|
3 | 3 | package systemd |
4 | 4 |
|
5 | 5 | import ( |
| 6 | + "fmt" |
| 7 | + "math" |
6 | 8 | "os" |
7 | 9 | "path/filepath" |
8 | 10 | "strconv" |
@@ -34,6 +36,125 @@ func NewUnifiedManager(config *configs.Cgroup, path string, rootless bool) cgrou |
34 | 36 | } |
35 | 37 | } |
36 | 38 |
|
| 39 | +// unifiedResToSystemdProps tries to convert from Cgroup.Resources.Unified |
| 40 | +// key/value map (where key is cgroupfs file name) to systemd unit properties. |
| 41 | +// This is on a best-effort basis, so the properties that are not known |
| 42 | +// (to this function and/or systemd) are ignored (but logged with "debug" |
| 43 | +// log level). |
| 44 | +// |
| 45 | +// For the list of keys, see https://www.kernel.org/doc/Documentation/cgroup-v2.txt |
| 46 | +// |
| 47 | +// For the list of systemd unit properties, see systemd.resource-control(5). |
| 48 | +func unifiedResToSystemdProps(conn *systemdDbus.Conn, res map[string]string) (props []systemdDbus.Property, _ error) { |
| 49 | + var err error |
| 50 | + |
| 51 | + for k, v := range res { |
| 52 | + if strings.Contains(k, "/") { |
| 53 | + return nil, fmt.Errorf("unified resource %q must be a file name (no slashes)", k) |
| 54 | + } |
| 55 | + sk := strings.SplitN(k, ".", 2) |
| 56 | + if len(sk) != 2 { |
| 57 | + return nil, fmt.Errorf("unified resource %q must be in the form CONTROLLER.PARAMETER", k) |
| 58 | + } |
| 59 | + // Kernel is quite forgiving to extra whitespace |
| 60 | + // around the value, and so should we. |
| 61 | + v = strings.TrimSpace(v) |
| 62 | + // Please keep cases in alphabetical order. |
| 63 | + switch k { |
| 64 | + case "cpu.max": |
| 65 | + // value: quota [period] |
| 66 | + quota := int64(0) // 0 means "unlimited" for addCpuQuota, if period is set |
| 67 | + period := defCPUQuotaPeriod |
| 68 | + sv := strings.Fields(v) |
| 69 | + if len(sv) < 1 || len(sv) > 2 { |
| 70 | + return nil, fmt.Errorf("unified resource %q value invalid: %q", k, v) |
| 71 | + } |
| 72 | + // quota |
| 73 | + if sv[0] != "max" { |
| 74 | + quota, err = strconv.ParseInt(sv[0], 10, 64) |
| 75 | + if err != nil { |
| 76 | + return nil, fmt.Errorf("unified resource %q period value conversion error: %w", k, err) |
| 77 | + } |
| 78 | + } |
| 79 | + // period |
| 80 | + if len(sv) == 2 { |
| 81 | + period, err = strconv.ParseUint(sv[1], 10, 64) |
| 82 | + if err != nil { |
| 83 | + return nil, fmt.Errorf("unified resource %q quota value conversion error: %w", k, err) |
| 84 | + } |
| 85 | + } |
| 86 | + addCpuQuota(conn, &props, quota, period) |
| 87 | + |
| 88 | + case "cpu.weight": |
| 89 | + num, err := strconv.ParseUint(v, 10, 64) |
| 90 | + if err != nil { |
| 91 | + return nil, fmt.Errorf("unified resource %q value conversion error: %w", k, err) |
| 92 | + } |
| 93 | + props = append(props, |
| 94 | + newProp("CPUWeight", num)) |
| 95 | + |
| 96 | + case "cpuset.cpus", "cpuset.mems": |
| 97 | + bits, err := rangeToBits(v) |
| 98 | + if err != nil { |
| 99 | + return nil, fmt.Errorf("unified resource %q=%q conversion error: %w", k, v, err) |
