From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 0B2C69505; Mon, 27 Jul 2026 11:27:31 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 2CB7E94E3; Mon, 27 Jul 2026 11:27:28 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fhigh-a6-smtp.messagingengine.com (fhigh-a6-smtp.messagingengine.com [103.168.172.157]) by atuin.qyliss.net (Postfix) with ESMTPS id 7214C94E2 for ; Mon, 27 Jul 2026 11:27:27 +0000 (UTC) Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfhigh.phl.internal (Postfix) with ESMTP id 947061400126; Mon, 27 Jul 2026 07:27:26 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Mon, 27 Jul 2026 07:27:26 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1785151646; x=1785238046; bh=wo+NooUP/t kdhy7usAdzliBPIqsBEi9GGmdPBa55JHs=; b=DCHrX7UWoe/OYryheQ3OcekCZi LkbSA3PJrYiuEX8G1XoOo5hS9QxKWtwpxlaV0Ph/hj/YZh/skvG0uaPzJceN/2De oF9gS4qFlfS2ueexU0h5Z/qP4V/FGBoFzBTewEvznMzIdIZKj6sO0rl3GhuAX8nE b8iIcd4so46PmjilVMNvtl1OCMz36pLDFhbYoGr4RbOmXt/Hpr8yWBZlBPQMIoLl f+ciy85hnpjzfgRJNL+n3jPom1vNaZKtHsA2m4bt2iaXo2mWVoL6fXNoaRIB0R09 upwYNyt5bx0/+ScY13T2BeUdGFN54sDICAeABrJI2I1Uo8mOMzXaSaXOsHGQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1785151646; x=1785238046; bh=wo+NooUP/tkdhy7usAdzliBPIqsBEi9GGmd PBa55JHs=; b=DypV9oVEZAhb10EfW9uGvvCx5YaCxy8PLg4BbZeldRbYGNxCnuJ lY5f+gzijqOq8+MSN8h5Nx4AaD4tGBr052RI0v+C7z7o9azorjz3S3qUK0clX2l0 impZBRxWsYs0DqMXkie2SfkfWY2FXLOa1Vg8qn31ZfvFaLt0crMnPHbSxThOp2hQ OuU986epLum0eLCkOjllfWBE0A4mdRqpZQ6scGCk1ZFUeUea2DjL52eUhIIeRjMX K9B505KgaSEj0Ma4eF8aqrBnqr5+lebUTBg7Fi34y+wXSVpMareJghUJptahn7M6 rNe4g6pxkNMQ6TuS5wV6/tiUXqmbaa4VsGA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTEj3GqVUuPyLt3T2TSN5Ow786sNK02PFw5DLqE7OkUTxCdA22QTOFkwMzI8w/i8cG vKfZE6qSyOr/CS+f0cA36742RxkGVRC4u5eojYzCkd2Ir06WYYxGUZfXIgt2J85eTXaUt2 GaNOZFixRFIkNWUPSOre4enhHuiF7+e4QJb8LqZTG3FvJFe99VDj2wRCbeoOU3XmvlJrnP xw/fEIMgQWCs33thC4V+///Z3RT9hqN2PiSxUEzxaXqDdVEAJJwN3qMCaPurFmhr9opGki xzVTX94WNhtbNo603UuGl2Yi7zAjlJjnuZa/CUQvaF1nLrEvI7+8+dMlM9ETuYaxGu5ggw yYMbt7B9figRrtij0nEOWM+nsbOCGELize6yNMXGTgTB77D/RpDsm8+/ZDLVlDJl3TkA6z WOae+Viaz25ICwZXjLSbOvme5qqkwFlroOPk5cl6caBSev/vhaI1zTYJ/17rLBNEcibD/5 St0eNwO4RMKU7Nq3+Plk+uxphUwxjRf2BUENlCNfDocCKQrhkG4eErQCtxRxLYjWOoKXIx gK3VvLsrdfSXQ7/qT2l641TFoNlscOlhe5cCEWNZSf8Dn8y9LtLnXpeT1Sl9Mox4kA4Uw1 A0j+EVzHTYcb8fiFafn8EnApkTYq5XEZ8E9cV6mFDWXCQ+wrNc+2NB6lA++g X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 27 Jul 2026 07:27:26 -0400 (EDT) Received: by fw12.qyliss.net (Postfix, from userid 1000) id 4E20DC4D7656; Mon, 27 Jul 2026 13:27:25 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH v4 05/20] host/rootfs: Add helper program for per-VM services In-Reply-To: <20260721-cgroups-v4-5-46b2e5fff7b6@gmail.com> References: <20260721-cgroups-v4-0-46b2e5fff7b6@gmail.com> <20260721-cgroups-v4-5-46b2e5fff7b6@gmail.com> Date: Mon, 27 Jul 2026 13:27:24 +0200 Message-ID: <87fr14llk3.