SYSTEMD.RESOURCE-CONTROL(5) systemd.resource-control systemd.resource-control - slice.slice, scope.scope, service.service, socket.socket, mount.mount, swap.swap (services) (slices) (scopes) (sockets) (mount points) (swap devices) . (cgroups) . . systemd.unit(5) systemd.slice(5) systemd.scope(5) systemd.service(5) systemd.socket(5) systemd.mount(5) systemd.swap(5) . [Slice] [Scope] [Service] [Socket] [Mount] [Swap] . systemd systemd.exec(5). . cgroup cgroup. cgroup . systemd . CPUWeight= cpu TasksMax= pids. MemoryAccounting=/TasksAccounting=/IOAccounting=. cgroup . . Delegate= ( ). . systemd ( user@.service) . cgroup DisableControllers= ( ). 1. -.slice / \ /-----/ \--------------\ / \ system.slice user.slice / \ / \ / \ / \ / \ user@42.service user@1000.service / \ Delegate= Delegate=yes a.service b.slice / \ CPUWeight=20 DisableControllers=cpu / \ / \ app.slice session.slice / \ CPUWeight=100 CPUWeight=100 / \ b1.service b2.service CPUWeight=1000 cpu b1.service b2.service. system.slice user.slice (CPU) . user.slice user@1000.service. app.slice session.slice cpu (nice levels). 42 cgroup . system.slice 1:6 a.service 5:6 b.slice b.slice 100 cpu.weight CPUWeight= . CPUWeight= b2.service DisableControllers= b.slice cpu b1.service b2.service (nice levels). systemd.unit(5) (drop-in) *.d/. . . user-nnn.slice. 1000 /etc/systemd/system/user-1000.slice /etc/systemd/system/user-1000.slice.d/*.conf /etc/systemd/system/user-.slice.d/*.conf. . [1] (APIs) . : o Slice= Requires= After= . : (CPU) CPUWeight=weight, StartupCPUWeight=weight cpu . "idle": o . "cpu.weight" . 1 10000. 100. v2[2] CFS[3]. . . o "idle" cgroup " " cgroup . cgroup "cpu.idle". cgroup-v2 cgroup-v1 . StartupCPUWeight= CPUWeight= . StartupCPUWeight= . cpu (session-id) " " (The autogroup feature) sched(7). cpu . 232. CPUQuota= cpu . . "%". . 100% . "cpu.max" "cpu.cfs_quota_us" . Control Groups v2[2] CFS Bandwidth Control[4]. CPUQuota= . : CPUQuota=20% 20% . 213. CPUQuotaPeriodSec= cpu . CPUQuota=. "ms" ( "s" .) 100 . [1ms, 1000ms]. 1 . CPUQuotaPeriodSec= . "cpu.max" "cpu.cfs_period_us" . Control Groups v2[2] CFS Scheduler[3]. : CPUQuotaPeriodSec=10ms 10 . 242. AllowedCPUs=, StartupAllowedCPUs= cpuset . . . . AllowedCPUs= StartupAllowedCPUs= . EffectiveCPUs=. StartupAllowedCPUs= AllowedCPUs= . StartupAllowedCPUs= . . 244. MemoryAccounting= memory . . (boolean). . DefaultMemoryAccounting= systemd-system.conf(5). 208. MemoryMin=bytes, MemoryLow=bytes, StartupMemoryLow=bytes memory . . . MemoryLow= (OOM killer) . ( ). MemoryMin= MemoryLow= . . . K M G T ( 1024) . . "infinity" . "memory.min" "memory.low". [5]. StartupMemoryLow= MemoryMin= . StartupMemoryLow= . 240. MemoryHigh=bytes, StartupMemoryHigh=bytes memory . (throttling limit) . . . . K M G T ( 1024) . . "infinity" . "memory.high". [5]. EffectiveMemoryHigh= ( EffectiveMemoryMax=). StartupMemoryHigh= MemoryHigh= . StartupMemoryHigh= . 