Skip to content

Delegate sandbox process cgroups at startup - #612

Merged
SaladDay merged 1 commit into
aos/cutoverfrom
aos/delegate-sandbox-process-cgroups
Oct 9, 2026
Merged

SaladDay merged 1 commit into
aos/cutoverfrom
aos/delegate-sandbox-process-cgroups

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

SandboxIO starts without writable cgroup delegation, preventing it from containing descendants that create new POSIX sessions. Prepare a dedicated cgroup beneath the existing guest resource hierarchy in the E2B and microsandbox startup adapters, then start the service as UID/GID 1000 within it. Unavailable delegation or an existing group fails startup; checkpoint restore keeps its existing VM state.

Validation: both real bootstrap paths exercised against nested Linux cgroups in disposable containers, including unprivileged child creation/migration, detached-descendant kill and empty-group cleanup; E2B startup failure regressions, both micro modules, build/vet and documentation checks pass. Actual micro guest prerequisites were probed separately. Final native qualification with the new ProcessService remains part of the integrated cancellation work; this change supplies provisioning only.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay force-pushed the aos/delegate-sandbox-process-cgroups branch from e4a613d to 69cd48b Compare October 9, 2026 08:27
@SaladDay
SaladDay merged commit 87e3360 into aos/cutover Oct 9, 2026
17 checks passed
@SaladDay
SaladDay deleted the aos/delegate-sandbox-process-cgroups branch October 9, 2026 08:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant