Articles

PROCESS ISOLATION IN THE ALT OPERATING SYSTEM USING CGROUPS V2 MECHANISMS

Download PDF Article on eLIBRARY.RU

Abstract

The problem of computational resource management in multitasking operating systems is of particular importance in the context of widespread use of containerization environments and the need to simultaneously execute tasks with different resource requirements. Traditional Linux mechanisms – nice, cpulimit, and ulimit – do not provide comprehensive group isolation: nice sets only a recommended priority, cpulimit uses SIGSTOP/CONT signals, and ulimit restricts only the user session. The workload interference problem, known as the 'noisy neighbor' effect, remains a key challenge in system administration and information security. Purpose: experimental quantitative evaluation of the efficiency of cgroups v2 resource isolation mechanisms in the Alt Linux distribution (kernel 6.1.115). Methods. To verify hypotheses H1a (CPU isolation) and H1b (memory isolation), a series of controlled experiments was conducted using cpuset and memory.max controllers with varying workloads: 1–2 cores, memory limits of 50–500 MB, and a mixed scenario with priority and background processes. Measured metrics: PSR (CPU core affinity), nr_switches (context switches), memory.events (OOM Killer counters). Results. With cpuset, PSR matched the assigned core in 100% of observations; nr_switches was 3–4 without cross-group migration. When the memory.max limit was exceeded, the OOM Killer mechanism (oom_kill=1) was activated without affecting other groups. Conclusions. Hypotheses H1a and H1b are fully confirmed. Cgroups v2 demonstrates significant advantages over traditional isolation mechanisms. The mechanisms may support selected resource-separation and exhaustion-control requirements; however, the experiment alone does not demonstrate full compliance with FSTEC Order No. 118 or PCI DSS 4.0.

Online viewer

References

  1. Nosenko, D. I., Zolotarev, A. P., & Uymin, A. G. (2025). Setevoe i sistemnoe administrirovanie. Podgotovka k Demonstratsionnomu ekzamenu KOD 09.02.06-1-2025 [Network and system administration: Practicum]. Profobrazovanie. ISBN 978-5-4488-2908-6. Retrieved May 13, 2025, from https://www.iprbookshop.ru/159510.html (accessed: 13.05.2025).
  2. Uymin, A. G., & Nikitin, O. R. (2023). Modeling a telecommunication network using Linux network tools: Digital twin creation tools. I-Methods, 15(2). EDN NFJDVH.
  3. Nice and Renice Command in Linux. (2025). GeeksforGeeks. Retrieved May 14, 2025, from https://www.geeksforgeeks.org/linux-unix/nice-and-renice-command-in-linux-with-examples/ (accessed: 14.05.2025).
  4. Cpulimit: CPU usage limiter for Linux. (2025). GitHub. Retrieved May 14, 2025, from https://github.com/opsengine/cpulimit (accessed: 13.05.2025).
  5. Ulimit(3) – Linux manual page. (2025). man7.org. Retrieved May 14, 2025, from https://man7.org/linux/man-pages/man3/ulimit.3.html (accessed: 14.05.2025).
  6. Control Group v2 – The Linux Kernel documentation. (2025). The Linux Kernel. Retrieved May 14, 2025, from https://docs.kernel.org/admin-guide/cgroup-v2.html (accessed: 14.05.2025).
  7. Conway, J. (2025). Re: Getting out ahead of OOM. pgsql-admin Mailing List. Retrieved May 14, 2025, from https://postgrespro.com/list/id/e52f00fc-ffe3-4745-8082-b492f44c6693@joeconway.com (accessed: 14.05.2025).
  8. Namespaces (7) – Linux manual page. (2024). man7.org. Retrieved May 14, 2025, from https://man7.org/linux/man-pages/man7/namespaces.7.html (accessed: 14.05.2025).
  9. Wiedner, F., Daichendt, A., Andre, J., & Carle, G. (2023). Control groups added latency in NFVs: An update needed? In 2023 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN) (pp. 40–45). IEEE. DOI: 10.1109/NFV-SDN59219.2023.10329612.
  10. freedesktop.org. (2025). systemd.resource-control — Resource control unit settings. Retrieved September 30, 2025, from https://www.freedesktop.org/software/systemd/man/latest/systemd.resource-control.html (accessed: 30.09.2025).
  11. Kraynov, P. A., & Pashina, S. A. (2025). Monitoring the system of control groups of processes in the Alt OS. All-Russian Collection of Articles and Publications of the Institute for Education Development. Retrieved May 14, 2025, from https://ropkip.ru/publication/415456 (accessed: 14.05.2025).
  12. ALT Linux – Documentation. (2025). BaseALT. Retrieved May 14, 2025, from https://docs.altlinux.org/ru-RU/index.html (accessed: 14.05.2025).
  13. Federal Service for Technical and Export Control of Russia. (2022). Ob utverzhdenii Trebovaniy po bezopasnosti informatsii k sredstvam konteynerizatsii [On approval of Information Security Requirements for Containerization Tools] (Order No. 118). GARANT. Retrieved May 14, 2025, from https://base.garant.ru/405955413/ (accessed: 14.05.2025).
  14. GOST R 59006-2020. (2020). Zashchita informatsii. Doverennaya zagruzka. Terminy i opredeleniya [Information protection. Trusted boot. Terms and definitions]. Standartinform. Retrieved May 14, 2025, from https://docs.cntd.ru/document/1200174521 (accessed: 13.05.2025).
  15. PCI Security Standards Council. (2024). PCI Data Security Standard (PCI DSS) version 4.0.1. Retrieved May 14, 2025, from https://www.pcisecuritystandards.org/document_library/ (accessed: 13.05.2025).

License

Copyright (c) 2025 E. A. Eremina , A. N. Prostova (Authors)

Keywords