231. MemoryMax=bytes, StartupMemoryMax=bytes memory . . (out-of-memory killer) . MemoryHigh= MemoryMax= . . K M G T ( 1024) . . "infinity" . "memory.max". [5]. EffectiveMemoryMax= ( ). StartupMemoryMax= MemoryMax= . StartupMemoryMax= . 231. MemorySwapMax=bytes, StartupMemorySwapMax=bytes memory . (swap) . . K M G T ( 1024) . . "infinity" . "memory.swap.max". [5]. StartupMemorySwapMax= MemorySwapMax= . StartupMemorySwapMax= . 232. MemoryZSwapMax=bytes, StartupMemoryZSwapMax=bytes memory . zswap . zswap . (RAM) . . Zswap[6] . . K M G T ( 1024) . "infinity" . "memory.zswap.max". [5]. StartupMemoryZSwapMax= MemoryZSwapMax= . StartupMemoryZSwapMax= . 253. MemoryZSwapWriteback= memory . (boolean). (true) Zswap (false). (true). (writeback) / Zswap. Zswap[6] . 256. AllowedMemoryNodes=, StartupAllowedMemoryNodes= cpuset . NUMA . NUMA . NUMA NUMA . AllowedMemoryNodes= StartupAllowedMemoryNodes= NUMA . EffectiveMemoryNodes=. StartupAllowedMemoryNodes= AllowedMemoryNodes= . StartupAllowedMemoryNodes= . . 244. TasksAccounting= pids . (task accounting) . (boolean). . (kernel threads) . . DefaultTasksAccounting= systemd-system.conf(5). 227. TasksMax=N pids . . ( ) . . "infinity" . "pids.max". pids[7]. EffectiveTasksMax=. DefaultTasksMax= systemd-system.conf(5). 227. / IOAccounting= io . / . . / . DefaultIOAccounting= systemd-system.conf(5). 230. IOWeight=weight, StartupIOWeight=weight / io . / . ( 1 10000) / . "io.weight" 100. /[8]. / / . / . StartupIOWeight= IOWeight= . . 230. IODeviceWeight=device weight io . / . 1 10000. (: "/dev/sda 1000"). . "io.weight" 100. . /[8]. / (loopback) . . 1:1 dm-crypt/LUKS. RAID . 230. IOReadBandwidthMax=device bytes, IOWriteBandwidthMax=device bytes / io . / . (not work-conserving) . ( ) . . K M G T 1000. (: "/dev/disk/by-path/pci-0000:00:1f.2-scsi-0:0:0:0 5M"). "io.max". . /[8]. IODeviceWeight= . 230. IOReadIOPSMax=device IOPS, IOWriteIOPSMax=device IOPS / io . / (IOPS) / . . IOPS IOPS . . IOPS K M G T IOPS KiloIOPS MegaIOPS GigaIOPS TeraIOPS 1000. (: "/dev/disk/by-path/pci-0000:00:1f.2-scsi-0:0:0:0 1K"). "io.max". IOPS . /[8]. IODeviceWeight= . 230. IODeviceLatencyTargetSec=device target io . / . . (: "/dev/sda 25ms"). . "io.latency". . /[8]. "IOAccounting=yes". . IODeviceWeight= . 240. IPAccounting= . (true) IPv4 IPv6 . IPv4 IPv6 . IPv4 IPv6 ( ). . . -- . DefaultIPAccounting= systemd-system.conf(5). . 235. IPAddressAllow=ADDRESS[/PREFIXLENGTH]..., IPAddressDeny=ADDRESS[/PREFIXLENGTH]... IP AF_INET AF_INET6. IPv4 IPv6 "/". (32 IPv4 128 IPv6). ( ). . . . IP IP . : o IP IPAddressAllow=. o IP IPAddressDeny=. o . IP () IPAddressDeny=any ( -.slice system.slice -- systemd.special(7) ) IPAddressAllow= . IP . IP . IP . . . . IPv4 IPv6 . : 1. / +-------------------+-----------------------+--------------------------+ | | | | | | | | +-------------------+-----------------------+--------------------------+ |any | 0.0.0.0/0 ::/0 | | +-------------------+-----------------------+--------------------------+ |localhost | 127.0.0.0/8 ::1/128 | | | | | | | | | | | | | | | | | | +-------------------+-----------------------+--------------------------+ |link-local | 169.254.0.0/16 | | | | fe80::/64 | IP | | | | | | | | | | | | (link-local) | +-------------------+-----------------------+--------------------------+ |multicast | 224.0.0.0/4 ff00::/8 | | | | | | | | | | | | | | | | | IP | +-------------------+-----------------------+--------------------------+ ( eBPF ). . IP. "+" . 235. SocketBindAllow=bind-rule, SocketBindDeny=bind-rule bind(2) . . bind-rule address-family transport-protocol ip-ports. bind-rule := { [address-family:][transport-protocol:][ip-ports] | any } address-family := { ipv4 | ipv6 } transport-protocol := { tcp | udp } ip-ports := { ip-port | ip-port-range } address-family ipv4 ipv6. IPv4 IPv6 transport-protocol ip-port. transport-protocol tcp udp. . ip-port 1...65535 0 . ip-port-range := ip-port-low-ip-port-high ip-port-low ip-port-high 1...65535 . any . SocketBindAllow= SocketBindDeny= . SocketBindAllow= SocketBindDeny=. SocketBindAllow= SocketBindDeny= 128. o SocketBindAllow=. o SocketBindDeny=. o . cgroup-bpf cgroup/bind4 cgroup/bind6. bind(2) . : bind(). : ... # Allow binding IPv6 socket addresses with a port greater than or equal to 10000. [Service] SocketBindAllow=ipv6:10000-65535 SocketBindDeny=any ... # Allow binding IPv4 and IPv6 socket addresses with 1234 and 4321 ports. [Service] SocketBindAllow=1234 SocketBindAllow=4321 SocketBindDeny=any ... # Deny binding IPv6 socket addresses. [Service] SocketBindDeny=ipv6 ... # Deny binding IPv4 and IPv6 socket addresses. [Service] SocketBindDeny=any ... # Allow binding only over TCP [Service] SocketBindAllow=tcp SocketBindDeny=any ... # Allow binding only over IPv6/TCP [Service] SocketBindAllow=ipv6:tcp SocketBindDeny=any ... # Allow binding ports within 10000-65535 range over IPv4/UDP. [Service] SocketBindAllow=ipv4:udp:10000-65535 SocketBindDeny=any ... "+" . 249. RestrictNetworkInterfaces= . . ( ). "~" : ( ). . . ( ) ( ). . ("lo") . 1: RestrictNetworkInterfaces=eth1 RestrictNetworkInterfaces=eth2 eth1 eth2. 2: RestrictNetworkInterfaces=~eth1 eth2 eth1 eth2. 3: RestrictNetworkInterfaces=eth1 eth2 RestrictNetworkInterfaces=~eth1 eth2. "+" . 250. BindNetworkInterface= . . VRF . ip vrf exec. nss-resolve DNS SYSTEMD_NSS_RESOLVE_IFINDEX. cgroup-bpf cgroup/sock_create. : [Service] BindNetworkInterface=vrf-mgmt "+" . 260. NFTSet=family:table:set (cgroup) NFT[9]. . NFT cgroup cgroup systemd . DynamicUser= . NFT. ( "cgroup" "user" "group") NFT ( "arp" "bridge" "inet" "ip" "ip6" "netdev") . NFT. NFT ("cgroup" "user" "group") . NFT . systemd ( ) NFT . . 