Compare commits

...

26 Commits

Author SHA1 Message Date
Fupan Li
4d8f704a4b Merge pull request #89 from Tim-Zhang/release-0.2.11
release: v0.2.11
2022-09-23 19:14:29 +08:00
Tim Zhang
860b484a30 release: v0.2.11
Release version 0.2.11

Signed-off-by: Tim Zhang <tim@hyper.sh>
2022-09-23 19:10:10 +08:00
Tim Zhang
99da9eeb1f Merge pull request #88 from Tim-Zhang/customized-attr-blkio
blkio: Add support for customized-attributes
2022-09-23 19:09:11 +08:00
Tim Zhang
ed49cf77e2 blkio: Add support for customized-attributes
Customized attributes are useful for customized kernels

Signed-off-by: Tim Zhang <tim@hyper.sh>
2022-09-23 17:43:17 +08:00
Tim Zhang
8f65a0ef89 Merge pull request #87 from quanweiZhou/add-retry-for-rmdir
fix: support retry for rmdir cgroup path
2022-09-23 11:07:20 +08:00
quanwei.zqw
f863f31395 fix: support retry for rmdir cgroup path
Compatible with runC for remove dir operation
https://github.com/opencontainers/runc/blob/main/libcontainer/cgroups/utils.go#L272

Signed-off-by: quanwei.zqw <quanwei.zqw@alibaba-inc.com>
2022-09-23 10:26:03 +08:00
Fupan Li
91e66f0197 Merge pull request #83 from Tim-Zhang/release-0.2.10
release: v0.2.10
2022-06-29 16:48:56 +08:00
Tim Zhang
3340211c6e release: v0.2.10
Release version 0.2.10

Signed-off-by: Tim Zhang <tim@hyper.sh>
2022-06-29 16:44:00 +08:00
Tim Zhang
bd31dc0e7d Merge pull request #82 from dubek/ignore-set-kmem-limit-unsupported
memory: set_kmem_limit: ignore Unsupported error
2022-06-29 10:21:49 +08:00
Dov Murik
0c908cddf8 memory: set_kmem_limit: ignore Unsupported error
Setting (writing into) `memory.kmem.limit_in_bytes` is not supported in
Linux kernel >= 5.16 (see kernel commit 58056f77502: "memcg, kmem:
further deprecate kmem.limit_in_bytes"):
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=58056f77502

If the write call in `set_kmem_limit()` returns EOPNOTSUPP, log a
warning message but ignore the error (do nothing).

Add a unit-test for `set_kmem_limit` in cgroups v1.

Fix #81

Signed-off-by: Dov Murik <dov.murik1@il.ibm.com>
2022-06-27 08:29:40 +00:00
Tim Zhang
556dea62b9 Merge pull request #78 from esrlabs/pr-clippy
clippy: Fix clippy version 0.1.60
2022-06-01 18:50:25 +08:00
Bin Liu
1a8f9823eb Merge pull request #79 from esrlabs/pr-android
fix: build for aarch64-linux-android
2022-05-25 23:01:33 +08:00
Bin Liu
dda639f5ab Merge pull request #77 from rtzoeller/nix_0.24
Upgrade nix to 0.24, limit features
2022-05-25 22:58:46 +08:00
Ryan Zoeller
476219ab93 Upgrade nix to 0.24, limit features
This removes memoffset as an indirect dependency, and should decrease build times slightly.

Signed-off-by: Ryan Zoeller <rtzoeller@rtzoeller.com>
2022-04-30 18:37:57 -05:00
Felix Obenhuber
138c85c4b1 fix: build for aarch64-linux-android
With #77 nix provides statfs::CGROUP2_SUPER_MAGIC for the target_os
"android". Fix the build build for `target_os = "android"` by adding
this cfg setting to the "linux and not musl" impl of
`is_cgroup2_unified_mode`.

This patch depends opn #77 beeing merged.

