From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 8FF606527; Wed, 22 Jul 2026 02:16:48 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 496ED64F3; Wed, 22 Jul 2026 02:16:46 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yw1-x112d.google.com (mail-yw1-x112d.google.com [IPv6:2607:f8b0:4864:20::112d]) by atuin.qyliss.net (Postfix) with ESMTPS id 4F03864F1 for ; Wed, 22 Jul 2026 02:16:45 +0000 (UTC) Received: by mail-yw1-x112d.google.com with SMTP id 00721157ae682-80dc4a68e4aso94142097b3.0 for ; Tue, 21 Jul 2026 19:16:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784686603; x=1785291403; darn=spectrum-os.org; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=i8Fb83/bgxh9cUDfGbXzaHfL8N2hcIkqHD20YzvtTrs=; b=LMAzbU9kDvVplu7UKyb4Zji1ztuZ1g4KxHvoCcRfrwlyduQDfTs2OCY26At8yvcoXq HKAm34FedWP+v51p9fcuz/Q0jcL6+3oVMIb77/CuhbxQvagAmOBNe8L3XsDlu5JUx6Ui iNEmBWGP1YVezTxCw6LB9QLub4ZOSa3mG17Jx4ETFdD4QmClI9SXcums+SWMUKTlP6js KAzRr+QqlrkPKXV8x98V/Vh+0RYmg1W/M9CpAShxb+IO0zc0GEeMZq7/Lu4WJfmqxudN Sg1VISuK8W1rvkRalcRWPH0FwpU/5iUiZ35t6eRDM98YR+2vEwZ2+bS5sfyyIVdTEVMo h/Vw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784686603; x=1785291403; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=i8Fb83/bgxh9cUDfGbXzaHfL8N2hcIkqHD20YzvtTrs=; b=gS2frlBEcB7Deq6zvz4iRkp1JnitzwvReE/zGQSTbzpAzUywsN0gBryorUAb1SwrRS 1Nj3Q7GYclEOUSBtKHUG8WJun9tSFsa7mZv/uQm+KV5UOWp8hUnGETb9v4HdetjYg5cu u8HtgnSbjoqV6Hnpvj1eOL4nFk+MnRbb+WWrHPd02qm+fJHlo/BQVTn/8LYWoH5kRb4E dTBTnzeIxKplSdwe9xSM5Sc+wv9ndmNm7Qym6LcfK411FLCRnD7pPQLbGsAYC+V5yuWo HrovXI8q6zJkl6LiQq6xDTVbtCQ24DMGivI423gmcWzDR4BpliX1YVfhMRfndSJUxdHj tF0w== X-Gm-Message-State: AOJu0Yw8GdPTyJe+c7+TL5cAOjOvvvtmD0JueU7/kW8CGOQRAykZ1j/6 0Qol37v6TDL5LtoHnNwF4QfHcIfIfmA9T3J31esWwIyx57m8b9fWD+hGS+eJsw== X-Gm-Gg: AR+sD13KoTL9ZK03AsAmeTESTM2SY/Av9G1S8IQ/+BSPVfey8e+ovsFXSQh0VKye2QN jND5Ym72qAiASdZr4MSWb8zTb9O9PQun7rglNoFx80iomn3+FKMQyz9XGQE2BiXT0/dsovSTLgV VnVW1qCDDjOgakSGNI4qegQ4Co8MrlNfRISjVKZNK7/4PndywhxgwRMbXMXQxKZvhld5bAU/y7C 2937YFkrDkr0ljEe61YtCs93zRmzhYcX2rmyvhMw077g6QbRmmqtUjDAXqKAG+bfk02RpWM/lsV wDxE+xd6ki9rR2WDf717fr6PuPGKwXyMxivWMY9m9TcM45yeHlFIcFYtyPpwWGuUi9I5nKfEzqR IKtGspT5xMjfbR7b7u6vRCn9lyhhvh1s/CHpjIkBJ3bZu+ms57plzt6ml4mjPJ5AcVXYQWJxdG1 DAY3udGAVQk0hWryXdi4NcnISAyA== X-Received: by 2002:a05:690c:4b8b:b0:80c:85c6:8999 with SMTP id 00721157ae682-81ef2696e28mr59735157b3.72.1784686603088; Tue, 21 Jul 2026 19:16:43 -0700 (PDT) Received: from localhost.localdomain ([185.98.168.14]) by smtp.gmail.com with UTF8SMTPSA id 00721157ae682-81f33bf2d8bsm6868087b3.1.2026.07.21.19.16.