Blame SOURCES/0330-cgroup-introduce-support-for-cgroup-v2-CPUSET-contro.patch

ddca0b
From b55c9b8e717d1967e6aa16c1e2646fc81d899ab7 Mon Sep 17 00:00:00 2001
ddca0b
From: Pavel Hrdina <phrdina@redhat.com>
ddca0b
Date: Mon, 29 Jul 2019 17:50:05 +0200
ddca0b
Subject: [PATCH] cgroup: introduce support for cgroup v2 CPUSET controller
ddca0b
ddca0b
Introduce support for configuring cpus and mems for processes using
ddca0b
cgroup v2 CPUSET controller.  This allows users to limit which cpus
ddca0b
and memory NUMA nodes can be used by processes to better utilize
ddca0b
system resources.
ddca0b
ddca0b
The cgroup v2 interfaces to control it are cpuset.cpus and cpuset.mems
ddca0b
where the requested configuration is written.  However, it doesn't mean
ddca0b
that the requested configuration will be actually used as parent cgroup
ddca0b
may limit the cpus or mems as well.  In order to reflect the real
ddca0b
configuration cgroup v2 provides read-only files cpuset.cpus.effective
ddca0b
and cpuset.mems.effective which are exported to users as well.
ddca0b
ddca0b
(cherry picked from commit 047f5d63d7a1ab75073f8485e2f9b550d25b0772)
ddca0b
ddca0b
Related: #1724617
ddca0b
---
ddca0b
 doc/TRANSIENT-SETTINGS.md             |  2 +
ddca0b
 man/systemd.resource-control.xml      | 30 +++++++++++++
ddca0b
 src/basic/cgroup-util.c               |  1 +
ddca0b
 src/basic/cgroup-util.h               |  2 +
ddca0b
 src/core/cgroup.c                     | 63 +++++++++++++++++++++++++++
ddca0b
 src/core/cgroup.h                     |  5 +++
ddca0b
 src/core/dbus-cgroup.c                | 59 +++++++++++++++++++++++++
ddca0b
 src/core/dbus-unit.c                  | 48 ++++++++++++++++++++
ddca0b
 src/core/load-fragment-gperf.gperf.m4 |  2 +
ddca0b
 src/core/load-fragment.c              | 38 ++++++++++++++++
ddca0b
 src/core/load-fragment.h              |  2 +
ddca0b
 src/shared/bus-unit-util.c            | 16 +++++++
ddca0b
 src/systemctl/systemctl.c             |  2 +-
ddca0b
 src/test/test-cgroup-mask.c           |  3 +-
ddca0b
 14 files changed, 271 insertions(+), 2 deletions(-)
ddca0b
ddca0b
diff --git a/doc/TRANSIENT-SETTINGS.md b/doc/TRANSIENT-SETTINGS.md
ddca0b
index c2b5c0dcce..0b2ad66dcb 100644
ddca0b
--- a/doc/TRANSIENT-SETTINGS.md
ddca0b
+++ b/doc/TRANSIENT-SETTINGS.md
ddca0b
@@ -218,6 +218,8 @@ All cgroup/resource control settings are available for transient units
ddca0b
 ✓ CPUShares=
ddca0b
 ✓ StartupCPUShares=
ddca0b
 ✓ CPUQuota=
ddca0b
+✓ AllowedCPUs=
ddca0b
+✓ AllowedMemoryNodes=
ddca0b
 ✓ MemoryAccounting=
ddca0b
 ✓ MemoryLow=
ddca0b
 ✓ MemoryHigh=
ddca0b
diff --git a/man/systemd.resource-control.xml b/man/systemd.resource-control.xml
ddca0b
index 370c110592..4329742e94 100644
ddca0b
--- a/man/systemd.resource-control.xml
ddca0b
+++ b/man/systemd.resource-control.xml
ddca0b
@@ -201,6 +201,36 @@
ddca0b
         </listitem>
ddca0b
       </varlistentry>
ddca0b
 
ddca0b
+      <varlistentry>
ddca0b
+        <term><varname>AllowedCPUs=</varname></term>
ddca0b
+
ddca0b
+        <listitem>
ddca0b
+          <para>Restrict processes to be executed on specific CPUs. Takes a list of CPU indices or ranges separated by either
ddca0b
+          whitespace or commas. CPU ranges are specified by the lower and upper CPU indices separated by a dash.</para>
ddca0b
+
ddca0b
+          <para>Setting <varname>AllowedCPUs=</varname> doesn't guarantee that all of the CPUs will be used by the processes
ddca0b
+          as it may be limited by parent units. The effective configuration is reported as <varname>EffectiveCPUs=</varname>.</para>
ddca0b
+
ddca0b
+          <para>This setting is supported only with the unified control group hierarchy.</para>
ddca0b
+        </listitem>
ddca0b
+      </varlistentry>
ddca0b
+
ddca0b
+      <varlistentry>
ddca0b
+        <term><varname>AllowedMemoryNodes=</varname></term>
ddca0b
+
ddca0b
+        <listitem>
ddca0b
+          <para>Restrict processes to be executed on specific memory NUMA nodes. Takes a list of memory NUMA nodes indices
ddca0b
+          or ranges separated by either whitespace or commas. Memory NUMA nodes ranges are specified by the lower and upper
ddca0b
+          CPU indices separated by a dash.</para>
ddca0b
+
ddca0b
+          <para>Setting <varname>AllowedMemoryNodes=</varname> doesn't guarantee that all of the memory NUMA nodes will
ddca0b
+          be used by the processes as it may be limited by parent units. The effective configuration is reported as
ddca0b
+          <varname>EffectiveMemoryNodes=</varname>.</para>
ddca0b
+
ddca0b
+          <para>This setting is supported only with the unified control group hierarchy.</para>
ddca0b
+        </listitem>
ddca0b
+      </varlistentry>
ddca0b
+
ddca0b
       <varlistentry>
ddca0b
         <term><varname>MemoryAccounting=</varname></term>
ddca0b
 
ddca0b
diff --git a/src/basic/cgroup-util.c b/src/basic/cgroup-util.c
ddca0b
index 038ece4b06..6f47c3aacb 100644
ddca0b
--- a/src/basic/cgroup-util.c
ddca0b
+++ b/src/basic/cgroup-util.c
ddca0b
@@ -2763,6 +2763,7 @@ bool fd_is_cgroup_fs(int fd) {
ddca0b
 static const char *cgroup_controller_table[_CGROUP_CONTROLLER_MAX] = {
ddca0b
         [CGROUP_CONTROLLER_CPU] = "cpu",
ddca0b
         [CGROUP_CONTROLLER_CPUACCT] = "cpuacct",
ddca0b
+        [CGROUP_CONTROLLER_CPUSET] = "cpuset",
ddca0b
         [CGROUP_CONTROLLER_IO] = "io",
ddca0b
         [CGROUP_CONTROLLER_BLKIO] = "blkio",
ddca0b
         [CGROUP_CONTROLLER_MEMORY] = "memory",
ddca0b
diff --git a/src/basic/cgroup-util.h b/src/basic/cgroup-util.h
ddca0b
index 26e3ae0404..b414600dca 100644
ddca0b
--- a/src/basic/cgroup-util.h
ddca0b
+++ b/src/basic/cgroup-util.h
ddca0b
@@ -21,6 +21,7 @@
ddca0b
 typedef enum CGroupController {
ddca0b
         CGROUP_CONTROLLER_CPU,
ddca0b
         CGROUP_CONTROLLER_CPUACCT,    /* v1 only */
ddca0b
+        CGROUP_CONTROLLER_CPUSET,     /* v2 only */
ddca0b
         CGROUP_CONTROLLER_IO,         /* v2 only */
ddca0b
         CGROUP_CONTROLLER_BLKIO,      /* v1 only */
ddca0b
         CGROUP_CONTROLLER_MEMORY,
ddca0b
@@ -36,6 +37,7 @@ typedef enum CGroupController {
ddca0b
 typedef enum CGroupMask {
ddca0b
         CGROUP_MASK_CPU = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_CPU),
ddca0b
         CGROUP_MASK_CPUACCT = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_CPUACCT),
ddca0b
+        CGROUP_MASK_CPUSET = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_CPUSET),
ddca0b
         CGROUP_MASK_IO = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_IO),
ddca0b
         CGROUP_MASK_BLKIO = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_BLKIO),
ddca0b
         CGROUP_MASK_MEMORY = CGROUP_CONTROLLER_TO_MASK(CGROUP_CONTROLLER_MEMORY),
ddca0b
diff --git a/src/core/cgroup.c b/src/core/cgroup.c
ddca0b
index 76eafdc082..664d269483 100644
ddca0b
--- a/src/core/cgroup.c
ddca0b
+++ b/src/core/cgroup.c
ddca0b
@@ -161,9 +161,14 @@ void cgroup_context_done(CGroupContext *c) {
ddca0b
 