Signed-off-by: Felix Obenhuber <felix@obenhuber.de>
2022-04-28 16:39:58 +02:00
Felix Obenhuber
92122de48d clippy: Fix clippy version 0.1.60
Fix clippy lints from clippy 0.1.60 (7737e0b 2022-04-04).

Signed-off-by: Felix Obenhuber <felix@obenhuber.de>
2022-04-28 16:36:57 +02:00
Fupan Li
1df6e7a26e Merge pull request #75 from Tim-Zhang/release-0.2.9
release: v0.2.9
2022-03-03 11:39:13 +08:00
Tim Zhang
1bdd52470f release: v0.2.9
Release version 0.2.9

Signed-off-by: Tim Zhang <tim@hyper.sh>
2022-03-03 10:37:13 +08:00
Fupan Li
231d9d599e Merge pull request #74 from Tim-Zhang/avoid-panic-in-hugetlb
hugetlb: avoid panic caused by readdir in get_hugepage_sizes()
2022-03-02 18:12:48 +08:00
Fupan Li
a3bd03c662 Merge pull request #73 from Burning1020/pid-cgroup-path
cgroup: support get cgroup relative paths by process pid
2022-03-02 18:12:10 +08:00
Tim Zhang
8932df3fa0 hugetlb: avoid panic caused by readdir in get_hugepage_sizes()
The error EBADF might be occured during readdir()
Skip the size when the error apperar, do not panic.

Signed-off-by: Tim Zhang <tim@hyper.sh>
2022-03-02 17:07:50 +08:00
Zhang Tianyang
fa94a1174f cgroup: support get cgroup relative paths by process pid
support get cgroup relative paths by process pid

Signed-off-by: Zhang Tianyang <burning9699@gmail.com>
2022-03-02 16:48:05 +08:00
Tim Zhang
b4df6016b3 Merge pull request #71 from Tim-Zhang/release-0.2.8
release: v0.2.8
2021-12-17 18:27:13 +08:00
Tim Zhang
0686400268 release: v0.2.8
Bump version from 0.2.7 to 0.2.8

Signed-off-by: Tim Zhang <tim@hyper.sh>
2021-12-17 17:40:45 +08:00
Tim Zhang
6986c49e70 Merge pull request #67 from jodh-intel/update-nix-version
cargo: Update nix to latest version
2021-11-30 17:58:31 +08:00
James O. D. Hunt
e0bf36ae23 cargo: Update nix to latest version
Update the `nix` crate to version `0.23.0` to resolve a dependency
issue related to making `cargo audit` run cleanly for the Kata
Containers agent.

See:

https://github.com/kata-containers/kata-containers/pull/3125

Fixes: #66.

Signed-off-by: James O. D. Hunt <james.o.hunt@intel.com>
2021-11-26 11:17:58 +00:00
13 changed files with 111 additions and 45 deletions

View File

@@ -5,7 +5,7 @@ repository = "https://github.com/kata-containers/cgroups-rs"
keywords = ["linux", "cgroup", "containers", "isolation"]
categories = ["os", "api-bindings", "os::unix-apis"]
license = "MIT OR Apache-2.0"
version = "0.2.7"
version = "0.2.11"
authors = ["The Kata Containers community <kata-dev@lists.katacontainers.io>", "Levente Kurusa <lkurusa@acm.org>", "Sam Wilson <tecywiz121@hotmail.com>"]
edition = "2018"
homepage = "https://github.com/kata-containers/cgroups-rs"
@@ -14,7 +14,7 @@ readme = "README.md"
[dependencies]
log = "0.4"
regex = "1.1"
nix = "0.20.2"
nix = { version = "0.24", default-features = false, features = ["event", "fs", "process"] }
libc = "0.2"
serde = { version = "1.0", features = ["derive"], optional = true }

