Migrating to Slackware-current - LXC-7 - cgroup2

September 29, 2026 by Roberto Puzzanghera 0 comments

Index


Let's see how to manage unprivileged containers also in Slackware-current (16.0 to be), which -at the time I'm writing- ships kernel-7.2.x, lxc-7.0 and libcgroups-3.2.0.

Version 7 of LXC dropped cgroup v1, so we have to use cgroup v2. Thanks to 0XBF for the big support in the cgroup v2 settings as far as the limits inside the containers are concerned.

First of all, enable cgroup2 in /etc/default/cgroups

# Which version of cgroups should we mount, version 1 or version 2? 
# Please note that the rc.cgred init script (as well as the cgrulesengd 
# utility itself) will not function with cgroups version 2. Upstream 
# did not implement support for this since systemd handles it (of course). 
CGROUPS_VERSION=2 

# A list of controllers to enable in the root cgroup.subtree_control file. 
# These are only used for cgroup version 2 configurations. Note that enabling 
# the 'cpu' controller will cause the kernel to no longer use real-time 
# scheduling. For a full list of available controllers, examine the contents 
# of /sys/fs/cgroup/cgroup.controllers. The following commented list is a 
# typical full list of controllers, while the shorter one is a typical default list 
# used on systemd/logind systems. 
# Warning: the stock kernel has CONFIG_RT_GROUP_SCHED=y. Adding 'cpu' here 
# will silently prevent real-time scheduling for processes in user sessions 
# (PipeWire, JACK, rtkit). Boot with rt_group_sched=0 if you need both. 
CGROUP_V2_CONTROLLERS="cpuset io memory pids misc dmem" 
#CGROUP_V2_CONTROLLERS="memory pids" 

# Options to pass when mounting cgroup2. Prefix options with '-o'. 
# The following example adds the 'nsdelegate' option to the mount 
# of cgroup2: 
CGROUP_V2_MOUNT_OPTS="-o nsdelegate"

Disable rc.cgconfig and rc.cgred at boot time:

chmod -x /etc/rc.d/rc.cgconfig /etc/rc.d/rc.cgred

Replace the file /etc/lxc/lxc-common.conf in this way (all lxc.cgroup.* options are now lxc.cgroup2.*):

lxc.net.0.type = veth 
lxc.net.0.flags = up 
lxc.net.0.link = lxcbr0 
lxc.net.0.name = eth0 
lxc.net.0.hwaddr = 00:16:3e:xx:xx:xx 

lxc.tty.max = 1 
lxc.pty.max = 1024 

lxc.cgroup2.devices.deny = a 
# /dev/null and zero 
lxc.cgroup2.devices.allow = c 1:3 rwm 
lxc.cgroup2.devices.allow = c 1:5 rwm 
# consoles 
lxc.cgroup2.devices.allow = c 5:1 rwm 
lxc.cgroup2.devices.allow = c 5:0 rwm 
lxc.cgroup2.devices.allow = c 4:0 rwm 
lxc.cgroup2.devices.allow = c 4:1 rwm 
# /dev/{,u}random 
lxc.cgroup2.devices.allow = c 1:9 rwm 
lxc.cgroup2.devices.allow = c 1:8 rwm 
lxc.cgroup2.devices.allow = c 136:* rwm 
lxc.cgroup2.devices.allow = c 5:2 rwm 
# rtc 
lxc.cgroup2.devices.allow = c 254:0 rwm 

# we don't trust even the root user in the container, better safe than sorry. 
# comment out only if you know what you're doing. 
lxc.cap.drop = sys_module mknod mac_override mac_admin sys_time setfcap setpcap

# you can try also this alternative to the line above, whatever suits you better. 
#lxc.cap.drop=sys_admin 

# proc & sys, remove from /etc/fstab 
lxc.mount.auto = proc:mixed sys:ro

When you start the containers, a cgroup structure is created in /sys/fs/cgroup:

# tree -d --noreport /sys/fs/cgroup 
/sys/fs/cgroup 
├── 1 
│   ├── delegated 
│   └── session 
├── elogind 
└── lxc-containers 
   ├── c1
   │   ├── delegated 
   │   │   ├── lxc.monitor.c1 
   │   │   └── lxc.payload.c1 
   │   └── session 
   ├── c2 
   │   ├── delegated 
   │   │   ├── lxc.monitor.c2
   │   │   └── lxc.payload.c2 
   │   └── session
   ├── c3
   │   ├── delegated 
   │   │   ├── lxc.monitor.c3
   │   │   └── lxc.payload.c3 
   │   └── session

Now you are able to setup container's limits inside each config file. For example, to set a memory limit to the container test just add the following in its config file:

lxc.cgroup2.memory.max = 256M

Restart the container and check that the memory limit has been set:

cat /sys/fs/cgroup/lxc-containers/test/delegated/lxc.payload.test/memory.max
268435456

Be aware that, if you want to use my scripts with slackware-current you have to download the main branch of my github instead of the latest release:

git clone https://github.com/sagredo-dev/LXC-scripts.git

Add a comment

Recent comments
Recent posts

RSS feeds