• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * cgroup_freezer.c -  control group freezer subsystem
3  *
4  * Copyright IBM Corporation, 2007
5  *
6  * Author : Cedric Le Goater <clg@fr.ibm.com>
7  *
8  * This program is free software; you can redistribute it and/or modify it
9  * under the terms of version 2.1 of the GNU Lesser General Public License
10  * as published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it would be useful, but
13  * WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
15  */
16 
17 #include <linux/module.h>
18 #include <linux/cgroup.h>
19 #include <linux/fs.h>
20 #include <linux/uaccess.h>
21 #include <linux/freezer.h>
22 #include <linux/seq_file.h>
23 
24 enum freezer_state {
25 	CGROUP_THAWED = 0,
26 	CGROUP_FREEZING,
27 	CGROUP_FROZEN,
28 };
29 
30 struct freezer {
31 	struct cgroup_subsys_state css;
32 	enum freezer_state state;
33 	spinlock_t lock; /* protects _writes_ to state */
34 };
35 
cgroup_freezer(struct cgroup * cgroup)36 static inline struct freezer *cgroup_freezer(
37 		struct cgroup *cgroup)
38 {
39 	return container_of(
40 		cgroup_subsys_state(cgroup, freezer_subsys_id),
41 		struct freezer, css);
42 }
43 
task_freezer(struct task_struct * task)44 static inline struct freezer *task_freezer(struct task_struct *task)
45 {
46 	return container_of(task_subsys_state(task, freezer_subsys_id),
47 			    struct freezer, css);
48 }
49 
cgroup_frozen(struct task_struct * task)50 int cgroup_frozen(struct task_struct *task)
51 {
52 	struct freezer *freezer;
53 	enum freezer_state state;
54 
55 	task_lock(task);
56 	freezer = task_freezer(task);
57 	state = freezer->state;
58 	task_unlock(task);
59 
60 	return state == CGROUP_FROZEN;
61 }
62 
63 /*
64  * cgroups_write_string() limits the size of freezer state strings to
65  * CGROUP_LOCAL_BUFFER_SIZE
66  */
67 static const char *freezer_state_strs[] = {
68 	"THAWED",
69 	"FREEZING",
70 	"FROZEN",
71 };
72 
73 /*
74  * State diagram
75  * Transitions are caused by userspace writes to the freezer.state file.
76  * The values in parenthesis are state labels. The rest are edge labels.
77  *
78  * (THAWED) --FROZEN--> (FREEZING) --FROZEN--> (FROZEN)
79  *    ^ ^                    |                     |
80  *    | \_______THAWED_______/                     |
81  *    \__________________________THAWED____________/
82  */
83 
84 struct cgroup_subsys freezer_subsys;
85 
86 /* Locks taken and their ordering
87  * ------------------------------
88  * css_set_lock
89  * cgroup_mutex (AKA cgroup_lock)
90  * task->alloc_lock (AKA task_lock)
91  * freezer->lock
92  * task->sighand->siglock
93  *
94  * cgroup code forces css_set_lock to be taken before task->alloc_lock
95  *
96  * freezer_create(), freezer_destroy():
97  * cgroup_mutex [ by cgroup core ]
98  *
99  * can_attach():
100  * cgroup_mutex
101  *
102  * cgroup_frozen():
103  * task->alloc_lock (to get task's cgroup)
104  *
105  * freezer_fork() (preserving fork() performance means can't take cgroup_mutex):
106  * task->alloc_lock (to get task's cgroup)
107  * freezer->lock
108  *  sighand->siglock (if the cgroup is freezing)
109  *
110  * freezer_read():
111  * cgroup_mutex
112  *  freezer->lock
113  *   read_lock css_set_lock (cgroup iterator start)
114  *
115  * freezer_write() (freeze):
116  * cgroup_mutex
117  *  freezer->lock
118  *   read_lock css_set_lock (cgroup iterator start)
119  *    sighand->siglock
120  *
121  * freezer_write() (unfreeze):
122  * cgroup_mutex
123  *  freezer->lock
124  *   read_lock css_set_lock (cgroup iterator start)
125  *    task->alloc_lock (to prevent races with freeze_task())
126  *     sighand->siglock
127  */
freezer_create(struct cgroup_subsys * ss,struct cgroup * cgroup)128 static struct cgroup_subsys_state *freezer_create(struct cgroup_subsys *ss,
129 						  struct cgroup *cgroup)
130 {
131 	struct freezer *freezer;
132 
133 	freezer = kzalloc(sizeof(struct freezer), GFP_KERNEL);
134 	if (!freezer)
135 		return ERR_PTR(-ENOMEM);
136 
137 	spin_lock_init(&freezer->lock);
138 	freezer->state = CGROUP_THAWED;
139 	return &freezer->css;
140 }
141 
freezer_destroy(struct cgroup_subsys * ss,struct cgroup * cgroup)142 static void freezer_destroy(struct cgroup_subsys *ss,
143 			    struct cgroup *cgroup)
144 {
145 	kfree(cgroup_freezer(cgroup));
146 }
147 
148 /* Task is frozen or will freeze immediately when next it gets woken */
is_task_frozen_enough(struct task_struct * task)149 static bool is_task_frozen_enough(struct task_struct *task)
150 {
151 	return frozen(task) ||
152 		(task_is_stopped_or_traced(task) && freezing(task));
153 }
154 
155 /*
156  * The call to cgroup_lock() in the freezer.state write method prevents
157  * a write to that file racing against an attach, and hence the
158  * can_attach() result will remain valid until the attach completes.