ddca0b
         c->ip_address_allow = ip_address_access_free_all(c->ip_address_allow);
ddca0b
         c->ip_address_deny = ip_address_access_free_all(c->ip_address_deny);
ddca0b
+
ddca0b
+        cpu_set_reset(&c->cpuset_cpus);
ddca0b
+        cpu_set_reset(&c->cpuset_mems);
ddca0b
 }
ddca0b
 
ddca0b
 void cgroup_context_dump(CGroupContext *c, FILE* f, const char *prefix) {
ddca0b
+        _cleanup_free_ char *cpuset_cpus = NULL;
ddca0b
+        _cleanup_free_ char *cpuset_mems = NULL;
ddca0b
         CGroupIODeviceLimit *il;
ddca0b
         CGroupIODeviceWeight *iw;
ddca0b
         CGroupBlockIODeviceBandwidth *b;
ddca0b
@@ -177,6 +182,9 @@ void cgroup_context_dump(CGroupContext *c, FILE* f, const char *prefix) {
ddca0b
 
ddca0b
         prefix = strempty(prefix);
ddca0b
 
ddca0b
+        cpuset_cpus = cpu_set_to_range_string(&c->cpuset_cpus);
ddca0b
+        cpuset_mems = cpu_set_to_range_string(&c->cpuset_mems);
ddca0b
+
ddca0b
         fprintf(f,
ddca0b
                 "%sCPUAccounting=%s\n"
ddca0b
                 "%sIOAccounting=%s\n"
ddca0b
@@ -189,6 +197,8 @@ void cgroup_context_dump(CGroupContext *c, FILE* f, const char *prefix) {
ddca0b
                 "%sCPUShares=%" PRIu64 "\n"
ddca0b
                 "%sStartupCPUShares=%" PRIu64 "\n"
ddca0b
                 "%sCPUQuotaPerSecSec=%s\n"
ddca0b
+                "%sAllowedCPUs=%s\n"
ddca0b
+                "%sAllowedMemoryNodes=%s\n"
ddca0b
                 "%sIOWeight=%" PRIu64 "\n"
ddca0b
                 "%sStartupIOWeight=%" PRIu64 "\n"
ddca0b
                 "%sBlockIOWeight=%" PRIu64 "\n"
ddca0b
@@ -212,6 +222,8 @@ void cgroup_context_dump(CGroupContext *c, FILE* f, const char *prefix) {
ddca0b
                 prefix, c->cpu_shares,
ddca0b
                 prefix, c->startup_cpu_shares,
ddca0b
                 prefix, format_timespan(u, sizeof(u), c->cpu_quota_per_sec_usec, 1),
ddca0b
+                prefix, cpuset_cpus,
ddca0b
+                prefix, cpuset_mems,
ddca0b
                 prefix, c->io_weight,
ddca0b
                 prefix, c->startup_io_weight,
ddca0b
                 prefix, c->blockio_weight,
ddca0b
@@ -541,6 +553,21 @@ static uint64_t cgroup_cpu_weight_to_shares(uint64_t weight) {
ddca0b
                      CGROUP_CPU_SHARES_MIN, CGROUP_CPU_SHARES_MAX);
ddca0b
 }
ddca0b
 
ddca0b
+static void cgroup_apply_unified_cpuset(Unit *u, CPUSet cpus, const char *name) {
ddca0b
+        _cleanup_free_ char *buf = NULL;
ddca0b
+        int r;
ddca0b
+
ddca0b
+        buf = cpu_set_to_range_string(&cpus);
ddca0b
+        if (!buf)
ddca0b
+            return;
ddca0b
+
ddca0b
+        r = cg_set_attribute("cpuset", u->cgroup_path, name, buf);
ddca0b
+        if (r < 0)
ddca0b
+                log_unit_full(u, IN_SET(r, -ENOENT, -EROFS, -EACCES) ? LOG_DEBUG : LOG_WARNING, r,
ddca0b
+                              "Failed to set %s: %m", name);
ddca0b
+
ddca0b
+}
ddca0b
+
ddca0b
 static bool cgroup_context_has_io_config(CGroupContext *c) {
ddca0b
         return c->io_accounting ||
ddca0b
                 c->io_weight != CGROUP_WEIGHT_INVALID ||
ddca0b
@@ -766,6 +793,11 @@ static void cgroup_context_apply(
ddca0b
                 }
ddca0b
         }
ddca0b
 
