Build your own container
Stage 5 of 8v2 · c08b2455

Memory limit

Generate a cgroup v2 with memory.max and move the process into it.

Memory limit

Generate a cgroup v2 with memory.max and move the process into it. Preserve earlier capabilities and use the fixture only to make observation deterministic.

Contract

The harness receives a JSON process description and returns a syscall, mount, and limit plan. Real privileged execution stays outside the runner, but the plan must match Linux.

{ "op": "memory-limit", "name": "demo", "pid": 42, "bytes": 67108864 }

produces exactly:

{
  "writes": [
    ["demo/memory.max", "67108864"],
    ["demo/cgroup.procs", "42"]
  ]
}

Emit compact JSON with a final newline. Invalid input leaves stdout empty, writes error to stderr, and exits non-zero.

Design and limits

Separate policy, mutable state, and system effects. Make resource ownership, cleanup order, and pre/post-operation invariants explicit. Do not replace the central mechanism with a simulation: the fixture controls inputs and time while your code implements isolation, memory, or synchronisation as appropriate.

Test empty boundaries, mid-operation failures, and idempotent cleanup. Sort output only at the presentation boundary.

Acceptance

  • The example produces the exact output.
  • Resources are not leaked and work is not duplicated.
  • Failure leaves the system coherent.