <vdavydov at parallels.com>
> 
> It is worth mentioning that this patch reverts commit 8d96fa6e147c
> ("ve/cgroup: Allow mounting existing cgroups inside container").

Thanks for the note! Kostya, add it please.



More information about the Devel mailing list