| 100 | + } |
| 101 | + m := map[string]string{ |
| 102 | + "cpuset.cpus": "AllowedCPUs", |
| 103 | + "cpuset.mems": "AllowedMemoryNodes", |
| 104 | + } |
| 105 | + props = append(props, |
| 106 | + newProp(m[k], bits)) |
| 107 | + |
| 108 | + case "memory.high", "memory.low", "memory.min", "memory.max", "memory.swap.max": |
| 109 | + num := uint64(math.MaxUint64) |
| 110 | + if v != "max" { |
| 111 | + num, err = strconv.ParseUint(v, 10, 64) |
| 112 | + if err != nil { |
| 113 | + return nil, fmt.Errorf("unified resource %q value conversion error: %w", k, err) |
| 114 | + } |
| 115 | + } |
| 116 | + m := map[string]string{ |
| 117 | + "memory.high": "MemoryHigh", |
| 118 | + "memory.low": "MemoryLow", |
| 119 | + "memory.min": "MemoryMin", |
| 120 | + "memory.max": "MemoryMax", |
| 121 | + "memory.swap.max": "MemorySwapMax", |
| 122 | + } |
| 123 | + props = append(props, |
| 124 | + newProp(m[k], num)) |
| 125 | + |
| 126 | + case "pids.max": |
| 127 | + num := uint64(math.MaxUint64) |
| 128 | + if v != "max" { |
| 129 | + var err error |
| 130 | + num, err = strconv.ParseUint(v, 10, 64) |
| 131 | + if err != nil { |
| 132 | + return nil, fmt.Errorf("unified resource %q value conversion error: %w", k, err) |
| 133 | + } |
| 134 | + } |
| 135 | + props = append(props, |
| 136 | + newProp("TasksAccounting", true), |
| 137 | + newProp("TasksMax", num)) |
| 138 | + |
| 139 | + case "memory.oom.group": |
| 140 | + // Setting this to 1 is roughly equivalent to OOMPolicy=kill |
| 141 | + // (as per systemd.service(5) and |
| 142 | + // https://www.kernel.org/doc/html/latest/admin-guide/cgroup-v2.html), |
| 143 | + // but it's not clear what to do if it is unset or set |
| 144 | + // to 0 in runc update, as there are two other possible |
| 145 | + // values for OOMPolicy (continue/stop). |
| 146 | + fallthrough |
| 147 | + |
| 148 | + default: |
| 149 | + // Ignore the unknown resource here -- will still be |
| 150 | + // applied in Set which calls fs2.Set. |
| 151 | + logrus.Debugf("don't know how to convert unified resource %q=%q to systemd unit property; skipping (will still be applied to cgroupfs)", k, v) |
| 152 | + } |
| 153 | + } |
| 154 | + |
| 155 | + return props, nil |
| 156 | +} |
| 157 | + |
37 | 158 | func genV2ResourcesProperties(c *configs.Cgroup, conn *systemdDbus.Conn) ([]systemdDbus.Property, error) { |
38 | 159 | var properties []systemdDbus.Property |
39 | 160 | r := c.Resources |
@@ -82,6 +203,15 @@ func genV2ResourcesProperties(c *configs.Cgroup, conn *systemdDbus.Conn) ([]syst |
82 | 203 |
|
83 | 204 | // ignore r.KernelMemory |
84 | 205 |
|
| 206 | + // convert Resources.Unified map to systemd properties |
| 207 | + if r.Unified != nil { |
| 208 | + unifiedProps, err := unifiedResToSystemdProps(conn, r.Unified) |
| 209 | + if err != nil { |
| 210 | + return nil, err |
| 211 | + } |
| 212 | + properties = append(properties, unifiedProps...) |
| 213 | + } |
| 214 | + |
85 | 215 | return properties, nil |
86 | 216 | } |
87 | 217 |
|
|
0 commit comments