docker / docker/cli

Units for `--ulimit memlock` is counter intuitive

Open
#5,799 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

kind/bug status/0-triage
Dominant language
Go
Stars
6.1k
Forks
2.2k
Avg merge
1d 15h
Merged PRs (30d)
43

Description

Description

From Linux, the units for memlock are in kb. However docker run --ulimit memlock appears to use bytes. Since I wasn't able to find docker documentation to indicate it uses bytes instead of kb, using this setting was counter intuitive.

Notes:

I have not tried other --ulimit settings that are based on size, but it appears at least a few others use kb in Linux and I'm guessing those may also be affected by this.

Reproduce

Using 4096 I expect to get 4096k but in the container, limits -a shows 4k for "max locked memory"

docker run --rm -it --ulimit memlock=4096 ubuntu
root@d1290e92e5f8:/# ulimit -a
real-time non-blocking time  (microseconds, -R) unlimited
core file size              (blocks, -c) unlimited
data seg size               (kbytes, -d) unlimited
scheduling priority                 (-e) 0
file size                   (blocks, -f) unlimited
pending signals                     (-i) 29730
max locked memory           (kbytes, -l) 4
max memory size             (kbytes, -m) unlimited
open files                          (-n) 1073741816
pipe size                (512 bytes, -p) 8
POSIX message queues         (bytes, -q) 819200
real-time priority                  (-r) 0
stack size                  (kbytes, -s) 8192
cpu time                   (seconds, -t) unlimited
max user processes                  (-u) unlimited
virtual memory              (kbytes, -v) unlimited
file locks                          (-x) unlimited

I attempted adding a unit to the call like --ulimit memlock=4096kb or --ulimit memlock=4096k but that immediately fails:

docker run --rm -it --ulimit memlock=4096kb ubuntu
invalid argument "memlock=4096kb" for "--ulimit" flag: strconv.ParseInt: parsing "4096kb": invalid syntax
See 'docker run --help'.
Expected behavior

One of:

  • Use kb as the units instead of bytes
  • Support (or require) specifying units so users can be explicit
  • Document that --ulimit uses bytes instead of kb
docker version
Client: Docker Engine - Community
 Version:           27.1.1
 API version:       1.46
 Go version:        go1.21.12
 Git commit:        6312585
 Built:             Fri Jul 26 06:15:46 2024
 OS/Arch:           linux/s390x
 Context:           default

Server: Docker Engine - Community
 Engine:
  Version:          27.1.1
  API version:      1.46 (minimum version 1.24)
  Go version:       go1.21.12
  Git commit:       cc13f95
  Built:            Fri Jul 26 06:45:34 2024
  OS/Arch:          linux/s390x
  Experimental:     false
 containerd:
  Version:          1.7.19
  GitCommit:        2bf793ef6dc9a18e00cb12efb64355c2c9d5eb41
 runc:
  Version:          1.7.19
  GitCommit:        v1.1.13-0-g58aa920
 docker-init:
  Version:          0.19.0
  GitCommit:        de40ad0
docker info
Client: Docker Engine - Community
 Version:    27.1.1
 Context:    default
 Debug Mode: false

Server:
 Containers: 1
  Running: 1
  Paused: 0
  Stopped: 0
 Images: 5
 Server Version: 27.1.1
 Storage Driver: overlay2
  Backing Filesystem: xfs
  Supports d_type: true
  Using metacopy: false
  Native Overlay Diff: true
  userxattr: false
 Logging Driver: json-file
 Cgroup Driver: cgroupfs
 Cgroup Version: 2
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Authorization: <*******>
  Log: awslogs fluentd gcplogs gelf journald json-file local splunk syslog
 CDI spec directories:
  /etc/cdi
  /var/run/cdi
 Swarm: inactive
 Runtimes: io.containerd.runc.v2 runc
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: 2bf793ef6dc9a18e00cb12efb64355c2c9d5eb41
 runc version: v1.1.13-0-g58aa920
 init version: de40ad0
 Security Options:
  seccomp
   Profile: builtin
  userns
  cgroupns
 Kernel Version: 5.14.0-427.40.1.el9.zfpc10.8.s390x
 Operating System: Linux
 OSType: linux
 Architecture: s390x
 CPUs: 2
 Total Memory: 7.314GiB
 Name: <*******>
 ID: a86f1633-c963-41d2-963a-76590c1ab455
 Docker Root Dir: /media/data/docker/24000.109
 Debug Mode: false
 Username: <********>
 Labels:
  platform=zOS
 Experimental: false
 Insecure Registries:
  127.0.0.0/8
 Live Restore Enabled: false
Additional Info

Limits.conf doc pages showing memlock as kb

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the documented docker run --ulimit memlock=4096 ubuntu command and compare its result with Linux's ulimit -a output. Trace the CLI entry point for --ulimit parsing and review the relevant Docker documentation; done means the unit behavior is corrected or explicitly documented, with coverage for size-based limits if applicable.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, linux
Domain
cli, operating-systems
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.