Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #88131 > unrolled thread

Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21

Started byHarald Dunkel <harri@afaics.de>
First post2025-06-25 09:10 +0200
Last post2025-09-19 03:20 +0200
Articles 15 — 7 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Harald Dunkel <harri@afaics.de> - 2025-06-25 09:10 +0200
    Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-06-26 18:30 +0200
      Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-06-26 19:20 +0200
        Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-07-09 00:50 +0200
          Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-07-09 14:00 +0200
      Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Harald Dunkel <harri@afaics.de> - 2025-06-26 20:50 +0200
        Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-06-29 14:30 +0200
    Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Ben Hutchings <ben@decadent.org.uk> - 2025-06-26 18:50 +0200
    Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21 Bastian Blank <waldi@debian.org> - 2025-06-26 20:30 +0200
    Processed: Re: kernel 6.12 breaks cgroup awareness of openjdk 21 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-07-09 00:50 +0200
    Bug#1108294: marked as done (kernel 6.12 breaks cgroup awareness  of openjdk 21) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-07-11 09:10 +0200
    Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups Harald Dunkel <harri@afaics.de> - 2025-07-14 08:30 +0200
    Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups Harald Dunkel <harald.dunkel@aixigo.com> - 2025-07-21 10:00 +0200
      Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups Salvatore Bonaccorso <carnil@debian.org> - 2025-07-27 17:00 +0200
    Bug#1108294: 洗澡最危险 寒冬“10大易猝死行为”曝光 Alan Zhou <avianrobles359@gmail.com> - 2025-09-19 03:20 +0200

#88131 — Bug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21

FromHarald Dunkel <harri@afaics.de>
Date2025-06-25 09:10 +0200
SubjectBug#1108294: kernel 6.12 breaks cgroup awareness of openjdk 21
Message-ID<L1sqB-d0on-1@gated-at.bofh.it>
Package: linux-image-6.12.33+deb13-amd64
Version: 6.12.33-1

By default kernel 6.12 dropped some deprecated features around cgroupv2
support. This affects openjdk 21 and older, see

	https://bugs.openjdk.org/browse/JDK-8347811
	https://bugs.debian.org/1107967

This is fatal: Using cgroupv2 openjdk 21 doesn't recognize the container
limits by default anymore, the Java GC is not run since there seems to
be plenty of memory, and the Java app runs into the container's memory
limit and is killed with OOM.

openjdk 25 has been fixed, AFAICT.

Workaround is to configure the kernel with

	CONFIG_CPUSETS_V1=y
	CONFIG_MEMCG_V1=y

to bring back the deprecated features.

I would like to suggest to re-enable the deprecated features in the
kernel. It is pretty much unlikely that openjdk 21 is fixed in time
for Trixie. Not to mention the kernel backport to Bookworm.


Regards
Harri

[toc] | [next] | [standalone]


#88153

FromBen Hutchings <ben@decadent.org.uk>
Date2025-06-26 18:30 +0200
Message-ID<L1XE6-dlPW-19@gated-at.bofh.it>
In reply to#88131

[Multipart message — attachments visible in raw view] — view raw

On Wed, 25 Jun 2025 08:33:24 +0200 Harald Dunkel <harri@afaics.de>
wrote:
> Package: linux-image-6.12.33+deb13-amd64
> Version: 6.12.33-1
> 
> By default kernel 6.12 dropped some deprecated features around
cgroupv2
> support. This affects openjdk 21 and older, see
> 
>       https://bugs.openjdk.org/browse/JDK-8347811
>       https://bugs.debian.org/1107967
> 
> This is fatal: Using cgroupv2 openjdk 21 doesn't recognize the
container
> limits by default anymore, the Java GC is not run since there seems to
> be plenty of memory, and the Java app runs into the container's memory
> limit and is killed with OOM.
> 
> openjdk 25 has been fixed, AFAICT.
> 
> Workaround is to configure the kernel with
> 
>       CONFIG_CPUSETS_V1=y
>       CONFIG_MEMCG_V1=y
> 
> to bring back the deprecated features.
> 
> I would like to suggest to re-enable the deprecated features in the
> kernel. It is pretty much unlikely that openjdk 21 is fixed in time
> for Trixie. Not to mention the kernel backport to Bookworm.

Thank you for bringing this to our attention.

I don't think it makes sense for us to re-enable cgroups v1, given that
it has been deprecated for so long and OpenJDK itself can use v2.

I will look into whether we can instead provide only a /proc/cgroups
file, which seems to be all that OpenJDK actually needed.

Ben.

-- 
Ben Hutchings
Quantity is no substitute for quality, but it's the only one we've got.

[toc] | [prev] | [next] | [standalone]


#88156

FromBen Hutchings <ben@decadent.org.uk>
Date2025-06-26 19:20 +0200
Message-ID<L1Yqt-dmnj-1@gated-at.bofh.it>
In reply to#88153

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2025-06-26 at 18:24 +0200, Ben Hutchings wrote:
[...]
> Thank you for bringing this to our attention.
> 
> I don't think it makes sense for us to re-enable cgroups v1, given that
> it has been deprecated for so long and OpenJDK itself can use v2.
> 
> I will look into whether we can instead provide only a /proc/cgroups
> file, which seems to be all that OpenJDK actually needed.

In fact this may be as simple as reverting:

commit af000ce85293b8e608f696f0c6c280bc3a75887f
Author: Michal Koutný <mkoutny@suse.com>
Date:   Mon Sep 9 18:32:23 2024 +0200
 
    cgroup: Do not report unavailable v1 controllers in /proc/cgroups

but I have not yet tested that.

Ben.

-- 
Ben Hutchings
Quantity is no substitute for quality, but it's the only one we've got.

[toc] | [prev] | [next] | [standalone]


#88277

FromBen Hutchings <ben@decadent.org.uk>
Date2025-07-09 00:50 +0200
Message-ID<L6piq-gdjs-5@gated-at.bofh.it>
In reply to#88156

[Multipart message — attachments visible in raw view] — view raw

Control: tag -1 patch

On Thu, 2025-06-26 at 19:17 +0200, Ben Hutchings wrote:
> On Thu, 2025-06-26 at 18:24 +0200, Ben Hutchings wrote:
> [...]
> > Thank you for bringing this to our attention.
> > 
> > I don't think it makes sense for us to re-enable cgroups v1, given that
> > it has been deprecated for so long and OpenJDK itself can use v2.
> > 
> > I will look into whether we can instead provide only a /proc/cgroups
> > file, which seems to be all that OpenJDK actually needed.
> 
> In fact this may be as simple as reverting:
> 
> commit af000ce85293b8e608f696f0c6c280bc3a75887f
> Author: Michal Koutný <mkoutny@suse.com>
> Date:   Mon Sep 9 18:32:23 2024 +0200
>  
>     cgroup: Do not report unavailable v1 controllers in /proc/cgroups
> 
> but I have not yet tested that.

Yes, this seems to work.

I compiled the following class:

--- BEGIN ---
import java.lang.System;

class Main {
    public static void main(String[] args) {
	int count = Integer.parseInt(args[0]);
	char[] one_mb;
	int i;

	for (i = 0; i != count; i++) {
	    one_mb = new char[0x100000];
	    System.out.println(one_mb[0] | one_mb[0xfffff]);
	}
    }
};
--- END ---

and ran it with an argument of "1000".

I used a podman container of Debian limited to 50 MiB.  With the current
kernel from trixie, it OOMs.  With that commit reverted, it runs to
completion.

I will open an MR tomorrow.

Ben.

-- 
Ben Hutchings
73.46% of all statistics are made up.

[toc] | [prev] | [next] | [standalone]


#88283

FromBen Hutchings <ben@decadent.org.uk>
Date2025-07-09 14:00 +0200
Message-ID<L6BCV-glSF-5@gated-at.bofh.it>
In reply to#88277

[Multipart message — attachments visible in raw view] — view raw

On Wed, 2025-07-09 at 00:46 +0200, Ben Hutchings wrote:
[...]
> I will open an MR tomorrow.

Opened <https://salsa.debian.org/kernel-team/linux/-/merge_requests/1572>.

Ben.

-- 
Ben Hutchings
73.46% of all statistics are made up.

