fix(agent): report LXC guest CPU usage from cgroup accounting (#2341)

Inside an LXC guest, lxcfs serves /proc/stat with the counters of the
host cores in the guest's cpuset, so an idle guest sharing a core with a
busy neighbor reported near-100% CPU.

When the agent detects it is running in an LXC guest (lxcfs mounted on
/proc/stat, container=lxc, or /run/systemd/container), derive CPU usage
from the guest's own cgroup instead: cpu.stat on cgroup v2, cpuacct on
v1, read at the cgroup mount root so it covers every process in the
guest. Usage is normalized by the usable cores (the smallest of the
affinity mask, cpuset and CPU quota).

Per-core usage is omitted in this mode, since the per-core /proc/stat
counters describe shared host cores and would contradict the total.
Iowait and steal are not available from cgroup accounting and report as
zero.

Hosts and Docker/Podman agents are unaffected and keep reading
/proc/stat, as does an LXC guest whose cgroup accounting is unreadable.

---------

Co-authored-by: hank <hank@henrygd.me>
This commit is contained in:
Santhi Prakash
2026-10-02 05:03:42 +05:30
committed by GitHub
parent c394a6b5b1
commit 01d91728f0
5 changed files with 747 additions and 3 deletions

View File

@@ -30,11 +30,20 @@ type CpuMetrics struct {
Iowait float64
Steal float64
Idle float64
// fromCgroup is set when Total comes from cgroup accounting (LXC) rather
// than /proc/stat, so per-core /proc/stat usage would not match it.
fromCgroup bool
}
// getCpuMetrics calculates detailed CPU usage metrics using cached previous measurements.
// It returns percentages for total, user, system, iowait, and steal time.
func getCpuMetrics(cacheTimeMs uint16) (CpuMetrics, error) {
// Inside LXC, lxcfs serves /proc/stat with the host cores' counters, not
// the guest's own usage. Prefer the cgroup's CPU accounting there. (#2332)
if metrics, ok := containerCpuMetrics(cacheTimeMs); ok {
metrics.fromCgroup = true
return metrics, nil
}
times, err := cpu.Times(false)
if err != nil || len(times) == 0 {
return CpuMetrics{}, err