ddca0b
+        if ((apply_mask & CGROUP_MASK_CPUSET) && !is_root) {
ddca0b
+                cgroup_apply_unified_cpuset(u, c->cpuset_cpus, "cpuset.cpus");
ddca0b
+                cgroup_apply_unified_cpuset(u, c->cpuset_mems, "cpuset.mems");
ddca0b
+        }
ddca0b
+
ddca0b
         if (apply_mask & CGROUP_MASK_IO) {
ddca0b
                 bool has_io = cgroup_context_has_io_config(c);
ddca0b
                 bool has_blockio = cgroup_context_has_blockio_config(c);
ddca0b
@@ -1068,6 +1100,9 @@ CGroupMask cgroup_context_get_mask(CGroupContext *c) {
ddca0b
             c->cpu_quota_per_sec_usec != USEC_INFINITY)
ddca0b
                 mask |= CGROUP_MASK_CPUACCT | CGROUP_MASK_CPU;
ddca0b
 
ddca0b
+        if (c->cpuset_cpus.set || c->cpuset_mems.set)
ddca0b
+                mask |= CGROUP_MASK_CPUSET;
ddca0b
+
ddca0b
         if (cgroup_context_has_io_config(c) || cgroup_context_has_blockio_config(c))
ddca0b
                 mask |= CGROUP_MASK_IO | CGROUP_MASK_BLKIO;
ddca0b
 
ddca0b
@@ -2697,4 +2732,32 @@ static const char* const cgroup_device_policy_table[_CGROUP_DEVICE_POLICY_MAX] =
ddca0b
         [CGROUP_STRICT] = "strict",
ddca0b
 };
ddca0b
 
ddca0b
+int unit_get_cpuset(Unit *u, CPUSet *cpus, const char *name) {
ddca0b
+        _cleanup_free_ char *v = NULL;
ddca0b
+        int r;
ddca0b
+
ddca0b
+        assert(u);
ddca0b
+        assert(cpus);
ddca0b
+
ddca0b
+        if (!u->cgroup_path)
ddca0b
+                return -ENODATA;
ddca0b
+
ddca0b
+        if ((u->cgroup_realized_mask & CGROUP_MASK_CPUSET) == 0)
ddca0b
+                return -ENODATA;
ddca0b
+
ddca0b
+        r = cg_all_unified();
ddca0b
+        if (r < 0)
ddca0b
+                return r;
ddca0b
+        if (r == 0)
ddca0b
+                return -ENODATA;
ddca0b
+        if (r > 0)
ddca0b
+                r = cg_get_attribute("cpuset", u->cgroup_path, name, &v);
ddca0b
+        if (r == -ENOENT)
ddca0b
+                return -ENODATA;
ddca0b
+        if (r < 0)
ddca0b
+                return r;
ddca0b
+
ddca0b
+        return parse_cpu_set_full(v, cpus, false, NULL, NULL, 0, NULL);
ddca0b
+}
ddca0b
+
ddca0b
 DEFINE_STRING_TABLE_LOOKUP(cgroup_device_policy, CGroupDevicePolicy);
ddca0b
diff --git a/src/core/cgroup.h b/src/core/cgroup.h
ddca0b
index 2d2ff6fc3c..da10575394 100644
ddca0b
--- a/src/core/cgroup.h
ddca0b
+++ b/src/core/cgroup.h
ddca0b
@@ -4,6 +4,7 @@
ddca0b
 #include <stdbool.h>
ddca0b
 
ddca0b
 #include "cgroup-util.h"
ddca0b
+#include "cpu-set-util.h"
ddca0b
 #include "ip-address-access.h"
ddca0b
 #include "list.h"
ddca0b
 #include "time-util.h"
ddca0b
@@ -77,6 +78,9 @@ struct CGroupContext {
ddca0b
         uint64_t startup_cpu_weight;
ddca0b
         usec_t cpu_quota_per_sec_usec;
ddca0b
 
ddca0b
+        CPUSet cpuset_cpus;
ddca0b
+        CPUSet cpuset_mems;
ddca0b
+
ddca0b
         uint64_t io_weight;
ddca0b
         uint64_t startup_io_weight;
ddca0b
         LIST_HEAD(CGroupIODeviceWeight, io_device_weights);
ddca0b
@@ -205,3 +209,4 @@ const char* cgroup_device_policy_to_string(CGroupDevicePolicy i) _const_;
ddca0b
 CGroupDevicePolicy cgroup_device_policy_from_string(const char *s) _pure_;
ddca0b
 
