Skip to content

fix(bundle): Pin urunc at the commit that sizes vCPUs from --cpus - #11

Merged
ananos merged 1 commit into
mainfrom
fix/urunc-vcpus-from-cpus
Sep 26, 2026
Merged

ananos merged 1 commit into
mainfrom
fix/urunc-vcpus-from-cpus

Conversation

@ananos

@ananos ananos commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Every guest the bundle boots has one vCPU, whatever brig run --cpus or the profile asks for (4 for the agent profiles). urunc never read the CPU resources in the container's OCI spec. It took the monitor's default_vcpus, which the bundle sets to 1, so cloud-hypervisor got --cpus boot=1. Memory was not affected, since urunc already follows the container's memory limit.

This moves the urunc pin to 74dd0cc9e3028ea18c5daff69e4ba5452075f21d on feat/unchanged_containers-exec-fixes. That is 0818ff1, the rc9 pin, plus one commit, feat(unikontainers): Size a container boot's vCPUs from its CPU limit:

  • a CPU quota (what nerdctl run --cpus sets) gives ceil(quota/period) vCPUs;
  • a cpuset gives the number of CPUs it names;
  • when both are set, the smaller wins;
  • the count is capped at the CPUs urunc may run on;
  • only a container boot changes, and a unikernel keeps the monitor default.

default_vcpus = 1 stays as the fallback for a container with no CPU limit.

Once this is merged, bundle rc10 is cut from main, and brig's install.sh moves its runtime pin from v0.1.0-rc9 to rc10 in a separate brig PR.

Changes

  • scripts/build-bundle.sh: URUNC_REF_DEFAULT moves from 0818ff1 to 74dd0cc, and the comment says what the pin carries.
  • README.md, DESIGN.md, docs/variants.md: the pinned commit, plus a line in the README's pins section on --cpus.

Testing

  • The urunc commit's own unit tests pass on an Ubuntu 24.04 amd64 host: TestMonitorVCPUs, TestCpusetCount, TestBuildMonitorSpecVCPUs, plus the existing monitor-spec and container-boot tests. With the line that applies the count removed, TestBuildMonitorSpecVCPUs fails. golangci-lint --new-from-rev reports 0 new issues.

  • This repo: sh -n and shellcheck are clean, and tests/*.sh all pass, source-pins.sh included.

  • CI built all four bundles, and each pins.env names URUNC_REF=74dd0cc… with URUNC_PINNED=true.

  • Live, on an Ubuntu 24.04 amd64 host (14 CPUs) with a rootless user install. This PR's bundle-amd64-rootless CI artifact was installed over rc9 with INSTALL_BRIG_BUNDLE (upgrade in place, no sudo), with brig main 3e5ae98. The cloud-hypervisor argument is read from ps:

    case CPU quota / period cloud-hypervisor guest nproc
    rc9 baseline, ubuntu (not read) --cpus boot=1 1
    ubuntu, profile default 200000/100000 --cpus boot=2 2
    claude-code, profile default 400000/100000 --cpus boot=4 4
    --cpus 1 100000/100000 --cpus boot=1 1
    --cpus 3 300000/100000 --cpus boot=3 3
    --cpus 64 6400000/100000 --cpus boot=14 (capped) 14, boots

    --mem 1024 still gives --memory size=1073M and a MemTotal of about 1 GB.

  • No regression on that host:

    • 300 short brig sh calls: none missing.
    • 10 claude-code boots: 0 .claude refusals.
    • A forced image pull with DOCKER_CONFIG unset.
    • No leftovers.

Every guest the bundle boots had one vCPU, whatever `brig run --cpus`
or the profile asked for (4 for the agent profiles). urunc never read
the CPU resources in the container's OCI spec. It took the monitor's
default_vcpus, which the bundle sets to 1, and cloud-hypervisor got
`--cpus boot=1`. Memory was not affected: urunc already follows the
container's memory limit.

urunc 74dd0cc sizes a container boot's vCPUs from the CPU quota that
`nerdctl run --cpus` sets, or from a cpuset, and caps the count at the
host's CPUs. It is 0818ff1 plus that one commit, on the same branch, so
the exec fixes stay as they were. default_vcpus = 1 stays as the
fallback for a container with no CPU limit.

Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
@ananos
ananos marked this pull request as ready for review September 26, 2026 00:17
@ananos
ananos merged commit 0d73225 into main Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant