Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Might be a bug: AllowedCPUs set to a fixed range due to endianness mismatch

オープン
#986 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
go, kubernetes, linux

調査の方向性

sysbox-runc の libcontainer/cgroups/systemd/cpuset_test.go から始め、そのバイトストリーム入力を systemd の cpu-set-util.c における処理と比較します。Kubernetes の static CPU manager 設定と、StartTransientUnit または SetUnitProperties のパスを使用して動作を再現します。systemd デーモンの reload 後も設定した CPU 範囲が正しいままであれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Background

We experienced significant performance degration for workloads running on sysbox after upgrading k8s os system from Ubuntu 20.04 (cgroup v1) to Ubuntu 22.04 (cgroup v2).

Potential Root Cause

  • When creating containers, sysbox writes AllowedCPUs into the transient systemd scope unit and its drop-in via the D-Bus APIs:
    • /run/systemd/transient/crio-<unit>.scope - created via StartTransientUnit
    • /run/systemd/transient/crio-<unit>.scope.d/50-AllowedCPUs.conf - set via SetUnitProperties
  • When building the above D-Bus requests, sysbox packs the CPU range into a byte stream using big-endian ordering.
  • However, based on systemd’s D-Bus CPU mask handling (see cpu-set-util.c), the D-Bus CPU mask representation appears to expect a little-endian byte stream. Using big-endian ordering therefore reverses the byte order and can cause the interpreted CPU range to drift. For example:
# big-endian encoding (current behavior)
CPU Range: 2-5      Bytes: 3c         Actual CPUs: [2 3 4 5]
CPU Range: 6-9      Bytes: 03 c0      Actual CPUs: [0 1 14 15]
CPU Range: 10-13    Bytes: 3c 00      Actual CPUs: [2 3 4 5]
CPU Range: 14-17    Bytes: 03 c0 00   Actual CPUs: [0 1 14 15]

# little-endian encoding (systemd expectation)
CPU Range: 2-5      Bytes: 3c         Actual CPUs: [2 3 4 5]
CPU Range: 6-9      Bytes: c0 03      Actual CPUs: [6 7 8 9]
CPU Range: 10-13    Bytes: 00 3c      Actual CPUs: [10 11 12 13]
CPU Range: 14-17    Bytes: 00 c0 03   Actual CPUs: [14 15 16 17]
  • Only until with cgroup v2, the EffectiveCPUs is constrained by AllowedCPUs(ref) after systemd reloads, which causes significant CPU idling and forces workloads to contend for an overlapping CPU range, resulting in performance degradation.

Direct Proof

Using the sysbox Unit Tests (cpuset_test.go) byte stream as input and the systemd-dbus function to retrieve the actual CPU set, we can observe a drift (see C program). Only when reversing the byte string can we retrieve the correct CPU set.

Reproduce

  1. Enable static cpu manager policy on kubelet
--cpu-cfs-quota=false --cpu-manager-policy=static
  1. Create 3 runners with 4 static CPU each running on sysbox
template:
  metadata:
    annotations:
      io.kubernetes.cri-o.userns-mode: auto:size=65536
  spec:
    runtimeClassName: sysbox-runc
    containers:
      - name: runner-x
        resources:
          limits:
            cpu: "4"
            memory: 256Mi
          requests:
            cpu: "4"
            memory: 256Mi
  1. Get the init state: effective cpu is correctly matched the kubelet setup 10-13
cat /var/lib/kubelet/cpu_manager_state
{"policyName":"static","defaultCpuSet":"0-1,34-63","entries":{"xx":{"runner-1":"2-5","runner-2":"6-9","runner-3":"10-13"}},"checksum":2693667676}

systemctl show crio-<unit>.scope -p EffectiveCPUs,AllowedCPUs
EffectiveCPUs=10-13
AllowedCPUs=2-5

cat /sys/fs/cgroup/kubepods.slice/kubepods-pod<uid>.slice/crio-<unit>.scope/cpuset.cpus
10-13
cat /sys/fs/cgroup/kubepods.slice/kubepods-pod<uid>.slice/crio-<unit>.scope/cpuset.cpus.effective
10-13

# Set by dbus StartTransientUnit
cat /run/systemd/transient/crio-<unit>.scope | grep AllowedCPUs
AllowedCPUs=2-5

# Set by dbus SetUnitProperties
cat /run/systemd/transient/crio-<unit>.scope.d/50-AllowedCPUs.conf  | grep AllowedCPUs
AllowedCPUs=2-5
  1. Trigger a systemd reloads
systemctl daemon-reload
  1. Effective CPU will then drift into the wrong range 2-5
systemctl show crio-<unit>.scope -p EffectiveCPUs,AllowedCPUs
EffectiveCPUs=2-5
AllowedCPUs=2-5

cat /sys/fs/cgroup/kubepods.slice/kubepods-pod<uid>.slice/crio-<unit>.scope/cpuset.cpus
2-5
cat /sys/fs/cgroup/kubepods.slice/kubepods-pod<uid>.slice/crio-<unit>.scope/cpuset.cpus.effective
2-5

Potential Fix

https://github.com/zehongwong/sysbox-runc/pull/1

主要言語
Shell
スター
3.9k
フォーク
230
平均マージ
11時間 18分
マージ済み PR(30日)
2

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

nestybox/sysbox のほかの issue

nestybox/sysbox の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。