1 /* SPDX-License-Identifier: LGPL-2.1+ */
8 #include <sys/statfs.h>
14 #define SYSTEMD_CGROUP_CONTROLLER_LEGACY "name=systemd"
15 #define SYSTEMD_CGROUP_CONTROLLER_HYBRID "name=unified"
16 #define SYSTEMD_CGROUP_CONTROLLER "_systemd"
18 /* An enum of well known cgroup controllers */
19 typedef enum CGroupController
{
20 /* Original cgroup controllers */
21 CGROUP_CONTROLLER_CPU
,
22 CGROUP_CONTROLLER_CPUACCT
, /* v1 only */
23 CGROUP_CONTROLLER_IO
, /* v2 only */
24 CGROUP_CONTROLLER_BLKIO
, /* v1 only */
25 CGROUP_CONTROLLER_MEMORY
,
26 CGROUP_CONTROLLER_DEVICES
, /* v1 only */
27 CGROUP_CONTROLLER_PIDS
,
29 /* BPF-based pseudo-controllers, v2 only */
30 CGROUP_CONTROLLER_BPF_FIREWALL
,
31 CGROUP_CONTROLLER_BPF_DEVICES
,
33 _CGROUP_CONTROLLER_MAX
,
34 _CGROUP_CONTROLLER_INVALID
= -1,
37 #define CGROUP_CONTROLLER_TO_MASK(c) (1U << (c))
39 /* A bit mask of well known cgroup controllers */
40 typedef enum CGroupMask
{
41 CGROUP_MASK_CPU
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_CPU
),
42 CGROUP_MASK_CPUACCT
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_CPUACCT
),
43 CGROUP_MASK_IO
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_IO
),
44 CGROUP_MASK_BLKIO
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_BLKIO
),
45 CGROUP_MASK_MEMORY
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_MEMORY
),
46 CGROUP_MASK_DEVICES
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_DEVICES
),
47 CGROUP_MASK_PIDS
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_PIDS
),
48 CGROUP_MASK_BPF_FIREWALL
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_BPF_FIREWALL
),
49 CGROUP_MASK_BPF_DEVICES
= CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_BPF_DEVICES
),
51 /* All real cgroupv1 controllers */
52 CGROUP_MASK_V1
= CGROUP_MASK_CPU
|CGROUP_MASK_CPUACCT
|CGROUP_MASK_BLKIO
|CGROUP_MASK_MEMORY
|CGROUP_MASK_DEVICES
|CGROUP_MASK_PIDS
,
54 /* All real cgroupv2 controllers */
55 CGROUP_MASK_V2
= CGROUP_MASK_CPU
|CGROUP_MASK_IO
|CGROUP_MASK_MEMORY
|CGROUP_MASK_PIDS
,
57 /* All cgroupv2 BPF pseudo-controllers */
58 CGROUP_MASK_BPF
= CGROUP_MASK_BPF_FIREWALL
|CGROUP_MASK_BPF_DEVICES
,
60 _CGROUP_MASK_ALL
= CGROUP_CONTROLLER_TO_MASK(_CGROUP_CONTROLLER_MAX
) - 1
63 static inline CGroupMask
CGROUP_MASK_EXTEND_JOINED(CGroupMask mask
) {
64 /* We always mount "cpu" and "cpuacct" in the same hierarchy. Hence, when one bit is set also set the other */
66 if (mask
& (CGROUP_MASK_CPU
|CGROUP_MASK_CPUACCT
))
67 mask
|= (CGROUP_MASK_CPU
|CGROUP_MASK_CPUACCT
);
72 /* Special values for all weight knobs on unified hierarchy */
73 #define CGROUP_WEIGHT_INVALID ((uint64_t) -1)
74 #define CGROUP_WEIGHT_MIN UINT64_C(1)
75 #define CGROUP_WEIGHT_MAX UINT64_C(10000)
76 #define CGROUP_WEIGHT_DEFAULT UINT64_C(100)
78 #define CGROUP_LIMIT_MIN UINT64_C(0)
79 #define CGROUP_LIMIT_MAX ((uint64_t) -1)
81 static inline bool CGROUP_WEIGHT_IS_OK(uint64_t x
) {
83 x
== CGROUP_WEIGHT_INVALID
||
84 (x
>= CGROUP_WEIGHT_MIN
&& x
<= CGROUP_WEIGHT_MAX
);
87 /* IO limits on unified hierarchy */
88 typedef enum CGroupIOLimitType
{
94 _CGROUP_IO_LIMIT_TYPE_MAX
,
95 _CGROUP_IO_LIMIT_TYPE_INVALID
= -1
98 extern const uint64_t cgroup_io_limit_defaults
[_CGROUP_IO_LIMIT_TYPE_MAX
];
100 const char* cgroup_io_limit_type_to_string(CGroupIOLimitType t
) _const_
;
101 CGroupIOLimitType
cgroup_io_limit_type_from_string(const char *s
) _pure_
;
103 /* Special values for the cpu.shares attribute */
104 #define CGROUP_CPU_SHARES_INVALID ((uint64_t) -1)
105 #define CGROUP_CPU_SHARES_MIN UINT64_C(2)
106 #define CGROUP_CPU_SHARES_MAX UINT64_C(262144)
107 #define CGROUP_CPU_SHARES_DEFAULT UINT64_C(1024)
109 static inline bool CGROUP_CPU_SHARES_IS_OK(uint64_t x
) {
111 x
== CGROUP_CPU_SHARES_INVALID
||
112 (x
>= CGROUP_CPU_SHARES_MIN
&& x
<= CGROUP_CPU_SHARES_MAX
);
115 /* Special values for the blkio.weight attribute */
116 #define CGROUP_BLKIO_WEIGHT_INVALID ((uint64_t) -1)
117 #define CGROUP_BLKIO_WEIGHT_MIN UINT64_C(10)
118 #define CGROUP_BLKIO_WEIGHT_MAX UINT64_C(1000)
119 #define CGROUP_BLKIO_WEIGHT_DEFAULT UINT64_C(500)
121 static inline bool CGROUP_BLKIO_WEIGHT_IS_OK(uint64_t x
) {
123 x
== CGROUP_BLKIO_WEIGHT_INVALID
||
124 (x
>= CGROUP_BLKIO_WEIGHT_MIN
&& x
<= CGROUP_BLKIO_WEIGHT_MAX
);
127 /* Default resource limits */
128 #define DEFAULT_TASKS_MAX_PERCENTAGE 15U /* 15% of PIDs, 4915 on default settings */
129 #define DEFAULT_USER_TASKS_MAX_PERCENTAGE 33U /* 33% of PIDs, 10813 on default settings */
131 typedef enum CGroupUnified
{
132 CGROUP_UNIFIED_UNKNOWN
= -1,
133 CGROUP_UNIFIED_NONE
= 0, /* Both systemd and controllers on legacy */
134 CGROUP_UNIFIED_SYSTEMD
= 1, /* Only systemd on unified */
135 CGROUP_UNIFIED_ALL
= 2, /* Both systemd and controllers on unified */
141 * We accept named hierarchies in the syntax "foo" and "name=foo".
143 * We expect that named hierarchies do not conflict in name with a
144 * kernel hierarchy, modulo the "name=" prefix.
146 * We always generate "normalized" controller names, i.e. without the
149 * We require absolute cgroup paths. When returning, we will always
150 * generate paths with multiple adjacent / removed.
153 int cg_enumerate_processes(const char *controller
, const char *path
, FILE **_f
);
154 int cg_read_pid(FILE *f
, pid_t
*_pid
);
155 int cg_read_event(const char *controller
, const char *path
, const char *event
,
158 int cg_enumerate_subgroups(const char *controller
, const char *path
, DIR **_d
);
159 int cg_read_subgroup(DIR *d
, char **fn
);
161 typedef enum CGroupFlags
{
163 CGROUP_IGNORE_SELF
= 2,
167 typedef void (*cg_kill_log_func_t
)(pid_t pid
, int sig
, void *userdata
);
169 int cg_kill(const char *controller
, const char *path
, int sig
, CGroupFlags flags
, Set
*s
, cg_kill_log_func_t kill_log
, void *userdata
);
170 int cg_kill_recursive(const char *controller
, const char *path
, int sig
, CGroupFlags flags
, Set
*s
, cg_kill_log_func_t kill_log
, void *userdata
);
172 int cg_migrate(const char *cfrom
, const char *pfrom
, const char *cto
, const char *pto
, CGroupFlags flags
);
173 int cg_migrate_recursive(const char *cfrom
, const char *pfrom
, const char *cto
, const char *pto
, CGroupFlags flags
);
174 int cg_migrate_recursive_fallback(const char *cfrom
, const char *pfrom
, const char *cto
, const char *pto
, CGroupFlags flags
);
176 int cg_split_spec(const char *spec
, char **controller
, char **path
);
177 int cg_mangle_path(const char *path
, char **result
);
179 int cg_get_path(const char *controller
, const char *path
, const char *suffix
, char **fs
);
180 int cg_get_path_and_check(const char *controller
, const char *path
, const char *suffix
, char **fs
);
182 int cg_pid_get_path(const char *controller
, pid_t pid
, char **path
);
184 int cg_trim(const char *controller
, const char *path
, bool delete_root
);
186 int cg_rmdir(const char *controller
, const char *path
);
188 int cg_create(const char *controller
, const char *path
);
189 int cg_attach(const char *controller
, const char *path
, pid_t pid
);
190 int cg_attach_fallback(const char *controller
, const char *path
, pid_t pid
);
191 int cg_create_and_attach(const char *controller
, const char *path
, pid_t pid
);
193 int cg_set_attribute(const char *controller
, const char *path
, const char *attribute
, const char *value
);
194 int cg_get_attribute(const char *controller
, const char *path
, const char *attribute
, char **ret
);
195 int cg_get_keyed_attribute(const char *controller
, const char *path
, const char *attribute
, char **keys
, char **values
);
197 int cg_set_access(const char *controller
, const char *path
, uid_t uid
, gid_t gid
);
199 int cg_set_xattr(const char *controller
, const char *path
, const char *name
, const void *value
, size_t size
, int flags
);
200 int cg_get_xattr(const char *controller
, const char *path
, const char *name
, void *value
, size_t size
);
202 int cg_install_release_agent(const char *controller
, const char *agent
);
203 int cg_uninstall_release_agent(const char *controller
);
205 int cg_is_empty(const char *controller
, const char *path
);
206 int cg_is_empty_recursive(const char *controller
, const char *path
);
208 int cg_get_root_path(char **path
);
210 int cg_path_get_session(const char *path
, char **session
);
211 int cg_path_get_owner_uid(const char *path
, uid_t
*uid
);
212 int cg_path_get_unit(const char *path
, char **unit
);
213 int cg_path_get_user_unit(const char *path
, char **unit
);
214 int cg_path_get_machine_name(const char *path
, char **machine
);
215 int cg_path_get_slice(const char *path
, char **slice
);
216 int cg_path_get_user_slice(const char *path
, char **slice
);
218 int cg_shift_path(const char *cgroup
, const char *cached_root
, const char **shifted
);
219 int cg_pid_get_path_shifted(pid_t pid
, const char *cached_root
, char **cgroup
);
221 int cg_pid_get_session(pid_t pid
, char **session
);
222 int cg_pid_get_owner_uid(pid_t pid
, uid_t
*uid
);
223 int cg_pid_get_unit(pid_t pid
, char **unit
);
224 int cg_pid_get_user_unit(pid_t pid
, char **unit
);
225 int cg_pid_get_machine_name(pid_t pid
, char **machine
);
226 int cg_pid_get_slice(pid_t pid
, char **slice
);
227 int cg_pid_get_user_slice(pid_t pid
, char **slice
);
229 int cg_path_decode_unit(const char *cgroup
, char **unit
);
231 char *cg_escape(const char *p
);
232 char *cg_unescape(const char *p
) _pure_
;
234 bool cg_controller_is_valid(const char *p
);
236 int cg_slice_to_path(const char *unit
, char **ret
);
238 typedef const char* (*cg_migrate_callback_t
)(CGroupMask mask
, void *userdata
);
240 int cg_create_everywhere(CGroupMask supported
, CGroupMask mask
, const char *path
);
241 int cg_attach_everywhere(CGroupMask supported
, const char *path
, pid_t pid
, cg_migrate_callback_t callback
, void *userdata
);
242 int cg_attach_many_everywhere(CGroupMask supported
, const char *path
, Set
* pids
, cg_migrate_callback_t callback
, void *userdata
);
243 int cg_migrate_everywhere(CGroupMask supported
, const char *from
, const char *to
, cg_migrate_callback_t callback
, void *userdata
);
244 int cg_trim_everywhere(CGroupMask supported
, const char *path
, bool delete_root
);
245 int cg_enable_everywhere(CGroupMask supported
, CGroupMask mask
, const char *p
);
247 int cg_mask_supported(CGroupMask
*ret
);
248 int cg_mask_from_string(const char *s
, CGroupMask
*ret
);
249 int cg_mask_to_string(CGroupMask mask
, char **ret
);
251 int cg_kernel_controllers(Set
**controllers
);
253 bool cg_ns_supported(void);
255 int cg_all_unified(void);
256 int cg_hybrid_unified(void);
257 int cg_unified_controller(const char *controller
);
258 int cg_unified_flush(void);
260 bool cg_is_unified_wanted(void);
261 bool cg_is_legacy_wanted(void);
262 bool cg_is_hybrid_wanted(void);
264 const char* cgroup_controller_to_string(CGroupController c
) _const_
;
265 CGroupController
cgroup_controller_from_string(const char *s
) _pure_
;
267 int cg_weight_parse(const char *s
, uint64_t *ret
);
268 int cg_cpu_shares_parse(const char *s
, uint64_t *ret
);
269 int cg_blkio_weight_parse(const char *s
, uint64_t *ret
);
271 bool is_cgroup_fs(const struct statfs
*s
);
272 bool fd_is_cgroup_fs(int fd
);