Commit Graph
26 Commits
Author SHA1 Message Date
Joachim Wiberg 3b495d7518 cgroup: fix too small buffer for strlcpy(), found by Coverity Scan
Off by one, of course.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:54:34 +02:00
Joachim Wiberg badf8701bf cgroup: fix use before NULL check, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:53:56 +02:00
Joachim Wiberg 85fa0d4926 cgroup: fix resource leak, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:53:25 +02:00
Joachim Wiberg c97c83bfb6 cgroup: basic instrumentation of critical functions
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:48 +02:00
Joachim Wiberg 19b18afac9 cgroup: Skip mkdir() and subtree control if group already exists
- No point in doing it twice
 - Don't anger the gods (possible kernel bugs)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:48 +02:00
Joachim Wiberg d43af8c9c1 Minor optimization, use strdupa() for small alloc ops.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 10:31:59 +02:00
Joachim Wiberg ca32cb0dfc cgroup: 'init' is a reserved leaf group with Finit
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-06 13:16:58 +02:00
Joachim Wiberg 665d212bd6 Add support for configuring cgroups and their settings on services
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.

Services can now be assigned to a cgroup, with optional extra settings
for that particular process group.  The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.

   cgroup maint cpu.weight:123,mem.max:10000

Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.

    cgroup.maint
    service foo
    service bar cgroup:mem.max:1000

This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.

NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-30 10:21:01 +02:00
Joachim Wiberg a1e38a3e40 cgroup: add missing pointer and result of fopen()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-22 14:28:25 +01:00
Joachim Wiberg 5b8fe12502 cgroup: error handling for critical operations
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-19 09:29:27 +01:00
Joachim Wiberg 6e24f2ff13 echo(): refactor and rename helper function -> fnwrite()
More often than not, the file to write to in sysfs changes rather than
the value.  This patch changes echo() into a fnwrite(), flipping what
is vsnprintf()'ed, and adds a stupid str() function that converts any
value (float/int/double/uint64_t) to a static string buffer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:25:11 +01:00
Joachim Wiberg d9993860cb cgroup: add inotify support for cgroup.events
Replaces previous cgreaper.sh functionality for release notification and
cleanup of service groups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:38 +01:00
Joachim Wiberg 6a6f3a8291 cgroup: refactor for cgroups v2, much cleaner + unified hieararchy
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1.  Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.

Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
            in cgroups v1 was handled by cgreaper.sh.  This is fixed
	    in the next commit in the series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:35 +01:00
Joachim Wiberg ce55f88a00 cgroup: add symlinks for traditional split controller world
Even systemd have collapsed a few of the cgroup controllers into a
semi-unified hierarchy and uses this approach.  We just take it to
the extreme and have collapsed all of them (like cgroup v2).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-16 16:47:08 +01:00
Joachim Wiberg 9842786453 cgroups: fix cpu.shares assignment and set memory hierarchy
- Fix obvious refactor mistake in cpu.shares assignment
- For unified memory hierarchy we need to set .use_hierarch=1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 12:27:46 +01:00
Joachim Wiberg 5428dea5bf cgroup: refactor, use a unified hierarchy for finit
As of now, the default finit cgroup behavior is to use a unified
hierarchy of controllers under /sys/fs/cgroup/finit.

We mount cpu,cpuacct,cpuset,memory (if available) and gain the
ability to control our three major groups: init, system, user.

The default CPU share setup is ~10% for init and user, and 90% for
system.  These are guaranteed CPU shares to ensure we do not starve
PID 1 or user processes.  Support for configuring these limits will
be added in a later commit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:07:13 +01:00
Joachim Wiberg 084b4ce8d3 cgroup: minor refactor/simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:40:52 +01:00
Joachim Wiberg 3ed291789c Fix GCC warnings with _FORTIFY_SOURCE=2
- Decleare some return values with (void)fn(), for cases where
  we don't care (dropping table headers), or best effor
- Check return value from fgets() and chdir() in some cases that
  are valid, i.e., continuing execution is pointless

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 12:36:48 +01:00
Joachim Wiberg 464bc831a5 Minor refactor, create FINIT_CGPATH in finit.h to reduce duplicaiton
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:48:57 +01:00
Joachim Wiberg e84911fe52 cgroup: create 'name' or 'name:id' entries, not 'name:'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:46:25 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson 25c194ef93 Create unique service cgroup based on name:id
We want to have unique cgroups per instance.  I.e., a DHCP client for
eth0 should have its own cgroup separate from a DHCP client for eth1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-11 21:50:38 +02:00
Joachim Nilsson 765ef63274 Handle mkdir() error in cgroups, don't fail if already exists
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-06 21:41:43 +01:00
Joachim Nilsson 0848b9b07a Minor, replace cgroup hard-coded path with path from configure
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-05-14 10:15:10 +02:00
Joachim Nilsson f51fde4d46 Initial support for cgroups
Similar to how systemd creates cgroups for all services, for purposes of
tracking, Finit now does the same.  We also mount all available cgroups
in the /sys/fs/cgroup namespace.

This patch adds support for grouping processes in logical cgroups, like
systemd, and an `initctl ps` command to list the hieararchy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-02-05 18:35:36 +01:00