Per-exec cgroups follow-up: host-configured hard memory.max (no protobuf)

Adds an opt-in hard per-session memory ceiling on top of patch #9's scoped-OOM.
The exec already ships the full OCI Spec, so the limit rides
spec.linux.resources.memory.limit — no RPC/protobuf change:

- host framework: LinuxProcessConfiguration.memoryLimitInBytes; LinuxContainer.exec
  stamps it onto the exec spec.
- guest: Server+GRPC.createProcess reads it back and applies it as the exec
  cgroup's memory.max (new Cgroup2Manager.setMemoryMax) via createExec/ManagedProcess.
- Nucleic: ContainerServiceSettings.controlPerSessionMemoryGiB (default 0 = off),
  applied only to the shared control container (ContainerManager.exec); wired
  through ContainerEngine.exec.

So one session can't consume the whole shared container's memory before its own
(oom.group-scoped) OOM. Default off preserves #9's behavior. Compile-verified host
+ musl guest; rides the pending -nucleic2 image, still runtime-pending.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
2026-07-13 20:12:42 -07:00
co-authored by Claude Opus 4.8
parent 2eb563c90c
commit 831d19c3a6
7 changed files with 53 additions and 8 deletions
@@ -911,6 +911,11 @@ extension LinuxContainer {
var config = LinuxProcessConfiguration()
try configuration(&config)
spec.process = config.toOCI()
// [Nucleic vendored patch] Per-exec memory ceiling → the exec's OCI resources, which the
// guest applies as memory.max on this exec's own cgroup (patch #9).
if let limit = config.memoryLimitInBytes {
spec.linux?.resources?.memory?.limit = Int64(limit)
}
let stdio = IOUtil.setup(
portAllocator: self.hostVsockPorts,
@@ -948,6 +953,10 @@ extension LinuxContainer {
var spec = self.generateRuntimeSpec()
spec.process = configuration.toOCI()
// [Nucleic vendored patch] Per-exec memory ceiling → the exec's OCI resources (see above).
if let limit = configuration.memoryLimitInBytes {
spec.linux?.resources?.memory?.limit = Int64(limit)
}
let stdio = IOUtil.setup(
portAllocator: self.hostVsockPorts,