the cgroups experimental feature does not work properly without this because we do not stop subdaemons when the main daemon is shut down. systemd needs the assigned cgroups to be empty to restart the daemon and thus cannot cleanly restart the daemon if any connections exist. starting a fresh unit for each connection creates a new cgroup every time instead of sharing any delegations and thus solves the problem. fixes #1030 Change-Id: Id6c458aad30eaa08c3609ac8280a7dde8e8f3cf9
52 lines
1.7 KiB
Nix
52 lines
1.7 KiB
Nix
{ nixpkgs, ... }:
|
|
|
|
{
|
|
name = "cgroups";
|
|
|
|
nodes =
|
|
{
|
|
host =
|
|
{ config, pkgs, ... }:
|
|
{ virtualisation.additionalPaths = [ pkgs.stdenvNoCC ];
|
|
nix.extraOptions =
|
|
''
|
|
extra-experimental-features = nix-command auto-allocate-uids cgroups
|
|
extra-system-features = uid-range
|
|
'';
|
|
nix.settings = {
|
|
download-attempts = 1;
|
|
use-cgroups = true;
|
|
};
|
|
nix.nixPath = [ "nixpkgs=${nixpkgs}" ];
|
|
};
|
|
};
|
|
|
|
testScript = { nodes }: ''
|
|
start_all()
|
|
|
|
host.wait_for_unit("multi-user.target")
|
|
|
|
# Start build in background
|
|
host.execute("nix build --use-cgroups --auto-allocate-uids --file ${./hang.nix} >&2 &")
|
|
pid = int(host.succeed("pgrep nix"))
|
|
service = "/sys/fs/cgroup/system.slice/system-nix\\\\x2ddaemon.slice/nix-daemon@*.service"
|
|
|
|
# Wait for cgroups to be created
|
|
host.succeed(f"until [ -e {service}/supervisor ]; do sleep 1; done", timeout=30)
|
|
host.succeed(f"until [ -e {service}/nix-build-uid-* ]; do sleep 1; done", timeout=30)
|
|
|
|
# Check that there aren't processes where there shouldn't be, and that there are where there should be
|
|
host.succeed(f'[ -z "$(cat {service}/cgroup.procs)" ]')
|
|
host.succeed(f'[ -n "$(cat {service}/supervisor/cgroup.procs)" ]')
|
|
host.succeed(f'[ -n "$(cat {service}/nix-build-uid-*/cgroup.procs)" ]')
|
|
|
|
# Perform an interrupt
|
|
host.execute(f"kill -SIGINT {pid}")
|
|
|
|
# Check that there aren't any cgroups anymore, neither any state records
|
|
host.succeed(f"until [ ! -e {service}/nix-build-uid-* ]; do sleep 1; done", timeout=30)
|
|
host.succeed("until [ ! -e /nix/var/nix/cgroups/nix-build-uid-* ]; do sleep 1; done", timeout=30)
|
|
'';
|
|
|
|
}
|