From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 19CE19155; Thu, 06 Aug 2026 01:19:48 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 5EC3A9103; Thu, 06 Aug 2026 01:19:43 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yw1-x1131.google.com (mail-yw1-x1131.google.com [IPv6:2607:f8b0:4864:20::1131]) by atuin.qyliss.net (Postfix) with ESMTPS id DF82D90B2 for ; Thu, 06 Aug 2026 01:19:41 +0000 (UTC) Received: by mail-yw1-x1131.google.com with SMTP id 00721157ae682-81ed2a06b9eso16708097b3.3 for ; Wed, 05 Aug 2026 18:19:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785979179; x=1786583979; darn=spectrum-os.org; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=X8EuxzLmm1sxdnYwqR/fEl+Sy2YxsC196cfQ4I4vM2Q=; b=hmisx1JGEBf6G7i7Q9lHCXvBa5US1d/tCobl29nUQG/3YzOwVYHVZCup9IhRsPjGIk 1n8cidmFi6EQ1hGCSZ3tUze10hnsd5gxaRG6ruotwtJ/MkQv/n2D3HbLCG3ATPg7DZVT DehnJfXhZNl78l+D/7nxpAYZRb4v5pFPPdb28+zBeL9dTHI4pE2ZiG+YpATgr/E2H16w HNm/T426tyyvgKXEE0fHfLSFpZlZk/3e8Xv6ARPhTi/CzWJ3agG+Jfp7kh0x0KwNfU9u ZskjkwNmdlSo+BxbZoVB17B/kAl4EbS3WBe/HSP8uxJ7DjhNAN+8HExQiAKSTD84abJc zV3A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785979179; x=1786583979; h=cc:to:references:in-reply-to:content-transfer-encoding:content-type :mime-version:message-id:date:subject:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=X8EuxzLmm1sxdnYwqR/fEl+Sy2YxsC196cfQ4I4vM2Q=; b=qRI5GSoOYqTBe9FSGZ2bFFm4pr+0sYmHJdOLSQx9LhzLqfbdvilD/X6IS/myRD5d2N tTuMbtLcbjRXFORcluZrKbmTJoIWzg7XcmEB/EzB3QkBiF/74vIsJ5mrY561cXgPKu8D pEp9zaYIYef8+lSN3o6mLed5w2NkcVeZIdSDXVix+rsDuPVwdx0zRxPv0hq5RkGF7hcC WxGbnyGxVeVT+dPaKWtkhim4Up6qieM2YhtcRTW4ypXf+wh8OAZhQiBKOK0ZI2TLvEdg pOSJViYn/IhwzeBc2N/Sz9CFSWV4X5tGPibQ1Q7o1Nit7VcucK1wyh/Ko+pP4s85E7C5 6JPw== X-Gm-Message-State: AOJu0Yycf2EBq8SufyvmEQCal6RWvYp7oLvbbkCzwHngHX8UmRlmIuJ7 MsgqwhvOPEu0HDotGBPg1HPVkDwJ7xkabvlJk22gdxKnrrw1hrSxxjjJO8RLAg== X-Gm-Gg: AR+sD11o2f627mq8M4KbtZCOMVqOl2CkR9Ov0AfZ1214qPBL0o5E9NWLJ5ucFXL8PO5 b8Zq5r+9dpw8GUjbXE/DgYKwtYd614ydMaUhcmWfWolFUreZmB/UNT1a1upilb8vzzGEMO54nTu hh7KhQUHVWOO6XZaedGWMBM2YNKQOmSO8JNSWQ+fs1oji88EQzOmopxeSTFyEJ4JuG1jAWOMqDy 6UL3W8p9XK/CaVz19S4JbXXPwG4wR8cROHXwulQ6dQ1T711wRFZLkYVzuRnoYvdJkKHM/QsQQRa D4aBdOVZ5C0dxhmxYoy2HS4dsl24BIJ3t0MCcQt07/JvMhgC6eu+0FG60h2rA14FbEN2VuY9WS5 /kUsn+pna6WFaweJ1xz/GfStRzPCifsNxDQ9MosypqbmNNJGO3EDZKaw98jMzTdA0iXHjc4Ns8A D8hDi2YBfvD1XV11/RTsuGAM8EbxK6bZkhczcS6ZQuwNZ5DZf/iPzvB8RQi+oIloKVvhev7sWHt fbTa6IGswVXbA== X-Received: by 2002:a05:690c:c106:b0:821:133e:569c with SMTP id 00721157ae682-821133e58ebmr14544477b3.15.1785979179247; Wed, 05 Aug 2026 18:19:39 -0700 (PDT) Received: from localhost.localdomain ([185.98.168.14]) by smtp.gmail.com with UTF8SMTPSA id 00721157ae682-82110301607sm8884247b3.28.2026.08.05.18.19.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 18:19:38 -0700 (PDT) From: Demi Marie Obenour Subject: [PATCH v6 00/19] Control group support Date: Wed, 05 Aug 2026 21:16:07 -0400 Message-Id: <20260805-cgroups-v6-0-086c0f00f55f@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-B4-Tracking: v=1; b=H4sIAAAAAAAC/3XN3YrCMBAF4FeRXJtlMvmp9cr3EC+SdFKzqJVEi 4v03TdVWENhr4YD5zvzZJlSpMy2qydLNMYch0sJZr1i/mgvPfHYlcwQ0IDGDfd9Gu7XzDsDLWE DZFTLSvuaKMTHa2l/eOd8d9/kbzOfG8eYb0P6eb0axdx7rxqEv9VRcMGBtHVBagHC7fqzjacvP 5zZvDriPw6L894SonLGb/TSyY9rhPg4WZz2zhphEcpdOlU5rJziwJVxSDqE0DizdLpysnK6OCd RO+vbTqpQu2mafgE4Dg0IkAEAAA== X-Change-ID: 20260528-cgroups-d609e270e649 In-Reply-To: <20260731-cgroups-v5-0-b325bac9d34f@gmail.com> References: <20260731-cgroups-v5-0-b325bac9d34f@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1785978967; l=7016; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=z/06eSGT3pevp7vJVo+aqWO7iet/K2AYtrqKr1WdqgI=; b=Tvu4tfm6DMyHe6uP6w7llPJR2kVPVC5Uf9J2o9WLon0BEn9XxFl4vSus3SyiOY+JzB+2oAeZd vnnh8kHsAlDDC3fuYcfDmDFaFc9K7FnNCQRsLjrktWknOcR9ZCeReah X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: GUO4SWSOWMUWCED7LPVBUM43ZWBWRIXH X-Message-ID-Hash: GUO4SWSOWMUWCED7LPVBUM43ZWBWRIXH X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Hits: member-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency CC: Demi Marie Obenour , Alyssa Ross , Valentin Gagarin X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Signed-off-by: Demi Marie Obenour --- Changes in v6: - Simplify command-line argument parsing. - Place SPDX-FileCopyrightText before SPDX-License-Identifier, except in patches that already have Reviewed-by tags. - Clean up cgroup-setup. - Make openat2_simple() take an enum instead of a flags argument. - Use recursive function to remove directories. The standard library remove_dir_all() function is recursive, and the complexity of being more robust than the standard library is not worth it here. Spectrum does not allow code running as non-root to create cgroups, so there is no security concern. - Link to v5: https://spectrum-os.org/lists/archives/spectrum-devel/20260731-cgroups-v5-0-b325bac9d34f@gmail.com Changes in v5: - Rename open_subtree_raw() to open_beneath(). - Use consistent file modes. - Avoid using O_NOFOLLOW when RESOLVE_NO_SYMLINKS is also used. - Drop tracking of specific cgroup paths (at the cost of worse error messages). - Have functions take &dyn AsFd where that makes sense. - Drop exclusive vs shared lock tracking. - Remove vm-service-run wrapper script. - Use explicit cgroup names in VM service run and finish scripts. - Use sed to write to cgroup.subtree_control in the root cgroup, avoiding a special case in cgroup-setup. - Avoid mutating the Cgroup struct when creating child cgroups. - Avoid mutating the Cgroup struct when purging cgroups. - Improve documentation. - Drop cgroup-s6-finish and call cgroup-purge directly. - Remove support for operating on . or / in cgroup-setup. - Fix comments. - Link to v4: https://spectrum-os.org/lists/archives/spectrum-devel/20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com Changes in v4: - Implement proper locking to make concurrent operations safe. - Purge VMM cgroup in vmm service finish script. - Delete /run/vsock/${VM}/vsock before running Cloud Hypervisor. - Massively refactor cgroup-setup tool. - Link to v3: https://spectrum-os.org/lists/archives/spectrum-devel/20260711-cgroups-v3-1-5cba61a20cba@gmail.com Changes in v3: - Remove the implicit .service suffix on leaf control groups. - Make cgroup-setup acts as an s6 finish script when called as "finish". - Put the VMMs in the same cgroups as the per-VM services. - Add common helper script for the per-VM services. - Significantly refactor the Rust code. - Link to v2: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v2-1-ccae224b6c85@gmail.com Changes in v2: - Omit resource control support. It was completely broken, and the way Spectrum run scripts work means that it is better to setup resource controls just before the execve() into the final service process. This will be done by a separate tool. - Link to