Author: Andy Green Date: Thu Jul 31 20:47:18 2025 +0100 cgroups: support builder encapsulation diff --git a/src/builder/b-nspawn.c b/src/builder/b-nspawn.c index 57a4a26..b595aa0 100644 --- a/src/builder/b-nspawn.c +++ b/src/builder/b-nspawn.c @@ -243,9 +243,9 @@ int saib_spawn(struct sai_nspawn *ns) { struct lws_spawn_piped_info info; - char args[290], st[2048], *p; + char args[290], st[2048], cgroup[128], *p; const char *respath = "unk"; - int fd, n; + int fd, n, in_cgroup = 1; const char * cmd[] = { "/bin/ps", NULL @@ -318,16 +318,20 @@ saib_spawn(struct sai_nspawn *ns) cmd[0] = args; + lws_snprintf(cgroup, sizeof(cgroup), "inst-%u-%d", (unsigned int)getpid(), ns->instance_idx); + memset(&info, 0, sizeof(info)); - info.vh = builder.vhost; - info.env_array = (const char **)env; - info.exec_array = cmd; - info.protocol_name = "sai-stdxxx"; - info.max_log_lines = 10000; - info.timeout_us = 30 * 60 * LWS_US_PER_SEC; - info.reap_cb = sai_lsp_reap_cb; - info.opaque = ns; - info.plsp = &ns->lsp; + info.vh = builder.vhost; + info.env_array = (const char **)env; + info.exec_array = cmd; + info.protocol_name = "sai-stdxxx"; + info.max_log_lines = 10000; + info.timeout_us = 30 * 60 * LWS_US_PER_SEC; + info.reap_cb = sai_lsp_reap_cb; + info.opaque = ns; + info.plsp = &ns->lsp; + info.cgroup_name_suffix = cgroup; + info.p_cgroup_ret = &in_cgroup; ns->lsp = lws_spawn_piped(&info); if (!ns->lsp) { @@ -336,7 +340,7 @@ saib_spawn(struct sai_nspawn *ns) return 1; } - lwsl_notice("%s: lws_spawn_piped started\n", __func__); + lwsl_notice("%s: lws_spawn_piped started (cgroup: %d)\n", __func__, in_cgroup); return 0; } diff --git a/src/builder/b-sai.c b/src/builder/b-sai.c index ca4af05..26e34d0 100644 --- a/src/builder/b-sai.c +++ b/src/builder/b-sai.c @@ -31,6 +31,10 @@ #include #include +#include +#include +#include + #if defined(__linux__) #include #endif @@ -847,6 +851,22 @@ int main(int argc, const char **argv) return 1; } +#if defined(__linux__) + /* + * At this point we're still root. So we should be able + * to register our toplevel cgroup OK + */ + { + struct passwd *pwd = getpwuid(sb.st_uid); + struct group *grp = getgrgid(sb.st_gid); + + if (lws_spawn_prepare_self_cgroup(pwd->pw_name, grp->gr_name)) { + lwsl_err("%s: failed to initialize cgroup dir %s %s\n", __func__, pwd->pw_name, grp->gr_name); + return 1; + } + } +#endif + #if !defined(__linux__) && !defined(WIN32) /* we are still root */ mkdir(UDS_PATHNAME_LOGPROXY, 0700);