[systemd-devel] Put some users to a different slice?

Lennart Poettering lennart at poettering.net
Wed Jun 26 15:05:38 UTC 2024


On Di, 25.06.24 11:57, Frank Steiner (fsteiner-mail1 at bio.ifi.lmu.de) wrote:

> Hi,
>
> I'd like to put a subgroup of our users into a separate slice (below
> the user slice), so that they could be restricted further than the other
> users.

We always had the intention to add something like this, but this is
not supported right now. This is not as easy to support, because
currently the hierarchy carries meaning, i.e. to determine if
something belongs to user scope, we check if it's below the user.slice
cgroup and so on. We could fix this, by stuffing more info in the
session scope name, and this has been on the todo list for a longer
time, but so far noone sat down and implemented this. This would
require making sure the sd-login APIs are all updated to look in the
scope unit name, and never consult slices up the tree anymore.

Hence, sorry, but we cannot do this right now.

Lennart

--
Lennart Poettering, Berlin


More information about the systemd-devel mailing list