v1: https://spectrum-os.org/lists/archives/spectrum-devel/20260620-cgroups-v1-1-0e5abf35101b@gmail.com --- Demi Marie Obenour (19): host/rootfs: Mount filesystems before s6-rc-init tools: Add control group manager Documentation: Mention control groups Mount cgroup2 filesystem at /sys/fs/cgroup host/rootfs: Enable controllers in non-root cgroups host/rootfs: Add comments where cgroups are intentionally not used host/rootfs: serial-getty-generator: Use cgroups host/rootfs: systemd-udevd: Run in cgroup host/rootfs: weston: Run in cgroup host/rootfs: Set up parent cgroup for all per-VM services host/rootfs: Create per-VM cgroup for all of the VM's services host/rootfs: run-vmm: Create per-VM cgroup host/rootfs: run-appimage: Purge the per-VM cgroup host/rootfs: run-flatpak: Purge the per-VM cgroup host/rootfs: dbus: Run in cgroup host/rootfs: vhost-user-fs: Run in cgroup host/rootfs: vhost-user-gpu: Run in cgroup host/rootfs: xdg-desktop-portal-spectrum-host: Run in cgroup host/rootfs: spectrum-router: Run in cgroup .codespellrc | 2 +- Documentation/doc/development/control-groups.adoc | 95 ++++++++ host/rootfs/default.nix | 6 +- host/rootfs/file-list.mk | 10 + host/rootfs/image/etc/fstab | 1 + host/rootfs/image/etc/init | 14 +- .../s6-linux-init/run-image/service/getty-tty2/run | 1 + .../s6-linux-init/run-image/service/getty-tty3/run | 1 + .../s6-linux-init/run-image/service/getty-tty4/run | 1 + .../run-image/service/root-terminal/run | 1 + .../run-image/service/s6-linux-init-shutdownd/run | 1 + .../run-image/service/s6-svscan-log/run | 1 + .../service/serial-getty-generator/finish | 5 + .../run-image/service/serial-getty-generator/run | 4 +- .../run-image/service/serial-getty/run | 1 + .../run-image/service/serial-getty/template/run | 1 + .../run-image/service/vm-services/run | 3 + .../vm-services/template/data/service/dbus/finish | 5 + .../vm-services/template/data/service/dbus/run | 2 + .../template/data/service/spectrum-router/finish | 5 + .../template/data/service/spectrum-router/run | 2 + .../template/data/service/vhost-user-fs/finish | 5 + .../template/data/service/vhost-user-fs/run | 5 +- .../template/data/service/vhost-user-gpu/finish | 5 + .../template/data/service/vhost-user-gpu/run | 2 + .../xdg-desktop-portal-spectrum-host/finish | 5 + .../service/xdg-desktop-portal-spectrum-host/run | 2 + .../run-image/service/vm-services/template/finish | 5 + .../run-image/service/vm-services/template/run | 4 + .../run-image/service/vmm/template/finish | 5 + .../rootfs/image/etc/s6-linux-init/scripts/rc.init | 7 - host/rootfs/image/etc/s6-rc/systemd-udevd/finish | 5 + host/rootfs/image/etc/s6-rc/systemd-udevd/run | 5 +- host/rootfs/image/etc/s6-rc/weston/finish | 5 + host/rootfs/image/etc/s6-rc/weston/run | 2 + host/rootfs/image/usr/bin/run-appimage | 7 +- host/rootfs/image/usr/bin/run-flatpak | 7 +- host/rootfs/image/usr/bin/run-vmm | 4 + host/rootfs/image/usr/bin/vm-stop | 5 +- pkgs/default.nix | 1 + tools/cgroup-setup/Cargo.lock | 67 +++++ tools/cgroup-setup/Cargo.lock.license | 2 + tools/cgroup-setup/Cargo.toml | 10 + tools/cgroup-setup/default.nix | 22 ++ tools/cgroup-setup/src/cgroup.rs | 269 +++++++++++++++++++++ tools/cgroup-setup/src/main.rs | 167 +++++++++++++ 46 files changed, 765 insertions(+), 20 deletions(-) --- base-commit: a7762d6f54b40560dd5255ce902e6e6a5d980fe9 change-id: 20260528-cgroups-d609e270e649 -- Sincerely, Demi Marie Obenour (she/her/hers)