Commit Graph
44 Commits
Author SHA1 Message Date
Jack Newman c058c05651 Fix AUTO_RELOAD typo 2023-01-05 09:00:51 +10:00
Joachim Wiberg d22dea74e3 Finalize refactor to new log macros, following-up to 37e3be9
This possible also mitigates the issue tracked in #307.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-10-09 12:52:40 +02:00
Joachim Wiberg c39106906d Check return value from iwatch_init(), found by Coverity
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-17 14:28:04 +02:00
Joachim Wiberg edc2d53923 cgroup: reduce loglevel for missing/disallowed cgroup support
A user with no cgroup support in kernel does not know what they are
missing, and a user running in a container has someone else managing
cgroups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-05-08 09:57:18 +02:00
Joachim Wiberg 108bbf56dd Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-19 19:35:49 +02:00
Joachim Wiberg a0820c7f20 Fix printf format specifier and formatting issues in use of log fns
Almost all related to and (less likely) possible causes of issue #236.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-04-14 00:26:14 +02:00
Joachim Wiberg 74ad34a0c5 Another case for when we need to silently disable cgroups
When running in a container we might not have the necessary privileges
to mount cgroups.  Don't cause error in this case, just log it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-02-13 22:45:47 +01:00
Joachim Wiberg 4fd95fdcbe Fix #215: disable cgroup support when cpu controller is missing
Previous patches only checked if cgroups v2 support was available in
the kernel.  If mounting failed cgroups support was disabled.

However, much of the core logic to cgroups in Finit revolve around the
CPU controller.  This patch adds checks to ensure that the kernel has
basic controller support as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-27 18:50:46 +01:00
Ming Liu add474e825 cgroup.c: fix a iwatcher initializing issue
iwatcher of cgroup needs to be initialized earlier before any
cgroup_add functions being called.

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2022-01-27 10:16:14 +01:00
Joachim Wiberg a37037ded4 Fix #188: support without cgroups v2 support
This patch adds support for detecting if the Linux kernel Fint runs on
has support for cgroups v2.  The probe is done very early, in runlevel
S, when attempting to mount /sys/fs/cgroup.  Meaning, the log message
may be lost on systems that do not run sysklogd[1].

Here's the relevant logs from a system running myLinux on a kernel
that has cgroups v2 support disabled:

    Jan 10 20:19:40 anarchy finit[1]: myLinux 2021.11-696-g8fddaf36ed, entering runlevel S
    Jan 10 20:19:40 anarchy finit[1]: Kernel does not support cgroups v2, disabling.
    Jan 10 20:19:41 anarchy finit[1]: myLinux 2021.11-696-g8fddaf36ed, entering runlevel 2

All code paths that attempt to set or query kernel cgroups config has
been short circuited when this happens.  However, this does not apply
to any cgroup related config in the Finit .conf files -- which may of
course be omitted.  Yet, if configuration directives exist, they will
be parsed and may cause error.

Also, the initctl tool checks if /sys/fs/cgroup is mounted at runtime
and disables all status output and commands that rely on the feature.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2022-01-10 21:21:35 +01:00
Joachim Wiberg 280d91b9bf Add support for new libite (-lite) header namespace
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from

   lite/*.h -> libite/*.h

This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config.  This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-12-06 21:38:20 +01:00
Ming Liu 00b33fbd42 Avoid using C++ key words
"protected" is a C++ key word, replace it with "is_protected" avoid
compiling failures with C++ compiler.

Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2021-08-29 10:35:08 +02:00
Joachim Wiberg c047e37a79 cgroup: ensure all services in init group remain as leaf nodes
The top-level cgroup init is a leaf group and should be treated as such,
even for user setup tasks/services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-05-15 10:29:29 +02:00
Joachim Wiberg 997f3d7862 cgroup: fix possible NULL pointer deref.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 18:58:32 +02:00
Joachim Wiberg f12f53692e cgroup: allow adding self (PID 0) to a leaf group
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 18:58:11 +02:00
Joachim Wiberg a42a789d29 Refactor, clean up removed top-level cgroups
The main purpose of this patch is to remove top-level cgroups when they
are remvoed from finit.conf.  However, this is tricky, becasue there may
still be supervised services (and children of them) running.  We must
postpone removal until a cgroup.events change.  To make matters worse,
events may arrive out-of-order, i.e. the last-child event for the parent
cgroup before the sub-group.

A spin-off from this patch is that we can now support arbitrarily long
group names and group config.  (Only applies to top-level cgroups, not
run/task/services.)