2. source type +-------------------+--------------------------+-----------------------+ | | | | | | | NFT | | | | | +-------------------+--------------------------+-----------------------+ |"cgroup" | | "cgroupsv2" | | | | | | | | | | | (control group ID) | | +-------------------+--------------------------+-----------------------+ |"user" | | "meta skuid" | | | | | | | (user ID) | | +-------------------+--------------------------+-----------------------+ |"group" | | "meta skgid" | | | | | | | (group ID) | | +-------------------+--------------------------+-----------------------+ NFT systemctl daemon-reload . : [Service] NFTSet=cgroup:inet:filter:my_service user:inet:filter:serviceuser NFT : table inet filter { set my_service { type cgroupsv2 } set serviceuser { typeof meta skuid } chain x { socket cgroupv2 level 2 @my_service accept drop } chain y { meta skuid @serviceuser accept drop } } . 255. BPF IPIngressFilterPath=BPF_FS_PROGRAM_PATH, IPEgressFilterPath=BPF_FS_PROGRAM_PATH BPF IP AF_INET AF_INET6. BPF BPF (/sys/fs/bpf/). ( ). IPAddressAllow= IPAddressDeny= . . . . BPF_FS_PROGRAM_PATH IPIngressFilterPath= BPFProgram= BPFProgram=ingress:BPF_FS_PROGRAM_PATH (cgroup). IPEgressFilterPath= egress. IP . IP . IP . ( eBPF ). . ( Delegate=yes) . 243. BPFProgram=type:program-path BPFProgram= BPF (cgroup) . ( IPEgressFilterPath= IPIngressFilterPath= .) Cgroup-bpf BPF BPF cgroup-bpf . bpf.h[10]. BPF [11]. BPF BPF ":" : type:program-path. BPF BPF bpftool(8) : egress ingress sock_create sock_ops device bind4 bind6 connect4 connect6 post_bind4 post_bind6 sendmsg4 sendmsg6 sysctl recvmsg4 recvmsg6 getsockopt setsockopt. (inode) BPF bpffs ( /sys/fs/bpf/). ( BPF ) ( ). BPFProgram= . / : . BPF egress program-path IPEgressFilterPath= BPFProgram= BPFProgram= (cgroup). ingress IPIngressFilterPath=. BPF BPFProgram= BPF multi type . : BPFProgram=egress:/sys/fs/bpf/egress-hook BPFProgram=bind6:/sys/fs/bpf/sock-addr-hook 249. DeviceAllow= . : r w m (reading) (writing) (mknod) . eBPF. PrivateDevices= . systemd.exec(5). /dev/ "char-" "block-" /proc/devices. . (globbing) "*" "?". ( !) /dev/char/ /dev/block/. . : /dev/sda5 ATA SCSI. "char-pts" "char-alsa" TTY ALSA . "char-cpu/*" . . . After=modprobe@xyz.service Wants=modprobe@xyz.service . : ... [Unit] Wants=modprobe@loop.service After=modprobe@loop.service [Service] DeviceAllow=block-loop DeviceAllow=/dev/loop-control ... "+" . 208. DevicePolicy=auto|closed|strict : strict . 208. closed /dev/null /dev/zero /dev/full /dev/random /dev/urandom. 208. auto DeviceAllow= . . 208. "+" . 208. Slice= . system.slice ( ). system.slice . systemd . . . DefaultDependencies=no systemd.service(5) " " . 208. Delegate= . . ( User=) . : ( ) . ( ) . (true) . (false) ( ). . . . false. . . : cpu cpuset io memory pids bpf-firewall bpf-devices bpf-foreign bpf-socket-bind bpf-restrict-network-interfaces bpf-bind-network-interface. . . cgroup . [12]. 218. DelegateSubgroup= . ( !) . (off). ( cgroup.procs ). Delegate= . "" ExecStart= ExecReload= . .control. ( / ) . . ("") . 254. DisableControllers= . . . . . DisableControllers= . DisableControllers= . cgroup systemd. : cpu cpuset io memory pids bpf-firewall bpf-devices bpf-foreign bpf-socket-bind bpf-restrict-network-interfaces bpf-bind-network-interface. 