From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 1627AAD7A; Thu, 30 Jul 2026 14:55:18 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id B9F50AD73; Thu, 30 Jul 2026 14:55:15 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,RCVD_IN_MSPIKE_H2, SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fhigh-b3-smtp.messagingengine.com (fhigh-b3-smtp.messagingengine.com [202.12.124.154]) by atuin.qyliss.net (Postfix) with ESMTPS id 3B4EFAD71 for ; Thu, 30 Jul 2026 14:55:14 +0000 (UTC) Received: from phl-compute-12.internal (phl-compute-12.internal [10.202.2.52]) by mailfhigh.stl.internal (Postfix) with ESMTP id DA8AE7A00A1; Thu, 30 Jul 2026 10:55:12 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-12.internal (MEProxy); Thu, 30 Jul 2026 10:55:12 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1785423312; x=1785509712; bh=Yz/y9uW98r 0W42OLCuSZiq2i4CC+/wjyRebteFVluvk=; b=qMmsjz/T8VsGuOxhRbgjqGOQAZ omhhXkeDbSh84NZDBLDLCUi7GrT/nX4JjlN2tvDuv0vBr30xD8n1jMbRnyFLcLI6 4vb2PIscTqaPd5fxULstjB8572cwF0oedAWGHHjyk+QUJvnetYC/wMNGTwtNfGrj WpmYElCJ0Z44fH6z7WG8/cQnDFCiHo3/OEWrlxY/0KnS6A9OKRyYb8AvqEaIgzoi df/+5YeGoe6/ayKKSbONarNo5wW63YImyeyAdReS0BtEA5aO6oR7hsHFdSlPWH7S /o7tnRcPy/gWKTH6JNnBipcshApM3tWMIEUm51p13z+jnwCqdSLaN5z6mCNw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1785423312; x=1785509712; bh=Yz/y9uW98r0W42OLCuSZiq2i4CC+/wjyReb teFVluvk=; b=p+HxgiDqok3djrCWEPzxVydhJxCzSULSpjEKVXWwar8HAV/lcHD PsPrnNK1A9s/2pb743xlk4wobVcP7GP/arBj/h8AQhFl1FFw3BxnpSOFYOA/uSl/ yc3X//kp93bUu1ieIVG869YA3fHler3f1jYL028IBmOnD7vWpk+tZMmxG2+Q+/qi 6PnfF/Fdzrg7Q+XoU9VDKnQ/R/rzqZYgzrF/U87s/9BNgihvEWayyg1w49W5QPnH ZlnlCfStp/2qatqzYSg3q3hUHw9Y0QiMmeHEZaRAgyCucnWpuIMSjb8uajHvvSGW FKH9jc/MSDiN9Es6E4vG7Gtnxt5FfZKk3/g== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTGZQ/QY48xsRa24MND7DtueAtjZLKrWaSoRBWWzesGx7LMcIS0GaZH89L+cVKEO68 iqk1cfEthgO1yqlSFIaQzpgUWhXanA1JMMr7g8NXY/KIYKjBhEKyx5OCMQ/G3G1bMO4vh4 Qyjfg6BFyZAkxlyMvfWzEFwH3TQa61Aa16nc/EvwRRb0979CbEHSSXIryF0TN1/5+mquhB 7FHnhFe5iqeotBxGZjkJIUwZEhK7/ZDmJUupXcpW3PotzbaoR/JO/FVz1/65R9ac/jzsNq myV4X205uhsgSgUuagHfVHpBGA6IsGKZ7lM9R7MAsxxcOcwI/kkxaavT26wkJ3DE1kplOE HxbY2+IUaBUFtIhURpXKQYFuCieqBcn5qQAlUTKZ2cEhfrKH7iyvMx7DnVhPpEuEMWhFLv 9Zqk7pkj8ZOcyggn8eHS/x1Uhm9YYfA5PqK71gTAIW4djN3USOuNUNkgrYcf9Uy+tc0ra+ VBl3e+3m+FK0ZsuFA2RWTDsuSCWQbLuGDejsfwGRjDoFtITrAGnO+MbD9fiN283MKCOx7N tY5nT/nZAMI1K61asEGcHZPtKy4YfIVaJ8xQpxdr9batwDw0/14bVBmFOHKWlMbRJrKkty m+5Bcni53HDAyGBe+T5xbL5n+++dTMfbZ6XLGOw4l0K/Cry42bTX2e9KlvwQ X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Thu, 30 Jul 2026 10:55:12 -0400 (EDT) Received: by mbp.qyliss.net (Postfix, from userid 1000) id 3B7FA8AFA675; Thu, 30 Jul 2026 16:55:11 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH v4 18/20] host/rootfs: systemd-udevd: Run in cgroup In-Reply-To: <8456ec8a-681b-4147-9494-ecf4f579252f@gmail.com> References: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> <20260721-cgroups-v4-18-46b2e5fff7b6@gmail.com> <87se54k4ir.fsf@alyssa.is> <3d1541ca-cb50-42f5-a289-697727773725@gmail.com> <878q6t6fvu.fsf@alyssa.is> <8456ec8a-681b-4147-9494-ecf4f579252f@gmail.com> Date: Thu, 30 Jul 2026 16:55:10 +0200 Message-ID: <87ecgkv86p.