159  */
freezer_can_attach(struct cgroup_subsys * ss,struct cgroup * new_cgroup,struct task_struct * task)160 static int freezer_can_attach(struct cgroup_subsys *ss,
161 			      struct cgroup *new_cgroup,
162 			      struct task_struct *task)
163 {
164 	struct freezer *freezer;
165 
166 	if ((current != task) && (!capable(CAP_SYS_ADMIN))) {
167 		const struct cred *cred = current_cred(), *tcred;
168 
169 		tcred = __task_cred(task);
170 		if (cred->euid != tcred->uid && cred->euid != tcred->suid)
171 			return -EPERM;
172 	}
173 
174 	/*
175 	 * Anything frozen can't move or be moved to/from.
176 	 *
177 	 * Since orig_freezer->state == FROZEN means that @task has been
178 	 * frozen, so it's sufficient to check the latter condition.
179 	 */
180 
181 	if (is_task_frozen_enough(task))
182 		return -EBUSY;
183 
184 	freezer = cgroup_freezer(new_cgroup);
185 	if (freezer->state == CGROUP_FROZEN)
186 		return -EBUSY;
187 
188 	return 0;
189 }
190 
freezer_fork(struct cgroup_subsys * ss,struct task_struct * task)191 static void freezer_fork(struct cgroup_subsys *ss, struct task_struct *task)
192 {
193 	struct freezer *freezer;
194 
195 	/*
196 	 * No lock is needed, since the task isn't on tasklist yet,
197 	 * so it can't be moved to another cgroup, which means the
198 	 * freezer won't be removed and will be valid during this
199 	 * function call.
200 	 */
201 	freezer = task_freezer(task);
202 
203 	/*
204 	 * The root cgroup is non-freezable, so we can skip the
205 	 * following check.
206 	 */
207 	if (!freezer->css.cgroup->parent)
208 		return;
209 
210 	spin_lock_irq(&freezer->lock);
211 	BUG_ON(freezer->state == CGROUP_FROZEN);
212 
213 	/* Locking avoids race with FREEZING -> THAWED transitions. */
214 	if (freezer->state == CGROUP_FREEZING)
215 		freeze_task(task, true);
216 	spin_unlock_irq(&freezer->lock);
217 }
218 
219 /*
220  * caller must hold freezer->lock
221  */
update_freezer_state(struct cgroup * cgroup,struct freezer * freezer)222 static void update_freezer_state(struct cgroup *cgroup,
223 				 struct freezer *freezer)
224 {
225 	struct cgroup_iter it;
226 	struct task_struct *task;
227 	unsigned int nfrozen = 0, ntotal = 0;
228 
229 	cgroup_iter_start(cgroup, &it);
230 	while ((task = cgroup_iter_next(cgroup, &it))) {
231 		ntotal++;
232 		if (is_task_frozen_enough(task))
233 			nfrozen++;
234 	}
235 
236 	/*
237 	 * Transition to FROZEN when no new tasks can be added ensures
238 	 * that we never exist in the FROZEN state while there are unfrozen
239 	 * tasks.