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 19:16:40 -0700 (PDT) From: Demi Marie Obenour Subject: [PATCH v4 00/20] Control group support Date: Tue, 21 Jul 2026 21:59:05 -0400 Message-Id: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-B4-Tracking: v=1; b=H4sIAAAAAAAC/3XN0QqCMBQG4FeRXbfYjm5qV71HdLHNoy5KZVMpx HdvKmQEXR1++L//TMSjs+jJKZqIw9F62zYhJIeImFo1FVJbhEyAgWQCMmoq1w6dp4VkOULKUCY 5Ce3OYWmf69LlumU/6BuafuFLo7a+b91rfTXypbetSmCf1ZFTThkKpctYcMb1uXooez+a9kGW1 RH+OAjOGIUAiZYmE78u3l3K+e7i4ITRSnIFLNxvN8/zG0JzYecgAQAA X-Change-ID: 20260528-cgroups-d609e270e649 In-Reply-To: <20260711-cgroups-v3-1-5cba61a20cba@gmail.com> References: <20260711-cgroups-v3-1-5cba61a20cba@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784685545; l=5606; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=RVrp+8xADBb7eikH5usHNFjNz6JV8lj7+M5PQIIMl7g=; b=z2UoOyatn3J1QxapAjc3cnJxZINLb4/BRXiFbrY23NWPd9CxnqagJlEdXSbCLkXn/QzbMqOu4 jfRmrr3kEkND+kQ6kU+Ho+XrDnfX3xTUsIqMCAxyQnGqCQT1CUb7vBI X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: VFRZEBAKVVWEDSPZICRNN3UJZH3CC76D X-Message-ID-Hash: VFRZEBAKVVWEDSPZICRNN3UJZH3CC76D X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Hits: member-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Signed-off-by: Demi Marie Obenour --- Changes in v4: - Implement proper locking to make concurrent operations safe. - Purge VMM cgroup in vmm service finish script. - Delete /run/vsock/${VM}/vsock before running Cloud Hypervisor. - Massively refactor cgroup-setup tool. - Link to v3: https://spectrum-os.org/lists/archives/spectrum-devel/20260711-cgroups-v3-1-5cba61a20cba@gmail.com Changes in v3: - Remove the implicit .service suffix on leaf control groups. - Make cgroup-setup acts as an s6 finish script when called as "finish". - Put the VMMs in the same cgroups as the per-VM services. - Add common helper script for the per-VM services. - Significantly refactor the Rust code. - Link to v2: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v2-1-ccae224b6c85@gmail.com Changes in v2: - Omit resource control support. It was completely broken, and the way Spectrum run scripts work means that it is better to setup resource controls just before the execve() into the final service process. This will be done by a separate tool. - Link to v1: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v1-1-0e5abf35101b@gmail.com --- Demi Marie Obenour (20): host/rootfs: Mount filesystems before s6-rc-init tools: Add control group manager Documentation: Mention control groups Mount cgroup2 filesystem at /sys/fs/cgroup host/rootfs: Add helper program for per-VM services host/rootfs: Enable controllers in sub-cgroups host/rootfs: Add comments where cgroups are intentionally not used host/rootfs: serial-getty-generator: Use cgroups host/rootfs: Set up parent cgroup for all per-VM services host/rootfs: Create per-VM cgroup for all of the VM's services host/rootfs: run-vmm: Create per-VM cgroup host/rootfs: run-appimage: Purge the per-VM cgroup host/rootfs: run-flatpak: Purge the per-VM cgroup host/rootfs: dbus: Run in cgroup