ddca0b
 bool unit_cgroup_delegate(Unit *u);
ddca0b
+int unit_get_cpuset(Unit *u, CPUSet *cpus, const char *name);
ddca0b
diff --git a/src/core/dbus-cgroup.c b/src/core/dbus-cgroup.c
ddca0b
index 540bc77aed..30d4e83932 100644
ddca0b
--- a/src/core/dbus-cgroup.c
ddca0b
+++ b/src/core/dbus-cgroup.c
ddca0b
@@ -53,6 +53,27 @@ static int property_get_delegate_controllers(
ddca0b
         return sd_bus_message_close_container(reply);
ddca0b
 }
ddca0b
 
ddca0b
+static int property_get_cpuset(
ddca0b
+                sd_bus *bus,
ddca0b
+                const char *path,
ddca0b
+                const char *interface,
ddca0b
+                const char *property,
ddca0b
+                sd_bus_message *reply,
ddca0b
+                void *userdata,
ddca0b
+                sd_bus_error *error) {
ddca0b
+
ddca0b
+        CPUSet *cpus = userdata;
ddca0b
+        _cleanup_free_ uint8_t *array = NULL;
ddca0b
+        size_t allocated;
ddca0b
+
ddca0b
+        assert(bus);
ddca0b
+        assert(reply);
ddca0b
+        assert(cpus);
ddca0b
+
ddca0b
+        (void) cpu_set_to_dbus(cpus, &array, &allocated);
ddca0b
+        return sd_bus_message_append_array(reply, 'y', array, allocated);
ddca0b
+}
ddca0b
+
ddca0b
 static int property_get_io_device_weight(
ddca0b
                 sd_bus *bus,
ddca0b
                 const char *path,
ddca0b
@@ -283,6 +304,8 @@ const sd_bus_vtable bus_cgroup_vtable[] = {
ddca0b
         SD_BUS_PROPERTY("CPUShares", "t", NULL, offsetof(CGroupContext, cpu_shares), 0),
ddca0b
         SD_BUS_PROPERTY("StartupCPUShares", "t", NULL, offsetof(CGroupContext, startup_cpu_shares), 0),
ddca0b
         SD_BUS_PROPERTY("CPUQuotaPerSecUSec", "t", bus_property_get_usec, offsetof(CGroupContext, cpu_quota_per_sec_usec), 0),
ddca0b
+        SD_BUS_PROPERTY("AllowedCPUs", "ay", property_get_cpuset, offsetof(CGroupContext, cpuset_cpus), 0),
ddca0b
+        SD_BUS_PROPERTY("AllowedMemoryNodes", "ay", property_get_cpuset, offsetof(CGroupContext, cpuset_mems), 0),
ddca0b
         SD_BUS_PROPERTY("IOAccounting", "b", bus_property_get_bool, offsetof(CGroupContext, io_accounting), 0),
ddca0b
         SD_BUS_PROPERTY("IOWeight", "t", NULL, offsetof(CGroupContext, io_weight), 0),
ddca0b
         SD_BUS_PROPERTY("StartupIOWeight", "t", NULL, offsetof(CGroupContext, startup_io_weight), 0),
ddca0b
@@ -671,6 +694,42 @@ int bus_cgroup_set_property(
ddca0b
 
ddca0b
                 return 1;
ddca0b
 
ddca0b
+        } else if (STR_IN_SET(name, "AllowedCPUs", "AllowedMemoryNodes")) {
ddca0b
+                const void *a;
ddca0b
+                size_t n;
ddca0b
+                _cleanup_(cpu_set_reset) CPUSet new_set = {};
ddca0b
+
ddca0b
+                r = sd_bus_message_read_array(message, 'y', &a, &n);
ddca0b
+                if (r < 0)
ddca0b
+                        return r;
ddca0b
+
ddca0b
+                r = cpu_set_from_dbus(a, n, &new_set);
ddca0b
+                if (r < 0)
ddca0b
+                        return r;
ddca0b
+
ddca0b
+                if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
ddca0b
+                        _cleanup_free_ char *setstr = NULL;
ddca0b
+                        _cleanup_free_ char *data = NULL;
ddca0b
+                        CPUSet *set;
ddca0b
+
ddca0b
+                        setstr = cpu_set_to_range_string(&new_set);
ddca0b
+
ddca0b
+                        if (streq(name, "AllowedCPUs"))
ddca0b
+                                set = &c->cpuset_cpus;
ddca0b
+                        else
ddca0b
+                                set = &c->cpuset_mems;
ddca0b
+
ddca0b
+                        if (asprintf(&data, "%s=%s", name, setstr) < 0)
ddca0b
+                                return -ENOMEM;
ddca0b
+
ddca0b
+                        cpu_set_reset(set);
ddca0b
+                        cpu_set_add_all(set, &new_set);
ddca0b
+                        unit_invalidate_cgroup(u, CGROUP_MASK_CPUSET);
ddca0b
+                        unit_write_setting(u, flags, name, data);
ddca0b
+                }
ddca0b
+
ddca0b
+                return 1;
ddca0b
+
ddca0b
         } else if ((iol_type = cgroup_io_limit_type_from_string(name)) >= 0) {
ddca0b
                 const char *path;
ddca0b
                 unsigned n = 0;
ddca0b
diff --git a/src/core/dbus-unit.c b/src/core/dbus-unit.c
ddca0b
index c5bca10979..aa15e47754 100644
ddca0b
--- a/src/core/dbus-unit.c
ddca0b
+++ b/src/core/dbus-unit.c
ddca0b
@@ -752,6 +752,52 @@ static int property_get_cpu_usage(
ddca0b
         return sd_bus_message_append(reply, "t", ns);
ddca0b
 }
ddca0b
 
ddca0b
+static int property_get_cpuset_cpus(
ddca0b
+                sd_bus *bus,
ddca0b
+                const char *path,
ddca0b
+                const char *interface,
ddca0b
+                const char *property,
ddca0b
+                sd_bus_message *reply,
ddca0b
+                void *userdata,
ddca0b
+                sd_bus_error *error) {
ddca0b
+
ddca0b
+        Unit *u = userdata;
ddca0b
+        _cleanup_(cpu_set_reset) CPUSet cpus = {};
ddca0b
+        _cleanup_free_ uint8_t *array = NULL;
ddca0b
+        size_t allocated;
ddca0b
+
ddca0b
+        assert(bus);
ddca0b
+        assert(reply);
ddca0b
+        assert(u);
ddca0b
+
ddca0b
+        (void) unit_get_cpuset(u, &cpus, "cpuset.cpus.effective");
ddca0b
+        (void) cpu_set_to_dbus(&cpus, &array, &allocated);
ddca0b
+        return sd_bus_message_append_array(reply, 'y', array, allocated);
ddca0b
+}
ddca0b
+
ddca0b
+static int property_get_cpuset_mems(
ddca0b
+                sd_bus *bus,
ddca0b
+                const char *path,
ddca0b
+                const char *interface,
ddca0b
+                const char *property,
ddca0b
+                sd_bus_message *reply,
ddca0b
+                void *userdata,
ddca0b
+                sd_bus_error *error) {
ddca0b
+
ddca0b
+        Unit *u = userdata;
ddca0b
+        _cleanup_(cpu_set_reset) CPUSet mems = {};
ddca0b
+        _cleanup_free_ uint8_t *array = NULL;
ddca0b
+        size_t allocated;
ddca0b
+
ddca0b
+        assert(bus);
ddca0b
+        assert(reply);
ddca0b
+        assert(u);
ddca0b
+
ddca0b
+        (void) unit_get_cpuset(u, &mems, "cpuset.mems.effective");
ddca0b
+        (void) cpu_set_to_dbus(&mems, &array, &allocated);
ddca0b
+        return sd_bus_message_append_array(reply, 'y', array, allocated);
ddca0b
+}
ddca0b
+
ddca0b
 static int property_get_cgroup(
ddca0b
                 sd_bus *bus,
ddca0b
                 const char *path,
ddca0b
@@ -1074,6 +1120,8 @@ const sd_bus_vtable bus_unit_cgroup_vtable[] = {
ddca0b
         SD_BUS_PROPERTY("ControlGroup", "s", property_get_cgroup, 0, 0),
ddca0b
         SD_BUS_PROPERTY("MemoryCurrent", "t", property_get_current_memory, 0, 0),
ddca0b
         SD_BUS_PROPERTY("CPUUsageNSec", "t", property_get_cpu_usage, 0, 0),
ddca0b
+        SD_BUS_PROPERTY("EffectiveCPUs", "ay", property_get_cpuset_cpus, 0, 0),
ddca0b
+        SD_BUS_PROPERTY("EffectiveMemoryNodes", "ay", property_get_cpuset_mems, 0, 0),
ddca0b
         SD_BUS_PROPERTY("TasksCurrent", "t", property_get_current_tasks, 0, 0),
ddca0b
         SD_BUS_PROPERTY("IPIngressBytes", "t", property_get_ip_counter, 0, 0),
ddca0b
         SD_BUS_PROPERTY("IPIngressPackets", "t", property_get_ip_counter, 0, 0),
ddca0b
diff --git a/src/core/load-fragment-gperf.gperf.m4 b/src/core/load-fragment-gperf.gperf.m4
ddca0b
index 49e938d0ce..ebb44df487 100644
ddca0b
--- a/src/core/load-fragment-gperf.gperf.m4
ddca0b
+++ b/src/core/load-fragment-gperf.gperf.m4
ddca0b
@@ -167,6 +167,8 @@ $1.StartupCPUWeight,             config_parse_cg_weight,             0,
ddca0b
 $1.CPUShares,                    config_parse_cpu_shares,            0,                             offsetof($1, cgroup_context.cpu_shares)
ddca0b
 $1.StartupCPUShares,             config_parse_cpu_shares,            0,                             offsetof($1, cgroup_context.startup_cpu_shares)
ddca0b
 $1.CPUQuota,                     config_parse_cpu_quota,             0,                             offsetof($1, cgroup_context)
ddca0b
+$1.CPUSetCpus,                   config_parse_cpuset_cpus,           0,                             offsetof($1, cgroup_context)
ddca0b
+$1.CPUSetMems,                   config_parse_cpuset_mems,           0,                             offsetof($1, cgroup_context)
ddca0b
 $1.MemoryAccounting,             config_parse_bool,                  0,                             offsetof($1, cgroup_context.memory_accounting)
ddca0b
 $1.MemoryLow,                    config_parse_memory_limit,          0,                             offsetof($1, cgroup_context)
ddca0b
 $1.MemoryHigh,                   config_parse_memory_limit,          0,                             offsetof($1, cgroup_context)
ddca0b
diff --git a/src/core/load-fragment.c b/src/core/load-fragment.c
ddca0b
index 35dd595098..6debf82401 100644
ddca0b
--- a/src/core/load-fragment.c
ddca0b
+++ b/src/core/load-fragment.c
ddca0b
@@ -3011,6 +3011,44 @@ int config_parse_cpu_quota(
ddca0b
         return 0;
ddca0b
 }
ddca0b
 
ddca0b
+int config_parse_cpuset_cpus(
ddca0b
+                const char *unit,
ddca0b
+                const char *filename,
ddca0b
+                unsigned line,
ddca0b
+                const char *section,
ddca0b
+                unsigned section_line,
ddca0b
+                const char *lvalue,
ddca0b
+                int ltype,
ddca0b
+                const char *rvalue,
ddca0b
+                void *data,
ddca0b
+                void *userdata) {
ddca0b
+
ddca0b
+        CGroupContext *c = data;
ddca0b
+
ddca0b
+        (void) parse_cpu_set_extend(rvalue, &c->cpuset_cpus, true, unit, filename, line, lvalue);
ddca0b
+
ddca0b
+        return 0;
ddca0b
+}
ddca0b
+
ddca0b
+int config_parse_cpuset_mems(
ddca0b
+                const char *unit,
ddca0b
+                const char *filename,
ddca0b
+                unsigned line,
ddca0b
+                const char *section,
ddca0b
+                unsigned section_line,
ddca0b
+                const char *lvalue,
ddca0b
+                int ltype,
ddca0b
+                const char *rvalue,
ddca0b
+                void *data,
ddca0b
+                void *userdata) {
ddca0b
+
ddca0b
+        CGroupContext *c = data;
ddca0b
+
ddca0b
+        (void) parse_cpu_set_extend(rvalue, &c->cpuset_mems, true, unit, filename, line, lvalue);
ddca0b
+
ddca0b
+        return 0;
ddca0b
+}
ddca0b
+
ddca0b
 int config_parse_memory_limit(
ddca0b
                 const char *unit,
ddca0b
                 const char *filename,
ddca0b
diff --git a/src/core/load-fragment.h b/src/core/load-fragment.h
ddca0b
index f2ca1b8ee7..6612e1fb32 100644
ddca0b
--- a/src/core/load-fragment.h
ddca0b
+++ b/src/core/load-fragment.h
ddca0b
@@ -86,6 +86,8 @@ CONFIG_PARSER_PROTOTYPE(config_parse_set_status);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_namespace_path_strv);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_temporary_filesystems);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_cpu_quota);
ddca0b
+CONFIG_PARSER_PROTOTYPE(config_parse_cpuset_cpus);
ddca0b
+CONFIG_PARSER_PROTOTYPE(config_parse_cpuset_mems);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_protect_home);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_protect_system);
ddca0b
 CONFIG_PARSER_PROTOTYPE(config_parse_bus_name);
ddca0b
diff --git a/src/shared/bus-unit-util.c b/src/shared/bus-unit-util.c
ddca0b
index 3c42e97b7a..8f3b463c6b 100644
ddca0b
--- a/src/shared/bus-unit-util.c
ddca0b
+++ b/src/shared/bus-unit-util.c
ddca0b
@@ -396,6 +396,22 @@ static int bus_append_cgroup_property(sd_bus_message *m, const char *field, cons
ddca0b
 
