Per-exec cgroups follow-up: host-configured hard memory.max (no protobuf)
Adds an opt-in hard per-session memory ceiling on top of patch #9's scoped-OOM. The exec already ships the full OCI Spec, so the limit rides spec.linux.resources.memory.limit — no RPC/protobuf change: - host framework: LinuxProcessConfiguration.memoryLimitInBytes; LinuxContainer.exec stamps it onto the exec spec. - guest: Server+GRPC.createProcess reads it back and applies it as the exec cgroup's memory.max (new Cgroup2Manager.setMemoryMax) via createExec/ManagedProcess. - Nucleic: ContainerServiceSettings.controlPerSessionMemoryGiB (default 0 = off), applied only to the shared control container (ContainerManager.exec); wired through ContainerEngine.exec. So one session can't consume the whole shared container's memory before its own (oom.group-scoped) OOM. Default off preserves #9's behavior. Compile-verified host + musl guest; rides the pending -nucleic2 image, still runtime-pending. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -288,6 +288,12 @@ public struct Cgroup2Manager: Sendable {
|
||||
try Self.writeValue(path: self.path, value: String(max), fileName: "pids.max")
|
||||
}
|
||||
|
||||
/// [Nucleic vendored patch] Hard memory ceiling (`memory.max`) — a host-configured per-exec cap so
|
||||
/// one session can't consume the whole container's memory before its own (oom.group-scoped) OOM.
|
||||
package func setMemoryMax(bytes: UInt64) throws {
|
||||
try Self.writeValue(path: self.path, value: String(bytes), fileName: "memory.max")
|
||||
}
|
||||
|
||||
/// [Nucleic vendored patch] Remove this cgroup directory (rmdir). The cgroup must already be empty
|
||||
/// of processes and child cgroups. Best-effort partial-setup cleanup for the per-exec layout.
|
||||
package func remove() throws {
|
||||
|
||||
Reference in New Issue
Block a user