From f5c219983c0f60a07f1bd52b6f6071e86f35455e Mon Sep 17 00:00:00 2001 From: Robert Günzler Date: Mon, 25 Sep 2023 11:56:34 +0200 Subject: add os config MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Robert Günzler --- .../src/mount-cgroups/cgroup-release-agent.sh | 19 +++ .../src/mount-cgroups/dependencies.d/mount-procfs | 0 os/etc/s6-rc/src/mount-cgroups/shell-up | 178 +++++++++++++++++++++ os/etc/s6-rc/src/mount-cgroups/type | 1 + os/etc/s6-rc/src/mount-cgroups/up | 3 + 5 files changed, 201 insertions(+) create mode 100755 os/etc/s6-rc/src/mount-cgroups/cgroup-release-agent.sh create mode 100644 os/etc/s6-rc/src/mount-cgroups/dependencies.d/mount-procfs create mode 100755 os/etc/s6-rc/src/mount-cgroups/shell-up create mode 100644 os/etc/s6-rc/src/mount-cgroups/type create mode 100644 os/etc/s6-rc/src/mount-cgroups/up (limited to 'os/etc/s6-rc/src/mount-cgroups') diff --git a/os/etc/s6-rc/src/mount-cgroups/cgroup-release-agent.sh b/os/etc/s6-rc/src/mount-cgroups/cgroup-release-agent.sh new file mode 100755 index 0000000..0a6ec17 --- /dev/null +++ b/os/etc/s6-rc/src/mount-cgroups/cgroup-release-agent.sh @@ -0,0 +1,19 @@ +#!/bin/sh +# This is run by the kernel after the last task is removed from a +# control group in the openrc hierarchy. + +# Copyright (c) 2007-2015 The OpenRC Authors. +# See the Authors file at the top-level directory of this distribution and +# https://github.com/OpenRC/openrc/blob/HEAD/AUTHORS +# +# This file is part of OpenRC. It is subject to the license terms in +# the LICENSE file found in the top-level directory of this +# distribution and at https://github.com/OpenRC/openrc/blob/HEAD/LICENSE +# This file may not be copied, modified, propagated, or distributed +# except according to the terms contained in the LICENSE file. + +cgroup=/sys/fs/cgroup/openrc +PATH=/bin:/usr/bin:/sbin:/usr/sbin +if [ -d ${cgroup}/"$1" ]; then + rmdir ${cgroup}/"$1" +fi diff --git a/os/etc/s6-rc/src/mount-cgroups/dependencies.d/mount-procfs b/os/etc/s6-rc/src/mount-cgroups/dependencies.d/mount-procfs new file mode 100644 index 0000000..e69de29 diff --git a/os/etc/s6-rc/src/mount-cgroups/shell-up b/os/etc/s6-rc/src/mount-cgroups/shell-up new file mode 100755 index 0000000..f26a99e --- /dev/null +++ b/os/etc/s6-rc/src/mount-cgroups/shell-up @@ -0,0 +1,178 @@ +#!/bin/sh +# Copyright (c) 2017 The OpenRC Authors. +# See the Authors file at the top-level directory of this distribution and +# https://github.com/OpenRC/openrc/blob/HEAD/AUTHORS +# +# This file is part of OpenRC. It is subject to the license terms in +# the LICENSE file found in the top-level directory of this +# distribution and at https://github.com/OpenRC/openrc/blob/HEAD/LICENSE +# This file may not be copied, modified, propagated, or distributed +# except according to the terms contained in the LICENSE file. + +set -eux + +cgroup_opts=${cgroup_opts:-nodev,noexec,nosuid} +rc_cgroup_mode=${cgroup_mode:-hybrid} +rc_cgroup_controllers=${cgroup_controllers:-} +rc_cgroup_memory_use_hierarchy=${cgroup_memory_use_hierarchy:-no} +rc_cgroupsize=${cgroupsize:-10m} + +yesno() +{ + [ -z "$1" ] && return 1 + + case "$1" in + [Yy][Ee][Ss]|[Tt][Rr][Uu]|[Oo][Nn]|1) return 0 ;; + [Nn][Oo]|[Ff][Aa][Ll][Ss]|[Oo][Ff][Ff]|0) return 1 ;; + esac + + local value= + eval value=\"\$$1\" + case "$value" in + [Yy][Ee][Ss]|[Tt][Rr][Uu]|[Oo][Nn]|1) return 0 ;; + [Nn][Oo]|[Ff][Aa][Ll][Ss]|[Oo][Ff][Ff]|0) return 1 ;; + *) echo "\$$1 is not set properly" >&2; return 2 ;; + esac +} + +cgroup2_find_path() +{ + if grep -qw cgroup2 /proc/filesystems; then + case "${rc_cgroup_mode}" in + hybrid) printf "/sys/fs/cgroup/unified" ;; + unified) printf "/sys/fs/cgroup" ;; + esac + fi + return 0 +} + +cgroup1_base() +{ + grep -qw cgroup /proc/filesystems || return 0 + if ! mountpoint -q /sys/fs/cgroup; then + local opts="${cgroup_opts},mode=755,size=${rc_cgroupsize:-10m}" + mount -n -t tmpfs -o "${opts}" cgroup_root /sys/fs/cgroup + fi + + if ! mountpoint -q /sys/fs/cgroup/openrc; then + local agent="/etc/s6-rc/src/mount-cgroups/cgroup-release-agent.sh" + mkdir /sys/fs/cgroup/openrc + mount -n -t cgroup \ + -o none,${cgroup_opts},name=openrc,release_agent="$agent" \ + openrc /sys/fs/cgroup/openrc + printf 1 > /sys/fs/cgroup/openrc/notify_on_release + fi + return 0 +} + +cgroup1_controllers() +{ + yesno "${rc_controller_cgroups:-YES}" && [ -e /proc/cgroups ] && + grep -qw cgroup /proc/filesystems || return 0 + while read -r name _ _ enabled _; do + case "${enabled}" in + 1) mountpoint -q "/sys/fs/cgroup/${name}" && continue + local x + for x in $rc_cgroup_controllers; do + [ "${name}" = "blkio" ] && [ "${x}" = "io" ] && + continue 2 + [ "${name}" = "${x}" ] && + continue 2 + done + mkdir "/sys/fs/cgroup/${name}" + mount -n -t cgroup -o "${cgroup_opts},${name}" \ + "${name}" "/sys/fs/cgroup/${name}" + yesno "${rc_cgroup_memory_use_hierarchy:-no}" && + [ "${name}" = memory ] && + echo 1 > /sys/fs/cgroup/memory/memory.use_hierarchy + ;; + esac + done < /proc/cgroups + return 0 +} + +cgroup2_base() +{ + grep -qw cgroup2 /proc/filesystems || return 0 + local base + base="$(cgroup2_find_path)" + if ! mountpoint -q "${base}"; then + mkdir -p "${base}" + mount -t cgroup2 none -o "${cgroup_opts},nsdelegate" "${base}" 2> /dev/null || + mount -t cgroup2 none -o "${cgroup_opts}" "${base}" + fi + return 0 +} + +cgroup2_controllers() +{ + grep -qw cgroup2 /proc/filesystems || return 0 + local active cgroup_path x y + cgroup_path="$(cgroup2_find_path)" + [ -z "${cgroup_path}" ] && return 0 + [ ! -e "${cgroup_path}/cgroup.controllers" ] && return 0 + [ ! -e "${cgroup_path}/cgroup.subtree_control" ]&& return 0 + read -r active < "${cgroup_path}/cgroup.controllers" + for x in ${active}; do + case "${rc_cgroup_mode}" in + unified) + echo "+${x}" > "${cgroup_path}/cgroup.subtree_control" + ;; + hybrid) + for y in ${rc_cgroup_controllers}; do + if [ "$x" = "$y" ]; then + echo "+${x}" > "${cgroup_path}/cgroup.subtree_control" + fi + done + ;; + esac + done + return 0 +} + +cgroups_hybrid() +{ + cgroup1_base + cgroup2_base + cgroup2_controllers + cgroup1_controllers + return 0 +} + +cgroups_legacy() +{ + cgroup1_base + cgroup1_controllers + return 0 +} + +cgroups_unified() +{ + cgroup2_base + cgroup2_controllers + return 0 +} + +mount_cgroups() +{ + case "${rc_cgroup_mode}" in + hybrid) cgroups_hybrid ;; + unified) cgroups_unified ;; + legacy) cgroups_legacy ;; + esac + return 0 +} + +restorecon_cgroups() +{ + if [ -x /sbin/restorecon ]; then + restorecon -rF /sys/fs/cgroup >/dev/null 2>&1 + fi + return 0 +} + +# set up kernel support for cgroups +if [ -d /sys/fs/cgroup ]; then + mount_cgroups + restorecon_cgroups +fi diff --git a/os/etc/s6-rc/src/mount-cgroups/type b/os/etc/s6-rc/src/mount-cgroups/type new file mode 100644 index 0000000..bdd22a1 --- /dev/null +++ b/os/etc/s6-rc/src/mount-cgroups/type @@ -0,0 +1 @@ +oneshot diff --git a/os/etc/s6-rc/src/mount-cgroups/up b/os/etc/s6-rc/src/mount-cgroups/up new file mode 100644 index 0000000..87c9a66 --- /dev/null +++ b/os/etc/s6-rc/src/mount-cgroups/up @@ -0,0 +1,3 @@ +#!/bin/execlineb -P +envfile /etc/s6-rc/config/cgroups.conf +exec sh /etc/s6-rc/src/mount-cgroups/shell-up -- cgit 1.4.1