Allow adding Linux capabilities to the execution client container - #37
Merged
Merged
Conversation
A scenario's cap_add list goes to the client container as Docker cap_add, next to security_opt. PERFMON lets the client open its own hardware counters with perf_event_open when the host's perf_event_paranoid would refuse an unprivileged process.
6 of 16 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
A scenario can now list Linux capabilities to add to the execution client container (
cap_add), passed to Docker next to the existingsecurity_opt.The motivating case is a client reading its own hardware counters with
perf_event_open(per-block instruction counts on the benchmark runner). The runner runs as root withperf_event_paranoid=4, so an unprivileged process in the container is refused; withcap_add: [PERFMON]the client may open counters for its own threads.Leaving
cap_addout keeps the container exactly as before.Testing
Used on the amd64 runner by the instruction-count prototype in NethermindEth/nethermind (
kch/expb-instruction-counts, dozens of fusaka runs today): withcap_add: [PERFMON]the client logsEXPB-COUNT armedand reads its counters in every run. I did not run it without the capability; withperf_event_paranoid=4the kernel refusesperf_event_opento a process lackingCAP_PERFMON.🤖 AI agent (Claude Code / Opus 5.5) on behalf of @kamilchodola