From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 11C2BBA15; Fri, 31 Jul 2026 22:00:37 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 51245B900; Fri, 31 Jul 2026 22:00:28 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yw1-x112d.google.com (mail-yw1-x112d.google.com [IPv6:2607:f8b0:4864:20::112d]) by atuin.qyliss.net (Postfix) with ESMTPS id 6B9D2B878 for ; Fri, 31 Jul 2026 22:00:27 +0000 (UTC) Received: by mail-yw1-x112d.google.com with SMTP id 00721157ae682-7ff05e5d009so19007457b3.1 for ; Fri, 31 Jul 2026 15:00:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785535221; x=1786140021; darn=spectrum-os.org; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=S1u+PzPqbuV//Ho74yxByrFxVZylReaz1ozj6bEWWjc=; b=UusI4mkiMABL7lCKhhENWewi9lNlwWDI77+FVGUPeoOEisNxYZzJAiGt1T+m7vdakT cQvnxgl/mRQrIEIVBwWHNnms6LJwsuedMCy6dFHS/7cp6jEk69qQP8D9YbjS+tMp8GJX qhrqHX0OGPtqcQSJppGFJvZchhFrT7oYeC8QzSQCI6emkgNJNodxE+VdEamDtUB1eYUr LD8ADqT2J5r3eI/MGEMi6oEeoOP6/npoaV1qjAGkEV9zdf52k4sv1ROG74KYXgxc24eH P0FIh8rTbpc4GD8MUHm6qehD9Fie9+mwkqFc3vhEOmFLTezUh+BGoa9hqJzsAx8Q0uvO OTtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785535221; x=1786140021; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=S1u+PzPqbuV//Ho74yxByrFxVZylReaz1ozj6bEWWjc=; b=FDu2pd+mrBYi4P85iBbH7bNlYcmVbEZmT25+ZAzwXtqxhuEomX5bkZnC8pcj6l6o3p /+MAeZ90iWEjf3jpGYChoP06N+LLkxWbjFuTPB3GhDO54LzIus53eb9xP/xSjHbjTS36 IrjhWxe+saTGUEeLhwRWl3JBN697iBWOUO5NkJihp+MWaf9mwFK6BUMezfxCR0zgnrhC 6Vva/R/MdO5FXj2+H9XKcCGAb/hJzcXjbVAnBBKmaC8Kpcz6cSjPLEYOPocDtSOgYcYw fEB/yMh3hXyNTXb7IIVf64B/CzbH4E39aI53z9VWukXe1E7QiXul2RmFDKvY+0uypx+Q gJoA== X-Gm-Message-State: AOJu0YyhfVpCjFMuTZpfvm0LL9sqOOCxgj5V1yYkTOYc5OV19OQrXQtS T6DBpqZwjygNevIoqW0bFktruPG27DtQGSawli2ca+IaS8mlQKLB7523SVvkPQ== X-Gm-Gg: AR+sD122Yq+hcyyQEoX9kW8jUW22wjLamgNm24d1vLDWy5RU+YJmnznsGjmwfNftm5p RsBZnSpV2YXbqKTEdaFMZ3xJ0Zl2YDn0Oz4Ey88JykVzaeABz8C1J84t485cnnDyRJOevLWxC5r 6QuY9AgSwrAG5sdO7/tZ0S5DMIYJuMv8lKz/m7lU8GaQb9zAgVrGcJqjdBWltAILo0XUobMqA74 65B1mdY5Ae1gxwgGjYw3Luhg/6bveQFFmBJcMsR2UqregCUhwtC9+xBRDkgDp4jKYXUBWZw9fzs 7WIvx8YAWvYFSneXQNXt3+jxyW+5++p7w7PkwvyZYTS3ffnj2JbGBZRUuF2cmsjZUaqqeySgRxe +KEfrJNbMOQtMBK+xnoa6WRXSem2o9CnZjNCGlZspScl8Be5H4tadWnuWVVeRaLDwN7eP3hzSv4 EViXPXt9zFeabVvI81LlxFGb/4m3QzTXORKKtpx8nupbABwT6DwTSvWs/HmpSQbXiasVBh/F6ie g== X-Received: by 2002:a05:690c:6084:b0:81e:8ccc:cd59 with SMTP id 00721157ae682-81fd4b40cbamr19976357b3.22.1785535220725; Fri, 31 Jul 2026 15:00:20 -0700 (PDT) Received: from localhost.localdomain ([185.98.168.14]) by smtp.gmail.com with UTF8SMTPSA id 00721157ae682-81fcd133d96sm14248467b3.44.2026.07.31.15.00.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 15:00:20 -0700 (PDT) From: Demi Marie Obenour Subject: [PATCH v5 00/19] Control group support Date: Fri, 31 Jul 2026 17:54:40 -0400 Message-Id: <20260731-cgroups-v5-0-b325bac9d34f@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-B4-Tracking: v=1; b=H4sIAAAAAAAC/3XNQQrCMBAF0KtI1kYm0yRVV95DXCTppEbUSqJFK b27aQtaBFfDh//+dCxRDJTYdtGxSG1IobnmoJYL5o7mWhMPVc4MATUoXHNXx+ZxS7zSsCEsgbT csNy+RfLhOS7tD1NOD3sidx/40DiGdG/ia3zViqE3rWqEz2oruOBAylhfKAHC7uqLCeeVay5sW