1 /*
2 * cgroup_freezer.c - control group freezer subsystem
3 *
4 * Copyright IBM Corporation, 2007
5 *
6 * Author : Cedric Le Goater <clg@fr.ibm.com>
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of version 2.1 of the GNU Lesser General Public License
10 * as published by the Free Software Foundation.
11 *
12 * This program is distributed in the hope that it would be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
15 */
16
17 #include <linux/module.h>
18 #include <linux/cgroup.h>
19 #include <linux/fs.h>
20 #include <linux/uaccess.h>
21 #include <linux/freezer.h>
22 #include <linux/seq_file.h>
23
24 enum freezer_state {
25 CGROUP_THAWED = 0,
26 CGROUP_FREEZING,
27 CGROUP_FROZEN,
28 };
29
30 struct freezer {
31 struct cgroup_subsys_state css;
32 enum freezer_state state;
33 spinlock_t lock; /* protects _writes_ to state */
34 };
35
cgroup_freezer(struct cgroup * cgroup)36 static inline struct freezer *cgroup_freezer(
37 struct cgroup *cgroup)
38 {
39 return container_of(
40 cgroup_subsys_state(cgroup, freezer_subsys_id),
41 struct freezer, css);
42 }
43
task_freezer(struct task_struct * task)44 static inline struct freezer *task_freezer(struct task_struct *task)
45 {
46 return container_of(task_subsys_state(task, freezer_subsys_id),
47 struct freezer, css);
48 }
49
cgroup_frozen(struct task_struct * task)50 int cgroup_frozen(struct task_struct *task)
51 {
52 struct freezer *freezer;
53 enum freezer_state state;
54
55 task_lock(task);
56 freezer = task_freezer(task);
57 state = freezer->state;
58 task_unlock(task);
59
60 return state == CGROUP_FROZEN;
61 }
62
63 /*
64 * cgroups_write_string() limits the size of freezer state strings to
65 * CGROUP_LOCAL_BUFFER_SIZE
66 */
67 static const char *freezer_state_strs[] = {
68 "THAWED",
69 "FREEZING",
70 "FROZEN",
71 };
72
73 /*
74 * State diagram
75 * Transitions are caused by userspace writes to the freezer.state file.
76 * The values in parenthesis are state labels. The rest are edge labels.
77 *
78 * (THAWED) --FROZEN--> (FREEZING) --FROZEN--> (FROZEN)
79 * ^ ^ | |
80 * | \_______THAWED_______/ |
81 * \__________________________THAWED____________/
82 */
83
84 struct cgroup_subsys freezer_subsys;
85
86 /* Locks taken and their ordering
87 * ------------------------------
88 * css_set_lock
89 * cgroup_mutex (AKA cgroup_lock)
90 * task->alloc_lock (AKA task_lock)
91 * freezer->lock
92 * task->sighand->siglock
93 *
94 * cgroup code forces css_set_lock to be taken before task->alloc_lock
95 *
96 * freezer_create(), freezer_destroy():
97 * cgroup_mutex [ by cgroup core ]
98 *
99 * can_attach():
100 * cgroup_mutex
101 *
102 * cgroup_frozen():
103 * task->alloc_lock (to get task's cgroup)
104 *
105 * freezer_fork() (preserving fork() performance means can't take cgroup_mutex):
106 * task->alloc_lock (to get task's cgroup)
107 * freezer->lock
108 * sighand->siglock (if the cgroup is freezing)
109 *
110 * freezer_read():
111 * cgroup_mutex
112 * freezer->lock
113 * read_lock css_set_lock (cgroup iterator start)
114 *
115 * freezer_write() (freeze):
116 * cgroup_mutex
117 * freezer->lock
118 * read_lock css_set_lock (cgroup iterator start)
119 * sighand->siglock
120 *
121 * freezer_write() (unfreeze):
122 * cgroup_mutex
123 * freezer->lock
124 * read_lock css_set_lock (cgroup iterator start)
125 * task->alloc_lock (to prevent races with freeze_task())
126 * sighand->siglock
127 */
freezer_create(struct cgroup_subsys * ss,struct cgroup * cgroup)128 static struct cgroup_subsys_state *freezer_create(struct cgroup_subsys *ss,
129 struct cgroup *cgroup)
130 {
131 struct freezer *freezer;
132
133 freezer = kzalloc(sizeof(struct freezer), GFP_KERNEL);
134 if (!freezer)
135 return ERR_PTR(-ENOMEM);
136
137 spin_lock_init(&freezer->lock);
138 freezer->state = CGROUP_THAWED;
139 return &freezer->css;
140 }
141
freezer_destroy(struct cgroup_subsys * ss,struct cgroup * cgroup)142 static void freezer_destroy(struct cgroup_subsys *ss,
143 struct cgroup *cgroup)
144 {
145 kfree(cgroup_freezer(cgroup));
146 }
147
148 /* Task is frozen or will freeze immediately when next it gets woken */
is_task_frozen_enough(struct task_struct * task)149 static bool is_task_frozen_enough(struct task_struct *task)
150 {
151 return frozen(task) ||
152 (task_is_stopped_or_traced(task) && freezing(task));
153 }
154
155 /*
156 * The call to cgroup_lock() in the freezer.state write method prevents
157 * a write to that file racing against an attach, and hence the
158 * can_attach() result will remain valid until the attach completes.