[toc] | [prev] | [next] | [standalone]


#88159

FromHarald Dunkel <harri@afaics.de>
Date2025-06-26 20:50 +0200
Message-ID<L1ZPz-dn7s-13@gated-at.bofh.it>
In reply to#88153
Ben Hutchings wrote:
> 
> Thank you for bringing this to our attention.
> 
> I don't think it makes sense for us to re-enable cgroups v1, given that
> it has been deprecated for so long and OpenJDK itself can use v2.
> 

You are right, it's been deprecated for quite some time, and this is
clearly a bug in openjdk, but currently there is no better version of
JDK21. I am not sure what you mean by "OpenJDK itself can use v2".

> I will look into whether we can instead provide only a /proc/cgroups
> file, which seems to be all that OpenJDK actually needed.
> 

How is this supposed to work? Since we are talking about the host system
here you cannot know how /proc was mounted in the container, which
Container framework is involved, or whether the container is based on
Debian at all.

[toc] | [prev] | [next] | [standalone]


#88197

FromBen Hutchings <ben@decadent.org.uk>
Date2025-06-29 14:30 +0200
Message-ID<L2Zkt-e0c1-5@gated-at.bofh.it>
In reply to#88159

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2025-06-26 at 20:40 +0200, Harald Dunkel wrote:
> Ben Hutchings wrote:
> > 
> > Thank you for bringing this to our attention.
> > 
> > I don't think it makes sense for us to re-enable cgroups v1, given that
> > it has been deprecated for so long and OpenJDK itself can use v2.
> > 
> 
> You are right, it's been deprecated for quite some time, and this is
> clearly a bug in openjdk, but currently there is no better version of
> JDK21. I am not sure what you mean by "OpenJDK itself can use v2".

OpenJDK (from v11 onwards) appears to use v2 of the cgroups API if
available, and only mistakenly relied on /proc/cgroups for detection of
which controllers are enabled.

> > I will look into whether we can instead provide only a /proc/cgroups
> > file, which seems to be all that OpenJDK actually needed.
> > 
> 
> How is this supposed to work? Since we are talking about the host system
> here you cannot know how /proc was mounted in the container, which
> Container framework is involved, or whether the container is based on
> Debian at all.

We have to assume that /proc/cgroups and cgroupfs are exposed to the
container, otherwise none of this detection could have worked before...

Ben.

-- 
Ben Hutchings
Quantity is no substitute for quality, but it's the only one we've got.

[toc] | [prev] | [next] | [standalone]


#88155

FromBen Hutchings <ben@decadent.org.uk>
Date2025-06-26 18:50 +0200
Message-ID<L1XXr-dlX5-3@gated-at.bofh.it>
In reply to#88131

[Multipart message — attachments visible in raw view] — view raw

For reference, I think this is the status of the OpenJDK versions in the
archive:

           | Debian release     | cgroups |
           | 11 | 12 | 13 | sid | support |
-----------+----+----+----+-----+---------+
openjdk-8  |    |    |    | X   | no      |
openjdk-11 | X  |    |    | X   | yes *   |
openjdk-17 | X  | X  |    | X   | yes *   |
openjdk-21 |    |    | X  | X   | yes *   |
openjdk-22 |    |    |    | X   | yes *   |
openjdk-23 |    |    |    | X   | yes *   |
openjdk-24 |    |    |    | X   | yes *   |
openjdk-25 |    |    | X  | X   | yes +   |

* CgroupSubsystemFactory depends on /proc/cgroups even if using v2
+ C++ implementation of CgroupSubsystemFactory does not depend on
  /proc/cgroups if using v2, but Java implementation still does

Ben.

-- 
Ben Hutchings
Quantity is no substitute for quality, but it's the only one we've got.

[toc] | [prev] | [next] | [standalone]


#88157

FromBastian Blank <waldi@debian.org>
Date2025-06-26 20:30 +0200
Message-ID<L1Zwd-dn0x-1@gated-at.bofh.it>
In reply to#88131
On Wed, Jun 25, 2025 at 08:33:24AM +0200, Harald Dunkel wrote:
> This is fatal: Using cgroupv2 openjdk 21 doesn't recognize the container
> limits by default anymore, the Java GC is not run since there seems to
> be plenty of memory, and the Java app runs into the container's memory
> limit and is killed with OOM.
> openjdk 25 has been fixed, AFAICT.

