Replies: 1 comment
-
|
I have reported this in #5087 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I found that runc uses 22 system calls between installing the seccomp filter and calling execve.
This list may not be complete, but at least these system calls must be allowed for the container to start.
If one of them is blocked with SCMP_ACT_KILL, the runc process is killed and stays as a zombie.
Examples:
runc list shows nothing, but the container still appears in Docker.
5.Process tree:
I am not sure whether this is an actual issue or just undefined behavior.
When containers are killed by seccomp after execve, they usually display clear error messages, but in this case they do not—it just hangs.
At the very least, the zombie process should be handled at some point.
versions:
Beta Was this translation helpful? Give feedback.
All reactions