From: Elias Huhsovitz <e.huhsovitz@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Subject: [PATCH manager v2] fix #8093: pvestatd: remove stale lxc console reaper
Date: Fri, 9 Oct 2026 14:38:19 +0200 [thread overview]
Message-ID: <20261009123819.136563-1-e.huhsovitz@proxmox.com> (raw)
remove_stale_lxc_consoles() calls PVE::LXC::vmstatus() every cycle,
which runs `lxc-info` once per running container. Since
update_lxc_status() already calls vmstatus() in the same cycle, this
doubles the overhead of running `lxc-info`. Thus, this overhead is
scaling linearly with the number of containers.
Under normal operation, lxc-console and dtach exit automatically when
the container stops. The reaper only fires in broken system states, such
as deleting the container config file while the container is still
running. A continuous polling reaper is not an appropriate mechanism for
these situations.
Remove the reaper entirely.
Signed-off-by: Elias Huhsovitz <e.huhsovitz@proxmox.com>
---
This patch removes the reaper entirely. No replacement mechanism is
added. If a console process becomes orphaned due to manual system
interference, the administrator can identify and kill it directly.
A type of "replacement" machenanism that bridges this gap is
currently being discussed [1], based on patch [2].
Alternatives considered
-----------------------
* Wrapping console commands in transient systemd scopes bound via
PartOf= to the container service.
Verdict: rejected because lxc-stop ends the
service without a systemd stop job, so PartOf= does not propagate.
* A manual `pct cleanup console` CLI tool.
Verdict: cleanup shouldn't be manual.
* An ExecStopPost= hook on pve-container@.service.
Changes v1->v2:
---------------
* scrap the idea of binding console sessions to container lifetime via
systemd scoopes.
Previous versions
-----------------
v1: https://lore.proxmox.com/pve-devel/20261007083726.26067-1-e.huhsovitz@proxmox.com/
References
----------
[1] https://lore.proxmox.com/pve-devel/82fceb8e-f52d-4e56-9dcf-5cd61393fa26@proxmox.com/
[2] https://lore.proxmox.com/pve-devel/20260121112335.84473-1-f.schauer@proxmox.com/
Summary of Changes
------------------
PVE/Service/pvestatd.pm | 18 ------------------
1 file changed, 18 deletions(-)
diff --git a/PVE/Service/pvestatd.pm b/PVE/Service/pvestatd.pm
index 34f9da71..cec66e00 100755
--- a/PVE/Service/pvestatd.pm
+++ b/PVE/Service/pvestatd.pm
@@ -444,20 +444,6 @@ sub update_qemu_status {
PVE::PullMetric::update($pull_txn, 'qemu', $vmstatus, $ctime);
}
-sub remove_stale_lxc_consoles {
-
- my $vmstatus = PVE::LXC::vmstatus();
- my $pidhash = PVE::LXC::find_lxc_console_pids();
-
- foreach my $vmid (keys %$pidhash) {
- next if defined($vmstatus->{$vmid});
- syslog('info', "remove stale lxc-console for CT $vmid");
- foreach my $pid (@{ $pidhash->{$vmid} }) {
- kill(9, $pid);
- }
- }
-}
-
my $rebalance_error_count = {};
my $NO_REBALANCE;
@@ -848,10 +834,6 @@ sub update_status {
$err = $@;
syslog('err', "storage status update error: $err") if $err;
- eval { remove_stale_lxc_consoles(); };
- $err = $@;
- syslog('err', "lxc console cleanup error: $err") if $err;
-
eval { rotate_authkeys(); };
$err = $@;
syslog('err', "authkey rotation error: $err") if $err;
--
2.47.3
reply other threads:[~2026-10-09 12:38 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009123819.136563-1-e.huhsovitz@proxmox.com \
--to=e.huhsovitz@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox