2 This file is part of systemd.
4 Copyright 2010 Lennart Poettering
6 systemd is free software; you can redistribute it and/or modify it
7 under the terms of the GNU Lesser General Public License as published by
8 the Free Software Foundation; either version 2.1 of the License, or
9 (at your option) any later version.
11 systemd is distributed in the hope that it will be useful, but
12 WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 Lesser General Public License for more details.
16 You should have received a copy of the GNU Lesser General Public License
17 along with systemd; If not, see <http://www.gnu.org/licenses/>.
29 #include <sys/statfs.h>
30 #include <sys/types.h>
31 #include <sys/xattr.h>
34 #include "alloc-util.h"
35 #include "cgroup-util.h"
37 #include "dirent-util.h"
38 #include "extract-word.h"
41 #include "format-util.h"
44 #include "login-util.h"
48 #include "parse-util.h"
49 #include "path-util.h"
50 #include "proc-cmdline.h"
51 #include "process-util.h"
54 #include "stat-util.h"
55 #include "stdio-util.h"
56 #include "string-table.h"
57 #include "string-util.h"
58 #include "unit-name.h"
59 #include "user-util.h"
61 int cg_enumerate_processes(const char *controller
, const char *path
, FILE **_f
) {
62 _cleanup_free_
char *fs
= NULL
;
68 r
= cg_get_path(controller
, path
, "cgroup.procs", &fs
);
80 int cg_read_pid(FILE *f
, pid_t
*_pid
) {
83 /* Note that the cgroup.procs might contain duplicates! See
84 * cgroups.txt for details. */
90 if (fscanf(f
, "%lu", &ul
) != 1) {
95 return errno
> 0 ? -errno
: -EIO
;
105 int cg_read_event(const char *controller
, const char *path
, const char *event
,
108 _cleanup_free_
char *events
= NULL
, *content
= NULL
;
112 r
= cg_get_path(controller
, path
, "cgroup.events", &events
);
116 r
= read_full_file(events
, &content
, NULL
);
121 while ((line
= strsep(&p
, "\n"))) {
124 key
= strsep(&line
, " ");
128 if (strcmp(key
, event
))
138 bool cg_ns_supported(void) {
139 static thread_local
int enabled
= -1;
144 if (access("/proc/self/ns/cgroup", F_OK
) == 0)
152 int cg_enumerate_subgroups(const char *controller
, const char *path
, DIR **_d
) {
153 _cleanup_free_
char *fs
= NULL
;
159 /* This is not recursive! */
161 r
= cg_get_path(controller
, path
, NULL
, &fs
);
173 int cg_read_subgroup(DIR *d
, char **fn
) {
179 FOREACH_DIRENT_ALL(de
, d
, return -errno
) {
182 if (de
->d_type
!= DT_DIR
)
185 if (dot_or_dot_dot(de
->d_name
))
188 b
= strdup(de
->d_name
);
199 int cg_rmdir(const char *controller
, const char *path
) {
200 _cleanup_free_
char *p
= NULL
;
203 r
= cg_get_path(controller
, path
, NULL
, &p
);
208 if (r
< 0 && errno
!= ENOENT
)
215 const char *controller
,
220 cg_kill_log_func_t log_kill
,
223 _cleanup_set_free_ Set
*allocated_set
= NULL
;
230 /* Don't send SIGCONT twice. Also, SIGKILL always works even when process is suspended, hence don't send
231 * SIGCONT on SIGKILL. */
232 if (IN_SET(sig
, SIGCONT
, SIGKILL
))
233 flags
&= ~CGROUP_SIGCONT
;
235 /* This goes through the tasks list and kills them all. This
236 * is repeated until no further processes are added to the
237 * tasks list, to properly handle forking processes */
240 s
= allocated_set
= set_new(NULL
);
248 _cleanup_fclose_
FILE *f
= NULL
;
252 r
= cg_enumerate_processes(controller
, path
, &f
);
254 if (ret
>= 0 && r
!= -ENOENT
)
260 while ((r
= cg_read_pid(f
, &pid
)) > 0) {
262 if ((flags
& CGROUP_IGNORE_SELF
) && pid
== my_pid
)
265 if (set_get(s
, PID_TO_PTR(pid
)) == PID_TO_PTR(pid
))
269 log_kill(pid
, sig
, userdata
);
271 /* If we haven't killed this process yet, kill
273 if (kill(pid
, sig
) < 0) {
274 if (ret
>= 0 && errno
!= ESRCH
)
277 if (flags
& CGROUP_SIGCONT
)
278 (void) kill(pid
, SIGCONT
);
286 r
= set_put(s
, PID_TO_PTR(pid
));
302 /* To avoid racing against processes which fork
303 * quicker than we can kill them we repeat this until
304 * no new pids need to be killed. */
311 int cg_kill_recursive(
312 const char *controller
,
317 cg_kill_log_func_t log_kill
,
320 _cleanup_set_free_ Set
*allocated_set
= NULL
;
321 _cleanup_closedir_
DIR *d
= NULL
;
329 s
= allocated_set
= set_new(NULL
);
334 ret
= cg_kill(controller
, path
, sig
, flags
, s
, log_kill
, userdata
);
336 r
= cg_enumerate_subgroups(controller
, path
, &d
);
338 if (ret
>= 0 && r
!= -ENOENT
)
344 while ((r
= cg_read_subgroup(d
, &fn
)) > 0) {
345 _cleanup_free_
char *p
= NULL
;
347 p
= strjoin(path
, "/", fn
);
352 r
= cg_kill_recursive(controller
, p
, sig
, flags
, s
, log_kill
, userdata
);
353 if (r
!= 0 && ret
>= 0)
356 if (ret
>= 0 && r
< 0)
359 if (flags
& CGROUP_REMOVE
) {
360 r
= cg_rmdir(controller
, path
);
361 if (r
< 0 && ret
>= 0 && r
!= -ENOENT
&& r
!= -EBUSY
)
376 _cleanup_set_free_ Set
*s
= NULL
;
392 _cleanup_fclose_
FILE *f
= NULL
;
396 r
= cg_enumerate_processes(cfrom
, pfrom
, &f
);
398 if (ret
>= 0 && r
!= -ENOENT
)
404 while ((r
= cg_read_pid(f
, &pid
)) > 0) {
406 /* This might do weird stuff if we aren't a
407 * single-threaded program. However, we
408 * luckily know we are not */
409 if ((flags
& CGROUP_IGNORE_SELF
) && pid
== my_pid
)
412 if (set_get(s
, PID_TO_PTR(pid
)) == PID_TO_PTR(pid
))
415 /* Ignore kernel threads. Since they can only
416 * exist in the root cgroup, we only check for
419 (isempty(pfrom
) || path_equal(pfrom
, "/")) &&
420 is_kernel_thread(pid
) > 0)
423 r
= cg_attach(cto
, pto
, pid
);
425 if (ret
>= 0 && r
!= -ESRCH
)
432 r
= set_put(s
, PID_TO_PTR(pid
));
452 int cg_migrate_recursive(
459 _cleanup_closedir_
DIR *d
= NULL
;
468 ret
= cg_migrate(cfrom
, pfrom
, cto
, pto
, flags
);
470 r
= cg_enumerate_subgroups(cfrom
, pfrom
, &d
);
472 if (ret
>= 0 && r
!= -ENOENT
)
478 while ((r
= cg_read_subgroup(d
, &fn
)) > 0) {
479 _cleanup_free_
char *p
= NULL
;
481 p
= strjoin(pfrom
, "/", fn
);
486 r
= cg_migrate_recursive(cfrom
, p
, cto
, pto
, flags
);
487 if (r
!= 0 && ret
>= 0)
491 if (r
< 0 && ret
>= 0)
494 if (flags
& CGROUP_REMOVE
) {
495 r
= cg_rmdir(cfrom
, pfrom
);
496 if (r
< 0 && ret
>= 0 && r
!= -ENOENT
&& r
!= -EBUSY
)
503 int cg_migrate_recursive_fallback(
517 r
= cg_migrate_recursive(cfrom
, pfrom
, cto
, pto
, flags
);
519 char prefix
[strlen(pto
) + 1];
521 /* This didn't work? Then let's try all prefixes of the destination */
523 PATH_FOREACH_PREFIX(prefix
, pto
) {
526 q
= cg_migrate_recursive(cfrom
, pfrom
, cto
, prefix
, flags
);
535 static const char *controller_to_dirname(const char *controller
) {
540 /* Converts a controller name to the directory name below
541 * /sys/fs/cgroup/ we want to mount it to. Effectively, this
542 * just cuts off the name= prefixed used for named
543 * hierarchies, if it is specified. */
545 if (streq(controller
, SYSTEMD_CGROUP_CONTROLLER
))
546 controller
= SYSTEMD_CGROUP_CONTROLLER_LEGACY
;
548 e
= startswith(controller
, "name=");
555 static int join_path_legacy(const char *controller
, const char *path
, const char *suffix
, char **fs
) {
562 dn
= controller_to_dirname(controller
);
564 if (isempty(path
) && isempty(suffix
))
565 t
= strappend("/sys/fs/cgroup/", dn
);
566 else if (isempty(path
))
567 t
= strjoin("/sys/fs/cgroup/", dn
, "/", suffix
);
568 else if (isempty(suffix
))
569 t
= strjoin("/sys/fs/cgroup/", dn
, "/", path
);
571 t
= strjoin("/sys/fs/cgroup/", dn
, "/", path
, "/", suffix
);
579 static int join_path_unified(const char *path
, const char *suffix
, char **fs
) {
584 if (isempty(path
) && isempty(suffix
))
585 t
= strdup("/sys/fs/cgroup");
586 else if (isempty(path
))
587 t
= strappend("/sys/fs/cgroup/", suffix
);
588 else if (isempty(suffix
))
589 t
= strappend("/sys/fs/cgroup/", path
);
591 t
= strjoin("/sys/fs/cgroup/", path
, "/", suffix
);
599 int cg_get_path(const char *controller
, const char *path
, const char *suffix
, char **fs
) {
607 /* If no controller is specified, we return the path
608 * *below* the controllers, without any prefix. */
610 if (!path
&& !suffix
)
618 t
= strjoin(path
, "/", suffix
);
622 *fs
= path_kill_slashes(t
);
626 if (!cg_controller_is_valid(controller
))
629 if (cg_all_unified())
630 r
= join_path_unified(path
, suffix
, fs
);
632 r
= join_path_legacy(controller
, path
, suffix
, fs
);
636 path_kill_slashes(*fs
);
640 static int controller_is_accessible(const char *controller
) {
644 /* Checks whether a specific controller is accessible,
645 * i.e. its hierarchy mounted. In the unified hierarchy all
646 * controllers are considered accessible, except for the named
649 if (!cg_controller_is_valid(controller
))
652 if (cg_all_unified()) {
653 /* We don't support named hierarchies if we are using
654 * the unified hierarchy. */
656 if (streq(controller
, SYSTEMD_CGROUP_CONTROLLER
))
659 if (startswith(controller
, "name="))
665 dn
= controller_to_dirname(controller
);
666 cc
= strjoina("/sys/fs/cgroup/", dn
);
668 if (laccess(cc
, F_OK
) < 0)
675 int cg_get_path_and_check(const char *controller
, const char *path
, const char *suffix
, char **fs
) {
681 /* Check if the specified controller is actually accessible */
682 r
= controller_is_accessible(controller
);
686 return cg_get_path(controller
, path
, suffix
, fs
);
689 static int trim_cb(const char *path
, const struct stat
*sb
, int typeflag
, struct FTW
*ftwbuf
) {
694 if (typeflag
!= FTW_DP
)
697 if (ftwbuf
->level
< 1)
704 int cg_trim(const char *controller
, const char *path
, bool delete_root
) {
705 _cleanup_free_
char *fs
= NULL
;
710 r
= cg_get_path(controller
, path
, NULL
, &fs
);
715 if (nftw(fs
, trim_cb
, 64, FTW_DEPTH
|FTW_MOUNT
|FTW_PHYS
) != 0) {
725 if (rmdir(fs
) < 0 && errno
!= ENOENT
)
732 int cg_create(const char *controller
, const char *path
) {
733 _cleanup_free_
char *fs
= NULL
;
736 r
= cg_get_path_and_check(controller
, path
, NULL
, &fs
);
740 r
= mkdir_parents(fs
, 0755);
744 if (mkdir(fs
, 0755) < 0) {
755 int cg_create_and_attach(const char *controller
, const char *path
, pid_t pid
) {
760 r
= cg_create(controller
, path
);
764 q
= cg_attach(controller
, path
, pid
);
768 /* This does not remove the cgroup on failure */
772 int cg_attach(const char *controller
, const char *path
, pid_t pid
) {
773 _cleanup_free_
char *fs
= NULL
;
774 char c
[DECIMAL_STR_MAX(pid_t
) + 2];
780 r
= cg_get_path_and_check(controller
, path
, "cgroup.procs", &fs
);
787 xsprintf(c
, PID_FMT
"\n", pid
);
789 return write_string_file(fs
, c
, 0);
792 int cg_attach_fallback(const char *controller
, const char *path
, pid_t pid
) {
799 r
= cg_attach(controller
, path
, pid
);
801 char prefix
[strlen(path
) + 1];
803 /* This didn't work? Then let's try all prefixes of
806 PATH_FOREACH_PREFIX(prefix
, path
) {
809 q
= cg_attach(controller
, prefix
, pid
);
818 int cg_set_group_access(
819 const char *controller
,
825 _cleanup_free_
char *fs
= NULL
;
828 if (mode
== MODE_INVALID
&& uid
== UID_INVALID
&& gid
== GID_INVALID
)
831 if (mode
!= MODE_INVALID
)
834 r
= cg_get_path(controller
, path
, NULL
, &fs
);
838 return chmod_and_chown(fs
, mode
, uid
, gid
);
841 int cg_set_task_access(
842 const char *controller
,
848 _cleanup_free_
char *fs
= NULL
, *procs
= NULL
;
853 if (mode
== MODE_INVALID
&& uid
== UID_INVALID
&& gid
== GID_INVALID
)
856 if (mode
!= MODE_INVALID
)
859 r
= cg_get_path(controller
, path
, "cgroup.procs", &fs
);
863 r
= chmod_and_chown(fs
, mode
, uid
, gid
);
867 if (cg_unified(controller
))
870 /* Compatibility, Always keep values for "tasks" in sync with
872 if (cg_get_path(controller
, path
, "tasks", &procs
) >= 0)
873 (void) chmod_and_chown(procs
, mode
, uid
, gid
);
878 int cg_set_xattr(const char *controller
, const char *path
, const char *name
, const void *value
, size_t size
, int flags
) {
879 _cleanup_free_
char *fs
= NULL
;
884 assert(value
|| size
<= 0);
886 r
= cg_get_path(controller
, path
, NULL
, &fs
);
890 if (setxattr(fs
, name
, value
, size
, flags
) < 0)
896 int cg_get_xattr(const char *controller
, const char *path
, const char *name
, void *value
, size_t size
) {
897 _cleanup_free_
char *fs
= NULL
;
904 r
= cg_get_path(controller
, path
, NULL
, &fs
);
908 n
= getxattr(fs
, name
, value
, size
);
915 int cg_pid_get_path(const char *controller
, pid_t pid
, char **path
) {
916 _cleanup_fclose_
FILE *f
= NULL
;
918 const char *fs
, *controller_str
;
926 if (!cg_controller_is_valid(controller
))
929 controller
= SYSTEMD_CGROUP_CONTROLLER
;
931 unified
= cg_unified(controller
);
933 if (streq(controller
, SYSTEMD_CGROUP_CONTROLLER
))
934 controller_str
= SYSTEMD_CGROUP_CONTROLLER_LEGACY
;
936 controller_str
= controller
;
938 cs
= strlen(controller_str
);
941 fs
= procfs_file_alloca(pid
, "cgroup");
944 return errno
== ENOENT
? -ESRCH
: -errno
;
946 FOREACH_LINE(line
, f
, return -errno
) {
952 e
= startswith(line
, "0:");
962 const char *word
, *state
;
965 l
= strchr(line
, ':');
975 FOREACH_WORD_SEPARATOR(word
, k
, l
, ",", state
) {
976 if (k
== cs
&& memcmp(word
, controller_str
, cs
) == 0) {
997 int cg_install_release_agent(const char *controller
, const char *agent
) {
998 _cleanup_free_
char *fs
= NULL
, *contents
= NULL
;
1004 if (cg_unified(controller
)) /* doesn't apply to unified hierarchy */
1007 r
= cg_get_path(controller
, NULL
, "release_agent", &fs
);
1011 r
= read_one_line_file(fs
, &contents
);
1015 sc
= strstrip(contents
);
1017 r
= write_string_file(fs
, agent
, 0);
1020 } else if (!path_equal(sc
, agent
))
1024 r
= cg_get_path(controller
, NULL
, "notify_on_release", &fs
);
1028 contents
= mfree(contents
);
1029 r
= read_one_line_file(fs
, &contents
);
1033 sc
= strstrip(contents
);
1034 if (streq(sc
, "0")) {
1035 r
= write_string_file(fs
, "1", 0);
1042 if (!streq(sc
, "1"))
1048 int cg_uninstall_release_agent(const char *controller
) {
1049 _cleanup_free_
char *fs
= NULL
;
1052 if (cg_unified(controller
)) /* Doesn't apply to unified hierarchy */
1055 r
= cg_get_path(controller
, NULL
, "notify_on_release", &fs
);
1059 r
= write_string_file(fs
, "0", 0);
1065 r
= cg_get_path(controller
, NULL
, "release_agent", &fs
);
1069 r
= write_string_file(fs
, "", 0);
1076 int cg_is_empty(const char *controller
, const char *path
) {
1077 _cleanup_fclose_
FILE *f
= NULL
;
1083 r
= cg_enumerate_processes(controller
, path
, &f
);
1089 r
= cg_read_pid(f
, &pid
);
1096 int cg_is_empty_recursive(const char *controller
, const char *path
) {
1101 /* The root cgroup is always populated */
1102 if (controller
&& (isempty(path
) || path_equal(path
, "/")))
1105 if (cg_unified(controller
)) {
1106 _cleanup_free_
char *t
= NULL
;
1108 /* On the unified hierarchy we can check empty state
1109 * via the "populated" attribute of "cgroup.events". */
1111 r
= cg_read_event(controller
, path
, "populated", &t
);
1115 return streq(t
, "0");
1117 _cleanup_closedir_
DIR *d
= NULL
;
1120 r
= cg_is_empty(controller
, path
);
1124 r
= cg_enumerate_subgroups(controller
, path
, &d
);
1130 while ((r
= cg_read_subgroup(d
, &fn
)) > 0) {
1131 _cleanup_free_
char *p
= NULL
;
1133 p
= strjoin(path
, "/", fn
);
1138 r
= cg_is_empty_recursive(controller
, p
);
1149 int cg_split_spec(const char *spec
, char **controller
, char **path
) {
1150 char *t
= NULL
, *u
= NULL
;
1156 if (!path_is_safe(spec
))
1164 *path
= path_kill_slashes(t
);
1173 e
= strchr(spec
, ':');
1175 if (!cg_controller_is_valid(spec
))
1192 t
= strndup(spec
, e
-spec
);
1195 if (!cg_controller_is_valid(t
)) {
1209 if (!path_is_safe(u
) ||
1210 !path_is_absolute(u
)) {
1216 path_kill_slashes(u
);
1232 int cg_mangle_path(const char *path
, char **result
) {
1233 _cleanup_free_
char *c
= NULL
, *p
= NULL
;
1240 /* First, check if it already is a filesystem path */
1241 if (path_startswith(path
, "/sys/fs/cgroup")) {
1247 *result
= path_kill_slashes(t
);
1251 /* Otherwise, treat it as cg spec */
1252 r
= cg_split_spec(path
, &c
, &p
);
1256 return cg_get_path(c
?: SYSTEMD_CGROUP_CONTROLLER
, p
?: "/", NULL
, result
);
1259 int cg_get_root_path(char **path
) {
1265 r
= cg_pid_get_path(SYSTEMD_CGROUP_CONTROLLER
, 1, &p
);
1269 e
= endswith(p
, "/" SPECIAL_INIT_SCOPE
);
1271 e
= endswith(p
, "/" SPECIAL_SYSTEM_SLICE
); /* legacy */
1273 e
= endswith(p
, "/system"); /* even more legacy */
1281 int cg_shift_path(const char *cgroup
, const char *root
, const char **shifted
) {
1282 _cleanup_free_
char *rt
= NULL
;
1290 /* If the root was specified let's use that, otherwise
1291 * let's determine it from PID 1 */
1293 r
= cg_get_root_path(&rt
);
1300 p
= path_startswith(cgroup
, root
);
1301 if (p
&& p
> cgroup
)
1309 int cg_pid_get_path_shifted(pid_t pid
, const char *root
, char **cgroup
) {
1310 _cleanup_free_
char *raw
= NULL
;
1317 r
= cg_pid_get_path(SYSTEMD_CGROUP_CONTROLLER
, pid
, &raw
);
1321 r
= cg_shift_path(raw
, root
, &c
);
1341 int cg_path_decode_unit(const char *cgroup
, char **unit
) {
1348 n
= strcspn(cgroup
, "/");
1352 c
= strndupa(cgroup
, n
);
1355 if (!unit_name_is_valid(c
, UNIT_NAME_PLAIN
|UNIT_NAME_INSTANCE
))
1366 static bool valid_slice_name(const char *p
, size_t n
) {
1371 if (n
< strlen("x.slice"))
1374 if (memcmp(p
+ n
- 6, ".slice", 6) == 0) {
1380 c
= cg_unescape(buf
);
1382 return unit_name_is_valid(c
, UNIT_NAME_PLAIN
);
1388 static const char *skip_slices(const char *p
) {
1391 /* Skips over all slice assignments */
1396 p
+= strspn(p
, "/");
1398 n
= strcspn(p
, "/");
1399 if (!valid_slice_name(p
, n
))
1406 int cg_path_get_unit(const char *path
, char **ret
) {
1414 e
= skip_slices(path
);
1416 r
= cg_path_decode_unit(e
, &unit
);
1420 /* We skipped over the slices, don't accept any now */
1421 if (endswith(unit
, ".slice")) {
1430 int cg_pid_get_unit(pid_t pid
, char **unit
) {
1431 _cleanup_free_
char *cgroup
= NULL
;
1436 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1440 return cg_path_get_unit(cgroup
, unit
);
1444 * Skip session-*.scope, but require it to be there.
1446 static const char *skip_session(const char *p
) {
1452 p
+= strspn(p
, "/");
1454 n
= strcspn(p
, "/");
1455 if (n
< strlen("session-x.scope"))
1458 if (memcmp(p
, "session-", 8) == 0 && memcmp(p
+ n
- 6, ".scope", 6) == 0) {
1459 char buf
[n
- 8 - 6 + 1];
1461 memcpy(buf
, p
+ 8, n
- 8 - 6);
1464 /* Note that session scopes never need unescaping,
1465 * since they cannot conflict with the kernel's own
1466 * names, hence we don't need to call cg_unescape()
1469 if (!session_id_valid(buf
))
1473 p
+= strspn(p
, "/");
1481 * Skip user@*.service, but require it to be there.
1483 static const char *skip_user_manager(const char *p
) {
1489 p
+= strspn(p
, "/");
1491 n
= strcspn(p
, "/");
1492 if (n
< strlen("user@x.service"))
1495 if (memcmp(p
, "user@", 5) == 0 && memcmp(p
+ n
- 8, ".service", 8) == 0) {
1496 char buf
[n
- 5 - 8 + 1];
1498 memcpy(buf
, p
+ 5, n
- 5 - 8);
1501 /* Note that user manager services never need unescaping,
1502 * since they cannot conflict with the kernel's own
1503 * names, hence we don't need to call cg_unescape()
1506 if (parse_uid(buf
, NULL
) < 0)
1510 p
+= strspn(p
, "/");
1518 static const char *skip_user_prefix(const char *path
) {
1523 /* Skip slices, if there are any */
1524 e
= skip_slices(path
);
1526 /* Skip the user manager, if it's in the path now... */
1527 t
= skip_user_manager(e
);
1531 /* Alternatively skip the user session if it is in the path... */
1532 return skip_session(e
);
1535 int cg_path_get_user_unit(const char *path
, char **ret
) {
1541 t
= skip_user_prefix(path
);
1545 /* And from here on it looks pretty much the same as for a
1546 * system unit, hence let's use the same parser from here
1548 return cg_path_get_unit(t
, ret
);
1551 int cg_pid_get_user_unit(pid_t pid
, char **unit
) {
1552 _cleanup_free_
char *cgroup
= NULL
;
1557 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1561 return cg_path_get_user_unit(cgroup
, unit
);
1564 int cg_path_get_machine_name(const char *path
, char **machine
) {
1565 _cleanup_free_
char *u
= NULL
;
1569 r
= cg_path_get_unit(path
, &u
);
1573 sl
= strjoina("/run/systemd/machines/unit:", u
);
1574 return readlink_malloc(sl
, machine
);
1577 int cg_pid_get_machine_name(pid_t pid
, char **machine
) {
1578 _cleanup_free_
char *cgroup
= NULL
;
1583 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1587 return cg_path_get_machine_name(cgroup
, machine
);
1590 int cg_path_get_session(const char *path
, char **session
) {
1591 _cleanup_free_
char *unit
= NULL
;
1597 r
= cg_path_get_unit(path
, &unit
);
1601 start
= startswith(unit
, "session-");
1604 end
= endswith(start
, ".scope");
1609 if (!session_id_valid(start
))
1625 int cg_pid_get_session(pid_t pid
, char **session
) {
1626 _cleanup_free_
char *cgroup
= NULL
;
1629 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1633 return cg_path_get_session(cgroup
, session
);
1636 int cg_path_get_owner_uid(const char *path
, uid_t
*uid
) {
1637 _cleanup_free_
char *slice
= NULL
;
1643 r
= cg_path_get_slice(path
, &slice
);
1647 start
= startswith(slice
, "user-");
1650 end
= endswith(start
, ".slice");
1655 if (parse_uid(start
, uid
) < 0)
1661 int cg_pid_get_owner_uid(pid_t pid
, uid_t
*uid
) {
1662 _cleanup_free_
char *cgroup
= NULL
;
1665 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1669 return cg_path_get_owner_uid(cgroup
, uid
);
1672 int cg_path_get_slice(const char *p
, char **slice
) {
1673 const char *e
= NULL
;
1678 /* Finds the right-most slice unit from the beginning, but
1679 * stops before we come to the first non-slice unit. */
1684 p
+= strspn(p
, "/");
1686 n
= strcspn(p
, "/");
1687 if (!valid_slice_name(p
, n
)) {
1692 s
= strdup(SPECIAL_ROOT_SLICE
);
1700 return cg_path_decode_unit(e
, slice
);
1708 int cg_pid_get_slice(pid_t pid
, char **slice
) {
1709 _cleanup_free_
char *cgroup
= NULL
;
1714 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1718 return cg_path_get_slice(cgroup
, slice
);
1721 int cg_path_get_user_slice(const char *p
, char **slice
) {
1726 t
= skip_user_prefix(p
);
1730 /* And now it looks pretty much the same as for a system
1731 * slice, so let's just use the same parser from here on. */
1732 return cg_path_get_slice(t
, slice
);
1735 int cg_pid_get_user_slice(pid_t pid
, char **slice
) {
1736 _cleanup_free_
char *cgroup
= NULL
;
1741 r
= cg_pid_get_path_shifted(pid
, NULL
, &cgroup
);
1745 return cg_path_get_user_slice(cgroup
, slice
);
1748 char *cg_escape(const char *p
) {
1749 bool need_prefix
= false;
1751 /* This implements very minimal escaping for names to be used
1752 * as file names in the cgroup tree: any name which might
1753 * conflict with a kernel name or is prefixed with '_' is
1754 * prefixed with a '_'. That way, when reading cgroup names it
1755 * is sufficient to remove a single prefixing underscore if
1758 /* The return value of this function (unlike cg_unescape())
1764 streq(p
, "notify_on_release") ||
1765 streq(p
, "release_agent") ||
1766 streq(p
, "tasks") ||
1767 startswith(p
, "cgroup."))
1772 dot
= strrchr(p
, '.');
1777 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
1780 n
= cgroup_controller_to_string(c
);
1785 if (memcmp(p
, n
, l
) != 0)
1795 return strappend("_", p
);
1800 char *cg_unescape(const char *p
) {
1803 /* The return value of this function (unlike cg_escape())
1804 * doesn't need free()! */
1812 #define CONTROLLER_VALID \
1816 bool cg_controller_is_valid(const char *p
) {
1822 if (streq(p
, SYSTEMD_CGROUP_CONTROLLER
))
1825 s
= startswith(p
, "name=");
1829 if (*p
== 0 || *p
== '_')
1832 for (t
= p
; *t
; t
++)
1833 if (!strchr(CONTROLLER_VALID
, *t
))
1836 if (t
- p
> FILENAME_MAX
)
1842 int cg_slice_to_path(const char *unit
, char **ret
) {
1843 _cleanup_free_
char *p
= NULL
, *s
= NULL
, *e
= NULL
;
1850 if (streq(unit
, SPECIAL_ROOT_SLICE
)) {
1860 if (!unit_name_is_valid(unit
, UNIT_NAME_PLAIN
))
1863 if (!endswith(unit
, ".slice"))
1866 r
= unit_name_to_prefix(unit
, &p
);
1870 dash
= strchr(p
, '-');
1872 /* Don't allow initial dashes */
1877 _cleanup_free_
char *escaped
= NULL
;
1878 char n
[dash
- p
+ sizeof(".slice")];
1880 /* Don't allow trailing or double dashes */
1881 if (dash
[1] == 0 || dash
[1] == '-')
1884 strcpy(stpncpy(n
, p
, dash
- p
), ".slice");
1885 if (!unit_name_is_valid(n
, UNIT_NAME_PLAIN
))
1888 escaped
= cg_escape(n
);
1892 if (!strextend(&s
, escaped
, "/", NULL
))
1895 dash
= strchr(dash
+1, '-');
1898 e
= cg_escape(unit
);
1902 if (!strextend(&s
, e
, NULL
))
1911 int cg_set_attribute(const char *controller
, const char *path
, const char *attribute
, const char *value
) {
1912 _cleanup_free_
char *p
= NULL
;
1915 r
= cg_get_path(controller
, path
, attribute
, &p
);
1919 return write_string_file(p
, value
, 0);
1922 int cg_get_attribute(const char *controller
, const char *path
, const char *attribute
, char **ret
) {
1923 _cleanup_free_
char *p
= NULL
;
1926 r
= cg_get_path(controller
, path
, attribute
, &p
);
1930 return read_one_line_file(p
, ret
);
1933 int cg_get_keyed_attribute(const char *controller
, const char *path
, const char *attribute
, const char **keys
, char **values
) {
1934 _cleanup_free_
char *filename
= NULL
, *content
= NULL
;
1938 for (i
= 0; keys
[i
]; i
++)
1941 r
= cg_get_path(controller
, path
, attribute
, &filename
);
1945 r
= read_full_file(filename
, &content
, NULL
);
1950 while ((line
= strsep(&p
, "\n"))) {
1953 key
= strsep(&line
, " ");
1955 for (i
= 0; keys
[i
]; i
++) {
1956 if (streq(key
, keys
[i
])) {
1957 values
[i
] = strdup(line
);
1963 for (i
= 0; keys
[i
]; i
++) {
1965 for (i
= 0; keys
[i
]; i
++) {
1976 int cg_create_everywhere(CGroupMask supported
, CGroupMask mask
, const char *path
) {
1980 /* This one will create a cgroup in our private tree, but also
1981 * duplicate it in the trees specified in mask, and remove it
1984 /* First create the cgroup in our own hierarchy. */
1985 r
= cg_create(SYSTEMD_CGROUP_CONTROLLER
, path
);
1989 /* If we are in the unified hierarchy, we are done now */
1990 if (cg_all_unified())
1993 /* Otherwise, do the same in the other hierarchies */
1994 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
1995 CGroupMask bit
= CGROUP_CONTROLLER_TO_MASK(c
);
1998 n
= cgroup_controller_to_string(c
);
2001 (void) cg_create(n
, path
);
2002 else if (supported
& bit
)
2003 (void) cg_trim(n
, path
, true);
2009 int cg_attach_everywhere(CGroupMask supported
, const char *path
, pid_t pid
, cg_migrate_callback_t path_callback
, void *userdata
) {
2013 r
= cg_attach(SYSTEMD_CGROUP_CONTROLLER
, path
, pid
);
2017 if (cg_all_unified())
2020 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
2021 CGroupMask bit
= CGROUP_CONTROLLER_TO_MASK(c
);
2022 const char *p
= NULL
;
2024 if (!(supported
& bit
))
2028 p
= path_callback(bit
, userdata
);
2033 (void) cg_attach_fallback(cgroup_controller_to_string(c
), p
, pid
);
2039 int cg_attach_many_everywhere(CGroupMask supported
, const char *path
, Set
* pids
, cg_migrate_callback_t path_callback
, void *userdata
) {
2044 SET_FOREACH(pidp
, pids
, i
) {
2045 pid_t pid
= PTR_TO_PID(pidp
);
2048 q
= cg_attach_everywhere(supported
, path
, pid
, path_callback
, userdata
);
2049 if (q
< 0 && r
>= 0)
2056 int cg_migrate_everywhere(CGroupMask supported
, const char *from
, const char *to
, cg_migrate_callback_t to_callback
, void *userdata
) {
2060 if (!path_equal(from
, to
)) {
2061 r
= cg_migrate_recursive(SYSTEMD_CGROUP_CONTROLLER
, from
, SYSTEMD_CGROUP_CONTROLLER
, to
, CGROUP_REMOVE
);
2066 if (cg_all_unified())
2069 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
2070 CGroupMask bit
= CGROUP_CONTROLLER_TO_MASK(c
);
2071 const char *p
= NULL
;
2073 if (!(supported
& bit
))
2077 p
= to_callback(bit
, userdata
);
2082 (void) cg_migrate_recursive_fallback(SYSTEMD_CGROUP_CONTROLLER
, to
, cgroup_controller_to_string(c
), p
, 0);
2088 int cg_trim_everywhere(CGroupMask supported
, const char *path
, bool delete_root
) {
2092 r
= cg_trim(SYSTEMD_CGROUP_CONTROLLER
, path
, delete_root
);
2096 if (cg_all_unified())
2099 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
2100 CGroupMask bit
= CGROUP_CONTROLLER_TO_MASK(c
);
2102 if (!(supported
& bit
))
2105 (void) cg_trim(cgroup_controller_to_string(c
), path
, delete_root
);
2111 int cg_mask_supported(CGroupMask
*ret
) {
2112 CGroupMask mask
= 0;
2115 /* Determines the mask of supported cgroup controllers. Only
2116 * includes controllers we can make sense of and that are
2117 * actually accessible. */
2119 if (cg_all_unified()) {
2120 _cleanup_free_
char *root
= NULL
, *controllers
= NULL
, *path
= NULL
;
2123 /* In the unified hierarchy we can read the supported
2124 * and accessible controllers from a the top-level
2125 * cgroup attribute */
2127 r
= cg_get_root_path(&root
);
2131 r
= cg_get_path(SYSTEMD_CGROUP_CONTROLLER
, root
, "cgroup.controllers", &path
);
2135 r
= read_one_line_file(path
, &controllers
);
2141 _cleanup_free_
char *n
= NULL
;
2144 r
= extract_first_word(&c
, &n
, NULL
, 0);
2150 v
= cgroup_controller_from_string(n
);
2154 mask
|= CGROUP_CONTROLLER_TO_MASK(v
);
2157 /* Currently, we support the cpu, memory, io and pids
2158 * controller in the unified hierarchy, mask
2159 * everything else off. */
2160 mask
&= CGROUP_MASK_CPU
| CGROUP_MASK_MEMORY
| CGROUP_MASK_IO
| CGROUP_MASK_PIDS
;
2165 /* In the legacy hierarchy, we check whether which
2166 * hierarchies are mounted. */
2168 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
2171 n
= cgroup_controller_to_string(c
);
2172 if (controller_is_accessible(n
) >= 0)
2173 mask
|= CGROUP_CONTROLLER_TO_MASK(c
);
2181 int cg_kernel_controllers(Set
*controllers
) {
2182 _cleanup_fclose_
FILE *f
= NULL
;
2186 assert(controllers
);
2188 /* Determines the full list of kernel-known controllers. Might
2189 * include controllers we don't actually support, arbitrary
2190 * named hierarchies and controllers that aren't currently
2191 * accessible (because not mounted). */
2193 f
= fopen("/proc/cgroups", "re");
2195 if (errno
== ENOENT
)
2200 /* Ignore the header line */
2201 (void) fgets(buf
, sizeof(buf
), f
);
2208 if (fscanf(f
, "%ms %*i %*i %i", &controller
, &enabled
) != 2) {
2213 if (ferror(f
) && errno
> 0)
2224 if (!cg_controller_is_valid(controller
)) {
2229 r
= set_consume(controllers
, controller
);
2237 static thread_local CGroupUnified unified_cache
= CGROUP_UNIFIED_UNKNOWN
;
2239 static int cg_update_unified(void) {
2243 /* Checks if we support the unified hierarchy. Returns an
2244 * error when the cgroup hierarchies aren't mounted yet or we
2245 * have any other trouble determining if the unified hierarchy
2248 if (unified_cache
>= CGROUP_UNIFIED_NONE
)
2251 if (statfs("/sys/fs/cgroup/", &fs
) < 0)
2254 if (F_TYPE_EQUAL(fs
.f_type
, CGROUP2_SUPER_MAGIC
))
2255 unified_cache
= CGROUP_UNIFIED_ALL
;
2256 else if (F_TYPE_EQUAL(fs
.f_type
, TMPFS_MAGIC
)) {
2257 if (statfs("/sys/fs/cgroup/systemd/", &fs
) < 0)
2260 unified_cache
= F_TYPE_EQUAL(fs
.f_type
, CGROUP2_SUPER_MAGIC
) ?
2261 CGROUP_UNIFIED_SYSTEMD
: CGROUP_UNIFIED_NONE
;
2268 bool cg_unified(const char *controller
) {
2270 assert(cg_update_unified() >= 0);
2272 if (streq_ptr(controller
, SYSTEMD_CGROUP_CONTROLLER
))
2273 return unified_cache
>= CGROUP_UNIFIED_SYSTEMD
;
2275 return unified_cache
>= CGROUP_UNIFIED_ALL
;
2278 bool cg_all_unified(void) {
2280 return cg_unified(NULL
);
2283 int cg_unified_flush(void) {
2284 unified_cache
= CGROUP_UNIFIED_UNKNOWN
;
2286 return cg_update_unified();
2289 int cg_enable_everywhere(CGroupMask supported
, CGroupMask mask
, const char *p
) {
2290 _cleanup_free_
char *fs
= NULL
;
2299 if (!cg_all_unified()) /* on the legacy hiearchy there's no joining of controllers defined */
2302 r
= cg_get_path(SYSTEMD_CGROUP_CONTROLLER
, p
, "cgroup.subtree_control", &fs
);
2306 for (c
= 0; c
< _CGROUP_CONTROLLER_MAX
; c
++) {
2307 CGroupMask bit
= CGROUP_CONTROLLER_TO_MASK(c
);
2310 if (!(supported
& bit
))
2313 n
= cgroup_controller_to_string(c
);
2315 char s
[1 + strlen(n
) + 1];
2317 s
[0] = mask
& bit
? '+' : '-';
2320 r
= write_string_file(fs
, s
, 0);
2322 log_debug_errno(r
, "Failed to enable controller %s for %s (%s): %m", n
, p
, fs
);
2329 bool cg_is_unified_wanted(void) {
2330 static thread_local
int wanted
= -1;
2334 /* If the hierarchy is already mounted, then follow whatever
2335 * was chosen for it. */
2336 if (cg_unified_flush() >= 0)
2337 return cg_all_unified();
2339 /* Otherwise, let's see what the kernel command line has to
2340 * say. Since checking that is expensive, let's cache the
2345 r
= proc_cmdline_get_bool("systemd.unified_cgroup_hierarchy", &b
);
2349 return (wanted
= r
> 0 ? b
: false);
2352 bool cg_is_legacy_wanted(void) {
2353 return !cg_is_unified_wanted();
2356 bool cg_is_unified_systemd_controller_wanted(void) {
2357 static thread_local
int wanted
= -1;
2361 /* If the unified hierarchy is requested in full, no need to
2362 * bother with this. */
2363 if (cg_is_unified_wanted())
2366 /* If the hierarchy is already mounted, then follow whatever
2367 * was chosen for it. */
2368 if (cg_unified_flush() >= 0)
2369 return cg_unified(SYSTEMD_CGROUP_CONTROLLER
);
2371 /* Otherwise, let's see what the kernel command line has to
2372 * say. Since checking that is expensive, let's cache the
2377 r
= proc_cmdline_get_bool("systemd.legacy_systemd_cgroup_controller", &b
);
2381 return (wanted
= r
> 0 ? b
: false);
2384 bool cg_is_legacy_systemd_controller_wanted(void) {
2385 return cg_is_legacy_wanted() && !cg_is_unified_systemd_controller_wanted();
2388 int cg_weight_parse(const char *s
, uint64_t *ret
) {
2393 *ret
= CGROUP_WEIGHT_INVALID
;
2397 r
= safe_atou64(s
, &u
);
2401 if (u
< CGROUP_WEIGHT_MIN
|| u
> CGROUP_WEIGHT_MAX
)
2408 const uint64_t cgroup_io_limit_defaults
[_CGROUP_IO_LIMIT_TYPE_MAX
] = {
2409 [CGROUP_IO_RBPS_MAX
] = CGROUP_LIMIT_MAX
,
2410 [CGROUP_IO_WBPS_MAX
] = CGROUP_LIMIT_MAX
,
2411 [CGROUP_IO_RIOPS_MAX
] = CGROUP_LIMIT_MAX
,
2412 [CGROUP_IO_WIOPS_MAX
] = CGROUP_LIMIT_MAX
,
2415 static const char* const cgroup_io_limit_type_table
[_CGROUP_IO_LIMIT_TYPE_MAX
] = {
2416 [CGROUP_IO_RBPS_MAX
] = "IOReadBandwidthMax",
2417 [CGROUP_IO_WBPS_MAX
] = "IOWriteBandwidthMax",
2418 [CGROUP_IO_RIOPS_MAX
] = "IOReadIOPSMax",
2419 [CGROUP_IO_WIOPS_MAX
] = "IOWriteIOPSMax",
2422 DEFINE_STRING_TABLE_LOOKUP(cgroup_io_limit_type
, CGroupIOLimitType
);
2424 int cg_cpu_shares_parse(const char *s
, uint64_t *ret
) {
2429 *ret
= CGROUP_CPU_SHARES_INVALID
;
2433 r
= safe_atou64(s
, &u
);
2437 if (u
< CGROUP_CPU_SHARES_MIN
|| u
> CGROUP_CPU_SHARES_MAX
)
2444 int cg_blkio_weight_parse(const char *s
, uint64_t *ret
) {
2449 *ret
= CGROUP_BLKIO_WEIGHT_INVALID
;
2453 r
= safe_atou64(s
, &u
);
2457 if (u
< CGROUP_BLKIO_WEIGHT_MIN
|| u
> CGROUP_BLKIO_WEIGHT_MAX
)
2464 bool is_cgroup_fs(const struct statfs
*s
) {
2465 return is_fs_type(s
, CGROUP_SUPER_MAGIC
) ||
2466 is_fs_type(s
, CGROUP2_SUPER_MAGIC
);
2469 bool fd_is_cgroup_fs(int fd
) {
2472 if (fstatfs(fd
, &s
) < 0)
2475 return is_cgroup_fs(&s
);
2478 static const char *cgroup_controller_table
[_CGROUP_CONTROLLER_MAX
] = {
2479 [CGROUP_CONTROLLER_CPU
] = "cpu",
2480 [CGROUP_CONTROLLER_CPUACCT
] = "cpuacct",
2481 [CGROUP_CONTROLLER_IO
] = "io",
2482 [CGROUP_CONTROLLER_BLKIO
] = "blkio",
2483 [CGROUP_CONTROLLER_MEMORY
] = "memory",
2484 [CGROUP_CONTROLLER_DEVICES
] = "devices",
2485 [CGROUP_CONTROLLER_PIDS
] = "pids",
2488 DEFINE_STRING_TABLE_LOOKUP(cgroup_controller
, CGroupController
);