Did you think about backporting those changes?

Bastian

-- 
It is necessary to have purpose.
		-- Alice #1, "I, Mudd", stardate 4513.3

[toc] | [prev] | [next] | [standalone]


#88279 — Processed: Re: kernel 6.12 breaks cgroup awareness of openjdk 21

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-07-09 00:50 +0200
SubjectProcessed: Re: kernel 6.12 breaks cgroup awareness of openjdk 21
Message-ID<L6piq-gdjs-3@gated-at.bofh.it>
In reply to#88131
Processing control commands:

> tag -1 patch
Bug #1108294 [src:linux] kernel 6.12 breaks cgroup awareness of openjdk 21
Added tag(s) patch.

-- 
1108294: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108294
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#88352 — Bug#1108294: marked as done (kernel 6.12 breaks cgroup awareness of openjdk 21)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-07-11 09:10 +0200
SubjectBug#1108294: marked as done (kernel 6.12 breaks cgroup awareness of openjdk 21)
Message-ID<L7g3n-gMXZ-5@gated-at.bofh.it>
In reply to#88131

[Multipart message — attachments visible in raw view] — view raw

Your message dated Fri, 11 Jul 2025 07:00:10 +0000
with message-id <E1ua7ju-003FcQ-H3@fasolo.debian.org>
and subject line Bug#1108294: fixed in linux 6.12.37-1
has caused the Debian Bug report #1108294,
regarding kernel 6.12 breaks cgroup awareness of openjdk 21
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1108294: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108294
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#88400 — Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups

FromHarald Dunkel <harri@afaics.de>
Date2025-07-14 08:30 +0200
SubjectBug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups
Message-ID<L8kRj-hunl-3@gated-at.bofh.it>
In reply to#88131
I booted the new kernel this morning. Using cgroupv2 I got

% docker run -it --rm -m 4g --cpus=3 debian:trixie 
root@b46ebbb70b04:/# apt update
Get:1 http://deb.debian.org/debian trixie InRelease [168 kB]
Get:2 http://deb.debian.org/debian trixie-updates InRelease [45.1 kB]
Get:3 http://deb.debian.org/debian-security trixie-security InRelease [43.4 kB]
Get:4 http://deb.debian.org/debian trixie/main amd64 Packages [9672 kB]
Get:5 http://deb.debian.org/debian-security trixie-security/main amd64 Packages [5304 B]
Fetched 9934 kB in 1s (9313 kB/s)                    
13 packages can be upgraded. Run 'apt list --upgradable' to see them.
root@b46ebbb70b04:/# apt -y install default-jdk
:
:
root@b46ebbb70b04:/# java -Xlog:os+container=trace --version
[0.001s][trace][os,container] OSContainer::init: Initializing Container Support
[0.001s][debug][os,container] Detected optional cpuset controller entry in /proc/cgroups
[0.001s][debug][os,container] Detected optional pids controller entry in /proc/cgroups
[0.002s][debug][os,container] Detected cgroups v2 unified hierarchy
[0.002s][trace][os,container] Path to /cpu.max is /sys/fs/cgroup/cpu.max
[0.002s][trace][os,container] Raw value for CPU quota is: 300000
[0.002s][trace][os,container] CPU Quota is: 300000
[0.002s][trace][os,container] Path to /cpu.max is /sys/fs/cgroup/cpu.max
[0.002s][trace][os,container] CPU Period is: 100000
[0.002s][trace][os,container] CPU Quota count based on quota/period: 3
[0.002s][trace][os,container] OSContainer::active_processor_count: 3
[0.002s][trace][os,container] CgroupSubsystem::active_processor_count (cached): 3
[0.002s][trace][os,container] total physical memory: 67099267072
[0.002s][trace][os,container] Path to /memory.max is /sys/fs/cgroup/memory.max
[0.002s][trace][os,container] Raw value for memory limit is: 4294967296
[0.002s][trace][os,container] Memory Limit is: 4294967296
[0.004s][trace][os,container] CgroupSubsystem::active_processor_count (cached): 3
[0.027s][trace][os,container] Path to /cpu.max is /sys/fs/cgroup/cpu.max
[0.027s][trace][os,container] Raw value for CPU quota is: 300000
[0.027s][trace][os,container] CPU Quota is: 300000
[0.027s][trace][os,container] Path to /cpu.max is /sys/fs/cgroup/cpu.max
[0.027s][trace][os,container] CPU Period is: 100000
[0.027s][trace][os,container] CPU Quota count based on quota/period: 3
[0.027s][trace][os,container] OSContainer::active_processor_count: 3
openjdk 21.0.7 2025-04-15
OpenJDK Runtime Environment (build 21.0.7+6-Debian-1)
OpenJDK 64-Bit Server VM (build 21.0.7+6-Debian-1, mixed mode, sharing)


