From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 71D921A52; Sat, 11 Jul 2026 20:14:17 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 45D2019FE; Sat, 11 Jul 2026 20:14:15 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yx1-xb12e.google.com (mail-yx1-xb12e.google.com [IPv6:2607:f8b0:4864:20::b12e]) by atuin.qyliss.net (Postfix) with ESMTPS id 97B9219F9 for ; Sat, 11 Jul 2026 20:14:13 +0000 (UTC) Received: by mail-yx1-xb12e.google.com with SMTP id 956f58d0204a3-66493875766so3595619d50.0 for ; Sat, 11 Jul 2026 13:14:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783800852; x=1784405652; darn=spectrum-os.org; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=A/XgY5hrdV777tyw9GUi/v/b98SvYCu8T9F3Yp037JA=; b=asi2Bgcz6Dxqd/PW44T3nOsYhg++QWLUC1XgCjEqk4D5TW+58LG77E+QAldtTCQ5zS M/o4duykC+IShPtSeFd3OGS7evF7HpznpLfZozzCELlv2ELvTFJhp1EWD1yguznsQYM7 PmX0PKKlbsPktY3olYcc8T7ab4dCYMcuy6NTq7YeVygJSQgQIF8J/fNQqUPYGa6Tbh3A oCyqiUnbpkqlCTVcpNrzn7sKAKGMY+LKnu+wHLAioV9W2tM5oFiB4SmT+dn7mkrr8ad4 Pp2FulIAEA0krUcNg05TVg/VZ68YBJLRq/qgn0CaBOw5yhuspLRJiMAyoNgjgrrDJwv4 HplA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783800852; x=1784405652; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=A/XgY5hrdV777tyw9GUi/v/b98SvYCu8T9F3Yp037JA=; b=Dhx4oiR+eK7xOE8t3DYptiuGe0q3Cf+dDITtG2E9B12J8pCZMLHA9D9B3RqNvCDG6O hN4w6laKj5VCEOg9mn1AUSI/TwmFshDE1NsELhu6gt2gzra7PyMa2ZhIPhugjbV4JU8j KfuZ1IDO1uORdqn4eVEXMFpar0MLgMjyOUOhlQfw44/AIPsdhSETrFUo2m6G6pEljONm Rkh4JClXE6QSoqCE+giz7RmtB266QjFpKBZtjCF1WY4G83FkCdrMcnhZQcLrVmWcPEqN jHWpi+Egae4GW8SUlJISlIqw1nSjfR4SZ50SlIlXX+GmzVgR1eGMHJ03+Fg+YBk4tkJq Md8Q== X-Gm-Message-State: AOJu0YwYcI1dya21+/vsEnn9g1yp6K3kLNwhLPLH6MCAzNXExqFi8r7h mKHZZ6xVIrYkFTXJLMaaviCilM5JLH9t03K0xxzsFXFcLQenNz8XHtI6AAv9kA== X-Gm-Gg: AfdE7clJHYkWKCKdajwf+RFvXm+9GdDJOgWWoWw27+mM6NfW3qpkTigRDZ85E8lkbsm pATQ/mkfew5bMt+8VGCcHHcVXSzSWJk9bgeKaMljYp5r0TPD78BqKEeyhUyqYk74Z6dbRKq8JCN h+IBCGFokC35VgT2pRkMkvSMbs3IqYHLi3tNaGu5ZVCmnskyf2keX/nbn60SZQ3Gaa0AnnqtbWK q4Rw6XiWTAvWWav/THflBxLcZWBaJdmOroZl5zhaBE9s7jAB4Qics81TAyBELMjTtqXWghjSdFL TmZYP0sDNrHpaKtL2/VXP7uIymDUeLaMgUlNtBkAoEQLJI7/CSQYGt7F7TeW1+KOj5Umo8VaT88 9sYutUSm9NMFNEUgqCAC1npN0285Jnf8D+9kP8k52ZtTrZI2RadNTGXbISaFrtCZL7PtovO3Ldk +8jqbImJePTcpPezRGKsc+e8CNNA== X-Received: by 2002:a05:690c:7248:b0:81c:b865:2228 with SMTP id 00721157ae682-81e902c770bmr28786067b3.63.1783800852087; Sat, 11 Jul 2026 13:14:12 -0700 (PDT) Received: from localhost.localdomain ([185.98.168.14]) by smtp.gmail.com with UTF8SMTPSA id 00721157ae682-81e6c212f14sm77576977b3.42.2026.07.11.13.14.