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: JCS6L4TFX2S2DNPVN63UIGPCZDEHK3PG X-Message-ID-Hash: JCS6L4TFX2S2DNPVN63UIGPCZDEHK3PG X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > The program handles cgroups and common substitutions. This is better > than repeating the boilerplate multiple times. > > Signed-off-by: Demi Marie Obenour > --- > host/rootfs/file-list.mk | 1 + > host/rootfs/image/usr/bin/vm-service-run | 34 ++++++++++++++++++++++++++= ++++++ > 2 files changed, 35 insertions(+) > > diff --git a/host/rootfs/file-list.mk b/host/rootfs/file-list.mk > index e1280ab56d8797e40b9b1c584ab0daef3cda41d7..c707c01179238231f70164ffd= a5b7c940b34192a 100644 > --- a/host/rootfs/file-list.mk > +++ b/host/rootfs/file-list.mk > @@ -65,6 +65,7 @@ FILES =3D \ > image/usr/bin/spectrum-update \ > image/usr/bin/vm-console \ > image/usr/bin/vm-import \ > + image/usr/bin/vm-service-run \ > image/usr/bin/vm-start \ > image/usr/bin/vm-stop \ > image/usr/bin/xdg-open \ > diff --git a/host/rootfs/image/usr/bin/vm-service-run b/host/rootfs/image= /usr/bin/vm-service-run > new file mode 100755 > index 0000000000000000000000000000000000000000..c788574cf95ec7fd0d93b6565= 57f85fa80b31690 > --- /dev/null > +++ b/host/rootfs/image/usr/bin/vm-service-run > @@ -0,0 +1,34 @@ > +#!/usr/bin/execlineb -WS1 > +# SPDX-License-Identifier: EUPL-1.2+ > +# SPDX-FileCopyrightText: 2026 Demi Marie Obenour > + > +# Substitute all of the needed environment variables > +# into both this script and its arguments > +# (the subsequent command to run). This substitutes > +# the *caller*'s arguments. > +multisubstitute { > + importas -iS VM > + importas -iS "#" > + importas -iS "1" > + importas -iS WAYLAND_DISPLAY > +} > + > +# Check that the VM name and service are reasonable. > +# Then run the cgroup-setup program and the provided > +# command line. Avoid premature substitution by > +# escaping ${#} and ${1} with backslashes. Otherwise, > +# they would be values for this script, not for the caller. > +case -- "\\${#}@${VM}@\\${1}" { > + # s6-supervise might start passing extra arguments in the future, but > + # 0 arguments is not okay. > + "[1-9][0-9]*@[A-Za-z0-9_][A-Za-z0-9_.-]*@[A-Za-z_][A-Za-z0-9_-]*" { > + # The caller has been migrated from using -WS1 to using -Wp. > + # Pop the environment to preserve the original behavior. > + emptyenv -P cgroup-setup --leaf -- "\\${1}" $@ > + } > +} > +fdmove -c 1 2 > +if { printf "Wrong VM name %s, \ > +parent argument count %s, or parent argument %s\n" > + $VM "\\$#" "\\${1}" } > +exit 100 Not sure I get this. This validation looks quite complicated and prescriptive, and why are we substituting e.g. WAYLAND_DISPLAY in here when not every service is going to need it? I fear that this is the sort of deduplication and validation that makes things harder to understand and maintain=E2=80=A6 --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQGoGac7QfI+H5ZtFCZddwkt31pFQUCamdAnAAKCRCZddwkt31p FR5mAP95bk1Rm3ILBu59ZNl9PcTtPje5i95N6b6FdN7GfIdoZwEAsMhjPavRq0nD /qsX7+rpf9VguJUw9GZsLF0m1axCywg= =/QXR -----END PGP SIGNATURE----- --=-=-=--