ddca0b
                 return bus_append_cg_cpu_shares_parse(m, field, eq);
ddca0b
 
ddca0b
+        if (STR_IN_SET(field, "AllowedCPUs", "AllowedMemoryNodes")) {
ddca0b
+                _cleanup_(cpu_set_reset) CPUSet cpuset = {};
ddca0b
+                _cleanup_free_ uint8_t *array = NULL;
ddca0b
+                size_t allocated;
ddca0b
+
ddca0b
+                r = parse_cpu_set(eq, &cpuset);
ddca0b
+                if (r < 0)
ddca0b
+                        return log_error_errno(r, "Failed to parse %s value: %s", field, eq);
ddca0b
+
ddca0b
+                r = cpu_set_to_dbus(&cpuset, &array, &allocated);
ddca0b
+                if (r < 0)
ddca0b
+                        return log_error_errno(r, "Failed to serialize CPUSet: %m");
ddca0b
+
ddca0b
+                return bus_append_byte_array(m, field, array, allocated);
ddca0b
+        }
ddca0b
+
ddca0b
         if (STR_IN_SET(field, "BlockIOWeight", "StartupBlockIOWeight"))
ddca0b
 
ddca0b
                 return bus_append_cg_blkio_weight_parse(m, field, eq);
ddca0b
diff --git a/src/systemctl/systemctl.c b/src/systemctl/systemctl.c
ddca0b
index 7274921e6d..a3074bc5e3 100644
ddca0b
--- a/src/systemctl/systemctl.c
ddca0b
+++ b/src/systemctl/systemctl.c
ddca0b
@@ -4892,7 +4892,7 @@ static int print_property(const char *name, sd_bus_message *m, bool value, bool
ddca0b
                         print_prop(name, "%s", h);
ddca0b
 
ddca0b
                         return 1;
ddca0b
-                } else if (contents[0] == SD_BUS_TYPE_BYTE && STR_IN_SET(name, "CPUAffinity", "NUMAMask")) {
ddca0b
+                } else if (contents[0] == SD_BUS_TYPE_BYTE && STR_IN_SET(name, "CPUAffinity", "NUMAMask", "AllowedCPUs", "AllowedMemoryNodes", "EffectiveCPUs", "EffectiveMemoryNodes")) {
ddca0b
                         _cleanup_free_ char *affinity = NULL;
ddca0b
                         _cleanup_(cpu_set_reset) CPUSet set = {};
ddca0b
                         const void *a;
ddca0b
diff --git a/src/test/test-cgroup-mask.c b/src/test/test-cgroup-mask.c
ddca0b
index d65959edf1..93c3f5d856 100644
ddca0b
--- a/src/test/test-cgroup-mask.c
ddca0b
+++ b/src/test/test-cgroup-mask.c
ddca0b
@@ -104,9 +104,10 @@ static void test_cg_mask_to_string_one(CGroupMask mask, const char *t) {
ddca0b
 
ddca0b
 static void test_cg_mask_to_string(void) {
ddca0b
         test_cg_mask_to_string_one(0, NULL);
ddca0b
-        test_cg_mask_to_string_one(_CGROUP_MASK_ALL, "cpu cpuacct io blkio memory devices pids");
ddca0b
+        test_cg_mask_to_string_one(_CGROUP_MASK_ALL, "cpu cpuacct cpuset io blkio memory devices pids");
ddca0b
         test_cg_mask_to_string_one(CGROUP_MASK_CPU, "cpu");
ddca0b
         test_cg_mask_to_string_one(CGROUP_MASK_CPUACCT, "cpuacct");
ddca0b
+        test_cg_mask_to_string_one(CGROUP_MASK_CPUSET, "cpuset");
ddca0b
         test_cg_mask_to_string_one(CGROUP_MASK_IO, "io");
ddca0b
         test_cg_mask_to_string_one(CGROUP_MASK_BLKIO, "blkio");
ddca0b
         test_cg_mask_to_string_one(CGROUP_MASK_MEMORY, "memory");