View File

@@ -16,7 +16,8 @@ use crate::error::*;
use crate::{read_string_from, read_u64_from};
use crate::{
BlkIoResources, ControllIdentifier, ControllerInternal, Controllers, Resources, Subsystem,
BlkIoResources, ControllIdentifier, ControllerInternal, Controllers, CustomizedAttribute,
Resources, Subsystem,
};
/// A controller that allows controlling the `blkio` subsystem of a Cgroup.
@@ -378,6 +379,10 @@ impl ControllerInternal for BlkIoController {
let _ = self.throttle_write_iops_for_device(dev.major, dev.minor, dev.rate);
}
res.attrs.iter().for_each(|(k, v)| {
let _ = self.set(k, v);
});
Ok(())
}
}
@@ -771,6 +776,7 @@ impl BlkIoController {
}
}
impl CustomizedAttribute for BlkIoController {}
#[cfg(test)]
mod test {
use crate::blkio::{parse_blkio_data, BlkIoData};

View File

@@ -359,9 +359,18 @@ fn create_v2_cgroup(root: PathBuf, path: &str) -> Result<()> {
}
pub fn get_cgroups_relative_paths() -> Result<HashMap<String, String>> {
let path = "/proc/self/cgroup".to_string();
get_cgroups_relative_paths_by_path(path)
}
pub fn get_cgroups_relative_paths_by_pid(pid: u32) -> Result<HashMap<String, String>> {
let path = format!("/proc/{}/cgroup", pid);
get_cgroups_relative_paths_by_path(path)
}
fn get_cgroups_relative_paths_by_path(path: String) -> Result<HashMap<String, String>> {
let mut m = HashMap::new();
let content =
fs::read_to_string("/proc/self/cgroup").map_err(|e| Error::with_cause(ReadFailed, e))?;
let content = fs::read_to_string(path).map_err(|e| Error::with_cause(ReadFailed, e))?;
for l in content.lines() {
let fl: Vec<&str> = l.split(':').collect();
if fl.len() != 3 {

View File

@@ -295,7 +295,7 @@ fn parse_cfs_quota_and_period(mut file: File) -> Result<CfsQuotaAndPeriod> {
return Err(Error::from_string(format!("invaild format: {}", content)));
}
let quota = parse_max_value(&fields[0].to_string())?;
let quota = parse_max_value(fields[0])?;
let period = fields[1]
.parse::<u64>()
.map_err(|e| Error::with_cause(ParseError, e))?;

View File

@@ -52,12 +52,11 @@ fn register_memory_event(
eventfd(0, EfdFlags::EFD_CLOEXEC).map_err(|e| Error::with_cause(ReadFailed, e))?;
let event_control_path = cg_dir.join("cgroup.event_control");
let data;
if arg.is_empty() {
data = format!("{} {}", eventfd, event_file.as_raw_fd());
let data = if arg.is_empty() {
format!("{} {}", eventfd, event_file.as_raw_fd())
} else {
data = format!("{} {} {}", eventfd, event_file.as_raw_fd(), arg);
}
format!("{} {} {}", eventfd, event_file.as_raw_fd(), arg)
};
// write to file and set mode to 0700(FIXME)
fs::write(&event_control_path, data).map_err(|e| Error::with_cause(WriteFailed, e))?;

View File

@@ -170,7 +170,7 @@ impl Hierarchy for V1 {
}
fn root_control_group(&self) -> Cgroup {
Cgroup::load(auto(), "".to_string())
Cgroup::load(auto(), "")
}
fn root(&self) -> PathBuf {
@@ -246,7 +246,7 @@ impl Hierarchy for V2 {
}
fn root_control_group(&self) -> Cgroup {
Cgroup::load(auto(), "".to_string())
Cgroup::load(auto(), "")
}
fn root(&self) -> PathBuf {
@@ -297,7 +297,10 @@ impl Default for V2 {
pub const UNIFIED_MOUNTPOINT: &str = "/sys/fs/cgroup";
#[cfg(all(target_os = "linux", not(target_env = "musl")))]
#[cfg(any(
all(target_os = "linux", not(target_env = "musl")),
target_os = "android"
))]
pub fn is_cgroup2_unified_mode() -> bool {
use nix::sys::statfs;

