runtime-spec icon indicating copy to clipboard operation
runtime-spec copied to clipboard

linux: clarify pids cgroup settings

Open cyphar opened this issue 10 months ago • 0 comments

While the original wording did not provide any justification for this, some runtimes have incorrectly treated a pids.limit value of 0 as being equivalent to "max" or otherwise handle it suboptimally.

So, add some clarifying wording that the correct representation of max is -1 (like every other cgroup configuration) and that users should not treat 0 as a special value of any kind.

Note that a pids.limit value of 0 is actually different to 1 now that CLONE_INTO_CGROUP exists (at the time pids was added to the kernel and the spec, this feature didn't exist and so it may have seemed redundant to have two equivalent values).

Signed-off-by: Aleksa Sarai [email protected]

cyphar avatar Feb 27 '25 01:02 cyphar