159 */
freezer_can_attach(struct cgroup_subsys * ss,struct cgroup * new_cgroup,struct task_struct * task)160 static int freezer_can_attach(struct cgroup_subsys *ss,
161 struct cgroup *new_cgroup,
162 struct task_struct *task)
163 {
164 struct freezer *freezer;
165
166 if ((current != task) && (!capable(CAP_SYS_ADMIN))) {
167 const struct cred *cred = current_cred(), *tcred;
168
169 tcred = __task_cred(task);
170 if (cred->euid != tcred->uid && cred->euid != tcred->suid)
171 return -EPERM;
172 }
173
174 /*
175 * Anything frozen can't move or be moved to/from.
176 *
177 * Since orig_freezer->state == FROZEN means that @task has been
178 * frozen, so it's sufficient to check the latter condition.
179 */
180
181 if (is_task_frozen_enough(task))
182 return -EBUSY;
183
184 freezer = cgroup_freezer(new_cgroup);
185 if (freezer->state == CGROUP_FROZEN)
186 return -EBUSY;
187
188 return 0;
189 }
190
freezer_fork(struct cgroup_subsys * ss,struct task_struct * task)191 static void freezer_fork(struct cgroup_subsys *ss, struct task_struct *task)
192 {
193 struct freezer *freezer;
194
195 /*
196 * No lock is needed, since the task isn't on tasklist yet,
197 * so it can't be moved to another cgroup, which means the
198 * freezer won't be removed and will be valid during this
199 * function call.
200 */
201 freezer = task_freezer(task);
202
203 /*
204 * The root cgroup is non-freezable, so we can skip the
205 * following check.
206 */
207 if (!freezer->css.cgroup->parent)
208 return;
209
210 spin_lock_irq(&freezer->lock);
211 BUG_ON(freezer->state == CGROUP_FROZEN);
212
213 /* Locking avoids race with FREEZING -> THAWED transitions. */
214 if (freezer->state == CGROUP_FREEZING)
215 freeze_task(task, true);
216 spin_unlock_irq(&freezer->lock);
217 }
218
219 /*
220 * caller must hold freezer->lock
221 */
update_freezer_state(struct cgroup * cgroup,struct freezer * freezer)222 static void update_freezer_state(struct cgroup *cgroup,
223 struct freezer *freezer)
224 {
225 struct cgroup_iter it;
226 struct task_struct *task;
227 unsigned int nfrozen = 0, ntotal = 0;
228
229 cgroup_iter_start(cgroup, &it);
230 while ((task = cgroup_iter_next(cgroup, &it))) {
231 ntotal++;
232 if (is_task_frozen_enough(task))
233 nfrozen++;
234 }
235
236 /*
237 * Transition to FROZEN when no new tasks can be added ensures
238 * that we never exist in the FROZEN state while there are unfrozen
239 * tasks.