View File

@@ -8,6 +8,7 @@
//!
//! See the Kernel's documentation for more information about this subsystem, found at:
//! [Documentation/cgroup-v1/hugetlb.txt](https://www.kernel.org/doc/Documentation/cgroup-v1/hugetlb.txt)
use log::warn;
use std::io::Write;
use std::path::PathBuf;
@@ -88,7 +89,7 @@ impl<'a> From<&'a Subsystem> for &'a HugeTlbController {
impl HugeTlbController {
/// Constructs a new `HugeTlbController` with `root` serving as the root of the control group.
pub fn new(root: PathBuf, v2: bool) -> Self {
let sizes = get_hugepage_sizes().unwrap();
let sizes = get_hugepage_sizes();
Self {
base: root.clone(),
path: root,
@@ -180,27 +181,29 @@ use regex::Regex;
use std::collections::HashMap;
use std::fs;
fn get_hugepage_sizes() -> Result<Vec<String>> {
let mut m = Vec::new();
fn get_hugepage_sizes() -> Vec<String> {
let dirs = fs::read_dir(HUGEPAGESIZE_DIR);
if dirs.is_err() {
return Ok(m);
return Vec::new();
}
for e in dirs.unwrap() {
let entry = e.unwrap();
let name = entry.file_name().into_string().unwrap();
let parts: Vec<&str> = name.split('-').collect();
if parts.len() != 2 {
continue;
}
let bmap = get_binary_size_map();
let size = parse_size(parts[1], &bmap)?;
let dabbrs = get_decimal_abbrs();
m.push(custom_size(size as f64, 1024.0, &dabbrs));
}
dirs.unwrap()
.filter_map(|e| {
let entry = e.map_err(|e| warn!("readdir error: {:?}", e)).ok()?;
let name = entry.file_name().into_string().unwrap();
let parts: Vec<&str> = name.split('-').collect();
if parts.len() != 2 {
return None;
}
let bmap = get_binary_size_map();
let size = parse_size(parts[1], &bmap)
.map_err(|e| warn!("parse_size error: {:?}", e))
.ok()?;
let dabbrs = get_decimal_abbrs();
Ok(m)
Some(custom_size(size as f64, 1024.0, &dabbrs))
})
.collect()
}
pub const KB: u128 = 1000;

View File

@@ -332,7 +332,23 @@ where
return Ok(());
}
remove_dir(self.get_path())
// Compatible with runC for remove dir operation
// https://github.com/opencontainers/runc/blob/main/libcontainer/cgroups/utils.go#L272
//
// We trying to remove all paths five times with increasing delay between tries.
// If after all there are not removed cgroups - appropriate error will be
// returned.
let mut delay = std::time::Duration::from_millis(10);
let cgroup_path = self.get_path();
for _i in 0..4 {
if let Ok(()) = remove_dir(cgroup_path) {
return Ok(());
}
std::thread::sleep(delay);
delay *= 2;
}
remove_dir(cgroup_path)
}
/// Attach a task to this controller.
@@ -613,6 +629,15 @@ pub struct BlkIoResources {
pub throttle_write_bps_device: Vec<BlkIoDeviceThrottleResource>,
/// Throttled write IO operations per second can be provided for each device.
pub throttle_write_iops_device: Vec<BlkIoDeviceThrottleResource>,
/// Customized key-value attributes
/// # Usage:
/// ```
/// let resource = &mut cgroups_rs::Resources::default();
/// resource.blkio.attrs.insert("io.cost.weight".to_string(), "10".to_string());
/// // apply here
/// ```
pub attrs: HashMap<String, String>,
}
/// The resource limits and constraints that will be set on the control group.
@@ -771,7 +796,7 @@ impl fmt::Display for MaxValue {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
match self {
MaxValue::Max => write!(f, "max"),
MaxValue::Value(num) => write!(f, "{}", num.to_string()),
MaxValue::Value(num) => write!(f, "{}", num),
}
}
}