G3xj8PsnDOEKK12a/Xriq8rhfi6IjvlrNHCIOT76+TM4cxJDlxqi6S896XVc9f3/RuQHNAtWAE AAA== X-Change-ID: 20260528-cgroups-d609e270e649 In-Reply-To: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> References: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1785534880; l=6313; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=CQaB18/U7mD3f5fSNIAibSZo1Z81ysrL2c1vMim5OBc=; b=AaWfMLLrBCiRmupqvjO4/dBsfyqKXh7pMIq+wCnRocIOFaQv/XJBm3udcr3i+a2SnY/054l6/ w+25NZ+fiT+DjI/I+g6oMVNgESg/jZRawYp0T1Wi3MzFzIxLMKwWWyy X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: MKHTDTYUGFIIY7PLXL3BHFLM3QFA72LI X-Message-ID-Hash: MKHTDTYUGFIIY7PLXL3BHFLM3QFA72LI X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Hits: member-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Signed-off-by: Demi Marie Obenour --- Changes in v5: - Rename open_subtree_raw() to open_beneath(). - Use consistent file modes. - Avoid using O_NOFOLLOW when RESOLVE_NO_SYMLINKS is also used. - Drop tracking of specific cgroup paths (at the cost of worse error messages). - Have functions take &dyn AsFd where that makes sense. - Drop exclusive vs shared lock tracking. - Remove vm-service-run wrapper script. - Use explicit cgroup names in VM service run and finish scripts. - Use sed to write to cgroup.subtree_control in the root cgroup, avoiding a special case in cgroup-setup. - Avoid mutating the Cgroup struct when creating child cgroups. - Avoid mutating the Cgroup struct when purging cgroups. - Improve documentation. - Drop cgroup-s6-finish and call cgroup-purge directly. - Remove support for operating on . or / in cgroup-setup. - Fix comments. - Link to v4: https://spectrum-os.org/lists/archives/spectrum-devel/20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com Changes in v4: - Implement proper locking to make concurrent operations safe. - Purge VMM cgroup in vmm service finish script. - Delete /run/vsock/${VM}/vsock before running Cloud Hypervisor. - Massively refactor cgroup-setup tool. - Link to v3: https://spectrum-os.org/lists/archives/spectrum-devel/20260711-cgroups-v3-1-5cba61a20cba@gmail.com Changes in v3: - Remove the implicit .service suffix on leaf control groups. - Make cgroup-setup acts as an s6 finish script when called as "finish". - Put the VMMs in the same cgroups as the per-VM services. - Add common helper script for the per-VM services. - Significantly refactor the Rust code. - Link to v2: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v2-1-ccae224b6c85@gmail.com Changes in v2: - Omit resource control support. It was completely broken, and the way Spectrum run scripts work means that it is better to setup resource controls just before the execve() into the final service process. This will be done by a separate tool. - Link to v1: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v1-1-0e5abf35101b@gmail.com --- Demi Marie Obenour (19): host/rootfs: Mount filesystems before s6-rc-init tools: Add control group manager Documentation: Mention control groups Mount cgroup2 filesystem at /sys/fs/cgroup host/rootfs: Enable controllers in