host/rootfs: vhost-user-fs: Run in cgroup host/rootfs: vhost-user-gpu: Run in cgroup host/rootfs: xdg-desktop-portal-spectrum-host: Run in cgroup host/rootfs: systemd-udevd: Run in cgroup host/rootfs: weston: Run in cgroup host/rootfs: spectrum-router: Run in cgroup .codespellrc | 2 +- Documentation/doc/development/control-groups.adoc | 88 ++++++ host/rootfs/default.nix | 6 +- host/rootfs/file-list.mk | 13 + host/rootfs/image/etc/fstab | 1 + host/rootfs/image/etc/init | 15 +- .../s6-linux-init/run-image/service/getty-tty2/run | 1 + .../s6-linux-init/run-image/service/getty-tty3/run | 1 + .../s6-linux-init/run-image/service/getty-tty4/run | 1 + .../run-image/service/root-terminal/run | 1 + .../run-image/service/s6-linux-init-shutdownd/run | 1 + .../run-image/service/s6-svscan-log/run | 1 + .../service/serial-getty-generator/finish | 5 + .../run-image/service/serial-getty-generator/run | 4 +- .../run-image/service/serial-getty/run | 1 + .../run-image/service/serial-getty/template/run | 1 + .../run-image/service/vm-services/run | 3 + .../vm-services/template/data/service/dbus/finish | 5 + .../vm-services/template/data/service/dbus/run | 4 +- .../template/data/service/spectrum-router/finish | 5 + .../template/data/service/spectrum-router/run | 4 +- .../template/data/service/vhost-user-fs/finish | 5 + .../template/data/service/vhost-user-fs/run | 5 +- .../template/data/service/vhost-user-gpu/finish | 5 + .../template/data/service/vhost-user-gpu/run | 9 +- .../xdg-desktop-portal-spectrum-host/finish | 5 + .../service/xdg-desktop-portal-spectrum-host/run | 4 +- .../run-image/service/vm-services/template/finish | 5 + .../run-image/service/vm-services/template/run | 4 + .../run-image/service/vmm/template/finish | 5 + .../rootfs/image/etc/s6-linux-init/scripts/rc.init | 7 - host/rootfs/image/etc/s6-rc/systemd-udevd/finish | 5 + host/rootfs/image/etc/s6-rc/systemd-udevd/run | 5 +- host/rootfs/image/etc/s6-rc/weston/finish | 5 + host/rootfs/image/etc/s6-rc/weston/run | 9 +- host/rootfs/image/usr/bin/cgroup-purge | 1 + host/rootfs/image/usr/bin/cgroup-s6-finish | 1 + host/rootfs/image/usr/bin/run-appimage | 7 +- host/rootfs/image/usr/bin/run-flatpak | 7 +- host/rootfs/image/usr/bin/run-vmm | 4 + host/rootfs/image/usr/bin/vm-service-run | 34 ++ host/rootfs/image/usr/bin/vm-stop | 5 +- pkgs/default.nix | 1 + tools/cgroup-setup/Cargo.lock | 67 ++++ tools/cgroup-setup/Cargo.lock.license | 2 + tools/cgroup-setup/Cargo.toml | 11 + tools/cgroup-setup/default.nix | 18 ++ tools/cgroup-setup/src/cgroup.rs | 349 +++++++++++++++++++++ tools/cgroup-setup/src/main.rs | 347 ++++++++++++++++++++ 49 files changed, 1060 insertions(+), 35 deletions(-) --- base-commit: c9726df5ae78c880a19226e958e5f1f4e3eae28a change-id: 20260528-cgroups-d609e270e649 -- Sincerely, Demi Marie Obenour (she/her/hers)