Limitations:
 - Processes in "removed" cgroups are not migrated/orphaned, the reasons
   are several: overhead and complexity and the fact that memory cannot
   be migrated
 - A lingering child of a moved service may prevent an old top-level
   cgroup from being removed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-09 17:49:55 +02:00
Joachim Wiberg 62c5a9d06d cgroup: add support for reserved cgroup 'root', for RT tasks
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-08 13:17:10 +02:00
Joachim Wiberg 4e6b9514d5 cgroup: check return value from fnwrite(), found by Coverity Scan
We check it everywhere else, and a log message for failing to move PID 1
to the init cgroup is useful as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:55:07 +02:00
Joachim Wiberg 3b495d7518 cgroup: fix too small buffer for strlcpy(), found by Coverity Scan
Off by one, of course.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:54:34 +02:00
Joachim Wiberg badf8701bf cgroup: fix use before NULL check, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:53:56 +02:00
Joachim Wiberg 85fa0d4926 cgroup: fix resource leak, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 13:53:25 +02:00
Joachim Wiberg c97c83bfb6 cgroup: basic instrumentation of critical functions
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:48 +02:00
Joachim Wiberg 19b18afac9 cgroup: Skip mkdir() and subtree control if group already exists
- No point in doing it twice
 - Don't anger the gods (possible kernel bugs)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 11:58:48 +02:00
Joachim Wiberg d43af8c9c1 Minor optimization, use strdupa() for small alloc ops.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-07 10:31:59 +02:00
Joachim Wiberg ca32cb0dfc cgroup: 'init' is a reserved leaf group with Finit
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-04-06 13:16:58 +02:00
Joachim Wiberg 665d212bd6 Add support for configuring cgroups and their settings on services
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.

Services can now be assigned to a cgroup, with optional extra settings
for that particular process group.  The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.

   cgroup maint cpu.weight:123,mem.max:10000

Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.

    cgroup.maint
    service foo
    service bar cgroup:mem.max:1000

This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.

NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-30 10:21:01 +02:00
Joachim Wiberg a1e38a3e40 cgroup: add missing pointer and result of fopen()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-22 14:28:25 +01:00
Joachim Wiberg 5b8fe12502 cgroup: error handling for critical operations
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-19 09:29:27 +01:00
Joachim Wiberg 6e24f2ff13 echo(): refactor and rename helper function -> fnwrite()
More often than not, the file to write to in sysfs changes rather than
the value.  This patch changes echo() into a fnwrite(), flipping what
is vsnprintf()'ed, and adds a stupid str() function that converts any
value (float/int/double/uint64_t) to a static string buffer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:25:11 +01:00
Joachim Wiberg d9993860cb cgroup: add inotify support for cgroup.events
Replaces previous cgreaper.sh functionality for release notification and
cleanup of service groups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:38 +01:00
Joachim Wiberg 6a6f3a8291 cgroup: refactor for cgroups v2, much cleaner + unified hieararchy
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1.  Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.

Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
            in cgroups v1 was handled by cgreaper.sh.  This is fixed
	    in the next commit in the series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-18 18:23:35 +01:00
Joachim Wiberg ce55f88a00 cgroup: add symlinks for traditional split controller world
Even systemd have collapsed a few of the cgroup controllers into a
semi-unified hierarchy and uses this approach.  We just take it to
the extreme and have collapsed all of them (like cgroup v2).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-16 16:47:08 +01:00
Joachim Wiberg 9842786453 cgroups: fix cpu.shares assignment and set memory hierarchy
- Fix obvious refactor mistake in cpu.shares assignment
- For unified memory hierarchy we need to set .use_hierarch=1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 12:27:46 +01:00
Joachim Wiberg 5428dea5bf cgroup: refactor, use a unified hierarchy for finit
As of now, the default finit cgroup behavior is to use a unified
hierarchy of controllers under /sys/fs/cgroup/finit.

We mount cpu,cpuacct,cpuset,memory (if available) and gain the
ability to control our three major groups: init, system, user.

The default CPU share setup is ~10% for init and user, and 90% for
system.  These are guaranteed CPU shares to ensure we do not starve
PID 1 or user processes.  Support for configuring these limits will
be added in a later commit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-14 11:07:13 +01:00
Joachim Wiberg 084b4ce8d3 cgroup: minor refactor/simplify
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-13 09:40:52 +01:00
Joachim Wiberg 3ed291789c Fix GCC warnings with _FORTIFY_SOURCE=2
- Decleare some return values with (void)fn(), for cases where
  we don't care (dropping table headers), or best effor
- Check return value from fgets() and chdir() in some cases that
  are valid, i.e., continuing execution is pointless

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-05 12:36:48 +01:00
Joachim Wiberg 464bc831a5 Minor refactor, create FINIT_CGPATH in finit.h to reduce duplicaiton
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:48:57 +01:00
Joachim Wiberg e84911fe52 cgroup: create 'name' or 'name:id' entries, not 'name:'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-03-04 23:46:25 +01:00
Joachim Wiberg a5714a058c Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2021-02-09 22:07:03 +01:00
Joachim Wiberg 24a78d3246 Update copyright years and author last name
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2020-09-02 23:38:11 +02:00
Joachim Nilsson 25c194ef93 Create unique service cgroup based on name:id
We want to have unique cgroups per instance.  I.e., a DHCP client for
eth0 should have its own cgroup separate from a DHCP client for eth1.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-04-11 21:50:38 +02:00
Joachim Nilsson 765ef63274 Handle mkdir() error in cgroups, don't fail if already exists
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2020-01-06 21:41:43 +01:00
Joachim Nilsson 0848b9b07a Minor, replace cgroup hard-coded path with path from configure
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-05-14 10:15:10 +02:00
Joachim Nilsson f51fde4d46 Initial support for cgroups
Similar to how systemd creates cgroups for all services, for purposes of
tracking, Finit now does the same.  We also mount all available cgroups
in the /sys/fs/cgroup namespace.

This patch adds support for grouping processes in logical cgroups, like
systemd, and an `initctl ps` command to list the hieararchy.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
2019-02-05 18:35:36 +01:00