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 13:14:10 -0700 (PDT) From: Demi Marie Obenour Subject: [PATCH v3 00/22] Control group support Date: Sat, 11 Jul 2026 16:12:04 -0400 Message-Id: <20260711-cgroups-v3-0-5cba61a20cba@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-B4-Tracking: v=1; b=H4sIAAAAAAAC/3WNQQ6CMBQFr0K6tqb90AquvIdxQcsXaoSSFhoN4 e62kBg3Lid5M28hHp1BT87ZQhwG440dIuSHjOiuHlqkpolMgIFkAkqqW2fn0dNGsgrhxFAWFYn r0eHdvLbS9bazn9UD9ZT0tOiMn6x7b1eBp91elcC+1cAppwxFre654IyrS9vX5nnUtiepGuCPB 9HTukaAQkldil9vXdcPiQGP+OgAAAA= X-Change-ID: 20260528-cgroups-d609e270e649 In-Reply-To: <20260620-cgroups-v2-1-ccae224b6c85@gmail.com> References: <20260620-cgroups-v2-1-ccae224b6c85@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783800724; l=5839; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=mfTKEhTZoklNffOPuHXVk78wLwKVlTmoj9TJ1IdNhLU=; b=C4w/D91N2XSZDS97g7DZJ8i6vud5d3pD/GKUgrbHsJmtYZ6xkBT4M3V0r7tAI+qyaq2vkOK/z 1E60wSg4qSpBiQxUZa4QenYVeI1ng/5Km8mTCW02RlZE8fSa4vGdP4y X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: KZHEAPM6GCPFS237FI5HJH3HGUU7VIG6 X-Message-ID-Hash: KZHEAPM6GCPFS237FI5HJH3HGUU7VIG6 X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Hits: member-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Signed-off-by: Demi Marie Obenour --- Changes in v3: - Remove the implicit .service suffix on leaf control groups. - Make cgroup-setup acts as an s6 finish script when called as "finish". - Put the VMMs in the same cgroups as the per-VM services. - Add common helper script for the per-VM services. - Significantly refactor the Rust code. - Link to v2: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v2-1-ccae224b6c85@gmail.com Changes in v2: - Omit resource control support. It was completely broken, and the way Spectrum run scripts work means that it is better to setup resource controls just before the execve() into the final service process. This will be done by a separate tool. - Link to v1: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v1-1-0e5abf35101b@gmail.com --- Demi Marie Obenour (22): host/rootfs: Mount filesystems before s6-rc-init scripts: Support symlinks in s6-rc-compile inputs tools: Add control group manager Documentation: Mention control groups Mount cgroup2 filesystem at /sys/fs/cgroup host/rootfs: Add helper program for per-VM services host/rootfs: Enable controllers in sub-cgroups host/rootfs: Add comments where cgroups are intentionally not used host/rootfs: serial-getty-generator: Use cgroups host/rootfs: Set up parent cgroup for all per-VM services host/rootfs: Create per-VM cgroup for all of the VM's services host/rootfs: run-vmm: Create per-VM cgroup host/rootfs: run-appimage: Purge the per-VM cgroup host/rootfs: run-flatpak: Purge the per-VM cgroup host/rootfs: dbus: Run in cgroup host/rootfs: vhost-user-fs: Run in cgroup host/rootfs: vhost-user-gpu: Run in cgroup host/rootfs: xdg-desktop-portal-spectrum-host: Run in cgroup host/rootfs: systemd-udevd: Run in cgroup host/rootfs: weston: Run in cgroup