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: S6KFV4AE7O6UZ4UBSUSENIBKEOEZX5RC X-Message-ID-Hash: S6KFV4AE7O6UZ4UBSUSENIBKEOEZX5RC X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > On 7/29/26 10:15, Alyssa Ross wrote: >> Demi Marie Obenour writes: >>=20 >>> On 7/27/26 08:20, Alyssa Ross wrote: >>>> Demi Marie Obenour writes: >>>> >>>>> Signed-off-by: Demi Marie Obenour >>>>> --- >>>>> host/rootfs/file-list.mk | 1 + >>>>> host/rootfs/image/etc/s6-rc/systemd-udevd/finish | 5 +++++ >>>>> host/rootfs/image/etc/s6-rc/systemd-udevd/run | 5 +++-- >>>>> 3 files changed, 9 insertions(+), 2 deletions(-) >>>>> >>>>> diff --git a/host/rootfs/file-list.mk b/host/rootfs/file-list.mk >>>>> index e3411d40014342e67071a48f9e1c7bc7b3954bcf..065571ef3a5c61fa79a1d= 2ed878052a5f391be96 100644 >>>>> --- a/host/rootfs/file-list.mk >>>>> +++ b/host/rootfs/file-list.mk >>>>> @@ -106,6 +106,7 @@ S6_RC_FILES =3D \ >>>>> image/etc/s6-rc/systemd-udevd-coldplug/dependencies.d/systemd-udevd= \ >>>>> image/etc/s6-rc/systemd-udevd-coldplug/type \ >>>>> image/etc/s6-rc/systemd-udevd-coldplug/up \ >>>>> + image/etc/s6-rc/systemd-udevd/finish \ >>>>> image/etc/s6-rc/systemd-udevd/notification-fd \ >>>>> image/etc/s6-rc/systemd-udevd/run \ >>>>> image/etc/s6-rc/systemd-udevd/type \ >>>>> diff --git a/host/rootfs/image/etc/s6-rc/systemd-udevd/finish b/host/= rootfs/image/etc/s6-rc/systemd-udevd/finish >>>>> new file mode 100755 >>>>> index 0000000000000000000000000000000000000000..4d5b454e97c3584d0644c= 2d738514f13b1c53957 >>>>> --- /dev/null >>>>> +++ b/host/rootfs/image/etc/s6-rc/systemd-udevd/finish >>>>> @@ -0,0 +1,5 @@ >>>>> +#!/usr/bin/execlineb -WS3 >>>>> +# SPDX-License-Identifier: EUPL-1.2+ >>>>> +# SPDX-FileCopyrightText: 2026 Demi Marie Obenour >>>>> + >>>>> +cgroup-s6-finish $@ >>>>> diff --git a/host/rootfs/image/etc/s6-rc/systemd-udevd/run b/host/roo= tfs/image/etc/s6-rc/systemd-udevd/run >>>>> old mode 100644 >>>>> new mode 100755 >>>>> index aec6444e951503eae988e666b77fda8f2ae33d72..901f3e6667a8de04a6af3= 9945406a1757455f089 >>>>> --- a/host/rootfs/image/etc/s6-rc/systemd-udevd/run >>>>> +++ b/host/rootfs/image/etc/s6-rc/systemd-udevd/run >>>>> @@ -1,7 +1,8 @@ >>>>> -#!/bin/execlineb -WP >>>>> +#!/bin/execlineb -WS1 >>>>> # SPDX-License-Identifier: EUPL-1.2+ >>>>> # SPDX-FileCopyrightText: 2025 Demi Marie Obenour >>>>> -s6-setlock /run/sd-notify-wrapper/systemd-udevd.lock >>>>> + >>>>> +cgroup-setup --delegate --child-name udev -- $1 >>>>> s6-ipcserver-socketbinder -b0 -m -a 0600 /run/sd-notify-wrapper/syst= emd-udevd.sock >>>>> background -d { >>>>> fdmove 1 3 >>>>> >>>> >>>> Is there a reason not to always enable delegation? Is there a reason = we >>>> need to set the name here? >>> >>> --delegate only sets the user.delegate=3D1 xattr used by systemd. >>> Programs that are systemd-aware and manage their own cgroups check this >>> xattr to see if a cgroup has been delegated by systemd. The kernel >>> and other programs do not care. >>=20 >> Right, but why can't we just always set user.delegate=3D1? Would we ever >> have a program that checked it that we didn't want to manage its own >> cgroups? > > It's slightly wasteful (extra syscall) but harmless. > >>> systemd-udevd.service uses the "udev" name, so I decided to also use it >>> for consistency. >>=20 >> Is this the only reason we even need a --child-name feature? If so, it >> doesn't seem well justified to me unless it actually affects something. > > I'd prefer to stick with what systemd uses, as that is what is tested. > Varying from what systemd uses increases the risk of regressions. I'd be very surprised if the name of the cgroup is a practical regression risk. I don't think it justifies extra complexity in cgroup-setup. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRV/neXydHjZma5XLJbRZGEIw/wogUCamtlzgAKCRBbRZGEIw/w oknCAQCHMCvsdRbZF9s7RqW8LvNq14YTgFGCeQeynxXmdT/WogD/Y9DUUYV01iaN LOuRKf9oE0So3uGuhfy99h2TgIWz0QI= =oeSY -----END PGP SIGNATURE----- --=-=-=--