+ except:
+ print "Error assigning resources: %s"%slice_name
+ exit(1)
+
+ try:
+ open('/sys/fs/cgroup/cpuacct/system/libvirtd.service/libvirt/lxc/%s/tasks'%slice_name,'w').write(str(os.getpid()))
+ except:
+ print "Error assigning cpuacct: %s" % slice_name
+ exit(1)
+
+ # If the slice is frozen, then we'll get an EBUSY when trying to write to the task
+ # list for the freezer cgroup. Since the user couldn't do anything anyway, it's best
+ # in this case to error out the shell. (an alternative would be to un-freeze it,
+ # add the task, and re-freeze it)
+ try:
+ f=open('/sys/fs/cgroup/freezer/libvirt/lxc/%s/tasks'%(slice_name),'w')
+ f.write(str(os.getpid()))
+ # note: we need to call f.close() explicitly, or we'll get an exception in
+ # the object destructor, which will not be caught
+ f.close()
+ except:
+ print "Error adding task to freezer cgroup. Slice is probably frozen: %s" % slice_name
+ exit(1)
+
+ setns.chcontext('/proc/%s/ns/uts'%pid)
+ setns.chcontext('/proc/%s/ns/ipc'%pid)
+
+ if (not args.pidns):
+ setns.chcontext('/proc/%s/ns/pid'%pid)
+
+ if (not args.netns):
+ setns.chcontext('/proc/%s/ns/net'%pid)
+
+ if (not args.mntns):
+ setns.chcontext('/proc/%s/ns/mnt'%pid)
+
+ proc_mounted = False
+ if (not os.access('/proc/self',0)):
+ proc_mounted = True
+ setns.proc_mount()
+
+ for (sysctl_file, sysctl_name, sysctl_val) in sysctls:
+ for fn in ["/sbin/sysctl", "/usr/sbin/sysctl", "/bin/sysctl", "/usr/bin/sysctl"]:
+ if os.path.exists(fn):
+ os.system("mount -o remount,rw none /proc/sys")
+ os.system('%s -w %s=%s'%(fn, sysctl_name,sysctl_val))
+ os.system("mount -o remount,ro none /proc/sys")
+ break
+ else:
+ print "Error: image does not have a sysctl binary"
+
+ # cgroups is not yet LXC-safe, so we need to use the coarse grained access control
+ # strategy of unmounting the filesystem
+
+ umount_result = True
+ for subsystem in ['cpuset','cpu,cpuacct','memory','devices','freezer','net_cls','blkio','perf_event']:
+ fs_path = '/sys/fs/cgroup/%s'%subsystem
+ if (not umount(fs_path)):
+ print "Error disabling cgroup access"
+ exit(1)
+
+ if (not umount('/sys/fs/cgroup')):
+ print "Error disabling cgroup access"
+ exit(1)