host/rootfs: spectrum-router: Run in cgroup host/rootfs: vm-import: Use elglob -w .codespellrc | 2 +- Documentation/doc/development/control-groups.adoc | 82 +++++ host/rootfs/Makefile | 32 +- host/rootfs/default.nix | 7 +- host/rootfs/file-list.mk | 12 + host/rootfs/image/etc/fstab | 1 + host/rootfs/image/etc/init | 15 +- .../s6-linux-init/run-image/service/getty-tty2/run | 1 + .../s6-linux-init/run-image/service/getty-tty3/run | 1 + .../s6-linux-init/run-image/service/getty-tty4/run | 1 + .../run-image/service/root-terminal/run | 1 + .../run-image/service/s6-linux-init-shutdownd/run | 1 + .../run-image/service/s6-svscan-log/run | 1 + .../service/serial-getty-generator/finish | 1 + .../run-image/service/serial-getty-generator/run | 4 +- .../run-image/service/serial-getty/run | 1 + .../run-image/service/serial-getty/template/run | 1 + .../run-image/service/vm-services/run | 3 + .../vm-services/template/data/service/dbus/finish | 1 + .../vm-services/template/data/service/dbus/run | 4 +- .../template/data/service/spectrum-router/finish | 1 + .../template/data/service/spectrum-router/run | 4 +- .../template/data/service/vhost-user-fs/finish | 1 + .../template/data/service/vhost-user-fs/run | 5 +- .../template/data/service/vhost-user-gpu/finish | 1 + .../template/data/service/vhost-user-gpu/run | 9 +- .../xdg-desktop-portal-spectrum-host/finish | 1 + .../service/xdg-desktop-portal-spectrum-host/run | 4 +- .../run-image/service/vm-services/template/finish | 1 + .../run-image/service/vm-services/template/run | 4 + .../rootfs/image/etc/s6-linux-init/scripts/rc.init | 9 +- host/rootfs/image/etc/s6-rc/systemd-udevd/finish | 1 + host/rootfs/image/etc/s6-rc/systemd-udevd/run | 5 +- host/rootfs/image/etc/s6-rc/weston/finish | 1 + host/rootfs/image/etc/s6-rc/weston/run | 9 +- host/rootfs/image/usr/bin/run-appimage | 5 +- host/rootfs/image/usr/bin/run-flatpak | 4 +- host/rootfs/image/usr/bin/run-vmm | 2 + host/rootfs/image/usr/bin/vm-import | 2 +- host/rootfs/image/usr/bin/vm-service-run | 34 ++ img/app/Makefile | 23 +- img/app/default.nix | 1 + img/app/file-list.mk | 2 + lib/targets.mk | 30 ++ pkgs/default.nix | 1 + release/live/Makefile | 12 +- release/live/default.nix | 1 + scripts/genfiles.awk | 13 +- tools/cgroup-setup/Cargo.lock | 67 ++++ tools/cgroup-setup/Cargo.lock.license | 2 + tools/cgroup-setup/Cargo.toml | 11 + tools/cgroup-setup/default.nix | 18 + tools/cgroup-setup/src/cgroup.rs | 203 +++++++++++ tools/cgroup-setup/src/main.rs | 406 +++++++++++++++++++++ vm/sys/net/Makefile | 19 +- vm/sys/net/default.nix | 1 + vm/sys/net/file-list.mk | 2 + 57 files changed, 979 insertions(+), 108 deletions(-) --- base-commit: 89f8c9238616b43e48b21e2eade41e061b006cd8 change-id: 20260528-cgroups-d609e270e649 -- Sincerely, Demi Marie Obenour (she/her/hers)