Put envd, ptys, socats, and commands into their own cgroups - #1580
Merged
Merged
Conversation
djeebus
requested review from
ValentaTomas,
dobrac and
jakubno
as code owners
December 4, 2025 23:16
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
ValentaTomas
reviewed
Dec 4, 2025
djeebus
commented
Dec 8, 2025
djeebus
force-pushed
the
oom-killing-no-systemd-run
branch
from
December 9, 2025 00:24
2fdcc9e to
3b9a6a2
Compare
other code review comments as well
ValentaTomas
approved these changes
Dec 12, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This configures memory reservations on the envd service, and puts internal processes into cgroups based on their process type. Most importantly, this keeps envd responsive when the system is saturated.
envd.service cgroup:
the envd process. manages and handles communication into the sandbox.
pty cgroup:
any process that defines a pty configuration. assumed to be interactive, so it gets higher priority.
socat cgroup:
forwarded ports. shouldn't require much cpu, but is used for interaction, so it gets higher priority.
user cgroup:
every other command launched by the user. the lowest priority, as it has the highest chance of interrupting envd.
Note
Adds a cgroup v2 manager and assigns envd, PTY, socat, and user processes to dedicated cgroups with CPU/memory settings; integrated into process handling, port forwarding, and orchestrator templates.
cgroupspackage with cgroup v2 manager (Cgroup2Manager), options, noop manager, and tests.main.go: create and configure cgroup manager (flags:--cgroup-root), set per-type CPU/memory (pty,socat,user), pass to process service and port forwarder; bumpVersionto0.4.3.port/forward.go: runsocatinProcessTypeSocatcgroup viaSysProcAttrFD.services/process: plumb cgroup manager;handler.NewsetsSysProcAttr{UseCgroupFD,CgroupFD}and selects proc type (ptyvsuser).envd.service.tplwith cgroup delegation and resource reservations (Delegate=yes,MemoryMin/Low,CPUWeight).github.laiyagushi.com/opencontainers/runtime-spectov1.3.0; adjust rootfs test accordingly.Written by Cursor Bugbot for commit 4d795e6. This will update automatically on new commits. Configure here.