non-root cgroups host/rootfs: Add comments where cgroups are intentionally not used host/rootfs: serial-getty-generator: Use cgroups host/rootfs: systemd-udevd: Run in cgroup host/rootfs: weston: Run in cgroup host/rootfs: Set up parent cgroup for all per-VM services host/rootfs: Create per-VM cgroup for all of the VM's services host/rootfs: run-vmm: Create per-VM cgroup host/rootfs: run-appimage: Purge the per-VM cgroup host/rootfs: run-flatpak: Purge the per-VM cgroup host/rootfs: dbus: Run in cgroup host/rootfs: vhost-user-fs: Run in cgroup host/rootfs: vhost-user-gpu: Run in cgroup host/rootfs: xdg-desktop-portal-spectrum-host: Run in cgroup host/rootfs: spectrum-router: Run in cgroup .codespellrc | 2 +- Documentation/doc/development/control-groups.adoc | 95 +++++++ host/rootfs/default.nix | 6 +- host/rootfs/file-list.mk | 10 + host/rootfs/image/etc/fstab | 1 + host/rootfs/image/etc/init | 14 +- .../s6-linux-init/run-image/service/getty-tty2/run | 1 + .../s6-linux-init/run-image/service/getty-tty3/run | 1 + .../s6-linux-init/run-image/service/getty-tty4/run | 1 + .../run-image/service/root-terminal/run | 1 + .../run-image/service/s6-linux-init-shutdownd/run | 1 + .../run-image/service/s6-svscan-log/run | 1 + .../service/serial-getty-generator/finish | 5 + .../run-image/service/serial-getty-generator/run | 4 +- .../run-image/service/serial-getty/run | 1 + .../run-image/service/serial-getty/template/run | 1 + .../run-image/service/vm-services/run | 3 + .../vm-services/template/data/service/dbus/finish | 5 + .../vm-services/template/data/service/dbus/run | 2 + .../template/data/service/spectrum-router/finish | 5 + .../template/data/service/spectrum-router/run | 2 + .../template/data/service/vhost-user-fs/finish | 5 + .../template/data/service/vhost-user-fs/run | 5 +- .../template/data/service/vhost-user-gpu/finish | 5 + .../template/data/service/vhost-user-gpu/run | 2 + .../xdg-desktop-portal-spectrum-host/finish | 5 + .../service/xdg-desktop-portal-spectrum-host/run | 2 + .../run-image/service/vm-services/template/finish | 5 + .../run-image/service/vm-services/template/run | 4 + .../run-image/service/vmm/template/finish | 5 + .../rootfs/image/etc/s6-linux-init/scripts/rc.init | 7 - host/rootfs/image/etc/s6-rc/systemd-udevd/finish | 5 + host/rootfs/image/etc/s6-rc/systemd-udevd/run | 5 +- host/rootfs/image/etc/s6-rc/weston/finish | 5 + host/rootfs/image/etc/s6-rc/weston/run | 2 + host/rootfs/image/usr/bin/run-appimage | 7 +- host/rootfs/image/usr/bin/run-flatpak | 7 +- host/rootfs/image/usr/bin/run-vmm | 4 + host/rootfs/image/usr/bin/vm-stop | 5 +- pkgs/default.nix | 1 + tools/cgroup-setup/Cargo.lock | 67 +++++ tools/cgroup-setup/Cargo.lock.license | 2 + tools/cgroup-setup/Cargo.toml | 10 + tools/cgroup-setup/default.nix | 22 ++ tools/cgroup-setup/src/cgroup.rs | 308 +++++++++++++++++++++ tools/cgroup-setup/src/main.rs | 186 +++++++++++++ 46 files changed, 823 insertions(+), 20 deletions(-) --- base-commit: 7e91788b3d630a4f4be8b318c9a3a436c37d39ec change-id: 20260528-cgroups-d609e270e649 -- Sincerely, Demi Marie Obenour (she/her/hers)