From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 9CA23A53B; Wed, 29 Jul 2026 14:13:55 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 95395A4AD; Wed, 29 Jul 2026 14:13:52 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fhigh-b7-smtp.messagingengine.com (fhigh-b7-smtp.messagingengine.com [202.12.124.158]) by atuin.qyliss.net (Postfix) with ESMTPS id A080FA4AC for ; Wed, 29 Jul 2026 14:13:50 +0000 (UTC) Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfhigh.stl.internal (Postfix) with ESMTP id 43C197A0164; Wed, 29 Jul 2026 10:13:48 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Wed, 29 Jul 2026 10:13:48 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1785334428; x=1785420828; bh=xgopwrAVih KmfVLMw0uhy6L0t1hcQRId3tiY2+02uJE=; b=bYQ10jwvQXDieZh2ee/WtrHtt+ mSHjfo7Og52612OMTmzy8kUVK4NQuVZlnVmpEQuz9Fvw2CmZKvrlAkBvgbr8sqRR IPrzEfmxDGVb2DDNCAeUX4P/Ax7N7vn4/RskX5JLHV97XxjDpcJMK5dNmiIhGSi7 8VDxqhtdn4w3hnRm0rHgsMgZVT1a1OOJw64FI1ePd0Twilu8MUs2D6Mg0voxMeMD JYSokYSR7qirfICjO581qrSJa2avr3260RtSLZmN5srmDNLgctvzyz8tgmoqlq32 Z7IMtTwki7G3xPwDXVA7mBvczlp8zWqGixyo9XJbmSX/R41uB4tkvqDeXsTA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1785334428; x=1785420828; bh=xgopwrAVihKmfVLMw0uhy6L0t1hcQRId3ti Y2+02uJE=; b=kjfLg3JOUxVcRcBTD5r+J3rlkfaeGT5ylFtvbB8a/0vXIZFxAJi uabaVGpn1GZW4oAokDZtXSSaktRSdp67GJ8aBy5NKIHlK3lynp7hiyZ8K84/e173 454CJhBrDKhfi3TcFmGC3CyBgNkg0EQ8X87/nxt0rlgIkW5bXBN0mkU0TXaEOBuF 690AgZTfGdUHF3p068IyRSQ5i61rvOiMStlD0UjJOONCGVsNR8QmhTmEW7/Z1Kvn +cpSZhzLWfDJaKEIU58P1TDjP7kNM1zfFFQ4zJIxTBlNX3pQJAluetK63whe3TRD p8lJpUFEPjIt0OI4DcN/krZTug9E5iTNKTg== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTEsDNx2VeLPX2RPYdCwsrmBNar3BTcgbfWLsPA0cbCTNqKJITmHGR5ZmCa6Ek0fYw fTZDtePD/Tz4z1VCf1Ys2qFvkm7ns2HKeBVgI01m0Lc2DvyUj+nmMKdr8HjiLAlpiLcFyx soDz608kvBuYESB+zKjAWft+XDwNhKXWAhLThjYjyDU91xOKNVo3x6AhsGtmZqtZ/DJuS6 dZLyLla6XVmKuJFZeKVYYwvx4tFYWi9cY2wRt1kACiU7l8zRvl8yzGK3mpGUEgZdiJN18w wz9hl8Gufmv5hciu+72krGQ8q5EZA7lyo8jREy2vOcSxXYpJ8x47rbzsyGti8hvph9glCL xo18gY6MNSj7S6F2dkZ8ZpDq4zuHd/mZh7Kg7XOinon4+rQ0r++7tLXdIMDzt1VjpAa5xJ Zb75bYS4pJdYpXlFmipuygNYQt+e6Hf5ETsy9RpTJHv9Tmr4abjcYpXbwZVoir9s2SSHGX hHkMBU2UNM/3Ci4ZKXOL4fgR5cSZzWWZEXlasPeLV3wAbGgaxWL26Wjg1DExHgDH0uzFAD GKJodAmTXMgRuaZZ6Fe2UvHtOM9lY7A2zbSC83EP2ST2VxEYpdqkOXhQRkwrFVkVflB6+2 aAE+CBepUTfrRH/b7U18GlKvl/IOvnxzOhOIYCxSZ0cvo8opEr0Gm3DBq53g X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 29 Jul 2026 10:13:47 -0400 (EDT) Received: by fw12.qyliss.net (Postfix, from userid 1000) id 0F69BC4E6F73; Wed, 29 Jul 2026 16:13:46 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH v4 06/20] host/rootfs: Enable controllers in sub-cgroups In-Reply-To: References: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> <20260721-cgroups-v4-6-46b2e5fff7b6@gmail.com> <87a4rclji0.fsf@alyssa.is> Date: Wed, 29 Jul 2026 16:13:44 +0200 Message-ID: <87bjbp6fzb.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: WS2XMSVCT7SJWQHKCRYTZREMOIRUXOCI X-Message-ID-Hash: WS2XMSVCT7SJWQHKCRYTZREMOIRUXOCI X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > On 7/27/26 08:11, Alyssa Ross wrote: >> Demi Marie Obenour writes: >>=20 >>> Actually use the cgroup manager for the first time. >>> >>> Signed-off-by: Demi Marie Obenour >>> --- >>> host/rootfs/image/etc/init | 4 ++++ >>> 1 file changed, 4 insertions(+) >>> >>> diff --git a/host/rootfs/image/etc/init b/host/rootfs/image/etc/init >>> index 8ec7859ab00e24007a93d4000c8f34e353de50ae..5d31a23bae2f29f35bfeced= 68242dededf6ae0c7 100755 >>> --- a/host/rootfs/image/etc/init >>> +++ b/host/rootfs/image/etc/init >>> @@ -12,4 +12,8 @@ if { /bin/ln -s /proc/self/fd/2 /dev/stderr } >>> if { /bin/mount --make-shared / } >>> if { /bin/mount -a --mkdir } >>>=20=20 >>> +# Enable subtree control of all cgroups and move >>> +# process to a child cgroup. >>> +/usr/bin/cgroup-setup --init-subtree . >>> + >>> /bin/s6-linux-init -c /etc/s6-linux-init -s /run/param -- $@ >>> >>=20 >> Why do we need this? Isn't the root cgroup an exception to the "no >> internal processes" rule? > > It is indeed exempt, though as systemd does create a sub-cgroup for > itself (init.scope) I don't know if the corresponding code paths in the > kernel are well-tested. However, enabling controllers *is* necessary. > If you'd prefer, I can use sed for that. I'd prefer to leave things as they come unless we have a reason not to. I wonder if there's a technical reason for systemd to do that, or if it just fit into their design better? If you can write a comment explaining why we need a cgroup, then this is fine; otherwise let's stick to what's strictly necessary. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQGoGac7QfI+H5ZtFCZddwkt31pFQUCamoKmAAKCRCZddwkt31p Fd9PAP9eQEHpPx85GOLPwTgLnF6f4HEp+jLVJ0kghUATTWMbKQEA/s/ERoNzRFYb FhLG70sR6b+E0AVK2V82HEnizgoJGAM= =hkG8 -----END PGP SIGNATURE----- --=-=-=--