diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-03-12 01:14:03 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-03-12 01:14:03 +0900 |
| commit | 196b200d0f19c41730db439c62db9b39e424f21f (patch) | |
| tree | 0723b900cea0816b6501f3933f768fb75453dd49 /container/container.go | |
| parent | 04e6bc3c5c99d6a99f17cfa5f69f34fe8941aee2 (diff) | |
container: expose priority and SCHED_OTHER policy
The more explicit API removes the arbitrary limit preventing use of SCHED_OTHER (referred to as SCHED_NORMAL in the kernel). This change also exposes priority value to set.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/container.go')
| -rw-r--r-- | container/container.go | 27 |
1 files changed, 21 insertions, 6 deletions
diff --git a/container/container.go b/container/container.go index ab597b72..ad86fb03 100644 --- a/container/container.go +++ b/container/container.go @@ -38,9 +38,13 @@ type ( Container struct { // Whether the container init should stay alive after its parent terminates. AllowOrphan bool - // Scheduling policy to set via sched_setscheduler(2). The zero value - // skips this call. Supported policies are [SCHED_BATCH], [SCHED_IDLE]. + // Whether to set SchedPolicy and SchedPriority via sched_setscheduler(2). + SetScheduler bool + // Scheduling policy to set via sched_setscheduler(2). SchedPolicy std.SchedPolicy + // Scheduling priority to set via sched_setscheduler(2). The zero value + // implies the minimum value supported by the current SchedPolicy. + SchedPriority std.Int // Cgroup fd, nil to disable. Cgroup *int // ExtraFiles passed through to initial process in the container, with @@ -373,7 +377,15 @@ func (p *Container) Start() error { // sched_setscheduler: thread-directed but acts on all processes // created from the calling thread - if p.SchedPolicy > 0 && p.SchedPolicy <= std.SCHED_LAST { + if p.SetScheduler { + if p.SchedPolicy < 0 || p.SchedPolicy > std.SCHED_LAST { + return &StartError{ + Fatal: false, + Step: "set scheduling policy", + Err: EINVAL, + } + } + var param schedParam if priority, err := p.SchedPolicy.GetPriorityMin(); err != nil { return &StartError{ @@ -382,10 +394,13 @@ func (p *Container) Start() error { Err: err, } } else { - param.priority = priority + param.priority = max(priority, p.SchedPriority) } - p.msg.Verbosef("setting scheduling policy %s", p.SchedPolicy) + p.msg.Verbosef( + "setting scheduling policy %s priority %d", + p.SchedPolicy, param.priority, + ) if err := schedSetscheduler( 0, // calling thread p.SchedPolicy, @@ -393,7 +408,7 @@ func (p *Container) Start() error { ); err != nil { return &StartError{ Fatal: true, - Step: "enforce landlock ruleset", + Step: "set scheduling policy", Err: err, } } |