240 	 */
241 	if (nfrozen == ntotal)
242 		freezer->state = CGROUP_FROZEN;
243 	else if (nfrozen > 0)
244 		freezer->state = CGROUP_FREEZING;
245 	else
246 		freezer->state = CGROUP_THAWED;
247 	cgroup_iter_end(cgroup, &it);
248 }
249 
freezer_read(struct cgroup * cgroup,struct cftype * cft,struct seq_file * m)250 static int freezer_read(struct cgroup *cgroup, struct cftype *cft,
251 			struct seq_file *m)
252 {
253 	struct freezer *freezer;
254 	enum freezer_state state;
255 
256 	if (!cgroup_lock_live_group(cgroup))
257 		return -ENODEV;
258 
259 	freezer = cgroup_freezer(cgroup);
260 	spin_lock_irq(&freezer->lock);
261 	state = freezer->state;
262 	if (state == CGROUP_FREEZING) {
263 		/* We change from FREEZING to FROZEN lazily if the cgroup was
264 		 * only partially frozen when we exitted write. */
265 		update_freezer_state(cgroup, freezer);
266 		state = freezer->state;
267 	}
268 	spin_unlock_irq(&freezer->lock);
269 	cgroup_unlock();
270 
271 	seq_puts(m, freezer_state_strs[state]);
272 	seq_putc(m, '\n');
273 	return 0;
274 }
275 
try_to_freeze_cgroup(struct cgroup * cgroup,struct freezer * freezer)276 static int try_to_freeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
277 {
278 	struct cgroup_iter it;
279 	struct task_struct *task;
280 	unsigned int num_cant_freeze_now = 0;
281 
282 	freezer->state = CGROUP_FREEZING;
283 	cgroup_iter_start(cgroup, &it);
284 	while ((task = cgroup_iter_next(cgroup, &it))) {
285 		if (!freeze_task(task, true))
286 			continue;
287 		if (is_task_frozen_enough(task))
288 			continue;
289 		if (!freezing(task) && !freezer_should_skip(task))
290 			num_cant_freeze_now++;
291 	}
292 	cgroup_iter_end(cgroup, &it);
293 
294 	return num_cant_freeze_now ? -EBUSY : 0;
295 }
296 
unfreeze_cgroup(struct cgroup * cgroup,struct freezer * freezer)297 static void unfreeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
298 {
299 	struct cgroup_iter it;
300 	struct task_struct *task;
301 
302 	cgroup_iter_start(cgroup, &it);
303 	while ((task = cgroup_iter_next(cgroup, &it))) {
304 		thaw_process(task);
305 	}
306 	cgroup_iter_end(cgroup, &it);
307 
308 	freezer->state = CGROUP_THAWED;
309 }
310 
freezer_change_state(struct cgroup * cgroup,enum freezer_state goal_state)311 static int freezer_change_state(struct cgroup *cgroup,
312 				enum freezer_state goal_state)
313 {
314 	struct freezer *freezer;
315 	int retval = 0;
316 
317 	freezer = cgroup_freezer(cgroup);
318 
319 	spin_lock_irq(&freezer->lock);
320 
321 	update_freezer_state(cgroup, freezer);
322 	if (goal_state == freezer->state)
323 		goto out;
324 
325 	switch (goal_state) {
326 	case CGROUP_THAWED:
327 		unfreeze_cgroup(cgroup, freezer);
328 		break;
329 	case CGROUP_FROZEN:
330 		retval = try_to_freeze_cgroup(cgroup, freezer);
331 		break;
332 	default:
333 		BUG();
334 	}
335 out:
336 	spin_unlock_irq(&freezer->lock);
337 
338 	return retval;
339 }
340 
freezer_write(struct cgroup * cgroup,struct cftype * cft,const char * buffer)341 static int freezer_write(struct cgroup *cgroup,
342 			 struct cftype *cft,
343 			 const char *buffer)
344 {
345 	int retval;
346 	enum freezer_state goal_state;
347 
348 	if (strcmp(buffer, freezer_state_strs[CGROUP_THAWED]) == 0)
349 		goal_state = CGROUP_THAWED;
350 	else if (strcmp(buffer, freezer_state_strs[CGROUP_FROZEN]) == 0)
351 		goal_state = CGROUP_FROZEN;
352 	else
353 		return -EINVAL;
354 
355 	if (!cgroup_lock_live_group(cgroup))
356 		return -ENODEV;
357 	retval = freezer_change_state(cgroup, goal_state);
358 	cgroup_unlock();
359 	return retval;
360 }
361 
362 static struct cftype files[] = {
363 	{
364 		.name = "state",
365 		.read_seq_string = freezer_read,
366 		.write_string = freezer_write,
367 	},
368 };
369 
freezer_populate(struct cgroup_subsys * ss,struct cgroup * cgroup)370 static int freezer_populate(struct cgroup_subsys *ss, struct cgroup *cgroup)
371 {
372 	if (!cgroup->parent)
373 		return 0;
374 	return cgroup_add_files(cgroup, ss, files, ARRAY_SIZE(files));
375 }
376 
377 struct cgroup_subsys freezer_subsys = {
378 	.name		= "freezer",
379 	.create		= freezer_create,
380 	.destroy	= freezer_destroy,
381 	.populate	= freezer_populate,
382 	.subsys_id	= freezer_subsys_id,
383 	.can_attach	= freezer_can_attach,
384 	.attach		= NULL,
385 	.fork		= freezer_fork,
386 	.exit		= NULL,
387 };
388