This looks as expected. CPU and memory limits are correct. Now I have
to wait for a backport for Bookworm to roll out the new kernel to our
developers and to our Kubernetes nodes.


Thank you very much. I highly appreciate your contribution to
Debian.


Harri

[toc] | [prev] | [next] | [standalone]


#88477 — Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups

FromHarald Dunkel <harald.dunkel@aixigo.com>
Date2025-07-21 10:00 +0200
SubjectBug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups
Message-ID<LaTBf-1xB3-1@gated-at.bofh.it>
In reply to#88131
> Applied to cgroup/for-6.17.

I would recommend to follow upstream for kernels beyond
Trixie in this aspect. Debian needs a workaround for kernel
6.12 in Trixie, because there are no JDKs fully compatible
with cgroupv2 yet, including the brand-new

	OpenJDK 11.0.28
        OpenJDK 17.0.16
        OpenJDK 21.0.8

released a few days ago. I expect the JDKs will be fixed for
Forky.

Just my $0.02 of course. Regards
Harri

[toc] | [prev] | [next] | [standalone]


#88561 — Bug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-07-27 17:00 +0200
SubjectBug#1108294: [PATCH 4/4] cgroup: Do not report unavailable v1 controllers in /proc/cgroups
Message-ID<Ldb10-38nz-17@gated-at.bofh.it>
In reply to#88477
Hi,

On Mon, Jul 21, 2025 at 09:42:23AM +0200, Harald Dunkel wrote:
> > Applied to cgroup/for-6.17.
> 
> I would recommend to follow upstream for kernels beyond
> Trixie in this aspect. Debian needs a workaround for kernel
> 6.12 in Trixie, because there are no JDKs fully compatible
> with cgroupv2 yet, including the brand-new
> 
> 	OpenJDK 11.0.28
>         OpenJDK 17.0.16
>         OpenJDK 21.0.8
> 
> released a few days ago. I expect the JDKs will be fixed for
> Forky.

This would be my "personal" (in terms of keeping deltas in the
packaging) preference:
- make sure the patches get backported down to 6.12.y
- drop our local revert
- make uses affected made aware of the kernel parameter to use (maybe
  via a NEWS entry?)

I had a short discussion on IRC with Ben about that, and as the
upstream changes are not yet down to 6.12.y the situation is rather
clear that we have the revert. If the changes goes down to 6.12.y
though I would love to rediscuss if we could consider the above
instread.

I though realize it is too early to at all consider, given it's not
yet applied upsream.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#89325 — Bug#1108294: 洗澡最危险 寒冬“10大易猝死行为”曝光

FromAlan Zhou <avianrobles359@gmail.com>
Date2025-09-19 03:20 +0200
SubjectBug#1108294: 洗澡最危险 寒冬“10大易猝死行为”曝光
Message-ID<LwxX3-gqwu-3@gated-at.bofh.it>
In reply to#88131

[Multipart message — attachments visible in raw view] — view raw

*你好!*

据TVBS的报道,洪永祥根据统计表示,约70%的猝死事件发生在家中,尤其是卧室和浴室

肾脏科医生洪永祥指出,心肌梗塞引发的心律不整是冬季猝死的常见原因之一

洪永祥特别提醒,民众应避免10大可能引发寒冬猝死的危险行为,以降低风险

这些信息十分珍贵,请务必查看完整内容!

https://simpleurl.link/dongtian-xizao-hen-weixian

祝你和你的家人好运!

---

愿光明与真相同行

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web