container freezer: prevent frozen tasks or cgroups from changing
[safe/jmp/linux-2.6] / kernel / cgroup_freezer.c
1 /*
2  * cgroup_freezer.c -  control group freezer subsystem
3  *
4  * Copyright IBM Corporation, 2007
5  *
6  * Author : Cedric Le Goater <clg@fr.ibm.com>
7  *
8  * This program is free software; you can redistribute it and/or modify it
9  * under the terms of version 2.1 of the GNU Lesser General Public License
10  * as published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it would be useful, but
13  * WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
15  */
16
17 #include <linux/module.h>
18 #include <linux/cgroup.h>
19 #include <linux/fs.h>
20 #include <linux/uaccess.h>
21 #include <linux/freezer.h>
22 #include <linux/seq_file.h>
23
24 enum freezer_state {
25         STATE_RUNNING = 0,
26         STATE_FREEZING,
27         STATE_FROZEN,
28 };
29
30 struct freezer {
31         struct cgroup_subsys_state css;
32         enum freezer_state state;
33         spinlock_t lock; /* protects _writes_ to state */
34 };
35
36 static inline struct freezer *cgroup_freezer(
37                 struct cgroup *cgroup)
38 {
39         return container_of(
40                 cgroup_subsys_state(cgroup, freezer_subsys_id),
41                 struct freezer, css);
42 }
43
44 static inline struct freezer *task_freezer(struct task_struct *task)
45 {
46         return container_of(task_subsys_state(task, freezer_subsys_id),
47                             struct freezer, css);
48 }
49
50 int cgroup_frozen(struct task_struct *task)
51 {
52         struct freezer *freezer;
53         enum freezer_state state;
54
55         task_lock(task);
56         freezer = task_freezer(task);
57         state = freezer->state;
58         task_unlock(task);
59
60         return state == STATE_FROZEN;
61 }
62
63 /*
64  * cgroups_write_string() limits the size of freezer state strings to
65  * CGROUP_LOCAL_BUFFER_SIZE
66  */
67 static const char *freezer_state_strs[] = {
68         "RUNNING",
69         "FREEZING",
70         "FROZEN",
71 };
72
73 /*
74  * State diagram
75  * Transitions are caused by userspace writes to the freezer.state file.
76  * The values in parenthesis are state labels. The rest are edge labels.
77  *
78  * (RUNNING) --FROZEN--> (FREEZING) --FROZEN--> (FROZEN)
79  *    ^ ^                     |                       |
80  *    | \_______RUNNING_______/                       |
81  *    \_____________________________RUNNING___________/
82  */
83
84 struct cgroup_subsys freezer_subsys;
85
86 /* Locks taken and their ordering
87  * ------------------------------
88  * css_set_lock
89  * cgroup_mutex (AKA cgroup_lock)
90  * task->alloc_lock (AKA task_lock)
91  * freezer->lock
92  * task->sighand->siglock
93  *
94  * cgroup code forces css_set_lock to be taken before task->alloc_lock
95  *
96  * freezer_create(), freezer_destroy():
97  * cgroup_mutex [ by cgroup core ]
98  *
99  * can_attach():
100  * cgroup_mutex
101  *
102  * cgroup_frozen():
103  * task->alloc_lock (to get task's cgroup)
104  *
105  * freezer_fork() (preserving fork() performance means can't take cgroup_mutex):
106  * task->alloc_lock (to get task's cgroup)
107  * freezer->lock
108  *  sighand->siglock (if the cgroup is freezing)
109  *
110  * freezer_read():
111  * cgroup_mutex
112  *  freezer->lock
113  *   read_lock css_set_lock (cgroup iterator start)
114  *
115  * freezer_write() (freeze):
116  * cgroup_mutex
117  *  freezer->lock
118  *   read_lock css_set_lock (cgroup iterator start)
119  *    sighand->siglock
120  *
121  * freezer_write() (unfreeze):
122  * cgroup_mutex
123  *  freezer->lock
124  *   read_lock css_set_lock (cgroup iterator start)
125  *    task->alloc_lock (to prevent races with freeze_task())
126  *     sighand->siglock
127  */
128 static struct cgroup_subsys_state *freezer_create(struct cgroup_subsys *ss,
129                                                   struct cgroup *cgroup)
130 {
131         struct freezer *freezer;
132
133         freezer = kzalloc(sizeof(struct freezer), GFP_KERNEL);
134         if (!freezer)
135                 return ERR_PTR(-ENOMEM);
136
137         spin_lock_init(&freezer->lock);
138         freezer->state = STATE_RUNNING;
139         return &freezer->css;
140 }
141
142 static void freezer_destroy(struct cgroup_subsys *ss,
143                             struct cgroup *cgroup)
144 {
145         kfree(cgroup_freezer(cgroup));
146 }
147
148 /* Task is frozen or will freeze immediately when next it gets woken */
149 static bool is_task_frozen_enough(struct task_struct *task)
150 {
151         return frozen(task) ||
152                 (task_is_stopped_or_traced(task) && freezing(task));
153 }
154
155 /*
156  * The call to cgroup_lock() in the freezer.state write method prevents
157  * a write to that file racing against an attach, and hence the
158  * can_attach() result will remain valid until the attach completes.