View File

@@ -8,6 +8,7 @@
//!
//! See the Kernel's documentation for more information about this subsystem, found at:
//! [Documentation/cgroup-v1/memory.txt](https://www.kernel.org/doc/Documentation/cgroup-v1/memory.txt)
use log::warn;
use std::collections::HashMap;
use std::io::Write;
use std::path::PathBuf;
@@ -840,8 +841,15 @@ impl MemController {
self.open_path("memory.kmem.limit_in_bytes", true)
.and_then(|mut file| {
file.write_all(limit.to_string().as_ref())
.map_err(|e| Error::with_cause(WriteFailed, e))
let r = file.write_all(limit.to_string().as_ref());
match r {
Ok(()) => Ok(()),
Err(ref e) if e.raw_os_error() == Some(libc::EOPNOTSUPP) => {
warn!("memory.kmem.limit_in_bytes is unsupported by the kernel");
Ok(())
}
Err(e) => Err(Error::with_cause(WriteFailed, e)),
}
})
}

View File

@@ -17,7 +17,7 @@ use crate::{ControllIdentifier, ControllerInternal, Controllers, Resources, Subs
pub struct SystemdController {
base: PathBuf,
path: PathBuf,
v2: bool,
_v2: bool,
}
impl ControllerInternal for SystemdController {
@@ -66,7 +66,7 @@ impl SystemdController {
Self {
base: root.clone(),
path: root,
v2,
_v2: v2,
}
}
}

View File

@@ -47,7 +47,8 @@ pub fn test_memory_res_build() {
{
let c: &MemController = cg.controller_of().unwrap();
if !c.v2() {
assert_eq!(c.kmem_stat().limit_in_bytes, 128 * 1024 * 1024);
// Note: we don't tests the value of c.kmem_stat().limit_in_bytes because on Linux
// kernel >= 5.16 setting this value is unsupported.
assert_eq!(c.memory_stat().swappiness, 70);
}
assert_eq!(c.memory_stat().limit_in_bytes, 1024 * 1024 * 1024);
@@ -137,11 +138,8 @@ pub fn test_hugepages_res_build() {
{
let c: &HugeTlbController = cg.controller_of().unwrap();
assert!(c.limit_in_bytes(&"2MB".to_string()).is_ok());
assert_eq!(
c.limit_in_bytes(&"2MB".to_string()).unwrap(),
4 * 2 * 1024 * 1024
);
assert!(c.limit_in_bytes("2MB").is_ok());
assert_eq!(c.limit_in_bytes("2MB").unwrap(), 4 * 2 * 1024 * 1024);
}
cg.delete().unwrap();
}

View File

@@ -40,5 +40,5 @@ fn test_hugetlb_sizes() {
}
fn assert_no_error(r: Result<u64>) {
assert!(!r.is_err())
assert!(r.is_ok())
}

View File

@@ -23,7 +23,7 @@ fn test_disable_oom_killer() {
if !mem_controller.v2() {
// disable oom killer
let r = mem_controller.disable_oom_killer();
assert!(!r.is_err());
assert!(r.is_ok());
// after disable
let m = mem_controller.memory_stat();
@@ -33,6 +33,21 @@ fn test_disable_oom_killer() {
cg.delete().unwrap();
}
#[test]
fn set_kmem_limit_v1() {
let h = cgroups_rs::hierarchies::auto();
if h.v2() {
return;
}
let cg = Cgroup::new(h, String::from("set_kmem_limit_v1"));
{
let mem_controller: &MemController = cg.controller_of().unwrap();
mem_controller.set_kmem_limit(1).unwrap();
}
cg.delete().unwrap();
}
#[test]
fn set_mem_v2() {
let h = cgroups_rs::hierarchies::auto();