pub trait ProcessSignalControl:
Debug
+ Send
+ Sync {
// Required methods
fn publish_alarm(
&self,
process: SignalProcessId,
event: SignalEvent,
) -> ProcessSignalPublicationResult;
fn signal_recipients(
&self,
process: SignalProcessId,
signal: i32,
) -> Result<Vec<SignalRecipient>, Errno>;
fn reserve_delivery(
&self,
permit: SignalDeliveryPermit,
) -> Result<(), Errno>;
fn release_delivery(
&self,
permit: SignalDeliveryPermit,
) -> Result<(), Errno>;
fn finish_publication_failure(
&self,
process: SignalProcessId,
) -> Result<(), Errno>;
// Provided methods
fn publish_child_exit(
&self,
_completion: ChildExitCompletion,
) -> ChildExitPublicationResult { ... }
fn alarm_recipients(
&self,
process: SignalProcessId,
) -> Result<Vec<SignalRecipient>, Errno> { ... }
fn finish_child_exit_publication_failure(
&self,
_receipt: ChildExitPublication,
) -> Result<(), Errno> { ... }
}Expand description
Shared run-owned facade. Implementations must not retain a Tool or Guest.
Calls are synchronous. Except for the explicitly named failure forwarding method, they must not call GlobalTool. No method may block on a guest callback, execute ordinary host IO, or drop retired descriptors while a signal/file-table guard is held. The caller supplies the causal scheduler fence; a snapshot by itself is not deterministic admission.
Required Methods§
Sourcefn publish_alarm(
&self,
process: SignalProcessId,
event: SignalEvent,
) -> ProcessSignalPublicationResult
fn publish_alarm( &self, process: SignalProcessId, event: SignalEvent, ) -> ProcessSignalPublicationResult
Publish a complete SIGALRM/SI_KERNEL event to an exact process lifetime.
Sourcefn signal_recipients(
&self,
process: SignalProcessId,
signal: i32,
) -> Result<Vec<SignalRecipient>, Errno>
fn signal_recipients( &self, process: SignalProcessId, signal: i32, ) -> Result<Vec<SignalRecipient>, Errno>
Eligible live recipients for one pending signal, in ascending numeric TID order. The caller intersects these with its causally admitted task generations.
Sourcefn reserve_delivery(&self, permit: SignalDeliveryPermit) -> Result<(), Errno>
fn reserve_delivery(&self, permit: SignalDeliveryPermit) -> Result<(), Errno>
Register one selected task. A second outstanding permit is not a retry.
Sourcefn release_delivery(&self, permit: SignalDeliveryPermit) -> Result<(), Errno>
fn release_delivery(&self, permit: SignalDeliveryPermit) -> Result<(), Errno>
Settle a permit that did not remove a signal (for example, a masked pending set after an authorized Tool operation). Exact duplicate receipts are acknowledged, never interpreted as a second operation.
Sourcefn finish_publication_failure(
&self,
process: SignalProcessId,
) -> Result<(), Errno>
fn finish_publication_failure( &self, process: SignalProcessId, ) -> Result<(), Errno>
Forward a retained publication failure to the run owner. This may call GlobalTool, so the caller MUST release its scheduler mutex first.
Provided Methods§
Sourcefn publish_child_exit(
&self,
_completion: ChildExitCompletion,
) -> ChildExitPublicationResult
fn publish_child_exit( &self, _completion: ChildExitCompletion, ) -> ChildExitPublicationResult
Publish one scheduler-authorized terminal child transition.
The caller supplies the causal scheduler fence. A committed or
failed-after-commit result must never be retried; backends may return the
retained receipt idempotently if an exact duplicate nevertheless arrives.
This publication makes waitability visible but does not reap the backend
child status. A Tool that schedules a consuming wait must still execute
that wait through crate::Guest::inject before retiring Tool shadow
state; publication is not a substitute for the backend wait syscall.
KVM may take its run-wide child-publication lock alone for an idempotent duplicate preflight. Its committing path then acquires the exact parent’s process-signal transaction before the run-wide registry and signal-state locks. A caller that holds a Tool scheduler mutex to make admission atomic must preserve that nested order: Tool scheduler -> backend parent transaction -> backend registry and signal state. No reverse path may acquire the Tool mutex while retaining those backend locks. An implementation used from that scheduler reservation must not call back into Tool code or wait for the fenced parent wait or other guest progress before returning.
Sourcefn alarm_recipients(
&self,
process: SignalProcessId,
) -> Result<Vec<SignalRecipient>, Errno>
fn alarm_recipients( &self, process: SignalProcessId, ) -> Result<Vec<SignalRecipient>, Errno>
Eligible live recipients, in ascending numeric TID order. The caller intersects these with its causally admitted task generations.
Sourcefn finish_child_exit_publication_failure(
&self,
_receipt: ChildExitPublication,
) -> Result<(), Errno>
fn finish_child_exit_publication_failure( &self, _receipt: ChildExitPublication, ) -> Result<(), Errno>
Forward one exact retained child-publication failure to the run owner.
The receipt prevents a caller from acknowledging a different terminal publication. This may call GlobalTool, so the caller MUST release its scheduler mutex first.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".