Per-exec cgroups follow-up: host-configured hard memory.max (no protobuf)
Adds an opt-in hard per-session memory ceiling on top of patch #9's scoped-OOM. The exec already ships the full OCI Spec, so the limit rides spec.linux.resources.memory.limit — no RPC/protobuf change: - host framework: LinuxProcessConfiguration.memoryLimitInBytes; LinuxContainer.exec stamps it onto the exec spec. - guest: Server+GRPC.createProcess reads it back and applies it as the exec cgroup's memory.max (new Cgroup2Manager.setMemoryMax) via createExec/ManagedProcess. - Nucleic: ContainerServiceSettings.controlPerSessionMemoryGiB (default 0 = off), applied only to the shared control container (ContainerManager.exec); wired through ContainerEngine.exec. So one session can't consume the whole shared container's memory before its own (oom.group-scoped) OOM. Default off preserves #9's behavior. Compile-verified host + musl guest; rides the pending -nucleic2 image, still runtime-pending. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -895,10 +895,18 @@ extension Initd: Com_Apple_Containerization_Sandbox_V3_SandboxContext.SimpleServ
|
||||
|
||||
// This is an exec.
|
||||
if let container = await self.state.containers[request.containerID] {
|
||||
// [Nucleic vendored patch] A per-exec memory ceiling rides the exec's OCI
|
||||
// resources (set host-side by LinuxContainer.exec); apply it as this exec's
|
||||
// own memory.max (patch #9). Only positive limits count.
|
||||
let execMemoryLimit: UInt64? = {
|
||||
guard let limit = ociSpec.linux?.resources?.memory?.limit, limit > 0 else { return nil }
|
||||
return UInt64(limit)
|
||||
}()
|
||||
try await container.createExec(
|
||||
id: request.id,
|
||||
stdio: stdioPorts,
|
||||
process: process
|
||||
process: process,
|
||||
memoryLimitBytes: execMemoryLimit
|
||||
)
|
||||
} else {
|
||||
// We need to make our new fangled container.
|
||||
|
||||
Reference in New Issue
Block a user