159  */
160 static int freezer_can_attach(struct cgroup_subsys *ss,
161                               struct cgroup *new_cgroup,
162                               struct task_struct *task)
163 {
164         struct freezer *freezer;
165         int retval;
166
167         /* Anything frozen can't move or be moved to/from */
168
169         if (is_task_frozen_enough(task))
170                 return -EBUSY;
171
172         freezer = cgroup_freezer(new_cgroup);
173         if (freezer->state == STATE_FROZEN)
174                 return -EBUSY;
175
176         retval = 0;
177         task_lock(task);
178         freezer = task_freezer(task);
179         if (freezer->state == STATE_FROZEN)
180                 retval = -EBUSY;
181         task_unlock(task);
182         return retval;
183 }
184
185 static void freezer_fork(struct cgroup_subsys *ss, struct task_struct *task)
186 {
187         struct freezer *freezer;
188
189         task_lock(task);
190         freezer = task_freezer(task);
191         task_unlock(task);
192
193         BUG_ON(freezer->state == STATE_FROZEN);
194         spin_lock_irq(&freezer->lock);
195         /* Locking avoids race with FREEZING -> RUNNING transitions. */
196         if (freezer->state == STATE_FREEZING)
197                 freeze_task(task, true);
198         spin_unlock_irq(&freezer->lock);
199 }
200
201 /*
202  * caller must hold freezer->lock
203  */
204 static void check_if_frozen(struct cgroup *cgroup,
205                              struct freezer *freezer)
206 {
207         struct cgroup_iter it;
208         struct task_struct *task;
209         unsigned int nfrozen = 0, ntotal = 0;
210
211         cgroup_iter_start(cgroup, &it);
212         while ((task = cgroup_iter_next(cgroup, &it))) {
213                 ntotal++;
214                 if (is_task_frozen_enough(task))
215                         nfrozen++;
216         }
217
218         /*
219          * Transition to FROZEN when no new tasks can be added ensures
220          * that we never exist in the FROZEN state while there are unfrozen
221          * tasks.
222          */
223         if (nfrozen == ntotal)
224                 freezer->state = STATE_FROZEN;
225         cgroup_iter_end(cgroup, &it);
226 }
227
228 static int freezer_read(struct cgroup *cgroup, struct cftype *cft,
229                         struct seq_file *m)
230 {
231         struct freezer *freezer;
232         enum freezer_state state;
233
234         if (!cgroup_lock_live_group(cgroup))
235                 return -ENODEV;
236
237         freezer = cgroup_freezer(cgroup);
238         spin_lock_irq(&freezer->lock);
239         state = freezer->state;
240         if (state == STATE_FREEZING) {
241                 /* We change from FREEZING to FROZEN lazily if the cgroup was
242                  * only partially frozen when we exitted write. */
243                 check_if_frozen(cgroup, freezer);
244                 state = freezer->state;
245         }
246         spin_unlock_irq(&freezer->lock);
247         cgroup_unlock();
248
249         seq_puts(m, freezer_state_strs[state]);
250         seq_putc(m, '\n');
251         return 0;
252 }
253
254 static int try_to_freeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
255 {
256         struct cgroup_iter it;
257         struct task_struct *task;
258         unsigned int num_cant_freeze_now = 0;
259
260         freezer->state = STATE_FREEZING;
261         cgroup_iter_start(cgroup, &it);
262         while ((task = cgroup_iter_next(cgroup, &it))) {
263                 if (!freeze_task(task, true))
264                         continue;
265                 if (is_task_frozen_enough(task))
266                         continue;
267                 if (!freezing(task) && !freezer_should_skip(task))
268                         num_cant_freeze_now++;
269         }
270         cgroup_iter_end(cgroup, &it);
271
272         return num_cant_freeze_now ? -EBUSY : 0;
273 }
274
275 static int unfreeze_cgroup(struct cgroup *cgroup, struct freezer *freezer)
276 {
277         struct cgroup_iter it;
278         struct task_struct *task;
279
280         cgroup_iter_start(cgroup, &it);
281         while ((task = cgroup_iter_next(cgroup, &it))) {
282                 int do_wake;
283
284                 task_lock(task);
285                 do_wake = __thaw_process(task);
286                 task_unlock(task);
287                 if (do_wake)
288                         wake_up_process(task);
289         }
290         cgroup_iter_end(cgroup, &it);
291         freezer->state = STATE_RUNNING;
292
293         return 0;
294 }
295
296 static int freezer_change_state(struct cgroup *cgroup,
297                                 enum freezer_state goal_state)
298 {
299         struct freezer *freezer;
300         int retval = 0;
301
302         freezer = cgroup_freezer(cgroup);
303         spin_lock_irq(&freezer->lock);
304         check_if_frozen(cgroup, freezer); /* may update freezer->state */
305         if (goal_state == freezer->state)
306                 goto out;
307         switch (freezer->state) {
308         case STATE_RUNNING:
309                 retval = try_to_freeze_cgroup(cgroup, freezer);
310                 break;
311         case STATE_FREEZING:
312                 if (goal_state == STATE_FROZEN) {
313                         /* Userspace is retrying after
314                          * "/bin/echo FROZEN > freezer.state" returned -EBUSY */
315                         retval = try_to_freeze_cgroup(cgroup, freezer);
316                         break;
317                 }
318                 /* state == FREEZING and goal_state == RUNNING, so unfreeze */
319         case STATE_FROZEN:
320                 retval = unfreeze_cgroup(cgroup, freezer);
321                 break;
322         default:
323                 break;
324         }
325 out:
326         spin_unlock_irq(&freezer->lock);
327
328         return retval;
329 }
330
331 static int freezer_write(struct cgroup *cgroup,
332                          struct cftype *cft,
333                          const char *buffer)
334 {
335         int retval;
336         enum freezer_state goal_state;
337
338         if (strcmp(buffer, freezer_state_strs[STATE_RUNNING]) == 0)
339                 goal_state = STATE_RUNNING;
340         else if (strcmp(buffer, freezer_state_strs[STATE_FROZEN]) == 0)
341                 goal_state = STATE_FROZEN;
342         else
343                 return -EIO;
344
345         if (!cgroup_lock_live_group(cgroup))
346                 return -ENODEV;
347         retval = freezer_change_state(cgroup, goal_state);
348         cgroup_unlock();
349         return retval;
350 }
351
352 static struct cftype files[] = {
353         {
354                 .name = "state",
355                 .read_seq_string = freezer_read,
356                 .write_string = freezer_write,
357         },
358 };
359
360 static int freezer_populate(struct cgroup_subsys *ss, struct cgroup *cgroup)
361 {
362         return cgroup_add_files(cgroup, ss, files, ARRAY_SIZE(files));
363 }
364
365 struct cgroup_subsys freezer_subsys = {
366         .name           = "freezer",
367         .create         = freezer_create,
368         .destroy        = freezer_destroy,
369         .populate       = freezer_populate,
370         .subsys_id      = freezer_subsys_id,
371         .can_attach     = freezer_can_attach,
372         .attach         = NULL,
373         .fork           = freezer_fork,
374         .exit           = NULL,
375 };