240 */
241 if (nfrozen == ntotal)
242 freezer->state = CGROUP_FROZEN;
243 else if (nfrozen > 0)
244 freezer->state = CGROUP_FREEZING;
245 else
246 freezer->state = CGROUP_THAWED;
247 cgroup_iter_end(cgroup, &it);
248 }
249
freezer_read(struct cgroup * cgroup,struct cftype * cft,struct seq_file * m)250 static int freezer_read(struct cgroup *cgroup, struct cftype *cft,
251 struct seq_file *m)
252 {
253 struct freezer *freezer;
254 enum freezer_state state;
255
256 if (!cgroup_lock_live_group(cgroup))
257 return -ENODEV;
258
259 freezer = cgroup_freezer(cgroup);
260 spin_lock_irq(&freezer->lock);
261 state = freezer->state;
262 if (state == CGROUP_FREEZING) {
263 /* We change from FREEZING to FROZEN lazily if the cgroup was
264 * only partially frozen when we exitted write. */
265 update_freezer_state(cgroup, freezer);
266 state = freezer->state;
267 }
268 spin_unlock_irq(&freezer->lock);
269 cgroup_unlock();
270
271 seq_puts(m, freezer_state_strs[state]);
272 seq_putc(m, '\n');
273 return 0;
274 }
275
try_to_freeze_cgroup(struct cgroup * cgroup,struct freezer * freezer)276 static int try_to_freeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
277 {
278 struct cgroup_iter it;
279 struct task_struct *task;
280 unsigned int num_cant_freeze_now = 0;
281
282 freezer->state = CGROUP_FREEZING;
283 cgroup_iter_start(cgroup, &it);
284 while ((task = cgroup_iter_next(cgroup, &it))) {
285 if (!freeze_task(task, true))
286 continue;
287 if (is_task_frozen_enough(task))
288 continue;
289 if (!freezing(task) && !freezer_should_skip(task))
290 num_cant_freeze_now++;
291 }
292 cgroup_iter_end(cgroup, &it);
293
294 return num_cant_freeze_now ? -EBUSY : 0;
295 }
296
unfreeze_cgroup(struct cgroup * cgroup,struct freezer * freezer)297 static void unfreeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
298 {
299 struct cgroup_iter it;
300 struct task_struct *task;
301
302 cgroup_iter_start(cgroup, &it);
303 while ((task = cgroup_iter_next(cgroup, &it))) {
304 thaw_process(task);
305 }
306 cgroup_iter_end(cgroup, &it);
307
308 freezer->state = CGROUP_THAWED;
309 }
310
freezer_change_state(struct cgroup * cgroup,enum freezer_state goal_state)311 static int freezer_change_state(struct cgroup *cgroup,
312 enum freezer_state goal_state)
313 {
314 struct freezer *freezer;
315 int retval = 0;
316
317 freezer = cgroup_freezer(cgroup);
318
319 spin_lock_irq(&freezer->lock);
320
321 update_freezer_state(cgroup, freezer);
322 if (goal_state == freezer->state)
323 goto out;
324
325 switch (goal_state) {
326 case CGROUP_THAWED:
327 unfreeze_cgroup(cgroup, freezer);
328 break;
329 case CGROUP_FROZEN:
330 retval = try_to_freeze_cgroup(cgroup, freezer);
331 break;
332 default:
333 BUG();
334 }
335 out:
336 spin_unlock_irq(&freezer->lock);
337
338 return retval;
339 }
340
freezer_write(struct cgroup * cgroup,struct cftype * cft,const char * buffer)341 static int freezer_write(struct cgroup *cgroup,
342 struct cftype *cft,
343 const char *buffer)
344 {
345 int retval;
346 enum freezer_state goal_state;
347
348 if (strcmp(buffer, freezer_state_strs[CGROUP_THAWED]) == 0)
349 goal_state = CGROUP_THAWED;
350 else if (strcmp(buffer, freezer_state_strs[CGROUP_FROZEN]) == 0)
351 goal_state = CGROUP_FROZEN;
352 else
353 return -EINVAL;
354
355 if (!cgroup_lock_live_group(cgroup))
356 return -ENODEV;
357 retval = freezer_change_state(cgroup, goal_state);
358 cgroup_unlock();
359 return retval;
360 }
361
362 static struct cftype files[] = {
363 {
364 .name = "state",
365 .read_seq_string = freezer_read,
366 .write_string = freezer_write,
367 },
368 };
369
freezer_populate(struct cgroup_subsys * ss,struct cgroup * cgroup)370 static int freezer_populate(struct cgroup_subsys *ss, struct cgroup *cgroup)
371 {
372 if (!cgroup->parent)
373 return 0;
374 return cgroup_add_files(cgroup, ss, files, ARRAY_SIZE(files));
375 }
376
377 struct cgroup_subsys freezer_subsys = {
378 .name = "freezer",
379 .create = freezer_create,
380 .destroy = freezer_destroy,
381 .populate = freezer_populate,
382 .subsys_id = freezer_subsys_id,
383 .can_attach = freezer_can_attach,
384 .attach = NULL,
385 .fork = freezer_fork,
386 .exit = NULL,
387 };
388