A user with no cgroup support in kernel does not know what they are
missing, and a user running in a container has someone else managing
cgroups.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When running in a container we might not have the necessary privileges
to mount cgroups. Don't cause error in this case, just log it.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Previous patches only checked if cgroups v2 support was available in
the kernel. If mounting failed cgroups support was disabled.
However, much of the core logic to cgroups in Finit revolve around the
CPU controller. This patch adds checks to ensure that the kernel has
basic controller support as well.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for detecting if the Linux kernel Fint runs on
has support for cgroups v2. The probe is done very early, in runlevel
S, when attempting to mount /sys/fs/cgroup. Meaning, the log message
may be lost on systems that do not run sysklogd[1].
Here's the relevant logs from a system running myLinux on a kernel
that has cgroups v2 support disabled:
Jan 10 20:19:40 anarchy finit[1]: myLinux 2021.11-696-g8fddaf36ed, entering runlevel S
Jan 10 20:19:40 anarchy finit[1]: Kernel does not support cgroups v2, disabling.
Jan 10 20:19:41 anarchy finit[1]: myLinux 2021.11-696-g8fddaf36ed, entering runlevel 2
All code paths that attempt to set or query kernel cgroups config has
been short circuited when this happens. However, this does not apply
to any cgroup related config in the Finit .conf files -- which may of
course be omitted. Yet, if configuration directives exist, they will
be parsed and may cause error.
Also, the initctl tool checks if /sys/fs/cgroup is mounted at runtime
and disables all status output and commands that rely on the feature.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to an unfortunate name clash with the DirectFB project LiTE, the
libite (-lite) project had to change its header namespace from
lite/*.h -> libite/*.h
This patch adds support for the new namepace in Finit, triggered by the
define _LIBITE_LITE, from the .pc file read by pkg-config. This should
only be needed on systems that install libite without the compatibility
symlink lite -> libite/ in the staging include directory.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
"protected" is a C++ key word, replace it with "is_protected" avoid
compiling failures with C++ compiler.
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
The top-level cgroup init is a leaf group and should be treated as such,
even for user setup tasks/services.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The main purpose of this patch is to remove top-level cgroups when they
are remvoed from finit.conf. However, this is tricky, becasue there may
still be supervised services (and children of them) running. We must
postpone removal until a cgroup.events change. To make matters worse,
events may arrive out-of-order, i.e. the last-child event for the parent
cgroup before the sub-group.
A spin-off from this patch is that we can now support arbitrarily long
group names and group config. (Only applies to top-level cgroups, not
run/task/services.)
Limitations:
- Processes in "removed" cgroups are not migrated/orphaned, the reasons
are several: overhead and complexity and the fact that memory cannot
be migrated
- A lingering child of a moved service may prevent an old top-level
cgroup from being removed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We check it everywhere else, and a log message for failing to move PID 1
to the init cgroup is useful as well.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for modifying settings for the default cgroups;
init, user, and system, as well as adding up to a total of eight groups
for the system.
Services can now be assigned to a cgroup, with optional extra settings
for that particular process group. The syntax is slightly contrivied
but follows the overall Finit syntax of prop:value,prop':value', e.g.
cgroup maint cpu.weight:123,mem.max:10000
Starting with the introduction of rlimits, a group of services sharing
the same .conf file can share the same (locally "global") rlimits, and
now also the same cgroup, e.g.
cgroup.maint
service foo
service bar cgroup:mem.max:1000
This puts foo and bar in the same top-level cgroup 'maint', with an
extra memory restriction on bar for max 1000 bytes memory.
NOTE: 'mem.' is a Finit extension, a shorthand for cgroups2 'memory.'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
More often than not, the file to write to in sysfs changes rather than
the value. This patch changes echo() into a fnwrite(), flipping what
is vsnprintf()'ed, and adds a stupid str() function that converts any
value (float/int/double/uint64_t) to a static string buffer.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Replaces previous cgreaper.sh functionality for release notification and
cleanup of service groups.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Since the cgroups support in Finit is not yet officially released, we
decided to change the back-end to use cgroups v2 instead of the aging
and rather clumsy cgroups v1. Even this initial refactor is a lot
easier to read and understand, more can still be done since there's
a lot of concepts, data values and the ilk that can now be shared
between different controllers.
Still ToDo: inotify for cgroup.events to clean up leaf nodes, which
in cgroups v1 was handled by cgreaper.sh. This is fixed
in the next commit in the series.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Even systemd have collapsed a few of the cgroup controllers into a
semi-unified hierarchy and uses this approach. We just take it to
the extreme and have collapsed all of them (like cgroup v2).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Fix obvious refactor mistake in cpu.shares assignment
- For unified memory hierarchy we need to set .use_hierarch=1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
As of now, the default finit cgroup behavior is to use a unified
hierarchy of controllers under /sys/fs/cgroup/finit.
We mount cpu,cpuacct,cpuset,memory (if available) and gain the
ability to control our three major groups: init, system, user.
The default CPU share setup is ~10% for init and user, and 90% for
system. These are guaranteed CPU shares to ensure we do not starve
PID 1 or user processes. Support for configuring these limits will
be added in a later commit.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Decleare some return values with (void)fn(), for cases where
we don't care (dropping table headers), or best effor
- Check return value from fgets() and chdir() in some cases that
are valid, i.e., continuing execution is pointless
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We want to have unique cgroups per instance. I.e., a DHCP client for
eth0 should have its own cgroup separate from a DHCP client for eth1.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Similar to how systemd creates cgroups for all services, for purposes of
tracking, Finit now does the same. We also mount all available cgroups
in the /sys/fs/cgroup namespace.
This patch adds support for grouping processes in logical cgroups, like
systemd, and an `initctl ps` command to list the hieararchy.
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>