240. ManagedOOMSwap=auto|kill, ManagedOOMMemoryPressure=auto|kill systemd-oomd.service(8) (cgroups) . auto. kill systemd-oomd. oomd.conf(5) systemd-oomd SIGKILL . systemd-oomd.service(8) oomd.conf(5). kill After= Wants= systemd-oomd.service DefaultDependencies=no. auto systemd-oomd . kill auto systemd-oomd. 247. ManagedOOMMemoryPressureLimit= oomd.conf(5) . 0% 100% . 0% oomd.conf(5). ManagedOOMMemoryPressure=kill. 247. ManagedOOMMemoryPressureDurationSec= oomd.conf(5) . "ms" "s" systemd.time(7) . (1s). oomd.conf(5). ManagedOOMMemoryPressure=kill. 257. ManagedOOMPreference=none|avoid|omit systemd-oomd . ( xattr(7)) avoid omit. (swap) systemd-oomd (root). systemd-oomd (root) . systemd-oomd -.slice /user.slice/user-1000.slice/user@1000.service/ UID 1000 -.slice UID 0. /user.slice/user-1000.slice/user@1000.service/ . avoid systemd-oomd . omit systemd-oomd . avoid omit systemd-oomd. . none systemd-oomd systemd-oomd.service(8) oomd.conf(5). 248. MemoryPressureWatch= . "auto" "skip". "no" $MEMORY_PRESSURE_WATCH /dev/null. "yes" . memory.pressure . $MEMORY_PRESSURE_WATCH . MemoryPressureThresholdSec= $MEMORY_PRESSURE_WRITE. "auto" . "skip" . . . systemd[13]. sd-event(3) sd_event_add_memory_pressure(3) . DefaultMemoryPressureWatch= systemd-system.conf(5). 254. MemoryPressureThresholdSec= MemoryPressureWatch=. . DefaultMemoryPressureThresholdSec= systemd-system.conf(5) ( 200ms). "ms" "s" systemd.time(7) . 254. (Coredump) CoredumpReceive= . (coredump) . CoredumpReceive=yes Delegate=yes. false. systemd-coredump CoredumpReceive=yes Delegate=yes systemd-coredump systemd-coredump . systemd-coredump(8). 255. systemd 252 ( 1[14]) : CPUShares=weight StartupCPUShares=weight MemoryLimit=bytes BlockIOAccounting= BlockIOWeight=weight StartupBlockIOWeight=weight BlockIODeviceWeight=device weight BlockIOReadBandwidth=device bytes BlockIOWriteBandwidth=device bytes. cgroup . systemd 258 CPUAccounting= cgroup . systemd(1) systemd-system.conf(5) systemd.unit(5) systemd.service(5) systemd.slice(5) systemd.scope(5) systemd.socket(5) systemd.mount(5) systemd.swap(5) systemd.exec(5) systemd.directives(7) systemd.special(7) systemd-oomd.service(8) : 2[2] 1. https://systemd.io/CONTROL_GROUP_INTERFACE 2. 2 https://docs.kernel.org/admin-guide/cgroup-v2.html 3. CFS https://docs.kernel.org/scheduler/sched-design-CFS.html 4. CFS https://docs.kernel.org/scheduler/sched-bwc.html 5. https://docs.kernel.org/admin-guide/cgroup-v2.html#memory-interface-files 6. Zswap https://docs.kernel.org/admin-guide/mm/zswap.html 7. pids https://docs.kernel.org/admin-guide/cgroup-v2.html#pid 8. https://docs.kernel.org/admin-guide/cgroup-v2.html#io-interface-files 9. NFT https://netfilter.org/projects/nftables/index.html 10. bpf.h https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/plain/include/uapi/linux/bpf.h 11. BPF https://docs.kernel.org/bpf/ 12. https://systemd.io/CGROUP_DELEGATION 13. systemd https://systemd.io/MEMORY_PRESSURE 14. 1 https://docs.kernel.org/admin-guide/cgroup-v1/index.html 3 . . : . systemd 260.2 SYSTEMD.RESOURCE-CONTROL(5)